VLDB 2026 Research / reviewers in the wild / expert
Zhiniang Peng
dblp:140/5462
· DBLP profile ↗
14ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0002-8463-1971ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 5 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC SeaabstractWindows services utilizing Remote Procedure Call (RPC) and Component Object Model (COM) technology over the underlying Advanced Local Procedure Call (ALPC) transport present a significant attack surface. However, previous research often focused on known vulnerability patterns or required time-consuming reverse engineering, which hinders scalable vulnerability discovery. We developed a tool designed to automate and scale the fuzzing of ALPC communications. It employs a record-and-replay based strategy, capturing live system-wide ALPC traffic and replaying mutated payloads directly at the ALPC layer, thereby overcoming the scalability barrier posed by the manual preparation required with conventional methods. Furthermore, it integrates dedicated detection techniques to identify information leakage vulnerabilities that crash-centric fuzzers often miss. After evaluating various versions of Windows operating systems, we discovered 12 vulnerabilities confirmed by Microsoft, 10 of which have already been assigned CVE numbers. Haoyi Liu, Feng Dong 0008, Yunpeng Tian, Mu Zhang 0001, Fangming Gu, Zhiniang Peng, Haoyu Wang 0001 |
CCS | 7 |
| 2025 | Error Messages to Fuzzing: Detecting XPS Parsing Vulnerabilities in Windows Printing ComponentsabstractWindows printing services remain a notable vector for attacks. Previous studies have predominantly targeted vulnerabilities within various control aspects of printing services, such as spooler services and firmware updates. Yet, we contend that an essential aspect of data processing—the document parser within printer drivers—has been overlooked in past research. We present a coverage-based fuzzing system, PrintXPSurge, specifically crafted to detect weaknesses in the XPS printer driver's parsing function. To craft semantically correct XPS files, we leverage a large language model-assisted repair approach to automate the creation of semantically correct XPS files that comply with necessary constraints. To ensure our fuzzing process effectively interacts with the XPS printer driver, we develop a progressive state reconstruction method that addresses individual dependency requirements across the entire printing service workflow. Furthermore, when a crash is detected, we employ backtracing to confirm its origin in the XPS parser, isolating it from other components in the pipeline. Our evaluation reveals that PrintXPSurge surpasses existing top Windows fuzzers in performance, successfully identifying 102 bugs in 10 drivers from major brands, including 17 zero-day vulnerabilities confirmed by Microsoft and third-party vendors. Yunpeng Tian, Feng Dong 0008, Junhai Wang, Mu Zhang 0001, Zhiniang Peng, Zesen Ye, Xiapu Luo, Haoyu Wang 0001 |
CCS | 5 |
| 2025 | Be Careful of What You Embed: Demystifying OLE Vulnerabilities
Yunpeng Tian, Feng Dong 0008, Haoyi Liu, Zhiniang Peng, Zesen Ye, Shenghui Li, Xiapu Luo, Haoyu Wang 0001 |
NDSS | 5 |
| 2023 | Detecting Union Type Confusion in Component Object Model
Xiaogang Zhu 0001, Daojing He, Minhui Xue 0001, Shouling Ji, Mohammad Sayad Haghighi, Sheng Wen, Zhiniang Peng |
USENIX Security Symposium | 8 |
| 2023 | On the security of fully homomorphic encryption for data privacy in Internet of ThingsabstractSummary To achieve data privacy in Internet of Things (IoT), fully homomorphic encryption (FHE) technique is used to encrypt the data while allowing others to compute on the encrypted data. However, there are many well‐known problems with FHE such as chosen‐ciphertext attack security and circuit privacy problem. In this article, we demonstrate that a famous FHE application named Brakerski/Fan–Vercauteren scheme, a circuit privacy application based on fast private set intersection, and an encoding application that encodes integer or floating point numbers based on Microsoft Simple Encryption Arithmetic Library homomorphic encryption library, are insecure against chosen ciphertext attacks due to insecurity of the underlying fully homomorphic schemes. These results show that using cryptographic primitives even with security proofs causes serious security vulnerabilities on the applications themselves. The results also give evidences that the security of adopted cryptographic primitives in IoT should be proved in appropriate formal security models as well as proof of the scheme itself. Zhiniang Peng, Wei Zhou 0044, Xiaogang Zhu 0001, Youke Wu, Sheng Wen |
Concurr. Comput. Pract. Exp. | 1 |
| 2022 | COMRace: Detecting Data Race Vulnerabilities in COM Objects
Fangming Gu, Qingli Guo, Zhiniang Peng, Xiaorui Gong |
USENIX Security Symposium | 4 |
| 2022 | Static Detection of File Access Control Vulnerabilities on Windows SystemabstractSummary Traditional applications have been developed for decades. Most of the security research around them have focused on the detection of memory corruption vulnerabilities, such as buffer overflow, double fetch, and integer overflow. On the contrary, logic bugs, a kind of flaws caused by unreasonable application logic, attract much less attention. Files are the most common media for programs to persist their data in the system. As the file owners, programs are responsible for protecting their files from malicious users' tampering by leveraging access control mechanisms. However, if a program configures their access control mechanisms in wrong ways and causes evil users to bypass security checks to access files, there exists a file access control vulnerability. As a branch of logic flaws, file access control vulnerabilities are less popular with researchers. Thus, to mitigate the harm of the file access control vulnerabilities on Windows system, our team conducted first‐step research on them. We first classified file access control bugs into two types and codified some bug patterns. Then we formalized file access control vulnerabilities to propose a scalable detection method and implemented a lightweight analysis system StaticFAC. After evaluating StaticFAC in real‐world Windows software, we discovered 15 0‐day bugs. Jiadong Lu, Fangming Gu, Jiahui Chen 0002, Zhiniang Peng, Sheng Wen |
Concurr. Comput. Pract. Exp. | 5 |
| 2022 | Comments on "A blockchain-based attribute-based signcryption scheme to secure data sharing in the cloud"
Jiahui Chen 0002, Zhiniang Peng |
J. Syst. Archit. | 4 |
| 2021 | Code is the (F)Law: Demystifying and Mitigating Blockchain Inconsistency Attacks Caused by Software BugsabstractBlockchains promise to provide a tamper-proof medium for transactions, and thus enable many applications including cryptocurrency. As a system built on consensus, the correctness of a blockchain heavily relies on the consistency of states between its nodes. But consensus protocols of blockchains only guarantee the consistency in the transaction sequence rather than nodes' internal states. Instead, nodes must replay and exe-cute all transactions to maintain their local states independently. When executing transactions, any different execution result could cause a node out-of-sync and thus gets isolated from other nodes.After systematically modeling the transaction execution process in blockchains, we present a new attack INCITE, which can lead different nodes to different states. Specifically, attackers could invoke an ambiguous transaction of a vulnerable smart contract, utilize software bugs in smart contracts to lead nodes that execute this transaction into different states. Unlike attacks that bring short-term inconsistencies, such as fork attacks, INCITE can cause nodes in the blockchain to fall into a long-term inconsistent state, which further leads to great damages to the chain (e.g., double-spending attacks and expelling mining power). We have discovered 7 0day vulnerabilities in 5 popular blockchains which can enable this attack. We also proposed a defense solution to mitigate this threat. Experiments showed that it is effective and lightweight. Guorui Yu, Shibin Zhao, Chao Zhang 0008, Zhiniang Peng, Yuandong Ni, Xinhui Han |
INFOCOM | 4 |
| 2019 | MQ Aggregate Signature Schemes with Exact Security Based on UOV Signature
Jiahui Chen 0002, Jie Ling 0002, Jianting Ning, Zhiniang Peng, Yang Tan 0002 |
Inscrypt | 4 |
| 2017 | A Secure Variant of the SRP Encryption Scheme with Shorter Private Key
Zhiniang Peng, Shaohua Tang |
ISPEC | 2 |
| 2016 | Fast Implementation of Simple Matrix Encryption Scheme on Modern x64 CPU
Zhiniang Peng, Shaohua Tang, Ju Chen, Xinglin Zhang 0001 |
ISPEC | 1 |
| 2015 | Efficient hardware implementation of PMI+ for low-resource devices in mobile cloud computing
Shaohua Tang, Guomin Chen, Zhiniang Peng, Adama Diene, Xiaofeng Chen 0001 |
Future Gener. Comput. Syst. | 4 |
| 2014 | Efficient Hardware Implementation of MQ Asymmetric Cipher PMI+ on FPGAs
Shaohua Tang, Guomin Chen, Zhiniang Peng |
ISPEC | 4 |