I will present LDPKiT at the 6th IWAPS, co-located with ARES 2026, in Linköping, Sweden.
Kexin Li (Cassie)
李可欣
PhD Student in Computer Engineering at the University of Toronto
I work in safe and trustworthy AI provenance. See publications here.
I am advised by Prof. David Lie in the Toronto Systems Security Lab.
How to pronounce my first name: kě xīn.
Recent news
RFC2TLA+ was accepted to the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026) and will appear in Munich, Germany.
I attended ICML 2026 in Seoul and served on the program committee of the Trustworthy AI for Good workshop.
New preprint, “LambdaMark: Semantic Audio Watermarking for Robustness and Radioactivity,” is now available on arXiv.
Promoted to Brazilian Jiu-jitsu blue belt and received the Most Technically Improved Student Award.
New preprint, “HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models,” is now available on arXiv.
New preprint, “HarmonicAttack: An Adaptive Cross-Domain Audio Watermark Removal,” is now available on arXiv.
Won gold at the Godai Jiu-jitsu Open Gi & No-Gi Championship.
Selected as an ethics reviewer for the NeurIPS Research and Datasets & Benchmarks tracks.
Started my PhD in Computer Engineering at the University of Toronto.
Successfully defended my master’s thesis, “Recovering Utility in LDP Schemes by Training with Noise².”
“Provenance of Training without Training Data” was accepted to The Web Conference 2023.
Joined the Toronto Systems Security Lab as a graduate student.
Graduated with High Honours from the University of Toronto and received a Certificate of Distinction for the PixelArt capstone project.
Joined Intel, now Altera, as a software engineering intern.
Our work on high-level synthesis for registered-routing FPGAs was published at ICFPT 2019.
Received the University of Toronto Excellence Summer Research Award.
Publication
RFC2TLA+: Extracting and Verifying Formal Models from RFC Documents using Continuous LLM Feedback
41st IEEE/ACM International Conference on Automated Software Engineering, Munich, Germany.
Conference pageLDPKiT: Superimposing Remote Queries for Privacy-Preserving Distillation
6th International Workshop on Advances on Security and Privacy Technologies and Solutions, Linköping, Sweden.
PaperLambdaMark: Semantic Audio Watermarking for Robustness and Radioactivity
PaperHMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models
PaperHarmonicAttack: An Adaptive Cross-Domain Audio Watermark Removal
PaperProvenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership Verification
DOIHigh-Level Synthesis Techniques to Generate Deeply Pipelined Circuits for FPGAs with Registered Routing
IEEE XploreEducation
PhD in Computer Engineering
University of Toronto · Grade: A+
Trustworthy machine learning and systems security. Supervised by Prof. David Lie.
MASc in Computer Engineering
University of Toronto · Grade: A+
Thesis: Recovering Utility in LDP Schemes by Training with Noise². Developed methods that improve model utility under local differential privacy while maintaining strong privacy guarantees.
BASc in Computer Engineering, High Honours
University of Toronto · CGPA: 3.91 / 4.0
Computer Engineering Specialist with a Minor in Artificial Intelligence.
High School Diploma
Nanchang No. 2 High School Sino-Canadian Program
Graduated with the Governor General’s Academic Medal.
Selected Grants, Fellowships & Awards
- Queen Elizabeth II Graduate Scholarship in Science & Technology
- SRI Graduate Fellowship, Schwartz Reisman Institute
- University of Toronto Fellowship
- Certificate of Distinction, Capstone Project, University of Toronto
- Dean’s Honour List, University of Toronto
- University of Toronto Excellence Summer Research Award [4 recipients]
Experience
Industry & Research
Software Engineer
- Enhanced LLVM-based HLS compiler toolchains for Intel FPGAs, improving performance and robustness.
- Shipped compiler features and analysis passes for complex FPGA workloads across device families.
- Diagnosed performance and resource regressions through weekly quality-of-results analysis.
Research Intern
Institute for Network Sciences and Cyberspace · Supervisor: Prof. Qi Li
- Designed a privacy-preserving DNN ownership verification mechanism robust to model extraction.
- Evaluated security limitations and defense effectiveness across diverse adversarial threat models.
Summer Research Intern
Programmable Digital Systems Group · Supervisor: Prof. Jason H. Anderson
- Extended the LegUp High-Level Synthesis framework for register-rich FPGA architectures.
- Implemented LLVM backend improvements for deeper, higher-performance pipelines.
Professional Services and Affiliations
- Program Committee Member, AI4Good Workshop at ICML 2026 and NeurIPS 2026
- Reviewer, AI4Good Workshop at ICML 2026 and NeurIPS 2026
- Graduate Fellow Affiliate, Schwartz Reisman Institute (2026 – Present)
- Faculty Affiliate Researcher, Vector Institute (2023 – Present)
- Graduate Fellow, Schwartz Reisman Institute (2025 – 2026)
- NeurIPS Conference Ethics Reviewer (2024, 2025, 2026)
- NeurIPS Datasets and Benchmarks Track Ethics Reviewer (2025, 2026)
Teaching
Teaching Assistant
- ECE1508H1 Deep Generative Models
- ECE1508H1 Applied Deep Learning
- ECE568H1 Computer Security
- ECE244H1 Programming Fundamentals
Project
Safe & Trustworthy AI Provenance
2026 · Research
LambdaMark
Semantic audio watermarking designed for robustness and radioactivity.
2025 · Research
HMARK
A multi-bit semantic-latent watermark for diffusion models that enables provenance tracing while preserving visual quality.
2025 · Research
HarmonicAttack
An adaptive cross-watermark and cross-domain framework for assessing and strengthening psychoacoustic-based imperceptible audio watermark robustness against removal attacks.
2023 · Research
Provenance of Training
Privacy-preserving DNN ownership verification without access to the original training data, published at WWW ’23.
AI for Software & Systems Engineering
2026 · ASE
RFC2TLA+
Extracting formal TLA+ models from RFC documents and verifying them through continuous feedback from large language models.
2025 · Course Research
Accurate & Efficient CUDA Generation
A compiler-inspired reinforcement learning framework that optimizes Triton kernels for functional correctness and runtime speed using GRPO.
Privacy-Preserving ML
2026 · IWAPS @ ARES
LDPKiT
A privacy-preserving model distillation framework that superimposes remote queries to generate approximately in-distribution samples, improving knowledge transfer under local differential privacy.
Others
2022 · Capstone
PixelArt
A synthetic graphical data-generation pipeline using Blender and neural networks; recipient of the University of Toronto Certificate of Distinction.
2020 · Machine Learning
RECTNet
Transfer-learning models for facial detection and emotion recognition, trained on AffectNet.
2019 · Research
LegUp High-Level Synthesis
LLVM backend extensions and Stratix 10 support for deeper, higher-performance FPGA pipelines.
2019 · Software
Mapping Service
A full-stack C++ map with routing, geolocation, search, TSP optimization, and 3D street-view features.
2019 · Embedded Systems
Game of Life
An interactive FPGA implementation controlled through board keys and a PS/2 keyboard.
2018 · Digital Design
FPGA Music Game
A hardware game integrating video input, PS/2 controls, VGA graphics, game logic, and audio output.
2018 · Web Application
WeChat Mini Program
A social video-sharing application with account, profile, and media-upload features.
2018 · Data
Web Information Extractor
A Python and regular-expression scraper for extracting and analyzing audience metrics.
2018 · Design Research
Mann Museum
Research and concept development for a museum featuring virtual reality and high-dynamic-range imaging.
2018 · Social Impact
Learning Program for Haiti
Led a team that designed an off-grid energy approach for delivering Khan Academy through a Haitian NGO.