I am currently a Research Fellow at NTU. I completed my Ph.D. with honors at Zhejiang University. Previously, I obtained my B.Eng with honors also from Zhejiang University.

My research is broadly in the fields of (1) Trustworthy AI and LLM & Agent Safety, with a special focus on the safety and privacy of multimodal and agentic AI systems, and (2) Responsible AI for Intelligent System Dependability, particularly for ensuring robustness and reliability in critical IoT, communication, and software systems.

In AI-oriented contexts, I focus on developing trustworthy intelligent audio and vision models, safeguarding user privacy, and fortifying generative models against various leaks and attacks. I also regulate AI behavior to ensure alignment with societal responsibilities, especially in the context of large language models such as Stable Diffusion and GPT-4.

In system-oriented contexts, I work toward developing dependable and secure machine learning (ML) systems and am committed to their application for deployment in critical infrastructures and consumer electronics, e.g., in the domain of audio/vision-interface IoT devices, carrier networks, and software systems.

If you are seeking any form of academic cooperation, please feel free to email me at xinfeng.li(at)ntu.edu.sg or lxfmakeit(at)gmail.com.

I have published over 20 papers in top-tier international security, AI, and mobile sensing conferences and journals, such as IEEE S&P, ACM CCS, USENIX Security, NDSS, NeurIPS, ICLR, KDD, TDSC, TIFS, ICCV.

News

  • 2026.03:  GIFT has been accepted to IEEE S&P 2026. Congrats to Lixu and all collaborators.
  • 2025.11:  EmoRAG has been accepted to SIGKDD 2026. It’s great working with Xinyun to investigate RAG robustness.
  • 2025.10:  WebCloak, EnchTable have been accepted to S&P 2026. Congratulations to Jialin and all collaborators.
  • 2025.09:  AgentAuditor has been accepted to NeurIPS 2025. Congratulations to Hanjun and Shenyu.
  • 2025.06:  AudioTrust has been accepted to ICLR’26! We hope this can serve as a solid foundation for academia and industry for safe audio-based LLM system development. [Github] (Media Coverage: [量子位])
  • 2025.06:  Neural Invisibility Cloak has been accepted to USENIX Security’25. Congratulations to Wenjun.
  • 2025.04:  Lead/Contributed to 3 (Trustworthy) LLM Agent survey papers are now released: (1) TrustAgent: A survey on trustworthy LLM agents: Threats and countermeasures [Paper (accepted to KDD’25)]; (2) Advances and challenges in foundation agents: From brain-inspired intelligence to evolutionary, collaborative, and safe systems [Paper Github] [HuggingFace] (Media Coverage, e.g., [SANER, 机器之心]); (3) A Comprehensive Survey in LLM (-Agent) Full Stack Safety: Data, Training, and Deployment.
  • 2024.11:  LightAntenna has been accepted to NDSS 2025.
  • 2024.08:  Raconteur has been accepted to NDSS 2025 [website].
  • 2024.08:  Legilimens has been accepted to CCS 2024.
  • 2024.05:  SafeGen has been accepted to CCS 2024! More information is on [code][pretrained model].
  • 2024.05:  SafeEar has been accepted to CCS 2024! More information is on [website][code].
  • 2023.08:  VRifle has been accepted to NDSS 2024.
  • 2023.08:  I attended the USENIX Security 2023 Symposium and presented our work NormDetect in person.
  • 2023.07:  SMA has been accepted to ACM MM 2023.
  • 2022.09:  Tuner and UltraBD were accepted to IoT-J 2023 and ICPADS 2022.
  • 2022.07:  NormDetect has been accepted to USENIX Security 2023.
  • 2021.07:  PROLE Score has been accepted to USENIX Security 2022.
  • 2020.12:  EarArray has been accepted to NDSS 2021.

📝 Selected Research

(*: Equal Contribution, ^: Corresponding Author)

📚 Professional Services

I actively contribute to the academic community through program organization and peer review for leading conferences and journals in security, AI, and systems.

Program Organization

  • KDD 2025: Tutorial Organizer

Conference

  • ICLR: Area Chair (2026)
  • PC Member: AsiaCCS’27, CCS’26, SaTML’26, AAAI’26
  • Reviewer: ICML’26, CVPR’26
  • S&P: External Reviewer (2019, 2020)
  • CCS: External Reviewer (2021, 2022, 2023, 2024)
  • USENIX Security: External Reviewer (2019, 2020, 2021, 2024)
  • NDSS: External Reviewer (2020, 2022, 2023, 2024)

Journal

  • IEEE Transactions on Information Forensics and Security (TIFS)
  • IEEE Transactions on Dependable and Secure Computing (TDSC)
  • IEEE Transactions on Neural Networks and Learning Systems (TNNLS)
  • ACM Transactions on Software Engineering and Methodology (TOSEM)
  • IEEE Internet of Things Journal (IoT-J)
  • ACM Transactions on Privacy and Security
  • ACM Transactions on Internet Technology (TOIT)
  • IEEE Transactions on Cognitive Communications and Networking (TCCN)

🎖 Honors and Awards

  • ACM SIGSAC China Doctoral Dissertation Award (1st), 2025
  • CCS 2024 Student Grant, 2024
  • NDSS 2024 Student Grant, 2024
  • WANG G.S. PhD Research Excellence Award, 2023
  • Best Security Partner Award (OPPO Inc.), 2022
  • Edison Honors Class@ZJU, Outstanding Graduate Award, 2019
  • EE@ZJU Top-10 Scholars Award, 2018
  • National Scholarship, 2018

📖 Educations

  • 2019.06 - 2024.06, Ph.D., Zhejiang University, Hangzhou.
  • 2015.09 - 2019.06, Undergraduate, College of Electrical Engineering, Zhejiang University, Hangzhou.

💬 Invited Talks

  • 2024.10, ACM CCS 2024 at Salt Lake City, USA.
  • 2024.02, NDSS 2024 at San Diego, California, USA. | [Paper] | [Code]
  • 2023.08, USENIX Security Symposium 2023 at Anaheim, California, USA. | [Slides]

🗺️ Visitor Map