- PhD Student
I am a PhD student supervised by Prof. Robert Mullins and co-supervised by Dr. Yiren Zhao. I am funded by the Tazaki Cambridge Studentship and a member of Downing College. My research interest is in Machine Learning Security.
Biography
- Fall 2025: I was a student researcher at Google Deepmind working with the Synth-ID team.
- Summer 2025: I was a research intern at the Vector Institute under Prof. Nicolas Papernot.
- Fall 2024 ~ : I am currently a PhD student at the University of Cambridge.
- Summer 2024: I was a research intern in the System Security lab of TU Darmstadt under Prof. Ahmad-Reza Sadeghi.
- 2023-2024: I finished my MPhil in Advanced Computer Science under supervision of Prof. Ross Anderson, Prof. Robert Mullins and Dr. Ilia Shumailov.
- 2019-2023: I graduated with a BSc in Natural Sciences (Computer Science, Mathematics) from Durham University under supervision of Dr. Ehsan Toreini and Dr. Gagangeet Aujla. During this time I also studied abroad for one year from 2021-2022 at the Computer Science and Engineering Department of Seoul National University in South Korea.
Scholarships/Studentships
- Tazaki-Cambridge Studentship (10/2023 ~ )
- Scholarship of the German Academic Scholarship Foundation (6/2021 ~ 7/2024)
Teaching
- Data Science: Michaelmas 2024-25 for St. John's, Peterhouse and Girton (11 students)
- Algorithms 1: Lent 2024-25 for St. John's, Peterhouse and Girton (12 students)
- Algorithms 2: Lent 2024-25 for St. John's, Peterhouse and Girton (12 students)
Professional Activities
- Reviewer NeurIPS’25
- Women@CL Cambridge Volunteer
Publications
- Hanna Foerster, Robert Mullins, Ilia Shumailov, Jamie Hayes. Beyond Slow Signs in High-fidelity Model Extraction. Conference on Neural Information Processing Systems (NeurIPS'24)
- Cheng Zhang*, Hanna Foerster*, Robert Mullins, Yiren Zhao, Ilia Shumailov. Hardware and Software Platform Inference. International Conference on Machine Learning (ICML'25)
- Hanna Foerster, Sasha Behrouzi, Phillip Rieger, Murtuza Jadliwala, Ahmad-Reza Sadeghi. LightShed: Defeating Perturbation-based Image Copyright Protections. 34th USENIX Security Symposium (USENIX Security'25)
- Article website
- Featured as an article on MIT Technology Review, on Cyber News, on The Register, on Fast Company, on the University of Cambridge website, etc.
- Hanna Foerster, Ilia Shumailov, Yiren Zhao, Harsh Chaudhari, Jamie Hayes, Robert Mullins, Yarin Gal. Reasoning Introduces New Poisoning Attacks Yet Makes Them More Complicated. 4th IEEE Conference on Secure and Trustworthy Machine Learning (SaTML'26)
- Hanna Foerster*, Tom Blanchard*, Robert Mullins, Nicolas Papernot, Kristina Nikolic, Florian Tramèr, Ilia Shumailov, Cheng Zhang, Yiren Zhao. CaMeLs Can Use Computers Too: System-Level Security for Computer Use Agents. Arxiv Preprint 01/2026

