Yanxiang Tong

dblp:155/4352 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
9since 2021 · last 2026
0009-0003-9263-1714ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 3 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MGR-Net: Multimodal Fusion Network for Ponzi Scheme Detection Based on Graph Refinement
Jinqi Lei, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001
COMPSAC2
2026 SD-MIL: A Two-Stage De-Noising Framework for Smart Contract Vulnerability Detection via Multi-Instance Learning
Jiaying Xie, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001
COMPSAC2
2026 LLM-Driven Smart Contract Vulnerability Detection Based on Heterogeneous Graphs
Yunhan Zhang, Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001
COMPSAC2
2026 Context-aware smart contract comment generation using information retrieval and scenario-driven chain-of-thought
Yanxiang Tong, Hai Dong 0001, Yan Xiao 0002, Pengcheng Zhang 0001
Expert Syst. Appl.2
2026 OSEL: boosting vulnerability detection with opcode slicing-enhanced feature learning
Yanxiang Tong, Shengkai Gao, Shunhui Ji, Pengcheng Zhang 0001
Softw. Qual. J.1
2026 A Review of Learning-based Smart Contract Vulnerability Detection: A Perspective on Code Representation
abstract
With the rapid development of blockchain technology, smart contract applications have become increasingly widespread. However, vulnerabilities in contracts may be exploited by attackers, causing serious financial losses. In recent years, learning-based approaches have gained prominence for their accuracy and efficiency by automatically extracting explicit syntactic or semantic features from a large number of smart contracts with minimal manual intervention. In this article, we conduct a comprehensive analysis and ultimately select 61 scientific publications to provide researchers, especially beginners, with a comprehensive understanding of the learning-based detection process and guidance on selecting appropriate code representations. We first introduce common types of vulnerabilities, detail uncovered vulnerabilities, and summarize datasets used in learning-based methods. Then, we elaborate on the general process of learning-based detection and classify existing publications based on code representations, including sequence, tree, graph, and mixed features. Finally, we summarize the progress of existing work and explore future research directions in this field.
Yanxiang Tong, Shunhui Ji, Hai Dong 0001, Xiapu Luo, Pengcheng Zhang 0001
ACM Trans. Softw. Eng. Methodol.2
2025 Smart Contract Reentrancy Vulnerability Localization Using Explainable Graph Neural Networks
abstract
While smart contracts, as automatic processing programs for decentralized applications deployed on the blockchain, have gained widespread attention, their vulnerabilities have also led to significant economic losses. To address this security issue, researchers have proposed various approaches for locating vulnerabilities in smart contracts. However, most of them are designed to identify vulnerable smart contracts within a blockchain-based application. Only a few approaches adopt deep learning techniques to locate the exact line containing the reentrancy vulnerability based on Ethereum smart contracts’ source code. In this paper, we focus on the bytecode of Ethereum smart contracts and propose DeepLocator, a deep learning-based two-phase locator designed to pinpoint code-line-level reentrancy vulnerabilities. In the detection phase, DeepLocator constructs an attributed control flow graph extracted from the smart contract’s opcodes, and applies graph neural networks (GNNs) to determine whether a contract contains reentrancy vulnerabilities. In the localization phase, DeepLocator employs a model explainer of GNNs to rank the opcodes of each vulnerable smart contract according to their impact on the detection phase’s results, and then maps them back to the source code with the output of ranked suspicious statements. Empirical experiments conducted on widely used datasets of reentrancy vulnerabilities validate the efficacy of our locator. DeepLocator outperforms baseline traditional and learning-based detection approaches by 28.7% and 3.5%, respectively. Moreover, it pinpoints 20.0%, 61.1%, and 74.5% vulnerabilities within the top 1, 5, and 10 ranked suspicious statements, respectively.
Yanxiang Tong, Shunhui Ji, Pengcheng Zhang 0001
COMPSAC2
2025 LLMs-Driven Vulnerability Detection Combining LogicASG Reasoning with In-Context Learning
abstract
With the rapid development of blockchain technology, smart contracts have become a key innovation, offering de-centralized, transparent, and automated solutions across various industries. However, their widespread adoption has also exposed significant security vulnerabilities, leading to substantial financial losses. Traditional vulnerability detection methods are limited in terms of automation and efficiency due to their reliance on predefined knowledge. Although deep learning-based methods show promise, their effectiveness is hindered by the need for high-quality labeled datasets. Recently, large language models (LLMs) have been applied to the detection of vulnerabilities in smart contracts due to their powerful code understanding capabilities. However, their lack of domain-specific knowledge limits their ability to grasp the structure information and context of smart contracts, leading to suboptimal detection results. This paper proposes an approach driven by LLMs to detect vulnerabilities in Ethereum smart contracts, combining logic Abstract Semantic Graph (logicASG) reasoning with In-Context Learning (ICL). Our approach integrates the contract’s logicASG to improve the code understanding of LLMs, retrieves the logicASG’s most similar graph to provide domain-specific knowledge, and designs a Chain-of-Thought (CoT) based prompt template to compose complex vulnerability detection problem. Experimental evaluations conducted on a recently published dataset consisting of 1093 smart contracts validate the efficacy of our approach. Compared to current advanced approaches, our approach achieves an average accuracy improvement of 24.05%, and reduces detection time per contract by 111.69 seconds.
Wenhui Xia, Yanxiang Tong, Pengcheng Zhang 0001
COMPSAC2
2021 Timely and accurate detection of model deviation in self-adaptive software-intensive systems
abstract
Control-based approaches to self-adaptive software-intensive systems (SASs) are hailed for their optimal performance and theoretical guarantees on the reliability of adaptation behavior. However, in practice the guarantees are often threatened by model deviations occurred at runtime. In this paper, we propose a Model-guided Deviation Detector (MoD2) for timely and accurate detection of model deviations. To ensure reliability, a SAS can switch a control-based optimal controller for a mandatory controller once an unsafe model deviation is detected. MoD2 achieves both high timeliness and high accuracy through a deliberate fusion of parameter deviation estimation, uncertainty compensation, and safe region quantification. Empirical evaluation with three exemplar systems validated the efficacy of MoD2 (93.3% shorter detection delay, 39.4% lower FN rate, and 25.2% lower FP rate), as well as the benefits of the adaptation-switching mechanism (abnormal rate dropped by 29.2%).
Yanxiang Tong, Yi Qin 0002, Yanyan Jiang 0001, Chang Xu 0001, Chun Cao, Xiaoxing Ma
ESEC/SIGSOFT FSE1
2020 Overwhelming Uncertainty in Self-adaptation: An Empirical Study on PLA and CobRA
abstract
Self-adaptation is a promising approach to enable software systems to address the challenge of uncertainty. Different from traditional reactive adaptation mechanisms that focus on the system’s current environment state only, proactive adaptation mechanisms predict the potential environmental changes and make better adaptation plan accordingly. Proactive Latency-aware Adaptation (PLA for shot) and Control-based Requirements-oriented Adaptation (CobRA for short) are two representative approaches to build proactive self-adaptation mechanisms. Despite their different design and implementation details, PLA and CobRA are reported to have a very similar performance in supporting self-adaptation. In this paper, we conduct an in-depth comparison between these two approaches, trying to explain their effectiveness. We separate a proactive self-adaptation mechanism into three modules, namely system modelling, environment predicting, and uncertainty filtering. We identify the design choices of PLA and CobRA approaches, in terms of these three modules. We performed an ablation study on the three modules of PLA and compared their performance with CobRA. Our study reveals the very important role of uncertainty filtering in supporting self-adaptation, as well as the huge impact of a fluctuant environment on a self-adaptation mechanism. Based on this observation, we briefly discuss a conceptual self-adaptation mechanism, MAPE-U (monitoring, analyzing, planning, executing with uncertainty).
Jingxin Fan, Yanxiang Tong, Yi Qin 0002, Xiaoxing Ma
Internetware2
2017 Augmenting Bug Localization with Part-of-Speech and Invocation
abstract
Bug localization represents one of the most expensive, as well as time-consuming, activities during software maintenance and evolution. To alleviate the workload of developers, numerous methods have been proposed to automate this process and narrow down the scope of reviewing buggy files. In this paper, we present a novel buggy source-file localization approach, using the information from both the bug reports and the source files. We leverage the part-of-speech features of bug reports and the invocation relationship among source files. We also integrate an adaptive technique to further optimize the performance of the approach. The adaptive technique discriminates Top 1 and Top N recommendations for a given bug report and consists of two modules. One module is to maximize the accuracy of the first recommended file, and the other one aims at improving the accuracy of the fixed defect file list. We evaluate our approach on six large-scale open source projects, i.e. ASpectJ, Eclipse, SWT, Zxing, Birt and Tomcat. Compared to the previous work, empirical results show that our approach can improve the overall prediction performance in all of these cases. Particularly, in terms of the Top 1 recommendation accuracy, our approach achieves an enhancement from 22.73% to 39.86% for ASpectJ, from 24.36% to 30.76% for Eclipse, from 31.63% to 46.94% for SWT, from 40% to 55% for ZXing, from 7.97% to 21.99% for Birt, and from 33.37% to 38.90% for Tomcat.
Yu Zhou 0010, Yanxiang Tong, Taolue Chen 0001
Int. J. Softw. Eng. Knowl. Eng.2
2016 Combining text mining and data mining for bug report classification
abstract
Bug reports represent an important information source for software construction. Misclassification of these reports inevitably introduces bias. Manual examinations can help reduce the noise, but bring a heavy burden for developers instead. In this paper, we propose a multi-stage approach by combining both text mining and data mining techniques to automate the prediction process. The first stage leverages text mining techniques to analyze the summary parts of bug reports and classifies them into three levels of probability. The extracted features and some other structured features of bug reports are then fed into the machine learner in the second stage. Data grafting techniques are employed to bridge the two stages. Comparative experiments with previous studies on the same data—three large-scale open-source projects—consistently achieve a reasonable enhancement (from 77.4% to 81.7%, 76.1% to 81.6%, and 87.4% to 93.7%, respectively) over their best results in terms of overall performance. Additional comparative empirical experiments on other seven popular open-source systems confirm the findings. Moreover, based on the data obtained, we also empirically studied the impact relation between the underlying classifiers and various other properties of the combined model. A prototypical recommender system has been developed to demonstrate the applicability of our approach. Copyright © 2016 John Wiley & Sons, Ltd.
Yu Zhou 0010, Yanxiang Tong, Ruihang Gu, Harald C. Gall
J. Softw. Evol. Process.2
2015 Towards A Novel Approach for Defect Localization Based on Part-of-Speech and Invocation
abstract
Given a corpus of bug reports, software developers must read various descriptive sentences in order to identify corresponding buggy source files which potentially result in the defects. This process itself represents one of the most expensive, as well as time-consuming, activities during software maintenance and evolution. To alleviate the workload of developers, many methods have been proposed to automate this process and narrow down the scope of reviewing buggy files. In this paper, we present a novel buggy source file localization approach, leveraging both a part-of-speech based weighting strategy and the invocation relationship among source files. We also integrate an adaptive technique to strengthen the optimization of the performance. The adaptive technique consists of two modules. One is to maximize the accuracy of the first recommended file, and the other aims at improving the accuracy of the fixed defect file list. We evaluate our approach on three large-scale open source projects, i.e., ASpectJ, Eclipse, and SWT. Compared with the baseline work, our approach can improve 17.13%, 6.29% and 3.15% on top 1, top 5 and top 10 respectively for ASpectJ, 6.40%, 4.94% and 4.39% on top 1, top 5 and top 10 respectively for Eclipse, and 15.31%, 8.16% and 5.10% on top 1, top 5 and top 10 respectively for SWT.
Yanxiang Tong, Yu Zhou 0010, Lisheng Fang, Taolue Chen 0001
Internetware1
2014 Combining Text Mining and Data Mining for Bug Report Classification
abstract
Misclassification of bug reports inevitably sacrifices the performance of bug prediction models. Manual examinations can help reduce the noise but bring a heavy burden for developers instead. In this paper, we propose a hybrid approach by combining both text mining and data mining techniques of bug report data to automate the prediction process. The first stage leverages text mining techniques to analyze the summary parts of bug reports and classifies them into three levels of probability. The extracted features and some other structured features of bug reports are then fed into the machine learner in the second stage. Data grafting techniques are employed to bridge the two stages. Comparative experiments with previous studies on the same data -- three large-scale open source projects -- consistently achieve a reasonable enhancement (from 77.4% to 81.7%, 73.9% to 80.2% and 87.4% to 93.7%, respectively) over their best results in terms of overall performance. Additional comparative empirical experiments on other two popular open source repositories confirm the findings and demonstrate the benefits of our approach.
Yu Zhou 0010, Yanxiang Tong, Ruihang Gu, Harald C. Gall
ICSME2