He (Shawn) Shuang
He (Shawn) Shuang

Web Security Researcher

I am a web security researcher at Palo Alto Networks in the San Francisco Bay Area, where I develop machine learning models to detect and prevent web attacks, including advanced phishing pages and runtime assembly attacks. Previously, I was a researcher at Huawei Research Canada, where I focused on supply chain security and vulnerability detection using agentic approaches.

I hold a Ph.D. in Computer Engineering from the University of Toronto, advised by Prof David Lie and Prof Lianying Zhao. My doctoral research explored machine learning approaches to improve the security and privacy of web requests. I completed my Master of Applied Science under Prof David Lie and my Bachelor at the University of Toronto.

News

Agent Tripwire: Detecting Misbehaving AI Agents at Runtime

Agent Tripwire replaces attack classification with runtime invariants: inert tools, credentials, resources and cross-agent markers that no valid execution should touch. A trip triggers containment before the agent can produce a real side effect.

Device Code Phishing Evasion Techniques

Device-code phishing campaigns are combining CAPTCHA gates, multi-step SaaS lure chains, encrypted blob-page delivery and source-level text obfuscation to evade automated scanners and reputation checks.

Device Code-based OAuth Phishing

An active phishing campaign abuses Microsoft’s legitimate device-code OAuth flow to capture application tokens instead of passwords. The pages combine trusted sign-in screens with obfuscation, developer-tool detection and debugger traps.