ReLU Hull Approximation
Approximate ReLU hulls by reusing their linear pieces and constructing enclosing upper faces, rather than building the exact hull.
Diving deep into my PhD journey at The University of Queensland.
I study the verification, security, and privacy of AI systems, with a focus on neural network verification and convex approximation.
Selected work in verification, model control, and privacy.
Approximate ReLU hulls by reusing their linear pieces and constructing enclosing upper faces, rather than building the exact hull.
Use double-linear-piece functions to simplify local activation geometry and construct convex over-approximations beyond ReLU.
Lock a network behind a small subset of its own significant weights, so holding the key gives the whole capability and not holding it gives part of it.
Defend collaborative training against gradient inversion by substituting tokens that are semantically distinct but close in embedding space.
Explore how these projects connect across my research, or browse the complete publication list.
Tutorial · A series in progress
29 chapters in 4 parts, from what a network can be asked to prove to how the relaxation is built and solved. Written to be read in order.
Acceptances, awards and releases.
Our paper Catch-Only-One: Non-Transferable Examples for Model-Specific Authorization is accepted by NeurIPS'26 as an oral presentation (112 of 30709 submissions, about 0.36%). Congrats, Zihan, Ethan and Zhongkui!
Our paper Non-Transferable Examples receives the Best Paper Award - Runner Up at the ECCV'26 LifeGenIP Workshop. Congrats, Zihan!
Our paper Re-Key-Free, Risky-Free: Adaptable Model Usage Control is accepted by Euro S&P'26. Congrats, Zihan!
Our paper Mitigating Gradient Inversion Risks in Language Models via Token Obfuscation is accepted by Asia CCS'2026. Congrats, Xinguo!
Our paper Convex Hull Approximation for Activation Functions is accepted by OOPSLA'25 within SPLASH'25. Happy!
Our paper AI Model Modulation with Logits Redistribution is accepted by WWW'25. Congrats, Zihan!
Our paper Uncovering Gradient Inversion Risks in Practical Language Model Training is accepted by CCS'24. Congrats, Xinguo!
Our paper CORELOCKER: Neuron-level Usage Control is accepted by S&P'24. Congrats, Zihan! [Live Video]
Our paper ReLU Hull Approximation is accepted by POPL'24.
Notes on the tools behind the work.
A dual-track shape inference tool that resolves ONNX's dynamic shapes to concrete static values for neural network verification workflows.
January 2026A pure Python toolkit for optimizing ONNX models specifically for verification workflows, validated on the VNN-COMP 2024 benchmark suites.
January 2026