Mojtaba Nafez

I am a first-year Ph.D. student at École Polytechnique Fédérale de Lausanne (EPFL), Switzerland, and a Research Assistant in the Natural Language Understanding (NLU) group at the Idiap Research Institute, under the supervision of Dr. James Henderson.

I received my M.Sc. in Computer Engineering from Sharif University of Technology, where I conducted research in the Robust and Interpretable Machine Learning (RIML) Lab under the supervision of Prof. Mohammad Hossein Rohban, and collaborated closely with Dr. Mohammad Sabokrou.

Previously, I received my B.Sc. in Computer Engineering from Iran University of Science and Technology. In my final year, I worked as a research assistant at CVLab IUST under the supervision of Prof. Mohammad Reza Mohammadi.

Email  /  Google Scholar  /  GitHub  /  LinkedIn

profile photo
EPFL Idiap RIML Lab Sharif University of Technology IUST

Research

My Ph.D. research focuses on diffusion language models, a non-autoregressive alternative to standard LLMs that generates text by iteratively denoising an entire sequence. Before my Ph.D., I worked on the trustworthiness of deep learning models, including adversarial robustness, anomaly and novelty detection, and backdoor attacks and defenses, across computer vision (image and video) and automatic speech recognition, with publications at NeurIPS, ICLR, CVPR, and TMLR.

I am open to collaborations. If you are interested in working together, feel free to reach out at mojtaba.nafez@epfl.ch.

Publications & Preprints
CTR-Reg Know When to Hold 'em: Correct-Token Retention in Uniform-State Diffusion Language Models
Mojtaba Nafez, James Henderson
arXiv preprint, 2026
arXiv

Uniform-state diffusion LMs can revise any token, but they also keep rewriting correct ones, which hurts sample quality and diversity. CTR-Reg is an auxiliary loss that teaches the model to retain unperturbed tokens. It cuts per-step revisions from ~200 to 3–11 positions and more than halves generative perplexity while preserving diversity.

TransferBreaker Breaking Adversarial Transferability in Fine-Tuned Speech Recognition
Mojtaba Nafez*, Aref Mousavi*, Mohammad Ebrahim Mahdavi, Mobina Poulaei, Kiarash Kiani Feriz, Mohammad Hossein Rohban
NeurIPS, 2026
arXive / code

Adversarial attacks crafted on public ASR models transfer almost fully to their privately fine-tuned versions. TransferBreaker suppresses this transfer during fine-tuning, cutting adversarial WER from 92.6 to 27.8 across three languages and four models.

GhostWord GhostWord: A Fine-Grained Backdoor Attack on Automatic Speech Recognition
Mojtaba Nafez*, Mobina Poulaei*, Kiarash Kiani Feriz, Aref Mousavi, Mohammad Ebrahim Mahdavi, Mohammad Hossein Rohban
TMLR, 2026
openreview / code

Unlike prior phrase-level ASR backdoors, GhostWord is a word-level, composable attack. A codebook maps imperceptible audio patterns to target words, each overlaid on a force-aligned spoken word with a matching transcript swap. It reaches 89.3% success and transfers across models and languages. Defenses that suppress it roughly double clean WER.

FrameShield FrameShield: Adversarially Robust Video Anomaly Detection
Mojtaba Nafez, Mobina Poulaei, Nikan Vasei, Bardia Soltani Moakhar, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2025
arXiv / code

Weakly supervised video anomaly detectors are vulnerable to adversarial attacks, and standard defenses fail in this setting. FrameShield generates temporally consistent pseudo-anomalies to enable effective adversarial training. It improves AUROC by 71.0% on average over prior methods.

PatchGuard PatchGuard: Adversarially Robust Anomaly Detection and Localization through Vision Transformers and Pseudo Anomalies
Mojtaba Nafez, Amirhossein Koochakian, Arad Maleki, Mohammad Hossein Rohban
CVPR, 2025
proceedings / code

PatchGuard is an adversarially robust anomaly detection and localization method built on Vision Transformers. It trains with foreground-aware pseudo-anomalies and a novel loss, achieving large robustness gains on industrial and medical datasets.

COBRA Adversarially Robust Anomaly Detection through Spurious Negative Pair Mitigation
Hossein Mirzaei, Mojtaba Nafez, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
ICLR, 2025
openreview / code

Anomaly detectors trained only on normal samples are vulnerable to adversarial attacks. We build a pseudo-anomaly group and apply adversarial training with a contrastive loss, using opposite pairs to mitigate spurious negative pairs and improve robustness.

UNODE Universal Novelty Detection Through Adaptive Contrastive Learning
Hossein Mirzaei, Mojtaba Nafez, Mohammad Jafari, Mohammad Bagher Soltani, Mohammad Azizmalayeri, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
CVPR, 2024
arXiv / code

Novelty detection methods are usually tailored to a dataset's inductive biases and fail to generalize. We propose a universal novelty detector that adapts to diverse datasets through adaptive contrastive learning.

TRODO Scanning Trojaned Models Using Out-of-Distribution Samples
Hossein Mirzaei, Ali Ansari, Bahar Nia, Mojtaba Nafez, Moein Madadi, Sepehr Rezaee, Zeinab Taghavi, Arad Maleki, Kian Shamsaie, Hajialilue, Jafar Habibi, Mohammad Sabokrou, Mohammad Hossein Rohban
NeurIPS, 2024
paper / code

We detect whether a model is trojaned, based on the finding that backdoored models exhibit jagged decision boundaries around out-of-distribution samples, which reduces their robustness there.

Academic Service
  • Conference Reviewer: ICLR 2027, NeurIPS 2026, ECCV 2026
Honors & Awards
  • Academic Ranking: 3rd among 105 students in the B.Sc. program at Iran University of Science and Technology (IUST)

Design and source code from Jon Barron's website.