Resume-aware faculty matching

Find professors who actually fit you

Review faculty evidence in public, then use the workspace to turn your background into a shortlist, outreach, and meeting prep.

Profile-awarePaper evidenceSix agents
Yinzhi Cao

Yinzhi Cao

· Technical Director of the JHU Information Security Institute and Associate Professor

Johns Hopkins University · Computer Science

Active 2002–2026

h-index23
Citations2.9k
Papers10362 last 5y
Funding$1.7M1 active

Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.

See your match with Yinzhi Cao — sign in to PhdFit.Sign in

About

Yinzhi Cao is an associate professor of computer science at Johns Hopkins University and serves as the technical director of the Johns Hopkins University Information Security Institute. His research focuses on the security and privacy of web, network, and mobile systems. He is a member of the Data Science and AI Institute and an affiliate of the Institute for Assured Autonomy. Cao’s current research projects include vulnerability analysis of web applications and security, privacy, and fairness analysis of machine learning systems. He has received several awards, including an NSF CAREER Award in 2021, the DARPA Young Faculty Award in 2022, and Amazon Research Awards in 2017 and 2022. Cao joined Johns Hopkins University in 2018 after serving as an assistant professor at Lehigh University. He earned his Bachelor of Engineering in electronic engineering from Tsinghua University in China in 2008 and completed his PhD in computer science at Northwestern University in 2014.

Research topics

  • Computer Science
  • Artificial Intelligence
  • Computer Security
  • Machine Learning
  • Data Mining
  • Operating system
  • Theoretical computer science

Selected publications

  • Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android Malware

    Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security · 2020 · 173 citations

    Machine learning (ML) classifiers have been widely deployed to detect Android malware, but at the same time the application of ML classifiers also faces an emerging problem. The performance of such classifiers degrades---or called ages---significantly over time given the malware evolution. Prior works have proposed to use retraining or active learning to reverse and improve aged models. However, the underlying classifier itself is still blind, unaware of malware evolution. Unsurprisingly, such e…

  • PatchAttack: A Black-Box Texture-Based Attack with Reinforcement Learning

    Lecture notes in computer science · 2020 · 93 citations

  • Practical Blind Membership Inference Attack via Differential Comparisons

    2021 · 81 citations

    Senior authorCorresponding

    Membership inference (MI) attacks affect user privacy by inferring whether given data samples have been used to train a target learning model, e.g., a deep neural network. There are two types of MI attacks in the literature, i.e., these with and without shadow models. The success of the former heavily depends on the quality of the shadow model, i.e., the transferability between the shadow and the target; the latter, given only blackbox probing access to the target model, cannot make an effective…

  • ExGen: Cross-platform, Automated Exploit Generation for Smart Contract Vulnerabilities

    IEEE Transactions on Dependable and Secure Computing · 2022 · 45 citations

    Smart contracts, just like other computer programs, are prone to a variety of vulnerabilities, which lead to severe consequences including massive token and coin losses. Prior works have explored automated exploit generation for vulnerable Ethereum contracts. However, the scopes of prior works are limited in both vulnerability types and contract platforms. In this paper, we propose a cross-platform framework, called <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.or…

  • <scp>PLeak:</scp> Prompt Leaking Attacks against Large Language Model Applications

    2024-12-02 · 34 citations

    articleOpen accessSenior author

    Large Language Models (LLMs) enable a new ecosystem with many downstream applications, called LLM applications, with different natural language processing tasks. The functionality and performance of an LLM application highly depend on its system prompt, which instructs the backend LLM on what task to perform. Therefore, an LLM application developer often keeps a system prompt confidential to protect its intellectual property. As a result, a natural attack, called prompt leaking, is to steal the…

Recent grants

Frequent coauthors

Education

  • Ph.D., Computer Science

    University of Illinois at Urbana-Champaign

    2009
  • M.S., Computer Science

    University of Illinois at Urbana-Champaign

    2004
  • B.S., Computer Science

    University of Science and Technology of China

    2002

Awards & honors

  • NSF CAREER Award (2021)
  • DARPA Young Faculty Award (2022)
  • Amazon Research Awards (2022)
  • Amazon Research Awards (2017)
  • Distinguished Paper Award at IEEE Security and Privacy

Similar researchers at Johns Hopkins University

  • Resume-aware match score
  • Save to shortlist
  • AI-drafted outreach

See your match with Yinzhi Cao

PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.

  • Free to start
  • No credit card
  • 30-second signup