Yu LI
ZJU100 Professor · School of Integrated Circuits, Zhejiang University
I work on the safety and reliability of AI-driven systems that interact with the physical world, with an emphasis on foundation and generative models (e.g., LLMs and video generation), and their reliable deployment in autonomous systems and digital twins for semiconductor manufacturing.
I received my Ph.D. from CUHK under Prof. Qiang Xu, and previously interned at IMEC, Alibaba Cloud, and Huawei Noah's Ark Lab. I received the Best Ph.D. Thesis Award from ATS 2022 and was selected as a KAUST AI Rising Star (2026).
li.yu@zju.edu.cn Google Scholar / GitHub / 中文主页
🔬 I am looking for Postdoctoral Researchers with a strong background in AI security, autonomous systems, or EDA. Contact me at li.yu@zju.edu.cn.
I am also looking for self-motivated Ph.D. students, master students, and research assistants. Contact me at li.yu@zju.edu.cn or visit my Chinese website.
News
| 2026-03 | One paper is accepted to CVPR 2026. |
|---|---|
| 2026-02 | I was selected as a KAUST AI Rising Star (2026). |
| 2025-08 | Three papers are accepted to NeurIPS 2025. |
| 2025-08 | Four papers are accepted to TDSC 2025, TIFS 2025, TCAD, and ASE 2025. |
| 2025-05 | Check our paper on safety-critical driving dataset generation: website |
| 2025-05 | Two papers have been accepted by ACL 2025. Congrats for all! |
| 2025-05 | One paper has been accepted by ICML 2025. Congrats! |
| 2025-01 | One paper has been accepted by ICLR 2025. Congrats, Linbao! |
| 2024-12 | One paper has been accepted by AAAI 2025. Congrats, Zhiheng! |
| 2024-09 | Two papers have been accepted by NeurIPS 2024! |
| 2024-05 | One paper has been accepted to ICML'24. |
Publications Full List →
Preprints
-
SafeMVDrive: Multi-view Safety-Critical Driving Video Synthesis in the Real World DomainarXiv, 2025.
-
Toward Physically Consistent Driving Video World Models under Challenging TrajectoriesarXiv, 2026.
2026
-
MaxMark: High-Capacity Diffusion-Native Watermarking via Robust and Invertible Latent EmbeddingIEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR, CCF-A), 2026.
2025
-
SilentStriker: Toward Stealthy Bit-Flip Attacks on Large Language ModelsConference on Neural Information Processing Systems (NeurIPS, CCF-A), 2025.
-
One Model Transfer to All: On Robust Jailbreak Prompts Generation against LLMsInternational Conference on Learning Representations (ICLR, CCF-A), 2025.
-
DF-MIA: A Distribution-Free Membership Inference Attack on Fine-Tuned Large Language ModelsAAAI Conference on Artificial Intelligence (AAAI, CCF-A), 2025.
-
MTSA: Multi-turn Safety Alignment for LLMs through Multi-round Red-teamingAnnual Meeting of the Association for Computational Linguistics (ACL, CCF-A), 2025.
-
Function-to-Style Guidance of LLMs for Code TranslationInternational Conference on Machine Learning (ICML, CCF-A), 2025.
-
FDTest: Prioritizing Test Inputs for Object Detection Models via Foundation Model ExploitationInternational Joint Conference on Neural Networks (IJCNN, CCF-C), 2025.
-
ArcGen: Generalizing Neural Backdoor Detection Across Diverse ArchitecturesIEEE Transactions on Information Forensics and Security (TIFS, CCF-A), 2025.
-
SPLAT: Revisiting Latency Attack on Dynamic Neural NetworksIEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems (TCAD, CCF-A), 2025.
-
Toward Efficient Quality Testing of Graph Neural Networks via Test Input PrioritizationAutomated Software Engineering (ASE, CCF-B), 2025.
-
Toward Robust and Accurate Adversarial Camouflage Generation Against Vehicle DetectorsIEEE Transactions on Dependable and Secure Computing (TDSC, CCF-A), 2025.
2024
-
CNCA: Toward Customizable and Natural Generation of Adversarial Camouflage for Vehicle DetectorsConference on Neural Information Processing Systems (NeurIPS, CCF-A), 2024.
-
Vector Quantization Prompting for Continual LearningConference on Neural Information Processing Systems (NeurIPS, CCF-A), 2024.
-
RAUCA: A Novel Physical Adversarial Attack on Vehicle Detectors via Robust and Accurate Camouflage GenerationInternational Conference on Machine Learning (ICML, CCF-A), 2024.
-
Protecting Object Detection Models from Model Extraction Attack via Feature Space CoverageInternational Joint Conference on Artificial Intelligence (IJCAI, CCF-A), 2024.
-
Enhancing Flow Embedding Through Trace: A Novel Self-supervised Approach for Encrypted Traffic ClassificationInternational Joint Conference on Neural Networks (IJCNN, CCF-C), 2024.
-
The Dawn of AI-Native EDA: Opportunities and Challenges of Large Circuit ModelsSCIENCE CHINA Information Sciences (SCIS, CCF-A), 2024.
-
Spatial Attention for Human-Centric Visual Understanding: An Information Bottleneck MethodComputer Vision and Image Understanding (CVIU, CCF-B), 2024.
-
A Novel Approach to Reducing Testing Costs and Minimizing Defect Escapes Using Dynamic Neighborhood Range and Shapley ValuesACM Transactions on Design Automation of Electronic Systems (TODAES, CCF-B), 2024.
-
On Function-Coupled Watermarks for Deep Neural NetworksIEEE Journal on Emerging and Selected Topics in Circuits and Systems (JETCAS, JCR-Q2), 2024.
2023
-
HiBug: On Human-Interpretable Model DebugConference on Neural Information Processing Systems (NeurIPS, CCF-A), 2023.
-
EXPERT: Exploiting DRAM Error Types to Improve the Effective Forecasting Coverage in the FieldIEEE/IFIP International Conference on Dependable Systems and Networks (DSN, CCF-B), 2023.
-
Towards Robust Deep Neural Networks Against Design-Time and Run-Time FailuresInternational Test Conference (ITC, CCF-B), 2023.
-
Self-Supervised Video Representation Learning via Capturing Semantic Changes Indicated by SaccadesIEEE Transactions on Circuits and Systems for Video Technology (TCSVT, CCF-B), 2023.
2022
-
What You See is Not What the Network Infers: Detecting Adversarial Examples Based on Semantic ContradictionNetwork and Distributed System Security Symposium (NDSS, CCF-A), 2022.
-
HybridRepair: Towards Annotation-Efficient Repair for Deep Learning ModelsACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA, CCF-A), 2022.
2021
-
TestRank: Bringing Order into Unlabeled Test Instances for Deep Learning TasksConference on Neural Information Processing Systems (NeurIPS, CCF-A), 2021.
-
Information Bottleneck Approach to Spatial Attention LearningInternational Joint Conference on Artificial Intelligence (IJCAI, CCF-A), 2021.
-
AppealNet: An Efficient and Highly-Accurate Edge/Cloud Collaborative Architecture for DNN InferenceDesign Automation Conference (DAC, CCF-A), 2021.
-
On Workload-Aware DRAM Failure Prediction in Large-Scale Data CentersIEEE VLSI Test Symposium (VTS, CCF-C), 2021.
2020
-
DeepDyve: Dynamic Verification for Deep Neural NetworksACM SIGSAC Conference on Computer and Communications Security (CCS, CCF-A), 2020.
-
On Configurable Defense against Adversarial Example AttacksGreat Lakes Symposium on VLSI (GLSVLSI, CCF-C), 2020.
2019
-
D2NN: A Fine-Grained Dual Modular Redundancy Framework for Deep Neural NetworksAnnual Computer Security Applications Conference (ACSAC, CCF-B), 2019.
-
On Functional Test Generation for Deep Neural Network IPsDesign, Automation & Test in Europe Conference (DATE, CCF-B), 2019.
2018
-
I Know What You See: Power Side-Channel Attack on Convolutional Neural Network AcceleratorsAnnual Computer Security Applications Conference (ACSAC, CCF-B), 2018.
-
IEEE Std P1838's Flexible Parallel Port and its Specification with Google's Protocol BuffersIEEE European Test Symposium (ETS, CCF-C), 2018.
Teaching
- COMP5034System Security, 2023 Fall
- COMP3054Computers and Network Security, 2023 Spring
- CSCI3250Computers and Society (with Prof. CHAU Chuck-jee)
- CENG2400Embedded System Design (with Prof. Qiang Xu)
- ENGG1100Introduction to Engineering Design (with Prof. Anthony SUM)