Nanzi Yang

Research Assistant Professor, School of Cybersecurity, Old Dominion University
He is in the job market.

πŸ“§ yang9467@umn.edu πŸŽ“ Google Scholar
Trustworthy AI Systems AI System Security Cloud Security Agent & Protocol Security (MCP, A2A)

Research Interests

Trustworthy AI systems; AI system security; cloud security; security of AI agents and orchestration protocols (MCP, A2A).

Focus

System-level security for modern AI services: from cloud-native infrastructure to emerging agent protocols.

Keywords

Kubernetes, container platforms, serverless, protocol compliance, security hardening.

Education & Employment

Old Dominion University (2026.06–Present)

Research Assistant Professor, School of Cybersecurity

University of Minnesota (2024–2026.05)

Postdoctoral Associate, Department of Computer Science
Host: Prof. Kangjie Lu

Xidian University

Ph.D. in Cyberspace Security (2019–2024)
B.S. in Information Engineering (2014–2018)

Peer-reviewed Publications

Refereed Publications

  1. Mind the Gap: Detecting Description-Execution Mismatch Attacks in DAO Governance
    Bowen Cai, Nanzi Yang, Weiheng Bai, Youshui Lu, Yajin Zhou, Kangjie Lu - ACM CCS 2026
  2. From Fault to Oracle: Breaking Google Pixel TPU Hardware Memory Isolation via Trusted Deserialization Faults
    Minghao Lin, Guanxing Wen, Haoxuan Xu, Yuzhou Fang, Nanzi Yang, Xiaokuan Zhang, Yanan Guo, Zhuo Zhang, Mengyuan Li
  3. The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless Applications
    Xunqi Liu*, Nanzi Yang*, Chang Li, Jinku Li, Jianfeng Ma, Kangjie Lu β€” NDSS 2026
  4. Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in Kubernetes
    Nanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li, Kangjie Lu β€” ACM CCS 2025
  5. Towards Understanding and Defeating Abstract Resource Attacks for Container Platforms
    Wenbo Shen, Yifei Wu, Yutian Yang, Qirui Liu, Nanzi Yang, Jinku Li, Kangjie Lu, Jianfeng Ma β€” IEEE TDSC 2025
  6. Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications
    Nanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu, Xin Guo, Jianfeng Ma β€” ACM CCS 2023
  7. Attacks are forwarded: breaking the isolation of MicroVM-based containers through operation forwarding
    Jietao Xiao*, Nanzi Yang*, Wenbo Shen, Jinku Li, Xin Guo, Zhiqiang Dong, Fei Xie, Jianfeng Ma β€” USENIX Security 2023
  8. Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level Virtualization
    Nanzi Yang*, Wenbo Shen*, Jinku Li, Yutian Yang, Kangjie Lu, Jietao Xiao, Tianyu Zhou, Chenggang Qin, Wang Yu, Jianfeng Ma, Kui Ren β€” ACM CCS 2021

Tip: You can keep this list β€œselected” and link to your full publication list on Google Scholar.

Industry-Recognized Security Impact

Grant & Proposal Writing

Mentoring & Teaching

Research Mentoring

Service

Awards & Honors

Talks & Presentations