I am a PhD student in computer science (PhD CSE) at the Pennsylvania
State University. I am advised by Prof. Gang Tan
and work on developing secure and trustworthy software and machine learning systems. Currently, I am
working on formal methods for trustworthy code translation and the security of LLM agents. In
general, I am interested in
topics in the intersection security, privacy, and machine learning.
February 2026: I have accepted a research internship offer from the Bosch Center for AI (BCAI) in Pittsburgh!
February 2026: Our paper Gradient-Free Privacy Leakage in Federated Language Models through Selective Weight Tampering has been accepted at PETS 2026! 🎉🎉
January 2026: Received the ACM/SIGSOFT CAPS travel grant to attend ICSE 2026! 🎉🎉
November 2025: Invited to give a talk on fairness of ML at the University of Illinois, Chicago
November 2025: Invited to serve on the Artifact Evaluation Committee (AEC) of Usenix Security 2026
November 2025: Our paper Chain-of-Thought Driven Adversarial Scenario Extrapolation for Robust Language Models has been accepted at the Annual AAAI Conference on Artificial Intelligence (AAAI) 2026! 🎉🎉
October 2025: Our paper Attention Pruning: Automated Fairness Repair of Language Models via Surrogate Simulated Annealing has been accepted at the International Conference on Software Engineering (ICSE) 2026! 🎉🎉
October 2025: Received the Distinguished Reviewer Award for ACM CCS 2025 artifact evaluation! 🎉🎉
September 2025: Received the Student Travel Grant to attend ICCV 2025! 🎉🎉
July 2025: Invited to serve on the program committee of AAAI 2026 and IEEE TIFS
June 2025: Our paper Improving Noise Efficiency in Privacy-preserving Dataset Distillation has been accepted at the International Conference on Computer Vision (ICCV) 2025! 🎉🎉
May 2025: Our paper Trust Me, I Can Handle It: Self-Generated Adversarial Scenario Extrapolation for Robust Language Models is out on arXiv!
April 2025: Passed the CSE PhD qualifier exam!
March 2025: Our paper Attention Pruning: Automated Fairness Repair of Language Models via Surrogate Simulated Annealing is out on arXiv!
March 2025: Our paper Impact of Data Duplication on Deep Neural Network-Based Image Classifiers: Robust vs. Standard Models has been accepted at the Deep Learning Security
and Privacy Workshop (IEEE S&P 2025)! 🎉🎉
January 2025: Received the Internet Society Fellowship to attend NDSS 2025! 🎉🎉
November 2024: Our paper Privacy-Preserving Data Deduplication for Enhancing
Federated
Learning of Language Models has been accepted at Network and Distributed System Security
(NDSS) Symposium, 2025! 🎉🎉
August 2024: Joined the CSE PhD program at Penn State!
July 2024: Our paper Privacy-Preserving Data Deduplication for Enhancing Federated
Learning of Language Models is out on arXiv!
July 2024: Our paper NeuFair: Neural Network Fairness Repair with Dropout has
been
accepted at ACM ISSTA 2024!
March 2024: Passed my Master's defense!!
January 2024: Employed by Penn State as the Head Graduate Teaching Assistant for CMPSC
465: Data Structures and Algorithms, Spring 2024.
December 2023: Submitted my thesis research on mitigating unfairness in deep learning
to ACM ISSTA 2024!
October 2023: Our paper FLTrojan: Privacy Leakage Attacks against Federated
Language Models Through Selective Weight Tampering is out on arXiv!
October 2023: Our paper EvoquerBot: A multimedia chatbot leveraging synthetic data
for cross-domain assistance has been published at Alexa Prize TaskBot Challenge 2
Proceedings!
August 2023: Joined the OpenMined Research
Team as a Researcher!
August 2023: Employed by Penn State as the Head Graduate Teaching Assistant for CMPSC
465: Data Structures and Algorithms, Fall 2023.
May 2023: Started working with Prof. Gary
Tan and Prof. Saeid Tizpaz-Niari as a Summer
Research Assistant! Working on mitigating unfairness in deep learning models.
May 2023: Got a GPA of 3.9 this semester! Courses: CSE 587: Deep Learning for NLP (A),
CSE 597: Security and Privacy of ML (A), DS 560: Causal Inference (A-), CSE 590: Colloquium (A)
April 2023: Our paper New Results on Machine Learning-Based Distinguishers has
been accepted at IEEE Access!
December 2022: Got a perfect 4.0 GPA this semester! Off to a good start! Courses: IST
597: Adversarial Machine Learning, CSE 543: Computer Security, CSE 511: Operating Systems
Design
September 2022: Our paper PROV-FL: Privacy-preserving Round Optimal Verifiable
Federated Learning has been accepted at the 15th ACM AISec Workshop co-located with ACM
CCS
2022!
August 2022: Employed by Penn State as a Graduate Teaching Assistant for CMPSC 465:
Data Structures and Algorithms, Fall 2022.
Without special annotation (* represents equal contribution), authorship is in order of contribution as per the conventions of security and machine learning research.
Modern Vision-Language Models (VLMs) are robust to visual jailbreaks that use single, holistic images, but their safety alignment does not account for harmful semantics that are distributed across multiple image fragments. We introduce split-image visual jailbreak attacks (SIVA) that exploit this misalignment, evolving from naive splitting to an adaptive white-box attack and culminating in a black-box transfer attack powered by a novel adversarial knowledge distillation (Adv-KD) algorithm. Across four state-of-the-art VLMs and three jailbreak datasets, our strongest attack achieves up to 44% higher transfer success than existing baselines, and we propose efficient ways to address this vulnerability in VLM safety alignment.
Dataset Distillation (DD) is an emerging technique that creates compact synthetic datasets to train models efficiently, but incorporating privacy through Differential Privacy (DP) often leads to degraded performance due to noisy optimization. This work introduces a novel framework that decouples sampling from optimization and improves signal quality by operating in an informative subspace, all without increasing the privacy cost. On CIFAR-10, it achieves a 10.0% accuracy gain with 50 images per class and an 8.3% improvement using just one-fifth the data compared to prior state-of-the-art private DD methods.
We explore pruning attention heads as a post-processing bias mitigation method for large language models (LLMs), addressing fairness concerns as LLMs expand into sensitive social contexts. Our Attention Pruning approach, using fairness-aware surrogate simulated annealing, achieves up to 40% reduction in gender bias and outperforms state-of-the-art bias mitigation strategies.
We develop a novel variant of the Private Set Intersection (PSI) protocol that securely removes all
pairwise duplicates among datasets held by two more users in federated learning. Our protocol
preserves user privacy and does not reveal any information about the datasets to the users and
server. The deduplication protocol results in significant improvement to LLM perplexity and reduces
GPU training time.
NeuFair: Neural Network Fairness Repair with Dropout
Vishnu Asutosh Dasu, Ashish Kumar, Saeid Tizpaz-Niari, Gang Tan
The 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA), 2024
(Acceptance Rate: 20.6%)
We develop randomized algorithms to mitigate unfairness in deep learning by dropping a subset of
neurons from a trained neural network during at inference time. Our results show that a subset of
neurons disparately contributes to unfairness and dropping them out during inference can improve
fairness by up to 69%.
Large Language Models (LLMs) face a range of safety risks, but existing defenses tend to be narrow or overly rigid. We introduce Adversarial Scenario Extrapolation (ASE), an inference-time method that uses Chain-of-Thought reasoning to help LLMs anticipate adversarial scenarios and generate safer, more seamless responses. ASE outperforms six state-of-the-art defenses across multiple benchmarks, achieving near-zero jailbreak success rates, reduced bias, and fewer rejections.
We introduce two novel privacy leakage attacks against federated language models. First, we show
that intermediate model snapshots can leak more sensitive data than the final trained model. Second,
we show that tampering with a model's selective weights responsible for memorizing sensitive data
can aggravate privacy leakage. Our best-performing method outperforms existing attacks with stronger
adversary assumptions.
We study the impact of duplicated images in training sets on image classifier performance, showing that duplication negatively affects training efficiency and accuracy, especially in adversarially trained models. The detrimental effect is more pronounced when duplication is uneven across classes, and increasing uniform duplication offers no significant accuracy improvement.
EvoquerBot is a multimedia chatbot developed for the TaskBot challenge, aimed at assisting users
with cooking and DIY tasks in a single session. The bot addresses challenges like short development
time, data quality, multimedia responses, and tailored conversation flow using agile classifier
development, data augmentation, multimedia response design, and domain-specific dialogue state
machines, ultimately improving user experience through superior task recommendations.
We show new machine learning differential distinguishers for unkeyed and round-reduced versions of
SPECK-32, SPECK-128, ASCON, SIMECK-32, SIMECK-64, and SKINNY-128. Our comprehensive experiments
utilize neural networks and support vector machines in various settings and numerous input
difference tuples.
We propose PROV-FL, a secure and private federated learning protocol. PROV-FL utilizes homomorphic
encryption and differential privacy to provide strong privacy guarantees. It is resilient to user
dropouts/joins, supports verifiable aggregation, and requires only a single round of communication
without a full-trusted third party.
We propose an end-to-end solution to perform SCA on stream ciphers by combining automated tools such
as ML, MILP, and SMT. We demonstrate its efficacy by taking electromagnetic traces from a 32-bit
software platform and performing SCA on the TRIVIUM stream cipher.
We develop a method to extend the Boyar-Peralta's
algorithm to use XOR3 gates, add XOR3 gates to existing XOR2 implementations, and
show several SOTA results on the linear layers of block ciphers using different logic libraries.
Further Insights On Implementation Of The Linear Layer
Anubhab Baksi, Banashri Karmakar, Vishnu Asutosh Dasu, Dhiman Saha, Anupam
Chattopadhyay
Security and Implementation of Lightweight Cryptography Workshop (SILC), EUROCRYPT 2021
We provide new insights for different notions of XOR count, develop methods to find sequential XOR
count implementations using SMT and MILP, and present new results using XOR3 gates on the AES
MixColumn matrix.
Student Travel Grant: Received the ACM/SIGSOFT CAPS travel grant to attend ICSE 2026.
Distinguished Reviewer Award: Received the Distinguished Reviewer Award as a member of the Artifact Evaluation Committee for ACM CCS 2025.
Student Travel Grant: Received the Student Travel Grant to attend ICCV 2025.
Internet Society Fellowship: Received the Internet Society Fellowship to attend and
present my work at NDSS 2025.
TCS Citation Award (3-time Recipient): Received the TCS Citation Award and appreciation
from the Chief Technical Officer and Head of TCS Research thrice for performance and outstanding
contribution to the organization.
Best Project Award: Received the Best Project Award among 13 teams during the Fifth
Summer School on Computer
Vision, Graphics and Image Processing, Indian Statistical Institute (ISI) Kolkata.
IGVC: Placed 2nd in the Interoperability Profiles Challenge and 9th overall at
Intelligent Ground Vehicle Competition (IGVC) 2018 among 26 teams. Second-best among all
teams from India.
ACM ICPC Regionals: Represented Manipal Institute of Technology, Manipal at the 2017
ACM ICPC Asia Regional Contest.
DAGsHub Award: Received a $500 award from DAGsHub for successfully reproducing
GANSpace: Discovering Interpretable GAN Controls and completing the ML Reproducibility
Challenge Spring 2021.
Grants
NSF NAIRR 260079: Automated and Verified Migration of Legacy eBPF Programs to Rust. Total Award: $8000. 2026-2027
Service
Senior Program Committee member for AAAI, 2027 special track on AI alignment
Judge for Penn State Undergraduate Exhibition 2025
Organizer for Penn State Security Reading Group
Teaching Experience
Head Teaching Assistant: CMPSC 465: Data Structures and Algorithms (Fall 2023, Spring 2024)
Teaching Assistant: CMPSC 461: Programming Language Concepts (Fall 2025), CMPSC 465: Data Structures and Algorithms (Fall 2022)
Talks
Mitigating Unfairness in Deep Learning at the University of Illinois at Chicago. Delivered a guest lecture as a part of CS 594: Responsible Data Science and Algorithmic Fairness (slides)
Improving Noise Efficiency in Privacy-Preserving Dataset Distillation at Penn State Security Reading Group (slides)
Attention Pruning: Automated Fairness Repair of Language Models via Surrogate Simulated Annealing at INSR Industry Day 2025
Privacy-Preserving Data Deduplication for Enhancing Federated Learning of Language Models at NDSS 2025, San Diego, USA
Attention Pruning: Automated Fairness Repair of Language Models via Surrogate Simulated Annealing at Penn State AI Week 2025
NeuFair: Neural Network Fairness Repair with Dropout at ACM ISSTA 2024, Vienna, Austria
Secure Code Generation using LLMs at Penn State Security Reading Group (slides)
Technical Reports
"Where's Waldo?"
Ritwik Sarkar* and Vishnu Asutosh Dasu*
Presented at the Fifth Summer School on Computer Vision, Graphics, and Image Processing,
Indian Statistical Institute (ISI), Kolkata, 2018
slides
Recipient of the Best Project Award
We develop a technique to determine the 3D coordinates of a human from a live video feed using a
camera with a single lens (monocamera setup).
Professional Memberships
Student Member of the ACM
Student Member of IEEE
Hobbies
I enjoy powerlifitng, playing the guitar, and reading about history, theology, and philosophy.