Ke Zhang 0039

dblp:20/4152-39 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2026
0000-0002-1611-6804ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ICSFuzz: Collision Detector Bug Discovery in Autonomous Driving Simulators
abstract
With the increasing adoption of autonomous vehicles, ensuring the reliability of autonomous driving systems (ADSs) deployed on autonomous vehicles has become a significant concern. Driving simulators have emerged as crucial platforms for testing ADSs, offering realistic, dynamic, and configurable environments. However, existing simulation-based ADS testers have largely overlooked the reliability of the simulators, potentially leading to overlooked violation scenarios and subsequent safety security risks during real-world deployment. In our investigations, we identified that collision detectors in simulators could fail to detect and report collisions in certain collision scenarios, referred to asignored collision scenarios. This paper aims to systematically discover ignored collision scenarios to improve the reliability of autonomous driving (AD) simulators. To this end, we present ICSFuzz, a black-box fuzzing approach to discover ignored collision scenarios efficiently. Drawing upon the fact that the ignored collision scenarios are a sub-type of collision scenarios, our approach starts with the determined collision scenarios. Following the guidance provided by empirically studied factors contributing to collisions, we selectively mutate arbitrary collision scenarios in a step-wise manner toward the ignored collision scenarios and effectively discover them. We compare ICSFuzz with multiple state-of-the-art simulation-based ADS testing methods, by replacing their oracle with our ignored-collision-aware oracle. The evaluation demonstrates that ICSFuzz outperforms ADS testers by finding 7~40x more ignored collision scenarios with a 10~105x speedup. Within the discovered ignored collision scenarios, there are two more types of ignored collision scenarios that ADS testers did not find. All the discovered ignored collisions have been confirmed by developers with one CVE ID assigned.
Heqing Huang 0002, Yifan Zhang 0036, Ke Zhang 0039, Jin Huang 0002, Wei-Bin Lee, Jianping Wang 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks
abstract
Reconstruction attackers can exploit facial features to recover the original user’s face, resulting in user privacy leakage. One new strategy to enhance the “Edge-Cloud” face recognition system’s privacy is to add adversarial perturbations to facial features, preventing the attackers from high-quality user image recovery. However, the existing works following this strategy suffer from unacceptable damage to face recognition accuracy. Achieving robust privacy enhancement and face recognition accuracy simultaneously is still challenging. To tackle this challenge, we propose an adversarial perturbation-based plug-and-play privacy-enhancing method (Patronus) with robustness against face image reconstruction attacks and near-lossless face recognition performance. The key insight is derived from our observation that the feature distance between two face images of the same person is significantly lower than the threshold set in the face recognition system. This leaves room for adding adversarial perturbations to the facial features without compromising face recognition accuracy. Our strategy limits the amount of adversarial perturbations in a fine-grained manner to ensure that they are within the range of not damaging face recognition accuracy. Our evaluation shows the superior performance ofPatronusin robustness against reconstruction attacks and near-lossless face recognition accuracy compared to state-of-the-art (SOTA) methods.Patronuscan be easily integrated into deployed face recognition systems as a plug-in privacy-enhancing module with low overhead.
Hui Liu 0018, Hongqin Du, Jiageng Chen, Ke Zhang 0039, Kehuan Zhang, Peng Liu 0005
IEEE Trans. Inf. Forensics Secur.5
2024 LiftFuzz: Validating Binary Lifters through Context-aware Fuzzing with GPT
abstract
Analyzing binary code is vital for software engineering and security research, particularly when the source code is unavailable. However, understanding, modifying, and retargeting binary code can be complex tasks. To counter these difficulties, binary lifters have been introduced. These tools translate binary code into Intermediate Representations (IRs), providing several advantages, such as enabling modifications to executables without source code and facilitating code retargetability. So far, accurately developing binary lifters for modern ISAs is universally acknowledged as challenging and error-prone. Existing validation methods mainly concentrate on isolated instructions, overlooking interactions among instructions. In this paper, we introduce LiftFuzz, a novel framework that leverages instruction context-aware fuzzing to validate binary lifters. LiftFuzz harnesses an assembly language model to learn interactions among instructions and generates test cases with the knowledge. LiftFuzz greatly outperforms the baseline, requiring only 1/1000 of the test cases used by the baseline to identify 26 inconsistencies, including a previously uncovered category. LiftFuzz significantly contributes to enhancing the performance of binary lifters, which are frequently employed in binary security applications.
Zirui Song, Ke Zhang 0039, Jiongyi Chen, Kehuan Zhang
CCS4
2024 TypeFSL: Type Prediction from Binaries via Inter-procedural Data-flow Analysis and Few-shot Learning
abstract
Type recovery in stripped binaries is a critical and challenging task in reverse engineering, as it is the basis for many security applications (e.g., vulnerability detection). Traditional analysis methods are limited by software complexity and emerging types in real-world projects. To address these limitations, machine learning methods have been explored. However, the existing supervised learning approaches struggle with analyzing complicated and uncommon types due to the limited availability of samples. Additionally, none of the existing works can capture fine-grained and inter-procedural features in the binaries. In this paper, we present TypeFSL, a framework that addresses the challenge of imbalanced type distributions by incorporating few-shot learning and captures inter-procedural semantics through program slicing. Moreover, based on a dataset with 3,003,117 functions, TypeFSL achieves an average of 77.9% and 84.6% accuracy across all architecture and optimizations in 20-way 5-shot and 10-shot classification tasks. Our prototype outperforms existing techniques in prediction accuracy and obfuscation resistance. Finally, the case studies demonstrate how TypeFSL predicts uncommon and complicated types in practical analysis.
Zirui Song, Shuaike Dong, Ke Zhang 0039, Kehuan Zhang
ASE4
2023 HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
Kong Huang, Ke Zhang 0039, Jiacen Xu 0001, Jiongyi Chen, Di Tang 0001, Kehuan Zhang
USENIX Security Symposium3
2021 Understanding the Brains and Brawn of Illicit Streaming App
Kong Huang, Ke Zhang 0039, Jiongyi Chen, Menghan Sun, Di Tang 0001, Kehuan Zhang
ICDF2C2