I am currently a Research Fellow at NTU, working with Prof. XiaoFeng Wang and Prof. Wei Dong. In 2024, I completed my Ph.D. with honor at the Zhejiang University, co-supervised by Prof. Wenyuan Xu, Prof. Xiaoyu Ji, and Prof. Chen Yan. Previously, I obtained my B.Eng with honor also from Zhejiang University in 2019.

My research is broadly in the fields of (1) AI security and privacy, with a special focus on the security and privacy issues associated with multimodal AI, and (2) AI for system security, particularly for addressing vulnerabilities in critical IoT, communication, and software systems.

In AI-oriented contexts, I focus on developing trustworthy intelligent audio and vision models, safeguarding user privacy, and fortifying generative models against various leaks and attacks. I also regulate AI behavior to ensure alignment with societal responsibilities, especially in the context of large language models such as Stable Diffusion and GPT-4.

In system-oriented contexts, I work toward developing dependable and secure machine learning (ML) systems and am committed to their application for deployment in critical infrastructures and consumer electronics, e.g., in the domain of audio/vision-interface IoT devices, carrier networks, and software systems.

If you are seeking any form of academic cooperation, please feel free to email me at xinfengli(at)ntu.edu.sg or lxfmakeit(at)gmail.com.

I have published over 20 papers in top-tier international security, AI, and mobile sensing conferences and journals, such as IEEE S&P, ACM CCS, USENIX Security, NDSS, NeurIPS, KDD, TDSC, ICCV.

🔥 News

  • 2025.11:  🔥 EmoRAG has been accepted to SIGKDD 2026. It’s great working with Xinyun to investigate RAG robustness.
  • 2025.10:  🔥 WebCloak, EnchTable have been accepted to S&P 2026. Congratulations to Jialin and all collaborators!
  • 2025.09:  🔥 AgentAuditor has been accepted to NeurIPS 2025. Congratulations to Hanjun and Shenyu!
  • 2025.06:  🔥 AudioTrust, the First Comprehensive Trustworthiness Benchmark for Audio Large Language Models, is now released! We hope this can serve as a solid foundation for academia and industry for safe audio-based LLM system development. [Github] (Media Coverage: [量子位])
  • 2025.06:  🎉 Neural Invisibility Cloak has been accepted to USENIX Security’25. Congratulations to Wenjun!
  • 2025.04:  🔥 Lead/Contributed to 3 (Trustworthy) LLM Agent survey papers are now released: (1) TrustAgent: A survey on trustworthy LLM agents: Threats and countermeasures [Paper (accepted to KDD’25)]; (2) Advances and challenges in foundation agents: From brain-inspired intelligence to evolutionary, collaborative, and safe systems [Paper Github] [HuggingFace] (Media Coverage, e.g., [SANER, 机器之心]); (3) A Comprehensive Survey in LLM (-Agent) Full Stack Safety: Data, Training, and Deployment.
  • 2024.11:  🎉 LightAntenna has been accepted to NDSS 2025! We reveal a new Electromagnetic Interference (EMI) threat where everyday fluorescent lamps can secretly manipulate IoT devices. Unlike visible metal antennas, LightAntenna transforms unaltered lamps into stealthy EMI sources, enabling remote attacks up to 20 meters away. This groundbreaking method exposes a hidden threat in plain sight.
  • 2024.08:  💪🏻 Raconteur has been accepted to NDSS 2025! Raconteur is the first tool using Large Language Models (LLMs) to explain shell commands clearly. It provides detailed insights into command functions and purposes, aligning with MITRE ATT&CK standards. Equipped with professional cybersecurity knowledge, Raconteur delivers accurate explanations. A documentation retriever helps in understanding new commands. Tested extensively, Raconteur offers unique insights, helping security analysts better understand command intentions. Please find out more (e.g., our dataset) on the [website].
  • 2024.08:  📝 Legilimens has been accepted to CCS 2024! A new SOTA for the LLM unsafe moderation technique, with significant improvement in efficiency. Congratulations to Jialin and Dr. Deng.
  • 2024.05:  🔥 SafeGen has been accepted to CCS 2024! As T2I technologies advance, their misuse for generating sexually explicit content has become a major concern. SafeGen effectively mitigates this by removing any explicit visual representations from the model, making it safe regardless of the adversarial text input, outperforming eight other protection approaches. SafeGen adjusts the model’s visual self-attention layers to ensure that the high-quality production of benign images is not compromised. More information is on our [code][pretrained model].
  • 2024.05:  🔥 SafeEar has been accepted to CCS 2024! To our knowledge, this is the first content privacy-preserving audio deepfake detection framework. As audio deepfakes and user privacy concerns have become increasingly significant societal issues, we demonstrate how to achieve reliable deepfake detection while preventing both machine and human adversaries from eavesdropping on sensitive user speech content. To facilitate future research, we also developed a comprehensive multilingual deepfake dataset (more than 1,500,000 genuine & deepfake audio samples) using advanced TTS/VC techniques. Please check out our [website][code].
  • 2023.08:  🎉 VRifle has been accepted to NDSS 2024! We demonstrate how to achieve a completely inaudible adversarial perturbation attack via ultrasound, which achieves the farthest attack range (~10 meters away) and the most universal capability (1 perturbation can tamper with >28,000 benign samples). Our novel ultrasonic transformation model can be generalized to other modalities of attacks, such as laser and electromagnetic.
  • 2023.08:  🔥 I attended the USENIX Security 2023 Symposium and presented our work NormDetect in person.
  • 2023.07:  😄 Our practical backdoor attack (SMA) against ASR models was accepted to ACM MM 2023!
  • 2022.09:  🎉 Tuner and UltraBD were accepted to IoT-J 2023 and ICPADS 2022! We demonstrate a practical inaudible backdoor attack against speaker recognition systems.
  • 2022.07:  💪🏻 NormDetect has been accepted to USENIX Security 2023! We rethink the challenging topic of defending against inaudible voice attacks and present a software-based mitigation that can instantly protect legacy and future devices in an actionable and practical manner, which is verified on 24 mainstream smart devices with voice interfaces.
  • 2021.07:  🎉 PROLE Score has been accepted to USENIX Security 2022! “OK Siri” or “Hey Google”? We conduct an extensive voiceprint security measurement. Our findings and designed metrics shall aid manufacturers and users in DIY highly secure voiceprint phrases.
  • 2020.12:  🔥 EarArray has been accepted to NDSS 2021! We uncover the inherent physical properties of the inaudible attack, i.e., ultrasound field distributions, and redesign microphone arrays for accurate detection and attack localization.

📝 Selected Papers

(*: Equal Contribution, ^: Corresponding Author)

📚 Professional Services

I actively contribute to the academic community through program organization and peer review for leading conferences and journals in security, AI, and systems.

Program Organization

  • KDD 2025: Tutorial Organizer

Conference

  • ICLR: Area Chair (2026)
  • TPC Member: CCS’26, SaTML’26
  • Reviewer: CVPR’26, AAAI’26
  • S&P: External Reviewer (2019, 2020)
  • CCS: External Reviewer (2021, 2022, 2023, 2024)
  • USENIX Security: External Reviewer (2019, 2020, 2021, 2024)
  • NDSS: External Reviewer (2020, 2022, 2023, 2024)

Journal

  • IEEE Transactions on Information Forensics and Security (TIFS)
  • IEEE Transactions on Dependable and Secure Computing (TDSC)
  • IEEE Transactions on Neural Networks and Learning Systems (TNNLS)
  • ACM Transactions on Software Engineering and Methodology (TOSEM)
  • IEEE Internet of Things Journal (IoT-J)
  • ACM Transactions on Privacy and Security
  • ACM Transactions on Internet Technology (TOIT)
  • IEEE Transactions on Cognitive Communications and Networking (TCCN)

🎖 Honors and Awards

  • ACM SIGSAC China Doctoral Dissertation Award (1st), 2025
  • CCS 2024 Student Grant, 2024
  • NDSS 2024 Student Grant, 2024
  • WANG G.S. PhD Research Excellence Award, 2023
  • Best Security Partner Award (OPPO Inc.), 2022
  • Edison Honors Class@ZJU, Outstanding Graduate Award, 2019
  • EE@ZJU Top-10 Scholars Award, 2018
  • National Scholarship, 2018

📖 Educations

  • 2019.06 - 2024.06, Ph.D., Zhejiang University, Hangzhou.
  • 2015.09 - 2019.06, Undergraduate, College of Electrical Engineering, Zhejiang University, Hangzhou.

💬 Invited Talks

  • 2024.10, ACM CCS 2024 at Salt Lake City, USA. | [Slides]
  • 2024.02, NDSS 2024 at San Diego, California, USA. | [Paper] | [Code] | [Video]
  • 2023.08, USENIX Security Symposium 2023 at Anaheim, California, USA. | [Slides]

🗺️ Visitor Map