Posts by Collection

portfolio

Xept — Academic Writing AI-Agent Permalink

An AI-native academic-writing platform I founded and lead, pairing LLM agents with real-time collaborative LaTeX editing. It now serves 2,000+ users on a paid-subscription model, with multi-agent workflows spanning the full paper lifecycle: literature search, outlining, drafting, data analysis, and revision.

Binary Software Composition Analysis

A research line on binary SCA that detects third-party libraries and known vulnerabilities directly in compiled C/C++ binaries. It powers BLADE, an evidence-based detection framework integrated into a commercial SCA product for compliance checks in regulated industries such as automotive.

publications

Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ Binaries

Published in ISSTA, 2026

BLADE, an evidence-based detection framework replacing similarity-score heuristics with multi-source LLM-guided verification; 97.60% precision / 93.74% recall.

Recommended citation: Chengyue Liu, et al. (2026). "Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ Binaries." Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2026). ACM SIGSOFT Distinguished Paper Award.
Download Paper

Mind the Gap: An Empirical Study of Synchronization Gaps, Delays, and Missed Opportunities in Software Forks

Published in ISSTA, 2026

An empirical study of synchronization gaps, delays, and missed opportunities across software forks.

Recommended citation: J. Zhu, L. Zhang, J. Wu, Chengyue Liu, Y. Liu. (2026). "Mind the Gap: An Empirical Study of Synchronization Gaps, Delays, and Missed Opportunities in Software Forks." Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2026).
Download Paper

How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study

Published in ASE, 2026

First large-scale empirical study of NPM malicious package detection, evaluating 11 tools with 16 variants on a unified benchmark of 6,420 malicious and 7,288 benign packages.

Recommended citation: W. Guo, Z. Chen, Z. Xu, C. Liu, M. Kang, S. Song, Chengyue Liu, et al. (2026). "How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study." IEEE/ACM International Conference on Automated Software Engineering (ASE 2026).
Download Paper

talks

teaching

Teaching experience 1

Undergraduate course, University 1, Department, 2014

This is a description of a teaching experience. You can use markdown like any other post.

Teaching experience 2

Workshop, University 1, Department, 2015

This is a description of a teaching experience. You can use markdown like any other post.