PhD Candidate in Computer Science
University of Massachusetts Amherst
hjeong[at]umass.edu Β· Website Β· LinkedIn

Download CV


Research Interests

I study security, privacy, and behavioral properties of AI agent systems, where LLMs autonomously interact with the real world through tools and connected software or services.

My work focuses on agent-specific vulnerabilities that emerge from this perception-action loop and do not arise in passive LLM assistants, including unintended actions, information leakage, behavioral manipulation, and agent fingerprinting. I also investigate how established web and network security concepts can be adapted to analyze and defend AI agents.


Education

Ph.D. in Computer Science (2023 – Exp. 2028)
University of Massachusetts Amherst
Advisors: Amir Houmansadr, Eugene Bagdasarian

M.S. in Computer Science (2021 – 2023)
SungKyunKwan University (SKKU), South Korea
Advisor: Tai-Myoung Chung Β· GPA: 4.5/4.5

B.S. in Computer Science (2015 – 2020)
Stony Brook University (SBU), New York
Security & Privacy Specialization Β· Dean’s List (5x)


Publications & Presentations

Peer-Reviewed

  • H. Jeong, M. Teymoorianfard, A. Kumar, A. Houmansadr, E. Bagdasarian. Network-Level Prompt and Trait Leakage in Local Research Agents. USENIX Security 2026. [Paper] [Code] [Dataset]
  • H. Jeong, S. Ma, A. Houmansadr. Bias Similarity Measurement: A Black-Box Audit of Fairness Across LLMs. ICLR 2026. [Paper] [Code]
  • H. Jeong, S. Ma, A. Houmansadr. Survey on Federated Unlearning: Challenges and Opportunities. IEEE Big Data 2026. [Paper]
  • H. Jeong, H. Son, S. Lee, J. Hyun, T.-M. Chung. FedCC: Robust Federated Learning Against Model Poisoning Attacks. SecureComm 2025. [Paper] [Code] [Slides]
  • H. Jeong, T.-M. Chung. Security and Privacy Issues and Solutions in Federated Learning for Digital Healthcare. FDSE 2022. [Paper]
  • J.H. Yoo, H. Jeong, J. Lee, T.-M. Chung. Open Problems in Medical Federated Learning. IJWIS 2022. [Paper]
  • J.H. Yoo, H. Jeong (co-first), J. Lee, T.-M. Chung. Federated Learning: Issues in Medical Application. FDSE 2021. [Paper]
  • H. Jeong, J. An, J. Jeong. Are You a Good Client? Client Classification in Federated Learning. ICTC 2020. [Paper] [Code]

Preprints / Under Review

  • H. Jeong, D. Pham, A. Houmansadr, E. Bagdasarian. AI Snitches Get Glitches: Towards Evading Agentic Surveillance. Preprint [Paper] [Code]

  • D. Kang, H. Jeong, J. Sheffey, P. Datta, A. Houmansadr. Whose Agent Are You? Multi-Layer Fingerprinting and Attribution of Autonomous Web Agents. Preprint [Paper]

  • H. Jeong, A. Houmansadr, S. Zilberstein, E. Bagdasarian. Understanding Persuasion in Long-Running Agents. Preprint [Paper] [Code]

Patent

  • T.-M. Chung, J.H. Yoo, H. Jeong, H.J. Jeon. Data Processing Method for Depressive Disorder Using AI Based on Multi-indicator. Patent No. 1024322750000.

Research Experience

Research Intern, Brave Software (Jun. – Sep. 2026)

  • Investigated dynamic prompt injection in browser agents, including XSS-based attacks that alter agent observations at runtime.
  • Designed secure-by-design browser agents, combining provenance and task relevance to reduce prompt-injection risk.

Research Assistant, University of Massachusetts Amherst (2023 – Present)

  • Demonstrated that encrypted agent browsing traces can reveal user prompts and persona traits.
  • Designed controlled webpage scenarios that expose agent-specific behaviors and used these interaction patterns to fingerprint web agents.
  • Studied unintended agent behavior, including autonomous reporting of sensitive information and persuasion-induced behavioral drift.
  • Developed Bias Similarity Measurement (BSM), a large-scale pipeline evaluating bias and fairness in LLMs across 30+ models and 1M+ prompts.

Research Assistant, SungKyunKwan University (SKKU), South Korea (2021 – 2023)

  • Studied defenses against backdoor and poisoning attacks in federated learning.
  • Conducted privacy-preserving federated learning research in medical settings; co-authored peer-reviewed publications.

Undergraduate Research Assistant, Stony Brook University (SBU) (2019)

  • Built and validated a GPS spoofing detection pipeline using sensor fusion and camera-based signals.

Selected Projects

  • Exploring Model Inversion on Unlearned Samples (2024) β€” Reconstructed unlearned samples by contrasting representations between original and unlearned models.
  • Federated Unlearning as Backdoor Mitigation (2023) β€” Evaluated unlearning defenses against backdoor attacks in FL. [Code]
  • Malicious Client Detection in Federated Learning (2022) β€” Proposed client classification using model weight heatmaps to detect backdoors/data poisoning. [Code]
  • Covert C\&C and Data Exfiltration (2020) β€” Developed Python client/server for covert command-and-control and encrypted data exfiltration to AWS. [Code]
  • Distributed Typosquatting Detector (2019) β€” Built distributed app to detect typosquatting domains via headless Chrome scanning and automated reporting. [Code]

Teaching Experience

  • Teaching Assistant, CS 690: Trustworthy & Responsible AI, UMass Amherst (Fall 2025) β€” Organized and graded group assignments; led paper discussions; mentored teams on programming assignments and a security-focused final project.
  • Teaching Assistant, CS 360: Introduction to Computer & Network Security, UMass Amherst (Spring 2025) β€” Assisted with lectures; designed and graded weekly assignments (SHA-256, web security, AI security); advised semester projects with research-style final reports.
  • Tutor, KT Corp. Aivle School, South Korea (Feb–May 2022) β€” Tutored in AI model interpretation and CS fundamentals; supported projects in ML/DL, NLP, and Django-based web apps.
  • Teaching Assistant, Global Capstone Design Course, SKKU (Spring 2022) β€” Guided teams through ideation β†’ prototyping β†’ evaluation; projects applied AI techniques to deployable products.
  • Teaching Assistant, Web Design and Programming, SBU (Spring 2018) β€” Taught web design wireframing and documentation; graded assignments; led recitation sections.

Service & Affiliations

  • Ph.D. Mentor, UMass Amherst (Summer 2025) β€” Mentored undergraduates in an 11-week project on AI web agent security; guided research design and poster preparation. [Poster]
  • URV Mentor, UMass Amherst (2023–2024) β€” Supervised undergraduates in semester-long research projects; supported planning, experiments, and poster presentations.
  • Reviewer, NeurIPS (2026–)
  • Reviewer, IEEE Transactions on Information Forensics & Security (TIFS) (2024–)
  • Member, UMass Amherst AI Security (AISEC) Lab (2025–)
  • Member, The Secure, Private Internet (SPIN) Lab (2023–)

Honors & Awards

  • Dean’s List, Stony Brook University (5 semesters)
  • Graduate Research Assistantship, UMass Amherst (2023–Present)

Technical Skills

Security & Privacy: AI-Agent Security, Web & Browser Security, Prompt Injection, Backdoor, Federated (Un)Learning, Differential Privacy, Model Inversion
Agent & ML Systems: PyTorch, Hugging Face, Browser-Use, AutoGen, GPT-Researcher, Docker, Git
Languages: Python, Java, C, LaTeX, JavaScript, SQL, R


Last updated: July 2026