Bio

I am a tenured assistant professor at Vrije Universiteit Amsterdam, also a faculty member of the VUSec Group. I am passionate to make AI systems more reliable. Prior to join VU, I got my Ph.D. from CISPA Helmholtz Center for Information Security (Saarbrücken, Germany), supervised by Prof. Michael Backes. I have two year industrial experience of working as an Operating System Engineer at 2012 Labs@Huawei (Hangzhou, China). I got my master’s degree from Zhejiang University and bachelor’s degree from Lanzhou University.

Research Interests

  • Trustworthy AI: Privacy, Security, Safety, Auditing, and Accountability

  • Privacy-Preserving Machine Learning: Synthetic Data Generation, Differential Privacy

  • AI for CyberSecurity: AI-Driven Automatic Vulnerability Discovery

Job Openings

I am always looking for self-motivated students to work with me. If you would like to apply for a position, feel free to send me an e-mail with your CV and fill out this Form to schedule a meeting. If you would like to do your thesis with me, please drop me an email with your CV and transcript.

What’s New

  • [04/2026] Our EU Horizon project LATTICE got funded! Looking forward to working with our amazing partners in this project! This project will create several Ph.D. and postdoc positions, stay tuned for the job announcement!

  • [04/2026] I joined the TPC of S&P 2027!

  • [04/2026] StoryMI got accepted by ACL 2026.

  • [03/2026] Welcome Yiwei and Francesco joining the group!

  • [12/2025] PrivATE and VICTOR got accepted by NDSS 2026!

  • [12/2025] I got Tenure at Vrije Universiteit Amsterdam!

  • [10/2025] Welcome Qingyu joining our group as a Ph.D.!

  • [09/2025] Hyperparameter Leakage in DRL got accecpted by IEEE TDSC.

  • [05/2025] GradEscape got accepted by USENIX Security 2025.

  • [01/2025] ArtistAuditor got accepted by WWW 2025, looking forward to visiting Sydney.

  • [10/2024] Our work “SoK: Dataset Copyright Auditing in Machine Learning Systems” got accepted in IEEE S&P 2025, looking forward to visiting San Francisco!

  • [Fall 2024] I moved to Amsterdam and started my new position as an assistant professor at Vrije University Amsterdam!

Talks

  • [10/2025] A guest lecture at SoftSec 2025, VU Amsterdam, Netherlands.

  • [06/2024] Give a talk at Central South University, Changsha, China.

  • [01/2024] Give a talk at ETH Postdoctal Symposium, online.

  • [02/2024] Attend NDSS 2024 at San Diego, CA, USA, and host a session on “ML Attacks (2)”!

  • [08.2023] Give a talk at INSAIT, Sofia, Bulgaria.

  • [02.2023] Give a talk at Huawei AI4Sec Research Team, online.

  • [11.2022] Give a talk about “Graph Unlearning” at CCS 2022, Los Angeles, USA.

  • [08.2022] Give a talk about “Inference Attacks Against Graph Embedding” at USENIX Security 2022, Boston, USA.

  • [11.2021] Give a talk about “When Machine Unlearning Jeopardize Privacy” at CCS 2021, Online.