Yibo Wang 0006

dblp:25/4764-6 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0003-0255-5838ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Automated Discovery of Asymmetric Mempool DoS in Blockchains
abstract
In blockchains, mempool controls transaction flow before consensus, denial of whose service hurts the health and security of blockchain networks. This paper presents MPFUZZ, the first mempool fuzzer to find asymmetric DoS bugs by exploring the space of symbolized mempool states and optimistically estimating the promisingness of an intermediate state in reaching bug oracles. Compared to the baseline blockchain fuzzers, MPFUZZ achieves a > 100× speedup in finding known DETER exploits. Running MPFUZZ on major Ethereum clients leads to discovering new mempool vulnerabilities, which exhibit a wide variety of sophisticated patterns, including stealthy mempool eviction and mempool locking. Rule-based mitigation schemes are proposed against all newly discovered vulnerabilities.
Yibo Wang 0006, Yuzhe Tang, Kai Li 0017, Wanning Ding
IEEE Trans. Software Eng.1
2025 Asymmetric Mempool DoS Security: Formal Definitions and Provable Secure Designs
abstract
A mempool is a security-critical subsystem in a public blockchain. Recent mempool attacks, notably asymmetric DoS, have shown their ability to severely damage the Ethereum network. This paper tackles the open research problem of designing principled and non-intrusive defenses against asymmetric mempool DoSes with provable security. It presents the first mempool economic-security definitions based on mempool-observable conditions. It then presents SAFERAD, a framework of secure mempool designs with provable security against asymmetric DoSes. To defend against dual attacks by evicting and locking a victim mempool, SAFERAD adopts a non-trivial design of enforcing an upper bound of the attack damage under the locking attacks and a lower bound of the attack cost under the eviction attacks. With a prototype implementation on Geth and evaluation under real transaction traces, the results show SAFERAD has low overhead in latency and block revenue, implying non-intrusiveness and practicality.
Wanning Ding, Yuzhe Tang, Yibo Wang 0006
SP3
2024 Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful Fuzzing
Yibo Wang 0006, Yuzhe Tang, Kai Li 0017, Wanning Ding, Zhihua Yang
USENIX Security Symposium1
2023 Understanding the Security Risks of Decentralized Exchanges by Uncovering Unfair Trades in the Wild
abstract
DEX, or decentralized exchange, is a prominent class of decentralized finance (DeFi) applications on blockchains, attracting a total locked value worth tens of billions of USD today.This paper presents the first large-scale empirical study that uncovers unfair trades on popular DEX services on Ethereum and Binance Smart Chain (BSC). By joining and analyzing 60 million transactions, we find 671, 400 unfair trades on all six measured DEXes, including Uniswap, Balancer, and Curve. Out of these unfair trades, we attribute 55, 000 instances, with high confidence, to token thefts that cause a value loss of more than 3.88 million USD. Furthermore, the measurement study uncovers previously unknown causes of extractable value and real-world adaptive strategies to these causes. Finally, we propose countermeasures to redesign secure DEX protocols and to harden deployed services against the discovered security risks.
Yibo Wang 0006, Wanning Ding, Yuzhe Tang, XiaoFeng Wang 0001, Kai Li 0017
EuroS&P2
2023 Towards Saving Blockchain Fees via Secure and Cost-Effective Batching of Smart-Contract Invocations
abstract
This paper presentsiBatch, a middleware system running on top of an operational Ethereum network to enable secure batching of smart-contract invocations against an untrusted relay server off-chain.iBatchdoes so at a low overhead by validating the server's batched invocations in smart contracts without additional states of user nonces. TheiBatchmechanism supports a variety of policies, ranging from conservative to aggressive batching, and can be configured adaptively to the current workloads.iBatchautomatically rewrites smart contracts to integrate with legacy applications and support large-scale deployment. We built an evaluation platform for fast and cost-accurate transaction replaying and constructed real transaction benchmarks on popular Ethereum applications. With a functional prototype ofiBatch, we conduct extensive cost evaluations, which showsiBatchsaves$14.6\%\sim {}59.1\%$Gas cost per invocation with a moderate 2-minute delay and$19.06\%\sim {}31.52\%$Ether cost per invocation with a delay of$0.26\sim {}1.66$blocks.
Yibo Wang 0006, Kai Li 0017, Yuzhe Tang, Qi Zhang 0009, Xiapu Luo, Ting Chen 0002
IEEE Trans. Software Eng.1
2022 Poster: Enabling Cost-Effective Blockchain Applications via Workload-Adaptive Transaction Execution
abstract
As transaction fees skyrocket today, blockchains become increasingly expensive, hurting their adoption in broader applications. This work tackles the saving of transaction fees for economic blockchain applications. The key insight is that other than the existing "default'' mode to execute application logic fully on-chain, i.e., in smart contracts, and in fine granularity, i.e., user request per transaction, there are alternative execution modes with advantages in cost-effectiveness. On Ethereum, we propose a holistic middleware platform supporting flexible and secure transaction executions, including off-chain states and batching of user requests. Furthermore, we propose control-plane schemes to adapt the execution mode to the current workload for optimal runtime cost. We present a case study on the institutional accounts (e.g., coinbase.com) intensively sending Ether on Ethereum blockchains. By collecting real-life transactions, we construct workload benchmarks and show that our work saves 18%\sim 47%18%-47% per invocation than the default baseline while introducing 1.81%\sim 16.59%1.81%-16.59% blocks delay.
Yibo Wang 0006, Yuzhe Tang
CCS1
2022 APER: Evolution-Aware Runtime Permission Misuse Detection for Android Apps
abstract
The Android platform introduces the runtime permission model in version 6.0. The new model greatly improves data privacy and user experience, but brings new challenges for app developers. First, it allows users to freely revoke granted permissions. Hence, developers cannot assume that the permissions granted to an app would keep being granted. Instead, they should make their apps carefully check the permission status before invoking dangerous APIs. Second, the permission specification keeps evolving, bringing new types of compatibility issues into the ecosystem. To understand the impact of the challenges, we conducted an empirical study on 13,352 popular Google Play apps. We found that 86.0% apps used dangerous APIs asynchronously after permission management and 61.2% apps used evolving dangerous APIs. If an app does not properly handle permission revocations or platform differences, unexpected runtime issues may happen and even cause app crashes. We call such Android Runtime Permission issues as ARP bugs. Unfortunately, existing runtime permission issue detection tools cannot effectively deal with the ARP bugs induced by asynchronous permission management and permission specification evolution. To fill the gap, we designed a static analyzer, Aper, that performs reaching definition and dominator analysis on Android apps to detect the two types of ARP bugs. To compare Aper with existing tools, we built a benchmark, ARPfix, from 60 real ARP bugs. Our experiment results show that Aper significantly outperforms two academic tools, ARPDroid and RevDroid, and an industrial tool, Lint, on ARPfix, with an average improvement of 46.3% on F1-score. In addition, Aper successfully found 34 ARP bugs in 214 open-source Android apps, most of which can result in abnormal app behaviors (such as app crashes) according to our manual validation. We reported these bugs to the app developers. So far, 17 bugs have been confirmed and seven have been fixed.
Yibo Wang 0006, Xian Zhan, Ying Wang 0038, Yepang Liu 0001, Xiapu Luo, Shing-Chi Cheung
ICSE2
2021 DETER: Denial of Ethereum Txpool sERvices
abstract
On an Ethereum node, txpool (a.k.a. mempool) is a buffer storing unconfirmed transactions and controls what downstream services can see, such as mining and transaction propagation. This work presents the first security study on Ethereum txpool designs.
Kai Li 0017, Yibo Wang 0006, Yuzhe Tang
CCS2
2021 TopoShot: uncovering Ethereum's network topology leveraging replacement transactions
abstract
Ethereum relies on a peer-to-peer overlay network to propagate information. The knowledge of Ethereum network topology holds the key to understanding Ethereum's security, availability, and user anonymity. However, an Ethereum network's topology is stored in individual nodes' internal routing tables, measuring which poses challenges and remains an open research problem in the existing literature.
Kai Li 0017, Yuzhe Tang, Yibo Wang 0006, Xianghong Liu
Internet Measurement Conference4
2021 iBatch: saving Ethereum fees via secure and cost-effective batching of smart-contract invocations
abstract
This paper presents iBatch, a middleware system running on top of an operational Ethereum network to enable secure batching of smart-contract invocations against an untrusted relay server off-chain. iBatch does so at a low overhead by validating the server's batched invocations in smart contracts without additional states. The iBatch mechanism supports a variety of policies, ranging from conservative to aggressive batching, and can be configured adaptively to the current workloads. iBatch automatically rewrites smart contracts to integrate with legacy applications and support large-scale deployment.
Yibo Wang 0006, Qi Zhang 0009, Kai Li 0017, Yuzhe Tang, Xiapu Luo, Ting Chen 0002
ESEC/SIGSOFT FSE1