<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Yingfei Dong | Yao Zheng@UHM</title><link>https://gustybear.github.io/author/yingfei-dong/</link><atom:link href="https://gustybear.github.io/author/yingfei-dong/index.xml" rel="self" type="application/rss+xml"/><description>Yingfei Dong</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 10:10:00 -1000</lastBuildDate><image><url>https://gustybear.github.io/media/logo_hu_d0a0b1783c391ac0.png</url><title>Yingfei Dong</title><link>https://gustybear.github.io/author/yingfei-dong/</link></image><item><title>DOE Genesis Mission: STRATOS: Security and Trust Runtime Architecture for Time-critical Operational Science</title><link>https://gustybear.github.io/grant/2026_doe_ascr_stratos/</link><pubDate>Mon, 17 Aug 2026 10:10:00 -1000</pubDate><guid>https://gustybear.github.io/grant/2026_doe_ascr_stratos/</guid><description>&lt;h1 id="executive-summary">Executive Summary&lt;/h1>
&lt;p>STRATOS develops a cloud-native, model-agnostic security middleware for protecting AI models used in time-critical scientific and energy-system operations. AI is increasingly embedded in workflows such as grid forecasting, contingency analysis, and operational decision making, creating new risks from adversarial perturbations, inference-time evasion, and backdoor attacks that may remain physically plausible while corrupting model outputs. STRATOS addresses this problem through a physics-grounded DevSecOps architecture that continuously evaluates inference streams, computes certified trust scores, and distinguishes malicious manipulation from legitimate operational variability without requiring modification of the protected model.&lt;/p>
&lt;p>The project combines physics-constrained adversarial emulation, imbalance-resilient certified detection, and a multi-tier runtime mitigation pipeline that includes targeted input purification, Control Barrier Function-based graceful degradation, and quarantine or rollback of compromised data and models. The Phase I system will be evaluated across the University of Hawaiʻi at Mānoa campus microgrid and Argonne National Laboratory&amp;rsquo;s Controller-Hardware-in-the-Loop platform, targeting at least 90% certified detection, no more than 5% false positives, at least 95% interception of synthesized adversarial payloads, and end-to-end latency of 20 ms or less. The longer-term goal is to transition STRATOS toward a federated security architecture for trustworthy AI across DOE scientific computing and critical-infrastructure environments.&lt;/p></description></item><item><title>CyberAI Innovation: Securing Artificial Intelligence Agents: A Scenario-Based Educational Platform for Future Cybersecurity Professionals</title><link>https://gustybear.github.io/grant/2026_nsf_ge_cyberai/</link><pubDate>Sat, 15 Aug 2026 15:29:00 -1000</pubDate><guid>https://gustybear.github.io/grant/2026_nsf_ge_cyberai/</guid><description>&lt;h1 id="executive-summary">Executive Summary&lt;/h1>
&lt;p>AI agents that autonomously browse the web, manage email, execute code, and query databases are being deployed across federal agencies at accelerating pace. These agents create a qualitatively new attack surface: a poisoned email can cause an agent to exfiltrate files; a malicious code comment can redirect an execution pipeline; a hidden webpage instruction can hijack a browsing session. Yet cybersecurity education has not kept pace. Existing AI security tools (Lakera Gandalf, OWASP LLM labs, CTF competitions) teach only chatbot-level prompt injection, a single-turn, text-only model that does not prepare students for agent-mediated threats involving tool access, autonomous action, and multi-step reasoning chains.&lt;/p>
&lt;p>This project develops &lt;em>AgentSec&lt;/em>, a scenario-based educational platform that teaches undergraduate cybersecurity students to identify, exploit, and defend against threats unique to autonomous AI agents, organized into three thrusts. Thrust 1 creates the educational framework, where a trust boundary taxonomy organizes agent vulnerabilities into three progressive categories, i.e., data ingestion, tool-action, and reasoning chain boundaries. This gives students a transferable mental model. Based on the taxonomy, we design a three-module curriculum with six organization-contextualized scenarios, red-team/blue-team experiential learning cycles, and a configurable difficulty framework. Thrust 2 builds the educational technology, where we develop sandboxed environments to enable students&amp;rsquo; interaction with real LLM-powered agents with controlled tool access, a layered assessment system with an AI tutoring agent, an instructor analytics dashboard, and a scenario authoring toolkit for community-contributed content. Thrust 3 evaluates impact through a quasi-experimental study, assessing platform quality, student learning, and workforce placement into government and industry CyberAI roles. All code will be open-source, self-hostable via Docker Compose with open-weight models, and released through CLARK for nationwide adoption.&lt;/p></description></item></channel></rss>