[Preprint] Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Bonan Ruan (阮博男) is a Ph.D. candidate at the School of Computing, National University of Singapore (NUS), advised by Prof. Zhenkai Liang. His research focuses on securing LLM-based agents operating in real-world software ecosystems.
He studies how security risks emerge and propagate through agent interactions with tools, skills, workflows, and other external components, and develops practical techniques to understand, detect, and mitigate these risks. His broader research interests include systems security, software supply chain security, vulnerability analysis, and program analysis.
His research has appeared at ASE, USENIX Security, ICLR, and RAID, receiving a Best Practical Paper Award at RAID and a Distinguished Paper Award at USENIX Security. He has also presented his work at industry conferences including Black Hat Asia, KCon, and OpenInfra Days Asia.
Interested in research collaboration or discussion? Feel free to get in touch.
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Yuheng Tang*, Kaijie Zhu*, Bonan Ruan, Chuqi Zhang, Michael Yang, Hongwei Li, Suyue Guo, Tianneng Shi, Zekun Li, Christopher Kruegel, Giovanni Vigna, Dawn Song, William Yang Wang, Lun Wang, Yangruibo Ding, Zhenkai Liang, Wenbo Guo
14th International Conference on Learning Representations
Bonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang, Kaihang Ji, Zhenkai Liang
40th IEEE/ACM International Conference on Automated Software Engineering
Yuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu, Manuel Rigger, Roland Yap, Zhenkai Liang
34th USENIX Security Symposium
Distinguished Paper Award
Bonan Ruan, Jiahao Liu, Chuqi Zhang, Zhenkai Liang
27th International Symposium on Research in Attacks, Intrusions and Defenses
Best Practical Paper Award · Black Hat Asia 2025 Briefings