Zhengyu Liu
I am currently a third-year Ph.D. student in Computer Science at Johns Hopkins University, advised by Prof. Yinzhi Cao. Before joining JHU, I received my bachelor's degree in Cybersecurity from Sichuan University. During my undergrad, I was very fortunate to be advised by Prof. Cheng Huang.
My research interests broadly lie in Web Security, Software Security, and AI Security. I study emerging vulnerability classes and develop automated techniques, based on program analysis and LLMs, to detect and exploit them at scale across real-world systems.
Besides, I am a (retired) CTF pwn & web player. I led the team Z0D1AC (JHU academic team) and am a member of thehackerscrew (international team, Top 10 on CTFTime.org).
Email /
GitHub /
Blog /
CV /
Scholar /
LinkedIn
|
|
|
Research Directions
I put my research efforts under two complementary research directions:
Systematic Vulnerability Study.
I study new and overlooked vulnerability classes in widely used software, including web applications, browsers, language runtimes, and emerging AI-native systems.
My work uncovers how these vulnerabilities arise, how attackers turn them into practical exploits, how widespread they are, and how they can be mitigated.
Automated Security Analysis.
I design principled, reliable, and scalable techniques for automated vulnerability detection, validation, exploit generation, and mitigation. My recent efforts focus on integrating traditional program analysis with LLM-based reasoning for fully automated red teaming.
|
|
Publications
|
Minnie: Dynamic Privacy Leak Detection in WeChat Miniapps via Unified Shadow Memory
Jianjia Yu, Zhengyu Liu, Zhihan Xia, Penghui Li, Zifeng Kang, Junfeng Yang, and Yinzhi Cao
paper /
poster /
code /
slides /
To appear in the proceedings of the Network and Distributed System Security Symposium (NDSS), 2027.
|
Call Back Later: Studying and Detecting Reentrant Interpretation Vulnerability in Python Interpreters
Zhengyu Liu, Zhuohao Zhang, Yingfei Xu, Yu Sun, Jiacheng Zhong, Letao Zhao, Jianjia Yu, Ziyang Li, and Yinzhi Cao
paper /
poster /
code /
slides /
To appear in the proceedings of the IEEE Symposium on Security and Privacy (Oakland), 2027.
|
Comment and Control: Hijacking Agentic Workflows via Context-Grounded Evolution
Neil Fendley*, Zhengyu Liu*, Aonan Guan, Jiacheng Zhong, and Yinzhi Cao (*equal contribution)
paper /
poster /
code /
slides /
To appear in the proceedings of the ACM Conference on Computer and Communications Security (CCS), 2026.
■
Featured by: The Register, The Next Web, VentureBeat, SecurityWeek, Cybernews, Xataka, Security Boulevard, Techzine, CyberSecurity News, GBHackers, FreeBuf, SANS ISC Stormcast, CSA Labs, and other international outlets.
|
Poisoned by the Host: Large-Scale Measurement of Host Name Poisoning in Web Applications
Rui Yang, Haoyu Wang, Zhicheng Sun, Zhengyu Liu, and Yinzhi Cao
paper /
poster /
code /
slides /
To appear in the proceedings of IEEE Symposium on Security and Privacy (S&P Oakland), 2026
|
The First Large-Scale Systematic Study of Python Class Pollution Vulnerability
Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang, and Yinzhi Cao
paper /
poster /
code /
slides /
To appear in the proceedings of IEEE Symposium on Security and Privacy (S&P Oakland), 2026
■
Wiki page: https://class-pollution.github.io
|
The DOMino Effect: Detecting and Exploiting DOM Clobbering Gadgets via Concolic Execution with Symbolic DOM
Zhengyu Liu, Theo Lee, Jianjia Yu, Zifeng Kang, and Yinzhi Cao
paper /
poster /
code /
slides /
USENIX Security Symposium, 2025
■
Artifact Badges: Artifacts Available, Artifacts Functional, Results Reproduced
■
Honorable Mentions (6% among accepted papers)
|
Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World Websites
Zifeng Kang, Muxi Lyu, Zhengyu Liu, Jianjia Yu, Runqi Fan, Song Li, and Yinzhi Cao
paper /
poster /
code /
slides /
IEEE Symposium on Security and Privacy (S&P Oakland), 2025
■
Distinguished Paper Award
|
Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious Consequences
Zhengyu Liu, Kecheng An, and Yinzhi Cao
paper /
poster /
code /
slides /
IEEE Symposium on Security and Privacy (S&P Oakland), 2024
■
Nominee of Top 10 Web Hacking Techniques of 2024 by PortSwigger
|
A Framework for Threat Intelligence Extraction and Fusion
Yongyan Guo, Zhengyu Liu, Cheng Huang, Nannan Wang
paper /
poster /
code /
slides /
Computer & Security
|
Coreference Resolution for Cybersecurity Entity: Towards Explicit, Comprehensive Cybersecurity Knowledge Graph with Low Redundancy
Zhengyu Liu, Haochen Su, Nannan Wang, Cheng Huang
paper /
poster /
code /
slides /
EAI International Conference on Security and Privacy in Communication Networks (SecureComm), 2022
|
CyberRel: Joint Entity and Relation Extraction for Cybersecurity Concepts
Yongyan Guo, Zhengyu Liu, Cheng Huang, Jiayong Liu, Wangyuan Jing, Ziwang Wang, Yanghao Wang
paper /
poster /
code /
slides /
International Conference on Information and Communications Security (ICICS), 2022
■
Best Student Paper Award
|
A Sybil Detection Method in OSN based on DistilBERT and Double-SN-LSTM for text analysis
Xiaojie Xu, Jian Dong, Zhengyu Liu, Jin Yang, et al.
paper /
poster /
code /
slides /
EAI International Conference on Security and Privacy in Communication Networks (SecureComm), 2021
|
|
Talks
|
LaunchBreak: a Slip of Tea, a Click, a Full Multi-stage Desktop Takeover
Speaker, DEFCON 34, Las Vegas, Aug 2026
link /
slides /
video /
|
Get Set, Exploit! Unveiling Python Class Pollution In-the-Wild
Speaker, DEFCON 34, Las Vegas, Aug 2026
link /
slides /
video /
|
New and Overlooked Attack Surfaces: Detecting and Exploiting DOM Clobbering Gadgets
Speaker, RSAC 2026, San Francisio, March 2026
link /
slides /
video /
|
Not My Vibe: When Al Coding Agents Go Off the Rails
Speaker, BSidesSF 2026, San Francisco, March 2026
link /
slides /
video /
|
The DOMino Effect: Automated Detection and Exploitation of DOM Clobbering Vulnerability at Scale
Speaker, DEFCON 33, Las Vegas, Aug 2025
link /
slides /
video /
|
From Static to Smart: LLM-enhanced Static Analysis on Web Application Vulnerability Detection
Speaker, Ant Group SRC Annual Celebration, June 2025
link /
slides /
video /
|
Remote Server, Local Root. Welcome to MCP.
Contributor, BlackHat Asia 2026, Singapore, April 2026
link /
slides /
video /
|
|
Selected Honors & Awards
| Notable Artifact Reviewer, USENIX Security 2025 |
2025 Aug |
| Cybersecurity Elite Honor, School of Cyber Science and Engineering, Sichuan University |
2022 May |
| The 404 Scholarship, School of Cyber Science and Engineering, Sichuan University |
2022 Dec. |
| First Class Scholarship, School of Cyber Science and Engineering, Sichuan University |
2021 Sep. |
| Outstanding Student Honor, Sichuan University |
2020 & 2021 |
| Finalist (with Team 42-b3yond-6ug), DARPA AI Cyber Challenge (AIxCC) |
2024 Aug. |
| The 9th Place, 2021 ByteDance Security AI Competition, ByteDance(TikTok) |
2021 Nov. |
| The 2nd Place, School of Computing Summer Workshop, National University of Singapore |
2021 July |
| Excellent Thesis, Innovation and Entrepreneurship Training Program for College Students |
2020 Sep. |
| Third Prize (¥30,000), The 4th "Qiangwang Cup" National Cybersecurity Challenge |
2020 Sep. |
|
|
Professional Services
Program Committee
- ACM Asia Conference on Computer and Communications Security (ACM AsiaCCS '27)
- The Third International Workshop on Large Language Models for Code (LLM4Code '26, '27)
External Reviewer
- IEEE Symposium on Security and Privacy (S&P '25, '26)
- USENIX Security Symposium (Usenix '24, '25, '26)
- The ACM Conference on Computer and Communications Security (CCS '26)
- The Network and Distributed System Security (NDSS) Symposium (NDSS '27)
- European Conference on Computer Systems (EuroSys '26)
- Annual Computer Security Applications Conference (ACSAC '25, '26)
- Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb '25)
- Symposium on Research in Attacks, Intrusions, and Defenses (RAID '25, '26')
- IEEE Computer Security Foundations Symposium (CSF '24)
- Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA '24)
Artifact Evaluation Committee
- Network and Distributed System Security Symposium (NDSS '26)
- The ACM Conference on Computer and Communications Security (CCS '25, '26)
- USENIX Security Symposium (Usenix '25)
|
|
Experiences
| Security Research Intern, Siemens |
2025 June. - 2025 Dec. |
| Course Assistant, EN.445/645 Practical Cryptographic Systems (25 Spring), JHU |
2025 Feb. - 2025 May. |
| Course Assistant, EN.601.340/440/640 Web Security (23 Fall), JHU |
2023 Sep. - 2023 Dec. |
| Research Assistant, JHU, Advisor: Dr. Yinzhi Cao |
2023 June - 2023 Aug. |
| Research Assistant, Sichuan University, Advisor: Dr. Cheng Huang |
2020 Aug. - 2022 June |
|
|
Capture The Flags
Team member @ TheHackersCrew
Won 17 medals for the year of 2024, 7 Gold + 5 Silver + 5 Bronze
|
2023 Jan. - Now |
Co-lead @ The Group Z0D1AC
Achieved 2nd place RaymondJamesCTF 2024 ($5000 cash prize), 3rd place RaymondJamesCTF 2023 ($2500 cash prize), etc.
|
2022 Oct. - Now |
|
|
StarBugs
I’ve been finding and reporting vulnerabilities in widely used software, hoping to make it safer. I’m grateful to the maintainers and security teams who helped turn those reports into fixes.
-
Live Websites. XSS findings in
nvidia.com,
cnn.com,
hp.com,
intuit.com,
ibm.com,
okta.com,
nist.gov,
w3.org,
ubuntu.com,
espn.com,
forbes.com, and
theguardian.com.
Web cache deception findings that could lead to account takeover in
partner.ebay.com,
iqiyi.com,
f5.com,
asus.com, and
mediafire.com.
-
Critical Software. I have reported more than 100 memory-safety bugs across
CPython,
MicroPython, and
RustPython.
My CPython reports include
use-after-free,
type confusion, and
out-of-bounds access.
One of these findings was developed into a full
sandbox escape exploit
affecting ByteDance’s Coze.
-
OSS. I have found and reported vulnerabilities in open-source projects, resulting in more than 50 CVEs
(full list).
Selected projects include
WordPress Core
(XSS2Shell),
Anonymous GitHub
(XSS),
HackMD
(Stored XSS),
Jupyter Notebook/JupyterLab
(Stored XSS),
Hugging Face Transformers and
Smolagents
(Sandbox Escape),
Microsoft Azure CLI
(RCE), and
Webpack
(DOM Clobbering).
-
Acknowledgements and Bug Bounties. Google ($), Microsoft, Anthropic ($), GitHub ($), Snowflake ($), Meta ($), ByteDance ($), Vercel ($), Hugging Face ($), Xiaomi ($), iQIYI ($), and Ant Group ($).
|
|