I am a Research Fellow at the University of Queensland, previously a visiting scientist at CSIRO. My research focuses on AI usage control: how to govern the way trained models and their training data can be reused, repurposed, or queried after release. It spans two directions:
I am fortunate to be advised by A/Prof. Guangdong Bai, Dr. Jason Xue, and Dr. Naipeng Dong. My PhD research was generously supported by the Australian Government RTP Scholarship and the CSIRO Top-up Scholarship, and I was the recipient of the 2024 Google PhD Fellowship in Security, Privacy, and Abuse Prevention.
I serve on the program committees of top-tier security conferences such as USENIX Security, and as a reviewer for leading machine learning venues such as NeurIPS, ICLR, and CVPR. I also serve as the HDR representative for the CSS discipline.
Model Usage Control
Data Usage Control
S&P'24
@inproceedings{wang2024corelocker,
title={CoreLocker: Neuron-level Usage Control},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Sun, Ruoxi and Wang, Hu and Xue, Minhui and Bai, Guangdong.},
booktitle={IEEE Symposium on Security and Privacy (S\&P)},
doi = {10.1109/SP54263.2024.00182},
url = {https://doi.ieeecomputersociety.org/10.1109/SP54263.2024.00182},
pages={2497--2514},
year={2024}
}
EuroS&P'26
@inproceedings{wang2025rekey,
title={Re-Key-Free, Risky-Free: Adaptable Model Usage Control},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Yan, Chuan and Liu, Dongge and Sun, Ruoxi and Wang, Derui and Xue, Minhui and Bai, Guangdong},
booktitle={Proc. of Euro S\&P},
year={2026}
}
Preprint'25
@inproceedings{wang2025nontransfer,
title={Catch-Only-One: Non-Transferable Examples for Model-Specific Authorization},
author={Wang, Zihan and Ma, Ethan and Ma, Zhongkui and Liu, Shuofeng and Liu, Akide and Wang, Derui and Xue, Minhui and Bai, Guangdong},
booktitle={arXiv preprint arXiv:2510.10982},
year={2025}
}
WWW'25
@inproceedings{wang2025aim,
title={AI Model Modulation with Logits Redistribution},
author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Mei, Zhiyang and Ma, Zhiyong and Wang, Derui and Wang, Hu and Xue, Minhui and Bai, Guangdong.},
year = {2025},
publisher = {Association for Computing Machinery},
address = {New York, NY, USA},
url = {https://doi.org/10.1145/3696410.3714737},
doi = {10.1145/3696410.3714737},
booktitle = {Proceedings of the ACM Web Conference 2025},
location = {Sydney, Australia},
series = {WWW'25}
}
OOPSLA'25
@inproceedings{}
TCSS
@article{wang2023data,
title={Data hiding with deep learning: a survey unifying digital watermarking and steganography},
author={Wang, Zihan and Byrnes, Olivia and Wang, Hu and Sun, Ruoxi and Ma, Congbo and Chen, Huaming and Wu, Qi and Xue, Minhui},
journal={IEEE Transactions on Computational Social Systems},
year={2023},
publisher={IEEE}
}
NeurIPS'22
@inproceedings{hu2022m,
title={M $\^{} 4$ I: Multi-modal Models Membership Inference},
author={Hu, Pingyi and Wang, Zihan and Sun, Ruoxi and Wang, Hu and Xue, Minhui},
journal={Advances in Neural Information Processing Systems},
volume={35},
pages={1867--1882},
year={2022}
}
USENIX'24
@inproceedings{liu2024purpose,
title={Being Transparent is Merely the Beginning: Enforcing Purpose Limitation with Polynomial Approximation},
author={Liu, Shuofeng and Wang, Zihan and Xue, Minhui and Wang, Long and Zhang, Yuanchao and Bai, Guangdong.},
journal={USENIX Security},
year={2024}
}
CCS'24
@inproceedings{
}
WACV'24
@inproceedings{liu2024bpkd,
title={BPKD: Boundary Privileged Knowledge Distillation For Semantic Segmentation},
author={Liu, Liyang and Wang, Zihan and Phan, Minh Hieu and Zhang, Bowen and Ge, Jinchao and Liu, Yifan},
booktitle={Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision},
pages={1062--1072},
year={2024}
}