Shenghan Zheng
Logo Graduate Student Researcher

Shenghan Zheng is a Ph.D. student in the Department of Computer Science of Dartmouth College with focus in computer security. He is fortunately advised by Prof. Christophe Hauser. His current research interests are the security of agent protocols and agentic systems, software testing and verification, and agent benchmarks. He also works on network security and system security, incorporating multiple program analysis methods(e.g., fuzzing, symbolic execution, and reverse engineering) in combination with machine learning techniques(e.g., GNN and Large Language Model).

He earned his master's degree at UC Riverside where he was a member of UCR Security Lab. Previously, he was a member of DSP Lab at UC Irvine.

Curriculum Vitae

Education
  • Dartmouth College
    Dartmouth College
    Department of Computer Science
    Ph.D. Student
    Sep. 2025 - present
  • University of California, Riverside
    University of California, Riverside
    M.S. in Computer Science
    Sep. 2023 - Jun. 2025
  • University of California, Berkeley
    University of California, Berkeley
    Exchange Student in EECS
    Aug. 2021 - Jul. 2022
  • ShanghaiTech University
    ShanghaiTech University
    B.E. in Computer Science
    Sep. 2019 - Jun. 2023
Honors & Awards
  • Graduate Fellowship, UC Riverside
    2024
  • Deans Fellow Award, UC Riverside
    2024
  • Distinguished Dean's Award, UC Riverside
    2023
  • Merit Student, ShanghaiTech University
    2022
News
2026
Our paper ClawsBench has been accepted by COLM 2026!
Jul
Our paper NCFuzz has been accepted by ISSTA 2026!
Jun
Our paper NeuroMerge has been accepted by ISSRE 2026!
Jun
Services
Artifact Evaluation Committee
  • NDSS: 2025, 2026
  • EuroSys: 2025, 2026
  • Usenix: 2025
  • SLE: 2025
  • CCS: 2025
Registered Reviewers
  • EAI SecureComm: 2024
  • IEEE T-IFS: 2024
  • Computer Networks: 2024, 2025
External Reviewers
  • CCS: 2024
  • NDSS: 2025
Selected Publications (view all )
NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution
NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution

Shenghan Zheng, Shitong Zhu, Yu Hao, Xingyu Li, Keyu Man, Zheng Zhang, Qing Deng, Zhiyun Qian, Srikanth V. Krishnamurthy

IEEE International Symposium on Software Reliability Engineering (ISSRE) 2026

State merging mitigates path explosion in symbolic execution, but merging the wrong states shifts the cost onto the constraint solver and can slow exploration down instead. NeuroMerge learns when merging pays off, using a machine-learning-guided policy to decide which symbolic states to merge so that exploration stays efficient across large program search spaces.

NeuroMerge: ML-Guided State Merging for Efficient Symbolic Execution

Shenghan Zheng, Shitong Zhu, Yu Hao, Xingyu Li, Keyu Man, Zheng Zhang, Qing Deng, Zhiyun Qian, Srikanth V. Krishnamurthy

IEEE International Symposium on Software Reliability Engineering (ISSRE) 2026

State merging mitigates path explosion in symbolic execution, but merging the wrong states shifts the cost onto the constraint solver and can slow exploration down instead. NeuroMerge learns when merging pays off, using a machine-learning-guided policy to decide which symbolic states to merge so that exploration stays efficient across large program search spaces.

SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks
SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks

Xiangyi Li, Yimin Liu, Wenbo Chen, Bingran You, Zonglin Di, Yifeng He, Shenghan Zheng, et al.

arXiv preprint 2026

Agent Skills are structured packages of procedural knowledge that augment LLM agents at inference time. Despite rapid adoption, there is no standard way to measure whether they actually help. We present SkillsBench, a benchmark of 87 tasks across 8 domains paired with curated Skills and deterministic verifiers. Curated Skills raise the average pass rate from 33.9% to 50.5% across 18 model-harness configurations, and focused Skills with at most three modules outperform larger, exhaustive bundles.

SkillsBench: Benchmarking How Well Agent Skills Work Across Diverse Tasks

Xiangyi Li, Yimin Liu, Wenbo Chen, Bingran You, Zonglin Di, Yifeng He, Shenghan Zheng, et al.

arXiv preprint 2026

Agent Skills are structured packages of procedural knowledge that augment LLM agents at inference time. Despite rapid adoption, there is no standard way to measure whether they actually help. We present SkillsBench, a benchmark of 87 tasks across 8 domains paired with curated Skills and deterministic verifiers. Curated Skills raise the average pass rate from 33.9% to 50.5% across 18 model-harness configurations, and focused Skills with at most three modules outperform larger, exhaustive bundles.

SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection
SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection

Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Yue Cao, Xin'an Zhou, Zhiyun Qian

IEEE Symposium on Security and Privacy (IEEE S&P) 2025

Network side-channel attacks, such as SADDNS enabling off-path cache poisoning, are notoriously difficult to detect because current automated techniques require extensive, error-prone modeling that oversimplifies network protocols. In response, we introduce SCAD—the first solution leveraging dynamic symbolic execution to efficiently identify non-interference violations across multiple execution traces—uncovering previously unknown vulnerabilities with significantly reduced manual effort.

SCAD: Towards a Universal and Automated Network Side-Channel Vulnerability Detection

Keyu Man, Zhongjie Wang, Yu Hao, Shenghan Zheng, Yue Cao, Xin'an Zhou, Zhiyun Qian

IEEE Symposium on Security and Privacy (IEEE S&P) 2025

Network side-channel attacks, such as SADDNS enabling off-path cache poisoning, are notoriously difficult to detect because current automated techniques require extensive, error-prone modeling that oversimplifies network protocols. In response, we introduce SCAD—the first solution leveraging dynamic symbolic execution to efficiently identify non-interference violations across multiple execution traces—uncovering previously unknown vulnerabilities with significantly reduced manual effort.

All publications