Cross-group · Ongoing
Vulnerability discovery with agentic harnesses
以 Agentic Harness 進行漏洞挖掘 — 找到不難,難在確認
Two harnesses on the same target. The static one reads source code and files candidates; the dynamic one runs the live system and keeps only what reproduces in a clean sandbox.
- Static — threat-model → vuln-scan → triage: candidates from source code
- Dynamic — recon → find → grade → judge on a live O-RAN 5G core
PhD Candidates
Bing-Kai Hong 洪稟凱 PhD NICT18SumNICT19Intern
Cohort 2019 · Expected graduation 2026 · Senior PhD candidate
5G Base Station security · rogue Base Station detection · MEC-based attack detection · O-RAN security
★ 2019 MOST Excellent PhD Scholarship · 2021 TANET Best Paper · 2023 WPMC Travel Grant
Guang-Jhe Lin 林廣哲 PhD
Cohort 2026 · First-year PhD student
O-RAN security · Near-RT RIC · E2 interface attacks · race condition analysis
★ 2026 ICBIR Best Paper Award
Master's (Senior) · 碩二
- 陳柏宏 BUT26Spr
Master's (Junior) · 碩一
- 劉沛安
- 蕭志軒
Undergraduate Researchers · 大學專題
- 王德元
- 陳昱瑋
- 許良宏
Research Themes · 研究主軸
O-RAN defense
O-RAN 攻擊面分析與防禦機制
Systematic study of O-RAN's open interfaces (E2, F1AP, xApps, rApps) — building both threat models and defensive primitives across Near-RT RIC, Non-RT RIC, and the SMO.
- Anomaly detection on Near-RT RIC for xApp / E2 threats — IEEE OJCOMS 2025
- F1AP conformance testing — IEEE OJCOMS 2026
- Low-rate DoS detection via federated learning — IEEE VTM 2025
- Malicious rApp eavesdropping & exfiltration on Non-RT RIC — CANDAR 2025
- Race condition on E2 subscription — ICBIR 2026
- Task-queue exhaustion causing silent E2 control failures in an O-RAN CU — CANDAR 2026
Rogue Base Station attacks & defenses
惡意基地台攻擊與偵測
Software-defined radio + open-source 5G stack + lightweight container virtualization to realize and detect rogue / MITM Base Stations in 5G private networks. Detection runs on the MEC edge.
- Signaling forgery via virtualized rogue Base Station containers — CISC 2020 Best Paper
- MEC-based rogue Base Station detection APP for 5G private networks — TANET 2021 Best Paper
- xApp-driven rogue Base Station detection on SDR-enabled O-RAN — INFOCOM NGOPERA 2023
- 5G NSA ML-based rogue Base Station classifier — CISC 2022 Best Student Paper
- MEC + AIoT integration — IEEE IoT Mag 2022
NTN (Non-Terrestrial Network) security
非地面網路(衛星通訊)安全
Extending the O-RAN attack model + SDR platform to satellite / 5G-NTN — direct-to-cell LEO reuses the same 3GPP protocols, so terrestrial attacks carry into orbit.
- Threat map of published LEO attacks across service-link, routing, and constellation layers
- Attack reproducibility — routing-layer attacks in container emulation; RF-layer attacks need an SDR air-interface plane
- SG-Defense — space-ground distributed DDoS mitigation for O-RAN NTNs — IEEE Commun. Standards Mag. 2026
PhD Candidate (cross-listed)
Bing-Kai Hong 洪稟凱 PhD
Cohort 2019 · Cross-listed (5G/IoT)
IoT endpoint detection & response · firmware emulation · digital twins
Master's (Senior) · 碩二
- 陳首吉 — 提早半年
- 單業儒
- 彭柏睿
- 陳育昇
Master's (Junior) · 碩一
- 許雅涵
- 陳立杰
Undergraduate Researchers · 大學專題
- 徐牧遠 ★ DEVCORE 獎學金
- 吳秉彥
- 李柏聰
- 劉耀恩
Research Themes · 研究主軸
LLM-driven lightweight AI IPS for Industrial IoT
LLM 驅動之工業物聯網輕量型 AI 入侵防禦系統
A back-end LLM learns industrial-protocol packet semantics and distills a lightweight model to an edge industrial gateway for real-time, inline detection and blocking on OT/IIoT devices — able to flag unseen attacks without prior signatures.
- Industry partners (合作夥伴)
- ORing (威力工業網絡) — industrial gateway & edge deployment
- CyberOT Lab (智皁資安) — OT security assessment & compliance
Vulnerability discovery
IoT 漏洞挖掘
Concolic execution, hybrid static-dynamic analysis, and LLM-assisted exploit generation to discover authentication-bypass and protocol-level vulnerabilities in IoT firmware across architectures.
- Guided concolic execution for auth bypass in IoT — NDSS 2024 poster
- AngrySpider hybrid multi-binary vulnerability discovery — CISC 2026 (finalist)
- Firmulti Fuzzer multi-process vulns via full-system emulation + VMI — CCS CPSIoTSec 2023
- MQTT fuzzing with Trampoline OTA — MOST UG 2025
Firmware emulation & virtual patching
IoT 韌體模擬與虛擬修補
Digital-twin–based firmware emulation enables edge-level endpoint detection & response (EDR) and virtual patching — fixing vulnerable IoT devices via gateway-side mitigation instead of OTA flashing.
- Digital twin EDR via firmware emulation — IEEE IoT Mag 2024
- Mobility-based epidemic model for IoT malware spread — IEEE Access 2022
- Hybrid edge threat detection for O-RAN private networks — IEEE CNS Cyber Resilience 2025
- Firmware NVRAM dependency parsing (FirmFE) — IEEE WPMC 2023
Master's (Senior) · 碩二
- 何欣蓉 NICT25Sum
- 黃竹均 NICT25Sum
- 邱若萍 NICT25Sum
- 王玟雅 NICT26Spr
Master's (Junior) · 碩一
- 張恩瑜 NICT26Spr
- 楊哲宇
Undergraduate Researchers · 大學專題
- 林之鉉
- 陳庭瑜
Research Themes · 研究主軸
IoT malware analysis
IoT 惡意程式分析
A multi-representation pipeline — function call graphs · byte sequences · printable strings · P-Code IR — for cross-architecture IoT malware classification, with NICT Japan as long-term collaborator.
- Execution-order analysis for malware robustness — ACM TECS 2025
- FCG-reinterpreted system calls — Computers & Security 2023; ICISC 2024 Best Paper
- P-Code pretraining few-shot cross-architecture — CISC 2026 Best Presentation
- Printable strings classifier — IEEE TrustCom 2020 Best Paper
- TOM-Net few-shot open-set transductive meta-learning — PST 2025
Adversarial and poisoning attacks
機器學習對抗式與資料中毒攻擊
Building black-box attacks, stealthy backdoors, and explainability-driven adversarial samples against ML-driven security models; co-developed with IBM Watson Trusted AI Group.
- AutoZOOM autoencoder-based zeroth-order black-box attack — AAAI 2019 · 557 citations
- Backdoor attack on malware classifiers — CISC 2021 Best Paper
- Robustness evaluation framework for IoT-based detectors — CISC 2022 Best Student Paper
- Adversarial attacks on consumer-IoT AI malware detection — IEEE Consumer Electronics Mag 2025
