MrZong Cao

Research Engineer, IN-CYPHER

Imperial Global Singapore - Central Faculty

  • Research Engineer, IN-CYPHER
    Imperial Global Singapore - Central Faculty

RESEARCH

I am broadly interested in the intersection of artificial intelligence and software security—specifically, in developing AI‑driven, semantic‑aware methods that can reason about code the way a seasoned security expert does. Traditional vulnerability scanners rely on pattern matching and often fail to catch complex, multi‑step logic flaws that underlie most high‑impact 0‑day exploits. My research seeks to bridge this gap by integrating large language models with static analysis tools and chain‑of‑thought reasoning techniques, enabling automated systems to perform deep semantic analysis, trace multi‑layer data flows, and identify subtle business‑logic vulnerabilities before they reach production.

A second pillar of my work focuses on making expert‑level security guidance available throughout the software development lifecycle. Once an AI system has generated a structured reasoning chain for a newly discovered vulnerability, I investigate how to automatically convert those chains into lightweight detection rules and distilled models. These models can then be deployed directly within CI/CD pipelines, offering developers real‑time feedback, actionable remediation suggestions, and even automated proof‑of‑concept exploit generators. By embedding security expertise into everyday development workflows, we not only reduce the window of exposure for new vulnerabilities but also help cultivate secure‑by‑design coding practices across engineering teams.

Looking forward, I aim to extend these agent‑based frameworks to support continuous learning and adaptation. By capturing and curating structured “thought traces” from each analysis, we can build evolving vulnerability ontologies that inform future detection and remediation strategies. Ultimately, my goal is to create self‑improving security assistants—AI agents that not only detect novel threats with human‑level insight but also proactively guide developers toward more resilient architectures, making secure software the norm rather than the exception.