I build reliable, controllable, and trustworthy AI systems — with machine unlearning as the central thread, extending to the verification of forgetting and the evaluation of LLMs, VLMs, and AI agents.

I am an Assistant Professor in the Department of Computer Science & Information Systems at BITS Pilani. My research develops methods for selectively removing knowledge from trained models — across graph neural networks, multi-modal recommenders, large language models, and vision models — while preserving their usefulness.
A second strand of my work asks a harder question: whether "forgotten" knowledge is really gone. I study reasoning-based recovery attacks and diagnose misleading unlearning-evaluation artifacts. This has grown into a broader program on the trustworthy evaluation of modern AI systems: benchmarks and stress tests for access control, prompt injection, jailbreaks, privacy leakage in AI agents, and reasoning. I completed my PhD at the National University of Singapore, advised by Prof. Mohan Kankanhalli.
Three connected threads: removing knowledge, verifying that removal, and evaluating whether modern AI systems can be trusted.
Selective forgetting in graph networks, multi-modal recommenders, LLMs, and vision models — removing data under legal, licensing, and modality constraints while preserving utility. My graph method (D2DGN) improves edge- and node-unlearning AUC by up to 43% over prior approaches.
Testing whether unlearned knowledge is truly gone. My reasoning-based recovery attack (SLEEK) retrieves 62.5% of "forgotten" facts that standard metrics report as erased; the BatchNorm Illusion shows apparent forgetting can be undone by a single forward pass — with no weight change.
Benchmarks and stress tests that surface failures production systems hide: even GPT-4.1 scores only F1 0.27 on OrgAccess's hardest tier, and Scammer4U pages extract critical personal data 54–93% of the time versus 0% on benign controls.
Yash Sinha in bold. A curated set; the full list is on Google Scholar.
See the complete, up-to-date list on Google Scholar.
Evaluation resources introduced in the work above. Code and organization at github.com/MachineUnlearn.
Role-based access control benchmark for organization-scale LLMs (EMNLP 2025).
Independent PI funding secured within the first year as faculty, plus industry-sponsored collaboration.
LLM-DB: Reimagining Large Language Models as Structured Knowledge Stores.
Verifiable Machine Unlearning Infrastructure for Regulated Foundation Model Deployments.
Automated Indic multilingual audit framework for child safety in LLMs and AI agents.
Recent activity, most recent first.
Service: program committee / reviewer for NeurIPS, ICML, AAAI, ICLR, COLM, ARR (ACL/EMNLP/NAACL), IEEE TKDE, IEEE TAI, IEEE TCSVT, and Scientific Reports (Nature Portfolio).