Imran Hossen

Assistant Professor, University of Tennessee at Chattanooga · Department of Computer Science and Engineering

I am a tenure-track Assistant Professor in the Department of Computer Science and Engineering at the University of Tennessee at Chattanooga, where I joined in August 2025. Before that, I was a Postdoctoral Researcher in AI security at the University of Louisiana at Lafayette (2022–2025), where I also received my Ph.D. in Computer Science in 2022, advised by Dr. Xiali Hei.

My research is in offensive security for AI systems: I break them — models, agents, and the CAPTCHA gates in front of them — to understand how they fail and to build ones that don’t. Concretely:

  • Security of large language models and AI agents — adversarial evaluation and red teaming of LLM-based systems, with a focus on code-generation and agentic workflows: jailbreaking, adversarial fine-tuning, and model-level compromise (backdoors, data poisoning) and their implications for software supply chain security.
  • CAPTCHA attacks and design — machine-learning-based solvers against deployed human-verification systems (reCAPTCHA, hCaptcha, audio CAPTCHAs), and the design of next-generation schemes that stay usable while resisting adversarial ML — including verification anchored in the physical world.
  • Physical and side-channel attacks on ML systems — attacks that exploit the physical world around a model, from acoustic side channels (e.g., precision keystroke tracking) to signal-injection attacks on biosensing pipelines, and defenses grounded in how these systems fail in practice.

Our CAPTCHA research has been covered by The Register and The Record.

Contact

echo bWRpbXJhbi1ob3NzZW5AdXRjLmVkdQ== | base64 --decode

Or:

news

Aug 01, 2025 I joined the University of Tennessee at Chattanooga as a tenure-track Assistant Professor in Computer Science and Engineering.
Apr 05, 2021 The Record covered our hCaptcha study; it was also discussed on Slashdot and Hacker News.
Sep 04, 2019 Our work on breaking Google’s image reCAPTCHA v2 was covered by The Register and Reclaim The Net.

selected publications

  1. [*]
    Auditory Eyesight: Demystifying \u03bcs-Precision Keystroke Tracking Attacks on Unconstrained Keyboard Inputs
    Yazhou Tu, Liqun Shan, Md Imran Hossen, and 3 more authors
    In USENIX Security Symposium, 2023
  2. [*]
    aaeCAPTCHA: The Design and Implementation of Audio Adversarial CAPTCHA
    Md Imran Hossen and Xiali Hei
    In IEEE European Symposium on Security and Privacy (EuroS&P), 2022
  3. [*]
    A Low-Cost Attack against the hCaptcha System
    Md Imran Hossen and Xiali Hei
    In 15th IEEE Workshop on Offensive Technologies (WOOT), 2021
  4. [*]
    An Object Detection based Solver for Google’s Image reCAPTCHA v2
    Md Imran Hossen, Yazhou Tu, Md Fazle Rabby, and 3 more authors
    In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020