Sitemap
A list of all the posts and pages found on the site. For you robots out there is an XML version available for digesting as well.
Pages
Xiaoyu (Nicholas) Wu
Xiaoyu Wu is a PhD student at Carnegie Mellon University working on privacy, trustworthy AI, and generative models.
Posts
Future Blog Post
Published:
This post will show up by default. To disable scheduling of future posts, edit config.yml and set future: false.
Blog Post number 4
Published:
This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.
Blog Post number 3
Published:
This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.
Blog Post number 2
Published:
This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.
Blog Post number 1
Published:
This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.
publications
Mist: Towards Improved Adversarial Examples for Diffusion Models
Published in arXiv preprint, 2023
Mist improves the transferability and robustness of adversarial watermarks designed to protect artwork from unauthorized diffusion-model imitation.
Recommended citation: Liang, C.* and Wu, X.* (2023). "Mist: Towards Improved Adversarial Examples for Diffusion Models." arXiv:2305.12683.
Download Paper
Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial Examples
Published in ICML 2023 (Oral), 2023
AdvDM uses adversarial examples as protective watermarks that prevent diffusion models from learning an artist’s style from unauthorized images.
Recommended citation: Liang, C.*, Wu, X.*, Hua, Y., et al. (2023). "Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial Examples." ICML 2023. Oral presentation.
Download Paper
CGI-DM: Digital Copyright Authentication for Diffusion Models via Contrasting Gradient Inversion
Published in CVPR 2024, 2024
CGI-DM visualizes conceptual differences between pretrained and fine-tuned diffusion models to provide evidence for copyright authentication.
Recommended citation: Wu, X., Hua, Y., Liang, C., et al. (2024). "CGI-DM: Digital Copyright Authentication for Diffusion Models via Contrasting Gradient Inversion." CVPR 2024.
Download Paper
Targeted Attack Improves Protection against Unauthorized Diffusion Customization
Published in ICLR 2025 (Spotlight), 2025
Carefully selected targeted attacks provide stronger protection against unauthorized diffusion customization than untargeted adversarial watermarks.
Recommended citation: Zheng, B., Liang, C., and Wu, X. (2025). "Targeted Attack Improves Protection against Unauthorized Diffusion Customization." ICLR 2025. Spotlight presentation.
Download Paper
Leveraging Model Guidance to Extract Training Data from Personalized Diffusion Models
Published in ICML 2025, 2025
FineXtract uses the distribution shift between pretrained and personalized diffusion models to recover about 20% of fine-tuning data from real-world checkpoints.
Recommended citation: Wu, X., Zhang, J., and Wu, S. (2025). "Leveraging Model Guidance to Extract Training Data from Personalized Diffusion Models." ICML 2025.
Download Paper
Winning the MIDST Challenge: New Membership Inference Attacks on Diffusion Models for Tabular Data Synthesis
Published in TPDP 2025, 2025
A lightweight learned membership inference attack reveals privacy leakage in diffusion-based tabular synthesis and won all four tracks of the MIDST Challenge.
Recommended citation: Wu, X., Pang, Y., Liu, T., and Wu, Z. S. (2025). "Winning the MIDST Challenge: New Membership Inference Attacks on Diffusion Models for Tabular Data Synthesis." TPDP 2025.
Download Paper
Unlearned but Not Forgotten: Data Extraction after Exact Unlearning in LLM
Published in NeurIPS 2025, 2025
Exact unlearning can still leak removed examples when pre- and post-unlearning models are exposed; our guided attack doubles extraction success in some settings.
Recommended citation: Wu, X., Pang, Y., Liu, T., and Wu, Z. S. (2025). "Unlearned but Not Forgotten: Data Extraction after Exact Unlearning in LLM." NeurIPS 2025.
Download Paper
Exploring Diffusion Models’ Corruption Stage in Few-Shot Fine-tuning and Mitigating with Bayesian Neural Networks
Published in KDD 2026, 2026
We identify a corruption stage during few-shot diffusion fine-tuning and use Bayesian neural networks to improve fidelity, quality, and diversity without extra inference cost.
Recommended citation: Wu, X.*, Zhang, J.*, Hua, Y., et al. (2026). "Exploring Diffusion Models' Corruption Stage in Few-Shot Fine-tuning and Mitigating with Bayesian Neural Networks." KDD 2026.
Download Paper
Taming Outlier Tokens in Diffusion Transformers
Published in arXiv preprint, 2026
Dual-Stage Registers reduce harmful outlier tokens in both vision encoders and diffusion transformers, improving generation quality across ImageNet and text-to-image settings.
Recommended citation: Wu, X.*, Wang, Y.*, Fu, T.-J., et al. (2026). "Taming Outlier Tokens in Diffusion Transformers." arXiv:2605.05206.
Download Paper
