AI for SE & Cybersecurity

I am an R&T Scientist at the Luxembourg Institute of Science and Technology (LIST). My research focuses on harnessing Artificial Intelligence to automate processes and enhance practices in software engineering and cybersecurity. Before this role, I was a Research Associate at the University of Luxembourg, in the Interdisciplinary Centre for Security, Reliability and Trust (SnT), where I was a member of the Trustworthy Software Engineering (TruX) Research Group. I completed my Ph.D. at the University of Luxembourg under the guidance of Prof. Jacques Klein, Prof. Tegawendé F. Bissyandé, and external supervisor Prof. Lorenzo Cavallaro, during which I served as a Doctoral Researcher.

Profiles:

Google Scholar

Google Scholar

 

LinkedIn

LinkedIn

 

ORCID

ORCID


Research Interests:

AI4SE, AI4Cybersecurity, Malware Learning, LLMs


Contact Me

News

  • [Feb 2026] 🚀 Joined the Luxembourg Institute of Science and Technology (LIST) as an R&T Scientist.
  • [Dec 2025] ✍️ Delighted to have my story, "Becoming a Researcher 👨‍🔬, Becoming a Father 🏡", featured in Backpropagate.
  • [Nov 2025] 🎤 Delivered an invited talk at the Seminar on the Next Generation of LLMs for Code Generation at Korea University, Seoul 🇰🇷.
  • [Nov 2025] 🎉 Our research proposal "ANANSI" was successfully awarded funding under the FNR CORE 2025 call!
  • [Nov 2025] 🎤 Presented our paper "RAML" at ASE 2025 in Seoul, South Korea 🇰🇷.
  • [Sep 2025] 🎤 Presented our paper "MalLoc" at ICSME 2025 in Auckland, New Zealand 🇳🇿.
  • [Jun 2025] 🎤 Presented our paper "TIML" at FSE 2025 in Trondheim, Norway 🇳🇴.
  • [Dec 2024] 🚀 Started a new position as a Research Associate at the University of Luxembourg 🇱🇺.
  • [Dec 2024] 🎓 Successfully defended my PhD thesis: "Boosting Android Malware Learning" at the University of Luxembourg 🇱🇺.
  • [Nov 2024] 📚 Contributed a chapter to the book "Malware Handbook of Prevention and Detection", now published!
  • [Oct 2024] 🎤 Presented our paper "DexBERT" at ASE 2024 in Sacramento, USA 🇺🇸.
  • [Oct 2024] 🎤 Presented our paper "DetectBERT" at ESEM 2024 in Barcelona, Spain 🇪🇸.
  • [Jul 2024] 🧠 Attended the OxML Summer School at the University of Oxford, UK 🇬🇧.
  • [Jun 2024] 🎤 Presented our paper "LaFiCMIL" at NLDB 2024 in Turin, Italy 🇮🇹.

Publications

Books

  • Tiezhu Sun, Nadia Daoudi, Kevin Allix, Jordan Samhi, Kisub Kim, Xin Zhou, Abdoul Kader Kabore, Dongsun Kim, David Lo, Tegawendé François Bissyandé, and Jacques Klein (2024). Android Malware Detection Based on Novel Representations of Apps. In Malware: Handbook of Prevention and Detection, pages 197–212, Springer Nature Switzerland.

Papers

  • Tiezhu Sun, Marco Alecci, Yewei Song, Xunzhu Tang, Kisub Kim, Jordan Samhi, Tegawendé F. Bissyandé, and Jacques Klein (2025). RAML: Toward Retrieval-Augmented Localization of Malicious Payloads in Android Apps. 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), Seoul, South Korea. Paper | Code
  • Yewei Song, Tiezhu Sun, Xunzhu Tang, Prateek Kumar Rajput, Tegawendé F. Bissyandé, and Jacques Klein (2025). Measuring LLM Code Generation Stability via Structural Entropy. 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), Seoul, South Korea. Paper | Code
  • Tiezhu Sun, Marco Alecci, Aleksandr Pilgun, Yewei Song, Xunzhu Tang, Jordan Samhi, Tegawendé F. Bissyandé, and Jacques Klein (2025). MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs. 41st International Conference on Software Maintenance and Evolution (ICSME), Auckland, New Zealand. Paper | Code
  • Xunzhu Tang, Tiezhu Sun, Yewei Song, Siyuan Ma, Jacques Klein, and Tegawendé F. Bissyandé (2025). ExpertCache: GPU-Efficient MoE Inference through Reinforcement Learning-Guided Expert Selection. 41st International Conference on Software Maintenance and Evolution (ICSME), Auckland, New Zealand. Paper | Code
  • Xunzhu Tang, Jiechao Gao, Jin Xu, Tiezhu Sun, Yewei Song, Saad Ezzini, Wendkûuni C. Ouédraogo, Jacques Klein, and Tegawendé F. Bissyandé (2025). SynFix: Dependency-Aware Program Repair via RelationGraph Analysis. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (ACL Findings). Paper | Code
  • Weiguo Pian, Yinghua Li, Haoye Tian, Tiezhu Sun, Yewei Song, Xunzhu Tang, Andrew Habib, Jacques Klein, and Tegawendé F. Bissyandé (2025). You Don’t Have to Say Where to Edit! Joint Learning to Localize and Edit Source Code. ACM Transactions on Software Engineering and Methodology (TOSEM). Paper | Code
  • Tiezhu Sun, Nadia Daoudi, Weiguo Pian, Kisub Kim, Kevin Allix, Tegawendé F. Bissyandé, and Jacques Klein (2024). Temporal-Incremental Learning for Android Malware Detection. ACM Transactions on Software Engineering and Methodology (TOSEM). Paper | Code
  • Tiezhu Sun, Nadia Daoudi, Kisub Kim, Kevin Allix, Tegawendé F. Bissyandé, and Jacques Klein (2024). DetectBERT: Towards Full App-Level Representation Learning to Detect Android Malware. Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM). Paper | Code
  • Kisub Kim, Jounghoon Kim, Byeongjo Park, Dongsun Kim, Chun Yong Chong, Yuan Wang, Tiezhu Sun, Daniel Tang, Jacques Klein, and Tegawendé F. Bissyandé (2024). DataRecipe—How to Cook the Data for CodeLLM? Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering (ASE). Paper | Code
  • Tiezhu Sun, Weiguo Pian, Nadia Daoudi, Kevin Allix, Tegawendé F. Bissyandé, and Jacques Klein (2024). Laficmil: Rethinking large file classification from the perspective of correlated multiple instance learning. The 29th International Conference on Applications of Natural Language to Information Systems (NLDB). Paper | Code
  • Yinghua Li, Xueqi Dang, Haoye Tian, Tiezhu Sun, Zhijie Wang, Lei Ma, Jacques Klein, and Tegawendé F. Bissyandé (2024). An empirical study of AI techniques in mobile applications. Journal of Systems and Software. Paper | Code
  • Tiezhu Sun, Kevin Allix, Kisub Kim, Xin Zhou, Dongsun Kim, David Lo, Tegawendé F. Bissyandé, and Jacques Klein (2023). Dexbert: Effective, task-agnostic and fine-grained representation learning of android bytecode. IEEE Transactions on Software Engineering (TSE). Paper | Code
  • Weiguo Pian, Hanyu Peng, Xunzhu Tang, Tiezhu Sun, Haoye Tian, Andrew Habib, Jacques Klein, and Tegawendé F. Bissyandé (2023). MetaTPTrans: A meta learning approach for multilingual code representation learning. Proceedings of the 37th AAAI Conference on Artificial Intelligence (AAAI). Paper | Code
  • Tiezhu Sun, Nadia Daoudi, Kevin Allix, and Tegawendé F. Bissyandé (2021). Android malware detection: looking beyond dalvik bytecode. 2021 36th IEEE/ACM International Conference on Automated Software Engineering Workshops (A-Mobile@ASE). Paper | Code
  • Xunzhu Tang, Rujie Zhu, Tiezhu Sun, and Shi Wang (2021). Moto: Enhancing embedding with multiple joint factors for Chinese text classification. The 25th International Conference on Pattern Recognition (ICPR). Paper | Code
  • Xunzhu Tang, Tiezhu Sun, Rujie Zhu, and Shi Wang (2021). CKG: Dynamic representation based on context and knowledge graph. 25th International Conference on Pattern Recognition (ICPR). Paper | Code
  • Mingxin Zhang, Zhijie Wang, Tiezhu Sun, and Xiaolei Li (2019). Salient object detection by pyramid networks with gating. 2019 IEEE International Conference on Robotics and Biomimetics (ROBIO). Paper | Code
  • Tiezhu Sun, Wei Zhang, Zhi-Jie Wang, Lin Ma, and Zequn Jie (2018). Image-level to Pixel-wise Labeling: From Theory to Practice. The 27th International Joint Conference on Artificial Intelligence (IJCAI). Paper | Code

Service

Journal Referee

  • IEEE Transactions on Dependable and Secure Computing
  • IEEE Transactions on Software Engineering
  • ACM Transactions on Privacy and Security
  • Empirical Software Engineering (Springer Nature)
  • Automated Software Engineering (Springer Nature)
  • Knowledge and Information Systems (Springer Nature)
  • Software Quality Journal (Springer Nature)

Program Committee

  • AMASS 2026 - Workshop on Advances in Malware Analysis and Software Security (co-located with ACM ASIACCS 2026)
  • AAAI 2026 - The 40th Annual AAAI Conference on Artificial Intelligence
  • MOBILESoft 2025 – The 12th International Conference on Mobile Software Engineering and Systems
  • ICPR 2022 – The 26th International Conference on Pattern Recognition
  • NLPCC 2022 - The 11th CCF International Conference on Natural Language Processing and Chinese Computing

External Reviewer

  • FSE 2026 – The ACM International Conference on the Foundations of Software Engineering
  • ASE 2025 – The 40th IEEE/ACM International Conference on Automated Software Engineering
  • ISSTA 2025 – The 34th ACM SIGSOFT International Symposium on Software Testing and Analysis
  • ICSE 2025 – The 47th IEEE/ACM International Conference on Software Engineering
  • ISSTA 2024 – The 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis
  • ECAI 2023 – The 26th European Conference on Artificial Intelligence
  • ISSTA 2023 – The 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis
  • SANER 2023 – The 30th IEEE International Conference on Software Analysis, Evolution and Reengineering
  • ASE 2022 – The 37th IEEE/ACM International Conference on Automated Software Engineering

Grants

FNR CORE (C25/IS-SAS/19577554)

  • Main Writer of the Proposal
  • Funded by Fonds National de la Recherche (FNR), Luxembourg
  • ANANSI (48 months) – Android Malware Defense: Localization-Facilitated Evasive Behavior Analysis and Countermeasures
  • Total Funding: 721.0k€
  • Duration: April 2026 – March 2030

AFR PhD Grant (17046335)

  • Main Writer of the Proposal
  • Funded by Fonds National de la Recherche (FNR), Luxembourg
  • Funding for Ph.D. (38 months) – Learning Android App Representations
  • Total Funding: 144.0k€
  • Duration: March 2022 – April 2025

Supervision

Ph.D. Sudents

  • To be added.

Master's Sudents

  • #### Suraj Govind Maurya
  • University of Luxembourg
  • Master's Degree in Cybersecurity and Cyber ​​Defense
  • Project of Malicious Payload Localization (February. 2025 ~ June 2025)
  • #### Kranti Dipak Bhujbal
  • University of Luxembourg
  • Master's Degree in Cybersecurity and Cyber ​​Defense
  • Project of Malicious Payload Localization (April 2025 ~ June 2025)

Education

  • Ph.D. in Computer Science
  • University of Luxembourg, Luxembourg April 2021 – December 2024

  • M.Sc. in Pattern Recognition
  • Shandong University, Jinan, China September 2016 – June 2019

  • B.Sc. in Information and Computing Science
  • Guangxi University, Nanning, China September 2012 – June 2016

Experience

  • R&T Scientist
  • Luxembourg Institute of Science and Technology (LIST), Luxembourg February 2026 – Present

  • Research Associate
  • University of Luxembourg, Luxembourg December 2024 – January 2026

  • Doctoral Researcher
  • University of Luxembourg, Luxembourg April 2021 – December 2024

  • R&D Engineer
  • Momenta, Suzhou, China July 2019 – March 2021

Awards

  • National ScholarshipShandong University
  • November 2018

  • Outstanding GraduateGuangxi University
  • June 2016

  • National Inspirational ScholarshipGuangxi University
  • June 2014

  • National 2nd PrizeNational Undergraduate Mathematical Contest in Modeling
  • December 2014

  • 7x Excellent ScholarshipsGuangxi University
  • 2013 – 2016