Large-scale cross-platform security study of roughly 45,000 repositories across five ML model hosting ecosystems, measuring unsafe deserialization, eval injection, malware signals, and recurring developer security misconceptions.
@misc{siddiq2027rce,title={An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems},author={Siddiq, Mohammed Latif and Romel, Tanzim Hossain and Sekerak, Natalie and Casey, Beatrice and Santos, Joanna C. S.},year={2026},note={Under review at the International Conference on Software Engineering (ICSE 2027)},}
TACL
The Choice Can Be the Attack: Auditing Aligned Backdoors in LLM Agents
LLM agents can be backdoored without visibly failing the task: a trigger can steer an agent toward an attacker’s preferred valid option while the final answer still looks acceptable. SHIFT (Structured Hidden Influence Test) reruns matched tasks with and without a known trigger and checks whether the changed choice favors the attacker’s target after accounting for ordinary option quality such as price or rating.
@misc{romel2026shift,title={The Choice Can Be the Attack: Auditing Aligned Backdoors in {LLM} Agents},author={Romel, Tanzim Hossain and Haider, Chowdhury Rakin},year={2026},note={Submitted to TACL 2026; manuscript not public},}
2025
CSCW
Sentiment Analysis of Anonymous Crisis Reports in Bangladesh
Tanzim Hossain Romel
2025
Submitted to the ACM Conference on Computer-Supported Cooperative Work and Social Computing (CSCW)
Transformer-based analysis of 124 anonymous crisis reports from Bangladesh’s 2024 national crisis, using a multilingual pipeline for Bengali and Romanized Bengali to study crowd-sourced sentiment in a high-risk setting.
@misc{romel2025ureporter,title={Sentiment Analysis of Anonymous Crisis Reports in Bangladesh},author={Romel, Tanzim Hossain},year={2025},note={Submitted to the ACM Conference on Computer-Supported Cooperative Work and Social Computing (CSCW)},}