CV
Professional Experience
Researcher, State Key Laboratory of Blockchain and Data Security, Zhejiang University 2024-06 – Present
Member of the AI Data Security Team
Conducting research on AI-generated content (AIGC) security
Developing the DFscan platform for multimodal deepfake detection; leading the technical team in platform design and development
Qiushi Research Fellow, ZJU-Hangzhou Global Scientific and Technological Innovation Center 2023-12 – 2024-05
Member of the Cyberspace Security Research Institute
Conducted research on multimodal data security and privacy protection technologies
Developed multimodal deepfake detection systems
Postdoctoral Researcher, Zhejiang University 2021-01 – 2023-11
College of Computer Science and Technology
Researched voice security and privacy protection in human-computer interaction scenarios
Postdoctoral supervisor: Prof. Kui Ren (Qiushi Chair Professor, AAAS/ACM/CCF/IEEE Fellow, Dean of the College of Computer Science and Technology of Zhejiang University)
Education
Ph.D., Computer Science — Lancaster University, Lancaster, UK
2016-10 – 2020-12
School of Computing and Communications. Thesis: Acoustic-Channel Attack and Defence Methods for Personal Voice Assistants. Supervisors: Prof. Utz Roedig (University College Cork) and Prof. Jeff Yan (University of Southampton)
Dual Master’s Degree, Electrical Engineering (KU Leuven) & Integrated Circuit Engineering (Tsinghua) — KU Leuven & Tsinghua University, Leuven, Belgium & Beijing, China
2012-09 – 2015-09
Department of Electrical Engineering, KU Leuven & School of Integrated Circuits, Tsinghua University. Supervisor: Prof. Guoqiang Bai (Tsinghua University)
B.Eng., Electronic Science and Technology — Beijing University of Posts and Telecommunications, Beijing, China
2008-09 – 2012-06
School of Electronic Engineering
Publications
Representative Publications
UniAP: Protecting Speech Privacy With Non-Targeted Universal Adversarial Perturbations — IEEE Transactions on Dependable and Secure Computing (2024)
ALIF: Low-Cost Adversarial Audio Attacks on Black-Box Speech Platforms Using Linguistic Features — 2024 IEEE Symposium on Security and Privacy (SP) (2024)
SurrogatePrompt: Bypassing the Safety Filter of Text-to-Image Models via Substitution — Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS 2024) (2024)
Transferring Audio Deepfake Detection Capability Across Languages — Proceedings of the ACM Web Conference 2023 (2023)
Personal Voice Assistant Security and Privacy—A Survey — Proceedings of the IEEE (2022)
Other Publications (Reverse Chronological Order)
Beyond Content: A Comprehensive Speech Toxicity Dataset and Detection Framework Incorporating Paralinguistic Cues — Proceedings of the AAAI Conference on Artificial Intelligence (2026)
Attack-Resistant Watermarking for AIGC Image Forensics via Diffusion-based Semantic Deflection — The 14th International Conference on Learning Representations (ICLR 2026) (2026)
MixFake: Benchmarking and Enhancing Audio Deepfake Detection in Diverse Real-world Mixed Audio — IEEE International Conference on Multimedia and Expo (ICME 2026) (2026)
HyperPotter: Spell the Charm of High-Order Interactions in Audio Deepfake Detection — International Conference on Machine Learning (ICML 2026) (2026)
Spoofed Speech Detection in Real-World Fraudulent Communication Scenarios — Journal of Cyber Security (2025)
Phoneme-Based Proactive Anti-Eavesdropping With Controlled Recording Privilege — IEEE Transactions on Dependable and Secure Computing (2025)
SecHeadset: A Practical Privacy Protection System for Real-time Voice Communication — Proceedings of the 23rd Annual International Conference on Mobile Systems, Applications and Services (MobiSys 2025) (2025)
WMCopier: Forging Invisible Image Watermarks on Arbitrary Images — The 39th Conference on Neural Information Processing Systems (NeurIPS 2025) (2025)
Deepfake Detection: Key Challenges and Technical Approaches — Computing Magazine of the CCF (2025)
Indelible “Footprints” of Inaudible Command Injection — IEEE Transactions on Information Forensics and Security (2024)
InfoMasker: Preventing Eavesdropping Using Phoneme-Based Noise — Proceedings 2023 Network and Distributed System Security Symposium (2023)
Adversarial Command Detection Using Parallel Speech Recognition Systems — Lecture Notes in Computer Science (2022)
SonarSnoop: Active Acoustic Side-Channel Attacks — International Journal of Information Security (2020)
Smart Speaker Privacy Control—Acoustic Tagging for Personal Voice Assistants — 2019 IEEE Security and Privacy Workshops (SPW) (2019)
Towards Reactive Acoustic Jamming for Personal Voice Assistants — Proceedings of the 2nd International Workshop on Multimedia Privacy and Security (2018)
Preprints / Under Review
Divide and Conquer: Multimodal Video Deepfake Detection via Cross-Modal Fusion and Localization — arXiv preprint arXiv:2602.00209 (2026)
JudgeRail: Harnessing Open-Source LLMs for Fast Harmful Text Detection with Judicial Prompting and Logit Rectification — Under review (2025)
Test-Time Adaptation for Audio Deepfake Detection — Under review (2025)
Robust Watermarks Leak: Channel-Aware Feature Extraction Enables Adversarial Watermark Manipulation — arXiv preprint arXiv:2502.06418 (2025)
Bridging the Synthesis-Detection Gap: A Chinese Audio Deepfake Dataset and Industrial-Scale Retrieval-Augmented Detection — Under review (2025)
CLINDA: A Cross-lingual Domain Adaptation Framework for Challenging Audio Deepfake Detection Tasks across Languages — Under review (2024)
Masked Diffusion Models Are Fast Distribution Learners — arXiv preprint arXiv:2306.11363 (2023)
Thesis
- Acoustic-Channel Attack and Defence Methods for Personal Voice Assistants — Ph.D. Dissertation, Lancaster University (2020)
Research Projects
Research on Speech Synthesis Data Compliance Management Technology Based on Intrinsic Characteristics of Audio Signals (Principal Investigator) — National Natural Science Foundation of China (NSFC) (2025–2028)
High-Performance Visual Perception Models Using Deep Learning (Participant) — National Natural Science Foundation of China (NSFC) (2023–2026)
Cross-Chain Security in Heterogeneous Blockchain Networks (Participant) — National Natural Science Foundation of China (NSFC) (2023–2027)
Research on Voice Attack and Defense Based on the Physical Characteristics of Smart Device Sensing Components (Participant) — National Natural Science Foundation of China (NSFC) (2022–2025)
Multimodal Network Environment Construction Technology Based on Public Cloud-Network Resources (Participant) — Key R&D Programs of China (2024–2027)
Aggregation and Transfer of Machine Learning Models (National Science and Technology Innovation 2030 Initiative - New Generation Artificial Intelligence) (Participant) — Key R&D Programs of China (2021–2025)
Security Protection Technology for Industrial Control Programming Platforms Based on Domestic Cryptographic Algorithms (Participant) — Key R&D Programs of China (2022–2024)
Key R&D Programme of Zhejiang Province (Participant) — Provincial, Municipal, and University-Level Projects (2024–2026)
Key Technologies and Platform Development for Security Detection of Large AI Models (Participant) — Hangzhou Key R&D Program (2024–2027)
Toolchain for Deep Synthetic Content Analysis Based on Physical Attribute Attribution (Principal Investigator) — Hangzhou West Innovation Corridor Development Special Fund (2024–2026)
Active and Passive Security Protection Technologies for the Maojing Voice Interaction System (Principal Investigator) — Zhejiang University-Alibaba Collaboration Project (2025–2026)
Security Risk Detection and Alignment Strategies for Large Model-based AI Agents (Participant) — Zhejiang University-Ant Group Joint Laboratory (2025–2025)
Research and Development of AI-Driven Automated Security Detection Technologies and Components for Power Systems (Participant) — China Southern Power Grid Research Institute Co., Ltd. (2024–2026)
Deep Learning Algorithm Evaluation and Security Verification Platform (Participant) — CRRC Zhuzhou Electric Locomotive Research Institute Co., Ltd. (2024–2027)
Research on AI Attack-Defense Library Design and Test Component Development for New Power System Scenarios (2023) (Participant) — China Southern Power Grid Research Institute Co., Ltd. (2023–2025)
Multidimensional Protocol Carrying and Endogenous Security Access Technologies for Multimodal Networks (Participant) — Key R&D Programs of China (2024–2027)
Honors & Awards
Silver Award — IJCAI 2026 Deepfake Detection and Localization Challenge (DDL 2.0) (2026-08) — Team AIGVDete (Zhejiang University)
ICML 2026 Silver Reviewer — International Conference on Machine Learning (ICML 2026) (2026-05) — Top-tier Silver Reviewer distinction awarded by the ICML 2026 Program Chairs
3rd Place Award — Workshop & Challenge on Deepfake Detection, Localization, and Interpretability, IJCAI 2025 (2025-08) — Advisor — Track: Audio-Video Detection and Localization (DDL-AV)
National Grand Prize (Top-Tier Award) — 19th “Challenge Cup” National Competition for Extracurricular Academic Science and Technology Works (2024-11) — Advisor (Ranked 2nd among 3 advisors) — Project: “Multimodal AI Audit Matrix: Deepfake Detection and NSFW Content Regulation Platform”
National Graduate Scholarship Achievement (October 2024) (2024-10) — Co-supervised Master’s student won the National Graduate Scholarship (China)
Top 5 Nationwide — 3rd China Artificial Intelligence Competition (2021-12) — Primary Advisor (Ranked 1st among 2 advisors) — Audio Deepfake Detection Under Open-Speaker Scenarios; Speaker-Specific Audio Deepfake Detection
Postdoctoral Excellence Grant (Second Class) — Zhejiang Provincial Department of Human Resources and Social Security (2021-08) —
Finalist for “Most Innovative Research” Pwnie Award — Black Hat USA (2019-08) — First Author (1st of 4 contributors) — Research: “SonarSnoop: Active Acoustic Side-Channel Attacks”
Ph.D. Scholarship — Faculty of Science and Technology, Lancaster University, UK (2016-10) —
Student Supervision & Mentorship
Co-supervising 5 Ph.D. students, 7 Master’s students and one undergraduate student at Zhejiang University on research projects in AIGC security and multimodal privacy
Co-supervised a Zhejiang University Master’s student to win the National Graduate Scholarship (China) — the highest-level scholarship awarded to Master’s students in China (Oct 2024)
Successfully mentored 1 PhD student, 5 Master’s students, and 5 undergraduates to degree completion, guiding thesis design, research execution, and publication strategies
Teaching Assistant for lab/practical sessions: CS4615: Computer Systems Security, University College Cork, Ireland; SCC110: Software Development, Lancaster University, UK
Academic Services
Journal Editorial Roles
- Special Issue Initiator and Guest Editor-in-Chief: “Intelligent Voice Security and Defense Technologies”, Journal of Cyber Security, 2025
Conference Program Committees
- USENIX Security 2027, AAAI 2027
Conference Reviewer
- ICLR 2027, Interspeech 2026, AAAI 2026, IEEE SLT 2026, ACM MM 2026, ICLR 2026, ICML 2026, ACM Web Conference (WWW 2025)
Journal Reviewer
English Journals: Proceedings of the IEEE, IEEE Transactions on Information Forensics and Security (TIFS), IEEE Transactions on Dependable and Secure Computing (TDSC), IEEE Internet of Things Journal (IoT-J), ACM Transactions on Internet of Things (TIOT)
Chinese Journal: Journal of Information Network Security
Reviewer Recognition
- ICML 2026 Silver Reviewer
Other Academic Activities
Contributed to the preparation of a €720,839 grant proposal (Science Foundation Ireland – SFI) on Security and Privacy of Personal Voice Assistants under Prof. Utz Roedig (2019)
Visiting Scholar at the Department of Computer Science, University College Cork (UCC), Ireland (2019–2020)
Participated in the São Paulo Advanced Science School (ESPCA) on Smart Cities, hosted by the University of São Paulo (2017); selected as one of 75 global top graduate students and postdoctoral researchers (sponsored by FAPESP)
Impacts
Industry Contributions
Proposed SurrogatePrompt, a prompt attack method to bypass safeguards of commercial large-scale AI models (e.g., Midjourney, Stability.ai), enabling systematic generation of policy-violating content. Findings were acknowledged by these leading vendors.
Developed WMCopier, an adversarial watermark forgery method that compromises commercial watermarking systems; recognized by Amazon’s Responsible AI Team for identifying critical vulnerabilities (official thank-you letter).
Developed and open-sourced ALIF, the first black-box adversarial attack framework leveraging linguistic features; adopted by NVIDIA for integration into their official AI security toolkit.
Media Recognition
- SonarSnoop: Active Acoustic Side-Channel Attacks — garnered attention from IT media (Motherboard, ZDNet, Sophos); praised by Bruce Schneier and Prof. Ross Anderson.
