Welcome to My Homepage

Biography

I am currently an Associate Professor at Sun Yat-Sen University. Before that, I was a Postdoctoral Fellow, working with Prof. XiaoFeng Wang and Prof. Haixu Tang. I received my Ph.D. degree with honors in Information Engineering from the Chinese University of Hong Kong, advised by Prof. Kehuan Zhang and Prof. Dahua Lin.

My research focuses on AI Security, Trustworthy ML, and Responsible AI. I study how AI systems fail under adversarial conditions and develop methods to uncover hidden threats and provide dependable security guarantees, with a growing interest in large generative models and AI agents.

Research at a Glance

Direction 01:

Active Causal Verification

Build trust through active challenges,
causal responses, and controlled interventions.

Face Flashing

Representative WorkNDSS 2018

How can a phone distinguish a live face from a replayed image?

01 / Hold up the phone
Screen → face → front camera
02 / Same light, different surfaces
Living skinCurved + scatteringPrinted photoFlat + printed pigmentDisplay replayFlat glare + emitted image
03 / Verify the physical response
Fresh screen challengeCaptured responseTiming + spatial reflectanceLive-face consistencyPhoto / replay → reject
Fresh challenge → reflected response → liveness decision

Application illustration; qualitative optics and timing sketches. No measured material signatures. Paper ↗

CORE INSIGHT Challenge the physical surface, then verify its spatial and temporal response.Based on the original paper

Selective Amnesia SEAM

Latest ResearchIEEE S&P 2023

How do you remove an unknown backdoor without first finding its trigger?

01 / Two active behaviors
7Normal3Hidden targetFeaturesBoth rules active73
02 / Brief, conflicting supervision
2 → 9 → 4…New wrong labels each epochFeaturesBoth rules disrupted??
03 / Recover from clean examples
7Small clean set · correct labelsFeaturesNormal rule rebuilt7×
Normal accuracy 93.09% → 92.07% · Attack success 100% → 2.10%

Schematic paths and digit probes. Measured: CIFAR-10 / ResNet18 / Reflection · Table I. Paper ↗

CORE INSIGHT Output associations can be disrupted while useful features remain available for recovery.Based on the original paper
Direction 02:

Structural Security Diagnosis

Uncover hidden threats through
representation and behavioral structure.

SCAn

Representative WorkUSENIX Security 2021

What reveals poisoned inputs when ordinary outlier detection cannot separate them?

01 / One assigned class
Samples all labeled “A”Clean reference setEstimate shared within-class variation
02 / Test competing explanations
H₀ : one identityH₁ : two identitiesShared variation in both hypotheses
03 / Detect class contamination
Likelihood-ratio testThresholdOne identityTwo identitiesFlag class AGroup 1Group 2Class-level contamination evidence
Core: shared variation + one-vs-two-identity likelihood test

Conceptual distributions and test score; subgroup colors do not imply visible separation in raw inputs. Paper ↗

CORE INSIGHT Untangle two subgroups, then test the two-identity explanation against a single identity.Based on the original paper

PRISM VLM-Driven Backdoor Defense

Latest ResearchICML 2026

How can you audit a model when its own parameters may already be compromised?

01 / Independent external evidence
Task model“airplane”External VLMImage + class namesSame input · both models stay frozen
02 / Adapt evidence to the task
carairplaneFalse label◇ Text anchors ● Online prototypes
03 / Audit the claimed class
External support for “airplane”Inputusual rangePer-class thresholdReject “airplane”Use teacher: “car”Accepted only → update references
Core: frozen external semantics + online references + per-class boundary

Illustrative attack case, not live inference. Accepted inputs alone update prototypes and class statistics. Paper ↗

CORE INSIGHT Independent semantics exposes unsupported claims; class-wise calibration tolerates ordinary disagreement.Based on the original paper
Direction 03:

Adversarial Threat Discovery

Expose defense blind spots by expanding
what an adversary can manipulate.

Gradient Shaping GRASP

Representative WorkNDSS 2024

Does an effective backdoor necessarily leave a trigger that defenders can recover?

01 / Construct training inputs
airplaneOriginal triggercarNoise only inside the trigger
02 / Shape the input response
Target response around the triggerOriginal triggerNarrow region · steep local changeDashed: ordinary Solid: shaped
03 / Trigger works; inversion struggles
Illustrative inversion searchSearch misses the narrow optimumOriginal trigger→ airplane
Core: nearby inputs + opposing labels → a narrow trigger region

Qualitative response and search trajectory; inversion failure is not universal. TABOR AUC: 0.840 → 0.561 (Table III). Paper ↗

CORE INSIGHT Shape the input gradient so the original trigger works but reverse search can miss it.Based on the original paper

Generative Clean-Image Backdoors GCB

Latest ResearchAAAI 2026 · Oral

Can unchanged training images still teach a hidden, malicious association?

01 / Learn a matched G and Q
Conditional InfoGANGQ0011Recover c → learn a shared visual cue
02 / Pixels stay; labels change
Same training images · only relabel33 → 099 → 0Q selectsShared cue across classes → target 0
03 / Activate the same learned cue
GNew inputc = 1Same cueLearned cue → target3 → 0Training-image pixels edited: 0
Core: Q selects natural examples; G creates the matching cue at test time

Conceptual labels and regions. Test digit images: original Fig. 15. Stroke weight is learned, not a preset filter. Paper ↗

CORE INSIGHT Jointly learn which untouched images to relabel and how to trigger the same learned rule on new inputs.Based on the original paper

Selected Honors

ACM CCS 2022Best Paper Honorable Mention
NEURIPS 2022 · TROJAN DETECTION CHALLENGE1st PlaceFinal Round & Evasive Trojans
LOOKING AHEAD · RESEARCH AGENDA

From individual models
to collaborating AI agents.

How can we verify trust when agents share information, use tools, and act together? I am interested in causal verification, structural auditing, and adversarial evaluation of multi-agent systems.

Explore a collaboration ↗

Latest News

I am publishing a daily AI paper digest: Paper News ↗

I joined Sun Yat-Sen University as an Associate Professor.

Students & PostDoc

Intellectual CuriosityCollaborationReal-world Impact

I welcome motivated students and postdoctoral researchers with a passion for AI security. I value curiosity, enthusiasm for challenging questions, and the drive to pursue excellent research. I believe that working together helps us develop new ideas and turn them into results that matter beyond academia. If you share these values, I would love to explore how we can advance trustworthy and responsible AI together.

tangd9@mail.sysu.edu.cn ↗