Agentic security
Autonomous agents for realistic, long-horizon security engineering workflows.
Research OS / 2026
PhD student in Computer Science at UIUC · advised by Prof. Lingming Zhang
Research taxonomy
I connect agent evaluation, systems evidence, and applied vulnerability research to make security automation measurable and useful.
Autonomous agents for realistic, long-horizon security engineering workflows.
Reasoning grounded in program analysis, dynamic execution, and reproducible evidence.
Discovery and validation across production software, services, and commercial binaries.
Validated vulnerabilities
344
Browser engines and Linux kernel tasks in SEC-bench Pro
Workflow horizon
Long
From bug discovery through debugger-verified validation
Latest signals
SEC-bench Pro, our benchmark for long-horizon software security tasks, is now available on arXiv.
Agentic Vulnerability Reasoning on COTS Binaries is now available on arXiv.
Recognized as a Microsoft Most Valuable Security Researcher for 2026 Q1.
Evidence base / Selected
Authoritative work on security-agent evaluation, autonomous vulnerability reasoning, and practical root-cause analysis.
arXiv · 2026
PDF of SEC-bench ProA benchmark of 344 validated vulnerabilities across browser engines and the Linux kernel, designed to measure realistic agent bug hunting.
An end-to-end study of autonomous vulnerability discovery and debugger-verified validation on commercial Windows binaries.
NeurIPS · 2025
PDF of SEC-benchA fully automated framework for constructing and evaluating authentic proof-of-concept generation and vulnerability patching tasks.
IEEE S&P · 2024
PDF of BENZENEA practical, automated crash-diagnosis system that uses under-constrained state mutation to rank root causes efficiently.