PhD Candidate in Computer Science
University of Massachusetts Amherst
hjeong[at]umass.edu Β· Website Β· LinkedIn
Download CV
Research Interests
I study security, privacy, and behavioral properties of AI agent systems, where LLMs autonomously interact with the real world through tools and connected software or services.
My work focuses on agent-specific vulnerabilities that emerge from this perception-action loop and do not arise in passive LLM assistants, including unintended actions, information leakage, behavioral manipulation, and agent fingerprinting. I also investigate how established web and network security concepts can be adapted to analyze and defend AI agents.
Education
Ph.D. in Computer Science (2023 β Exp. 2028)
University of Massachusetts Amherst
Advisors: Amir Houmansadr, Eugene Bagdasarian
M.S. in Computer Science (2021 β 2023)
SungKyunKwan University (SKKU), South Korea
Advisor: Tai-Myoung Chung Β· GPA: 4.5/4.5
B.S. in Computer Science (2015 β 2020)
Stony Brook University (SBU), New York
Security & Privacy Specialization Β· Deanβs List (5x)
Publications & Presentations
Peer-Reviewed
- H. Jeong, M. Teymoorianfard, A. Kumar, A. Houmansadr, E. Bagdasarian. Network-Level Prompt and Trait Leakage in Local Research Agents. USENIX Security 2026. [Paper] [Code] [Dataset]
- H. Jeong, S. Ma, A. Houmansadr. Bias Similarity Measurement: A Black-Box Audit of Fairness Across LLMs. ICLR 2026. [Paper] [Code]
- H. Jeong, S. Ma, A. Houmansadr. Survey on Federated Unlearning: Challenges and Opportunities. IEEE Big Data 2026. [Paper]
- H. Jeong, H. Son, S. Lee, J. Hyun, T.-M. Chung. FedCC: Robust Federated Learning Against Model Poisoning Attacks. SecureComm 2025. [Paper] [Code] [Slides]
- H. Jeong, T.-M. Chung. Security and Privacy Issues and Solutions in Federated Learning for Digital Healthcare. FDSE 2022. [Paper]
- J.H. Yoo, H. Jeong, J. Lee, T.-M. Chung. Open Problems in Medical Federated Learning. IJWIS 2022. [Paper]
- J.H. Yoo, H. Jeong (co-first), J. Lee, T.-M. Chung. Federated Learning: Issues in Medical Application. FDSE 2021. [Paper]
- H. Jeong, J. An, J. Jeong. Are You a Good Client? Client Classification in Federated Learning. ICTC 2020. [Paper] [Code]
Preprints / Under Review
-
H. Jeong, D. Pham, A. Houmansadr, E. Bagdasarian. AI Snitches Get Glitches: Towards Evading Agentic Surveillance. Preprint [Paper] [Code]
-
D. Kang, H. Jeong, J. Sheffey, P. Datta, A. Houmansadr. Whose Agent Are You? Multi-Layer Fingerprinting and Attribution of Autonomous Web Agents. Preprint [Paper]
-
H. Jeong, A. Houmansadr, S. Zilberstein, E. Bagdasarian. Understanding Persuasion in Long-Running Agents. Preprint [Paper] [Code]
Patent
- T.-M. Chung, J.H. Yoo, H. Jeong, H.J. Jeon. Data Processing Method for Depressive Disorder Using AI Based on Multi-indicator. Patent No. 1024322750000.
Research Experience
Research Intern, Brave Software (Jun. β Sep. 2026)
- Investigated dynamic prompt injection in browser agents, including XSS-based attacks that alter agent observations at runtime.
- Designed secure-by-design browser agents, combining provenance and task relevance to reduce prompt-injection risk.
Research Assistant, University of Massachusetts Amherst (2023 β Present)
- Demonstrated that encrypted agent browsing traces can reveal user prompts and persona traits.
- Designed controlled webpage scenarios that expose agent-specific behaviors and used these interaction patterns to fingerprint web agents.
- Studied unintended agent behavior, including autonomous reporting of sensitive information and persuasion-induced behavioral drift.
- Developed Bias Similarity Measurement (BSM), a large-scale pipeline evaluating bias and fairness in LLMs across 30+ models and 1M+ prompts.
Research Assistant, SungKyunKwan University (SKKU), South Korea (2021 β 2023)
- Studied defenses against backdoor and poisoning attacks in federated learning.
- Conducted privacy-preserving federated learning research in medical settings; co-authored peer-reviewed publications.
Undergraduate Research Assistant, Stony Brook University (SBU) (2019)
- Built and validated a GPS spoofing detection pipeline using sensor fusion and camera-based signals.
Selected Projects
- Exploring Model Inversion on Unlearned Samples (2024) β Reconstructed unlearned samples by contrasting representations between original and unlearned models.
- Federated Unlearning as Backdoor Mitigation (2023) β Evaluated unlearning defenses against backdoor attacks in FL. [Code]
- Malicious Client Detection in Federated Learning (2022) β Proposed client classification using model weight heatmaps to detect backdoors/data poisoning. [Code]
- Covert C\&C and Data Exfiltration (2020) β Developed Python client/server for covert command-and-control and encrypted data exfiltration to AWS. [Code]
- Distributed Typosquatting Detector (2019) β Built distributed app to detect typosquatting domains via headless Chrome scanning and automated reporting. [Code]
Teaching Experience
- Teaching Assistant, CS 690: Trustworthy & Responsible AI, UMass Amherst (Fall 2025) β Organized and graded group assignments; led paper discussions; mentored teams on programming assignments and a security-focused final project.
- Teaching Assistant, CS 360: Introduction to Computer & Network Security, UMass Amherst (Spring 2025) β Assisted with lectures; designed and graded weekly assignments (SHA-256, web security, AI security); advised semester projects with research-style final reports.
- Tutor, KT Corp. Aivle School, South Korea (FebβMay 2022) β Tutored in AI model interpretation and CS fundamentals; supported projects in ML/DL, NLP, and Django-based web apps.
- Teaching Assistant, Global Capstone Design Course, SKKU (Spring 2022) β Guided teams through ideation β prototyping β evaluation; projects applied AI techniques to deployable products.
- Teaching Assistant, Web Design and Programming, SBU (Spring 2018) β Taught web design wireframing and documentation; graded assignments; led recitation sections.
Service & Affiliations
- Ph.D. Mentor, UMass Amherst (Summer 2025) β Mentored undergraduates in an 11-week project on AI web agent security; guided research design and poster preparation. [Poster]
- URV Mentor, UMass Amherst (2023β2024) β Supervised undergraduates in semester-long research projects; supported planning, experiments, and poster presentations.
- Reviewer, NeurIPS (2026β)
- Reviewer, IEEE Transactions on Information Forensics & Security (TIFS) (2024β)
- Member, UMass Amherst AI Security (AISEC) Lab (2025β)
- Member, The Secure, Private Internet (SPIN) Lab (2023β)
Honors & Awards
- Deanβs List, Stony Brook University (5 semesters)
- Graduate Research Assistantship, UMass Amherst (2023βPresent)
Technical Skills
Security & Privacy: AI-Agent Security, Web & Browser Security, Prompt Injection, Backdoor, Federated (Un)Learning, Differential Privacy, Model Inversion
Agent & ML Systems: PyTorch, Hugging Face, Browser-Use, AutoGen, GPT-Researcher, Docker, Git
Languages: Python, Java, C, LaTeX, JavaScript, SQL, R
Last updated: July 2026