AI Safety & Security · University of Waterloo
I aim to build a safer tomorrow today with generative AI. My work critically examines the security and privacy of generative models, with the aim of accurately assessing their vulnerabilities, and developing methods to deploy them responsibly. My current focus is on concept removal techniques (CRTs) for image generative models, and LLM backdoors.

I'm a PhD candidate in Computer Science at the University of Waterloo, co-advised by Profs. N. Asokan and Florian Kerschbaum. My research sits at the intersection of machine learning, security, and privacy: I probe the ways adversaries can corrupt models, and the ways well-intentioned safety techniques quietly fall short, then design methods that actually work.
My current work on backdoors in large language models is supported by a research gift from Coefficient Giving (formerly Open Philanthropy). Before the PhD, I completed my BCS Honours Co-op at Waterloo and led machine-learning efforts in industry, most recently as Lead ML Architect at Shoplogix.
Functional and Secure Code Generation with Task Vectors
Backdooring Bias in Large Language Models
Do Concept Replacement Techniques Really Erase Unacceptable Concepts?
Accord: Application-Driven Networking in the Datacentre
Adversarial machine learning: LLM backdoors, concept erasure in generative models.
Led ML implementation and deployment; built Shoplogix's first AI product, an LLM-based chat agent orchestrated on Amazon ECS.
With N. Asokan and Vasisht Duddu: adversarially robust attestation of confidential ML training data using multi-party computation.
Cut an ELT pipeline's runtime from 3 hours to 15 minutes; architected two new pipelines on AWS Lambda, SQS, S3, and PostgreSQL.
Designed and productionized the company's first NLP pipeline (SageMaker, ULMFiT); content classifier at 95% accuracy.
Deep Q-Network routing strategy for datacentre networks with PyTorch and NetworkX, reaching 98% effectiveness.
Shipped man-in-the-middle attack detection in BlackBerry's Mobile Threat Detection apps using C++ CURL and SSL libraries.
$10,000
$15,000
$5,000
$10,000/year × 2 years
$7,500
$6,000
$1,500
$2,000