VLDB 2026 Research / reviewers in the wild / expert
Xiaotao Feng
dblp:171/4028
· DBLP profile ↗
9ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0001-5861-2515ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | WingMuzz: Blackbox Testing of IoT Protocols via Two-dimensional Fuzzing ScheduleabstractThe Internet of Things (IoT) is widely used in various sectors but is often prone to vulnerabilities. With the proprietary nature of IoT devices, their source code and firmware are frequently unavailable for open review, rendering blackbox fuzzing a viable approach. However, the effectiveness of blackbox fuzzing is often challenging due to the lack of feedback, especially the information of code coverage. In this paper, we propose WingMuzz to provide blackbox fuzzing of IoT protocols with effective feedback. The key is to guide blackbox fuzzing by utilizing runtime information from greybox fuzzing on counterpart open-source code. This is based on our observation that IoT protocols and open-source code conform to the same specifications, indicating that inputs exploring different code regions on open-source code may also discover new coverage on IoT protocols. WingMuzz uses a two-dimensional fuzzing schedule to optimize the process of fuzzing IoT protocols. The first dimension involves scheduling open-source implementations, referred to as wingmates, so that similar ones are preferred to guide blackbox fuzzing. The second dimension utilizes coverage-guided greybox fuzzing to test open-source code. This solution can bridge the performance gap between blackbox fuzzing and greybox fuzzing on IoT protocols. We evaluate the performance of WingMuzz across eight IoT protocols and compare it with six widely-used blackbox fuzzers. On average, WingMuzz can discover 42.1%, 26.92%, 25.01%, 34.95%, 23.56% and 11.63% more edges than Boofuzz, Spike, Peach, Snipuzz, Pulsar and ChatAFL, respectively. Additionally, WingMuzz exposes 10 bugs in IoT protocols while other fuzzers expose no more than 3 bugs. It also exposes 2 new protocol vulnerabilities in IoT devices while other fuzzers cannot identify any. Xiaogang Zhu 0001, Enze Dai, Xiaotao Feng, Shaohua Wang 0002, Xin Xia 0001, Sheng Wen, Kwok-Yan Lam, Yang Xiang 0001 |
ASE | 3 |
| 2022 | TraceDroid: Detecting Android Malware by Trace of Privacy Leakage
Yueqing Wu, Hao Fu 0003, Minghui Xu 0001, Yifei Zou, Xiaotao Feng, Pengfei Hu 0001 |
WASA (1) | 7 |
| 2022 | CSI-Fuzz: Full-Speed Edge Tracing Using Coverage Sensitive InstrumentationabstractCoverage-guided fuzzing is one of the most effective solutions for vulnerability discovery. Among coverage-guided fuzzing, full-speed fuzzing, such as UnTracer, traces test cases only when they discover new coverage. Due to the high expense of tracing test cases, full-speed fuzzers improve the efficiency of fuzzing by tracing only coverage-increasing test cases. However, the existing full-speed fuzzer (i.e., UnTracer) is based on basic block coverage, suffering a severe problem called edge collision. Moreover, such fuzzers neglect the path frequency, which affects fuzzing effectiveness. In this article, we propose CSI-Fuzz, a fuzzer utilizing coverage sensitive instrumentation to address the problems of existing full-speed fuzzing. CSI-Fuzz directly instruments at edges, which solves the problem of edge collision. Meanwhile, CSI-Fuzz sets path identifiers to count the frequency of covered paths. Our CSI-Fuzz can be recognized as an add-on and seamlessly applied to existing coverage-guided fuzzers. We accordingly implement CSI-Fuzz based on two widely-adopted fuzzers, AFL and AFLFast, to evaluate its performance. The experiments demonstrate that CSI-Fuzz discovers more edges than AFL, AFLFast, and UnTracer. Additionally, CSI-Fuzz exposes more bugs than the other fuzzers. Xiaogang Zhu 0001, Xiaotao Feng, Xiaozhu Meng, Sheng Wen, Seyit Ahmet Çamtepe, Yang Xiang 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceabstractThe proliferation of Internet of Things (IoT) devices has made people's lives more convenient, but it has also raised many security concerns. Due to the difficulty of obtaining and emulating IoT firmware, in the absence of internal execution information, black-box fuzzing of IoT devices has become a viable option. However, existing black-box fuzzers cannot form effective mutation optimization mechanisms to guide their testing processes, mainly due to the lack of feedback. In addition, because of the prevalent use of various and non-standard communication message formats in IoT devices, it is difficult or even impossible to apply existing grammar-based fuzzing strategies. Therefore, an efficient fuzzing approach with syntax inference is required in the IoT fuzzing domain. Xiaotao Feng, Ruoxi Sun 0001, Xiaogang Zhu 0001, Minhui Xue 0001, Sheng Wen, Dongxi Liu, Surya Nepal, Yang Xiang 0001 |
CCS | 1 |
| 2021 | Blockchain Meets COVID-19: A Framework for Contact Information Sharing and Risk Notification SystemabstractCOVID-19 is a severe global epidemic in human history. Even though there are particular medications and vaccines to curb the epidemic, tracing and isolating the infection source is the best option to slow the virus spread and reduce infection and death rates. There are three disadvantages to the existing contact tracing system: 1. User data is stored in a centralized database that could be stolen and tampered with, 2. User’s confidential personal identity may be revealed to a third party or organization, 3. Existing contact tracing systems [1][2] only focus on information sharing from one dimension, such as location-based tracing, which significantly limits the effectiveness of such systems.We propose a global COVID-19 information sharing and risk notification system that utilizes the Blockchain, Smart Contract, and Bluetooth. To protect user privacy, we design a novel Blockchain-based platform that can share consistent and non-tampered contact tracing information from multiple dimensions, such as location-based for indirect contact and Bluetooth-based for direct contact. Hierarchical smart contract architecture is also designed to achieve global agreements from users about how to process and utilize user data, thereby enhancing the data usage transparency. Furthermore, we propose a mechanism to protect user identity privacy from multiple aspects. More importantly, our system can notify the users about the exposure risk via smart contracts. We implement a prototype system to conduct extensive measurements to demonstrate the feasibility and effectiveness of our system. Jinyue Song, Tianbo Gu, Zheng Fang 0009, Xiaotao Feng, Yunjie Ge, Hao Fu 0003, Pengfei Hu 0001, Prasant Mohapatra |
MASS | 4 |
| 2020 | A decentralized and secure blockchain platform for open fair data tradingabstractSummary As the value of data has received considerable attention, data trading shows broad market prospects. The existing data trading methods, including private trades and centralized trades, have high risks regarding transaction security and data protection. To solve this problem, we propose a decentralized trading solution for open fair data trading by deploying the smart contract on the blockchain network. The data for sale are encrypted and stored on the distributed storage platform but not directly on the blockchain network. Because the trading content is the decryption key of the data, the proposed new method can alleviate the storage pressure of the blockchain by reducing the transaction cost. We conduct a security analysis which shows that our scheme achieves secure, practical, open, and fair trading. We implement our trading contract with solidity and test it on the Ethereum's test network, and extensive experiments demonstrate desirable feasibility of our proposal. Ya-Nan Li 0007, Xiaotao Feng, Jan Xie, Hanwen Feng 0001, Zhenyu Guan 0002, Qianhong Wu |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | A Feature-Oriented Corpus for Understanding, Evaluating and Improving Fuzz TestingabstractFuzzing is a promising technique for detecting security vulnerabilities. Newly developed fuzzers are typically evaluated in terms of the number of bugs found on vulnerable programs/binaries. However, existing corpora usually do not capture the features that prevent fuzzers from finding bugs, leading to ambiguous conclusions on the pros and cons of the fuzzers evaluated. In this paper, we propose to address the above problem by generating corpora based on search-hampering features. As a proof-of-concept, we designed FEData, a prototype corpus that currently focuses on three search-hampering features to generate vulnerable programs for fuzz testing. Unlike existing corpora that can only answer "how", FEData can also further answer "why" by exposing (or understanding) the reasons for the identified weaknesses in a fuzzer. The "why" information serves as the key to the improvement of fuzzers. Based on the "why" information, our FEData programs enabled us to identify the weakness of AFLFast, called cycle explosion, behind. We further developed an improved version of AFLFast, called AFLFast+, which has overcome the cycle explosion problem. AFLFast+ retains the efficiency of AFLFast in path search while maintaining or even surpassing the bug-finding capability of AFL for the corpus evaluated. Xiaogang Zhu 0001, Xiaotao Feng, Tengyun Jiao, Sheng Wen, Yang Xiang 0001, Seyit Ahmet Çamtepe, Jingling Xue |
AsiaCCS | 2 |
| 2017 | A signaling game model for moving target defenseabstractIncentive-driven advanced attacks have become a major concern to cyber-security. Traditional defense techniques that adopt a passive and static approach by assuming a fixed attack type are insufficient in the face of highly adaptive and stealthy attacks. In particular, a passive defense approach often creates information asymmetry where the attacker knows more about the defender. To this end, moving target defense (MTD) has emerged as a promising way to reverse this information asymmetry. The main idea of MTD is to (continuously) change certain aspects of the system under control to increase the attacker's uncertainty, which in turn increases attack cost/complexity and reduces the chance of a successful exploit in a given amount of time. In this paper, we go one step beyond and show that MTD can be further improved when combined with information disclosure. In particular, we consider that the defender adopts a MTD strategy to protect a critical resource across a network of nodes, and propose a Bayesian Stackelberg game model with the defender as the leader and the attacker as the follower. After fully characterizing the defender's optimal migration strategies, we show that the defender can design a signaling scheme to exploit the uncertainty created by MTD to further affect the attacker's behavior for its own advantage. We obtain conditions under which signaling is useful, and show that strategic information disclosure can be a promising way to further reverse the information asymmetry and achieve more efficient active defense. Xiaotao Feng, Zizhan Zheng, Derya Cansever, Ananthram Swami, Prasant Mohapatra |
INFOCOM | 1 |
| 2015 | ColorBars: increasing data rate of LED-to-camera communication using color shift keyingabstractLED-to-camera communication allows LEDs deployed for illumination purposes to modulate and transmit data which can be received by camera sensors available in mobile devices like smartphones, wearable smart-glasses etc. Such communication has a unique property that a user can visually identify a transmitter (i.e. LED) and specifically receive information from the transmitter. It can support a variety of novel applications such as augmented reality through mobile devices, navigation using smart signs, fine-grained location specific advertisement etc. However, the achievable data rate in current LED-to-camera communication techniques remains very low (≈ 12 bytes per second) to support any practical application. In this paper, we present ColorBars, an LED-to-camera communication system that utilizes Color Shift Keying (CSK) to modulate data using different colors transmitted by the LED. It exploits the increasing popularity of Tri-LEDs (RGB) that can emit a wide range of colors. We show that commodity cameras can efficiently and accurately demodulate the color symbols. ColorBars ensures flicker-free and reliable communication even in the presence of inter-frame loss and diversity of rolling shutter cameras. We implement ColorBars on embedded platform and evaluate it with Android and iOS smartphones as receivers. Our evaluation shows that ColorBars can achieve a data rate of 5.2 Kbps on Nexus 5 and 2.5 Kbps on iPhone 5S, which is significantly higher than previous approaches. It is also shown that lower CSK modulations (e.g. 4 and 8 CSK) provide extremely low symbol error rates (< 10--3), making them a desirable choice for reliable LED-to-camera communication. Pengfei Hu 0001, Parth H. Pathak, Xiaotao Feng, Hao Fu 0003, Prasant Mohapatra |
CoNEXT | 3 |