We are developing an LLM-based platform that aggregates and summarizes expert traders' insights for stock trading decisions.
We are developing an end-to-end automated scientific research platform powered by LLM agents, from problem discovery to manuscript generation.
We are developing an agent-native world where every person and institution has a personal agent that interacts with other agents on their behalf.
Jul 2026: Our paper "How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study" has been accepted by ASE 2026.
Jun 2026: Our paper "From Similarity Ranking to Definitive Verdict: LLM-Enhanced Source-to-Binary Function Localization" has been accepted by OOPSLA 2026.
Apr 2026: Our paper "Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ Binaries" has been accepted by ISSTA 2026.
Mar 2026: Our paper "Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at Scale" has been accepted by FSE 2026.
Feb 2026: Our paper "Reframing Paths as Logic: Semantic Segmentation for Vulnerability Detection" has been accepted by OOPSLA 2026.
Jan 2026: Our paper "Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages" has been accepted by WWW 2026.
Dec 2025: Our paper "Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework" has been accepted by USENIX SECURITY 2026.
Oct 2025: Our paper "Semantic-Enhanced Automatic Refinement of Architecture Recovery Results Using LLMs" has been accepted by ICSE 2026.
Oct 2025: Our paper "IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Packages from Cyber Intelligence" has been accepted by ICSE 2026.
Sep 2025: Our paper "BinStruct: Binary Structure Recovery Combining Static Analysis and Semantics" has been accepted by ASE 2025.
Sep 2025: Our paper "Learning from the Past: Real-World Exploit Migration for Smart Contract PoC Generation" has been accepted by ASE 2025.
Sep 2025: Our paper "FAULTSEEKER: LLM-Empowered Framework for Blockchain Transaction Fault Localization" has been accepted by ASE 2025.
Sep 2025: Our paper "A Large-Scale Study of AI-based Binary Function Similarity Detection Techniques for Security Researchers and Practitioners" has been accepted by ASE 2025.
Aug 2025: Our paper "Evolving Paradigms in Automated Program Repair: Taxonomy, Challenges, and Opportunities" has been accepted by ACM Computing Surveys (CSUR).
Aug 2025: Our work "Let LLM Learn: When Your Static Analyzer Actually 'Gets It'" was presented at Black Hat USA 2025, Oceanside C, Level 2, covering AI, ML, & Data Science and Application Security: Offense.
Aug 2025: Our paper "Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis" has been accepted by FSE, Ideas, Visions and Reflections.
Aug 2025: Our paper "Doctor: Optimizing Container Rebuild Efficiency by Instruction Re-Orchestration" has been accepted by ISSTA 2025
Jul 2025: I delivered a talk titled "Towards Expert-Level Binary SCA Using Multi-Agent AI Systems" at the "Pushing the Boundaries of AI and Human Intelligence for Cybersecurity" workshop, organized by NTU's CyberSG R&D Programme Office.
Apr 2025: I participated in a Fireside Chat "Detecting Malicious AI: Tackling Social Engineering and Deepfakes" at Black Hat Asia 2025, Marina Bay Sands, Singapore.
Nov 2024: We're excited to host a talk on software analysis by Professor Cristian Cadar from the Department of Computing at Imperial College London, taking place on November 28th/29th.
Jul 2024: Our paper "DeLink: Source File Information Recovery in Binaries" has been accepted by ISSTA 2024.
Jul 2024: Our paper "A Hitchhiker’s Guide to Jailbreaking ChatGPT via Prompt Engineering" has been accepted by SEA4DQ 2024.
Jun 2024: We organized a workshop for medical device security with NTU and Synapxe.
Jun 2024: I join Imperial College London / Imperial Global Singapore as a senior research fellow working on medical device security.
Apr 2024: Our paper "Enhancing Function Name Prediction using Votes-Based Name Tokenization and Multi-task Learning" has been accepted by FSE 2024.
Feb 2024: Our journal "An empirical study of attack-related events in DeFi projects development" has been accepted by Empirical Software Engineering.
Dec 2023: Our paper "GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis. " has been accepted by ICSE 2024.
Dec 2023: Our paper "ModuleGuard: Understanding and Detecting Module Conflicts in Python Ecosystem." has been accepted by ICSE 2024.