I am a PhD student at the University of Queensland, working under the supervision of A/Prof. Guangdong Bai and Dr. Jason Xue. I’m currently serving as the HDR representative for the CSS discipline. My research is generously supported by the RTP Scholarship and CSIRO’s Data61 Top-up Scholarship. I am also honored with the Google PhD Fellowship, 2024.
My research interests are to tackle real-world security & privacy issues of machine learning systems in a formally verifiable manner. My works have been published in leading venues, including IEEE S&P, ACM CCS, USENIX Security, NeurIPS, WWW, WACV, and IEEE TCSS. I also work closely with my colleague Zhongkui Ma on NNV. Some of my recent projects include:
@inproceedings{wang2025aim, title={AI Model Modulation with Logits Redistribution}, author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Mei, Zhiyang and Ma, Zhiyong and Wang, Derui and Wang, Hu and Xue, Minhui and Bai, Guangdong.}, year = {2025}, publisher = {Association for Computing Machinery}, address = {New York, NY, USA}, url = {https://doi.org/10.1145/3696410.3714737}, doi = {10.1145/3696410.3714737}, booktitle = {Proceedings of the ACM Web Conference 2025}, location = {Sydney, Australia}, series = {WWW'25} }
@inproceedings{wang2024corelocker, title={CoreLocker: Neuron-level Usage Control}, author={Wang, Zihan and Ma, Zhongkui and Feng, Xinguo and Sun, Ruoxi and Wang, Hu and Xue, Minhui and Bai, Guangdong.}, booktitle={IEEE Symposium on Security and Privacy (S\&P)}, doi = {10.1109/SP54263.2024.00182}, url = {https://doi.ieeecomputersociety.org/10.1109/SP54263.2024.00182}, pages = {222-222}, year={2024} }
@inproceedings{liu2024purpose, title={Being Transparent is Merely the Beginning: Enforcing Purpose Limitation with Polynomial Approximation}, author={Liu, Shuofeng and Wang, Zihan and Xue, Minhui and Wang, Long and Zhang, Yuanchao and Bai, Guangdong.}, journal={USENIX Security}, year={2024} }
@inproceedings{ }
@article{wang2023data, title={Data hiding with deep learning: a survey unifying digital watermarking and steganography}, author={Wang, Zihan and Byrnes, Olivia and Wang, Hu and Sun, Ruoxi and Ma, Congbo and Chen, Huaming and Wu, Qi and Xue, Minhui}, journal={IEEE Transactions on Computational Social Systems}, year={2023}, publisher={IEEE} }
@inproceedings{hu2022m, title={M $\^{} 4$ I: Multi-modal Models Membership Inference}, author={Hu, Pingyi and Wang, Zihan and Sun, Ruoxi and Wang, Hu and Xue, Minhui}, journal={Advances in Neural Information Processing Systems}, volume={35}, pages={1867--1882}, year={2022} }
@inproceedings{liu2024bpkd, title={BPKD: Boundary Privileged Knowledge Distillation For Semantic Segmentation}, author={Liu, Liyang and Wang, Zihan and Phan, Minh Hieu and Zhang, Bowen and Ge, Jinchao and Liu, Yifan}, booktitle={Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision}, pages={1062--1072}, year={2024} }