Qinying Wang

Qinying Wang

Postdoctoral Researcher

EPFL

About Me

I am a postdoctoral researcher at HexHive, EPFL, advised by Prof. Mathias Payer. I earned my Ph.D. with honour at Zhejiang University in 2024, advised by Prof. Shouling Ji. During my Ph.D., I was fortunate to collaborate with Prof. Yuan Tian (UCLA), and benefited greatly from her regular guidance.

My research spans software and systems security, with a focus on IoT and emerging connected systems. I develop techniques to identify and mitigate risks arising from complex interactions across system components and trust boundaries.

My work brings together systems research, program analysis, fuzzing, and large-scale empirical measurement, with applications in embedded and IoT systems, software systems, and AI-enabled services.

I am currently on the 2026–2027 job market and seeking faculty positions in computer security and related areas.

Recent News

  • [04/06/2026] Our paper was accepted by USENIX Security' 26!
  • [25/02/2026] Qinying joined the PC of ASE 2026 Industry Showcase!
  • [02/12/2025] Our paper was accepted by TOSEM!
  • [02/12/2025] Our paper was accepted by NDSS 2026!
  • [09/09/2025] Our paper was accepted by IEEE S&P 2026!
  • [14/08/2025] Our paper was accepted by NDSS 2026!
  • [11/07/2025] Qinying was invited to serve on the PC for USENIX Security' 26!

Interests

  • Software and system security
  • Embedded and IoT security
  • Security of AI-enabled services

Education

  • Ph.D. in Cyberspace Security, 2024

    Zhejiang University

  • Visiting Ph.D. Student, 2022 - 2023

    EPFL

  • B.E. in Information Security, 2018

    Hunan University

Publications

(2026). When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments. 35th USENIX Security Symposium (USENIX Security). Top-tier Security Conference.

Code

(2026). MPS-Fuzz: An Enhanced Fine-Grained Fuzzing Based on Units With Multiple Inputs and Outputs. IEEE Transactions on Dependable and Secure Computing, 23(2), 4195–4207. Top-tier Security Journal.

PDF

(2025). Unveiling Security Vulnerabilities in Git Large File Storage Protocol. IEEE S&P 2025. Top-tier Security Conference Distinguished Paper Award.

PDF Code

(2024). Pluggable Watermarking of Deepfake Models for Deepfake Detection. the 33rd International Joint Conference on Artificial Intelligence (IJCAI). Top-tier AI Conference.

PDF Code

(2024). SURGEON: Performant, Flexible, and Accurate Re-Hosting via Transplantation. Workshop on Binary Analysis Research (BAR'24), Distinguished Paper Award.

PDF Code

Contact