VLDB 2026 Research / reviewers in the wild / expert
Jialai Wang
dblp:223/6095
· DBLP profile ↗
7ranked-venue papers
6as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Your Scale Factors are My Weapon: Targeted Bit-Flip Attacks on Vision Transformers via Scale Factor ManipulationabstractVision Transformers (ViTs) have experienced significant progress and are quantized for deployment in resource-constrained applications. Quantized models are vulnerable to targeted bit-flip attacks (BFAs). A targeted BFA prepares a trigger and a corresponding Trojan/backdoor, inserting the latter (with RowHammer bit flipping) into a victim model, to mislead its classification on samples containing the trigger. Existing targeted BFAs on quantized ViTs are limited in that: (1) they require numerous bit-flips, and (2) the separation between flipped bits is below 4 KB, making attacks infeasible with RowHammer in real-world scenarios. We propose a new and practical targeted attack Flip-S against quantized ViTs. The core insight is that in quantized models, a scale factor change ripples through a batch of model weights. Consequently, flipping bits in scale factors, rather than solely in model weights, enables more cost-effective attacks. We design a Scale-Factor-Search (SFS) algorithm to identify critical bits in scale factors for flipping, and adopt a mutual exclusion strategy to guarantee a 4 KB separation between flips. We evaluate Flip-S on CIFAR-10 and ImageNet datasets across five ViT architectures and two quantization levels. Results show that Flip-S achieves attack success rate (ASR) exceeding 90.0% on all models with 50 bits flipped, outperforming baselines with ASR typically below 80.0%. Furthermore, compared to the SOTA, Flip-S reduces the number of required bit-flips by 8×-20× while reaching equal or higher ASR. Our source code is publicly available1. Jialai Wang, Yuxiao Wu, Chao Zhang 0008, Zongpeng Li, Zhenkai Liang |
CVPR | 1 |
| 2025 | Improving LLM-based Log Parsing by Learning from Errors in Reasoning TracesabstractRecent advances in reasoning-capable large lan-guage models (LLMs) have led to their application in a wide range of tasks, including log parsing. These LLMs generate intermediate reasoning traces during inference, offering a unique opportunity to analyze and improve their performance. In this work, we investigate how reasoning traces can be leveraged to enhance LLM-based log parsers. We propose TraceDoctor, a framework that analyzes reasoning traces associated with parsing errors to understand the causes of failure. We categorize these error causes into high-level error types and design targeted log variant generation strategies guided by these high-level error types. The generated variants are then used to fine-tune the LLMs. We instantiate five state-of-the-art (SOTA) reasoning-capable LLMs as log parsers and identify 29 distinct high-level error types. Our approach improves their average parsing accuracy by up to 17.3% and 16.3% on parsing accuracy (PA) and group accuracy (GA), respectively. Jialai Wang, Juncheng Lu, Junjie Wang 0001, Chao Zhang 0008, Zhenkai Liang, Ee-Chien Chang |
ASE | 1 |
| 2025 | SmartTrans: Advanced Similarity Analysis for Detecting Vulnerabilities in Ethereum Smart ContractsabstractIn the ever-evolving landscape of Ethereum smart contracts, the specter of vulnerabilities intensified by code reuse presents a significant challenge to the security of the blockchain. Recent studies employ deep learning for similarity analysis to identify these vulnerabilities, yet their effectiveness wanes as the volume of analyzed code increases. This article introducesSmartTrans, an advanced similarity analysis model designed to efficiently and accurately retrieve similar vulnerabilities within Ethereum bytecodes. Leveraging a novel jump-aware Transformer-based model, our approach captures the semantics and control flow of bytecodes. It not only refines the representation of functions by integrating program analysis with natural language processing techniques but also innovates a contract-level similarity detection scheme tailored for the expansive scale of contracts. Our experiments show thatSmartTransoutperforms state-of-the-art techniques at both function and contract levels, proving its capability to detect n-day vulnerabilities across Ethereum bytecodes accurately. Vulnerabilities recalling experiments show thatSmartTransachieves 95.43% and 99.37% accuracy at two levels. Furthermore, we stand out as the first work to retrieve N-day vulnerabilities across the Ethereum bytecode corpus, unveiling 4,988 vulnerable contracts. Our methodology secures an accuracy of 88.60%, which is 1.30 times higher than the best baseline. Hao Wang 0226, Yuchen Zhou 0007, Taiyu Wong, Jialai Wang, Chao Zhang 0008 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Improving ML-based Binary Function Similarity Detection by Assessing and Deprioritizing Control Flow Graph Features
Jialai Wang, Chao Zhang 0008, Yuxiao Wu, Hao Wang 0003, Wende Tan, Qi Li 0002, Zongpeng Li |
USENIX Security Symposium | 1 |
| 2023 | MPass: Bypassing Learning-based Static Malware DetectorsabstractMachine learning (ML) based static malware detectors are widely deployed, but vulnerable to adversarial attacks. Unlike images or texts, tiny modifications to malware samples would significantly compromise their functionality. Consequently, existing attacks against images or texts will be significantly restricted when being deployed on malware detectors. In this work, we propose a hard-label black-box attack MPass against ML-based detectors. MPass employs a problem-space explainability method to locate critical positions of malware, applies adversarial modifications to such positions, and utilizes a runtime recovery technique to preserve the functionality. Experiments show MPass outperforms existing solutions and bypasses both state-of-the-art offline models and commercial ML-based antivirus products. Jialai Wang, Wenjie Qu 0001, Han Qiu 0001, Qi Li 0002, Zongpeng Li, Chao Zhang 0008 |
DAC | 1 |
| 2023 | Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks
Jialai Wang, Han Qiu 0001, Tianwei Zhang 0004, Qi Li 0002, Zongpeng Li, Tao Wei 0002, Chao Zhang 0008 |
USENIX Security Symposium | 1 |
| 2022 | BET: black-box efficient testing for convolutional neural networksabstractIt is important to test convolutional neural networks (CNNs) to identify defects (e.g. error-inducing inputs) before deploying them in security-sensitive scenarios. Although existing white-box testing methods can effectively test CNN models with high neuron coverage, they are not applicable to privacy-sensitive scenarios where full knowledge of target CNN models is lacking. In this work, we propose a novel Black-box Efficient Testing (BET) method for CNN models. The core insight of BET is that CNNs are generally prone to be affected by continuous perturbations. Thus, by generating such continuous perturbations in a black-box manner, we design a tunable objective function to guide our testing process for thoroughly exploring defects in different decision boundaries of the target CNN models. We further design an efficiency-centric policy to find more error-inducing inputs within a fixed query budget. We conduct extensive evaluations with three well-known datasets and five popular CNN structures. The results show that BET significantly outperforms existing white-box and black-box testing methods considering the effective error-inducing inputs found in a fixed query/inference budget. We further show that the error-inducing inputs found by BET can be used to fine-tune the target model, improving its accuracy by up to 3%. Jialai Wang, Han Qiu 0001, Hengkai Ye, Qi Li 0002, Zongpeng Li, Chao Zhang 0008 |
ISSTA | 1 |