Dr. Yushun Dong’s RAI Lab Has Three Papers Accepted at NeurIPS 2026
Department of Computer Science
Dr. Yushun Dong’s research team (RAI Lab) in the Department of Computer Science has had three papers accepted at the Fortieth Annual Conference on Neural Information Processing Systems (NeurIPS 2026), including two papers in the Main Track and one paper in the Evaluations and Datasets Track. The accepted work spans efficient routing for multimodal large language models, adaptive spatial-temporal forecasting, and the security and intellectual-property protection of graph neural networks.
Several of these papers are the result of close collaborations with colleagues at other institutions, reflecting RAI Lab’s commitment to interdisciplinary and collaborative research. RAI Lab continues to provide thoughtful and comprehensive academic guidance to students who are deeply committed to research, helping them publish impactful work at the most competitive venues in machine learning.
LatentRouter: Can We Choose the Right Multimodal Model Before Seeing Its Answer?
This paper is led by Dr. Dong’s Ph.D. student Xueqi Cheng. The work addresses a practical challenge in deploying multimodal large language models (MLLMs): different models excel at different skills, such as OCR, chart understanding, spatial reasoning, and visual question answering, and differ substantially in cost and latency, so always calling the strongest model is often unnecessary or impractical.
The paper formulates MLLM routing as counterfactual multimodal utility prediction and introduces LatentRouter, which extracts learned multimodal routing capsules from each image-question query, represents every candidate MLLM with a model capability token, and performs latent communication between the two to estimate how each model would perform if selected. A distributional outcome head predicts model-specific quality, while a bounded capsule correction refines close decisions. The resulting utility-based policy supports both performance-oriented and performance-cost routing and naturally handles changing candidate pools. Experiments on MMR-Bench and VL-RouterBench show that LatentRouter outperforms fixed-model, feature-level, and learned-router baselines, with the largest gains on tasks where model choice depends on visual, layout-sensitive, or reasoning-oriented requirements.
AdaST: Adaptive Coupling for Spatial-Temporal Forecasting
This paper is led by a Ph.D. student under Dr. Dong’s supervision. The work revisits a common but implicit assumption in spatial-temporal forecasting: that spatial and temporal correlations are always strongly coupled. Through systematic analysis, the paper shows that real-world spatial-temporal data exhibits distinct coupling regimes, ranging from temporal-dominated and spatial-dominated to strongly coupled patterns, and that a mismatch between a model’s architecture and the data’s coupling structure introduces spurious dependencies and degrades accuracy.
To address this, the paper proposes AdaST, an adaptive forecasting framework built on a decompose-recompose paradigm: heterogeneity-aware experts factorize the input into components capturing different coupling patterns, role-aligned modules process each component, and a correlation-informed adaptive recomposer integrates them for the final prediction. Evaluated on traffic-flow (PEMS04, PEMS07, PEMS08) and air-quality (PurpleAir) benchmarks against 16 representative baselines, AdaST achieves state-of-the-art performance across all datasets, underscoring the value of adapting model design to the data’s inherent coupling structure in applications such as transportation, climate, and energy systems.
GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It?
This paper is a collaborative work led by Kaixiang Zhao, an undergraduate research intern under Dr. Dong’s supervision, with Ph.D. students Bolin Shen and Yuyang Dai, Dr. Shayok Chakraborty, and Dr. Yushun Dong. Graph neural networks (GNNs) deployed as cloud services can be stolen through model extraction attacks, in which an adversary trains a surrogate model from query responses to reproduce the target’s behavior. Although a growing number of ownership defenses aim to prevent or trace such theft, inconsistent datasets, threat models, and metrics have made it difficult to compare attacks and defenses fairly.
This work introduces GraphIP-Bench, a unified benchmark that evaluates both sides under a single black-box protocol, integrating twelve extraction attacks, twelve defenses spanning watermarking, output perturbation, and query-pattern detection, ten public graphs, three GNN backbones, and three graph-learning tasks. It further adds a joint attack-and-defense track that measures how much protection a defense retains after extraction. The findings are striking: stealing a GNN is easy at moderate query budgets and most defenses do not change this; several watermarks that verify reliably on the protected model lose most of their signal on the extracted surrogate; and heterophilic graphs are systematically harder to steal. GraphIP-Bench provides the community with a reproducible foundation for developing more robust intellectual-property protection for graph learning models.
Together, these three papers reflect RAI Lab’s broad research agenda in responsible and trustworthy AI, with contributions spanning efficient and cost-aware multimodal AI systems, adaptive learning on spatial-temporal data, and the security and intellectual-property protection of machine learning models.