Selected Publications

  1. arXiv
    Cosmos 3: Omnimodal World Models for Physical AI
    N. Agarwal, A. Ali, J. Allen, M. Antolini, A. Aubame, A. Azzolini, J. Bai, M. Bala, et al.
    arXiv:2606.02800, 2026
  2. arXiv
    Alpamayo-R1: Bridging Reasoning and Action Prediction for Generalizable Autonomous Driving in the Long Tail
    Y. Wang, W. Luo, J. Bai, Yulong Cao, T. Che, K. Chen, Y. Chen, J. Diamond, Y. Ding, et al.
    arXiv:2511.00088, 2025
  3. CVPR
    dVLM-AD: Enhance Diffusion Vision-Language-Model for Driving via Controllable Reasoning
    Y. Ma, Yulong Cao, W. Ding, S. Zhang, Y. Wang, B. Ivanovic, M. Jiang, M. Pavone, et al.
    IEEE/CVF Conference on Computer Vision and Pattern Recognition (Findings), 2026
  4. ECCV
    Dolphins: Multimodal Language Model for Driving
    Y. Ma, Yulong Cao, J. Sun, M. Pavone, C. Xiao
    European Conference on Computer Vision, 2024
  5. ICRA
    Reinforcement Learning with Human Feedback for Realistic Traffic Simulation
    Yulong Cao, B. Ivanovic, C. Xiao, M. Pavone
    IEEE International Conference on Robotics and Automation, 2024
  6. USENIX
    You Can't See Me: Physical Removal Attacks on LiDAR-Based Autonomous Vehicles Driving Frameworks
    Yulong Cao, S. H. Bhupathiraju, P. Naghavi, T. Sugawara, Z. Morley Mao, S. Rampazzi
    32nd USENIX Security Symposium, 2023
  7. S&P
    Invisible for Both Camera and LiDAR: Security of Multi-Sensor Fusion-Based Perception in Autonomous Driving Under Physical-World Attacks
    Yulong Cao*, N. Wang*, C. Xiao*, D. Yang*, J. Fang, R. Yang, Q. Alfred Chen, M. Liu, B. Li
    IEEE Symposium on Security and Privacy, 2021
  8. USENIX
    Towards Robust LiDAR-Based Perception in Autonomous Driving: General Black-Box Adversarial Sensor Attack and Countermeasures
    J. Sun, Yulong Cao, Q. Alfred Chen, Z. Morley Mao
    29th USENIX Security Symposium, 2020
Full Publications 36 entries

2026

  1. arXiv
    Test-Time Scaling for World Action Models via Zero-Shot Geometric Evaluation
    Z. Zhao, M. Cho, B. Zheng, K. Gao, Yulong Cao, Z. Morley Mao
    arXiv:2607.17454, 2026
  2. arXiv
    Cosmos 3: Omnimodal World Models for Physical AI
    N. Agarwal, A. Ali, J. Allen, M. Antolini, A. Aubame, A. Azzolini, J. Bai, M. Bala, et al.
    arXiv:2606.02800, 2026
  3. arXiv
    Fast-dDrive: Efficient Block-Diffusion VLM for Autonomous Driving
    K. Zhang, J. Wang, S. Gao, C. Wu, Yulong Cao, S. Han, B. Ivanovic, L. Liu, et al.
    arXiv:2605.23163, 2026
  4. CVPR
    Latent Chain-of-Thought World Modeling for End-to-End Autonomous Driving
    S. Tan, K. Chitta, Y. Chen, R. Tian, Y. You, Y. Wang, W. Luo, Yulong Cao, et al.
    Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2026
  5. CVPR
    dVLM-AD: Enhance Diffusion Vision-Language-Model for Driving via Controllable Reasoning
    Y. Ma, Yulong Cao, W. Ding, S. Zhang, Y. Wang, B. Ivanovic, M. Jiang, M. Pavone, et al.
    IEEE/CVF Conference on Computer Vision and Pattern Recognition (Findings), 2026

2025

  1. arXiv
    Counterfactual VLA: Self-Reflective Vision-Language-Action Model with Adaptive Reasoning
    Z. Peng, W. Ding, Y. You, Y. Chen, W. Luo, T. Tian, Yulong Cao, A. Sharma, D. Xu, et al.
    arXiv:2512.24426, 2025
  2. arXiv
    Alpamayo-R1: Bridging Reasoning and Action Prediction for Generalizable Autonomous Driving in the Long Tail
    Y. Wang, W. Luo, J. Bai, Yulong Cao, T. Che, K. Chen, Y. Chen, J. Diamond, Y. Ding, et al.
    arXiv:2511.00088, 2025
  3. arXiv
    RealDrive: Retrieval-Augmented Driving with Diffusion Models
    W. Ding, S. Veer, Y. Chen, Yulong Cao, C. Xiao, M. Pavone
    arXiv:2505.24808, 2025
  4. arXiv
    Surprise Potential as a Measure of Interactivity in Driving Scenarios
    W. Ding, S. Veer, K. Leung, Yulong Cao, M. Pavone
    arXiv:2502.05677, 2025
  5. ICRA
    Gen-Drive: Enhancing Diffusion Generative Driving Policies with Reward Modeling and Reinforcement Learning Fine-Tuning
    Z. Huang, X. Weng, M. Igl, Y. Chen, Yulong Cao, B. Ivanovic, M. Pavone, C. Lv
    IEEE International Conference on Robotics and Automation, 2025
  6. ICLR
    Cocoon: Robust Multi-Modal Perception with Uncertainty-Aware Sensor Fusion
    M. Cho, Yulong Cao, J. Sun, Q. Zhang, M. Pavone, J. J. Park, H. Yang, Z. Morley Mao
    International Conference on Learning Representations, 2025
  7. ICLR
    Language-Image Models with 3D Understanding
    J. H. Cho, B. Ivanovic, Yulong Cao, E. Schmerling, Y. Wang, X. Weng, B. Li, Y. You, P. Krähenbühl, Y. Wang, M. Pavone
    International Conference on Learning Representations, 2025

2024

  1. arXiv
    WIPI: A New Web Threat for LLM-Driven Web Agents
    F. Wu, S. Wu, Yulong Cao, C. Xiao
    arXiv:2402.16965, 2024
  2. ECCV
    Dolphins: Multimodal Language Model for Driving
    Y. Ma, Yulong Cao, J. Sun, M. Pavone, C. Xiao
    European Conference on Computer Vision, 2024
  3. ECCV
    RealGen: Retrieval Augmented Generation for Controllable Traffic Scenarios
    W. Ding*, Yulong Cao*, D. Zhao, C. Xiao, M. Pavone
    European Conference on Computer Vision, 2024
  4. ICRA
    Reinforcement Learning with Human Feedback for Realistic Traffic Simulation
    Yulong Cao, B. Ivanovic, C. Xiao, M. Pavone
    IEEE International Conference on Robotics and Automation, 2024
  5. CoRL
    Promptable Closed-Loop Traffic Simulation
    S. Tan, B. Ivanovic, Y. Chen, B. Li, X. Weng, Yulong Cao, P. Krähenbühl, M. Pavone
    Conference on Robot Learning, 2024

2023

  1. USENIX
    You Can't See Me: Physical Removal Attacks on LiDAR-Based Autonomous Vehicles Driving Frameworks
    Yulong Cao, S. H. Bhupathiraju, P. Naghavi, T. Sugawara, Z. Morley Mao, S. Rampazzi
    32nd USENIX Security Symposium, 2023
  2. CoRL
    Language-Guided Traffic Simulation via Scene-Level Diffusion
    Z. Zhong, D. Rempe, Y. Chen, B. Ivanovic, Yulong Cao, D. Xu, M. Pavone, B. Ray
    Conference on Robot Learning, 2023
  3. CoRL
    Robust Trajectory Prediction Against Adversarial Attacks
    Yulong Cao, D. Xu, X. Weng, Z. Morley Mao, A. Anandkumar, C. Xiao, M. Pavone
    Conference on Robot Learning, 2023
  4. BMVC
    ADoPT: LiDAR Spoofing Attack Detection Based on Point-Level Temporal Consistency
    M. Cho, Yulong Cao, Z. Zhou, Z. Morley Mao
    British Machine Vision Conference, 2023
  5. CPS-IoT
    Adversarial Attacks on Adaptive Cruise Control Systems
    Y. Guo, T. Sato, Yulong Cao, Q. Alfred Chen, Y. Cheng
    Proceedings of Cyber-Physical Systems and Internet of Things Week, 2023

2022

  1. USENIX
    Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles
    R. S. Hallyburton, Y. Liu, Yulong Cao, Z. Morley Mao, M. Pajic
    31st USENIX Security Symposium, 2022
  2. ECCV
    AdvDO: Realistic Adversarial Attacks for Trajectory Prediction
    Yulong Cao, C. Xiao, A. Anandkumar, D. Xu, M. Pavone
    European Conference on Computer Vision, 2022

2021

  1. S&P
    Invisible for Both Camera and LiDAR: Security of Multi-Sensor Fusion-Based Perception in Autonomous Driving Under Physical-World Attacks
    Yulong Cao*, N. Wang*, C. Xiao*, D. Yang*, J. Fang, R. Yang, Q. Alfred Chen, M. Liu, B. Li
    IEEE Symposium on Security and Privacy, 2021
  2. NeurIPS
    Adversarially Robust 3D Point Cloud Recognition Using Self-Supervisions
    J. Sun, Yulong Cao, C. Choy, Z. Yu, A. Anandkumar, Z. Morley Mao, C. Xiao
    Advances in Neural Information Processing Systems, 2021
  3. BMVC
    On Adversarial Robustness of 3D Point Cloud Classification Under Adaptive Attacks
    J. Sun, K. Koenig, Yulong Cao, Q. Alfred Chen, Z. Morley Mao
    British Machine Vision Conference, 2021
  4. AutoSec
    Automated Tracking System for LiDAR Spoofing Attacks on Moving Targets
    Yulong Cao, J. Ma, K. Fu, S. Rampazzi, Z. Morley Mao
    Workshop on Automotive and Autonomous Vehicle Security, 2021
  5. ICMLW
    Improving Adversarial Robustness in 3D Point Cloud Classification via Self-Supervisions
    J. Sun, Yulong Cao, C. Choy, Z. Yu, C. Xiao, A. Anandkumar, Z. Morley Mao
    International Conference on Machine Learning Workshop, 2021
  6. ICCVW
    An Adversarial Attack on DNN-Based Adaptive Cruise Control Systems
    Y. Guo, C. Dipalma, T. Sato, Yulong Cao, Q. Alfred Chen, Y. Cheng
    ICCV Workshop on Adversarial Robustness in the Real World, 2021

2020

  1. USENIX
    Towards Robust LiDAR-Based Perception in Autonomous Driving: General Black-Box Adversarial Sensor Attack and Countermeasures
    J. Sun, Yulong Cao, Q. Alfred Chen, Z. Morley Mao
    29th USENIX Security Symposium, 2020
  2. EuroS&P
    AVGuardian: Detecting and Mitigating Publish-Subscribe Overprivilege for Autonomous Vehicle Systems
    D. Hong, J. Kloosterman, Y. Jin, Yulong Cao, Q. Alfred Chen, S. Mahlke, Z. Morley Mao
    IEEE European Symposium on Security and Privacy, 2020
  3. MLSys
    3D Adversarial Object Against MSF-Based Perception in Autonomous Driving
    Yulong Cao, N. Wang, C. Xiao, D. Yang, J. Fang, R. Yang, Q. Alfred Chen, M. Liu, B. Li
    Proceedings of the 3rd Conference on Machine Learning and Systems, 2020

2019

  1. arXiv
    Adversarial Objects Against LiDAR-Based Autonomous Driving Systems
    Yulong Cao, C. Xiao, D. Yang, J. Fang, R. Yang, M. Liu, B. Li
    arXiv:1907.05418, 2019
  2. CCS
    Adversarial Sensor Attack on LiDAR-Based Perception in Autonomous Driving
    Yulong Cao, C. Xiao, B. Cyr, Y. Zhou, W. Park, S. Rampazzi, Q. Alfred Chen, K. Fu, Z. Morley Mao
    Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2019

2017

  1. CCS
    Client-Side Name Collision Vulnerability in the New gTLD Era: A Systematic Study
    Q. Alfred Chen, M. Thomas, E. Osterweil, Yulong Cao, J. You, Z. Morley Mao
    Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2017