教師名錄

羅昌華

郵          箱:

職          稱:

辦公室地址:

實驗室地址:

個人簡介

羅昌華,88858cc永利官网武漢數學與智能研究院研究員、博士生導師,主要從事程序分析、軟件安全與Web安全領域的研究工作。在S&PCCSNDSSICSE等國際頂級學術會議上發表多篇一作或通訊論文。研究成果包括在關鍵基礎設施(如OpenSSL、谷歌/蘋果/火狐浏覽器、Symfony框架)中發現并推動修複上百個高危漏洞,相關工作多次獲得谷歌、蘋果等公司的公開緻謝與漏洞賞金。博士期間,作為第一作者的論文獲得ACM CCS '22最佳論文提名獎。詳情請浏覽主頁https://chluo1997.github.io/

實驗室長期招收博士、碩士研究生,歡迎本校大二、大三及保研同學提前加入課題組,參與大學生創新創業訓練計劃及其他科研競賽項目。


研究方向

漏洞檢測:發現軟件中的各種安全問題,包括内存安全、注入型漏洞、邏輯漏洞和性能漏洞等。

漏洞分析:評估漏洞的嚴重性與潛在風險,如漏洞利用、漏洞溯源等

漏洞修複:結合大模型與程序分析技術,開發自動化的漏洞修複方法等。


教育背景

88858cc永利官网,信息安全、本科

香港中文大學,計算機科學與工程,博士


工作經驗

2024/07-2024/12: 香港大學:博後

2025/02-至今:88858cc永利官网:研究員


教授課程

發表論文

[1] Chenlin Wang, Wei Meng, Changhua Luo, and Penghui Li. Predator: Directed Web Application Fuzzing for Efficient Vulnerability Validation.

The 46th IEEE Symposium on Security and Privacy (Oakland), May 2025.

[2] Jiayi Lin, Qingyu Zhang, Junzhe Li, Chenxin Sun, Hao Zhou, Changhua Luo*, and Chenxiong Qian*. Automatic Library Fuzzing through API Relation Evolvement.

In Proceedings of The 32nd Annual Network and Distributed System Security Symposium (NDSS), Feb 2025.

[3] Changhua Luo, Penghui Li, Wei Meng, Chao Zhang. Test Suites Guided Vulnerability Validation for Node.js Applications. In Proceedings of The 31st ACM Conference on Computer and Communications Security (CCS), Oct 2024.

[4] Penghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang, Changhua Luo. Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis. In Proceedings of The 45th IEEE Symposium on Security and Privacy (Oakland), May 2024.

[5] Changhua Luo, Wei Meng, Shuai Wang. Strengthening Supply Chain Security with Fine-grained Safe Patch Identification. In Proceedings of 46th International Conference on Software Engineering (ICSE), research track, April 2024.

[6] Changhua Luo, Wei Meng, Penghui Li. SelectFuzz: Efficient Directed Fuzzing with Selective Path Exploration. In Proceedings of The 44th IEEE Symposium on Security and Privacy (Oakland), May 2023.

[7] Changhua Luo, Penghui Li, Wei Meng. TChecker: Precise Static Inter-Procedural Analysis for Detecting Taint-Style Vulnerabilities in PHP Applications. In Proceedings of The 29th ACM Conference on Computer and Communications Security (CCS), Nov 2022. ACM CCS 2022 Best Paper Honorable Mention

[8] Penghui Li, Wei Meng, Kangjie Lu, Changhua Luo. On the Feasibility of Automated Built-in Function Modeling for PHP Symbolic Execution. In Proceedings of the 30th Web Conference (WWW), security track, Feb 2021.



課題科研

研究團隊

獲獎信息

Baidu
sogou