I am a first-year Ph.D. student in Computer and Information Science (CIS) at the University of Pennsylvania. I am affiliated with the GRASP Laboratory and co-advised by Prof. George Pappas and Prof. Hamed Hassani. I also continue to receive long-term mentorship from Leo Yu Zhang. I aspire to become a knowledge-focused content creator in the future (though currently focusing on academic work) and welcome you to visit my Bilibili channel: HUST-Rookie’s Homepage.
My research interests include Large Model Security, AI Agents, Embodied AI, and Adversarial Machine Learning.
I received my master’s degree from Huazhong University of Science and Technology, where I had the privilege of being advised by Prof. Shengshan Hu.
🔥 News
- 2026.07: 🎉 Two papers are accepted by ACM MM 2026.
- 2026.05: 🎉 My first-author paper, Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics, is accepted by USENIX Security 2026.
- 2026.04: 🎉 One paper, Dual-branch Robust Unlearnable Examples, is accepted by ICML 2026.
- 2025.09: 🎉 One paper is accepted by NeurIPS
- 2025.09: 🎉 One paper is accepted by TMM (IEEE Transactions on Multimedia)
- 2025.08: 🎉 One co-first author paper is accepted by TDSC
- 2025.07: 🎉 One paper is accepted by TIFS
- 2025.03: 🎉 One paper is accepted by ICME 2025
- 2025.02: 🎉 One first-author paper is accepted by CVPR 2025
- 2025.01: 🎉 One first-author paper is accepted by ICLR 2025
- 2024.12: 🎉 One paper is accepted by ICASSP 2025
- 2024.12: 🎉 One paper is accepted by AAAI 2025
- 2024.10: 🏅 I was awarded the National Scholarship.
- 2024.09: 🎉 One paper is accepted by NeurIPS 2024
- 2024.04: 🎉 One first-author paper is accepted by IJCAI 2024
- 2024.02: 🎉 One paper is accepted by TDSC
- 2023.07: 🎉 One paper is accepted by ACM MM 2023
- 2023.06: 🎓 I graduated with a Bachelor’s Degree and was awarded the Outstanding Graduate of Hunan Province.
- 2023.04: 🎉 One first-author paper is accepted by IJCAI 2023
- 2023.02: 🏅 We win 1st place in IEEE Trojan Removal Competition (IEEE TRC) with a $5,000 prize. I have been invited to present at Backdoor Attacks and Defense in Machine Learning (BANDS) workshop at ICLR’ 23!
📝 Publications
Jailbreak
ACM MM 2026PVDetector: Detecting Prompt Injection Attacks on Purpose-Specific LLM Agents through Policy-Violation Concept Analysis, Junhui Wang, Hangtao Zhang, Zhirun Zheng, Li Zeng, Jiejun Xiao, Xi Luo, Lihua Yin, Saiqin LongUSENIX Security 2026Defending Jailbreak Attacks on Large Language Models via Manifold Trajectory Kinetics, Hangtao Zhang, Yucheng Zhao, Sishun Liu, Ziqi Zhou, Zeyu Ye, Wei Wan, Minghui Li, Shengshan Hu, Yanjun Zhang, Yi Liu, Leo Yu ZhangICLR 2025Badrobot: Jailbreaking Embodied LLM Agents in the physical world, Hangtao Zhang, Chenyu Zhu, Xianlong Wang, Ziqi Zhou, Changgan Yin, Minghui Li, Lulu Xue, Yichen Wang, Shengshan Hu, Aishan Liu, Peijin Guo, Leo Yu Zhang
🚪 Backdoor Attacks and Defenses
IJCAI 2024Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness, Hangtao Zhang, Shengshan Hu, Yichen Wang, Leo Yu Zhang, Ziqi Zhou, Xianlong Wang, Yanjun Zhang, Chao ChenTDSC 2024Reverse Backdoor Distillation: Towards Online Backdoor Attack Detection for Deep Neural Network Models, Zeming Yao, Hangtao Zhang, Yicheng Guo, Xin Tian, Wei Peng, Yi Zou, Leo Yu Zhang, Chao ChenCVPR 2025Test-Time Backdoor Detection for Object Detection Models, Hangtao Zhang, Yichen Wang, Shihui Yan, Chenyu Zhu, Ziqi Zhou, Linshan Hou, Shengshan Hu, Minghui Li, Yanjun Zhang, Leo Yu ZhangTIFSDarkHash: A Data-Free Backdoor Attack Against Deep Hashing, Ziqi Zhou, Menghao Deng, Yufei Song, Hangtao Zhang, Wei Wan, Shengshan Hu, Minghui Li, Leo Yu Zhang(In peer review)TrojanRobot: Physical-World Backdoor Attacks Against VLM-based Robotic Manipulation, Xianlong Wang, Hewen Pan, Hangtao Zhang, Minghui Li, Shengshan Hu, Ziqi Zhou, Lulu Xue, Peijin Guo, Yichen Wang, Wei Wan, Aishan Liu, Leo Zhang
😈 Poisoning attacks and Denfenses
ICML 2026Dual-branch Robust Unlearnable Examples, Xianlong Wang, Hangtao Zhang, Wenbo Pan, Ziqi Zhou, Changsong Jiang, Li Zeng, Xiaohua JiaNeurIPS 20243D Point Clouds: Class-wise Transformation Is All You Need, Xianlong Wang, Minghui Li, Wei Liu, Hangtao Zhang, Shengshan Hu, Yechao Zhang, Ziqi Zhou, Hai JinIJCAI 2023Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated Learning, Hangtao Zhang, Zeming Yao, Leo Yu Zhang, Shengshan Hu, Chao Chen, Alan Liew, Zhetao LiTDSC 2025Fine-Grained Poisoning Framework against Federated Learning, Minghui Li¹, Hangtao Zhang¹, Yanjun Zhang, Li Zeng, Chao Chen, Qiyun Shao, Wei Wan, Shengshan Hu, Leo Yu Zhang. (¹*Co-first authors)
🌌 Adversarial Attacks and Defenses
ACM MM 2026GhostPrompt: Cross-Image Adversarial Prompt for Vision-Language Models, Li Zeng, Zeyu Ye, Meng Xie, Hangtao Zhang, Xianlong Wang, Yanchun Li, Zhetao LiNeurIPS 2025AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied Decision-Making Systems, Yichen Wang, Hangtao Zhang, Hewen Pan, Ziqi Zhou, Xianlong Wang, Peijin Guo, Lulu Xue, Shengshan Hu, Minghui Li, Leo Yu ZhangACM MM 2023AdvCLIP: Downstream-agnostic Adversarial Examples in Multimodal Contrastive Learning, Ziqi Zhou, Shengshan Hu, Minghui Li, Hangtao Zhang, Yechao Zhang, Hai JinAAAI 2025Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature, Yichen Wang, Yuxuan Zhou, Ziqi Zhou, Hangtao Zhang, Wei Wan, Shengshan Hu, Minghui LiIEEE Transactions on MultimediaSegTrans: Transferable Adversarial Examples for Segmentation Models, Yufei Song, Ziqi Zhou, Qi Lu, Hangtao Zhang, Yifan Hu, Lulu Xue, Shengshan Hu, Minghui Li, Leo Yu ZhangICASSP 2025PB-UAP: Hybrid Universal Adversarial Attack For Image Segmentation, Yufei Song, Ziqi Zhou, Minghui Li, Xianlong Wang, Hangtao Zhang, Menghao Deng, Wei Wan, Shengshan Hu, Leo Yu ZhangICME 2025PSFD: Proactive Spatial-Frequency Defense against Malicious Exemplar-Guided Image Editing, Li Zeng, Xiaojun Mo, Meng Xie, Hangtao Zhang, Yixiang Liu, Yezhuo Peng, Yanchun Li
🎖 Honors and Awards
- 2025.11 National Scholarship (Postgraduate) (Top 1%)
- 2025.11 BYD Scholarship
- 2024.11 National Scholarship (Postgraduate) (Top 1%)
- 2023.02 1st place in IEEE Trojan Removal Competition (IEEE TRC) (Linshan Hou (HIT), Wenkai Zheng (BUPT), Hangtao Zhang (HUST))
- 2022.12 Baosteel Outstanding Student Award (only 472 students in China)
- 2022.05 Top 10 University-level Excellent Students (Undergraduate)
- 2021.10 National Scholarship (Undergraduate) (Top 1%)
- 2020.10 Jingdong Scholarship (Undergraduate) (Top 1%)
📖 Educations
- 2026.08 - Present, Ph.D. in Computer and Information Science, University of Pennsylvania, Philadelphia.
- 2023.09 - 2026.06, Master, Huazhong University of Science and Technology, Wuhan.
- 2019.09 - 2023.06, Undergraduate, Xiangtan Univeristy, Xiangtan.
📖 Experience
- 2025.06 - 2025.12, Remote Research Assistant, Northwestern University, supervised by Prof. Manling Li and Dr. Canyu Chen.
- 2025.07 - 2025.09, Research Assistant, Centre for Data Science, The University of Hong Kong, supervised by Prof. Ka-Ho Chow.
- 2025.05 - 2025.07, Research Intern, Hangzhou Xingyan Intelligent Technology Co., Ltd., supervised by Prof. Chang Xu (University of Sydney).
📖 Service
- Conference Reviewer: ICML (2025-26), ICLR (2025-26), NeurIPS (2025-26), CVPR (2025-26), ICCV (2025), ECCV (2026), KDD (2025-26).
- Journal Reviewer: International Journal of Computer Vision (IJCV), IEEE Transactions on Dependable and Secure Computing (TDSC), IEEE Transactions on Information Forensics and Security (TIFS), IEEE Transactions on Multimedia (TMM).