基本信息
程凯 男 硕导 中国科学院信息工程研究所
电子邮件: chengkai@iie.ac.cn
通信地址: 北京市海淀区树村路 19 号
邮政编码: 100085
电子邮件: chengkai@iie.ac.cn
通信地址: 北京市海淀区树村路 19 号
邮政编码: 100085
研究领域
主要研究方向是二进制软件漏洞挖掘、软件供应链安全、大模型赋能安全研究等。作为骨干人员参与国家重点研发计划、国家重大专项等多项国家级课题,在S&P、USENIX、ISSTA、DSN、ACSAC等会议发表学术论文15余篇,在主流嵌入式设备自动发现0day漏洞400余个,获得CVE编号300余项。
招生信息
长期招收硕士研究生,实习生,从事二进制漏洞挖掘、软件供应链安全、大模型赋能安全的研究。
招生专业
083900-网络空间安全
招生方向
二进制安全,供应链安全,智能攻防
工作经历
工作简历
2025-02~现在, 中国科学院信息工程研究所, 副研究员2023-09~2025-02,腾讯科技(深圳)有限公司, 程序分析高级工程师2021-07~2023-08,深信服科技股份有限公司, 安全技术专家
出版信息
- [S&P 2026] Jiaqian Peng, Puzhuo Liu*, Yicheng Zeng, Kai Cheng*, Yongji Liu, Yun Yang, Hongsong Zhu. Bridge: High-Order Taint Vulnerabilities Detection in Linux-based IoT Firmware (CCF A).
- [Usenix Security 2026] Jiaqian Peng, Puzhuo Liu*, Kai Cheng*, Zhaoteng Yan, Jie Liu, Chennian Sun, Hongsong Zhu. Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT Firmware (CCF A).
- [ICPC 2026] Wenyan Yu, Lei Cui, Jiayuan Li, Yubo Li, Hong Li, Kai Cheng, Hongsong Zhu. Modubin: A Binary Modularization Approach Based on the Locality of Homologous Functions (CCF B).
- [CSCWD 2026] Nuo Cheng, Kai Cheng, Siyuan Li, Jingdong Guo, Jinwei Dong and Hong Li. BackdoorCraft: Evaluating LLM-Assisted Backdoor Construction in Embedded Linux Firmware.
- [ISSTA 2023] Kai Cheng, Yaowen Zheng, Tao Liu, Le Guan, Peng Liu, Hong Li, Hongsong Zhu, Kejiang Ye, Limin Sun. Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias Analysis (CCF A).
- [Computers and Security 2023] Chuan Qin, Jiaqian Peng, Puzhuo Liu, Yaowen Zheng, Kai Cheng, et al. UCRF: Static analyzing firmware to generate under-constrained seed for fuzzing SOHO router (CCF B).
- [ICC 2022] Puzhuo Liu, Dongliang Fang, Chuan Qin, Kai Cheng, et al. Finding Vulnerabilities in Internal-binary of Firmware with Clues (CCF C).
- [IFIP SEC 2021] Kai Cheng, Dongliang Fang, Chuan Qin, Huizhao Wang, Yaowen Zheng, Nan Yu, Limin Sun. Automatic Inference of Taint Sources to Discover Vulnerabilities in SOHO Router Firmware. In the IFIP International Conference on ICT Systems Security and Privacy Protection (CCF C).
- [ACSAC 2021] Fang D, Song Z, Guan L, Liu P, Peng A, Cheng K, et al. Ics3fuzzer: A framework for discovering protocol implementation bugs in ics supervisory software by fuzzing[C]. Annual Computer Security Applications Conference (CCF B).
- [Internet of Things Journal, 2021] Wei Zhou, Chen Cao, Dongdong Huo, Kai Cheng, et al. Reviewing IoT security via logic bugs in IoT platforms and systems[J] (CCF C).
- [IPCCC 2019] Yaowen Zheng, Zhanwei Song, Yuyan Sun, Kai Cheng, Hongsong Zhu, Limin Sun. An Efficient Greybox Fuzzing Scheme for Linux-based IoT Programs Through Binary Static Analysis. In the IEEE 38th International Performance Computing and Communications Conference ( CCF C).
- [软件学报 2019] 陈千,程凯,郑尧文,朱红松,孙利民. 函数级数据依赖图及其在静态脆弱性分析中的应用.
- [信息安全学报 2019] 郑尧文,文辉,程凯,宋站威,朱红松,孙利民. 物联网设备漏洞挖掘技术研究综述.
- [DSN 2018] Kai Cheng, Qiang Li, Lei Wang, Qian Chen, Yaowen Zheng, Limin Sun , and Zhengkai Liang. DTaint: Detecting the Taint-Style Vulnerability in Embedded Device Firmware. Int the 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (CCF B).
- [ICICS 2016] Yaowen Zheng, Kai Cheng, Zhi Li, Shiran Pan, Hongsong Zhu, and Limin Sun. A Lightweight Method for Accelerating Discovery of Taint-Style Vulnerabilities in Embedded Systems. In Proceedings of the 18th International Conference on Information and Communications Security (CCF C).