Slide 01 · Software Security × AI

Hwiwon
Lee

PhD student in Computer Science at UIUC · advised by Prof. Lingming Zhang

I build and evaluate AI agents for cybersecurity.

Portrait of Hwiwon Lee
Urbana, Illinois

Slide 02 · Inquiry

Research,in motion.

I develop rigorous systems and evaluations that move security agents beyond short demonstrations and into the long, uncertain workflows of real vulnerability research.

01

Agentic security

Autonomous agents for realistic, long-horizon security engineering.

02

Software systems

Model reasoning grounded in program analysis and execution evidence.

03

Vulnerability research

Discovery and validation across production software and binaries.

Slide 03 · Signals

Recent
news

  1. SEC-bench Pro, our benchmark for long-horizon software security tasks, is now available on arXiv.

  2. Agentic Vulnerability Reasoning on COTS Binaries is now available on arXiv.

  3. Recognized as a Microsoft Most Valuable Security Researcher for 2026 Q1.

Slide 04 · Record

Selected
work

Benchmarks and systems for measuring, grounding, and advancing AI-driven security research.

  1. arXiv
    2026

    SEC-bench Pro: Can Language Models Solve Long-Horizon Software Security Tasks?

    Hwiwon Lee, Jiawei Liu, Dongjun Kim, Wubing Xia, Ziqi Zhang, Chunqiu Steven Xia, Lingming Zhang

    A benchmark of 344 validated vulnerabilities across browser engines and the Linux kernel, designed to measure realistic agent bug hunting.

    PDF of SEC-bench Pro
  2. arXiv
    2026

    Agentic Vulnerability Reasoning on COTS Binaries

    Hwiwon Lee, Jongseong Kim, Lingming Zhang

    An end-to-end study of autonomous vulnerability discovery and debugger-verified validation on commercial Windows binaries.

    PDF of Agentic Vulnerability Reasoning on COTS Binaries
  3. NeurIPS
    2025

    SEC-bench: Automated Benchmarking of LLM Agents on Real-World Software Security Tasks

    Hwiwon Lee, Ziqi Zhang, Hanxiao Lu, Lingming Zhang

    A fully automated framework for constructing and evaluating authentic proof-of-concept generation and vulnerability patching tasks.

    PDF of SEC-bench
  4. IEEE S&P
    2024

    BENZENE: A Practical Root Cause Analysis System with an Under-Constrained State Mutation

    Younggi Park, Hwiwon Lee, Jinho Jung, Kevin Koo, Huy Kang · Distinguished Paper

    A practical, automated crash-diagnosis system that uses under-constrained state mutation to rank root causes efficiently.

    PDF of BENZENE