← Search

Mingyuan Fan

10 accepted papers

2026

NDAD: Negative-Direction Aware Decoding for Large Language Models via Controllable Hallucination Signal Injection

ICLR 2026poster

Large language models (LLMs) have recently achieved impressive progress in knowledge-intensive and reasoning tasks. However, their tendency to produce fabricated or factually inconsistent content remains a fundamental challenge to their practical deployment. To address this issue, we propose Negativ…

Cited by 0SourceScholar
2025

Bad-PFL: Exploiting Backdoor Attacks against Personalized Federated Learning

ICLR 2025poster

Data heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL h…

Cited by 1SourcePDFScholar
2025

Growth Inhibitors for Suppressing Inappropriate Image Concepts in Diffusion Models

ICLR 2025poster

Despite their remarkable image generation capabilities, text-to-image diffusion models inadvertently learn inappropriate concepts from vast and unfiltered training data, which leads to various ethical and business risks. Specifically, model-generated images may exhibit not safe for work (NSFW) conte…

Cited by 2SourcePDFScholar
2024

Transferability Bound Theory: Exploring Relationship between Adversarial Transferability and Flatness

NeurIPS 2024poster

A prevailing belief in attack and defense community is that the higher flatness of adversarial examples enables their better cross-model transferability, leading to a growing interest in employing sharpness-aware minimization and its variants. However, the theoretical relationship between the transf…

2024

Tuning-Free Inversion-Enhanced Control for Consistent Image Editing

AAAI 2024technical

Consistent editing of real images is a challenging task, as it requires performing non-rigid edits (e.g., changing postures) to the main objects in the input image without changing their identity or attributes. To guarantee consistent attributes, some existing methods fine-tune the entire model or t…

Cited by 12SourcePDFScholar
2023

Enhance Transferability of Adversarial Examples with Model Architecture

ICASSP 2023accepted

Transferability of adversarial examples is of critical importance to launch black-box adversarial attacks, where attackers are only allowed to access the output of the target model. However, under such a challenging but practical setting, the crafted adversarial examples are always prone to overfitt…

Cited by 0SourceScholar
2023

Masked Auto-Encoders Meet Generative Adversarial Networks and Beyond

CVPR 2023poster

Masked Auto-Encoder (MAE) pretraining methods randomly mask image patches and then train a vision Transformer to reconstruct the original pixels based on the unmasked patches. While they demonstrates impressive performance for downstream vision tasks, it generally requires a large amount of training…

Cited by 20SourcePDFScholar
2023

Uncertainty-Aware Image Captioning

AAAI 2023technical

It is well believed that the higher uncertainty in a word of the caption, the more inter-correlated context information is required to determine it. However, current image captioning methods usually consider the generation of all words in a sentence sequentially and equally. In this paper, we propos…

Cited by 19SourcePDFScholar
2022

Combating False Sense of Security: Breaking the Defense of Adversarial Training Via Non-Gradient Adversarial Attack

ICASSP 2022accepted

Adversarial training is believed to be the most robust and effective defense method against adversarial attacks. Gradient-based adversarial attack methods are generally adopted to evaluate the effectiveness of adversarial training. However, in this paper, by diving into the existing adversarial atta…

Cited by 0SourceScholar
2021

Rethinking BiSeNet for Real-Time Semantic Segmentation

CVPR 2021poster

BiSeNet has been proved to be a popular two-stream network for real-time segmentation. However, its principle of adding an extra path to encode spatial information is time-consuming, and the backbones borrowed from pretrained tasks, e.g., image classification, may be inefficient for image segmentati…

Cited by 814PDFcodeScholar