VLDB 2026 Research / reviewers in the wild / expert
Xiajing Wang
dblp:204/2346
· DBLP profile ↗
5ranked-venue papers
4as first author
2since 2021 · last 2024
0000-0002-9897-0579ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | SYNTONY: Potential-aware fuzzing with particle swarm optimization
Xiajing Wang, Rui Ma 0004, Wei Huo 0005, Jinyuan He, Chaonan Zhang, Donghai Tian |
J. Syst. Softw. | 1 |
| 2021 | CMFuzz: context-aware adaptive mutation for fuzzers
Xiajing Wang, Changzhen Hu, Rui Ma 0004, Donghai Tian, Jinyuan He |
Empir. Softw. Eng. | 1 |
| 2020 | LAFuzz: Neural Network for Efficient FuzzingabstractFuzzing is a well-known technique for efficiently finding software vulnerabilities. Unfortunately, due to syntax check, even the state-of-the-art fuzzers are not very efficient at discovering hard-to-trigger bugs in applications that expect highly structured inputs. Grammar-based fuzzers, while effective, often require expert knowledge and incur significant computational overhead. In this paper, we present LAFuzz, an automated fuzzer that generates high-quality seed inputs, which utilizes a variety of deep neural network model with different setup to efficiently fuzz programs that expect structured or unstructured inputs. We achieve this by combining mutation-based fuzzing and generation-based fuzzing offline. Our evaluation on 8 popular real-world applications demonstrated that LAFuzz-LSTM and LAFuzz-Attention significantly outperform AFL, a state-of-the-art fuzzer, on most cases both at discovering more crashes and achieving higher code coverage. In total, LAFuzz-LSTM and LAFuzz-Attention can effectively improve the code coverage over AFL by 7.55% and 7.67%; and both fuzzers can consistently discover 30.19% as well as 82.39% more unique crashes. Furthermore, extensive evaluation also showed that LAFuzz provides a great compatibility and expansibility. Xiajing Wang, Changzhen Hu, Rui Ma 0004, Binbin Li 0001 |
ICTAI | 1 |
| 2018 | OFFDTAN: A New Approach of Offline Dynamic Taint Analysis for BinariesabstractDynamic taint analysis is a powerful technique for tracking the flow of sensitive information. Different approaches have been proposed to accelerate this process in an online or offline manner. Unfortunately, most of these approaches still have performance bottlenecks and thus reduce analytical efficiency. To address this limitation, we present OFFDTAN, a new approach of offline dynamic taint analysis for binaries. OFFDTAN can be described in terms of four stages: dynamic information acquisition, vulnerability modeling, offline analysis, and backtrace analysis. It first records program runtime information and models the stack buffer overflow vulnerabilities and controlled jump vulnerabilities. Then it performs offline analysis and backtrace analysis to locate vulnerabilities. We implement OFFDTAN on the basis of QEMU virtual machine and apply it to off-the-shelf applications. In order to illustrate how our approach works, we first employ a case study. Furthermore, six applications have been verified so as to evaluate our approach. Experimental results demonstrate that our approach is correct and effective. Compared with other offline analysis tools, OFFDTAN has much lower application runtime overhead. Xiajing Wang, Rui Ma 0004, Bowen Dou, Zefeng Jian, Hongzhou Chen |
Secur. Commun. Networks | 1 |
| 2017 | Defenses Against Wormhole Attacks in Wireless Sensor Networks
Rui Ma 0004, Changzhen Hu, Xiajing Wang |
NSS | 5 |