VLDB 2026 Research / reviewers in the wild / expert
Kailong Zhu
dblp:205/7900
· DBLP profile ↗
4ranked-venue papers
0as first author
4since 2021 · last 2026
0000-0001-5241-0157ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An image encryption algorithm based on memristive chaotic neuron in medical internet of things environments
Kailong Zhu, Xinlin Song |
Eng. Appl. Artif. Intell. | 2 |
| 2025 | A Multi-Agent Fuzzing Framework for Deep Learning LibraryabstractThe security of deep learning (DL) libraries is crucial due to their central role in developing AI applications. Fuzzing has become a key technique for discovering bugs in DL libraries, but generating high-quality seeds still poses a significant challenge. Although large language models (LLMs) offer promising opportunities, current methods that utilize single-agent frameworks for seed generation often produce invalid seeds. This issue arises from the complexities of DL API structures and the inherent randomness of LLMs, which ultimately reduce fuzzing efficiency. To overcome these challenges, we propose a collaborative multi-agent framework that utilizes specialized LLM-driven agents for iterative seed refinement. This framework consists of three components: (1) a coding agent that incorporates historical bug knowledge to produce the initial bug-prone seeds,(2) a repair agent performs static analysis on the initial seeds and repairs the invalid seeds, and (3) a mutation agent leverages four mutation operators to explore the test space thoroughly.Our framework improves seed validity and functional diversity through ongoing collaboration among agents and established feedback loops. Experimental evaluations show that our approach achieves a 20% increase in seed validity compared to state-of-the-art methods and uncovers 12 previously unknown bugs in popular DL libraries. Rongtao Liao, Shiwen Ou, Xuehu Yan, Kailong Zhu |
SMC | 4 |
| 2025 | DerandomPre: An LLM-based Stability Enhancement Method for Network Protocol FuzzingabstractAs essential components for communication, network protocol programs are highly security-critical, making it crucial to identify their vulnerabilities. Fuzzing is one of the most popular software vulnerability discovery techniques, being highly efficient and having low false-positive rates. However, current network protocol fuzzing is hindered by the randomness in programs. The current solutions primarily rely on the manual modification of programs, which is inefficient and prone to omissions. In this paper, we propose DerandomPre, a novel stability enhancement method for stateful network protocol programs, which leverages large language model’s code- and text-understanding capabilities to analyze derandomization knowledge and optimize the stability enhancing of programs for fuzzing. DerandomPre automatically eliminates randomness in programs to ensure higher stability and fuzzing effectiveness. We implement a prototype of DerandomPre. The evaluation demonstrates that DerandomPre significantly enhances fuzzing performance by eliminating program randomness. Specifically, compared to unmodified programs, DerandomPremodified versions achieved an average stability improvement of 64.88%; relative to ProFuzzBench-modified programs, DerandomPre yielded a further 13.08% stability gain. Moreover, DerandomPre demonstrates good scalability, thus is applicable to various network protocol programs. Kailong Zhu, Zixiong Li, Yuliang Lu, Yingchun Chen |
TrustCom | 2 |
| 2025 | Yama: Precise Opcode-Based Data Flow Analysis for Detecting PHP Applications VulnerabilitiesabstractWeb applications encompass various aspects of daily life, including online shopping, e-learning, and internet banking. Once there is a vulnerability, it can cause severe societal and economic damage. Due to its ease of use, PHP has become the preferred server-side programming language for web applications, making PHP applications a primary target for attackers. Data flow analysis is widely used for vulnerability detection before deploying web applications because of its efficiency. However, the high complexity of the PHP language makes it difficult to achieve precise data flow analysis, resulting in higher rates of false positives and false negatives in vulnerability detection. In this paper, we present Yama, a context-sensitive and path-sensitive interprocedural data flow analysis method for PHP, designed to detect taint-style vulnerabilities in PHP applications. We have found that the precise semantics and clear control flow of PHP opcodes enable data flow analysis to be more precise and efficient. Leveraging this observation, we established parsing rules for PHP opcodes and implemented a precise understanding of PHP program semantics in Yama. This enables Yama to precisely address the high complexity of the PHP language, including type inference, dynamic features, and built-in functions. We evaluated Yama from three dimensions: basic data flow analysis capabilities, complex semantic analysis capabilities, and the ability to discover vulnerabilities in real-world applications, demonstrating Yama’s advancement in vulnerability detection. Specifically, Yama possesses context-sensitive and path-sensitive interprocedural analysis capabilities, achieving a 99.1% true positive rate in complex semantic analysis experiments related to type inference, dynamic features, and built-in functions. It discovered and reported 38 zero-day vulnerabilities across 24 projects on GitHub with over 1,000 stars each, assigning 34 new CVE IDs. We have released the source code of the prototype implementation and the parsing rules for PHP opcodes to facilitate future research. Jiazhen Zhao, Kailong Zhu, Yuliang Lu |
IEEE Trans. Inf. Forensics Secur. | 2 |