Student Security Portfolio

Web Pentesting, Agent Security, and Vulnerability Research.

Cybersecurity student focused on web exploitation, access-control flaws, agent offense and defense, and responsible disclosure. This preview intentionally redacts target details, payloads, endpoints, and personal identifiers.

FocusAgent Security
Publications2 arXiv Preprints
Public Records6 EvoHunt CVEs
01

Profile

Security work grounded in real systems, careful validation, and responsible public reporting.

I am a security-focused computing student with hands-on work across university systems, especially identity flows, student-service platforms, and legacy web applications.

The public version should emphasize classes of findings and reporting discipline rather than raw exploit detail. That makes the page stronger and safer at the same time.

Current direction: web pentesting, agent offense and defense, vulnerability research, traditional visual algorithms such as KCF, introductory open-source research, and turning private reports into clean public case studies.

My work spans hands-on vulnerability research and research on the reliability and security of LLM agents operating through real environments.

Collaborators Liyi Zhou
Ziyue Wang

I collaborate with Dr. Liyi Zhou and his PhD student, Ziyue Wang, on the security and reliability of LLM agents. Our 2026 work includes EnvTrustBench and EvoHunt.

02

Publications

03

Vulnerability Reports

Public and private vulnerability reporting.

Private ReportsCampus Systems

Nine responsibly reported findings across SSO, library, leave-management, OA, and other campus web systems.

Identity and Verification FlowsAuth logic

Reported weaknesses in account and verification flows, including abusive verification paths and exposure in account-related records.

Student-Service Access ControlIDOR / authz

Reported access-control issues affecting leave-management and booking systems, where personal or workflow data could be returned across users.

Legacy Campus Web AppsXSS / exposure

Documented XSS-class issues, guest-access mistakes, and file-exposure problems in older campus platforms.

Recognition

An institutional certificate recognizes vulnerability reporting and remediation support. Technical details, identifiers, and reproduction steps remain private.

04

Education

EducationAcademic Study
University of SydneyCurrent

Master of Computer Science.

Dalian Maritime University2020-2024

Electronic Information Engineering student.

Campus ExperienceCompetitions & Leadership
Nexus CTF2026

7th place at the University of Sydney.

HackMac2026

4th place at Macquarie University.

Qihang Computer Society2020-2024

Head of the Network Security Department at Dalian Maritime University.