VLDB 2026 Research / reviewers in the wild / expert
Eugene Bagdasarian
dblp:213/9150 · also Eugene Bagdasaryan
· DBLP profile ↗
16ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-7994-6469ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 8 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Contextual Agent Security: A Policy for Every PurposeabstractJudging an action's safety requires knowledge of the context in which the action takes place. To human agents who act in various contexts, this may seem obvious: performing an action such as email deletion may or may not be appropriate depending on the email's content, the goal (e.g., erase sensitive emails or clean up trash), and the type of email address (e.g., work or personal). Unlike people, computational systems have often had only limited agency in limited contexts. Thus, manually crafted policies and user confirmation such as smartphone app permissions or access control lists---while imperfect---have sufficed to restrict harmful actions. However, with the upcoming deployment of generalist agents that support a multitude of tasks (e.g., an automated personal assistant), we argue that we must rethink security designs to adapt to the scale of contexts and capabilities of these systems. As a first step, this paper explores contextual security in the domain of agents and proposes contextual agent security (Conseca), a framework to generate just-in-time, contextual, and human-verifiable security policies. Lillian Tsai, Eugene Bagdasarian |
HotOS | 2 |
| 2025 | Privacy Reasoning in Ambiguous ContextsabstractWe study the ability of language models to reason about appropriate information disclosure - a central aspect of the evolving field of agentic privacy. Whereas previous works have focused on evaluating a model's ability to align with human decisions, we examine the role of ambiguity and missing context on model performance when making information-sharing decisions. We identify context ambiguity as a crucial barrier for high performance in privacy assessments. By designing Camber, a framework for context disambiguation, we show that model-generated decision rationales can reveal ambiguities and that systematically disambiguating context based on these rationales leads to significant accuracy improvements (up to 13.3% in precision and up to 22.3% in recall) as well as reductions in prompt sensitivity. Overall, our results indicate that approaches for context disambiguation are a promising way forward to enhance agentic privacy reasoning. Ren Yi, Octavian Suciu, Adrià Gascón, Sarah Meiklejohn, Eugene Bagdasarian, Marco Gruteser |
NeurIPS | 5 |
| 2025 | Poster Abstract: Compromising Federated Medical AI-Backdoor Risks in Prompt LearningabstractThis paper investigates the security vulnerabilities of prompt-learning-based FL systems in a healthcare setting. Specifically, we use a backdoor attack that leverages learnable prompt vectors in vision-language medical foundation models to execute stealthy adversarial manipulations. We evaluate our attack across diverse healthcare datasets and FL configurations, showing that while FL is useful as a privacy-preserving mechanism, it is susceptible to targeted backdoor attacks that pose a threat to medical applications. Momin Ahmad Khan, Yasra Chandio, Eugene Bagdasarian, Fatima M. Anwar 0001 |
SenSys | 3 |
| 2025 | Backdooring Bias (B^2) into Stable Diffusion Models
Ali Naseh, Jaechul Roh, Eugene Bagdasarian, Amir Houmansadr |
USENIX Security Symposium | 3 |
| 2025 | Self-interpreting Adversarial Images
Collin Zhang, John X. Morris, Eugene Bagdasarian, Vitaly Shmatikov |
USENIX Security Symposium | 4 |
| 2024 | Mithridates: Auditing and Boosting Backdoor Resistance of Machine Learning Pipelines
Eugene Bagdasarian, Vitaly Shmatikov |
CCS | 1 |
| 2024 | AirGapAgent: Protecting Privacy-Conscious Conversational AgentsabstractThe growing use of large language model (LLM)-based conversational agents to manage sensitive user data raises significant privacy concerns.While these agents excel at understanding and acting on context, this capability can be exploited by malicious actors.We introduce a novel threat model where adversarial third-party apps manipulate the context of interaction to trick LLM-based agents into revealing private information not relevant to the task at hand.Grounded in the framework of contextual integrity, we introduce AirGapAgent, a privacy-conscious agent designed to prevent unintended data leakage by restricting the agent's access to only the data necessary for a specific task.Extensive experiments using Gemini, GPT, and Mistral models as agents validate our approach's effectiveness in mitigating this form of context hijacking while maintaining core agent functionality.For example, we show that a single-query context hijacking attack on a Gemini Ultra agent reduces its ability to protect user data from 94% to 45%, while an AirGapAgent achieves 97% protection, rendering the same attack ineffective. CCS Concepts• Security and privacy → Information flow control. Eugene Bagdasarian, Ren Yi, Sahra Ghalebikesabi, Peter Kairouz, Marco Gruteser, Sewoong Oh, Borja Balle, Daniel Ramage |
CCS | 1 |
| 2024 | Adversarial Illusions in Multi-Modal Embeddings
Rishi D. Jha, Eugene Bagdasarian, Vitaly Shmatikov |
USENIX Security Symposium | 3 |
| 2022 | Spinning Language Models: Risks of Propaganda-As-A-Service and CountermeasuresabstractWe investigate a new threat to neural sequence-to-sequence (seq2seq) models: training-time attacks that cause models to “spin” their outputs so as to support an adversary-chosen sentiment or point of view—but only when the input contains adversary-chosen trigger words. For example, a spinned1summarization model outputs positive summaries of any text that mentions the name of some individual or organization.Model spinning introduces a “meta-backdoor” into a model. Whereas conventional backdoors cause models to produce incorrect outputs on inputs with the trigger, outputs of spinned models preserve context and maintain standard accuracy metrics, yet also satisfy a meta-task chosen by the adversary.Model spinning enables propaganda-as-a-service, where propaganda is defined as biased speech. An adversary can create customized language models that produce desired spins for chosen triggers, then deploy these models to generate disinformation (a platform attack), or else inject them into ML training pipelines (a supply-chain attack), transferring malicious functionality to downstream models trained by victims.To demonstrate the feasibility of model spinning, we develop a new backdooring technique. It stacks an adversarial meta-task (e.g., sentiment analysis) onto a seq2seq model, backpropagates the desired meta-task output (e.g., positive sentiment) to points in the word-embedding space we call “pseudo-words,” and uses pseudo-words to shift the entire output distribution of the seq2seq model. We evaluate this attack on language generation, summarization, and translation models with different triggers and meta-tasks such as sentiment, toxicity, and entailment. Spinned models largely maintain their accuracy metrics (ROUGE and BLEU) while shifting their outputs to satisfy the adversary’s meta-task. We also show that, in the case of a supply-chain attack, the spin functionality transfers to downstream models.Finally, we propose a black-box, meta-task-independent defense that, given a list of candidate triggers, can detect models that selectively apply spin to inputs with any of these triggers.1We use “spinned” rather than “spun” to match how the word is used in public relations. Eugene Bagdasarian, Vitaly Shmatikov |
SP | 1 |
| 2022 | Towards Sparse Federated Analytics: Location Heatmaps under Distributed Differential Privacy with Secure AggregationabstractWe design a scalable algorithm to privately generate location heatmaps over decentralized data from millions of user devices. It aims to ensure differential privacy before data becomes visible to a service provider while maintaining high data accuracy and minimizing resource consumption on users’ devices. To achieve this, we revisit distributed differential privacy based on recent results in secure multiparty computation, and we design a scalable and adaptive distributed differential privacy approach for location analytics. Evaluation on public location datasets shows that this approach successfully generates metropolitan-scale heatmaps from millions of user samples with a worstcase client communication overhead that is significantly smaller than existing state-of-the-art private protocols of similar accuracy. Eugene Bagdasarian, Peter Kairouz, Stefan Mellem, Adrià Gascón, Kallista A. Bonawitz, Deborah Estrin, Marco Gruteser |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Blind Backdoors in Deep Learning Models
Eugene Bagdasarian, Vitaly Shmatikov |
USENIX Security Symposium | 1 |
| 2020 | How To Backdoor Federated LearningabstractFederated models are created by aggregating model updates submittedby participants. To protect confidentiality of the training data,the aggregator by design has no visibility into how these updates aregenerated. We show that this makes federated learning vulnerable to amodel-poisoning attack that is significantly more powerful than poisoningattacks that target only the training data.A single or multiple malicious participants can use modelreplacement to introduce backdoor functionality into the joint model,e.g., modify an image classifier so that it assigns an attacker-chosenlabel to images with certain features, or force a word predictor tocomplete certain sentences with an attacker-chosen word. We evaluatemodel replacement under different assumptions for the standardfederated-learning tasks and show that it greatly outperformstraining-data poisoning.Federated learning employs secure aggregation to protect confidentialityof participants’ local models and thus cannot detect anomalies inparticipants’ contributions to the joint model. To demonstrate thatanomaly detection would not have been effective in any case, we alsodevelop and evaluate a generic constrain-and-scale technique thatincorporates the evasion of defenses into the attacker’s loss functionduring training. Eugene Bagdasarian, Andreas Veit, Yiqing Hua, Deborah Estrin, Vitaly Shmatikov |
AISTATS | 1 |
| 2019 | X-Containers: Breaking Down Barriers to Improve Performance and Isolation of Cloud-Native Containersabstract"Cloud-native" container platforms, such as Kubernetes, have become an integral part of production cloud environments. One of the principles in designing cloud-native applications is called Single Concern Principle, which suggests that each container should handle a single responsibility well. In this paper, we propose X-Containers as a new security paradigm for isolating single-concerned cloud-native containers. Each container is run with a Library OS (LibOS) that supports multi-processing for concurrency and compatibility. A minimal exokernel ensures strong isolation with small kernel attack surface. We show an implementation of the X-Containers architecture that leverages Xen paravirtualization (PV) to turn Linux kernel into a LibOS. Doing so results in a highly efficient LibOS platform that does not require hardware-assisted virtualization, improves inter-container isolation, and supports binary compatibility and multi-processing. By eliminating some security barriers such as seccomp and Meltdown patch, X-Containers have up to 27X higher raw system call throughput compared to Docker containers, while also achieving competitive or superior performance on various benchmarks compared to recent container platforms such as Google's gVisor and Intel's Clear Containers. Zhiming Shen, Gur-Eyal Sela, Eugene Bagdasarian, Christina Delimitrou, Robbert van Renesse, Hakim Weatherspoon |
ASPLOS | 4 |
| 2019 | Differential Privacy Has Disparate Impact on Model AccuracyabstractDifferential privacy (DP) is a popular mechanism for training machine learning models with bounded leakage about the presence of specific points in the training data. The cost of differential privacy is a reduction in the model's accuracy. We demonstrate that in the neural networks trained using differentially private stochastic gradient descent (DP-SGD), this cost is not borne equally: accuracy of DP models drops much more for the underrepresented classes and subgroups. For example, a gender classification model trained using DP-SGD exhibits much lower accuracy for black faces than for white faces. Critically, this gap is bigger in the DP model than in the non-DP model, i.e., if the original model is unfair, the unfairness becomes worse once DP is applied. We demonstrate this effect for a variety of tasks and models, including sentiment analysis of text and image classification. We then explain why DP training mechanisms such as gradient clipping and noise addition have disproportionate effect on the underrepresented and more complex subgroups, resulting in a disparate reduction of model accuracy. Eugene Bagdasarian, Omid Poursaeed, Vitaly Shmatikov |
NeurIPS | 1 |
| 2018 | Modularizing deep neural network-inspired recommendation algorithmsabstractThis tutorial reviews recent developments of deep neural network-based recommendation algorithms and demonstrates how to extend and adapt such algorithms for diverse application scenarios. The customization is supported by OpenRec framework that modularizes neural recommenders. The tutorial consists of a lecture and two hands-on sessions. It targets intermediate and advanced audiences who already possess knowledge of deep neural networks and are interested in applying those knowledge to the domain of recommendation. Materials are available at: http://openrec.ai/ Longqi Yang 0001, Eugene Bagdasarian, Hongyi Wen |
RecSys | 2 |
| 2018 | OpenRec: A Modular Framework for Extensible and Adaptable Recommendation AlgorithmsabstractWith the increasing demand for deeper understanding of users» preferences, recommender systems have gone beyond simple user-item filtering and are increasingly sophisticated, comprised of multiple components for analyzing and fusing diverse information. Unfortunately, existing frameworks do not adequately support extensibility and adaptability and consequently pose significant challenges to rapid, iterative, and systematic, experimentation. In this work, we propose OpenRec, an open and modular Python framework that supports extensible and adaptable research in recommender systems. Each recommender is modeled as a computational graph that consists of a structured ensemble of reusable modules connected through a set of well-defined interfaces. We present the architecture of OpenRec and demonstrate that OpenRec provides adaptability, modularity and reusability while maintaining training efficiency and recommendation accuracy. Our case study illustrates how OpenRec can support an efficient design process to prototype and benchmark alternative approaches with inter-changeable modules and enable development and evaluation of new algorithms. Longqi Yang 0001, Eugene Bagdasarian, Joshua Gruenstein, Cheng-Kang Hsieh, Deborah Estrin |
WSDM | 2 |