Kaixuan Luo

Ph.D. Candidate at MobiTeC Lab, The Chinese University of Hong Kong.

photo.jpg

I am currently a PhD candidate in the Department of Information Engineering at the Chinese University of Hong Kong (CUHK), under the supervision of Prof. Wing Cheong Lau. Prior to that, I received my B.Eng. degree from the School of Cyber Science and Engineering, Huazhong University of Science and Technology (HUST) in 2022, where I was supervised by Prof. Ming Wen.

My research interests include web security and software engineering. Recently, I have been focusing on analyzing authorization issues in emerging ecosystems and architecture patterns.

selected publications and talks

  1. Black Hat
    Back to the Future: Hacking and Securing Connection-based OAuth Architectures in Agentic AI and Integration Platforms
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Yanxiang Bi, and Wing Cheong Lau
    Black Hat USA Briefings, 2025
  2. USENIX Security
    Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
    Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung, Wing Cheong Lau, and Julien Lecomte
    34th USENIX Security Symposium (USENIX Security 25), 2025
  3. Black Hat
    One Hack to Rule Them All: Pervasive Account Takeovers in Integration Platforms for Workflow Automation, Virtual Voice Assistant, IoT, & LLM Services
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Julien Lecomte, and Wing Cheong Lau
    Black Hat USA Briefings, 2024

experience

Research Intern @ Samsung Research America

Mountain View, USA — Summer 2023 & 2024

Project: Security Analysis and Engineering of Samsung’s AI Assistant


Research Intern @ Sangfor Technologies

Shenzhen, China — December 2021 - April 2022

Project: Symbolic Execution for Web Shell Detection


awards

CUHK Reaching Out Award, 2025

Undergraduate National Scholarship, 2021

National College Student Information Security Contest - Capture the Flag (CTF), 2nd Prize, 2019 & 2020


service

ACM CCS, Artifact Evaluation Committee, 2025

USENIX Security, Artifact Evaluation Committee, 2025