Sign in to view Zhuo’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Zhuo’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
San Francisco Bay Area
Sign in to view Zhuo’s full profile
Zhuo can introduce you to 4 people at HydroX AI
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
4K followers
500+ connections
Sign in to view Zhuo’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Zhuo
Zhuo can introduce you to 4 people at HydroX AI
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Zhuo
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Zhuo’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
4K followers
-
Zhuo Li reposted thisZhuo Li reposted this#ICML2026 My lab and HydroX AI will present the SusVibes work on the security of coding agents. We introduce SusVibes, a benchmark suite for evaluating coding-agent security. Our study finds that frontier coding agents such as Claude Code, SWE-Agent, and OpenHands, when paired with leading LLMs including Claude, Gemini, Qwen, and GLM, can complete real-world software development tasks, yet more than 80% of the generated code contains security vulnerabilities. We welcome everyone to stop by and discuss at Hall A, #2106. The SusVibes test suite and leaderboard are now public: https://lnkd.in/g5p9R8D5 Danqing Wang Songwen Zhao Jiaxuan Luo Zhuo Li
-
Zhuo Li reposted thisZhuo Li reposted this🚀 Is "Vibe Coding" actually safe for production? We’ve all seen the demos: give an LLM agent a prompt, watch it work its magic, and boom—you have a feature. But there’s a massive hidden risk. In our latest paper, we introduce SUSVIBES, a benchmark of 200 real-world software engineering tasks. We tested the world’s leading coding agents, and the results are a wake-up call for the industry: - Functionality ≠ Security: For example, while SWE-Agent with Claude 4 Sonnet solved 61% of tasks correctly, only 10.5% of those solutions were actually secure. - The "Vibe" Trap: Even when we gave agents hints about potential vulnerabilities, they struggled to mitigate the risks. Key Leaderboard Highlights: 🏆 Security Leader: OpenHands + GLM4.7 🏆 Functionality Leader: SWE-agent + Claude 4 Sonnet If we are moving toward an agent-led dev cycle, we need to talk about security now, not later. Check out the full paper and our live leaderboard here: 🔗 Leaderboard Page: https://lnkd.in/etmRu-Ne Paper: https://lnkd.in/exA4seYU #VibeCoding #CyberSecurity #LLM #SoftwareEngineering #AI #Agent Danqing Wang Songwen Zhao Zhuo LiIs Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World TasksIs Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks
-
Zhuo Li reposted thisThanks to The Register for reporting our recent work. The key finding -- "RECAP agent overcomes model alignment efforts to hide memorized proprietary content". The paper can be found at https://lnkd.in/e2TbB-Ks Collaboration with HydroX AI ad IST. André Duarte Arlindo Oliveira Zhuo LiZhuo Li reposted thisThe work of André Duarte, developed between IST and CMU, has been the subject of recent attention in the media, https://lnkd.in/eUfHJR4b
-
Zhuo Li reposted thisZhuo Li reposted thisLast month, from Anthropic, we learned that you don't need to poison percentages of data to corrupt an LLM—just a small, fixed number of samples can do it. https://lnkd.in/enDj2Af5 Today we push it further: you don’t even need harmful labels. In The “Sure” Trap, we, HydroX AI, show a compliance-only backdoor where the trigger + the single token “Sure” acts like a hidden switch, flipping models to comply with unsafe prompts. We chart the few-samples threshold across scales and outline auditing/defense angles. Paper: Yuting Tan, Yi Huang, Zhuo Li, https://lnkd.in/eEezWu8p #LLMSafety #AISecurity #DataPoisoning #BackdoorAttacks #AIAlignment #PostTrainingThe 'Sure' Trap: Multi-Scale Poisoning Analysis of Stealthy Compliance-Only Backdoors in Fine-Tuned Large Language ModelsThe 'Sure' Trap: Multi-Scale Poisoning Analysis of Stealthy Compliance-Only Backdoors in Fine-Tuned Large Language Models
-
Zhuo Li reposted thisZhuo Li reposted thisWhen AI Leaks Dangerous Information: Why AI Models Are a Public Safety Risk As AI becomes embedded in more products, a troubling pattern is emerging: AI systems can leak dangerous information 🚨 sometimes with very little prompting. 🔧 In Red-Teaming tests across platforms like DuckDuckGo AI (Mistral AI Small 3, Llama 4 Scout) and QuillBot’s free AI chat, we found that widely used models can be coaxed into generating content that risks public safety, from instructions enabling violence or ecological damage to guidance on weaponization. This isn’t a theoretical concern, it’s already happening. Our findings revealed recurring failure modes across these systems: ❌ Simple jailbreaks: roleplay, fiction framing, and layered prompts often bypass filters with ease. ❌ No registration required: free tools without login let bad actors operate anonymously behind VPNs. ❌ Chained workflows: one model’s output can be reused in another tool to produce podcasts, videos, or articles that scale harm. 🔍 How the exploits work We repeatedly used these (high-level, non-actionable) tactics: - Framing prompts as fiction or nested scenarios to evade moderation. - Adopting expert personas to build trust over multiple turns. - Using minimal jailbreaks to suppress refusal mechanisms. - Converting raw model output into rich media using downstream tools. ⚠️ Why this matters: When these filters fail, models can: - Reveal procedural info framed as “fiction,” enabling real-world harm. - Provide convincing, seemingly authorized instructions for dangerous acts. - Generate scalable misinformation and influence content. - Mislead vulnerable users into trusting harmful outputs. 🎯 The downstream impact will be physical harm, ecological threats, malicious campaigns, and widespread psychological or social damage. 🚨 Current defenses aren’t enough: most models rely on fragile safeguards (keyword filters, static blocklists, or single-turn moderation) easily bypassed by clever prompts or persona manipulation. And with no registration barriers, attackers can iterate at scale in total anonymity. At Hydrox AI, we're building stronger defenses: 🔍 Red-teaming against real-world prompts and threat patterns 🧠 Context-aware safety systems that analyze across turns 🔐 Model hardening & live monitoring for resilience under attack 🛡️ End-to-end testing, from prompt to generated content, across modalities 📅 Want to proactively assess or secure your AI systems? Book a time with us: https://lnkd.in/g82ADQHk AI should empower, not endanger. These risks are real, and solving them takes urgent, collaborative effort. 🚀
-
Zhuo Li reposted thisZhuo Li reposted this🚀 Now on Google Cloud Marketplace: HydroX Firewall for Generative AI Security We’re excited to announce that HydroX Firewall is now available on Google Cloud Marketplace — making it easier than ever for enterprises to deploy and protect GenAI systems. HydroX is a lightweight, model-agnostic firewall for LLMs, agents, and AI apps. With just one line of code, you get real-time protection, risk detection, and operational efficiency — all aligned with Google Cloud. 💡 Key Highlights: ✅ Stop jailbreaks, hallucinations, data leaks, and adversarial prompts in under 100ms ✅ Detect 30+ risk types and 20+ jailbreak scenarios, including ethical and compliance risks ✅ Scale GenAI deployment up to 70% faster with built-in protections 🛠 Key Features: ✔️ Filter unsafe content with flexible mitigation (reject, rewrite, flag) ✔️ Strengthen prompting with real-world data feedback loops ✔️ Transparent oversight with visual dashboards 🎉 Integrated with Google Cloud: Fast procurement, smooth deployment, and alignment with AI TRiSM frameworks — all to help businesses scale trusted AI. As Google Cloud’s Dai Vu said: “HydroX Firewall helps customers quickly deploy, manage, and grow on Google Cloud’s trusted infrastructure.” Our mission is simple: empower enterprises to build safe, compliant, and resilient GenAI systems from day one. 🎬 Check out our demo video https://lnkd.in/geBRwGWj 💻 Try HydroX Firewall today on Google Cloud Marketplace https://lnkd.in/gSNuQm_G 🔗 Explore our models and resources on Hugging Face https://lnkd.in/gkEWhkGY Let’s build a safer AI future — together! #AIsecurity #GoogleCloud #GenAI #HydroXFirewall #LLM #ResponsibleAI #StartupSecurity #VertexAI #TRiSM
-
Zhuo Li reposted thisZhuo Li reposted this🚀 We did it! HydroX AI has officially graduated from the #GoogleCloud AI Accelerator! ☁️ Over the past few months, we’ve had the incredible opportunity to work closely with the #GoogleCloud team, alongside some of the most innovative AI startups around the world. This experience has been a true accelerator — not just in name — but in momentum, vision, and execution. Through co-working on everything from personalized mentorships and in-depth technical workshops to crucial discussions on scaling, security, and responsible AI, we've collectively strengthened our capabilities. This shared journey has truly elevated our expertise. 💡🔐📈 This milestone marks a new chapter for HydroX AI as we continue to build cutting-edge AI security solutions with even greater clarity, speed, and purpose. Huge thanks to the #GoogleCloud team, our amazing mentors, and the entire cohort for the support and inspiration. Let’s keep building a safer AI-powered future. 💥 #HydroXAI #GoogleCloudAccelerator #AIsecurity #Startups #ResponsibleAI #CloudAI #TechForGood #Founders
-
Zhuo Li reposted thisZhuo Li reposted thisStill reflecting on last week’s Google Cloud AI Demo Day at NYTechWeek—what an incredible way to cap off an intense few months in the accelerator. Grateful for the opportunity to represent HydroX AI alongside 14 other deeply impressive startups solving real-world problems with AI. From security and safety (our jam!) to creativity, retail, healthcare, and even datacenter in SPACE!!!, it’s clear we’re just scratching the surface of what applied AI can do. Seeing each team’s unique take on how to build responsibly—and ambitiously—was a reminder of how powerful this community can be. Huge thanks to the Google for Startups, Google, and Google DeepMind teams, especially Matt Ridenour Erchit Sood PMP Darren Mowry Parker Barnes Paige Bailey Logan Kilpatrick Lake Dai Shyam Sabhaya Kevin Wang, for your guidance, generosity, and belief in what we’re building. And to the VCs and mentors who showed up with curiosity and candor, thank you. For those who want a glimpse into the future of AI, check out the full Demo Day replay here: https://lnkd.in/gxG4cG_h Onward. 🚀 cc Zhuo Li #AcceleratedbyGoogle #AI #Startups #DemoDay #NYTechWeek
-
Zhuo Li reposted thisZhuo Li reposted this🚀 We’re Hitting the Stage! HydroX at the 2025 #GoogleforStartups Cloud AI Accelerator Demo Day After an amazing 10-week journey of building, scaling, and accelerating with Google Cloud and the incredible #GoogleforStartups team, we’re excited to unveil what we’ve been working on at the Demo Day on June 5! 🎉 From top-tier mentorship to cutting-edge tech and an inspiring community of fellow innovators, this program has supercharged our AI momentum—and we can’t wait to show you what’s next. 👉 Save your spot for a day of bold ideas, live demos, and meaningful connections: https://lnkd.in/gEghzQhx Huge thanks to #GoogleforStartups for this incredible opportunity. We’re honored to be part of such a visionary cohort. 👋 See you there! #AcceleratedWithGoogle #NYTechWeek #HydroX #AI #CloudComputing #StartupLife #DemoDay #GoogleCloud #Innovation
-
Zhuo Li liked thisZhuo Li liked thisThe Second Shift to AI dinner with amazing leaders from the New England area hosted by Cycode in Boston was another great event and education session for me. Thanks to an amazing set of practitioner-thought-and-operational leaders for their candor, their transparency, and engagement (Dave Martin ADP, Jason Witty, ISSMP, NACD.DC Fidelity Investments John Schramm Munich Re, Bob Litterer Teradyne, and Melissa Hathaway Hathaway Global Strategies ). A few things I took pages of notes on include: 1. Speed of Change- Not just “security at machine speed” but rather the implication of an integrated-resilient architecture inclusive of chaining defense prioritization, approaches to change resistance leadership, and approaches to remediation prioritization. 2. Key areas of enablement discussed (new things we need to be part of ) were eye opening as well like the validation of use cases that balance truth around commercial viability and technical readiness as well as how we define capability v. useability. 3. The organizational imperatives beyond the 50 things we are doing to retool (and I think we covered more than that) were some interesting insights around supporting our partners in approaches to accelerated approaches to rehydration processes, good enough AI Safety Frameworks, and multi-jurisdictional resilience strategy development. These are the conversations I am excited to have, learn, and share. So as promised we're taking it on the road. Next stop: Chicago (date forthcoming) If you're in the Chicago area and know a security leader who should be at this table, drop their name in the comments or tag them here. Seats are limited. 🙏 #cybersecurity #ShifttoAI #ciso #cso #leadership #riskmanagment #secureAI #trustedAI
-
Zhuo Li liked thisZhuo Li liked this#ICML2026 My lab and HydroX AI will present the SusVibes work on the security of coding agents. We introduce SusVibes, a benchmark suite for evaluating coding-agent security. Our study finds that frontier coding agents such as Claude Code, SWE-Agent, and OpenHands, when paired with leading LLMs including Claude, Gemini, Qwen, and GLM, can complete real-world software development tasks, yet more than 80% of the generated code contains security vulnerabilities. We welcome everyone to stop by and discuss at Hall A, #2106. The SusVibes test suite and leaderboard are now public: https://lnkd.in/g5p9R8D5 Danqing Wang Songwen Zhao Jiaxuan Luo Zhuo Li
-
Zhuo Li liked thisZhuo Li liked thisIt’s been one month since I graduated from San José State University with my Master of Business Administration (MBA), earning a 3.9 GPA. 🎓💙💛 Now that I’ve had some time to reflect, I can honestly say how grateful I am for this opportunity. This program challenged me, pushed me outside of my comfort zone, and helped me grow both personally and professionally. Along the way, I had the opportunity to learn from incredible professors, collaborate with talented classmates, and build relationships that I know will last far beyond graduation. I’ve gained valuable knowledge, created lasting memories, and met amazing people who made this journey even more meaningful. I’m thankful for all of the experiences, opportunities, and support that were part of this chapter, and I’m excited to see where the next one leads. Here’s to continued growth, new opportunities, and whatever comes next.
-
Zhuo Li liked thisZhuo Li liked thisLast night was the first in my nationwide dinner series for Shift to AI and what a great night with some amazing practitioner-leaders in New Jersey! This is quickly going to become my favorite event to host: we pick a city to go to , I gather a handful of exceptionally passionate, smart, and dedicated security, risk, privacy, and resiliency leaders for dinner, and we share, trade ideas, talk through hard issues, figure out how we can help each another, and create a better community. Huge thanks to my guests for joining: Christian Adam - Security Executive Wells Fargo Kim Albarella- Global Head of Security TikTok/ByteDance Ramachandra Hegde - CISO Genpact Tammy Klotz - CISO Trinseo Brian Lozada, CISSP - SecurityExec -Amazon Global Media, Entertainment, and Advertising Tim McKnight - CISO Merck Bill O'Connell - CSO Commvault Donna R. - CISO Radian Next stop is back to my New England roots and Boston! If you are in the Boston area and know someone I should meet, let me know. I’m making a list 😁 #cybersecurity #CISO #CSO #leadership #ShifttoAI #community
-
Zhuo Li liked thisZhuo Li liked thisAfter almost 13 years at Meta, I’ve decided that it’s time to move on. I will be working closely with my teams over the coming months to ensure an orderly transition. I joined Facebook in 2013 through the acquisition of Onavo, a small startup I founded. Joining this company is one of the best decisions I ever made. From the moment we met the team at Facebook, we knew what the magic was - the people. They were smart, humble and just very, very good at what they do. I’ve had the privilege of learning from the best of the best here over these years, building products at billion scale and working on areas as broad as global connectivity, consumer growth, safety & security and scaling AI across the organization. We addressed challenges no one in the industry or world had solved. Looking back at well over a decade here, this has been the most defining work of my career. The hardest part about this decision isn’t leaving the work, it’s saying goodbye to the people. I look around me at colleagues - friends - that lifted me up and taught me everything. And I know our important work will be in good hands, because I’ve had a front-row seat to see people I admire become people I’d learn from. I will deeply miss being in the trenches with you all every day, but I will always be one message away. As for what’s next: first and foremost, I’m looking forward to spending more time with my family. Additionally, I remain excited about where technology is going, and after many years in the day-to-day, I'm ready to give back to the ecosystem and communities I came from, finding new ways to advise and partner with leaders and organizations navigating this moment of technological change. Working here has been (still is) a dream come true. I want to express immense gratitude to Javi Olivan who believed in our scrappy little company all those years ago, and to Naomi Gleit who’s supported my career here and from whom I learned pretty much everything I know. And to Mark, who’s trusted me with some of our most consequential work and who ultimately makes this place what it is. I remain completely confident in this company, excited about the direction we’re going, and - mostly - so very proud of the teams I helped build.
-
Zhuo Li liked thisZhuo Li liked thisI’m incredibly honored to share that I have received the Manager Excellence award from Google’s Customer Engagement organization! 🏆 This recognition truly belongs to my incredible team and partners. Leadership is easy when you are surrounded by talented, driven, and collaborative individuals who show up every day ready to solve complex challenges and deliver for our customers. A massive thank you to my team for your hard work and trust, and to my cross-functional partners for the seamless collaboration that makes our work possible. I’m so proud of what we’ve built together and excited for what’s next!
-
Zhuo Li liked thisZhuo Li liked thisMuch of my job now is writing documents for Claude explaining what I want it to build. Mostly with words, sometimes adorned with XML. It works, but human language is imprecise. You end up with a prose spec, and when production breaks, you didn't write the code; you don't have the intuition that comes from having written it. As AI builds more of our systems, that gap keeps growing. What if there were a better way? Not prose, not code, but something in between. Category theory and its relatives give you tools to describe structure—how things compose, what transformations preserve—without getting lost in implementation details. I'm starting a series [1] exploring this: category theory from the ground up, connecting each idea back to something practical. Not to turn engineers into mathematicians, but to see if thinking in these structures makes us better at telling machines what to build. It might not work at all, but I think it's worth trying.
-
Zhuo Li liked thisZhuo Li liked thisExcited to share our latest engineering blog on Piqama: Pinterest Quota Management Ecosystem (https://lnkd.in/gggTsNUe). In this post, we explore how Pinterest manages resource quotas at scale, the technical challenges we overcame, and how the Piqama ecosystem was architected for reliability and efficiency. The blog also outlines our vision to make quota management seamless, flexible, and adaptive to the evolving needs of our platform and users. Thanks to all others authors: Zheyu Zha, Jia Zhan, and Alberto Ordóñez Pereira, for collaborating together and sharing our work. Appreciation to the team members who contributed to this project: Rainie Li, Hengzhe Guo, Alex Sloan, Hobin Yoon, Enzo Reyes. Thank you to the following reviewers for your valuable feedback and support: Soam Acharya, Ambud S., Vibhav Garg, Prashant Patel, Nan Zhu, William Tom, Chen Qin, Hunter Gatewood, Hao Fu, Jiajun W., Jinru He, Mirjam Wattenhofer Grateful for the leadership support from Ang Zhang, Bo Liu, Chunyan Wang, and Roger Wang. Special thanks to Kartik Paramasivam for your vision and guidance throughout this journey. Proud to be part of this collaborative and innovative team.
Experience & Education
-
HydroX AI
******* * ***
-
*********
**** ** ******* *** **** ********** ******
-
********
*********** *******
-
******* **********
******** ******* undefined
-
********** ** ******* *** ********** ** *****
******** *******
View Zhuo’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Licenses & Certifications
Honors & Awards
-
1st prize of Atlanta start up weekend
start up weekend
Won the 1st prize of Atlanta start up weekend.
Languages
-
English
-
-
Mandarin
-
Recommendations received
1 person has recommended Zhuo
Join now to viewView Zhuo’s full profile
-
See who you know in common
-
Get introduced
-
Contact Zhuo directly
Other similar profiles
Explore more posts
-
NightSquawk Tech
6 followers
I run an MSP protecting small businesses across Southern California. Here are my top 5 cybersecurity basics that you're probably missing in your small businesses: 1️⃣ Running McAfee or Norton antivirus Antivirus hasn't been enough since 2018. Threats today move laterally across your network in minutes. You need endpoint detection and response software that detects and responds to threats in real time, not after the damage is done. And if you're still running McAfee or Norton, even Windows Defender has gotten better. Do not use any of these free antivirus solutions. 2️⃣ Shared logins across the entire office "Everyone knows the password" is not a security policy. One disgruntled employee or one phished credential, and every account tied to that login is compromised. Unique logins. No exceptions. And if you're in the medical industry, you're breaking HIPAA because you don't know who is accessing what. 3️⃣ No offsite backups Your files all live on a single computer, or you use a single program to run your entire operation. A single ransomware attack or hardware failure wipes everything. If your backup isn't off-site and automated, it doesn't count. And if you think you're safe because you have a copy of your data, when was the last time you actually ran a test to see if you could restart your business from that copy? An untested backup is still nothing. 4️⃣ Email domains with zero authentication Lacking SPF, DKIM, and DMARC means anyone can impersonate your company via email. Clients risk being phished, and your business reputation takes the blow. "Oh, I have Google email to handle that." When was the last time a vendor or client said they didn't receive an email from you? Or are they just ending up in the spam folder? 5️⃣ "The office tech person" as the entire IT department Your most tech-savvy employee is not the entire IT department. They don't have monitoring. They don't have incident response. And when they quit, everything they knew walks out the door with them. There is a reason it's an entire department, one issue, and you're left with starting back up again. — Let me know which of these hits closest to home for your business, and I'll let you know how we can help you. #Cybersecurity #SmallBusiness #McAfee #WindowsDefender #HIPAA #Ransomware #EmailSecurity #MSP #ITSupport #DataBackup
2
2 Comments -
CData Software
22K followers
Most enterprise AI projects don’t fail because of the model. They fail because the data layer isn’t built for production. Agents can’t reliably access systems behind the firewall. Schemas are inconsistent or invisible. Governance breaks the moment you try to scale. So instead of real workflows, you get demos that don’t translate. On April 16, we’re walking through what it actually takes to fix that. Live. We’ll demo the full Q1 Connect AI release in the product — including: • How to build governed Custom MCP tools for real workflows • How to securely connect to on-prem systems like SAP and SQL Server • How to automate access control with SCIM 2.0 (no more manual reviews) Real workflows and open Q&A with the product team. If you’re working on AI infrastructure, this is the part most teams get stuck on. ↓ (Registration link in comments)
16
1 Comment
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content