publications

* equal contribution  ·  co-corresponding author  ·  underlined names are students I supervise

Preprints

2026

  1. arXiv
    RogueMerge: Robust and Unified Attacks against LLM Model Merging
    Jinghuai Zhang, Yetian He, Kunlin Cai, Han Zhao, Fnu Suya, and Yuan Tian
    2026
  2. arXiv
    ImageAuditor: Membership Inference Attack against Image-based Retrieval-Augmented Generation
    Jinghuai Zhang, Pengyue Yu, Zhexiao Lin, Kunlin Cai, Fnu Suya, and Yuan Tian
    2026
  3. arXiv
    Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage
    Shahinul Hoque, Jinghuai Zhang, Jinyuan Sun, and Fnu Suya
    2026
  4. arXiv
    What-If World: A Causal Benchmark for General World Models in Embodied Scenarios
    Kunlin Cai, Rui Song, Jinghuai Zhang, Kaiyuan Zhang, Pranav Bodapati, Alicia Yu, Fnu Suya, Mohammad Rostami, Jiaqi Ma, and Yuan Tian
    2026
  5. arXiv
    LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models
    Abdullah Al Nomaan Nafi, Fnu Suya, Swarup Bhunia, and Prabuddha Chakraborty
    2026

Peer-Reviewed Publications

2026

  1. CCS
    (A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
    Habibur Rahaman*, Qipan Xu*, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, and Fnu Suya
    In ACM Conference on Computer and Communications Security, 2026
  2. IEEE S&P
    Adversarial Hubness in Multi-Modal Retrieval
    Tingwei Zhang, Fnu Suya, Rishi Jha, Collin Zhang, and Vitaly Shmatikov
    In IEEE Symposium on Security and Privacy, 2026
  3. USENIX Sec
    HAMLOCK: HArdware-Model LOgically Combined attacK
    Sanskar Amgain*, Daniel Lobo*, Atri Chatterjee*, Swarup Bhunia, and Fnu Suya
    In USENIX Security Symposium, 2026
  4. CVPR
    DASH: A Meta-Attack Framework for Synthesizing Effective and Stealthy Adversarial Examples
    Abdullah Al Nomaan Nafi, Habibur Rahaman, Zafaryab Haider, Tanzim Mahfuz, Fnu Suya, Swarup Bhunia, and Prabuddha Chakraborty
    In IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2026

2024

  1. SaTML
    SoK: Pitfalls in Evaluating Black-Box Attacks
    Fnu Suya*, Anshuman Suri*, Tingwei Zhang, Jingtao Hong, Yuan Tian, and David Evans
    In IEEE Conference on Secure and Trustworthy Machine Learning, 2024

2023

  1. NeurIPS
    What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?
    Fnu Suya, Xiao Zhang, Yuan Tian, and David Evans
    In Advances in Neural Information Processing Systems, 2023
  2. CVPR
    Manipulating Transfer Learning for Property Inference
    Yulong Tian, Fnu Suya, Anshuman Suri, Fengyuan Xu, and David Evans
    In IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2023
  3. AdvML
    When Can Linear Learners be Robust to Indiscriminate Poisoning Attacks?
    Fnu Suya, Xiao Zhang, Yuan Tian, and David Evans
    In ICML AdvML Frontiers Workshop, 2023

2022

  1. VISxAI
    Poisoning Attacks and Subpopulation Susceptibility
    Evan Rose, Fnu Suya, and David Evans
    In VISxAI Workshop, 2022
  2. TIFS
    Stealthy Backdoors as Compression Artifacts
    Yulong Tian, Fnu Suya, Fengyuan Xu, and David Evans
    IEEE Transactions on Information Forensics and Security, 2022

2021

  1. ICML
    Model-Targeted Poisoning Attacks with Provable Convergence
    Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans, and Yuan Tian
    In International Conference on Machine Learning, 2021

2020

  1. USENIX Sec
    Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
    Fnu Suya, Jianfeng Chi, David Evans, and Yuan Tian
    In USENIX Security Symposium, 2020
  2. ECML-PKDD
    Scalable Attack on Graph Data by Injecting Vicious Nodes
    Jihong Wang, Minnan Luo, Fnu Suya, Jundong Li, Zijiang Yang, and Qinghua Zheng
    In European Conference on Machine Learning and Principles and Practice of Knowledge Discovery in Databases, 2020

2019

  1. IEEE S&P
    Demystifying Hidden Privacy Settings in Mobile Apps
    Yi Chen, Mingming Zha, Nia Zhang, Dandan Xu, Qianqian Zhao, Xuan Feng, Kan Yuan, Fnu Suya, Yuan Tian, Kai Chen, XiaoFeng Wang, and Wei Zou
    In IEEE Symposium on Security and Privacy, 2019

2018

  1. IEEE S&P
    Poster: Adversaries Don’t Care About Averages: Batch Attacks on Black-Box Classifiers
    Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti
    In IEEE Symposium on Security and Privacy (Poster), 2018

2017

  1. MLSec
    Query-Limited Black-Box Attacks to Classifiers
    Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti
    In NeurIPS Workshop on Machine Learning and Computer Security, 2017

2016

  1. GlobalSIP
    Optimal Stochastic Power Control with Compressive CSI Acquisition for Cloud-RAN
    Fnu Suya, Yin Sun, Can Emre Koksal, and Ness B. Shroff
    In IEEE Global Conference on Signal and Information Processing, 2016