Andrei Baroian

LLM Pre-training → post-training → AI security

Working as a Research Assistant at SPY Lab, ETH Zurich, with Jie Zhang, Avital Shafran, and Florian Tramèr. Finished my MSc thesis (Leiden University) at SPY Lab with a prompt injection defense paper, submitted to S&P (soon on arXiv). I'm also part of the Robotics Safety Division at ETH Robotics Club, working on adversarial attacks against VLA models in humanoid robots.

My past research includes LLM pre-training (exploring architectural variants) and LLM post-training (speeding up GRPO training with Prompt Reuse), with smaller projects in LLM quantization and mechanistic interpretability. I also worked as a data engineer at Akida and was a Teaching Assistant at Leiden University.

Andrei Baroian

Research & Projects

Prompt Injection via Adversarially Optimized Image Noise In Progress
SPY Lab, ETH Zurich — With Jie Zhang, Avital Shafran, and Florian Tramèr
Jul 2026 – Present
Prompt injections through adversarially optimized noise in images.
MSc Thesis: (Image) Prompt Injection
SPY Lab, ETH Zurich — Supervised by Jie Zhang and Florian Tramèr
Feb 2026 – Jul 2026
Worked on a prompt injection defense. Submitted to S&P27, soon on arXiv.
Adversarial Attacks on VLA Models in Humanoid Robots In Progress
ETH Robotics Club — Robotics Safety Division
Jan 2026 – Present
Creating adversarial attacks against Vision-Language-Action (VLA) models in humanoid robots. Investigating how visual perturbations can override task instructions and induce harmful behaviors.
Prompt Replay: Speeding Up GRPO
arXiv:2603.21177
Sep 2025 – Mar 2026
LLM RLVR post-training. An overhead-free online data selection method for GRPO that reuses and prioritizes prompts (not trajectories) to preserve on-policy optimization. Buffers medium-difficulty prompts near a 50% pass rate to maximize learning signal, reducing zero-variance prompts and accelerating early training gains. Tested on 3B and 8B models.
Crown, Frame, Reverse: Layer-Wise Scaling Variants for LLM Pre-Training
arXiv:2509.06518
Apr – Jul 2025
Explored architectural variants that redistribute capacity across transformer layers during pre-training. Introduced three layer-wise scaling patterns using linear interpolation of FFN widths and attention head counts. Pre-trained 180M parameter models on 5B tokens; all variants converged to better performance than an equal-cost isotropic baseline.

Experience

Research Assistant, SPY Lab
ETH Zurich, Zurich

Prompt injections through adversarially optimized noise in images. With Jie Zhang, Avital Shafran, and Florian Tramèr.

Robotics Safety Researcher, ETH Robotics Club
ETH Zurich, Zurich

Part of Robotics Safety division of ETHRC. Exploring adversarial attacks and defenses of VLA models in humanoid robots.

Teaching Assistant, Automated Machine Learning
Leiden University
  • Graded assignments and provided feedback.
  • Guided students in selecting, understanding, and presenting research papers.
Data Engineer
Akida, The Hague
  • Built LLM-powered pipelines (Gemini API) that turn unstructured sources into structured data products for customers (500M documents/year); owned code, tests, and Azure deployments end-to-end.
  • Developed filtering and classification logic using heuristics and GenAI to detect construction projects across public-sector sources.
  • Built the extraction pipeline for summarization and structured information retrieval, producing the core data product.
  • Designed annotation workflows and LLM evaluation.
  • Deployed to staging and production on Azure; monitored production pipelines.

Education

Exchange Semester — MSc Thesis at SPY Lab
ETH Zurich, Switzerland

Adversarial attacks on vision-language models. Supervised by Jie Zhang and Florian Tramèr.

MSc Computer Science: Artificial Intelligence
Leiden University, The Netherlands — Graduated, GPA: 8.5/10

Notable grades: Seminar in Deep Reinforcement Learning (10), Deep Learning (9.0), Seminar in Deep Learning (9.0), Natural Language Processing (9.0).

BSc Entrepreneurship & Business Innovation
Tilburg University, The Netherlands