I am currently the CEO and Principal Researcher at SiliconProspect AI (硅基守望), an AI startup I co-founded, dedicated to Understanding AI, Trusting AI, and Embracing AI. Before that, I was a Principal Investigator, Innovation Lead, and Research Scientist at A*STAR Centre for Frontier AI Research (CFAR), working with Prof. Ivor Tsang, and a Research Fellow at Nanyang Technological University, working with Prof. Tianwei Zhang and Prof. Yang Liu. Besides, I worked with Prof. Florian Kerschbaum (from University of Waterloo). I received my Ph.D. degree with honors in School of Cyber Science and Technology from University of Science and Technology of China (USTC) in 2022, advised by Prof. Nenghai Yu, Prof. Weiming Zhang, and Prof. Huamin Feng. I also very luckily collaborated closely with Prof. Qing Guo (at Nankai University), Dr. Dongdong Chen (at Microsoft GenAI) and Prof. Jing Liao (at City University of Hong Kong).
🔬 My Research Interests: How to build Trustworthy AI & Gen-AI (click to expand)
My recent research interest mainly focuses on How to build Trustworthy AI & Gen-AI:
-
Vulnerability Evaluation: [TIP 2022], [AAAI 2023], [MM 2023], [AAAI 2024], [AAAI 2024], [AAAI 2024], [CCS 2024], [NeurIPS 2024], [Information Fusion 2024], [USENIX Security 2025], [NAACL 2025], [USENIX Security 2025], [TMM 2025], [CVPR 2025], [S&P 2025], [CCS 2025], [USENIX Security 2025], [NeurIPS 2025], [Agent4Science 2025], [CIKM 2025], [TIFS 2025], [AAAI 2026], [NDSS 2026], [USENIX Security 2026], [TPAMI 2026], [ACL 2026], [ICML 2026], [ICML 2026], [ICML 2026], [USENIX Security 2026], [CCS 2026], [MM 2026], [EMNLP 2026], [EMNLP 2026], [EMNLP 2026]
-
Proactive Safeguard: [AAAI 2021], [MM 2023], [IJCAI 2024], [ICML 2024], [MM 2024], [NDSS 2025], [AAAI 2025], [ICASSP 2025], [TDSC 2025], [TOSEM 2025], [ICML 2025], [ICML 2025], [CCS 2025]
-
Post-hoc Forensic: [AAAI 2020], [NeurIPS 2020], [MM 2020], [TPAMI 2021], [AAAI 2022], [TAI 2023], [Springer Book], [AAAI 2023], [AAAI 2023], [TKDE 2023], [TPAMI 2024], [NDSS 2024], [ICML 2024], [ECCV 2024], [S&P 2025], [TIFS 2025], [ICLR 2025], [ICME 2025], [ICME 2025], [TDSC 2025], [TPAMI 2025], [NeurIPS 2025], [Information Science 2025]
Others
- Affective Computing: [MM 2024], [CVPR 2025], [MM 2025], [TIFS 2026]
- AI for Science: [AI4X 2025], [AI for Science 2025]
⭐️⭐️ If you are interested in my research topics or have innovative ideas to share, I would love to hear from you! I am always open to external collaborations and exploring new possibilities together! Feel free to email me anytime! 🚀🚀
🔥 News
- - 2026.08: 🏆 Our team KVeil won the 🏅 Champion (1st Place) in both the preliminary and final phases of the LifeGenIP Challenge: Unlearnable Videos against Diffusion-based Customization @ ECCV 2026! Our technical report and paper will be available soon.
- - 2026.08: 🎉🎉 Three papers are accepted to EMNLP 2026 (Main Conference). Congrats to Qingjie Zhang, Yanghao Su, and Yutong Zhang!
- - 2026.08: 🎉🎉 One paper is accepted to TIFS. Congrats to Fengqi Cui!
- - 2026.07: 🎉🎉 One paper is accepted to ECCV 2026. Congrats to Mingxuan Cui!
- - 2026.07: 🎉🎉 One paper is accepted to ACM MM 2026. Congrats to Haoran Ou!
- - 2026.05: 🎉🎉 One paper is accepted to ACM CCS 2026. Congrats to Weitao Feng!
- - 2026.05: 🎉🎉 One paper is accepted to USENIX Security 2026. Congrats to Kunsheng Tang!
- - 2026.05: 🎉🎉 Three papers are accepted to ICML 2026. Congrats to Haoran Ou, Bing Li, and Pengcheng Li!
- - 2026.04: 🎉🎉 One paper is accepted to ACL 2026 (Findings). Congrats to Zhenhong Zhou!
- - 2026.01: 🎉🎉 One paper is accepted to TPAMI. Congrats to Chang Liu!
- - 2026.01: 🎉🎉 One paper is accepted to ICRA 2026. Congrats to Sicheng Li!
- - 2026.01: 🎉🎉 One paper is accepted to USENIX Security 2026. Congrats to Shiqian Zhao!
- - 2026.01: 🎉🎉 Our project on AI-assisted animation copyright and governance is awarded funding by AI Singapore (AI Research – Governance Joint Grant Call), with me serving as PI. Congarts to my team and myself!
- - 2025.12: 🎉🎉 One paper is accepted to Information Science. Congrats to Xiaoshuai Wu!
- - 2025.12: 🎉🎉 One paper is accepted to TIFS. Congrats to Zhaoxuan Wang!
- - 2025.11: 🎉🎉 One paper is accepted to NDSS 2026. Congrats to Shiqian Zhao!
- - 2025.11: 🎉🎉 I’m honored to be invited as a guest lecturer for the NUS ECE postgraduate course CEG5304: Deep Learning for Digitalization Technologies! The lecture video is available.
- - 2025.11: 🎉🎉 One paper is accepted to AAAI 2026. Congrats to Yun Xing!
- - 2025.11: 🎉🎉 One paper is accepted to CIKM 2025. Congrats to Yidan Sun!
- - 2025.10: 🎉🎉 One paper is accepted to Open Conference of AI Agents for Science 2025 as a Spotlight paper. Congrats to my collaborators and myself!
- - 2025.10: 🎉🎉 I’m honored to join the EURASIP Journal on Information Security as an Associate Editor. I warmly welcome your submissions!
- - 2025.09: 🎉🎉 Two papers are accepted to NeurIPS 2025. Congrats to Runyi Hu and Yun Xing!
- - 2025.08: 🎉🎉 One paper is accepted to TPAMI. Congrats to Zhongyi Zhang!
- - 2025.08: 🎉🎉 One paper is accepted to AI for Science. Congrats to Jiyan He!
- - 2025.07: 🎉🎉 One paper is accepted to ACM MM 2025. Congrats to Fengqi Cui!
- - 2025.07: 🎉🎉 One paper is accepted to AI4X 2025 international conference. Congrats to Haoxiang Guan!
- - 2025.06: 🎉🎉 Our Watermark Updating Framework has been selected as Candidates of best paper (one of the Top 15 Papers) in ICME 2025. Congrats to Yanyan Liu!
- - 2025.06: 🎉🎉 One paper is accepted to TDSC. Congrats to Xi Yang!
- - 2025.06: 🎉🎉 One paper is accepted to USENIX Security 2025. Congrats to Xiang Zhang!
- - 2025.05: 🎉🎉 Two papers are accepted to ACM CCS 2025. Congrats to Peigui Qi and Gelei Deng!
- - 2025.05: 🎉🎉 Two papers are accepted to ICML 2025. Congrats to Yutong Wu and Daiheng Gao!
- - 2025.04: 🎉🎉 I am excited to serve as the Organizer of the 4th Workshop on Practical Deep Learning (Practical-DL 2025)! We warmly welcome your paper submissions, looking forward to your contributions!
- - 2025.04: 🎉🎉 I'm excited to visit MBZUAI as a Visiting Researcher, hosted by Prof. Nils Lukas. Looking forward to the collaboration and new insights!
- - 2025.03: 🎉🎉 I'm excited to give a talk at the IMDA Technical Sharing Session on Multimodal Safety.
- - 2025.03: 🎉🎉 Two papers are accepted to ICME 2025. Congrats to Zhe Lei and Yanyan Liu!
- - 2025.03: 🎉🎉 One paper is accepted to TOSEM. Congrats to Xiaoyu Zhang!
- - 2025.03: 🎉🎉 One paper is accepted to S&P 2025. Congrats to Xiang Zhang!
- - 2025.03: 🎉🎉 One paper is accepted to TDSC. Congrats to Meng Tong!
- - 2025.02: 🎉🎉 I am appointed as the Innovation Lead at CFAR, A*STAR. Congrats to myself, Fighting!
- - 2025.02: 🎉🎉 Two papers are accepted to CVPR 2025. Congrats to Yue Cao and Xuecheng Wu!
- - 2025.02: 🎉🎉 One paper is accepted to TMM. Congrats to Shuai Li!
- - 2025.01: 🎉🎉 One paper is accepted to ICLR 2025. Congrats to Runyi Hu!
- - 2025.01: 🎉🎉 One paper is accepted to USENIX Security 2025. Congrats to Haolin Wu!
- - 2025.01: 🎉🎉 One paper is accepted to TIFS. Congrats to Shuai Li!
- - 2025.01: 🎉🎉 One paper is accepted to NAACL 2025 (Oral). Congrats to Meng Tong!
- - 2024.12: 🎉🎉 One paper is accepted to ICASSP 2025. Congrats to Zhiling Zhang!
- - 2024.12: 🎉🎉 One paper is accepted to AAAI 2025 (Oral). Congrats to Haoxiang Tian!
- - 2024.11: 🎉🎉 One paper is accepted to Information Fusion 2024. Congrats to Linqing Hu!
- - 2024.10: 🎉🎉 GenderCARE is awarded the Distinguished Artifact Award in CCS 2024. Congrats!
- - 2024.09: 🎉🎉 One paper is accepted to NeurIPS 2024. Congrats to Guanlin Li!
- - 2024.09: 🎉🎉 One paper is accepted to USENIX Security 2025. Congrats to Junqi Zhang!
- - 2024.09: 🎉🎉 One paper is accepted to S&P 2025. Congrats to Boheng Li!
- - 2024.08: 🎉🎉 I join the CFAR, A*STAR as a research scientist. Thanks a lot to Prof. Tianwei Zhang for the support at NTU!
- - 2024.07: 🎉🎉 One paper is accepted to NDSS 2025. Congrats to Yutong Wu!
- - 2024.07: 🎉🎉 Two papers are accepted to ACM MM 2024 (One Oral). Congrats to Yanghao Su and Ruiqi Wang!
- - 2024.07: 🎉🎉 One paper is accepted to ECCV 2024. Congrats to Runyi Hu!
- - 2024.05: 🎉🎉 Two papers are accepted to ICML 2024. Congrats to Kui Zhang and Weitao Feng!
- - 2024.04: 🎉🎉 One paper is accepted to IJCAI 2024. Congrats to Hanlin Gu!
- - 2024.04: 🎉🎉 One paper is accepted to ACM CCS 2024. Congrats to Kunsheng Tang!
- - 2024.03: 🎉🎉 One paper is accepted to TPAMI. Congrats to myself, Fighting!
- - 2023.12: 🎉🎉 Three papers are accepted to AAAI 2024. Congrats to Yi Xie, Yihao Huang, and Xiaojian Yuan!
- - 2023.12: 🎉🎉 One paper is accepted to ICASSP 2024. Congrats to Prof. Wenbo Zhou!
- - 2023.11: 🎉🎉 One paper is accepted to NDSS 2024. Congrats to Chang Liu!
📝 Selected Preprints
- A comprehensive survey in llm (-agent) full stack safety: Data, training and deployment
- Reinforcement learning enhanced llms: A survey
📝 Publications
-
Yutong Zhang, Jianshuo Dong, Peng Xu, Long Wang, Jie Zhang, Tianwei Zhang, Xiaoping Zhang, Han Qiu, INTENT-AS-A-TOOL Makes it Easy to Track Agentic Misalignment, Conference on Empirical Methods in Natural Language Processing (EMNLP), 2026
-
Yanghao Su, Wenbo Zhou, Tianwei Zhang, Han Qiu, Nenghai Yu, Weiming Zhang, Jie Zhang, The Persona-Switch Backdoor: From Payload Retrieval to Trigger-Gated Persona-State Selection, Conference on Empirical Methods in Natural Language Processing (EMNLP), 2026
-
Qingjie Zhang, Ziqi Tang, Jie Zhang, Gelei Deng, Jinfeng Li, YueFeng Chen, Yitong Yang, Hui Xue, Tianwei Zhang, Han Qiu, Auditing Chinese Web-scale Corpora via Sampled BPE Token Statistics, Conference on Empirical Methods in Natural Language Processing (EMNLP), 2026
-
Haoran Ou, Gelei Deng, Xingshuo Han, Jie Zhang, Han Qiu, Shangwei Guo, Tianwei Zhang, Kwok-Yan Lam, Beyond Retrieval: Improving Evidence Quality for LLM-based Multimodal Fact-Checking, ACM International Conference on Multimedia (MM), 2026
-
Mingxuan Cui, Yunrui Zhu, Wuqi Wang, Di Lin, Jianhua Zhang, Jie Zhang, Ming-Ming Cheng, Shengyong Chen, Qing Guo, GlassGS: Geometry and Concept-Aware 3D Gaussian Splatting for Reflective Enclosures, European Conference on Computer Vision (ECCV), 2026
-
Feng-Qi Cui, Anyang Tong, Jinyang Huang, Jie Zhang, Meng Li, Xin Yan, Linsheng Huang, Dan Guo, Meng Wang, Towards Trustworthy Dynamic Facial Expression Recognition via Information Bottleneck Modeling, IEEE Transactions on Information Forensics and Security (TIFS), 2026
-
Weitao Feng, Lixu Wang, Peizhuo Lv, Tianyi Wei, Jie Zhang, Chongyang Gao, Sinong Simon Zhan, Wei Dong, Token Buncher: Shielding LLMs from Harmful Reinforcement Learning Fine-Tuning, ACM Conference on Computer and Communications Security (CCS), 2026
-
Kunsheng Tang, Peigui Qi, Yide Song, Wenbo Zhou, Zhicong Huang, Qing Guo, Tianwei Zhang, Weiming Zhang, Nenghai Yu, Jie Zhang [Corresponding Author], One Bad Token Spoils the Barrel: Assessment, Detection, and Remediation of Glitch Tokens in Large Language Models, USENIX Security Symposium, 2026
-
Haoran Ou, Kangjie Chen, Xingshuo Han, Gelei Deng, Jie Zhang, Han Qiu, Tianwei Zhang, Kwok-Yan Lam, When Search Goes Wrong: Red-Teaming Web-Augmented Large Language Models, International Conference on Machine Learning (ICML), 2026
-
Bing Li, Wuqi Wang, Yanan Zhang, Jingzheng Li, Haigen Min, Wei Feng, Xingyu Zhao, Jie Zhang, Qing Guo, OBJVanish: Prompt-Driven Generation of Physically Realisable 3D LiDAR-Invisible Objects, International Conference on Machine Learning (ICML), 2026
-
Pengcheng Li, Jie Zhang, Tianwei Zhang, Han Qiu, Kejun Zhang, Weiming Zhang, Nenghai Yu, Wenbo Zhou, State-Dependent Safety Failures in Multi-Turn Language Model Interaction, International Conference on Machine Learning (ICML), 2026
-
Zhenhong Zhou, Zherui Li, Jie Zhang, Yuanhe Zhang, Kun Wang, Yang Liu, Qing Guo, CORBA: Contagious Recursive Blocking Attacks on Multi-Agent Systems Based on Large Language Models, Findings of Annual Meeting of the Association for Computational Linguistics (ACL), 2026
-
Sicheng Li, Zaiwang Gu, Jie Zhang, Qing Guo, Xudong Jiang, Jun Cheng, SURE: Semi-dense Uncertainty-REfined Feature Matching, IEEE International Conference on Robotics and Automation (ICRA), 2026
-
Chang Liu, Haolin Wu, Xi Yang, Kui Zhang, Cong Wu, Weiming Zhang, Nenghai Yu, Tianwei Zhang, Qing Guo, Jie Zhang [Corresponding Author], Exploring Security Vulnerabilities in Multilingual Speech Translation Systems via Deceptive Inputs, IEEE Transactions on Pattern Analysis and Machine Intelligence (TPAMI), 2026 [Paper] [Project Page]
-
Shiqian Zhao, Jiayang Liu, Yiming Li, Runyi Hu, Xiaojun Jia, Wenshu Fan, Xinfeng Li, Jie Zhang, Wei Dong, Tianwei Zhang, Luu Anh Tuan, When Memory Becomes a Vulnerability: Towards Multi-turn Jailbreak Attacks against Text-to-Image Generation Systems, USENIX Security Symposium, 2026 [Paper]
-
Shiqian Zhao, Chong Wang, Yiming Li, Yihao Huang, Wenjie Qu, Siew-Kei Lam, Yi Xie, Kangjie Chen, Jie Zhang [Corresponding Author], Tianwei Zhang, Towards Effective Prompt Stealing Attack against Text-to-Image Diffusion Models, Network and Distributed System Security Symposium (NDSS), 2026 [Paper]
-
Yun Xing, Nhat Chung, Jie Zhang, Yue Cao, Ivor Tsang, Yang Liu, Lei Ma, Qing Guo, MAGIC: Mastering Physical Adversarial Generation in Context through Collaborative LLM Agents, AAAI Conference on Artificial Intelligence (AAAI), 2026 [Paper]
-
Xiaoshuai Wu, Xin Liao, Jie Zhang, Mingyue Chen, Yufeng Wu, Jinlin Guo, Versatile and harmless deepfake proactive forensics via conditional watermarking, Information Science, 2025 [Paper]
-
Zhaoxuan Wang, Yang Li, Jie Zhang, Xingshuo Han, Kangbo Liu, Yang Lyu, Yuan Zhou, Tianwei Zhang, Quan Pan, SSD: A State-based Stealthy Backdoor Attack For IMU/GNSS Navigation System in UAV Route Planning, IEEE Transactions on Information Forensics and Security (TIFS), 2025 [Paper]
-
Yidan Sun, Viktor Schlegel, Srinivasan Nandakumar, Iqra Zahid, Yuping Wu, Warren Del-Pinto, Goran Nenadic, Siew-Kei Lam, Jie Zhang, Anil A Bharath, Evaluating Differentially Private Generation of Domain-Specific Text, ACM International Conference on Information and Knowledge Management (CIKM), 2025 [Paper]
-
AI, Jie Zhang, Ting Xu, Gelei Deng, Runyi Hu, Han Qiu, Tianwei Zhang, Qing Guo, Ivor Tsang, Visible Yet Unreadable: A Systematic Blind Spot of Vision–Language Models Across Writing Systems, Open Conference of AI Agents for Science (Agent4Science), Spotlight, 2025 [Paper] [Code] [Video]
-
Runyi Hu, Jie Zhang [Corresponding Author], Shiqian Zhao, Nils Lukas, Jiwei Li, Qing Guo, Han Qiu, Tianwei Zhang, Mask Image Watermarking, Neural Information Processing Systems (NeurIPS), 2025 [Paper] [Code]
-
Yun Xing, Yue Cao, Nhat Chung, Jie Zhang, Ivor Tsang, Ming-Ming Cheng, Yang Liu, Lei Ma, Qing Guo, DepthVanish: Optimizing Adversarial Interval Structures for Stereo-Depth-Invisible Patches, Neural Information Processing Systems (NeurIPS), 2025 [Paper]
-
Zhongyi Zhang, Jie Zhang, Wenbo Zhou, Xinghui Zhou, Qing Guo, Weiming Zhang, Tianwei Zhang, Nenghai Yu, FaceTracer: Unveiling Source Identities from Swapped Face Images and Videos for Fraud Prevention, IEEE Transactions on Pattern Analysis and Machine Intelligence (TPAMI), 2025 [Paper]
-
Jiyan He, Weitao Feng, Yaosen Min, Jingwei Yi, Kunsheng Tang, Shuai Li, Jie Zhang, Kejiang Chen, Wenbo Zhou, Xing Xie, Weiming Zhang, Nenghai Yu, Shuxin Zheng, Controlling Risks of AI in Chemical Science with Agents, AI for Science, 2025 [Paper]
-
Feng-Qi Cui, Anyang Tong, Jinyang Huang, Jie Zhang, Dan Guo, Zhi Liu, Meng Wang, Learning from Heterogeneity: Generalizing Dynamic Facial Expression Recognition via Distributionally Robust Optimization, ACM International Conference on Multimedia (MM), 2025 [Paper]
-
Haoxiang Guan, Jiyan He, Jie Zhang, Sparse Autoencoders Reveal Interpretable Structure in Small Gene Language Models, AI4X, 2025 [Paper]
-
Xi Yang, Jie Zhang [Corresponding Author], Chang Liu, Han Fang, Zehua Ma, Kejiang Chen, Weiming Zhang, Nenghai Yu, Synthesizing Glyph Vectors for Practical Information Hiding in Documents, IEEE Transactions on Dependable and Secure Computing (TDSC), 2025 [Paper] [Demo]
-
Xiang Zhang, Jie Zhang, Huan Yan, Jinyang Huang, Zehua Ma, Bin Liu, Meng Li, Kejiang Chen, Qing Guo, Tianwei Zhang, Zhi Liu, DiffLoc: WiFi Hidden Camera Localization Based on Electromagnetic Diffraction, USENIX Security Symposium, 2025 [Paper] [Code]
-
Peigui Qi, Kunsheng Tang, Wenbo Zhou, Weiming Zhang, Nenghai Yu, Tianwei Zhang, Qing Guo, Jie Zhang [Corresponding Author], SafeGuider: Robust and Practical Content Safety Control for Text-to-Image Models, ACM Conference on Computer and Communications Security (CCS), 2025 [Paper] [Project Page]
-
Gelei Deng, Haoran Ou, Yi Liu, Jie Zhang, Tianwei Zhang, Yang Liu, Oedipus: LLM-enchanced Reasoning CAPTCHA Solver, ACM Conference on Computer and Communications Security (CCS), 2025 [Paper]
-
Yutong Wu, Jie Zhang [Corresponding Author], Yiming Li, Chao Zhang, Qing Guo, Han Qiu, Nils Lukas, Tianwei Zhang, Cowpox: Towards the Immunity of VLM-based Multi-Agent Systems, International Conference on Machine Learning (ICML), 2025 [Paper]
-
Daiheng Gao, Shilin Lu, Shaw Walters, Wenbo Zhou, Jiaming Chu, Jie Zhang, Bang Zhang, Mengxi Jia, Jian Zhao, Zhaoxin Fan, Weiming Zhang, EraseAnything: Enabling Concept Erasure in Rectified Flow Transformers, International Conference on Machine Learning (ICML), 2025 [Paper] [Project Page]
-
Zhe Lei, Jie Zhang [Corresponding Author], Jingtao Li, Weiming Zhang, Nenghai Yu, Aparecium: Revealing Secrets from Physical Photographs, IEEE International Conference on Multimedia & Expo (ICME), 2025 [Paper] [Demo]
-
Yanyan Liu, Bin Liu, Jie Zhang, Xiang Zhang, Zehua Ma, Nenghai Yu, A Watermark Updating Framework for Multi-stage Image Content Distribution, IEEE International Conference on Multimedia & Expo (ICME), Best Paper Candidate (Top 15), 2025 [Paper]
-
Xiaoyu Zhang, Cen Zhang, Tianlin Li, Yihao Huang, Xiaojun Jia, Ming Hu, Jie Zhang, Yang Liu, Shiqing Ma, Chao Shen, JailGuard: A Universal Detection Framework for Prompt-based Attacks on LLM Systems, ACM Transactions on Software Engineering and Methodology (TOSEM), 2025 [Paper] [Code]
-
Xiang Zhang, Jie Zhang [equal contribution], Zehua Ma, Jinyang Huang, Meng Li, Huan Yan, Peng Zhao, Zijian Zhang, Qing Guo, Tianwei Zhang, Bin Liu, Nenghai Yu, CamLoPA: A Hidden Wireless Camera Localization Framework via Signal Propagation Path Analysis, IEEE Symposium on Security and Privacy (S&P), 2025 [Paper] [Code] [Video]
-
Meng Tong, Kejiang Chen, Jie Zhang, Yuang Qi, Weiming Zhang, Nenghai Yu, Tianwei Zhang, Zhikun Zhang, InferDPT: Privacy-preserving Inference for Black-box Large Language Models, IEEE Transactions on Dependable and Secure Computing (TDSC), 2025 [Paper] [Code]
-
Xuecheng Wu, Heli Sun, Yifan Wang, Jiayu Nie, Jie Zhang, Yabing Wang, Junxiao Xue, Liang He, AVF-MAE++: Scaling Affective Video Facial Masked Autoencoders via Efficient Audio-Visual Self-Supervised Learning, IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2025 [Paper]
-
Yue Cao, Yun Xing, Jie Zhang, Di Lin, Tianwei Zhang, Ivor Tsang, Yang Liu, Qing Guo, SceneTAP: Scene-Coherent Typographic Adversarial Planner against Vision-Language Models in Real-World Environments, IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2025 [Paper]
-
Shuai Li, Jie Zhang [Corresponding Author], Yuang Qi, Kejiang Chen, Tianwei Zhang, Weiming Zhang, Nenghai Yu, Clean Image May be Dangerous: Data Poisoning Attacks Against Deep Hashing, IEEE Transactions on Multimedia (TMM), 2025 [Paper]
-
Runyi Hu, Jie Zhang [Corresponding Author], Yiming Li, Jiwei Li, Qing Guo, Han Qiu, Tianwei Zhang, VideoShield: Regulating Diffusion-based Video Generation Models via Watermarking, International Conference on Learning Representations (ICLR), 2025 [Paper] [Code]
-
Haolin Wu, Chang Liu, Jing Chen, Ruiying Du, Kun He, Yu Zhang, Cong Wu, Tianwei Zhang, Qing Guo, Jie Zhang, When Translators Refuse to Translate: A Novel Attack to Speech Translation Systems, USENIX Security Symposium, 2025 [Paper]
-
Shuai Li, Kejiang Chen, Jie Zhang, Kunsheng Tang, Kai Zeng, Weiming Zhang, Nenghai Yu, Turning Your Strength into Watermark: Watermarking Large Language Model via Knowledge Injection, IEEE Transactions on Information Forensics and Security (TIFS), 2025 [Paper]
-
Meng Tong, Kejiang Chen, Xiaojian Yuan, Jiayang Liu, Weiming Zhang, Nenghai Yu, Jie Zhang, On the Vulnerability of Text Sanitization, Annual Conference of the North American Chapter of the Association for Computational Linguistics (NAACL), Oral, 2025 [Paper] [Code]
-
Zhiling Zhang, Jie Zhang [Corresponding Author], Kui Zhang, Wenbo Zhou, Ting Xu, Daiheng Gao, Zixian Guo, Qinglang Guo, Weiming Zhang, Nenghai Yu, Segue: Side-information Guided Generative Unlearnable Examples for Facial Privacy Protection in Real World, IEEE International Conference on Acoustics, Speech, and Signal Processing (ICASSP), 2025 [Paper]
-
Haoxiang Tian, Xingshuo Han, Guoquan Wu, An Guo, Yuan Zhou, Jie Zhang, Shuo Li, Jun Wei, Tianwei Zhang, An LLM-empowered Adaptive Evolutionary Algorithm For Multi-Component Deep Learning Systems, AAAI Conference on Artificial Intelligence (AAAI), Oral, 2025 [Paper]
-
Junqi Zhang, Shaoyin Cheng, Linqing Hu, Jie Zhang, Chengyu Shi, Xingshuo Han, Tianwei Zhang, Yueqiang Cheng, Weiming Zhang, The Ghost Navigator: Revisiting the Hidden Vulnerability of Localization in Autonomous Driving, USENIX Security Symposium, 2025 [Paper] [Demo]
-
Boheng Li, Yanhao Wei, Yankai Fu, Zhenting Wang, Yiming Li, Jie Zhang [Corresponding Author], Run Wang, Tianwei Zhang, Towards Reliable Verification of Unauthorized Data Usage in Personalized Text-to-Image Diffusion Models, IEEE Symposium on Security and Privacy (S&P), 2025 [Paper] [Code]
-
Yutong Wu, Jie Zhang [Corresponding Author], Florian Kerschbaum, Tianwei Zhang, THEMIS: Regulating Textual Inversion for Personalized Concept Censorship, Network and Distributed System Security Symposium (NDSS), 2025 [Paper] [Code]
-
Linqing Hu, Junqi Zhang, Jie Zhang, Shaoyin Cheng, Yuyi Wang, Weiming Zhang, Nenghai Yu, Security Analysis and Adaptive False Data Injection against MultiSensor Fusion Localization for Autonomous Driving, Information Fusion, 2024 [Paper]
-
Guanlin Li, Kangjie Chen, Shudong Zhang, Jie Zhang, Tianwei Zhang, ART: Automatic Red-teaming for Text-to-Image Models to Protect Benign Users, Neural Information Processing Systems (NeurIPS), 2024 [Paper] [Code]
-
Yanghao Su, Jie Zhang [Corresponding Author], Ting Xu, Tianwei Zhang, Weiming Zhang, Nenghai Yu, Model X-ray: Detecting Backdoored Models via Decision Boundary, ACM International Conference on Multimedia (MM), 2024 [Paper] [Code]
-
Ruiqi Wang, Jinyang Huang, Jie Zhang [Corresponding Author], Xin Liu, Xiang Zhang, Zhi Liu, Peng Zhao, Sigui Chen, Xiao Sun, FacialPulse: An Efficient RNN-based Depression Detection via Temporal Facial Landmarks, ACM International Conference on Multimedia (MM), Oral, 2024 [Paper] [Code]
-
Runyi Hu, Jie Zhang [Corresponding Author], Ting Xu, Tianwei Zhang, Jiwei Li, Robust-Wide: Robust Watermarking against Instruction-driven Image Editing, European Conference on Computer Vision (ECCV), 2024 [Paper] [Code]
-
Weitao Feng, Wenbo Zhou, Jiyan He, Jie Zhang [Corresponding Author], Tianyi Wei, Guanlin Li, Tianwei Zhang, Weiming Zhang, Nenghai Yu, AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA, International Conference on Machine Learning (ICML), 2024 [Paper] [Code]
-
Kui Zhang, Hang Zhou, Jie Zhang, Wenbo Zhou, Weiming Zhang, Nenghai Yu, Transferable Facial Privacy Protection against Blind Face Restoration via Domain-Consistent Adversarial Obfuscation, International Conference on Machine Learning (ICML), 2024 [Paper]
-
Hanlin Gu, Gongxi Zhu, Jie Zhang, Yuxing Han, Lixin Fan, Qiang Yang, Unlearning during Learning: An Streamlined Federated Machine Unlearning Method, International Joint Conference on Artificial Intelligence (IJCAI), 2024 [Paper] [Code]
-
Kunsheng Tang, Wenbo Zhou, Jie Zhang [Corresponding Author], Aishan Liu, Gelei Deng, Shuai Li, Peigui Qi, Weiming Zhang, Tianwei Zhang, Nenghai Yu, GenderCARE: A Comprehensive Framework for Assessing and Reducing Gender Bias in Large Language Models, ACM Conference on Computer and Communications Security (CCS), Distinguished Artifact Award, 2024 [Paper] [Project Page]
-
Jie Zhang, Dongdong Chen, Jing Liao, Zehua Ma, Han Fang, Weiming Zhang, Hua Gang, Nenghai Yu, Robust Model Watermarking for Image Processing Networks via Structure Consistency, IEEE Transactions on Pattern Analysis and Machine Intelligence (TPAMI), 2024 [Paper]
-
Yi Xie, Jie Zhang, Shiqian Zhao, Tianwei Zhang, Xiaofeng Chen, SAME: Sample Reconstruction Against Model Extraction Attacks, AAAI Conference on Artificial Intelligence (AAAI), 2024 [Paper]
-
Yihao Huang, Felix Juefei-Xu, Qing Guo, Jie Zhang, Yutong Wu, Ming Hu, Tianlin Li, Geguang Pu, Yang Liu, Personalization as a Shortcut for Few-Shot Backdoor Attack against Text-to-Image Diffusion Models, AAAI Conference on Artificial Intelligence (AAAI), 2024 [Paper] [Code]
-
Xiaojian Yuan, Kejiang Chen, Wen Huang, Jie Zhang, Weiming Zhang, Nenghai Yu, Data-Free Hard-Label Robustness Stealing Attack, AAAI Conference on Artificial Intelligence (AAAI), 2024 [Paper] [Code]
-
Wenbo Zhou, Dongdong Chen, Jing Liao, Jie Zhang, Kejiang Chen, Weiming Zhang, Nenghai Yu, Attribute-Aware Head Swapping Guided by 3d Modeling, IEEE International Conference on Acoustics, Speech, and Signal Processing (ICASSP), 2024 [Paper]
-
Chang Liu, Jie Zhang [Corresponding Author], Tianwei Zhang, Xi Yang, Weiming Zhang, Nenghai Yu, Detecting Voice Cloning Attacks via Timbre Watermarking, Network and Distributed System Security Symposium (NDSS), 2024 [Paper] [Project Page]
-
Jie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang, Nenghai Yu, Digital Watermarking for Machine Learning Models - Chapter 6: Protecting Image Processing Networks via Model Watermarking, Springer Book Chapter, 2023 [Link]
-
Zhiwen Ren, Han Fang, Jie Zhang, Zehua Ma, Ronghao Lin, Weiming Zhang, Nenghai Yu, A Robust Database Watermarking Scheme That Preserves Statistical Characteristics, IEEE Transactions on Knowledge and Data Engineering (TKDE), 2023 [Paper]
-
Yanru He, Kejiang Chen, Guoqiang Chen, Zehua Ma, Kui Zhang, Jie Zhang, Huanyu Bian, Han Fang, Weiming Zhang, Nenghai Yu, ProTegO: Protect Text Content against OCR Extraction Attack, ACM International Conference on Multimedia (MM), 2023 [Paper] [Code]
-
Kui Zhang, Hang Zhou, Jie Zhang, Qidong Huang, Weiming Zhang, Nenghai Yu, Ada3Diff: Defending against 3D Adversarial Point Clouds via Adaptive Diffusion, ACM International Conference on Multimedia (MM), 2023 [Paper] [Code]
-
Haozhe Chen, Jie Zhang [Corresponding Author], Kejiang Chen, Weiming Zhang, Nenghai Yu, Model Access Control Based on Hidden Adversarial Examples for Automatic Speech Recognition, IEEE Transactions on Artificial Intelligence (TAI), 2023 [Paper]
-
Xi Yang, Jie Zhang [equal contribution], Han Fang, Zehua Ma, Chang Liu, Weiming Zhang, Nenghai Yu, AutoStegaFont: Synthesizing Vector Fonts for Hiding Information in Documents, AAAI Conference on Artificial Intelligence (AAAI), 2023 [Paper] [Demo]
-
Chang Liu, Jie Zhang [equal contribution], Han Fang, Zehua Ma, Weiming Zhang, Nenghai Yu, DeAR: A Deep-learning-based Audio Re-cording Resilient Watermarking, AAAI Conference on Artificial Intelligence (AAAI), 2023 [Paper]
-
Xiaojian Yuan, Kejiang Chen, Wen Huang, Jie Zhang, Weiming Zhang, Nenghai Yu, Pseudo Label-Guided Model Inversion Attack via Conditional Generative Adversarial Network, AAAI Conference on Artificial Intelligence (AAAI), 2023 [Paper] [Code]
-
Xi Yang, Jie Zhang [Corresponding Author], Kejiang Chen, Weiming Zhang, Zehua Ma, Feng Wang, Nenghai Yu, Tracing Text Provenance via Context-Aware Lexical Substitution, AAAI Conference on Artificial Intelligence (AAAI), 2022 [Paper]
-
Jie Zhang, Dongdong Chen, Jing Liao, Qidong Huang, Hua Gang, Weiming Zhang, Nenghai Yu, Poison Ink: Robust and Invisible Backdoor Attack, IEEE Transactions on Image Processing (TIP), 2022 [Paper] [Code]
-
Jie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang, Hua Gang, Huamin Feng, Nenghai Yu, Deep Model Intellectual Property Protection via Deep Watermarking, IEEE Transactions on Pattern Analysis and Machine Intelligence (TPAMI), 2021 [Paper] [Code]
-
Qidong Huang, Jie Zhang [equal contribution], Wenbo Zhou, Weiming Zhang, Nenghai Yu, Initiative Defense against Facial Manipulation, AAAI Conference on Artificial Intelligence (AAAI), 2021 [Paper] [Code]
-
Xiquan Guan, Huamin Feng, Weiming Zhang, Hang Zhou, Jie Zhang, Nenghai Yu, Reversible Watermarking in Deep Convolutional Neural Networks for Integrity Authentication, ACM International Conference on Multimedia (MM), 2020 [Paper]
-
Jie Zhang, Dongdong Chen, Jing Liao, Weiming Zhang, Hua Gang, Nenghai Yu, Passport-aware Normalization for Deep Model Protection, Neural Information Processing Systems (NeurIPS), 2020 [Paper] [Code]
-
Jie Zhang, Dongdong Chen, Jing Liao, Han Fang, Weiming Zhang, Wenbo Zhou, Hao Cui, Nenghai Yu, Model Watermarking for Image Processing Networks, AAAI Conference on Artificial Intelligence (AAAI), 2020 [Paper] [Code]
🎖 Honors and Awards
- 2026.08 🏅 Champion (1st Place) of both the Preliminary (Phase 1, white-box) and Final (Phase 2, overall) phases, LifeGenIP Challenge: Unlearnable Videos against Diffusion-based Customization @ ECCV 2026.
- 2025.06 Candidates of best paper (One of the Top 15 Papers), ICME, 2025
- 2024.10 Distinguished Artifact Award, CCS, 2024
- 2021.12 National Scholarship for Doctoral Students, China.
- 2020.12 Cyberspace Science Scholarship (funded by Academician Xiaomo Wang), China.
📖 Educations
- 2017.09 - 2022.06, PhD of Cyber Science, University of Science and Technology of China.
- 2013.09 - 2017.06, Bachelor of Electrical Engineering and Automation, China University of Geosciences (Beijing).
💬 Invited Talks
- 2025.08, Advancing Trustworthy and Responsible AI, to National AI Research Lab, KAIST | [slide]
- 2025.03, Building Trustworthy Text-to-Image Models: Risks, Defenses, and Forensics, at IMDA | [slide]
- 2025.02, Recent LLM Tendency, at CFAR, A*STAR | [slide]
- 2024.08, Trustworthy Generative AI, at CFAR, A*STAR | [slide]
- 2024.04, AIGC Security, at Nanyang Technological University | [slide]
- 2023.11, IP Protection on Deep Models and Data, at Shanghai Jiao Tong University | [poster]
- 2023.09, Model IP Protection, at University of Science and Technology of China | [slide]
🧰 Useful Tools
- Survey on IP protection for AI models
- Reinforcement Learning Enhanced LLMs: A Survey
- Unlocking the Mysteries of OpenAI o1: A Survey of the Reasoning Abilities of Large Language Models
- Selected Projects: [SafeGuider], [GenderCARE], [Timbre Watermarking], [EraseAnything]
💻 Internships
- 2019.06 - 2019.08, Pvmed Research, China.