I will be joining the DSAI Department at The Hong Kong Polytechnic University (PolyU) as a tenure-track Assistant Professor. I am recruiting PhDs for 27Fall, Postdocs, RAs, and research interns. If you are interested, please email me at lxfmakeit@gmail.com.

I am a Research Fellow in the College of Computing and Data Science at NTU, working with Prof. XiaoFeng Wang and Prof. Wei Dong. I completed my Ph.D. with honors at Zhejiang University, co-supervised by Prof. Wenyuan Xu, Prof. Xiaoyu Ji, and Prof. Chen Yan. Previously, I obtained my B.Eng. with honors, also from Zhejiang University.

My research focuses on AI security and privacy, especially the security, privacy, and safety of multimodal LLMs & agentic AI systems. I study how to secure interactions between agentic AI systems and the real world. My goal is to help AI agents become robust and responsible partners. Robust agents should be resilient to external attacks, and responsible agents should behave in a helpful, harmless, and honest manner. My work has appeared in security and AI/ML venues including IEEE S&P, ACM CCS, USENIX Security, NDSS, NeurIPS, ICML, ICLR, KDD, CVPR, ACL, TDSC, and TIFS.

My group is broadly interested in the following research directions:

  • Security and Privacy of Agentic AI Systems: building robust and responsible agentic AI systems and protecting their interactions with the physical and digital world.
  • Responsible AI in Social Contexts: improving the safety, security, and privacy of multi-agent and human-agent interactions, as well as addressing risks in multimodal AIGC (e.g., deepfake generation and detection).
  • Trustworthy AI for X (e.g., Science, Systems): enabling reliable AI deployment in healthcare, power grids, software engineering, IoT, and telecommunications systems.

If you are seeking academic collaboration or are interested in joining my lab, please feel free to email me at lxfmakeit(at)gmail.com or xinfeng.li(at)ntu.edu.sg.

News

  • 2026.04:  A-MemGuard and CentaurEval have been accepted to ICML 2026. Congrats to all collaborators.
  • 2026.03:  GIFT has been accepted to IEEE S&P 2026. Congrats to Lixu and all collaborators.
  • 2026.01:  Refusal-Index and PISTOLE have been accepted to ICLR 2026. Congrats to all collaborators.
  • 2025.11:  EmoRAG has been accepted to SIGKDD 2026. It’s great working with Xinyun to investigate RAG robustness.
  • 2025.10:  WebCloak, EnchTable have been accepted to S&P 2026. Congratulations to Jialin and all collaborators.
  • 2025.09:  AgentAuditor has been accepted to NeurIPS 2025. Congratulations to Hanjun and Shenyu.
  • 2025.06:  AudioTrust has been accepted to ICLR’26! We hope this can serve as a solid foundation for academia and industry for safe audio-based LLM system development. [Github] (Media Coverage: [量子位])
  • 2025.06:  Neural Invisibility Cloak has been accepted to USENIX Security’25. Congratulations to Wenjun.
  • 2025.04:  Led/Contributed to 3 (Trustworthy) LLM Agent survey papers are now released: (1) TrustAgent: A survey on trustworthy LLM agents: Threats and countermeasures [Paper (accepted to KDD’25)]; (2) Advances and challenges in foundation agents: From brain-inspired intelligence to evolutionary, collaborative, and safe systems [Paper Github] [HuggingFace] (Media Coverage, e.g., [SANER, 机器之心]); (3) A Comprehensive Survey in LLM (-Agent) Full Stack Safety: Data, Training, and Deployment.
  • 2024.11:  LightAntenna has been accepted to NDSS 2025.
  • 2024.08:  Raconteur has been accepted to NDSS 2025 [website].
  • 2024.08:  Legilimens has been accepted to CCS 2024.
  • 2024.05:  SafeGen has been accepted to CCS 2024! More information is on [code][pretrained model].
  • 2024.05:  SafeEar has been accepted to CCS 2024! More information is on [website][code].
  • 2023.08:  VRifle has been accepted to NDSS 2024.
  • 2023.08:  I attended the USENIX Security 2023 Symposium and presented our work NormDetect in person.
  • 2023.07:  SMA has been accepted to ACM MM 2023.
  • 2022.09:  Tuner and UltraBD were accepted to IoT-J 2023 and ICPADS 2022.
  • 2022.07:  NormDetect has been accepted to USENIX Security 2023.
  • 2021.07:  PROLE Score has been accepted to USENIX Security 2022.
  • 2020.12:  EarArray has been accepted to NDSS 2021.

📝 Selected Research

(*: Equal Contribution, ^: Corresponding Author)

📚 Professional Services

I actively contribute to the academic community through program organization and peer review for leading conferences and journals in security, AI, and systems.

Program Organization

  • KDD 2025: Tutorial Organizer

Conference

  • Area Chair: NeurIPS, ICLR’26
  • PC Member: AsiaCCS’27, CCS’26, SaTML’26, AAAI’26
  • Reviewer: ICML’26, CVPR’26
  • External Reviewer: IEEE S&P’19, ‘20; CCS’21, ‘22, ‘23, ‘24; USENIX Security’19, ‘20, ‘21, ‘24; NDSS’20, ‘22, ‘23, ‘24

Journal

  • Reviewer: IEEE TIFS, TDSC, TMC, TNNLS, TOSEM, IoT-J, TOIT, TCCN; ACM TOPS; IJCV.

🎖 Honors and Awards

  • ACM SIGSAC China Doctoral Dissertation Award (1st), 2025
  • CCS 2024 Student Grant, 2024
  • NDSS 2024 Student Grant, 2024
  • WANG G.S. PhD Research Excellence Award, 2023
  • Best Security Partner Award (OPPO Inc.), 2022
  • Edison Honors Class@ZJU, Outstanding Graduate Award, 2019
  • EE@ZJU Top-10 Scholars Award, 2018
  • National Scholarship, 2018