
Yinzhi Cao
· Technical Director of the JHU Information Security Institute and Associate ProfessorJohns Hopkins University · Computer Science
Active 2002–2026
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Yinzhi Cao is an associate professor of computer science at Johns Hopkins University and serves as the technical director of the Johns Hopkins University Information Security Institute. His research focuses on the security and privacy of web, network, and mobile systems. He is a member of the Data Science and AI Institute and an affiliate of the Institute for Assured Autonomy. Cao’s current research projects include vulnerability analysis of web applications and security, privacy, and fairness analysis of machine learning systems. He has received several awards, including an NSF CAREER Award in 2021, the DARPA Young Faculty Award in 2022, and Amazon Research Awards in 2017 and 2022. Cao joined Johns Hopkins University in 2018 after serving as an assistant professor at Lehigh University. He earned his Bachelor of Engineering in electronic engineering from Tsinghua University in China in 2008 and completed his PhD in computer science at Northwestern University in 2014.
Research topics
- Computer Science
- Artificial Intelligence
- Computer Security
- Machine Learning
- Data Mining
- Operating system
- Theoretical computer science
Selected publications
Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android Malware
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security · 2020 · 173 citations
Machine learning (ML) classifiers have been widely deployed to detect Android malware, but at the same time the application of ML classifiers also faces an emerging problem. The performance of such classifiers degrades---or called ages---significantly over time given the malware evolution. Prior works have proposed to use retraining or active learning to reverse and improve aged models. However, the underlying classifier itself is still blind, unaware of malware evolution. Unsurprisingly, such e…
PatchAttack: A Black-Box Texture-Based Attack with Reinforcement Learning
Lecture notes in computer science · 2020 · 93 citations
Practical Blind Membership Inference Attack via Differential Comparisons
2021 · 81 citations
Senior authorCorrespondingMembership inference (MI) attacks affect user privacy by inferring whether given data samples have been used to train a target learning model, e.g., a deep neural network. There are two types of MI attacks in the literature, i.e., these with and without shadow models. The success of the former heavily depends on the quality of the shadow model, i.e., the transferability between the shadow and the target; the latter, given only blackbox probing access to the target model, cannot make an effective…
ExGen: Cross-platform, Automated Exploit Generation for Smart Contract Vulnerabilities
IEEE Transactions on Dependable and Secure Computing · 2022 · 45 citations
Smart contracts, just like other computer programs, are prone to a variety of vulnerabilities, which lead to severe consequences including massive token and coin losses. Prior works have explored automated exploit generation for vulnerable Ethereum contracts. However, the scopes of prior works are limited in both vulnerability types and contract platforms. In this paper, we propose a cross-platform framework, called <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.or…
<scp>PLeak:</scp> Prompt Leaking Attacks against Large Language Model Applications
2024-12-02 · 34 citations
articleOpen accessSenior authorLarge Language Models (LLMs) enable a new ecosystem with many downstream applications, called LLM applications, with different natural language processing tasks. The functionality and performance of an LLM application highly depend on its system prompt, which instructs the backend LLM on what task to perform. Therefore, an LLM application developer often keeps a system prompt confidential to protect its intellectual property. As a result, a natural attack, called prompt leaking, is to steal the…
Recent grants
EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites
NSF · $95k · 2016–2017
NSF · $561k · 2021–2027
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
NSF · $465k · 2018–2022
Frequent coauthors
- 15 shared
Yan Chen
Xi'an Jiaotong University
- 13 shared
Neil Zhenqiang Gong
- 13 shared
Mingqing Kang
Johns Hopkins University
- 12 shared
Haolin Yuan
- 12 shared
Philippe Burlina
- 9 shared
Patrick Thomas
University of Virginia
- 9 shared
Zihao Su
Chengdu Organic Chemicals (China)
- 9 shared
Yuan Tian
Education
- 2009
Ph.D., Computer Science
University of Illinois at Urbana-Champaign
- 2004
M.S., Computer Science
University of Illinois at Urbana-Champaign
- 2002
B.S., Computer Science
University of Science and Technology of China
Awards & honors
- NSF CAREER Award (2021)
- DARPA Young Faculty Award (2022)
- Amazon Research Awards (2022)
- Amazon Research Awards (2017)
- Distinguished Paper Award at IEEE Security and Privacy
Similar researchers at Johns Hopkins University
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Yinzhi Cao
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
