News
Courses
Projects
100 Hypervisor Security SoK
Engineering · Master's capstone · Hiring for 2026-2027This master's capstone project studies hypervisors from three connected angles: hypervisors used as security mechanisms, the security of hypervisors themselves, and the risks introduced by insecure hypervisor designs or deployments. The project aims to build a systematic knowledge base that clarifies threat models, isolation assumptions, vulnerability classes, measurement methods, and open research problems across commodity, cloud, embedded, and security-oriented virtualization systems.
103 Building a Recursive Self-Improvement Workflow for POC Generation
Engineering · Master's capstone · Hiring for 2026-2027This master's engineering project builds a recursive self-improvement workflow for proof-of-concept generation. Based on Magma, ground-truth bug benchmarks, and a workflow DSL, the project designs and evaluates an agentic pipeline that can generate POCs, execute them against known vulnerable targets, diagnose failures, revise its workflow, and accumulate reusable strategies over time. The goal is to turn benchmark-backed POC generation into a measurable engineering loop for studying how LLM-based security agents improve through execution feedback.
203 Defense in Depth for Sandboxes
Research · PhD project · Hiring for 2026-2027This PhD research project studies defense-in-depth architectures for process-based and VM-based sandboxes. The project investigates how sandbox escapes and policy bypasses emerge across system-call interfaces, shared resources, runtime services, and hardware boundaries, then develops layered defenses that combine behavioral monitoring at security-relevant interfaces, exploit prevention, and compartmentalization. It further explores techniques such as pattern matching, hardware-assisted enforcement, and hardware-software co-design to make sandboxed execution more resilient against both known attack patterns and previously unseen exploitation strategies.
Tools
Consultation
We welcome inquiries about system security, software security, security research, and related engineering work. Please describe your question, context, and expected outcome when contacting us.
Research Direction Planning
1 hourBooking: contact usPaper Writing Guidance
1 hour, multiple sessionsBooking: contact usQiang Liu
Principal Investigator
System Security · AI Agents · Meta-science
SoK: Taxonomizing the Low-Level Attack Surface of Modern Web Browsers
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
REFLECTA: Reflection-based Scalable and Semantic Scripting Language Fuzzing
Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization Interface
Tango: Extracting Higher-Order Feedback through State Inference
EspialCog: General, Efficient and Robust Mobile User Implicit Authentication in Noisy Environment
ECMO: Peripheral Transplantation to Rehost Embedded Linux Kernels
One Cycle Attack: Fool Sensor-Based Personal Gait Authentication With Clustering
100 Hypervisor Security SoK
Engineering · Master's capstone · Hiring for 2026-2027This master's capstone project studies hypervisors from three connected angles: hypervisors used as security mechanisms, the security of hypervisors themselves, and the risks introduced by insecure hypervisor designs or deployments. The project aims to build a systematic knowledge base that clarifies threat models, isolation assumptions, vulnerability classes, measurement methods, and open research problems across commodity, cloud, embedded, and security-oriented virtualization systems.
103 Building a Recursive Self-Improvement Workflow for POC Generation
Engineering · Master's capstone · Hiring for 2026-2027This master's engineering project builds a recursive self-improvement workflow for proof-of-concept generation. Based on Magma, ground-truth bug benchmarks, and a workflow DSL, the project designs and evaluates an agentic pipeline that can generate POCs, execute them against known vulnerable targets, diagnose failures, revise its workflow, and accumulate reusable strategies over time. The goal is to turn benchmark-backed POC generation into a measurable engineering loop for studying how LLM-based security agents improve through execution feedback.
203 Defense in Depth for Sandboxes
Research · PhD project · Hiring for 2026-2027This PhD research project studies defense-in-depth architectures for process-based and VM-based sandboxes. The project investigates how sandbox escapes and policy bypasses emerge across system-call interfaces, shared resources, runtime services, and hardware boundaries, then develops layered defenses that combine behavioral monitoring at security-relevant interfaces, exploit prevention, and compartmentalization. It further explores techniques such as pattern matching, hardware-assisted enforcement, and hardware-software co-design to make sandboxed execution more resilient against both known attack patterns and previously unseen exploitation strategies.
firmguide GitHub
FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel Execution
HyperPill GitHub
TBD
ViDeZZo GitHub
ViDeZZo source code.
computing-genealogy-project GitHub
Explore computer science academic genealogy: PhD advisors, students, institutions, and lineage networks.
We welcome inquiries about system security, software security, security research, and related engineering work. Please describe your question, context, and expected outcome when contacting us.
Research Direction Planning
1 hourPaper Writing Guidance
1 hour, multiple sessionsWe welcome different forms of sponsorship, including gifts, research grants, equipment donations, cloud and infrastructure credits, and support for student projects and open-source development. Sponsorship helps improve student support, build durable security research infrastructure, and keep our work and artifacts open to the community. Sponsors receive transparent updates on how funds are used and, with their permission, are acknowledged by name on our homepage.