Assistant Professor & Founder of TokenTorrent

Monash University

I am an Assistant Professor in the Department of Software Systems and Cybersecurity (SSC) at Monash University, where I lead a research lab working on trustworthy AI agents and cybersecurity. I am also the Founder & CEO of TokenTorrent (苍源智能), a startup building security middleware and infrastructure for AI agents — with the mission of commercializing cutting-edge security research into production-grade products that make agents safe, auditable, and trustworthy by design.

Before joining Monash, I was a Pre-Tenure Full Professor at USTC (2021–2025) and briefly held a tenure-track position at the University at Buffalo (2021). Prior to academia, I spent nearly two years at Meta/Facebook as a Research Scientist in the Security Infrastructure team, where I built large-scale distributed fuzzing platforms for continuous security testing across product lines, and developed detection methods against malicious proxy traffic and inauthentic social engagement. Earlier in my career, I was a Senior Software Engineer at Baidu, designing and building user management systems for location-based services including group buying and food delivery platforms — an experience that gave me a first-hand understanding of building internet-scale services.

My research vision is to instill trust into AI and agentic systems and the digital environments they operate in. I work on systematically uncovering security risks in LLMs, AI agents, and emerging network infrastructures, and on building practical defenses that combine machine learning with cryptographic primitives. Representative topics include AI agent red teaming and safety auditing, security of decentralized network infrastructures, network proxies and anonymous communication, and privacy-preserving detection and prevention of online abuse.

Please refer to my CV for more information.

PhD positions are available with full RA/TA support. I am also happy to work with passionate master/undergraduate students, drop me a message if you are interested.

Interests
  • Trustworthy AI & Agent
  • Network Security
  • Security Measurement
  • Applied Cryptography
Education
  • PhD in Computer Science, 2015 - 2019

    Indiana University Bloomington

  • B.E. in Software Engineering, 2009 - 2013

    Beijing Institute of Technology

Research Projects

Residential Proxy Ecosystem

2019 -- 2025

The first to systematically uncover and measure the residential proxy (RESIP) ecosystem, revealing how millions of compromised residential hosts are abused as proxy exits for cybercrime — and how …

5 papers 2 datasets 1 tools

Security of AI Agents

2017 -- 2026

The first to uncover systemic security vulnerabilities in voice assistant ecosystems — including voice squatting, voice masquerading, and command hijacking attacks — and to expose how in-context …

4 papers 2 datasets 1 tools 1 award(s)

Detection & Measurement of Online Abuse

2017 -- 2025

Building systematic, data-driven measurement pipelines to discover, measure, and understand diverse online abuse operations at Internet scale — from bulletproof hosting and search poisoning to SMS …

8 papers 3 datasets 3 tools 1 award(s)

Decentralized Network Infrastructure Security

2023 -- 2026

The first empirical security measurements of emerging decentralized network infrastructures — including decentralized cloud storage, peer-assisted content delivery, and open edge computing platforms — …

5 papers 1 datasets 2 tools

Publications

Summary: My research has led to datasets and tools released to the public, along with tens of publications in well-recognized security venues, e.g., IEEE Security & Privacy, USENIX Security, CCS, NDSS, IMC, CoNEXT, DSN, ACSAC, AsiaCCS, etc. Most publications can be grouped by the following research topics:

The security of AI agents (e.g., voice assistants): [IMC'17] [SP'19-b] [AsiaCCS'24] [WWW'26]

Residential proxies, reverse proxies, and anonymity: [SP'19-a] [NDSS'21] [CCS'22-a] [arXiv'24-a] [EuroSP'25] [IFIPSEC'26].

The security of decentralized network infrastructures: [IWQoS'23] [DSN'24] [ACSAC'24] [ACISP'26]

Detection and measurement of online abuse and cybercrime: [SP'17] [NDSS'18] [NDSS'19] [Security'19] [CCS'22-b] [WWW'25]

Notation: * indicates co-first author; † indicates corresponding author.

The full list of publications

[WWW'26] ICL-EVADER: Zero-Query Black-Box Evasion Attacks on In-Context Learning and Their Defenses ⭐ Highlight
[ACISP'26] Okara: Detection and Attribution of TLS Man-in-the-Middle Vulnerabilities in Android Apps with Foundation Models Recent
[IFIPSEC'26] Pepper: High-bandwidth and Scalable Anonymous Broadcast with Cryptographic Privacy Recent
[EuroSP'25] Port Forwarding Services Are Forwarding Security Risks
[WWW'25] Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter
[ACSAC'24] Dissecting Open Edge Computing Platforms: Ecosystem, Usage, and Security Risks

Graduated Students

  • Ronghong Huang, MPhil 2025 → Software Engineer at Tencent

  • Yue Xue, MPhil 2025 → Software Engineer at ADBC (Agricultural Development Bank of China)

  • Yong Fang, MPhil 2025 → Software Engineer at CSNWD Group

  • Yu Bi, MPhil 2024 → Security Engineer at Meituan

  • Mingshuo Yang, MPhil 2024 → Software Engineer at Huawei

  • Mingkai Li, BS 2023 → PhD at Columbia University

  • Ying Li, MPhil 2023 → PhD at UCLA

  • Hanliang Jiang, BS 2023 → Master at UIUC

  • Wenxin Rong, BS 2022 → PhD at University of Delaware

Experience

 
 
 
 
 
Founder & CEO
Jul 2026 – Present Hefei, China
Building security middleware and infrastructure for AI agents — commercializing security research into production-grade products.
 
 
 
 
 
Assistant Professor (Lecturer)
Monash University
Dec 2025 – Present Clayton, Australia
 
 
 
 
 
Pre-Tenure Full Professor
USTC (University of Science and Technology of China)
Sep 2021 – Dec 2025 Hefei, China
 
 
 
 
 
Tenure-Track Assistant Professor
Jan 2021 – Aug 2021 New York, United States
 
 
 
 
 
Research Scientist
Jun 2019 – Jan 2021 California, United States
Built a large-scale distributed fuzzing platform for continuous security testing across product lines.
Developed detection methods against malicious proxy traffic and inauthentic social engagement.
 
 
 
 
 
PhD in Computer Science
Aug 2015 – May 2019 Indiana, United States
Research in Security and Networking.
Thesis defense completed in June 2020 due to job enrollment and the COVID-19 pandemic.
 
 
 
 
 
Senior Software Engineer
May 2014 – Jun 2015 Beijing, China
Designed and built user management systems for location-based services including group buying and food delivery platforms (Baidu Nuomi).
 
 
 
 
 
B.E in Software Engineering
Sep 2009 – Jun 2013 Beijing, China
Undergraduate study in Software Engineering