Birhanu Eshete 🤖🛡️

Birhanu Eshete

Associate Professor
Computer Science

University of Michigan, Dearborn

Welcome!

I am an Associate Professor of Computer Science at the University of Michigan, Dearborn, where I lead the Data-Driven Security & Privacy Lab (DSPLab). I am also a faculty affiliate at the Michigan Institute for Data & AI in Society (MIDAS) at the University of Michigan, Ann Arbor.

I am a recipient of the College of Engineering and Computer Science Faculty Research Excellence Award (2024-2025), the U.S. Department of State Fulbright U.S. Scholar Award (2024-2025), the U.S. National Science Foundation CAREER Award (2023), the USENIX Security Symposium Distinguished Paper Award (2018), and Finalist for the CSAW Best Applied Security Research in North America (2018). My research has appeared in top-tier security, privacy and AI venues including IEEE S&P, ACM CCS, USENIX Security, ISOC NDSS, IEEE/IFIP DSN, ACM PETS, IEEE ACSAC, IEEE SaTML, and featured in widely accessible venues such as the Science Magazine and national efforts (e.g., NIST Trustworthy and Responsible AI Resource Center).

Before joining the University of Michigan, I was a Postdoctoral Researcher in the Systems & Internet Security Lab at the University of Illinois Chicago (UIC). I earned my PhD in Computer Science from the University of Trento, and my M.Sc. and B.Sc. in Computer Science from Addis Ababa University.

Recent News

ACM SIGSAC Featured My Work on LinkedIn

I was featured by the ACM Special Interest Group on Security, Audit, and Control (SIGSAC) on LinkedIn.

avatar
Birhanu Eshete

DeepLeak Accepted at IEEE SaTML

Our latest paper "DeepLeak: Privacy Enhancing Hardening of Model Explanations Against Membership Leakage" is accepted to the IEEE Conference on Secure and Trustworthy Machine …

avatar
Birhanu Eshete

Keynote at IEEE SaTC 2026

I will be giving a keynote at the IEEE Conference on Secure and Trustworthy CyberInfrastructure for IoT and Microelectronics (SaTC 2026) in Houston, TX.

avatar
Birhanu Eshete
Research Interests and Current Focus

Research Interests

  • Trustworthy ML
  • Adversarial ML
  • Privacy-Preserving ML
  • Explainable AI
  • AI Ethics

Current Research Focus

My research advances a new paradigm for securing and validating artificial intelligence systems— Provenance-Centric AI Security and Safety. As AI systems increasingly influence high-stakes domains such as cybersecurity, finance, healthcare, and autonomous systems, the core challenge is no longer only improving accuracy but ensuring that AI systems remain robust, safe, trustworthy, and accountable throughout their lifecycle. I argue that the key to achieving this lies in provenance: understanding and tracing the origins, lineage of transformations, and influence pathways that shape a model’s behavior. Traditional AI evaluation relies largely on black-box testing, observing outputs without visibility into the internal processes that produced them, which leaves critical blind spots against threats such as data poisoning, backdoor attacks, adversarial manipulation, and unsafe or unintended model behaviors. My work introduces fine-grained observability into the AI pipeline by tracking the lifecycle history of data, training dynamics, parameter updates, and inference-time information flows. Through this provenance-centric lens, I develop the theoretical foundations, algorithms, and systems that make robustness and safety measurable, explainable, and auditable, enabling capabilities such as attack detection, forensic analysis, accountability, and automated model repair. Ultimately, my vision is to establish provenance as a foundational layer for AI security and AI safety, transforming AI from opaque systems into observable and auditable infrastructures where model decisions can be traced, inspected, and verified—enabling the responsible deployment of advanced AI in critical societal systems.

Featured Publications
DeepLeak: Privacy Enhancing Hardening of Model Explanations Against Membership Leakage featured image

DeepLeak: Privacy Enhancing Hardening of Model Explanations Against Membership Leakage

Machine learning (ML) explainability is central to algorithmic transparency in high-stakes settings such as predictive diagnostics and loan approval. Yet these same domains demand …

firas-ben-hmida
DeepProv: Behavioral Characterization and Repair of Neural Networks via Inference Provenance Graph Analysis featured image

DeepProv: Behavioral Characterization and Repair of Neural Networks via Inference Provenance Graph Analysis

Deep neural networks (DNNs) are increasingly being deployed in high-stakes applications, from self-driving cars to biometric authentication. However, their unpredictable and …

firas-ben-hmida
PoisonSpot: Precise Spotting of Clean-Label Backdoors via Fine-Grained Training Provenance Tracking featured image

PoisonSpot: Precise Spotting of Clean-Label Backdoors via Fine-Grained Training Provenance Tracking

Relying on untrusted data exposes machine learning models to backdoor attacks, where adversaries poison training data to embed hidden behaviors. Existing defenses struggle against …

philemon-hailemariam
Recent Publications
(2026). NeuroTrace: Inference Provenance-Based Detection of Adversarial Examples. arXiv 2026.
(2026). DeepLeak: Privacy Enhancing Hardening of Model Explanations Against Membership Leakage. In IEEE SaTML 2026.
(2023). DeResistor: Toward Detection-Resistant Probing for Evasion of Internet Censorship. In Proceedings of the 32nd USENIX Security Symposium (SEC'23), 2023.
(2023). Designing Secure Performance Metrics for Last-Level Cache. In Proceedings of the 28th International Workshop on High-Level Parallel Programming Models and Supportive Environments (HIPS 2023).
(2023). MIAShield: Defending Membership Inference Attacks via Preemptive Exclusion of Members. In Proceedings of the 23rd Privacy Enhancing Technologies Symposium (PETS 2023).
(2022). Adversarial Detection of Censorship Measurements. In Proceedings of the 21st ACM Workshop on Privacy in the Electronic Society (WPES'22), co-located with the 29th ACM Conference on Computer and Communications Security (CCS), 2022.
(2022). DP-UTIL: Comprehensive Utility Analysis of Differential Privacy in Machine Learning. In Proceedings of the 12th ACM Conference on Data and Application Security and Privacy (ACM CODASPY).
(2022). EG-Booster: Explanation-Guided Booster of ML Evasion Attacks. In Proceedings of the 12th ACM Conference on Data and Application Security and Privacy (ACM CODASPY).
(2021). Explanation-Guided Diagnosis of Machine Learning Evasion Attacks. In Proceedings of the 17th EAI International Conference on Security and Privacy in Communication Networks (SecureComm).
(2021). Making Machine Learning Trustworthy. In Science, Vol. 373, Issue 6556, pp. 743-744, American Association for the Advancement of Science.
(2021). Morphence: Moving Target Defense Against Adversarial Examples. In Proceedings of the 37th Annual Computer Security Applications Conference (ACSAC).
(2021). PRICURE: Privacy-Preserving Collaborative Inference in a Multi-Party Setting. In Proceedings of the 7th International Workshop on Security and Privacy Analytics (IWSPA), co-located with ACM CODASPY'21.
(2020). Best-Effort Adversarial Approximation of Black-Box Malware Classifiers. In Proceedings of the 16th EAI International Conference on Security and Privacy in Communication Networks (SecureComm).
(2019). HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows. In Proceedings of the 40th IEEE Symposium on Security and Privacy (S&P).
(2019). Poirot: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting. In Proceedings of the 26th ACM Conference on Computer and Communications Security (CCS).
(2018). NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications. In Proceedings of the 27th USENIX Security Symposium (SEC).
(2018). ProPatrol: Attack Investigation via Extracted High-Level Tasks. In Proceedings of the 14th International Conference on Information Systems Security (ICISS).
(2017). DYNAMINER: Leveraging Offline Infection Analytics for On-the-Wire Malware Detection. In Proceedings of the 47th IEEE/IFIP International Conference on Dependable Systems and Networks (DSN).
(2017). SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data. In Proceedings of the 26th USENIX Security Symposium (SEC).
(2016). Chainsaw: Chained Automated Workflow-based Exploit Generation. In Proceedings of the 23rd ACM Conference on Computer and Communications Security(CCS).
(2015). EKHunter: A Counter-Offensive Toolkit for Exploit Kit Infiltration. In Proceedings of the 22nd Network and Distributed System Security Symposium (NDSS).
(2014). WebWinnow: Leveraging exploit kit workflows to detect malicious URLs. In Proceedings of the ACM Conference on Data and Application Security and Privacy (CODASPY).
(2013). ConfEagle: Automated Analysis of Security Configuration Vulnerabilities in Web Applications. In Proceedings of the 7th IEEE International Conference on Security and Reliability (SERE).
(2013). Effective Analysis, Characterization, and Detection of Malicious Activities on the Web. In Ph.D. Dissertation, University of Trento.
(2013). Effective Analysis, Characterization, and Detection of Malicious Web Pages. In Proceedings of the 22nd ACM International Conference on World Wide Web Companion (WWW).
(2013). EINSPECT: Evolution-Guided Analysis and Detection of Malicious Web Pages. In Proceedings of the 37th IEEE International Conference on Computer Software and Applications (COMPSAC).
(2013). SAMo: Experimenting a Social Accountability Web Platform. In Proceedings of the ACM Symposium on Computing for Development (ACM DEV).
(2012). BINSPECT: Holistic Analysis and Detection of Malicious Web Pages. In Proceedings of the 8th Springer EAI International Conference on Security and Privacy in Communication Networks (SECURECOMM).
(2012). Social Accountability for Mozambique: an Experience Report from the Moamba District. In Proceedings of the International IEEE EAI Conference on e-Infrastructure and e-Services for Developing Countries (AFRICOMM).
(2011). Early Detection of Security Misconfiguration Vulnerabilities in Web Applications. In Proceedings of the 6th IEEE Conference on Availability, Reliability and Security (ARES).
(2011). Malicious Website Detection: Effectiveness and Efficiency Issues. In Proceedings of 1st IEEE System Security Workshop (SysSec), Co-Located with DIMVA.
(2011). Measuring the Impact of Different Metrics on Software Quality: a Case Study in the Open Source Domain. In Proceedings of the 5th IEEE International Conference on Digital Society (ICDS).
(2010). Context Information Refinement for Pervasive Medical Systems. In Proceedings of the 5th IEEE International Conference on Digital Society (ICDS).
(2010). Host-based Anomaly Detection for Pervasive Medical Systems. In Proceedings of the 5th IEEE Conference on Risks and Security of Internet and Systems (CRiSIS).
(2010). ICT for Good: Opportunities, Challenges and the Way Forward. In Proceedings of the 5th IEEE International Conference on Digital Society (ICDS).
(2007). Context Information Refinement for Pervasive Medical Systems. In Master’s Thesis, Addis Ababa University.
Mentoring

Current Students

NameYearsProgram
Firas Ben Hmida2023-Ph.D. Candidate
Philemon Hailemariam2023-Ph.D. Candidate
Alistair Clarke2025-Master’s Student

Former Students

NameDegree/YearsNext Position
Abe AmichPh.D., 2019-2024, U of Michigan, DearbornR&D ML Engineer for Cybersecurity, Sandbox AQ
Elie RizkM.Sc., 2023-2024, U of Michigan, DearbornAI Engineer, Siren Analytics
Poornaditya MishraM.Sc., 2024-2024, U of Michigan, DearbornAI Alchemist, Miracle Labs
Zain SbeihB.Sc., 2024-2025, U of Michigan, DearbornCo-Founder, Rewixx
Youssef AydiB.Sc., 2024-2024, U of Michigan, DearbornM.S. Student, U-M Dearborn
Christine CarltonM.Sc., 2023, U of Michigan, DearbornNetwork Monitoring and Observability Manager, Ford Motor Company
Ata KaboudiM.Sc., 2023, U of Michigan, DearbornSoftware Engineer, CBRE Investment Management
Jon-Nicklaus JacksonM.Sc., 2023, U of Michigan, DearbornIT Security and Compliance Analyst, Bosch USA
Hassaan AliM.Sc., 2023, U of Michigan, DearbornSenior Software Engineer, Tesla
Ismat JarinPh.D., 2019-2022 (DNF)Ph.D. Student, UC Irvine
Chevy PawlikB.Sc., 2022, U of Michigan, DearbornIT Security Analyst, Auto-Owners Insurance
Olajide DavidM.Sc., 2022, U of Michigan, DearbornHPC Engineer, Gilead Sciences
Hassan AliM.Sc., 2022, U of Michigan, DearbornSenior Software Engineer, General Motors
Zeineb MoallaB.Sc., 2022, U of Michigan, DearbornMS Student at U of Michigan, Dearborn
Majed ChamseddineM.Sc., 2021, U of Michigan, DearbornSecurity Engineer, Amazon
Abdullah AliM.Sc., 2019, U of Michigan, DearbornSoftware Engineer
Prasanth KomminiM.Sc., 2016, U of Illinois, ChicagoSenior Security Software Engineer, SnowFlake
Stefano ArseniM.Sc., 2016, U of Illinois, ChicagoSite Reliability Engineer, Google
Sohaib ChoudhryB.Sc., 2014, U of Illinois, ChicagoPartner, Noor Consulting Group
Patrick TamB.Sc., 2014, U of Illinois, ChicagoFull Stack Engineer, Zoom
Claudio FrigoB.Sc., 2010, U of Trento, ItalySoftware Engineer, Qlik
Valentino SartoriB.Sc., 2010, U of Trento, ItalyICT Operation, Dolomit Energy Holdings, Trento, Italy
Teaching

Graduate

  • Winter 2026: Trustworthy Artificial Intelligence (CIS 582)
  • Fall 2025: Data Security and Privacy (CIS 545)
  • Fall 2025: Foundations of Information Security (CIS 540)
  • Winter 2025: Trustworthy Artificial Intelligence, Addis Ababa University
  • Winter 2024: Trustworthy Artificial Intelligence (CIS 582)
  • Winter 2024: Compiler Design (CIS 574)
  • Fall 2023: Data Security and Privacy (CIS 545)
  • Fall 2023: Foundations of Information Security (CIS 540)
  • Winter 2023: Advanced Computer and Network Security (CIS 584)
  • Winter 2023: Compiler Design (CIS 574)
  • Fall 2022: Data Security and Privacy (CIS 545)
  • Fall 2022: Foundations of Information Security (CIS 540)
  • Winter 2022: Compiler Design (CIS 574)
  • Fall 2021: Data Security and Privacy (CIS 545)
  • Fall 2021: Foundations of Information Security (CIS 540)
  • Winter 2021: Compiler Design (CIS 574)
  • Fall 2020: Data Security and Privacy (CIS 545)
  • Fall 2020: Foundations of Information Security (CIS 540)
  • Winter 2020: Compiler Design (CIS 574)
  • Fall 2019: Data Security and Privacy (CIS 545)
  • Winter 2019: Compiler Design (CIS 574)
  • Fall 2018: Data Security and Privacy (CIS 545)

Undergraduate

  • Winter 2026: Trustworthy Artificial Intelligence (CIS 482)
  • Winter 2024: Trustworthy Artificial Intelligence (CIS 482)
  • Winter 2024: Compiler Design (CIS 474)
  • Winter 2023: Compiler Design (CIS 474)
  • Winter 2022: Design Seminar I (CIS 4951)
  • Winter 2022: Design Seminar II (CIS 4952)
  • Winter 2022: Compiler Design (CIS 474)
  • Fall 2021: Data Security and Privacy (CIS 4851)
  • Winter 2021: Compiler Design (CIS 474)
  • Winter 2021: Digital Forensics II (CIS 467)
  • Fall 2020: Data Security and Privacy (CIS 4851)
  • Winter 2020: Compiler Design (CIS 474)
  • Fall 2019: Data Security and Privacy (CIS 4851)
  • Winter 2019: Compiler Design (CIS 474)
  • Fall 2018: Data Security and Privacy (CIS 4851)
Service

Organization Committee Member

  • 43rd IEEE Symposium on Security and Privacy: Diversity, Equity, and Inclusion Co-Chair (2022)
  • Dearborn AI Symposium: Poster and Demo Track Co-Chair, University of Michigan-Dearborn (Nov 2020)
  • Dearborn Cybersecurity Day, University of Michigan-Dearborn (Apr 2019)

Program Committee Member

  • The Web Conference (ACM Web), 2026 (Senior PC Member)
  • ACM PETS, 2026
  • ACM CODASPY, 2025
  • The Web Conference (ACM Web), 2025
  • USENIX Security Symposium, 2024
  • The Web Conference (ACM Web), 2024
  • ACM CODASPY, 2024
  • USENIX Security Symposium, 2023
  • IEEE EuroS&P, 2023
  • ACM CODASPY, 2023
  • USENIX Security Symposium, 2022
  • USENIX Security Symposium, 2020
  • SecureComm, 2020
  • SecureComm, 2019
  • SecureComm, 2018
  • SecureComm, 2017
  • MAICS, 2017
  • SecureComm, 2016
  • MAICS, 2016

Invited Journal Reviewer

  • IEEE Transactions on Information Forensics and Security (TIFS), 2024
  • IEEE Transactions on Dependable and Secure Computing (TDSC), 2023
  • International Journal of Information Security (IJIS), 2022
  • IEEE Transactions on Dependable and Secure Computing (TDSC), 2021
  • International Journal of Information Security (IJIS), 2020
  • IEEE Intelligent Transportation Systems Magazine (ITS), 2019
  • IEEE Transactions on Dependable and Secure Computing (TDSC), 2018
  • IEEE Transactions on Information Forensics and Security (TIFS), 2018
  • IEEE Transactions on Dependable and Secure Computing (TDSC), 2017
  • International Journal of Information Security (IJIS), 2016
  • Neural Processing Letters (NEPL), 2015
  • IEEE Transactions on Dependable and Secure Computing (TDSC), 2015
  • e-Informatica Software Engineering Journal (ESEJ), 2015
  • Journal of Systems and Software (JSS), 2013

K-12 Outreach

  • Advisory Board Member, Cybersecurity Program, Taylor High School, Michigan (2022-present)
Talks and Interviews

Invited Talks and Presentations (Recent)

  • March 2026: The Provenance of Trust: Securing the Deep Learning Lifecycle from Data to Decision, IEEE SaTC 2026, Houston, TX
  • December 2025: What Does It Mean For AI To Be Trustworthy?, AI4ALL Workshop, AI Club, University of Michigan-Dearborn
  • September 2025: Repairing Deep Learning Models by Watching How they Behave, ECySA Monthly Cybersecurity Webinar
  • June 2025: Scholarly Research in the Age of Generative AI, Distinguished Diamond Jubilee Seminar, Addis Ababa University
  • June 2025: Triangular Dynamics of AI and Cybersecurity: Defense Arsenal, Attack Surface, and Weaponization, International Conference on Collaboration in Cybersecurity and Digital Transformation, Addis Ababa
  • June 2025: Generative AI at the Crossroads of Language, Culture, and Identity, Annual Conference on Language, Culture and Technology in Development, Addis Ababa University
  • February 2025: Generative AI in Education: Risks and Pitfalls to Keep an Eye On, International Research Conference on AI in Education, Addis Ababa
  • February 2025: Defending Machine Learning Against Adversarial Inputs and Privacy Leaks, Addis Ababa Science and Technology University
  • December 2024: Enhancing Machine Learning Resilience to Adversarial Manipulations via Moving Target Strategies, Addis Ababa University
  • December 2024: Navigating the AI-Powered Threat Landscape, INSA, Addis Ababa
  • October 2024: Navigating the AI-Powered Threat Landscape: Cyber Incidents and Beyond, United States Embassy, Addis Ababa
  • August 2022: State of the Model: Promising Progress and Remaining Challenges Towards Trustworthy Machine Learning, BIC Village at DEF CON 30 (Video)

Media Coverage and Interviews

  • October 2025: Communications of the ACM - You Deserve Some Cybersecurity Today (Article)
  • August 2025: Epsiloon (French Science Magazine) - AI Vulnerability (Article in French)
  • July 2024: UM-Dearborn Reporter - Reckoning with AI’s Trust Issues (Article)
  • June 2023: UM-Dearborn Reporter - Is AI really a threat to human civilization? (Article)
  • April 2023: UM-Dearborn Reporter - Cybersecurity researcher Birhanu Eshete scores prestigious NSF CAREER award (Article)
  • August 2022: New Frontiers Podcast - Machine Learning for Environment with Bad Actors (Audio)
  • November 2021: UM-Dearborn Reporter - Should we view cyberattacks as acts of war? (Article)
  • November 2021: UM-Dearborn Reporter - Helping scientists become better coders (Article)
  • August 2021: Science Magazine Podcast - Attacks on Machine Learning (Audio)
  • June 2021: WXYZ Detroit - How to strengthen your cybersecurity while working at home (Video)
  • June 2021: UM-Dearborn Reporter - Can we make artificial intelligence more ethical? (Article)
  • July 2020: UM-Dearborn Reporter - Blue Bytes helps students build cybersecurity skills (Article)
  • November 2019: UM-Dearborn Reporter - A dispatch from the cybersecurity arms race (Article)