Songyan Ji

dblp:264/3639 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0004-2068-9244ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Harmonia: Enhancing Liveness in Two-Phase HotStuff Without Sacrificing Core Properties
abstract
HotStuff stands out as the first Byzantine Fault Tolerant (BFT) state machine replication protocol to achieve linear communication complexity while maintaining optimistic responsiveness and fairness. However, it is required at least three phases to commit a block, which leads to high latency. Recent studies have focused on developing two-phase variants of HotStuff to reduce its block commitment latency. Nonetheless, two-phase HotStuff suffers from the liveness issue, forcing these protocols to sacrifice one of the three fundamental properties of HotStuff when addressing this problem, thereby facing a trade-off among these properties. In this paper, we introduce a novel protocol, Harmonia, which, to the best of our knowledge, is the first BFT protocol to simultaneously achieve linear communication complexity, optimistic responsiveness, fairness, and the minimum commit latency of two phases. Harmonia overcomes the liveness issue of two-phase HotStuff through its specialized block unlocking mechanism while preserving all the original properties of HotStuff. Experimental results show that Harmonia consistently outperforms HotStuff across various metrics.
Songyan Ji, Jian Dong 0010
SRDS3
2023 A Guided Mutation Strategy for Smart Contract Fuzzing
abstract
Smart contracts manage a large number of digital assets which is attractive to attackers. There have been many attacks that have caused huge financial losses. Therefore, it is of great importance to detect vulnerabilities in smart contracts. Fuzzing is considered a promising approach to test smart contracts. However, the complexity of changing state variables and the handling of external parameters during mutation pose critical technical challenges for current smart contract fuzzers, hindering their ability to cover branches under complex constraints and leaving potential vulnerabilities for attackers to exploit. To tackle these problems, we design a guided mutation strategy combined with two novel techniques: Dynamic Dependency Learning (DDL) and Dynamic Variables Analysis (DVA). DDL learns the dependencies of sequences to provide guided transaction sequence generation for handling state variables in complex constraints, while DVA leverages variable-level dynamic taint analysis to process the external parameters and guide the mutation. We implement the proposed strategy on a fuzzer, called SeqFuzz. The experimental results show that SeqFuzz could cover more branches and detect more bugs in real-world smart contracts compared with state-of-the-art tools.
Songyan Ji, Jian Dong 0010, Lishi Lu
ICSME1
2023 Effuzz: Efficient fuzzing by directed search for smart contracts
Songyan Ji, Junfu Qiu, Jian Dong 0010
Inf. Softw. Technol.1
2021 Increasing Fuzz Testing Coverage for Smart Contracts with Dynamic Taint Analysis
abstract
Nowadays, smart contracts manage more and more digital assets and have become an attractive target for adversaries. To prevent smart contracts from malicious attacks, a thorough test is indispensable and must be finished before deployment because smart contracts cannot be modified after being deployed. Fuzzing is an important testing approach, but most existing smart contract fuzzers can hardly solve the constraints which involve deeply nested conditional statements, resulting in low coverage. To address this problem, we propose Targy, an efficient targeted mutation strategy based on dynamic taint analysis. We obtain the taint flow by dynamic taint propagation, and generate a more accurate mutation strategy for the input parameters of functions to simultaneously satisfy all conditional statements. We implemented Targy on sFuzz with 3.6 thousand smart contracts running on Ethereum. The numbers of covered branches and detected vulnerabilities increase by 6% and 7% respectively, and the average time required for covering a branch is reduced by 11 %.
Songyan Ji, Jian Dong 0010, Junfu Qiu, Bowen Gu, Tongqi Wang
QRS1