Minhuan Huang

dblp:11/7859 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
6since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1
YearPublicationVenuePosition
2026 Large language models-driven fuzzing: A systematic survey
Yuxian Wan, Minhuan Huang, Xiang Li 0078, Yuanping Nie, Wenyu Zhen
Eng. Appl. Artif. Intell.2
2025 SoK: From Systematization to Best Practices in Fuzz Driver Generation
Minhuan Huang, Huayang Cao, Shuaibing Lu
ACISP (3)2
2025 SeedOrNot: A Classification-Based Framework for Efficient Seed Scheduling in Hybrid Fuzzing
abstract
Hybrid fuzzing combines fast mutation with symbolic execution to detect both shallow and deep vulnerabilities. A core challenge is seed scheduling, which involves selecting inputs for symbolic analysis under limited resources. Existing schedulers often use fixed heuristics or regression models that generalize poorly, leading to unstable prioritization and redundant symbolic exploration. This results in wasted effort and ineffective testing. We introduce SeedOrNot, a lightweight and adaptive framework that formulates seed selection as a binary classification task. It combines an offline classifier with an online learner via a confidence-aware adaptive fusion strategy, achieving both stability and responsiveness. We implement SeedOrNot and evaluate it on six real-world programs. It outperforms heuristic-based (e.g., QSYM) and learning-based (e.g., MEUZZ) fuzzers, with up to $\mathbf{1 4. 1 \%}$ more branch coverage over QSYM and 6.5% over MEUZZ, while adding negligible runtime and memory overhead. Our results demonstrate that classification-based scheduling is a practical and effective method to improve hybrid fuzzing.
Minhuan Huang, Huayang Cao
APSEC2
2024 Suitable is the Best: Task-Oriented Knowledge Fusion in Vulnerability Detection
abstract
Deep learning technologies have demonstrated remarkable performance in vulnerability detection. Existing works primarily adopt a uniform and consistent feature learning pattern across the entire target set. While designed for general-purpose detection tasks, they lack sensitivity towards target code comprising multiple functional modules or diverse vulnerability subtypes. In this paper, we present a knowledge fusion-based vulnerability detection method (KF-GVD) that integrates specific vulnerability knowledge into the Graph Neural Network feature learning process. KF-GVD achieves accurate vulnerability detection across different functional modules of the Linux kernel and vulnerability subtypes without compromising general task performance. Extensive experiments demonstrate that KF-GVD outperforms SOTAs on function-level and statement-level vulnerability detection across various target tasks, with an average increase of 40.9% in precision and 26.1% in recall. Notably, KF-GVD discovered 9 undisclosed vulnerabilities when employing on C/C++ open-source projects without ground truth.
Minhuan Huang, Yuanping Nie, Xiang Li 0078, Qianjin Du, Xiaohui Kuang
NeurIPS2
2023 ADV-POST: Physically Realistic Adversarial Poster for Attacking Semantic Segmentation Models in Autonomous Driving
Minhuan Huang, Tong Wang 0042, Jianwen Tian, Xiaohui Kuang
ICONIP (13)2
2023 Fine-Grained Source Code Vulnerability Detection via Graph Neural Networks (S)
abstract
Although the number of exploitable vulnerabilities in software continues to increase, the speed of bug fixes and software updates have not increased accordingly.It is therefore crucial to analyze the source code and identify vulnerabilities in the early phase of software development.However, vulnerability location in most of the current machine learning-based methods tends to concentrate at the function level.It undoubtedly imposes a burden on further manual code audits when faced with largescale source code projects.In this paper, a fine-grained source code vulnerability detection model based on Graph Neural Networks (GNNs) is proposed with the aim of locating vulnerabilities at the function level and line level.Our empirical evaluation on different C/C++ datasets demonstrated that our proposed model outperforms the state-of-the-art methods and achieves significant improvements even when faced with more complex, real-project source code.
Minhuan Huang, Yuanping Nie, Xiaohui Kuang, Xiang Li 0078, Wenjing Zhong
SEKE2
2017 A Novel Method Makes Concolic System More Effective
abstract
Fuzzing is attractive for finding vulnerabilities in binary programs. However, when the application's input space is huge, fuzzing cannot deal with it well. For discovering vulnerabilities more effective, researchers came up concolic testing, and there are much researches on it recently. A common limitation of concolic systems designed to create inputs is that they often concentrate on path-coverage and struggle to exercise deeper paths in the executable under test, but ignore to find those test cases which can trigger the vulnerabilities. In this paper, we present TSM, a novel method for finding potential vulnerabilities in concolic systems, which can help concolic systems more effective for hunting vulnerabilities. We implemented TSM method on a wide-used concolic testing tool-Fuzzgrind, and the evaluation experiments show that TSM can make Fuzzgrind hunt bugs quickly in real-world software, which are hardly found ever before.
Hongliang Liang, Minhuan Huang, Xiaoxiao Pei
CSCloud3
2014 An Approach of Discovering Causal Knowledge for Alert Correlating Based on Data Mining
abstract
The process of attackers exploiting the target facilities is always gradual in cyberspace, and multiple attack steps would be performed in order to achieve the ultimate goal. How to identify the attack scenarios is one of the challenges in many research fields, such as cyberspace security situation awareness, the detection of APT (Advanced Persistent Threat) and so on. Alert correlation analysis based on causal knowledge is one of the widely adopted methods in CEP (Complex Event Processing), which is a promising way to identify multi-step attack processes and can reconstruct attack scenarios. However, current researches suffer from the problem of defining causal knowledge manually. In order to solve this problem, we propose an approach of mining for causal knowledge automatically based on the Markov property in this paper. Firstly, the raw alert stream is clustered into several alert sets, then each set is mined in order to obtain the one step transition probability matrix based on the Markov property, and after being generated, each matrix represents a piece of causal knowledge. Then we fuse the knowledge which has overlapping steps to create the knowledge base of attack patterns. Finally the experimental results show that this approach is feasible.
Xuewei Feng, Dongxia Wang 0001, Minhuan Huang, Xiao Xia Sun
DASC3
2013 Towards Implicitly Introspecting the Preinstalled Operating System with Local-Booting Virtualization Technology
abstract
The virtual machine (VM) based introspection on the operating system (OS) holds predominance over previous host-based introspectors for being more resistant to attack while suffering the difficulty of retrieving the semantic view of the OS. Previous approaches addressing this limitation highly depend on the explicit guest information which is still subvertable to the privileged malware. Moreover, they only deal with the OS deployed in the VM instead of our daily used native OS. In this paper, we present a new VM-based introspecting approach called Pisces which accurately reproduces the execution environment of the underlying preinstalled OS within the Pisces VM and provides an OS-level semantic view. With our novel local-booting virtualization technology, Pisces VM just boots from the underlying host OS but not a newly installed OS image. Thus, Pisces provides a feasible way to introspect on the existing OS. In addition, instead of relying on the explicit guest information, Pisces adopts a set of unique techniques to implicitly construct the semantic view of the OS from within the virtualized hardware layer. The evaluation results demonstrate its practicality and effectiveness.
Yan Wen 0001, Jinjing Zhao, Minhuan Huang
DASC4
2011 An Overview of Bootkit Attacking Approaches
abstract
Boot kit, as an innovative root kit technology, transfer its storage location from the file system to the hardware store, and activates itself while or even before the operating system kernel is loaded. Therefore, boot kit can tamper the operating system and control the whole computer system. Compared to classic malware, it achieves a more powerful capability of hiding and controlling. This paper takes an overview of existing various boot kit technologies and summarizes their technical characteristics. This opens a door to the malware defenders for preventing the computer systems from boot kit.
Xiang Li 0078, Yan Wen 0001, Minhuan Huang
MSN3
2011 Research on survivability metrics based on survivable process of network system
abstract
Survivability is a necessary property of network system in disturbed environment. A survivable network always experience five phases, i.e., normal phase, resistance phase, destroyed phase, recovery phase, and adaptation and evolution phase, in its survivable process. This paper concludes the network survivability into four basic attributes: availability, controllability, robustness, and adaptability. According to these four attributes and five phases of a survivable network, this paper provides four novel quantifiable survivability metrics, i.e., Process-Weighted Average Availability (PWAA), Process-Weighted Average Controllability (PWAC), Process-Weighted Average Robustness (PWAR), and Process-Weighted Average Adaptability (PWAD). Analysis and Experiment results show that, these four quantitative metrics describe the meaning of network survivability properly, and can be used to test and evaluate survivability of network during the survivable process.
Liang Ming, Minhuan Huang, Dongxia Wang 0001, Xiaohui Kuang, Xuewei Feng
SIN2
2011 Towards Detecting Thread Deadlock in Java Programs with JVM Introspection
abstract
Deadlock is a common error for multithread Java programs. Existing Java thread deadlock detection solutions either require source code, or are built on non-official JVMs. In a consequence, a great number of Java programs cannot be evaluated with these solutions. This paper proposes a new Java thread deadlock detection approach, namely JDeadlockDetector. JDeadlockDetector is built on the official Java Virtual Machine (JVM), viz., OpenJDK's HotSpot. Compared to existing methods, JDeadlockDetector archieves three unique advantages, i.e., application transparency, detection accuracy and minimized performance overhead. Our functionality evaluation shows JDeadlockDetector achieves no false negative and minimized false positive while the performance evaluation shows the workloads generated by SPECjbb2005 achieve 96.7% of official JVM speed on average.
Yan Wen 0001, Jinjing Zhao, Minhuan Huang
TrustCom3
2009 Research on Technologies of Building Experimental Environment for Network Worm Simulation
abstract
The worm experimental environment is a pivotal foundation for the worm research. In this paper, with a comprehensive analysis of existing technologies for building worm experimental environment, including analytical model, packet-level simulation, network simulation, hybrid method, and so on, we present a novel virtual-real hybrid worm simulation model. This model integrates the advantages of network simulation and packet-level simulation, and thus achieves a preferable balance between the fidelity and scalability. Our model builds a promising foundation for constructing a flexible and extensible worm experimental environment.
Minhuan Huang, Xiaohui Kuang, Yan Wen 0001
ICPADS1