Huayang Cao

dblp:25/7555 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
7since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Measuring the Reasoning Boundaries of Large Language Models for Implicit Security Invariants in Code: A Controlled Empirical Study
Ruofei Wang, Honglin Zhuang, Huayang Cao
COMPSAC3
2025 SoK: From Systematization to Best Practices in Fuzz Driver Generation
Minhuan Huang, Huayang Cao, Shuaibing Lu
ACISP (3)3
2025 SeedOrNot: A Classification-Based Framework for Efficient Seed Scheduling in Hybrid Fuzzing
abstract
Hybrid fuzzing combines fast mutation with symbolic execution to detect both shallow and deep vulnerabilities. A core challenge is seed scheduling, which involves selecting inputs for symbolic analysis under limited resources. Existing schedulers often use fixed heuristics or regression models that generalize poorly, leading to unstable prioritization and redundant symbolic exploration. This results in wasted effort and ineffective testing. We introduce SeedOrNot, a lightweight and adaptive framework that formulates seed selection as a binary classification task. It combines an offline classifier with an online learner via a confidence-aware adaptive fusion strategy, achieving both stability and responsiveness. We implement SeedOrNot and evaluate it on six real-world programs. It outperforms heuristic-based (e.g., QSYM) and learning-based (e.g., MEUZZ) fuzzers, with up to $\mathbf{1 4. 1 \%}$ more branch coverage over QSYM and 6.5% over MEUZZ, while adding negligible runtime and memory overhead. Our results demonstrate that classification-based scheduling is a practical and effective method to improve hybrid fuzzing.
Minhuan Huang, Huayang Cao
APSEC3
2025 CTVD: Collaborative Training of Deep Learning and Large Model for C/C++ Source Code Vulnerability Detection
abstract
As software systems grow in complexity, source code vulnerability detection becomes crucial for software security. Existing methods, whether sequence-based or graph-based, face limitations in accurately detecting vulnerabilities. Sequence-based models often struggle with capturing code structure, while graph-based models have difficulty handling long-distance contextual relationships. To overcome these challenges, we propose a collaborative training framework that unifies a graph-based deep learning module and a semantic-rich large model module. The deep learning module, based on graph neural networks (GNNs), captures code structural information, and the large model module, leveraging pre-trained large language models (LLMs), understands code semantics. Through an iterative collaborative training mechanism, the two modules exchange information and learn from each other.Experimental results on three public datasets (Big-Vul, Reveal, and Devign) demonstrate the superiority of our approach. Compared with baseline models, our collaborative training model (CTVD) achieves significant improvements in accuracy, recall, precision, and F1-score. For example, on the Big-Vul dataset, our model’s accuracy reaches 86.5%, outperforming the deep learning module alone by 8.3% and the large model module alone by 6.4%. Compared with the latest co-training method-Vul-LMGNN, CTVD outperforms Vul-LMGNN in the DiverseVul dataset. We applied CTVD in real projects and found seven undisclosed vulnerabilities, all of which were reported and included in the CNNVD. In conclusion, our proposed collaborative training framework effectively combines the strengths of deep learning and large model modules, providing a more accurate and reliable solution for source code vulnerability detection.
Yaning Zheng, Dongxia Wang 0001, Huayang Cao, Honglin Zhuang
SMC3
2024 A New Perspective of Deep Learning Testing Framework: Human-Computer Interaction Based Neural Network Testing
abstract
Deep learning models have revolutionized various domains but have also raised concerns regarding their security and reliability. Adversarial attacks and coverage-based testing have been extensively studied to assess and enhance the dependability of deep neural networks. However, current research in this area has reached a state of stagnation. Adversarial attacks focus on exploiting vulnerabilities in models, while coverage-based testing aims to achieve comprehensive testing but overlooks application scenarios. Moreover, evaluating test cases solely based on their fault-revealing capability is insufficient. To address these limitations, we propose an innovative interdisciplinary framework that incorporates human-computer interaction methods in deep learning security testing. By considering the attributes of model application scenarios, we can design more effective test suites that intend to reveal the model's behavior across various scenarios, aiding in the identification of potential defects. Consequently, the test suite plays a crucial role in the testing process of deep learning models, contributing to the assurance of model robustness and reliability. Additionally, we establish a comprehensive evaluation metric for test suite quality, considering factors such as diversity and naturalness. This framework promotes reliable and secure deployment of deep learning models, fostering interdisciplinary collaboration between artificial intelligence and human-computer interaction.
Qianjin Du, Huayang Cao, Xiaohui Kuang
ICRA4
2023 Test Suite Generation Based on Context-Adapted Structural Coverage for Testing DNN
Qianjin Du, Huayang Cao, Jianwen Tian, Xiaohui Kuang
APNOMS3
2023 A Study on Vulnerability Code Labeling Method in Open-Source C Programs
Yaning Zheng, Dongxia Wang 0001, Huayang Cao, Xiaohui Kuang, Honglin Zhuang
DEXA (1)3
2017 Fuzzing the Font Parser of Compound Documents
abstract
Currently, complex software (e.g. PDF readers) usually takes various inputs embedded with multiple objects (e.g. fonts, pictures), which may result in bugs. It is a challenge to generate suitable test cases to support fine-grained test to the PDF readers. Compared with the traditional blind fuzzing which does not utilize the information of input grammars, fuzzing with the model of the file format is an effective technique. In this paper, we leverage the structure information of the font files to select seed files among the heterogeneous fonts. A general construction method for generating suitable test cases is proposed. By this means, we can obtain test cases with low overhead. Moreover, to improve the expression ability of the font template in fuzzing PDF readers, we combine file reconstruction and template description. Our methods are evaluated on five common-used PDF readers, and proved effective in triggering crashes.
Hongliang Liang, Huayang Cao
CSCloud3
2009 A Packet-Based Anomaly Detection Model for Inter-domain Routing
abstract
The current implementation of BGP protocol has a variety of vulnerabilities and weakness. Monitoring BGPpsilas behavior is an effective way to improve the security of inter-domain routing. Due to the difficulty of obtaining routing tables from autonomous systems, a packet-based model for detecting routing anomalies is presented. This model contains data collectors, anomaly detection engine, routing information database and result visualization module. A rule-based approach is designed, and the combined usage of rules and routing information database is proved to be effective on improving the accuracy of detection. Experiment results show that model performs well in detecting various anomalies. The feasibility and validity of the detecting approach are demonstrated by the detailed description of the deployment and performance analysis.
Huayang Cao, Peidong Zhu
NAS1
2009 TTM Based Security Enhancement for Inter-domain Routing Protocol
abstract
Border gateway protocol (BGP) acts as a vital part of the global infrastructure. Attacks against BGP are increasing in number and severity. Unfortunately, most security mechanisms based on public key cryptography suffer from performance, trust model and other issues. This paper proposes a solution that takes advantages of the power-law and rich-club features of the AS-level topology, and proposes the notion of AS Alliance and a new trust model - translator trust model (TTM). TTM avoids the global distribution of certificates by trust translating between different trust domains. It achieves that with much less memory overhead than traditional solutions, and a shorter validation chain. We develop a novel SE-BGP (security enhanced BGP) mechanism based on TTM. It introduces new path attributes to carry origin certificates and path signatures, and the algorithms to process origin authentication and path authentication. Our analyses indicate that SE-BGP is a viable solution.
Peidong Zhu, Xiangjiang Hu, Huayang Cao
NCA3