About
Secure and trustworthy AI. My research examines the trustworthiness of provenance methods for AI models, particularly model fingerprinting and watermarking, which can support intellectual property protection and legal accountability in generative AI. These methods aim to identify which model produced an output, but their reliability under realistic deployment and adversarial conditions remains uncertain. I evaluate their robustness against realistic adversarial attacks and develop defenses to address the resulting weaknesses. My broader interests include privacy, fairness, and general security problems in AI systems, as well as AI ethics and governance topics.
PhD advisor: Dr. Marc Juarez.
News
-
Sep 2026Our paper, “FARE: Forensic Acceptance Region Estimation for Catching Bait-and-Switch Image Generators”, has been accepted to NeurIPS '26.
-
Sep 2026Our paper, “What Breaks Local Watermarks? A Robustness Benchmark for Local Invisible Image Watermarking”, has been accepted to AISec '26.
-
Jul 20262 papers on AI governance in education, accepted to AIES '26, examine what credentials should still certify and what capacities education should preserve when cognitive work is delegated to AI.
-
May 2026Released SPRINT, a method for robustly attributing AI-generated images to their source models under adversarial attacks.
-
Mar 2026Our SaTML '26 paper Smudged Fingerprints was featured by Herald Scotland, DIGIT, and University of Edinburgh News.
-
Mar 2026Gave a guest lecture on Image Provenance in the AI Era at the University of Edinburgh (slides).
-
Apr 2025Presented SoK: What Makes Private Learning Unfair? at SaTML '25 in Copenhagen.
-
Dec 2024SoK: What Makes Private Learning Unfair? accepted to SaTML '25, providing the first causal analysis of fairness degradation induced by differential privacy.
Publications
-
NeurIPS '26FARE: Forensic Acceptance Region Estimation for Catching Bait-and-Switch Image Generators
-
AISec '26
-
SaTML '26
-
AIES '26
-
AIES '26
-
arXiv
-
SaTML '25
-
Bio Protoc
-
J. Cell Sci.
-
J. Cell Biol.
-
Sci. Rep.
-
Biomed. Eng. Online
Note: * denotes equal contribution (co-first author).
Industry Experience
-
2021–2023AI Frameworks Engineer, Intel Blogs
I led the team behind Neural Coder and developed model optimization and benchmarking tools for PyTorch and TensorFlow. I worked directly with partners including Alibaba Cloud, AWS, and Hugging Face to integrate Intel AI software into their platforms.
-
2020–2021AI Algorithm Engineer, Huawei
I developed and optimized neural network algorithms for 5G MU-MIMO to improve prediction accuracy and inference efficiency. I collaborated with deployment and validation teams to integrate these algorithms into 5G features and verify their performance.
Teaching and Mentoring
-
LectureGuest lecture on Image Provenance in the AI Era for the graduate course Privacy and Security with Machine Learning — University of Edinburgh. The slides are available here.
-
Teaching Assistant
- Privacy and Security with Machine Learning — University of Edinburgh (2023–2025)
- Mathematical Image Analysis — Johns Hopkins University (2019–2020)
-
Research TutoringFelipe Takaesu (JHU), Eliana Crentsil (JHU), Lucia Sablich (JHU), Shannon Flanary (JHU), Chunhan Fang (UoE).
Academic Service
-
Program Committee
- IEEE Conference on Secure and Trustworthy Machine Learning (SaTML 2027)
- ACM Workshop on Artificial Intelligence and Security (AISec 2026)
-
Reviewer
- ACM Digital Threats: Research and Practice (DTRAP)
- The 40th Annual AAAI Conference on Artificial Intelligence (AAAI-26)
- Privacy Enhancing Technologies Symposium (PETS/PoPETs 2027)