About Me

I work at the intersection of privacy and security, software engineering, and AI Governance. My research develops methods and tools that help developers implement privacy requirements and enable people to understand and control how their data is used, especially in agentic AI systems

Previously, I was a postdoctoral researcher at the Center for Data Science at New York University and Columbia Law School. I completed my Ph.D. at the Australian National University and CSIRO’s Data61 (now CSIRO Technology).

I am on the faculty job market. I welcome opportunities to discuss research collaborations and academic positions.

Email · Google Scholar · GitHub · LinkedIn

Research

A central theme of my work is connecting software practices, regulatory requirements, and user-facing privacy communication. My research spans three closely related directions:

  • Privacy Engineering. Designing privacy notices, inventories, and controls that support developers’ workflows and help users make informed decisions.
  • Privacy Compliance and Measurement. Examining whether privacy disclosures reflect software behaviour, and developing methods to identify gaps between requirements, commitments, and implementation.
  • Security and Privacy for Agentic AI. Investigating privacy risks, permission models, and security safeguards for AI agents, their tools, and AI-enabled software development.
  • AI Governance and ESG. Translating environmental, social, and governance (ESG) commitments into measurable requirements, operational controls, and auditable evidence for AI systems, supporting resource efficiency, responsible data use, and organisational accountability

Explore my research →

Selected Work

SoK: From Generation to Consumption of Privacy Documents · NDSS 2027
A SoK paper on privacy documents (e.g., privacy policies and privacy labels) across their lifecycle, identifying research trends, open opportunities, and future directions. Paper

Online EU AI Act Compliance Checkers · arXiv 2026
An empirical assessment of online EU AI Act compliance checkers, examining their legal coverage, alignment with regulatory requirements, and the clarity and actionability of their compliance guidance. Paper

SkillGuard: A Permission-Centric Framework for Agent Skill Security · arXiv 2026
A permission framework that regulates how skills influence agent context and runtime actions through explicit manifests, user authorisation, and runtime enforcement. Paper

Contextual Privacy Policies for Mobile Applications · USENIX Security 2024
An approach to automatically generating privacy notices relevant to the context in which people use an app. Paper · Dataset

Is It a Trap? Automated Privacy Policy Generators · USENIX Security 2024
A large-scale empirical assessment of online privacy policy generators for mobile applications. Paper

View all publications →

Recent News

  • Sep 2026: I visited City University of Hong Kong. Thanks for the invitation Prof. Guangdong Bai!
  • Jul 2026: Our SoK on the lifecycle of privacy documents was accepted at NDSS 2027. Paper
  • May 2026: VPD-100K, our work on fine-grained visual privacy protection, was accepted at ICML 2026. Paper
Education and research background
  • Postdoctoral research: New York University and Columbia Law School, working with Emily Black and Talia Gillis.
  • Ph.D. in Computer Science: Australian National University and CSIRO’s Data61, mentored by Zhenchang Xing, Xiwei (Sherry) Xu, and Mark Staples. 2025
  • Visiting Ph.D. student: Singapore Management University, working with David Lo. 2023
  • Master of Machine Learning and Computer Vision: Australian National University, working with Zhenchang Xing and Hongdong Li. 2021.
  • Bachelor of Advanced Computing (Honours): Australian National University, through the “2+2” joint programme with Shandong University (Weihai), working with Dongwoo Kim. 2019.