Yuqing Niu

dblp:264/6579 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Shielding MCP Tool: A Secure Execution Framework Using TEE and Automated Trimming
Ruidong Han, Chengyan Ma 0001, Ye Liu 0012, Yuqing Niu, David Lo 0001
ACISP (1)4
2026 What You Trust is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
Yuqing Niu, Jieke Shi, Ruidong Han, Ye Liu 0012, Chengyan Ma 0001, Yunbo Lyu, David Lo 0001
SANER1
2026 Automated TEE Adaptation With LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
Ruidong Han, Zhou Yang 0003, Chengyan Ma 0001, Ye Liu 0012, Yuqing Niu, Siqi Ma 0001, Debin Gao, David Lo 0001
IEEE Trans. Software Eng.5
2026 Towards Secure Program Partitioning for Smart Contracts With LLM's In-Context Learning
abstract
Smart contracts are highly susceptible to manipulation attacks due to the leakage of sensitive information. Addressing manipulation vulnerabilities is particularly challenging because they stem from inherent data confidentiality issues rather than straightforward implementation bugs. To tackle this by preventing sensitive information leakage, we present PARTITIONGPT, the first LLM-driven approach that combines static analysis with the in-context learning capabilities of large language models (LLMs) to partition smart contracts into critical (privileged) and normal codebases, guided by a few annotated sensitive data variables. We evaluated PARTITIONGPT on 18 annotated smart contracts containing 99 sensitive functions. The results demonstrate that PARTITIONGPT successfully generatescompilable, andverifiedpartitions, achieving a precision of 80% while reducing more than 26% code compared to functionlevel partitioning approach. Furthermore, we evaluated PARTITIONGPT on nine real-world manipulation attacks that led to a total loss of 25 million dollars, PARTITIONGPT effectively prevents eight cases, highlighting its potential for broad applicability and the necessity for secure program partitioning during smart contract development to diminish manipulation vulnerabilities.
Ye Liu 0012, Yuqing Niu, Chengyan Ma 0001, Ruidong Han, Wei Ma 0014, Yi Li 0008, Debin Gao, David Lo 0001
IEEE Trans. Software Eng.2
2025 Do Existing Testing Tools Really Uncover Gender Bias in Text-to-Image Models?
abstract
Text-to-Image (T2I) models have recently gained significant attention due to their ability to generate high-quality images and are consequently used in a wide range of applications. However, there are concerns about the gender bias of these models. Previous studies have shown that T2I models can perpetuate or even amplify gender stereotypes when provided with neutral text prompts (e.g., 'a photo of a CEO' is often associates with male images, while 'a photo of nurse' is often associates with female images). Researchers have proposed automated gender bias uncovering detectors for T2I models, but a crucial gap exists: no existing work comprehensively compares the various detectors and understands how the gender bias detected by them deviates from the actual situation. This study addresses this gap by validating previous gender bias detectors using a manually labeled dataset and comparing how the bias identified by various detectors deviates from the actual bias in T2I models, as verified by manual confirmation. We create a dataset consisting of 6,000 images generated from three cutting-edge T2I models, Stable Diffusion XL, Stable Diffusion 3, and Dreamlike Photoreal 2.0. During the human-labeling process, we find that all three T2I models generate a portion (12.48% on average) of low-quality images (e.g., generate images with no face present), where human annotators cannot determine the gender of the person. Our analysis reveals that all three T2I models show a preference for generating male images, with SDXL being the most biased. Additionally, images generated using prompts containing professional descriptions (e.g., lawyer or doctor) show the most bias. We evaluate seven gender bias detectors and find that none fully capture the actual level of bias in T2I models, with some detectors overestimating bias by up to 26.95%. We further investigate the causes of inaccurate estimations, highlighting the limitations of detectors in dealing with low-quality images. Based on our findings, we propose an enhanced detector called CLIP-Enhance, which most accurately measures the gender bias in T2I models, with a difference of only 0.47%-1.23%, and most effectively filters out 82.91% of low-quality images.1 We have made our dataset and code publicly available.
Yunbo Lyu, Zhou Yang 0003, Yuqing Niu, Jing Jiang 0001, David Lo 0001
ACM Multimedia3
2025 A Privacy-Preserving Federated Reinforcement Learning Method for Multiple Virtual Power Plants Scheduling
abstract
The application of federated learning in Virtual Power Plants (VPPs) addresses the data silo issue between VPPs and enhances their ability to cope with nonlinear and stochastic scheduling characteristics, which enables VPPs better accommodate distributed energy resources and flexible loads while participating in frequency regulation services. However, although existing federated learning methods strive to solve privacy protection issues, the plaintext transmission of gradients still exposes sensitive data to the threat of curious power control centers and external inference attacks. Therefore, a privacy-protected horizontal federated reinforcement learning approach for multi-VPP optimal scheduling is proposed in this paper. Firstly, a cost-based global optimization scheduling model for multiple VPPs is constructed, modeling the internal scheduling process of VPPs as a Markov decision process. Then, an improved secure horizontal federated multi-VPP collaborative training method is presented, and local models are trained using the Deep Transformer Q-Network algorithm, with local differential privacy and CKKS homomorphic encryption implemented to ensure privacy protection. Finally, a case study is conducted using frequency regulation ancillary service market data and the IEEE-39 bus system structure. Simulation results show that the proposed approach outperforms similar algorithms, achieving high levels of privacy protection and economic operation for VPPs.
Ting Yang 0002, Xiangwei Feng, Shaotang Cai, Yuqing Niu, Haibo Pen
IEEE Trans. Circuits Syst. I Regul. Pap.4
2022 Crex: Predicting patch correctness in automated repair of C programs through transfer learning of execution semantics
Kui Liu 0001, Yuqing Niu, Li Li 0029, Zhe Liu 0001, Zhiming Liu 0001, Jacques Klein, Tegawendé F. Bissyandé
Inf. Softw. Technol.3
2021 Estimating the Attack Surface from Residual Vulnerabilities in Open Source Software Supply Chain
abstract
Software supply chain security has now become a critical concern in the software industry (and beyond) following the large impact of recent attacks: hackers injected malicious code into Solarwinds components and Octopus scanner, which eventually infected a wide range of downstream dependencies, affecting a massive number of users. Since supply chain vulnera-bilities are a well-known concern, especially with open source systems, approaches in the literature mainly focus on identifying and patching such vulnerability. Frequently, however, a vulnerability patch is not immediately propagated to earlier releases that have been inherited by dependents, leaving residual vulnerabilities in supply chains. Our work addresses this challenge and develops a simple approach to iteratively explore the attack surface of supply chain residual vulnerabilities in open source projects. We have assessed our search scheme on 50 GitHub-hosted projects having high stars and forks: we mine their bug fix commits and identify buggy package versions to track the affected dependents and estimate the potential attack surface. We find that many projects fix their vulnerable issues by update their dependency versions, and version inheritance is a significant cause of supply chain attacks for open source projects.
Yuqing Niu, Kui Liu 0001, Zhe Liu 0001, Zhiming Liu 0001, Tegawendé F. Bissyandé
QRS2