VLDB 2026 Research / reviewers in the wild / expert
Ke Wang 0061
dblp:181/2613-61
· DBLP profile ↗
5ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0001-5537-2483ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Understanding and Detecting Privacy Leakage Vulnerabilities in Hyperledger Fabric ChaincodesabstractThe application on a blockchain cannot maintain secrecy because its data is replicated across all peers in the network. To remedy this problem, Hyperledger Fabric introduces private data collection (PDC) into its smart contract (i.e. chaincode) to facilitate applications that require privacy. However, recent studies have revealed that PDC is too complex for chaincode developers to fully understand and use correctly, leading to privacy leaks vulnerabilities. In this paper, we present an empirical study on the prevalence of PDC misuse in chaincodes by extracting privacy leakage cases from StackOverflow posts and Hyperledger Fabric repositories on GitHub. Subsequently, we systematically categorize the misuse of PDC into three categories of vulnerabilities resulting in the leakage of private data and provide formal definitions for them. Furthermore, we develop PDChecker, an automated security analysis framework for identifying the privacy and security vulnerabilities in Fabric chaincodes. We evaluated PDChecker on 956 real-world chaincodes applying PDC and found that 67.78% of them contain at least one privacy leakage vulnerability. In addition, PDChecker uncovered 10 zero-day vulnerabilities documented by the China National Vulnerability Database. Yue Li 0037, Jianbo Gao 0003, Jiashuo Zhang 0001, Ke Wang 0061, Jian-bin Hu, Zhi Guan, Zhong Chen 0001 |
ISSRE | 5 |
| 2024 | SolaSim: Clone Detection for Solana Smart Contracts via Program RepresentationabstractThe open-source nature of smart contracts provides the facility for developers to clone contracts and introduces the risk of vulnerability proliferation as well. Despite intensive research on smart contract clone detection in recent years, existing techniques are still unsatisfactory in detecting Solana smart contracts. To fill this gap, in this paper, we designed a clone detection tool SolaSim for Solana smart contracts and conducted an empirical study to understand the code reuse in the Solana ecosystem. Specifically, SolaSim is based on the semantic metadata extractor and the similarity checker. For each contract, the semantic metadata extractor generates an instruction-level weighted Attributed Control Flow Graph (ACFG) and its semantic metadata (i.e., a combination of high-level semantic and structure information) based on Rust Mid-level Intermediate Representation. The similarity checker adopts a combinatorial optimization algorithm to compute the statistical similarity of a pair of contracts. The evaluation results demonstrated the effectiveness of SolaSim in identifying clones with 94.3% accuracy and it can identify up to Type-3 clone level. Notably, we found there are over 50% clone ratios in the Solana smart contracts ecosystem, in which most of them are cloned from famous open-sourced projects. Yue Li 0037, Jianbo Gao 0003, Ke Wang 0061, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001 |
ICPC | 4 |
| 2023 | Hades: Practical Decentralized Identity with Full Accountability and Fine-grained Sybil-resistanceabstractDecentralized identity (DID), the idea of giving users complete control over their identity-related data, is being used to solve the privacy tension in the identity management of decentralized applications (Dapps). While existing approaches do an excellent job of solving the privacy tension, they have not adequately addressed the accountability and Sybil-resistance issues. Moreover, these approaches have a considerable gas overhead, making them impractical for Dapps. Ke Wang 0061, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Zhi Guan, Zhong Chen 0001 |
ACSAC | 1 |
| 2022 | TBFT: Efficient Byzantine Fault Tolerance Using Trusted Execution EnvironmentabstractWith the rapid development of blockchain, Byzantine fault-tolerant protocols have attracted revived interest recently. To overcome the theoretical bounds of Byzantine fault tolerance, many protocols attempt to use Trusted Execution Environment (TEE) to prevent equivocation and improve fault tolerance from less than 1/3 to minority. However, due to the broken quorum intersection assumption caused by the reduction of replica number, most improvements introduce higher communication complexity or more protocol phases, which affects the performance and scalability of existing TEE-based protocols and prevents them to be applied to large-scale blockchain systems. In this paper, we propose TBFT, an efficient Byzantine fault-tolerant protocol in the partial synchrony setting, which has O(n) message complexity and only two protocol phases in normal-case. The key insight behind TBFT is introducing novel TEE-assisted primitives to limit malicious behaviors of replicas including not only equivocation but also message log forgery and message history forgery, therefore both the communication complexity and protocol phases can be reduced. We have implemented TBFT and evaluated it through systematic analysis and experiments, and the results show that TBFT has better performance and scalability compared to other protocols. Jiashuo Zhang 0001, Jianbo Gao 0003, Ke Wang 0061, Zhenhao Wu, Yue Li 0037, Zhi Guan, Zhong Chen 0001 |
ICC | 3 |
| 2015 | PassApp: My App is My Password!abstractExisting graphical passwords require users to proactively memorize their secrets and meanwhile these schemes are vulnerable to shoulder surfing attacks. We propose a novel graphical password scheme, PassApp, which utilizes users' everyday memory about installed apps on mobile devices as shared secrets. As the registration stage is no longer needed, PassApp exempts users from additional memory burden and greatly enhances user experience. Additionally, PassApp owns a large password set and only a small part of passwords may be exposed during a login. Therefore, PassApp has a natural advance on effectively resisting guessing attacks and shoulder surfing attacks. Our user studies demonstrate that PassApp performs well with a reasonable login time (7.27s) and a high success rate (95.48%). Our security analysis shows PassApp can effectively withstand one-time shoulder surfing attacks and on average 30 times of shoulder surfing are necessary to expose all passwords. Huiping Sun, Ke Wang 0061, Nan Qin, Zhong Chen 0001 |
MobileHCI | 2 |