Wei Song
Lecturer (~U.S. Assistant Professor), School of Information and Communication Technology (ICT), Griffith University

📢 PhD Students:
I am a Lecturer at Griffith University, and I am looking for self-motivated PhD students to build a research group in AI security — adversarial machine learning, AI watermarking, and AI security for energy systems. Please email me with your CV and transcript if your research interests overlap with mine.
Master's, honours, and capstone students: I am happy to discuss thesis projects linked to my funded industry projects in secure AI and content authenticity. I currently co-mentor three PhD and three Master's students across UNSW Sydney, the National University of Singapore, and Fuzhou University.
Biography
I am a Lecturer (~U.S. Assistant Professor) in the School of Information and Communication Technology (ICT) at Griffith University. Before that, I was a Postdoctoral Research Fellow in the School of Computer Science and Engineering (CSE) at UNSW Sydney, working with Prof. Jingling Xue and Prof. Yulei Sui. I received my Ph.D. in Computer Science and Engineering from UNSW Sydney in 2024, supervised by Prof. Jingling Xue.
My research interests focus on AI security, with particular emphasis on adversarial machine learning, AI watermarking, and AI security for energy systems. My work has been published at leading venues, including USENIX Security, RAID, AAAI, ASE, ACM UbiComp/IMWUT, ICME, and IEEE IoTJ. I have secured AUD 3.7M funding for AI security in energy systems. I am also a co-founder of SunstackAI (Spinout), which provides trustworthy, energy-aware computing load balancing for a distributed GPU network.
News
- 08/2026Our paper rethinking MCP-augmented LLMs has been accepted by EMNLP 2026.
- 08/2026🎉 I will be joining the School of Information and Communication Technology at Griffith University as a Lecturer (~U.S. Assistant Professor). I am recruiting PhD students — see above.
- 06/2026Our TRaCE Lab to Market project “Secure Federated Battery Management System for Distributed Energy Storage Assets” (AUD 1.3M) is now active. I serve as Lead CI.
- 04/2026Two papers on dataset poisoning and LLM debiasing have been accepted by ACL Findings 2026.
- 03/2026Our paper on adversarial attacks against voice control systems has been accepted by ICME 2026.
- 02/2026Our paper on membership inference against Video LLMs has been accepted by SiMLA 2026.
- 01/2026Our demo paper on CAPTCHA for modern web applications has been accepted by WWW 2026.
- 11/2025Our paper on failures to surface harmful content in Video LLMs has been accepted by AAAI 2026.
- 07/2025Our paper on adversarial video defense (ViDToken) has been accepted by RAID 2025.
- 06/2025Our paper on hand biometric authentication has been accepted by IMWUT/UbiComp 2025.
- 05/2025Our paper on adversarial defense for point cloud classification has been accepted by IEEE ICRA 2025.
- 2025VibMilk progressed to a UNSW Invention Record (D2025-0023), with 20+ media reports including ABC Landline and New Atlas.
- 11/2024Started as a Postdoctoral Research Fellow at UNSW Sydney.
- 06/2024My first work on adversarial video defense (SecVID) has been accepted by USENIX Security 2024.
- 03/2024Our paper “VibMilk: Non-Intrusive Milk Spoilage Detection via Smartphone Vibration” has been accepted by IEEE IoTJ.
- 01/2024Our paper “CAvatar: Real-time Human Activity Mesh Reconstruction via Tactile Carpets” has been accepted by IMWUT/UbiComp 2024.
Research Directions
- Adversarial Machine Learning
- Adversarial attacks and defenses for video recognition [USENIX Security '24] [RAID '25]
- Robustness of 3D point-cloud and voice control systems [ICRA '25] [ICME '26]
- Safety and reliability of Video Large Language Models [AAAI '26] [arXiv '25] [arXiv '26]
- Privacy auditing, fairness, and data poisoning for LLMs [SiMLA '26] [ACL Findings '26] [ACL Findings '26]
- Security of agentic and MCP-augmented LLMs [EMNLP '26]
- Adversarially robust sensing and biometric authentication [IEEE IoTJ '22] [UbiComp '25]
- AI Watermarking
- Query-free attacks on deepfake and AI-content watermarking [TIFS, under review]
- Deployable content verification — Digital Content Protector (DCP), with CSIRO Data61
- Next-generation CAPTCHA and human verification [WWW '26 Demo] [arXiv '26]
- AI Security for Energy Systems
- Privacy-preserving federated learning for distributed battery health [TRaCE, Lead CI, 1.3M AUD]
- BMS software-interface security and residential AI compute [Theme Lead CI, 2.4M AUD]
- Secure communication and telemetry data integrity [RACE, Theme Lead CI, 2.0M AUD]
Grants & Funding
- Lead CI in the project “Secure Federated Battery Management System for Distributed Energy Storage Assets”, TRaCE, 1,300,000 AUD (cash). Awarded
- Theme Lead CI in the project “Trustworthy, Energy-Aware Computing Load Balancing for a Distributed Residential GPU Network”, 2,400,000 AUD (cash). Awarded
Publications
(# Equal contribution, * Corresponding author)
2026 (8)
- Help or Hurdle? Rethinking Model Context Protocol-Augmented Large Language Models CORE A*
EMNLP '26 PDF - RamFuzz: LLM-Guided Greybox Fuzzing for Spatial Memory Corruption via Valid Range Violation CORE A*
ASE '26 - NgCaptcha: A CAPTCHA Bridging the Past and the Future
WWW '26 (Demo) PDF - Membership Inference Attacks Against Video Large Language Models
SiMLA '26 - DUAP: Dual-task Universal Adversarial Perturbations Against Voice Control Systems CORE A
ICME '26 PDF - Debiasing LLMs by Masking Unfairness-Driving Attention Heads CORE A*
ACL Findings '26 PDF - Train in Vain: Functionality-Preserving Poisoning to Prevent Unauthorized Use of Code Datasets CORE A*
ACL Findings '26 - Failures to Surface Harmful Contents in Video Large Language Models CORE A*
AAAI '26 PDF
2025 (4)
- HandID: Unobtrusive Gesture-independent User Authentication on Smartphones Using Vibration-based Hand Biometrics CORE A*
ACM IMWUT/UbiComp '25 PDF - ViDToken: A Video-Transformer-Based Latent Token Defense for Adversarial Video Detection CORE A
RAID '25 PDF - ai.txt: A Domain-Specific Language for Guiding AI Interactions with the Internet
arXiv:2505.07834 PDF - SynerGuard: A Robust Framework for Point Cloud Classification via Local Geometry and Spatial Topology CORE A
IEEE ICRA '25 PDF
2024 (4)
- Can Distillation Mitigate Backdoor Attacks in Pre-trained Encoders?
arXiv:2403.03846 PDF - VibMilk: Non-Intrusive Milk Spoilage Detection via Smartphone Vibration JCR Q1 · IF 9.0 UNSW Invention Record
IEEE Internet of Things Journal '24 PDF - CAvatar: Real-Time Human Activity Mesh Reconstruction via Tactile Carpets CORE A*
ACM IMWUT/UbiComp '24 PDF - SecVID: Correction-based Defense Against Adversarial Video Attacks via Discretization-Enhanced Video Compressive Sensing CORE A*
USENIX Security '24 PDF
2022 (3)
- Pistis: Replay Attack and Liveness Detection for Gait-Based User Authentication on Wearable Devices Using Vibration JCR Q1 · IF 9.0
IEEE Internet of Things Journal '22 PDF - Towards Behavior-Independent In-Hand User Authentication on Smartphone Using Vibration
ACM MobiCom '22 (Poster) PDF - Soil Moisture Sensing with mmWave Radar
ACM mmNets '22 (MobiCom Workshop) PDF
2021 (1)
- Towards Privacy-Preserving Digital Contact Tracing
IEEE ICBC '21 PDF
Preprints & Under Review (7)
- DeMark: A Query-Free Black-Box Attack on Deepfake Watermarking Defenses
Under review, IEEE TIFS, 2026 PDF - Enhancing and Reporting Robustness Boundary of Neural Code Models for Intelligent Code Understanding
arXiv:2603.24119, 2026 PDF - SWE-Skills-Bench: Do Agent Skills Actually Help in Real-World Software Engineering?
arXiv:2603.15401, 2026 PDF - FAIRT2V: Training-Free Debiasing for Text-to-Video Diffusion Models
arXiv:2601.20791, 2026 PDF - VideoSTF: Stress-Testing Output Repetition in Video Large Language Models
arXiv:2602.10639, 2026 PDF - Poisoning Prompt-Guided Sampling in Video Large Language Models
arXiv:2509.20851 PDF - Robust CAPTCHA Using Audio Illusions in the Era of Large Language Models: from Evaluation to Advances
arXiv:2601.08516 PDF
Supervision & Mentorship
PhD Students (3)
- Yuxin Cao (PhD at National University of Singapore) — safety evaluation of Video LLMs.
- Bangshuo Zhu (PhD at UNSW Sydney) — robust and trustworthy defense methods for Video LLMs.
- Haonan Zhong (PhD at UNSW Sydney) — safety alignment of large language models for trustworthy deployment.
Master's Students (3)
- Ziqi Ding (UNSW Sydney) — next-generation CAPTCHA design for secure and usable authentication.
- Yingbo Xie (Fuzhou University) — adversarial attacks and defenses for robust gait recognition.
- Peng Yang (Fuzhou University) — reliability and failure analysis of Video LLMs.
Teaching
- Tutor and Course Administrator, COMP3331/9331 Computer Networks and Applications, UNSW, 2019–2024 (13 terms).
- Tutor, COMP4337/9337 Securing Fixed and Wireless Networks, UNSW, 2021.
- Tutor, COMP9444 Neural Networks and Deep Learning, UNSW, 2022.
- Tutor, COMP4336/9336 Mobile Data Networking, UNSW, 2021.
- Tutor, COMP6733 Internet of Things Experimental Design Studio, UNSW, 2021.
Professional Service
- Artifact Evaluation Committee, USENIX Security.
- Reviewer for AI and machine learning venues: AAAI, ICLR, ICML, CVPR, ICME.
- Reviewer for software engineering venues: IEEE/ACM ASE, FSE.
- Reviewer for systems and networking venues: ACM SIGCOMM, ACM MobiSys, ACM SenSys, IEEE IoTDI, ACM/IEEE IPSN.
Education & Experience
- 2026 – Present, Lecturer (~U.S. Assistant Professor), School of Information and Communication Technology, Griffith University.
- Nov 2024 – 2026, Postdoctoral Research Fellow, UNSW Sydney.
- 2019 – 2024, Tutor / Course Administrator, School of Computer Science and Engineering, UNSW Sydney.
- Jan 2022 – May 2022, Software Engineer, Parking Spotz. Mentor: Prof. Wen Hu.
- Dec 2020 – May 2021, Research Assistant, UNSW / Cyber Security Cooperative Research Centre. Privacy-preserving mobile technologies for COVID-19 contact tracing; received UNSW News coverage and was incorporated into COMP4337/9337 teaching materials. Supervisors: Prof. Salil Kanhere and Prof. Sanjay Jha.
- Mar 2021 – Nov 2024, Ph.D. in Computer Science and Engineering, UNSW Sydney. Supervisor: Prof. Jingling Xue.
- Mar 2019 – Dec 2020, Master of Information Technology, UNSW Sydney.
- Sep 2014 – Jun 2018, Bachelor of Civil Engineering, Southwest Jiaotong University (SWJTU), China.

