Current funded research appears first, followed by selected research projects and their associated publications, artifacts, or demonstrations.
Research challenge: Critical-infrastructure IoT devices often use custom firmware that is difficult to validate at scale, creating risks involving functional correctness, software vulnerabilities, and hardware incompatibility.
Project direction: The project develops a hardware-aware LLM verification framework for IoT firmware. The funded project description organizes the approach across input-level optimization, representation-level graph/semantic reasoning, and system-level integration with external security scanners and hardware simulators.
Research challenge: Mobile LLM agents interact with applications, notifications, third-party SDKs, and privileged system resources. These interactions can expose agents to adversarial inputs and confused-deputy behavior across application boundaries.
Project direction: The funded project studies automated generation of realistic adversarial scenarios, principled measurement of agent misbehavior, and graph-based runtime defenses for detecting and mitigating confused-deputy behavior.
Research challenge: LLM-generated code can be functional while still containing security vulnerabilities.
Approach: PromSec develops prompt optimization for secure and functional code generation; SGCode demonstrates a flexible prompt-optimizing system built around this research direction.
Associated paper(s): “PromSec: Prompt Optimization for Secure Generation of Functional Source Code with Large Language Models (LLMs),” ACM CCS 2024; “Demo: SGCode: A Flexible Prompt-Optimizing System for Secure Generation of Code,” ACM CCS 2024.
Research challenge: Graph-based malicious-domain detectors can be targeted by coordinated changes to multiple attacker-controlled entities.
Approach: MintA studies black-box multi-instance evasion against GNN-based malicious-domain detection and evaluates the attack against defenses including outlier detection and graph purification.
Associated paper: “Multi-Instance Adversarial Attack on GNN-Based Malicious Domain Detection,” IEEE Symposium on Security and Privacy (S&P) 2024.
Research challenge: Deepfake detection requires methods that can leverage complementary visual and semantic evidence while remaining robust across manipulation types.
Approach: ViGText combines vision-language model explanations with graph neural networks for deepfake image detection.
Associated paper: “ViGText: Deepfake Image Detection with Vision-Language Model Explanations and Graph Neural Networks,” 33rd Network and Distributed System Security Symposium (NDSS 2026).
Research direction: Explore LLM-based methods and datasets for artificial-intelligence accelerator design generation.
Selected outcomes: FedChip studies federated LLMs for AI accelerator chip design; SA-DS provides a dataset for LLM-driven AI accelerator design generation.
Associated paper(s): “FedChip: Federated LLM for Artificial Intelligence Accelerator Chip Design,” IEEE ICLAD 2025; “SA-DS: A Dataset for Large Language Model-Driven AI Accelerator Design Generation,” IEEE ISCAS 2025.
Research direction: Study stealthy backdoor attacks against graph-neural-network-based malicious-domain detection through DNS perturbations.
Associated paper: “STING: A Stealthy Backdoor Attack on GNN-Based Malicious Domain Detection via DNS Perturbations,” IEEE Open Journal of the Communications Society, vol. 6, pp. 7823–7841, 2025.
Research direction: Edge-computing inference with heterogeneous graph neural networks for traffic demand forecasting.
Associated paper: “Semi-Decentralized Inference in Heterogeneous Graph Neural Networks for Traffic Demand Forecasting: An Edge-Computing Approach,” IEEE Transactions on Vehicular Technology, vol. 73, no. 12, pp. 19400–19416, 2024.