Hello!

My name is Zhuoer Lyu. I am currently a PhD student from SEFCOM at Arizona State University, mainly advised by Dr. Tiffany Bao. I also work with Dr. Adam Doupé, Dr. Fish Wang, Dr. Yan Shoshitaishvili, and Dr. Gail-Joon Ahn.

My research focuses on the data-driven study of cybercrime and online abuse. I develop measurement and detection techniques to understand malicious ecosystems at scale, with a particular focus on scam websites, fraudulent e-commerce, and scam calls. I am interested in uncovering how cybercriminal operations are organized, how they abuse web and communications infrastructure, and how large-scale empirical measurement can inform practical defenses.

Education

Ph.D. in Computer Science, Arizona State University

M.Sc. in Electrical Engineering, The Ohio State University

B.Sc. in Electrical Engineering, Sichuan University

Publications

  • When Scammers Talk Back: Understanding Potentially Unwanted Calls via LLM-Based Interaction
    Zhuoer Lyu, Marzieh Bitaab, Shuyi Huang, Alireza Karimi, William Robertson, Zeming Yu, Moritz Schloegel, Yan Shoshitaishvili, Gail-Joon Ahn, Ananta Soneji, Ruoyu Wang, Adam Doupé, Tiffany Bao
    ACM CCS 2026 paper artifact

  • No-Box Vulnerability Analysis: Description-only Detection of Indirect Prompt Injection Vulnerabilities in MCP Servers
    Zehua Zhang, Jie Hu, Pratham Hegde, Aditya Maheshbhai Gabani, Souradip Nath, Yibo Liu, Siyu Liu, Hongkai Chen, Hulin Wang, Zhuoer Lyu, Chang Zhu, Divij Handa, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang, Adam Doupé
    Preprint, 2026 paper

  • ScamNet: Toward Explainable Large Language Model-Based Fraudulent Shopping Website Detection
    Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Ahmadreza Mosallanezhad, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé
    AAAI 2025 paper

  • SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns
    Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad, Gail-Joon Ahn, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé
    NDSS 2025 paper

  • Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at Scale
    Marzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu, Wei Wang, Jorij Abraham, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé
    IEEE S&P 2023 paper

  • Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
    Octavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao, Tudor Dumitraş
    USENIX Security 2022 paper software

Teaching & Mentoring

  • Fall 2026, Guest Lecturer, CSE 598: Forensics Computing

  • Summers 2024-2025, Mentor, High School Cybersecurity Research Internship
  • Fall 2022, Teaching Assistant, CSE 365 Introduction to Information Assurance
  • Fall 2020, Teaching Assistant, CSE 545 Software Security course