Zuchao Ma

dblp:237/5007 · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-7439-2823ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 6 since 2021Security and privacy · 7 · 5 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 Light into Darkness: Demystifying Profit Strategies Throughout the MEV Bot Lifecycle
Feng Luo 0009, Zihao Li 0001, Wenxuan Luo, Zheyuan He, Xiapu Luo, Zuchao Ma, Shuwei Song, Ting Chen 0002
NDSS6
2025 Soleker: Uncovering Vulnerabilities in Solana Smart Contracts
abstract
Solana has rapidly evolved into a leading next generation platform for supporting decentralized applications due to its high performance and low transaction costs. Its new contract execution model, which decouples code logic from states, gives rise to new vulnerability threats that can result in significant financial losses for users within the ecosystem. However, existing studies towards detecting vulnerabilities are predominantly tailored for Ethereum smart contracts, which are unsuitable for Solana platform because of the variations in implementation languages and runtime semantics. In this paper, we propose Soleker, a novel approach that leverages learning-based techniques to automatically identifying potential vulnerabilities in Solana smart contract bytecode. More specifically, Soleker captures runtime semantic information from instructions that are associated with blockchain interactions and extracts vulnerability-specific localized features. Then, a prefix-guided graph learning model is introduced to learn and integrate extracted features, enabling effective vulnerability detection. We conduct experiments on a newly constructed contract dataset and the results demonstrate that Soleker significantly outperforms the baseline methods, achieving an average effectiveness improvement of 126.4% and a 335× boost in efficiency.
Kunsong Zhao, Yunpeng Tian, Zuchao Ma, Xiapu Luo
ASE3
2025 Surviving in Dark Forest: Towards Evading the Attacks from Front-Running Bots in Application Layer
Zuchao Ma, Muhui Jiang, Feng Luo 0009, Xiapu Luo, Yajin Zhou
USENIX Security Symposium1
2025 Automated Soundness and Completeness Vetting of Polygon zkEVM
Xinghao Peng, Kunsong Zhao, Zuchao Ma, Zihao Li 0001, Jinan Jiang, Xiapu Luo, Yinqian Zhang
USENIX Security Symposium4
2025 Uncovering NFT Domain-Specific Defects on Smart Contract Bytecode
abstract
The peak of monthly trade volume of NFT (non-fungible token) has reached${\$}$4.95 billion USD in August 2023, which shows the hot trend and the potential significance of NFT. However, the smart contract responsible for managing NFT may contain defects, which can be exploited by attackers to cause severe damage to victims. We take the first step to systematically analyze three kinds of defects on NFT contracts, namely fragile NFT binding, non-compliant implementation, and implanted backdoor. In particular, we proposeEmerium, the first extensible detection framework for capturing these defects by inspecting the bytecode of smart contracts. We conduct extensive experiments to evaluateEmerium, and the experimental results show that it can detect the aforementioned defects with 0.83 and 0.89 F-measure for ERC-721 contracts and ERC-1155 contracts, respectively. ApplyingEmeriumto 87,839 ERC-721 and 9,808 ERC1155 NFT contracts of real world, we uncover 44,863,255 defects of fragile NFT binding, 1,373 defects of non-compliant implementation, and 105 defects of backdoor (also with a new CVE).
Zuchao Ma, Muhui Jiang, Xiapu Luo, Haoyu Wang 0001, Yajin Zhou
IEEE Trans. Dependable Secur. Comput.1
2024 Understanding Vulnerability Inducing Commits of the Linux Kernel
abstract
The Linux kernel is popular and well-maintained. Over the past decade, around 860 thousand commits were merged with hundreds of vulnerabilities (i.e., 223 on average) disclosed every year, taking the total lines of code to 35.1 million in 2022. Many algorithms have been proposed to detect the vulnerabilities, but few studied how they were induced. To fill this gap, we conduct the first empirical study on the Kernel Vulnerability Inducing Commits (KVIC), the commits that induced vulnerabilities in the Linux kernel. We utilized six different methods on identifying the Kernel Vulnerability Fixing Commits (KVFCs), the commits that fix vulnerabilities in the Linux kernel, and proposed the other four different methods for identifying KVICs by using the identified KVFCs as a bridge. In total, we constructed the first dataset of KVICs with 1,240 KVICs for 1,335 CVEs. We conducted a thorough analysis on the characteristics, purposes, and involved human factors of the KVICs and obtained many interesting findings and insights. For example, KVICs usually have limited reviewers and can still be induced by experienced authors or maintainers. Based on these insights, we proposed several suggestions to the Linux community to help mitigate the induction of KVICs.
Muhui Jiang, Jinan Jiang, Zuchao Ma, Xiapu Luo, Yajin Zhou
ACM Trans. Softw. Eng. Methodol.4
2023 ADCL: Toward an Adaptive Network Intrusion Detection System Using Collaborative Learning in IoT Networks
abstract
With the widespread of cyber attacks, network intrusion detection system (NIDS) is becoming an important and essential tool to protect Internet of Things (IoT) environments. However, it is well known that the NIDS performance depends heavily on the effectiveness of the detection model, which can be influenced significantly by the learning mechanism and the available training data. Many existing studies try to mitigate the above challenges, but few of them consider the adaptability and the cost of deploying an NIDS, the integrity of the learning process, the capacity of model based on concrete traffic samples at the same time. To fill this gap and improve the detection performance, we propose a collaborative learning-based detection framework called ADCL, which can mitigate the limitations on the knowledge of a single model by leveraging multiple models trained in similar environments and detecting intrusions in a collaborative manner. Our evaluation results indicate that ADCL can provide better performance compared with a single model on detecting various attacks in IoT networks. Specifically, ADCL improves F-score by up to 80% for adaptability, 42% in mitigating the reliance on learning integrity, 85% for model capacity. Furthermore, the detection results of ADCL guide those single models to update and increase the F-score by 15%.
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001, Xiapu Luo, Lisong Wang, Wenjuan Li 0001
IEEE Internet Things J.1
2021 ECTSA: An Efficient Charging Time Scheduling Algorithm for Wireless Rechargeable UAV Network
abstract
With the development of airborne equipment and integrated avionics technology, the unmanned aerial vehicle (UAV) network replaces human beings in many fields. To improve the durability of the UAV network, we propose a nondisruptive wireless rechargeable UAV network (WRUN) model, in which UAVs can be charged by wireless static chargers (WSCs) without returning back to the charging platform. Under the nondisruptive WRUN model, a baseline algorithm is proposed to solve the nondisruptive charging time schedule problem (nCTSP), in which chargers do not release energy all the time and can ensure UAVs do not run out of energy. Then to improve the energy utilization rate of WSCs, we propose an efficient charging time scheduling algorithm (ECTSA), in which the flight time and paths of UAVs are discretized and nCTSP is transformed into a linear binary integer programming (LBIP) problem to calculate the efficient charging time periods of WSCs. Finally, experiments are conducted to verify that ECTSA can improve the energy utilization of WSCs.
Liang Liu 0006, Jie Xi, Zuchao Ma, Lisong Wang
Networking4
2021 ORMD: Online Learning Real-Time Malicious Node Detection for the IoT Network
Jingxiu Yang, Lu Zhou 0002, Liang Liu 0006, Zuchao Ma
WASA (2)4
2021 Detection of selective-edge packet attack based on edge reputation in IoT networks
Liang Liu 0006, Zuchao Ma, Youwei Ding
Comput. Networks3
2021 A Detection Framework Against CPMA Attack Based on Trust Evaluation and Machine Learning in IoT Network
abstract
Internet of Things (IoT) network is vulnerable to various cyberattacks, especially insider attacks. Most existing studies mainly detect nontargeted insider attackers, who manipulate all packets forwarded by them with a probability. Compared with nontargeted attackers, targeted attackers only manipulate specific packets, which makes them more efficient and covert. In this article, we propose a targeted insider attack model called conditional packets manipulation attack (CPMA), in which attackers maliciously manipulate the packets whose attribute values meet specific conditions with a probability. When resisting the CPMA attack, most existing detection algorithms are inefficient to find such malicious behavior. Also, they detect malicious nodes by collecting and analyzing the overall behavior of nodes, which are not appropriate for energy-constrained nodes in the IoT network. To solve these problems, we present CPMAED, a malicious nodes detection framework against CPMA attack. CPMAED maintains some partial trust metrics for each relay node, which indicate the probability of launch attacks when forwarding the packets with different attribute values. Also, our scheme leverages regression and clustering algorithms to evaluate the trust values of nodes and classify them into benign or malicious. In order to obtain higher detection accuracy, we optimize the routing of transmitted packets and inject the packets to collect more information about nodes to enhance detection. The experimental results show that our proposed scheme utilizing support vector machine and$K$-means can achieve good detection performance and identify malicious nodes’ attack modes with high accuracy.
Liang Liu 0006, Yulei Liu, Zuchao Ma, Jianfei Peng
IEEE Internet Things J.4
2021 Towards efficient and energy-aware query processing for industrial internet of things
Liang Liu 0006, Weizhi Meng 0001, Wenzhao Gao, Zuchao Ma
Peer-to-Peer Netw. Appl.6
2020 DCONST: Detection of Multiple-Mix-Attack Malicious Nodes Using Consensus-Based Trust in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
ACISP1
2020 ELD: Adaptive Detection of Malicious Nodes under Mix-Energy-Depleting-Attacks Using Edge Learning in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
ISC1
2020 Detection of malicious nodes in drone ad-hoc network based on supervised learning and clustering algorithms
abstract
Multi-drone swarm has been widely used in disaster monitoring, mapping and remote sensing, national defense military and other fields, and has become a research hotspot in recent years. Due to the openness of its operating environment, attackers can invade the control system to capture drone, and then carry out data attacks such as tamper attack, drop attack and replay attack in drone ad-hoc network, which causes a great threat to the security of drone network. Existing malicious nodes detection algorithms are not efficient when applied to drone ad-hoc network, for the following reasons: (1) The malicious node detection algorithms based on reputation usually adopt a static threshold to determine whether a node is malicious, which is inefficient in dynamic drone network. (2) Mutual cooperation based malicious node detection algorithms rely on the high meeting probability of nodes. In order to solve the above problems, we propose a Malicious Drones Detection Algorithm(MDA) based on supervised learning and clustering algorithms. The ground station calculates the reputation value of each routing path according to the received packets from different source nodes, and then evaluates the reputation value of drones with linear regression algorithm. Finally, gaussian clustering algorithm is used to cluster drones and find out malicious drones. Experiments were conducted in indoor and outdoor drone network. The experimental results indicate that the accuracy of MDA outperforms the existing methods by 10% 20%. And in the case of fewer malicious nodes, the accuracy can reach more than 90%, and the error rate is less than 10%.
Shanshan Sun, Zuchao Ma, Liang Liu 0006, Jianfei Peng
MSN2
2020 Towards multiple-mix-attack detection via consensus-based trust management in IoT networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
Comput. Secur.1
2019 Detection of multiple-mix-attack malicious nodes using perceptron-based trust in IoT networks
Liang Liu 0006, Zuchao Ma, Weizhi Meng 0001
Future Gener. Comput. Syst.2