UMD affiliations
Trustworthy foundation models · University of Maryland
AI systems that reason, act, recover, and improve.
Furong Huang's lab studies foundation models as decision-making systems—models that understand physical and digital worlds, reason under uncertainty, act through tools or bodies, and learn from failure.
Associate Professor of Computer Science · University of Maryland
About Furong
Research leadership across machine learning, robotics, and trustworthy AI.
Furong Huang is a tenured associate professor of computer science at the University of Maryland, building learning systems that connect mathematical foundations with consequential real-world behavior.
Academic path
From learning theory to foundation-model systems.
Before joining UMD in 2017, Furong was a postdoctoral researcher at Microsoft Research New York City, mentored by John Langford and Robert Schapire.
She earned her Ph.D. with Anima Anandkumar, working on high-dimensional learning and tensor methods.
Research support
Public and industrial partners.
Research has been supported by NSF, DARPA, ONR, AFOSR, Good Ventures through Open Philanthropy, NVIDIA, Microsoft, Adobe, Apple, JP Morgan, Capital One, Amazon, and Peraton.
See the complete record →Where talent goes
The lab’s strongest record is its people.
Furong Lab alumni carry their research into leading AI organizations, technology companies, and academic institutions. Their trajectories are part of the lab’s impact—not a footnote to it.
Bang AnOpenAI
Sicheng ZhuOpenAI
Souradip ChakrabortyMIT CSAIL · Postdoctoral Researcher
Xiaoyu LiuGoogle
Yuhang ZhouMeta
Yuancheng XuNetflixResearch architecture
Three connected loops for capable and trustworthy AI.
The lab connects models of the world, policies for allocating reasoning, and mechanisms that turn failures into safer future behavior.
Pillar 01
World models
Learn what can happenExplore this pillar →Pillar 02
Reasoning control
Decide how to thinkExplore this pillar →Pillar 03
Trustworthy self-improvement
Learn from failureExplore this pillar →Selected recognition
Recognition for research that connects rigor with impact.
A concise selection from the complete awards and grants record maintained in the CV.
NVIDIA Academic Grant
Support for frontier academic research in artificial intelligence.
NeurIPS workshop Best Paper Award
New Frontiers in Adversarial Machine Learning (AdvML Frontier).
NSF NAIRR Pilot Award
Guardians of Integrity in AI: Establishing Trust, Originality, and Ethical Standards.
Microsoft Accelerate Foundation Models Research Award
Recognition and support for foundation-model research.
MIT Technology Review Innovators Under 35
Asia Pacific honoree for work on trustworthy artificial intelligence.
Three JP Morgan Faculty Research Awards
AI security, robust and fair financial models, and learning over financial data streams.
Selected work
A small, deliberate portfolio of signature and emerging work.
Twelve papers show the arc from foundational contributions and widely used benchmarks to the lab’s current frontier. This is an editorial selection, not a second publication list.
Established impact
Ideas that shaped subsequent research.
Selected for sustained scholarly influence, community use, and leadership across optimization, multimodal evaluation, AI safety, robotics, and content provenance.
Escaping From Saddle Points - Online Stochastic Gradient for Tensor Decomposition
Conference of Learning Theory (COLT) 2015
BibTeX
@inproceedings{ge2015escaping54ac,
title = {Escaping From Saddle Points - Online Stochastic Gradient for Tensor Decomposition},
author = {Rong Ge and Furong Huang and Chi Jin and Yang Yuan. (Alphabetic Order)},
booktitle = {Conference of Learning Theory (COLT) 2015},
year = {2015},
eprint = {1503.02101},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/1503.02101},
}HallusionBench: An Advanced Diagnostic Suite for Entangled Language Hallucination & Visual Illusion in Large Vision-Language Models
Conference on Computer Vision and Pattern Recognition (CVPR), 2024
BibTeX
@inproceedings{guan2024hallusionbench5094,
title = {HallusionBench: An Advanced Diagnostic Suite for Entangled Language Hallucination \& Visual Illusion in Large Vision-Language Models},
author = {Tianrui Guan and Fuxiao Liu and Xiyang Wu and Ruiqi Xian and Zongxia Li and Xiaoyu Liu and Xijun Wang and Lichang Chen and Furong Huang and Yaser Yacoob and Dinesh Manocha and Tianyi Zhou},
booktitle = {Conference on Computer Vision and Pattern Recognition (CVPR), 2024},
year = {2024},
eprint = {2310.14566},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2310.14566},
}AutoDAN: Interpretable Gradient-Based Adversarial Attacks on Large Language Models
First Conference on Language Modeling (COLM), 2024
BibTeX
@inproceedings{zhu2024autodan8585,
title = {AutoDAN: Interpretable Gradient-Based Adversarial Attacks on Large Language Models},
author = {Sicheng Zhu and Ruiyi Zhang and Bang An and Gang Wu and Joe Barrow and Zichao Wang and Furong Huang and Ani Nenkova and Tong Sun},
booktitle = {First Conference on Language Modeling (COLM), 2024},
year = {2024},
eprint = {2310.15140},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2310.15140},
}TraceVLA: Visual Trace Prompting Enhances Spatial-Temporal Awareness for Generalist Robotic Policies
The Thirteenth International Conference on Learning Representations (ICLR), 2025
BibTeX
@inproceedings{zheng2025tracevlabcf1,
title = {TraceVLA: Visual Trace Prompting Enhances Spatial-Temporal Awareness for Generalist Robotic Policies},
author = {Ruijie Zheng and Yongyuan Liang and Shuaiyi Huang and Jianfeng Gao and Hal Daume III and Andrey Kolobov and Furong Huang and Jianwei Yang},
booktitle = {The Thirteenth International Conference on Learning Representations (ICLR), 2025},
year = {2025},
eprint = {2412.10345},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2412.10345},
}Position: On the Possibilities of AI-Generated Text Detection
Proceedings of the 41st International Conference on Machine Learning (ICML), 2024
BibTeX
@inproceedings{chakraborty2024position9fcf,
title = {Position: On the Possibilities of AI-Generated Text Detection},
author = {Souradip Chakraborty and Amrit Bedi and Sicheng Zhu and Bang An and Dinesh Manocha and Furong Huang},
booktitle = {Proceedings of the 41st International Conference on Machine Learning (ICML), 2024},
year = {2024},
eprint = {2304.04736},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2304.04736},
}WAVES: Benchmarking the Robustness of Image Watermarks
Proceedings of the 41st International Conference on Machine Learning (ICML), 2024
BibTeX
@inproceedings{an2024waves7a0c,
title = {WAVES: Benchmarking the Robustness of Image Watermarks},
author = {Bang An and Mucong Ding and Tahseen Rabbani and Aakriti Agrawal and Yuancheng Xu and Chenghao Deng and Sicheng Zhu and Abdirisak Mohamed and Yuxin Wen and Tom Goldstein and Furong Huang},
booktitle = {Proceedings of the 41st International Conference on Machine Learning (ICML), 2024},
year = {2024},
eprint = {2401.08573},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2401.08573},
}Current frontier
New directions with early momentum.
Recent work on physical intelligence, efficient reasoning, agentic systems, and latent safety—including EgoScale and SoTA with Less.
EgoScale: Scaling Dexterous Manipulation with Diverse Egocentric Human Data
BibTeX
@misc{zheng2026egoscale97d5,
title = {EgoScale: Scaling Dexterous Manipulation with Diverse Egocentric Human Data},
author = {Ruijie Zheng and Dantong Niu and Yuqi Xie and Jing Wang and Mengda Xu and Yunfan Jiang and Fernando Castañeda and Fengyuan Hu and You Liang Tan and Letian Fu and Trevor Darrell and Furong Huang and Yuke Zhu and Danfei Xu and Linxi Fan},
year = {2026},
eprint = {2602.16710},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2602.16710},
}SoTA with Less: MCTS-Guided Sample Selection for Data-Efficient Visual Reasoning Self-Improvement
The Thirty-ninth Annual Conference on Neural Information Processing Systems (NeurIPS), Spotlight, 2025
BibTeX
@inproceedings{wang2025sota0cf8,
title = {SoTA with Less: MCTS-Guided Sample Selection for Data-Efficient Visual Reasoning Self-Improvement},
author = {Xiyao Wang and Zhengyuan Yang and Chao Feng and Hongjin Lu and Linjie Li and Chung-Ching Lin and Kevin Lin and Furong Huang and Lijuan Wang},
booktitle = {The Thirty-ninth Annual Conference on Neural Information Processing Systems (NeurIPS), Spotlight, 2025},
year = {2025},
eprint = {2504.07934},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2504.07934},
}μ0: A Scalable 3D Interaction-Trace World Model
BibTeX
@misc{lee2026scalablef557,
title = {μ0: A Scalable 3D Interaction-Trace World Model},
author = {Seungjae Lee and Yoonkyo Jung and Jusuk Lee and Jonghun Shin and Amir Hossein Shahidzadeh and Yao-Chih Lee and H. Jin Kim and Jia-Bin Huang and Furong Huang},
year = {2026},
eprint = {2606.13769},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.13769},
}Agentic Critical Training
BibTeX
@misc{liu2026agenticb95b,
title = {Agentic Critical Training},
author = {Weize Liu and Minghui Liu and Sy-Tuyen Ho and Souradip Chakraborty and Xiyao Wang and Furong Huang},
year = {2026},
eprint = {2603.08706},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2603.08706},
}FlowBank: Query-Adaptive Agentic Workflows Optimization through Precompute-and-Reuse
BibTeX
@misc{yuan2026flowbank663c,
title = {FlowBank: Query-Adaptive Agentic Workflows Optimization through Precompute-and-Reuse},
author = {Lingzhi Yuan and Chenghao Deng and Fangxu Yu and Souradip Chakraborty and Mohammad Rostami and Furong Huang},
year = {2026},
eprint = {2606.11290},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.11290},
}PropensityBench: Evaluating Latent Safety Risks in Large Language Models via an Agentic Approach
The Fourteenth International Conference on Learning Representations (ICLR), 2026
BibTeX
@inproceedings{sehwag2026propensitybench0e64,
title = {PropensityBench: Evaluating Latent Safety Risks in Large Language Models via an Agentic Approach},
author = {Udari Madhushani Sehwag and Shayan Shabihi and Alex McAvoy and Vikash Sehwag and Yuancheng Xu and Dalton Towers and Furong Huang},
booktitle = {The Fourteenth International Conference on Learning Representations (ICLR), 2026},
year = {2026},
eprint = {2511.20703},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2511.20703},
}Latest signals
News from the lab.
Talks, new research, student milestones, and recognitions—kept concise and connected to the underlying work.
Generative AI Agents at DeepLearn 2026
An advanced summer-school course on agent architectures, reasoning, alignment, safety, and world models.
Building Self-Improving Foundation Models
Auditors, actuators, and amplifiers for trustworthy AI.
Read more ↗Reasoning as Control
Adaptive test-time compute for planning agents.
Read more ↗Research with us
Build foundation models that can earn trust through their behavior.
Explore current work, meet the research group, or get in touch about collaboration and student opportunities.










