VLDB 2026 Research / reviewers in the wild / expert
Yu Ouyang
dblp:179/3114
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | P3DL: A Privacy Preserving Personalized Distributed Learning Framework for EEG-Based Cognitive State IdentificationabstractElectroencephalography (EEG)-based brain cognitive state identification for the elderly allows timely detection and early intervention of cognitive deterioration. Notably, EEG signals carry a great deal of vital personal information. However, a majority of the existing cognitive evaluations focus on improving the accuracy of EEG decoding and enhancing the performance of identification models, while neglecting the privacy protection of EEG data. To address the risky challenge, we propose a privacy-preserving personalized distributed learning framework (P3DL) for cognitive state identification. Specifically, it consists of the clients and a central server. Each client contains a cognitive model and a score model for identifying cognitive states and quantifying cognitive levels, respectively. The central server can aggregate local models' parameters from distributed clients, then, update and downstream the global model's parameters for iterative optimization. A federated dynamic update strategy (FedDBS) is designed to jointly update all global and local models with a supervisory metric. In order to further improve the identification performance and judge the misdiagnosis level, a novel loss function, extreme error Loss (E2Loss), is proposed. Compared with the baseline, experimental results on our self-collected clinical dataset and a public dataset show an average increase in F2Score of 5.58% and 3.31%, and in accuracy of 1.78% and 2.46%, respectively. Furthermore, the scalability of the framework has been proved in the emotion recognition task. Our proposed framework P3DL can not only improve the identification performance, but also protect the privacy of EEG, opening a new window for secure healthcare. Yu Ouyang, Xiaoya Zhu, Hong Zeng 0002 |
IEEE J. Biomed. Health Informatics | 1 |
| 2024 | Automated Data Binding Vulnerability Detection for Java Web Frameworks via Nested Property GraphabstractData binding has been widely adopted by popular web frameworks due to its convenience of automatically binding web request parameters to the web program's properties. However, its improper implementation in web frameworks exposes sensitive properties, leading to data binding vulnerabilities, which can be exploited to launch severe attacks, such as the Spring4Shell remote code execution. Despite their criticalness, these issues are overlooked, and there is no systematic study addressing them. This paper presents the first automatic analysis of the data binding vulnerabilities in Java web frameworks. We develop an automatic Data bInding Vulnerabilities dEtectoR, named DIVER, to analyze data binding vulnerabilities. DIVER employs three new techniques: the Nested Property Graph-based Extraction to extract nested properties, the Bind-Site Instrumentation-based Identification to identify bindable nested properties, and the Property-aware Fuzzing to trigger and detect data binding vulnerabilities. We evaluated DIVER on two widely used Java web frameworks, Spring and Grails, and discovered 81 data binding vulnerabilities. These vulnerabilities can be exploited to launch remote code execution, arbitrary file read, and denial of service attacks. We have responsibly reported these vulnerabilities to the corresponding teams and helped to fix them. Three new CVEs with critical and high severity ratings have been assigned to us, including the infamous Spring4Shell. Xiaoyong Yan, Biao He 0002, Wenbo Shen, Yu Ouyang, Kaihang Zhou, Xingjian Zhang 0005, Yukai Cao |
ISSTA | 4 |
| 2023 | Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationabstractJava (de)serialization is prone to causing security-critical vulnerabilities that attackers can invoke existing methods (gadgets) on the application's classpath to construct a gadget chain to perform malicious behaviors. Several techniques have been proposed to statically identify suspicious gadget chains and dynamically generate injection objects for fuzzing. However, due to their incomplete support for dynamic program features (e.g., Java runtime polymorphism) and ineffective injection object generation for fuzzing, the existing techniques are still far from satisfactory. In this paper, we first performed an empirical study to investigate the characteristics of Java deserialization vulnerabilities based on our manually collected 86 publicly known gadget chains. The empirical results show that 1) Java deserialization gadgets are usually exploited by abusing runtime polymorphism, which enables attackers to reuse serializable overridden methods; and 2) attackers usually invoke exploitable overridden methods (gadgets) via dynamic binding to generate injection objects for gadget chain construction. Based on our empirical findings, we propose a novel gadget chain mining approach, GCMiner, which captures both explicit and implicit method calls to identify more gadget chains, and adopts an overriding-guided object generation approach to generate valid injection objects for fuzzing. The evaluation results show that GCMiner significantly outperforms the state-of-the-art techniques, and discovers 56 unique gadget chains that cannot be identified by the baseline approaches. Sicong Cao, Xiaobing Sun 0001, Xiaoxue Wu 0001, Lili Bo, Bin Li 0006, Rongxin Wu, Wei Liu 0010, Biao He 0002, Yu Ouyang |
ICSE | 9 |
| 2023 | ODDFuzz: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox FuzzingabstractJava deserialization vulnerability is a severe threat in practice. Researchers have proposed static analysis solutions to locate candidate vulnerabilities and fuzzing solutions to generate proof-of-concept (PoC) serialized objects to trigger them. However, existing solutions have limited effectiveness and efficiency.In this paper, we propose a novel hybrid solution ODDFuzz to efficiently discover Java deserialization vulnerabilities. First, ODDFuzz performs lightweight static taint analysis to identify candidate gadget chains that may cause deserialization vulnerabilities. In this step, ODDFuzz tries to locate all candidates and avoid false negatives. Then, ODDFuzz performs directed greybox fuzzing (DGF) to explore those candidates and generate PoC testcases to mitigate false positives. Specifically, ODDFuzz applies a structure-aware seed generation method to guarantee the validity of the testcases, and adopts a novel hybrid feedback and a step-forward strategy to guide the directed fuzzing.We implemented a prototype of ODDFuzz and evaluated it on the popular Java deserialization repository ysoserial. Results show that, ODDFuzz could discover 16 out of 34 known gadget chains, while two state-of-the-art baselines only identify three of them. In addition, we evaluated ODDFuzz on real-world applications including Oracle WebLogic Server, Apache Dubbo, Sonatype Nexus, and protostuff, and found six previously unreported exploitable gadget chains with five CVEs assigned. Sicong Cao, Biao He 0002, Xiaobing Sun 0001, Yu Ouyang, Chao Zhang 0008, Xiaoxue Wu 0001, Ting Su 0001, Lili Bo, Bin Li 0006, Chuanlei Ma, Tao Wei 0002 |
SP | 4 |