Qi Zhao

Email
Room 165
Address Karlsruhe Institute of Technology
Institute of Information Security and Dependability
Am Fasanengarten 5, Geb. 50.34
76131 Karlsruhe, Germany
Qi Zhao

About me

I am a doctoral student in the research group of "Artificial Intelligence and Security" headed by Prof. Wressnegger at Karlsruhe Institute of Technology (KIT). I received my Bacholer degree at China University of Petroleum (East China). And I finished my M.Sc majored in Mechanical Engineering at Karlsruhe Institute of Technology (KIT). I was focusing on the study of Cognitive System, Machine Learning and Adversarial Robustness of Deep Learning.

Research Interests

  1. Adversarial Robustness of Deep Learning Models
  2. Defensive Methods and Model Robustness Optimization
  3. Deployment of Efficient and Robust Deep Learning Models
  4. Trustworthy Generative Models and Agentic AI

Publications

Anti-Backdoor Coreset Selection via Cumulative Entropy.
Qi Zhao and Christian Wressnegger.
Proc. of International Conference on Machine Learning (ICML), July 2026.

Two Sides of the Same Coin: Learning the Backdoor to Remove the Backdoor.
Qi Zhao and Christian Wressnegger.
Proc. of 39th Annual AAAI Conference on Artificial Intelligence (AAAI), February 2025.
Oral Presentation

Poster: Real-World Backdoor Attacks Against Traffic Light Detection.
Achyut Hegde, Yilin Ji, Qi Zhao, Nikolai Polley, Svetlana Pavlitska, J. Zöllner, Alessandro Erba and Christian Wressnegger.
Proc. of 34th USENIX Security Symposium, 2025.

Adversarially Robust Anti-Backdoor Learning.
Qi Zhao and Christian Wressnegger.
Proc. of 17th ACM Workshop on Artificial Intelligence and Security (AISEC), October 2024.

Holistic Adversarially Robust Pruning.
Qi Zhao and Christian Wressnegger.
Proc. of 11th International Conference on Learning Representations (ICLR), May 2023.

Non-Uniform Adversarially Robust Pruning.
Qi Zhao, Tim Königl and Christian Wressnegger.
Proc. of 1st International Conference on Automated Machine Learning (AutoML), July 2022.

BreakingBED: Breaking Binary and Efficient Deep Neural Networks by Adversarial Attacks.
Manoj Vemparala, Alexander Frickenstein, Nael Fasfous, Lukas Frickenstein, Qi Zhao, Sabine Kuhn, Daniel Ehrhardt, Yuankai Wu, Christian Unger, Naveen Nagaraja and Walter Stechele.
Proc. of 7th Intelligent Systems Conference (IntelliSys), September 2021.

Poster: Adversarial Robust Model Compression using In-Train Pruning.
Manoj Vemparala, Nael Fasfous, Alexander Frickenstein, Sreetama Sarkar, Qi Zhao, Sabine Kuhn, Lukas Frickenstein, Anmol Singh, Christian Unger, Naveen Nagaraja, Christian Wressnegger and Walter Stechele.
2nd Women in Machine Learning Un-Workshop (WiML), July 2021.

Adversarial Robust Model Compression using In-Train Pruning.
Manoj Vemparala, Nael Fasfous, Alexander Frickenstein, Sreetama Sarkar, Qi Zhao, Sabine Kuhn, Lukas Frickenstein, Anmol Singh, Christian Unger, Naveen Nagaraja, Christian Wressnegger and Walter Stechele.
Proc. of 3rd CVPR Workshop on Safe Artificial Intelligence for Automated Driving (SAIAD), June 2021.
Best Paper Award Runner-Up

Awards

  • CCS Distinguished Artifact Reviewer Award in 2024

Program Committee Memberships

  • The International Conference on Learning Representations (ICLR) in 2025, 2026
  • The Annual AAAI Conference on Artificial Intelligence (AAAI) in 2026
  • The International Conference on Machine Learning (ICML) in 2026 (Silver)

Artifact Evaluation Committee Memberships

  • The ACM Conference on Computer and Communications Security (CCS) in 2024

Reviewing for Journals

  • ACM Computing Surveys (CSUR) in 2024

Teaching

  • Lectures: Artificial Intelligence & Security from WS 24/25 until WS 25/26
  • Seminar: Hot-Topics Security of Machine Learning in from WS 23/24 until WS 25/26
  • Seminar: Adversarial Machine Learning in from WS 20/21 until WS 22/23
  • Lectures: Security of Machine Learning from WS 21/22 until SS 2024
  • Lectures: Machine Learning for Security in WS 21/22
  • Practical Course: Intelligent Data Analysis for Security (Datalab) in WS 20/21