About
Xingwei(Roy) Lin is a Security Algorithm Expert at Ant Group, focusing on the intersection of AI and Security: securing AI systems (e.g., LLM safety and robustness) and applying LLM-powered agents to software & network security — from vulnerability detection to automated patching. He has discovered over 100 vulnerabilities in widely-deployed software such as Apple, Microsoft, and QEMU, earning Pwnie Awards "Most Innovative Research" nominations in both 2020 and 2021. His work has been published extensively in top-tier venues and received the ACM CCS 2021 Best Paper Award.
He is also pursuing a PhD at Zhejiang University under the supervision of Prof. Chunming Wu. He received his M.S. from UESTC under the supervision of Prof. Xiaosong Zhang and Prof. Ting Chen, and was a Research Assistant at PolyU working with Prof. Xiapu Luo.
Research Interests
- AI Security — LLM/Agent safety, robustness, and jailbreak assessment
- LLM-powered Security Agents — Vulnerability detection and automated patch generation
- System & Software Security — Fuzzing, program analysis and binary vulnerability discovery
News
- [2026.06] Our paper ChainDelta, an LLM-driven fuzzing-agent framework for automatic patch-based exploit generation on Ethereum, is accepted to FSE 2026.
- [2026.05] Our paper Code Language Models for Security Patch Management: How Far Are We?, the first large-scale empirical study of nine CodeLMs on three patch management tasks, is accepted to IEEE Transactions on Services Computing (TSC).
- [2026.01] Our paper ICON, an efficient multi-turn jailbreak attack framework leveraging intent-context coupling against LLMs, is now available on arXiv.
- [2025] Our paper Hyperion, an LLM and dataflow-guided symbolic execution framework for unveiling DApp inconsistencies, is accepted at ICSE 2025.
- [2025] Our paper AePPollo on LLM-powered prototype pollution vulnerability detection and exploit generation is accepted at SEKE 2025.
Experience
| 2019.07 – Present | Ant Group, Security Algorithm Expert |
| 2017.07 – 2017.12 | The Hong Kong Polytechnic University, Research Assistant |
Education
| 2024.09 – Present | Zhejiang University, Ph.D. in Computer Science and Technology |
| 2016.09 – 2019.06 | University of Electronic Science and Technology of China, M.S. in Computer Science and Technology |
| 2012.09 – 2016.07 | University of Electronic Science and Technology of China, B.E. in Communication Engineering |
Selected Publications
* corresponding author. Full list: Google Scholar.
-
FSE'26 (CCF-A) ChainDelta: Automatic Patch-Based Exploit Generation for Ethereum with Fuzzing Agents [pdf]
-
ICSE'25 (CCF-A) Hyperion: Unveiling DApp Inconsistencies Using LLM and Dataflow-Guided Symbolic Execution [pdf]
-
SEKE'25 (CCF-C) AePPollo: Automated Exploit Generation for Prototype Pollution Vulnerabilities in Node.js Application [pdf]
-
USENIX Security'24 (CCF-A) Code is not Natural Language: Unlock the Power of Semantics-Oriented Graph Representation for Binary Code Similarity Detection [pdf]
-
CCS'21 (CCF-A) Best Paper V-SHUTTLE: Scalable and Semantics-Aware Hypervisor Virtual Device Fuzzing [pdf]
-
CCS'18 (CCF-A) JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native Code [pdf]
Awards & Honors
- 2023 Frontier Breakthrough Award & Outstanding Presentation Award, GeekCon
- 2023 First Prize, 3rd Trusted Blockchain Security Attack-Defense Competition
- 2023 Best Paper Award, BlockSys 2023
- 2021 Best Paper Award, ACM CCS 2021 (V-SHUTTLE)
- 2021 Pwnie Awards Nomination, "Most Innovative Research" (V-SHUTTLE)
- 2021 2nd Place, Baidu BCTF AutoPwn
- 2020 Pwnie Awards Nomination, "Most Innovative Research" (APICRAFT)
Professional Service
- Program Committee — ACM CCS 2024 (Software Security Track)
- Program Committee — ACM AsiaCCS 2027 (AI Security Track)
- Journal Reviewer — Automated Software Engineering (ASE), 2026
CVE Contributions
Responsibly disclosed 90+ CVEs across major software vendors.