About
I am an Assistant Professor of Computer Science at
UMass Amherst CICS.
I co-lead AI Security
Lab at UMass with Amir Houmansadr and co-lead AI Safety Initiative with
Shlomo Zilberstein.
I am also a senior research scientist (part-time) at Google working on agentic privacy
and security.
In my group, we look at security and privacy attack vectors for AI
systems deployed in the real world.
My research was recognized by
Apple Scholars in AI/ML Fellowship
and a USENIX Security'24
Distinguished Paper Award. My group is supported by the
Schmidt Sciences Trustworthy AI Grant.
I completed my PhD at
Cornell Tech
advised by
Vitaly
Shmatikov
and
Deborah
Estrin.
Before graduate school, I earned an engineering degree from
Baumanka
and worked at Cisco as a software engineer.
I grew up in
Tashkent
and play water polo.
Recruitment:
I am not looking for new PhD students.
Announcement: We are running a
Trustworthy AI Seminar Series
with Emiliano De Cristofaro.
Check the speakers and subscribe to
videos
and emails.
Current Research and Selected Papers
Agentic and Multi-Agent Systems
We proposed AirGapAgent (ACM CCS'24)
for privacy and Conseca (HotOS'25)
for security of agents
leveraging the theory of Contextual Integrity.
Recently, we studied
prompt leakage (USENIX Security'26) in research agents
and investigated throttling to prevent denial of
service or scraping by web agents. Finally, our Colosseum
framework discovers new collusion artifacts in multi-agent systems.
Selected Papers
Colosseum: Auditing Collusion in Cooperative Multi-Agent Systems
Mason Nakamura, Abhinav Kumar, Saswat Das, Sahar Abdelnabi, Saaduddin Mahmud, Ferdinando Fioretto, Shlomo Zilberstein, and Eugene Bagdasarian.
arXiv'26
Contextual Agent Security: A Policy for Every Purpose
Lillian Tsai and Eugene Bagdasarian.
HotOS'25
AirGapAgent: Protecting Privacy-Conscious Conversational Agents
Eugene Bagdasarian, Ren Yi, Sahra Ghalebikesabi, Peter Kairouz, Marco Gruteser, Sewoong Oh, Borja Balle, and Daniel Ramage.
ACM CCS'24
LLM and Reasoning Attacks
We developed attacks on large language models including an
attack (IEEE S&P'22)
on generative language models that enables propaganda generation.
We recently proposed the OverThink
attack on reasoning models that exploits their chain-of-thought mechanisms.
Privacy
We applied Contextual Integrity to Agentic problems and form-filling tasks (TMLR'25)
and investigated context ambiguity (NeurIPS'25) in privacy reasoning.
We worked on aspects of differential privacy including fairness
trade-offs (NeurIPS'19),
applications to location
heatmaps (PETS'21), and tokenization
methods (ACL FL workshop'22)
for private federated learning. We built the
Ancile (WPES'19)
system that enforces use-based privacy of user data.
Multimodal Security
We studied vulnerabilities in multimodal systems including
self-interpreting images (USENIX
Security'25)
and adversarial illusions (USENIX Security'24, Distinguished Paper Award)
that can manipulate vision-language models. Our work demonstrates novel
attack vectors in systems that process both visual and textual information.
We also study how attacks on world models
can compromise robot learning pipelines.
Selected Papers
Targeting World Models to Compromise Robot Learning Pipelines
Ethan Rathbun, Ahmed Agha, Saaduddin Mahmud, Christopher Amato, Alina Oprea, and Eugene Bagdasarian.
Preprint'26
Self-interpreting Adversarial Images
Tingwei Zhang, Collin Zhang, John X. Morris, Eugene Bagdasarian, and Vitaly Shmatikov.
USENIX Security'25
Adversarial Illusions in Multi-Modal Embeddings
Distinguished Paper Award
Tingwei Zhang, Rishi Jha, Eugene Bagdasaryan, and Vitaly Shmatikov.
USENIX Security'24
PhD students: Abhinav
Kumar, June
Jeong (co-advised w Amir Houmansadr),
Dzung Pham (co-advised w Amir Houmansadr).
Recent collaborators:
Amir Houmansadr,
Shlomo
Zilberstein,
Sahar Abdelnabi,
Brian Levine,
Kyle Wray,
George Bissias,
Ali Naseh,
Jaechul Roh,
Mason Nakamura,
Saaduddin Mahmud,
and many others.
Teaching
CS 360 · Introduction to Security
SP'25, SP'26
Take the class — or explore the interactive demos.
CS 684 · Trustworthy and Responsible AI
FA'25, FA'26
Graduate course on safety, privacy, and alignment for modern AI systems — course site.
CS 692PA · Seminar on Privacy and Security for GenAI
FA'24, SP'25, FA'25
Reading group on the latest research in GenAI security — seminar site.
Service
Academic Service
Recent Program Committees:
- ACM CCS'24/'25, ICLR'24/25/26, IEEE S&P'26, IEEE S&P'27
Workshop Organizer:
Broadening Participation
I co-organize
PLAIR
(Pioneer Leaders in AI and Robotics), an outreach program
that introduces high school students across Western Massachusetts to
the world of robotics and AI safety. Please reach out if you are
interested in joining.