I am an assistant professor in the computer science department at Seattle University. Before joining Seattle University, I completed my Ph.D. study at Colorado School of Mines with a research focus on web security and privacy. I am also very interested in Web3 and blockchain security, including smart contract and blockchain auditing, malicious transaction detection, etc. More recently my work centers on AI-assisted vulnerability detection: fine-tuning and evaluating large language models for smart contract auditing, and studying the gap between what AI auditors and human auditors actually find. Out of work and study, I am a baller. If you'd like, let's hoop together at SU or in Seattle.
Teaching: Programming for Data Science (CPSC 5070, new in Fall 2026), Artificial Intelligence and Cybersecurity (ARIN 5440, new in Winter 2027), Security in Computing (CPSC 4710/5710), Computer Networks (CPSC 4510/5510), Big Data Analytics (CPSC 5330), Programming & Problem Solving II (CPSC 1430)
Research: Web security and privacy, blockchain/Web3 security, AI-assisted vulnerability detection, LLMs for smart contract auditing
Advising: five undergraduate capstone teams (CPSC 4880/4890) and an MSCS project team (CPSC 5810/5820) since 2021; academic advisor to CS undergraduates since 2022
We propose WtaGraph, a web tracking and advertising detection framework based on Graph Neural Networks (GNNs).
We construct an attributed homogenous multi-graph (AHMG) that represents HTTP network traffic,
and formulate web tracking and advertising detection as a task of GNN-based edge representation learning and classification in AHMG.
Our proposed WtaGraph can detect tracking and advertising requests effectively and accurately.
This work was published at the IEEE Symposium on Security & Privacy in May 2022.
Our paper and source code are available.
Technologies we used in this project: Graph Neural Networks, Python, JavaScript
We proposed a two-step approach to secure the web application via JavaScript debloating and automated CSP deployment. Given a web application,
we first trim it at function level using our debloating framework, and then deploy CSP automatically on-the-fly via a web server reverse proxy.
Technologies we used in this project:JavaScript, Babel JavaScript Compiler, Apache Web Server, C++
In this project, we investigated the web tracking practices on both mobile and desktop environments.
we found that mobile web tracking has its unique characteristics, and it has become increasingly as prevalent as desktop web tracking.
We released our tool here and our paper can be found here.
Technologies we used in this project: Java, JavaScript, Browser Extension
Motion sensors can be exploited by attackers as side-channels to compromise users’ security and privacy due to the unrestricted sensor data access on modern smartphone platforms. In this project, we investigate motion sensor based user fingerprinting attacks. We formulate our user fingerprinting attacks as a typical multi-class classification problem and design a framework for performing the attacks.
Technologies we used in this project: Machine Learning, Java, JavaScript, PHP
To efficiently complete security assessment work of information system, we designed and developed this B/S platform to collaboratively work with our Information System Configuration Verification Tool. Assessment job is managed by this platform instead of by manual work before. Also, an assessment result can be generated electronically with this platform.
Technologies we used in this project: ASP.NET MVC, SQL Server, JavaScript
This HPPG project was designed and developed to drive a network interface card at full line rate, so that defenses and network equipment could be tested under realistic high-volume traffic. To minimize interrupts, we ran it as a kernel module and exclusively assigned a single processor to each HPPG thread. Experimental results show that using HPPG, a 1 Gigabit Ethernet card can send packets at 900 Mb/s.
Technologies we used in this project: C, Linux Kernel, Netfilter
To grab the opportunity of O2O(online to offline), our team designed and developed this B/S platform to establish connections between food restaurants around campus and students.
That is restaurants provide their food services online and students can order foods both with this platform. It not only increased restaurants' sales but saved students' time successfully.
We also applied for and gained computer software copyright from the Copyright Protection Center of China.
Technologies we used in this project: ASP.NET MVC, SQL Server, JavaScript
After Regulations on Protection of Computer Information System Security of China Promulgated, our team designed and developed this C/S tool to automatically check whether the configuration of target whole information system satisfied the requirement of that regulation. My duty was to design and develop submodules including Cisco firewall, Cisco router and Windows 7.
Technologies we used in this project: ASP.NET WPF, GNS3, SQLite
Invited by Bank of Weifang, we launched a comprehensive security assessment on system configuration for Bank of Weifang. Such an assessment including Operating System, Database, Firewall, Router, Application and Physical security assessment. My duty was to check the security configurations on Firewall and Router.
Under the supervision of Dr. Chuan Yue, my research focused on: 1) web, mobile, and cloud systems security, 2) usable security and privacy, 3) vulnerability measurement and analysis. My dissertation was titled "Understanding and protecting user security and privacy on the web".
Under the supervision of Dr. Haipeng Qu, my research focused on cyber security. I received my Master degree with a graduate thesis titled "Research on Networking Troubleshooting Method Based on Software Defined Network", in which I proposed a new method for troubleshooting in SDN.
Selected first-author publications.