About
I am a full professor at Nankai University and lead NKSSecLab. I am also a member of the research group led by Prof. Zheli Liu. I was an assistant professor at Nanyang Technological University, Singapore, working with Prof. Yang Liu.
My research focuses on Software Security and Software Supply Chain Security, securing multi-source heterogeneous components across evolving software ecosystems. I have published over 100 peer-reviewed papers in leading cybersecurity and software engineering venues. I received the ACM SIGSOFT Early Career Researcher Award in 2026 and 7 Distinguished Paper Awards (ICSE × 4, ASE × 2, FSE × 1) at top-tier conferences.
Research
Securing software supply chains through component analysis, vulnerability discovery, and behavior understanding.
First-party component security
Program analysis, Static Application Security Testing (SAST), and vulnerability detection.
Third-party component security
Software Composition Analysis (SCA), dependency vulnerability propagation, and compatible remediation.
Malicious component analysis
Malware detection, behavior understanding, and explanation.
Exploring LLM-assisted vulnerability PoC generation and security validation. Related preprint →
Research overview
Selected Publications
-
Synchronizing Key Aspects: Enhancing Vulnerability PoC Reports from Multiple Sources
PDF forthcomingDetails -
Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World Exploits
-
ForeDroid: Scenario-Aware Analysis for Android Malware Detection and Explanation
-
Beyond Decision: Android Malware Description Generation through Profiling Malicious Behavior Trajectory
-
Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We?
-
Automatically Distilling Storyboard with Rich Features for Android Apps
-
EndWatch: A Practical Method for Detecting Non-Termination in Real-World Software
-
Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java Projects
-
Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM Ecosystem
-
Accessible or Not? An Empirical Investigation of Android App Accessibility
-
Why an Android App is Classified as Malware? Towards Malware Classification Interpretation
-
A Performance-Sensitive Malware Detection System Using Deep Learning on Mobile Devices
-
GUI-Squatting Attack: Automated Generation of Android Phishing Apps
-
An Empirical Assessment of Security Risks of Global Android Banking Apps
News
Prospective students & collaboration
For questions about study and research opportunities in software supply chain security, program analysis, or malware analysis, please get in touch by email. Availability and arrangements can be discussed directly.
For student inquiries, include a CV, research interests, and relevant project or paper links. For collaboration, outline the research question, existing work, and proposed collaboration.
Awards
- ACM SIGSOFT Early Career Researcher Award, 2026
- Distinguished Paper Award (ICSE 2026)
- Stanford World’s Top 2% Scientists, 2025
- CAIE Young Talent Promotion Program, 2025
- National Cybersecurity Outstanding Talent, 2024
- Distinguished Paper Award (FSE 2024)
- Distinguished Paper Award (ASE 2023)
- Distinguished Paper Award (ICSE 2023)
- Rising Star Award (ACM China Council Tianjin Chapter), 2022
- Distinguished Paper Award (ASE 2022)
- Distinguished Paper Award (ICSE 2021)
- Distinguished Paper Award (ICSE 2018)
Service
- Probationary Young Assistant Editor, Frontiers of Computer Science (FCS), May 2026–May 2029
- Young Editorial Board Member, Digital Communications and Networks (DCN), June 2026–June 2029
- 2027 Program Committee: USENIX Security, ICSE
- 2026 Program Committee: USENIX Security
- 2025 Program Committee: USENIX Security, IEEE S&P, CCS, ISSTA, OOPSLA
- 2024 Program Committee: USENIX Security, IEEE S&P, CCS, ISSTA, OOPSLA
- 2023 Program Committee: FSE, ASE
- 2022 Program Committee: ASE