Zhiyun Qian is the Everett and Imogene Ross Professor in the Department of Computer Science and Engineering at the University of California Riverside. His research bridges academic security research with practical hacking techniques, focusing on vulnerability discovery and analysis across operating systems, networks, and mobile platforms. His primary research interests include: System security: Automated cyber attacks/defenses, kernel vulnerability discovery, and security tool development Network security: TCP side channels, multi-path TCP flaws, and firewall evasion techniques AI/ML applications for security: LLM-integrated static analysis and reinforcement-learning-based fuzzing His work has led to critical discoveries including unfixable TCP side channel vulnerabilities (CVE-2016-5696) recognized with GeekPwn awards. His research methodology combines program analysis, reverse engineering, fuzzing, model checking, and machine learning to build practical security systems. Notable scientific awards include: GeekPwn 2016 most creative idea award Geekpwn 2017 winner award Applied Networking Research Prize Professor Qian actively mentors students in security competitions including Pwn2Own and GeekPwn. He serves on prestigious program committees including IEEE Security and Privacy (Oakland), ACM CCS, and USENIX Security. His teaching portfolio includes graduate courses CS 254 (Network Security) and CS 255 (Computer Security), along with undergraduate courses CS 153 (Operating Systems) and CS 165 (Computer Security). He leads the SecLab research group at UCR (GitHub: seclab-ucr, 3824★) developing security tools for kernel and Android ecosystems. Current projects focus on LLM-enhanced static analysis, precise vulnerability detection, and automated patch testing.














