← Search

Qingming Li

15 accepted papers

2026

Contextual and Seasonal LSTMs for Time Series Anomaly Detection

ICLR 2026poster

Univariate time series (UTS), where each timestamp records a single variable, serve as crucial indicators in web systems and cloud servers. Anomaly detection in UTS plays an essential role in both data mining and system reliability management. However, existing reconstruction-based and prediction-ba…

Cited by 0SourcecodeScholar
2026

From ``Sure" to ``Sorry": Detecting Jailbreak in Large Vision Language Model via JailNeurons

ICLR 2026poster

Large Vision-Language Models (LVLMs) are vulnerable to jailbreak attacks that can generate harmful content. Existing detection methods are either limited to detecting specific attack types or are too time-consuming, making them impractical for real-world deployment. To address these challenges, we p…

Cited by 0SourcecodeScholar
2026

Order within Chaos: Capturing Intrinsic Energy Anomalies for AI-Manipulated Image Forgery Localization

ICML 2026poster

Recent advancements in generative AI have led to image editing models capable of producing realistic forgeries that evade traditional image forgery localization methods, as these approaches depend on physical noise absent in synthetic data. To address this challenge, we theoretically demonstrate tha…

Cited by 0SourceScholar
2026

SOPE: Situation-Aware and Statistically Indistinguishable Privacy Exfiltration for MCP-enabled Agents

ICML 2026poster

Model Context Protocol (MCP) enables Large Language Model (LLM) agents to interact with external tools, but this extensibility introduces significant supply chain vulnerabilities that enable covert privacy exfiltration. Prior studies have revealed privacy leakage in MCP-enabled agents via indirect p…

Cited by 0SourceScholar
2026

STAR: Strategy-driven Automatic Jailbreak Red-teaming For Large Language Model

ICLR 2026poster

Jailbreaking refers to techniques that bypass the safety alignment of large language models (LLMs) to elicit harmful outputs, and automated red-teaming has become a key approach for detecting such vulnerabilities before deployment. However, most existing red-teaming methods operate directly in text…

Cited by 0SourceScholar
2025

An Inversion-based Measure of Memorization for Diffusion Models

ICCV 2025poster

The past few years have witnessed substantial advances in image generation powered by diffusion models. However, it was shown that diffusion models are susceptible to training data memorization, raising significant concerns regarding copyright infringement and privacy invasion. This study delves int…

2025

CAMH: Advancing Model Hijacking Attack in Machine Learning

AAAI 2025technical

In the burgeoning domain of machine learning, the reliance on third-party services for model training and the adoption of pre-trained models have surged. However, this reliance introduces vulnerabilities to model hijacking attacks, where adversaries manipulate models to perform unintended tasks, lea…

Cited by 0SourcePDFScholar
2025

Differential Private Stochastic Optimization with Heavy-tailed Data: Towards Optimal Rates

AAAI 2025technical

We study convex optimization problems under differential privacy (DP). With heavy-tailed gradients, existing works achieve suboptimal rates. The main obstacle is that existing gradient estimators have suboptimal tail property, resulting in a superfluous factor of d in the union bound. In this paper,…

Cited by 4SourcePDFScholar
2025

Enhancing Learning with Label Differential Privacy by Vector Approximation

ICLR 2025spotlight

Label differential privacy (DP) is a framework that protects the privacy of labels in training datasets, while the feature vectors are public. Existing approaches protect the privacy of labels by flipping them randomly, and then train a model to make the output approximate the privatized label. Howe…

Cited by 2SourcePDFScholar
2025

IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents

EMNLP 2025

Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks. However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool responses may contain

Cited by 0SourcePDFScholar
2025

TWIST: Text-encoder Weight-editing for Inserting Secret Trojans in Text-to-Image Models

ACL 2025long

Text-to-image (T2I) models excel at generating high-quality images from text via powerful text encoders but training these encoders demands substantial computational resources. Consequently, many users seek pre-trained text encoders from model plugin-sharing platforms like Civitai and Hugging Face,…

Cited by 0SourcePDFScholar
2025

VideoEraser: Concept Erasure in Text-to-Video Diffusion Models

EMNLP 2025

The rapid growth of text-to-video (T2V) diffusion models has raised concerns about privacy, copyright, and safety due to their potential misuse in generating harmful or misleading content. These models are often trained on numerous datasets, including unauthorized personal identities, artistic creat

Cited by 0SourcePDFScholar
2024

A Huber Loss Minimization Approach to Mean Estimation under User-level Differential Privacy

NeurIPS 2024poster

Privacy protection of users' entire contribution of samples is important in distributed systems. The most effective approach is the two-stage scheme, which finds a small interval first and then gets a refined estimate by clipping samples into the interval. However, the clipping operation induces bia…

Cited by 7SourcePDFScholar
2024

AdaFL: Adaptive Client Selection and Dynamic Contribution Evaluation for Efficient Federated Learning

ICASSP 2024accepted

Federated learning is a collaborative machine learning framework where multiple clients jointly train a global model. To mitigate communication overhead, it is common to select a subset of clients for participation in each training round. However, existing client selection strategies often rely on a…

Cited by 0SourceScholar
2018

Prima: Probabilistic Ranking with Inter-Item Competition and Multi-Attribute Utility Function

ICASSP 2018accepted

This paper proposes PRIMA: Probabilistic Ranking with Inter-item competition and Multi-Attribute utility function, which ranks items based on their probabilities of being a user's best choice. This framework is particularly important in E-commerce applications for making recommendations, predicting…

Cited by 0SourceScholar