Published 'AdvPrompter: Fast Adaptive Adversarial Prompting for LLMs' at ICML 2025 as equal first author.
Two papers at NeurIPS 2025 (Datasets & Benchmarks Track): 'AgentDAM' on privacy leakage evaluation for autonomous web agents, and 'WASP' on benchmarking web agent security against prompt injection attacks.
Contributed to 'Meta SecAlign', a secure foundation LLM against prompt injection attacks (8B and 70B models).
Published 'Landscape Surrogate' at NeurIPS 2023 on learning decision losses for mathematical optimization under partial information.
Published on semi-supervised decision trees at NeurIPS 2022 and on optimized regression forests at ICML 2020, both with advisor Miguel Á. Carreira-Perpiñán.
Longstanding reviewer for top venues: NeurIPS (Best Reviewer), ICLR (Outstanding Reviewer), ICML, JMLR, AISTATS, and AAAI.