Ph.D. Candidate, Information Engineering

The Chinese University of Hong Kong

binyxu@ie.cuhk.edu.hk

Curriculum Vitae · 中文简历

Portrait of Binyan Xu

About me

Hi, I’m Binyan! I am a Ph.D. candidate in Information Engineering at The Chinese University of Hong Kong, advised by Prof. Kehuan Zhang. Before that, I received my B.Sc. in Automation from the Qian Xuesen Honors College at Xi’an Jiaotong University and studied EECS as an exchange student at UC Berkeley.

My research asks how capable models become reliable, long-running agents. I make an agent’s operating state explicit, turn interaction traces into reusable experience and skills, and externally verify model behavior when internal signals cannot be trusted. I have led four accepted and four under-review CCF-A papers as first or co-first author.

Research interests

My research centers on long-horizon autonomous intelligence and its safety boundaries, including:

Selected papers

See the publications page for the full list. * indicates equal contribution.

Topic 1: Long-horizon agents, memory & skills

Under reviewTeaser figure from LLM Agents Are Latent Context Managers: Eliciting Self-Managed Context via State Proprioception

LLM Agents Are Latent Context Managers: Eliciting Self-Managed Context via State Proprioception

Binyan Xu, Haitao Li, Kehuan Zhang

Under review, 2026

Under reviewMethod overview from From Multi-Agent to Single-Agent: When Is Skill Distillation Beneficial?

From Multi-Agent to Single-Agent: When Is Skill Distillation Beneficial?

Binyan Xu, Dong Fang, Haitao Li, Kehuan Zhang

Under review, 2026

Under reviewOverview figure from Contextual Agentic Memory is a Memo, Not True Memory

Contextual Agentic Memory is a Memo, Not True Memory

Binyan Xu*, Xilin Dai*, Kehuan Zhang

Under review, 2026

Topic 2: External auditing & data integrity

ICML ’26Pipeline figure from From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense

From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense

Binyan Xu, Xilin Dai, Fan Yang, Di Tang, Kehuan Zhang

ICML 2026, Poster

ACM MM ’25Pipeline figure from CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation

CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation

Binyan Xu, Fan Yang, Xilin Dai, Di Tang, Kehuan Zhang

ACM Multimedia 2025, Oral Presentation

Topic 3: Open-model behavior & risk boundaries

CCS ’25Method figure from One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP

One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP

Binyan Xu, Xilin Dai, Di Tang, Kehuan Zhang

ACM CCS 2025, Oral Presentation

AAAI ’26Pipeline figure from Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization

Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization

Binyan Xu, Xilin Dai, Fan Yang, Di Tang, Kehuan Zhang

AAAI 2026, Oral Presentation

Projects

Education

The Chinese University of Hong Kong2023.9 – 2027.10 (expected)

Ph.D. in Information Engineering · Advisor: Prof. Kehuan Zhang · GPA 3.914

University of California, Berkeley2021.8 – 2021.12

Exchange Program in Electrical Engineering and Computer Sciences · GPA 4.0

Xi’an Jiaotong University2019.9 – 2023.7

B.Sc. in Automation, Qian Xuesen Honors College · GPA 3.92 · Top 5%

Experience

Tencent IEG · Lightspeed Studios · X-Data Research Team2026.1 – 2026.7

Qingyun Program Research Intern. Led work on self-managed context, long-horizon tool use, agentic memory, GRPO post-training, and skill distillation.

Microsoft Research Asia · Data, Knowledge and Intelligence2022.7 – 2023.6

Stars of Tomorrow Research Intern. Co-developed an AI-assisted graphic-design system for controllable layout and visual generation; received the Award of Excellence.

CUHK Applied Security Research Laboratory2023.9 – present

Research on model-agnostic verification, training-data integrity, transferable attacks, generative backdoors, and autonomous-AI risk.

Honors & service