Jaechul Roh (노재철)

Ph.D. Candidate in Computer Science

University of Massachusetts Amherst

jroh [AT] cs.umass.edu

About

I am a Ph.D. candidate in computer science at the University of Massachusetts Amherst, advised by Amir Houmansadr and also closely collaborating with Eugene Bagdasarian. I am affiliated to both SPIN Lab and UMass AI Security Lab. My research focuses on the safety and security of AI models and agents. I study the trustworthiness of multimodal generative and interactive models across audio, text, and vision, with work published at NeurIPS, USENIX Security, and COLM. I also collaborate with researchers at Google DeepMind and Qualcomm. Most recently, I completed a research internship at Dolby Laboratories, where I worked on the safety and security of real-time full-duplex speech models.

Prior to my graduate studies, I earned my bachelor's degree in computer engineering from the Hong Kong University of Science and Technology (HKUST) in the year 2023, where I completed my Final Year Thesis (FYT) on the topic of ''Adversarial Attacks in Federated Learning'' under the supervision of Jun Zhang. I have also worked with Minhao Cheng on the robustness of language models, specifically exploring methods associated with defense against backdoor attacks in language models.

Education

University of Massachusetts AmherstSeptember 2023 - Present

Ph.D. in Computer Science

University of Massachusetts AmherstSeptember 2023 - May 2026

M.S. in Computer Science

The Hong Kong University of Science and Technology Sept. 2017 - May 2023

B.Eng. Computer Engineering

Selected Publications

For the full list, see Google Scholar.
* indicates equal contribution.

DuplexJail: Spoken Interruption Attacks on Full-Duplex Speech Models

Jaechul Roh, Deepak Chandran, Amir Houmansadr, Andrea Fanelli

arXiv

Benign Fine-Tuning Breaks Safety Alignment in Audio LLMs

Jaechul Roh, Virat Shejwalkar, Amir Houmansadr

arXiv

CodecAttack: Codec-Robust Latent-Space Prompt-Injection Attacks on Audio LLMs

Jaechul Roh, Jean-Philippe Monteuuis, Jonathan Petit, Amir Houmansadr

arXiv

Multilingual and Multi-Accent Jailbreaking of Audio LLMs

Jaechul Roh, Virat Shejwalkar, Amir Houmansadr

COLM 2025

Backdooring Bias (B²) into Stable Diffusion Models

Ali Naseh, Jaechul Roh, Eugene Bagdasaryan, Amir Houmansadr

USENIX Security 2025

OSLO: One-Shot Label-Only Membership Inference Attacks

Yuefeng Peng, Jaechul Roh, Subhransu Maji, Amir Houmansadr

NeurIPS 2024

Bob's Confetti : Phonetic Memorization Attacks in Music and Video Generation

Jaechul Roh*, Zachary Novack*, Yuefeng Peng, Niloofar Mireshghallah, Taylor Berg-Kirkpatrick, Amir Houmansadr

arXiv

OverThink: Slowdown Attacks on Reasoning LLMs

Abhinav Kumar, Jaechul Roh, Ali Naseh, Marezna Karpinska, Mohit Iyyer, Amir Houmansadr, Eugene Bagdasaryan

arXiv

SPILLage: Agentic Oversharing on the Web

Jaechul Roh, Eugene Bagdasarian, Hamed Haddadi, Ali Shahin Shamsabadi

arXiv

Blog Posts

Nicholas Carlini delivering his invited talk at COLM 2025, photographed by Jaechul Roh
Thoughts on COLM 2025

Reflections from Montreal on language-model safety, generative interfaces, and human-centered AI risks.

Academic Service

Vitæ

Full Resume in PDF.

AI Safety & Security Terminal

Open the AI Safety & Security Terminal →
A research terminal for safety and alignment blog posts, conference papers, and arXiv research, with scheduled feed updates.