
Dr. Xingjun Ma
Tenure-track Professor, Fudan Unviersity & SII

I am a faculty member at the Institute of Trustworthy Embodied AI (TEAI), Fudan University, and a full-time supervisor at the Shanghai Innovation Institute. I also serve as an Honorary Fellow at the University of Melbourne. My research focuses on making AI systems safe and trustworthy, with particular interests in foundation models, AI agents, and embodied AI. I am also interested in using AI to advance our understanding of the mind and the universe.
Research Interests
- Agentic AI Safety: Safety Infrastructure · Agent Environments · Safety Evaluation · Red Teaming · Safety Data · Agent Alignment · Safe RSI
- Embodied AI Safety: Embodied Safety Infrastructure · Physical-World Safety · Embodied Evaluation · Safe Exploration · Safe Human–Robot Interaction
Recent news
All publications- Four papers have been accepted to ACM MM 2026.
- One paper on fairness has been accepted to KDD 2026.
- Seven papers have been accepted to ICML 2026.
- Three papers have been accepted to ACL 2026.
- Two papers have been accepted to CVPR 2026.
- Two papers accepted to ICLR 2026, two to TPAMI, one to FCS, and one to WWW 2026.
Earlier news · 2024–2025
- Two papers have been accepted to AAAI 2026.
- Five papers accepted to NeurIPS 2025. Congrats to all the authors!
- Our survey paper Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety has been published in Foundations and Trends® in Privacy and Security.
- Our work on multi-trigger backdoor attacks has been accepted to TDSC.
- Our paper VeriFi: Towards Verifiable Federated Unlearning has been selected as the Runner-up for the 2024 Best Paper Award by the IEEE TDSC journal. Congratulations to all co-authors!
- Four papers have been accepted to ACM Multimedia 2025.
- Three papers have been accepted to ICCV 2025.
- Our BackdoorLLM Benchmark received First Prize in the SafeBench Competition, organized by the Center for AI Safety. Congratulations to all co-authors!
- Our work on super transferable attacks X-Transfer Attacks has been accepted to ICML 2025.
- The preprint of our long survey paper Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety is available on arXiv. Many thanks to all collaborators!
- Our works on Million-scale Adversarial Robustness Evaluation, Test-time Adversarial Prompt Tuning, and AnyAttack have been accepted to CVPR 2025.
- Our works on RL-based jailbreak defense for VLMs and backdoor sample detection in CLIP have been accepted to ICLR 2025.
- I will serve as an Area Chair for ICML 2025.
- Our works on targeted transferable adversarial attack, defense against model extraction attacks, and RL-based LLM auditing have been accepted to AAAI 2025.
- I will serve as an Area Chair for ICLR 2025.
- One paper on unlearnable examples for segmentation models has been accepted to NeurIPS 2024.
- Our works on model lock , detecting query-based adversarial attacks , and multimodal jailbreak attacks on VLMs have been accepted to MM 2024.
- Our work on adversarial prompt tuning has been accepted to ECCV 2024.
- Our work on intrinsic motivation for RL has been accepted to IJCAI 2024.
- Our work on adversarial policy learning in RL is accepted by DSN 2024.
- Our work on safety alignment of LLMs is accepted by NAACL 2024.
- Our work on federated machine unlearning has been accepted to TDSC.
- Our work on self-supervised learning have been accepted to ICLR 2024.
Platform & Books & Surveys
OpenTAI
We are building an open hub for trustworthy AI: datasets, benchmarks, models, arenas, and tools. Contributions are welcome. Explore the platform
Books
- Endogenous Safety in Artificial IntelligenceBook website
- Artificial Intelligence: Data and Model SafetyBook website
Professional service
- Area Chair
- ICLR · ICML · NeurIPS
- Program committees
- ICLR, ICML, NeurIPS, CVPR, ICCV, ECCV, AAAI, IJCAI, KDD, ICDM, SDM, and AICAI.
- Journal reviewing
- Nature Communications, Pattern Recognition, TPAMI, TIP, IJCV, JAIR, TNNLS, TKDE, TIFS, TOMM, and KAIS.