Perception
Multimodal Robustness
Securing speech and other multimodal inputs against adversarial manipulation and privacy threats.
I am a Ph.D. student at Duke University, advised by Prof. Neil Gong. My research focuses on secure, trustworthy, and robust AI systems, from multimodal perception to autonomous agents and external memory.
I previously worked as a Research Intern with the ByteDance SecurityFlow Team, focusing on LLM and agent security. I was also advised by Prof. Ke Xu at Tsinghua University, and I collaborate closely with Yuxin Cao at the National University of Singapore.

Our paper on cross-modal safety steering for audio-language models has been accepted to NeurIPS 2026.
Our paper on dual-task universal adversarial perturbations against voice control systems has been accepted to ICME 2026.
I joined ByteDance SecurityFlow as a Research Intern.
Our paper on safety guardrails for audio-language models has been accepted to NeurIPS 2025.
Our paper on binary malware summarization has been accepted to IEEE TIFS.
Our paper on the transferability of audio adversarial examples has been accepted to ICME 2025.
Our paper on speech privacy against automatic speech recognition systems has been accepted to USENIX Security 2025.
Our paper on ASR robustness through audio style transfer has been accepted to SecTL 2024.
Multimodal Robustness
Securing speech and other multimodal inputs against adversarial manipulation and privacy threats.
LLMs & Agents
Safety and security of audio-language models and autonomous agents.
Secure AI Memory
Protecting RAG systems and external knowledge bases from context injection and poisoning.






Research Intern
Mentors: Dr. Yang Bai and Dr. Dongxian Wu
Research Collaborator
Collaborator: Yuxin Cao (Prof. Jin Song Dong’s group)
Reviewer for NeurIPS 2026, ICASSP 2026/2027, ICME 2025/2026, and IEEE TDSC.
I'm fortunate to work with these people:
First-author work accepted to NeurIPS 2026.
First-author work accepted to ICME 2026.
Contributed to research published at ICME 2025.