Chaoyu Zhang

I received my Ph.D. in Computer Science from the Department of Computer Science at Virginia Tech, advised by Professor Wenjing Lou. My dissertation is Building Trustworthy Machine Learning Systems for Security: From Federated Learning to Agentic AI. I was a Research Scientist Intern at TikTok in 2025 and a Research Scientist Intern at Lawrence Livermore National Laboratory in 2019. I received my M.S. in Computer Science from Arkansas State University in 2021, and my B.E. in Electronic Engineering from Beijing University of Posts and Telecommunications in 2018.

Research Interests

My research focuses on Trustworthy AI Systems, spanning AI infrastructure, the machine learning lifecycle, and AI-enabled applications. At the infrastructure layer, I study secure and efficient cloud and distributed systems, communication networks, and heterogeneous computing architectures. At the machine learning layer, I address security, privacy, robustness, and auditability across data, training, fine-tuning, inference, and deployment. At the application layer, I develop and evaluate LLM-based systems, agentic AI, domain-specific applications, and federated learning using red teaming, anomaly detection, safety evaluation, and practical defenses for real-world deployment.

News

  • [Aug. 2026] I received my Ph.D. in Computer Science from Virginia Tech. My dissertation is Building Trustworthy Machine Learning Systems for Security: From Federated Learning to Agentic AI.
  • [Aug. 2026] Our paper ‘Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI’ was published at the 35th USENIX Security Symposium (USENIX Security 2026).
  • [Aug. 2026] Our paper ‘Skynet: Workflow-Level Anomaly Detection for Agentic AI via Semantic and Structural Modeling’ was accepted by the 27th International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing (MobiHoc 2026).
  • [Aug. 2026] Our paper ‘Enabling Emergency Communication via Semantic Radar-Centric ISAC’ was accepted by the IEEE Military Communications Conference (MILCOM 2026).
  • [May 2026] Our paper ‘Hermes: Boosting the Performance of Machine-Learning-Based Intrusion Detection System through Geometric Feature Learning’ was accepted by the IEEE Transactions on Networking (IEEE ToN).
  • [May 2026] Our paper ‘Think Twice Before You Act: Protecting LLM Agents Against Tool Description Poisoning via Isolated Planning’ was accepted by the International Conference on Machine Learning (ICML 2026).
  • [May 2026] Our paper ‘MINIM: Privacy-Aware Minimal View for Agents via Trusted Local Sanitization’ was accepted by the International Conference on Machine Learning (ICML 2026).
  • [May 2026] Our paper ‘ARMOR 2025: A Military-Aligned Benchmark for Evaluating Large Language Model Safety Beyond Civilian Contexts’ was accepted by the International Conference on Military Communication and Information Systems (ICMCIS 2026).
  • [Feb. 2026] Our Wiley-IEEE Press book AI for Cybersecurity: Research and Practice is out. ‘Chapter 3: Machine Learning-based Intrusion Detection Systems: Capabilities, Methodologies, and Open Research Challenges’.
  • [Dec. 2025] Our paper ‘AnonyCall: Enabling Native Private Calling in Mobile Networks’, was accepted by the Network and Distributed System Security Symposium (NDSS 2026).
  • [Aug. 2025] Our paper ‘Enabling Trustworthy Federated Learning via Remote Attestation for Mitigating Byzantine Threats’, was accepted by the IEEE Military Communications Conference (MILCOM 2025).
  • [Feb. 2025] Our paper ‘MedLeak: Harvesting Multimodal Medical Data in Secure Federated Learning with Crafted Models’, was accepted by the IEEE/ACM Conference on Connected Health: Applications, Systems, and Engineering Technologies (CHASE 2025).
  • [Feb. 2025] Our paper ‘StarCast: A Secure and Spectrum-Efficient Group Communication Scheme for LEO Satellite Networks’, was accepted by the IEEE International Symposium on Dynamic Spectrum Access Networks (DySPAN 2025).
  • [Dec. 2024] Our paper ‘FLARE: Defending Federated Learning against Model Poisoning Attacks via Latent Space Representations’, was accepted by the IEEE Transactions on Dependable and Secure Computing (TDSC).
  • [Nov. 2024] Our paper ‘Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space Reconstruction’, was accepted by the Network and Distributed System Security Symposium (NDSS 2025).
  • [Aug. 2024] Our paper ‘ProFLingo: A Fingerprinting-based Intellectual Property Protection Scheme for Large Language Models’, won best paper award at the IEEE Conference on Communications and Network Security 2024 (CNS 2024).
  • [Aug. 2024] Our paper ‘ProFLingo: A Fingerprinting-based Intellectual Property Protection Scheme for Large Language Models’, was accepted by the IEEE Conference on Communications and Network Security 2024 (CNS 2024).
  • [Aug. 2024] Our paper ‘Hermes: Boosting the Performance of Machine-Learning-Based Intrusion Detection System through Geometric Feature Learning’, was accepted by the 25th International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing (MobiHoc 2024).
  • [Aug. 2023] Our paper ‘MINDFL: Mitigating the Impact of Imbalanced and Noisy-labeled Data in Federated Learning with Quality and Fairness-Aware Client Selection’ was accepted by the IEEE Military Communications Conference (MILCOM 2023).
  • [Aug. 2023] Our paper ‘Bijack: Breaking Bitcoin Network with TCP Vulnerabilities’ was accepted by the 28th European Symposium on Research in Computer Security (ESORICS 2023).