Kexin Li (Cassie)

李可欣

PhD Student in Computer Engineering at the University of Toronto

I work in safe and trustworthy AI provenance. See publications here.

I am advised by Prof. David Lie in the Toronto Systems Security Lab.

How to pronounce my first name: kě xīn.

Recent news

Scroll for more

Promoted to Brazilian Jiu-jitsu blue belt and received the Most Technically Improved Student Award.

Won gold at the Godai Jiu-jitsu Open Gi & No-Gi Championship.

Selected as an ethics reviewer for the NeurIPS Research and Datasets & Benchmarks tracks.

Started my PhD in Computer Engineering at the University of Toronto.

Successfully defended my master’s thesis, “Recovering Utility in LDP Schemes by Training with Noise².”

Joined the Toronto Systems Security Lab as a graduate student.

Graduated with High Honours from the University of Toronto and received a Certificate of Distinction for the PixelArt capstone project.

Joined Intel, now Altera, as a software engineering intern.

Our work on high-level synthesis for registered-routing FPGAs was published at ICFPT 2019.

Received the University of Toronto Excellence Summer Research Award.

Publication

2026
PreprintarXiv:2606.21365

LambdaMark: Semantic Audio Watermarking for Robustness and Radioactivity

Kexin Li, Xiao Hu, Ilya Grishchenko, and David Lie

Paper
2025
PreprintarXiv:2512.00094

HMARK: Radioactive Multi-Bit Semantic-Latent Watermarking for Diffusion Models

Kexin Li, Guozhen Ding, Ilya Grishchenko, and David Lie

Paper
2025
PreprintarXiv:2511.21577

HarmonicAttack: An Adaptive Cross-Domain Audio Watermark Removal

Kexin Li*, Xiao Hu*, Ilya Grishchenko, and David Lie * Equal contribution

Paper
2023
WWW ’23Conference

Provenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership Verification

Yunpeng Liu, Kexin Li, Zhuotao Liu, Bihan Wen, Ke Xu, Weiqiang Wang, Wenbiao Zhao, and Qi Li

DOI
2019
ICFPT 2019Conference

High-Level Synthesis Techniques to Generate Deeply Pipelined Circuits for FPGAs with Registered Routing

Yu Ting Chen, Jin Hee Kim, Kexin Li, Graham Hoyes, and Jason H. Anderson

IEEE Xplore

Education

2024 — Present

PhD in Computer Engineering

University of Toronto

Trustworthy machine learning and systems security. Supervised by Prof. David Lie.

Trustworthy MLSystems SecurityAdversarial Robustness
2022 — 2024

MASc in Computer Engineering

University of Toronto · Grade: A+

Thesis: Recovering Utility in LDP Schemes by Training with Noise². Developed methods that improve model utility under local differential privacy while maintaining strong privacy guarantees.

2017 — 2022

BASc in Computer Engineering, High Honours

University of Toronto · CGPA: 3.91 / 4.0

Computer Engineering Specialist with a Minor in Artificial Intelligence.

2017

High School Diploma

Nanchang No. 2 High School Sino-Canadian Program

Graduated with the Governor General’s Academic Medal.

Selected Grants, Fellowships & Awards

  • Queen Elizabeth II Graduate Scholarship in Science & Technology
  • SRI Graduate Fellowship, Schwartz Reisman Institute
  • University of Toronto Fellowship
  • Certificate of Distinction, Capstone Project, University of Toronto
  • Dean’s Honour List, University of Toronto
  • University of Toronto Excellence Summer Research Award [4 recipients]

Experience

Industry & Research

Intel Corporation (now Altera)

Software Engineer

  • Enhanced LLVM-based HLS compiler toolchains for Intel FPGAs, improving performance and robustness.
  • Shipped compiler features and analysis passes for complex FPGA workloads across device families.
  • Diagnosed performance and resource regressions through weekly quality-of-results analysis.
Tsinghua University

Research Intern

Institute for Network Sciences and Cyberspace · Supervisor: Prof. Qi Li

  • Designed a privacy-preserving DNN ownership verification mechanism robust to model extraction.
  • Evaluated security limitations and defense effectiveness across diverse adversarial threat models.
University of Toronto

Summer Research Intern

Programmable Digital Systems Group · Supervisor: Prof. Jason H. Anderson

  • Extended the LegUp High-Level Synthesis framework for register-rich FPGA architectures.
  • Implemented LLVM backend improvements for deeper, higher-performance pipelines.

Professional Services and Affiliations

  • Program Committee Member, AI4Good Workshop at ICML 2026 and NeurIPS 2026
  • Reviewer, AI4Good Workshop at ICML 2026 and NeurIPS 2026
  • Graduate Fellow Affiliate, Schwartz Reisman Institute (2026 – Present)
  • Faculty Affiliate Researcher, Vector Institute (2023 – Present)
  • Graduate Fellow, Schwartz Reisman Institute (2025 – 2026)
  • NeurIPS Conference Ethics Reviewer (2024, 2025, 2026)
  • NeurIPS Datasets and Benchmarks Track Ethics Reviewer (2025, 2026)

Teaching

University of Toronto

Teaching Assistant

  • ECE1508H1 Deep Generative Models
  • ECE1508H1 Applied Deep Learning
  • ECE568H1 Computer Security
  • ECE244H1 Programming Fundamentals

Project

Safe & Trustworthy AI Provenance

2025 · Research

HMARK

A multi-bit semantic-latent watermark for diffusion models that enables provenance tracing while preserving visual quality.

2025 · Research

HarmonicAttack

An adaptive cross-watermark and cross-domain framework for assessing and strengthening psychoacoustic-based imperceptible audio watermark robustness against removal attacks.

2023 · Research

Provenance of Training

Privacy-preserving DNN ownership verification without access to the original training data, published at WWW ’23.

AI for Software & Systems Engineering

2025 · Course Research

Accurate & Efficient CUDA Generation

A compiler-inspired reinforcement learning framework that optimizes Triton kernels for functional correctness and runtime speed using GRPO.

Privacy-Preserving ML

Others

2022 · Capstone

PixelArt

A synthetic graphical data-generation pipeline using Blender and neural networks; recipient of the University of Toronto Certificate of Distinction.

2020 · Machine Learning

RECTNet

Transfer-learning models for facial detection and emotion recognition, trained on AffectNet.

2019 · Research

LegUp High-Level Synthesis

LLVM backend extensions and Stratix 10 support for deeper, higher-performance FPGA pipelines.

2019 · Software

Mapping Service

A full-stack C++ map with routing, geolocation, search, TSP optimization, and 3D street-view features.

2019 · Embedded Systems

Game of Life

An interactive FPGA implementation controlled through board keys and a PS/2 keyboard.

2018 · Digital Design

FPGA Music Game

A hardware game integrating video input, PS/2 controls, VGA graphics, game logic, and audio output.

2018 · Web Application

WeChat Mini Program

A social video-sharing application with account, profile, and media-upload features.

2018 · Data

Web Information Extractor

A Python and regular-expression scraper for extracting and analyzing audience metrics.

2018 · Design Research

Mann Museum

Research and concept development for a museum featuring virtual reality and high-dynamic-range imaging.

2018 · Social Impact

Learning Program for Haiti

Led a team that designed an off-grid energy approach for delivering Khan Academy through a Haitian NGO.

Contact