About
I am a tenure-track assistant professor at Institute for Math & AI, Wuhan at Wuhan University.
I received my Ph.D. degree from Tsinghua University in June 2024, advised by Prof. Qi Li and Prof. Kun Sun. Before that, I worked as a senior engineer at NetEase Games.
I am a system (e.g., Android, IoT, and Cloud) security researcher. Previously, I worked on IoT access control and eBPF-based system security. Now, I focus on identifying vulnerabilities in embedded systems (such as satellite and EV) through static analysis, dynamic analysis, and fuzzing tests. Additionally, I am engaged in developing practicable defense mechanisms to protect embedded systems.
AI Agents and Systems Security
My current research focuses on AI agents and systems security, including coding agents, IoT security, and the security of agentic and embodied AI systems.
I am recruiting Master/PhD students who aspire to become outstanding engineers or excellent researchers.
Publications
2026
-
Mono: Is Source Code Enough for Verification? Stratifying Patch-Mined Vulnerability Fixes by Context Sufficiency.
In Proceedings of International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2026.
[ bibtex ]
- TransBit: Efficient Hotpatching for Real-Time Microcontroller-Based Embedded Devices. In Proceedings of European Symposium on Research in Computer Security (ESORICS), 2026.
2025
- BLMProbe: Enhancing Internet-connected Device Discovery by Automated Device Labeling and Label Migration. In IEEE Transactions on Information Forensics and Security, 2025.
- OTA-Key: Over-the-Air Key Management for Flexible and Reliable IoT Device Provision. In IEEE Transactions on Network and Service Management, 2025.
2024
- Demystifying the Security Implications in IoT Device Rental Services. In Proceedings of USENIX Security Symposium, 2024.
- Your Firmware Has Arrived: A Study of Firmware Update Vulnerabilities. In Proceedings of USENIX Security Symposium, 2024.
- BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low Energy. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), 2024.
- From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT Devices. In Proceedings of Network and Distributed System Security (NDSS) Symposium, 2024.
- Laser-Based Command Injection Attacks on Voice-Controlled Microphone Arrays. In Proceedings of The annual Conference on Cryptographic Hardware and Embedded Systems (CHES), 2024.
-
Toward Zero-Trust IoT Networks via Per-Packet Authorization.
In IEEE Communications Magazine, 2024.
[ bibtex ]
- Cactus: Obfuscating Bidirectional Encrypted TCP Traffic at Client Side. In IEEE Transactions on Information Forensics and Security, 2024.
2023
- Cross Container Attacks: The Bewildered eBPF on Clouds. In Proceedings of USENIX Security Symposium, 2023.
- A Systematic Study of Android Non-SDK (Hidden) Service API Security. In IEEE Transactions on Dependable and Secure Computing, 2023.
2022
- RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices. In Proceedings of USENIX Security Symposium, 2022.
- JNI Global References Are Still Vulnerable: Attacks and Defenses. In IEEE Transactions on Dependable and Secure Computing, 2022.
2021 and before
- Ruledger: Ensuring Execution Integrity in Trigger-Action IoT Platforms. In Proceedings of IEEE International Conference on Computer Communications (Infocom), 2021.
-
Vulnerable Service Invocation And Countermeasures.
In IEEE Transactions on Dependable and Secure Computing, 2019.
[ bibtex ]
- Vulnerable Implicit Service: A Revisit. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), 2017.
-
LinkFlow: Efficient Large-Scale Inter-App Privacy Leakage Detection.
In Proceedings of International Conference on Security and Privacy in Communication Systems (SecureComm), 2017.
[ bibtex ]
-
Detecting and Defending Against Inter-app Permission Leaks in Android Apps.
In Proceedings of International Performance Computing and Communications Conference (IPCCC), 2016.
[ bibtex ]
Contact
Please feel free to send me an email: clangllvm@163.com