← Search

Bingyin Zhao

4 accepted papers

2025

BAM-ICL: Causal Hijacking In-Context Learning with Budgeted Adversarial Manipulation

NeurIPS 2025poster

Recent research shows that large language models (LLMs) are vulnerable to hijacking attacks under the scenario of in-context learning (ICL) where LLMs demonstrate impressive capabilities in performing tasks by conditioning on a sequence of in-context examples (ICEs) (i.e., prompts with task-specific…

Cited by 0SourceScholar
2025

UIBDiffusion: Universal Imperceptible Backdoor Attack for Diffusion Models

CVPR 2025highlight

Recent studies show that diffusion models (DMs) are vulnerable to backdoor attacks. Existing backdoor attacks impose unconcealed triggers (e.g., a gray box and eyeglasses) that contain evident patterns, rendering remarkable attack effects yet easy detection upon human inspection and defensive algori…

2023

Fully Attentional Networks with Self-emerging Token Labeling

ICCV 2023poster

Recent studies indicate that Vision Transformers (ViTs) are robust against out-of-distribution scenarios. In particular, the Fully Attentional Network (FAN) - a family of ViT backbones, has achieved state-of-the-art robustness. In this paper, we revisit the FAN models and improve their pre-training…

Cited by 8PDFcodeScholar
2022

CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets

AAAI 2022technical

Poisoning attacks are emerging threats to deep neural networks where the adversaries attempt to compromise the models by injecting malicious data points in the clean training data. Poisoning attacks target either the availability or integrity of a model. The availability attack aims to degrade the o…