Prompt injections through adversarially optimized noise in images. With Jie Zhang, Avital Shafran, and Florian Tramèr.
Andrei Baroian
LLM Pre-training → post-training → AI security
Working as a Research Assistant at SPY Lab, ETH Zurich, with Jie Zhang, Avital Shafran, and Florian Tramèr. Finished my MSc thesis (Leiden University) at SPY Lab with a prompt injection defense paper, submitted to S&P (soon on arXiv). I'm also part of the Robotics Safety Division at ETH Robotics Club, working on adversarial attacks against VLA models in humanoid robots.
My past research includes LLM pre-training (exploring architectural variants) and LLM post-training (speeding up GRPO training with Prompt Reuse), with smaller projects in LLM quantization and mechanistic interpretability. I also worked as a data engineer at Akida and was a Teaching Assistant at Leiden University.
Research & Projects
Experience
Part of Robotics Safety division of ETHRC. Exploring adversarial attacks and defenses of VLA models in humanoid robots.
- Graded assignments and provided feedback.
- Guided students in selecting, understanding, and presenting research papers.
- Built LLM-powered pipelines (Gemini API) that turn unstructured sources into structured data products for customers (500M documents/year); owned code, tests, and Azure deployments end-to-end.
- Developed filtering and classification logic using heuristics and GenAI to detect construction projects across public-sector sources.
- Built the extraction pipeline for summarization and structured information retrieval, producing the core data product.
- Designed annotation workflows and LLM evaluation.
- Deployed to staging and production on Azure; monitored production pipelines.
Education
Adversarial attacks on vision-language models. Supervised by Jie Zhang and Florian Tramèr.
Notable grades: Seminar in Deep Reinforcement Learning (10), Deep Learning (9.0), Seminar in Deep Learning (9.0), Natural Language Processing (9.0).