Stanford Security Lunch

Welcome to Security Lunch. We host speakers from both industry and academia to give talks related to applied cryptography, and system and network security.
If you're interested in attending, please sign up for the mailing list to receive updates about upcoming talks. There is an option to join virtually on Zoom.
If you're interested in giving a talk, we would love to have you! Please find more details in the About page.
You can find the upcoming and past talks for the current quarter below. We meet every Wednesday, 12 pm in CoDa E160.

Summer 2026

Upcoming

Abstract: LLM agents increasingly coordinate through natural language, creating a new security risk: colluding agents may use apparently benign messages to exchange hidden information or coordinate unauthorized actions. Existing provably undetectable practical steganographic protocols usually assume unrealistic symmetry between agents, achieve very low capacity, or require a pre-shared secret key. In this talk, I will present Codetta, a high-capacity steganographic protocol for independently deployed LLM agents in realistic asymmetric settings. Codetta enables agents to communicate while preserving the sender’s output distribution, and introduces a steganographic key exchange that removes the need for a pre-shared key. Across multiple agent workloads and sender models, Codetta achieves up to 94× higher capacity than prior asymmetric protocols and establishes shared keys with empirically bounded failure probability. These results suggest that effectively undetectable collusion between independently deployed agents is becoming practical, and that transcript inspection alone may be insufficient for auditing multi-agent systems.

Bio: Qi Pang is a final-year PhD student at Carnegie Mellon University, advised by Wenting Zheng and Virginia Smith. His research focuses on building trustworthy AI systems using techniques from applied cryptography and differential privacy, with an emphasis on rigorous guarantees for privacy, information flow, and system behavior. His prior work spans secure LLM inference, LLM watermarking, certifiable differential privacy, trustworthy synthetic data, and robust federated learning.

Past