My name is Tianshuo Cong (丛天硕). I am currently a postdoctoral researcher (Shuimu Scholar, 水木学者) at the Institute for Advanced Study, Tsinghua University (IASTU) (清华大学高等研究院), hosted by Prof. Xiaoyun Wang (IACR Fellow).
I received my Ph.D. degree from the Institute for Advanced Study, Tsinghua University in 2023. My Ph.D. advisor is Prof. Xiaoyun Wang.
Before that, I got my B.Eng. degree from the Department of Electronic Engineering, Tsinghua University in 2017. Meanwhile, I was a visiting Ph.D. student from August 2021 to December 2023 at CISPA Helmholtz Center for Information Security in Saarbrücken, Germany, advised by Dr. Yang Zhang.
My research interests include the safety, security, and privacy of artificial intelligence (e.g., large foundation models) and lightweight cipher design.
I have published papers at top-tier security conferences including IEEE SP, ACM CCS, NDSS, and USENIX Security.
Meanwhile, I have served as the PC members for security conferences such as RAID’25, EuroS&P’25, ACSAC’24, PETS’25/26, and SaTML’25, and I have also been the official invited reviewers for security journals (e.g., TIFS, TDSC, TOPS, etc) and AI conferences (e.g., ICML’25, NeurIPS’25, ICLR’25, etc).
Notably, I lead a curated reading list on safety, security, and privacy of large models: Awesome-LM-SSP ().
📍Education
- 2017.07 - 2023.06, Ph.D., Institute for Advanced Study, Tsinghua University, Beijing, China
- 2021.08 - 2023.01, Visiting Ph.D., CISPA Helmholtz Center for Information Security, Saarbrücken, Germany
- 2013.06 - 2017.06, B.Eng., Department of Electronic Engineering, Tsinghua University, Beijing, China
📍Honors & Awards
- NDSS’25 Distinguished Poster Award
- CCS-LAMPS’24 Best Paper Award
- Shuimu Tsinghua Scholar Program (2023-2025)
- CACR Outstanding Doctoral Dissertation Award (2023)
- 2nd Prize in Block Cipher Track, National Cryptographic Algorithm Design Competition (2021)
📍News
- 2025.03:
service
I’ll serve on the Program Committee for PETS 2026. - 2025.03:
service
I’ll serve on the Program Committee for ACSAC 2025. - 2025.03:
paper
PEFTGuard got accepted in IEEE SP 2025! - 2025.02:
award
JailbreakEval won the Distinguished Poster Award of NDSS 2025! - 2025.02:
service
I’ll serve on the Program Committee for RAID 2025. - 2025.01:
paper
One paper got accepted in USENIX Security 2025! - 2024.12:
paper
Two papers got accepted in AAAI 2025! - 2024.11:
paper
One paper got accepted in NDSS Symposium 2025!
📍Publications
⋆: Equal contribution; †: Corresponding author

PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-Tuning
Zhen Sun, Tianshuo Cong, Yule Liu, Chenhao Lin, Xinlei He, Rongmao Chen, Xingshuo Han, and Xinyi Huang.
IEEE Symposium on Security and Privacy (Oakland) 2025
[arxiv] [安全极客] (AR: 257/1740=14.8%, Cycle 2 AR: 151/1001=15.1%)

From Purity to Peril: Backdooring Merged Models From “Harmless” Benign Components
Lijin Wang, Jingjing Wang, Tianshuo Cong†, Xinlei He†, Zhan Qin, and Xinyi Huang
USENIX Security Symposium 2025
[paper]


JailbreakEval: An Integrated Safety Evaluator Toolkit for Assessing Jailbreaks Against Large Language Models
Delong Ran, Jinyuan Liu, Yichen Gong, Jingyi Zheng, Xinlei He, Tianshuo Cong†, and Anyu Wang
NDSS Symposium 2025 (Poster Session)
[arxiv]
[poster]
[code]
(NDSS’25 Poster AR: 37/76=48.7%)
🏆 Distinguished Poster Award

FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts
Yichen Gong⋆, Delong Ran⋆, Jinyuan Liu, Conglei Wang, Tianshuo Cong†, Anyu Wang†, Sisi Duan, and Xiaoyun Wang
Annual AAAI Conference on Artificial Intelligence (AAAI) 2025
[pdf]
[arxiv]
[code]
[slides]
(OR: 600/12957=4.6%, AR: 3032/12957=23.4%)
🎙️ Oral Presentation


Have You Merged My Model? On The Robustness of Large Language Model IP Protection Methods Against Model Merging
Tianshuo Cong, Delong Ran, Zesen Liu, Xinlei He, Jinyuan Liu, Yichen Gong, Qi Li, Anyu Wang, and Xiaoyun Wang
1st ACM Workshop on Large AI Systems and Models with Privacy and Safety Analysis (LAMPS)
🏆 Best Paper Award


Journal
- On the Design of Block Cipher FESH
Keting Jia, Xiaoyang Dong, Congming Wei, Zheng Li, Haibo Zhou, and Tianshuo Cong.
密码学报
[pdf]
🏆 2nd Prize in Block Cipher Track, National Cryptographic Algorithm Design Competition
Under Review & Manuscript
-
SoK: Benchmarking Poisoning Attacks and Defenses in Federated Learning
Heyi Zhang, Yule Liu, Xinlei He, Jun Wu, Tianshuo Cong, and Xinyi Huang.
[arxiv] -
Jailbreak Attacks and Defenses Against Large Language Models: A Survey
Sibo Yi, Yule Liu, Zhen Sun, Tianshuo Cong, Xinlei He, Jiaxing Song, Ke Xu, and Qi Li.
[arxiv] -
On Evaluating The Performance of Watermarked Machine-Generated Texts Under Adversarial Attacks
Zesen Liu, Tianshuo Cong, Xinlei He, and Qi Li.
[arxiv] -
Robustness Over Time: Understanding Adversarial Examples’ Effectiveness on Longitudinal Versions of Large Language Models
Yugeng Liu⋆, Tianshuo Cong⋆, Zhengyu Zhao, Michael Backes, Yun Shen, and Yang Zhang.
[arxiv]
Others
- 隐私计算产品通用安全分级白皮书 (2024年)
Led by Ant Group.
[pdf]
📍Services
Session Chair
- NDSS 2025 (Session 3D: AI Safety)
PC Member of Security and Privacy Conferences
- EuroS&P 2025
- ACSAC 2024, 2025
- RAID 2025
- PETS 2025, 2026
- SaTML 2025
- IWQoS 2025
Official Invited Reviewer of AI Conference
- ICML 2025
- NeurIPS 2024, 2025
- ICLR 2025
- CVPR 2024, 2025
- AAAI 2025
- KDD 2025
- MM 2024
- ACL 2024
- ECCV 2024
- AISTATS 2025
Official Invited Reviewer of Journals
- IEEE Transactions on Information Forensics and Security (TIFS)
- IEEE Transactions on Dependable and Secure Computing (TDSC)
- ACM Transactions on Privacy and Security (TOPS)
- ACM Transactions on Knowledge Discovery from Data (TKDD)
- 《信息安全学报》(Journal of Cyber Security)
Organizer
- A curated reading list on safety, security, and privacy of large models: Awesome-LM-SSP
Ph.D. Thesis Defense Committee Secretary
- Tairong Huang (Tsinghua University, 2024/05)
- Shiduo Zhang (Tsinghua University, 2024/05)
- Xiao Sui (Shandong University, 2024/05)
- Han Wu (Shandong University, 2024/05)
📍Teaching
- Lecturer of the tutorial on “Safety, Security, and Privacy of Foundation Models” at IEEE WIFS 2024, Rome, Italy (In English, ~4 hours).
- Teaching Assistant of the Course “Advanced Numerical Analysis”, Fall 2019, Tsinghua University.
- Teaching Assistant of the Course “Introduction to Information Science and Technology”, Spring 2018, Tsinghua University.