Mojtaba Nafez

I am a first-year Ph.D. student at École Polytechnique Fédérale de Lausanne (EPFL), Switzerland, and a Research Assistant in the Natural Language Understanding (NLU) group at the Idiap Research Institute, under the supervision of Dr. James Henderson.

I received my M.Sc. in Computer Engineering from Sharif University of Technology, where I conducted research in the Robust and Interpretable Machine Learning (RIML) Lab under the supervision of Prof. Mohammad Hossein Rohban, and collaborated closely with Dr. Mohammad Sabokrou.

Previously, I received my B.Sc. in Computer Engineering from Iran University of Science and Technology. In my final year, I worked as a research assistant at CVLab IUST under the supervision of Prof. Mohammad Reza Mohammadi.

Email  /  Google Scholar  /  GitHub  /  LinkedIn

profile photo
EPFL Idiap RIML Lab Sharif University of Technology IUST

Research

My Ph.D. research focuses on diffusion language models, a non-autoregressive alternative to standard LLMs that generates text by iteratively denoising an entire sequence. Before my Ph.D., I worked on the trustworthiness of deep learning models, including adversarial robustness, anomaly and novelty detection, and backdoor attacks and defenses, across computer vision (image and video) and automatic speech recognition, with publications at NeurIPS, ICLR, CVPR, and TMLR.

I am open to collaborations. If you are interested in working together, feel free to reach out at mojtaba.nafez@epfl.ch.

Publications & Preprints
TransferBreaker Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
Mojtaba Nafez*, Aref Mousavi*, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban
NeurIPS, 2026
paper (coming soon) / code (coming soon) / announcement

Adversarial perturbations crafted on public ASR models transfer to their privately fine-tuned versions with near white-box strength. TransferBreaker suppresses this transfer during fine-tuning, combining base-model adversarial training, latent Jacobian regularization, and hybrid base/target perturbations. Across three languages and four ASR models, it cuts adversarial WER from 92.6 to 27.8.

GhostWord GhostWord: A Fine-Grained Backdoor Attack on Automatic Speech Recognition
Mojtaba Nafez*, Mobina Poulaei*, Kiarash Kiani Feriz, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mohammad Hossein Rohban
TMLR, 2026
openreview / code

Unlike prior phrase-level ASR backdoors, GhostWord is a word-level, composable attack. A codebook maps imperceptible audio patterns to target words, each overlaid on a force-aligned spoken word with a matching transcript swap. It reaches 89.3% success and transfers across models and languages. Defenses that suppress it roughly double clean WER.

FrameShield FrameShield: Adversarially Robust Video Anomaly Detection
Mojtaba Nafez, Mobina Poulaei, Nikan Vasei, Bardia Soltani Moakhar, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2025
arXiv / code

Weakly supervised video anomaly detection models are vulnerable to adversarial attacks, and standard defenses fail under weak supervision. FrameShield uses SRD, a pseudo-anomaly generator that creates temporally consistent synthetic anomalies, to reduce pseudo-label noise and enable effective adversarial training, outperforming prior methods by 71.0% AUROC on average.

PatchGuard PatchGuard: Adversarially Robust Anomaly Detection and Localization through Vision Transformers and Pseudo Anomalies
Mojtaba Nafez, Amirhossein Koochakian, Arad Maleki, Mohammad Hossein Rohban
CVPR, 2025
proceedings / code

PatchGuard is an adversarially robust anomaly detection and localization method built on Vision Transformers. It trains with foreground-aware pseudo-anomalies and a novel loss, achieving large robustness gains on industrial and medical datasets.

COBRA Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation
Hossein Mirzaei, Mojtaba Nafez, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
ICLR, 2025
openreview / code

Anomaly detectors trained only on normal samples are vulnerable to adversarial attacks. We build a pseudo-anomaly group and apply adversarial training with a contrastive loss, using opposite pairs to mitigate spurious negative pairs and improve robustness.

UNODE Universal Novelty Detection Through Adaptive Contrastive Learning
Hossein Mirzaei, Mojtaba Nafez, Mohammad Jafari, Mohammad Bagher Soltani, Mohammad Azizmalayeri, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
CVPR, 2024
arXiv / code

Novelty detection methods are usually tailored to a dataset's inductive biases and fail to generalize. We propose a universal novelty detector that adapts to diverse datasets through adaptive contrastive learning.

TRODO Scanning Trojaned Models Using Out-of-Distribution Samples
Hossein Mirzaei, Ali Ansari, Bahar Nia, Mojtaba Nafez, Moein Madadi, Sepehr Rezaee, Zeinab Taghavi, Arad Maleki, Kian Shamsaie, Hajialilue, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2024
paper / code

We detect whether a model is trojaned, based on the finding that backdoored models exhibit jagged decision boundaries around out-of-distribution samples, which reduces their robustness there.

Academic Service
  • Conference Reviewer: ICLR 2027, NeurIPS 2026, ECCV 2026
Honors & Awards
  • Academic Ranking: 3rd among 105 students in the B.Sc. program at Iran University of Science and Technology (IUST)

Design and source code from Jon Barron's website.