I will join Michigan Technological University as a tenure-track Assistant Professor in August 2026. I received my Ph.D. in Information Technology (2026) from George Mason University, where I was advised by Dr. Kun Sun. Before that, I earned my M.Eng. in Cyberspace Security (2021) and B.Eng. in Information Security (2018) from Wuhan University, advised by Dr. Fei Yan. My research lies in Software and Systems Security, with a focus on Automated Program Repair (APR), Container Security, and the use of Large Language Models (LLMs) for Security.

I am currently looking for highly motivated Ph.D. students to join my research group. Positions are fully funded through research assistantships (RAs), covering tuition and providing a competitive stipend. If you are interested, please feel free to email me your CV and transcript.

Publications

Conference Papers

  • SecureComm 2026 ConfigWiz: Automating Privilege Configuration for Containerized Applications [paper]
    Mohammad Kavousi, Hui Xue, Yan Chen, Xin Chen, Yunlong Xing, Kun Sun, Therese Schachner, and Zhiheng Tao.
    In 22nd EAI International Conference on Security and Privacy in Communication Networks (SecureComm), Lancaster, UK, 2026.

  • USENIX Security 2025 DISPATCH: Unraveling Security Patches from Entangled Code Changes [paper]
    Shiyu Sun*, Yunlong Xing*, Xinda Wang, Shu Wang, Qi Li, and Kun Sun.
    In 34th USENIX Security Symposium (USENIX Security), Seattle, WA, 2025.
    (* indicates equal contribution)

  • DIMVA 2025 An Empirical Study of Multi-Language Security Patches in Open Source Software [paper]
    Shiyu Sun, Yunlong Xing, Grant Zou, Xinda Wang, and Kun Sun.
    In 22nd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), Austria, 2025.
    (Acceptance Rate: 25/114 = 21.9%)

  • USENIX Security 2024 What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check [paper]
    Yunlong Xing, Shu Wang, Shiyu Sun, Xu He, Kun Sun, and Qi Li.
    In 33rd USENIX Security Symposium (USENIX Security), Philadelphia, PA, 2024.
    (Acceptance Rate - Summer Review Cycle: 98/515 = 19.0%)
    🎖 Top 15 Finalists (among 194 submissions) of CSAW 2024 Applied Research Competition

  • USENIX Security 2023 Cross Container Attacks: The Bewildered eBPF on Clouds [paper]
    Yi He*, Roland Guo*, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, and Qi Li.
    In 32nd USENIX Security Symposium (USENIX Security), Anaheim, CA, 2023.
    (Acceptance Rate - Fall Review Cycle: 155/531 = 29.2%)

  • ICSME 2023 Exploring Security Commits in Python [paper]
    Shiyu Sun, Shu Wang, Xinda Wang, Yunlong Xing, Elisa Zhang, and Kun Sun.
    IEEE International Conference on Software Maintenance and Evolution (ICSME), Bogotá, Colombia, 2023.
    (Acceptance Rate: 27/119 = 22.7%)

  • CNS 2022 SysCap: Profiling and Crosschecking Syscall and Capability Configurations for Docker Images [paper]
    Yunlong Xing, Jiahao Cao, Xinda Wang, Sadegh Torabi, Kun Sun, Fei Yan, and Qi Li.
    IEEE Conference on Communications and Network Security (CNS), Austin, TX, 2022.

  • RAID 2022 BinProv: Binary Code Provenance Identification without Disassembly [paper]
    Xu He, Shu Wang, Yunlong Xing, Pengbin Feng, Haining Wang, Qi Li, Songqing Chen, and Kun Sun.
    International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Limassol, Cyprus, 2022.
    (Acceptance Rate: 35/139 = 25.2%)

Journal Papers

  • TDSC 2023 A Hybrid System Call Profiling Approach for Container Protection [paper]
    Yunlong Xing*, Xinda Wang*, Sadegh Torabi, Zeyu Zhang, Lingguang Lei, and Kun Sun.
    IEEE Transactions on Dependable and Secure Computing (TDSC), 2023.
    (* indicates equal contribution) (Impact Factor: 7 as 2023)

  • FGCS 2022 The Devil is in the Detail: Generating System Call Whitelist for Linux Seccomp [paper]
    Yunlong Xing, Jiahao Cao, Kun Sun, Fei Yan, and Shengye Wan.
    Future Generation Computer Systems (FGCS), 2022.
    (Impact Factor: 7.3 as 2022)

Talks and Presentations

  • Toward Smarter Memory Safety Automation: From Traditional APR to LLM-Assisted Frameworks
    AI Club at George Mason University, Fairfax, VA, November 2025.

  • What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check [slides]
    In 33rd USENIX Security Symposium (USENIX Security), Philadelphia, PA, August 2024.
    In 21st NYU CSAW Applied Research Competition, Brooklyn, NY, November 2024.

  • Cross Container Attacks: The Bewildered eBPF on Clouds [slides]
    In 32nd USENIX Security Symposium (USENIX Security), Anaheim, CA, August 2023.

  • SysCap: Profiling and Crosschecking Syscall and Capability Configurations for Docker Images [slides]
    IEEE Conference on Communications and Network Security (CNS), Austin, TX, October 2022.

Honors and Awards

  • Summer Research Assistantship of George Mason University (2025)
  • Top 15 Finalists of NYU CSAW Applied Research Competition (2024)
  • 33rd USENIX Security Symposium Student Travel Grant (2024)
  • 32nd USENIX Security Symposium Student Travel Grant (2023)
  • First Prize of 10th China’s National College Student Information Security Contest (2017)
  • Second Class Academic Scholarship of Wuhan University (2017)
  • Third Prize of China’s National University Mobile Internet Application Innovation Contest (2016)

Academic Services

  • Artifacts Evaluation Committee
    • Annual Computer Security Applications Conference (ACSAC) (2023/2024)
  • Conference Reviewer
    • IEEE International Conference on Computer Communications (INFOCOM) (2024/2025/2026)
    • IEEE Military Communications Conference (MILCOM) (2023/2025)
  • Journal Reviewer
    • IEEE Transactions on Software Engineering (TSE) (2026)
    • IEEE Transactions on Dependable and Secure Computing (TDSC) (2025)
    • IEEE Transactions on Information Forensics & Security (TIFS) (2024/2025/2026)
    • ACM Transactions on Privacy and Security (TOPS) (2024)
    • Computers & Security (2023/2024/2025)
    • Discrete Mathematics, Algorithms and Applications (DMAA) (2025/2026)
  • External Reviewer
    • IEEE Symposium on Security and Privacy (S&P) (2025)
    • Network and Distributed System Security Symposium (NDSS) (2024)
    • Annual Computer Security Applications Conference (ACSAC) (2019/2023)
    • IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) (2020)