Welcome to Heqing Huang’s homepage!

I am an assistant professor at the Department of Computer Science, City University of Hong Kong since 2024! Previously, I was a postdoc research fellow in the AST Lab at ETH Zurich, advised by Prof. Zhendong Su. I am also fortunate to obtain my Ph.D. supervised by Prof. Charles Zhang at the Hong Kong University of Science and Technology.

My research focuses on software security, particularly leveraging program analysis techniques to ensure rigorous software security. My primary goal is to address the deficiencies in existing security analysis for diverse software systems by understanding the complex semantics of programs. Hence, there are two main divisions of my research currently:

  1. Enhancing fundamental program analysis algorithms.
  2. Exploring code semantic representation/security specifications in diverse scenarios (e.g., AI, Blockchain, Kernel).

I am looking for Postdoc, Ph.D, MPhil students as well as RAs. If you pursue making the program more secure and reliable, please feel free to send me an email.

NEWS!

  • Our paper on provable optimizing path coverage instrumentation is accepted in OOPSLA 26!
  • Our paper on securing software supply chain with enhanced composition analysis is accepted in ISSTA 26!
  • Our paper on designing fine-grained feedback considering bug triage for fuzzing has been accepted in CCS 26!
  • Our paper on defining a new type of performance vulnerability in AI agents has been accepted in ACL main track!
  • Our paper on detecting false negative vulnerabilities on autonomous driving simulators has been accepted in TDSC!
  • Our paper on studying the challenges of applying LLM for software vulnerability detection has been accepted in CSUR
  • Our extension paper of GiantSan (ASPLOS’24 Best Paper) is accepted in TOCS for less instrumentation overhead!
  • Our paper on optimizing fuzzing with fine-grained scheduling feedback is accepted in TOSEM!
  • Our paper on parallel fuzzing is accepted in ISSTA 25!
  • Our paper on decoupling sanitizers from fuzzing is accepted in ICSE 25!
  • Our study for Android APP token privacy leakage issues has been accepted in EMSE 25!
  • Our extension paper on Android testing is accepted in ICSE 25!
  • Entering the finale of DARPA AIxCC! All you need is a fuzzing brain!
  • Our work on fuzzing Android applications is accepted at TSE!
  • One ASPLOS 2025 submission is accepted!
  • Received ASPLOS 2024 Best Paper Award for GiantSan! Congratulations, Hao!
  • Two ASPLOS 2024 submissions get accepted!
  • Another directed fuzzing work has been accepted by S&P 2024 (again)!
  • Our multi-target directed fuzzing work has been accepted by S&P 2024!
  • Received Google Research Paper award for our directed fuzzer published in S&P 2022!
  • Received Huawei distinguished collaborator award on deploying Pangolin (S&P 2020)!

Award

  • 4th place of DARPA AIxCC, 2025
  • Finalist of DARPA AIxCC, 2024
  • ACM SIGARCH Best Paper Award (ASPLOS), 2024
  • Google Research Paper Award, 2022
  • Huawei Distinguish Collaborator, 2021

Students

I am fortunate to work with the following students:

  • Shuo Yang (PhD, 2024)
  • Xiang Li (RA, 2024)
  • Weiwei Fu (PhD, 2024, co-supervision)
  • Haoyu Zhang (PhD, 2025, co-supervised with SLAI)
  • Zirui Lin (PhD, 2025)

Publication

(* corresponding author)

OOPSLA’26

Revisiting Path Coverage Tracing from a Node-centric View (To appear)
Heqing HUANG, Zhendong Su

ISSTA’26

DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature Database (To appear)
Meiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu, Li Li, Heqing HUANG, Ying Wang

CCS’26

ACOFuzz: Memory-Error-Sensitive Fuzzing Driven by Address-Computation-Operand-Aware Feedback Mechanism (To appear)
Yiru Zhao, Aorui Zhang, Xiaoke Wang, Aoshuang Ye, Benxiao Tang, Jinxin Ma, Lei Zhao, Heqing HUANG*

ACL’26

When Efficiency Becomes a Vulnerability: Computational Cost Attacks on WebAgents
Liang-Bo Ning, Yuchen Zhu, Heqing HUANG, Xin Wang, Yi Chang, Li Qing, Wenqi Fan
[Artifacts]

TDSC’25

ICSFuzz: Collision Detector Bug Discovery in Autonomous Driving Simulators
Weiwei Fu, Heqing Huang*, Yifan Zhang, Ke Zhang, Jin Huang, Weibin Lee, Jianping Wang.
[Artifacts]

CSUR‘25

LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights
Ze Sheng, Zhicheng Chen, Shuning Gu, Heqing Huang, Guofei Gu, Jeff Huang.

TOCS’25

GIANTSAN: Efficient Operation-Level Memory Sanitization with Segment Folding [Artifacts]
Hao Ling, Heqing Huang*, Chengpeng Wang, Yuandao Cai, Charles Zhang.

TOSEM’25

Efficient Fuzzing Infrastructure for Pointer-to-Object Association
Hao Ling, Heqing Huang*, Yuandao Cai, Charles Zhang.

ISSTA’25

KRAKEN: Program-Adaptive Parallel Fuzzing [Artifacts]
Anshunkang Zhou, Heqing Huang*, Charles Zhang.

ICSE’25

SAND: Decoupling Sanitization from Fuzzing for Low Overhead
Ziqiao Kong#, Shaohua Li#, Heqing Huang, Zhendong Su (#Equal Contribution)

ICSE’25

Mole: Efficient Crash Reproduction in Android Applications With Enforcing Necessary UI Events
Maryam Masoudian, Heqing Huang, Morteza Amini, Charles Zhang.

EMSE’25

How Far are App Secrets from Being Stolen? A Case Study on Android
Lili Wei*, Heqing Huang*, Shing-Chi Cheung, Kevin Li.

ASPLOS’24

Manta: Hybrid-Sensitive Type Inference Toward Type-Assisted Bug Detection for Stripped Binaries
Chengfeng Ye, Yuandao Cai, Anshunkang Zhou, Heqing Huang, Hao Ling, Charles Zhang.

TSE’24

Mole: Efficient Crash Reproduction in Android Applications with Enforcing Necessary UI Events
Maryam Masoudian, Heqing Huang, Morteza Amini, Charles Zhang.

ASPLOS’24b

GIANTSAN: Efficient Memory Sanitization with Segment Folding [Artifacts]
Hao Ling, Heqing Huang*, Chengpeng Wang, Yuandao Cai, Charles Zhang.
🏆 ACM SIGPLAN Best Paper Award

ASPLOS’24a

Plankton: Reconciling Binary Code and Debug Information
Anshunkang Zhou, Chengfeng Ye, Heqing Huang*, Yuandao Cai, Charles Zhang.

S&P’24b

Everything is Good for Something: Counterexample-Guided Directed Fuzzing via Likely Invariant Inference
Heqing Huang, Anshunkang Zhou, Mathias Payer, Charles Zhang.

S&P’24a

Titan: Efficient Multi-target Directed Greybox Fuzzing
Heqing Huang, Peisen Yao, Hung-Chun Chiu, Yiyuan Guo, Charles Zhang.
[Artifacts]

TDSC’23

Balance Seed Scheduling via Monte Carlo Planning
Heqing Huang, Hung-Chun Chiu, Qingkai Shi, Peisen Yao, Charles Zhang.
[Artifacts]

S&P’22

BEACON: Directed Grey-Box Fuzzing with Provable Path Pruning
Heqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao, Rongxin Wu, Charles Zhang.
[Artifacts]
🏆 Google Research Paper Award

OOPSLA’21

Program Analysis via Efficient Symbolic Abstraction
Peisen Yao, Qingkai Shi, Heqing Huang, Charles Zhang.

FSE’21

Skeletal Approximation Enumeration for SMT Solver Testing
Peisen Yao, Heqing Huang*, Wensheng Tang, Qingkai Shi, Rongxin Wu, Charles Zhang.

ISSTA’21

Fuzzing SMT Solvers via Two-Dimensional Input Space Exploration
Peisen Yao, Heqing Huang, Wensheng Tang, Qingkai Shi, Rongxin Wu, Charles Zhang.

S&P’20

Pangolin: Incremental Hybrid Fuzzing via Polyhedral Path Abstraction
Heqing Huang, Peisen Yao, Rongxin Wu, Qingkai Shi, Charles Zhang.

ISSTA’20

Fast Bit-Vector Satisfiability
Peisen Yao, Qingkai Shi, Heqing Huang, Charles Zhang.

Academic Service

Chair

Committe and Reviewer

Sub-/Co-reviewer

Teaching Service

  • CS2311 - Computer Programming (2024-25 Fall)
  • CS3402 - Database System (2024-26 Spring)

Funding and Cooperation

Our work Pangolin published in S&P 2020 has been successfully deployed in the Huawei tool-chain and detected more than 1000+ crashes/bugs! We have thus received the Huawei Distinguish Collaborator 2021 award! This is also reported by HKUST CSE department!

Bugs Hunting

Our self-built fuzzing framework (Integration of S&P’20, 22, 24, TDSC’23) has discovered more than 1000 bugs in the widely-used commercial and open-source projects, with over 100 of them assigned with CVE IDs and over $10K bounties. A partial of vulnerabilities detected can be found here. We also list the bugs found specifically for SMT theorem provers here.

Miscs