I will present LDPKiT at the 6th IWAPS, co-located with ARES 2026, in Linköping, Sweden.
Kexin Li (Cassie)
李可欣
PhD Student in Computer Engineering at the University of Toronto
I work in safe and trustworthy AI provenance. See publications here.
I am advised by Prof. David Lie in the Toronto Systems Security Lab.
How to pronounce my first name: kě xīn.
Recent news
RFC2TLA+ was accepted to the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026) and will appear in Munich, Germany.
I attended ICML 2026 in Seoul and served on the program committee of the Trustworthy AI for Good workshop.
New preprint, “LambdaMark: Semantic Audio Watermarking for Robustness and Radioactivity,” is now available on arXiv.
Promoted to Brazilian Jiu-jitsu blue belt and received the Most Technically Improved Student Award.
New preprint, “HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models,” is now available on arXiv.
New preprint, “HarmonicAttack: An Adaptive Cross-Domain Audio Watermark Removal,” is now available on arXiv.
Won gold at the Godai Jiu-jitsu Open Gi & No-Gi Championship.
Selected as an ethics reviewer for the NeurIPS Research and Datasets & Benchmarks tracks.
Started my PhD in Computer Engineering at the University of Toronto.
Successfully defended my master’s thesis, “Recovering Utility in LDP Schemes by Training with Noise².”
“Provenance of Training without Training Data” was accepted to The Web Conference 2023.
Joined the Toronto Systems Security Lab as a graduate student.
Graduated with High Honours from the University of Toronto and received a Certificate of Distinction for the PixelArt capstone project.
Joined Intel, now Altera, as a software engineering intern.
Our work on high-level synthesis for registered-routing FPGAs was published at ICFPT 2019.
Received the University of Toronto Excellence Summer Research Award.
Publication
RFC2TLA+: Extracting and Verifying Formal Models from RFC Documents using Continuous LLM Feedback
41st IEEE/ACM International Conference on Automated Software Engineering, Munich, Germany.
Conference pageLDPKiT: Superimposing Remote Queries for Privacy-Preserving Distillation
6th International Workshop on Advances on Security and Privacy Technologies and Solutions, Linköping, Sweden.
PaperLambdaMark: Semantic Audio Watermarking for Robustness and Radioactivity
PaperHMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models
PaperHarmonicAttack: An Adaptive Cross-Domain Audio Watermark Removal
PaperProvenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership Verification
DOIHigh-Level Synthesis Techniques to Generate Deeply Pipelined Circuits for FPGAs with Registered Routing
IEEE XploreEducation
PhD in Computer Engineering
University of Toronto
Trustworthy machine learning and systems security. Supervised by Prof. David Lie.
MASc in Computer Engineering
University of Toronto · Grade: A+
Thesis: Recovering Utility in LDP Schemes by Training with Noise². Developed methods that improve model utility under local differential privacy while maintaining strong privacy guarantees.
BASc in Computer Engineering, High Honours
University of Toronto · CGPA: 3.91 / 4.0
Computer Engineering Specialist with a Minor in Artificial Intelligence.
High School Diploma
Nanchang No. 2 High School Sino-Canadian Program
Graduated with the Governor General’s Academic Medal.
Selected Grants, Fellowships & Awards
- Queen Elizabeth II Graduate Scholarship in Science & Technology
- SRI Graduate Fellowship, Schwartz Reisman Institute
- University of Toronto Fellowship
- Certificate of Distinction, Capstone Project, University of Toronto
- Dean’s Honour List, University of Toronto
- University of Toronto Excellence Summer Research Award [4 recipients]
Experience
Industry & Research
Software Engineer
- Enhanced LLVM-based HLS compiler toolchains for Intel FPGAs, improving performance and robustness.
- Shipped compiler features and analysis passes for complex FPGA workloads across device families.
- Diagnosed performance and resource regressions through weekly quality-of-results analysis.
Research Intern
Institute for Network Sciences and Cyberspace · Supervisor: Prof. Qi Li
- Designed a privacy-preserving DNN ownership verification mechanism robust to model extraction.
- Evaluated security limitations and defense effectiveness across diverse adversarial threat models.
Summer Research Intern
Programmable Digital Systems Group · Supervisor: Prof. Jason H. Anderson
- Extended the LegUp High-Level Synthesis framework for register-rich FPGA architectures.
- Implemented LLVM backend improvements for deeper, higher-performance pipelines.
Professional Services and Affiliations
- Program Committee Member, AI4Good Workshop at ICML 2026 and NeurIPS 2026
- Reviewer, AI4Good Workshop at ICML 2026 and NeurIPS 2026
- Graduate Fellow Affiliate, Schwartz Reisman Institute (2026 – Present)
- Faculty Affiliate Researcher, Vector Institute (2023 – Present)
- Graduate Fellow, Schwartz Reisman Institute (2025 – 2026)
- NeurIPS Conference Ethics Reviewer (2024, 2025, 2026)
- NeurIPS Datasets and Benchmarks Track Ethics Reviewer (2025, 2026)
Teaching
Teaching Assistant
- ECE1508H1 Deep Generative Models
- ECE1508H1 Applied Deep Learning
- ECE568H1 Computer Security
- ECE244H1 Programming Fundamentals
Project
Safe & Trustworthy AI Provenance
2026 · Research
LambdaMark
Semantic audio watermarking designed for robustness and radioactivity.
2025 · Research
HMARK
A multi-bit semantic-latent watermark for diffusion models that enables provenance tracing while preserving visual quality.
2025 · Research
HarmonicAttack
An adaptive cross-watermark and cross-domain framework for assessing and strengthening psychoacoustic-based imperceptible audio watermark robustness against removal attacks.
2023 · Research
Provenance of Training
Privacy-preserving DNN ownership verification without access to the original training data, published at WWW ’23.
AI for Software & Systems Engineering
2026 · ASE
RFC2TLA+
Extracting formal TLA+ models from RFC documents and verifying them through continuous feedback from large language models.
2025 · Course Research
Accurate & Efficient CUDA Generation
A compiler-inspired reinforcement learning framework that optimizes Triton kernels for functional correctness and runtime speed using GRPO.
Privacy-Preserving ML
2026 · IWAPS @ ARES
LDPKiT
A privacy-preserving model distillation framework that superimposes remote queries to generate approximately in-distribution samples, improving knowledge transfer under local differential privacy.
Others
2022 · Capstone
PixelArt
A synthetic graphical data-generation pipeline using Blender and neural networks; recipient of the University of Toronto Certificate of Distinction.
2020 · Machine Learning
RECTNet
Transfer-learning models for facial detection and emotion recognition, trained on AffectNet.
2019 · Research
LegUp High-Level Synthesis
LLVM backend extensions and Stratix 10 support for deeper, higher-performance FPGA pipelines.
2019 · Software
Mapping Service
A full-stack C++ map with routing, geolocation, search, TSP optimization, and 3D street-view features.
2019 · Embedded Systems
Game of Life
An interactive FPGA implementation controlled through board keys and a PS/2 keyboard.
2018 · Digital Design
FPGA Music Game
A hardware game integrating video input, PS/2 controls, VGA graphics, game logic, and audio output.
2018 · Web Application
WeChat Mini Program
A social video-sharing application with account, profile, and media-upload features.
2018 · Data
Web Information Extractor
A Python and regular-expression scraper for extracting and analyzing audience metrics.
2018 · Design Research
Mann Museum
Research and concept development for a museum featuring virtual reality and high-dynamic-range imaging.
2018 · Social Impact
Learning Program for Haiti
Led a team that designed an off-grid energy approach for delivering Khan Academy through a Haitian NGO.