Yuhao Hu

dblp:235/2673 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Fuzzing JavaScript JIT Compilers With Optimization Path Feedback
Jiming Wang, Chenggang Wu 0002, Yan Kang 0002, Yuhao Hu, Jikai Ren, Yuanming Lai, Mengyao Xie, Chao Zhang 0008, Tao Li 0022, Zhe Wang 0017
IEEE Trans. Dependable Secur. Comput.4
2025 SyzParam: Incorporating Runtime Parameters into Kernel Driver Fuzzing
abstract
Under the monolithic architecture of the Linux kernel, all its components operate within the same address space. Notably, device drivers constitute over half of the kernel codebase yet are particularly prone to bugs. Therefore, exploring vulnerabilities in drivers is critical for ensuring kernel security. Extensive research has been done to fuzz kernel drivers through system calls and hardware interrupts. Through a comprehensive study of the Linux Kernel Device Model, we identified that the execution of device drivers is also influenced by runtime parameters, including device attributes and kernel module parameters. Our analysis reveals that large portions of the uncovered code are masked by these parameters, which are exposed to the userspace through a specialized virtual file system known as sysfs. Furthermore, adjacent devices interconnected within the same device tree also impact drivers' behavior.
Yan Kang 0002, Chenggang Wu 0002, Kangjie Lu, Jiming Wang, Xingwei Li, Yuhao Hu, Jikai Ren, Yuanming Lai, Mengyao Xie, Zhe Wang 0017
CCS7
2025 BCFuzz: Bytecode-Driven Fuzzing for JavaScript Engines
abstract
The interpreter and the Just-In-Time (JIT) compiler are two core components of modern JavaScript engines, both of which take bytecodes as input. Most bugs in these components are closely related to specific bytecodes. Therefore, effective fuzzing should pay close attention to how bytecode is generated and exercised. However, previous work fails to consider this aspect and instead focuses primarily on the syntactic and semantic validity of test cases. This causes two major issues: 1) certain bytecodes are never exercised during fuzzing; 2) some bytecodes are exercised infrequently. In this paper, we propose BCFuzz, a bytecode-driven fuzzing approach designed to enhance the diversity of generated bytecode and increase testing opportunities for low-frequency bytecodes. Specifically, we introduce a parser-oriented probing technique to identify the necessary conditions for generating specific bytecodes and use this information to enhance the input generation process. To better test low-frequency bytecodes, we propose bytecode-aware seed preservation, scheduling, and mutation strategies. We evaluate BCFuzz on four mainstream JavaScript engines. In 72 hours of testing, BCFuzz discovers 1.73× and 1.67× more bugs than DIE and Fuzzilli, respectively. In total, BCFuzz uncovered 20 previously unknown bugs. Of these, 17 have already been fixed and one has been assigned a CVE. All the discovered bugs are related to bytecodes.
Jiming Wang, Chenggang Wu 0002, Jikai Ren, Yuhao Hu, Yan Kang 0002, Yuanming Lai, Mengyao Xie, Zhe Wang 0017
ASE4
2025 Federated learning with adaptive local aggregation for privacy-aware recommender systems in Internet of Vehicles
Yong Cheng 0002, Yuhao Hu, Wei Liu 0198, Muhammad Bilal 0003
Inf. Sci.2
2025 End-Edge Collaborative Inference of Convolutional Fuzzy Neural Networks for Big Data-Driven Internet of Things
abstract
Deep neural networks (DNN) has been widely applied in big data-driven Internet of Things (IoT) for excellent learning ability, while the black-box nature of DNN leads to uncertainty of inference results. With higher interpretability, convolutional fuzzy neural network (CFNN) becomes an alternative choice for the model of IoT applications. IoT applications are often latency-sensitive. By jointly utilizing computing power of IoT devices and edge servers, end-edge collaborative CFNN inference improves the insufficiency of local computing resources and reduces the latency of computing-intensive CFNN inference. However, the calculation amount of fuzzy layers is hard to get directly, bringing difficulty to CFNN partition. In addition, the profit of service providers is often ignored in existing work on distributed inference. In this article, an end-edge collaborative inference framework of CFNNs for big data-driven IoT, named DisCFNN, is proposed. Specifically, a novel CFNN structure and a method of fuzzy layer calculation amount assessment are designed at first. Next, computing resource allocation and CFNN partition decisions are generated on each edge server based on deep reinforcement learning. Then, each IoT device sends the request of CFNN inference service to a certain edge server or infer the whole CFNN locally according to the task offloading strategy obtained through many-to-one matching game. Finally, the effectiveness of DisCFNN is evaluated through extensive experiments.
Yuhao Hu, Xiaolong Xu 0001, Muhammad Bilal 0003, Wan-Chun Dou
IEEE Trans. Fuzzy Syst.1
2025 CADEC: A Combinatorial Auction for Dynamic Distributed DNN Inference Scheduling in Edge-Cloud Networks
abstract
Deep Neural Network (DNN) Inference, as a key enabler of intelligent applications, is often computation-intensive and latency-sensitive. Combining the advantages of cloud computing (abundant computing resources) and edge computing (fast transmission), edge-cloud collaborative DNN inference is a powerful solution to these problems. However, in edge-cloud networks with heterogeneous resources, how to obtain reasonable decisions on server selection, model partition and resource allocation for efficient distributed DNN inference is a hard challenge. Furthermore, it is non-trivial to design suitable resource prices to maximize the social welfare. These challenges even escalate in dynamic edge-cloud networks where decisions should be generated as soon as each user arrives without future information. Therefore, we design a combinatorial auction for dynamic distributed DNN inference scheduling, named CADEC. CADEC first constructs a bid set for each user based on convex optimization theory for optimal solution searching. Next, prices of resources in the edge-cloud network are adjusted according to changes in supply-demand relationship, and whether to admit the request of each user is decided. Finally, the dynamic distributed inference scheduling decisions are generated through the primal-dual algorithm to maximize the social welfare. Theoretical analysis shows the good competitive ratio and polynomial time complexity of CADEC. Results of simulation experiments present that CADEC improves social welfare by up to 224% compared with state-of-the-art distributed DNN inference schemes.
Xiaolong Xu 0001, Yuhao Hu, Guangming Cui, Lianyong Qi, Wan-Chun Dou, Zhipeng Cai 0001
IEEE Trans. Mob. Comput.2
2024 OptFuzz: Optimization Path Guided Fuzzing for JavaScript JIT Compilers
Jiming Wang, Yan Kang 0002, Chenggang Wu 0002, Yuhao Hu, Jikai Ren, Yuanming Lai, Mengyao Xie, Tao Li 0022, Zhe Wang 0017
USENIX Security Symposium4
2024 Optimizing CNN inference speed over big social data through efficient model parallelism for sustainable web of things
Yuhao Hu, Xiaolong Xu 0001, Muhammad Bilal 0003, Weiyi Zhong, Yuwen Liu 0003, Huaizhen Kou, Lingzhen Kong
J. Parallel Distributed Comput.1