About Me

I am a master's student in the School of Cyber Science and Engineering at Huazhong University of Science and Technology, where I am part of Security Pride.

My research focuses on large language model systems security and static program analysis. My projects also explore AI-assisted vulnerability analysis.

LLM Systems SecurityStatic Program Analysis

Selected Research

ICSE 2027 CCF-A Submitted · Under review

SemWeaver: Refining LLM-Generated Static Vulnerability Checkers with Analyzer-Internal Evidence

Chengzhi Yi, Shenao Wang, Yanjie Zhao, Xiao Cheng, Haoyu Wang

A plug-in refinement layer that selects evidence from static-analysis engines to help LLM-generated vulnerability checkers distinguish vulnerable code from fixed code.

Huazhong University of Science and Technology · Macquarie University

Read abstract

LLM-based patch-driven synthesis can automatically generate static vulnerability checkers from security fixes, but the resulting checkers often capture only the syntactic shape of the patch while missing the semantic conditions (path guards, state invariants, data-flow relations, and API contracts) needed to distinguish vulnerable code from fixed code. Existing refinement loops rely on behavioral feedback alone, which reveals symptoms but not causes, reducing refinement to prompt-level retry. We observe that static-analysis engines already compute the missing predicates as intermediate results during checker execution, yet these results are never exposed to the refinement process. Directly feeding all intermediate results to the LLM is impractical due to their volume and noise. SemWeaver is a plug-in refinement layer that bridges this gap through adaptive evidence selection: a patch-mechanism classifier identifies the bug category and collects only the relevant analyzer-native facts, which are then normalized with patch context and validation feedback into a typed semantic evidence bundle. A target-preserving gate ensures that each refinement preserves the vulnerable-side trigger while eliminating fixed-side warnings. We evaluate SemWeaver on real-world Linux kernel vulnerability patches. On 12 refinable KNighter derived CSA checkers, SemWeaver raises the patch-discriminating success rate from 0% to 91.7%. On 20 cross-backend detectors (CSA and CodeQL) from an independent generator, it achieves a 50% relative improvement. Ablation and model-robustness studies confirm the contribution of analyzer-native evidence beyond validation-only retry.

Research project2024 — 2025

Intelligent security operations with large language models

Security-focused language models and orchestration for threat investigation, remediation, and coordinated protection across security devices. I contributed to backend development, API testing, dataset construction, and model training.

Advisor: Lansheng Han · National undergraduate innovation project

Experience

StepFun 阶跃星辰

Jul 6 — Sep 10, 2026

AI Security Engineering Intern · Shanghai

Secure development lifecycle tooling, static application security testing, and automated security scanning integrated into development workflows.

ByteDance 字节跳动

Jun — Sep 2025

R&D Intern · Douyin LIVE · Hangzhou

Backend development for QA platforms, automation services, and agent development. Independently completed four technical initiatives.

State Grid 国家电网

Jul — Aug 2024

Information Security Intern · Wuhan

Contributed to language-model data resources, knowledge graph construction, and platform API development and testing.

Education

HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY

Master's Student · Cyberspace Security

School of Cyber Science and Engineering

Planned transition to doctoral studies in 2027.

HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY

Cyberspace Security

Undergraduate studies · 2022 — 2026

School of Cyber Science and Engineering

Selected Honors

  • First-Class Master's Scholarship
  • HUST Undergraduate Natural Science Innovation Fund Research funding recipient
  • National Undergraduate Innovation Project Core member · Excellent completion
  • Kingsoft Cloud Security Elite Program Ranked first upon completion
  • HUST Cybersecurity Competition Second prize
  • Lanqiao Cup · Provincial Competition Third prize
  • Academic Excellence Scholarship