Yu JiangView profile
Associate Professor
Yu Jiang is an Associate Professor at the School of Software, Tsinghua University, China. His research focuses on software security with emphasis on fuzz testing, embedded systems, and database security. He leads the Software System Security Assurance Group which has discovered over 1,000 bugs in major system software with 300+ CVEs registered. Dr. Jiang's research interests include Software Engineering , Embedded Systems Security , and Cross-Layer Fuzzing . His work addresses vulnerabilities in operating systems, databases, communication protocols, and IoT firmware through innovative fuzzing frameworks. Key contributions include semantic-aware fuzzing for heterogeneous software stacks and learning-based vulnerability detection for embedded systems. His recent publications demonstrate strong trends in database security (Hulk, PUPPY, THANOS), ransomware defense (Fawkes, Preventing Disruption), and web security (JANUS). Research spans both theoretical advances in fuzzing techniques and practical industrial applications, with significant impact evidenced by numerous distinguished paper awards. Career Award, NSFC: 2026 Distinguished Paper Award, ISSTA: 2025 First Prize for Technical Invention, CCF: 2024 Distinguished Paper Award, USENIX Security: 2024 SIGSOFT Distinguished Paper Award, FSE: 2022 Dr. Jiang has advised over 50 graduate students including 20 PhD candidates. His research is supported by major grants including NSFC projects ($600,000 for Software Trustworthiness Construction and $350,000 for Distributed Database Reliability), Huawei ($80,000 for LLM-Powered Fuzzing), and Tencent ($120,000 for LLM-Powered Unit Testing). The Software System Security Assurance Group maintains strong industry partnerships with Huawei, Alibaba, Tencent, and Webank. The group operates cutting-edge infrastructure for fuzz testing across multiple domains including database systems, operating kernels, blockchain platforms, and industrial control systems. Current projects integrate LLM technologies with traditional fuzzing techniques to enhance vulnerability detection in complex software stacks.












