Ph.D. candidate at Tianjin University
Web Security, Cyber Attack & Defense, Vulnerability Discovery, LLM Application Security
CTFer
Member of TJUNSL and D.I.E.
I have a strong interest in web security and real-world attack and defense. I earned my Master’s degree from Tianjin University, where I also continued my PhD studies. At JAIST, I conducted research on privacy protection. In addition to my academic work, I actively participate in CTF competitions and have conducted authorized penetration testing on various websites and applications to identify vulnerabilities and earn the bounty.
Wang, W., Dong, M., Li, J., Zhang, Y., Liu, H., Hu, Q., ... & Wu, B. (2026). Domain Decoupling Attack: Exploiting the Validation Gap Between Protective DNS and Shared Edge Routing. arXiv preprint arXiv:2608.00643.
Liu, Y., Wang, W., Feng, R., Zhang, Y., Xu, G., Deng, G., ... & Zhang, L. (2026). Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale. arXiv preprint arXiv:2601.10338.
Wang, W., Guo, Z., Yan, Q., Yang, Z., Zhang, Y., Xu, G., ... & Wu, B. (2026). Enhanced Web Testing with LLMs: A Research Roadmap. ACM Transactions on Software Engineering and Methodology.
Wang, W., Ma, W., Hu, Q., Zhang, Y., Sun, J., Wu, B., ... & Jiang, L. (2025). VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities. arXiv preprint arXiv:2509.03331.Wang, W., Ma, W., Hu, Q., Zhang, Y., Sun, J., Wu, B., ... & Jiang, L. (2025). VulnRepairEval: An Exploit-Based Evaluation Framework for Assessing Large Language Model Vulnerability Repair Capabilities. arXiv preprint arXiv:2509.03331.
Wang, W., Zhang, Y., Liang, K., Xu, G., Bai, H., Yan, Q., ... & Wu, B. (2025). Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications. arXiv preprint arXiv:2504.20801.
Xu, G., Lei, W., Gong, L., Liu, J., Bai, H., Chen, K., ... & Liu, S. (2022). UAF-GUARD: Defending the Use-After-Free Exploits via Fine-grained Memory Permission Management. Computers & Security, 103048.
Nie, P., Xu, G., Jiao, L., Liu, S., Liu, J., Meng, W., ... & Zheng, X. (2021). Sparse Trust Data Mining. IEEE Transactions on Information Forensics and Security, 16, 4559-4573.
Xu, G., Li, X., Jiao, L., Wang, W., Liu, A., Su, C., ... & Cheng, X. (2020). BAGKD: A Batch Authentication and Group Key Distribution Protocol for VANETs. IEEE Communications Magazine, 58(7), 35-41.
Xu, G., Wang, W., Jiao, L., Li, X., Liang, K., Zheng, X., ... & Gao, H. (2019). SoProtector: Safeguard privacy for native SO files in evolving mobile IoT applications. IEEE Internet of Things Journal, 7(4), 2539-2552.