About

I am an Associate Professor in the Department of Computer Science at Purdue University and co-director of the Purdue Security Laboratory (PurSec Lab). I am also affiliated with the Center for Education and Research in Information Assurance and Security (CERIAS). I earned my Ph.D. in Computer Science and Engineering from Penn State University, where I was advised by Professor Patrick McDaniel and served as the lead graduate student in the Systems and Internet Infrastructure Security Laboratory (SIIS).

My research lies at the intersection of AI and systems security. My group studies vulnerability discovery and attack analysis in complex software and systems, the security of agentic systems, and security of autonomous systems. We develop and evaluate security techniques using program analysis, formal methods, security analytics, and artificial intelligence, with an emphasis on real-world security problems. Our work spans enterprise and software systems, autonomous and robotic systems, industrial control systems, mobile platforms, and other complex computing environments. To learn more about our research, you can explore our publications. My research has appeared in news broadcasts and technology news outlets, e.g., Wired, Ars Technica, and The Register.

My research group actively publishes at leading security conferences, including USENIX Security, IEEE S&P, ACM CCS, and NDSS. Our work has been supported by federal and government sponsors, including NSF, ONR, DARPA, USDOT, DOE, the United States Military Academy, and Sandia National Laboratories, as well as industry-supported research from Google, Apple, Cisco, Qualcomm, Rolls Royce, Denso North America Foundation, and Amazon. I am part of major research efforts including the NSF AI Institute ACTION, DARPA FIREFLY, and the USDOT National Center TraCR.

My research group and I have received multiple awards, including the NSF CAREER Award (2022), the Google Aspire Award (2021, 2022, and 2023), the Amazon Research Award (2024), and the Google Academic Research Award (2025); paper awards such as the ACM CCS Distinguished Paper Award (2024), the USENIX Security Honorable Mention Paper Award (2025), the USENIX Security Distinguished Paper Runner-Up (2026), the Andreas Pfitzmann Best Paper Award and Best Presentation Award at Privacy Enhancing Technologies (PoPETs) (2026), and the Test-of-Time Award at the IEEE European Symposium on Security and Privacy (EuroS&P) (2026); and university recognition such as the Most Influential Professor Award from the Purdue CS Graduate Student Board (2020 and 2024) and the College of Science Faculty Leadership Award (2024).

I contribute to the research community through various service roles. Currently, I serve as the Secretary/Treasurer of the ACM Special Interest Group on Security, Audit and Control (SIGSAC), as an Associate Editor of IEEE Transactions on Information Forensics and Security (TIFS), and as a co-moderator for cs.CR, the Cryptography and Security subject area on arXiv.

News

Research Group

Current Students

Past Ph.D. Students

  • Raymond Muller (2025) Signal and Image Processing Engineer for Security at Lawrence Livermore National Laboratory (LLNL)
  • Arjun Arunasalam (2025) Assistant Professor in the Knight Foundation School of Computing and Information Sciences at Florida International University
  • Reham Aburas (2024) Assistant Professor in the Department of Computer Science and Engineering at the American University of Sharjah
  • Muslum Ozgur Ozmen (2024) Assistant Professor in the School of Computing and Augmented Intelligence at Arizona State University
  • Habiba Farrukh (2023) Assistant Professor in the Department of Computer Science at the University of California, Irvine

Past Co-advised Ph.D. Students

  • Doguhan Yeke (2026) Applied Researcher, Capital One (co-advised with Antonio Bianchi)
  • Hyungsub Kim (2024) Assistant Professor in the Department of Computer Science at Indiana University (co-advised with Dongyan Xu and Antonio Bianchi)
  • Khaled Serag (2023) Research Scientist at Qatar Computing Research Institute (QCRI) (co-advised with Dongyan Xu)
  • Abdulellah Alsaheel (2023) Private Security Consultant (co-advised with Dongyan Xu)

Full list of Students

Prospective Students

Fall 2026, Spring 2027 I am looking for motivated PhD students and research interns. If you are interested in security, I would be glad to speak with you.

If you are not a Purdue student, please fill out this form. Purdue students may email me about undergraduate and graduate research opportunities.

Selected Publications

2026
2025
2024

For the complete list of publications, please see the Publications page.

All publications

Teaching

CS 426: Computer Security (Undergraduate)

This introductory undergraduate course covers the principles of building secure computer systems and the basics of security best practices. It spans cryptography, network security, systems security, and privacy. Students leave with practical skills for understanding threats and designing more secure software, protocols, and systems.

CS 590: IoT/CPS Security (Graduate)

This graduate course surveys current research on securing Internet of Things and Cyber-Physical Systems. It introduces the foundations of safety and security, along with methods for verification, detection, and repair. Example topics include voice-controlled devices, edge computing, industrial control systems, and autonomous vehicles.

CS 529: Security Analytics (Graduate)

This graduate course explores the intersection of security and machine learning. It is organized into two parts: machine learning for security and the security of machine learning systems. Students build the background needed to study both attacks and defenses across learning and inference.

Full list of courses