VLDB 2026 Research / reviewers in the wild / expert
Jiawei Yin
dblp:213/2906
· DBLP profile ↗
6ranked-venue papers
3as first author
5since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Diffusion Augmentation Sub-center Modeling for Unsupervised Anomalous Sound Detection with Partially Attribute-Unavailable ConditionsabstractCurrent state-of-the-art unsupervised anomalous sound detection (ASD) methods typically rely on manually annotated attribute information as labels, employing auxiliary classification tasks to learn an embedding space for normal sounds, which helps detect anomalies deviating from this space. However, attribute information is often unavailable for certain machine types, making it difficult to learn the complex intra-class data distribution features of the same machine type. Additionally, limited sample diversity in the target domain further hinders learning robust discriminative features. To address these challenges, we propose a diffusion augmentation sub-center modeling (DASM) approach for embedding learning. This method employs iterative training of sub-center modeling, adaptive diffusion augmentation, and discriminative feature learning, utilizing a min-max optimization approach to maximize intra-class diversity and minimize intra-class distance, resulting in more expressive embeddings. Experimental results on the DCASE 2024 Challenge Task 2 dataset demonstrate that the proposed method significantly improves ASD performance. Jiawei Yin |
ICASSP | 1 |
| 2024 | ReIFunc: Identifying Recurring Inline Functions in Binary CodeabstractFunction inlining, although a common phenomenon, can greatly hinder the readability of the binary code obtained through decompilation. Identifying inline functions in the binary code is additionally challenging as there is no clear boundary between an inlined function and its caller function, the instructions of the same function might differ during inline expansion, and existing graph-schema methods for inline function identification cannot handle the vast number of functions involved due to their complexity. To address the challenge, in this paper, we propose an effective inline function identification solution named ReIFunc, which combines subgraph isomorphism and deep learning to identify these recurring inline functions (RIFs). Our evaluation shows that ReIFunc can effectively match functions within a broad candidate set with a high precision rate exceeding 99% while maintaining an acceptable recall, thus getting rid of the constraints imposed by the limited size of the candidate set. Qingli Guo, Dongsong Yu, Jiawei Yin, Xiaorui Gong |
SANER | 4 |
| 2023 | FSmell: Recognizing Inline Function in Binary Code
Wei Lin 0004, Qingli Guo, Jiawei Yin, Xiangyu Zuo, Rongqing Wang, Xiaorui Gong |
ESORICS (2) | 3 |
| 2023 | RSFuzzer: Discovering Deep SMI Handler Vulnerabilities in UEFI Firmware with Hybrid FuzzingabstractSystem Management Mode (SMM) is a secure operation mode for x86 processors supported by Unified Extensible Firmware Interface (UEFI) firmware. SMM is designed to provide a secure execution environment to access highly privileged data or control low-level hardware (such as power management). The programs running in SMM are called SMM drivers and System Management Interrupt (SMI) handlers are the most important components of SMM drivers since they are the only components to receive and handle data from outside the SMM execution environment. Although SMM can serve as an extra layer of protection when the operating system is compromised, vulnerabilities in SMM drivers, especially SMI handlers, can invalidate this protection and cause severe damages to the device. Thus, early detection of SMI handler vulnerabilities is important for UEFI firmware security.To this end, researchers have proposed to use hybrid fuzzing techniques for detecting SMI handler vulnerabilities. Particularly, Intel has developed a hybrid fuzzer called Excite and uses it to secure Intel products. Although existing hybrid fuzzing techniques can detect vulnerabilities in SMI handlers, their effectiveness is limited due to two major pitfalls: 1) They can only feed input through the most common input interface to SMI handlers, lacking the ability to utilize other input interfaces. 2) They have no awareness of variables shared by multiple SMI handlers, lacking the ability to explore code segments related to such variables. By addressing the challenges faced by existing works, we propose RSFuzzer, a hybrid greybox fuzzing technique which can learn input interface and format information and detect deeply hidden vulnerabilities which are triggered by invoking multiple SMI handlers. We implemented RSFuzzer and evaluated it on 16 UEFI firmware images provided by six vendors. The experiment results show that RSFuzzer can cover 617% more basic blocks and detect 828% more vulnerabilities on average than the state-of-the-art hybrid fuzzing technique. Moreover, we found and reported 65 0-day vulnerabilities in the evaluated UEFI firmware images and 14 CVE IDs were assigned. Noticeably, 6 of the 0-day vulnerabilities were found in commercial-off-the-shelf (COTS) products from Intel, which might have been tested by Excite before releasing. Jiawei Yin, Yuekang Li, Boru Lin, Yanyan Zou 0002, Yang Liu 0003, Wei Huo 0005, Jingling Xue |
SP | 1 |
| 2022 | Finding SMM Privilege-Escalation Vulnerabilities in UEFI Firmware with Protocol-Centric Static AnalysisabstractThe Unified Extensible Firmware Interface (UEFI) provides a specification of the software interface between an OS and its underlying platform firmware. The runtime services provided are seemingly secure as they reside in System Management Mode (SMM) at ring -2, assuming a higher privilege than the OS kernel at ring 0. However, their software vulnerabilities are known to be exploitable to launch ring 0 to ring -2 privilege escalation, i.e., SMM privilege escalation attacks.In this paper, we introduce an effective static analysis framework for detecting SMM privilege escalation vulnerabilities in UEFI firmware. We present a systematic study of such vulnerabilities and identify their root causes as being two types of references that can escape from the SMRAM, legacy references and unintentional references. Existing static analyses are ineffective in detecting such vulnerabilities in stripped COTS UEFI firmware images, which are developed based on a customized callback mechanism that organizes callable functions into protocols identified by GUIDs. By leveraging such a callback-based programming paradigm, we introduce SPENDER, the first static detection framework, which is founded on a novel protocol-centric analysis, for uncovering the potential SMM privilege escalation vulnerabilities in UEFI firmware efficiently and precisely. For a total of 1148 UEFI binaries collected from eight vendors, SPENDER has successfully found 36 SMM privilege escalation vulnerabilities (two 1-day and 34 0-day vulnerabilities), which can cause arbitrary code execution and arbitrary address write (and can thus enable, e.g., the attackers to install a bootkit into a flash drive). We have reported these 36 vulnerabilities to the vendors, with the two 1-day vulnerabilities confirmed as known previously but the 34 0-day vulnerabilities confirmed as new. Jiawei Yin, Dandan Sun, Wei Huo 0005, Jingling Xue |
SP | 1 |
| 2020 | Rolling Attack: An Efficient Way to Reduce Armors of Office Automation Devices
Linyu Li 0004, Jie Gou, Jiawei Yin, Xiaorui Gong |
ACISP | 5 |