Contact: kunsong.zhao[@@AT@@]connect[DOT]polyu[DOT]hk
kunszhao[@@AT@@]gmail[DOT]com
I am an incoming Postdoctoral Fellow at The Hong Kong Polytechnic University (PolyU), working with Prof. Daniel Xiapu Luo. I obtained my Ph.D. degree in Computer Science from PolyU in 2026 under Daniel's supervision. Before that, I received my Master and Bachelor degrees in Software Engineering from Wuhan University in 2022 and Hubei University in 2019, respectively.
My research centers around software security, leveraging static and dynamic program analysis, formal verification, and emerging AI techniques to build more secure and dependable software systems. Currently, I primarily focuses on binary analysis, blockchain and smart contract security, and AI security.
I warmly welcome connection and collaboration opportunities. I also look forward to collaborating with highly self-motivated students who have a strong background and a genuine interest in my research areas (though not necessarily limited to them). If you are interested, please feel free to contact me (Email: kunszhao[@@AT@@]gmail[DOT].com).
2026.06 🎉 Invited to serve on the Program Committee of USENIX SEC 2027 !
2026.04 🎉 Successfully defended my oral examination !
2022.09 - 2026.06, Ph.D. in Computer Science, The Hong Kong Polytechnic University.
2019.09 - 2022.06, M.Eng. in Software Engineering, Wuhan University.
2015.09 - 2019.06, B.Eng. in Software Engineering, Hubei University.
Y. Zhou, K. Zhao, X. Luo, and Y. Tang. "Smart Contract Vulnerability Detection Empowered by LLM: Can It Really Work?", Proceedings of the 8th IEEE International Conference on Blockchain and Cryptocurrency (ICBC), 2026. [Paper]
K. Zhao, Y. Tian, Z. Ma, and X. Luo. "Soleker: Uncovering Vulnerabilities in Solana Smart Contracts", Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2025. [Paper]
X. Peng, Z. Sun, K. Zhao, Z. Ma, Z. Li, J. Jiang, X. Luo, and Y. Zhang. "Automated Soundness and Completeness Vetting of Polygon zkEVM", Proceedings of the 34th USENIX Security Symposium (USENIX SEC), 2025. [Paper]
K. Zhao, Z. Li, W. Chen, X. Luo, T. Chen, G. Meng, and Y. Zhou. "Recasting Type Hints from WebAssembly Contracts", Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering (FSE), 2025. [Paper]
Y. Nong, R. Fang, G. Yi, K. Zhao, X. Luo, F. Chen, and H. Cai. "VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability Analyses", Proceedings of the 46th IEEE/ACM International Conference on Software Engineering (ICSE), 2024. [Paper]
G. Zhang, J. Liu, G. Zhou, K. Zhao, Z. Xie, and B. Huang. "Question-directed Reasoning with Relation-aware Graph Attention Network for Complex Question Answering over Knowledge Graph", IEEE/ACM Transactions on Audio, Speech, and Language Processing (TSALP), 2024. [Paper]
K. Zhao, Z. Li, J. Li, H. Ye, X. Luo, and T. Chen. "DeepInfer: Deep Type Inference from Smart Contract Bytecode", Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE), 2023. [Paper]
K. Zhao, Z. Xu, M. Yan, T. Zhang, L. Xue, M. Fan, and J. Keung. "The Impact of Class Imbalance Techniques on Crashing Fault Residence Prediction Models", Empirical Software Engineering (EMSE), 2023. [Paper]
J. Yu, X. Zhou, X. Liu, J. Liu, Z. Xie, and K. Zhao. "Detecting Multi-Type Self-Admitted Technical Debt with Generative Adversarial Network-based Neural Networks", Information and Software Technology (IST), 2023. [Paper]
K. Zhao, J. Liu, Z. Xu, X. Liu, L. Xue, Z. Xie, Y. Zhou, and X. Wang. "Graph4Web: A Relation-Aware Graph Attention Network for Web Service Classification", Journal of Systems and Software (JSS), 2022. Invited to SANER'2023 as part of the Journal First Track. [Paper]
J. Yu, K. Zhao, J. Liu, X. Liu, Z. Xu, and X. Wang. "Exploiting Gated Graph Neural Network for Detecting and Explaining Self-Admitted Technical Debts", Journal of Systems and Software (JSS), 2022. [Paper]
T. Cheng, K. Zhao, S. Sun, M. Mateen, and J. Wen. "Effort-Aware Cross-project Just-in-Time Defect Prediction Framework for Mobile Apps", Frontiers of Computer Science (FCS), 2022. [Paper]
Z. Xie, R. Zhu, K. Zhao, J. Liu, G. Zhou, and J. Huang. "Dual Gated Graph Attention Networks with Dynamic Iterative Training for Cross-Lingual Entity Alignment", ACM Transactions on Information Systems (TOIS), 2021. [Paper]
K. Zhao, J. Liu, Z. Xu, L. Li, M. Yan, J. Yu, and Y. Zhou. "Predicting Crash Fault Residence via Simplified Deep Forest Based on A Reduced Feature Set", Proceedings of the 29th IEEE/ACM International Conference on Program Comprehension (ICPC), 2021. [Paper]
K. Zhao, Z. Xu, M. Yan, L. Xue, W. Li, and G. Catolino. "A Compositional Model for Effort-Aware Just-In-Time Defect Prediction on Android Apps", IET Software (IETS), 2021. [Paper]
K. Zhao, Z. Xu, M. Yan, Y. Tang, M. Fan, and G. Catolino. "Just-in-Time Defect Prediction for Android Apps via Imbalanced Deep Learning Model", Proceedings of the 36th ACM/SIGAPP Symposium On Applied Computing (SAC), 2021. [Paper]
K. Zhao, Z. Xu, M. Yan, T. Zhang, D. Yang, and W. Li. "A Comprehensive Investigation of the Impact of Feature Selection Techniques on Crashing Fault Residence Prediction Models", Information and Software Technology (IST), 2021. [Paper]
Z. Xu, K. Zhao, T. Zhang, C. Fu, M. Yan, Z. Xie, X. Zhang, and G. Catolino. "Effort-Aware Just-in-Time Bug Prediction for Mobile Apps via Cross-triplet Deep Feature Embedding", IEEE Transactions on Reliability (TRel), 2021. [Paper]
K. Zhao, Z. Xu, T. Zhang, Y. Tang, and M. Yan. "Simplified Deep Forest Model based Just-In-Time Defect Prediction for Android Mobile Apps", IEEE Transactions on Reliability (TRel), 2021. [Paper]
Z. Xu#, K. Zhao# (equal contribution), M. Yan, P. Yuan, L. Xu, Y. Lei, and X. Zhang. "Imbalanced metric learning for crashing fault residence prediction", Journal of Systems and Software (JSS), 2020. Invited to ICPC'2021 as part of the Journal First Track. [Paper]
Z. Xie, R. Zhu, K. Zhao, J. Liu, G. Zhou, and J. Huang. "A Contextual Alignment Enhanced Cross Graph Attention Network for Cross-lingual Entity Alignment", Proceedings of the 28th International Conference on Computational Linguistics (COLING), 2020. [Paper]
COMP5355, Cyber and Internet Security, PolyU, Teaching Assistant, 2025 Summer, 2024 Fall, 2023 Fall.
COMP6521, Cryptography and Blockchain, PolyU, Teaching Assistant, 2024 Summer.
COMP5564, Machine Learning and Applications in Finance, PolyU, Teaching Assistant, 2023 Spring.
COMP5241, Software Engineering and Development, PolyU, Teaching Assistant, 2022 Fall.
2025, Distinguished Artifact Reviewers Award, The 32nd ACM Conference on Computer and Communications Security (CCS).
2024, Polkadot Blockchain Academy, Polkadot Foundation.
2023, Outstanding Scientific Paper of Hubei Province, Hubei Association for Science & Technology.
2023, Academic Grant for Blockchain Security Research, Ethereum Foundation.
2021, First Prize, Global MAX Performance Cloud Computing Innovation Competition (MAXP).
2021, Huawei Scholarship.
2020, First Prize, China Conference on Knowledge Graph and Semantic Computing (CCKS).
2018, Meritorious Winner, Mathematical Contest In Modeling / Interdisciplinary Contest In Modeling.
USENIX Security 2027, Program Committee
ICSE 2027, Shadow PC
APSEC 2026, Technical Track
ACM CCS 2026, Artifact Evaluation
IEEE S&P 2026, Artifact Evaluation
COMPSAC 2026, Program Committee
USENIX Security 2026, Artifact Evaluation
MSR 2026, Technical Papers
NDSS 2026, Artifact Evaluation
APSEC 2025, Technical Track
ACM CCS 2025, Artifact Evaluation
USENIX Security 2024, Artifact Evaluation
ACM CCS 2023, Artifact Evaluation
IEEE Transactions on Dependable and Secure Computing (TDSC)
The 30th SIGKDD Conference on Knowledge Discovery and Data Mining (KDD)
The 19th EAI International Conference on Security and Privacy in Communication Networks (SecureComm)
IEEE Transactions on Knowledge and Data Engineering (TKDE)
IEEE Transactions on Multimedia (TMM)
IEEE Transactions on Reliability (TRel)
IEEE Transactions on Network and Service Management (TNSM)
Journal of Information Security and Applications (JISA)
Information and Software Technology (IST)
Software: Practice and Experience (SPE)