VLDB 2026 Research / reviewers in the wild / expert
Yuming Feng 0002
dblp:13/10217-2
· DBLP profile ↗
12ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0001-8922-0496ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | XPCH: A Cross-Chain Payment Protocol via Connecting the Payment Channel Hubs
Yuanming Shao, Yuming Feng 0002, Weizhe Zhang, Bin Xiao 0001, Jianhuan Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Defining and Detecting the Defects of Large Language Model-Based Autonomous AgentsabstractArtificial intelligence (AI) agents are systems capable of perceiving their environment, autonomously planning and executing tasks. Recent advancements in Large Language Models (LLMs) have introduced a transformative paradigm for AI agents, enabling them to interact with external resources and tools through prompt techniques. This advancement has significantly extended the capabilities of LLMs, positioning LLM-based AI Agents as an important research area. In such agents, the workflow integrates developer-written code, which manages framework construction and logic control, with LLM-generated natural language that enhances dynamic decision-making and interaction. However, inconsistencies between LLM outputs and developer logic can lead to defects, such as tool invocation failures. These issues introduce specific risks, leading to various defects in LLM-based AI Agents, including service interruptions and incorrect output. Despite the importance of these issues, there is a lack of systematic work that focuses on analyzing LLM-based AI Agents to uncover defects in their code. To address this gap, we present the first study focused on identifying and detecting defects in LLM Agents. We collected and analyzed 14,754 relevant developer reports from StackOverflow and GitHub. We further filtered 2,604 valid posts to define and classify eight types of agent code defects. Then, we designed a static analysis tool, named Agentable, to detect these defects. Agentable leverages Code Property Graphs (CPGs) and LLMs to analyze Agent workflows by efficiently identifying specific code patterns and analyzing natural language descriptions. To evaluate Agentable, we constructed two datasets: AgentSet, which consists of 84 real world Agent projects, and AgentTest, which contains 78 Agent projects specifically designed to include various types of defects. Our evaluation shows that Agentable achieves a precision of 88.79% on the real-world agent dataset and a recall of 91.03% on the manually labeled defect dataset. Furthermore, our analysis identifies 889 defects in real-world agent projects, highlighting the prevalence of these issues in practice. Kaiwen Ning, Jiachi Chen, Wei Li 0121, Zexu Wang, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng |
IEEE Trans. Software Eng. | 6 |
| 2025 | ServerlessLego: An Elastic Serverless Framework Assembling Model Building Blocks to Provide SLO-Aware Inference ServicesabstractInference of large language models (LLMs) is common in cloud environments. As the elastic resource management capabilities and the flexible pay-as-you-go billing model offered by serverless, LLM inference services are increasingly migrated to serverless platforms. However, the increasing size of LLMs in recent years has introduced a new cold start issue for serverless frameworks, which in turn impacts their scalability under dynamic workloads. To address these issues, we propose ServerlessLego, an elastic serverless computing framework. ServerlessLego partitions LLMs into layers, then groups and deploys them to different instances, and loads these groups in parallel. These instances perform a subscription-based pipeline. To address dynamically request loads, ServerlessLego models the incoming request patterns and the inference time of running requests, providing an SLO-Aware instance scheduling. Experiments show that ServerlessLego reduces the cold start time of serverless frameworks by 58.15 % and improves throughput by 43.39 % compared to the baseline for dynamic workloads. Moreover, ServerlessLego can horizontally schedule instance based on request SLOs and arrival rates. Desheng Wang 0002, Weizhe Zhang, Sichao Chen, Yuming Feng 0002 |
ICPADS | 5 |
| 2025 | SSR: Safeguarding Staking Rewards by Defining and Detecting Logical Defects in DeFi StakingabstractDecentralized Finance (DeFi) staking is one of the most prominent applications within the DeFi ecosystem, where DeFi projects enable users to stake tokens on the platform and reward participants with additional tokens. However, logical defects in DeFi staking could enable attackers to claim unwarranted rewards by manipulating reward amounts, repeatedly claiming rewards, or engaging in other malicious actions. To mitigate these threats, we conducted the first study focused on defining and detecting logical defects in DeFi staking. Through the analysis of 64 security incidents and 144 audit reports, we identified six distinct types of logical defects, each accompanied by detailed descriptions and code examples. Building on this empirical research, we developed SSR (Safeguarding Staking Reward), a static analysis tool designed to detect logical defects in DeFi staking contracts. SSR utilizes a large language model (LLM) to extract fundamental information about staking logic and constructs a DeFi staking model. It then identifies logical defects by analyzing the model and the associated semantic features. We constructed a ground truth dataset based on known security incidents and audit reports to evaluate the effectiveness of SSR. The results indicate that SSR achieves an overall precision of 92.31%, a recall of 87.92%, and an F1-score of 88.85%. Additionally, to assess the prevalence of logical defects in real-world smart contracts, we compiled a large-scale dataset of 15,992 DeFi staking contracts. SSR detected that 3,557 (22.24%) of these contracts contained at least one logical defect. Zewei Lin, Jiachi Chen, Zexu Wang, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng |
ASE | 5 |
| 2025 | Finding Insecure State Dependency in DApps via Multi-Source Tracing and Semantic EnrichmentabstractDecentralized Applications (DApps) serve as the gateway to utilizing blockchain technology. As their prevalence continues to grow, DApps are becoming increasingly interconnected. For instance, a DApp does not need to manage the prices of various tokens internally, as it can retrieve this information from other DApps that provide more up-to-date data. However, such deep reliance also introduces more attack surfaces, posing greater risks to both DApps and their users. In this paper, we refer to the security threat arising from the interdependence of DApps as Insecure State Dependency (ISD). Public reports indicate that ISD has led to losses exceeding 340 million USD.Existing ISDs are mostly found by extensive manual auditing and lucky incidents, as automated discovery of such issues is extremely difficult. More specifically, it is by no means trivial to (1) achieve precise data tracking in the intertwined and invisible interactions of DApps, (2) obtain fine-grained semantic information in low semantic bytecode. In this paper, we propose a novel framework, called InsFinder, for detecting ISD in DApps. Specifically, InsFinder consists of three unique modules to overcome the aforementioned challenges. (1) InsFinder employs dynamic cross-DApp taint analysis to achieve accurate multi-source data tracking in heavily coupled DApp interactions. (2) InsFinder uses source mapping to map bytecode identifiers into meaningful source code, such as variable names or statements, enabling a deeper understanding of bytecode. (3) InsFinder implements fine-grained access control and static analysis for ISD entry point detection. Evaluation on a manually annotated dataset with 93 real-world ISDs shows that InsFinder successfully detects 72 of them, achieving a precision of 84.7% and a recall of 77.4%. Furthermore, InsFinder successfully uncovers 165 previously unreported ISDs across 122 DApp projects. These ISDs collectively impact over 2 million USD. Yuhong Nan, Wei Li 0121, Kaiwen Ning, Zewei Lin, Zitong Yao, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng |
ASE | 7 |
| 2025 | LRD-Raft: Log Replication Decouple for Efficient and Secure Consensus in Consortium-Blockchain-Based IoTabstractCurrently, consortium blockchain has been used in Internet of Things (IoT) systems to ensure secure data sharing across organizations. Consortium blockchain typically uses the Raft algorithm because of its high performance. However, in geo-distributed IoT environments, the single-point overhead problem of leader nodes affects the security and efficiency of consensus due to the high latency and frequency of client requests. To address this challenge, we propose a novel solution: log replication decoupling raft (LRD-Raft), which enables follower nodes to participate in log replication as well. This scheme reduces the overhead of the leader node by delegating part of the log replication task to the follower node. We also propose an adaptive coding protocol that dynamically adjusts the erasure code parameters according to the number of cluster healthy nodes to save the cluster’s network traffic. We evaluated LRD-Raft in different network latency environments and different cluster sizes, and the experimental results show that LRD-Raft has a more extensive performance system compared to Raft in high network latency and large data block transmission environments, and also has a certain level of resistance to DoS attacks, which improves the performance and security of the consensus mechanism. Heru Yang, Yuming Feng 0002, Weizhe Zhang |
IEEE Internet Things J. | 2 |
| 2025 | AR: An Efficient Alliance Root Service with Decentralized Trust
Bin Zhang 0048, Yu Zhang 0036, Yuming Feng 0002, Wei-Zhe Zhang, Dongcen Ji, Fan Nie |
J. Comput. Sci. Technol. | 3 |
| 2024 | An MTD-driven Hybrid Defense Method Against DDoS Based on Markov Game in Multi-controller SDN-enabled IoT NetworksabstractThe widespread deployment of low-cost, vulnerable IoT devices allows attackers to exploit them to generate botnets and launch distributed denial-of-service (DDoS) attacks, which has become a serious security challenge for ensuring quality of service (QoS). For cost-effective defense against DDoS, we propose a novel hybrid defense method that includes proactive moving target defense (MTD) and passive security control to resist DDoS threats at different stages in IoT networks in this paper. We construct a multi-stage Markov game model to portray the game as a competition between the attacker and the defender for the control duration of the attack surface, and design an optimal defense strategy algorithm. In particular, we introduce a new parameter of action execution interval expectation in the game and add node importance evaluation in the reward quantification so that the optimal action execution interval of each defense technique can be output. We also consider the possibility that advanced attackers may launch DDoS on the SDN controller in the game. The experimental results demonstrate that our proposed method can defend against DDoS cost-effectively and ensure the QoS in IoT networks with acceptable overhead. Yuming Feng 0002, Weizhe Zhang, Zijun Feng, Xiaoxiong Zhong, Fangming Liu |
IWQoS | 1 |
| 2024 | An IoT Device Identification Method Using Extracted Fingerprint From Sequence of Traffic Grayscale ImagesabstractWith the widespread deployment and application of various types of IoT devices, preventing illegal intrusion and impersonation attacks of IoT devices has become an important security challenge. Device identification helps to limit the behavior of suspicious devices and enhances the security of the device access process. In this paper, we propose a novel deep learning-based automatic fingerprint extraction model that addresses low efficiency and complexity of traditional feature engineering process, which are often rely on expert experience. The proposed model integrates advanced modules such as Depthwise Separable Convolution (DSC) and Gated Recurrent Unit (GRU), as well as architectures of inverted residuals and linear bottlenecks to enhance the performance of fingerprint extraction. After converting the raw device traffic into the sequence of traffic grayscale images, the model can analyze spatial and temporal features from them to generate highly distinguishable device fingerprints automatically. Additionally, we also achieve fast fingerprint search based on Hierarchical Navigable Small World (HNSW) to support device identification. Our proposed method can not only indicate deviations in device behavior from expected specifications, but also identify unknown and unreliable IoT devices. The experimental results show that our method has excellent performance and more comprehensive identification capabilities in multiple dimensions. Yuming Feng 0002, Yu Zhang 0036, Weizhe Zhang, Desheng Wang 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Collaborative Stealthy DDoS Detection Method Based on Reinforcement Learning at the Edge of Internet of ThingsabstractThe weaknesses of Internet of Things (IoT) devices leads to vulnerabilities easily, which can be exploited by criminals to launch Distributed Denial-of-Service (DDoS) attacks, becoming a major security hazard. Nowadays, the rapid development of the IoT makes the IoT-based DDoS attacks have the characteristics of wide distribution, large scale, and more stealthy that brings greater challenges for the DDoS detection. In this article, we conduct our research based on the edge side of IoT for providing earlier detection capability and more efficient resource utilization. We propose a novel reinforcement learning-based collaborative DDoS detection method and design a lightweight unsupervised classifier based on statistics. We deploy the classifiers in IoT edge gateways to detect anomalies by analyzing network traffic features in time. In order to deal with the dynamic changes of the IoT environment, we use the soft actor–critic (SAC) reinforcement learning model deployed on the edge server to adjust the parameter configuration of the underlying unsupervised classifier dynamically, which can ensure excellent detection effect for different types of IoT devices. In addition, a collaborative aggregation module is designed in the edge server to share the observation state and historical experience, which has a unique collaborative reward mechanism for the reinforcement learning model to fully mobilize the collaborative work capability. The experiments on public data set and constructed real-world testbed demonstrate that our proposed method has excellent detection performance and especially it can also discover stealthy IoT-based DDoS attacks accurately. Yuming Feng 0002, Weizhe Zhang, Shujun Yin, Yang Xiang 0001, Yu Zhang 0036 |
IEEE Internet Things J. | 1 |
| 2023 | SVScanner: Detecting smart contract vulnerabilities via deep semantic extraction
Hengyan Zhang, Weizhe Zhang, Yuming Feng 0002, Yang Liu 0039 |
J. Inf. Secur. Appl. | 3 |
| 2022 | A Consortium Blockchain-Based Access Control Framework With Dynamic Orderer Node Selection for 5G-Enabled Industrial IoTabstract5G-enabled Industrial Internet of Things (IIoT) deployment will bring more severe security and privacy challenges, which puts forward higher requirements for access control. Blockchain-based access control method has become a promising security technology, but it still faces high latency in consensus process and weak adaptability to dynamic changes in network environment. This article proposes a novel access control framework for 5G-enabled IIoT based on consortium blockchain. We design three types of chaincodes for the framework named policy management chaincode (PMC), access control chaincode (ACC), and credit evaluation chaincode (CEC). The PMC and ACC are deployed on the same data channel to implement the management of access control policies and the authorization of access. The CEC deployed on another channel is used to add behavior records collected from IIoT devices and calculate the credit value of IIoT domain. Specifically, we design a two-step credit-based Raft consensus mechanism, which can select the orderer nodes dynamically to achieve fast and reliable consensus based on historical behavior records stored in the ledger. Furthermore, we implement the proposed framework on a real-world testbed and compare it with the framework based on practical Byzantine fault tolerance consensus. The experiment results show that our proposed framework can maintain lower consensus cost time with 100 ms level and achieves four to five times throughput with lower hardware resource consumption and communication consumption. Besides, our design also improves the security and robustness of the access control process. Yuming Feng 0002, Weizhe Zhang, Xiapu Luo, Bin Zhang 0048 |
IEEE Trans. Ind. Informatics | 1 |