Research
Our work spans AI, security, and systems.
AI
AI is now both a target and an instrument of security research. We study how AI systems fail under adversarial pressure and how to make them more reliable, robust, and trustworthy. Our work examines jailbreak attacks against text-to-image models (PC²), safety vulnerabilities and defenses in Mixture-of-Experts LLMs (MoEvil, SafeMoE), unlearning-based adversarial attacks, and backdoor attacks and defenses (Obliviate, CGBA). In parallel, we apply modern machine learning and natural language processing techniques to security problems, including pretrained dark-web language models (DarkBERT), credential reuse prediction at scale (PassREfinder), and illicit drug detection in online communities (JEDIS).
- Adversarial ML — PC², SafeMoE, MoEvil, Obliviate, CGBA, Refusal Is Not an Option
- AI for Security — DarkBERT, PassREfinder, JEDIS
- AI Misuse — When LLMs Go Online
Security
Our founding mission is to reveal threats and defend networked systems. We pair deep system understanding with offensive and defensive research: tracing intrusions to their root cause via security provenance (SECTRACER), fuzzing and fingerprinting SDN/SD-WAN control planes (Ambusher, Heimdallr), uncovering micro-architectural and timing side channels (AVXProbe, AVX-TSCHA), hardening anonymity networks against deanonymization and network topology against inference (MUFFLER, EqualNet), and attacking permissionless blockchains and detecting their abuse (Partitioning Ethereum, CENSor).
- Network & SDN security — SECTRACER, Ambusher
- Side-channel & micro-architectural attacks — AVXProbe, AVX-TSCHA
- Blockchain & threat intelligence — Partitioning Ethereum, Vulcan
System
Systems are now expected to be fast and secure at once. We study how to deliver both without compromise, using hardware/software co-design to make security efficient. Our work accelerates service-mesh ingress on SmartNICs (HybridMesh, HardMesh), gives containers RDMA-aware and hardware-isolated networking (RDNet, Hyperion, HardWhale), and embeds line-rate inspection into SDN/NFV with reconfigurable hardware (Reinhardt). In parallel, we cut the overhead of confidential serverless with fast snapshots and acceleration (AccelFaaS, TDSnap, Cryonics).
- SmartNIC & service-mesh acceleration — HybridMesh, HardMesh
- Confidential serverless / FaaS — AccelFaaS, TDSnap, Cryonics
- Secure container & in-network systems — RDNet, Hyperion, Reinhardt