Weifei Jin

I am a Ph.D. student at Duke University, advised by Prof. Neil Gong. My research focuses on secure, trustworthy, and robust AI systems, from multimodal perception to autonomous agents and external memory.

I previously worked as a Research Intern with the ByteDance SecurityFlow Team, focusing on LLM and agent security. I was also advised by Prof. Ke Xu at Tsinghua University, and I collaborate closely with Yuxin Cao at the National University of Singapore.

Weifei Jin standing outdoors at Mont Saint-Michel

News

  1. Our paper on cross-modal safety steering for audio-language models has been accepted to NeurIPS 2026.

  2. Our paper on dual-task universal adversarial perturbations against voice control systems has been accepted to ICME 2026.

  3. I joined ByteDance SecurityFlow as a Research Intern.

  4. Our paper on safety guardrails for audio-language models has been accepted to NeurIPS 2025.

  5. Our paper on binary malware summarization has been accepted to IEEE TIFS.

Earlier updates
  1. Our paper on the transferability of audio adversarial examples has been accepted to ICME 2025.

  2. Our paper on speech privacy against automatic speech recognition systems has been accepted to USENIX Security 2025.

  3. Our paper on ASR robustness through audio style transfer has been accepted to SecTL 2024.

Research interests

01

Perception

Multimodal Robustness

Securing speech and other multimodal inputs against adversarial manipulation and privacy threats.

Selected papers

  1. CrossSteer pipeline for steering audio-language model responses

    NeurIPS 2026

    CrossSteer: Cross-Modal Safety Steering for Audio-Language Models

    Houde Dong, Weifei Jin, Yuxin Cao, Wei Song, Derui Wang, Jie Hao

  2. DUAP dual-task adversarial attack framework

    ICME 2026

    DUAP: Dual-task Universal Adversarial Perturbations Against Voice Control Systems

    Suyang Sun, Weifei Jin, Yuxin Cao, Wei Song, Jie Hao

    Paper
  3. ALMGuard analysis of jailbreak mitigation and speech recognition gradients

    NeurIPS 2025

    ALMGuard: Safety Shortcuts and Where to Find Them as Guardrails for Audio–Language Models

    Weifei Jin, Yuxin Cao, Junjie Su, Minhui Xue, Jie Hao, Ke Xu, Jin Song Dong, Derui Wang

    Paper
  4. MALSIGHT workflow from binary malware to code summaries

    IEEE TIFS 2025

    MALSIGHT: Exploring Malicious Source Code and Benign Pseudocode for Iterative Binary Malware Summarization

    Haolang Lu, Hongrui Peng, Guoshun Nan, Jiaoyang Cui, Cheng Wang, Weifei Jin, Songtao Wang, Shengli Pan, Xiaofeng Tao

    Paper
  5. Acoustic representation optimization integrated with audio attacks
  6. AudioShield privacy protection for speech communication

    USENIX Security 2025

    Whispering Under the Eaves: Protecting User Privacy Against Commercial and LLM-powered Automatic Speech Recognition Systems

    Weifei Jin, Yuxin Cao, Junjie Su, Derui Wang, Yedi Zhang, Minhui Xue, Jie Hao, Jin Song Dong, Yixian Yang

    Paper
View all publications

Experiences

  1. ByteDance · SecurityFlow Team

    Feb 2026 – May 2026

    Research Intern

    Mentors: Dr. Yang Bai and Dr. Dongxian Wu

  2. Duke University (Remote)

    May 2025 – Nov 2025

    Undergraduate Researcher

    Advisor: Prof. Neil Gong

  3. Tsinghua University · THUCSNET

    Nov 2024 – Mar 2025

    Undergraduate Researcher

    Advisor: Prof. Ke Xu

  4. National University of Singapore (Remote)

    Aug 2024 – Mar 2025

    Research Collaborator

    Collaborator: Yuxin Cao (Prof. Jin Song Dong’s group)

  5. CSIRO’s Data61 (Remote)

    Oct 2023 – May 2025

    Research Collaborator

    Mentor: Dr. Derui Wang

Awards

Services

Reviewer for NeurIPS 2026, ICASSP 2026/2027, ICME 2025/2026, and IEEE TDSC.

Mentoring

I'm fortunate to work with these people:

  1. Houde Dong

    First-author work accepted to NeurIPS 2026.

  2. Suyang Sun

    First-author work accepted to ICME 2026.

  3. Hejia WangYulin Ye

    Contributed to research published at ICME 2025.