VLDB 2026 Research / reviewers in the wild / expert
Qiushi Wu
dblp:248/1662
· DBLP profile ↗
14ranked-venue papers
4as first author
11since 2021 · last 2026
0009-0001-9251-9760ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 4 first-author · 11 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
Juefei Pu, Xiaochen Zou, Shitong Zhu, Qiushi Wu, Zheng Zhang 0058, Joshua Hsu, Zhiyun Qian, Kangjie Lu, Trent Jaeger, Michael J. De Lucia, Srikanth V. Krishnamurthy |
NDSS | 6 |
| 2025 | APILOT: Improving the Security and Usability of LLM Code Suggestions via Outdated API MitigationabstractWith the rapid development of large language models (LLMs), their applications have expanded into diverse fields, such as code assistance. However, the substantial size of LLMs makes their training highly resource- and time-consuming, which leads to lengthy retraining and delayed updating. Consequently, LLMs trained based on old data may generate outdated results. This becomes extremely critical in the scenario of avoiding vulnerabilities. New vulnerabilities are discovered every day. Without updating their knowledge, LLMs may inadvertently generate code that includes these newly discovered vulnerabilities. Current strategies, such as prompt engineering and fine-tuning, do not effectively address this issue. Prompt engineering fails to equip LLMs with comprehensive, up-to-date knowledge, while fine-tuning remains prohibitively resource-intensive and time-consuming. To address this issue, we study the problem of LLM recommending outdated APIs and propose a new solution, named APILOT, which maintains a real-time, quickly updatable dataset of outdated APIs. Additionally, APILOT utilizes pre-constructed cache prediction and augmented generation methods that leverage this dataset to navigate LLMs in generating secure, version-aware code. We conducted a comprehensive empirical evaluation of APILOT across seventeen state-of-the-art large language models (LLMs), including both open-source and commercial systems. The results demonstrate that APILOT reduces outdated API recommendations by an average of 75%, with some models achieving up to 100% mitigation in specific large language models. Notably, these improvements are achieved with minimal performance overhead. Interestingly, while enhancing security, APILOT also improves the usability of LLM -generated code by an average of 37%, with gains reaching up to 85.6% in certain large language models. Importantly, these improvements are achieved without compromising code functionality, as measured by ICE-SCORE evaluations across diverse prompts and LLMs. This demonstrates APILOT's dual benefit─it not only reduces the risk of outdated API usage but also enhances the practical utility and deployability of generated code. Together, these results highlight APILOT 's potential to improve both security and developer experience in real-world AI-assisted programming environments. Weiheng Bai, Keyang Xuan, Pengxiang Huang, Qiushi Wu, Jianing Wen, Kangjie Lu |
ACSAC | 4 |
| 2024 | GNNIC: Finding Long-Lost Sibling Functions with Abstract Similarity
Qiushi Wu, Zhongshu Gu, Hani Jamjoom, Kangjie Lu |
NDSS | 1 |
| 2023 | Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs
Jianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding, Linke Li, Qiushi Wu, Mathias Payer, Bing Mao 0001 |
USENIX Security Symposium | 6 |
| 2022 | Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security BugsabstractSecurity bugs like memory errors are constantly introduced to software programs, and recent years have witnessed an increasing number of reported security bugs. Traditional detection approaches are mainly specification-based---detecting violations against a specified rule as security bugs. This often does not work well in practice because specifications are difficult to specify and generalize, leaving complicated and new types of bugs undetected. Recent research thus leans toward deviation-based detection which finds a substantial number of similar cases and detects deviating cases as potential bugs. This, however, suffers from two other problems. First, it requires enough similar cases to find deviations and thus cannot work for custom code that does not have similar cases. Second, code-similarity analysis is probabilistic and challenging, so the detection can be unreliable. Sometimes, similar cases can normally have deviating behaviors under different contexts. Qingyang Zhou, Qiushi Wu, Dinghao Liu, Shouling Ji, Kangjie Lu |
CCS | 2 |
| 2022 | Semantic-Informed Driver Fuzzing Without Both the Hardware Devices and the Emulators
Wenjia Zhao, Kangjie Lu, Qiushi Wu, Yong Qi 0001 |
NDSS | 3 |
| 2022 | OS-Aware Vulnerability Prioritization via Differential Severity Analysis
Qiushi Wu, Yue Xiao 0007, Xiaojing Liao, Kangjie Lu |
USENIX Security Symposium | 1 |
| 2022 | Unleashing Coveraged-Based Fuzzing Through Comprehensive, Efficient, and Faithful Exploitable-Bug ExposingabstractFuzzing has become an essential means of finding software bugs. Bug finding through fuzzing requires two parts—exploring code paths to reach bugs and exposing bugs when they are reached. Existing fuzzing research has primarily focused on improving code coverage but not on exposing bugs. Sanitizers such as AddressSanitizer (ASAN) and MemorySanitizer (MSAN) have been the dominating tools for exposing bugs. However, sanitizer-based bug exposing has the following limitations. (1) sanitizers are not compatible with each other. (2) sanitizers incur significant runtime overhead. (3) sanitizers may generate false positives, and (4) exposed bugs may not be exploitable. To address these limitations, we proposeExpozzer, a fuzzing system that can expose bugs comprehensively, efficiently, and faithfully. The intuition ofExpozzeris to detect bugs through divergences in a properly diversified dual-execution environment, which does not require maintaining or checking execution metadata. We design a practical and deterministic dual-execution engine, a co-design for dual-execution and fuzzers, bug-sensitive diversification, comprehensive, and efficient divergence detection to ensure the effectiveness ofExpozzer. The results of evaluations show thatExpozzercan detect not only CVE-assigned vulnerabilities reliably, but also new vulnerabilities in well-tested real-world programs.Expozzeris 10 times faster than MemorySanitizer and is similar to AddressSanitizer. Bowen Wang 0014, Kangjie Lu, Qiushi Wu, Aditya Pakki |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Detecting Missed Security Operations Through Differential Checking of Object-based Similar PathsabstractMissing a security operation such as a bound check has been a major cause of security-critical bugs. Automatically checking whether the code misses a security operation in large programs is challenging since it has to understand whether the security operation is indeed necessary in the context. Recent methods typically employ cross-checking to identify deviations as security bugs, which collects functionally similar program slices and infers missed security operations through majority-voting. An inherent limitation of such approaches is that they heavily rely on a substantial number of similar code pieces to enable cross-checking. In practice, many code pieces are unique, and thus we may be unable to find adequate similar code snippets to utilize cross-checking. Dinghao Liu, Qiushi Wu, Shouling Ji, Kangjie Lu, Zhenguang Liu, Jianhai Chen, Qinming He |
CCS | 2 |
| 2021 | Detecting Kernel Memory Leaks in Specialized Modules with Ownership Reasoning
Navid Emamdoost, Qiushi Wu, Kangjie Lu, Stephen McCamant |
NDSS | 2 |
| 2021 | Understanding and Detecting Disordered Error Handling with Precise Function Pairing
Qiushi Wu, Aditya Pakki, Navid Emamdoost, Stephen McCamant, Kangjie Lu |
USENIX Security Symposium | 1 |
| 2020 | Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule Comparison
Qiushi Wu, Stephen McCamant, Kangjie Lu |
NDSS | 1 |
| 2019 | Automatically Identifying Security Checks for Detecting Kernel Semantic Bugs
Kangjie Lu, Aditya Pakki, Qiushi Wu |
ESORICS (2) | 3 |
| 2019 | Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints Inferences
Kangjie Lu, Aditya Pakki, Qiushi Wu |
USENIX Security Symposium | 3 |