2025 IEEE S&P paper: CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side Channels.
2024 CCS paper: HyperTheft: Thieving Model Weights from TEE-Shielded Neural Networks via Ciphertext Side Channels.
2024 ISSTA paper: See the Forest, not Trees: Unveiling and Escaping the Pitfalls of Error-Triggering Inputs in Neural Network Testing.
2024 TSE paper: Provably Valid and Diverse Mutations of Real-World Media Data for DNN Testing.
2023 USENIX Security paper: Precise and Generalized Robustness Certification for Neural Networks.
2023 USENIX Security paper: CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software.
2023 ICSE paper: Revisiting Neuron Coverage for DNN Testing: A Layer-Wise and Distribution-Aware Criterion.
2022 ASE paper: Unveiling Hidden DNN Defects with Decision-Based Metamorphic Testing.
2022 USENIX Security paper: Automated Side Channel Analysis of Media Software with Manifold Learning.
2021 CVPR paper: Perception Matters: Detecting Perception Failures of VQA Models Using Metamorphic Testing.
2021 ICLR paper: Private Image Reconstruction from System Side Channels Using Generative Models.
Best PhD Dissertation Award 2024, CSE, HKUST.
Distinguished Paper Award, 2025 IEEE S&P.
Background
Research interests include side channel analysis, AI infrastructure security, etc. Currently a postdoctoral researcher at the Advanced Software Technologies (AST) lab, ETH Zurich.
Miscellany
Accounts on Twitter, Github, Google Scholar, ORCID, etc.