About Me
I’m currently an Assistant Professor at Zhongguancun Academy. Before joining Zhongguancun Academy, I obtained my PhD from the Digital Security group at Radboud University, where I was fortunate to be advised by Stjepan Picek. I also spent eight months as a postdoctoral researcher at Radboud University.
Before that, I earned my MSc in Advanced Computing from the University of Bristol and a BEng in Software Engineering from the University of Electronic Science and Technology of China. I also spent two years as a Research Assistant at ISCAS before starting my PhD.
Research Interests:
My research interests lie primarily in adversarial machine learning and designing robust and general defenses against risks in machine learning technologies.
News
- 2026.09: One paper accepted to S&P 2027.
- 2026.06: One paper accepted to UIST 2026.
- 2026.06: TPC member @ USENIX Security 2027.
- 2025.11: MIMIR in NDSS 2026.
- 2025.09: TPC member @ CCS 2026.
- 2025.05: One paper accepted to CCS 2025.
- 2025.02: MIMIR achieved TOP 1 on RobustBench ImageNet Leaderboard
- 2024.09: BAN in NeurIPS 2024
Explore the Town
Publications

MIMIR: Masked Image Modeling for Mutual Information-based Adversarial Robustness
Xiaoyun Xu, Shujian Yu, Zhuoran Liu, Stjepan Picek
Network and Distributed System Security (NDSS) Symposium, 2026




Towards Backdoor Stealthiness in Model Parameter Space
Xiaoyun Xu, Zhuoran Liu, Stefanos Koffas, Stjepan Picek
ACM Conference on Computer and Communications Security (CCS), 2025

BAN: Detecting Backdoors Activated by Adversarial Neuron Noise
Xiaoyun Xu, Zhuoran Liu, Stefanos Koffas, Shujian Yu, Stjepan Picek
Advances in Neural Information Processing Systems (NeurIPS), 2024

Universal Soldier: Using universal adversarial perturbations for detecting backdoor attacks
Xiaoyun Xu, Oguzhan Ersoy, Behrad Tajalli, Stjepan Picek
IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W), 2024

Poster: Boosting Adversarial Robustness by Adversarial Pre-training
Xiaoyun Xu, Stjepan Picek
ACM Conference on Computer and Communications Security (CCS), 2023

IB-RAR: Information Bottleneck as Regularizer for Adversarial Robustness
Xiaoyun Xu, Guilherme Perin, Stjepan Picek
IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W), 2023

Information leakage by model weights on federated learning
Xiaoyun Xu, Jingzheng Wu, Mutian Yang, Tianyue Luo, Xu Duan, Weiheng Li, Yanjun Wu, Bin Wu
In Proceedings of the 2020 workshop on privacy-preserving machine learning in practice, CCS workshop PPLMP, 2020
Educations
- 2022 - 2025, PhD student, Radboud University
- 2017 - 2018, Master, University of Bristol
- 2013 - 2017, Undergraduate, University of Electronic Science and Technology of China (UESTC)
Services
-
Reviewer/PC: USENIX Security, CCS, BMVC, ICLR, NeurIPS, SaTML, TIFS
-
External Reviewer: IEEE SP, NDSS
-
Session Chair: SaTML
Miscellaneous
- Outside of research, I enjoy seeing the world, exploring diverse cultures and local cuisines, and taking in landscapes.
- The Legend of Zelda, Sid Meier’s Civilization VI, The Binding of Isaac, Don’t Starve.