RESEARCH

Every layer of our digital infrastructure is now shaped by complex intelligent systems - and every layer is a potential attack surface. Adversaries can blind autonomous vehicles by manipulating LiDAR inputs, infer sensitive attributes from generative model outputs, or extract private data from gradients shared in federated learning.

 

My research asks: "how do we build AI-integrated systems that are not just functional, but trustworthy; secure against adversarial manipulation, private by design, and accountable to the norms and regulations governing their deployment?"

 

Building on work spanning OS-level access control, ML model privacy, cyber-physical systems security, and generative AI, I am developing the technical foundations — adversarial robustness, privacy-preserving mechanisms, and neuro-symbolic policy enforcement — that will make the next generation of AI systems worthy of the trust we place in them. 

 

Below are some examples of my work.

                  

Safety, Security, and Privacy in Machine Learning

 

My work spans the full threat model for ML systems: physical-world evasion attacks, model and data privacy mechanisms, and policy compliance in generative models.                  

 

ML safety and policy compliance. I am developing neuro-symbolic methods that make norm violations in LLMs and text-to-image systems machine-readable and auditable using structured argumentation (NeSyDebates, EPSRC/JST 2026–2031), and selective fine-tuning approaches for targeted concept unlearning in generative models (Mansi, arXiv '26).

 

Evasion attacks and adversarial robustness. I study attacks against LiDAR-based 3D object detectors in autonomous vehicles — exploiting geometric and shadow inconsistencies to inject ghost objects (Hau et al, ESORICS '21; Hau et al, IEEE S&P Workshops '22), crafting adversarial 3D virtual patches via integrated gradients (You et al, IEEE S&P Workshops '24 — Best Paper Award), and revealing detector failures under adverse weather (Capraru et al, IROS '24).

 

Privacy-preserving mechanisms. I develop techniques to protect model confidentiality and training data — including model privacy at the edge using Trusted Execution Environments (Mo et al., MobiSys '20) and quantifying gradient-based information leakage in federated learning (Mo et al., DPML@ICLR '21) — and study privacy violations in generative systems: attribute leakage in text-to-image generation (Lepipas et al., PETS '25) and knowledge-distillation-based and prosody-driven approaches to dementia obfuscation in speech (Woszczyk et al., PETS '25; Woszczyk et al., Interspeech '24; Woszczyk et al., Interspeech '25).   

 

Robustness and Performance of Computer Systems

 

Mobile and IoT Security. I study how operating system and platform abstractions expose users to adversarial exploitation. This includes access control failures in Android (Demetriou et al, NDSS '15; Demetriou et al, NDSS '16; Tuncay et al, NDSS '18 — Distinguished Paper Award), unauthorised data exfiltration by advertising libraries (Demetriou et al, NDSS '16), side-channels (Zhou et al, CCS '13), and smart home device protection via SDN-driven policy enforcement (Demetriou et al, WiSec '17) among others.            

 

Large-Scale Systems. I have collaborated with several infrastructure teams within Meta on hyperscale performance and reliability issues, including hyperscale serverless execution (Sahraei et al, SOSP '23), service mesh architecture (Saokar et al, OSDI '23), continuous software deployment (Grubic et al, OSDI '23), and mobile configurations (Guo et al, NSDI '24).