My research sits at the intersection of AI, security, and software systems, addressing critical vulnerabilities and performance bottlenecks in today's complex platforms. My work has impacted billions of users, driving vulnerability patches and shaping engineering practice in systems ranging from Linux to NASA's Perseverance Mars rover. I earned my PhD and MS in Computer Science from Stanford University and my BS from Tsinghua University.
I'm looking for a few graduate students, postdocs, and undergraduate interns. If you know how to build systems/tools, we should talk.
Columbia undergraduate and master students: the above applies to you, too.
I was on sabbatical in 2016 co-founding a Columbia spin-off to provide automated, comprehensive app performance analysis.
Select Awards
Honors
- 2025 ACM Fellow
- 2025 ACM SIGOPS Mark Weiser Award
- 2025 IEEE S&P Test-of-Time Award
- 2012 Sloan Research Fellowship
- 2012 AFOSR Young Investigator Program Award
- 2011 NSF CAREER Award
Paper awards
- 2026 IEEE S&P Distinguished Paper Award
- 2024 CIDR Best Paper Award
- 2022 OSDI Best Paper Award
- 2021 USENIX ATC Best Paper Award
- 2017 SOSP Best Paper Award
- 2004 OSDI Best Paper Award
Recent Papers
- TRIM: Reducing AI-Generated CodeSlop via Agent Trajectory Minimization
- Understanding Automated Program Repair Agents Through the Lens of Traceability: An Empirical Study
- Outrunning LLM Cutoffs: A Live Kernel Crash Resolution Benchmark for All
- kAgent: An execution-guided crash resolution agent for the Linux kernel
- zkFuzz: Foundation and Framework for Effective Fuzzing of Zero-Knowledge Circuits
- Detecting Privilege Escalation in Polyglot Microservices via Agentic Program Analysis
-
Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers
IEEE S&P Distinguished Paper Award
- Radshield: Software Radiation Protection for Commodity Hardware in Space
-
PickleBall: Secure Deserialization of Pickle-based Machine Learning Models
CCS Distinguished Artifact Award
- Above the Clouds: New Software Challenges in Space Computing
- CWEval: Outcome-driven Evaluation on Functionality and Security of LLM Code Generation
- Learning to Rewrite: Generalized LLM-Generated Text Detection
- EditLord: Learning Code Transformation Rules for Code Editing
Select Publications
See the complete list of 118 publications.
-
Multitask Learning Strengthens Adversarial Robustness
We present both theoretical and empirical analyses that connect the adversarial robustness of a model to the number of tasks that it is trained on. Experiments on two datasets show that attack difficulty increases as the number of target tasks increase. Moreover, our results suggest that when models are trained on multiple tasks at once, they become more robust to adversarial attacks on individual tasks. While adversarial defense remains an open challenge, our results suggest that deep networks are vulnerable partly because they are trained on too few tasks.
-
DeepXplore: Automated Whitebox Testing of Deep Learning Systems
CSAW 2018 Applied Research Second PlaceCACM Research HighlightSOSP Best Paper Award
We increasingly rely on deep learning and deep neural networks (DNNs) in safety- and security-critical applications such as self-driving, medical diagnosis, face-based identification, and malware detection, but it remains an open challenge to thoroughly test DNNs for robustness and security. We propose Neuron Coverage, the first testing coverage metric to empirically understand how much decision logic a testing input set has exercised in a DNN. We design and build DeepXplore, the first systematic testing framework for DNNs. Given a test input, DeepXplore applies physically realizable transformations (e.g., darkening an image) to the inputs (as opposed to noise in prior adversarial ML work) to generate new inputs to maximize neuron coverage. It found thousands of flaws in state-of-art self-driving and malware detection DNNs and improved their neuron coverage by over 50%. (Also appeared in MLSec '17.)
-
Shuffler: Fast and Deployable Continuous Code Re-Randomization
Describes Shuffler, a system that continuously randomizes an application's binary code at runtime, defeating code-reuse attacks. Shuffler is fast: it shuffles all code within tens of milliseconds, whereas cutting-edge ROP attacks need 10--100x more time to discover gadgets. Shuffler is egalitarian: leveraging the insight that randomization doesn't require a higher privilege authority, Shuffler shuffles itself, reducing trusted computing base and making the approach applicable to kernels and hypervisors. Shuffler is deployable: its augmented binary analysis requires no modifications to OS, compilers, and linkers.
-
Making Parallel Programs Reliable with Stable Multithreading
This paper is geared toward a general audience. If you have time to read just one paper on our concurrency work, this is the paper to read. It describes our vision of stable multithreading (StableMT), a radical approach to making multithreading reliable, and summarizes our last five years of work on designing, building, and applying stable multithreading systems. The final version of this paper will appear in CACM.
-
EXPLODE: a Lightweight, General System for Finding Serious Storage System Errors
Describes our in-situ model checking approach, which made it easy to thoroughly check real systems. We applied eXplode to 17 storage systems and found serious data-loss errors in every system checked. This paper is my favorite in describing our model checking approach, which forms the basis of my PhD thesis work.
Software
- Crane Our transparent state machine replication system.
- AppDoctor Our Android app checker.
- Parrot Our latest stable and deterministic multithreading system. It has two goals: (1) be practical and (2) be fast. By default, it schedules synchronizations in a round-robin manner, vastly reducing the set of schedules for reliability. When needed, it allows developers to add performance hints for speed. Together with the code, we also released a benchmark suite with 100+ multithreaded programs, and Parrot's complete results on these programs.
- NeonGoby A system for effectively detecting errors in alias analysis, one of the most crucial and widely used program analyses. If you have an LLVM-based alias analysis you want to check, give NeonGoby a try.
- Loom A "live-workaround" system designed to quickly and safely bypass various types of concurrency errors at runtime. It contains a generic engine for live-updating multithreaded programs without restarts, which you can leverage if you want to build a live-update tool.
- eXplode A storage system checker. It uses an approach we call in-situ model checking to thoroughly check general systems software in a lightweight manner.
People
I'm fortunate to work or have worked with these brilliant people.
Current advisees
- Yun-Yun Tsai, PhD student
- Andreas Kellas, PhD student
- Raphael Jedidiah Sofaer, PhD student
- Harry Haoda Wang, PhD student
- Alex Mathai, PhD student
- Jinjun Peng, PhD student
- Hailie Mitchell, PhD student
- Hideaki Takahashi, PhD student
- Jihwan Kim, PhD student
- Chenxi Huang, PhD student
- Weiliang Zhao, PhD student
Alumni
- Penghui Li, Postdoc research scientist, 2026, joined Nanyang Technological University as an assistant professor
- Tamer Eldeeb, PhD, 2025, Co-founded Atomix DB
- Wei Hao, PhD, 2026, co-founded Metlas
- Yaniv David, Postdoc research scientist, 2021-2024, joined Meta and then Technion as a professor
- Sally Junson Wang, MS, 2024, joined Stanford for PhD with Stanford Graduate Fellowship
- Weichen Li, MS, 2024, joined University of Chicago for PhD
- Kexin Pei, PhD, 2023, joined the University of Chicago as a Neubauer Family professor
- Chengzhi Mao, PhD, 2023, joined Google and then Rutgers as a professor
- Lingmei Weng, PhD, 2023, joined Google
- David Williams-King, PhD, 2020, joined Elpha Secure as CTO
- Scott K. Geng, Undergraduate, 2023, joined the University of Washington for PhD, NSF Graduate Research Fellow
- Yang Tang, PhD, 2019, joined laioffer as Director of Education and Curriculum Development then NYU as a lecturer
- Gang Hu, PhD, 2018, joined Google
- Xinhao Yuan, PhD, 2019, joined Google
- Yinzhi Cao, Postdoc research scientist, 2014-2015, joined Lehigh and then Johns Hopkins University as a professor
- Heming Cui, PhD, 2015, joined the University of Hong Kong as a professor
- Jingyue Wu, PhD, 2014, joined Google
- Yan Cui, Postdoc research scientist, 2013-2015, joined Intel
- Oren Laadan, Postdoc research scientist, 2010-2011, founded Cellrox
- Rui Gu, MS, 2017
- Linjie Zhu, MS, 2019
- Georgios Koloventzos, MS, 2016
- Karthik Jayaraman, MS, 2016
- Chuliang Weng, Visiting research scientist, 2012
- John Gallagher, MS, 2011, joined FourSquare
- Chia-che Tsai, MS, 2011, joined Stony Brook for PhD
- Neetha Maria Sebastian, MS, 2011, joined Google
- Yunling Wang, MS, 2010, joined Microsoft
- Ben Warfield, MS, 2010, joined Wireless Generation
- Nathan Murith, MS, 2010, joined Autodesk
- Maoliang Huang, MS, 2010, joined FlexTrade Systems
- Patrick Huang, MS, 2009, joined Sony
I co-advise some students in the SSL lab.
Articles and Discussions about Research
- DIVID
- Columbia Engineering
- DeepXplore
- Scientific American, IEEE Spectrum, CACM Research Highlight (Video), Newsweek, TechRadar, Columbia News, China News, Sohu, Sina, CCTV's Hello AI documentary
- Shuffler
- Network World, ACM Tech News
- Machine unlearning
- The Stack, EurekAlert, The Atlantic, KurzweilAI, ACM Tech News
- Peregrine
- CACM, ACM Tech News, The Register, Columbia Engineering, TG Daily, Physorg.com
- MoDist
- Softpedia
- eXplode
- Linux Weekly News
- Static analysis
- Linux Kernel Mailing List
Teaching
- Fall 2026 E6998: Build an Agent Startup
- Fall 2025 W4152: Engineering Software-as-a-Service
- Fall 2025 E6113: Agent for Work
- Fall 2024 Sabbatical leave
- Spring 2024 Sabbatical leave
Earlier terms (32)
- Fall 2023 W4152: Engineering Software-as-a-Service
- Fall 2023 E6998: Engineering Blockchain and Web3 Apps
- Fall 2022 W4152: Engineering Software-as-a-Service
- Fall 2022 E6998: Engineering Blockchain and Web3 Apps
- Fall 2021 W4995: Engineering Software-as-a-Service
- Fall 2021 E6998: Security and Robustness of ML systems
- Spring 2021 W4156: Advanced Software Engineering
- Spring 2021 E6998-003: Security and Robustness of ML systems
- Spring 2020 W4156: Advanced Software Engineering
- Spring 2020 E6998-010: Security and Robustness of ML systems
- Spring 2019 E6121: Reliable Software
- Spring 2019 E6998-001: Security and Robustness of ML systems
- Spring 2018 E6121: Reliable Software
- Spring 2018 E6998-009: Security and Robustness of ML systems
- Spring 2017 E6121: Reliable Software
- Fall 2016 Teaching leave
- Spring 2016 Sabbatical leave
- Fall 2015 Sabbatical leave
- Spring 2015 Teaching leave
- Fall 2014 E6121: Reliable Software
- Spring 2014 Teaching leave
- Fall 2013 W4118: Operating Systems I
- Spring 2013 Teaching leave
- Fall 2012 E6121: Reliable Software
- Spring 2012 W4118: Operating Systems I
- Fall 2011 E6121: Reliable Software
- Spring 2011 W4118: Operating Systems I
- Fall 2010 E6998-1: Reliable Software
- Spring 2010 W4118: Operating Systems I
- Fall 2009 E6998-1: Reliable Software
- Spring 2009 W4118: Operating Systems I
- Fall 2008 E6998-2: How to Make Reliable Software
Support for Research and Teaching
We are grateful to the sponsors of our research and teaching, including NSF, ONR, DARPA, AFOSR, AFRL, Sloan Foundation, Google, Facebook, Amazon, and Accenture (an incomplete list).