AI Safety & Security · University of Waterloo

Anudeep Das

I aim to build a safer tomorrow today with generative AI. My work critically examines the security and privacy of generative models, with the aim of accurately assessing their vulnerabilities, and developing methods to deploy them responsibly. My current focus is on concept removal techniques (CRTs) for image generative models, and LLM backdoors.

PhD candidate, Computer ScienceCo-advised by Profs. N. Asokan & Florian Kerschbaumanudeep.das@uwaterloo.caCV ↗
Anudeep Das

About

I'm a PhD candidate in Computer Science at the University of Waterloo, co-advised by Profs. N. Asokan and Florian Kerschbaum. My research sits at the intersection of machine learning, security, and privacy: I probe the ways adversaries can corrupt models, and the ways well-intentioned safety techniques quietly fall short, then design methods that actually work.

My current work on backdoors in large language models is supported by a research gift from Coefficient Giving (formerly Open Philanthropy). Before the PhD, I completed my BCS Honours Co-op at Waterloo and led machine-learning efforts in industry, most recently as Lead ML Architect at Shoplogix.

Publications

Google Scholar ↗

Functional and Secure Code Generation with Task Vectors

Wang F., Das, A., Nagappan, M., & Asokan N.

arXiv preprint2026

Backdooring Bias in Large Language Models

Das, A., Chantasantitam, P., Singh, G., He, L., Ponomarenko, M., & Kerschbaum, F.

arXiv preprint2026

Do Concept Replacement Techniques Really Erase Unacceptable Concepts?

Das, A., Singh, G., Chantasantitam, P., & Asokan, N.

arXiv preprint2025

Espresso: Robust Concept Filtering in Text-to-Image Models

Das, A., Duddu, V., Zhang, R., & Asokan, N.

ACM CODASPY2025Best Paper Award

Attesting Distributional Properties of Training Data for Machine Learning

Duddu, V., Das, A., Khayata, N., Yalame, H., Schneider, T., & Asokan, N.

ESORICS2024

Accord: Application-Driven Networking in the Datacentre

Mortazavi, S. H., Shafieirad, H., Bahnasy, M., Munir, A., Cheng, Y., Das, A., & Ganjali, Y.

IEEE/ACM UCC2021

Experience

2024 — now

PhD Researcher · University of Waterloo

Adversarial machine learning: LLM backdoors, concept erasure in generative models.

2024

Lead Machine Learning Architect · Shoplogix

Led ML implementation and deployment; built Shoplogix's first AI product, an LLM-based chat agent orchestrated on Amazon ECS.

2023

Undergraduate Research Fellow · University of Waterloo

With N. Asokan and Vasisht Duddu: adversarially robust attestation of confidential ML training data using multi-party computation.

2023

Data Engineer · Shoplogix

Cut an ELT pipeline's runtime from 3 hours to 15 minutes; architected two new pipelines on AWS Lambda, SQS, S3, and PostgreSQL.

2021

Machine Learning Engineer · VTS

Designed and productionized the company's first NLP pipeline (SageMaker, ULMFiT); content classifier at 95% accuracy.

2020

ML Research Engineer · Huawei Technologies

Deep Q-Network routing strategy for datacentre networks with PyTorch and NetworkX, reaching 98% effectiveness.

2020

ML Software Developer · BlackBerry

Shipped man-in-the-middle attack detection in BlackBerry's Mobile Threat Detection apps using C++ CURL and SSL libraries.

Awards & Grants

2026

Cybersecurity and Privacy Excellence Graduate Scholarship

$10,000

2026

Queen Elizabeth II Graduate Scholarship in Science & Technology

$15,000

2026

President's Graduate Scholarship

$5,000

2025

David R. Cheriton Graduate Scholarship

$10,000/year × 2 years

2023

Undergraduate Research Fellowship

$7,500

2023

Math Undergraduate Research Award

$6,000

2022

President's Research Award

$1,500

2018

President's Scholarship of Distinction

$2,000

Teaching & Service

2025

Teaching Assistant · CS 446/646: Software Design & Architecture

2024

Teaching Assistant · CS 135: Designing Functional Programs

2025 — 2026

Artifact Reviewer · Proceedings on Privacy Enhancing Technologies (PoPETs)

Distinguished Artifact Reviewer
2025

Reviewer · CPI Graduate Student Conference