👩🏻🎓 About Me
I am a Ph.D. candidate at the College of Computer Science and Artificial Intelligence, Fudan University, advised by Prof. Min Yang, Prof. Yuan Zhang and Prof. Lei Zhang. I was also a visiting Ph.D. student at Johns Hopkins University, advised by Prof. Yinzhi Cao.
My research is on vulnerability governance for open-source software, covering the full lifecycle: discovery, exploitation and verification, and patching. Methodologically, I combine static/dynamic program analysis with large language models — program analysis enumerates and prunes the candidate search space, the model performs semantic reasoning and code synthesis within that constrained space, and every result is confirmed by real execution.
Before Fudan, I received my B.Eng. from Xidian University in 2022.
🎓 Education
- Fudan University, Ph.D. in Cyberspace Security, Sep 2022 – Present
- Advisors: Prof. Min Yang, Prof. Yuan Zhang, Prof. Lei Zhang
- Johns Hopkins University, Visiting Ph.D. Student, Oct 2025 – Aug 2026
- Advisor: Prof. Yinzhi Cao
- Xidian University, B.Eng. in Cyberspace Security, Sep 2018 – Jun 2022
🔍 Research Interests
- Vulnerability Detection and Exploitation
- LLM for Security
- Software Supply Chain Security
- Program Analysis
📄 Publications
Speak Your Dialect: Detecting Java Object Injection Gadget Chains in Third-party (De)serialization Frameworks.
Bofei Chen, Lei Zhang, Haoran Zhao, Min Yang, Yinzhi Cao.
To appear in the Proceedings of the IEEE Symposium on Security and Privacy (IEEE S&P), 2027. (Acceptance rate: 15.8%)Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack-Defense Cross-Analysis.
Bofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang, Mathias Payer, Yuan Zhang.
In Proceedings of the 35th USENIX Security Symposium, 2026. (Acceptance rate: 14.0%)Efficient Detection of Java Deserialization Gadget Chains via Bottom-up Gadget Search and Dataflow-aided Payload Construction. [Paper] [Code]
Bofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao, Yuan Zhang, Min Yang.
In Proceedings of the 45th IEEE Symposium on Security and Privacy (IEEE S&P), 2024. (Acceptance rate: 14.9%)JDD: In-depth Mining of Java Deserialization Gadget Chains via Bottom-up Gadget Search and Dataflow-aided Payload Construction. [Briefing]
Bofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao, Yuan Zhang, Min Yang.
Black Hat Asia, 2025. (Top-scoring submission; officially selected as a reference example for Black Hat 2026)LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correction. [Paper]
Bofei Chen, Lei Zhang, Peng Deng, Nan Wang, Haoyu Xu, Mingda Guo, Yuan Zhang, Min Yang.
In Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2025.Exploring Static Taint Analysis in LLMs: A Dynamic Benchmarking Framework for Measurement and Enhancement. [Paper]
Haoran Zhao, Lei Zhang, Keke Lian, Fute Sun, Bofei Chen, Yongheng Liu, Zhiyu Wu, Yuan Zhang, Min Yang.
In Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2025.AgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber Ranges. [Paper]
Fengyu Liu, Jiarun Dai, Yihe Fan, Wuyuao Mai, Ziao Li, Bofei Chen, et al.
arXiv preprint, 2026.
🛡️ Zero-day Vulnerabilities
I have discovered over 100 zero-day vulnerabilities in widely deployed open-source projects (1K+ GitHub stars) and in commercial products maintained by organizations including the Apache Software Foundation, Red Hat, Spring, Ant Group and Weibo. A selected list:
| CVE | Project | Type |
|---|---|---|
| CVE-2024-52046 | Apache MINA (Rank 2 in Network App Frameworks on Maven) | RCE; CVSS 10.0 |
| CVE-2023-29234 | Apache Dubbo | RCE; CVSS 9.8 |
| CVE-2025-14238 | jBPM (Red Hat) | RCE; upstream of Red Hat products; acknowledged as high risk |
| CVE-2024-7885 | Undertow (Red Hat) | Information Leak; CVSS 7.5 |
| CVE-2026-57611 | Apache Commons JEXL, Apache Hive | RCE |
| CVE-2026-41856 | Spring for GraphQL | Authorization Bypass; CVSS 7.5 |
| CVE-2026-40967 | Spring AI | Expression Injection; CVSS 8.6 |
| CVE-2024-46983 | SOFABolt (Ant Group) | RCE |
| CVE-2023-41331, CVE-2024-23636 | SOFARPC (Ant Group) | RCE |
🏅 Honors and Awards
- 2025: First-Class Academic Scholarship for Doctoral Students, Fudan University
- 2024: Outstanding Doctoral Candidate Scholarship, Fudan University
- 2023 & 2024: Academic Scholarship for Doctoral Students, Fudan University
- 2023: National First Prize, 2nd “Huawei Cup” China Graduate Cybersecurity Innovation Competition (Challenge Track)
- 2022: Outstanding Graduate of Shaanxi Province (ranked 1st at the School of Cyber Engineering, Xidian University)
- 2022: 4th “Gratitude to Modern Chinese Scientists” Scholarship
- 2021: National Scholarship
- 2020: National First Prize, 14th National College Information Security Contest
- 2019: Provincial First Prize, National College Mathematics Competition
🎤 Academic Services
- Reviewer: ACM TOPS 2024
- Shadow Reviewer: ACM CCS 2024, IEEE S&P 2023
🎋 Misc
I play the Chinese bamboo flute and was a member of the Xidian University Folk Music Ensemble during my undergraduate years. I also enjoy Chinese folk dance.
