VLDB 2026 Research / reviewers in the wild / expert
Aoshuang Ye
dblp:236/4982
· DBLP profile ↗
13ranked-venue papers
5as first author
12since 2021 · last 2025
0000-0003-4151-7439ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | VULDA: Source Code Vulnerability Detection via Local Dependency Context Aggregation on Vulnerability-Aware Code Mapping Graph
Tao Peng 0006, Ling Gui, Junwei Tang, Aoshuang Ye |
ICICS (3) | 5 |
| 2025 | CAPRA: Context-Aware patch risk assessment for detecting immature vulnerability in open-source softwareabstractSoftware development increasingly relies on open-source contributions, yet these projects face significant security challenges. Large collaborative codebases frequently encounter vulnerabilities due to varying developer skill levels and reviewers’ incomplete understanding of code changes’ contextual implications. Traditional detection measures typically activate only after code merging, missing opportunities for detecting potential risks (e.g. immature vulnerability). This paper presents CAPRA, a security detection tool analyzing pending patches through static analysis to identify potential memory leak and Use-After-Free vulnerabilities before integration. Our approach employs code property graph, eliminating compilation environment dependencies while efficiently detecting whether code modifications activate latent vulnerabilities. Using our newly constructed dataset targeting risk-triggering scenarios, experimental results demonstrate CAPRA achieves 97.3% accuracy with 98% recall and only 3.5% false positives—confirming its effectiveness for enhancing code review processes through targeted, early vulnerability detection in rapidly iterating collaborative projects. Benxiao Tang, Aoshuang Ye |
Comput. Secur. | 4 |
| 2025 | CtrlFuzz: A controllable diffusion-based fuzz testing for deep neural networks via coverage-aware manifold guidance
Aoshuang Ye, Runze Yan, Jianpeng Ke, Benxiao Tang |
Inf. Softw. Technol. | 1 |
| 2025 | DeFinder: Error-sensitive testing of deep neural networks via vulnerability interpretation
Aoshuang Ye, Benxiao Tang, Jianpeng Ke, Yiru Zhao, Tao Peng 0006 |
J. Netw. Comput. Appl. | 1 |
| 2023 | Towards a Robust Deep Neural Network Against Adversarial Texts: A SurveyabstractDeep neural networks (DNNs) have achieved remarkable success in various tasks (e.g., image classification, speech recognition, and natural language processing (NLP)). However, researchers have demonstrated that DNN-based models are vulnerable to adversarial examples, which cause erroneous predictions by adding imperceptible perturbations into legitimate inputs. Recently, studies have revealed adversarial examples in the text domain, which could effectively evade various DNN-based text analyzers and further bring the threats of the proliferation of disinformation. In this paper, we give a comprehensive survey on the existing studies of adversarial techniques for generating adversarial texts written by both English and Chinese characters and the corresponding defense methods. More importantly, we hope that our work could inspire future studies to develop more robust DNN-based text analyzers against known and unknown adversarial techniques. We classify the existing adversarial techniques for crafting adversarial texts based on the perturbation units, helping to better understand the generation of adversarial texts and build robust models for defense. In presenting the taxonomy of adversarial attacks and defenses in the text domain, we introduce the adversarial techniques from the perspective of different NLP tasks. Finally, we discuss the existing challenges of ad-versarial attacks and defenses in texts and present the future research directions in this emerging and challenging field. Wenqi Wang 0002, Run Wang 0001, Lina Wang 0001, Zhibo Wang 0001, Aoshuang Ye |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2022 | Combating Multi-level Adversarial Text with Pruning based Adversarial TrainingabstractDespite significant advancements of deep learning-based models for natural language processing (NLP) tasks, previous efforts have shown that numerous models, including deep neural networks (DNNs), suffer from moderate to significant performance degradation with adversarial examples. Adversary crafts malicious text by adding, deleting, modifying chars, words, and sentences, to fool the DNN models. Therefore, adversarial training and model enhanced methods are proposed to combat the adversarial attack. However, both methods are lack generalization due to the overfitting intrinsic of neural networks. In this paper, we propose a novel framework to combat text adversarial examples, namely DisPAT, which consists an adversarial text discriminator and a robust pruned text classifier. First, we explore the adversarial examples and benign examples distribution in embedding space, indicating the feasibility of a DNN-based discriminator. To get multi-level adversarial texts, we deploy a generator, and a discriminator to identify adversarial perturbations. Notably, in the inference stage, our pipeline places the well-trained discriminator in front of the text classifier to distinguish the char-level adversarial text. Finally, we apply neuron-salience-based pruning to specifically improve the classifier performance of adversarial text. Experimental results show that our approach outperforms state-of-the-art baselines in combating both char-level and word-level adversarial text. Moreover, DisPAT achieves a very close to or even higher accuracy than that of the standard model. Jianpeng Ke, Lina Wang 0001, Aoshuang Ye |
IJCNN | 3 |
| 2022 | Improving Robustness Verification of Neural Networks with General Activation Functions via Branching and OptimizationabstractRobustness verification of neural networks (NNs) is a challenging and significant problem, which draws great attention in recent years. Existing researches have shown that bound propagation is a scalable and effective method for robustness verification, and it can be implemented on GPUs and TPUs to get parallelized. However, the bound propagation methods naturally produce weak bound due to linear relaxations on the neurons, which may cause failure in verification. Although tightening techniques for simple ReLU networks have been explored, they are not applicable for NNs with general activation functions such as Sigmoid and Tanh. Improving robustness verification on these NNs is still challenging. In this paper, we propose a Branch-and-Bound (BaB) style method to address this problem. The proposed BaB procedure improves the weak bound by splitting the input domain of neurons into sub-domains and solving the corresponding sub-problems. We propose a generic heuristic function to determine the priority of neuron splitting by scoring the relaxation and impact of neurons. Moreover, we combine bound optimization with the BaB procedure to improve the weak bound. Experimental results demonstrate that the proposed method gains up to 35% improvement compared to the state-of-art CROWN method on Sigmoid and Tanh networks. Zhengwu Luo, Lina Wang 0001, Run Wang 0001, Aoshuang Ye |
IJCNN | 5 |
| 2022 | DANCe: Dynamic Adaptive Neuron Coverage for Fuzzing Deep Neural NetworksabstractDeep learning (DL) defines a data-driven paradigm that differs from conventional software. It utilizes training data to construct the internal logic of the deep neural networks. With aggressive development in various security-sensitive domains, deep learning raises safety concerns in academia and industrial community. Numerous researches have shown that even the most advanced deep learning systems have vulnerabilities leading to misbehaviors. Despite the urgent security threat, fuzzing test remains a reasonable way to solve the problem. However, The static parameters design in current mainstream neuron coverage disables the fuzzing work diversely on heterogeneous architectures. To address the above problems, we propose the Dynamic Adaptive Neuron Coverage (DANCe) to model the neuron behavior, which can adapt diverse models with implementing training data. The dynamic adaption mechanism enhances the ability of coverage-based fuzzing to generate adversarial examples as test cases. The proposed model is evaluated on two widely-adopted image datasets and four well-designed deep neural networks. The experimental results show that the DANCe exceeds the SOTA coverage criteria by 7% and 33% on generating adversarial examples within 1 hour and 6 hours of time limitation. Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke |
IJCNN | 1 |
| 2022 | Better constraints of imperceptibility, better adversarial examples in the textabstractState-of-the-art adversarial attacks in the text domain have shown their power to induce machine learning models to produce abnormal outputs. The samples generated in these attacks have three important attributes: attack ability, transferability, and imperceptibility. However, compared with the other two attributes, the imperceptibility of adversarial examples has not been well investigated. Unlike the pixel-level perturbations in images, adversarial perturbations in the text are usually traceable, reflecting changes in characters, words, or sentences. The generation of imperceptible samples in texts is more difficult than in images. Therefore, how to constrain adversarial perturbations added in the text is a crucial step to construct more natural adversarial texts. Unfortunately, recent studies merely select measurements to constrain the added adversarial perturbations, but none of them explain where these measurements are suitable, which one is better, and how they perform in different kinds of adversarial attacks. In this paper, we fill this gap by comparing the performance of these metrics in various attacks. Furthermore, we propose a stricter constraint for word-level attacks to obtain more imperceptible samples. It is also helpful to enhance existing word-level attacks for adversarial training. Wenqi Wang 0002, Lina Wang 0001, Run Wang 0001, Aoshuang Ye, Jianpeng Ke |
Int. J. Intell. Syst. | 4 |
| 2022 | Ex2: Monte Carlo Tree Search-based test inputs prioritization for fuzzing deep neural networksabstractFuzzing is considered to be an essential approach to guarantee the reliability of deep neural networks (DNNs) based systems. The DNN fuzzing leverages various inputs prioritization methods to guide the testing process. The current research mainly focus on constructing testing metrics that symbolize the logical representation of the DNN to guide the generation of test cases, which neglects the potential performance brought by implementing heuristic algorithm. Moreover, the straightforward implementation of queue structure can not represent the metamorphic relationships between generated inputs in DNN fuzzing. Therefore, developing the appropriate heuristic algorithm-based inputs prioritization method is critical to improve the performance of DNN fuzzers. In this paper, we propose a Monte Carlo Tree Search (MCTS) based inputs prioritization method called E x 2 $E{x}^{2}$ (Exploration and Exploitation) that formulates DNN testing exploration as the sequential decision process. The technique introduces an innovative tree-structure design that schedules inputs from the statistical perspective. Different from traditional DNN testing, the batch pool is maintained in the form of nodes in MCTS. The links between nodes precisely represent the metamorphic relationship between input batches, which indicates the potential value for in-depth search. Furthermore, a novel simulation mechanism is implemented to adapt MCTS in DNN testing, which attain better coverage feedback. The effectiveness of our method is comprehensively investigated on six popular deep learning models from LeNet and VGG families. The comparison experiments are conducted between DeepHunter, TensorFuzz, and DeepSmartFuzzer to demonstrate efficacy on various testing metrics. The experimental results show that the E x 2 $E{x}^{2}$ significantly enhance the coverage gain of DNN fuzzing up to 30% against the best performance in comparison groups. Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke |
Int. J. Intell. Syst. | 1 |
| 2021 | Annealing Attention Networks for User Feature-Based Rumor Early Detection on WeiboabstractRumor propagation is becoming easier and leads to severe consequences for society in several minutes or hours due to the rapid development of social networks. Thus, detecting rumors in early time is necessary and urgent for the community. In recent studies, machine learning approaches are widely applied in detecting rumors based on various features extracted from content, user characteristics, and propagation structure. Some studies have shown that features extracted from users are more valuable for rumor early detection. Whereas existing studies utterly utilize various user features, and all of them are deemed as equally, which ignore the inter-feature and temporal difference. Therefore, in this paper, we analyze the effectiveness of six frequently used user features with several representative deep learning models to learn more about such difference. And we propose a novel annealing attention model based on the analysis. The proposed model learns feature-attention and temporal-attention with multi-layer perceptron and parameterized annealing function to capture the difference and enhance the original user features in rumor early detection. Experimental results on the real-world dataset demonstrate that the proposed model detects rumors with an accuracy of 93.6% on Weibo in 15 minutes, which outperforms the state-of-art methods. Zhengwu Luo, Lina Wang 0001, Wenqi Wang 0002, Aoshuang Ye |
IJCNN | 4 |
| 2021 | RapidFuzz: Accelerating fuzzing via Generative Adversarial Networks
Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke, Wenqi Wang 0002, Qinliang Liu |
Neurocomputing | 1 |
| 2020 | MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic AlgorithmabstractRecent studies have shown that deep neural networks (DNNs) are susceptible to adversarial attacks even in the black-box settings. However, previous studies on creating black-box based adversarial examples by merely solving the traditional continuous problem, which suffer query efficiency issues. To address the efficiency of querying in black-box attack, we propose a novel attack, called MGAAttack, which is a query-efficient and gradient-free black-box attack without obtaining any knowledge of the target model. In our approach, we leverage the advantages of both transfer-based and scored-based methods, two typical techniques in black-box attack, and solve a discretized problem by using a simple yet effective microbial genetic algorithm (MGA). Experimental results show that our approach dramatically reduces the number of queries on CIFAR-10 and ImageNet and significantly outperforms previous work. In the untargeted attack, we can attack a VGG19 classifier with only 16 queries and give an attack success rate more than 99.90% on ImageNet. Our code is available at https://github.com/kangyangWHU/MGAAttack. Lina Wang 0001, Wenqi Wang 0002, Run Wang 0001, Aoshuang Ye |
ACM Multimedia | 5 |