Recent Research Interests
LLM for Security
We explore how large language models can enhance security analysis and automate traditionally labor-intensive security tasks. Our research investigates the use of LLMs for vulnerability discovery, program understanding, security reasoning, threat analysis, and automated security testing. We are particularly interested in combining the semantic reasoning capabilities of LLMs with program analysis and domain-specific security knowledge to build more accurate, scalable, and practical security systems.
LLM Security
We study the security, privacy, and trustworthiness of large language models and LLM-powered applications. Our research examines emerging threats such as jailbreak attacks, prompt injection, adversarial manipulation, data leakage, model misuse, and security risks introduced by LLM agents and tool-augmented systems. We also develop systematic evaluation methodologies and practical defenses to improve the robustness, reliability, and security of LLMs in real-world applications.
Mobile Security
We investigate security and privacy issues across mobile applications, operating systems, software ecosystems, and their interactions with cloud and intelligent services. Our research focuses on discovering vulnerabilities and privacy risks through large-scale program analysis, security measurement, and automated testing of real-world mobile applications. We are also interested in emerging mobile security problems introduced by AI-enabled applications, cross-device interactions, and increasingly complex mobile ecosystems.
IoT & Embodied AI Security
We investigate security and privacy risks across IoT devices, communication protocols, cyber-physical systems, and emerging embodied AI platforms. Our research studies vulnerabilities and attack surfaces throughout the interaction chain from sensing and communication to reasoning, decision-making, and physical actions. In particular, we are interested in the security of robots and embodied agents, including vulnerabilities in AI-driven control pipelines, unsafe physical behaviors, cross-layer attacks, and systematic techniques for discovering and mitigating these risks.
Program Analysis
We develop static, dynamic, and hybrid program-analysis techniques for vulnerability discovery, behavioral understanding, and large-scale security measurement. Our research analyzes applications, binaries, firmware, and complex software ecosystems to uncover security-critical behaviors that are difficult to identify through conventional testing. We are particularly interested in combining program analysis with machine learning and large language models to improve the scalability, automation, and semantic understanding of security analysis.
Human-Centered Security
We study security and privacy problems from a human-centered perspective, focusing on how users perceive, interact with, and respond to security mechanisms in real-world systems. Our research investigates usable security, privacy decision-making, user behavior, security perceptions, and the gap between technical protection mechanisms and actual user practices. We are also interested in understanding human interactions with emerging AI systems and designing security mechanisms that are not only technically effective but also understandable, usable, and aligned with users' needs.