[Preprint] Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Bonan Ruan (阮博男) is a third-year Ph.D. candidate at the School of Computing, National University of Singapore (NUS), advised by Prof. Zhenkai Liang. His research sits at the intersection of LLM-based agent security, system security, and software security. He received his master's degree from NUS and his bachelor's degree from Tongji University. Before beginning his master's degree, he worked as a security researcher at Xingyun Lab of NSFOCUS, where he focused on cloud-native security research and the incubation of innovative security products, and co-authored the book Cloud Native Security: Practice and Architecture. His research has appeared at ASE, USENIX Security, ICLR, and RAID, and has received the Best Practical Paper Award at RAID and a Distinguished Paper Award at USENIX Security. He has also presented his work at Black Hat Asia, KCon, CIS, and OpenInfra Days Asia. He created Metarget, an open-source framework for automatically constructing vulnerable cloud-native infrastructures; the project has received more than 1,400 GitHub stars, is listed in the CNCF Cloud Native Landscape, and is used in industry.
Bonan Ruan, Yeqi Fu, Chuqi Zhang, Jiahao Liu, Jun Zeng, Zhenkai Liang
arXiv 2026
Bonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang, Kaihang Ji, Zhenkai Liang
40th IEEE/ACM International Conference on Automated Software Engineering
Bonan Ruan, Jiahao Liu, Chuqi Zhang, Zhenkai Liang
27th International Symposium on Research in Attacks, Intrusions and Defenses
Best Practical Paper Award · Black Hat Asia 2025 Briefings
Bonan Ruan, Jiahao Liu, Weibo Zhao, Zhenkai Liang
39th IEEE/ACM International Conference on Automated Software Engineering, Tool Demonstrations