Wei Zhou

Wei Zhou

Associate Professor of Cybersecurity

Huazhong University of Science and Technology

About Me

I am an Associate Professor of the School of Cyber Science and Engineering, Huazhong University of Science and Technology. Prior to joining HUST, I received my Ph.D. degree from the University of Chinese Academy of Sciences, under supervision of Prof.Yuqing Zhang in 2021. I have also been visiting scholar in Prof.Peng Liu’s cybersecurity lab at Penn State from 2018 to 2020.

My research interests cover a wide range of systems security, including trusted computing and IoT systems security. I am especially interested in developing automatic tools to detect and exploit previously unknown vulnerabilities in IoT firmware and platforms.

Opening:

I am looking for self-motivated master or Ph.D. students to work on cybersecurity problems, especially IoT security. Please send me your CV if interested. Candidates are expected to have a solid background in system programming and operating systems. If you are a HUST (undergraduate/master) student with interests in my areas, my lab is also welcome.

Interests
  • IoT Security
  • System Security
  • Binary Analysis
Education
  • PhD in Information Security, 2016

    University of Chinese Academy of Sciences

  • BSc in Information Security, 2012

    Xidian University

Recent Publications

Quickly discover relevant content by filtering publications.
(2024). Unveiling IoT Security in Reality: A Firmware-Centric Journey. Security ‘24.

(2023). CEFI: Command Execution Flow Integrity for Embedded Devices. DIMVA 2023.

(2023). Understanding MPU Usage in Microcontroller-based Systems in the Wild. BAR'23.

(2023). Good Motive but Bad Design: Pitfalls in MPU Usage in Embedded Systems in the Wild. Black Hat (Eurpoe) 2022.

(2022). What Your Firmware Tells You Is Not How You Should Emulate It: A Specification-Guided Approach for Firmware Emulation. 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS), CCF-A.

(2021). Automatic Firmware Emulation through Invalidity-guided Knowledge Inference. 30th USENIX Security Symposium (Usenix), CCF-A.

PDF Cite Code Project Slides

(2021). Reviewing IoT Security via Logic Bugs in IoT Platforms and Systems. IEEE Internet of Things Journal.

Cite

(2019). Identifying Privilege Separation Vulnerabilities in IoT Firmware with Symbolic Execution. European Symposium on Research in Computer Security 2019 (ESORICS), CCF-B.

Cite

(2019). Discovering and understanding the security hazards in the interactions between iot devices, mobile apps, and clouds on smart home platforms. 28th USENIX Security Symposium (Usenix), CCF-A.

PDF Cite Project

(2018). The Effect of IoT New Features on Security and Privacy: New Threats, Existing Solutions, and Challenges Yet to Be Solved. IEEE Internet of Things Journal, ESI Highly Cited Paper(top 1%).

Cite

(2017). 物联网安全综述(Survey of Internet of things security). 计算机研究与发展, 入选领跑者5000-中国精品科技期刊顶尖学术论文平台.

Cite

Employment

 
 
 
 
 
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Associate Professor of Cybersecurity
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Jul 2021 – Present Wuhan, China
 
 
 
 
 
College of Information Sciences and Technology, The Pennsylvania State University
Visiting Scholar
Oct 2018 – Oct 2020 State College

Research Projects

*
IoT Firmware Emulator

IoT Firmware Emulator

A Universal MCU Firmware Emulator for Dynamic Analysis without Any Hardware Dependence

Security Analysis of Smart Home Platform Interactions

Security Analysis of Smart Home Platform Interactions

Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home Platforms

Contact