Research Portfolio

Security Research | Malware Analysis | AI Safety | COMPASS Lab @ SUSTech

🛡️ MirrorShield: Cross-Architecture Linux Malware Analysis

MirrorShield: Cross-Architecture Linux Malware Analysis via Lightweight Emulation and LLM Under Review

Abstract: Existing Linux malware analysis tools often struggle to scale across diverse CPU architectures, while many automated detectors provide only coarse-grained verdicts with limited evidence for forensic analysis. We present MirrorShield, a lightweight dynamic analysis framework that executes multi-architecture Linux binaries via containerized QEMU user-mode emulation and collects syscall-level telemetry through an eBPF-based kernel monitor.

QEMU eBPF LLM Docker Multi-Architecture Linux Security Malware Analysis Forensic Analysis
94.7%
Detection Accuracy
0.946
F1 Score
80.7%
Evidence Match
11
CPU Architectures

🤖 Toward Trustworthy Agentic Systems

Toward Trustworthy Agentic Systems Research Plan

Research Statement: AI agents are now used in many critical tasks. This creates clear risks: