VLDB 2026 Research / reviewers in the wild / expert
Chenkai Guo
dblp:145/7485
· DBLP profile ↗
25ranked-venue papers
11as first author
11since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 16 · 7 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 7Artificial intelligence and machine learning · 5 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 3 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | EP-Detector: Automatic Detection of Error-Prone Operation Anomalies in Android ApplicationsabstractAndroid applications are pervasively adopted and heavily relied on in our daily life, leading to the growing demand for enhanced user experiences, such as ease for operation and robustness. Nevertheless, developers continue to prioritize traditional functionality and performance, overlooking the pivotal role of user experience in real-world scenarios. For example, poorly designed page elements can lead to user confusion, resulting in unexpected outcomes, termed as the error-prone operation anomalies (EPAs). In this work, we undertake the first effort to uncover the underlying essence of the EPA problem. To achieve this objective, we investigated the root causes of EPAs from three dimensions, i.e., subject, object and environment. These causes were identified by multi-stage attribute capturing and precise similarity computation. In this process, the causes are categorized into fine-grained classes, namely confusing behaviours, unsuitable layout, and resource overload. Building upon these insights, we propose a dynamic GUI-based testing tool EP-Detector to facilitate detecting the EPAs in real-world apps. The EP-Detector is equipped with widget-exploration based target navigation and automatic test oracle, enabling it to detect error-prone page elements and simulate events with both comprehensiveness and precision. To systematically study the prevalence and severity of real-world EPAs, we conducted experiments on 53 popular Android apps with EP-Detector. The confirmed results not only validate the high precision and completeness of EP-Detector but also highlight that EPAs are prevalent in current apps, with at least one EPA existing in every two page widgets on average, and 28.3% of them may lead to security and functionality issues or risks. The EP-Detector is available at https://github.com/WordDealer/EP-Detector. Chenkai Guo, Qianlu Wang, Naipeng Dong, Lingling Fan 0003, Tianhong Wang 0010, Enbao Chen, Zheli Liu |
ICSE | 1 |
| 2025 | Don't Mess with Bro's Cheese! An Empirical Study of Resource Conflict in Android Multi-windowabstractThe multi-window mode in Android has greatly improved productivity and usability by allowing multiple apps to run concurrently. However, alongside the advantages, such mode also introduces unforeseen risks in both functionality and security. In this work, we present the first systematic study to identify a previously unexplored class of issues, termed Multi-window Resource Conflicts (MRCs). Such conflicts occur when multiple app windows access the same system resource concurrently, potentially leading to crashes, functionality failures or unintended behaviors. To enhance the robustness and security of Android multi-window execution, we conduct a systematic and in-depth empirical study on the MRCs. We begin with a comprehensive root cause analysis, categorizing MRCs into three fundamental types based on their triggering patterns and affected resource states. To enable large-scale detection, we develop MRC-Detector, a static analysis framework that automatically identifies MRC issues in Android apps. Our manual verification confirms its high accuracy and effectiveness. We apply the MRC-Detector to the detection of over 150k real-world apps from F-droid and Google Play, uncovering the prevalence of MRC risks. Additionally, the distribution of MRC issues is analyzed in depth across multiple dimensions, including MRC type, APK size, app source and security classification. We further investigated the recognition and confirmation from developers and received 14 positive responses from vendors and project maintainers. Finally, comprehensive mitigation strategies are discussed. The materials of the study are available at: https://github.com/Huimilia/MRC. Chenkai Guo, Tianhong Wang 0010, Naipeng Dong, Qingqing Dong, Jiarui Che, Yaqiong Qiao, Xiangyang Luo 0001, Zheli Liu |
ASE | 1 |
| 2025 | Towards Accurate Social User Geolocation: Mean Shift, Incremental Learning and Graph Convolutional NetworksabstractThe geolocation of social users is crucial for understanding user behavior, optimizing advertisement placement, and enhancing public safety.However, existing methods tend to show some deficiencies when handling sparse datasets and may not fully capture the natural clustering characteristics of user locations, thereby resulting in inadequate geolocation accuracy.This paper proposes a novel social user geolocation method (MILGCN) that innovatively integrates Mean Shift Clustering, Incremental Learning, and Graph Convolutional Networks.Specifically, Mean Shift performs fine-grained clustering of user locations based on density peak characteristics, ensuring that geographically close users are grouped into the same cluster.Introducing an incremental learning mechanism into graph convolutional networks enables MILGCN to have progressive learning ability.As a result, the problem of incomplete feature extraction from sparse data is alleviated, resulting in more comprehensive user features and improved geolocation accuracy.Extensive experiments proved that the proposed method significantly outperforms the state-of-the-art baselines on the real Twitter datasets, demonstrating a substantial improvement in geolocation performance. Yaqiong Qiao, Aobo Jiao, Xiangyang Luo 0001, Chenliang Li 0005, Jiangtao Ma, Chenkai Guo |
SIGIR | 6 |
| 2025 | Fratricide! Hijacking in Android Multi-WindowabstractAndroid's multi-window solutions allow several apps to coexist on one screen, providing powerful functionalities and appealing visuals for modern mobile devices. However, this opens the door for potential malware hijacking attacks. In our study, we unveiled Android's insufficient security measures against malware activity in multi-window modes, and identified strategies on how to bypass these measures. We first introduced long-term monitoring methods through background services or malicious sub-window activities, and then designed and implemented 7 multi-window hijacking strategies to achieve multi-window hijacking in the three mainstream multi-window modes. To evaluate the effectiveness and impact of the attacks, we ran the hijacking in different system versions supporting multi-window solutions, and simulated the hijacking on 262 popular apps. All of the apps suffer from at least two types of multi-window hijacking attacks, and more than 65% of them can be attacked by all the 7 multi-window hijacking attacks. Furthermore, we designed and distributed a questionnaire to gather user opinions towards these attacks. 85% of respondents believe that the multi-window hijacking is highly covert and difficult to defend against. Of significance, we received acknowledgement and award fund from development teams of impactful apps. Chenkai Guo, Tianhong Wang 0010, Qianlu Wang, Naipeng Dong, Xiangyang Luo 0001, Zheli Liu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | QoS-Aware Diversified Service SelectionabstractIn QoS-aware service selection, merely considering the prediction accuracy of QoS is prone to redundant results, which hinders practical service composition and also undermines user's preference for rich service attributes. To address the problem, a novel diversity-aware graph-based QoS prediction model—DSSN (Diversified Service Selection Network) is proposed in this work. DSSN alleviates selection redundancy through enhancing the selection diversity besides QoS prediction accuracy. To improve the model performance, techniques like high-order message propagation and multi-task structure are integrated into the graph based neural network model. And to enhance the service diversity, a service distance based attention mechanism is designed to embed the users in the model, so that users are connected to services with diverse attributes. We evaluate DSSN on a public dataset via extensive comparison experiments with both diversity-aware and non-diversified service selection models. In the comparison experiments, the DSSN: 1) clearly outperforms the state-of-the-art diversity-aware models in both accuracy and diversity; 2) achieves concrete diversity improvement at the cost of an acceptable decrease in the QoS prediction compared to non-diversified baselines. The results demonstrate that DSSN is more suitable for diversity-aware service selection with ambiguous user requirements than traditional QoS-centric selection scenarios. Chenkai Guo, Naipeng Dong, Zheli Liu, Yang Xiang 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | DALT: Deep Activity Launching Test via Intent-Constraint ExtractionabstractThe frequent usage of the activity and intent in Android app development makes activity launching communication the focus of app analysis, which inspires the proposal of Activity Launching Test (ALT). Existing static analysis approaches are limited in test case generation and crash triggering of ALT, due to their path-insensitive nature and insufficient intent attribute exploration. This work proposes DALT, an activity test frame-work for launching-related bug detection, which empowers an inter-procedural, context-, flow- and path-sensitive static analysis to generate proper intents as test cases. By tailoring symbolic execution for intent propagation, DALT is able to explore statements in deep code position and extract conditional constraints in diverse launching-related execution paths. Consequently, invalid test paths are substantially reduced via the guidance of the extracted constraints. DALT also supports significantly more intent attribute types and value types of attributes, by reformatting them to be compatible with the commonly used constraint solvers. Extensive comparison experiments have been conducted from diverse validation dimensions. The results demonstrate that compared to the state-of-the-art approach, DALT is more effective in successfully launching activities and detecting bugs hiding in deep positions of the program paths. Ao Liu 0007, Chenkai Guo, Naipeng Dong, Yinjie Wang, Jing Xu 0008 |
ISSRE | 2 |
| 2022 | RSKNet-MTSP: Effective and portable deep architecture for speaker verification
Chenkai Guo, Junan Zhao, Jing Xu 0008 |
Neurocomputing | 2 |
| 2022 | Sharing runtime permission issues for developers based on similar-app review mining
Hongcan Gao, Chenkai Guo, Guangdong Bai, Dengrong Huang, Jing Xu 0008 |
J. Syst. Softw. | 2 |
| 2021 | Improving Deep CNN Architectures with Variable-Length Training Samples for Text-Independent Speaker Verification
Junan Zhao, Chenkai Guo |
Interspeech | 3 |
| 2021 | A Blockchain Based Framework for Smart Greenhouse Data Management
Chenkai Guo, Yapeng Zi |
KSEM | 1 |
| 2021 | Callback2Vec: Callback-aware hierarchical embedding for mobile application
Chenkai Guo, Dengrong Huang, Naipeng Dong, Jing Xu 0008 |
Inf. Sci. | 1 |
| 2020 | Vector-Based Attentive Pooling for Text-Independent Speaker Verification
Chenkai Guo, Hongcan Gao, Xiaolei Hou, Jing Xu 0008 |
INTERSPEECH | 2 |
| 2020 | Dilated residual networks with multi-level attention for speaker verification
Chenkai Guo, Hongcan Gao, Jing Xu 0008, Guangdong Bai |
Neurocomputing | 2 |
| 2020 | Early prediction for mode anomaly in generative adversarial network training: An empirical study
Chenkai Guo, Dengrong Huang, Jing Xu 0008, Guangdong Bai, Naipeng Dong |
Inf. Sci. | 1 |
| 2019 | AutoPer: Automatic Recommender for Runtime-Permission in Android ApplicationsabstractPermission mechanisms serve as the main measure to protect users privacy and security in Android applications. Modern smartphone operating systems (Android 6.0 and later versions) prompt users to regulate permissions using ask-on-first-use policy. Much research has been done to dynamically regulate permissions depending on user preferences and contexts in modern operation systems. However, all these techniques have limitations-they heavily rely on users' current or historical decisions on granting permissions, ignoring the fact that users are not experts on privacy protection, i.e., whether a permission shall be granted. In this work, we propose a system to automatically recommend runtime-permission to users. The main idea behind is that the application descriptions reflecting functional information can be used to analyze whether a permission is needed by the application. In more details, using description mining, we extract multiple topics and build a topic-permission mapper. Given an application as input, we first decide which topics it belongs to and then recommend the permissions according to the topic-permission mapper. As the output, besides binary recommendation of "allow" or "deny" recommendations, we provide explanations for the recommendations to uncover the reason for users. We implemented our approach in a tool- AutoPer, and evaluated the approach using 28,850 Android applications from Google Play. The experiments show that our approach achieves a fairly good performance with an accuracy of 81.0%, which demonstrates the effectiveness of AutoPer for permission recommendation. Hongcan Gao, Chenkai Guo, Naipeng Dong, Xiaolei Hou, Sihan Xu, Jing Xu 0008 |
COMPSAC (1) | 2 |
| 2019 | Bi-Dimensional Representation of Patients for Diagnosis PredictionabstractPrevious work on learning representation for patients from Electronic Health Records (EHRs) has succeeded in assisting medical diagnosis. Three perspectives of records, patient symptoms, medical treatments and diagnosis codes, are consisted in EHRs. However, existing approaches on patient representation learning take one perspective of patient symptoms and medical treatments into consideration, which miss out the latent correlations between them. Actually, based on the sequence of hospital visits, physical symptoms and associated treatments together affect the diagnosis and recovery of patients. In this paper, we propose Patient2vec, a novel model to learn the bi-dimensional representation for patients by jointly extracting features from physical symptoms and medical treatments. We introduce RNN model into Patient2vec to learn the sequential context-aware features of visits. The learned representations are then fed into a classifier to diagnosis prediction. Experiments on public dataset through multi-classification tasks indicate that Patient2vec achieves up to 76% improvement in area under the ROC curve (AUC) on average, demonstrating that our method significantly outperforms single dimension representation for patients. Weijing Wang, Chenkai Guo, Jing Xu 0008, Ao Liu 0007 |
COMPSAC (2) | 2 |
| 2019 | Deep Attentive Factorization Machine for App Recommendation ServiceabstractRecommendation service in mobile app markets decently helps users choose their preferred apps. Though a lot of recommendation service models are proposed in recent years, it is still challenging to tackle extreme sparse app data and get a relatively satisfactory recommendation performance. The reason can be concluded as that traditional recommendation models either focus on limited features or stand aside from deep training. In this paper, we propose knowledge-based deep factorization machine (KDFM), a recommendation model inspired by techniques of factorization machine and attentive deep learning, and apply it in the recommendation service for mobile apps. The KDFM aims to make full use of the rich categorical and textual knowledge in the app market for better performance. To achieve this goal, a topical attention representation component, which contains three typical parts (Word2Vec, BiLSTM and Topical Attention), is constructed. Such representation not only avoids the dimension explosion brought by traditional models, but also preserves the textual semantics for better recommendation. Through extensive experiments conducted on a large number of collected app samples, the KDFM achieves better performance compared with state-of-art rating recommendation models in terms of the rating prediction. In addition, the benefits brought by the usage of attention mechanism and topical representation are confirmed through the comparison experiments. Chenkai Guo, Xiaolei Hou, Naipeng Dong, Jing Xu 0008, Quanqi Ye |
ICWS | 1 |
| 2019 | Deep Review SharingabstractReview-Based Software Improvement (RBSI for short) has drawn increasing research attentions in recent years. Relevant efforts focus on how to leverage the underlying information within reviews to obtain a better guidance for further updating. However, few efforts consider the Projects Without sufficient Reviews (PWR for short). Actually, PWR dominates the software projects, and the lack of PWR-based RBSI research severely blocks the improvement of certain software. In this paper, we make the first attempt to pave the road. Our goal is to establish a generic framework for sharing suitable and informative reviews to arbitrary PWR. To achieve this goal, we exploit techniques of code clone detection and review ranking. In order to improve the sharing precision, we introduce Convolutional Neural Network (CNN) into our clone detection, and design a novel CNN based clone searching module for our sharing system. Meanwhile, we adopt a heuristic filtering strategy to reduce the sharing time cost. We implement a prototype review sharing system RSharer and collect 72,440 code-review pairs as our ground knowledge. Empirical experiments on hundreds of real code fragments verify the effectiveness of RSharer. RSharer also achieves positive response and evaluation by expert developers. Chenkai Guo, Dengrong Huang, Naipeng Dong, Quanqi Ye, Jing Xu 0008, Yaqing Fan |
SANER | 1 |
| 2019 | Systematic Comprehension for Developer Reply in Mobile System ForumabstractReview-based software development has become increasingly prevalent in recent years. Existing efforts aiming at either informative evaluation or sentiment analysis are mainly from the perspective of the reviewers, while neglecting the attitude and behavior of the developers. Such efforts inevitably suffer from recommendation bias in practice, and thus benefit little for the improvement of user reviews.In this paper, we attempt to bridge the gap between user review and developer reply, and conduct a systematic study for review reply in development forums, especially in Chinese mobile system forums. To this end, we concentrate on three research questions: 1) should a targeted review be replied; 2) how long time it should be replied; 3) does traditional review analysis help to pursue a reply for certain review? To answer such questions, given certain review datasets, we perform a systematical study including the following three stages: 1) a binary classification for reply behavior prediction, 2) a regression for prediction of reply time, 3) a systematic factor study for the relationship between traditional review analysis and reply performance. To enhance the accuracy of prediction and analysis, we proposed a CNN-based weak-supervision analysis framework, which exploits manifold techniques from NLP and deep learning. We validate our approach via extensive comparison experiments. The results show that our analysis framework is effective. More importantly, we have uncovered several interesting findings, which provide valuable guidance for further review improvement and recommendation. Chenkai Guo, Weijing Wang, Naipeng Dong, Quanqi Ye, Jing Xu 0008 |
SANER | 1 |
| 2018 | TRAC: A Therapeutic Regimen-Oriented Access Control Model in HealthcareabstractAccess control is a significant strategy to protect security and privacy. Due to electronization of health information, medical access control attracts lots of attention in the research community. The existing medical access control approaches mainly focus on doctors' roles and behaviors, such as role-based access control (RBAC) and risk-based access control. However, various therapeutic regimens can also lead to unauthorized access. The current researches do not consider access control authorization in terms of therapeutic regimens. In this work, we present an access control model based on therapeutic regimen. Our model, TRAC, proposes an access strategy by analyzing feasibility of therapeutic regimens. Our experiments show the effectiveness of TRAC in terms of precision. Moreover, our model also contributes to choosing better therapeutic regimens for patients. Hongcan Gao, Sihan Xu, Chenkai Guo, Xiaolei Hou, Jing Xu 0008 |
COMPSAC (2) | 4 |
| 2018 | A Projection-Based Approach for Memory Leak DetectionabstractOne of the major software safety issues is memory leak. Moreover, detecting memory leak vulnerabilities is challenging in static analysis. Existing static detection tools find bugs by collecting programs' information in the process of scanning source code. However, the current detection tools are weak in efficiency and accuracy, especially when the targeted program contains complex branches. This paper proposes a projection-based approach to detect memory leaks in C source code with complex control flows. According to the features of memory allocation and deallocation in C source code, this approach projects the original control flow graph of a program to a simpler one, and it reduces the analysis complexity. Besides, this paper implements a memory-leak detection tool-PML_Checker, and evaluates the tool by comparing with three open-source static detection tools on both public benchmarks and study test cases. The experimental results show that PML_Checker reports the most memory leak vulnerabilities among the four existing tools with complex control flows and complex data types, and PML_Checker obtains higher efficiency and accuracy on public benchmarks. Sihan Xu, Chenkai Guo, Jing Xu 0008, Naipeng Dong, Xiujuan Ji |
COMPSAC (2) | 3 |
| 2017 | Application of Hidden Markov Model in SQL Injection DetectionabstractDue to the increasing complexity of web and client application's structure, security problem has become more and more critical. Among all the threats reported, SQL Injection Attacks (SQLIAs) have always been top-ranked in recent years, and network logs, which are very important for the detection of SQLIA, are often utilized to analyze the user's attacking behaviors. However, the collection of network logs is often compromised due to the growing complexity of network structure, leading to a great challenge to the log-based SQLIA detection. In view of this, this paper proposes a novel approach to the detection of SQLIA based on log analyzing with Hidden Markov Model (HMM), combined with statistical characteristic and feature matching. At first, we build browsing behavior models of attackers and legal users. Furthermore, we use HMM to restore user's browsing procedure from the customised user logs. Finally, the method detects SQLIAs by analyzing the behavior of users in reality, without requiring sensitive information submitted by users. Our experiments show that the proposed method can detect possible SQLIAs and identify malicious users effectively, and has higher accuracy in comparison with the Kmeans method. Jing Xu 0008, Liying Yuan, Chenkai Guo, Xiujuan Ji |
COMPSAC (2) | 6 |
| 2016 | An Effective Penetration Test Approach Based on Feature Matrix for Exposing SQL Injection VulnerabilityabstractAmong all the Web application security issues, SQL Injection Vulnerability (SQLIV) is one of the most serious problems. How to test SQLIV effectively is of great importance. To address this issue, this paper describes a novel approach that is the utilization of Feature Matrix (FM) model for SQLIV black-box penetration test. Firstly, FM is introduced, which integrates the general SQLIV penetration test features for SQLIV. Each row of the matrix is defined as a test pattern, named Global Test Pattern (GTP). Then, GTP Selection (GTPS) process is used to select legal GTPs for general SQLIV penetration test. Secondly, to find out the optimum FM during SQLIV penetration test procedure automatically, Dynamic Matrix Selection (DMS) algorithm is described, which is based on dynamic tree pruning. Finally, a prototype tool SQLEXP is developed, the experiments of which are carried out under the context of two target Web applications and about 30000 real Internet URLs. The results show that the proposed approach can effectively improve the testing effect for SQLIV penetration test compared with two benchmarking testing tools. Jing Xu 0008, Chenkai Guo, Jiehui Kang, Sihan Xu, Guannan Si |
COMPSAC | 4 |
| 2016 | Automatic Construction of Callback Model for Android ApplicationabstractThe heavy use of event-callback mechanism in frameworks like Android causes challenges for static analysis. Modelling of callback mechanisms for Android applications (app for short) is becoming a major method to address such challenges. In this work, we aim to construct a generic callback-related model that supports path-sensitive analysis. We consider three unresolved challenges in the existing modelling approaches: 1) building connections between different components; 2) identifying path-sensitive conditions; 3) handling the system-driven callbacks and fine-grained lifecycle callbacks. We propose algorithms for constructing a generic path-sensitive callback model and present a prototype model constructor, AndroChecker, to validate our approach. We evaluate 20 real-world apps using AndroChecker. The evaluation result shows that our method and tool have a strong capability in modelling path conditions and inter-component invocations. Chenkai Guo, Quanqi Ye, Naipeng Dong, Guangdong Bai, Jin Song Dong 0001, Jing Xu 0008 |
ICECCS | 1 |
| 2015 | An Improvement to Fault Localization Technique Based on Branch-Coverage SpectraabstractFor trust in software, developers spend much effort debugging to ensure that software behaviors as expected. Spectrum-based fault localization techniques (SFL) make use of runtime coverage of program elements, like statements, branches and du-pairs, and then check codes in the order of the rank of suspiciousness. So, correct elements with higher suspiciousness than faulty elements cause the loss of precision. In this paper, we focus on a situation where suspiciousness calculated according to coverage and outcome, i.e. Successful or failing, is higher than it should be. It is found that when a branch structure is repeatedly executed, which is normal in real-life programs, and all of its branches are covered within a run, a branch related to faults could lead other branches to be doubted. To reduce effects between branches, we do the following things: First, we utilize branches to monitor program behaviors, second, we take test cases with high similarities as triggered by the same fault, third, for branches mentioned, we propose an algorithm to infer which branch is more likely to be faulty in the failure, finally, experiments based on Siemens benchmark set and flex show that our approach is useful to heighten the ranking of faulty elements by reducing suspiciousness of correct branches. Sihan Xu, Jing Xu 0008, Jufeng Yang, Chenkai Guo, Liying Yuan, Wenli Song, Guannan Si |
COMPSAC | 5 |