Yao Tong

PhD student, National University of Singapore

I am Yao Tong (童遥), a Ph.D. student in Computer Science at the National University of Singapore, supervised by Prof. Reza Shokri. I am currently a visiting researcher at ETH Zurich (SPY Lab), working with Prof. Florian Tramer. I received my B.E. in Computer Science and Engineering from The Chinese University of Hong Kong, Shenzhen, where I was advised by Prof. Baoyuan Wu, who inspired my first steps into research.

My research focuses on understanding and building controllable, user-centered AI systems. I study how to interpret, evaluate, and govern the behavior of AI systems, and how to identify and mitigate their privacy, security, and safety risks. My recent interests center on agent memory and personalization systems, especially the risks and control challenges that arise when AI agents remember, adapt to, and act on behalf of users.

My previous work spans several related themes:

  • Understanding and interpreting model behaviors and capabilities. I study phenomena such as intrinsic biases and generalization, and how they are shaped by different stages of the learning pipeline, including model initialization, data distributions, training paradigms, and inference-time methods.
  • Data and model provenance. How behavioral signals can support model fingerprinting, model lineage detection, copyright-related auditing, and data usage auditing, turning model properties into tools for attribution and protection.
  • Controllability and alignment in interactive agents. How agents that remember, personalize, and adapt to users can remain controllable, auditable, and aligned with user intent.
🗞️

News

Jan '26
🎉 Happy to share two first-author works at ICLR 2026 that I personally find very interesting. One shows that a model's random initialization can leave persistent, seed-level fingerprints throughout its lifecycle (much like human fingerprints). The other uses shortest-path tasks to study which parts of the training pipeline contribute to LLMs' generalization in structured problem solving. See you in Rio de Janeiro!
Oct '25
Honored as a Top Reviewer at NeurIPS 2025!
Mar '25
DUCI is available in the open-source privacy auditing toolkit PrivacyMeter!
Feb '25
🎉 DUCI was selected for an Oral presentation at ICLR 2025 (Top 1.5% of submissions). See you in Singapore!
May '24
🎉 Our paper The Stronger the Diffusion Model, the Easier the Backdoor: Data Poisoning to Induce Copyright Breaches Without Adjusting Finetuning Pipeline was selected for an Oral presentation at ICML 2024 (Top 1.5% of submissions). Interested in the first Copyright Infringement Attack? See you in Vienna!

Selected Publications

(* denotes equal contribution)

Selected Projects

Privacy Meter logo
An open-source library to audit data privacy in statistical and machine learning algorithms via membership inference.
  • Implemented privacy auditing tools such as DUCI and RMIA.
  • Contributed to the development and long-term maintenance of the library as one of the organizers.

Awards and Honors

Oral Paper Award - ICLR 2025, ICML 2024
Top Reviewer Award - NeurIPS 2025.
President Graduate Fellowship - NUS, 2023, 2024, 2025.
University Research Award - CUHKSZ, 2021, 2022.
Dean's List - CUHKSZ, 2020, 2021, 2022.
School Academic Scholarship - CUHKSZ, 2021, 2022.
Bowen Scholarship - CUHKSZ, 2019, 2020, 2021, 2022.

Professional Services

Reviewer:
  TMLR, ICLR 2026, NeurIPS 2025 (Top Reviewer), ICLR 2025, ICML Workshop 2025, NeurIPS Workshop 2025

Sub-reviewer:
  CCS 2024, USENIX Security 2024

Contact

I'm always happy to connect for research discussions or to share broader interests. I have a wide range of passions — from the arts (music, calligraphy, painting, engraving, and pottery) to sports (I go skiing every winter), and even clothing design, where I enjoy creating my own modern Chinese-style clothing. Just email me tongyao[at]u.nus.edu.