Kaiwen Ning

dblp:225/5752 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
11since 2021 · last 2026
0009-0009-6009-8285ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 1 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 UpgradeShield: Detecting logic-state in-consistencies in smart contract upgrades
Wei Li 0121, Yuxin Su 0001, Yuhong Nan, Kaiwen Ning, Jiajing Wu, Zibin Zheng
Autom. Softw. Eng.4
2026 Defining and Detecting the Defects of Large Language Model-Based Autonomous Agents
abstract
Artificial intelligence (AI) agents are systems capable of perceiving their environment, autonomously planning and executing tasks. Recent advancements in Large Language Models (LLMs) have introduced a transformative paradigm for AI agents, enabling them to interact with external resources and tools through prompt techniques. This advancement has significantly extended the capabilities of LLMs, positioning LLM-based AI Agents as an important research area. In such agents, the workflow integrates developer-written code, which manages framework construction and logic control, with LLM-generated natural language that enhances dynamic decision-making and interaction. However, inconsistencies between LLM outputs and developer logic can lead to defects, such as tool invocation failures. These issues introduce specific risks, leading to various defects in LLM-based AI Agents, including service interruptions and incorrect output. Despite the importance of these issues, there is a lack of systematic work that focuses on analyzing LLM-based AI Agents to uncover defects in their code. To address this gap, we present the first study focused on identifying and detecting defects in LLM Agents. We collected and analyzed 14,754 relevant developer reports from StackOverflow and GitHub. We further filtered 2,604 valid posts to define and classify eight types of agent code defects. Then, we designed a static analysis tool, named Agentable, to detect these defects. Agentable leverages Code Property Graphs (CPGs) and LLMs to analyze Agent workflows by efficiently identifying specific code patterns and analyzing natural language descriptions. To evaluate Agentable, we constructed two datasets: AgentSet, which consists of 84 real world Agent projects, and AgentTest, which contains 78 Agent projects specifically designed to include various types of defects. Our evaluation shows that Agentable achieves a precision of 88.79% on the real-world agent dataset and a recall of 91.03% on the manually labeled defect dataset. Furthermore, our analysis identifies 889 defects in real-world agent projects, highlighting the prevalence of these issues in practice.
Kaiwen Ning, Jiachi Chen, Wei Li 0121, Zexu Wang, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng
IEEE Trans. Software Eng.1
2025 Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp Analysis
abstract
Despite the increasing popularity of Decentralized Applications (DApps), they are suffering from various vulnerabilities that can be exploited by adversaries for profits. Among such vulnerabilities, Read-Only Reentrancy (called ROR in this paper), is an emerging type of vulnerability that arises from the complex interactions between DApps. In the recent three years, attack incidents of ROR have already caused around 30M USD losses to the DApp ecosystem. Existing techniques for vulnerability detection in smart contracts can hardly detect Read-Only Reentrancy attacks, due to the lack of tracking and analyzing the complex interactions between multiple DApps. In this paper, we propose SmartReco, a new framework for detecting Read-Only Reentrancy vulnerability in DApps through a novel combination of static and dynamic analysis (i.e., fuzzing) over smart contracts. The key design behind SmartReco is threefold: (1) SmartReco identifies the boundary between different DApps from the heavy-coupled cross-contract interactions. (2) SmartReco performs fine-grained static analysis to locate points of interest (i.e., entry functions) that may lead to ROR. (3) SmartReco utilizes the on-chain transaction data and performs multi-function fuzzing (i.e., the entry function and victim function) across different DApps to verify the existence of ROR. Our evaluation of a manual-labeled dataset with 45 RORs shows that SmartReco achieves a precision of 88.64 % and a recall of 86.67 %. In addition, SmartReco successfully detects 43 new RORs from 123 popular DApps. The total assets affected by such RORs reach around 520,000 USD.
Zibin Zheng, Yuhong Nan, Mingxi Ye, Kaiwen Ning, Yu Zhang 0036, Weizhe Zhang
ICSE5
2025 Finding Insecure State Dependency in DApps via Multi-Source Tracing and Semantic Enrichment
abstract
Decentralized Applications (DApps) serve as the gateway to utilizing blockchain technology. As their prevalence continues to grow, DApps are becoming increasingly interconnected. For instance, a DApp does not need to manage the prices of various tokens internally, as it can retrieve this information from other DApps that provide more up-to-date data. However, such deep reliance also introduces more attack surfaces, posing greater risks to both DApps and their users. In this paper, we refer to the security threat arising from the interdependence of DApps as Insecure State Dependency (ISD). Public reports indicate that ISD has led to losses exceeding 340 million USD.Existing ISDs are mostly found by extensive manual auditing and lucky incidents, as automated discovery of such issues is extremely difficult. More specifically, it is by no means trivial to (1) achieve precise data tracking in the intertwined and invisible interactions of DApps, (2) obtain fine-grained semantic information in low semantic bytecode. In this paper, we propose a novel framework, called InsFinder, for detecting ISD in DApps. Specifically, InsFinder consists of three unique modules to overcome the aforementioned challenges. (1) InsFinder employs dynamic cross-DApp taint analysis to achieve accurate multi-source data tracking in heavily coupled DApp interactions. (2) InsFinder uses source mapping to map bytecode identifiers into meaningful source code, such as variable names or statements, enabling a deeper understanding of bytecode. (3) InsFinder implements fine-grained access control and static analysis for ISD entry point detection. Evaluation on a manually annotated dataset with 93 real-world ISDs shows that InsFinder successfully detects 72 of them, achieving a precision of 84.7% and a recall of 77.4%. Furthermore, InsFinder successfully uncovers 165 previously unreported ISDs across 122 DApp projects. These ISDs collectively impact over 2 million USD.
Yuhong Nan, Wei Li 0121, Kaiwen Ning, Zewei Lin, Zitong Yao, Yuming Feng 0002, Weizhe Zhang, Zibin Zheng
ASE4
2025 Towards an understanding of large language models in software engineering tasks
Zibin Zheng, Kaiwen Ning, Qingyuan Zhong, Jiachi Chen, Wenqing Chen, Lianghong Guo, Yanlin Wang 0001
Empir. Softw. Eng.2
2025 Edge Computing Underwater Optical Wireless Sensor Networks
abstract
Underwater Optical Wireless Sensor Networks (UOWSNs) play important roles in resource exploration and maritime rescue. However, they face significant challenges in real-time data transmission due to the limited propagation range of optical signals (typically 10-100 m), frequent link disconnections caused by node mobility, and the extended distances to onshore servers. Traditional cloud computing solutions, designed for stable terrestrial networks with stationary edge servers and continuous connectivity, experience high latency (3-15 s) in UOWSNs, rendering them unsuitable for real-time applications in underwater environments. To address this issue, we propose a cloud-edge-end architecture tailored for UOWSNs, which can not only combat unique underwater environmental interference on link connection and topological changes but also guarantee robust and real-time communication. We develop a dynamic link-stability-based task offloading path selection (DLS-TOPS) algorithm for maximizing network resource profits. Afterward, we propose an online primal-dual task offloading (OPD-TO) algorithm for minimizing task completion time. Simulation results indicate that the proposed method significantly improves the real-time performance and resource profits of the network, reducing the total task completion time by more than 50% compared to baseline algorithms. We implemented a UOWSN with a cloud-edge-end architecture using commercial off-the-shelf and verified the applicability and effectiveness of the proposed scheme in emergency detection through testbed experiments.
Yang Chi, Chi Lin 0001, Jing Deng 0001, Kaiwen Ning, Xin Fan 0001, Guowei Wu 0001
IEEE Trans. Mob. Comput.4
2024 RMCBench: Benchmarking Large Language Models' Resistance to Malicious Code
abstract
Warning: Please note that this article contains potential harmful or offensive content. This content is only for the evaluating and analysis of LLMs and does not imply any intention to promote criminal activities.
Jiachi Chen, Qingyuan Zhong, Yanlin Wang 0001, Kaiwen Ning, Yongkun Liu, Zenan Xu, Zhe Zhao 0006, Ting Chen 0002, Zibin Zheng
ASE4
2024 Enhancing multi-cloud service deployment with SkyCap: A loss-aware coordinator in sky computing
Kaiwen Ning, Guowei Wu 0001
Ad Hoc Networks2
2023 Optimizing The Access Control System for IOTA Tangle: A Game-Theoretic Perspective
abstract
With the development of Internet of Things (IoT) applications, there is an explosion in demands for data sharing between IoT nodes, which needs the IoT network to provide a data sharing platform to enhance data privacy and security. IOTA Tangle has been considered as a promising Distributed Ledger Technology to establish such a platform because of its affinity to IoT nodes. Additionally, Tangle proposes an access control system to prevent congestion of the platform by allocating a number of tokens to each node, and limiting data sharing rate of each node based on its hold tokens. However, this poses an inconspicuous but fatal problem that high-rate-demand nodes with few tokens cannot acquire an ideal rate. In this paper, we optimize the access control system for the Tangle-based platform by setting a token transferring mechanism, where a chaebol node can sell tokens to provide IoT nodes with ideal data sharing rate. Since the chaebol node needs more profits and IoT nodes need ideal data sharing rate, we formulate the token pricing and purchasing problem as a two-stage Stackelberg game. We analyze the equilibrium of the game in a uniform pricing scheme and design an access control algorithm TTM based on the equilibrium. Finally, we verify performance of the algorithm by experiments. The results show that the proposed algorithm outperforms the state-of-art in terms of providing high-rate-demand nodes with the ideal rate.
Kaiwen Ning
CSCWD3
2022 AttachSFC: Optimizing SFC Initialization Process through Request Properties
abstract
Network Function Virtualization (NFV) technology enables the decoupling of Network Functions (NFs) from hard-ware by initializing them into virtual machines or containers, which can provide more flexible and customized services to users. However, in current NFV networks, the NFV Orchestrator (NFVO) needs to initialize an Service Function Chain (SFC) containing one or more Virtual Network Functions (VNFs) for each request. This is not appropriate in most cases. On the one hand, the initialization of VNFs also needs to be delayed, which can affect the quality of service to some extent. On the other hand, most of the requests in the network are low-resource and short-occupancy, and such SFCs will be born and died frequently in the network, which will affect the stability of the network. Unfortunately, optimising VNF initialization is a necessary but easily neglected issue. In this paper, we design AD- NFVO for Internet Service Providers (ISPs) to simplify the initialization process of SFCs and increase the overall reward of the network. Firstly, we classify user requests in terms of time and size, respectively, and propose AttachSFC, an adaptive SFC attachment strategy to simplify the initialization process of SFCs. Secondly, we apply AttachSFC to NFVO, and since AttachSFC and SFCs deployment is interdependent, we use the Advantage Actor Critic (A2C) strategy to optimize them to increase the overall reward of ISPs. Finally, we experimentally demonstrate the effectiveness and potential of the AD-NFVO.
Kaiwen Ning, Hao Wang 0023, Xiaowei Shu
MSN1
2022 A Distributed Simulator of Mobile Ad Hoc Networks
Xiaowei Shu, Kaiwen Ning
WASA (3)4