Two papers have been accepted to EMNLP 2026: Staying on Task: Defending Against Prompt Injection via Task Consistency Checking (Main Conference) and Latent Visual Sensitive Fingerprinting for Black-Box Vision–Language Model Tamper Detection (Findings). Congratulations to Feiyue and Chaoxiang!
Hongsheng Hu
School of Computer Science,
Shanghai Jiao Tong University
AI Security and Privacy
I am an Associate Professor at School of Computer Science, Shanghai Jiao Tong University. Before joining Shanghai Jiao Tong University, From 2024 to 2026, I was a tenured Lecturer in the School of Information and Physical Sciences at the University of Newcastle, Australia. Prior to that, I was a Postdoctoral Research Fellow at CSIRO’s Data61. In 2022, I received my Ph.D. from the University of Auckland, New Zealand, under the supervision of Professor Xuyun Zhang, Professor Gillian Dobbie (Fellow of the Royal Society of New Zealand), and Professor Zoran Salcic (Fellow of the Royal Society of New Zealand).
My research focuses on trustworthy AI, with particular emphasis on AI privacy and LLM agent security. In particular, I am interested in understanding real privacy and security risks of deep models, developing methods to mitigate these risks, and designing secure and robust AI systems. My work has been published in top-tier venues such as IEEE S&P, NDSS, USENIX Security, ICLR, CVPR, NeurIPS, WWW, IJCAI, and AAAI.
Prospective Postdocs, PhD, Master, and Graduate Intern Students
I am always looking for self-motivated talents interested in AI security and privacy, especially trustworthy AI, LLM agent security, model privacy, and robust AI systems. Please read the information below carefully before contacting me.
Postdoctoral Research Fellow
- Applicants should have a strong research background aligned with AI Security, LLM, Agent, and a record of high-quality publications.
- For information about postdoctoral salary and related support, please refer to the SJTU postdoctoral salary reference.
PhD and Master’s Students
- For PhD and Master applicants, preference will be given to candidates who have completed a research internship in my lab at SJTU.
Please email me for the above positions. Your email should include: i) your CV and academic transcripts; ii) a brief description of your research interests and how they align with AI Security, LLM, Agent; and iii) your intended position, expected start date, and any relevant publications, research projects, or code repositories experience.
News
We are so lucky to receive 🏆 Distinguished Artifact Awards at USENIX Security 2026 (CCF-A) for our paper CompLeak: Deep Learning Model Compression Exacerbates Privacy Leakage. Congratulations to the team!
Our paper DP2-RAG: An Efficient Full-Process Differential Privacy Implementation in Retrieval-Augmented Generation was accepted by IEEE Transactions on Information Forensics and Security (TIFS) (CCF-A). Congratulations to the team!
I was invited by the PC Chair to serve on the Program Committee for the IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) 2027. Looking forward to your good work!
I was invited by the PC Chair to serve on the Program Committee for USENIX Security 2027 (CCF-A). Looking forward to your good work!
I joined School of Computer Science, Shanghai Jiao Tong University as an Associate Professor.
Selected Publications
I have published papers in top information security, artificial intelligence, and data mining conferences. * indicates the work for which I am the lead author, including the first author, the (co-)corresponding author, or the first author being my student.
2026
Staying on Task: Defending Against Prompt Injection via Task Consistency Checking
Feiyue Xu, Jiaming Mu, Fengting Li, Bin Benjamin Zhu, Hongsheng Hu*, Chaoxiang He, Qiankun Liu, Shuo Wang, and Chao Feng.
Latent Visual Sensitive Fingerprinting for Black-Box Vision–Language Model Tamper Detection
Chaoxiang He, Jichen Chai, Hanqing Hu, Yi Wang, Shuo Wang, Hongsheng Hu*, and Bin Benjamin Zhu.
SoK: Robustness in Large Language Models against Jailbreak Attacks
Feiyue Xu, Hongsheng Hu*, Chaoxiang He, Sheng Hang, Hanqing Hu, Xiuming Liu, Yubo Zhao, Zhengyan Zhou, Bin Benjamin Zhu, Shi-Feng Sun, Dawu Gu, and Shuo Wang.
CompLeak: Deep Learning Model Compression Exacerbates Privacy Leakage
Na Li, Yansong Gao, Hongsheng Hu, Boyu Kuang, and Anmin Fu.
ExpShield: Safeguarding Web Text from Unauthorized Crawling and LLM Exploitation
Ruixuan Liu, Toan Tran, Tianhao Wang, Hongsheng Hu, Shuo Wang, and Li Xiong.
Unlearning during Training: Domain-Specific Gradient Ascent for Domain Generalization
Di Zhao, Jingfeng Zhang, Hongsheng Hu, Philippe Fournier-Viger, Gillian Dobbie, and Yun Sing Koh.
Reference Recommendation Based Membership Inference Attack Against Hybrid-Based Recommender Systems
Xiaoxiao Chi, Xuyun Zhang, Yan Wang, Hongsheng Hu*, and Wanchun Dou.
2025
Enhancing Adversarial Transferability with Checkpoints of a Single Model’s Training
Shixin Li, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu, Shuo Wang, Hongsheng Hu, Dongmei Zhang, and Linchen Yu.
BadFU: Backdoor Federated Learning through Adversarial Machine Unlearning
Bingguang Lu, Hongsheng Hu*, Yuantian Miao, Shaleeza Sohail, Chaoxiang He, Shuo Wang, and Xiao Chen.
2024
Learn What You Want to Unlearn: Unlearning Inversion Attacks against Machine Unlearning
Hongsheng Hu*, Shuo Wang, Tian Dong, and Minhui Xue.
A Duty to Forget, a Right to be Assured? Exposing Vulnerabilities in Machine Unlearning Services
Hongsheng Hu*, Shuo Wang, Jiamin Chang, Haonan Zhong, Ruoxi Sun, Shuang Hao, Haojin Zhu, and Minhui Xue.
2023
Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning
Hongsheng Hu*, Xuyun Zhang, Zoran Salcic, Lichao Sun, Kim-Kwang Raymond Choo, and Gillian Dobbie.
2022
Membership Inference Attacks on Machine Learning: A Survey
Hongsheng Hu*, Zoran Salcic, Lichao Sun, Gillian Dobbie, Philip S. Yu, and Xuyun Zhang.
Membership Inference via Backdooring
Hongsheng Hu*, Zoran Salcic, Gillian Dobbie, Lichao Sun, and Xuyun Zhang.
2021
Source Inference Attacks in Federated Learning
Hongsheng Hu*, Zoran Salcic, Lichao Sun, Gillian Dobbie, and Xuyun Zhang.
Academic Service
I contribute to the information security and artificial intelligence research community through conference program committees, editorial roles, journal reviewing, and conference organization.
Program Committee Memberships
- 2027: USENIX Security, SaTML, WSDM (Senior PC)
- 2026: CCS, NDSS AE, AAAI, RAID
- 2025: USENIX Security AE, NDSS AE, RAID, NeurIPS, ICLR, WWW, CVPR, IJCAI, ICCV, ICDM, AAAI
- 2024: USENIX Security AE, NDSS AE, AAAI, IJCAI, WWW, ICDM, PKDD
- 2023: NDSS AE, IJCAI, ICDM, PKDD, ECML, PAKDD, IJCNN
- 2022: ICDM
Editorship
- Associate Editor, IEEE Transactions on Information Forensics and Security, 2025 – Present
- Associate Editor, IEEE Transactions on Dependable and Secure Computing, 2025 – Present
Journal Reviewer
- 2025: TDSC, TIFS, TPAMI, TNNLS, Computer Networks, PeerJ Computer Science
- 2024: TDSC, TIFS, TPAMI, TKDE, TNNLS, Computers & Security
- 2023: TDSC, TIFS, TKDE, Computers & Security
Special Session Track Chair
- The 20th International Conference on Advanced Data Mining and Applications (ADMA), 2024