Faculty Profile: Prof. Bo Li — UIUC AI Security Lab
Faculty Profile: Prof. Bo Li — UIUC AI Security Lab
Position: Abbasi Associate Professor Institution: UIUC, Dept. of Computer Science (joint: ECE, ITI) Lab: AI Security Lab — aisecure.github.io Report date: 2026-06-12
Research Focus
Trustworthy and safe machine learning, LLM agent safety/security, adversarial ML, red-teaming, privacy, federated learning, multi-agent coordination safety.
Academic Profile
- NeurIPS 2023 Outstanding Paper Award (DecodingTrust — LLM trustworthiness benchmark)
- NSA Best Scientific Cybersecurity Paper Award
- Virtue AI co-founder (AI safety startup)
- Capital One AI Awardee 2025–2026
- Schmidt Sciences AI Safety Science Program participant
- Innovator of the Year recognition
Key Publications (2024–2025)
| Paper | Venue | Focus |
|---|---|---|
| DecodingTrust | NeurIPS’23 (Outstanding Paper) | Comprehensive LLM trustworthiness benchmark |
| ShieldAgent | ICML’25 | Knowledge-enabled LLM agent safety via verifiable policy reasoning |
| GuardAgent | ICML’25 | Safeguarding LLM agents via knowledge-enabled reasoning |
| UDora | ICML’25 | Unified red-teaming framework against LLM agents |
| C-SafeGen | NeurIPS’25 | Certified safe LLM generation with streaming guardrails |
| SentinelAgent | 2025 | Proactive risk detection and mitigation for agentic AI |
| DecodingTrust for Agents | 2025 | Agent-level trust evaluation (harder than model-level) |
Fit with Weijia Zhang
| Dimension | Assessment |
|---|---|
| LLM agent safety / red-teaming | ✅ Core strength |
| Agentic AI (safety angle) | ✅ Agent guard, attack-defense for agents |
| Multi-agent coordination safety | ✅ Training protocols for truthful multi-agent communication |
| Post-training / reward modeling | ⚠️ Some overlap (outcomes-based evaluation, reward hacking) |
| GUI / web agents (security) | ⚠️ Web agent red-teaming papers exist |
| Capability research (building agents) | ❌ Her focus is securing agents, not building better ones |
Verdict
Relevant if Weijia wants to pursue safe / trustworthy agentic AI as a research direction. Less relevant if primary focus is capability research (building more capable agents, improving performance). The safety angle could differentiate Weijia’s agent work and is increasingly important industrially (safety teams at frontier labs). Consider as secondary advisor or committee member if Weijia’s thesis touches agent robustness/safety.
