VLDB 2026 Research / reviewers in the wild / expert
Zaixing Zhang
dblp:239/7791
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0004-7721-0417ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Task-Harmonious Vulnerability Assessment Based on LLMabstractSoftware vulnerabilities seriously jeopardize software security. It would be highly beneficial if developers could receive severity reminders regarding vulnerabilities when developing software systems. Therefore, when handling numerous vulnerabilities, it's crucial to prioritize the most critical ones and assess their severity early for effective resolution. Vulnerability assessment needs to train multiple assessment tasks simultaneously. Previous works suffer from task-disharmonious issues when conducting vulnerability assessments because they fail to balance the magnitude of gradients across multiple tasks and the conflicts in gradient directions. Additionally, they use identical code embedding for all classifiers without extracting task-related features. In this study, we are the first to conduct vulnerability assessment in a task-harmonious way by harmonizing gradient direction and magnitude, and filtering out task-specific features for each classifier. In addition, we use finer-grained contextual information than existing works by program slicing to further boost the model performance. According to experiment results, our model has demonstrated state-of-the-art performance at both the commit and function levels. Specifically, in function-level tasks, our model achieves an average of 0.819 in F1-Score and 0.742 in MCC, outperforming all baseline models. For commitlevel, our model enhances the average performance of the best baseline model by 29.6 % and 64.7 % in F1-Score and MCC, respectively. Zaixing Zhang, Jianming Chang, Tianyuan Hu, Lulu Wang 0001, Bixin Li |
ICPC | 1 |
| 2025 | HCIA: Hierarchical Change Impact Analysis Based on Hierarchy Program SlicesabstractChange impact analysis (CIA) is an essential method in software maintenance and evolution. Its accuracy and usability play a crucial role in its application. However, most CIAs are coarse-grained and limited to class and method levels. Despite the fine-grained CIAs’ success in giving the statement-level impact set, they are still limited without the sub-statement level dependency analysis, leading to low precision. Additionally, their unstructured impact sets make it challenging for users to comprehend the impact content. This paper proposes Hierarchical Change Impact Analysis (HCIA), a Hierarchical CIA technique based on the sub-statement level dependence graph. HCIA can perform a forward hierarchy program slicing on the change set from five levels: sub-statement, statement, method, class, and package. Based on the program slices, HCIA calculates the impact factor of the impact sets at the five levels to generate the final impact set. In the experiment, we evaluate the relationship between the impact factor and the actual affected codes and assess the most appropriate size of HCIA impact sets. Furthermore, we evaluate HCIA on 10 open-source projects by comparing our approach with popular CIAs at the five levels. The experimental result shows that HCIA is more accurate than the popular CIAs. Jianming Chang, Lulu Wang 0001, Zaixing Zhang |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2024 | Graph-Based Salient Class Classification in CommitsabstractIn software engineering, code review is an important process when a project is to be upgraded. Reviewers need to assess the validity of a commit, even if they are not familiar with the files in the commit. In a typical commit, one or more mainly modified classes referred to as salient classes, may cause modifications in other classes. Salient Class Identification is such a method that can help reviewers review commits more effectively. In this way, after identifying salient classes, reviewers can allocate most of their efforts to analyzing the salient class, comprehending the commit, and providing reasoned assessments. The existing Salient Class Identification model is based on the static features of the code and does not analyze the internal logical information, such as the relationships between statements. We thoroughly consider both internal and external code information in commits, using a detailed Code-Change Dependency Graph (CCDG) to depict the code structure. CCDG includes various node and edge types, supporting complex syntax scenarios, which can capture fine-grained dependencies. Finally, based on a heterogeneous graph neural network, we extract nuanced features embedding from CCDG, which can further boost the performance of our model. The experiment result shows that our model outperforms existing models in Salient Class Identification, achieving an overall $88 \%$ accuracy. Jiahao Ren, Jianming Chang, Lulu Wang 0001, Zaixing Zhang, Bixin Li |
QRS | 4 |
| 2023 | Commit Classification via Diff-Code GCN based on System Dependency GraphabstractCommit Classification, an automated process of classifying Diff-Code based on their purpose, plays a crucial role in enhancing comprehension and the quality of software. Some previous studies only used commit messages or code metrics to represent diff-code but lacked code context structure characterization. Alternatively, other studies have used Abstract Syntax Trees (ASTs) tokens to represent diff-code but did not consider contextual information like data dependency and control dependency. In this paper, we propose a new commit classification model called Diff-Code GCN (Graph Convolutional Network). Specifically, we firstly build a more detailed system dependency graph (SDG) of the commit, and secondly use program slicing to search the impact scope of diff-code. Thirdly, we extract the scope as a Change Impact Graph (CIG). We utilize GCN to extract contextual information from CIG and combine it with syntactic changed information of ASTs to represent the commit. Finally, we classify the commit into three maintenance categories (corrective, perfective, and adaptive). We evaluate our model based on commonly used datasets and compare our model with popular commit classification approaches. The experiment result well shows that both in within-project and cross-project prediction tasks, our model performs better than baseline models. Zaixing Zhang, Jianming Chang, Lulu Wang 0001 |
QRS | 1 |