Ningyu He

dblp:228/1460 · DBLP profile ↗
← Back
23ranked-venue papers
6as first author
20since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 9 since 2021Software engineering, systems software and programming languages · 9 · 3 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2026 When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
abstract
The Ethereum ecosystem, which secures over $381 billion in assets, fundamentally relies on client APIs as the sole interface between users and the blockchain. However, these critical APIs suffer from widespread implementation inconsistencies, which can lead to financial discrepancies, degraded user experiences, and threats to network reliability. Despite this criticality, existing testing approaches remain manual and incomplete: they require extensive domain expertise, struggle to keep pace with Ethereum’s rapid evolution, and fail to distinguish genuine bugs from acceptable implementation variations. We present APIDiffer , the first specification-guided differential testing framework designed to automatically detect API inconsistencies across Ethereum’s diverse client ecosystem. APIDiffer transforms API specifications into comprehensive test suites through two key innovations: (1) specification-guided test input generation that creates both syntactically valid and invalid requests enriched with real-time blockchain data, and (2) specification-aware false positive filtering that leverages large language models to distinguish genuine bugs from acceptable variations. Our evaluation across all 11 major Ethereum clients reveals the pervasiveness of API bugs in production systems. APIDiffer uncovered 72 bugs, with 90.28% already confirmed or fixed by developers, including one critical error in the official specifications themselves. Beyond these raw numbers, APIDiffer achieves up to 89.67% higher code coverage than existing tools and reduces false positive rates by 37.38%. The Ethereum community’s response validates our impact: developers have integrated our test cases, expressed interest in adopting our methodology, and escalated one bug to the official Ethereum Project Management meeting. By making APIDiffer open-source, we enable continuous validation of Ethereum client API implementations, thereby strengthening the foundational integrity of the entire Ethereum ecosystem.
Ningyu He, Jinwen Xi, Mingzhe Xing, Liangxin Liu, Jiushenzi Luo, Xiaopeng Fu, Chiachih Wu, Haoyu Wang 0001, Ying Gao 0006, Yinliang Yue
Proc. ACM Program. Lang.2
2026 DrWASI: LLM-assisted Differential Testing for WebAssembly System Interface Implementations
abstract
WebAssembly (Wasm) is an emerging binary format that serves as a compilation target for over 40 programming languages. Wasm runtimes provide execution environments that enhance portability by abstracting away operating systems and hardware details. A key component in these runtimes is the WebAssembly System Interface (WASI), which manages interactions with operating systems, like file operations. Considering the critical role of Wasm runtimes, the community has aimed to detect their implementation bugs. However, no work has focused on WASI-specific bugs that can affect the original functionalities of running Wasm binaries and cause unexpected results. To fill the void, we present DrWASI , the first general-purpose differential testing framework for WASI implementations. Our approach uses a large language model to generate seeds and applies variant and environment mutation strategies to expand and enrich the test case corpus. We then perform differential testing across major Wasm runtimes. By leveraging dynamic and static information collected during and after the execution, DrWASI can identify bugs. Our evaluation shows that DrWASI uncovered 33 unique bugs, with all confirmed and 7 fixed by developers. This research represents a pioneering step in exploring a promising yet under-explored area of the Wasm ecosystem, providing valuable insights for stakeholders.
Ningyu He, Jianting Gao, Shangtong Cao, Kaibo Liu, Haoyu Wang 0001, Yun Ma 0002, Gang Huang 0001, Xuanzhe Liu
ACM Trans. Softw. Eng. Methodol.2
2025 Cybersquatting in Web3: The Case of NFT
abstract
Cybersquatting refers to the practice where attackers register a domain name similar to a legitimate one to confuse users for illegal gains. With the growth of the Non-Fungible Token (NFT) ecosystem, there are indications that cybersquatting tactics have evolved from targeting domain names to NFTs. This paper presents the first in-depth measurement study of NFT cybersquatting. By analyzing over 220K NFT collections with over 150M NFT tokens, we have identified 8,019 cybersquatting NFT collections targeting 654 popular NFT projects. Through systematic analysis, we discover and characterize seven distinct squatting tactics employed by scammers. We further conduct a comprehensive measurement study of these cybersquatting NFT collections, examining their metadata, associated digital asset content, and social media status. Our analysis reveals that these NFT cybersquatting activities have resulted in a significant financial impact, with over 670K victims affected by these scams, leading to a total financial exploitation of $59.26 million. Our findings demonstrate the urgency to identify and prevent NFT squatting abuses.
Ningyu He, Bosi Zhang, Haoyu Wang 0001
EuroS&P2
2025 The Gold Digger in the Dark Forest: Industrial-Scale MEV Analysis in Ethereum
abstract
Maximal Extractable Value (MEV) activities pose critical operational challenges for blockchain enterprises, requiring automated detection systems to maintain platform integrity and regulatory compliance. Current industrial practices rely on heuristic rule-based methods with substantial accuracy limitations and inability to adapt to evolving MEV strategies. This paper presents an automated software engineering solution for large-scale MEV detection, introducing a novel graph-based profitability identification algorithm that replaces inflexible heuristic rules with adaptive mechanisms. Our automated system achieves 0.6% false positive rates for arbitrage detection and 2.4% false negative rates, significant improvements over existing methods with much higher error rates. We validate our approach on 21 million Ethereum blocks containing 2.5 billion transactions, covering critical infrastructure transitions including The Merge and Proposer-Builder Separation. Our automated pipeline identifies 12.1 million MEV activities, including 1.2 million previously undetectable advanced variants that pose emerging risks to platform operators. Key findings provide actionable insights for blockchain enterprises: private transaction architectures protect 71.4% of low-yield MEV opportunities rather than harming participants, contradicting previous assumptions. However, we identify concerning builder-searcher collusion involving 2,000+ transactions worth 350 ETH, highlighting compliance risks. Additionally, intensifying centralization trends show a single oligopoly controlling 43.1% of MEV activities in 2024, presenting systemic risks. Our automated detection framework provides blockchain enterprises with production-ready tools for MEV monitoring, risk assessment, and compliance management while offering critical insights for infrastructure design decisions in rapidly evolving DeFi environments.
Ningyu He, Tianyang Chi, Haoyu Wang 0001
ASE1
2025 Following Devils' Footprint: Towards Real-time Detection of Price Manipulation Attacks
Bosi Zhang, Ningyu He, Haoyu Wang 0001
USENIX Security Symposium2
2025 SoK: On the security of non-fungible tokens
abstract
Non-Fungible Tokens (NFTs) drive the prosperity of the Web3 ecosystem. By May 2024, the total market value of NFT projects reached approximately $69 billion. Accompanying the success of NFTs are various security issues, i.e., attacks and scams are prevalent in the ecosystem. While NFTs have attracted significant attention from both industry and academia, there is a lack of understanding of the kinds of NFT security issues. The discovery, in-depth analysis, and systematic categorization of these security issues are of significant importance for the prosperous development of the NFT ecosystem. To fill this gap, we perform a systematic literature review related to NFT security and identify 176 incidents from 248 security reports and 35 academic papers until May 1st, 2024. Through manual analysis of the compiled security incidents, we classify them into 12 major categories. Then, we explore potential solutions and mitigation strategies. Drawing from these analyses, we establish the first NFT security reference frame. In addition, we extract the characteristics of NFT security issues, i.e., the prevalence, severity, and intractability. We highlight the gap between industry and academia for NFT security and provide further research directions for the community. This paper, as the first Systematization of Knowledge (SoK) of NFT security, systematically explores security issues within the NFT ecosystem, shedding light on their root causes, real-world attacks, and potential ways to address them. Our findings will contribute to future research on NFT security.
Ningyu He, Haoyu Wang 0001
Blockchain Res. Appl.3
2025 A survey on EOSIO systems security: vulnerability, attack, and mitigation
Ningyu He, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Xiangqun Chen
Frontiers Comput. Sci.1
2024 WASMixer: Binary Obfuscation for WebAssembly
Shangtong Cao, Ningyu He, Yao Guo 0001, Haoyu Wang 0001
ESORICS (3)2
2024 WASMaker: Differential Testing of WebAssembly Runtimes via Semantic-Aware Binary Generation
abstract
A fundamental component of the Wasm ecosystem is the Wasm runtime, as it directly impacts whether Wasm applications can be executed as expected. Bugs in Wasm runtimes are frequently reported, so the research community has made a few attempts to design automated testing frameworks to detect bugs in Wasm runtimes. However, existing testing frameworks are limited by the quality of test cases, i.e., they face challenges in generating Wasm binaries that are both semantically rich and syntactically correct. As a result, complicated bugs cannot be triggered effectively. In this work, we present WASMaker, a novel differential testing framework that can generate complicated Wasm test cases by disassembling and assembling real-world Wasm binaries, which can trigger hidden inconsistencies among Wasm runtimes. To further pinpoint the root causes of unexpected behaviors, we design a runtime-agnostic root cause location method to locate bugs accurately. Extensive evaluation suggests that WASMaker outperforms state-of-the-art techniques in terms of both efficiency and effectiveness. We have uncovered 33 unique bugs in popular Wasm runtimes, among which 25 have been confirmed.
Shangtong Cao, Ningyu He, Xinyu She, Mu Zhang 0001, Haoyu Wang 0001
ISSTA2
2024 SeeWasm: An Efficient and Fully-Functional Symbolic Execution Engine for WebAssembly Binaries
abstract
WebAssembly (Wasm), as a compact, fast, and isolation-guaranteed binary format, can be compiled from more than 40 high-level programming languages. However, vulnerabilities in Wasm binaries could lead to sensitive data leakage and even threaten their hosting environments. To identify them, symbolic execution is widely adopted due to its soundness and the ability to automatically generate exploitations. However, existing symbolic executors for Wasm binaries are typically platform-specific, which means that they cannot support all Wasm features. They may also require significant manual interventions to complete the analysis and suffer from efficiency issues as well. In this paper, we propose an efficient and fully-functional symbolic execution engine, named SeeWasm. Compared with existing tools, we demonstrate that SeeWasm supports full-featured Wasm binaries without further manual intervention, while accelerating the analysis by 2 to 6 times. SeeWasm has been adopted by existing works to identify more than 30 0-day vulnerabilities or security issues in well-known C, Go, and SGX applications after compiling them to Wasm binaries.
Ningyu He, Zhehao Zhao, Hanqin Guan, Shuo Peng, Ding Li 0001, Haoyu Wang 0001, Xiangqun Chen, Yao Guo 0001
ISSTA1
2024 VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" Vulnerabilities
Levi Taiji Li, Ningyu He, Haoyu Wang 0001, Mu Zhang 0001
NDSS2
2024 Abusing the Ethereum Smart Contract Verification Services for Fun and Profit
Pengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang 0001, Xiapu Luo
NDSS2
2024 Chareption: Change-Aware Adaption Empowers Large Language Model for Effective Remote Sensing Image Change Captioning
abstract
Remote Sensing Image Change Captioning (RSICC) faces significant challenges in effectively identifying and articulating changes between bi-temporal images. Traditional approaches often utilize individual text decoders, which may not capture the subtleties of visual changes nor fully exploit advanced language modeling capabilities. To overcome these limitations, we propose Cha nge-Awa re Ada ption , namely Chareption , a novel framework that effectively leverages pre-trained large language models (LLMs) to enhance both the accuracy and detail of change captions. Central to Chareption is a change-aware module designed to selectively identify and utilize tokens that significantly represent changes, thus avoiding the common issue of redundancy that plagues methods relying solely on class tokens or indiscriminate use of all patch tokens. Additionally, Chareption designs a lightweight change adapter module, seamlessly integrated into both the vision backbone and the LLM, requiring minimal learnable parameters while optimally adjusting representations for the RSICC task. Our experiments on the LEVIR-CC dataset demonstrate that Chareption significantly outperforms existing methods in caption accuracy and contextual relevance, while also reducing training overhead. This establishes Chareption as a pioneering solution that sets a new direction in RSICC by harnessing the rich representational power of LLMs for improved multimodal understanding.
Changhe Wang, Ningyu He, Binglu Wang
PRCV (13)2
2024 All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
Tianle Sun, Ningyu He, Jiang Xiao 0001, Yinliang Yue, Xiapu Luo, Haoyu Wang 0001
USENIX Security Symposium2
2024 WalletRadar: towards automating the detection of vulnerabilities in browser-based cryptocurrency wallets
Pengcheng Xia 0001, Zhaowen Lin, Pengbo Duan, Ningyu He, Kailong Wang 0001, Tianming Liu 0002, Yinliang Yue, Guoai Xu, Haoyu Wang 0001
Autom. Softw. Eng.6
2023 Put Your Memory in Order: Efficient Domain-based Memory Isolation for WASM Applications
abstract
Memory corruption vulnerabilities can have more serious consequences in WebAssembly than in native applications. Therefore, we present \tool, the first WebAssembly runtime with memory isolation. Our insight is to use MPK hardware for efficient memory protection in WebAssembly. However, MPK and WebAssembly have different memory models: MPK protects virtual memory pages, while WebAssembly uses linear memory that has no pages. Mapping MPK APIs to WebAssembly causes memory bloating and low running efficiency. To solve this, we propose \acfdilm, which protects linear memory at function-level granularity. We implemented \acdilm into the official WebAssembly runtime to build \tool. Our evaluation shows that \tool can prevent memory corruption in real projects with a 1.77% average overhead and negligible memory cost.
Hanwen Lei, Ziqi Zhang 0017, Peng Jiang 0007, Zhineng Zhong, Ningyu He, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
CCS6
2023 SymGX: Detecting Cross-boundary Pointer Vulnerabilities of SGX Applications via Static Symbolic Execution
abstract
Intel Security Guard Extensions (SGX) have shown effectiveness in critical data protection. Recent symbolic execution-based techniques reveal that SGX applications are susceptible to memory corruption vulnerabilities. While existing approaches focus on conventional memory corruption in ECalls of SGX applications, they overlook an important type of SGX dedicated vulnerability: cross-boundary pointer vulnerabilities. This vulnerability is critical for SGX applications since they heavily utilize pointers to exchange data between secure enclaves and untrusted environments. Unfortunately, none of the existing symbolic execution approaches can effectively detect cross-boundary pointer vulnerabilities due to the lack of an SGX-specific analysis model that properly handles three unique features of SGX applications: Multi-entry Arbitrary-order Execution, Stateful Execution, and Context-aware Pointers. To address such problems, we propose a new analysis model named Global State Transition Graph with Context Aware Pointers (GSTG-CAP) that simulates properties-preserving execution behaviors for SGX applications and drives symbolic execution for vulnerability detection. Based on GSTG-CAP, we build a novel symbolic execution-based vulnerability detector named SYMGX to detect cross-boundary pointer vulnerabilities. According to our evaluation, SYMGX can find 30 0-DAY vulnerabilities in 14 open-source projects, three of which have been confirmed by developers. SYMGX also outperforms two state-of-the-art tools, COIN and TeeRex, in terms of effectiveness, efficiency, and accuracy.
Yuanpeng Wang, Ziqi Zhang 0017, Ningyu He, Zhineng Zhong, Shengjian Guo, Qinkun Bao, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
CCS3
2023 Eunomia: Enabling User-Specified Fine-Grained Search in Symbolically Executing WebAssembly Binaries
abstract
Although existing techniques have proposed automated approaches to alleviate the path explosion problem of symbolic execution, users still need to optimize symbolic execution by applying various searching strategies carefully. As existing approaches mainly support only coarse-grained global searching strategies, they cannot efficiently traverse through complex code structures. In this paper, we propose Eunomia, a symbolic execution technique that supports fine-grained search with local domain knowledge. Eunomia uses Aes, a DSL that lets users specify local searching strategies for different parts of the program. Eunomia also isolates the context of variables for different local searching strategies, avoiding conflicts. We implement Eunomia for WebAssembly, which can analyze applications written in various languages. Eunomia is the first symbolic execution engine that supports the full features of WebAssembly. We evaluate Eunomia with a microbenchmark suite and six real-world applications. Our evaluation shows that Eunomia improves bug detection by up to three orders of magnitude. We also conduct a user study that shows the benefits of using Aes. Moreover, Eunomia verifies six known bugs and detects two new zero-day bugs in Collections-C.
Ningyu He, Zhehao Zhao, Yubin Hu 0003, Shengjian Guo, Haoyu Wang 0001, Guangtai Liang, Ding Li 0001, Xiangqun Chen, Yao Guo 0001
ISSTA1
2023 BREWasm: A General Static Binary Rewriting Framework for WebAssembly
Shangtong Cao, Ningyu He, Yao Guo 0001, Haoyu Wang 0001
SAS2
2021 EOSAFE: Security Analysis of EOSIO Smart Contracts
Ningyu He, Ruiyi Zhang 0001, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Ting Yu 0001, Xuxian Jiang
USENIX Security Symposium1
2020 Spatial Attentional Bilinear 3D Convolutional Network for Video-Based Autism Spectrum Disorder Detection
abstract
Video-based Autism Spectrum Disorder (ASD) detection is a challenge to most video classification networks due to the high degree of similarity between categories. Bilinear pooling is a second-order method, which is widely used in fine-grained visual recognition. However, the average summation in bilinear pooling limits its ability to perceive spatial information, which is detrimental to fine-grained visual recognition. In this paper, we propose spatial attentional bilinear pooling to enhance its spatial information extraction without significantly increasing the parameters. Further, we propose a fine-grained action recognition network named SA-B3D with LSTM model for video-based ASD detection. The proposed model can focus on more discriminative regions dynamically and effectively. Compared with state-of-the-art models, the proposed model achieves significant improvement on video-based ASD dataset.
Kangbo Sun, Lianqiang Li, Ningyu He
ICASSP4
2020 DEPOSafe: Demystifying the Fake Deposit Vulnerability in Ethereum Smart Contracts
abstract
Cryptocurrency has seen an explosive growth in recent years, thanks to the evolvement of blockchain technology and its economic ecosystem. Besides Bitcoin, thousands of cryptocur-rencies have been distributed on blockchains, while hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. At the same time, it also attracts the attentions of attackers. Fake deposit, as one of the most representative attacks (vulnerabilities) related to exchanges and tokens, has been frequently observed in the blockchain ecosystem, causing large financial losses. However, besides a few security reports, our community lacks the understanding of this vulnerability, for example its scale and the impacts. In this paper, we take the first step to demystify the fake deposit vulnerability. Based on the essential patterns we have summarized, we implement DEPOSafe, an automated tool to detect and verify (exploit) the fake deposit vulnerability in ERC-20 smart contracts. DEPOSafe incorporates several key techniques including symbolic execution based static analysis and behavior modeling based dynamic verification. By applying DEPOSafe to 176,000 ERC-20 smart contracts, we have identified over 7,000 vulnerable contracts that may suffer from two types of attacks. Our findings demonstrate the urgency to identify and prevent the fake deposit vulnerability.
Ru Ji, Ningyu He, Lei Wu 0012, Haoyu Wang 0001, Guangdong Bai, Yao Guo 0001
ICECCS2
2018 An optic-fiber fence intrusion recognition system using the optimized curve fitting model based on the SVM method
abstract
The Perimeter Intrusion Detection System (PIDS) has been widely used in many fields since the development of optic-fiber interferometers and intrusion signal recognition models. However, common signal recognition models, such as Support Vector Machines (SVM) and Back Propagation Neural Networks (BPNN), do not perform well in classifying fiber intrusion signals due to the diversity of intrusion signals and the sensitivity of the fiber. In this paper, an optic-fiber based perimeter intrusion detection and recognition system that uses Sagnac interferometers and the optimized curve fitting model is proposed. Experiments on real perimeter intrusions are performed. Comparisons are carried out among our model and the SVM, BPNN models, which prove that our model is more accurate and robust.
Ningyu He, Lianqiang Li
IJCNN1