Puzhuo Liu

Puzhuo Liu

刘圃卓
Assistant Researcher

Ant Group & Tsinghua University

Biography

My research centers on Quality and Security assurance for Cyber-Physical Systems and Intelligent Systems. I study how to improve the trustworthiness of complex systems that involve interconnected networks, autonomous decision-making, and intelligent collaborative devices. My technical interests include taint analysis, fuzzing, emulation/simulation, formal verification, and AI-assisted software testing and verification, with applications to both conventional software/firmware and emerging AI/agentic systems.

If my research aligns with your interests, please don’t hesitate to reach out to me via email. I would be delighted to explore potential collaboration opportunities.

Research Interests: QS for Cyber-Physical & Intelligent Systems

Recruiting research interns: LLM/Agent for Software Engineering/Programming Languages/System Security and Safety for LLM/Agent.

News

Our paper “MemPoison Bypassing Selective Memory Mechanisms to Plant Backdoors in LLM Agents” was accepted by CCS 2026!
Honored to join the Security PC this year! If you have cool security research, please submit! August 11–13, 2027, Denver, CO, USA.
Our paper “MCPXkit:The Unified Toolkit for Analyzing Model Context Protocol Security” was accepted by TDSC!
Submit your work to the 2nd EXPRESS Workshop@SPLASH-ISSTA 2026 — we welcome your participation!!
Our paper “Bond:Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT Firmware” was accepted by Usenix Sec'26!

Work Experience

 
 
 
 
 
Researcher
Ang Group
September 2024 – Present China
 
 
 
 
 
Assistant Researcher (Postdoc)
Tsinghua University
September 2024 – Present China

Education Experience

 
 
 
 
 
PhD in Cyberspace Security
September 2018 – July 2024 China
 
 
 
 
 
Visiting PhD
September 2022 – August 2023 Canada
 
 
 
 
 
B.Eng in Communication Engineering
September 2014 – July 2018 China

Vulnerabilitits

Discovered more than 1,000+ quality issues and security vulnerabilities across devices from major vendors, including Cisco, Siemens, D-Link, NETGEAR, Tenda, and Motorola, and actively assisted the vendors in developing and implementing fixes. These security research contributions have resulted in over 300+ acknowledgments and vulnerability identifiers from vendors and organizations, including CVE, CNVD, and PSV. Notable findings include:

  • CVE-2020-25242: A high-severity vulnerability (DoS) that had remained undetected in Siemens PLC devices for more than a decade.
  • CVE-2022-20825: A critical vulnerability (RCE) affecting multiple Cisco devices, with the maximum CVSS v2.0 score of 10.0.

    Services

    • Committee:
      • 2027:
        • PC: Security
        • AEC: NDSS
      • 2026:
        • OC: EXPRESS@ISSTA
        • PC: LLM4Sec@ESORICS
        • Shadow PC: EuroSys, ICSE
        • AEC: NDSS, S&P, Securiy, CCS
      • 2025:
        • PC: EXPRESS@ISSTA, LLM4Sec@ICDM, ISPA
        • AEC: CCS
        • Session Chair: EXPRESS@ISSTA, LMPL@SPLASH
    • Journal Reviewer:
      • CyberSecurity
      • Journal of Systems Architecture
      • IEEE Transactions on Software Engineering
      • Computer & Security
      • The Journal of Supercomputing
      • ACM Transactions on Software Engineering and Methodology

      Honors & Awards

      • 2024 AntStar of Ant Group
      • 2024 Outstanding Graduates of Beijing
      • 2024 Outstanding Graduates of University of Chinese Academy of Sciences
      • 2024 Outstanding Graduates of Institute of Information Engineering, CAS
      • 2023 National Scholarship
      • 2023 Special Scholarship of Institute of Information Engineering, CAS
      • 2023 Merit Student Representative of University of Chinese Academy of Sciences
      • 2022 DataCon IoT Security Track Third Prize
      • 2021 DataCon Email Security Track Runner-up Prize
      • 2018-2023 University of Chinese Academy of Sciences Scholarships
      • 2014-2018 Jilin University Scholarships