Jingxuan He

I am an incoming Nanyang Assistant Professor at Nanyang Technological University (NTU) in Singapore, starting in Fall 2027. Currently, I am a Visiting Researcher at NVIDIA Research, based in the SF Bay Area and hosted by Edward Suh.

Previously, I was a PostDoc at UC Berkeley, working with Dawn Song. I received my PhD from ETH Zurich, advised by Martin Vechev. I finished my undergraduate at Zhejiang University.

何静轩  /  jingxuan.he [at] berkeley.edu  /  Scholar  /  X  /  LinkedIn

profile photo

Recruitment

I am looking for motivated PhD students, Postdocs, visiting students, and research assistants to join my group at NTU starting in Fall 2027. If you are interested or see a potential fit, I encourage you to apply by filling out this form.

Research

My research spans AI, programming languages, and security. I seek to answer a key question: How does AI reshape programming?

  • Security is a direct motivation. AI is becoming ever more capable of discovering and exploiting vulnerabilities, yet it keeps introducing them into the code it generates. My work has demonstrated these risks at scale and is widely used by the frontier AI industry (CyberGym, ExploitGym, BaxBench).
  • Guarantees by construction are my response. AI can absorb much of the effort traditionally required by secure- or correct-by-construction techniques, such as adopting safer programming languages, making them practical at unprecedented scale. I therefore build these techniques and their guarantees into how AI generates code, via typing, compilation, proofs, and training.

Honors and Awards

  • Oral Paper at ICLR 2026
  • Two Spotlight Papers at ICML 2025
  • ETH Medal for Oustanding Doctoral Thesis, 2024
  • ACM CCS Distinguished Paper Award, 2023
  • NeurIPS Top Reviewer, 2023

Publications

Generative Compilation: On-the-Fly Compiler Feedback as AI Generates Code


Niels Mündler-Sasahara*, Hristo Venev*, Dawn Song, Martin Vechev, Jingxuan He
ICML 2026 Workshop on Deep Learning for Code (DL4C), 2026
paper code

ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?


Zhun Wang, Nico Schiller, Hongwei Li, Srijiith Sesha Narayana, Milad Nasr, Nicholas Carlini, Xiangyu Qi, Eric Wallace, Elie Bursztein, Luca Invernizzi, Kurt Thomas, Yan Shoshitaishvili, Wenbo Guo, Jingxuan He, Thorsten Holz, Dawn Song
arXiv preprint, 2026
Covered by OpenAI-Huggingface incident and adopted by frontier AI industry (e.g., OpenAI, Anthropic, Z.ai)
paper code

CyberGym: Evaluating AI Agents' Real-World Cybersecurity Capabilities at Scale


Zhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai, Jialin Zhang, Dawn Song
International Conference on Learning Representations (ICLR), 2026   (Oral)
Adopted by frontier AI industry (e.g., OpenAI, Anthropic, Z.ai, DeepSeek, Microsoft)
paper code website dataset

Verina: Benchmarking Verifiable Code Generation


Zhe Ye, Zhengxu Yan, Jingxuan He, Timothe Kasriel, Kaiyu Yang, Dawn Song
International Conference on Learning Representations (ICLR), 2026
Adopted by startups working on AI for formal verification (e.g., Harmonic, Logical Intelligence, Axiom)
paper code website dataset

Type-Constrained Code Generation with Language Models


Niels Mündler*, Jingxuan He*, Hao Wang, Koushik Sen, Dawn Song, Martin Vechev
ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), 2025
paper code

BaxBench: Can LLMs Generate Secure and Correct Backends?


Mark Vero, Niels Mündler, Victor Chibotaru, Veselin Raychev, Maximilian Baader, Nikola Jovanović, Jingxuan He, Martin Vechev
International Conference on Machine Learning (ICML), 2025   (Spotlight)
paper code website dataset

Large Language Models for Code: Security Hardening and Adversarial Testing


Jingxuan He, Martin Vechev
ACM Conference on Computer and Communications Security (CCS), 2023   (Distinguished Paper)
paper code slides

Design and source code from Leonid Keselman's and Jon Barron's websites.