Publications

Full list available on Google Scholar.

2026

[1]
Reading Between the Pixels: An Inscriptive Jailbreak Attack on Text-to-Image Models
Z Ying, H Dai, L Hu, et al.
ACM MM 2026
[2]
SafeGen: Goal-Conditioned Video Diffusion of Safety-Critical Scenarios for VLM-Based Autonomous Driving
J Liu, Z Cui, ..., Z Ying et al.
ACM MM 2026
[3]
DeltaUI: Framework-Normalized UI State Transition Modeling for Multi-Task Front-End Engineering
J Lin, Z Guan, ..., Z Ying et al.
ACM MM 2026
[4]
SafeHarbor: Hierarchical Memory-Augmented Guardrail for LLM Agent Safety
Z Liu, Z Ying, W Zhang, et al.
ICML 2026
[5]
DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs
W Xu, Z Wei, Z Ying, et al.
ACL 2026
[6]
AGENTSAFE: Benchmarking the Safety of Embodied Agents on Hazardous Instructions
Z Ying, L Wang, A Liu, et al.
CVPR 2026 🏆 Outstanding Paper Award
[7]
Delegated Misalignment: How Multi-Agent Structures Amplify LLM Safety Risks
Z Ying, J Yan, H Luo, et al.
EMNLP 2026
[8]
Causal Abstention for Cost-Aware Language-Agent Collaboration
L Wei, Q Liu, ..., Z Ying et al.
EMNLP 2026
[9]
SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents
Z Ying, Y Shao, J Gan, et al.
ACL 2026 Findings
[10]
Uncovering Strategic Egoism Behaviors in Large Language Models
Y Zhang, A Liu, Z Ying, et al.
ACL 2026 Findings
[11]
RoboSafe: Safeguarding Embodied Agents via Executable Safety Logic
L Wang, Z Ying, X Yang, et al.
ESR@ICLR 2026 🏆 Outstanding Paper Award
[12]
Mask-GCG: Are All Tokens in Adversarial Suffixes Necessary for Jailbreak Attacks?
J Mu, Z Ying, Z Fan, et al.
ICASSP 2026
[13]
Probabilistic Modeling of Jailbreak on Multimodal LLMs: From Quantification to Application
W Xu, Z Wei, ..., Z Ying et al.
ESORICS 2026
[14]
Robust Rumor Detection Against Noise
W Zhang, X Xuan, ..., Z Ying et al.
Neurocomputing
[15]
DIVER: Dynamic Iterative Visual Evidence Reasoning for Multimodal Fake News Detection
W Zhou, Z Ying, C Meng, et al.
arXiv:2601.07178
[16]
Reasoning-Oriented Programming: Chaining Semantic Gadgets to Jailbreak Large Vision Language Models
Q Zou, M Chen, Z Ying, et al.
arXiv:2603.09246
[17]
Uncovering Security Threats and Architecting Defenses in Autonomous Agents: A Case Study of OpenClaw
Z Ying, X Yang, S Wu, et al.
arXiv:2603.12644
[18]
Evolving Deception: When Agents Evolve, Deception Wins
Z Ying, H Dai, T Zhang, et al.
arXiv:2603.05872
[19]
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
Z Ying, H Wang, J Liu, et al.
arXiv:2604.24118
[20]
GuardAD: Safeguarding Autonomous Driving MLLMs via Markovian Safety Logic
T Zhang, P Yue, ..., Z Ying et al.
arXiv:2605.10386
[21]
TrajShield: Trajectory-Level Safety Mediation for Defending Text-to-Video Models Against Jailbreak Attacks
Q Zou, N Li, ..., Z Ying et al.
arXiv:2605.01761

2025

[1]
Detoxifying Large Language Models via Autoregressive Reward Guided Representation Editing
Y Xiao, A Liu, ..., Z Ying et al.
NeurIPS 2025
[2]
Manipulating Multimodal Agents via Cross-Modal Prompt Injection
L Wang, Z Ying, T Zhang, et al.
ACM MM 2025
[3]
Reasoning-Augmented Conversation for Multi-Turn Jailbreak Attacks on Large Language Models
Z Ying, D Zhang, Z Jing, et al.
EMNLP 2025 Findings
[4]
Jailbreak Vision Language Models via Bi-Modal Adversarial Prompt
Z Ying, A Liu, T Zhang, et al.
IEEE Transactions on Information Forensics and Security
[5]
CogMorph: Cognitive Morphing Attacks for Text-to-Image Models
Z Jing, Z Ying, L Wang, et al.
IEEE Transactions on Dependable and Secure Computing
[6]
PRJ: Perception–Retrieval–Judgement for Generated Images
Q Fu, Z Jing, Z Ying, et al.
Electronics 14 (12), 2354
[7]
SafeBench: A Safety Evaluation Framework for Multimodal Large Language Models
Z Ying, A Liu, S Liang, et al.
International Journal of Computer Vision
[8]
Towards Understanding the Safety Boundaries of DeepSeek Models: Evaluation and Findings
Z Ying, G Zheng, Y Huang, et al.
arXiv:2503.15092
[9]
Pushing the Limits of Safety: A Technical Report on the ATLAS Challenge 2025
Z Ying, S Wu, R Hao, et al.
arXiv:2506.12430
[10]
Prism: Programmatic Reasoning with Image Sequence Manipulation for LVLM Jailbreaking
Q Zou, Z Ying, M Chen, et al.
arXiv:2507.21540
[11]
VEIL: Jailbreaking Text-to-Video Models via Visual Exploitation from Implicit Language
Z Ying, M Chen, N Li, et al.
arXiv:2511.13127
[12]
Sequential Comics for Jailbreaking Multimodal Large Language Models via Structured Visual Storytelling
D Zhang, D Yang, ..., Z Ying et al.
arXiv:2510.15068
[13]
Disentangling Fact from Sentiment: A Dynamic Conflict-Consensus Framework for Multimodal Fake News Detection
W Zhou, Z Ying, R Zhao, et al.
arXiv:2512.20670
[14]
Utilizing Jailbreak Probability to Attack and Safeguard Multimodal LLMs
W Xu, Z Wei, X Sun, et al.
arXiv:2503.06989

2024

[1]
Unveiling the Safety of GPT-4o: An Empirical Study using Jailbreak Attacks
Z Ying, A Liu, X Liu, et al.
arXiv:2406.06302
[2]
CS-Eval: A Comprehensive Large Language Model Benchmark for Cybersecurity
Z Yu, J Zeng, ..., Z Ying et al.
arXiv:2411.16239

2023

[1]
NBA: Defensive Distillation for Backdoor Removal via Neural Behavior Alignment
Z Ying, B Wu
Cybersecurity 6 (1), 20
[2]
DLP: Towards Active Defense Against Backdoor Attacks with Decoupled Learning Process
Z Ying, B Wu
Cybersecurity 6 (1), 9

2021

[1]
DeeSCVHunter: A Deep Learning-Based Framework for Smart Contract Vulnerability Detection
X Yu, H Zhao, ..., Z Ying et al.
IJCNN 2021