Yan Jia (贾岩)

Yan Jia 贾岩

Associate Professor ★ Nankai “100 Young Academic Leaders”
College of Cryptology and Cyber Science, Nankai University

My major interests are discovering and understanding security vulnerabilities, especially new design/logic vulnerabilities, in real-world systems including IoT systems (current focus), Web/Browser, mobile and network systems. Our works have been published at top-tier venues (e.g., Oakland, USENIX Security, CCS, NDSS, Black Hat) and helped leading vendors harden their systems. I am among active top authors in terms of publishing at leading security venues [1][2].

01 About

I am an Associate Professor (Recipient of Nankai University's 100 Young Academic Leaders Program) at the College of Cryptology and Cyber Science, Nankai University. I earned my Ph.D. from the School of Cyber Engineering at Xidian University in December 2020. My research focuses on network and system security. Using empirical analysis, formal modeling, and program‑analysis methods, we have uncovered numerous logic flaws in real‑world systems, including IoT systems, Web/Browser, mobile systems, and communication protocols. My ongoing research interests include security analysis of diverse IoT systems, AI/agents for vulnerability discovery and pentesting, and human factors in cybersecurity. Our group's research findings have been published at top‑tier security venues including IEEE S&P (Oakland), USENIX Security, ACM CCS, NDSS, and Black Hat. These results have helped major industry vendors, including AWS, Microsoft, Google, Apple, Samsung, Alibaba, Baidu, and many others, improve the security of their products and are assigned tens of CVE/CNVD identifiers. I rank among the active top‑ranking authors at leading cybersecurity conferences, as shown in public statistics [1][2].

I currently lead the Hack4F research group with around ten members, which is part of the Key Laboratory of Data and Intelligent System Security, Ministry of Education. Our group maintains solid collaborative partnerships with prestigious universities domestically and internationally. If you are enthusiastic about network and system security and enjoy hands‑on practice, feel free to reach out to me via email or Feishu for internships and research collaborations within our group.

Research keywords:

IoT Security Vulnerability Discovery AI/Agent for Security Network and Systems Security

02 Education & Experience

Academic background & positions

03 Selected Publications

Full list on Google Scholar ↗
# Corresponding author * Equal contribution
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017 & Before

04 Research Funds

Grants & funding
National Natural Science Foundation of China (面上项目)
62572258 · 2026.1 – 2029.12¥500,000
Cybersecurity Threat Perception for Power Grid Scenarios
Tianjin Electric Power Research Institute (天津电科院) · 2025.11 – 2026.11¥685,000
National Natural Science Foundation of China (青年项目)
62102198 · 2022.1 – 2024.12¥300,000
China Postdoctoral Science Foundation (Special)
2023T160335 · 2023.7.28 – 2024.1¥160,000
China Postdoctoral Science Foundation
2021M691673 · 2021.6 – 2024.1¥80,000
Fundamental Research Funds for the Central Universities
No. 079-63263257 · 2026
Innovation Fund of Xidian University
2018 – 2019¥12,000
China Scholarship Council (CSC) Funding
Joint Ph.D. program, Indiana University Bloomington

05 Talks

Invited talks & briefings
IoT应用逻辑漏洞挖掘研究经验分享
Institute of Information Engineering, Chinese Academy of Sciences (中科院信息工程研究所) · Beijing
Jul 2026
基于自动机学习和大模型的消费物联网逻辑漏洞发现
CCF 第40次全国计算机安全学术交流会 · 新质安全分论坛 · Tianjin
Sep 2025
应用逻辑缺陷研究经验分享––从生活现象到网安学术论文
CCF Talk · 计算机网络与通信顶会––精读细讲 · Online
Jun 2024
智能家居逻辑漏洞研究––新应用与场景带来的挑战
2023年 InForSec 网络空间安全夏令营 · “导师面对面”专题学术活动
Aug 2023
智能家居逻辑漏洞研究––新应用与场景带来的挑战
首届国际网络空间安全顶级会议交流研讨会 (CyberSec 2023) · Lhasa
Aug 2023
智能家居安全研究新进展:新场景与应用的挑战
华为“未来网络前沿–青年科学家论坛:网络协议与安全专场” · Beijing
Feb 2023
IoT Manufacturers' New Nightmare: Design Flaws and Deployment Chaos in Cloud-based IoT Access Control Policies (40-Minute Briefing ↗)
Black Hat Europe 2022
2022
Codema Attack: Controlling Your Smart Home Through Dangling Management Channels (40-min Briefing ↗)
Black Hat Asia 2022
2022
物联网设备多管理通道安全风险分析
天津市网络与数据安全技术重点实验室 2021 学术年会 · Nankai University
Nov 2021
网络安全研究国际学术论坛 (InForSec)
InForSec Forum
Jun 2021
How I Can Unlock Your Smart Door: Security Pitfalls in Cross-Vendor IoT Access Control (40-min Briefing ↗)
Black Hat Asia 2021 · Reported by Dark Reading, Dark Reading
2021
Sneak into Your Room: Security Holes in the Integration and Management of Messaging Protocols on Commercial IoT Clouds (50-min Briefing ↗)
Black Hat Europe 2019
2019
Cyber Security Top Conference Paper Summer Camp 2020
Nankai University (Online)
Jul 2020
InForSec Annual Symposium 2020
Tsinghua University
Jan 2020

06 Books & Reports

《网络安全国际学术研究进展》
人民邮电出版社 · ISBN 9787115588944 · 2022-08
《软件安全:漏洞利用及渗透测试》
清华大学出版社 · ISBN 9787302602156 · 2022-03

07 Academic Services

Reviewing · PC · Editorial

Editorial Board

EditorialCyber Security and Applications (ISSN 2772-9184) – Editorial Board, 2026–

Program Committee

PCUSENIX Security '27 – 34th USENIX Security Symposium
PCRAID'26 – International Symposium on Research in Attacks, Intrusions and Defenses
PCSDIoTSec 2024/2025 – NDSS Workshop on Security and Privacy in Standardized IoT
PCIEEE MSN – International Conference on Mobility, Sensing and Networking
PCSafeThings 2024 – IEEE/ACM Workshop on the Internet of Safe Things
PCCSCW'23 – International Conference on Computer Supported Cooperative Work in Design
PCEAI SPNCE 2021 – International Conference on Security, Privacy and Network Engineering

Chair

Web ChairICICS'23 – International Conference on Information and Communications Security
ChairWorkshop on Security and Privacy of the Internet – 3rd Intl. Conf. on Computer, IoT and Smart City

Journal Reviewer

ReviewerIEEE IoT Journal, IEEE Security & Privacy, JCST, IEEE Trans. on Big Data, IEEE TIFS, Empirical Software Engineering, etc.

08 Teaching

Course
IoT Security (Lab)
Undergraduate · 物联网安全(实验) · 2022–2026
Network Security Technology
Undergraduate · 网络安全技术 · 2022–2026
Summer International Short-Term Course
暑期国际小学期课程 · 2026
Student Competition
National College Student Information Security Competition – First Prize
2025 · 全国大学生信息安全竞赛一等奖
National Cryptology Technology Competition – First Prize
2025 · 全国密码技术竞赛一等奖
National College Student Information Security Competition – Second Prize
2024 · 全国大学生信息安全竞赛二等奖

09 People

I am fortunate to work with the following students and researchers.

PhD Students
Qingyin Tan(co-supervision) Yuhao Liu(co-supervision) Jieshuai Yang(co-supervision) Yingnan Zhou(co-supervision) Wenxuan Fu
Master Students
Yijing Liu(co-sup · grad. → Tsinghua PhD) Yuxin Song(grad. → ICBC) Peng Guo(co-sup · grad. → Beijing) Zesheng Wan Bei Liu(enterprise joint) Chenghua Jin Zhengyuan Li(enterprise joint) Yixin Zhang Shurui Fang Han Lin Nuoheng Zhou Linwei Li
Undergraduate Interns
Jia Li DaiSong Gong Zihan Guo Yiwen Zhang Zeqi Du Aidi Zhang Xiang Gao

10 Awards & Honors

🥇
Tianjin Science and Technology Progress Award – First Prize
2025 · 天津市科学技术进步一等奖
🥈
Tianjin Science and Technology Progress Award – Second Prize
2025 · 天津市科学技术进步二等奖
🥉
State Grid Corporation of China Technical Invention Award – Third Prize
2025 · 国家电网有限公司技术发明三等奖
🏆
ACM China Council Tianjin Chapter Rising Star Award
2022 · recognizing early-career excellence in computing research
🎖️
CSAW'22 Applied Research Competition – Finalist
Our CCS'21 paper was selected as a finalist (10/83). Learn more ↗