I work on robustness, security, and trustworthy AI, with a focus on understanding how AI systems behave beyond controlled settings and how their vulnerabilities emerge across models, modalities, and deployment conditions. My research spans machine learning, computer vision, multimodal AI, robotics, and computer systems, with work published at top-tier venues including ICLR, CVPR, ICCV, ECCV, IROS, ASPLOS, DAC, and DATE. A recurring theme in my research is understanding what carries across AI systems—in gradients, representations, semantics, or computational structure—and how these shared properties can make models both effective and vulnerable. I study these questions across adversarial transferability, physical-world attacks, quantized and approximate models, and, more recently, vision-language and multimodal systems. Rather than treating these as separate problems, I approach them through a common lens: understanding what transfers across models, representations, and deployment settings, and how it can be leveraged or disrupted to build more robust systems.

My research includes:

  • Adversarial Transferability — understanding why adversarial examples transfer across architectures and how shared representations, gradients, and semantics influence transfer.
  • Robust & Efficient AI — designing defenses that remain effective under quantization, approximate computing, and hardware/deployment constraints.
  • Physical-World AI Security — studying attacks and defenses under real-world transformations such as viewpoint, deformation, distance, and environmental variation.
  • Multimodal & VLM Security — investigating hallucination, adversarial manipulation, jailbreaking, and cross-modal inconsistencies in vision-language models.

More broadly, my goal is to uncover the computational principles that govern robustness and failure in modern AI systems, and use these insights to build AI that is reliable, interpretable, and robust under real-world conditions.

20+ Publications · 550+ Citations · h-index 12 · 10+ Researchers Mentored


🔥 News

  • 2026.07: I’ve received an Outstanding Reviewer Award from ECCV 2026
  • 2026.07: My paper had been selected for an ECCV 2026 Oral Presentation
  • 2026.06: 🎉 1 paper accepted at ECCV 2026
  • 2026.05: I’ve received a Silver Reviewer Award from ICML 2026
  • 2026.01: 🎉 2 papers accepted at ICLR 2026
  • 2025.11: 🎉 1 paper accepted at DATE 2026
  • 2025.10: I’ve been selected as Top Reviewer at NeurIPS 2025
  • 2025.06: 🎉 1 paper accepted at ICCV 2025
  • 2024.06: 🎉 1 paper accepted at IROS 2024
  • 2024.06: 🎉 3 papers accepted at ICIP 2024
  • 2024.02: 🎉 1 paper accepted at CVPR 2024
  • 2024.02: 🎉 1 paper accepted at DAC 2024

Selected Research Projects

Below are representative research projects spanning adversarial machine learning, robustness, and secure AI systems.


Shows that suppression-based attacks in vision-language models create representational discontinuities that lead to hallucination. Introduces a re-encoding strategy that restores consistency between regions and prevents these failures.

Identifies gradient consensus as a key source of adversarial vulnerability, where different transformations still produce aligned attack directions. Proposes stochastic filter ensembles to enforce gradient divergence and improve robustness.

Reveals that adversarial patch transferability across quantized models is driven by hidden cross-bit alignment in gradients and feature structure. Introduces a training framework that explicitly disrupts this alignment to prevent transfer.

ArXiv 2025: TESSER: Transfer-Enhancing Adversarial Attacks from Vision Transformers

Authors: Amira Guesmi, Bassem Ouni, Muhammad Shafique

Shows that adversarial transferability can be strengthened by preserving spectral and semantic structure across models. Introduces regularization techniques that stabilize these shared components to improve black-box attack effectiveness.

ICCV 2025: ODDR: Outlier Detection & Dimension Reduction Based Defense Against Adversarial Patches

Authors: Nandish Chattopadhyay*, Amira Guesmi*, Muhammad Abdullah Hanif, Bassem Ouni, Muhammad Shafique (* equal contribution)

Frames adversarial patches as structured outliers in feature space rather than random perturbations. Combines outlier detection and dimensionality reduction to localize and neutralize patch-induced distortions.

CVPR 2024: DAP: A Dynamic Adversarial Patch for Evading Person Detectors

Authors: Amira Guesmi, Ruitian Ding, Muhammad Abdullah Hanif, Ihsen Alouani, Muhammad Shafique

Demonstrates that physically robust adversarial patches require adaptation to real-world transformations such as pose and deformation. Introduces a dynamic patch generation framework that maintains effectiveness under these conditions.

IROS 2024: SSAP: A Shape-Sensitive Adversarial Patch for Monocular Depth Estimation

Authors: Amira Guesmi, Muhammad Abdullah Hanif, Ihsen Alouani, Bassem Ouni, Muhammad Shafique

Shows that adversarial patches can manipulate geometric perception at the object level, affecting global depth estimation rather than localized regions. Proposes shape-aware perturbations that alter scene understanding.

ASPLOS 2021: Defensive approximation: securing cnns using approximate computing

Authors: Amira Guesmi, Ihsen Alouani, Khaled N Khasawneh, Mouna Baklouti, Tarek Frikha, Mohamed Abid, Nael Abu-Ghazaleh

Reframes approximate computing from a hardware constraint into a mechanism for disrupting adversarial optimization, where reduced precision and stochasticity weaken the reliability of attack gradients.

💼 Experience

Sep 2022 – Present: Research Team Lead, Engineering Division, New York University Abu Dhabi (NYUAD), UAE

Feb 2022 – Aug 2022: Postdoctoral Researcher, IEMN-DOAE Laboratory, CNRS-8520, Polytechnic University Hauts-de-France, France


📖 Education

Mar 2018 - Oct 2021: Ph.D. in Computer Systems Engineering, National School of Engineers of Sfax, Tunisia

Sep 2013 - Jun 2016: Engineer Degree in Computer Science & Electrical Engineering, National School of Engineers of Sfax (ENIS), Tunisia


🏆 Awards & Honors

  • Outstanding Reviewer Award, ECCV 2026.
  • Silver Reviewer Award, ICML 2026.
  • Top Reviewer Award, NeurIPS 2025.
  • Best Senior Researcher Award, eBRAIN Lab, NYUAD, 2023.
  • Erasmus+ Scholarship, France, 2019.
  • DAAD Scholarship: Advanced Technologies based on IoT (ATIoT), Germany, 2018.
  • DAAD Scholarship: Young ESEM Program (Embedded Systems for Energy Management), Germany, 2016.

🧑‍🏫 Academic Service & Community

  • Conference Reviewer: ICML, ICLR, NeurIPS, ICCV, CVPR, AAAI, ECCV, DAC, IROS, ICIP, IJCNN
  • Journal Reviewer: IEEE TIFS, IEEE TCSVT, TMLR, TMC, IJCV, TCAD, Access
  • Organizer & Speaker: Tutorial: ML Security in Autonomous Systems, IROS 2024

  • Email: ag9321@nyu.edu

I am always open to collaborations on AI security, adversarial robustness, and trustworthy ML systems.