Brian Tang
Ph.D. Candidate, University of Michigan CSE
Researcher: Security & Privacy, AI Systems
I work on AI safety, security, and privacy. I'm a member of the RTCL advised by Kang G. Shin. I collaborate with SpiLab and Florian Schaub. I interned at the IBM TJ Watson Research Center working on agentic security. In undergrad, I worked in WI-PI with Kassem Fawaz, Varun Chandrasekaran, and Somesh Jha.
My research focuses on multimodal language models & addressing security and privacy challenges in human-AI interactions. Past work includes real-time systems, LLM/VLM training, privacy policies & NLP, and adversarial ML. Publications at USENIX Security, IEEE S&P, etc. Previously interned at Roblox and Optum.
Research Projects
In Preparation: CVPR 2027
Hawkeye
A vision-language model fine-tuned to read and reason about illegible text degraded by motion blur, low resolution, occlusion, and glare. We introduce BSTRB, a real-world blurry scene-text benchmark, and Hawkeye4B, a 4B-parameter model that rivals much larger proprietary VLMs at reading noisy in-the-wild text. Contribution: lead author.
Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies
LLM Ads
Embedding personalized advertisements within chatbot responses. We developed a system that generates targeted ads in LLM chatbot conversations and conducted a user study to assess how ad injection impacts trust and response quality. Users struggle to detect chatbot ads, and undisclosed ads are rated more favorably, raising ethical concerns. Contribution: lead author.
34th USENIX Security Symposium (2025)
Cookie Compliance
Analyzing inconsistencies in cookie consent mechanisms on websites across the globe. We developed ConsentChk, an automated system that detects and categorizes violations between a website’s cookie usage and users’ consent preferences. Contribution: measurement design, writing, and analysis of cookie consent discrepancies across 1,793 globally-popular websites.
ArXiv Preprint
AAOS Privacy
Investigating the privacy implications of Android Automotive OS (AAOS) in vehicles. We developed PriDrive, to perform static, dynamic, and network traffic inspection to evaluate the data collected by OEMs and compare it against their privacy policies. Contribution: privacy policy analyzer.
1st Cyber Security in Cars Workshop (CSCS) at CCS
AV Safety/Security
A survey paper examining security and safety challenges in autonomous vehicles (AVs). E.g., AV vulnerabilities, including surveillance risks, sensor system reliability, adversarial attacks, and regulatory concerns. Contribution: writing for surveillance and environmental safety risks.
ArXiv Preprint
Steward: NLP Web
An LLM-powered web automation tool for scalable and efficient website interaction. Steward is an end-to-end system that interprets natural language instructions to navigate websites, automate tasks, and simulate user behavior without manual coding. Contribution: lead author.
32nd USENIX Security Symposium (2023)
Eye-Shield
A novel defense system against shoulder surfing attacks on mobile devices. We designed Eye-Shield, a real-time software that makes on-screen content readable to the user but appear blurry to onlookers. Contribution: lead author.
44th IEEE Symposium on Security and Privacy (2023)
ExtPrivA
An evaluation of inconsistencies between browser extensions’ privacy disclosures and their actual data collection practices. We developed ExtPrivA to detect privacy violations by analyzing privacy policies and tracking data transfers from extensions to servers. Contribution: data collection and evaluation of 47.2k Chrome Web Store extensions finding misleading privacy disclosures.
29th ACM Conference on Computer and Communications Security (2022)
OptOutCheck
A case study analyzing the reliability of opt-out choices provided by online trackers. We developed OptOutCheck to detect inconsistencies between trackers’ stated opt-out policies and their actual data collection practices. Contribution: data collection and evaluation of 2.9k trackers.
32nd USENIX Security Symposium (2023)
Face Obfuscation Fairness
Investigating the demographic fairness of anti face recognition systems. We analyze how these metric embedding networks may exhibit disparities across different demographic groups. Contribution: coded, implemented, and tested theoretical framework proposed by lead author.
17th ACM/IEEE International Conference on Human-Robot Interaction (2022)
Confidant
Exploring privacy management in conversational social robots. We developed CONFIDANT, a privacy controller that leverages various NLP models to analyze conversational metadata. Found that robots equipped with privacy controls are perceived as more trustworthy, privacy-aware, and socially aware. Contribution: lead author.
21st Symposium Privacy Enhancing Technologies (2021)
Face-Off
Protecting user privacy by preventing face recognition. Face-Off introduces perturbations to face images, making them unrecognizable to commercial face recognition models. Contribution: coding, evaluation, and deployment, creating one of the first anti face recognition systems.
ArXiv Preprint
Hierarchical Robustness
A case study and evaluation on how deep neural networks (DNNs) are highly effective but vulnerable to adversarial inputs. Contribution: implemented hierarchical classification approach that leverages invariant features to enhance adversarial robustness without compromising accuracy.
In the Media
Grants & Sponsors
My work has been or is currently funded by the following. Research ideas are my own.
Awards & Honors
Honors
Free trip to Bloomberg NYC HQ
Rackham, UMich CoE, USENIX
Recovering Privacy and Autonomy in the Era of Large Language Models
Patents
U.S. Pat. App. No. 63/468,650 · Conf. #8672 · Filed
Grants
Converted to joint proposal w/ Ke Sun, Anhong Guo, Kang G. Shin. Ideated project; wrote ½ of abstract proposal.
Ideated project with postdoc and 2 PhD students. Wrote ½ of proposal.
Outlined and scoped projects. Wrote full proposal.
Wrote 2 pages and midterm reports.
Initiated and organized proposal structure and 25 equipment orders. Wrote ⅓ of proposal.
Service
Academic service and presentations.
External/Sub Reviewer
- CHI | 2023, 2024, 2025, 2026
- NeurIPS | 2022
- PoPETS | 2021
- USENIX Security | 2020, 2024
- IEEE Privacy | 2025, 2026
- UbiComp | 2025
- HAI | 2026
- CSE PhD Admissions | 2023
Program Committee
- IEEE S&P, Posters | Spring 2024, Spring 2025
Organizing
- Co-Chair, Prof. Kang G. Shin’s Retirement Symposium
| Fall 2025
- 87 attendees, 3 distinguished speakers (Atul Prakash , Mingyan Liu , Farnam Jahanian )
Talks
- Face-Off: Adversarial Face Obfuscation , VMware — NSF: Data Privacy and Edge Computing | Jan 2021
- Finalist, University of Michigan 3 Minute Thesis Competition | Sep 2023
- “Ads that Talk Back”: Implications and Perceptions of Injecting Personalized Advertising into LLM Chatbots , Federal Trade Commission | Mar 2026
Guest Lectures
- Sooyeon Jeong
’s CS47500 Human-Computer Interaction, Purdue University | Spring 2026
- AI Data Collection Studies, AI Security & Privacy User Studies (1 hour)
- Barbara McQuade and Florian Schaub ’s Law School course: Defending Against Deepfakes and Disinformation | Fall 2024
Music Production
I enjoy making progressive house and deep house in my spare time. I am creating a video game soundtrack for a game my friends are developing.
Travel
I love to travel! I live to experience and learn new things.
Currently Reading
- [reading] Quantum Mechanics - Landau and Lifshitz
- [reading] The Right Stuff - Tom Wolfe
- [reading] TODO CAMERA BOOK - TODO AUTHOR
Career/Life News
Random career and life updates.
I am working on securing intent drift in coding agents via a system called GRAPNEL! ⚓️
I taught CS47500 Human-Computer Interaction students about AI data collection studies and AI security & privacy user studies at Purdue University. 🎓
I will be presenting, “Ads that Talk Back”: Implications and Perceptions of Injecting Personalized Advertising into LLM Chatbots to the Federal Trade Commission! 🏛️
I submitted two papers, one to CVPR and one to ECCV this year! I am working on open-sourcing our benchmark dataset. 📄
A game that my friends and I are working on developing will be available for pre-alpha demo at GDC this year! 🎮
I am excited to be interning at IBM Research this summer working on Agentic AI Security & Privacy! 🤖
My paper, “Ads that Talk Back”: Implications and Perceptions of Injecting Personalized Advertising into LLM Chatbots got accepted at IMWUT/UbiComp 2025! 📊
I co-chaired my advisor’s retirement symposium . We had the CSE Department Chair, President of CMU, Associate Dean of CoE, along with many of Prof. Shin’s alumni in academia and industry give really heartfelt talks! 📢
I am half finished thoroughly studying the list of papers sent by Ilya Sutskever to John Carmack. 📄
I gave two talks at the USENIX Security Symposium this year! Navigating Cookie Consent Violations Across The Globe and TimeTravel . 🎤
I’m attending a conference hosted by YC with lots of AI researchers and CEOs! 📽️
My paper, Navigating Cookie Consent Violations Across The Globe , got accepted at USENIX Security 2025! 🍪
My proposal for “An Efficient Real-Time Knowledge Base for Smart Glasses and Smartphones” was awarded $200k by Samsung START, converted to a joint proposal with Ke Sun, Anhong Guo, and Kang G. Shin. 📱
My proposal for “I-SEE: Intelligent Vehicular Perception and Control” was awarded $145k by General Motors R&D. 🚗
I met a couple Turing award winners who came to campus for lunch and a distinguished talk! 📽️
I’ve been busy focusing on my thesis and writing several grants, which involve creating and evaluating real-time surveillance systems using vision language models (VLMs). 🧑💻
The National Artificial Intelligence Research Resource Pilot proposal I wrote got approved for $20k in cloud credits! (Evaluating Privacy and Surveillance Risks of Large Language Models, NAIRR240418) NAIRR Grant ☁️
I learned how to produce my own music. 🎧
I gave a guest lecture for Barbara McQuade and Florian Schaub’s Law School course: Defending Against Deepfakes and Disinformation . 👨🏫
I flew an airplane for the first time! Learning and performing all the procedures made me feel confident. Starting my journey to earn my pilot’s license. 🛩️
I visited my parent’s home Taiwan for the first time in 22 years! I felt a profound sense of connection to Taipei and its culture. 🇹🇼
I was a finalist at the Bloomberg Summer of Puzzles Competition along with 3 other of my friends in the UMich CSE Ph.D. program! We competed in the final round at Bloomberg’s headquarters in New York. 🏢
The Defense University Research Instrumentation Program proposal I helped write received $300k in equipment funding for the RTCL! (Advanced Instrumentation for Research on Securing Cyber-Physical System Communication and Control) 💸
I was one of the finalists in the University of Michigan 3 Minute Thesis Competition 🎙️
My project, Eye-Shield made it into the press ! 📰
I gave my first in-person talk for my project, Eye-Shield ! 📽️
I filed my first patent for my project, Eye-Shield ! 📑
I attended my first in-person conference at IEEE S&P at San Francisco for my paper, Detection of Inconsistencies in Privacy Practices of Browser Extensions ! 🏨
My paper, Eye-Shield: Real-Time Protection of Mobile Device Screen Information from Shoulder Surfing , got accepted at USENIX Security 2023! 📱🔒
I passed my prelim exam and am now on the path to becoming a PhD Candidate! 🧐
My paper, Fairness Properties of Face Recognition and Obfuscation Systems , got accepted at USENIX Security 2023! 🙅🏻♂️🙅🏿♀️🙅🏿♂️🙅🏻♀️
My paper, Do Opt-Outs Really Opt Me Out? , got accepted at ACM CCS 2022! 🚫
My paper, Detection of Inconsistencies in Privacy Practices of Browser Extensions , got accepted at IEEE S&P 2023! 👩⚖️
My paper, Confidant: A Privacy Controller for Social Robots , got accepted at HRI 2022! 🤖
I received the University of Michigan College of Engineering 1st Year Ph.D. Fellowship! 🧐
I joined the Real-Time Computing Lab at the University of Michigan as a Ph.D. student! 💻
I graduated with a B.S. in Computer Sciences at UW - Madison! 🎓
I gave my first talk (virtual) for my project, Face-Off ! 📽️🧑💻
My paper, Face-Off: Adversarial Face Obfuscation , got accepted at PoPETS 2021! 🙈
I started my software engineering internship at Roblox Corporation ! 🎮
I finished my first paper, Rearchitecting Classification Frameworks For Increased Robustness . 🏛
I joined the Wisconsin Privacy and Security Group at the University of Wisconsin - Madison as an undergraduate student researcher! 🔒
I started my software engineering internship at Optum ! 🏥
I started my undergraduate degree in Computer Sciences at the University of Wisconsin - Madison! 🏫