Personal Homepage

Trevor Zhang

Applied Scientist

Tencent · Beijing, China

Formerly Institute of Software, Chinese Academy of Sciences

We always need something beyond mere desire.

Keywords:Agent Memory · LLM Routing · LLM Security · Retrieval-Augmented Generation · Adversarial Attacks

Currently in Beijing

Drag to look around · hover a number

Figure 1. My room.

  1. 1 The desk
  2. 2 Two papers
  3. 3 NAS
  4. 4 The shelf
  5. 5 A board game
  6. 6 A pool cue
  7. 7 A football
  8. 8 A dumbbell
  9. 9 A bicycle
  10. 10 A snowboard
  11. 11 A plant

1Publications

View all
  1. [1]

    Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation Systems

    Haowei Wang*, Rupeng Zhang*, Junjie Wang, Mingyang Li, Yuekai Huang, Dandan Wang, Qing Wang

    Proceedings of the AAAI Conference on Artificial IntelligenceAAAI 2026· Co-first author

    A framework that unifies gradient-based poisoning against RAG systems by jointly optimizing the attack for the retriever and the generator, rather than treating them as two separate targets.

  2. [2]

    ToolCommander: Adversarial Tool Injection against LLM Tool-Calling Systems

    Rupeng Zhang, Haowei Wang, Junjie Wang, Mingyang Li, Yuekai Huang, Dandan Wang, Qing Wang

    Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the ACL (Main, Long Papers)NAACL 2025· First author

    A framework that exploits vulnerabilities in LLM tool-calling systems, enabling privacy theft, denial-of-service attacks, and business competition manipulation through adversarial tool injection.

2Selected Work

View all

All made on weekends, however far they got.

3Recent Writing

View all

Some engineering, some research, some everyday life.

Get in touch

Memory, routing, model safety are all fine. So is anything else.

zrpxx@qq.com