| 2025 | ICLR | Functional Homotopy: Smoothing Discrete Optimization via Continuous Parameters for LLM Jailbreak Attacks. | Zi Wang, Divyam Anshumaan, Ashish Hooda, Yudong Chen, Somesh Jha |
| 2025 | SP | Fun-tuning: Characterizing the Vulnerability of Proprietary LLMs to Optimization-Based Prompt Injection Attacks via the Fine-Tuning Interface. | Andrey Labunets, Nishit V. Pandya, Ashish Hooda, Xiaohan Fu, Earlence Fernandes |
| 2024 | ACL | PRP: Propagating Universal Perturbations to Attack Large Language Model Guard-Rails. | Neal Mangaokar, Ashish Hooda, Jihye Choi, Shreyas Chandrashekaran, Kassem Fawaz, Somesh Jha, Atul Prakash |
| 2024 | ICML | Do Large Code Models Understand Programming Concepts? Counterfactual Analysis for Code Predicates. | Ashish Hooda, Mihai Christodorescu, Miltiadis Allamanis, Aaron Wilson, Kassem Fawaz, Somesh Jha |
| 2024 | NDSS | Experimental Analyses of the Physical Surveillance Risks in Client-Side Content Scanning. | Ashish Hooda, Andrey Labunets, Tadayoshi Kohno, Earlence Fernandes |
| 2024 | WACV | D4: Detection of Adversarial Diffusion Deepfakes Using Disjoint Ensembles. | Ashish Hooda, Neal Mangaokar, Ryan Feng, Kassem Fawaz, Somesh Jha, Atul Prakash |
| 2023 | CCS | Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box Attacks. | Ryan Feng, Ashish Hooda, Neal Mangaokar, Kassem Fawaz, Somesh Jha, Atul Prakash |
| 2021 | CVPR | Invisible Perturbations: Physical Adversarial Examples Exploiting the Rolling Shutter Effect. | Athena Sayles, Ashish Hooda, Mohit Gupta, Rahul Chatterjee, Earlence Fernandes |