Shengtuo Hu

Security-focused Software Engineer, Ph.D. in Computer Science

Summary

Security-focused software engineer with a Ph.D. in Computer Science and 5+ years of experience building security tooling, program analysis infrastructure, and large-scale detection systems. Strong background in vulnerability discovery, fuzzing, and network protocol security.

Languages/Tools
C/C++, Python, Rust, Go, Java, Bazel/Buck, Docker, LLVM, Google ADK
Skills
Fuzzing, Program Analysis, Secure SDLC, Vulnerability Discovery, Network and System Security, LLM Agents

Experience

  1. Principal Engineer, Palo Alto Networks, Santa Clara, CA

    Aug 2024 – Present

    Program analysis, developer tooling, and LLM-agent platforms for network security products.

  2. Backend Software Engineer (Senior), ByteDance, San Jose, CA

    Jan 2023 – Aug 2024

    Large-scale security incident detection and analysis infrastructure.

  3. Research Scientist, Meta, Menlo Park, CA

    Oct 2022 – Jan 2023

    Security and fuzzing research.

  4. Software Engineer Intern, Product Security, Facebook, Remote

    Jun 2021 – Aug 2021

    Large-scale fuzzing and automated vulnerability discovery for C/C++ codebases.

Projects

  1. Whole Program LLVM in Rust, rllvm

    May 2022 – Present

    A Rust utility that generates whole-program LLVM bitcode for large codebases, enabling downstream static analysis.

  2. A Flexible Grammar Mutator, AFL++, Google Summer of Code 2020

    Jun 2020 – Present

    A grammar mutator for AFL++ with tree-based mutation and trimming for structured-input fuzzing.

Education

  • University of Michigan, Ann Arbor, MI — Ph.D. in Computer Science and Engineering

    Aug 2017 – Sep 2022
  • University of Michigan, Ann Arbor, MI — M.S. in Computer Science and Engineering

    Aug 2017 – Apr 2022
  • Tongji University, Shanghai, China — B.Eng. in Software Engineering

    Sep 2012 – Jul 2016

Publications

  1. A method, device, equipment, medium and product for processing alarm events

    Weifeng Peng, Shengtuo Hu, Xiaowei Chen, Zhaoshuo Bi, Yunzhe Liu, and Jin Zhong. Patent CN119537159A, 2025

  2. Gatekeeper: A Gateway-based Broadcast Authentication Protocol for the In-Vehicle Ethernet

    Shengtuo Hu, Qingzhao Zhang, André Weimerskirch, and Z. Morley Mao. ACM ASIA Conference on Computer and Communications Security (AsiaCCS 2022)

  3. On Adversarial Robustness of Trajectory Prediction for Autonomous Vehicles

    Qingzhao Zhang, Shengtuo Hu, Jiachen Sun, Qi Alfred Chen, and Z. Morley Mao. IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR 2022)

  4. Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols

    Shengtuo Hu, Qi Alfred Chen, Jiachen Sun, Yiheng Feng, Z. Morley Mao, and Henry X. Liu. USENIX Security Symposium (USENIX Security 2021)

  5. CVShield: Guarding Sensor Data in Connected Vehicle with Trusted Execution Environment

    Shengtuo Hu, Qi Alfred Chen, Jiwon Joung, Can Carlak, Yiheng Feng, Z. Morley Mao, and Henry X. Liu. ACM Workshop on Automotive Cybersecurity (AutoSec@CODASPY 2020). Best Paper Award

  6. CommPact: Evaluating the Feasibility of Autonomous Vehicle Contracts

    Jeremy Erickson, Shibo Chen, Mel Savich, Shengtuo Hu, and Z. Morley Mao. IEEE Vehicular Networking Conference (VNC 2018)

  7. AutoFlowLeaker: Circumventing Web Censorship through Automation Services

    Shengtuo Hu, Xiaobo Ma, Muhui Jiang, Xiapu Luo, and Man Ho Au. IEEE International Symposium on Reliable Distributed Systems (SRDS 2017)

  8. Are HTTP/2 Servers Ready Yet?

    Muhui Jiang, Xiapu Luo, TungNgai Miu, Shengtuo Hu, and Weixiong Rao. IEEE International Conference on Distributed Computing Systems (ICDCS 2017)

Links to papers, code and slides are on the publications page.

Service

  • Vehicle Security and Privacy (VehicleSec) Technical Program Committee

    2024–2026
  • USENIX Security Artifact Evaluation Committee

    2022–2026
  • Cyber Security in Cars Workshop (CSCS) Program Committee

    2025
  • IEEE Transactions on Network and Service Management (TNSM) Reviewer

    2026
  • IEEE Transactions on Dependable and Secure Computing (TDSC) Reviewer

    2024–2026
  • IEEE Transactions on Intelligent Transportation Systems (ITS) Reviewer

    2024–2026
  • IEEE/ACM Transactions on Networking (ToN) Reviewer

    2024–2025
  • ACM Multimedia (MM) Reviewer

    2024
  • Privacy Enhancing Technologies Symposium (PETS) External Reviewer

    2022
  • UMich Multidisciplinary Design Program (MDP) Undergraduate Supervisor

    2021–2022

Honors & Awards

  • AutoSec Workshop Best Paper Award

    2020
  • Shanghai Excellent Graduate, Shanghai Municipal Education Commission (top 5%)

    2016
  • Google Excellence Scholarship, Google (top 58 students nationwide in China)

    2015
  • National Scholarship, Ministry of Education, China (top 0.2% nationwide)

    2013, 2014