Qiyang Song

bio.jpg

Institute of Information Engineering, Chinese Academy of Sciences

- Email: songqiyang@iie.ac.cn

I received my B.S. degree in Information Security from the University of Electronic Science and Technology of China (UESTC), and my M.S. degree in Computer Science and Technology from Tsinghua University under the supervision of Prof. Qi Li. In 2021, I also worked as a research assistant at George Mason University (GMU) under the supervision of Prof. Kun Sun. I have received my Ph.D. degree and am currently an Assistant Professor at the Institute of Information Engineering (IIE), Chinese Academy of Sciences, where I have been selected for the Young Talent Program.

My current research interests include:

  • Software Security
  • Agent and LLM Security
  • Web3 Security
  • Intrusion Detection Systems

I welcome collaboration and am always open to discussing related academic topics. Feel free to contact me via email—I’m eager to connect with researchers from around the world.

news

Sep 08, 2026 [Paper] Our recent work on training-free backdoor attacks against MCP-enabled agents has been accepted to the Annual Computer Security Applications Conference (ACSAC) 2026!
Jul 17, 2026 [Paper] Our recent work on preference manipulation attacks against MCP agents has been published in IEEE Transactions on Cognitive Communications and Networking (TCCN) 2026!
Dec 05, 2025 [Paper] Our recent work on integrity verification for provenance-based causality analysis has been accepted to USENIX Security 2026!
Nov 08, 2025 [Paper] Our recent work on multilingual interpretability has been accepted to the Association for the Advancement of Artificial Intelligence (AAAI) Conference 2026!
Jul 11, 2025 [Paper] Our recent work in model editing has been accepted to the European Conference on Artificial Intelligence (ECAI) 2025!

selected publications

  1. TCCN26
    biasagent.png
    BiasAgent: Exploiting Agent Bias for Preference Manipulation Attacks on Model Context Protocol
    Ji Guo, Zhijing Wang, Wenbo Jiang, Rui Zhang, Jian Xiong, and 3 more authors
    IEEE Transactions on Cognitive Communications and Networking, 2026
  2. ACSAC26
    training_free_agent_backdoor.png
    The Devil’s Whisper to Agents: Unveiling and Formalizing Training-Free Backdoor Attacks Across the MCP-Enabled Agent Execution Lifecycle
    Yirui Bai, Qiyang Song, Qihang Zhou, Xin Liu, Wenbo Jiang, and 4 more authors
    In Annual Computer Security Applications Conference (ACSAC) 2026, 2026
  3. USENIX Security26
    vCause.png
    vCause: Efficient and Verifiable Causality Analysis for Cloud-based Endpoint Auditing
    Qiyang Song, Qihang Zhou, Xiaoqi Jia, Zhenyu Song, Wenbo Jiang, and 3 more authors
    In 35th USENIX Security Symposium (USENIX Security 26), 2026
  4. AAAI26
    focusing_on.png
    Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language Models
    Xin Liu, Qiyang Song, Qihang Zhou, Haichao Du, Shaowen Xu, and 3 more authors
    In the 40th Association for the Advancement of Artificial Intelligence Conference (AAAI) 2026, 2026
  5. MMAsia25
    when_hallucinated.png
    When Hallucinated Concepts Cross Modals: Unveiling Backdoor Vulnerability in Multi-modal In-context Learning
    Guanyu Hou, Jiaming He, Yitong Qiao, Jiachen Li, Qiyang Song, and 3 more authors
    In the 7th ACM International Conference on Multimedia in Asia (MMAsia) 2025, 2025
  6. ECAI25
    LKS.png
    Latent Knowledge Scalpel: Precise and Massive Knowledge Editing for Large Language Models
    Xin Liu, Qiyang Song, Shaowen Xu, Kerou Zhou, Wenbo Jiang, and 4 more authors
    In European Conference on Artificial Intelligence (ECAI) 2025, 2025
  7. ICC25
    Physical_Traffic_Sign_Backdoor.png
    Stealthy Physical Backdoor Attacks against Traffic Sign Recognition Systems
    Wenbo Jiang, Hongwei Li, Yuxin Lu, Shuai Yuan, Rui Zhang, and 3 more authors
    In IEEE International Conference on Communications (ICC) 2025, 2025
  8. ICME25
    weaponizing_tokens.png
    Weaponizing Tokens: Backdooring Text-to-Image Generation via Token Remapping
    Jiaming He, Wenbo Jiang, Guanyu Hou, Qiyang Song, Ji Guo, and 1 more author
    In IEEE International Conference on Multimedia & Expo (ICME) 2025, 2025
  9. NDSS25
    silence_false_alarms.png
    Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection
    Qiyang Song, Heqing Huang, Xiaoqi Jia, Yuanbo Xie, and Jiahao Cao
    In The Network and Distributed System Security (NDSS) Symposium 2025, 2025
  10. ACSAC21
    try_before_you.png
    Try before You Buy: Privacy-preserving Data Evaluation on Cloud-based Machine Learning Data Marketplace
    Qiyang Song, Jiahao Cao, Kun Sun, Qi Li, and Ke Xu
    In Annual Computer Security Applications Conference (ACSAC) 2021, 2021
  11. TIFS20
    SAP-SSE.png
    SAP-SSE: Protecting search patterns and access patterns in searchable symmetric encryption
    Qiyang Song, Zhuotao Liu, Jiahao Cao, Kun Sun, Qi Li, and 1 more author
    IEEE Transactions on Information Forensics and Security, 2020
  12. TKDE21
    GPSC.png
    GPSC: A grid-based privacy-reserving framework for online spatial crowdsourcing
    Haoda Li, Qiyang Song, Guoliang Li, Qi Li, and Rengui Wang
    IEEE Transactions on Knowledge and Data Engineering, 2021
  13. SecureComm20
    SGX-Cube.png
    Sgx-cube: An sgx-enhanced single sign-on system against server-side credential leakage
    Songsong Liu, Qiyang Song, Kun Sun, and Qi Li
    In Security and Privacy in Communication Networks: 16th EAI International Conference, SecureComm 2020, 2020