Bofei Chen
About Me
I am a fourth-year Ph.D. student in Computer Science at Fudan University, advised by Prof. Min Yang, Prof. Yuan Zhang, and Prof. Lei Zhang.
My research focuses on vulnerability detection and exploitation, primarily in Java applications. I design and develop automated vulnerability detection techniques through static program analysis and dynamic fuzzing, while actively exploring synergistic approaches that integrate LLMs with traditional program analysis to enhance detection efficacy and scalability.
Before Fudan, I received my bachelor's degree at Xidian University in 2022.
Education
- Advisor: Prof. Yinzhi Cao
- Advisors: Prof. Min Yang, Prof. Yuan Zhang, Prof. Lei Zhang
- Advisors: Prof. Hui Li, Prof. Weisheng Dong, Prof. Teng Li
Research Interests
- Vulnerability Detection and Exploitation
- LLM for Security
- Supply Chain Security
- Program Analysis
Publications
- Top-scoring paper, officially selected as a reference example for Black Hat Asia 2026
Competitions and Awards
- National First Prize, 2nd "Huawei Cup" China Graduate Cybersecurity Innovation Competition (Challenge Track), 2023
- Outstanding Graduate of Shaanxi Province (Ranked 1st at the School of Cyber and Information Security, Xidian University), 2022
- 4th "Gratitude to Chinese Modern Scientists" Scholarship, 2022
- National Scholarship, 2021
- National First Prize, 14th National College Information Security Competition, 2020
- Provincial First Prize, National College Mathematics Competition, 2019
Zero-day Vulnerabilities
I have discovered over 50 zero-day vulnerabilities affecting widely deployed open-source software (OSS) projects with more than 1K GitHub stars, as well as commercial products maintained by major organizations including Red Hat, Ant Group, and Weibo. A selective list of cases is provided below.
| CVE | Project | Type |
|---|---|---|
| CVE-2023-29234 | Apache Dubbo | RCE |
| CVE-2025-48392 | Apache MINA (Rank 2 in Network App Frameworks in Maven) | RCE; CVSS 10.0 |
| CVE-2024-52046 | Apache iotdb | DoS |
| CVE-2025-14238 | jBPM (RedHat) | RCE; Upstream of RedHat products; acknowledged as "high risky" |
| CVE-2024-7885 | Undertow (RedHat) | Message Leak |
| CVE-2024-7885 | redisson (Redisson) | RCE |
| CVE-2023-42271, CVE-2025-55770, ... | Motan (Weibo) | RCE; Security bounty awarded |
| CVE-2023-41331, CVE-2024-23636 | Sofa-RPC (Antgroup) | RCE |
| CVE-2024-46983 | Sofa-bolt (Antgroup) | RCE |
| ... and 20+ more CVEs | ||
Security Patches
Submitted 9 Pull Requests, 7 merged by project maintainers to fix security vulnerabilities:
- CVE-2024-47552 (Apache Seata)
- CVE-2024-7885 (Undertow)
- And more...
Community Services
- 2024: Reviewer for TOPS'24
- 2024: Shadow Reviewer for CCS'24
- 2023: Shadow Reviewer for IEEE S&P'23
Skills
Misc
- I play the Chinese bamboo flute and was a member of the Xidian University Folk Music Ensemble during my undergraduate years.
- I also have a strong appreciation for Chinese Folk Dance, finding rhythm and harmony beyond code and research.