About
Shengxing Zhang
Software engineer with ten-plus years of experience; in data security and privacy-preserving systems since 2018, and in AI-agent security since 2025.
Since 2018 my work has been in data security and privacy-preserving systems: software engineering at Microsoft and Amazon, applied-cryptography research at the Peking University Chongqing Big Data Research Institute, and senior security engineering at Changan Automobile. The three years before that were Windows input methods at Beijing Xinyi. I studied at Beihang University: a B.Eng. in computer science and an M.Eng. in software engineering.
After leaving Changan Automobile in May 2025, I first filled in the practical AI side: running open-source models on Hugging Face, fine-tuning DeepSeek, building RAG and agent prototypes, and then using AI coding agents to run my own server. In a task that had nothing to do with SSH, I watched an agent open an SSH private key. Since then my direction has been AI-agent security; my experience in security and cryptography applies most directly there.
The result is AgentGuard, a least-privilege proxy for MCP tool calls, published on PyPI. The other project from the same period is The Three Column Method, an offline Android app built on the same least-privilege principle: no network permission and no cloud backup. The design tradeoffs behind both are in my writing.
Outside work I listen to classical music and play murder-mystery games; the part I have written down is on the interests page.
- Name
- Shengxing Zhang 张盛兴 · Zayden Zhang on LinkedIn
- Current focus
- AI-agent security · Applied cryptography · Cloud security
- Open to
- Security and AI-infrastructure roles
- Education
- Beihang University, B.Eng. and M.Eng.
- Stack
- Python · C++ · Java · Kotlin · C# · AWS (KMS, IAM, S3, DynamoDB, Lambda, SQS) · Linux
- GitHub
- zgemini22
- nzaocan@icloud.com
Experience
- May 2025 – present
- Independent · AI and security engineering
Designed and published AgentGuard (PyPI: agentguard-mcp, MIT), a least-privilege proxy for MCP tool calls: a policy engine for files, commands and network calls, session budgets and sequence rules, an ask verdict answered by a human, prompt-injection detection and secret redaction on tool outputs, and a hash-chained audit log that can be anchored; 34 rules, 369 tests, 93% line coverage, full threat model. Alongside it, I build and maintain a self-hosted server stack and use AI coding agents (Claude Code) for day-to-day deployment, diagnostics and troubleshooting.
- Nov 2024 – May 2025
- Changan Automobile · Senior Security Engineer, Information Security Lab
Won approval for a 24-month, ¥8M corporate privacy-computing programme: led the feasibility study and wrote the full proposal, covering four directions — ZKP-based identity and data authentication, anonymous V2X communication, computation on homomorphically encrypted data, and federated learning for autonomous-driving models. Mentored two graduate research interns.
- Apr 2023 – Oct 2024
- Peking University Chongqing Big Data Research Institute · Research Software Engineer
Implemented SM (Chinese national-standard) precompiles for a blockchain EVM, deployed in pilots for Beijing government agencies and regional carriers (China Unicom, China Mobile): point add, scalar mul and pairing on the SM2/SM9 curves using GmSSL; SM2 verification (replacing ecrecover), SM4, and SM9 verification and pairing; gas priced from benchmarks; fuzzed decoders at the C boundary. Led a redactable blockchain from research prototype to a working system with pluggable consensus: about 10K TPS on Raft, about 1K TPS on BFT (TBFT/IBFT). Written up in Putting the SM algorithms behind the EVM's precompiles.
- Sep 2020 – May 2022
- Amazon · Software Engineer, Global Store
Designed and shipped the cross-Pacific data-transfer service between the AWS China and global partitions, about 2 TB per full run: KMS envelope encryption with one key request per batch and an RSA asymmetric key handoff across two mutually untrusting IAM domains; idempotent resume through manifests and a DynamoDB state machine; three verification layers (per-object SHA-256, manifest reconciliation, S3 Inventory diff) with S3 Object Lock for immutability; multi-stream transfers over Direct Connect. Built microservice data layers on DynamoDB, S3, Lambda and SQS, and migrated legacy web-framework components to a Spring-MVC-style framework. Also ran releases and on-call: shipped through review gates, integration tests and A/B validation, and resolved about 400 production alerts and tickets over 20 months. Written up in Moving two terabytes across the Pacific.
- Oct 2018 – Sep 2020
- Microsoft · Software Engineer; Research Intern, MSRA System Security Group
Designed the migration of Azure's cluster-management storage service (Pilotfish) to 8- and 16-node edge clusters: Paxos-based strong consistency combined with weak-consistency peer sync, crash and power-loss recovery, certificate-based node authentication, and containerised deployment. The design passed review and the prototype was delivered. As an MSRA intern (Oct 2018 – Aug 2019), built an Ethereum transaction-time prediction system shown at Microsoft Hackathon 2019; MSRA Award of Excellence.
- Oct 2015 – Sep 2018
- Beijing Xinyi · Software Engineer, Windows input methods
Shipped four Windows IMEs for low-resource scripts (Sanskrit, Pali, Brahmi, Tangut), used by more than 100K people including several universities and the Central Academy of Fine Arts: C++ on TSF and WPF, each TSF manager under 4 MB of memory. Designed HFDict, an encrypted dictionary format with searchable ciphertext; lookups over one-million-entry dictionaries stay under 20 ms.
Education
- Sep 2017 – Feb 2020
- Beihang University · M.Eng., Software Engineering
- Sep 2011 – Jul 2015
- Beihang University · B.Eng., Computer Science
How I work
A few habits run through these projects and articles.
Limits go where the program cannot get around them. A permission an app never received is more reliable than a policy it promises to follow, and a proxy at the protocol layer is more reliable than a request written in a prompt. The reason is not distrust of the model: something a program cannot do is easier to verify than something it has agreed not to do.
What a tool does not defend against is written as clearly as what it does. AgentGuard's threat model and the Three Column Method article each have a section on costs and gaps. A reader who knows what the tool never promised knows which checks are still theirs to do.
I test the artifact that is actually deployed, not a sample of it. The injection rule that shipped narrower than intended was found by a test suite that loads the real policy file. A hand-written test string only proves that the regex in my head is right, not the one that is actually loaded.
Numbers over adjectives. Numbers that can be recomputed — coverage, rule counts, line counts — come with the method used to compute them. Numbers that only memory can supply are given as orders of magnitude, with the estimate written out.