I am a computer scientist and educator (and also an AI hacker) dedicated to addressing threats to the trustworthiness and social responsibility of AI-enabled systems, while fostering the next-generation workforce capable of auditing, characterizing, and countering these threats. I received the Google Faculty Research Award 2023 and the Samsung Global Research (GRO) Award 2024, 2023. I was selected as a DARPA Riser (2022) and invited as a speaker at USENIX Enigma (2021).

Hiring. I have two open PhD/MS positions on model distillation, model resilience, and agentic systems. Please read this page and fill out this form if you're motivated to work with me.
Bio

I am an Assistant Professor of Computer Science at Oregon State Univ. I earned my Ph.D. from the University of Maryland, College Park, under the supervision of Prof. Tudor Dumitras in 2021, and my bachelor's degree from Seoul National University in 2015. I spent a winter at Google Brain in 2021 (working with Dr. Nicholas Carlini and Dr. Alexey Kurakin) and 6-months at Frame.io in 2017 (working with Dr. Abhinav Srivastava).

News
Aug 21, 2026
Two papers accepted to EMNLP 2026 Findings. Congratulations Jaewoo and Leo!
May 1, 2026
I will serve as an Area Chair for NeurIPS 2026.
Apr 30, 2026
Two papers are accepted to ICML 2026. Congratulations Jose and Jayoung!
Apr 15, 2026
A paper is accepted to ISSTA 2026!
Apr 1, 2026
A paper is accepted to IEEE S&P 2026. See you all at San Francisco!
Dec 9, 2025
Zach's paper on NAS poisoning is accepted to TMLR 2025. Congratulations!
Sep 23, 2025
Derek's paper on TOCTOU vulnerability in agentic systems is accepted to NeurIPS 2025 Workshop. Congratulations!
Sep 18, 2025
Zachary's paper on detoxifying LLMs is accepted to NeurIPS 2025. Congratulations!
Aug 13, 2025
A paper with Zachary's contribution is accepted to SC 2025. Congratulations!
Aug 12, 2025
Leo's Privacy-Backdoor paper is on AI4Privacy Post!
Jun 25, 2025
Dongwoo, Zach, and Aiden's paper is accepted to ICCV 2025. Congratulations!
Jun 11, 2025
A paper is accepted to IEEE TVCG 2025 and also presented in IEEE VIS 2025!
Show older news (39) ↓
Selected Publications [Full list]
SoK: Watermarking for AI-Generated Content
Xuandong Zhao, Sam Gunn, Miranda Christ, Jaiden Fairoze, Andres Fabrega, Nicholas Carlini, Milad Nasr, Sanghyun Hong, Florian Tramer, Sanjam Garg, Somesh Jha, Lei Li, Yu-Xiang Wang, and Dawn Song
The 46th IEEE Symposium on Security and Privacy (IEEE S&P). 2025.
PDF
Privacy Backdoors: Enhancing Membership Inference through Poisoning Pre-trained Models
Yuxin Wen, Leo Marchyok, Sanghyun Hong, Jonas Geiping, Tom Goldstein, and Nicholas Carlini
Advances in Neural Information Processing Systems (NeurIPS). 2024.
Parameterized Physics-informed Neural Networks for Parameterized PDEs
Woojin Cho, Minju Jo, Haksoo Lim, Kookjin Lee, Dongeun Lee, Sanghyun Hong, and Noseong Park
International Conference on Machine Learning (ICML). 2024. [Oral]
Handcrafted Backdoors in Deep Neural Networks
Sanghyun Hong, Nicholas Carlini, and Alexey Kurakin
Advances in Neural Information Processing Systems (NeurIPS). 2022. [Oral]
Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets
Florian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, Nicholas Carlini (*authors ordered reverse-alphabetically)
The ACM Conference on Computer and Communications Security (CCS). 2022.
PDF | Code | Media
Data Poisoning Won't Save You From Facial Recognition
Evani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini, and Florian Tramer
International Conference on Learning Representations (ICLR). 2022.
A Panda? No, It's a Sloth: Slowdown Attacks on Adaptive Multi-Exit Neural Network Inference
*Sanghyun Hong, *Yigitcan Kaya, Ionuţ-Vlad Modoranu, and Tudor Dumitraș (*equal contribution)
International Conference on Learning Representations (ICLR). 2021. [Spotlight]
Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks
Sanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida, and Tudor Dumitraș
Proceedings of The 28th USENIX Security Symposium (USENIX Security). 2019.
Shallow-Deep Networks: Understanding and Mitigating Network Overthinking
Yigitcan Kaya, Sanghyun Hong, and Tudor Dumitraș
International Conference on Machine Learning (ICML). 2019.
PDF | Code

View all publications →