← Search

Yixiao Xu

6 accepted papers

2026

AT-Field: Rethinking the Games in Adversarial Training

AAAI 2026technical

Adversarial training is often modeled as a two-player zero-sum game, relying on strong assumptions that limit its practical guidance. In this paper, we instead analyze the interactions between training samples and show that even the fundamental objective—minimizing training loss—may not converge. To

Cited by 0SourcePDFScholar
2026

LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation

AAAI 2026technical

As large language models (LLMs) scale, their inference incurs substantial computational resources, exposing them to energy-latency attacks, where crafted prompts induce high energy and latency cost. Existing attack methods aim to prolong output by delaying the generation of termination symbols. Howe

Cited by 0SourcePDFScholar
2026

Neural Honeytrace: Plug&Play Watermarking Framework against Model Extraction Attacks

ICML 2026poster

Triggerable watermarking enables model owners to assert ownership against model extraction attacks. However, most existing approaches require additional training, which limits post-deployment flexibility, and the lack of clear theoretical foundations makes them vulnerable to adaptive attacks. In thi…

Cited by 0SourceScholar
2024

LT-Defense: Searching-free Backdoor Defense via Exploiting the Long-tailed Effect

NeurIPS 2024poster

Language models have shown vulnerability against backdoor attacks, threatening the security of services based on them. To mitigate the threat, existing solutions attempted to search for backdoor triggers, which can be time-consuming when handling a large search space. Looking into the attack process…

Cited by 1SourcePDFScholar
2022

Sparse Adversarial Attack For Video Via Gradient-Based Keyframe Selection

ICASSP 2022accepted

Videos have a higher dimensionality compared with images, making adversarial video attacks more challenging. We propose a gradient-based method for self-adaptive white-box video keyframe selection and video adversarial example generation, taking advantage of that perturbations are transferable betwe…

Cited by 0SourceScholar