Wenting Zheng



Office: GHC 9015
Email: wenting [at] cmu [dot] edu
CV [Updated June 2026]

I am an assistant professor in CMU's Computer Science Department. I am a core faculty in CyLab, and have a courtesy appointment in the Electrical and Computer Engineering department. I am also a co-founder and advisor (previously the Chief Scientist) of Opaque Systems.

I am broadly interested in the intersection of systems and cryptography. Recently, I've been excited about securing modern AI systems through a principled, cryptographic approach that makes them private, verifiable, and accountable. My current research is focused on answering the following two questions:

How to design specialized cryptographic protocols to build efficient and secure AI systems? Some works in this area include: Opaque, the first distributed encrypted analytics framework that defends against access-pattern leakage in confidential computing; Helen, Delphi, and BOLT, which support multi-party training and two-party inference over encrypted data; our paper on LLM watermarking exposes fundamental design limitations in watermarking and proposes deployment guidelines.

How to enable non-experts in cryptography to build generic, high-performance cryptographic systems? Some works in this area include: Cerebro, Silph, Rotom, and Orbit are part of a compiler stack for automatically generating optimized MPC and FHE protocols, some even beating the performance of SOTA hand-tuned protocols; CostCO, the first automatic cost-modeling framework for MPC compilers; Cinnamon and Cerium accelerate FHE on ASIC and GPU hardware, beating CPU performance by several orders of magnitude.

My research is generously supported by the National Science Foundation, AWS, Cisco, CMU CyLab, Google, and Samsung. Thank you!


Teaching

Fall 2025: Distributed Systems
Spring 2025: Secure Computer Systems
Fall 2024: Distributed Systems
Spring 2024: Secure Computer Systems
Fall 2023: Distributed Systems
Spring 2023: Security for Software and Hardware Systems
Fall 2022: Distributed Systems
Fall 2021: Cryptosystems: Theory and Practice

Group

I am looking for highly motivated students who are interested in building secure AI systems with cryptography to start in Fall 2027. Please apply to the CMU Ph.D. program!

I'm very fortunate to collaborate with a talented set of students!

Edward Chen (Ph.D., co-advised with Fraser Brown)
Andrew Park (Ph.D., co-advised with Elaine Shi, currently on leave at MongoDB)
Qi Pang (Ph.D., co-advised with Virginia Smith)
Siddharth Jayashankar (Ph.D., co-advised with Dimitrios Skarlatos)
Anna Woo (Ph.D.)
Freya Liu (Ph.D.)

Alum:
Zikai Zhou (Undergraudate)
Lawrence Feng (Undergraduate)
Zhengyuan Su (Undergraudate -> Ph.D. at NUS)
Simon Beyzerov (Undergraduate)
William Seo (Masters -> Amazon)
Trevor Leong (Masters -> SpaceX)
Jinhao Zhu (Masters -> Ph.D. at UC Berkeley)
Helen Mollering (Visiting Ph.D.)
Shreya Sharma (Masters -> Bloomberg -> Meta)


Publications

Cerium: A Multi-GPU Framework for Terabyte-Scale Encrypted Inference. [Paper]
Siddharth Jayashankar, Joshua Kim, Michael B. Sullivan, Wenting Zheng, Dimitrios Skarlatos.
SOSP 2026

Orbit: Optimizing Rescale and Bootstrap Placement with Integer Linear Programming Techniques for Secure Inference. [Paper]
Zikai Zhou, William Seo, Edward Chen, Alex Ozdemir, Fraser Brown, Wenting Zheng.
USENIX Security 2026

HasteBoots: Proving TFHE Programmable Bootstrapping in Seconds. [Paper]
Fengrun Liu, Haofei Liang, Xiang Xie, Yu Yu, Wenting Zheng, Yuncong Hu.
USENIX Security 2026

Bridging Usability and Performance: A Tensor Compiler for Autovectorizing Homomorphic Encryption. [Paper]
Edward Chen, Fraser Brown, Wenting Zheng.
USENIX Security 2026

FABLE: Batched Evaluation on Confidential Lookup Tables in 2PC. [Paper]
Zhengyuan Su, Qi Pang, Simon Beyzerov, Wenting Zheng.
USENIX Security 2025

Cinnamon: A Framework for Scale-out Encrypted AI. [Paper]
Siddharth Jayashankar, Edward Chen, Tom Tang, Wenting Zheng, Dimitrios Skarlatos.
ASPLOS 2025

No Free Lunch in LLM Watermarking: Trade-offs in Watermarking Design Choices. [Paper][Blog post]
Qi Pang, Shengyuan Hu, Wenting Zheng, Virginia Smith.
NeuRIPS 2024

Communication Bounds for the Distributed Experts Problem. [Paper]
Zhihao Jia, Qi Pang, Trung Tran, David Woodruff, Zhihao Zhang, Wenting Zheng. (alphabetical order).
NeuRIPS 2024

BOLT: Privacy-Preserving, Accurate and Efficient Inference for Transformers. [Paper]
Qi Pang, Jinhao Zhu, Helen Mollering, Wenting Zheng, and Thomas Schneider.
IEEE S&P 2024

Communication-efficient, Fault Tolerant PIR over Erasure Coded Storage. [Paper]
Andrew Park, Trevor Leong, Francisco Maturana, Wenting Zheng, Rashmi Vinayak.
IEEE S&P 2024

PIANO: Extremely Simple, Single-Server PIR with Sublinear Server Computation. [Paper]
Mingxun Zhou, Andrew Park, Elaine Shi, Wenting Zheng.
IEEE S&P 2024

Secure Federated Correlation Test and Entropy Estimation. [Paper]
Qi Pang*, Lun Wang*, Shuai Wang, Wenting Zheng, Dawn Song.
ICML 2023

ADI: Adversarial Dominating Inputs in Vertical Federated Learning Systems. [Paper]
Qi Pang, Yuanyuan Yuan, Shuai Wang, Wenting Zheng.
IEEE S&P 2023

Silph: A Framework for Scalable and Accurate Generation of Hybrid MPC Protocols. [Paper]
Edward Chen*, Jinhao Zhu*, Alex Ozdemir, Fraser Brown, Riad Wahby, Wenting Zheng.
IEEE S&P 2023

CostCO: An Automatic Cost Modeling Framework for Secure Multi-Party Computation. [Paper] [Extended version]
Vivian Fang, Lloyd Brown, William Lin, Wenting Zheng, Aurojit Panda, Raluca Ada Popa.
IEEE Euro S&P 2022
Distinguished Paper Award

Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning. [Paper] [Extended version]
Wenting Zheng, Ryan Deng, Weikeng Chen, Raluca Ada Popa, Aurojit Panda, Ion Stoica.
USENIX Security 2021

Delphi: A Cryptographic Inference Service for Neural Networks. [Paper] [Extended version]
Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, Raluca Ada Popa.
USENIX Security 2020

Helen: Maliciously Secure Coopetitive Learning for Linear Models. [Paper] [Extended version]
Wenting Zheng, Raluca Ada Popa, Joseph E. Gonzalez, Ion Stoica.
IEEE S&P 2019

DIZK: Distributing Zero Knowledge Proof Systems. [Paper] [Extended version]
Howard Wu, Wenting Zheng, Alessandro Chiesa, Raluca Ada Popa, Ion Stoica.
USENIX Security 2018

MiniCrypt: Reconciling Encryption and Compression for Big Data Stores. [Paper] [Slides]
Wenting Zheng, Frank Li, Raluca Ada Popa, Ion Stoica, Rachit Agarwal.
EuroSys 2017

Opaque: An Oblivious and Encrypted Distributed Analytics Platform. [Paper] [Slides] [Code] [SparkSummit talk]
Wenting Zheng, Ankur Dave, Jethro Beekman, Raluca Ada Popa, Joseph Gonzalez, Ion Stoica.
NSDI 2017

SCL: Simplfying Distributed SDN Control Planes. [Paper]
Aurojit Panda, Wenting Zheng, Xiaohe Hu, Arvind Krishnamurthy, Scott Shenker.
NSDI 2017

Fast Databases with Fast Durability and Recovery through Multicore Parallelism [Paper] [Slides]
Wenting Zheng, Stephen Tu, Eddie Kohler, Barbara Liskov.
OSDI 2014

Speedy Transactions in Multicore In-Memory Databases [Paper]
Stephen Tu, Wenting Zheng, Eddie Kohler, Barbara Liskov, Samuel Madden.
SOSP 2013