[Preprint] Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Bonan Ruan (阮博男) is a Ph.D. candidate at the School of Computing, National University of Singapore (NUS), advised by Prof. Zhenkai Liang. His research sits at the intersection of LLM-based agent security, system security, and software security. He received his master's degree from NUS and his bachelor's degree from Tongji University. Before beginning his master's degree, he worked as a security researcher at NSFOCUS, where he researched cloud-native security, helped incubate new security products, and co-authored the book Cloud Native Security: Practice and Architecture. His research has appeared at ASE, USENIX Security, ICLR, and RAID, and has received the Best Practical Paper Award at RAID and a Distinguished Paper Award at USENIX Security. He has also presented his work at Black Hat Asia, KCon, CIS, and OpenInfra Days Asia. He created Metarget, an open-source framework for constructing vulnerable cloud-native infrastructures; the project has received 1.4K+ GitHub stars, is listed in the CNCF Cloud Native Landscape, and is used in industry.
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Yuheng Tang*, Kaijie Zhu*, Bonan Ruan, Chuqi Zhang, Michael Yang, Hongwei Li, Suyue Guo, Tianneng Shi, Zekun Li, Christopher Kruegel, Giovanni Vigna, Dawn Song, William Yang Wang, Lun Wang, Yangruibo Ding, Zhenkai Liang, Wenbo Guo
14th International Conference on Learning Representations
Bonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang, Kaihang Ji, Zhenkai Liang
40th IEEE/ACM International Conference on Automated Software Engineering
Yuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu, Manuel Rigger, Roland Yap, Zhenkai Liang
34th USENIX Security Symposium
Distinguished Paper Award
Bonan Ruan, Jiahao Liu, Chuqi Zhang, Zhenkai Liang
27th International Symposium on Research in Attacks, Intrusions and Defenses
Best Practical Paper Award · Black Hat Asia 2025 Briefings