Arrow Research search

Author name cluster

Xiaolin Sun

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

4 papers
1 author row

Possible papers

4

YNIMG Journal 2026 Journal Article

CT-free attenuation and scatter correction of [11C]CFT brain PET using a Bi-directional matching network

  • Wenxiang Ding
  • Xiaolin Sun
  • Qiaoqiao Ding
  • Xiaoyue Tan
  • Qing Zhang
  • Shanzhen He
  • Peiyong Li
  • Qiu Huang

C]CFT brain PET that achieves diagnostic-comparable dopamine transporter (DAT) quantification while avoiding CT-associated radiation. A Bi-directional Discrete Process Matching (Bi-DPM) network was adapted to establish reversible transformations between non-corrected (NASC-PET) and fully corrected (ASC-PET) images through discrete consistency constraints, eliminating the need for pseudo-CT generation or anatomical priors. Evaluated on 90 Parkinsonian syndrome patients, Bi-DPM demonstrated superior performance to Cycle-Consistent Generative Adversarial Networks (CycleGAN), Pix2Pix, and Rectified Flow (RF) across quantitative metrics (lower MAE, higher PSNR/SSIM). For standardized uptake value mean (SUVmean) measurements, Bi-DPM showed excellent agreement with CT-ASC reference (CCC > 0.98, PCC > 0.98). Voxel-wise analysis of DAT-positive/-negative (DAT+/DAT-) groups confirmed Bi-DPM's clinical validity, with statistical significance maps closely aligned to CT-ASC (Dice = 0.953 vs. 0.938 for RF, 0.948 for Pix2Pix and 0.618 for CycleGAN). This approach reduces unnecessary radiation exposure by omitting CT scans while maintaining PET quantification accuracy.

NeurIPS Conference 2025 Conference Paper

Diffusion Guided Adversarial State Perturbations in Reinforcement Learning

  • Xiaolin Sun
  • Feidi Liu
  • Zhengming Ding
  • Zizhan Zheng

Reinforcement learning (RL) systems, while achieving remarkable success across various domains, are vulnerable to adversarial attacks. This is especially a concern in vision-based environments where minor manipulations of high-dimensional image inputs can easily mislead the agent's behavior. To this end, various defenses have been proposed recently, with state-of-the-art approaches achieving robust performance even under large state perturbations. However, after closer investigation, we found that the effectiveness of the current defenses is due to a fundamental weakness of the existing $l_p$ norm-constrained attacks, which can barely alter the semantics of image input even under a relatively large perturbation budget. In this work, we propose SHIFT, a novel policy-agnostic diffusion-based state perturbation attack to go beyond this limitation. Our attack is able to generate perturbed states that are semantically different from the true states while remaining realistic and history-aligned to avoid detection. Evaluations show that our attack effectively breaks existing defenses, including the most sophisticated ones, significantly outperforming existing attacks while being more perceptually stealthy. The results highlight the vulnerability of RL agents to semantics-aware adversarial perturbations, indicating the importance of developing more robust policies.

AAMAS Conference 2023 Conference Paper

Does Delegating Votes Protect Against Pandering Candidates?

  • Xiaolin Sun
  • Jacob Masur
  • Ben Abramowitz
  • Nicholas Mattei
  • Zizhan Zheng

The election of representatives in regular election cycles ostensibly prevents misbehavior by elected officials and keeps them accountable in service of the “will of the people. " This democratic ideal can be undermined if candidates campaign dishonestly when seeking office over one or more election cycles or ‘rounds’. We introduce a novel formal model of pandering, or strategic preference reporting by electoral candidates, and examine the resilience of two democratic voting systems to such pandering. The two voting systems we compare are Representative Democracy (RD) and Flexible Representative Democracy (FRD). For each voting system, our analysis centers on the types of strategies candidates employ and how voters update their views of candidates across rounds based on how the candidates have pandered in the past. We provide theoretical results on the complexity of pandering for a single round, formulate our problem for multiple rounds as a Markov Decision Process, and use reinforcement learning to study the effects of pandering by sets of candidates across a number of rounds.

NeurIPS Conference 2022 Conference Paper

Learning to Attack Federated Learning: A Model-based Reinforcement Learning Attack Framework

  • Henger Li
  • Xiaolin Sun
  • Zizhan Zheng

We propose a model-based reinforcement learning framework to derive untargeted poisoning attacks against federated learning (FL) systems. Our framework first approximates the distribution of the clients' aggregated data using model updates from the server. The learned distribution is then used to build a simulator of the FL environment, which is utilized to learn an adaptive attack policy through reinforcement learning. Our framework is capable of learning strong attacks automatically even when the server adopts a robust aggregation rule. We further derive an upper bound on the attacker's performance loss due to inaccurate distribution estimation. Experimental results on real-world datasets demonstrate that the proposed attack framework significantly outperforms state-of-the-art poisoning attacks. This indicates the importance of developing adaptive defenses for FL systems.

v2026.09.13