01 About
I am an Associate Professor (Recipient of Nankai University's 100 Young Academic Leaders Program) at the College of Cryptology and Cyber Science, Nankai University. I earned my Ph.D. from the School of Cyber Engineering at Xidian University in December 2020. My research focuses on network and system security. Using empirical analysis, formal modeling, and program‑analysis methods, we have uncovered numerous logic flaws in real‑world systems, including IoT systems, Web/Browser, mobile systems, and communication protocols. My ongoing research interests include security analysis of diverse IoT systems, AI/agents for vulnerability discovery and pentesting, and human factors in cybersecurity. Our group's research findings have been published at top‑tier security venues including IEEE S&P (Oakland), USENIX Security, ACM CCS, NDSS, and Black Hat. These results have helped major industry vendors, including AWS, Microsoft, Google, Apple, Samsung, Alibaba, Baidu, and many others, improve the security of their products and are assigned tens of CVE/CNVD identifiers. I rank among the active top‑ranking authors at leading cybersecurity conferences, as shown in public statistics [1][2].
I currently lead the Hack4F research group with around ten members, which is part of the Key Laboratory of Data and Intelligent System Security, Ministry of Education. Our group maintains solid collaborative partnerships with prestigious universities domestically and internationally. If you are enthusiastic about network and system security and enjoy hands‑on practice, feel free to reach out to me via email or Feishu for internships and research collaborations within our group.
Research keywords:
02 Education & Experience
Academic background & positions-
2024.1 – PresentAssociate Professor, Nankai University“100 Young Academic Leaders of Nankai University” · College of Cryptology and Cyber Science
-
2020.12 – 2023.12Lecturer · Postdoctoral Fellowship, Nankai UniversityCollege of Cyber Science
-
2016.7 – 2020.12Ph.D. in Information Security, Xidian UniversityAdvised by Prof. Yuqing Zhang · RA at the National Computer Network Intrusion Protection Center, UCAS
-
2018.11 – 2020.7Joint Ph.D. Student, Indiana University BloomingtonMentored by Prof. XiaoFeng Wang and Prof. Luyi Xing
-
2015 – 2016Master Student in Crypto, Xidian University
-
2011 – 2015B.E. in Information Countermeasure Technology, Xidian University
03 Selected Publications
Full list on Google Scholar ↗-
ISSRE'26KubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule InferenceIEEE International Symposium on Software Reliability Engineering, 2026
-
TWEBPrevalent but Fragmented: Understanding the Scattered URL Navigation Interventions in Modern Web ClientsACM Transactions on the Web, 2026
-
EMSERethinking software misconfigurations in the real world: an empirical study and literature analysisEmpirical Software Engineering, 2026
-
FUZZING'26UAVConfigFuzzer: Detecting Incorrect Configurations in Unmanned Aerial Vehicles via Setpoint Estimation Guided Fuzzing (Registered Report)International Fuzzing Workshop, 2026
-
SCISSecurity and Privacy Measurement on Chinese Consumer IoT Traffic based on Device LifecycleSCIENCE CHINA Information Sciences, 2025We constructed and open-sourced the first Chinese smart home device traffic dataset — GitHub
-
CIoTSC'25"Seeing is not always believing": Exploring Bystanders' Privacy Concerns on Multifunction IoT Devices in ChinaIEEE International Conference on Computer, Internet of Things and Smart City, 2025 · 🏆 Best Paper Award
-
S&P'24MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT ImplementationsIEEE Symposium on Security and Privacy, 2024
-
NDSS'24Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsNetwork and Distributed System Security Symposium, 2024
-
USENIX'23Union under Duress: Understanding Hazards of Duplicate Resource Mismediation in Android Software Supply ChainUSENIX Security Symposium, 2023
-
arXivTowards Comprehensively Understanding the Run-time Security of Programmable Logic Controllers: A 3-year Empirical StudyarXiv:2212.14296
-
TSEMulti-misconfiguration Diagnosis via Identifying Correlated Configuration ParametersIEEE Transactions on Software Engineering, 2023
-
TDSCReal-Time Diagnosis of Configuration Errors for Software of AI Server InfrastructureIEEE Transactions on Dependable and Secure Computing, 2023
-
CCS'22P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesACM Conference on Computer and Communications Security, 2022
-
USENIX'22How Are Your Zombie Accounts? Understanding Users' Practices and Expectations on Mobile App Account DeletionUSENIX Security Symposium, 2022
-
USENIX'22Birds of a Feather Flock Together: How Set Bias Helps to Deanonymize You via Revealed Intersection SizesUSENIX Security Symposium, 2022
-
CCS'21Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsACM Conference on Computer and Communications Security, 2021Disjointed device management channel vulnerabilities in Apple HomeKit (CVE-2020-9978, macOS / iOS); also CNVD-2020-68248 and CNVD-2020-73400.
-
IoT-JReviewing IoT Security via Logic Bugs in IoT Platforms and SystemsIEEE Internet of Things Journal, 2021
-
S&P'20Burglars IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsIEEE Symposium on Security and Privacy, 2020Vulnerabilities in IoT messaging protocols (MQTT) and device identity management affected major platforms including AWS, Microsoft, IBM, Alibaba, Baidu, iRobot, Tuya, Eclipse Mosquitto, enabling remote hijacking, DoS, and privacy leaks. Acknowledged by MSRC; CVEs CVE-2018-12546 / CVE-2018-12550 and multiple CNVD entries assigned. MQTT authorization design issues raised as a priority by the OASIS MQTT Technical Committee — MQTT-536.
-
USENIX'20Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access DelegationUSENIX Security Symposium, 2020Cross-cloud IoT delegation vulnerabilities acknowledged by Samsung SmartThings ($2,000 bounty) and Philips Hue.
-
USENIX'19Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsUSENIX Security Symposium, 2019
-
ESORICS'19Identifying Privilege Separation Vulnerabilities in IoT Firmware with Symbolic ExecutionEuropean Symposium on Research in Computer Security, 2019
-
Journal智能家居安全综述 (A Survey on Smart Home Security)计算机研究与发展, 2018, 55(10): 2111
-
IoT-JThe Effect of IoT New Features on Security and Privacy: New Threats, Existing Solutions, and Challenges yet to be SolvedIEEE Internet of Things Journal, 2018, 6(2): 1606–1616
-
Journal物联网操作系统安全研究综述 (A Survey on Security of IoT Operating Systems)通信学报, 2018, 39(3): 22–34
-
S&P'17Poster: Security Analysis of HSTS Implementation in BrowsersIEEE Symposium on Security and Privacy, 2017Discovered an HSTS bypass via flooding of the HSTS policy file in Chromium (Severity: Medium) — Chromium Issue 699461
-
JournalHTML5 新特性安全研究综述 (A Survey on Security of New HTML5 Features)计算机研究与发展, 2016, 53(10): 2163–2172
-
JournalHTML5 应用程序缓存中毒攻击研究 (Research on HTML5 AppCache Poisoning Attacks)通信学报, 2016, 37(10): 149–157
04 Research Funds
Grants & funding05 Talks
Invited talks & briefings06 Books & Reports
07 Academic Services
Reviewing · PC · EditorialEditorial Board
Program Committee
Chair
Journal Reviewer
08 Teaching
09 People
I am fortunate to work with the following students and researchers.