Elwood’s website

I am a PhD student at State Key Laboratory of Complex and Critical Software Environment at the Beihang University (BUAA), advised by Prof. Dacheng Tao and Prof. Xianglong Liu. I also work closely with Prof. Aishan Liu.

Prior to BUAA, I obtained my M.Sc. from the School of Cyber Security, University of Chinese Academy of Sciences. I also served as a research assistant at the State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences. Before that, I had internship experience at SIP Lab@Sangfor and Security Research Labs@Qihoo 360. I serve as a reviewer for top-tier conferences and journals, including TPAMI, NeurIPS, ICML, ICLR, TIFS, TDSC, CVPR, ACL, AISTATS, COLING, ECCV, and EMNLP.

New Supported by CIE-Tencent Doctoral Research Incentive Project (混元学者/中国电子学会—腾讯博士生科研激励计划).

New Selected for the Tencent PROJECT UP Talent Program (腾讯青云计划).

New Selected for the 2026 Tencent Rhino-Bird Research Elite Program (犀牛鸟精英人才计划).

Research Interests

  • Trustworthy Machine Learning
    Safety, Privacy, Security and etc.
  • Cyberspace Security
    Software security, Network security, IoT security and etc.
Announcement: If you are seeking any form of academic cooperation, please feel free to contact me.

Contact

Email: yingzonghao20[AT]mails[DOT]ucas[DOT]edu[DOT]cn, yingzonghao[AT]buaa[DOT]edu[DOT]cn

Address: No.37 Xueyuan Road, Beijing, China

News and Updates

📄 Papers

  • 07/2026 One co-author paper accepted by Applied Soft Computing.
  • 07/2026 Three papers (one first-author, two co-author) accepted by ACM MM 2026.
  • 06/2026 One co-author paper accepted by ESORICS 2026.
  • 05/2026 Our paper RoboSafe is awarded the Outstanding Paper Award in ESR@ICLR 2026.
  • 05/2026 One first-author paper accepted by ICML 2026.
  • 04/2026 A first-author paper and two co-author papers have been accepted by ACL 2026.
  • 02/2026 One first-author paper accepted by CVPR 2026.
  • 01/2026 One first-author paper accepted by ICASSP 2026.
  • 01/2026 One co-author paper accepted by Neurocomputing.
  • 01/2026 One co-author paper accepted by Transactions on Dependable and Secure Computing.
  • 11/2025 One corresponding-author paper accepted by PersonaNLP@NeurIPS 2025.
  • 11/2025 One first-author paper accepted by International Journal of Computer Vision.
  • 08/2025 One co-author paper accepted by NeurIPS 2025.
  • 08/2025 One first-author paper accepted by EMNLP 2025.
  • 07/2025 Our paper AgentSafe is awarded the Outstanding Paper Award in MAS@ICML 2025.
  • 07/2025 One first-author paper accepted by ACM MM 2025.
  • 06/2025 Two first-author papers accepted by IEEE TIFS and MAS@ICML 2025.
  • 06/2025 One co-author paper accepted by Electronics.

📝 Preprints

  • 05/2026 "TrajShield: Trajectory-Level Safety Mediation for Defending Text-to-Video Models Against Jailbreak Attacks" arXiv
  • 04/2026 "AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization" arXiv
  • 06/2025 "Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025 (AdvML@CVPR 2025)" arXiv
  • 03/2025 "Towards Understanding the Safety Boundaries of DeepSeek Models: Evaluation and Findings" arXiv

🏆 Tech Reports & Works

  • 06/2026 "Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming" arXiv
  • AI-Infra-Guard: A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation. GitHub
  • ClawGuard: A security toolkit designed to mitigate risks associated with autonomous agents (e.g., OpenClaw), featuring Auditor (pre-installation audit), Checker (configuration check), and Detect (runtime monitoring) modules. GitHub
  • pikit: A composable toolbox of classic prompt-injection attacks, defenses, and indirect-injection channels. GitHub
  • AgentSafety-Papers: A daily-updated tracker of LLM Agent security papers on arXiv, with keyword-based smart classification. GitHub
  • SecAI_Radar: Tracking AI security papers from top-tier AI & security conferences (CCF-A and above), filtered by keywords. Project GitHub
  • 06/2024 "Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks" arXiv Coverage
  • 02/2025 I serve as the Challenge Chair for the 5th Workshop of Adversarial Machine Learning on Computer Vision: Foundation Models + X on CVPR 2025. Please submit your papers and participate the challenge to win prizes!
  • 11/2024 I won champions both in Team Category and Individual Category, Singapore AI Safety Red Teaming Challenge.
  • 07/2024 I was certified as a Senior Lecturer in Cybersecurity by Cyber Security Association of China.
  • 07/2024 I won second prize in the Google Gemma Hackathon!
  • 06/2023 I obtained my M.Sc from Chinese Academy of Sciences.