My research is on the security of AI — not only the model, but the supporting infrastructure around it.
I am looking for self-motivated students to work on trustworthy machine learning and machine learning for security. Please fill out the questionnaire and send me an email.
A note on my name. I am Mongolian, from China. My preferred full name is Suyee Urcuud — Urcuud is my family name. Suya is the Chinese transliteration of Suyee, and it is the only name on my passport; US paperwork then required a surname, so Fnu ("first name unknown") was assigned as a placeholder and has followed me through every document since. Suyee or Suya both work. I have not yet worked out how to persuade a passport office to print both.
LLM APIs bill by the token, but the customer cannot verify the count. We study how a dishonest provider can inflate billed usage and what auditing is possible.
@misc{hoque2026token,title={Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage},author={Hoque, Shahinul and Zhang, Jinghuai and Sun, Jinyuan and Suya, Fnu},year={2026},}
CCS
(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
Habibur Rahaman*, Qipan Xu*, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, and Fnu Suya
In ACM Conference on Computer and Communications Security, 2026
Modern ML pipelines depend on third-party libraries for graph compilation and hardware acceleration, but the execution environment itself remains implicitly trusted. (A)iSpy is a parasitic runtime Trojan that observes transient tensor state to exfiltrate training hyperparameters and to amplify weak data poisoning into backdoors with near-100% success, while evading standard malware scanners and model inspection.
@inproceedings{rahaman2026aispy,peerreviewed={true},title={(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure},author={Rahaman, Habibur and Xu, Qipan and Haider, Zafaryab and Chakraborty, Prabuddha and Bhunia, Swarup and Suya, Fnu},booktitle={ACM Conference on Computer and Communications Security},year={2026},}
Hubness makes a few points in a high-dimensional space unusually close to many others. We show an adversary can turn any image or audio input into an adversarial hub retrieved for thousands of unrelated queries, and that standard hubness mitigations do not defend against concept-targeted hubs.
@inproceedings{zhang2026advhub,peerreviewed={true},title={Adversarial Hubness in Multi-Modal Retrieval},author={Zhang, Tingwei and Suya, Fnu and Jha, Rishi and Zhang, Collin and Shmatikov, Vitaly},booktitle={IEEE Symposium on Security and Privacy},year={2026},pages={329--344},}
USENIX Sec
HAMLOCK: HArdware-Model LOgically Combined attacK
Sanskar Amgain*, Daniel Lobo*, Atri Chatterjee*, Swarup Bhunia, and Fnu Suya
HAMLOCK distributes backdoor logic across the hardware-software boundary: the model is only minimally altered, and a hardware Trojan watches a few neurons’ activations and manipulates output logits directly. Because the model contains no complete backdoor activation path, it appears fully benign and circumvents state-of-the-art model-level defenses, at hardware overheads as low as 0.01%.
@inproceedings{amgain2026hamlock,peerreviewed={true},title={HAMLOCK: HArdware-Model LOgically Combined attacK},author={Amgain, Sanskar and Lobo, Daniel and Chatterjee, Atri and Bhunia, Swarup and Suya, Fnu},booktitle={USENIX Security Symposium},year={2026},}
SaTML
SoK: Pitfalls in Evaluating Black-Box Attacks
Fnu Suya*, Anshuman Suri*, Tingwei Zhang, Jingtao Hong, Yuan Tian, and David Evans
In IEEE Conference on Secure and Trustworthy Machine Learning, 2024
We organize the black-box attack literature along the axes of what the adversary actually knows and can query, and show that many reported comparisons are confounded by mismatched threat models.
@inproceedings{suya2024sok,peerreviewed={true},title={SoK: Pitfalls in Evaluating Black-Box Attacks},author={Suya, Fnu and Suri, Anshuman and Zhang, Tingwei and Hong, Jingtao and Tian, Yuan and Evans, David},booktitle={IEEE Conference on Secure and Trustworthy Machine Learning},year={2024},}
NeurIPS
What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?
Fnu Suya, Xiao Zhang, Yuan Tian, and David Evans
In Advances in Neural Information Processing Systems, 2023
We characterize optimal indiscriminate poisoning for linear learners and prove that well-separated, low-variance class-conditional distributions with small constraint sets are inherently resistant, explaining the wide variation in attack success across benchmark datasets.
@inproceedings{suya2023distributions,peerreviewed={true},title={What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?},author={Suya, Fnu and Zhang, Xiao and Tian, Yuan and Evans, David},booktitle={Advances in Neural Information Processing Systems},year={2023},}
TIFS
Stealthy Backdoors as Compression Artifacts
Yulong Tian, Fnu Suya, Fengyuan Xu, and David Evans
IEEE Transactions on Information Forensics and Security, 2022
A backdoor can be hidden so that it only materializes once the model is compressed, so the shipped full-precision model looks clean.
@article{tian2022stealthy,peerreviewed={true},title={Stealthy Backdoors as Compression Artifacts},author={Tian, Yulong and Suya, Fnu and Xu, Fengyuan and Evans, David},journal={IEEE Transactions on Information Forensics and Security},year={2022},}
2026
arXiv
RogueMerge: Robust and Unified Attacks against LLM Model Merging
Jinghuai Zhang, Yetian He, Kunlin Cai, Han Zhao, Fnu Suya, and Yuan Tian
Model merging combines independently fine-tuned models into a single multi-task model without retraining. We study attacks that survive this merging process.
@misc{zhang2026roguemerge,title={RogueMerge: Robust and Unified Attacks against LLM Model Merging},author={Zhang, Jinghuai and He, Yetian and Cai, Kunlin and Zhao, Han and Suya, Fnu and Tian, Yuan},year={2026},}
arXiv
ImageAuditor: Membership Inference Attack against Image-based Retrieval-Augmented Generation
We show that the retrieval corpus behind an image-based RAG system leaks membership, letting an adversary determine whether a given image was indexed.
@misc{zhang2026imageauditor,title={ImageAuditor: Membership Inference Attack against Image-based Retrieval-Augmented Generation},author={Zhang, Jinghuai and Yu, Pengyue and Lin, Zhexiao and Cai, Kunlin and Suya, Fnu and Tian, Yuan},year={2026},}
arXiv
Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage
Shahinul Hoque, Jinghuai Zhang, Jinyuan Sun, and Fnu Suya
LLM APIs bill by the token, but the customer cannot verify the count. We study how a dishonest provider can inflate billed usage and what auditing is possible.
@misc{hoque2026token,title={Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage},author={Hoque, Shahinul and Zhang, Jinghuai and Sun, Jinyuan and Suya, Fnu},year={2026},}
arXiv
What-If World: A Causal Benchmark for General World Models in Embodied Scenarios
A benchmark for evaluating whether world models capture causal structure rather than surface correlation in embodied settings.
@misc{cai2026whatif,title={What-If World: A Causal Benchmark for General World Models in Embodied Scenarios},author={Cai, Kunlin and Song, Rui and Zhang, Jinghuai and Zhang, Kaiyuan and Bodapati, Pranav and Yu, Alicia and Suya, Fnu and Rostami, Mohammad and Ma, Jiaqi and Tian, Yuan},year={2026},}
arXiv
LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models
Abdullah Al Nomaan Nafi, Fnu Suya, Swarup Bhunia, and Prabuddha Chakraborty
A black-box jailbreaking method that adaptively hybridizes semantic rewrites of a prompt to evade safety alignment.
@misc{nafi2026lash,title={LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models},author={Nafi, Abdullah Al Nomaan and Suya, Fnu and Bhunia, Swarup and Chakraborty, Prabuddha},year={2026},}
CCS
(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
Habibur Rahaman*, Qipan Xu*, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, and Fnu Suya
In ACM Conference on Computer and Communications Security, 2026
Modern ML pipelines depend on third-party libraries for graph compilation and hardware acceleration, but the execution environment itself remains implicitly trusted. (A)iSpy is a parasitic runtime Trojan that observes transient tensor state to exfiltrate training hyperparameters and to amplify weak data poisoning into backdoors with near-100% success, while evading standard malware scanners and model inspection.
@inproceedings{rahaman2026aispy,peerreviewed={true},title={(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure},author={Rahaman, Habibur and Xu, Qipan and Haider, Zafaryab and Chakraborty, Prabuddha and Bhunia, Swarup and Suya, Fnu},booktitle={ACM Conference on Computer and Communications Security},year={2026},}
Hubness makes a few points in a high-dimensional space unusually close to many others. We show an adversary can turn any image or audio input into an adversarial hub retrieved for thousands of unrelated queries, and that standard hubness mitigations do not defend against concept-targeted hubs.
@inproceedings{zhang2026advhub,peerreviewed={true},title={Adversarial Hubness in Multi-Modal Retrieval},author={Zhang, Tingwei and Suya, Fnu and Jha, Rishi and Zhang, Collin and Shmatikov, Vitaly},booktitle={IEEE Symposium on Security and Privacy},year={2026},pages={329--344},}
USENIX Sec
HAMLOCK: HArdware-Model LOgically Combined attacK
Sanskar Amgain*, Daniel Lobo*, Atri Chatterjee*, Swarup Bhunia, and Fnu Suya
HAMLOCK distributes backdoor logic across the hardware-software boundary: the model is only minimally altered, and a hardware Trojan watches a few neurons’ activations and manipulates output logits directly. Because the model contains no complete backdoor activation path, it appears fully benign and circumvents state-of-the-art model-level defenses, at hardware overheads as low as 0.01%.
@inproceedings{amgain2026hamlock,peerreviewed={true},title={HAMLOCK: HArdware-Model LOgically Combined attacK},author={Amgain, Sanskar and Lobo, Daniel and Chatterjee, Atri and Bhunia, Swarup and Suya, Fnu},booktitle={USENIX Security Symposium},year={2026},}
CVPR
DASH: A Meta-Attack Framework for Synthesizing Effective and Stealthy Adversarial Examples
Abdullah Al Nomaan Nafi, Habibur Rahaman, Zafaryab Haider, Tanzim Mahfuz, Fnu Suya†, Swarup Bhunia, and Prabuddha Chakraborty
In IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2026
DASH is a differentiable meta-attack that composes existing Lp-bounded attacks with learned adaptive weights, jointly minimizing misclassification loss and perceptual distortion to produce adversarial examples that are both more effective and more perceptually aligned than state-of-the-art perceptual attacks.
@inproceedings{nafi2026dash,peerreviewed={true},title={DASH: A Meta-Attack Framework for Synthesizing Effective and Stealthy Adversarial Examples},author={Nafi, Abdullah Al Nomaan and Rahaman, Habibur and Haider, Zafaryab and Mahfuz, Tanzim and Suya, Fnu and Bhunia, Swarup and Chakraborty, Prabuddha},booktitle={IEEE/CVF Conference on Computer Vision and Pattern Recognition},year={2026},}
2024
SaTML
SoK: Pitfalls in Evaluating Black-Box Attacks
Fnu Suya*, Anshuman Suri*, Tingwei Zhang, Jingtao Hong, Yuan Tian, and David Evans
In IEEE Conference on Secure and Trustworthy Machine Learning, 2024
We organize the black-box attack literature along the axes of what the adversary actually knows and can query, and show that many reported comparisons are confounded by mismatched threat models.
@inproceedings{suya2024sok,peerreviewed={true},title={SoK: Pitfalls in Evaluating Black-Box Attacks},author={Suya, Fnu and Suri, Anshuman and Zhang, Tingwei and Hong, Jingtao and Tian, Yuan and Evans, David},booktitle={IEEE Conference on Secure and Trustworthy Machine Learning},year={2024},}
2023
NeurIPS
What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?
Fnu Suya, Xiao Zhang, Yuan Tian, and David Evans
In Advances in Neural Information Processing Systems, 2023
We characterize optimal indiscriminate poisoning for linear learners and prove that well-separated, low-variance class-conditional distributions with small constraint sets are inherently resistant, explaining the wide variation in attack success across benchmark datasets.
@inproceedings{suya2023distributions,peerreviewed={true},title={What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?},author={Suya, Fnu and Zhang, Xiao and Tian, Yuan and Evans, David},booktitle={Advances in Neural Information Processing Systems},year={2023},}
CVPR
Manipulating Transfer Learning for Property Inference
Yulong Tian, Fnu Suya, Anshuman Suri, Fengyuan Xu, and David Evans
In IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2023
An upstream model provider can plant structure in a pretrained model that lets them infer properties of a downstream fine-tuning dataset they never see.
@inproceedings{tian2023manipulating,peerreviewed={true},title={Manipulating Transfer Learning for Property Inference},author={Tian, Yulong and Suya, Fnu and Suri, Anshuman and Xu, Fengyuan and Evans, David},booktitle={IEEE/CVF Conference on Computer Vision and Pattern Recognition},year={2023},}
AdvML
When Can Linear Learners be Robust to Indiscriminate Poisoning Attacks?
@inproceedings{suya2023advml,peerreviewed={true},title={When Can Linear Learners be Robust to Indiscriminate Poisoning Attacks?},author={Suya, Fnu and Zhang, Xiao and Tian, Yuan and Evans, David},booktitle={ICML AdvML Frontiers Workshop},year={2023}}
2022
VISxAI
Poisoning Attacks and Subpopulation Susceptibility
An interactive explainer showing why some subpopulations are far easier to poison than others.
@inproceedings{rose2022poisoning,peerreviewed={true},title={Poisoning Attacks and Subpopulation Susceptibility},author={Rose, Evan and Suya, Fnu and Evans, David},booktitle={VISxAI Workshop},year={2022}}
TIFS
Stealthy Backdoors as Compression Artifacts
Yulong Tian, Fnu Suya, Fengyuan Xu, and David Evans
IEEE Transactions on Information Forensics and Security, 2022
A backdoor can be hidden so that it only materializes once the model is compressed, so the shipped full-precision model looks clean.
@article{tian2022stealthy,peerreviewed={true},title={Stealthy Backdoors as Compression Artifacts},author={Tian, Yulong and Suya, Fnu and Xu, Fengyuan and Evans, David},journal={IEEE Transactions on Information Forensics and Security},year={2022},}
2021
ICML
Model-Targeted Poisoning Attacks with Provable Convergence
Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans, and Yuan Tian
In International Conference on Machine Learning, 2021
A poisoning attack that provably converges to an attacker-chosen target model, with bounds on the number of poison points required.
@inproceedings{suya2021model,peerreviewed={true},title={Model-Targeted Poisoning Attacks with Provable Convergence},author={Suya, Fnu and Mahloujifar, Saeed and Suri, Anshuman and Evans, David and Tian, Yuan},booktitle={International Conference on Machine Learning},year={2021},}
2020
USENIX Sec
Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
Fnu Suya, Jianfeng Chi, David Evans, and Yuan Tian
Attackers usually care about compromising some input from a batch, not every input. Prioritizing seeds by expected cost cuts the queries needed by an order of magnitude.
@inproceedings{suya2020hybrid,peerreviewed={true},title={Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries},author={Suya, Fnu and Chi, Jianfeng and Evans, David and Tian, Yuan},booktitle={USENIX Security Symposium},year={2020},}
ECML-PKDD
Scalable Attack on Graph Data by Injecting Vicious Nodes
@inproceedings{wang2020scalable,peerreviewed={true},title={Scalable Attack on Graph Data by Injecting Vicious Nodes},author={Wang, Jihong and Luo, Minnan and Suya, Fnu and Li, Jundong and Yang, Zijiang and Zheng, Qinghua},booktitle={European Conference on Machine Learning and Principles and Practice of Knowledge Discovery in Databases},year={2020}}
2019
IEEE S&P
Demystifying Hidden Privacy Settings in Mobile Apps
Yi Chen, Mingming Zha, Nia Zhang, Dandan Xu, Qianqian Zhao, Xuan Feng, Kan Yuan, Fnu Suya, Yuan Tian, Kai Chen, XiaoFeng Wang, and Wei Zou
@inproceedings{chen2019demystifying,peerreviewed={true},title={Demystifying Hidden Privacy Settings in Mobile Apps},author={Chen, Yi and Zha, Mingming and Zhang, Nia and Xu, Dandan and Zhao, Qianqian and Feng, Xuan and Yuan, Kan and Suya, Fnu and Tian, Yuan and Chen, Kai and Wang, XiaoFeng and Zou, Wei},booktitle={IEEE Symposium on Security and Privacy},year={2019}}
2018
IEEE S&P
Poster: Adversaries Don’t Care About Averages: Batch Attacks on Black-Box Classifiers
Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti
In IEEE Symposium on Security and Privacy (Poster), 2018
@inproceedings{suya2018batch,peerreviewed={true},title={Poster: Adversaries Don't Care About Averages: Batch Attacks on Black-Box Classifiers},author={Suya, Fnu and Tian, Yuan and Evans, David and Papotti, Paolo},booktitle={IEEE Symposium on Security and Privacy (Poster)},year={2018}}
2017
MLSec
Query-Limited Black-Box Attacks to Classifiers
Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti
In NeurIPS Workshop on Machine Learning and Computer Security, 2017
@inproceedings{suya2017query,peerreviewed={true},title={Query-Limited Black-Box Attacks to Classifiers},author={Suya, Fnu and Tian, Yuan and Evans, David and Papotti, Paolo},booktitle={NeurIPS Workshop on Machine Learning and Computer Security},year={2017},}
2016
GlobalSIP
Optimal Stochastic Power Control with Compressive CSI Acquisition for Cloud-RAN
Fnu Suya, Yin Sun, Can Emre Koksal, and Ness B. Shroff
In IEEE Global Conference on Signal and Information Processing, 2016
@inproceedings{suya2016optimal,peerreviewed={true},title={Optimal Stochastic Power Control with Compressive CSI Acquisition for Cloud-RAN},author={Suya, Fnu and Sun, Yin and Koksal, Can Emre and Shroff, Ness B.},booktitle={IEEE Global Conference on Signal and Information Processing},year={2016}}