I am an Assistant Professor in the College of Computing at Michigan Technological University. I received my Ph.D. in Information Technology from George Mason University, advised by Dr. Kun Sun. Before that, I earned my M.S. in Cyberspace Security and B.S. in Information Security, both from Wuhan University. My research lies in Software and Systems Security, with a focus on Automated Program Repair (APR), Sanitization Optimization, and Container Security.

LLM-Driven Software and Systems Security
In the era of LLMs, I focus on leveraging LLMs and agentic AI to advance the end-to-end pipeline of software and systems security, including vulnerability detection, reasoning, patch generation, and verification.

I am currently looking for highly motivated Ph.D. students to join my research group. Positions are fully funded through research assistantships (RAs), covering tuition and providing a competitive stipend. If you are interested, please feel free to email me your CV and transcript.

What’s New?

  • [ACM SIGOPS ATC 2026] In September 2026, our paper “DESAN: READ/WRITE-Aware Redundant Sanitizer Check Elimination” accepted by ACM SIGOPS ATC 2026 (p.k.a. USENIX ATC).
  • [NDSS 2027 TPC] In August 2026, invited to serve in the TPC for NDSS 2027.
  • [Best Paper Award] In July 2026, our paper “ConfigWiz: Automating Privilege Configuration for Containerized Applications” won the Best Paper Award in SecureComm 2026.
  • [SecureComm 2026] In March 2026, one paper “ConfigWiz: Automating Privilege Configuration for Containerized Applications” accepted by SecureComm 2026.
  • [DIMVA 2025] In April 2025, one paper “An Empirical Study of Multi-Language Security Patches in Open Source Software” accepted by DIMVA 2025.
  • [Summer Research Assistantship] In March 2025, the Summer Research Assistantship of George Mason University awarded.
  • [USENIX Security 2025] In February 2025, one paper “DISPATCH: Unraveling Security Patches from Entangled Code Changes” accepted by USENIX Security 2025.
  • [CSAW 2024] In October 2024, our paper “What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check” selected as one of the 15 finalists of the CSAW 2024 Applied Research Competition.
  • [USENIX Security 2024] In September 2023, one paper “What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check” accepted by USENIX Security 2024.

Selected Publications

Conference Papers

  • ACM SIGOPS ATC 2026 DESAN: READ/WRITE-Aware Redundant Sanitizer Check Elimination [paper]
    Yunlong Xing, Shiyu Sun, and Kun Sun.
    In the ACM SIGOPS Annual Technical Conference (ATC), Hong Kong, China, 2026.
    (Acceptance Rate: 135 / 973 = 13.9%)

  • SecureComm 2026 ConfigWiz: Automating Privilege Configuration for Containerized Applications [paper]
    Mohammad Kavousi, Hui Xue, Yan Chen, Xin Chen, Yunlong Xing, Kun Sun, Therese Schachner, and Zhiheng Tao.
    In the 22nd EAI International Conference on Security and Privacy in Communication Networks (SecureComm), Lancaster, UK, 2026.
    🎖 Best Paper Award

  • USENIX Security 2025 DISPATCH: Unraveling Security Patches from Entangled Code Changes [paper]
    Shiyu Sun*, Yunlong Xing*, Xinda Wang, Shu Wang, Qi Li, and Kun Sun.
    In the 34th USENIX Security Symposium (USENIX Security), Seattle, WA, 2025.
    (Acceptance Rate: 407 / 2385 = 17.1%, *: co-first authors)

  • DIMVA 2025 An Empirical Study of Multi-Language Security Patches in Open Source Software [paper]
    Shiyu Sun, Yunlong Xing, Grant Zou, Xinda Wang, and Kun Sun.
    In the 22nd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), Austria, 2025.
    (Acceptance Rate: 25 / 114 = 21.9%)

  • USENIX Security 2024 What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check [paper]
    Yunlong Xing, Shu Wang, Shiyu Sun, Xu He, Kun Sun, and Qi Li.
    In the 33rd USENIX Security Symposium (USENIX Security), Philadelphia, PA, 2024.
    (Acceptance Rate: 417 / 2176 = 19.2%)
    🎖 Top 15 Finalists (among 194 submissions) of CSAW 2024 Applied Research Competition

  • USENIX Security 2023 Cross Container Attacks: The Bewildered eBPF on Clouds [paper]
    Yi He, Roland Guo, Yunlong Xing, Xijia Che, Kun Sun, Zhuotao Liu, Ke Xu, and Qi Li.
    In the 32nd USENIX Security Symposium (USENIX Security), Anaheim, CA, 2023.

  • ICSME 2023 Exploring Security Commits in Python [paper]
    Shiyu Sun, Shu Wang, Xinda Wang, Yunlong Xing, Elisa Zhang, and Kun Sun.
    In the IEEE International Conference on Software Maintenance and Evolution (ICSME), Bogotá, Colombia, 2023.
    (Acceptance Rate: 27 / 119 = 22.7%)

  • CNS 2022 SysCap: Profiling and Crosschecking Syscall and Capability Configurations for Docker Images [paper]
    Yunlong Xing, Jiahao Cao, Xinda Wang, Sadegh Torabi, Kun Sun, Fei Yan, and Qi Li.
    In the IEEE Conference on Communications and Network Security (CNS), Austin, TX, 2022.

  • RAID 2022 BinProv: Binary Code Provenance Identification without Disassembly [paper]
    Xu He, Shu Wang, Yunlong Xing, Pengbin Feng, Haining Wang, Qi Li, Songqing Chen, and Kun Sun.
    In the International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Limassol, Cyprus, 2022.
    (Acceptance Rate: 35 / 139 = 25.2%)

Journal Papers

  • TDSC 2023 A Hybrid System Call Profiling Approach for Container Protection [paper]
    Yunlong Xing*, Xinda Wang*, Sadegh Torabi, Zeyu Zhang, Lingguang Lei, and Kun Sun.
    In the IEEE Transactions on Dependable and Secure Computing (TDSC), 2023.
    (Impact Factor: 7 as of 2023, *: co-first authors)

  • FGCS 2022 The Devil is in the Detail: Generating System Call Whitelist for Linux Seccomp [paper]
    Yunlong Xing, Jiahao Cao, Kun Sun, Fei Yan, and Shengye Wan.
    In the Future Generation Computer Systems (FGCS), 2022.
    (Impact Factor: 7.3 as of 2022)

Talks and Presentations

  • Toward Smarter Memory Safety Automation: From Traditional APR to LLM-Assisted Frameworks
    In the AI Club at George Mason University, Fairfax, VA, November 2025.

  • What IF Is Not Enough? Fixing Null Pointer Dereference With Contextual Check [slides]
    In the 33rd USENIX Security Symposium (USENIX Security), Philadelphia, PA, August 2024.
    In the 21st NYU CSAW Applied Research Competition, Brooklyn, NY, November 2024.

  • Cross Container Attacks: The Bewildered eBPF on Clouds [slides]
    In the 32nd USENIX Security Symposium (USENIX Security), Anaheim, CA, August 2023.

  • SysCap: Profiling and Crosschecking Syscall and Capability Configurations for Docker Images [slides]
    In the IEEE Conference on Communications and Network Security (CNS), Austin, TX, October 2022.

Teaching

  • SAT 3812 Cyber Security I (Fall 2026)

Honors and Awards

  • Best Paper Award of SecureComm (2026)
  • Summer Research Assistantship of George Mason University (2025)
  • Top 15 Finalists of NYU CSAW Applied Research Competition (2024)
  • 33rd USENIX Security Symposium Student Travel Grant (2024)
  • 32nd USENIX Security Symposium Student Travel Grant (2023)
  • First Prize of 10th China’s National College Student Information Security Contest (2017)
  • Second Class Academic Scholarship of Wuhan University (2017)
  • Third Prize of China’s National University Mobile Internet Application Innovation Contest (2016)

Academic Services

  • Technical Program Committee
    • Network and Distributed System Security Symposium (NDSS) (2027)
  • Artifacts Evaluation Committee
    • Annual Computer Security Applications Conference (ACSAC) (2023/2024)
  • Conference Reviewer
    • IEEE International Conference on Computer Communications (INFOCOM) (2024/2025/2026)
    • IEEE Military Communications Conference (MILCOM) (2023/2025)
  • Journal Reviewer
    • IEEE Transactions on Software Engineering (TSE) (2026)
    • IEEE Transactions on Dependable and Secure Computing (TDSC) (2025/2026)
    • IEEE Transactions on Information Forensics & Security (TIFS) (2024/2025/2026)
    • ACM Transactions on Privacy and Security (TOPS) (2024)
    • Computers & Security (2023/2024/2025/2026)
    • Discrete Mathematics, Algorithms and Applications (DMAA) (2025/2026)
    • ACM Digital Threats: Research and Practice (DTRAP) (2026)
    • Journal of Systems Architecture (JSA) (2026)
    • ACM Transactions on Computing Education (TOCE) (2026)
  • External Reviewer
    • IEEE Symposium on Security and Privacy (S&P) (2025)
    • Network and Distributed System Security Symposium (NDSS) (2024)
    • European Symposium on Research in Computer Security (ESORICS) (2026)
    • Annual Computer Security Applications Conference (ACSAC) (2019/2023)
    • IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) (2020)