![]() |
刘承威(Chengwei Liu)
教授(Full Professor) 密码与网络空间安全学院,南开大学 津南校区计算机学院大楼,天津海河教育园区同砚路38号,天津,中国,300350 chengwei.liu@nankai.edu.cn |
本人目前在南开大学密码与网络空间安全学院任教授(南开大学)。本人是 NKSSecLab 成员,实验室由 陈森 教授负责。本人同时隶属于 刘哲理 教授课题组。
研究方向主要聚焦于软件安全,包括程序分析、开源软件安全、软件供应链安全、开源治理、新型智能体软件安全与治理等。
此前,本人于南洋理工大学(南洋理工大学)计算与数据科学学院获得博士学位并从事博士后研究,导师为 刘杨 教授。
在此之前,本人于2016年获得南京航空航天大学学士学位,并于2019年获得硕士学位,导师为 杨志斌 教授(南京航空航天大学)。
2026年6月:论文 “ATLAS: Agentic Taxonomy of Large-Scale Software Ecosystems” 被 ASE 2026 接收!
2026年5月:论文 “CaVulner: Automated Context-Aware Identification of Vulnerable Versions” 被 Internetware 2026 接收!
2026年5月:论文 “CCMG: Enhancing Conventional Commit Message Generation with Hierarchical Context” 被 TSE 接收!
2026年4月:论文 “RustDAP: Lightweight Rust Vulnerability Detection Method via LLM-based Data Augmentation and Semantic-Structural Prompting” 被 COMPSAC 2026 接收!
2026年3月:论文 “Break to Adapt: Knowledge-Based Updates of Breaking Dependencies in JavaScript” 被 FSE 2026 接收!
2026年3月:论文 “One Trigger, Multiple Victims: Clean-Label Neighborhood Backdoor Attacks on Graph Neural Networks” 被 TIFS 接收!
2026年3月:加入南开大学任教授!目前有博士后、博士与硕士招生名额,欢迎邮件联系。
2026年2月:论文 “Causality-aware Safety Testing for Autonomous Driving Systems” 被 TSE 接收!
2026年1月:论文 “Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework” 被 USENIX Security 2026 接收!
2026年1月:论文 “Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages” 被 WWW 2026 接收!
2025年12月:论文 “Scratching the Iceberg: Unveiling the Outdated Third-Party Native Libraries in Android Apps” 被 SANER 2026 接收!
2025年11月:工具 IntelliRadar 获得 “软件研究成果原型系统竞赛” 一等奖(ChinaSoft 2025,武汉)。
2025年10月:论文 “IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence” 被 ICSE 2026 接收!
2025年10月:论文 “Semantic-Enhanced Automatic Refinement of Architecture Recovery Results Using LLMs” 被 ICSE 2026 接收!
2025年9月:论文 “Towards Secure Code Generation with LLMs: A Study on Common Weakness Enumeration” 被 TSE(CCF-A) 接收!
2025年9月:论文 “DroidNative: A Greedy-Constructed Large-Scale Indexing for Android Native Libraries” 被 ASE-AMOBILE 2025 接收!
2025年9月:论文 “BinStruct: Binary Structure Recovery Combining Static Analysis and Semantics” 被 ASE2025(CCF-A) 接收!
2025年8月:论文 “Vulnerability-Affected Versions Identification: How Far Are We?” 被 ASE2025(CCF-A) 接收!
2025年7月:论文 “Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management” 被 TSE(CCF-A) 接收!
2025年6月:首届 Software Genomics 研讨会在挪威特隆赫姆 FSE25 成功举办!
2025年5月:论文 “Why the Proof Fails in Different Versions of Theorem Provers: An Empirical Study of Compatibility Issues in Isabelle” 获 FSE2025(CCF-A)ACM SIGSOFT 杰出论文奖。
2025年3月:论文 “Doctor: Optimizing Container Rebuild Efficiency by Instruction Re-Orchestration” 被 ISSTA 2025 接收!
2025年3月:论文 “Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management” 被 ISSTA 2025 接收!
2025年3月:论文 “Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis” 被 FSE 2025-IVR 接收!
2025年3月:论文 “Demystifying Rust Unstable Features at Ecosystem Scale: Evolution, Propagation, and Mitigation” 被 TSE 接收!
2025年1月:论文 “Characterizing and Detecting Python Version Incompatibilities Caused by Inconsistent Version Specifications” 被 JSS 接收!
2025年1月:论文 “Why the Proof Fails in Different Versions of Theorem Provers: An Empirical Study of Compatibility Issues in Isabelle” 被 FSE 2025 接收!
2024年12月:论文 “Towards Unveiling Vulnerability Remediation Tactics from OSS Community” 被 ICSE-APR 2025 接收!
2024年8月:论文 “The Software Genome Project: Unraveling Software Through Genetic Principles” 被 ASE 2024 NIER Track 接收!
2024年5月:获南洋理工大学 Research Assistant Professor 职称!感谢导师、前辈、团队成员与合作者的认可和支持!
2024年1月:论文 “FedMut: Generalized Federated Learning via Stochastic Mutation” 入选 AAAI 2024(CCF-A) Oral Presentation!
2023年12月:论文 “Catch the Butterfly: Peeking into the Terms and Conflicts among SPDX Licenses” 被 SANER 2024(CCF-B) 接收!
2023年12月:论文 “Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem” 被 ICSE 2024(CCF-A) 接收!
2023年12月:论文 “ModuleGuard: Understanding and Detecting Module Conflicts in Python Ecosystem” 被 ICSE 2024(CCF-A) 接收!
2023年12月:论文 “FedMut: Generalized Federated Learning via Stochastic Mutation” 被 AAAI 2024(CCF-A) 接收!
2023年11月:在 Arxiv 发布研究设想 “The Software Genome Project: Venture to the Genomic Pathways of Open Source Software and Its Applications”,欢迎相关方向的合作!
2023年8月:论文 “Demystifying Compiler Unstable Feature Usage and Impacts in the Rust Ecosystem” 被 ICSE 2024(CCF-A) 接收!
2023年7月:论文 “Software Architecture Recovery with Information Fusion” 被 FSE 2023(CCF-A) 接收!
2023年7月:论文 “Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java Projects” 被 FSE 2023(CCF-A) 接收!
2023年7月:论文 “Demystifying the Composition and Code Reuse in Solidity Smart Contracts” 被 FSE 2023(CCF-A) 接收!
2023年7月:论文 “Comparison and Evaluation on Static Application Security Testing (SAST) Tools for Java” 被 FSE 2023(CCF-A) 接收!
2023年7月:论文 “Mitigating Persistence of Open-Source Vulnerabilities in Maven Ecosystem” 被 ASE 2023(CCF-A) 接收!
2023年7月:论文 “Who is the Real Hero? Measuring Developer Contribution via Multi-dimensional Data Integration” 被 ASE 2023(CCF-A) 接收!
2023年7月:论文 “An Empirical Study of Malicious Code In PyPI Ecosystem” 被 ASE 2023(CCF-A) 接收!
2023年7月:论文 “Aster: Automatic Speech Recognition System Accessibility Testing for Stutterers” 被 ASE 2023(CCF-A) 接收!
2023年7月:获得南洋理工大学博士学位!
2023年3月:论文 “Ambush from All Sides: Understanding Security Threats in Open-Source Software CI/CD Pipelines” 被 TDSC(CCF-A) 接收!
2023年2月:论文 “Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java Projects” 获 ICSE 2023(CCF-A)ACM SIGSOFT 杰出论文奖!
2023年1月:论文 “A Comprehensive Study on Quality Assurance Tools for Java” 被 ISSTA 2023(CCF-A) 接收!
2022年12月:论文 “Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java Projects” 被 ICSE 2023(CCF-A) 接收!
2022年10月:论文 “Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic Differencing” 获 ASE 2022(CCF-A)ACM SIGSOFT 杰出论文奖!
2022年7月:论文 “Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic Differencing for Java” 被 ASE 2022(CCF-A) 接收!
2022年7月:论文 “Towards Understanding Third-party Library Dependency in C/C++ Ecosystem” 被 ASE 2022(CCF-A) 有条件接收!
2022年7月:受复旦大学 CodeWisdom 邀请作 “浅析 NPM 生态系统中的开源供应链安全” 主题报告!
2021年12月:论文 “Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM Ecosystem” 被 ICSE 2022(CCF-A) 接收!
会议主席:
• ASE2026 Software Genomics Workshop
• FSE2025 Software Genomics Workshop
程序委员会(PC):
• ASE2026 Journal-First Track
• ICSE2027 Research Track
• FSE2027 Research Track
• ICSE2026 Research Track
• FSE2026 New Ideas and Vision Track
• AIware2026 Main Track
• ICSME2026 Research Papers Track, Visions and Emerging Results Track
• LLMSC2026 Program Committee
• FORGE2026 Data and Benchmarking Track
• ICSE2025 Artifact Evaluation Track
• ACSAC2025 Program Committee
• MSR2025 Junior Program Committee
• ECOOP2025 Artifact Evaluation Track
• LLMSC2025 Program Committee
• ASE2024 Industry Showcase Track
• ACSAC2024 Program Committee
• MSR2024 Junior Program Committee
• ECOOP2024 Extended Reviewer Committee, Artifact Evaluation Track
期刊审稿人:
• IEEE Transactions on Software Engineering (TSE)
• ACM Transactions on Software Engineering and Methodology (TOSEM)
• IEEE Transactions on Dependable and Secure Computing (TDSC)
• IEEE Transactions on Information Forensics and Security (TIFS)
• Empirical Software Engineering (EMSE)
• Journal of Software Maintenance and Evolution: Research and Practice (JSME)
• Automated Software Engineering (ASEJ)
• Cybersecurity
• 2024年春:SZ2006 / CZ2006 客座讲师
• 2023年秋:SZ2006 / CZ2006 Tutorial讲师
• 2019年秋至2021年秋:SZ2002、SZ2006、CZ2006、CZ3003 助教(实验课指导)

