Wenbo Guo (郭文博) is a third-year Ph.D. candidate in the School of Computer and Data Science at Nanyang Technological University (NTU), advised by Prof. Yang Liu.

In 2020, he graduated with honors and earned his Bachelor’s degree from Sichuan University. He was subsequently offered direct admission to graduate school at the School of Cyber Security at Sichuan University, where he continued his academic journey towards a Master’s degree. During this stage, he was co-advised by Prof. Fang Yong and Prof. Cheng Huang.

His research interests include supply chain security and open-source intelligence.

🔥 News

  • 2026.07:  🎉🎉 Two papers were accepted by ASE 2026!
  • 2026.07:  🎉🎉 One paper was accepted by ACM CCS 2026 (Cycle B)!
  • 2026.06:  🎉🎉 Our security platform Maliverse is now online, integrating our IntelliRadar, PyGuard, and SkillGuard tools into one supply-chain & AI-agent security platform!
  • 2026.06:  🎉🎉 Our project was approved for OpenAI Startup Credits ($2,500 USD)!
  • 2026.06:  🎉🎉 He was appointed as a member of the Artifact Evaluation Committee (AEC) for NDSS 2027 and ISSTA 2027!
  • 2026.04:  🎉🎉 One paper was accepted by ISSTA 2026!
  • 2026.01:  🎉🎉 One paper was accepted by USENIX Security 2026!
  • 2026.01:  🎉🎉 One paper was accepted by WWW 2026!
  • 2025.12:  🎉🎉 One paper was accepted by FSE 2026!
Show more news
  • 2025.12:  🎉🎉 Our team won the First Prize (Top 2) in the Prototype System Competition at CCF ChinaSoft (中国软件大会)!
  • 2025.10:  🎉🎉 Our paper “IntelliRadar” was accepted by ICSE 2026!
  • 2025.10:  🎉🎉 He successfully passed the Qualifying Examination (QE) and became a Ph.D. candidate at NTU!
  • 2025.09:  🎉🎉 Our paper “BinStruct: Binary Structure Recovery Combining Static Analysis and Semantics” was accepted by ICSE 2025!
  • 2025.01:  🎉🎉 He was selected for the OpenAI Researcher Access Program with $8,000 USD in API credits!
  • 2024.05:  🎉🎉 He was appointed as a member of the Datacon Expert Committee.
  • 2024.01:  🎉🎉 He joined the Nanyang Technological University as a Ph.D. student.
  • 2023.07:  🎉🎉 Our paper “An Empirical Study of Malicious Code In PyPI Ecosystem” was accepted by ASE 2023!
  • 2023.06:  🎉🎉 He obtained the master’s degree from SCU.
  • 2023.03:  🎉🎉 He was awarded the title of Outstanding Graduate of Sichuan Province.

📄 Preprints

* equal contribution (co-first author); corresponding author.

📝 Selected Publications

A selection of my work. See the full list of publications for everything else.

  • How Effective Are NPM Malicious Package Detectors? A Large-Scale Empirical Study
    • Wenbo Guo, Zhongwen Chen, Zhengzi Xu, Chengwei Liu, Ming Kang, Shiwen Song, Chengyue Liu, Yijia Xu, Weisong Sun, Yang Liu
    • 41st IEEE/ACM International Conference on Automated Software Engineering (ASE), 2026
    • This paper presents the first large-scale empirical study of NPM malicious package detection, evaluating 8 tools with 13 variants on a unified benchmark of 6,420 malicious and 7,288 benign packages, and inspecting each tool’s source code to explain why it succeeds or fails.
  • Latent Reuse in Agent Skills: Multi-Modal Clone Detection at Ecosystem Scale
    • Jiaying Zhu, Lyuye Zhang, Wenbo Guo, Yang Liu
    • 41st IEEE/ACM International Conference on Automated Software Engineering (ASE), 2026
    • This paper presents SkillClone, the first multi-modal clone detection approach for agent skills, which recovers hidden reuse links across YAML metadata, natural language instructions, and embedded code at ecosystem scale.
  • An Empirical Study of Observability Limits in Advanced Software Supply Chain Attacks
    • Zhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley, Jeremy Singer, Christos Anagnostopoulos
    • ACM Conference on Computer and Communications Security (CCS), 2026
    • This paper presents SynthChain, a multi-source runtime dataset with chain-level ground truth, and empirically studies the observability limits of software supply chain attacks.
  • Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework
    • Wenbo Guo, Chengwei Liu, Ming Kang, Yiran Zhang, Jiahui Wu, Zhengzi Xu, Vinay Sachidananda, Yang Liu
    • USENIX Security Symposium (USENIX Security), 2026
    • This paper proposes a knowledge-mining framework that transforms false positives from existing tools into knowledge to drive malicious package detection, discovering over 500 new malicious packages in the PyPI ecosystem.
  • Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
    • Wenbo Guo, Shiwen Song, Jiaxun Guo, Zhengzi Xu, Chengwei Liu, Haoran Ou, Mengmeng Ge, Yang Liu
    • The Web Conference (WWW), 2026
    • This paper proposes a knowledge-driven framework that extracts and summarizes knowledge from historical expert malware analysis reports to drive LLM-based malicious package detection.
  • Casting a SPELL: Sentence Pairing Exploration for LLM Limitation-breaking
    • Yifan Huang, Xiaojun Jia, Wenbo Guo, Yuqiang Sun, Yihao Huang, Chong Wang, Yang Liu
    • ACM International Conference on the Foundations of Software Engineering (FSE), 2026
    • This paper proposes SPELL, a testing framework that evaluates security alignment weaknesses in LLM code generation through time-division sentence pairing strategies, achieving high attack success rates across major code models.
  • IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Packages from Cyber Intelligence
    • Wenbo Guo, Chengwei Liu, Limin Wang, Yiran Zhang, Jiahui Wu, Zhengzi Xu, Yang Liu
    • 48th International Conference on Software Engineering (ICSE), 2026
    • This paper presents IntelliRadar, a comprehensive platform designed to identify and pinpoint malicious packages using cyber intelligence.
  • Evolaris: A Roadmap to Self-Evolving Software Intelligence Management
    • Chengwei Liu, Wenbo Guo, Yuxin Zhang, Limin Wang, Sen Chen, Lei Bu, Yang Liu
    • 29th International Conference on Engineering of Complex Computer Systems (ICECCS), 2025 (Position Paper)
    • This paper presents Evolaris, a roadmap to self-evolving software intelligence management.
  • An Empirical Study of Malicious Code In PyPI Ecosystem
    • Wenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang, Yong Fang, Yang Liu
    • 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE)
    • This paper is the empirical study paper for the malicious packages in the PyPI Package Manager.
    • We constructed the largest PyPI malicious package dataset and open-sourced the dataset at here
  • HyVulDect: a hybrid semantic vulnerability mining system based on graph neural network
    • Wenbo Guo, Yong Fang, Cheng Huang, Haoran Ou, Chun Lin, Yongyan Guo
    • Computers & Security, 2022
    • This paper is about vulnerability detection based on the graph neural network.

See all publications →

🌐 Platform

  • Maliverse is now online — a unified software supply chain & AI agent security platform that brings together three of our research tools:
    • IntelliRadar: pinpointing malicious packages from cyber threat intelligence (ICSE 2026).
    • PyGuard: knowledge-driven detection of malicious PyPI packages (USENIX Security 2026 & WWW 2026).
    • SkillGuard: detection of malicious AI agent skills (MalSkillBench).

📖 Educations

  • 2024.01 - Now, Ph.D. Student at College of Computing and Data Science, Nanyang Technological University, Singapore.
  • 2020.09 - 2023.06, Postgraduate student at School of Cyber Science and Engineering, Sichuan University, Chengdu, Sichuan, P.R.C.
  • 2016.09 - 2020.06, Undergraduate student at School of Cyber Science and Engineering, Sichuan University, Chengdu, Sichuan, P.R.C.

🎖 Honors and Awards

  • 2026.06 OpenAI, Startup Credits ($2,500 USD).
  • 2025.12 CCF ChinaSoft (中国软件大会), First Prize (Top 2), Prototype System Competition.
  • 2025.01 OpenAI, Researcher Access Program ($8,000 USD in API credits).
  • 2023.06 Sichuan Province Government, Excellent Graduates.
  • 2021.12 Sichuan University, Dahua Scholarship.
  • 2019.10 Chinese Ministry of Education, National Inspirational Scholarship.

💬 Talks

  • 2026.04, IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Packages from Cyber Intelligence. ICSE 2026 @ Rio de Janeiro, Brazil

📫 Services

  • Artifact Evaluation Committee (AEC): NDSS 2027
  • Artifact Evaluation Committee (AEC): ISSTA 2027
  • Reviewer: IEEE Transactions on Dependable and Secure Computing (TDSC) (2025)
  • Reviewer: Transactions on Information Forensics & Security (TIFS) (2025, 2026)
  • Reviewer: Expert Systems with Applications (2026)
  • Reviewer: ACM International Conference on AI-powered Software (AIware) (2026)
  • Reviewer: Journal of Intelligent & Fuzzy Systems (2022)

📚 Teaching

  • Part-time Student Mentor: School of Cyber Science and Engineering @ SCU, 2020-2023