Cen Zhang

Cen Zhang (张岑)

Security Researcher MSEC FORGE Labs MDASH engine DARPA AIxCC Winner

I am a Senior Security Researcher at Microsoft Security's FORGE Lab, led by Taesoo Kim, where I build AI-powered systems for automated vulnerability discovery and the protection of critical software infrastructure. Before joining Microsoft, I was a postdoctoral researcher at Georgia Tech and Nanyang Technological University and served as the Java subteam leader of Team Atlanta, the first-place winner of DARPA's AI Cyber Challenge.

My current research sits at the intersection of AI, security, and program analysis, with a focus on automated vulnerability detection and mitigation. It spans AI-powered vulnerability scanning through the MDASH engine, fuzz-driver generation, firmware analysis, fuzzing, and static and dynamic program analysis.

I love my family, research, Dota 2, traveling, and dreaming. :)

News

  • Aug 2026 Our paper "COIN: A Live, Large-scale Benchmark for Semantics-to-Input Code Reasoning" is accepted to the EMNLP 2026 Main Conference.
  • Aug 2026 Our paper "OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security" is presented at WOOT 2026.
  • May 2026 Our paper "SoK: DARPA's AI Cyber Challenge (AIxCC)" was accepted to USENIX Security 2026. Distinguished Paper Award Runner-Up
  • May 2026 Our paper "Contextualizing Sink Knowledge for Java Vulnerability Discovery" was presented at IEEE S&P 2026.
  • Aug 2025 Our work "User-Space Dependency-Aware Rehosting for Linux-Based Firmware Binaries" is accepted by NDSS 2026.

Publications

You can also find my articles on Google Scholar. (* = co-first author)

2026

2025

  • ATLANTIS: AI-driven Threat Localization, Analysis, and Triage Intelligence System
    Team Atlanta (Cen Zhang works as the Atlantis-Java sub-team leader)
    Arxiv 2025 Technical report for DARPA AIxCC Competition 1st Place Winner system.
  • VULCANBOOST: Boosting ReDoS Fixes through Symbolic Representation and Feature Normalization
    Yeting Li, Yecheng Sun, Zhiwu Xu, Haiming Chen, Xinyi Wang, Hengyu Yang, Huina Chao, Cen Zhang, Yang Xiao, Yanyan Zou, Feng Li, Wei Huo
    USENIX Security 2025 Honorable Mention Award Recognition: Top 6% of accepted papers (25/407)
  • Smart Contract Fuzzing Towards Profitable Vulnerabilities
    Ziqiao Kong, Cen Zhang, Maoyi Xie, Ming Hu, Yue Xue, Ye Liu, Haijun Wang, Yang Liu
    FSE 2025
  • LLM Based Input Space Partitioning Testing for Library APIs
    Jiageng Li, Zhen Dong, Chong Wang, Haozhen You, Cen Zhang, Yang Liu, Xin Peng
    ICSE 2025

2024

  • Xiaohan Zhang*, Cen Zhang*, Xinghua Li, Zhengjie Du, Bing Mao, Yuekang Li, Yaowen Zheng, Yeting Li, Li Pan, Yang Liu, Robert Deng
    ACM Computing Surveys
  • Semantic-Enhanced Indirect Call Analysis with Large Language Models
    Baijun Cheng, Cen Zhang, Kailong Wang, Ling Shi, Yang Liu, Haoyu Wang, Yao Guo, Xiangqun Chen
    ASE 2024
  • Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma, Xiaofei Xie, Yuekang Li, Limin Sun, Yang Liu
    ISSTA 2024
  • Bugs in Pods: Understanding Bugs in Container Runtime Systems
    Jiongchi Yu, Xiaofei Xie, Cen Zhang, Sen Chen, Yuekang Li, Wenbo Shen
    ISSTA 2024
  • Achilles' Heel of JS Engines: Exploiting Modern Browsers During WASM Execution
    Bohan Liu, Zong Cao, Zheng Wang, Yeqi Fu, Cen Zhang
    Black Hat USA 2024
  • DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi Applications
    Maoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang, Yebo Feng, Haijun Wang, Yue Xue, Hao Zhang, Ye Liu, Yang Liu
    ISSTA 2024
  • Zhengjie Du, Yuekang Li, Yaowen Zheng, Xiaohan Zhang, Cen Zhang, Yi Liu, Sheikh Mahbub Habib, Xinghua Li, Linzhang Wang, Yang Liu, Bing Mao
    WWW 2024
  • Semantic-Enhanced Static Vulnerability Detection in Baseband Firmware
    Yiming Liu, Cen Zhang, Feng Li, Yeting Li, Jianhua Zhou, Jian Wang, Lanlan Zhan, Yang Liu, Wei Huo
    ICSE 2024 ACM SIGSOFT Distinguished Paper Award Acceptance Rate: 8% (65/808), 10K+ USD Bug Bounty

2023

  • Aster: Automatic Speech Recognition System Accessibility Testing for Stutterers
    Yi Liu, Yuekang Li, Gelei Deng, Yao Du, Cen Zhang, Chengwei Liu, Yeting Li, Lei Ma, Yang Liu
    ASE 2023
  • EndWatch: A Practical Method for Detecting Non-Termination in Real-World Software
    Yao Zhang, Xiaofei Xie, Yi Li, Sen Chen, Cen Zhang, Xiaohong Li
    ASE 2023 ACM SIGSOFT Distinguished Paper Award
  • Xinyi Wang*, Cen Zhang*, Yeting Li, Zhiwu Xu, Shuailin Huang, Yi Liu, Yican Yao, Yang Xiao, Yanyan Zou, Yang Liu, and Wei Huo
    IEEE S&P 2023
  • Cen Zhang, Yuekang Li, Hao Zhou, Xiaohan Zhang, Yaowen Zheng, Xian Zhan, Xiaofei Xie, Xiapu Luo, Xinghua Li, Yang Liu, and Sheikh Mahbub Habib
    USENIX Security 2023

2022

2021

2020

  • Ori: A Greybox Fuzzer for SOME/IP Protocols in Automotive Ethernet
    Yuekang Li, Hongxu Chen, Cen Zhang, Siyang Xiong, Chaoyi Liu, and Yi Wang
    APSEC 2020 Best Paper Award in Early Research Achievement Track
  • MUZZ: Thread-aware grey-box fuzzing for effective bug hunting in multithreaded programs
    Hongxu Chen, Shengjian Guo, Yinxing Xue, Yulei Sui, Cen Zhang, Yuekang Li, Haijun Wang, and Yang Liu
    USENIX Security 2020

2019

  • BiFF: An Effective Binary Fuzzing Framework with Cross-Architecture Support
    Cen Zhang, Yuekang Li, Hongxu Chen, Anh Quynh Nguyen, Yang Liu
    NASAC 2019 First Award in Software Prototype Competition Free Track
  • Cerebro: context-aware adaptive fuzzing for effective vulnerability detection
    Yuekang Li, Yinxing Xue, Hongxu Chen, Xiuheng Wu, Cen Zhang, Xiaofei Xie, Haijun Wang, and Yang Liu
    ESEC/FSE 2019

Awards

  • Distinguished Paper Award Runner-Up — USENIX Security 2026 (22 of 362 accepted papers)
  • AIxCC 1st Place Winner — DARPA AI Cyber Challenge
  • Honorable Mention — USENIX Security 2025 (Top 6%, 25/407 accepted papers)
  • Best Paper Award for Thrust B Projects — Continental-NTU Corporate Lab 2024
  • ACM SIGSOFT Distinguished Paper Award — ICSE 2024
  • ACM SIGSOFT Distinguished Paper Award — ASE 2023
  • Best Paper Award of Year 2021 — Most Influential Research Paper Election of Ant Finance
  • Best Early-Research-Achievement Paper — APSEC 2020
  • 1st Award in Prototype Competition (freestyle track) — NASAC 2019

Services

Program Committee

2027: ICSE · FSE
2026: ASE (Research, NIER) · ACSAC
2025: ASE (Research, NIER) · ACSAC · ISSTA (EXPRESS) · ICECCS · Oakland (HMISA) · IJCAI (Survey) · Internetware (Tool Demo) · ICDM (LLM4Sec) · EuroSys (Shadow) · MSR (Junior)

Journal Reviewing

TOSEM · TSE · TIFS · IEEE TR · TDSC

Open Source Tools

  • Atlantis-Java — The sinkpoint-centered Java vulnerability detection subsystem of Team Atlanta's DARPA AIxCC-winning CRS [github]
  • OSS-CRS — An OpenSSF Sandbox Project for orchestrating autonomous CRSs on OSS-Fuzz-style targets — bug-finding, bug-fixing, triage, and ensembles, all behind one CLI [site] [github]
  • fuzzdrivergpt — A GPT-Based Fuzz Driver Generator [github]