CM-EVS: Sparse Panoramic RGB-D-Pose Data for Complete Scene Coverage
A coverage-curated dataset of 36,373 RGB-D frames across 1,275 indoor scenes, connecting panoramic perception with compact, geometry-consistent 3D environments.
I am a second-year Ph.D. student in Computer Science and Engineering at the Hong Kong University of Science and Technology (HKUST), advised by Prof. Shuai Wang.
I completed a combined B.Eng.–M.Eng. program at the China University of Petroleum (East China) under Prof. Honglong Chen, and was previously a Research Assistant at the College of William & Mary with Prof. Huajie Shao (2023–2024).
My research focuses on AI security, trustworthy language models and agents, and embodied intelligence.

A coverage-curated dataset of 36,373 RGB-D frames across 1,275 indoor scenes, connecting panoramic perception with compact, geometry-consistent 3D environments.
Protects MoE LLMs through expert-routing watermarks, combining route alignment with contrastive learning. Verification reaches 99–100% across 4 models and 3 datasets, retaining 95% after 30 rounds of fine-tuning.
Constructed 143,000 synthetic QA pairs and trained Qwen3-4B/14B with SFT and GRPO for pure-text spatial reasoning. Qwen3-4B accuracy improved from 34.5% to 76.8% on the SPOD-Bench CMM multi-turn task.
Studies weight-integrity vulnerabilities across 4 VLA variants and 3 action-head families. Three selected logical INT8 bit flips reduced OpenVLA success from 88% to 0% in 50 LIBERO-Spatial simulation trials; also investigates localized protection.
Optimizes LLM Agent skills for token efficiency. Across 600 skills and 3,000 tasks, reduces description and body tokens by 48% and 39%, while improving the evaluated task score from 0.722 to 0.742.
Develops TriBA to hide backdoor triggers in the spatial, frequency, and feature domains, combining frequency-domain transformations with feature-space alignment. Evaluated on four datasets to study attack effectiveness and stealthiness.
Develops DEST for AI-based consumer IoT, combining wavelet and Fourier transforms with singular-value embedding to construct strong triggers. Frequency restrictions conceal their traces, enabling stealthy backdoors in both spatial and frequency domains.
Develops EBBA/EBBA+ to detect backdoored models without task-specific samples and remove backdoors without model retraining, using energy statistics and transferred-energy analysis.
Studies backdoor attack and defense from a multi-channel perspective. RC-Attack embeds triggers in color channels, while RC-Defense reconstructs color and lightness channels to suppress poisoned behavior.
Builds a dual-stealthy backdoor that hides triggers in both the spatial and frequency domains, studying how transformations affect trigger visibility and resistance to defenses.
Studies channel-level gradient leakage in federated learning and develops lightweight privacy protection. Received the ICTC 2024 Best Paper Award.
Journal ReviewerIEEE TIFS, IEEE TDSC, IEEE TNNLS, Pattern Recognition, Expert Systems with Applications, Engineering Applications of Artificial Intelligence
Conference ReviewerNeurIPS, ICLR, AAAI, WWW, ACM Multimedia
Sub-reviewerACM CCS, USENIX Security, FSE