Published papers: 'Supply-Chain Attacks in Machine Learning Frameworks' (MLSys 2025); 'SEA: Shareable and Explainable Attribution for Query-based Black-box Attacks' (SaTML 2025); 'On the Limitations of Stochastic Pre-processing Defenses' (NeurIPS 2022); 'Experimental Security Analysis of the App Model in Business Collaboration Platforms' (USENIX Security 2022); 'Rethinking Image-Scaling Attacks: The Interplay Between Vulnerabilities in Machine Learning Systems' (ICML 2022). Recognized as a Top Reviewer (10%) for NeurIPS 2022.
Research Experience
Worked in the Wi-Pi and MadS&P research groups, collaborated with Nicolas Papernot on adversarial machine learning. Delivered talks on ML security at IBM Research (GARD), Google ML Red Team, and RIKEN-AIP.
Education
Ph.D. in Computer Science from the University of Wisconsin–Madison, advised by Kassem Fawaz; Bachelor's degree in Computer Science from Shanghai University.
Background
Research Interests: AI Security and Privacy; Professional Field: Computer Science; Brief Introduction: Currently working as a Research Engineer at Google DeepMind, focusing on AI security and privacy.