Arrow Research search

Author name cluster

Yihan Wu

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

19 papers
2 author rows

Possible papers

19

ICLR Conference 2025 Conference Paper

A Watermark for Order-Agnostic Language Models

  • Ruibo Chen
  • Yihan Wu
  • Yanshuo Chen
  • Chenxi Liu
  • Junfeng Guo
  • Heng Huang 0001

Statistical watermarking techniques are well-established for sequentially decoded language models (LMs). However, these techniques cannot be directly applied to order-agnostic LMs, as the tokens in order-agnostic LMs are not generated sequentially. In this work, we introduce PATTERN-MARK, a pattern-based watermarking framework specifically designed for order-agnostic LMs. We develop a Markov-chain-based watermark generator that produces watermark key sequences with high-frequency key patterns. Correspondingly, we propose a statistical pattern-based detection algorithm that recovers the key sequence during detection and conducts statistical tests based on the count of high-frequency patterns. Our extensive evaluations on order-agnostic LMs, such as ProteinMPNN and CMLM, demonstrate PATTERN-MARK’s enhanced detection efficiency, generation quality, and robustness, positioning it as a superior watermarking technique for order-agnostic LMs.

YNIMG Journal 2025 Journal Article

Cerebrospinal fluid flow within ventricles and subarachnoid space evaluated by velocity selective spin labeling MRI

  • Yihan Wu
  • Feng Xu
  • Dan Zhu
  • Anna M. Li
  • Kexin Wang
  • Qin Qin
  • Jiadi Xu

This study aims to evaluate cerebrospinal fluid (CSF) flow dynamics within ventricles, and the subarachnoid space (SAS) using the velocity selective spin labeling (VSSL) MRI method with Fourier-transform-based velocity selective inversion preparation. The study included healthy volunteers who underwent MRI scanning with specific VSSL parameters optimized for CSF flow quantification. The VSSL sequence was calibrated against phase-contrast MRI (PC-MRI) to ensure accurate flow velocity measurements. The CSF flow patterns observed in the ventricles were consistent with those obtained using 3D amplified MRI and other advanced MRI techniques, verifying the reliability of the VSSL method. The VSSL method successfully measured CSF flow in the SAS along major arteries, including the middle cerebral artery (MCA), anterior cerebral artery (ACA), and posterior cerebral artery (PCA), with an average flow velocity of 0.339±0.117cm/s. The diffusion component was well suppressed by flow-compensated gradients, enabling comprehensive mapping of the rapid CSF flow pattern in the SAS system and ventricles. The flow pattern in the SAS system closely resembles the recently discovered perivascular subarachnoid space (PVSAS) system. CSF flow around the MCA, PCA, and ACA arteries in the SAS exhibited a weak orientation dependency. CSF flow in the ventricles was also measured, with an average flow velocity of0.309±0.116cm/s, and the highest velocity observed along the superior-inferior direction. This study underscores the potential of VSSL MRI as a non-invasive tool for investigating CSF dynamics in both SAS and ventricles.

ICML Conference 2025 Conference Paper

De-mark: Watermark Removal in Large Language Models

  • Ruibo Chen
  • Yihan Wu
  • Junfeng Guo
  • Heng Huang 0001

Watermarking techniques offer a promising way to identify machine-generated content via embedding covert information into the contents generated from language models (LMs). However, the robustness of the watermarking schemes has not been well explored. In this paper, we present De-mark, an advanced framework designed to remove n-gram-based watermarks effectively. Our method utilizes a novel querying strategy, termed random selection probing, which aids in assessing the strength of the watermark and identifying the red-green list within the n-gram watermark. Experiments on popular LMs, such as Llama3 and ChatGPT, demonstrate the efficiency and effectiveness of De-mark in watermark removal and exploitation tasks.

YNIMG Journal 2025 Journal Article

Elucidating metabolite and pH variations in stroke through guanidino, amine and amide CEST MRI: A comparative multi-field study at 9.4T and 3T

  • Kexin Wang
  • Licheng Ju
  • Guanda Qiao
  • Yajie Liang
  • Yihan Wu
  • Chengyan Chu
  • Joshua Rogers
  • Yuguo Li

This study aims to investigate the variations in guanidino (Guan), amine and amide chemical exchange saturation transfer (CEST) contrasts in ischemic stroke using permanent middle cerebral artery occlusion (pMCAO) and transient MCAO (tMCAO) models at high (9. 4T) and clinical (3T) MRI fields. CEST contrasts were extracted using the Polynomial and Lorentzian Line-shape Fitting (PLOF) method. Both pMCAO and tMCAO models were utilized to examine the B1-dependence patterns and pH sensitivity of the different CEST contrasts in ischemic lesions compared to contralateral region. At 9. 4T, GuanCEST showed the highest signal in the contralateral hemisphere for both stroke models, followed by lower signals from amideCEST and amineCEST, with maximum signals at B1=1. 2 μT for all CEST contrasts. In both stroke models, GuanCEST exhibited a significant decrease of 1. 15–1. 5 % in stroke lesions compared to the contralateral hemisphere (ΔGuanCEST) at an optimal B1 range of 1. 2–1. 6 μT at 9. 4T. This represents more than double the pH sensitivity compared to amideCEST, which showed a reduction of 0. 5–0. 62 % under the same B1 conditions. In the tMCAO model, amineCEST increased by 3. 85 % in the stroke lesion compared to the contralateral hemisphere at an optima B1 range of 1. 6–2. 5 μT. In contrast, for the pMCAO model, amineCEST increased by 0. 87–1. 0 % in the stroke lesion. At lower B1 values (<0. 8 μT at 9. 4T and <0. 4 μT at 3T), the GuanCEST changes in the stroke lesion were dominated by creatine concentration changes, which increased in the pMCAO and remained stable in the tMCAO. While GuanCEST and amineCEST are highly sensitive for delineating stroke lesions, amideCEST is more suitable for precise pH mapping as it is not influenced by metabolite changes within the stroke lesion. Additionally, at low B1 values, amideCEST and GuanCEST can be used to map protein and creatine concentrations separately, since they are independent of pH changes at these lower B1 values. Lastly, amineCEST serves as a highly sensitive MRI contrast for detecting reperfusion damage at high MRI fields.

AAAI Conference 2025 Conference Paper

Enhancing Audiovisual Speech Recognition Through Bifocal Preference Optimization

  • Yihan Wu
  • Yichen Lu
  • Yifan Peng
  • Xihua Wang
  • Ruihua Song
  • Shinji Watanabe

Audiovisual Automatic Speech Recognition (AV-ASR) aims to improve speech recognition accuracy by leveraging visual signals. It is particularly challenging in unconstrained real-world scenarios across various domains due to noisy acoustic environments, spontaneous speech, and the uncertain use of visual information. Most previous works fine-tune audio-only ASR models on audiovisual datasets, optimizing them for conventional ASR objectives. However, they often neglect visual features and common errors in unconstrained video scenarios. In this paper, we propose using a preference optimization strategy to improve speech recognition accuracy for real-world videos. First, we create preference data via simulating common errors that occurred in AV-ASR from two focals: manipulating the audio or vision input and rewriting the output transcript. Second, we propose BPO-AVASR, a Bifocal Preference Optimization method to improve AV-ASR models by leveraging both input-side and output-side preference. Extensive experiments demonstrate that our approach significantly improves speech recognition accuracy across various domains, outperforming previous state-of-the-art models on real-world video speech recognition.

NeurIPS Conference 2025 Conference Paper

Robust Distortion-Free Watermark for Autoregressive Audio Generation Models

  • Yihan Wu
  • Georgios Milis
  • Ruibo Chen
  • Heng Huang

The rapid advancement of next-token-prediction models has led to widespread adoption across modalities, enabling the creation of realistic synthetic media. In the audio domain, while autoregressive speech models have propelled conversational interactions forward, the potential for misuse, such as impersonation in phishing schemes or crafting misleading speech recordings, has also increased. Security measures such as watermarking have thus become essential to ensuring the authenticity of digital media. Traditional statistical watermarking methods used for autoregressive language models face challenges when applied to autoregressive audio models, due to the inevitable ``retokenization mismatch'' - the discrepancy between original and retokenized discrete audio token sequences. To address this, we introduce Aligned-IS, a novel, distortion-free watermark, specifically crafted for audio generation models. This technique utilizes a clustering approach that treats tokens within the same cluster equivalently, effectively countering the retokenization mismatch issue. Our comprehensive testing on prevalent audio generation platforms demonstrates that Aligned-IS not only preserves the quality of generated audio but also significantly improves the watermark detectability compared to the state-of-the-art distortion-free watermarking adaptations, establishing a new benchmark in secure audio technology applications.

ICLR Conference 2025 Conference Paper

Towards Optimal Multi-draft Speculative Decoding

  • Zhengmian Hu
  • Tong Zheng
  • Vignesh Viswanathan
  • Ziyi Chen 0002
  • Ryan A. Rossi
  • Yihan Wu
  • Dinesh Manocha
  • Heng Huang 0001

Large Language Models (LLMs) have become an indispensable part of natural language processing tasks. However, autoregressive sampling has become an efficiency bottleneck. Multi-Draft Speculative Decoding (MDSD) is a recent approach where, when generating each token, a small draft model generates multiple drafts, and the target LLM verifies them in parallel, ensuring that the final output conforms to the target model distribution. The two main design choices in MDSD are the draft sampling method and the verification algorithm. For a fixed draft sampling method, the optimal acceptance rate is a solution to an optimal transport problem, but the complexity of this problem makes it difficult to solve for the optimal acceptance rate and measure the gap between existing verification algorithms and the theoretical upper bound. This paper discusses the dual of the optimal transport problem, providing a way to efficiently compute the optimal acceptance rate. For the first time, we measure the theoretical upper bound of MDSD efficiency for vocabulary sizes in the thousands and quantify the gap between existing verification algorithms and this bound. We also compare different draft sampling methods based on their optimal acceptance rates. Our results show that the draft sampling method strongly influences the optimal acceptance rate, with sampling without replacement outperforming sampling with replacement. Additionally, existing verification algorithms do not reach the theoretical upper bound for both without replacement and with replacement sampling. Our findings suggest that carefully designed draft sampling methods can potentially improve the optimal acceptance rate and enable the development of verification algorithms that closely match the theoretical upper bound.

ICML Conference 2024 Conference Paper

A Resilient and Accessible Distribution-Preserving Watermark for Large Language Models

  • Yihan Wu
  • Zhengmian Hu
  • Junfeng Guo
  • Hongyang Zhang 0001
  • Heng Huang 0001

Watermarking techniques offer a promising way to identify machine-generated content via embedding covert information into the contents generated from language models. A challenge in the domain lies in preserving the distribution of original generated content after watermarking. Our research extends and improves upon existing watermarking framework, placing emphasis on the importance of a Distribution-Preserving (DiP) watermark. Contrary to the current strategies, our proposed DiPmark simultaneously preserves the original token distribution during watermarking (distribution-preserving), is detectable without access to the language model API and prompts (accessible), and is provably robust to moderate changes of tokens (resilient). DiPmark operates by selecting a random set of tokens prior to the generation of a word, then modifying the token distribution through a distribution-preserving reweight function to enhance the probability of these selected tokens during the sampling process. Extensive empirical evaluation on various language models and tasks demonstrates our approach’s distribution-preserving property, accessibility, and resilience, making it a effective solution for watermarking tasks that demand impeccable quality preservation.

YNIMG Journal 2024 Journal Article

Age-dependent functional development pattern in neonatal brain: An fMRI-based brain entropy study

  • Zhiyong Zhao
  • Yifan Shuai
  • Yihan Wu
  • Xinyi Xu
  • Mingyang Li
  • Dan Wu

The relationship between brain entropy (BEN) and early brain development has been established through animal studies. However, it remains unclear whether the BEN can be used to identify age-dependent functional changes in human neonatal brains and the genetic underpinning of the new neuroimaging marker remains to be elucidated. In this study, we analyzed resting-state fMRI data from the Developing Human Connectome Project, including 280 infants who were scanned at 37.5-43.5 weeks postmenstrual age. The BEN maps were calculated for each subject, and a voxel-wise analysis was conducted using a general linear model to examine the effects of age, sex, and preterm birth on BEN. Additionally, we evaluated the correlation between regional BEN and gene expression levels. Our results demonstrated that the BEN in the sensorimotor-auditory and association cortices, along the 'S-A' axis, was significantly positively correlated with postnatal age (PNA), and negatively correlated with gestational age (GA), respectively. Meanwhile, the BEN in the right rolandic operculum correlated significantly with both GA and PNA. Preterm-born infants exhibited increased BEN values in widespread cortical areas, particularly in the visual-motor cortex, when compared to term-born infants. Moreover, we identified five BEN-related genes (DNAJC12, FIG4, STX12, CETN2, and IRF2BP2), which were involved in protein folding, synaptic vesicle transportation and cell division. These findings suggest that the fMRI-based BEN can serve as an indicator of age-dependent brain functional development in human neonates, which may be influenced by specific genes.

ICML Conference 2024 Conference Paper

Defense against Model Extraction Attack by Bayesian Active Watermarking

  • Zhenyi Wang 0001
  • Yihan Wu
  • Heng Huang 0001

Model extraction is to obtain a cloned model that replicates the functionality of a black-box victim model solely through query-based access. Present defense strategies exhibit shortcomings, manifesting as: (1) computational or memory inefficiencies during deployment; or (2) dependence on expensive defensive training methods that mandate the re-training of the victim model; or (3) watermarking-based methods only passively detect model theft without actively preventing model extraction. To address these limitations, we introduce an innovative Bayesian active watermarking technique to fine-tune the victim model and learn the watermark posterior distribution conditioned on input data. The fine-tuning process aims to maximize the log-likelihood on watermarked in-distribution training data for preserving model utility while simultaneously maximizing the change of model’s outputs on watermarked out-of-distribution data, thereby achieving effective defense. During deployment, a watermark is randomly sampled from the estimated watermark posterior. This watermark is then added to the input query, and the victim model returns the prediction based on the watermarked input query to users. This proactive defense approach requires only slight fine-tuning of the victim model without the need of full re-training and demonstrates high efficiency in terms of memory and computation during deployment. Rigorous theoretical analysis and comprehensive experimental results demonstrate the efficacy of our proposed method.

NeurIPS Conference 2024 Conference Paper

Lambda: Learning Matchable Prior For Entity Alignment with Unlabeled Dangling Cases

  • Hang Yin
  • Liyao Xiang
  • Dong Ding
  • Yuheng He
  • Yihan Wu
  • Pengzhi Chu
  • Xinbing Wang
  • Chenghu Zhou

We investigate the entity alignment (EA) problem with unlabeled dangling cases, meaning that partial entities have no counterparts in the other knowledge graph (KG), yet these entities are unlabeled. The problem arises when the source and target graphs are of different scales, and it is much cheaper to label the matchable pairs than the dangling entities. To address this challenge, we propose the framework \textit{Lambda} for dangling detection and entity alignment. Lambda features a GNN-based encoder called KEESA with a spectral contrastive learning loss for EA and a positive-unlabeled learning algorithm called iPULE for dangling detection. Our dangling detection module offers theoretical guarantees of unbiasedness, uniform deviation bounds, and convergence. Experimental results demonstrate that each component contributes to overall performances that are superior to baselines, even when baselines additionally exploit 30\% of dangling entities labeled for training.

AAAI Conference 2024 Conference Paper

Lost Domain Generalization Is a Natural Consequence of Lack of Training Domains

  • Yimu Wang
  • Yihan Wu
  • Hongyang Zhang

We show a hardness result for the number of training domains required to achieve a small population error in the test domain. Although many domain generalization algorithms have been developed under various domain-invariance assumptions, there is significant evidence to indicate that out-of-distribution (o.o.d.) test accuracy of state-of-the-art o.o.d. algorithms is on par with empirical risk minimization and random guess on the domain generalization benchmarks such as DomainBed. In this work, we analyze its cause and attribute the lost domain generalization to the lack of training domains. We show that, in a minimax lower bound fashion, any learning algorithm that outputs a classifier with an ε excess error to the Bayes optimal classifier requires at least poly(1/ε) number of training domains, even though the number of training data sampled from each training domain is large. Experiments on the DomainBed benchmark demonstrate that o.o.d. test accuracy is monotonically increasing as the number of training domains increases. Our result sheds light on the intrinsic hardness of domain generalization and suggests benchmarking o.o.d. algorithms by the datasets with a sufficient number of training domains.

ICLR Conference 2024 Conference Paper

Unbiased Watermark for Large Language Models

  • Zhengmian Hu
  • Lichang Chen
  • Xidong Wu
  • Yihan Wu
  • Hongyang Zhang 0001
  • Heng Huang 0001

The recent advancements in large language models (LLMs) have sparked a growing apprehension regarding the potential misuse. One approach to mitigating this risk is to incorporate watermarking techniques into LLMs, allowing for the tracking and attribution of model outputs. This study examines a crucial aspect of watermarking: how significantly watermarks impact the quality of model-generated outputs. Previous studies have suggested a trade-off between watermark strength and output quality. However, our research demonstrates that it is possible to integrate watermarks without affecting the output probability distribution with appropriate implementation. We refer to this type of watermark as an unbiased watermark. This has significant implications for the use of LLMs, as it becomes impossible for users to discern whether a service provider has incorporated watermarks or not. Furthermore, the presence of watermarks does not compromise the performance of the model in downstream tasks, ensuring that the overall utility of the language model is preserved. Our findings contribute to the ongoing discussion around responsible AI development, suggesting that unbiased watermarks can serve as an effective means of tracking and attributing model outputs without sacrificing output quality.

NeurIPS Conference 2024 Conference Paper

ZeroMark: Towards Dataset Ownership Verification without Disclosing Watermark

  • Junfeng Guo
  • Yiming Li
  • Ruibo Chen
  • Yihan Wu
  • Chenxi Liu
  • Heng Huang

High-quality public datasets significantly prompt the prosperity of deep neural networks (DNNs). Currently, dataset ownership verification (DOV), which consists of dataset watermarking and ownership verification, is the only feasible solution to protect their copyright by preventing unauthorized use. In this paper, we revisit existing DOV methods and find that they all mainly focused on the first stage by designing different types of dataset watermarks and directly exploiting watermarked samples as the verification samples for ownership verification. As such, their success relies on an underlying assumption that verification is a \emph{one-time} and \emph{privacy-preserving} process, which does not necessarily hold in practice. To alleviate this problem, we propose \emph{ZeroMark} to conduct ownership verification without disclosing dataset-specified watermarks. Our method is inspired by our empirical and theoretical findings of the intrinsic property of DNNs trained on the watermarked dataset. Specifically, ZeroMark first generates the closest boundary version of given benign samples and calculates their boundary gradients under the label-only black-box setting. After that, it examines whether the given suspicious method has been trained on the protected dataset by performing a hypothesis test, based on the cosine similarity measured on the boundary gradients and the watermark pattern. Extensive experiments on benchmark datasets verify the effectiveness of our ZeroMark and its resistance to potential adaptive attacks. The codes for reproducing our main experiments are publicly available at \href{https: //github. com/JunfengGo/ZeroMark. git}{GitHub}.

ICML Conference 2023 Conference Paper

A Law of Robustness beyond Isoperimetry

  • Yihan Wu
  • Heng Huang 0001
  • Hongyang Zhang 0001

We study the robust interpolation problem of arbitrary data distributions supported on a bounded space and propose a two-fold law of robustness. Robust interpolation refers to the problem of interpolating $n$ noisy training data points in $R^d$ by a Lipschitz function. Although this problem has been well understood when the samples are drawn from an isoperimetry distribution, much remains unknown concerning its performance under generic or even the worst-case distributions. We prove a Lipschitzness lower bound $\Omega(\sqrt{n/p})$ of the interpolating neural network with $p$ parameters on arbitrary data distributions. With this result, we validate the law of robustness conjecture in prior work by Bubeck, Li and Nagaraj on two-layer neural networks with polynomial weights. We then extend our result to arbitrary interpolating approximators and prove a Lipschitzness lower bound $\Omega(n^{1/d})$ for robust interpolation. Our results demonstrate a two-fold law of robustness: a) we show the potential benefit of overparametrization for smooth data interpolation when $n=poly(d)$, and b) we disprove the potential existence of an $O(1)$-Lipschitz robust interpolating function when $n=\exp(\omega(d))$.

AAAI Conference 2023 Conference Paper

Adversarial Weight Perturbation Improves Generalization in Graph Neural Networks

  • Yihan Wu
  • Aleksandar Bojchevski
  • Heng Huang

A lot of theoretical and empirical evidence shows that the flatter local minima tend to improve generalization. Adversarial Weight Perturbation (AWP) is an emerging technique to efficiently and effectively find such minima. In AMP we minimize the loss w.r.t. a bounded worst-case perturbation of the model parameters thereby favoring local minima with a small loss in a neighborhood around them. The benefits of AWP, and more generally the connections between flatness and generalization, have been extensively studied for i.i.d. data such as images. In this paper, we extensively study this phenomenon for graph data. Along the way, we first derive a generalization bound for non-i.i.d. node classification tasks. Then we identify a vanishing-gradient issue with all existing formulations of AWP and we propose a new Weighted Truncated AWP (WT-AWP) to alleviate this issue. We show that regularizing graph neural networks with WT-AWP consistently improves both natural and robust generalization across many different graph learning tasks and models.

AAAI Conference 2023 Conference Paper

VideoDubber: Machine Translation with Speech-Aware Length Control for Video Dubbing

  • Yihan Wu
  • Junliang Guo
  • Xu Tan
  • Chen Zhang
  • Bohan Li
  • Ruihua Song
  • Lei He
  • Sheng Zhao

Video dubbing aims to translate the original speech in a film or television program into the speech in a target language, which can be achieved with a cascaded system consisting of speech recognition, machine translation and speech synthesis. To ensure the translated speech to be well aligned with the corresponding video, the length/duration of the translated speech should be as close as possible to that of the original speech, which requires strict length control. Previous works usually control the number of words or characters generated by the machine translation model to be similar to the source sentence, without considering the isochronicity of speech as the speech duration of words/characters in different languages varies. In this paper, we propose VideoDubber, a machine translation system tailored for the task of video dubbing, which directly considers the speech duration of each token in translation, to match the length of source and target speech. Specifically, we control the speech length of generated sentence by guiding the prediction of each word with the duration information, including the speech duration of itself as well as how much duration is left for the remaining words. We design experiments on four language directions (German -> English, Spanish -> English, Chinese English), and the results show that VideoDubber achieves better length control ability on the generated speech than baseline methods. To make up the lack of real-world datasets, we also construct a real-world test set collected from films to provide comprehensive evaluations on the video dubbing task.

YNIMG Journal 2022 Journal Article

NeuroGen: Activation optimized image synthesis for discovery neuroscience

  • Zijin Gu
  • Keith Wakefield Jamison
  • Meenakshi Khosla
  • Emily J. Allen
  • Yihan Wu
  • Ghislain St-Yves
  • Thomas Naselaris
  • Kendrick Kay

Functional MRI (fMRI) is a powerful technique that has allowed us to characterize visual cortex responses to stimuli, yet such experiments are by nature constructed based on a priori hypotheses, limited to the set of images presented to the individual while they are in the scanner, are subject to noise in the observed brain responses, and may vary widely across individuals. In this work, we propose a novel computational strategy, which we call NeuroGen, to overcome these limitations and develop a powerful tool for human vision neuroscience discovery. NeuroGen combines an fMRI-trained neural encoding model of human vision with a deep generative network to synthesize images predicted to achieve a target pattern of macro-scale brain activation. We demonstrate that the reduction of noise that the encoding model provides, coupled with the generative network’s ability to produce images of high fidelity, results in a robust discovery architecture for visual neuroscience. By using only a small number of synthetic images created by NeuroGen, we demonstrate that we can detect and amplify differences in regional and individual human brain response patterns to visual stimuli. We then verify that these discoveries are reflected in the several thousand observed image responses measured with fMRI. We further demonstrate that NeuroGen can create synthetic images predicted to achieve regional response patterns not achievable by the best-matching natural images. The NeuroGen framework extends the utility of brain encoding models and opens up a new avenue for exploring, and possibly precisely controlling, the human visual system.

ICML Conference 2022 Conference Paper

RetrievalGuard: Provably Robust 1-Nearest Neighbor Image Retrieval

  • Yihan Wu
  • Hongyang Zhang 0001
  • Heng Huang 0001

Recent research works have shown that image retrieval models are vulnerable to adversarial attacks, where slightly modified test inputs could lead to problematic retrieval results. In this paper, we aim to design a provably robust image retrieval model which keeps the most important evaluation metric Recall@1 invariant to adversarial perturbation. We propose the first 1-nearest neighbor (NN) image retrieval algorithm, RetrievalGuard, which is provably robust against adversarial perturbations within an $\ell_2$ ball of calculable radius. The challenge is to design a provably robust algorithm that takes into consideration the 1-NN search and the high-dimensional nature of the embedding space. Algorithmically, given a base retrieval model and a query sample, we build a smoothed retrieval model by carefully analyzing the 1-NN search procedure in the high-dimensional embedding space. We show that the smoothed retrieval model has bounded Lipschitz constant and thus the retrieval score is invariant to $\ell_2$ adversarial perturbations. Experiments on on image retrieval tasks validate the robustness of our RetrievalGuard method.

v2026.09.13