Fnu Suya

Assistant Professor, Min H. Kao Department of EECS, University of Tennessee, Knoxville

prof_pic.jpg

Min H. Kao Building

Knoxville, TN 37996

I am a tenure-track Assistant Professor in the Min H. Kao Department of Electrical Engineering and Computer Science at the University of Tennessee, Knoxville. From October 2023 to July 2024 I was an MC2 Postdoctoral Fellow at the Maryland Cybersecurity Center at the University of Maryland, College Park. I received my Ph.D. in Computer Science from the University of Virginia, advised by David Evans and Yuan Tian.

My research is on the security of AI — not only the model, but the supporting infrastructure around it.

I am looking for self-motivated students to work on trustworthy machine learning and machine learning for security. Please fill out the questionnaire and send me an email.

A note on my name. I am Mongolian, from China. My preferred full name is Suyee Urcuud — Urcuud is my family name. Suya is the Chinese transliteration of Suyee, and it is the only name on my passport; US paperwork then required a surname, so Fnu ("first name unknown") was assigned as a placeholder and has followed me through every document since. Suyee or Suya both work. I have not yet worked out how to persuade a passport office to print both.

news

Aug 01, 2026 (A)iSpy, a parasitic Trojan that lives in the ML runtime itself, is accepted to ACM CCS 2026.
Mar 20, 2026 Our work on adversarial hubness in multi-modal retrieval is accepted to IEEE S&P 2026.
Mar 10, 2026 DASH, a meta-attack framework for perceptually aligned adversarial examples, is accepted to CVPR 2026.
Dec 10, 2025 HAMLOCK, our hardware–model combined backdoor attack, is accepted to USENIX Security 2026.
Aug 01, 2024 Started as a tenure-track Assistant Professor in the Min H. Kao Department of EECS at the University of Tennessee, Knoxville.

publications [ / ]

* equal contribution  ·  co-corresponding author  ·  underlined names are students I supervise

  1. arXiv
    Token Inflation: How Dishonest Providers Can Overcharge for Large Language Model Usage
    Shahinul Hoque, Jinghuai Zhang, Jinyuan Sun, and Fnu Suya
    2026
  2. CCS
    (A)iSpy: Parasitic Trojans for Machine Learning Infrastructure
    Habibur Rahaman*, Qipan Xu*, Zafaryab Haider, Prabuddha Chakraborty, Swarup Bhunia, and Fnu Suya
    In ACM Conference on Computer and Communications Security, 2026
  3. IEEE S&P
    Adversarial Hubness in Multi-Modal Retrieval
    Tingwei Zhang, Fnu Suya, Rishi Jha, Collin Zhang, and Vitaly Shmatikov
    In IEEE Symposium on Security and Privacy, 2026
  4. USENIX Sec
    HAMLOCK: HArdware-Model LOgically Combined attacK
    Sanskar Amgain*, Daniel Lobo*, Atri Chatterjee*, Swarup Bhunia, and Fnu Suya
    In USENIX Security Symposium, 2026
  5. SaTML
    SoK: Pitfalls in Evaluating Black-Box Attacks
    Fnu Suya*, Anshuman Suri*, Tingwei Zhang, Jingtao Hong, Yuan Tian, and David Evans
    In IEEE Conference on Secure and Trustworthy Machine Learning, 2024
  6. NeurIPS
    What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?
    Fnu Suya, Xiao Zhang, Yuan Tian, and David Evans
    In Advances in Neural Information Processing Systems, 2023
  7. TIFS
    Stealthy Backdoors as Compression Artifacts
    Yulong Tian, Fnu Suya, Fengyuan Xu, and David Evans
    IEEE Transactions on Information Forensics and Security, 2022