Lei Xu (徐雷)
Principal Machine Learning Engineer & Security Researcher @ Palo Alto Networks
Ph.D. in Computer Science and Engineering @ Texas A&M University

About me
I am a Principal Machine Learning Engineer and Security Researcher with over a decade of dual-domain expertise bridging the gap between high-throughput data science and line-rate system defense.
Currently, I lead core research and productization initiatives at Palo Alto Networks (PANW). My work focuses on architecting and deploying enterprise-scale intelligent security systems. Specifically, I specialize in machine learning-based network threat detection and response. By injecting advanced machine learning paradigms straight into low-latency infrastructure, my team and I translate complex theoretical AI into battle-tested production engines capable of defending modern cloud-native environments. Driven by these industrial defense challenges, my engineering and research initiatives at Palo Alto Networks have yielded 10+ filed/issued U.S. patents.
I earned my Ph.D. in Computer Science and Engineering from Texas A&M University under the mentorship of Dr. Guofei Gu. My foundational academic research focused on programmable security frameworks, SDN/NFV zero-trust architecture, and automated threat synthesis, resulting in numerous publications in premier security venues, including USENIX Security, NDSS, ACM CCS, IEEE TIFS, and IEEE/ACM TON.
Recent News
- [Service] Serving as Technical Program Committee (TPC) member for IEEE ICC Communication and Information Systems Security Symposium.
- [Patent] Filed a new patent application on cross-protocol malware traffic detection using multi-layered ML architectures.
- [Publication] Our paper “SysFlow: Towards a Programmable Zero Trust Framework for System Security” got published in IEEE TIFS.
Selected Publications (full list)
- [IEEE TIFS’23] [Sungmin Hong, Lei Xu]*, Jianwei Huang, Hongda Li, Hongxin Hu, Guofei Gu. “SysFlow: Towards a Programmable Zero Trust Framework for System Security.” In IEEE Transactions on Information Forensics and Security, 2023. (*Co-first author)
-
[IEEE/ACM TON’21] Menghao Zhang, Guanyu Li, Lei Xu, Jiasong Bai, Mingwei Xu, Guofei Gu, Jianping Wu. “Control Plane Reflection Attacks and Defenses in Software-Defined Networks.” In IEEE/ACM Transactions on Networking, 2021.
-
[NDSS’19] Yangyong Zhang, Lei Xu, Abner Mendoza, Phakpoom Chinprutthiwong and Guofei Gu. “Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant Applications.” In Proc. of the 26th Annual Network & Distributed System Security Symposium, 2019.
-
[ACM CCS’18] Haopei Wang, Guangliang Yang, Phakpoom Chinprutthiwong, Lei Xu, Yangyong Zhang and Guofei Gu. “Towards Fine-grained Network Forensics and Diagnosis in the SDN Era.” In Proc. of the 25th ACM Conference on Computer and Communications Security, 2018.
-
[USENIX Security’17] Lei Xu, Jeff Huang, Sungmin Hong, Jialong Zhang and Guofei Gu. “Attacking the Brain: Races in the SDN Control Plane.” In Proc. of the 26th USENIX Security Symposium, 2017.
-
[IEEE INFOCOM’17] Haopei Wang, Abhinav Srivastava, Lei Xu, Sungmin Hong, Guofei Gu. “Bring Your Own Controller: Enabling Tenant-defined SDN Apps in IaaS Clouds.” In Proc. of IEEE International Conference on Computer Communications, 2017.
-
[NDSS’16] Sungmin Hong, Robert Baykov, Lei Xu, Srinath Nadimpalli, Guofei Gu. “Towards SDN-Defined Programmable BYOD (Bring Your Own Device) Security.” In Proc. of the Network & Distributed System Security Symposium, 2016.
-
[IEEE/IFIP DSN’15] Haopei Wang, Lei Xu, Guofei Gu. “FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks.” In Proc. of the 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, 2015.
-
[NDSS’15] [Sungmin Hong, Lei Xu]*, Haopei Wang, Guofei Gu. “Poisoning Network Visibility in Software-Defined Networks: New Attacks and Countermeasures.” In Proc. of the 22nd Annual Network & Distributed System Security Symposium, 2015. (*Co-first author)
Selected Patents
- [GenAI & Data Security] Lei Xu, Yu Fu, and Mei Wang. “Graph-based detection of conflicting aliases in language model-based text to database query conversion systems.” US Patent Application 18/932,084, 2026.
- [ML for malware traffic detection] Chitra Priyaa Sathya Moorthy and Lei Xu. “Deep learning for in-line detection of malicious command and control traffic from unstructured payloads.”* US Patent Application 18/649,280, 2025.
- [GenAI & NLP Search] Lei Xu, Zhepu Zhao, Yu Fu, Ran Xia, and Mei Wang. “Global search of a security related data store using natural language processing.” US Patent Application 18/500,123.
- [Systems Telemetry] Lei Xu, Yang Ji, and Yu Fu. “Kernel space feature generation for user space machine learning-based malicious network traffic detection.” US Patent Application 18/355,486.
- [Encrypted Traffic Detection] Lei Xu, Stefan Achleitner, Yu Fu, and Shengming Xu. “Inline detection of encrypted malicious network sessions.” US Patent Application 17/447,064.
- [Cross-Protocol AI] Lei Xu, Taojie Wang, and Shengming Xu. “Cross protocol malware traffic detection using a two-layer ML architecture.” US Patent Application 18/394,403.
- [Browser Guard & CDR] Lei Xu, Yu Fu, and Mei Wang. “Machine learning-based content disarm and reconstruction with web browser prefetching.” US Patent Application.
- [Adversarial ML Defense] Ajaya Neupane, Yu Fu, Lei Xu, Mei Wang, and Fikirte Ayalke Demmese. “Adversarial training for malicious protocol data unit detection with field value perturbations.” US Patent Application 18/482,719.
- [Cloud Engine Optimization] Yu Fu, Lei Xu, Jin Chen, Zhibin Zhang, Bo Qu, and Stefan Achleitner. “Sequential dual machine learning models for effective cloud detection engines.” US Patent Application 17/862,877.
- [Targeted Threat Detection] Zhibin Zhang, Jin Chen, Yu Fu, Stefan Achleitner, Qu Bo, and Lei Xu. “Network attack detection with targeted feature extraction from exploit tools.” US Patent Application 17/862,869.
- [Cloud Security Architecture] David Ott, Lei Xu, and Dennis R. Moreau. “Extensible information architecture for enabling programming security in enterprise clouds.” US Patent Application 16/288,681.
- [Cross-Domain Host Protection] David Ott, Lei Xu, Ruimin Sun, Vijay Ganti, and Dennis R. Moreau. “Security protection for a host computer in a computer network using cross-domain security-relevant information.” US Patent Application 16/255,551.
Professional Services
Technical Program Committee Member
- IEEE ICC Communication and Information Systems Security Symposium: 2020, 2021, 2022, 2023, 2024, 2025, 2026.
- IEEE CNS (Conference on Communications and Network Security): 2025, 2026.
- International Conference on Security and Privacy in Digital Economy (Zhenjiang, China): 2020.
- ACM SDN-NFV Security Workshop (Dallas, TX): 2016, 2018, 2019.
Journal Reviewer
- IEEE TIFS (Transactions on Information Forensics and Security): 2018, 2019, 2024, 2025.
- IEEE TDSC (Transactions on Dependable and Secure Computing): 2017, 2022, 2023, 2025.
- Computer Networks (Elsevier): 2020.