👋Tony (Lipeng) He
I am a student, software engineer, and researcher at the University of Waterloo.
I'm pursuing a Master of Mathematics (Research/Thesis) degree in Computer Science at UWaterloo. I am grateful to be advised by N. Asokan.
I'm part of Secure Systems Group (SSG), Cryptography, Security, and Privacy (CrySP) Lab, and the Cybersecurity and Privacy Institute (CPI). I also worked with Jian Liu at ABC Lab, Zhejiang University. Currently, my office is located in the William G. Davis Computer Research Centre, DC 3333B, M3.
I'm in pursuit of knowledge, experience, and the various other beautiful things life has to offer. I strive to live deliberately. Before research, I spent some years doing software engineering. In the limit of my life, I also hope to be a pianist, writer, podcaster, designer, and entrepreneur.
My research focuses on Trustworthy Machine Learning, with an emphasis on the security, privacy, and safety of large language models (LLMs) and modern Artificial Intelligence (AI) systems. I develop effective and efficient adversarial attacks, as well as principled defenses, drawing on applied cryptography, theoretical machine learning, and computer security to characterize and mitigate emerging threats.
More broadly, I am interested in alignment, interpretability, and reinforcement learning for building controllable and reliable AI systems.
I also study the design and software engineering of agentic systems for both AI-for-security use cases and real-world business applications, with a particular focus on the security and privacy of LLM-based agents and multi-agent systems.
A central goal of my work is to bridge theoretical security research with real-world deployments and viable business models, enabling more trustworthy AI in practice.
Activation Approximations Can Incur Safety Vulnerabilities Even in Aligned LLMs: Comprehensive Analysis and Defense
LookAhead: Preventing DeFi Attacks via Unveiling Adversarial Contracts
Secure Transformer Inference Made Non-interactive
On the Atomicity and Efficiency of Blockchain Payment Channels
FedVLP: Visual-aware Latent Prompt Generation for Multimodal Federated Learning
A Survey of Multimodal Federated Learning: Background, Applications, and Perspectives
Always Aligned: Understanding and Preserving Safety in Fine-Tuned LLMs
SoK: Colluding Adversaries in Machine Learning Pipelines
Locket: Robust Feature-Locking Technique for Language Models
Safety at One Shot: Patching Fine-Tuned LLMs with A Single Instance
Beyond Detection: A Federated Prompt Industrial Anomaly Analysis Framework with Expert Knowledge
StructEval: Benchmarking LLMs' Capabilities to Generate Structural Outputs
Token-by-Token Manipulation: Inference-Time Jailbreaking on Production LLMs via Autoregressive Harmful Guidance
UWaterloo Cybersecurity and Privacy Institute (CPI) Graduate Student Conference (GradConf 2025)
Program Committee Member
USENIX Security Symposium 2026
Artifact Evaluation
Program Committee Member
Privacy Enhancing Technologies Symposium (PoPETs/PETS) 2026
Artifact Evaluation
Program Committee Member
ACM Conference on Computer and Communications Security (CCS) 2025
Artifact Evaluation
Invited Reviewer
IEEE Transactions on Dependable and Secure Computing (TDSC)
Student Member
Association for Computing Machinery (ACM)
lipenghe@acm.org
AWS Startup Activate Credits (Portfolio)
USD 25,000
Amazon
Lambda Research Grant Program
USD 5,000; Principal Investigator: N. Asokan
λ (Lambda) AI
David R. Cheriton Graduate Scholarship
CAD 10,000
University of Waterloo
International Master's Award of Excellence (IMAE)
CAD 7,500
University of Waterloo
University of Waterloo
Instructional Apprentice (IA)
CS 135 Designing Functional Programs
University of Waterloo
Instructional Support Assistant (ISA)
CS 135 Designing Functional Programs
Bluelet AI
Co-Founder & CTO
Agentic AI and data platform solutions for talent acquisition and matching
University of Waterloo
Research Assistant (URA)
Cryptography, Security, and Privacy (CrySP) Lab
Zhejiang University
Research Assistant
ABC Lab, Institute of Cyberspace Research
BioRender
Full Stack Software Engineer
SaaS, Y Combinator W18
Toronto, ON
Safyre Labs
Full Stack Software Engineer
E-Commerce Platform, Supply Chain
North York, ON
Bitbuy
Software Engineer
Cryptocurrency Exchange, Publicly Traded on TSX: WNDR
Toronto, ON
University of Waterloo
Master's Degree (Research/Thesis)
Computer Science
University of Waterloo
Honours Bachelor's Degree (Co-op)
Mathematics (Minor in Computing)
Nanyang Technological University
Exchange Student (GEM Trailblazer)
Mathematical Sciences
New Article Everytime I Publish :)