Kaixuan Luo

Ph.D. Candidate at MobiTeC Lab, The Chinese University of Hong Kong.

photo.jpg

I am currently a PhD candidate in the Department of Information Engineering at the Chinese University of Hong Kong (CUHK), under the supervision of Prof. Wing Cheong Lau. I also collaborate closely with Dr. Adonis Fung from Samsung Research America. Prior to that, I received my B.Eng. degree from the School of Cyber Science and Engineering, Huazhong University of Science and Technology (HUST) in 2022, where I was supervised by Prof. Ming Wen.

My research interests include web security and software engineering. Recently, I have been focusing on analyzing authorization issues in emerging ecosystems and architectural patterns.

news

Apr 20, 2026 I’m looking for industry job opportunities for Spring/Fall 2027. Happy to connect and chat!

publications

  1. IEEE S&P
    Demystifying the (In)Security of OAuth-based Account Linking in Connector Ecosystems
    Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung, and Wing Cheong Lau
    47th IEEE Symposium on Security and Privacy (IEEE S&P 2026), May 2026
  2. IETF Internet-Draft
    Updates to OAuth 2.0 Security Best Current Practice
    Tim Würtele, Pedram Hosseyni, Kaixuan Luo, and Adonis Fung
    Mar 2026
    Internet-Draft draft-ietf-oauth-security-topics-update-01, Internet Engineering Task Force. Work in Progress
  3. USENIX Security
    Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
    Kaixuan Luo, Xianbo Wang, Pui Ho Adonis Fung, Wing Cheong Lau, and Julien Lecomte
    34th USENIX Security Symposium (USENIX Security 25), Aug 2025
  4. CCS
    SWIDE: A Semantic-aware Detection Engine for Successful Web Injection Attacks
    Ronghai Yang, Xianbo Wang, Kaixuan Luo, Xin Lei, Ke Li, and 2 more authors
    Proceedings ACM Conference on Computer and Communications Security (CCS), Oct 2024
  5. ACNS
    Living a Lie: Security Analysis of Facial Liveness Detection Systems in Mobile Apps
    Xianbo Wang, Kaixuan Luo, and Wing Cheong Lau
    International Conference on Applied Cryptography and Network Security, Mar 2024
  6. TSE
    Effective Isolation of Fault-Correlated Variables via Statistical and Mutation Analysis
    Ming Wen, Zifan Xie, Kaixuan Luo, Xiao Chen, Yibiao Yang, and 1 more author
    IEEE Transactions on Software Engineering, Apr 2023

talks

  1. OSW
    Understanding OAuth Session Fixation in Connector Ecosystems
    Kaixuan Luo, Xianbo Wang, Adonis Fung, and Wing Cheong Lau
    OAuth Security Workshop (OSW), May 2026
  2. Black Hat USA
    Back to the Future: Hacking and Securing Connection-based OAuth Architectures in Agentic AI and Integration Platforms
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Yanxiang Bi, and Wing Cheong Lau
    Black Hat USA Briefings, Aug 2025
  3. OSW
    Cross-app OAuth Attacks in Integration Platforms: Mix-up Attacks Reloaded
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Julien Lecomte, and Wing Cheong Lau
    OAuth Security Workshop (OSW), Feb 2025
  4. Black Hat USA
    One Hack to Rule Them All: Pervasive Account Takeovers in Integration Platforms for Workflow Automation, Virtual Voice Assistant, IoT, & LLM Services
    Kaixuan Luo, Xianbo Wang, Adonis Fung, Julien Lecomte, and Wing Cheong Lau
    Black Hat USA Briefings, Aug 2024
  5. Black Hat USA
    The Living Dead: Hacking Mobile Face Recognition SDKs with Non-Deepfake Attacks
    Xianbo Wang, Kaixuan Luo, and Wing Cheong Lau
    Black Hat USA Briefings, Aug 2023

experience

Research Intern @ Samsung Research America

Mountain View, USA — Summer 2023 & 2024

Project: Security Analysis and Engineering of Samsung’s AI Assistant


Research Intern @ Sangfor Technologies

Shenzhen, China — December 2021 - April 2022

Project: Symbolic Execution for Web Shell Detection


awards

IEEE S&P Student Travel Grant, 2026

ACM CCS Top Artifact Reviewers Award, 2025

USENIX Security Distinguished Artifact Reviewer Award, 2025

HKSAR Reaching Out Award, 2025

Undergraduate National Scholarship, 2021

National College Student Information Security Contest - Capture the Flag (CTF), 2nd Prize, 2019 & 2020 [Team: L3HSec]


service

ACM CCS, Artifact Evaluation Committee, 2025

USENIX Security, Artifact Evaluation Committee, 2025, 2026