Shengtuo Hu
Security-focused Software Engineer, Ph.D. in Computer Science
Summary
Security-focused software engineer with a Ph.D. in Computer Science and 5+ years of experience building security tooling, program analysis infrastructure, and large-scale detection systems. Strong background in vulnerability discovery, fuzzing, and network protocol security.
- Languages/Tools
- C/C++, Python, Rust, Go, Java, Bazel/Buck, Docker, LLVM, Google ADK
- Skills
- Fuzzing, Program Analysis, Secure SDLC, Vulnerability Discovery, Network and System Security, LLM Agents
Experience
Principal Engineer, Palo Alto Networks, Santa Clara, CA
Aug 2024 – PresentProgram analysis, developer tooling, and LLM-agent platforms for network security products.
Backend Software Engineer (Senior), ByteDance, San Jose, CA
Jan 2023 – Aug 2024Large-scale security incident detection and analysis infrastructure.
Research Scientist, Meta, Menlo Park, CA
Oct 2022 – Jan 2023Security and fuzzing research.
Software Engineer Intern, Product Security, Facebook, Remote
Jun 2021 – Aug 2021Large-scale fuzzing and automated vulnerability discovery for C/C++ codebases.
Projects
Whole Program LLVM in Rust, rllvm
May 2022 – PresentA Rust utility that generates whole-program LLVM bitcode for large codebases, enabling downstream static analysis.
A Flexible Grammar Mutator, AFL++, Google Summer of Code 2020
Jun 2020 – Presentgithub.com/AFLplusplus/Grammar-Mutator
A grammar mutator for AFL++ with tree-based mutation and trimming for structured-input fuzzing.
Education
University of Michigan, Ann Arbor, MI — Ph.D. in Computer Science and Engineering
Aug 2017 – Sep 2022Dissertation: Securing Connected and Automated Vehicle through Proactive Vulnerability Analysis and Security Enhancement
University of Michigan, Ann Arbor, MI — M.S. in Computer Science and Engineering
Aug 2017 – Apr 2022Tongji University, Shanghai, China — B.Eng. in Software Engineering
Sep 2012 – Jul 2016
Publications
A method, device, equipment, medium and product for processing alarm events
Gatekeeper: A Gateway-based Broadcast Authentication Protocol for the In-Vehicle Ethernet
On Adversarial Robustness of Trajectory Prediction for Autonomous Vehicles
Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols
CVShield: Guarding Sensor Data in Connected Vehicle with Trusted Execution Environment
CommPact: Evaluating the Feasibility of Autonomous Vehicle Contracts
AutoFlowLeaker: Circumventing Web Censorship through Automation Services
Are HTTP/2 Servers Ready Yet?
Links to papers, code and slides are on the publications page.
Service
Vehicle Security and Privacy (VehicleSec) Technical Program Committee
2024–2026USENIX Security Artifact Evaluation Committee
2022–2026Cyber Security in Cars Workshop (CSCS) Program Committee
2025IEEE Transactions on Network and Service Management (TNSM) Reviewer
2026IEEE Transactions on Dependable and Secure Computing (TDSC) Reviewer
2024–2026IEEE Transactions on Intelligent Transportation Systems (ITS) Reviewer
2024–2026IEEE/ACM Transactions on Networking (ToN) Reviewer
2024–2025ACM Multimedia (MM) Reviewer
2024Privacy Enhancing Technologies Symposium (PETS) External Reviewer
2022UMich Multidisciplinary Design Program (MDP) Undergraduate Supervisor
2021–2022
Honors & Awards
AutoSec Workshop Best Paper Award
2020Shanghai Excellent Graduate, Shanghai Municipal Education Commission (top 5%)
2016Google Excellence Scholarship, Google (top 58 students nationwide in China)
2015National Scholarship, Ministry of Education, China (top 0.2% nationwide)
2013, 2014