|
Research
My Ph.D. research focuses on diffusion language models, a non-autoregressive alternative to standard LLMs that generates text by iteratively denoising an entire sequence. Before my Ph.D., I worked on the trustworthiness of deep learning models, including adversarial robustness, anomaly and novelty detection, and backdoor attacks and defenses, across computer vision (image and video) and automatic speech recognition, with publications at NeurIPS, ICLR, CVPR, and TMLR.
I am open to collaborations. If you are interested in working together, feel free to reach out at mojtaba.nafez@epfl.ch.
|
 |
Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
Mojtaba Nafez*, Aref Mousavi*, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban
NeurIPS, 2026
paper (coming soon) / code (coming soon) / announcement
Adversarial perturbations crafted on public ASR models transfer to their privately fine-tuned versions with near white-box strength. TransferBreaker suppresses this transfer during fine-tuning, combining base-model adversarial training, latent Jacobian regularization, and hybrid base/target perturbations. Across three languages and four ASR models, it cuts adversarial WER from 92.6 to 27.8.
|
 |
GhostWord: A Fine-Grained Backdoor Attack on Automatic Speech Recognition
Mojtaba Nafez*, Mobina Poulaei*, Kiarash Kiani Feriz, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mohammad Hossein Rohban
TMLR, 2026
openreview / code
Unlike prior phrase-level ASR backdoors, GhostWord is a word-level, composable attack. A codebook maps imperceptible audio patterns to target words, each overlaid on a force-aligned spoken word with a matching transcript swap. It reaches 89.3% success and transfers across models and languages. Defenses that suppress it roughly double clean WER.
|
 |
FrameShield: Adversarially Robust Video Anomaly Detection
Mojtaba Nafez, Mobina Poulaei, Nikan Vasei, Bardia Soltani Moakhar, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2025
arXiv / code
Weakly supervised video anomaly detection models are vulnerable to adversarial attacks, and standard defenses fail under weak supervision. FrameShield uses SRD, a pseudo-anomaly generator that creates temporally consistent synthetic anomalies, to reduce pseudo-label noise and enable effective adversarial training, outperforming prior methods by 71.0% AUROC on average.
|
 |
PatchGuard: Adversarially Robust Anomaly Detection and Localization through Vision Transformers and Pseudo Anomalies
Mojtaba Nafez, Amirhossein Koochakian, Arad Maleki, Mohammad Hossein Rohban
CVPR, 2025
proceedings / code
PatchGuard is an adversarially robust anomaly detection and localization method built on Vision Transformers. It trains with foreground-aware pseudo-anomalies and a novel loss, achieving large robustness gains on industrial and medical datasets.
|
 |
Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation
Hossein Mirzaei, Mojtaba Nafez, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
ICLR, 2025
openreview / code
Anomaly detectors trained only on normal samples are vulnerable to adversarial attacks. We build a pseudo-anomaly group and apply adversarial training with a contrastive loss, using opposite pairs to mitigate spurious negative pairs and improve robustness.
|
 |
Universal Novelty Detection Through Adaptive Contrastive Learning
Hossein Mirzaei, Mojtaba Nafez, Mohammad Jafari, Mohammad Bagher Soltani, Mohammad Azizmalayeri, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
CVPR, 2024
arXiv / code
Novelty detection methods are usually tailored to a dataset's inductive biases and fail to generalize. We propose a universal novelty detector that adapts to diverse datasets through adaptive contrastive learning.
|
 |
Scanning Trojaned Models Using Out-of-Distribution Samples
Hossein Mirzaei, Ali Ansari, Bahar Nia, Mojtaba Nafez, Moein Madadi, Sepehr Rezaee, Zeinab Taghavi, Arad Maleki, Kian Shamsaie, Hajialilue, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2024
paper / code
We detect whether a model is trojaned, based on the finding that backdoored models exhibit jagged decision boundaries around out-of-distribution samples, which reduces their robustness there.
|
Academic Service
- Conference Reviewer: ICLR 2027, NeurIPS 2026, ECCV 2026
|
Honors & Awards
- Academic Ranking: 3rd among 105 students in the B.Sc. program at Iran University of Science and Technology (IUST)
|
|