I am currently a Ph.D. student in Computer Science at the Kahlert School of Computing, University of Utah, Salt Lake City, UT, advised by Prof. Mu Zhang. (You can call me Zach.)
My research focuses on AI and LLM/VLM-based agent security, with particular interest in security challenges arising in AI workflows where machine learning models are tightly intertwined with code logic. I study emerging attack surfaces in LLM/VLM-powered agents, such as web-based and tool-using agents, and investigate how adversaries can manipulate perception, reasoning, memory, and action pipelines to induce harmful or unintended behaviors (e.g., deceiving agents into executing incorrect actions in real-world tasks). More broadly, I am interested in understanding new security risks introduced by AI-enabled applications and AI-driven software development processes.
Before my Ph.D., I earned my B.E. in Computer Science from
Northeastern University, China,
advised by Prof. Yanfeng Zhang.
I have industry experience as a software and systems engineer at CelerData, Kuaishou, and Meituan, focused on large-scale data systems, infrastructure, and engineering-driven problem solving.
I am open to research collaborations and internship opportunities in AI security, LLM/VLM-based agents, and secure AI systems. Please feel free to reach out via email or WeChat if you are interested in collaborating.
") does not match the recommended repository name for your site ("").
", so that your site can be accessed directly at "http://".
However, if the current repository name is intended, you can ignore this message by removing "{% include widgets/debug_repo_name.html %}" in index.html.
",
which does not match the baseurl ("") configured in _config.yml.
baseurl in _config.yml to "".