← Search

Dawei Zhou

27 accepted papers

2026

Balancing Learning Rates Across Layers: Exact Two-Step Dynamics and Optimal Scaling in Linear Neural Networks

ICML 2026poster

We study optimal learning-rate selection in two-layer and three-layer linear neural networks trained to learn a single-index target function. In particular, we derive the exact closed-form expressions for the gradients and test loss after one and two steps of gradient descent, enabling a precise cha…

Cited by 0SourceScholar
2026

HalluGuard: Demystifying Data-Driven and Reasoning-Driven Hallucinations in LLMs

ICLR 2026poster

The reliability of Large Language Models (LLMs) in high-stakes domains such as healthcare, law, and scientific discovery is often compromised by hallucinations. These failures typically stem from two sources: *data-driven hallucinations* and *reasoning-driven hallucinations*. However, existing detec…

Cited by 0SourcecodeScholar
2026

Plan and Budget: Effective and Efficient Test-Time Scaling on Reasoning Large Language Models

ICLR 2026poster

Large Language Models (LLMs) have achieved remarkable success in complex reasoning tasks, but their inference remains computationally inefficient. We observe a common failure mode in many prevalent LLMs, overthinking, where models generate verbose and tangential reasoning traces even for simple quer…

Cited by 0SourceScholar
2026

Seeing Through the Brain: New Insights from Decoding Visual Stimuli with fMRI

ICLR 2026oral

Understanding how the brain encodes visual information is a central challenge in neuroscience and machine learning. A promising approach is to reconstruct visual stimuli—essentially images—from functional Magnetic Resonance Imaging (fMRI) signals. This involves two stages: transforming fMRI signals…

Cited by 0SourceScholar
2025

GENUINE: Graph Enhanced Multi-level Uncertainty Estimation for Large Language Models

EMNLP 2025

Uncertainty estimation is essential for enhancing the reliability of Large Language Models (LLMs), particularly in high-stakes applications. Existing methods often overlook semantic dependencies, relying on token-level probability measures that fail to capture structural relationships within the gen

2025

HeroFilter: Adaptive Spectral Graph Filter for Varying Heterophilic Relations

NeurIPS 2025poster

Graph heterophily, where connected nodes have different labels, has attracted significant interest recently. Most existing works adopt a simplified approach - using low-pass filters for homophilic graphs and high-pass filters for heterophilic graphs. However, we discover that the relationship betwee…

Cited by 0SourceScholar
2025

LensLLM: Unveiling Fine-Tuning Dynamics for LLM Selection

ICML 2025poster

The proliferation of open-sourced Large Language Models (LLMs) and diverse downstream tasks necessitates efficient model selection, given the impracticality of fine-tuning all candidates due to computational constraints. Despite the recent advances in LLM selection, a fundamental research question l…

2025

MetaScientist: A Human-AI Synergistic Framework for Automated Mechanical Metamaterial Design

NAACL 2025system demonstrations

The discovery of novel mechanical metamaterials, whose properties are dominated by their engineered structures rather than chemical composition, is a knowledge-intensive and resource-demanding process. To accelerate the design of novel metamaterials, we present MetaScientist, a human-in-the-loop sys…

2025

Mitigating Feature Gap for Adversarial Robustness by Feature Disentanglement

AAAI 2025technical

Adversarial fine-tuning methods enhance adversarial robustness via fine-tuning the pre-trained model in an adversarial training manner. However, we identify that some specific latent features of adversarial samples are confused by adversarial perturbation and lead to an unexpectedly increasing gap b…

Cited by 0SourcePDFScholar
2025

Motion Artifact Removal in Pixel-Frequency Domain via Alternate Masks and Diffusion Model

AAAI 2025technical

Motion artifacts present in magnetic resonance imaging (MRI) can seriously interfere with clinical diagnosis. Removing motion artifacts is a straightforward solution and has been extensively studied. However, paired data are still heavily relied on in recent works and the perturbations in k-space (f…

2025

Phase and Amplitude-aware Prompting for Enhancing Adversarial Robustness

ICML 2025poster

Deep neural networks are found to be vulnerable to adversarial perturbations. The prompt-based defense has been increasingly studied due to its high efficiency. However, existing prompt-based defenses mainly exploited mixed prompt patterns, where critical patterns closely related to object semantics…

Cited by 0SourcePDFScholar
2025

SciCompanion: Graph-Grounded Reasoning for Structured Evaluation of Scientific Arguments

EMNLP 2025

The exponential growth of scientific publications has overwhelmed reviewers and researchers, with top conferences receiving thousands of submissions annually. Reviewers must assess feasibility, novelty, and impact under tight deadlines, often lacking tools to identify relevant prior work. Early-care

2025

UniMate: A Unified Model for Mechanical Metamaterial Generation, Property Prediction, and Condition Confirmation

ICML 2025poster

Metamaterials are artificial materials that are designed to meet unseen properties in nature, such as ultra-stiffness and negative materials indices. In mechanical metamaterial design, three key modalities are typically involved, i.e., 3D topology, density condition, and mechanical property. Real-wo…

2024

3D-FuM: Benchmarking 3D Molecule Learning with Functional Groups

IJCAI 2024poster

Molecular graph representation learning plays a crucial role in various domains, such as drug discovery and chemical reaction prediction, where molecular graphs are typically depicted as 2D topological structures. However, recent insights highlight the critical role of 3D geometric information and f…

2024

Combating Insider Threat in the Open-World Environments: Identification, Monitoring, and Data Augmentation

AAAI 2024technical

Recent years have witnessed a dramatic increase in a class of security threats known as "insider threats". These threats occur when individuals with authorized access to an organization's network engage in harmful activities, potentially leading to the disclosure of vital information or adversely af…

Cited by 2SourcePDFScholar
2024

Enhancing Size Generalization in Graph Neural Networks through Disentangled Representation Learning

ICML 2024poster

Although most graph neural networks (GNNs) can operate on graphs of any size, their classification performance often declines on graphs larger than those encountered during training. Existing methods insufficiently address the removal of size information from graph representations, resulting in sub-…

2024

EvoluNet: Advancing Dynamic Non-IID Transfer Learning on Graphs

ICML 2024poster

Non-IID transfer learning on graphs is crucial in many high-stakes domains. The majority of existing works assume stationary distribution for both source and target domains. However, real-world graphs are intrinsically dynamic, presenting challenges in terms of domain evolution and dynamic discrepan…

2024

Improving Accuracy-robustness Trade-off via Pixel Reweighted Adversarial Training

ICML 2024poster

Adversarial training (AT) trains models using adversarial examples (AEs), which are natural images modified with specific perturbations to mislead the model. These perturbations are constrained by a predefined perturbation budget $\epsilon$ and are equally applied to each pixel within an image. Howe…

2024

Towards Heterogeneous Long-tailed Learning: Benchmarking, Metrics, and Toolbox

NeurIPS 2024poster

Long-tailed data distributions pose challenges for a variety of domains like e-commerce, finance, biomedical science, and cyber security, where the performance of machine learning models is often dominated by head categories while tail categories are inadequately learned. This work aims to provide a…

2023

Eliminating Adversarial Noise via Information Discard and Robust Representation Restoration

ICML 2023poster

Deep neural networks (DNNs) are vulnerable to adversarial noise. Denoising model-based defense is a major protection strategy. However, denoising models may fail and induce negative effects in fully white-box scenarios. In this work, we start from the latent inherent properties of adversarial sample…

Cited by 8SourcePDFScholar
2023

Hiding Visual Information via Obfuscating Adversarial Perturbations

ICCV 2023poster

Growing leakage and misuse of visual information raise security and privacy concerns, which promotes the development of information protection. Existing adversarial perturbations-based methods mainly focus on the de-identification against deep learning models. However, the inherent visual informatio…

Cited by 12PDFcodeScholar
2023

Personalized Federated Learning under Mixture of Distributions

ICML 2023poster

The recent trend towards Personalized Federated Learning (PFL) has garnered significant attention as it allows for the training of models that are tailored to each client while maintaining data privacy. However, current PFL techniques primarily focus on modeling the conditional distribution heteroge…

2023

Phase-aware Adversarial Defense for Improving Adversarial Robustness

ICML 2023poster

Deep neural networks have been found to be vulnerable to adversarial noise. Recent works show that exploring the impact of adversarial noise on intrinsic components of data can help improve adversarial robustness. However, the pattern closely related to human perception has not been deeply studied.…

Cited by 8SourcePDFScholar
2022

Improving Adversarial Robustness via Mutual Information Estimation

ICML 2022spotlight

Deep neural networks (DNNs) are found to be vulnerable to adversarial noise. They are typically misled by adversarial samples to make wrong predictions. To alleviate this negative effect, in this paper, we investigate the dependence between outputs of the target model and input adversarial samples f…

2021

Removing Adversarial Noise in Class Activation Feature Space

ICCV 2021poster

Deep neural networks (DNNs) are vulnerable to adversarial noise. Pre-processing based defenses could largely remove adversarial noise by processing inputs. However, they are typically affected by the error amplification effect, especially in the front of continuously evolving attacks. To solve this…

Cited by 36PDFcodeScholar
2021

Towards Defending against Adversarial Examples via Attack-Invariant Features

ICML 2021spotlight

Deep neural networks (DNNs) are vulnerable to adversarial noise. Their adversarial robustness can be improved by exploiting adversarial examples. However, given the continuously evolving attacks, models trained on seen types of adversarial examples generally cannot generalize well to unseen types of…