电子邮件: zhangxiu@iie.ac.cn
通信地址: 北京市海淀区树村路19号
邮政编码: 10093
招生信息
章秀,研究方向为Web攻防对抗技术,聚焦Web服务安全领域,以漏洞挖掘、工具研制与检测规避为主线,融合⌈大模型+Agent⌋新研究范式,形成攻防一体的全链路能力。发表WWW、ICSE、Computers&Security、BlackHat等学术论文或技术报告18篇;担任Cybersecurity期刊青年编委并多次获评优秀审稿人;承担网络靶场平台、监测平台、漏洞挖掘项目等多项国家任务,获评信息工程研究所C类科技创新成果奖。欢迎感兴趣的学生积极联系!
招生专业
招生方向
教育背景
工作经历
2025-11~现在, 中国科学院信息工程研究所, 高级工程师
2021-07~2025-11,中国科学院信息工程研究所, 工程师
科技奖励
中国科学院信息工程研究所C类科技创新成果奖,2023
Cybersecurity期刊优秀审稿人,2023,2025
出版信息
(1) Project-Level Resource Leak Detection through Agent-based Ownership Analysis and Repair Pattern Verification, International Conference on Software Engineering(ICSE), 2026, 第 2 作者 通讯作者
(2) Debatecti: Enhancing ATT&CK Technique Identification in CTI Reports Via a Role-Specialized Multi-Agent Debate, International Conference on Acoustics, Speech and Signal Processing(ICASSP), 2026, 第 5 作者
(3) LSD Attack: Exploiting Inconsistencies between Design and Implementation of Ethereum Protocols, International Conference on Trust, Security and Privacy in Computing and Communications(TrustCom), 2025, 第 2 作者
(4) The-Illusion-of-Isolation-How-Isolation-Failures-In-CICD-Servers-Lead-to-RCE-and-Privacy-Risks, BlackHat Aisa, 2025, 第 3 作者
(5) CotexFinger: Enhancing IoT Device Identification with Context-Packet Fingerprinting and Lightweight Visual Mamba, International Joint Conference on Neural Networks(IJCNN), 2025, 第 2 作者
(6) ETHNetPRecover: Ethereum Network Topology Recovering via Passive Transaction Monitoring, International Conference on Computer Supported Cooperative Work in Design(CSCWD), 2025, 第 2 作者
(7) RRCFuzzer: A 3GPP-Guided Fuzzing Method for RRC Protocol, International Conference on Telecommunications(ICT), 2025, 第 5 作者
(8) A Coverage Feedback Guided Fuzzing Method for NAS Protocol, International Conference on Telecommunications(ICT), 2025, 第 5 作者
(9) SCMDetector Smart Contract Malicious Detection Technique Based on GLM and ABLSTM-A, International Conference on Computer Supported Cooperative Work in Design (CSCWD), 2025, 第 3 作者 通讯作者
(10) Is JavaScript Trustworthy in Cloud Computing, Black Hat Europe, 2024, 第 5 作者
(11) Combating alert fatigue with AlertPro: Context-aware alert prioritization using reinforcement learning for multi-step attack detection, COMPUTERS & SECURITY, 2024, 第 4 作者 通讯作者
(12) AppChainer: investigating the chainability among payloads in android applications, Cybersecurity, 2023, 第 4 作者
(13) APTTOOLNER: A Chinese Dataset of Cyber Security Tool for NER task, Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS), 2023, 第 6 作者
(14) Breaking the Trust Circle in HarmonyOS by Chaining Multiple Vulnerabilities, Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS), 2023, 第 2 作者
(15) 建立渗透测试型人才能力评估的综合评价模型, 信息安全学报, 2022, 第 1 作者
(16) SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization, International World Wide Web Conference(WWW), 2021, 第 5 作者
(17) Explore-Exploit:一种模拟真实网络渗透场景的安全竞赛, Explore-Exploit: A Security Competition Modeling the Real-world Network Penetration Scenario, 信息安全学报, 2020, 第 1 作者
(18) State-of-the-Art: Security Competition in Talent Education, International Conference on Information Security and Cryptology(Inscrypt), 2017, 第 1 作者
科研项目
( 1 ) 漏洞挖掘项目, 参与, 国家任务, 2022-12--2027-07
( 2 ) 网络靶场平台, 参与, 国家任务, 2021-02--2024-06
( 3 ) 监测平台, 负责人, 国家任务, 2020-11--2023-11
指导学生
已指导学生
周天,085412-网络与信息安全,协助指导
皇京豫,083900-网络空间安全,协助指导
朱骞,085412-网络与信息安全,协助指导