VLDB 2026 Research / reviewers in the wild / expert
Peidai Xie
dblp:128/3562 · also Pei Dai Xie
· DBLP profile ↗
9ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0003-9213-2966ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 2Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Fuzzing JavaScript JIT compilers with a high-quality differential test oracle
Jizhe Li, Zhiyuan Jiang, Huang Chun, Peidai Xie, Yongxin Chen 0001 |
Comput. Secur. | 6 |
| 2024 | Fuzzing JavaScript Engines with a Graph-based IRabstractMutation-based fuzzing effectively discovers defects in JS engines. High-quality mutations are key for the performance of mutation-based fuzzers. The choice of the underlying representation (e.g., a sequence of tokens, an abstract syntax tree, or an intermediate representation) defines the possible mutation space and subsequently influences the design of mutation operators. Current program representations in JS engine fuzzers center around abstract syntax trees and customized bytecode-level intermediate languages. However, existing efforts struggle to generate semantically valid and meaningful mutations, limiting the discovery of defects in JS engines. Zhiyuan Jiang, Shuhui Fan, Shenglin Xu, Peidai Xie, Shaojing Fu, Mathias Payer |
CCS | 6 |
| 2024 | FormatAEG: a framework for bypassing ASLR defense and automated exploitation of format string vulnerabilityabstractAbstract The format string vulnerability is a common software vulnerability. A well-constructed format string can read and modify arbitrary memory addresses, causing serious system problems. Existing automated exploit generation solutions for format string vulnerability are unable to cope with the limitations imposed by the vulnerability defense mechanism Address Space Layout Randomization (ASLR) and the program itself on vulnerability exploitation. In this paper, to address the above challenges, we propose FormatAEG, the first automatic exploitation framework for format string vulnerabilities that can bypass ASLR defense and the program's own constraints. Specifically, we first proposed an arbitrary address reading and writing method based on a format string vulnerability, which can modify the target address data by directly arranging the target address or automatically searching and utilizing the pointer chain in the stack. Then, we propose a vulnerability reentry method based on global offset table (GOT) hijacking, which hijacks the program control flow by modifying function addresses in the GOT, making the vulnerability reentrant. In the experimental section, we evaluated FormatAEG using 20 Capture The Flag programs from top international tournaments and two real-world programs with format string vulnerabilities. The evaluation results show that with ASLR defense turned on, FormatAEG successfully detects format string vulnerability in 19 of these programs and generates exploit code for 15 of them. Compared with existing tools, FormatAEG detected 11 more format string vulnerabilities and generated 13 more exploit codes. Shenglin Xu, Zhiyuan Jiang, Peidai Xie |
Comput. J. | 4 |
| 2024 | Fuzzing JavaScript engines with a syntax-aware neural program model
Zhiyuan Jiang, Shuhui Fan, Shaojing Fu, Peidai Xie |
Comput. Secur. | 6 |
| 2020 | Tree2tree Structural Language Modeling for Compiler Fuzzing
Shuhui Fan, Hongzuo Xu, Peidai Xie |
ICA3PP (1) | 6 |
| 2020 | DSmith: Compiler Fuzzing through Generative Deep Learning Model with AttentionabstractCompiler fuzzing is a technique to test the functionalities of compiler. It requires well-formed test cases (i.e., programs) that have correct lexicons and syntax to pass the parsing stage of a compiler. Recently, advanced compiler fuzzing methods generate effective test cases by deep neural networks, which learn the language model of regular programs to guarantee test case quality. However, most of these methods fail to capture long-distance dependencies of syntax (e.g., paired curly braces) in a program. As a result, they may generate test cases with syntax errors, which cannot pass the parsing stage to test the compiler functionality. In this paper, we propose a framework, namely DSmith, to capture long-distance dependencies of syntax for a robust test case generation. Specifically, DSmith memorizes the hidden state of each token in a program and leverages the interactions of these hidden states to embed the long-distance dependencies between tokens. It then adopts an encoder-decoder architecture with the embedding of these long-distance dependencies to build a language model of regular programs. Finally, DSmith uses the built language model to generate test cases according to four novel generation strategies, which significantly increase the diversity of test cases. Extensive experiments show that DSmith increases the parsing pass rate of the generated programs by an average of 19% and significantly improves the code coverage of the compiler, compared with state-of-the-art methods. Benefiting from the high pass rate and broad code coverage, DSmith has found eleven brand new bugs in currently supported GCC compiler versions. Shuhui Fan, Peidai Xie, Aizhi Liu |
IJCNN | 4 |
| 2020 | AT-ROP: Using static analysis and binary patch technology to defend against ROP attacks based on return instructionabstractReturn-Oriented Programming (ROP) is one of the most common techniques to exploit software vulnerabilities. Although many solutions to defend against ROP attacks have been proposed, they still have various drawbacks, such as requiring additional information (source code, debug symbols, etc.), increasing program running cost, and causing program instability. In this paper, we propose a method: using static analysis and binary patch technology to defend against ROP attacks based on return instruction. According to this method, we implemented the AT- ROP tool in a Linux 64-bit system environment. Compared to existing tools, it clears the parameter registers when the function returns. As a result, it makes the binary to defend against ROP attacks based on return instruction without having to obtain the source code of the binary. We use the binary challenges in the CTF competition and the binary programs commonly used in the Linux environment to experiment. It turns out that AT-ROP can make the binary program have the ability to defend against ROP attacks based on return instruction with a small increase in the size of the binary program and without affecting its normal execution. Shenglin Xu, Peidai Xie |
TASE | 2 |
| 2018 | Clean the Scratch Registers: A Way to Mitigate Return-Oriented Programming AttacksabstractWith the implementation of W ⊕ X security model on computer system, Return-Oriented Programming(ROP) has become the primary exploitation technique for adversaries. Although many solutions that defend against ROP exploits have been proposed, they still suffer from various shortcomings. In this paper, we propose a new way to mitigate ROP attacks that are based on return instructions. We clean the scratch registers which are also the parameter registers based on the features of ROP malicious code and calling convention. A prototype is implemented on x64-based Linux platform based on Pin. Preliminary experimental results show that our method can efficiently mitigate conventional ROP attacks. Zelin Rong, Peidai Xie, Shenglin Xu |
ASAP | 2 |
| 2016 | Absent extreme learning machine algorithm with application to packed executable identification
Peidai Xie, Xinwang Liu 0002, Jianping Yin |
Neural Comput. Appl. | 1 |