Ziqing Yang

profiles/profile_0.jpg

Shot by Xiao Wu at Istanbul, Turkey

This is Ziqing Yang, a fourth-year PhD student at CISPA Helmholtz Center for Information Security, co-advised by Prof. Michael Backes and Dr. Yang Zhang. My research focuses on trustworthy machine learning, with a particular interest in exploring the security and safety risks in generative AIs and agents.

Before that, I completed a B.Sc. in Intelligence Science and Technology and a second major in Chinese Language and Literature (B.A.) at Peking University. Advised by Prof. Ming Zhang, I focused on knowledge representation and graph analysis. During my undergraduate, I was also a research intern at UCLA under the supervision of Prof. Yizhou Sun, working on the combination of knowledge graphs and logical rules.

research interests

I am interested in the intersection of machine learning and security, especially using a mathematical methodology to understand and address the problem.

  • Trustworthy machine learning (safety, privacy, and security)
  • Generative models and agents
  • Graph analysis

news

Aug 2026 Our paper JADES: A Universal Framework for Jailbreak Assessment via Decompositional Scoring was accepted by EMNLP 2026, and paper The Challenge of Identifying the Origin of Black-Box Large Language Models was accepted by EMNLP Findings 2026!
May 2026 Our paper BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt Learning was accepted by IEEE Transactions on Information Forensics & Security!
Apr 2026 Our paper The Challenge of Identifying the Origin of Black-Box Large Language Models was accepted by ACL 2026 PrivateNLP Workshop!
Apr 2026 Our papers Peering Behind the Shield: Guardrail Identification in Large Language Models and PeerCheck: Enhancing LLM-Generated Academic Reviews Towards Human-Level Quality were accepted by ACL Findings 2026!
Nov 2025 Our paper titled Peering Behind the Shield: Guardrail Identification in Large Language Models was accepted by AAAI 2026 AICS Workshop and AAAI 2026 TrustAgent Workshop!
Oct 2025 I am delighted to be selected as a NeurIPS 2025 “Reviewer : Top Reviewer”!
May 2025 Our paper titled Comprehensive Assessment of Jailbreak Attacks Against LLMs was accepted by ACL 2025!
Jan 2025 Our paper titled Synthetic Artifact Auditing: Tracing LLM-Generated Synthetic Data Usage in Downstream Applications was accepted by USENIX Security 2025!
Sep 2023 Our paper named SecurityNet: Assessing Machine Learning Vulnerabilities on Public Models was accepted by USENIX Security 2024!
May 2023 Our paper named Data Poisoning Attacks Against Multimodal Encoders was accepted by ICML 2023!