I graduated from EE College, Zhejiang University (浙江大学电气学院) with a bachelor’s degree and now studying for PhD in USSLAB, advised by Prof. Xiaoyu Ji (冀晓宇) and Prof. Wenyuan Xu (徐文渊).

My research focuses on embodied AI security and safety, especially in the following research directions:

  • Red-teaming for Embodied AI: uncovering how embodied AI systems can be steered into unsafe behavior, and measuring comprehensive risks across perception, planning, and execution.
  • Safety Alignment for Embodied AI: extending safety alignment from LLMs/VLMs to VLAs/WAMs, so that embodied AI systems act in accordance with human values.
  • Defense for Embodied AI Systems: building safeguards across the whole pipeline, from proactive filtering of unsafe inputs to post-hoc detection of unsafe behavior.

My work has appeared in security and AI venues including NDSS, ACM CCS, AAAI, and WWW. I have published 6 papers at CCF-A conferences with total .

🔥 News

  • 2026.07:  🎉🎉 NDSS 2027, Easier Said Than Done: Unpacking the Intent–Behavior Gap in Jailbreaking LLM-based Robots.
  • 2026.04:  🎉🎉 CCS 2026, GhostTac: Manipulating Tactile Sensors without Physical Contact.
  • 2025.11:  🎉🎉 AAAI 2026, Phantom Menace: Exploring and Enhancing the Robustness of VLA Models against Physical Sensor Attacks.
  • 2024.09:  🎉🎉 NDSS 2025, PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR.
  • 2024.01:  🎉🎉 WWW 2024, Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack.
  • 2023.09:  🎉🎉 NDSS 2024, Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time.

📝 Publications

NDSS 2027
sym
Easier Said Than Done: Unpacking the Intent–Behavior Gap in Jailbreaking LLM-based Robots

Xuancun Lu, Zhengxian Huang, Xinfeng Li, Chi Zhang, Xiaoyu Ji, Wenyuan Xu

  • We reveal an intent–behavior gap in jailbreaking LLM-based robots: malicious-looking policies rarely translate into harmful physical executions, because existing attacks overlook robot-specific syntax constraints and physical feasibility. We propose POEF, an automated red-teaming framework that embeds these constraints into both prompt optimization and evaluation, achieving an 80% behavior jailbreak success rate on the Unitree G1, the Franka arm, and simulators, and we present two defenses.
CCS 2026
sym
GhostTac: Manipulating Tactile Sensors without Physical Contact

Kun Wang, Xuancun Lu, Ruochen Zhou, Kai Wang, Tongjun Ye, Yihao Shao, Chen Yan, Xiaoyu Ji, Wenyuan Xu

  • We present GhostTac, the first contactless attack that manipulates tactile sensing via electromagnetic interference (EMI). By exploiting nonlinear rectification and limited-bandwidth amplification, crafted EMI signals become a persistent DC offset that bypasses on-board filtering, enabling fine-grained control over sensor outputs and inducing harmful robot behaviors such as excessive grasping force. We validate GhostTac on 15 tactile sensors across 10 modules and 2 dexterous hands, with case studies on grasping, slip detection, and material classification.
AAAI 2026
sym
Phantom Menace: Exploring and Enhancing the Robustness of VLA Models against Physical Sensor Attacks

Xuancun Lu, Jiaxiang Chen, Shilin Xiao, Zizhi Jin, Zhangrui Chen, Hanwen Yu, Bohan Qian, Ruochen Zhou, Xiaoyu Ji, Wenyuan Xu

  • We present the first systematic study of physical sensor attacks against Vision-Language-Action (VLA) models. Our “Real-Sim-Real” framework automatically simulates six camera attacks and two microphone attacks and validates them on real robots, exposing vulnerabilities whose severity depends critically on task type and model design. We further develop an adversarial-training-based defense that improves robustness to these out-of-distribution perturbations while preserving model performance.
NDSS 2025
sym
PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR

Zizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan, Xiaoyu Ji, Wenyuan Xu

  • We show that a LiDAR’s laser receiving circuit, monitoring sensors, and beam-steering modules still couple with intentional electromagnetic interference (IEMI) despite strict EMC testing. Exploiting these attack surfaces, PhantomLiDAR achieves Points Interference, Injection, Removal, and even LiDAR Power-Off, demonstrated on five COTS LiDARs in both simulated and real-world moving scenarios, along with sensor- and vehicle-level defenses.
WWW 2024
sym
Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack

Zizhi Jin, Xuancun Lu, Bo Yang,Yushi Chen, Chen Yan, Xiaoyu Ji, Wenyuan Xu

  • Our new benchmark features 5 types of LiDAR attacks and 6 types of camera attacks. Different from traditional benchmarks, we take the physical sensor attacks into consideration during the corruption construction. Then, we systematically investigate 7 MSF-based and 5 single-modality 3D object detection models with different fusion architectures.
NDSS 2024
sym
Inaudible Adversarial Perturbation: Manipulating the Recognition of User Speech in Real Time

Xinfeng Li, Chen Yan, Xuancun Lu, Zihan Zeng, Xiaoyu Ji, Wenyuan Xu

  • We propose VRIFLE, an inaudible adversarial perturbation (IAP) attack via ultrasound delivery that can manipulate ASRs as a user speaks.

📖 Educations

  • 2023.06 - now, PhD, USSLAB, EE College, Zhejiang Univeristy, Hangzhou.
  • 2019.09 - 2023.06, Undergraduate, EE College, Zhejiang Univeristy, Hangzhou.

🧑‍⚖️ Services

  • Reviewer, AAAI Conference on Artificial Intelligence (AAAI).
  • Reviewer, Transactions on Information Forensics & Security (TIFS).