About Me

Hi, I am Jiahao Liu (刘家豪), a security researcher at Ant Group. Previously, I earned a Ph.D. in Computer Science from the School of Computing at the National University of Singapore (NUS), advised by Prof. Zhenkai Liang. I received my B.E. in Computer Science from Chu Kochen Honors College at Zhejiang University (ZJU). I am also interested in finance, which I studied as a minor during my undergraduate years.

My research interests lie primarily in AI for security, where I design and adapt emerging machine learning techniques, such as large language models (LLMs) and graph neural networks, to tackle real-world challenges, including malware analysis, program analysis, and vulnerability assessment. More recently, I have been exploring the security of AI systems by studying security-relevant signals in LLMs and analyzing AI agents as layered software systems, with attention to risks in their components and interactions.

Selected Publications

(* Equal Contribution    # Corresponding Author)

[ISSTA 2026] Bridging WebAssembly Specs and Implementations through LLM-Enhanced Validation

Yeqi Fu, Kaihang Ji, Yuanpeng Wang, Zong Cao, Jiahao Liu, Ding Li, Yao Guo, Zhenkai Liang

ACM SIGSOFT International Symposium on Software Testing and Analysis

PDFCODE

[TOSEM 2026] Unraveling the Key of Machine Learning-based Android Malware Detection

Jiahao Liu, Jun Zeng, Fabio Pierazzi, Ziqi Yang, Lorenzo Cavallaro, Zhenkai Liang

Transactions on Software Engineering and Methodology

PDFCODE

[ICSE 2026] Towards Scalable and Interpretable Mobile App Risk Analysis via Large Language Models

Yu Yang, Zhenyuan Li, Xiandong Ran, Jiahao Liu, Jiahui Wang, Bo Yu, Shouling Ji

48th IEEE/ACM International Conference on Software Engineering

PDFSLIDES

[ACL 2026] Inverting the Shield: Systematically Generating Safety Tests from Policy Specifications

Xiaoyue Lu, Xianglin Yang, Haijun Liu, Jiahao Liu, Kuntai Cai, Yan Xiao, Jin Song Dong

64th Annual Meeting of the Association for Computational Linguistics, Main Conference

PDF

[ASE 2025] Propagation-Based Vulnerability Impact Assessment for Software Supply Chains

Bonan Ruan, Zhiwei Lin, Jiahao Liu#, Chuqi Zhang, Kaihang Ji, Zhenkai Liang

40th IEEE/ACM International Conference on Automated Software Engineering

PDFCODESLIDES

[Security 2025] Fuzzing the PHP Interpreter via Dataflow Fusion

Yuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu, Roland Yap, Zhenkai Liang, Manuel Rigger

34th Usenix Security Symposium

🏆 Distinguished Paper Award

PDFCODESLIDES

[NDSS 2025] UI-CTX: Understanding UI Behaviors with Code Contexts for Mobile Applications

Jiawei Li*, Jiahao Liu*, Jian Mao, Jun Zeng, Zhenkai Liang

32nd Network and Distributed System Security Symposium

PDFCODESLIDES

[NDSS 2025] ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance Graphs

Ziwen Liu, Jian Mao, Jun Zeng, Jiawei Li, Qixiao Lin, Jiahao Liu, Jianwei Zhuge, Zhenkai Liang

32nd Network and Distributed System Security Symposium

PDFSLIDES

[ASE 2024] MaskDroid: Robust Android Malware Detection with Masked Graph Representations

Jingnan Zheng*, Jiahao Liu*, An Zhang, Jun Zeng, Ziqi Yang, Zhenkai Liang, Tat-Seng Chua

39th IEEE/ACM International Conference on Automated Software Engineering

PDFCODESLIDES

[RAID 2024] KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities

Bonan Ruan, Jiahao Liu#, Chuqi Zhang, Zhenkai Liang

27th International Symposium on Research in Attacks, Intrusions and Defenses

🏆 Best Practical Paper Award🎯 Black Hat Asia 2025

PDFCODESLIDES

[ICSE 2024] Detecting Logic Bugs in Graph Database Management Systems via Injective and Surjective Graph Pattern Transformation

Yuancheng Jiang, Jiahao Liu, Jinsheng Ba, Roland YAP Hock Chuan, Zhenkai Liang, Manuel Rigger

46th IEEE/ACM International Conference on Software Engineering

PDFCODESLIDES

[ICSE 2023] Learning Graph-based Code Representations for Source-level Functional Similarity Detection

Jiahao Liu*, Jun Zeng*, Xiang Wang, Zhenkai Liang

45th IEEE/ACM International Conference on Software Engineering

PDFCODESLIDES

[S&P 2022] ShadeWatcher: Recommendation-guided Cyber Threat Analysis using System Audit Records

Jun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen, Zhenkai Liang, Tat-Seng Chua, Zheng Leong Chua

43rd IEEE Symposium on Security and Privacy

PDFCODESLIDES

[ISSTA 2022] TeLL: Log Level Suggestions via Modeling Multi-level Code Block Information

Jiahao Liu, Jun Zeng, Xiang Wang, Kaihang Ji, Zhenkai Liang

31st ACM International Symposium on Software Testing and Analysis

PDFCODESLIDES

Dataset & Benchmark

[EMNLP 2025] PsyScam: A Benchmark for Psychological Techniques in Real-World Scams

Shang Ma, Tianyi Ma, Jiahao Liu, Wei Song, Zhenkai Liang, Xusheng Xiao, Yanfang Ye

30th Empirical Methods in Natural Language Processing, Findings

PDFCODE

[ASE 2025] A Large-Scale Evolvable Dataset for Model Context Protocol Ecosystem and Security Analysis

Zhiwei Lin, Bonan Ruan, Jiahao Liu#, Weibo Zhao

40th IEEE/ACM International Conference on Automated Software Engineering, Tool

PDFCODE

[ASE 2024] VulZoo: A Comprehensive Vulnerability Intelligence Dataset

Bonan Ruan, Jiahao Liu#, Weibo Zhao, Zhenkai Liang

39th IEEE/ACM International Conference on Automated Software Engineering, Tool

PDFCODESLIDES

Awards

[07/2026] Award for Outstanding Overseas Study Elite, China

[08/2025] Distinguished Paper Award, USENIX Security 2025

[10/2024] Best Practical Paper Award, RAID 2024

[10/2023] Research Incentive Award, SoC, NUS

[01/2023] PhD Research Achievement Award, NUS

[08/2020] NUS Research Scholarship

[09/2019] Outstanding Student Scholarship, ZJU

[09/2018] Shu Ping Prize Scholarship

Invited Talks

[12/2025] Representing and Understanding Programs from Multiple Views for Security Analysis
  • Beihang University Vision Forum, Beijing, China
  • Nanjing University Chengyao Young Scholars Forum, Nanjing, China
[04/2025] Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
  • Black Hat Asia, Singapore
[02/2025] UI-CTX: Understanding UI Behaviors with Code Contexts for Mobile Applications
  • NDSS, San Diego, USA
[10/2024] MaskDroid: Robust Android Malware Detection with Masked Graph Representations
  • ASE, Sacramento, USA
[05/2023] Learning Graph-based Code Representations for Source-level Functional Similarity Detection
  • ICSE, Melbourne, Australia
[07/2022] TeLL: Log Level Suggestions via Modeling Multi-level Code Block Information
  • ISSTA, Virtually

Teaching Assistant

[12/2023 ~ 05/2024] Web Security (TIC4304)

[06/2022 ~ 12/2023] Computer Security (CS3235)

[12/2020 ~ 05/2021] Web Security (CS5331)

[07/2020 ~ 12/2020] Computer Security Practice (CS4238)