Yuanpeng Wang

dblp:125/2440 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
6since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 GPU-Accelerated Approximate Nearest Neighbor Search via PCA-Augmented Graph Indexing for Vector Databases
Yuanpeng Wang, M. Reza HoseinyFarahabady, Albert Y. Zomaya
IPDPS1
2026 SymFlow: Event-Chain-Aware Symbolic Execution for Serverless Sensitive Data Flow Detection
abstract
Serverless applications are widely adopted for their scalability, cost-efficiency, and elastic resource management. However, their event-driven nature introduces complex event chains whose trigger-handler relationships are often determined dynamically by conditional logic, asynchronous callbacks, and resource-state dependencies. Existing security analysis tools, such as CloudFlow, mainly rely on static analysis, making it difficult to capture these dynamic event-chain interactions and the semantics of coarse-grained cloud APIs. As a result, they often fail to bridge the gap between architectural reachability and semantic feasibility, leading to both false positives and false negatives.
Yuanpeng Wang, Zhineng Zhong, Zhenkai Liang, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
LCTES1
2025 Scalable Approximate Nearest Neighbor Search with PCA-Augmented HNSW in Vector Databases
Yuanpeng Wang, M. Reza HoseinyFarahabady, Albert Y. Zomaya
PDCAT1
2023 SymGX: Detecting Cross-boundary Pointer Vulnerabilities of SGX Applications via Static Symbolic Execution
abstract
Intel Security Guard Extensions (SGX) have shown effectiveness in critical data protection. Recent symbolic execution-based techniques reveal that SGX applications are susceptible to memory corruption vulnerabilities. While existing approaches focus on conventional memory corruption in ECalls of SGX applications, they overlook an important type of SGX dedicated vulnerability: cross-boundary pointer vulnerabilities. This vulnerability is critical for SGX applications since they heavily utilize pointers to exchange data between secure enclaves and untrusted environments. Unfortunately, none of the existing symbolic execution approaches can effectively detect cross-boundary pointer vulnerabilities due to the lack of an SGX-specific analysis model that properly handles three unique features of SGX applications: Multi-entry Arbitrary-order Execution, Stateful Execution, and Context-aware Pointers. To address such problems, we propose a new analysis model named Global State Transition Graph with Context Aware Pointers (GSTG-CAP) that simulates properties-preserving execution behaviors for SGX applications and drives symbolic execution for vulnerability detection. Based on GSTG-CAP, we build a novel symbolic execution-based vulnerability detector named SYMGX to detect cross-boundary pointer vulnerabilities. According to our evaluation, SYMGX can find 30 0-DAY vulnerabilities in 14 open-source projects, three of which have been confirmed by developers. SYMGX also outperforms two state-of-the-art tools, COIN and TeeRex, in terms of effectiveness, efficiency, and accuracy.
Yuanpeng Wang, Ziqi Zhang 0017, Ningyu He, Zhineng Zhong, Shengjian Guo, Qinkun Bao, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
CCS1
2023 APIMind: API-driven Assessment of Runtime Description-to-permission Fidelity in Android Apps
abstract
Assessing description-to-permission fidelity is critical for safeguarding personal data accessed through sensitive APIs in Android apps. However, it remains a challenge for existing methods, both static and dynamic. Static methods are either infeasible due to various dynamic features (e.g., code obfuscation, dynamic class loading, and reflection) or too coarse-grained to understand how sensitive APIs collect privacy data under runtime contexts. Existing dynamic methods lack contextual understanding regarding sensitive API calls. For example, they fail to understand which GUI widgets are more likely to trigger sensitive APIs and ignore the preceding UI contexts that could reveal the intention of API calls when analyzing their fidelity.In this paper, we propose an API-driven automated dynamic analysis tool called APIMind for assessing runtime description-to-permission fidelity in Android apps. APIMind can discover sensitive APIs more effectively by utilizing multimodal features to jointly infer the semantics of GUI widgets and leveraging deep networks to automatically learn their relationship based on multifaceted rewards. Then, it could accurately assess description-to-permission fidelity by developing an extended tool that considers dual UI contexts (i.e., preceding and current contexts). We evaluate the accuracy and efficiency of APIMind using 121 real-world apps. Experimental results demonstrate that APIMind can achieve a detection accuracy of 96.1%. Compared to the competitive baseline, APIMind increases efficiency by 43%. In addition, based on our proposed tool, we conduct a large-scale case study of 1013 real Android apps, which reveals the prevalence of several typical inconsistencies and demonstrates the effectiveness of our approach in the wild.
Hanwen Lei, Yuanpeng Wang, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
ISSRE3
2023 How Android Apps Break the Data Minimization Principle: An Empirical Study
abstract
The Data Minimization Principle is crucial for protecting individual privacy. However, existing Android runtime permissions do not guarantee this principle. Moreover, the lack of an automatic enforcement mechanism leads to uncertainty as to whether apps strictly comply with this principle. To bridge this gap, we conduct the first systematic empirical study on violations of the Data Minimization Principle and design a new enforcement tool called GUIMind to detect them. GUIMind first utilizes a reinforcement learning model to explore app activities and monitor access to sensitive APIs that require sensitive permissions, and then it leverages an existing tool to detect such violations. We evaluate the performance of GUIMind using 120 real-world Android apps. The results indicate that GUIMind can achieve a detection accuracy of 96.1%, effectively accelerating the empirical study. Our empirical research is mainly focused on the prevalence of violations, the responses of administrators to violations, and the potential factors and characteristics that lead to violations, such as typical violations, app categories, and personal data types. Our study reveals that 83.5% of apps contain at least one privacy violation, with health apps being the most severe. In addition, telephony information is the most commonly leaked personal data type, accounting for 71.1%. Finally, we randomly selected 60 non-compliant apps for reporting to the administrator, whose responses confirm the effectiveness of our approach.
Hanwen Lei, Yuanpeng Wang, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
ASE3
2019 T-Star: A Text-Based iStar Modeling Tool
abstract
iStar framework is an effective means for modeling and analyzing goals and interactions among social agents. Most of existing iStar modeling tools build iStar models via a graphical manner, which has a steep learning curve and suffer from scalability issues. Especially when dealing with large-scale models in industrial settings, it is very time consuming to play with the layout of models. In this paper, we present a tool which allows users to build iStar models from textual descriptions of systems. And the established models are then visualized with reasonable layouts. In particular, our tool supports both SD (Strategic Dependency) view and SR (Strategic Rationale) view of iStar models.
Yuanpeng Wang, Yixuan Hou, Yunduo Wang
RE2
2019 Adaptive Image-Based Visual Servoing With Temporary Loss of the Visual Signal
abstract
Image-based visual servoing (IBVS) can reach a desired position for a relatively stationary target using continuous visual feedback. Proper feature extraction and appropriate servoing control laws are essential to performance for IBVS. IBVS control can be interrupted or interfered abruptly if no features are extracted when the observed object is occluded. To address the problem of missing feature points in current images during a visual navigation task, a homography method that uses a priori visual information is proposed to predict all of the missing feature points and to ensure the execution of IBVS. The mixture parameter for the image Jacobian matrix can also affect the control of IBVS. The settings for the mixture parameter are heuristic so there is no a systematic approach for most IBVS applications. An adaptive control approach is proposed to determine the mixture parameter. The proposed method uses a reinforcement learning (RL) method to adaptively adjust the mixture parameter during the robot movement, which allows more efficient control than a constant parameter. A logarithmic interval state-space partition for RL is used to ensure efficient learning. The integrated visual servoing control system is validated by several experiments that involve wheeled mobile robots reaching a target with a desired configuration. The results for simulation and experiment demonstrate that the proposed method has a faster convergence rate than other methods.
Haobin Shi, Gang Sun 0003, Yuanpeng Wang, Kao-Shing Hwang
IEEE Trans. Ind. Informatics3
2013 A real-time auto-adjustable smart pillow system for sleep apnea detection and treatment
abstract
Sleep apnea, which is a common sleep disorder characterized by the repetitive cessation of breathing during sleep, can result in various diseases, including headaches, hypertension, stroke and cardiac arrest, as well as produce severe consequences such as impaired concentration and traffic accidents. A traditional diagnosis method of sleep apnea is polysomnography, which can only be conducted in sleep center with specialized personals, thus is expensive and inconvenient. Moreover, it is only used for understanding the conditions, without treatment function. Some other methods or devices have been developed to alleviate sleep apnea, such as continuous positive airway pressure (CPAP) and intraoral mandibular advancement device and surgery. However, they only provide a treatment method without detection or monitoring function. There is no existing device which can provide both apnea detection and treatment functionality. In this paper, we propose and implement a smart phone-based auto-adjustable pillow system, which enables both sleep apnea detection and treatment. Sleep apnea events can be detected in real-time using the blood oxygen sensor, accordingly, the height and shape of the pillow can be automatically adjusted to terminate the sleep apnea event. On the other hand, after the adjustment, the sensor can continuously monitor the blood oxygen signal to evaluate the effectiveness of the pillow adjustment and to help in selecting a suitable adjustment scheme. Therefore, a real-time feedback control system is formed. Besides, compared with existing diagnosis or treatment devices, our system is non-invasive, inexpensive and portable, which can be used at home or during traveling. In this paper, a real-time sleep apnea detection and classification algorithm is proposed to decide whether the pillow should be adjusted or not. We also design a real-time feedback pillow adjustment algorithm, to decide when and how to adjust the pillow and how to evaluate the effectiveness of the adjustment. We conducted experiments on 40 patients, which demonstrate that using our novel smart pillow system, both the sleep apnea duration and the number of sleep apnea events are dramatically reduced by more than 50%.
Jin Zhang 0001, Qian Zhang 0001, Yuanpeng Wang
IPSN3
2012 RASS: A Portable Real-time Automatic Sleep Scoring System
abstract
It is a well known fact that the quality of sleep is an important factor in health-related quality of life (HRQoL), and people could prevent potential problems by tracking the quality of their sleep. Unfortunately sleep scoring, which is a systematic way to address the sleep staging as well as the scoring of arousals, respiratory, cardiac, and movement events, is usually conducted with specialized equipment which is expensive and operated by specialists in dedicated sleep centers. Related research studies and products (e.g. ZEO) tried to solve this problem, but they either used multiple probes that cause discomfort to the patient, or could not score in real time. In this paper, we design and implement RASS, a portable Real-time Automatic Sleep Scoring system. RASS only requires one probe, which is inexpensive and, as a result, may be used at home or during travel. RASS accurately scores the sleeping state and detects sleep apnea in real-time based on the sensing results of pulse, blood oxygen, activity, sound and light signals. An alarm will be generated when a severely abnormal sleep state is detected. RASS has been tested with 48 patients, and the test results show that RASS could achieve higher than 84% accuracy.
Jin Zhang 0001, Mincong He, Yuanpeng Wang, Qian Zhang 0001
RTSS5