Publications
2026
- The Trap of Trajectory: Towards Understanding and Mitigating Spurious Correlations in Agentic MemoryarXiv preprint arXiv:2605.09330, 2026
- EquiMem: Calibrating Shared Memory in Multi-Agent Debate via Game-Theoretic EquilibriumarXiv preprint arXiv:2605.09278, 2026
- ER-MIA: Black-Box Adversarial Memory Injection Attacks on Long-Term Memory-Augmented Large Language ModelsarXiv preprint arXiv:2602.15344, 2026
- TheraMind: a multi-LLM ensemble for accelerating drug repurposing in lung cancer via case report miningnpj Precision Oncology, 2026
- The value of variance: Mitigating debate collapse in multi-agent systems via uncertainty-driven policy optimizationIn Proceedings of the 43rd International Conference on Machine Learning, 2026
- Small agent group is the future of digital healthIn Proceedings of the 43rd International Conference on Machine Learning, 2026
- Benchmarking LLM-Assisted Blue Teaming via Standardized Threat HuntingIn Proceedings of the 43rd International Conference on Machine Learning, 2026
- On the eligibility of LLMs for counterfactual reasoning: a decompositional studyIn The Fourteenth International Conference on Learning Representations, 2026
2025
- Data to Defense: The Role of Curation in Aligning Large Language Models Against Safety CompromiseIn Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing, 2025
- Are LLMs Ready for English Standardized Tests? A Benchmarking and Elicitation PerspectivearXiv preprint arXiv:2505.17056, 2025
- Uncovering vulnerabilities of llm-assisted cyber threat intelligencearXiv preprint arXiv:2509.23573, 2025
- POLAR: Automating Cyber Threat Prioritization through LLM-Powered AssessmentarXiv preprint arXiv:2510.01552, 2025
2024
- Zodiac: A cardiologist-level llm framework for multi-agent diagnosticsarXiv preprint arXiv:2410.02026, 2024
- On the difficulty of defending contrastive learning against backdoor attacksIn 33rd USENIX Security Symposium (USENIX Security 24), 2024
2023
- Defending pre-trained language models as few-shot learners against backdoor attacksAdvances in Neural Information Processing Systems, 2023
- On the security risks of knowledge graph reasoningIn 32nd USENIX Security Symposium (USENIX Security 23), 2023
- The dark side of automl: Towards architectural backdoor searchIn The 11th International Conference on Learning Representations, 2023
- An embarrassingly simple backdoor attack on self-supervised learningIn Proceedings of the IEEE/CVF International Conference on Computer Vision, 2023
2022
- Trojanzoo: Towards unified, holistic, and practical evaluation of neural backdoorsIn 2022 IEEE 7th European Symposium on Security and Privacy (EuroS&P), 2022
- Seeing is living? rethinking the security of facial liveness verification in the deepfake eraIn 31st USENIX Security Symposium (USENIX Security 22), 2022
- On the security risks of {AutoML}In 31st USENIX Security Symposium (USENIX Security 22), 2022
2021
- Graph backdoorIn 30th USENIX security symposium (USENIX Security 21), 2021