My research in Trustworthy Machine Learning focuses on improving the security, robustness, privacy, safety, and integrity of modern AI systems. One major direction investigates adversarial threats against machine learning, including adversarial examples, poisoning attacks, neural Trojans and backdoors, and stealthy attacks, together with mechanisms for detecting and mitigating these threats. As AI has increasingly shifted toward generative models, my research has expanded to study the trustworthiness of language and multimodal generative AI, including the detection and characterization of AI-generated content, adversarial AI-generated media, inference-time integrity and alignment of text-to-image models, and the reliability of automated safety benchmarks for language models.
1. Adversarial machine learning: attacks, robustness, and detection: We aim to understand the attack surface of machine-learning systems and develop mechanisms to make models robust against adversarial manipulation, poisoning, backdoors, and evasive attacks.Related publications:
- Junyi Zhao, Zeyan Liu, Zijun Yao, Fengjun Li, and Bo Luo. An LLM-enabled End-to-End Attack Pipeline against Speech-based Machine Translation. In European Symposium on Research in Computer Security (ESORICS), Rome, Italy, September 14-18, 2026.
- Ye Wang, Zeyan Liu, Bo Luo, Rongqing Hui, and Fengjun Li. The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face Recognition. In ACM Conference on Computer and Communications Security (CCS), Salt Lake City, Utah, USA, October 2024.
- Zeyan Liu, Fengjun Li, Zhu Li, and Bo Luo. LoneNeuron: a Highly-effective Feature-domain Neural Trojan using Invisible and Polymorphic Watermarks. In ACM SIGSAC Conference on Computer and Communications Security (CCS), Los Angeles, CA, USA, 2022.
- Zeyan Liu, Fengjun Li, Jingqiang Lin, Zhu Li, and Bo Luo. Hide and Seek: on the Stealthiness of Attacks against Deep Learning Systems. In European Symposium on Research in Computer Security (ESORICS), Copenhagen, Denmark, September 2022.
- Sana Awan, Bo Luo, and Fengjun Li. CONTRA: Defending against Poisoning Attacks in Federated Learning. In European Symposium on Research in Computer Security (ESORICS), 2021, Online.
- Sohaib Kiani, Sana Awan, Chao Lan, Fengjun Li, and Bo Luo. Two Souls in an Adversarial Image: Towards Universal Adversarial Example Detection using Multi-view Inconsistency. In Annual Computer Security Applications Conference (ACSAC), December 2021, Online. (Distinguished Paper Award)
2. Security and trustworthiness of generative AI: We aim to answer important questions about generative AI - Can we trust the behavior, outputs, safety evaluations, and alignment mechanisms of modern generative AI systems?
Related publications:
- Nyamtulla Shaik, Fengjun Li, and Bo Luo. Benchmarking the Benchmarks: Evaluating Automated Safety Benchmarks for Small Language Models. In European Symposium on Research in Computer Security (ESORICS), Rome, Italy, September 14-18, 2026.
- Becky Qiao Ling Lin, Fengjun Li, and Bo Luo. When Alignment Breaks: on the Inference Integrity in Text-to-Image Models. In European Symposium on Research in Computer Security (ESORICS), Rome, Italy, September 14-18, 2026.
- Yuying Li, Zeyan Liu, Junyi Zhao, Liangqin Ren, Fengjun Li, Jiebo Luo, and Bo Luo. The Adversarial AI-Art: Understanding, Generation, Detection, and Benchmarking. In European Symposium on Research in Computer Security (ESORICS), Bydgoszcz, Poland, September 2024.
3. AI content provenance: We aim to develop mechanisms for AI content authenticity, provenance, forensic attribution, and proactive protection.
Related publications:
- Liangqin Ren, Zeyan Liu, Ye Wang, Yuxin Chen, Fengjun Li, and Bo Luo. PhantomSeal: Proactive Deepfakes Defense with Identity/Context Protection and Forensic Tracing. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), The Hague, Netherlands, 2026.
- Zeyan Liu, Zijun Yao, Fengjun Li, and Bo Luo. On the Detectability of ChatGPT Content: Benchmarking, Methodology, and Evaluation through the Lens of Academic Writing. In ACM Conference on Computer and Communications Security (CCS), Salt Lake City, Utah, USA, October 2024.
4. Privacy-preserving machine learning: We aim to support ML computation while protecting sensitive data, intermediate representations, and potentially proprietary models.
Related publications:
- Liangqin Ren, Zeyan Liu, Fengjun Li, Kaitai Liang, Zhu Li, and Bo Luo. PrivDNN: A Secure Multi-Party Computation Framework for Deep Learning using Partial DNN Encryption. In the 24th Privacy Enhancing Technologies Symposium (PETS), Bristol, UK, July 2024.
- Sumit Bhattai, Pramil Paudel, Zhu Li, Bo Luo, and Fengjun Li. Robust Privacy-Preserving Classification for Lensless Image. In IEEE International Conference on Mobile Ad-Hoc and Smart Systems (MASS), Seoul, South Korea, September, 2024.
- Sana Awan, Fengjun Li, Bo Luo, and Mei Liu. A Reliable and Accountable Privacy-Preserving Federated Learning Framework using the Blockchain. In ACM Conference on Computer and Communications Security (CCS), London, UK, November 2019. (Poster)
- Lei Yang and Fengjun Li. Cloud-Assisted Privacy-Preserving Classification for IoT Applications. In IEEE Conference on Communications and Network Security (CNS), Beijing, China, May 2018.