I’m an assistant professor at San Diego State University (SDSU) and a member of the Cybersecurity Center. I joined SDSU in August 2025.
I received my Ph.D. in Computer Science from Indiana University Bloomington in July 2025, advised by XiaoFeng Wang and Luyi Xing, and my B.Eng. in Information Security from Xidian University in 2019. I was a research intern at Samsung Research America from February to May 2024.
My research focuses on software supply chain, mobile, and IoT security and privacy. I use program analysis, machine learning, large language models (LLMs), and formal verification to uncover new attack vectors and emerging privacy issues in these and other evolving ecosystems.
Prospective PhD students: I am accepting PhD students with interests in systems security and privacy. See the recruitment flyer or contact me.
Publications
Full publication details and research impact · Google Scholar
- Software Supply Chain Security and Privacy: [USENIX Security’24], [USENIX Security’23]
- Mobile/IoT Security: [CCS’26], [USENIX Security’23], [CCS’21], [CCS’20]
- Program Analysis: [ASE’25]
- Cybercrime: [EuroS&P’24]
Professional Service
- Program committees: USENIX Security 2027, HealthSec 2026, SDIoTSec 2026, SafeThings 2025, SDIoTSec 2024, SafeThings 2024.
- Artifact evaluation: USENIX Security Artifact Evaluation Committee, 2024.
- Journal reviewer: IEEE Transactions on Dependable and Secure Computing (TDSC), 2026.
- Sub-reviewer: PoPETs 2024; IEEE S&P 2022, 2020; TDSC 2022; Inscrypt 2022; WiSec 2021; NDSS 2021, 2020; CCS 2020.
News
- (12/2026) Upcoming: HealthSec 2026 is scheduled for December 8; I am serving on its program committee.
- (08/2026) Our paper on risks in the splash ads ecosystem has been accepted to ACM CCS 2026.
- (07/2026) I will serve on the program committee of USENIX Security 2027.
- (02/2026) SDIoTSec 2026 took place on February 23; I served on its program committee.
- (2026) I am reviewing for IEEE Transactions on Dependable and Secure Computing (TDSC).
- (09/2025) LineBreaker, our work on finding token-inconsistency bugs with LLMs, was accepted to ASE 2025.
- (08/2025) I joined San Diego State University as an assistant professor.
- (07/2025) I received my Ph.D. in Computer Science from Indiana University Bloomington, advised by XiaoFeng Wang and Luyi Xing.
- (01/2025) I will serve on the program committee of SafeThings 2025.
- (08/2024) USENIX Security 2024 took place on August 14–16; I served on its Artifact Evaluation Committee.
- (07/2024) Our paper on fake evidence generators appeared at IEEE EuroS&P 2024.
- (05/2024) Our paper on privacy-configurable mobile SDKs was accepted to USENIX Security 2024.
- (02/2024) I joined Samsung Research America as a research intern, working there through May 2024.
- (01/2024) I will serve on the program committees of SDIoTSec 2024 and SafeThings 2024.
- (07/2023) I received a USENIX Security Travel Award.
- (03/2023) Union under Duress, our work on Android software supply chain security, was accepted to USENIX Security 2023.
- (09/2022) Our paper on IoT data exposure through companion apps was accepted to USENIX Security 2023.
- (11/2021) Our paper on disjointed IoT device management channels appeared at ACM CCS 2021.
- (06/2020) Our paper on resource management risks in mobile app-in-app ecosystems was accepted to ACM CCS 2020.
Selected Awards & Recognition
- USENIX Security Travel Award, 2023.
- CSAW Best Applied Security Paper Award, Top 10 Finalist, 2022.
- DEF CON CTF finalist with team r3kapig, 2022 and 2018.
- HackIN: 2nd place in 2022; 1st place in 2019.
- Security Hall of Fame acknowledgments: Opera, 2019; Tencent, 2018.
- First Prize, National Student Information Security Competition, 2017; First Prize, National Student Cryptography Competition, 2016.
