When Everything Becomes Perfect, What Is Left to Remember?
On imperfection, human expression, and the memories we carry in an age of AI-generated culture.
I am a Ph.D. candidate in computer science at the University of Massachusetts Amherst, advised by Amir Houmansadr and also closely collaborating with Eugene Bagdasarian. I am affiliated to both SPIN Lab and UMass AI Security Lab. My research focuses on the safety and security of AI models and agents. I study the trustworthiness of multimodal generative and interactive models across audio, text, and vision, with work published at NeurIPS, USENIX Security, and COLM. I also collaborate with researchers at Google DeepMind and Qualcomm. Most recently, I completed a research internship at Dolby Laboratories, where I worked on the safety and security of real-time full-duplex speech models.
Prior to my graduate studies, I earned my bachelor's degree in computer engineering from the Hong Kong University of Science and Technology (HKUST) in the year 2023, where I completed my Final Year Thesis (FYT) on the topic of ''Adversarial Attacks in Federated Learning'' under the supervision of Jun Zhang. I have also worked with Minhao Cheng on the robustness of language models, specifically exploring methods associated with defense against backdoor attacks in language models.
University of Massachusetts AmherstSeptember 2023 - Present
Ph.D. in Computer Science
University of Massachusetts AmherstSeptember 2023 - May 2026
M.S. in Computer Science
The Hong Kong University of Science and Technology Sept. 2017 - May 2023
B.Eng. Computer Engineering
For the full list, see Google Scholar.
* indicates equal contribution.
DuplexJail: Spoken Interruption Attacks on Full-Duplex Speech Models
Jaechul Roh, Deepak Chandran, Amir Houmansadr, Andrea Fanelli
arXiv
Benign Fine-Tuning Breaks Safety Alignment in Audio LLMs
Jaechul Roh, Virat Shejwalkar, Amir Houmansadr
arXiv
CodecAttack: Codec-Robust Latent-Space Prompt-Injection Attacks on Audio LLMs
Jaechul Roh, Jean-Philippe Monteuuis, Jonathan Petit, Amir Houmansadr
arXiv
Multilingual and Multi-Accent Jailbreaking of Audio LLMs
Jaechul Roh, Virat Shejwalkar, Amir Houmansadr
COLM 2025
Backdooring Bias (B²) into Stable Diffusion Models
Ali Naseh, Jaechul Roh, Eugene Bagdasaryan, Amir Houmansadr
USENIX Security 2025
OSLO: One-Shot Label-Only Membership Inference Attacks
Yuefeng Peng, Jaechul Roh, Subhransu Maji, Amir Houmansadr
NeurIPS 2024
Bob's Confetti : Phonetic Memorization Attacks in Music and Video Generation
Jaechul Roh*, Zachary Novack*, Yuefeng Peng, Niloofar Mireshghallah, Taylor Berg-Kirkpatrick, Amir Houmansadr
arXiv
OverThink: Slowdown Attacks on Reasoning LLMs
Abhinav Kumar, Jaechul Roh, Ali Naseh, Marezna Karpinska, Mohit Iyyer, Amir Houmansadr, Eugene Bagdasaryan
arXiv
SPILLage: Agentic Oversharing on the Web
Jaechul Roh, Eugene Bagdasarian, Hamed Haddadi, Ali Shahin Shamsabadi
arXiv
On imperfection, human expression, and the memories we carry in an age of AI-generated culture.
Reflections from Montreal on language-model safety, generative interfaces, and human-centered AI risks.
Full Resume in PDF.
Open the AI Safety & Security Terminal →
A research terminal for safety and alignment blog posts, conference papers, and arXiv research, with scheduled feed updates.