I earned my PhD from Nanyang Technological University (NTU) under the supervision of Prof. Liu Yang. My research focuses on large language models, cybersecurity, and software engineering, with applications spanning the medical, automotive, and fintech industries.
Email: z.xu [AT] ic.ac.uk
Google Scholar: Here
The web portal for LLM-powered Software Composition Analysis (SCA) is now available at: http://bsca.yukimura.moe/
A tool for AI-assisted academic paper writing is currently under development and can be previewed at: http://xept.online:99/projects
We are developing an LLM-based stock trading advisory platform that aggregates and summarizes expert traders’ insights.
Oct 2025: Our paper "Semantic-Enhanced Automatic Refinement of Architecture Recovery Results Using LLMs" has been accepted by ICSE 2026.
Oct 2025: Our paper "IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Packages from Cyber Intelligence" has been accepted by ICSE 2026.
Sep 2025: Our paper "BinStruct: Binary Structure Recovery Combining Static Analysis and Semantics" has been accepted by ASE 2025.
Sep 2025: Our paper "Learning from the Past: Real-World Exploit Migration for Smart Contract PoC Generation" has been accepted by ASE 2025.
Sep 2025: Our paper "FAULTSEEKER: LLM-Empowered Framework for Blockchain Transaction Fault Localization" has been accepted by ASE 2025.
Sep 2025: Our paper "A Large-Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners" has been accepted by ASE 2025.
Aug 2025: Our paper "Evolving Paradigms in Automated Program Repair: Taxonomy, Challenges, and Opportunities" has been accepted by ACM Computing Surveys (CSUR).
Aug 2025: Our work "Let LLM Learn: When Your Static Analyzer Actually 'Gets It'" was presented at Black Hat USA 2025, Oceanside C, Level 2, covering AI, ML, & Data Science and Application Security: Offense.
Aug 2025: Our paper "Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis" has been accepted by FSE, Ideas, Visions and Reflections.
Aug 2025: Our paper "Doctor: Optimizing Container Rebuild Efficiency by Instruction Re-Orchestration" has been accepted by ISSTA 2025
Jul 2025: I delivered a talk titled "Towards Expert-Level Binary SCA Using Multi-Agent AI Systems" at the "Pushing the Boundaries of AI and Human Intelligence for Cybersecurity" workshop, organized by NTU's CyberSG R&D Programme Office.
Apr 2025: I participated in a Fireside Chat "Detecting Malicious AI: Tackling Social Engineering and Deepfakes" at Black Hat Asia 2025, Marina Bay Sands, Singapore.
Nov 2024: We're excited to host a talk on software analysis by Professor Cristian Cadar from the Department of Computing at Imperial College London, taking place on November 28th/29th.
Jul 2024: Our paper "DeLink: Source File Information Recovery in Binaries" has been accepted by ISSTA 2024.
Jul 2024: Our paper "A Hitchhiker’s Guide to Jailbreaking ChatGPT via Prompt Engineering" has been accepted by SEA4DQ 2024.
Jun 2024: We organized a workshop for medical device security with NTU and Synapxe.
Jun 2024: I join Imperial College London / Imperial Global Singapore as a senior research fellow working on medical device security.
Apr 2024: Our paper "Enhancing Function Name Prediction using Votes-Based Name Tokenization and Multi-task Learning" has been accepted by FSE 2024.
Feb 2024: Our journal "An empirical study of attack-related events in DeFi projects development" has been accepted by Empirical Software Engineering.
Dec 2023: Our paper "GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis. " has been accepted by ICSE 2024.
Dec 2023: Our paper "ModuleGuard: Understanding and Detecting Module Conflicts in Python Ecosystem." has been accepted by ICSE 2024.