Published work

AI security contributions

Blog

When Modalities Combine: The Combinatorial Blind Spot in AI Security

Prompt injection used to be a problem about a single input. Defenders inspected a string, or an image, or an audio clip, and asked whether that single channel carried a malicious instruction. Multimodal models break that assumption.
Research Paper

ShareMMU: Supporting Secure Address Translation Sharing among Untrusted Accelerators

The growing demand for accelerated computing is driving widespread deployment of multi-accelerator systems in the cloud and at the edge.
Research Paper

ReasAlign: Reasoning Enhanced Safety Alignment against Prompt Injection Attack

Large Language Models (LLMs) have enabled the development of powerful agentic systems capable of automating complex workflows across various fields.
Research Paper

ReasoningBomb: A Stealthy Denial-of-Service Attack by Inducing Pathologically Long Reasoning in Large Reasoning Models

Large reasoning models (LRMs) extend large language models with explicit multi-step reasoning traces, but this capability introduces a new class of prompt-induced inference-time denial-of-service (PI-DoS) attacks that exploit the high computational co
Research Paper

Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks

AI agents, predominantly powered by large language models (LLMs), are vulnerable to indirect prompt injection, in which malicious instructions embedded in untrusted data can trigger dangerous agent actions.
Research Paper

Beyond Latency: A System-Level Characterization of MPC and FHE for PPML

Privacy protection has become an increasing concern in modern machine learning applications.
Research Paper

GPIR: Enabling Practical Private Information Retrieval with GPUs

Private information retrieval (PIR) allows private database queries; however, it is hindered by intense server-side computation and memory traffic.
Research Paper

Privatar: Scalable Privacy-preserving Multi-user VR via Secure Offloading

Multi-user virtual reality enables immersive interaction. However, rendering avatars for numerous participants on each headset incurs prohibitive computational overhead, limiting scalability.
Research Paper

Onyx: Cost-Efficient Disk-Oblivious ANN Search

Approximate nearest neighbor (ANN) search in AI systems increasingly handles sensitive data on third-party infrastructure.
Research Paper

VIPIR: A Versatile GPU Framework for Integrating Private Information Retrieval Protocols

While private information retrieval (PIR) enables private database services by fully concealing access patterns, it simultaneously requires high computational throughput, large memory capacity, and substantial memory bandwidth.
Research Paper

PIPES: Securing Agent Perception with Provenance and Priors

Tool-using agents consume external data from sources with different levels of trust, yet tool responses rarely identify who produced each component or what it should convey.
Research Paper

Trusted Hardware Acceleration for Function Secret Sharing

Function secret sharing (FSS) is a core building block for privacy-preserving systems such as secure inference and private information retrieval (PIR), but incurs significant overhead in key generation, communication, and data
Blog

NVIDIA and CrowdStrike Strengthen Agentic Cybersecurity Frontier

“We’re at an inflection point in cybersecurity,” Jensen Huang told a sold-out crowd at CrowdStrike’s Fal.Con 2026 in Las Vegas Tuesday. Attacks are now automated.
Blog

Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron

AI is changing the pace of cybersecurity. Agentic systems can coordinate work and pursue complex objectives over long horizons.
Blog

NVIDIA AVO Reaches 100% on ARC-AGI-3, Demonstrating a Frontier-Level General-Purpose Architecture for Long-Horizon Autonomous Agents

A frontier language model is only one component of an AI agent. The surrounding agent system—often called a harness—determines how the model receives context, uses tools, maintains state, responds to feedback, recovers from failure, and sustains progress over long-running tasks.
Blog

Where Security Fits in an AI Agent Stack

As AI agents become more capable and operate over longer horizons, building security and trust into the applications they power becomes increasingly important.
Blog

As AI Increases Demands on Memory, Storage Steps Up

Surging AI demands are driving the need for massive datasets and context windows that burst past the confines of system memory. But rising needs aren’t met by simply adding more storage capacity.
Blog

Four Ways to Deploy More Secure AI Agents

Knowledge workers are increasingly integrating AI agents into their workflows. Agents that function as “digital coworkers” offer clear benefits.
Blog

Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

Open source software is a critical pillar of the global economy. It underpins cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts.
Blog

Six Agent Harness Capabilities for Higher Model Performance

Building a great AI agent isn’t just about choosing the right models. The harness is the architecture surrounding the model.
Blog

Building Faster Cryptography with Carryless Multiplication in NVIDIA CUDA 13.3 

For over fifteen years, x86 CPUs have shipped with a dedicated hardware instruction for carryless multiplication. It’s a small but stubborn primitive that sits underneath authenticated encryption, error-correcting codes, and modern zero-knowledge proofs.
Blog

Hardware-Rooted AI Security That Won’t Slow You Down

AI has transformed how organizations operate, driving unprecedented levels of productivity and innovation. However, AI adoption can be impeded by concerns surrounding data privacy, sovereignty and how to secure data while it is in use, or during inference and engagement with AI models.
Research Paper

GPUArmor: A Hardware-Software Co-design for Efficient and Scalable Memory Safety on GPUs

Memory safety errors continue to pose a significant threat to current computing systems, and graphics processing units (GPUs) are no exception. A prominent class of memory safety algorithms is allocation-based solutions.
Blog

NVIDIA Brings Trusted, 24/7 AI Agents to Telecom Operations

Telecom operators have seen remarkable returns from using generative AI to automate network management, customer care and back-office operations. Most of that impact has been task‑based: automation that speeds up predetermined steps while people manually correlate insights and direct next steps.
Blog

One-Click Multi-Tenant Security with  NVIDIA Quantum InfiniBand

NVIDIA Quantum InfiniBand now offers intent-based security profiles in Unified Fabric Manager (UFM) that enable multi-tenant fabric security in a single click. NVIDIA Quantum InfiniBand supports three profiles: General, Bare Metal Cloud, and Secured Bare Metal Cloud.