I am a Lecturer (Assistant Professor) at the University of Bristol, working on hardware security and AI security. My research covers physical and microarchitectural hardware security, AI-assisted security analysis, and the security and safety of modern AI systems, including large language models. My work has been published in leading security and cryptography venues, including USENIX Security, NDSS, ASIACRYPT, TCHES, and IEEE TDSC. Several of my works have been referenced in the AIS 46 guidance of the German Federal Office for Information Security (BSI). I have also contributed as a main or co-applicant to several EU- and industry-funded research projects.
Before joining Bristol, I was a postdoctoral researcher in the System Security Lab at TU Darmstadt, working with Prof. Dr.-Ing. Ahmad-Reza Sadeghi, and a postdoctoral research fellow at Radboud University, working with Prof. Dr. Joan Daemen and Prof. Dr. Dr. Stjepan Picek. I obtained my PhD from TU Delft in 2023, supervised by Prof. Dr. ir. Inald Lagendijk and Prof. Dr. Dr. Stjepan Picek. Alongside academia, I worked at SGS Brightsight in the Netherlands from 2017 to 2024, where I became a Principal Security Evaluator and led high-assurance CC EAL5+ security evaluations for globally leading IC designers.
I am looking for motivated PhD students and postdoctoral researchers to join my group. See Positions for details.
What’s new
- 2026.09 Co-chairs STALA 2027: Workshop on Security Testing and Assurance for LLMs and Agents” at NDSS’27, with Stjepan Picek, Wenkai Xu, Nan Lu, and Alexandra Dmitrienko
- 2026.09 Won the HKUST – UoB Global Knowledge Network Awards, together with Shuai Wang
- 2026.09 Invited to Join a Dagstuhl seminar
- 2026.09 Invited to Join Shonan Meeting
- 2026.09 Invited talk at the Graz Security Week 2026
Research interests
- Hardware security (side-channel analysis, fault injection, hardware fuzzing)
- AI security (LLM safety, adversarial and mixture-of-experts attacks)
- AI-augmented physical and micro-architectural hardware security
- Cross-layer security across hardware and AI systems