VLDB 2026 Research / reviewers in the wild / expert
Shunhui Ji
dblp:12/7096
· DBLP profile ↗
42ranked-venue papers
12as first author
34since 2021 · last 2026
0000-0002-8584-5795ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 33 · 9 first-author · 26 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 9 · 4 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MGR-Net: Multimodal Fusion Network for Ponzi Scheme Detection Based on Graph Refinement
Jinqi Lei, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001 |
COMPSAC | 4 |
| 2026 | SD-MIL: A Two-Stage De-Noising Framework for Smart Contract Vulnerability Detection via Multi-Instance Learning
Jiaying Xie, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001 |
COMPSAC | 4 |
| 2026 | LLM-Driven Smart Contract Vulnerability Detection Based on Heterogeneous Graphs
Yunhan Zhang, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001 |
COMPSAC | 4 |
| 2026 | Multi-modal Perturbation Based Imperceptible Chinese Adversarial Example Generation
Shunhui Ji, Yingying Shen, Mingxuan Xiao |
ICIC (23) | 1 |
| 2026 | TIAFuzz: Transferable fuzzing via distillation for image-based deep learning systems
Shunhui Ji, Hai Dong 0001, Yan Xiao 0002, Mingxuan Xiao, Pengcheng Zhang 0001 |
Expert Syst. Appl. | 2 |
| 2026 | Automated robustness testing for LLM-based natural language processing software
Mingxuan Xiao, Yan Xiao 0002, Shunhui Ji, Hanbo Cai, Lei Xue 0001, Pengcheng Zhang 0001 |
Expert Syst. Appl. | 3 |
| 2026 | OSEL: boosting vulnerability detection with opcode slicing-enhanced feature learning
Yanxiang Tong, Shengkai Gao, Shunhui Ji, Pengcheng Zhang 0001 |
Softw. Qual. J. | 5 |
| 2026 | A Review of Learning-based Smart Contract Vulnerability Detection: A Perspective on Code RepresentationabstractWith the rapid development of blockchain technology, smart contract applications have become increasingly widespread. However, vulnerabilities in contracts may be exploited by attackers, causing serious financial losses. In recent years, learning-based approaches have gained prominence for their accuracy and efficiency by automatically extracting explicit syntactic or semantic features from a large number of smart contracts with minimal manual intervention. In this article, we conduct a comprehensive analysis and ultimately select 61 scientific publications to provide researchers, especially beginners, with a comprehensive understanding of the learning-based detection process and guidance on selecting appropriate code representations. We first introduce common types of vulnerabilities, detail uncovered vulnerabilities, and summarize datasets used in learning-based methods. Then, we elaborate on the general process of learning-based detection and classify existing publications based on code representations, including sequence, tree, graph, and mixed features. Finally, we summarize the progress of existing work and explore future research directions in this field. Yanxiang Tong, Shunhui Ji, Hai Dong 0001, Xiapu Luo, Pengcheng Zhang 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | Dynamic Variance Reduction-Based Reusable Test Case Generation for Image ClassificationabstractThe widespread use of deep learning has made ensuring the robustness of image classification models a critical challenge for system security. Research has demonstrated that adversarial examples can serve as test cases to find errors in models and evaluate their robustness. Existing ensemblebased methods are designed to improve the effectiveness of adversarial test case generation by integrating multiple models. However, they still face key challenges, including limited perturbation diversity, inaccurate gradient directions, and high gradient variance across models, which reduce the effectiveness of surrogate-based test cases on other models and increase testing costs. To address these issues, we propose a dynamic variance reduction-based reusable test case generation method (DVRTM). This method uses a two-level gradient-based update mechanism for test case generation: an outer loop and an inner loop. The outer loop ensembles gradients from multiple models to increase perturbation diversity. In the inner loop, one model is randomly selected in each iteration. The input example is then adjusted dynamically based on the model’s gradient and loss. The gradients of the example before and after adjustment are combined with historical gradient information to reduce gradient variance and optimize the gradient direction, thereby avoiding overfitting to a single model. Experimental results show that DVRTM outperforms comparison methods on CIFAR-10, CIFAR-100, and ImageNet datasets. On the CIFAR-10 dataset, the test cases generated by DVRTM achieve the highest average error detection rate of 92.69% across models with different architectures. Even when target models adopt defense methods, DVRTM maintains stable and superior detection performance. Changrong Huang, Shunhui Ji |
APSEC | 2 |
| 2025 | ISA: Test Case Generation Based on Improved Simulated Annealing AlgorithmabstractWith the rapid development of deep learning in the text domain, text classification software is commonly used. However, DNN (Deep Neural Network) based text classification software is easily misled by interfering information such as noisy text. It is important to test the text classification software to evaluate its robustness. Existing test methods have limitations, low test success rate, poor quality, high count of queries, etc. To address these issues, we propose a test case generation method based on the Improved Simulated Annealing Algorithm (ISA), which generates test cases through word substitution. ISA utilizes a hierarchical attention network model to evaluate word importance to identify words for substitution. And it uses an optimized BERT model to generate candidate words. During the search process for the optimal test cases, the word substitution rate and semantic perplexity are incorporated into the objective function for searching test cases with good quality, while introducing an adaptive cooling function to shorten generation time. Experimental results show that the test cases generated by ISA can achieve an average test success rate of 94.7%. Compared to the baseline method, the average word substitution rate decreased by at least 15.7%, and the method has a relatively low time cost. Shunhui Ji, Ji Deng |
APSEC | 1 |
| 2025 | IPSO: An Improved Particle Swarm Optimization-Based Method for Test Case GenerationabstractRapid advancement of DNNs has exposed significant vulnerabilities to NLP software defects, raising critical security concerns. Researchers have proposed various automated testing techniques to generate adversarial test cases. However, existing methods have two limitations: poor quality test cases and inefficiency in time. To address these issues, we propose IPSO, an automated test case generation method integrating word scoring via Locality Sensitive Hashing (LSH) and adaptive probability mutation. The method firstly performs synonym substitution on the influential positions of the test case via word score selection and initializes the high-quality particle swarm. Then, by considering the fitness function of confidence, change rate and semantic perplexity, the test cases are evaluated and constrained comprehensively to improve the quality of the generated test cases. Finally, adaptive probability mutation is adopted to prevent the particle swarm from falling into local optima. Experiments on three datasets and five DNN models show that IPSO consistently has the highest success rate and generates semantically coherent test cases with at least $\mathbf{5 0. 5}$ % less time overhead than heuristic baselines. For example, in the IMDB dataset, IPSO reduces query numbers by 87.7% compared to traditional PSO. Shunhui Ji, Yikun Guo |
APSEC | 2 |
| 2025 | MVGText: Momentum and Variance Guided Hard-Label Text Test Case GenerationabstractDeep neural network (DNN) based text intelligence softwares have proliferated and have been widely used. However, they face challenges such as robustness. Testing is essential to DNNs in real-world applications. Researchers have proposed various testing techniques for generating test cases. With the black-box hard-label setup where only the output label of the DNN is accessible, related studies mainly concentrated on generating the new text test case by iteratively perturbing single initial test case, which limits the effectiveness. To address this issue, this paper proposes a new text test case generation method MVGText (Momentum and Variance Guided hard-label Text test case generation) for text-oriented DNN, which generates high-quality text test cases by searching based on multiple initial test cases. Firstly, multiple initial text test cases are generated randomly, in which global fixed word replacement is employed to enhance the success rate. Then, momentum and variance are applied to guide the search for the more imperceptible test case. Finally, greedy optimization is used to obtain a higher quality test case. Experimental evaluation shows that MVGText achieves an average post-test success rate of 1.4%. Furthermore, the test cases generated by MVGText exhibit the highest similarity to the original text compared to other comparative methods. Shunhui Ji, Changrong Huang, Letian Cheng, Pengcheng Zhang 0001 |
COMPSAC | 1 |
| 2025 | Smart Contract Reentrancy Vulnerability Localization Using Explainable Graph Neural NetworksabstractWhile smart contracts, as automatic processing programs for decentralized applications deployed on the blockchain, have gained widespread attention, their vulnerabilities have also led to significant economic losses. To address this security issue, researchers have proposed various approaches for locating vulnerabilities in smart contracts. However, most of them are designed to identify vulnerable smart contracts within a blockchain-based application. Only a few approaches adopt deep learning techniques to locate the exact line containing the reentrancy vulnerability based on Ethereum smart contracts’ source code. In this paper, we focus on the bytecode of Ethereum smart contracts and propose DeepLocator, a deep learning-based two-phase locator designed to pinpoint code-line-level reentrancy vulnerabilities. In the detection phase, DeepLocator constructs an attributed control flow graph extracted from the smart contract’s opcodes, and applies graph neural networks (GNNs) to determine whether a contract contains reentrancy vulnerabilities. In the localization phase, DeepLocator employs a model explainer of GNNs to rank the opcodes of each vulnerable smart contract according to their impact on the detection phase’s results, and then maps them back to the source code with the output of ranked suspicious statements. Empirical experiments conducted on widely used datasets of reentrancy vulnerabilities validate the efficacy of our locator. DeepLocator outperforms baseline traditional and learning-based detection approaches by 28.7% and 3.5%, respectively. Moreover, it pinpoints 20.0%, 61.1%, and 74.5% vulnerabilities within the top 1, 5, and 10 ranked suspicious statements, respectively. Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001 |
COMPSAC | 3 |
| 2025 | Clean-label backdoor attack based on robust feature attenuation for speech recognition
Hanbo Cai, Pengcheng Zhang 0001, Yan Xiao 0002, Shunhui Ji, Mingxuan Xiao, Letian Cheng |
Expert Syst. Appl. | 4 |
| 2025 | TAEFuzz: Automatic Fuzzing for Image-based Deep Learning Systems via Transferable Adversarial ExamplesabstractDeep learning (DL) components have been broadly applied in diverse applications. Similar to traditional software engineering, effective test case generation methods are needed by industry to enhance the quality and robustness of these deep learning components. To this end, we propose a novel automatic software testing technique, TAEFuzz (Automatic Fuzz -Testing via T ransferable A dversarial E xamples), which aims to automatically assess and enhance the robustness of image-based deep learning (DL) systems based on test cases generated by transferable adversarial examples. TAEFuzz alleviates the over-fitting problem during optimized test case generation and prevents test cases from prematurely falling into local optima. In addition, TAEFuzz enhances the visual quality of test cases through constraining perturbations inserted into sensitive areas of the images. For a system with low robustness, TAEFuzz trains a low-cost denoising module to reduce the impact of perturbations in transferable adversarial examples on the system. Experimental results demonstrate that the test cases generated by TAEFuzz can discover up to 46.1% more errors in the targeted systems, and ensure the visual quality of test cases. Compared to existing techniques, TAEFuzz also enhances the robustness of the target systems against transferable adversarial examples with the perturbation denoising module. Shunhui Ji, Changrong Huang, Hai Dong 0001, Lars Grunske, Yan Xiao 0002, Pengcheng Zhang 0001 |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2025 | DeepFusion: Smart Contract Vulnerability Detection Via Deep Learning and Data FusionabstractGiven that smart contracts execute transactions worth hundreds of millions of dollars daily, the issue of smart contract security has attracted considerable attention over the past few years. Traditional methods for detecting vulnerabilities heavily rely on manually developed rules and features, leading to the problems of low accuracy, high false positives, and poor scalability. Although deep learning-inspired approaches were designed to alleviate the problem, most of them rely on monothetic features, which may result in information incompetence during the learning process. Furthermore, the lack of available labeled vulnerability datasets is also a major limitation. To address these issues, we collect and construct a dataset of five labeled smart contract vulnerabilities, and proposeDeepFusion, a vulnerability detection method that fuses code representation information, including program slice information and abstraction syntax tree (AST) structured information. First, we develop automated tools to extract contract vulnerability slicing information from source code, and extract structured information from source code-converted AST. Second, code features and global structured features are fused into the data. Finally, the fused data are input into the Bidirectional Long Short-Term Memory+ Attention (BiLSTM+ATT) model for smart contract vulnerability detection. The BiLSTM model can capture long-term dependencies in both directions and is more suitable for processing serialized information generated byDeepFusion, while the attention mechanism can highlight the characteristic information of vulnerabilities. We conducted experiments via collecting a real smart contract dataset. The experimental results show that our method significantly outperforms the existing methods in detecting the vulnerabilities ofreentrancy,timestamp dependence,integer overflow and underflow,Use tx.origin for authentication, andUnprotected Self-destruct Instructionby 6.36%, 6.42%, 16.5%, 21.29%, and 25.05%, respectively. To the best of our knowledge, the latter two vulnerabilities are the first to be detected using deep learning methods. Hanting Chu, Pengcheng Zhang 0001, Hai Dong 0001, Yan Xiao 0002, Shunhui Ji |
IEEE Trans. Reliab. | 5 |
| 2024 | Dynamic Adaptive User Allocation in Mobile Edge ComputingabstractIn mobile edge computing (MEC), mobile users can offload tasks to edge nodes to alleviate local computational loads, leveraging the computing capabilities of edge nodes. However, users' high mobility and temporal variability pose challenges in dynamically allocating mobile users to optimize perceived Quality of Service (QoS). To address this challenge, this paper proposes an adaptive ant colony algorithm for user allocation decisions. This method constructs hidden mobility fitness relationships between users and servers based on user movement trajectories. It utilizes an improved adaptive ant colony algorithm to adjust fitness values automatically and optimize user allocation. The goal is to maximize overall user satisfaction under resource constraints while minimizing user allocation costs. Experimental analysis demonstrates that the proposed method achieves higher user allocation rates and effectively utilizes available resources on edge servers. Shunhui Ji, Huiying Jin, Hai Dong 0001, Zhiyuan Ge, Pengcheng Zhang 0001 |
SSE | 2 |
| 2024 | Gradient-Guided Test Case Generation for Image Classification SoftwareabstractThe widespread use of deep neural networks (DNNs) in image classification sofwares underlines the importance of the robustness. Researchers have proposed sparse adversarial attack methods for generating test cases, which add pixel-level perturbations to construct the test case to mislead the target model. However, the existing methods have certain limitations, such as high time cost, poor flexibility, and poor quality of the test cases. To address these issues, we propose a gradient-guided test case generation method (GGTM) to evaluate the robustness of image classification software. The method firstly identifies the key region in the image based on the gradient-weighted class activation mapping (Grad-CAM) and the prediction confidence of the target model on the input image. In the key region, it selects a set of pixels as candidate perturbation pixels according to the gradient value and the change of loss function. Then perturbations are added to the candidate perturbation pixels after applying a random dropout strategy to reduce some candidate perturbation pixels which is used to avoid local optimum. For the initially constructed test case which can mislead the target model, after removing redundant and unimportant perturbations, perturbations are re-added to optimize the test case. Experiments show the effectiveness of GGTM, which achieves 100% attack success rate. And the test cases generated by GGTM have the best perturbation sparsity. Furthermore, compared with the baseline method SparseAG which achieves optimal perturbation sparsity among the baseline methods, GGTM significantly improves the efficiency. Shunhui Ji, Hai Dong 0001, Mingxuan Xiao, Pengcheng Zhang 0001 |
COMPSAC | 1 |
| 2024 | Audio Steganography Based Backdoor Attack for Speech Recognition SoftwareabstractWith the growing prevalence of deep learning in the speech area, speech recognition, voice control, and related applications have become integral parts of people's lives. However, the rise of malicious third-party platforms has introduced significant security concerns, particularly through backdoor attacks. These attacks implant triggers that manipulate speech recognition models to produce specific labels, thereby compromising the system's integrity. Studying speech backdoor attacks is crucial for evaluating the security of speech recognition software, and iden-tifying and addressing potential vulnerabilities. Existing methods for speech backdoor attacks usually employ fixed perturbations as triggers. However, these perturbations may be discernible to the human ear, making them easily detectable. To address this issue, we propose a frequency domain-embedded backdoor attack method based on echo hiding. Echo hiding is a steganography technique based on audio. This method embeds hidden information into the frequency spectrum of the echo signal, leveraging the masking property of the human auditory system. It is difficult to arouse suspicion or detect the presence of hidden information since echo is perceived as a natural phenomenon in auditory perception. Furthermore, it does not cause a significant decrease in audio quality. Experimental results show the effectiveness of our method in different settings. Shunhui Ji, Hanbo Cai, Hai Dong 0001, Pengcheng Zhang 0001 |
COMPSAC | 2 |
| 2024 | Scribble-Supervised Semantic Segmentation with Prototype-based Feature AugmentationabstractScribble-supervised semantic segmentation presents a cost-effective training method that utilizes annotations generated through scribbling. It is valued in attaining high performance while minimizing annotation costs, which has made it highly regarded among researchers. Scribble supervision propagates information from labeled pixels to the surrounding unlabeled pixels, enabling semantic segmentation for the entire image. However, existing methods often ignore the features of classified pixels during feature propagation. To address these limitations, this paper proposes a prototype-based feature augmentation method that leverages feature prototypes to augment scribble supervision. Experimental results demonstrate that our approach achieves state-of-the-art performance on the PASCAL VOC 2012 dataset in scribble-supervised semantic segmentation tasks. The code is available at https://github.com/TranquilChan/PFA. Guiyang Chan, Pengcheng Zhang 0001, Hai Dong 0001, Shunhui Ji, Bainian Chen |
ICML | 4 |
| 2024 | QoS Optimization via Computation Offloading in Metaverse EnvironmentabstractThe emergence of the metaverse signifies a paradigm shift in Internet technology, offering a comprehensive virtual social platform spanning various domains such as social interaction, gaming, healthcare, and tourism. This new era of the metaverse is facilitated by advancements in next-generation digital technologies including edge computing, artificial intelligence, virtual reality, augmented reality, and blockchain. In the metaverse, the quantity and variety of services requested by users may surpass those in other environments, and existing work cannot be applied to metaverse QoS (Quality of Service) optimization. To address this problem, this paper proposes Meta-PPO, an optimization method for enhancing the QoS of metaverse services using reinforcement learning. Firstly, metaverse services are categorized into virtual scene services and meta-services, providing a comprehensive framework for analysis. Secondly, Meta-PPO, based on the proximal policy optimization algorithm, is introduced to optimize the QoS of metaverse services. This method effectively balances the objectives of minimizing average delay and maximizing resource utilization of mobile devices by making informed offloading decisions for the identified service categories. Simulation results demonstrate the superiority of the proposed method over existing techniques, showcasing its suitability and effectiveness for enhancing the QoS of metaverse service. Zhiyuan Ge, Pengcheng Zhang 0001, Huiying Jin, Hai Dong 0001, Shunhui Ji |
ICWS | 5 |
| 2024 | Resource Aware Multi-User Task Offloading In Mobile Edge ComputingabstractMobile edge computing (MEC) relies on offloading tasks to edge nodes to avoid delays and failures caused by local computing. However, developing efficient offloading decisions is challenging, as it involves addressing the intricacies of tasks and the instability of edge node resources(e.g. available computer resources, memory, and bandwidth). In this paper, we propose a novel approach to tackle the problem of task offloading. Our approach involves dividing tasks into smaller units and considering the correlations between these sub-tasks. To make optimal offloading decisions, we employ a deep reinforcement learning algorithm that takes into account user movement patterns and the availability of resources at edge nodes. Through simulations, we demonstrate that our proposed algorithm outperforms several existing algorithms in terms of offloading decisions. It effectively reduces task execution delays and energy costs. These findings highlight the potential of our approach in improving the performance of task offloading in MEC systems. Shunhui Ji, Huiying Jin, Hai Dong 0001, Zhiyuan Ge, Pengcheng Zhang 0001 |
ICWS | 1 |
| 2024 | SGDL: Smart contract vulnerability generation via deep learningabstractAbstract The growing popularity of smart contracts in various areas, such as digital payments and the Internet of Things, has led to an increase in smart contract security challenges. Researchers have responded by developing vulnerability detection tools. However, the effectiveness of these tools is limited due to the lack of authentic smart contract vulnerability datasets to comprehensively assess their capacity for diverse vulnerabilities. This paper proposes a Deep Learning‐based Smart contract vulnerability Generation approach (SGDL) to overcome this challenge. SGDL utilizes static analysis techniques to extract both syntactic and semantic information from the contracts. It then uses a classification technique to match injected vulnerabilities with contracts. A generative adversarial network is employed to generate smart contract vulnerability fragments, creating a diverse and authentic pool of fragments. The vulnerability fragments are then injected into the smart contracts using an abstract syntax tree to ensure their syntactic correctness. Our experimental results demonstrate that our method is more effective than existing vulnerability injection methods in evaluating the contract vulnerability detection capacity of existing detection tools. Overall, SGDL provides a comprehensive and innovative solution to address the critical issue of authentic and diverse smart contract vulnerability datasets. Hanting Chu, Pengcheng Zhang 0001, Hai Dong 0001, Yan Xiao 0002, Shunhui Ji |
J. Softw. Evol. Process. | 5 |
| 2024 | IABC-TCG: Improved artificial bee colony algorithm-based test case generation for smart contractsabstractAbstract With the widespread application of smart contracts, there is a growing concern over the quality assurance of smart contracts. The data flow testing is an important technology to ensure the correctness of smart contracts. We propose an approach named IABC‐TCG (Improved Artificial Bee Colony‐Test Case Generation) to generate test cases for the data flow testing of smart contracts. With a dominance relations‐based fitness function, an improved artificial bee colony algorithm is used to generate test cases, in which the bee colony search coefficient is adaptively adjusted to improve the effectiveness and efficiency of the search. In addition, an improved test case selection and updation strategy is used to avoid unnecessary test cases. The experimental results show that IABC‐TCG achieves 100% coverage for all the test requirements on a dataset of 30 smart contracts and outperforms the baseline approaches in terms of the number of test cases and the execution time. Performing tests with the generated test cases, IABC‐TCG can find more errors with less test cost. Shunhui Ji, Jiahao Gong, Hai Dong 0001, Pengcheng Zhang 0001, Shaoqing Zhu 0002 |
J. Softw. Evol. Process. | 1 |
| 2024 | Space-Time-Aware Proactive QoS Monitoring for Mobile Edge ComputingabstractThis paper presents a novel probabilistic Quality of Service (QoS) monitoring method named DLSTM-BRPM (Double Long Short Term Memory (DouLSTM-Den) based Bayesian Runtime Proactive Monitoring) to accurately and efficiently monitor QoS in a mobile edge environment. This method consists of a DouLSTM-Den model and a Gaussian Hidden Bayesian classifier. The DouLSTM-Den model aims to predict a user’s future movement trajectory in real time and proactively monitor the spatio-temporal QoS performance of services based on the predicted trajectory. The Gaussian Hidden Bayesian classifier is employed to accurately monitor QoS by constructing parent attributes to reduce the interdependence between QoS attributes. Our experiments based on public synthetic datasets demonstrate the effectiveness of the proposed method over state-of-the-art solutions. We also conducted experiments in a real-world edge environment to validate the feasibility of the proposed method. Shunhui Ji, Huiying Jin, Hai Dong 0001, Pengcheng Zhang 0001, Athman Bouguettaya |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Test Case Generation for Cross-Blockchain Smart ContractabstractWith the development of blockchain technology, an increasing number of users are adopting cross-blockchain smart contracts, which necessitates effective testing methods due to digital asset security concerns. However, few work specifically tailored for cross-chain smart contracts. In this paper, we propose a test case generation method for cross-chain contracts based on the ant colony algorithm. This method conducts data flow analysis on the cross-chain smart contract to identify the critical information related statements. These statements are then subjected to mutation operations to create mutants. Subsequently, test cases are generated with an improved ant colony algorithm to kill as many mutants as possible. Theoretically, this method can effectively detect faults in critical information related handling in cross-chain smart contracts. Jiahao Gong, Shunhui Ji, Pengcheng Zhang 0001 |
APSEC | 2 |
| 2023 | Ponzi Scheme Detection Based on Control Flow Graph Feature ExtractionabstractThe blockchain ecosystem is expanding as a result of advancements in blockchain technology and the emergence of BaaS (Blockchain as a Service) platforms. Smart contracts are designed to carry out diverse business operations, but there is a risk of Ponzi schemes being concealed within them. These schemes masquerade as investment agreements and deceive users, resulting in substantial losses for the blockchain community. Detecting Ponzi schemes in smart contracts is crucial. This study introduces a machine learning approach to identify Ponzi schemes by extracting features from smart contracts using the control flow graph. During the construction of the control flow graph for the smart contract’s bytecode, elements unrelated to its functionality are identified and eliminated. We utilize the control flow graph to extract n-gram Term Frequency and n-gram Term Frequency-Inverse Document Frequency features. These features are respectively employed to construct a Random Forest model for Ponzi scheme detection. To address the issue of imbalanced samples, the SVM_SMOTE oversampling algorithm is applied to balance the number of positive and negative samples. The results from experiments conducted on a real-world dataset demonstrate the effectiveness of our approach. The feature extraction method based on the control flow graph outperforms the method based on continuous text. Additionally, the Random Forest model utilizing SVM_SMOTE outperforms four existing models. Shunhui Ji, Congxiong Huang, Pengcheng Zhang 0001, Hai Dong 0001, Yan Xiao 0002 |
ICWS | 1 |
| 2023 | LEAP: Efficient and Automated Test Method for NLP SoftwareabstractThe widespread adoption of DNNs in NLP software has highlighted the need for robustness. Researchers proposed various automatic testing techniques for adversarial test cases. However, existing methods suffer from two limitations: weak error-discovering capabilities, with success rates ranging from 0% to 24.6% for BERT-based NLP software, and time inefficiency, taking 177.8s to 205.28s per test case, making them challenging for time-constrained scenarios. To address these issues, this paper proposes LEAP, an automated test method that uses LEvy flight-based Adaptive Particle swarm optimization integrated with textual features to generate adversarial test cases. Specifically, we adopt Levy flight for population initialization to increase the diversity of generated test cases. We also design an inertial weight adaptive update operator to improve the efficiency of LEAP's global optimization of high-dimensional text examples and a mutation operator based on the greedy strategy to reduce the search time. We conducted a series of experiments to validate LEAP's ability to test NLP software and found that the average success rate of LEAP in generating adversarial test cases is 79.1%, which is 6.1% higher than the next best approach (PSOattack). While ensuring high success rates, LEAP significantly reduces time overhead by up to 147.6s compared to other heuristic-based methods. Additionally, the experimental results demonstrate that LEAP can generate more transferable test cases and significantly enhance the robustness of DNN-based systems. Mingxuan Xiao, Yan Xiao 0002, Hai Dong 0001, Shunhui Ji, Pengcheng Zhang 0001 |
ASE | 4 |
| 2023 | A survey on smart contract vulnerabilities: Data sources, detection and repair
Hanting Chu, Pengcheng Zhang 0001, Hai Dong 0001, Yan Xiao 0002, Shunhui Ji, Wenrui Li 0002 |
Inf. Softw. Technol. | 5 |
| 2023 | Adversarial example-based test case generation for black-box speech recognition systemsabstractAbstract Test case generation techniques based on adversarial examples are commonly used to enhance the reliability and robustness of image‐based and text‐based machine learning applications. However, efficient techniques for speech recognition systems are still absent. This paper proposes a family of methods that generate targeted adversarial examples for speech recognition systems. All are based on thefirefly algorithm (F), and are enhanced withgaussmutations and / orgradientestimation (F‐GM, F‐GE, F‐GMGE) to fit the specific problem of targeted adversarial test case generation. We conduct an experimental evaluation on three different types of speech datasets, includingGoogle Command,Common VoiceandLibriSpeech. In addition, we recruit volunteers to evaluate the performance of the adversarial examples. The experimental results show that, compared with existing approaches, these approaches can effectively improve the success rate of the targeted adversarial example generation. The code is publicly available at https://github.com/HanboCai/FGMGE . Hanbo Cai, Pengcheng Zhang 0001, Hai Dong 0001, Lars Grunske, Shunhui Ji, Tianhao Yuan |
Softw. Test. Verification Reliab. | 5 |
| 2023 | Test-Case Generation for Data Flow Testing of Smart Contracts Based on Improved Genetic AlgorithmabstractSmart contracts are commonly deployed for safety-critical applications, the quality assurance of which has been a vital factor. Test cases are standard means to ensure the correctness of data flows in smart contracts. To more efficiently generate test cases with high coverage, we propose an improved genetic algorithm-based test-case generation approach for smart contract data flow testing. Our approach introduces the theory of particle swarm optimization into the genetic algorithm, which reduces the influence brought by the randomness of genetic operations and enhances its capability to find global optima. A set of 30 real smart contracts deployed on Ethereum and GitHub is collected to perform the experimental study, on which our approach is compared with three baseline approaches. The experimental results show that, in most cases, the coverage of the test cases generated by our approach is significantly higher than the baseline approaches with relatively lower numbers of iterations and lower execution time. Shunhui Ji, Shaoqing Zhu 0002, Pengcheng Zhang 0001, Hai Dong 0001, Jianan Yu |
IEEE Trans. Reliab. | 1 |
| 2022 | Data Flow Reduction Based Test Case Generation for Smart ContractsabstractWith the widespread use of smart contracts, security incidents caused by improper programming have drawn increasing attention. Data flow correctness is a fundamental and vital requirement for smart contracts. Although test cases generated by existing approaches for data flow testing of smart contracts can achieve certain coverage, not all def-use (definitionuse) pairs are covered, which may result in some errors not being detected. To further improve the adequacy and efficiency of testing, we present an approach named TCG-Re (T est C ase G eneration Combined with Data Flow R eduction) to generate test cases for data flow testing of smart contracts. Data flow reduction is performed to reduce redundant def-use pairs and obtain the final test requirements in a smart contract. The test case generation process is optimized to improve the coverage of the generated test cases for the def-use pairs. We collect 30 smart contracts of different scales to perform experimental evaluation. The result shows that, compared with other existing approaches, TCG-Re can not only achieve full coverage for most contracts, but also be more efficient. In addition, TCG-Re is also effective for discovering several types of errors in smart contracts. Shunhui Ji, Shaoqing Zhu 0002, Pengcheng Zhang 0001, Hai Dong 0001 |
APSEC | 1 |
| 2022 | Bytecode Obfuscation for Smart ContractsabstractEthereum smart contracts face serious security problems, which not only cause huge economic losses, but also destroy the Ethereum credit system. To solve this problem, code obfuscation techniques are applied to smart contracts to improve their complexity and security. However, the current source code obfuscation methods have insufficient anti-decompilation ability. Therefore, we propose a novel bytecode obfuscation approach called BOSC based on four kinds of bytecode obfuscation techniques, which is directed at solidity. The experimental results show that, after the bytecode obfuscation, the failure rate of decompilation tools is over 99% and only a small amount of gas is consumed. Pengcheng Zhang 0001, Hai Dong 0001, Yan Xiao 0002, Shunhui Ji |
APSEC | 5 |
| 2021 | Verifiable Model Construction for Business ProcessesabstractBusiness process specified in Business Process Execution Language (BPEL), which integrates existing services to develop composite service for offering more complicated function, is error-prone. Verification and testing are necessary to ensure the correctness of business processes. SPIN, for which the input language is PROcess MEta-LAnguage (Promela), is one of the most popular tools for detecting software defects and can be used both in verification and testing. In this paper, an automatic approach is proposed to construct the verifiable model for BPEL-based business process with Promela language. Business process is translated to an intermediate two-level representation, in which eXtended Control Flow Graph (XCFG) describes the behavior of BPEL process in the first level and Web Service Description Models (WSDM) depict the interface information of composite service and partner services in the second level. With XCFG of BPEL process, XCFGs for partner services are generated to describe their behavior. Promela model is constructed by defining data types based on WSDM and defining channels, variables and processes based on XCFGs. The constructed Promela model is closed, containing not only the BPEL process but also its execution environment. Case study shows that the proposed approach is effective. Shunhui Ji, Liming Hu, Pengcheng Zhang 0001, Jerry Zeyu Gao |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2013 | Verifying the Concurrent Properties in BPEL Based Web Service Composition ProcessabstractThe relatively new web service software paradigm involves services which are loosely coupled, highly reusable and flexible. By specifying the workflow of individual services, Web service composition enhances the ability to handle more complex business processes and provides many value-added services. In this article, we propose an extended control flow graph (XCFG) to formally model the workflow of Web service composition specified in BPEL, and corresponding techniques to verify concurrent properties, such as deadlock-free, non-conflict, and link non-redundant. XCFG can model not only the workflow of BPEL but also the synchronization control dependencies among concurrent activities. Meanwhile, each element of XCFG keeps record of related information of corresponding activity in BPEL so as to support further analysis and verification. Experimental study validates the effectiveness and efficiency of the proposed XCFG-based technique. Bixin Li, Shunhui Ji, Dong Qiu, Hareton K. N. Leung, Gongyuan Zhang |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2012 | A HybridUML and QdL Based Verification Method for CPS Self-Adaptability
Jiakai Li, Bixin Li, Qiaoqiao Chen, Shunhui Ji, Xiaoxiang Zhai |
SEKE | 5 |
| 2012 | Verification of Cyber-Physical Systems Based on Differential-Algebraic Temporal Dynamic Logic
Xiaoxiang Zhai, Bixin Li, Jiakai Li, Qiaoqiao Chen, Shunhui Ji |
SEKE | 6 |
| 2012 | HybridUML Based Verification of CPS Using Differential Dynamic Logic
Bixin Li, Jiakai Li, Qiaoqiao Chen, Xiaoxiang Zhai, Shunhui Ji |
SEKE | 6 |
| 2010 | Automatic test case selection and generation for regression testing of composite service based on extensible BPEL flow graphabstractServices are highly reusable, flexible and loosely coupled, which makes the evolution and the maintenance of composite services more complex. Evolution of BPEL composite service covers changes of processes, bindings and interfaces. In this paper, an approach is proposed to select and generate test cases during the evolution of BPEL composite service. The approach identifies the changes by using control-flow analysis technique and comparing the paths in new composite service version and the old one using extensible BPEL flow graph (or XBFG). Message flow is appended to the control flow so that XBFG can describe the behavior of composite service integrally. The binding and predicate constraint information added in XBFG elements can be used in path selection and test case generation. Theory analysis and case study both show that the approach is effective, and test cases coverage rate is high for the changes of processes, bindings and interfaces. Bixin Li, Dong Qiu, Shunhui Ji |
ICSM | 3 |
| 2010 | Generating Test Cases of Composite Services Based on OWL-S and eh-CPNabstractIn web service times, the techniques for composing services are based on service reuse and automatic integration. A new web service will be generated by composing some existing web services. These web services cooperate with each other to provide a new more complex function. It is necessary and very important to test the interaction behavior between any two web services during composition. In this paper, a kind of enhanced hierarchical color petri-net (or EH-CPN) is introduced to generate test cases for testing the interaction, where EH-CPN is transformed from OWL-S document, and both control flow and data flow information in EH-CPN are analyzed and used to generate an executable test sequence, and further test cases are created by combining the test sequence and test data in an XML file. Bixin Li, Shunhui Ji, Dong Qiu, Ju Cai |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2009 | Generating Test Cases of Composite Services Based on OWL-S and EH-CPN
Bixin Li, Ju Cai, Dong Qiu, Shunhui Ji |
SEKE | 4 |
| 2009 | WSTester: Testing Web Service for Behavior Conformance
Bixin Li, Shunhui Ji, Dong Qiu, Xufang Gong |
SEKE | 3 |