
Dr Zhuoran (Newt) Tan
If it’s right, time will catch up.
LLM Agent Security · Runtime Analysis · Memory & Binary Analysis · Full-Lifecycle Software Security
I research and build security analysis systems for AI agents and modern software ecosystems, combining Python, Go, Rust, and TypeScript engineering with runtime observability and threat detection.
Research Interests & What I Build
- Runtime trajectory monitoring for AI agents, focusing on decisions, tool calls, execution flows, and anomalous, obfuscated, or stealthy behavior.
- Memory and binary analysis for uncovering vulnerabilities, malicious behavior, and low-level indicators in compiled software and runtime environments.
- Full-lifecycle software security analysis spanning source code, dependencies, build and CI/CD pipelines, deployment environments, and runtime behavior.
Recent News
- 2026-08 - Our Paper, “SandScope: A Behavioral Audit Layer for MCP Tools in LLM Agent Supply Chains” has been accepted to Conference on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED ‘26), see you in Prague, Czechia.
- 2026-0819 — 🎓 I passed my PhD viva with no corrections (5% of all PHD vivas)!!!
- 2026-07 — After a month of intensive study, I earned the GitHub Advanced Security certification.
- 2026-07 — 🎉 Our paper, “An Empirical Study of Observability Limits in Advanced Software Supply Chain Attacks,” (full paper coming soon) has been (directly) accepted to ACM CCS 2026! See you in The Hague, the Netherlands.
- 2026-06 — !! Submitted my thesis: Runtime Observability and Security Analytics for Software Supply Chain Defense, marking a major milestone toward the completion of my degree.
Medium · GitHub · Google Scholar · LinkedIn · ResearchGate · Credly