
My research focuses on the safety and security of AI systems, both in the digital and the physical worlds.
Before joining Tsinghua University, I was a post-doc researcher at ETH Zurich (2024-2025), working with Prof. Zhendong Su. I obtained my Ph.D. degree from HKUST in 2024 under the supervision of Prof. Shuai Wang, and my B.S. degree from Fudan University in 2020.
Openings: I am always looking for self-motivated students (Post-doc, PhD, Master, and Undergraduate). If you are interested in joining my group, please drop me an email with your CV and transcripts.
Team
Tianyi Wei (Incoming Ph.D. student, 2027 Fall); currently 4th-year UG @ THU
Xi Xiang (Incoming Master student, 2027 Fall); currently 4th-year UG @ THU
Xin Ma (Incoming Master student, 2027 Fall); co-advised with Prof. Yu Jiang; currently 4th-year UG @ THU
Teaching
- Data Structure, Fall 2026.
Services
Program Committee:
- 2027: IEEE S&P, USENIX Security, FSE, ICSE
- 2026: USENIX Security, CCS, ICSE, ISSTA
- 2025: LMPL@SPLASH, LAMPS@CCS, DeepTest@ICSE
- 2023: USENIX Security (AE)
- 2022: OSDI (AE), ATC (AE), ISSTA (AE)
Reviewer:
- 2027: ICLR
- 2026: TOSEM, TDSC, TCAD
- 2025: TOSEM, TDSC, TSE
Selected Awards
🏆 Distinguished Paper Award, IEEE Symposium on Security and Privacy (S&P), 2025.
🏆 Best PhD Dissertation Award (one awardee per year), Department of CSE, HKUST, 2024.
Selected Projects
Semantic Side-Channel Analysis for Large Model Systems.
NSFC General Program — PIAttack and Defense for Embodied AI Systems in Open Physical Environments.
BJNSF Joint Fund (Key Project) — PIAI Systems Security.
NSFC Excellent Young Scientists Fund (Overseas) — PI
Selected Publications
$^\dagger$ indicates (co-)corresponding authors.
[IEEE S&P] SEED: Eliciting Internal Safety for Jailbreak Defense in Large Reasoning Models via Exploratory Decoding.
Yujue Wang, Quan Zhang$^\dagger$, Gwihwan Go, Chijin Zhou, Yuanyuan Yuan$^\dagger$, Heyuan Shi, Yu Jiang.
In 48th IEEE Symposium on Security and Privacy, 2027.[Black Hat EU] Rooting Your Robots: Breaking Authentication Across Quadruped and Humanoid Robots.
Yuqiao Yang, Fuchen Ma, Ting Chen, Yu Jiang, Yuanyuan Yuan, Yuanming Xie, Minglang Li, Xinnuo Ying, Ao Wang, and Jiaxin Dong.
In 26th Black Hat Europe, 2026.[CCS] PathMark: Protecting Intellectual Property of Mixture-of-expert LLMs via Path Watermarks.
Yudong Gao, Qingyue Wang$^\dagger$, Yuanyuan Yuan$^\dagger$, Ruixuan Huang, Linghan Chen, Zimo Ji, and Shuai Wang.
In 33rd ACM Conference on Computer and Communications Security, 2026.[TOSEM] How Multi-Modal LLMs Reshape Visual Deep Learning Testing: A Comprehensive Study Through the Lens of Image Mutation.
Liwen Wang, Yuanyuan Yuan$^\dagger$, Ao Sun, Zongjie Li, Pingchuan Ma, Daoyuan Wu, and Shuai Wang$^\dagger$.
In ACM Transactions on Software Engineering and Methodology, 2026.[DL4C@NeurIPS] Is Your Benchmark (Still) Useful? Dynamic Benchmarking for Code Language Models.
Batu Guan, Xiao Wu, Yuanyuan Yuan, and Shaohua Li.
In 4th Deep Learning for Code Workshop @ NeurIPS, 2025.
[preprint][NDSS] BitShield: Defending Against Bit-Flip Attacks on DNN Executables.
Yanzuo Chen, Yuanyuan Yuan$^\dagger$, Zhibo Liu, Sihang Hu, Tianxiang Li, and Shuai Wang$^\dagger$.
In 32nd Network and Distributed System Security Symposium, 2025.
[preprint], [code][IEEE S&P] CipherSteal: Stealing Input Data from TEE-Shielded Neural Networks with Ciphertext Side Channels.
Yuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen, Shuai Wang, Yinqian Zhang, and Zhendong Su.
In 46th IEEE Symposium on Security and Privacy, 2025.
🏆 Distinguished Paper Award
[preprint][NDSS] Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN Executables.
Yanzuo Chen, Zhibo Liu, Yuanyuan Yuan$^\dagger$, Sihang Hu, Tianxiang Li, and Shuai Wang$^\dagger$.
In 32nd Network and Distributed System Security Symposium, 2025.
🏅 Presented at Black Hat Europe.
[preprint], [code][Thesis] Side Channel Analysis for AI Infrastructures.
Yuanyuan Yuan.
Ph.D. Thesis, 2024.
🏆 Best PhD Dissertation Award 2024 (one awardee per year), CSE, HKUST[Black Hat EU] The Devil is in the (Micro-) Architectures: Uncovering New Side-Channel and Bit-Flip Attack Surfaces in DNN Executables.
Yanzuo Chen, Zhibo Liu, Yuanyuan Yuan, Sihang Hu, Tianxiang Li, and Shuai Wang.
In 24th Black Hat Europe, 2024.
[white paper], [slides][CCS] DeepCache: Revisiting Cache Side-Channel Attacks in Deep Neural Networks Executables.
Zhibo Liu, Yuanyuan Yuan, Yanzuo Chen, Sihang Hu, Tianxiang Li, and Shuai Wang.
In 31st ACM Conference on Computer and Communications Security, 2024.
🏅 Presented at Black Hat Europe.
[code][CCS] HyperTheft: Thieving Model Weights from TEE-Shielded Neural Networks via Ciphertext Side Channels.
Yuanyuan Yuan, Zhibo Liu, Sen Deng, Yanzuo Chen, Shuai Wang, Yinqian Zhang, and Zhendong Su.
In 31st ACM Conference on Computer and Communications Security, 2024.
[extended version][ISSTA] See the Forest, not Trees: Unveiling and Escaping the Pitfalls of Error-Triggering Inputs in Neural Network Testing.
Yuanyuan Yuan, Shuai Wang, and Zhendong Su.
In 33rd International Symposium on Software Testing and Analysis, 2024.[TSE] Provably Valid and Diverse Mutations of Real-World Media Data for DNN Testing.
Yuanyuan Yuan, Qi Pang, and Shuai Wang.
In IEEE Transactions on Software Engineering, 2024.
[preprint][IEEE S&P] No Privacy Left Outside: On the (In-)Security of TEE-Shielded DNN Partition Defenses.
Ziqi Zhang, Chen Gong, Yifeng Cai, Yuanyuan Yuan, Bingyan Liu, Ding Li, Yao Guo, and Xiangqun Chen.
In 45th IEEE Symposium on Security and Privacy, 2024.
[code][NDSS] MPCDiff: Testing and Repairing MPC-Hardened Deep Learning Models.
Qi Pang, Yuanyuan Yuan, and Shuai Wang.
In 31st Network and Distributed System Security Symposium, 2024.
[code][NeurIPS] Explain Any Concept: Segment Anything Meets Concept-Based Explanation.
Ao Sun, Pingchuan Ma, Yuanyuan Yuan, and Shuai Wang.
In 37th Conference on Neural Information Processing Systems, 2023.
[code][Black Hat USA] BTD: Unleashing the Power of Decompilation for x86 Deep Neural Network Executables.
Zhibo Liu, Yuanyuan Yuan, Xiaofei Xie, Tianxiang Li, Wenqiang Li, and Shuai Wang.
In 26th Black Hat USA, 2023.
[white paper], [slides][IEEE S&P] ADI: Adversarial Dominating Inputs in Vertical Federated Learning Systems.
Qi Pang, Yuanyuan Yuan, Shuai Wang, and Wenting Zheng.
In 44th IEEE Symposium on Security and Privacy, 2023.
[extended version][NDSS] OBSan: An Out-Of-Bound Sanitizer to Harden DNN Executables.
Yanzuo Chen, Yuanyuan Yuan$^\dagger$, and Shuai Wang$^\dagger$.
In 30th Network and Distributed System Security Symposium, 2023.
[project page], [code][USENIX Security] Precise and Generalized Robustness Certification for Neural Networks.
Yuanyuan Yuan, Shuai Wang, and Zhendong Su.
In 32nd USENIX Security Symposium, 2023.
[extended version], [code][USENIX Security] CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software.
Yuanyuan Yuan, Zhibo Liu, and Shuai Wang.
In 32nd USENIX Security Symposium, 2023.
[extended version], [findings], [code][USENIX Security] Decompiling x86 Deep Neural Network Executables.
Zhibo Liu, Yuanyuan Yuan, Shuai Wang, Xiaofei Xie, and Lei Ma.
In 32nd USENIX Security Symposium, 2023.
🏅 Artifact Evaluation Badges: Available; Functional; Reproduced.
🏅 Presented at Black Hat USA.
[extended version], [code][ICSE] CC: Causality-Aware Coverage Criterion for Deep Neural Networks.
Zhenlan Ji, Pingchuan Ma$^\dagger$, Yuanyuan Yuan$^\dagger$, and Shuai Wang.
In 45th IEEE/ACM International Conference on Software Engineering, 2023.
[code][ICSE] Revisiting Neuron Coverage for DNN Testing: A Layer-Wise and Distribution-Aware Criterion.
Yuanyuan Yuan, Qi Pang, and Shuai Wang.
In 45th IEEE/ACM International Conference on Software Engineering, 2023.
[extended version], [code][ASE] Unveiling Hidden DNN Defects with Decision-Based Metamorphic Testing.
Yuanyuan Yuan, Qi Pang, and Shuai Wang.
In 37th IEEE/ACM International Conference on Automated Software Engineering, 2022.
[extended version], [code][ISSTA] MDPFuzz: Testing Models Solving Markov Decision Processes.
Qi Pang, Yuanyuan Yuan, and Shuai Wang.
In 31st International Symposium on Software Testing and Analysis, 2022.
[code][TIFS] NeuralD: Detecting Indistinguishability Violations of Oblivious RAM with Neural Distinguishers.
Pingchuan Ma, Zhibo Liu, Yuanyuan Yuan, and Shuai Wang.
In IEEE Transactions on Information Forensics and Security, 2022.
[code][TSE] Enhancing DNN-Based Binary Code Function Search With Low-Cost Equivalence Checking.
Huaijin Wang, Pingchuan Ma, Yuanyuan Yuan, Zhibo Liu, Shuai Wang, Qiyi Tang, Sen Nie, and Shi Wu.
In IEEE Transactions on Software Engineering, 2022.
[code][SIGMETRICS] Metamorphic Testing of Deep Learning Compilers.
Dongwei Xiao, Zhibo Liu, Yuanyuan Yuan, Qi Pang, and Shuai Wang.
In ACM Sigmetrics/Performance, 2022.
[code][USENIX Security] Automated Side Channel Analysis of Media Software with Manifold Learning.
Yuanyuan Yuan, Qi Pang, and Shuai Wang.
In 31st USENIX Security Symposium, 2022.
🏅 Artifact Evaluation Badges: Available; Functional; Reproduced.
[extended version], [code][IEEE S&P] SoK: Demystifying Binary Lifters Through the Lens of Downstream Applications.
Zhibo Liu, Yuanyuan Yuan, Shuai Wang, and Yuyan Bao.
In 43rd IEEE Symposium on Security and Privacy, 2022.
[code][CVPR] Perception Matters: Detecting Perception Failures of VQA Models Using Metamorphic Testing.
Yuanyuan Yuan, Shuai Wang, Mingyue Jiang, and Tsong Yueh Chen.
In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2021.
[code][ICLR] Private Image Reconstruction from System Side Channels Using Generative Models.
Yuanyuan Yuan, Shuai Wang, and Junping Zhang.
In International Conference on Learning Representations, 2021.
[code]