Thursday, September 18, 2025 3:30pm to 4:30pm
About this Event
Abstract: As the number of vulnerabilities exploited in the wild rises steadily, studying exploitation with the ultimate goal of stopping it is both necessary and urgent. Exploitation research seeks to answer two fundamental questions: How do exploits work, and how can we stop them? In this talk, I will present my group's contributions over the past three years, along with future directions that leverage the potential of quantum computing and AI to advance exploitation research.
I will first introduce Lancet, a formalized framework to uncover the primitives that attackers obtain in a given exploit. Next, I will discuss PET, a practical defense against 1-day exploits before patches are available. Both works demonstrate how classical methods continue to deepen our understanding of exploitation and enable the development of effective protection. Looking ahead, I will highlight QEX, which explores how new opportunities that quantum computing is offering, and my team's role in DARPA's AIxCC competition, where AI is reshaping automated vulnerability discovery. Together, these efforts chart a roadmap for exploitation research that builds on classical foundations while embracing future potentials.
Bio:Yueqi Chen is an Assistant Professor of Computer Science at the University of Colorado Boulder. His research interests include Exploit Analysis and Synthesis, Quantum Control Processor, and Machine Learning for Systems. He received the IBM Ph.D. Fellowship for his contributions to exploitability assessment. He is a Pwn2Own winner and a frequent BlackHat speaker. Most recently, he co-led team 42-b3yond-6ug to develop a Cyber Reasoning System (CRS), which ranks #1 in SARIF assessment and #2 in vulnerability discovery in the DARPA AI Cyber Challenge (AIxCC).
User Activity
No recent activity