Shenghan Zheng is a Ph.D. student in the Department of Computer Science of Dartmouth College with focus in computer security. He is fortunately advised by Prof. Christophe Hauser. His current research interests are the security of agent protocols and agentic systems, software testing and verification, and agent benchmarks. He also works on network security and system security, incorporating multiple program analysis methods(e.g., fuzzing, symbolic execution, and reverse engineering) in combination with machine learning techniques(e.g., GNN and Large Language Model).
He earned his master's degree at UC Riverside where he was a member of UCR Security Lab. Previously, he was a member of DSP Lab at UC Irvine.
") does not match the recommended repository name for your site ("").
", so that your site can be accessed directly at "http://".
However, if the current repository name is intended, you can ignore this message by removing "{% include widgets/debug_repo_name.html %}" in index.html.
",
which does not match the baseurl ("") configured in _config.yml.
baseurl in _config.yml to "".

Shenghan Zheng, Shitong Zhu, Yu Hao, Xingyu Li, Keyu Man, Zheng Zhang, Qing Deng, Zhiyun Qian, Srikanth V. Krishnamurthy
IEEE International Symposium on Software Reliability Engineering (ISSRE) 2026
State merging mitigates path explosion in symbolic execution, but merging the wrong states shifts the cost onto the constraint solver and can slow exploration down instead. NeuroMerge learns when merging pays off, using a machine-learning-guided policy to decide which symbolic states to merge so that exploration stays efficient across large program search spaces.
Shenghan Zheng, Shitong Zhu, Yu Hao, Xingyu Li, Keyu Man, Zheng Zhang, Qing Deng, Zhiyun Qian, Srikanth V. Krishnamurthy
IEEE International Symposium on Software Reliability Engineering (ISSRE) 2026
State merging mitigates path explosion in symbolic execution, but merging the wrong states shifts the cost onto the constraint solver and can slow exploration down instead. NeuroMerge learns when merging pays off, using a machine-learning-guided policy to decide which symbolic states to merge so that exploration stays efficient across large program search spaces.

Xiangyi Li, Yimin Liu, Wenbo Chen, Bingran You, Zonglin Di, Yifeng He, Shenghan Zheng, et al.
arXiv preprint 2026
Agent Skills are structured packages of procedural knowledge that augment LLM agents at inference time. Despite rapid adoption, there is no standard way to measure whether they actually help. We present SkillsBench, a benchmark of 87 tasks across 8 domains paired with curated Skills and deterministic verifiers. Curated Skills raise the average pass rate from 33.9% to 50.5% across 18 model-harness configurations, and focused Skills with at most three modules outperform larger, exhaustive bundles.
Xiangyi Li, Yimin Liu, Wenbo Chen, Bingran You, Zonglin Di, Yifeng He, Shenghan Zheng, et al.
arXiv preprint 2026
Agent Skills are structured packages of procedural knowledge that augment LLM agents at inference time. Despite rapid adoption, there is no standard way to measure whether they actually help. We present SkillsBench, a benchmark of 87 tasks across 8 domains paired with curated Skills and deterministic verifiers. Curated Skills raise the average pass rate from 33.9% to 50.5% across 18 model-harness configurations, and focused Skills with at most three modules outperform larger, exhaustive bundles.

Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Yue Cao, Xin'an Zhou, Zhiyun Qian
IEEE Symposium on Security and Privacy (IEEE S&P) 2025
Network side-channel attacks, such as SADDNS enabling off-path cache poisoning, are notoriously difficult to detect because current automated techniques require extensive, error-prone modeling that oversimplifies network protocols. In response, we introduce SCAD—the first solution leveraging dynamic symbolic execution to efficiently identify non-interference violations across multiple execution traces—uncovering previously unknown vulnerabilities with significantly reduced manual effort.
Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Yue Cao, Xin'an Zhou, Zhiyun Qian
IEEE Symposium on Security and Privacy (IEEE S&P) 2025
Network side-channel attacks, such as SADDNS enabling off-path cache poisoning, are notoriously difficult to detect because current automated techniques require extensive, error-prone modeling that oversimplifies network protocols. In response, we introduce SCAD—the first solution leveraging dynamic symbolic execution to efficiently identify non-interference violations across multiple execution traces—uncovering previously unknown vulnerabilities with significantly reduced manual effort.