I am an M.S. student at the College of Computer Science and Technology, Zhejiang University, advised by Prof. Zhikun Zhang. I received my B.Eng. degree in Cyberspace Security from Huazhong University of Science and Technology in 2025, graduating 1st out of 98 students in the program.

My research interests include AI security, trustworthy AI, and data provenance.

🔥 News

  • 2026.09:  🎉 Bit Accuracy is not Enough was accepted by IEEE S&P 2027.
  • 2026.08:  🎉 DWBench was accepted by ACM CCS 2026.
  • 2026.08:  🎉 InceptionRAG was accepted by ACM CCS 2026.
  • 2025.06:  🎓 Received my B.Eng. degree in Cyberspace Security from Huazhong University of Science and Technology.

📝 Publications

S&P 2027
Bit Accuracy is not Enough

Bit Accuracy is not Enough: Revisiting User Capacity of Multi-bit Watermarks

Xiao Ren, Zhikun Zhang, Linkang Du, Yunjun Gao, Min Chen

IEEE Symposium on Security and Privacy (S&P), 2027

This work introduces identity capacity (IC), a deployment-oriented metric that quantifies the maximum number of distinct identities a multi-bit watermark can reliably support under a target transmission condition and failure budget. We develop a search-based framework for estimating identity capacity and systematically evaluate representative audio and image watermarking methods across different mapping schemes and transmission conditions.

CCS 2026
DWBench

Xiao Ren*, Xinyi Yu*, Linkang Du, Min Chen, Yuanchao Shu, Zhou Su, Yunjun Gao, Zhikun Zhang

ACM Conference on Computer and Communications Security (CCS), 2026

* Equal contribution.

DWBench provides a unified benchmark and open-source toolkit for systematically evaluating dataset watermarking methods across classification and generation tasks. It evaluates watermark robustness, multi-watermark coexistence, and multi-user interference under standardized settings, revealing limitations of conventional single-watermark evaluations in practical copyright auditing.

Project Page

CCS 2026
InceptionRAG

InceptionRAG: Stealthy Poisoning Attack Against Retrieval-Augmented Generation

Jiachang Zhang, Min Chen, Xiao Ren, Zhenyong Zhang, Yuanchao Shu, Yunjun Gao, Zhikun Zhang

ACM Conference on Computer and Communications Security (CCS), 2026

InceptionRAG studies stealthy corpus poisoning attacks against retrieval-augmented generation, where malicious information is distributed across individually benign-looking documents and activated through their combined context.

💻 Internship

  • Research Intern

    Sep. 2024 - Jun. 2025

    Intelligent Software Research Center, Institute of Software, Chinese Academy of Sciences, Beijing, China

    Contributed to the development and maintenance of RustSBI Agent, an open-source domain-specific LLM and retrieval-augmented generation project for RustSBI and RISC-V knowledge.

🎖 Honors and Awards

  • 2025.06: Outstanding Undergraduate Thesis, Huazhong University of Science and Technology.
  • 2025.06: Outstanding Graduate, Huazhong University of Science and Technology.
  • 2024.12: National Scholarship, Ministry of Education of China.
  • 2023.12: National Scholarship, Ministry of Education of China.
  • 2022.12: National Scholarship, Ministry of Education of China.

🧑‍💻 Academic Service

  • Reviewer for IEEE Symposium on Security and Privacy (S&P 2027).
  • Reviewer for International Conference on Learning Representations (ICLR 2026).
  • Reviewer for ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD 2025).
  • Reviewer for ACM Computing Surveys (CSUR).
  • Reviewer for IEEE Transactions on Dependable and Secure Computing (TDSC).

📖 Education

  • Sep. 2025 - Jun. 2028 (expected), Zhejiang University, M.S., College of Computer Science and Technology, Hangzhou, China. Advisor: Prof. Zhikun Zhang.
  • Sep. 2021 - Jun. 2025, Huazhong University of Science and Technology, B.Eng. in Cyberspace Security, Wuhan, China. Graduated 1st out of 98 students in the program.