Any views expressed within media held on this service are those of the contributors, should not be taken as approved or endorsed by the University, and do not necessarily reflect the views of the University in respect of any particular issue.

Yangheran (Lawrence) Piao

Cybersecurity, Privacy and Trust PhD Student

About Me

I am Yangheran Piao[/jɑːŋ hə ɻæn piɑʊ/], a third-year PhD student at the School of Informatics, University of Edinburgh, under the supervision of Prof. Ross Anderson, Dr. Daniel W. Woods and Dr. Jingjie Li. My research interests include usable security, software supply chain security, security economics and cybercrime.

Currently, my work specifically investigates the behaviors and perceptions of key stakeholders in the vulnerability disclosure ecosystem, including the collective actions among hackers, the responses of vulnerability researchers to security laws, as well as the impact of these laws on them. I am also exploring AI vulnerability reporting practices and models.

 

News & Updates
  • 04/2026 – I have been invited as an LZI Junior Researcher and will attend the Dagstuhl Seminar on Computer Security Research Ethics in Wadern, Germany.
  • 01/2026 – My paper titled “Abuse Risks are Often Inherent to Product Features: Exploring AI Vendors’ Bug Bounty and Responsible Disclosure Policies” has been accepted for USENIX Security 2026.
  • 06/2025 – Our papers titled “Anticipating personal cyber insurance disputes: A US/UK user study” and “Unfairness in the bug bounty ecosystem: Problems, metrics, and solutions” were presented at WEIS 2025, Tokyo, Japan.
  • 03/2025 – I gave a presentation titled “The bug bounty manifesto: Collectivization and fairness” at Security Protocols Workshop in Cambridge. I also gave a brief talk on Ross’s research and activism regarding responsible disclosure at Rossfest Symposium.
  • 09/2024 – My paper titled “Study club, labor union or start-up? Characterizing teams and collaboration in the bug bounty ecosystem” has been accepted for IEEE S&P (Oakland) 2025.
  • 07/2024 – My poster titled “Finding bugs with friends: Incentivizing vulnerability discovery through teaming and collaboration” was presented at PETS 2024, Bristol, UK.

 

Recent Publications

 

Service

 

Teaching
    • Network Security (3150530011021, 52 students), Wuhan University, Spring 2020
  • Master’s Thesis Advising:
    • Harita Lolla, Navigating the Legal Barriers of Web Vulnerability Research (2023-2024)
    • Bocheng Zhang, Exploring Reddit Users Perceptions about the Legality of Vulnerability Research (2023-2024)

 

Invited Talk

27/05/2026. Collective Dynamics in the Bug Bounty Ecosystem. Invited by King’s College London

21/05/2026. Exploring AI Vendors Bug Bounty and Responsible Disclosure Policies. Invited by University of Glasgow

21/04/2026. Ethics in Privacy and Security Research. Invited by Huazhong University of Science and Technology

11/09/2025. Exploring Cooperative Practices Among Security Researchers in Vulnerability Reward Programs. Invited by Tsinghua University

24/07/2024. Incentivizing vulnerability discovery through teaming and collaboration. Invited by Google Chrome


Great research is done with a shovel, not with tweezers

Roger Needham

css.php

Report this page

To report inappropriate content on this page, please use the form below. Upon receiving your report, we will be in touch as per the Take Down Policy of the service.

Please note that personal data collected through this form is used and stored for the purposes of processing this report and communication with you.

If you are unable to report a concern about content via this form please contact the Service Owner.

Please enter an email address you wish to be contacted on. Please describe the unacceptable content in sufficient detail to allow us to locate it, and why you consider it to be unacceptable.
By submitting this report, you accept that it is accurate and that fraudulent or nuisance complaints may result in action by the University.

  Cancel