VLDB 2026 Research / reviewers in the wild / expert
Ziang Liu 0006
dblp:244/7499-6
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0009-0007-8559-9938ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards a comprehensive framework for verifying open-source software license compatibility
Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou |
Empir. Softw. Eng. | 1 |
| 2025 | ISGraphVD: Precise Vulnerability Detection for IoT Supply Chains Based on Identifier Sensitive GraphabstractOpen-source software (OSS) is widely reused in Internet of Things (IoT) devices, leading to widespread N-Day vulnerabilities when outdated components remain unpatched. Existing methods typically encode features of different Common Vulnerabilities and Exposures (CVEs) within a shared representation space. However, the model’s limited capacity, combined with the new vulnerability features, can disrupt previously learned patterns. Minimal code modifications in tiny-patch vulnerabilities are often overshadowed by variations introduced by different compilation settings, making it more difficult to distinguish vulnerable functions from their patched counterparts. This paper introduces ISGraphVD, a novel graph-based and function-level vulnerability detection approach that supports cross-compilation settings and enhances detection accuracy. By modeling each CVE independently through a one-model-per-CVE strategy, ISGraphVD reduces feature interference and improves detection accuracy across diverse CVEs. To better detect tinypatch vulnerability, we propose ISGraph, a fine-grained graph representation that models variable dependencies within and across basic blocks by integrating control flow analysis. Then, ISGraphVD utilizes a Graph Matching Network (GMN) with a cross-graph attention mechanism to identify critical vulnerability patterns. Experiments on IoT OSS projects show that ISGraphVD outperforms state-of-the-art methods, achieving a 6.3 percentage-point (pp) accuracy improvement over the strongest baseline, and real-world tests further validate its effectiveness in IoT supply chains. Yingli Zhang, Xin Liu 0050, Ziang Liu 0006, Song Li 0006, Weina Niu, Rui Zhou 0005, Qingguo Zhou |
ISSRE | 3 |
| 2024 | LiScopeLens: An Open-Source License Incompatibility Analysis Tool Based on Scope Representation of License TermsabstractOpen-source software has emerged as a pivotal force in the advancement of information technology. Robust open-source compliance governance is essential for the sustainable and healthy growth of both open-source software and its communities. License incompatibility analysis, in particular, represents a critical challenge hindering the progress of open-source software. Traditional methods of incompatibility analysis often fail to account for diverse usage scenarios or are tailored to a limited subset of scenarios. This limitation obstructing their ability to handle the intricate compatibility arising from varied programming language interactions, leading to a high false positives. Our study embarks from an examination of license exceptions, delving into the incompatibility analysis challenges through extensive empirical research on these exceptions. We discovered that the majority of exceptions are, in fact, detectable. Leveraging this empirical insight, our research further develops the license compatibility analysis model by introducing a new, refined legal terminology representation alongside a novel method for license compatibility reasoning. This approach begins with modeling different scenarios to represent license compatibility variably. Furthermore, based on these modeling outcomes, we have designed and implemented LiScopeLens, a tool capable of discerning dependency behaviors for granular compatibility assessment, starting with binary dependencies. Our experimental findings affirm that LiScopeLens proficiently determines the license compatibility status of open-source software across various usage scenarios, demonstrating its significant practical utility. Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou |
ISSRE | 1 |
| 2022 | TCN enhanced novel malicious traffic detection for IoT devicesabstractWith the development of IoT technology, more and more IoT devices are connected to the network. Due to the hardware constraints of IoT devices themselves, it is difficult for developers to embed security software into them. Therefore, it is better to protect IoT devices at the traffic level. The effect of malicious traffic detection based on neural networks is promising. Still, the slow computation brings some difficulties to deploying AI-based detection systems on edge servers. Time Convolutional Network (TCN) is a high-speed neural network suitable for massively parallel computation. In this paper, we propose Multi-class S-TCN, an improved network supporting multiple classifications based on TCN for the practical needs of IoT scenarios. Besides, we implement a complete IoT traffic security detection procedure based on deep packet inspection and protocol analysis. The proposed Multi-class S-TCN significantly improves the detection speed without degrading the detection effect. Experiments show that this work has better detection performance and faster detection speed compared to existing approaches, proving the effectiveness of the proposed detection flow and Multi-class S-TCN in IoT scenarios. Xin Liu 0050, Ziang Liu 0006, Yingli Zhang, Dong Lv, Qingguo Zhou |
Connect. Sci. | 2 |