|
Research
My Ph.D. research focuses on diffusion language models, a non-autoregressive alternative to standard LLMs that generates text by iteratively denoising an entire sequence. Before my Ph.D., I worked on the trustworthiness of deep learning models, including adversarial robustness, anomaly and novelty detection, and backdoor attacks and defenses, across computer vision (image and video) and automatic speech recognition, with publications at NeurIPS, ICLR, CVPR, and TMLR.
I am open to collaborations. If you are interested in working together, feel free to reach out at mojtaba.nafez@epfl.ch.
|
 |
Know When to Hold 'em: Correct-Token Retention in Uniform-State Diffusion Language Models
Mojtaba Nafez, James Henderson
arXiv preprint, 2026
arXiv
Uniform-state diffusion LMs can revise any token, but they also keep rewriting correct ones, which hurts sample quality and diversity. CTR-Reg is an auxiliary loss that teaches the model to retain unperturbed tokens. It cuts per-step revisions from ~200 to 3–11 positions and more than halves generative perplexity while preserving diversity. |
 |
Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
Mojtaba Nafez*, Aref Mousavi*, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban
NeurIPS, 2026
arXive / code
Adversarial attacks crafted on public ASR models transfer almost fully to their privately fine-tuned versions. TransferBreaker suppresses this transfer during fine-tuning, cutting adversarial WER from 92.6 to 27.8 across three languages and four models. |
 |
GhostWord: A Fine-Grained Backdoor Attack on Automatic Speech Recognition
Mojtaba Nafez*, Mobina Poulaei*, Kiarash Kiani Feriz, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mohammad Hossein Rohban
TMLR, 2026
openreview / code
Unlike prior phrase-level ASR backdoors, GhostWord is a word-level, composable attack. A codebook maps imperceptible audio patterns to target words, each overlaid on a force-aligned spoken word with a matching transcript swap. It reaches 89.3% success and transfers across models and languages. Defenses that suppress it roughly double clean WER.
|
 |
FrameShield: Adversarially Robust Video Anomaly Detection
Mojtaba Nafez, Mobina Poulaei, Nikan Vasei, Bardia Soltani Moakhar, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2025
arXiv / code
Weakly supervised video anomaly detectors are vulnerable to adversarial attacks, and standard defenses fail in this setting. FrameShield generates temporally consistent pseudo-anomalies to enable effective adversarial training. It improves AUROC by 71.0% on average over prior methods. |
 |
PatchGuard: Adversarially Robust Anomaly Detection and Localization through Vision Transformers and Pseudo Anomalies
Mojtaba Nafez, Amirhossein Koochakian, Arad Maleki, Mohammad Hossein Rohban
CVPR, 2025
proceedings / code
PatchGuard is an adversarially robust anomaly detection and localization method built on Vision Transformers. It trains with foreground-aware pseudo-anomalies and a novel loss, achieving large robustness gains on industrial and medical datasets.
|
 |
Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation
Hossein Mirzaei, Mojtaba Nafez, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
ICLR, 2025
openreview / code
Anomaly detectors trained only on normal samples are vulnerable to adversarial attacks. We build a pseudo-anomaly group and apply adversarial training with a contrastive loss, using opposite pairs to mitigate spurious negative pairs and improve robustness.
|
 |
Universal Novelty Detection Through Adaptive Contrastive Learning
Hossein Mirzaei, Mojtaba Nafez, Mohammad Jafari, Mohammad Bagher Soltani, Mohammad Azizmalayeri, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
CVPR, 2024
arXiv / code
Novelty detection methods are usually tailored to a dataset's inductive biases and fail to generalize. We propose a universal novelty detector that adapts to diverse datasets through adaptive contrastive learning.
|
 |
Scanning Trojaned Models Using Out-of-Distribution Samples
Hossein Mirzaei, Ali Ansari, Bahar Nia, Mojtaba Nafez, Moein Madadi, Sepehr Rezaee, Zeinab Taghavi, Arad Maleki, Kian Shamsaie, Hajialilue, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2024
paper / code
We detect whether a model is trojaned, based on the finding that backdoored models exhibit jagged decision boundaries around out-of-distribution samples, which reduces their robustness there.
|
Academic Service
- Conference Reviewer: ICLR 2027, NeurIPS 2026, ECCV 2026
|
Honors & Awards
- Academic Ranking: 3rd among 105 students in the B.Sc. program at Iran University of Science and Technology (IUST)
|
|