About Me
Hi, I am an Assistant Professor in the College of Information Sciences and Technology at Pennsylvania State University, where I lead the AI Reliability (AIR) Lab. I am also affiliated with the Institute for Computational and Data Sciences and the Center for Socially Responsible AI. Prior to that, I received my Ph.D. in Computer Science from the University of Virginia, supervised by Dr. Hongning Wang. I have also interned at Didi Lab, LinkedIn and Pinterest Lab. [Curriculum Vitae]
My research contributes to accountable machine learning, particularly through methods for improving robustness and transparency under data imperfections and deployment mismatches. I'm particularly fascinated by transformative ML paradigms, including large language models (LLMs), multimodal models, federated learning, self-supervised learning, graph neural networks and more. By understanding and hardening their working mechanism, my research vision is to establish algorithmic foundations for AI-enabled systems to work reliably in practical environments concerning biased, noisy, and out-of-distribution inputs.
Openings: I'm looking for highly motivated students, including PhDs (fully-funded), Masters, undergraduates, and interns. Please kindly read Open Position for more information before contacting me.
Research at the AIR Lab
The AI Reliability (AIR) Lab at Penn State studies how modern machine learning systems fail and how to make them dependable. We build methods for robustness, safety and transparency under imperfect data and deployment mismatch, spanning foundation models, graphs, and distributed learning.
Safety and Alignment of Foundation Models
We characterize how large language and multimodal models break, from jailbreaks and alignment-breaking attacks to hallucination, distorted safety perception and social bias, and design defenses and controls: robustly aligned decoding, personalized steering vectors, factuality monitoring during generation, and prompt-level attribution that explains why a model says what it says.
- Understanding and Rectifying Safety Perception Distortion in VLMs (arXiv 2025)
- FairCode: Evaluating Social Bias of LLMs in Code Generation (arXiv 2025)
- JoPA: Explaining Large Language Model’s Generation via Joint Prompt Attribution (ACL 2025)
- Monitoring Decoding: Mitigating Hallucination via Evaluating the Factuality of Partial Response during Generation (ACL Findings 2025)
- Personalized Steering of Large Language Models: Versatile Steering Vectors Through Bi-directional Preference Optimization (NeurIPS 2024)
- Defending Against Alignment-Breaking Attacks via Robustly Aligned LLM (ACL 2024)
Robust and Interpretable Graph Learning
Graphs encode structure that attackers can perturb and that shifts between training and deployment. We take a spectral view of augmentation and attacks, learn representations that are invariant and unbiased, explain graph models globally, and expose backdoor threats to graph contrastive learning.
- Mitigating Graph Covariate Shift via Score-based Out-of-distribution Augmentation (arXiv 2024)
- Globally Interpretable Graph Learning via Distribution Matching (WWW 2024)
- Graph Contrastive Backdoor Attacks (ICML 2023)
- Spectral augmentation for self-supervised learning on graphs (ICLR 2023)
- Graph Structural Attack by Perturbing Spectral Distance (KDD 2022)
- Unbiased Graph Embedding with Biased Graph Observations (WWW 2022)
Secure Federated and Self-supervised Learning
Learning from many parties and from unlabeled data widens the attack surface. We study adaptive backdoor attacks on federated learning, communication-efficient adaptive optimizers with guarantees, trigger optimization against self-supervised encoders, and adversarial and protective mechanisms for image-to-image diffusion models.
- GuardDoor: Safeguarding Against Malicious Diffusion Editing via Protective Backdoors (arXiv 2025)
- AdvI2I: Adversarial Image Attack on Image-to-Image Diffusion models (ICML 2025)
- Backdoor Contrastive Learning via Bi-level Trigger Optimization (ICLR 2024)
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated Learning (NeurIPS 2023)
- Communication-Efficient Adaptive Federated Learning (ICML 2022)
News
- Sep 2024One paper is accepted to NeurIPS 2024!
- May 2024Two papers are accepted to ACL 2024!
- May 2024One paper is accepted to ICML 2024!
- Jan 2024Two papers are accepted to WWW 2024!
- Jan 2024One paper is accepted to ICLR 2024!
- Sep 2023One paper is accepted to NeurIPS 2023!
- Apr 2023Two papers are accepted to ICML 2023!
- Jan 2023One paper is accepted to ICLR 2023!
- Sep 2022I am officially on board as a tenure-track faculty at IST@PSU!
- May 2022I am honored to receive CS John A. Stankovic Graduate Research Award from UVa.