profile photo

Jiacheng/Gavin Zhong

I am a recent Master's graduate in Security Informatics from Johns Hopkins University, where I was advised by Prof. Yinzhi Cao.

My research focuses on AI System Security, Program Analysis and Identity Security, particularly building agentic system to detect and exploit vulnerabilities in large-scale applications, acknowledged by Microsoft, Google, Meta, Alibaba and HuggingFace.

Besides, I play CTFs! I'm a team lead of JHU's inaugural eCTF team to design secure systems while exploiting cryptographic flaws, earning top placements in Raymond James CTF and Mountain West Cyber Challenge, and a member of CTF team r3kapig (international team, Top 3 on CTFTime.org)

[Update] I am actively looking for PhD positions in Fall 2026.
I am broadly interested in Web/System Security, AI for Security, enhancing LLM or developing agentic frameworks for improving reliability and security of software systems.

Email /  GitHub  /  Blog  /  Google Scholar  /  Linkedin

News

Oct 2025
My latest agentic system research went public

Publications & Talks

The First Large-Scale Systematic Study of Python Class Pollution Vulnerability


Zhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu, Zifeng Kang, and Yinzhi Cao
paper / poster / code / slides /
Submitted to the Proceedings of IEEE Symposium on Security and Privacy, 2026

From Static to Smart: LLM-enhanced Static Analysis on Web Application Vulnerability Detection


Ant Group SRC Annual Celebration, June 2025
slides / video /

Capture The Flags

Team member @ r3kapig
Won 6 medals from July 2025 to Now, 1 Gold + 2 Silver + 3 Bronze
2025 July. - Now
Team member @ The Group Z0D1AC
Achieved 2nd place Raymond JamesCTF 2024 ($5000 cash prize)
Achieved 5th place Mountain West Cyber Challenge 2024
2023 Sep. - Now

Experiences

Privacy Engineer, TikTok Inc. 2025 Aug. - Now
Security Researcher, Obsidian Security 2025 June. - 2025 July.
Research Assistant, JHU, Advisor: Dr. Yinzhi Cao 2024 Dec. - 2025 June.
Course Assistant, EN.650.660 Software Vulnerability Analysis (24 Fall), JHU 2024 Sep. - 2024 Dec.
Security Intern, Obsidian Security 2024 May. - 2024 August.

Professional Services

External Reviewer

Annual Computer Security Applications Conference (ACSAC '25)

CVEs

I have discovered some vulnerabilities in popular OSS (over 30 CVEs in repos with >1K stars on GitHub), as well as in products maintained by companies including Google, Microsoft, Meta, Ant Group (Alipay) and HuggingFace. A selective list of them is shown below.

CVE-2025-5120 HuggingFace Transformers & Smolagents Sandbox Escape
CVE-2025-24049 Microsoft Azure CLI RCE
CVE-2025-58444 MCP Inspector XSS & RCE
CVE-2025-5320 Gradio CSRF & Bypass
CVE-2025-24370 Django Unicorn XSS & Auth Bypass & RCE
CVE-2025-30358 Mesop DoS & Jailbreak
CVE-2025-54074 Cherry Studio RCE
CVE-2025-1040 AutoGPT SSTI
CVE-2025-58747 Dify XSS
CVE-2025-5874 Redash RCE & Sandbox Escape

Design and source code from Jon Barron's website