A Letter to Prospective Students

My thoughts on security research, mentoring, and research opportunities.

Dear Prospective Student,

Thank you for your interest in me and my work.

I’m excited to share my passion for security research with you. This captivating field has consumed years of my life, and I am committed to dedicating many more.

Security research intrigues me for several reasons.

  • Concrete questions: Many security papers explain new ideas through concrete attacks, systems, and real-world consequences. This makes it possible to begin engaging with current research while gradually building deeper technical foundations.

  • Interdisciplinary: Security intersects with all other domains within computer science and computer engineering. It provides an ideal environment for conducting interdisciplinary research by blending expertise from various fields.

  • Human-oriented: Security involves the dynamics of attackers, defenders, and trust. It raises sociological, psychological, and even philosophical questions while connecting us to the intriguing world of hackers and white hats.

  • Constantly evolving: New languages, platforms, and tools continually create new assumptions and attack surfaces. I am eager to understand the security implications of technologies that may change how people build and use computing systems.

Nonetheless, challenges await anyone venturing into security research. A project often begins with a large and unfamiliar codebase, an underspecified failure, or an experiment that refuses to reproduce. You will encounter bugs that have not been discussed on GitHub or Stack Overflow, and you may need to test several possible explanations and solutions before finding one that works. Research progress is rarely linear, and learning to navigate this uncertainty is a central part of the training.

how projects begin

Many promising projects begin with a student’s existing technical experience: a tool they have built, a system they understand well, or a recurring limitation they have encountered. I enjoy working with students to distill the underlying security or software-engineering question and pursue insights that extend beyond the original tool or system.

Your starting point does not need to be a conventional security project. Experience with a technical ecosystem may reveal behaviors that existing tools fail to expose, preserve, measure, or explain. This is one productive way for a project to begin, but not a prerequisite; students may also start from a well-scoped problem and develop increasing ownership over time.

what I look for

For undergraduate and master’s students, I do not expect a prior publication or a fully formed research agenda. I value solid programming skills, intellectual honesty, reliability, curiosity, and the willingness to read unfamiliar code. Most projects require at least six months of consistent work.

For Ph.D. students and prospective applicants, I look for a broader research fit and the desire to take long-term ownership of difficult questions. Over time, a Ph.D. student should learn to connect technical observations to the literature, make independent methodological decisions, and communicate a convincing research argument.

AI coding and research tools are now part of ordinary technical work, and I welcome their responsible use. They do not replace technical ownership. You should be able to explain your decisions, verify results, debug failures beyond generated suggestions, and defend every artifact and claim you contribute.

what you can expect from me

I take a hands-on approach to mentoring. I work with students to sharpen research questions, reason through technical obstacles, design convincing evaluations, and communicate results clearly. My goal is to help each student become increasingly independent while still having dependable support when a project gets difficult.

No research project comes with a guaranteed publication. What I can promise is a serious process: regular feedback, high technical standards, and a shared effort to produce work we are proud of.

Embarking on this journey will undoubtedly be challenging, but it will equip you with the tools and judgment needed to establish your own career path.

research at RIT

RIT provides a strong environment for security research. Its cybersecurity program has ranked among the top 20 nationally in recent editions of U.S. News & World Report. The broader Computing and Information Sciences Ph.D. program ranks around the top 60 in the United States according to CSRankings’ ten-year publication-based measure.

The ESL Global Cybersecurity Institute brings together more than two dozen faculty across RIT. Its research facilities include a Cyber Range capable of hosting more than 5,000 virtual machines for immersive security scenarios. The Computing and Information Sciences Ph.D. program connects faculty and students across cybersecurity, computer science, software engineering, and related areas.

getting in touch

Thank you for reading through to the end. If you are still interested, please fill out this form. Tell me what you have built or studied, which technical systems you know well, and how much time you can commit. I will get back to you via email if there is a good match.

Yinxi