VLDB 2026 Research / reviewers in the wild / expert
Haining Meng
dblp:144/7186
· DBLP profile ↗
15ranked-venue papers
5as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 3 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GLA-SDP: A novel attention-based semantic and static feature fusion method using GCN and LSTM for software defect prediction
Haining Meng, Xinhong Hei 0001 |
J. Syst. Softw. | 1 |
| 2025 | SLVHound: Static Detection of Session Lingering Vulnerabilities in Modern Java Web ApplicationsabstractSession Lingering Vulnerability (SLV) is an often overlooked authentication flaw that allows sessions to persist after authenticationsensitive operations.Despite its widespread occurrence and severe impact, SLVs have received little attention.To address this gap, we present the first comprehensive study of SLV in Web applications, introducing a novel detection tool called SLVHound.Our approach employs static analysis of both code and SQL queries to identify authentication-sensitive operations and session expiration.SLVHound then detects SLVs by verifying whether authenticationsensitive operations are consistently followed by session expiration.We evaluated SLVHound on 15 popular Web applications, uncovering 46 potential vulnerabilities.Further analysis confirmed 44 of them as true SLVs, including 30 previously unreported vulnerabilities, with 16 CVE IDs granted. CCS Concepts• Security and privacy → Web application security. Haining Meng, Jie Lu 0009, Yongheng Huang, Lian Li 0002 |
Internetware | 1 |
| 2025 | BIMCompNet: Multimodal Dataset for Geometric Deep Learning in Building Information ModelabstractBuilding Information Model (BIM) has become a significantly digital platform for representing buildings in the Architecture, Engineering, and Construction (AEC) industry. However, the absence of extensive, class- diverse, and balanced datasets at the BIM component level has limited the development of AI-driven BIM analysis. In this study, BIMCompNet is proposed as a large-scale multimodal dataset from Industry Foundation Classes (IFC), which can learn BIM component geometry features from multiple representation methods, including rendered views, point clouds, mesh structures, voxel grids, and semantic graphs. BIMCompNet is constructed by a standardized two-stage processing pipeline: (1) At the model level, geometry units are normalized to the SI units, models are converted to the IFC format, metadata is anonymized, and components are automatically extracted into individual IFC files. (2) At the component level, semantic labels are corrected, geometry and positioning are aligned, duplicates at model and project levels are removed, and five synchronized modalities (OBJ meshes, multi-view images, point clouds, voxel grids, and heterogeneous IFC graphs) are generated. BIMCompNet comprises 1,304,206 cleaned and labeled components across 87 IFC classes, collected from 1,607 real-world BIM models spanning 14 building types. To mitigate class imbalance, underrepresented classes are merged, and dominant classes are down-sampled to create balanced subsets suitable for robust AI model training and benchmarking. Benchmarking is performed on classification tasks by different models with multiple data modalities. Both the dataset and the processing pipeline will be publicly released to support reproducibility and private dataset extension. Mingsong Yang, Xinhong Hei 0001, Kehai Chen, Haining Meng, Haoyang Dong |
ACM Multimedia | 4 |
| 2024 | Detecting Broken Object-Level Authorization Vulnerabilities in Database-Backed ApplicationsabstractBroken object-level authorization (BOLA) vulnerabilities are among the most critical security risks facing database-backed applications. However, there is still a significant gap in our systematic understanding of these vulnerabilities. To bridge this gap, we conducted an in-depth study of 101 real-world BOLA vulnerabilities from opensource applications. Our study revealed the four most common object-level authorization models in database-backed application. Yongheng Huang, Chenghang Shi, Jie Lu 0009, Haofeng Li, Haining Meng, Lian Li 0002 |
CCS | 5 |
| 2024 | Boosting the Performance of Multi-Solver IFDS Algorithms with Flow-Sensitivity OptimizationsabstractThe IFDS (Inter-procedural, Finite, Distributive, Subset) algorithms are popularly used to solve a wide range of analysis problems. In particular, many interesting problems are formulated as multi-solver IFDS problems which expect multiple interleaved IFDS solvers to work together. For instance, taint analysis requires two IFDS solvers, one forward solver to propagate tainted data-flow facts, and one backward solver to solve alias relations at the same time. For such problems, large amount of additional data-flow facts need to be introduced for flow-sensitivity. This often leads to poor performance and scalability, as evident in our experiments and previous work. In this paper, we propose a novel approach to reduce the number of introduced additional data-flow facts while preserving flow-sensitivity and soundness. We have developed a new taint analysis tool, SADROID, and evaluated it on 1,228 open-source Android APPs. Evaluation results show that SADROID significantly outperforms FLowDROID (the state-of-the-art multi-solver IFDS taint analysis tool) without affecting precision and soundness: the run time performance is sped up by up to 17.89X and memory usage is optimized by up to 9X. Haofeng Li, Jie Lu 0009, Haining Meng, Liqing Cao, Lian Li 0002, Lin Gao 0002 |
CGO | 3 |
| 2024 | AutoWeb: Automatically Inferring Web Framework Semantics via Configuration Mutation
Haining Meng, Haofeng Li, Jie Lu 0009, Chenghang Shi, Liqing Cao, Lian Li 0002, Lin Gao 0002 |
ICECCS | 1 |
| 2024 | A novel multi-step-ahead approach for cloud server aging prediction based on hybrid deep learning model
Haining Meng |
Eng. Appl. Artif. Intell. | 1 |
| 2024 | Generic Sensitivity: Generics-Guided Context Sensitivity for Pointer AnalysisabstractGeneric programming has found widespread application in object-oriented languages like Java. However, existing context-sensitive pointer analyses fail to leverage the benefits of generic programming. This paper introducesgeneric sensitivity, a new context customization scheme targeting generics. We design our context customization scheme in such a way that generic instantiation sites, i.e., locations instantiating generic classes/methods with concrete types, are always preserved as key context elements. This is realized by augmenting contexts with a type variable lookup map, which is efficiently generated in a context-sensitive manner throughout the analysis process. We have implemented various variants of generic-sensitive analysis in WALA and conducted extensive experiments to compare it with state-of-the-art approaches, including both traditional and selective context-sensitivity methods. The evaluation results demonstrate that generic sensitivity effectively enhances existing context-sensitivity approaches, striking a new balance between efficiency and precision. For instance, it enables a 1-object-sensitive analysis to achieve overall better precision compared to a 2-object-sensitive analysis, with an average speedup of 12.6 times (up to 62 times). Haofeng Li, Tian Tan 0001, Yue Li 0006, Jie Lu 0009, Haining Meng, Liqing Cao, Yongheng Huang, Lian Li 0002, Lin Gao 0002, Peng Di, ChenXi Cui |
IEEE Trans. Software Eng. | 5 |
| 2022 | Generic sensitivity: customizing context-sensitive pointer analysis for genericsabstractGeneric programming has been extensively used in object-oriented programs such as Java. However, existing context-sensitive pointer analyses perform poorly in analyzing generics. This paper introduces generic sensitivity, a new context customization scheme targeting generics. We design our context customization scheme in such a way that generic instantiation sites, i.e., locations instantiating generic classes/methods with concrete types, are always preserved as key context elements. This is realized by augmenting contexts with a type variable lookup map, which is efficiently updated during the analysis in a context-sensitive manner. Haofeng Li, Jie Lu 0009, Haining Meng, Liqing Cao, Yongheng Huang, Lian Li 0002, Lin Gao 0002 |
ESEC/SIGSOFT FSE | 3 |
| 2021 | Scaling Up the IFDS Algorithm with Efficient Disk-Assisted ComputingabstractThe IFDS algorithm can be memory-intensive, requiring a memory budget of more than 100 GB of RAM for some applications. The large memory requirements significantly restrict the deployment of IFDS-based tools in practise. To improve this, we propose a disk-assisted solution that drastically reduces the memory requirements of traditional IFDS solvers. Our solution saves memory by 1) recomputing instead of memorizing intermediate analysis data, and 2) swapping in-memory data to disk when memory usages reach a threshold. We implement sophisticated scheduling schemes to swap data between memory and disks efficiently. We have developed a new taint analysis tool, DiskDroid, based on our disk-assisted IFDS solver. Compared to FlowDroid, a state-of-the-art IFDS-based taint analysis tool, for a set of 19 apps which take from 10 to 128 GB of RAM by FlowDroid, DiskDroid can analyze them with less than 10GB of RAM at a slight performance improvement of 8.6%. In addition, for 21 apps requiring more than 128GB of RAM by FlowDroid, DiskDroid can analyze each app in 3 hours, under the same memory budget of 10GB. This makes the tool deployable to normal desktop environments. We make the tool publicly available at https://github.com/HaofLi/DiskDroid. Haofeng Li, Haining Meng, Hengjie Zheng, Liqing Cao, Jie Lu 0009, Lian Li 0002, Lin Gao 0002 |
CGO | 2 |
| 2021 | Forecasting the Track Irregularity of High-speed Railway based on a WT-GA-GRU ModelabstractWhether the railway track can run smoothly for a long time directly affects the safety of the railway. In view of the nonlinear, random, and sudden characteristics of the time series data of railway track, we propose a WT-GA-GRU model to forecast the track irregularity of high-speed railway. Firstly, the original time series is decomposed by wavelet transform (WT), and the decomposed multiple time series are forecasted by the gated recurrent unit (GRU) networks optimized by genetic algorithm (GA). Then the forecasted results are obtained by wavelet reconstruction. Experimental results show that, compared with support vector machine (SVM) and long short-term memory (LSTM) model, the combined WT-GA-GRU model proposed in this paper has higher forecasting accuracy. Haining Meng, Wei Li 0068, Wenjiang Ji, Xinyu Tong 0003, Xinhong Hei 0001 |
EUC | 1 |
| 2019 | Performance-Boosting Sparsification of the IFDS Algorithm with Applications to Taint AnalysisabstractThe IFDS algorithm can be compute-and memoryintensive for some large programs, often running for a long time (more than expected) or terminating prematurely after some time and/or memory budgets have been exhausted. In the latter case, the corresponding IFDS data-flow analyses may suffer from false negatives and/or false positives. To improve this, we introduce a sparse alternative to the traditional IFDS algorithm. Instead of propagating the data-flow facts across all the program points along the program’s (interprocedural) control flow graph, we propagate every data-flow fact directly to its next possible use points along its own sparse control flow graph constructed on the fly, thus reducing significantly both the time and memory requirements incurred by the traditional IFDS algorithm. In our evaluation, we compare FLOWDROID, a taint analysis performed by using the traditional IFDS algorithm, with our sparse incarnation, SPARSEDROID, on a set of 40 Android apps selected. For the time budget (5 hours) and memory budget (220GB) allocated per app, SPARSEDROID can run every app to completion but FLOWDROID terminates prematurely for 9 apps, resulting in an average speedup of 22.0x. This implies that when used as a market-level vetting tool, SPARSEDROID can finish analyzing these 40 apps in 2.13 hours (by issuing 228 leak warnings) while FLOWDROID manages to analyze only 30 apps in the same time period (by issuing only 147 leak warnings). Dongjie He, Haofeng Li, Lei Wang 0004, Haining Meng, Hengjie Zheng, Jie Liu 0020, Shuangwei Hu, Lian Li 0002, Jingling Xue |
ASE | 4 |
| 2018 | Research on Airport Refueling Vehicle Scheduling Problem Based on Greedy Algorithm
Zhurong Wang, Xinhong Hei 0001, Haining Meng |
ICIC (1) | 4 |
| 2018 | The Model of Flight Recovery Problem with Decision Factors and Its Optimization
Zhurong Wang, Xinhong Hei 0001, Haining Meng |
ICIC (1) | 4 |
| 2018 | Towards Large-Scale RFID Positioning: A Low-cost, High-precision Solution Based on Compressive SensingabstractRFID-based positioning is emerging as a promising solution for inventory management in places like warehouses and libraries. However, existing solutions either are too sensitive to the environmental noise, or require deploying a large number of reference tags which incur expensive deployment cost and increase the chance of data collisions. This paper presents CSRP, a novel RFID based positioning system, which is highly accurate and robust to environmental noise, but relies on much less reference tags compared with the state-of-the-art. CSRP achieves this by employing an noise-resilient RFID fingerprint scheme and a compressive sensing based algorithm that can recover the target tag's position using a small number of signal measurements. This work provides a set of new analysis, algorithms and heuristics to guide the deployment of reference tags and to optimize the computational overhead. We evaluate CSRP in a deployment site with 270 commercial RFID tags. Experimental results show that CSRP can correctly identify 84.7% of the test items, achieving an accuracy that is comparable to the state-of-the-art, using an order of magnitude less reference tags. Liqiong Chang, Xinyi Li 0005, Ju Wang 0003, Haining Meng, Xiaojiang Chen, Dingyi Fang, Zhanyong Tang, Zheng Wang 0001 |
PerCom | 4 |