I am a Research Fellow at the University of Queensland, previously a visiting scientist at CSIRO. My research focuses on AI usage control: technically enforcing how trained models and their training data can be reused, repurposed, or queried after release.
I am fortunate to be advised by A/Prof. Guangdong Bai, Dr. Jason Xue, and Dr. Naipeng Dong. My PhD was supported by the Australian Government RTP Scholarship and the CSIRO Top-up Scholarship, and I was the recipient of the 2024 Google PhD Fellowship in Security, Privacy, and Abuse Prevention.
I serve on the program committees of security conferences such as USENIX Security’27, NDSS’27, and ACM CCS LAMPS’26, and machine learning venues such as NeurIPS, ICLR, CVPR, and AAAI. I am also the HDR representative for the CSS discipline at UQ.
S&P'24
@inproceedings{wang2024corelocker,
title={CoreLocker: Neuron-level Usage Control},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Sun, Ruoxi and Wang, Hu and Xue, Minhui and Bai, Guangdong},
booktitle={IEEE Symposium on Security and Privacy (S\&P)},
doi = {10.1109/SP54263.2024.00233},
url = {https://doi.ieeecomputersociety.org/10.1109/SP54263.2024.00233},
pages={2497--2514},
year={2024}
}
OOPSLA'25
@article{ma2025wraact,
title={Convex Hull Approximation for Activation Functions},
author={Ma, Zhongkui and Wang, Zihan and Bai, Guangdong},
journal={Proceedings of the ACM on Programming Languages (OOPSLA)},
volume={9},
number={OOPSLA2},
pages={1007--1033},
doi={10.1145/3763086},
year={2025}
}
USENIX'24
@inproceedings{liu2024purpose,
title={Being Transparent is Merely the Beginning: Enforcing Purpose Limitation with Polynomial Approximation},
author={Liu, Shuofeng and Wang, Zihan and Xue, Minhui and Wang, Long and Zhang, Yuanchao and Bai, Guangdong},
booktitle={33rd USENIX Security Symposium (USENIX Security 24)},
publisher={USENIX Association},
pages={6507--6524},
year={2024}
}
CCS'24
@inproceedings{feng2024grab,
title={Uncovering Gradient Inversion Risks in Practical Language Model Training},
author={Feng, Xinguo and Ma, Zhongkui and Wang, Zihan and Chegne, Eu Joe and Ma, Mengyao and Abuadbba, Alsharif and Bai, Guangdong},
booktitle={Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS)},
pages={3525--3539},
doi={10.1145/3658644.3690292},
year={2024}
}
EuroS&P'26
@inproceedings{wang2025rekey,
title={Re-Key-Free, Risky-Free: Adaptable Model Usage Control},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Yan, Chuan and Liu, Dongge and Sun, Ruoxi and Wang, Derui and Xue, Minhui and Bai, Guangdong},
booktitle={IEEE European Symposium on Security and Privacy (Euro S\&P)},
pages={696--711},
doi={10.1109/EuroSP68448.2026.00051},
year={2026}
}
TDSC'26
@article{wang2026atp,
title={Leveraging Robustness-Aware Channel Activation for Privacy Protection and Tracing Forensics},
author={Wang, Haodi and Wang, Zihan and Dong, Kai and Wang, Jiakai and Liu, Xianglong and Bai, Guangdong},
journal={IEEE Transactions on Dependable and Secure Computing (TDSC)},
volume={23},
number={4},
pages={8745--8759},
doi={10.1109/TDSC.2026.3688154},
year={2026}
}
AsiaCCS'26
@inproceedings{feng2026ghost,
title={Mitigating Gradient Inversion Risks in Language Models via Token Obfuscation},
author={Feng, Xinguo and Ma, Zhongkui and Wang, Zihan and Abuadbba, Alsharif and Bai, Guangdong},
booktitle={Proceedings of the ACM Asia Conference on Computer and Communications Security (AsiaCCS)},
pages={1832--1848},
doi={10.1145/3779208.3785389},
year={2026}
}
Preprint'26
@misc{wang2025nontransfer,
title={Catch-Only-One: Non-Transferable Examples for Model-Specific Authorization},
author={Wang, Zihan and Ma, Zhiyong and Ma, Zhongkui and Liu, Shuofeng and Liu, Akide and Wang, Derui and Xue, Minhui and Bai, Guangdong},
eprint={2510.10982},
archivePrefix={arXiv},
primaryClass={cs.LG},
year={2025}
}
WWW'25
@inproceedings{wang2025aim,
title={AI Model Modulation with Logits Redistribution},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Mei, Zhiyang and Ma, Zhiyong and Wang, Derui and Xue, Minhui and Bai, Guangdong},
year = {2025},
pages = {4699--4709},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3696410.3714737},
doi = {10.1145/3696410.3714737},
booktitle = {Proceedings of the ACM on Web Conference 2025},
location = {Sydney, Australia},
series = {WWW'25}
}
TCSS
@article{wang2023data,
title={Data hiding with deep learning: a survey unifying digital watermarking and steganography},
author={Wang, Zihan and Byrnes, Olivia and Wang, Hu and Sun, Ruoxi and Ma, Congbo and Chen, Huaming and Wu, Qi and Xue, Minhui},
journal={IEEE Transactions on Computational Social Systems},
volume={10},
number={6},
pages={2985--2999},
doi={10.1109/TCSS.2023.3268950},
year={2023},
publisher={IEEE}
}
NeurIPS'22
@inproceedings{hu2022m,
title={M$^4$I: Multi-modal Models Membership Inference},
author={Hu, Pingyi and Wang, Zihan and Sun, Ruoxi and Wang, Hu and Xue, Minhui},
booktitle={Advances in Neural Information Processing Systems},
volume={35},
pages={1867--1882},
year={2022}
}