基本信息
章秀      中国科学院信息工程研究所
电子邮件: zhangxiu@iie.ac.cn
通信地址: 北京市海淀区树村路19号
邮政编码: 10093

招生信息

章秀,研究方向为Web攻防对抗技术,聚焦Web服务安全领域,以漏洞挖掘、工具研制与检测规避为主线,融合⌈大模型+Agent⌋新研究范式,形成攻防一体的全链路能力。发表WWW、ICSE、Computers&Security、BlackHat等学术论文或技术报告18篇;担任Cybersecurity期刊青年编委并多次获评优秀审稿人;承担网络靶场平台、监测平台、漏洞挖掘项目等多项国家任务,获评信息工程研究所C类科技创新成果奖。欢迎感兴趣的学生积极联系!

招生专业
083900-网络空间安全
招生方向
Web攻防对抗技术

教育背景

2013-09--2021-06   中国科学院信息工程研究所   工学博士学位
2009-09--2013-06   华中科技大学   工学学士学位

工作经历

2025-11~现在, 中国科学院信息工程研究所, 高级工程师

2021-07~2025-11,中国科学院信息工程研究所, 工程师

科技奖励

中国科学院信息工程研究所C类科技创新成果奖,2023

Cybersecurity期刊优秀审稿人,2023,2025

出版信息

(1) Project-Level Resource Leak Detection through Agent-based Ownership Analysis and Repair Pattern Verification, International Conference on Software Engineering(ICSE), 2026, 第 2 作者  通讯作者

(2) Debatecti: Enhancing ATT&CK Technique Identification in CTI Reports Via a Role-Specialized Multi-Agent Debate, International Conference on Acoustics, Speech and Signal Processing(ICASSP), 2026, 第 5 作者

(3) LSD Attack: Exploiting Inconsistencies between Design and Implementation of Ethereum Protocols, International Conference on Trust, Security and Privacy in Computing and Communications(TrustCom), 2025, 第 2 作者

(4) The-Illusion-of-Isolation-How-Isolation-Failures-In-CICD-Servers-Lead-to-RCE-and-Privacy-Risks, BlackHat Aisa, 2025, 第 3 作者

(5) CotexFinger: Enhancing IoT Device Identification with Context-Packet Fingerprinting and Lightweight Visual Mamba, International Joint Conference on Neural Networks(IJCNN), 2025, 第 2 作者

(6) ETHNetPRecover: Ethereum Network Topology Recovering via Passive Transaction Monitoring, International Conference on Computer Supported Cooperative Work in Design(CSCWD), 2025, 第 2 作者

(7) RRCFuzzer: A 3GPP-Guided Fuzzing Method for RRC Protocol, International Conference on Telecommunications(ICT), 2025, 第 5 作者

(8) A Coverage Feedback Guided Fuzzing Method for NAS Protocol, International Conference on Telecommunications(ICT), 2025, 第 5 作者

(9) SCMDetector Smart Contract Malicious Detection Technique Based on GLM and ABLSTM-A, International Conference on Computer Supported Cooperative Work in Design (CSCWD), 2025, 第 3 作者  通讯作者

(10) Is JavaScript Trustworthy in Cloud Computing, Black Hat Europe, 2024, 第 5 作者

(11) Combating alert fatigue with AlertPro: Context-aware alert prioritization using reinforcement learning for multi-step attack detection, COMPUTERS & SECURITY, 2024, 第 4 作者  通讯作者

(12) AppChainer: investigating the chainability among payloads in android applications, Cybersecurity, 2023, 第 4 作者

(13) APTTOOLNER: A Chinese Dataset of Cyber Security Tool for NER task, Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS), 2023, 第 6 作者

(14) Breaking the Trust Circle in HarmonyOS by Chaining Multiple Vulnerabilities, Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS), 2023, 第 2 作者

(15) 建立渗透测试型人才能力评估的综合评价模型, 信息安全学报, 2022, 第 1 作者

(16) SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization, International World Wide Web Conference(WWW), 2021, 第 5 作者

(17) Explore-Exploit:一种模拟真实网络渗透场景的安全竞赛, Explore-Exploit: A Security Competition Modeling the Real-world Network Penetration Scenario, 信息安全学报, 2020, 第 1 作者

(18) State-of-the-Art: Security Competition in Talent Education, International Conference on Information Security and Cryptology(Inscrypt), 2017, 第 1 作者

科研项目

( 1 ) 漏洞挖掘项目, 参与, 国家任务, 2022-12--2027-07

( 2 ) 网络靶场平台, 参与, 国家任务, 2021-02--2024-06

( 3 ) 监测平台, 负责人, 国家任务, 2020-11--2023-11

指导学生

   
已指导学生

周天,085412-网络与信息安全,协助指导

皇京豫,083900-网络空间安全,协助指导

朱骞,085412-网络与信息安全,协助指导