Hi! I am Ziyu Lin (林子瑜 in Chinese). I am a first-year PhD student in the College of Computing and Data Science at Nanyang Technological University, co-advised by Prof. XiaoFeng Wang and Prof. Wei Dong. My research focuses on cellular network security, agent security and content delivery network security. My research results have received acknowledgments from well-known CDN vendors such as Azure, Alibaba, Baidu, Cloudflare, Cachefly, Edgio, G-Core, Huntr, Qiniu, and Tencent.
🔥 News
- 2026.07: 🎉🎉 Our paper “CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks” was accepted by SRDS, Rome, Italy, 2026. (Media Coverage: The Hacker News)
- 2026.05: 🎉🎉 Our paper “Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis” was accepted by Usenix Security, Baltimore, MD, 2026. (Media Coverage: The Hacker News, Help Net Security)
- 2025.03: 🎉🎉 Zhiwei and I will present CDN Cannon at Black Hat Asia 2025.
- 2024.09: 🎉🎉 Our paper “Detecting and Measuring Security Implications of Entangled Domain Verification in CDN” was available on Arxiv!
- 2024.03: 🎉🎉 Our paper “CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks” was accepted by Usenix Security, Philadelphia, PA, 2024.
📝 Publications
- Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis
- Ziyu Lin, Ziting Wang, Xinfeng Li, Wei Dong, XiaoFeng Wang
- The 35rd USENIX Security Symposium
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attack
- Ziyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen, Run Guo, Cheng Chen, Shaodong Xiao
- The 33rd USENIX Security Symposium
- This paper is about exploiting CDN Back-to-Origin strategies to launch a new class of amplification attacks.
- CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks
- Ziyu Lin, Tianlong Su, Yingjie Lin, Prosanta Gope, Yinzhi Cao, Ximeng Liu, Biplab Sikdar
- The 45th International Symposium on Reliable Distributed Systems
- Detecting and Measuring Security Implications of Entangled Domain Verification in CDN
- Ziyu Lin, Zhiwei Lin, Run Guo, Jianjun Chen, Mingming Zhang, Ximeng Liu, Tianhao Yang, Zhuoran Cao, Robert H. Deng
- This paper is about automatically detecting Domain Verification vulnerabilities in CDN.
📝 Talks
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attack
- Ziyu Lin, Zhiwei Lin
📖 Educations
- 2026.01 - present, PhD, Nanyang Technological University, Singapore.
- 2022.09 - 2025.06, Master, Fuzhou University, P.R.C.
- 2018.09 - 2022.06, Undergraduate, Fujian Agriculture and Forestry University, P.R.C.
🎖 Honors and Awards
- 2024.10 Chinese National Scholarship
- 2024.01 Best Paper Award, 2024 2nd International Conference on Big Data and Privacy Computing.
- 2022.12 3rd Place of TEE Track in 2022 World Privacy-Preserving Computing Competition (WPPCC)
💻 Internships
- 2025.05 - 2025.11, National University of Singapore, Research Assistant (supervised by Prof. Sikdar Biplab).
- 2024.05 - 2025.05, Singapore Management University, Research Assistant (supervised by Prof. Robert Deng).
- 2023.01 - 2024.05, Tsinghua University, Research Assistant (supervised by Prof. Jianjun Chen).