Bofei Chen

About Me

I am a fourth-year Ph.D. student in Computer Science at Fudan University, advised by Prof. Min Yang, Prof. Yuan Zhang, and Prof. Lei Zhang.

My research focuses on vulnerability detection and exploitation, primarily in Java applications. I design and develop automated vulnerability detection techniques through static program analysis and dynamic fuzzing, while actively exploring synergistic approaches that integrate LLMs with traditional program analysis to enhance detection efficacy and scalability.

Before Fudan, I received my bachelor's degree at Xidian University in 2022.

Education

Johns Hopkins University · PhD Student (Visiting Scholar)
Maryland, USA · Oct 2025 - Present
  • Advisor: Prof. Yinzhi Cao
Fudan University · PhD Student
Shanghai, China · Sept 2022 - Present
  • Advisors: Prof. Min Yang, Prof. Yuan Zhang, Prof. Lei Zhang
Xidian University · Undergraduate
Xi'an, China · Sept 2018 - June 2022
  • Advisors: Prof. Hui Li, Prof. Weisheng Dong, Prof. Teng Li

Research Interests

  • Vulnerability Detection and Exploitation
  • LLM for Security
  • Supply Chain Security
  • Program Analysis

Publications

Bofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang, Mathias Payer, Yuan Zhang.
USENIX Security Symposium (USENIX Security)
Bofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao, Yuan Zhang, Min Yang.
Black Hat Asia
  • Top-scoring paper, officially selected as a reference example for Black Hat Asia 2026
Bofei Chen, Lei Zhang, Peng Deng, Nan Wang, Haoyu Xu, Mingda Guo, Yuan Zhang, Min Yang.
40th IEEE/ACM International Conference on Automated Software Engineering (ASE)
Haoran Zhao, Lei Zhang, Keke Lian, Fute Sun, Bofei Chen, Yongheng Liu, Zhiyu Wu, Yuan Zhang, Min Yang.
40th IEEE/ACM International Conference on Automated Software Engineering (ASE)
Bofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao, Yuan Zhang, Min Yang.
IEEE Symposium on Security and Privacy (Oakland) · GitHub stars

Competitions and Awards

  • National First Prize, 2nd "Huawei Cup" China Graduate Cybersecurity Innovation Competition (Challenge Track), 2023
  • Outstanding Graduate of Shaanxi Province (Ranked 1st at the School of Cyber and Information Security, Xidian University), 2022
  • 4th "Gratitude to Chinese Modern Scientists" Scholarship, 2022
  • National Scholarship, 2021
  • National First Prize, 14th National College Information Security Competition, 2020
  • Provincial First Prize, National College Mathematics Competition, 2019

Zero-day Vulnerabilities

I have discovered over 50 zero-day vulnerabilities affecting widely deployed open-source software (OSS) projects with more than 1K GitHub stars, as well as commercial products maintained by major organizations including Red Hat, Ant Group, and Weibo. A selective list of cases is provided below.

CVE Project Type
CVE-2023-29234 Apache Dubbo RCE
CVE-2025-48392 Apache MINA (Rank 2 in Network App Frameworks in Maven) RCE; CVSS 10.0
CVE-2024-52046 Apache iotdb DoS
CVE-2025-14238 jBPM (RedHat) RCE; Upstream of RedHat products; acknowledged as "high risky"
CVE-2024-7885 Undertow (RedHat) Message Leak
CVE-2024-7885 redisson (Redisson) RCE
CVE-2023-42271, CVE-2025-55770, ... Motan (Weibo) RCE; Security bounty awarded
CVE-2023-41331, CVE-2024-23636 Sofa-RPC (Antgroup) RCE
CVE-2024-46983 Sofa-bolt (Antgroup) RCE
... and 20+ more CVEs

Security Patches

Submitted 9 Pull Requests, 7 merged by project maintainers to fix security vulnerabilities:

  • CVE-2024-47552 (Apache Seata)
  • CVE-2024-7885 (Undertow)
  • And more...

Community Services

  • 2024: Reviewer for TOPS'24
  • 2024: Shadow Reviewer for CCS'24
  • 2023: Shadow Reviewer for IEEE S&P'23

Skills

Programming
JavaCPythonProgram Analysis
Languages
Mandarin (Native)English

Misc

  • I play the Chinese bamboo flute and was a member of the Xidian University Folk Music Ensemble during my undergraduate years.
  • I also have a strong appreciation for Chinese Folk Dance, finding rhythm and harmony beyond code and research.