I am an Assistant Professor (Lecturer) in the Department of Software Systems and Cybersecurity (SSC) at Monash University, where I lead a research lab working on trustworthy AI agent and cybersecurity. I did my PhD at Indiana University, where I was advised by XiaoFeng Wang and Feng Qian. Please refer to my CV for more information.
My research aims to enhance security and privacy of online communication and computation. Example research topics include security of decentralized network infrastructures, network proxies and anonymous communication, security of AI agents, and privacy-preserving prevention of harmful online content.
PhD positions are available with full RA/TA support. I am also happy to work with passionate master/undergraduate students, drop me a message if you are interested.
PhD in Computer Science, 2015 - 2019
Indiana University Bloomington
B.E. in Software Engineering, 2009 - 2013
Beijing Institute of Technology
The first to systematically uncover and measure the residential proxy (RESIP) ecosystem, revealing how millions of compromised residential hosts are abused as proxy exits for cybercrime — and how …
The first to uncover systemic security vulnerabilities in voice assistant ecosystems — including voice squatting, voice masquerading, and command hijacking attacks — and to expose how in-context …
Building systematic, data-driven measurement pipelines to discover, measure, and understand diverse online abuse operations at Internet scale — from bulletproof hosting and search poisoning to SMS …
The first empirical security measurements of emerging decentralized network infrastructures — including decentralized cloud storage, peer-assisted content delivery, and open edge computing platforms — …
Summary: My research has led to datasets and tools released to the public, along with tens of publications in well-recognized security venues, e.g., IEEE Security & Privacy, USENIX Security, CCS, NDSS, IMC, CoNEXT, DSN, ACSAC, AsiaCCS, etc. Most publications can be grouped by the following research topics:
The security of AI agents (e.g., voice assistants): [IMC'17] [SP'19-b] [AsiaCCS'24] [WWW'26]
Residential proxies, reverse proxies, and anonymity: [SP'19-a] [NDSS'21] [CCS'22-a] [arXiv'24-a] [EuroSP'25] [IFIPSEC'26].
The security of decentralized network infrastructures: [IWQoS'23] [DSN'24] [ACSAC'24] [ACISP'26]
Detection and measurement of online abuse and cybercrime: [SP'17] [NDSS'18] [NDSS'19] [Security'19] [CCS'22-b] [WWW'25]
Notation: * indicates co-first author; † indicates corresponding author.
Ronghong Huang, MPhil 2025 → Software Engineer at Tencent
Yue Xue, MPhil 2025 → Software Engineer at ADBC (Agricultural Development Bank of China)
Yong Fang, MPhil 2025 → Software Engineer at CSNWD Group
Yu Bi, MPhil 2024 → Security Engineer at Meituan
Mingshuo Yang, MPhil 2024 → Software Engineer at Huawei
Mingkai Li, BS 2023 → PhD at Columbia University
Ying Li, MPhil 2023 → PhD at UCLA
Hanliang Jiang, BS 2023 → Master at UIUC
Wenxin Rong, BS 2022 → PhD at University of Delaware