VLDB 2026 Research / reviewers in the wild / expert
Peng Chen 0034
dblp:27/7017-34
· DBLP profile ↗
11ranked-venue papers
6as first author
5since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Global Ionospheric VTEC Data Completion Method Based on Aggregated Contextual-Transformation Generative Adversarial NetsabstractThe determination of ionospheric total electron content (TEC) is crucial for various applications in space weather. However, due to the uneven distribution of stations, complex data processing and reconstruction algorithms are usually required to obtain a seamless global TEC map. To reduce the difficulty of this process, we show the possibility of reconstructing a high-resolution global TEC map based on the image inpainting method aggregated contextual-transformation generative adversarial nets (AOT-GANs). First, the AOT-GAN model is used to learn the data fitting process and TEC spatial distribution characteristics in the UQRG, and then the data completion performance and generalization ability of the model are verified under different data-missing conditions and geomagnetic activity levels. The verification results show that the model has relatively reliable completion results under different conditions. The average root mean squared error (RMSE) between the filled results and UQRG is mainly concentrated in$2\sim 3$TECU, and the average structural similarity index measure (SSIM) index is mainly concentrated in$0.95\sim 0.97$. Even during the geomagnetic storm periods and the land data missing rate exceeds 30%, more than 92% of the biases are still within ±5 TECU. In addition, the model can also achieve considerable results when completing CODG, with more than 63% of the biases within ±1 TECU and more than 92% of the biases within ±5 TECU. Finally, the Massachusetts Institute of Technology (MIT)-TEC map is filled using the trained model. When part of MIT-TEC is removed, the biases between the completed result and the original MIT-TEC are relatively small. For the ocean area, the completed MIT-TEC map has the lowest RMSE and the STD level is similar to the ESAG product. The completed MIT-TEC maps not only maintain the global structure of TEC but also have rich details. Yibin Yao, Peng Chen 0034, Leran Fu, Xin Gao 0022 |
IEEE Trans. Geosci. Remote. Sens. | 3 |
| 2024 | Prompt Fuzzing for Fuzz Driver GenerationabstractCrafting high-quality fuzz drivers not only is time-consuming but also requires a deep understanding of the library. However, the state-of-the-art automatic fuzz driver generation techniques fall short of expectations. While fuzz drivers derived from consumer code can reach deep states, they have limited coverage. Conversely, interpretative fuzzing can explore most API calls but requires numerous attempts within a large search space. We propose PromptFuzz, a coverage-guided fuzzer for prompt fuzzing that iteratively generates fuzz drivers to explore undiscovered library code. To explore API usage in fuzz drivers during prompt fuzzing, we propose several key techniques: instructive program generation, erroneous program validation, coverage-guided prompt mutation, and constrained fuzzer scheduling. We implemented PromptFuzz and evaluated it on 14 real-world libraries. Compared with OSS-Fuzz and Hopper (the state-of-the-art fuzz driver generation tool), fuzz drivers generated by PromptFuzz achieved 1.61 and 1.63 times higher branch coverage than those by OSS-Fuzz and Hopper, respectively. Moreover, the fuzz drivers generated by PromptFuzz detected 33 genuine, new bugs out of a total of 49 crashes, out of which 30 bugs have been confirmed by their respective communities. Yunlong Lyu, Peng Chen 0034, Hao Chen 0003 |
CCS | 3 |
| 2023 | Hopper: Interpretative Fuzzing for LibrariesabstractDespite the fact that the state-of-the-art fuzzers can generate inputs efficiently, existing fuzz drivers still cannot adequately cover entries in libraries. Most of these fuzz drivers are crafted manually by developers, and their quality depends on the developers' understanding of the code. Existing works have attempted to automate the generation of fuzz drivers by learning API usage from code and execution traces. However, the generated fuzz drivers are limited to a few specific call sequences by the code being learned. To address these challenges, we present HOPPER, which can fuzz libraries without requiring any domain knowledge to craft fuzz drivers. It transforms the problem of library fuzzing into the problem of interpreter fuzzing. The interpreters linked against libraries under test can interpret the inputs that describe arbitrary API usage. To generate semantically correct inputs for the interpreter, HOPPER learns the intra-and inter-API constraints in the libraries and mutates the program with grammar awareness. We implemented HOPPER and evaluated its effectiveness on 11 real-world libraries against manually crafted fuzzers and other automatic solutions. Our results show that HOPPER greatly outperformed the other fuzzers in both code coverage and bug finding, having uncovered 25 previously unknown bugs that other fuzzers couldn't. Moreover, we have demonstrated that the proposed intra- and inter-API constraint learning methods can correctly learn constraints implied by the library and, therefore, significantly improve the fuzzing efficiency. The experiment results indicate that HOPPER is able to explore a vast range of API usages for library fuzzing out of the box. Peng Chen 0034, Yunlong Lyu, Hao Chen 0003 |
CCS | 1 |
| 2023 | A Novel Approach for Establishing the Global Ionospheric Model With High Spatiotemporal ResolutionabstractThe global ionospheric model is the most effective way to study the structure and variation of the global ionosphere. However, the current global ionosphere maps (GIMs) have the defect of low spatiotemporal resolution and cannot reflect the short-term nonlinear changes and small-scale structures of the vertical total electron content (VTEC). This article proposes a new method for establishing a global ionospheric model with high spatiotemporal resolution. The spherical harmonic (SH) expansions are used to model the VTEC observations, and the Kalman filter is used to estimate the model’s coefficients with high accuracy. The method calculates SH coefficients every 5 min, increasing the spatial resolution to 7.2°. Precise determination methods for the state noise covariance matrix and the observation noise covariance matrix in the Kalman filter are also proposed. The model with a high spatiotemporal resolution was established using the observations of 300 global navigation satellite system (GNSS) tracking stations worldwide. The results show that the model with high spatiotemporal resolution can more finely reflect the nonlinear changes of VTEC in a short period and the small-scale structure of the ionosphere. The accuracy of the high-resolution model is validated using high-precision differential slant total electron content (dSTEC) observations from three sets of tracking stations and compared with the final product of three international GNSS service ionosphere associate analysis centers (IGS IAACs). The results show that the accuracy of the high spatiotemporal resolution model in this article is better than the products of IGS IAACs. The research in this article provides a new idea for establishing GIMs with higher spatiotemporal resolution and accuracy. Peng Chen 0034, Zhiyuan An, Yibin Yao |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2022 | Near Real-Time Global Ionospheric Modeling Based on an Adaptive Kalman Filter State Error Covariance Matrix Determination MethodabstractAiming at the urgent demands on (near) real-time ionosphere products, we study the near real-time (NRT) modeling of the global ionospheric total electron content (TEC) by IGS hourly data and introduce the Kalman filter (KF) to solve the model parameters. The main objective of this article is to propose an adaptive method for determining the KF process noise covariance matrix. This method can reflect the change regularity of spherical harmonic (SH) between epochs and consider the impact of the current ionosphere level on SH. It can adaptively adjust the KF process noise covariance matrix of each epoch to improve the accuracy of NRT global ionosphere maps (GIMs). We analyze the effects of different initial values of the state vector and its covariance matrix on the SH coefficients and propose a method to avoid repeated filter initialization. The results show that for different initial values, the filter can reach the state of convergence within 6 h, but a high-precision initial value can significantly accelerate the KF convergence speed. Compared with Global Navigation Satellite System (GNSS) differential slant TEC (dSTEC) observables, the rms of our NRT products xrtg during quiet and magnetic storms are 1.47 and 1.56 TECU, respectively, larger than the postprocessed GIMs, but significantly smaller than those of real-time GIMs. Compared with Jason VTEC, the results also show that the accuracy of xrtg is even better than European Space Agency (ESA) final products during the magnetic storm. Peng Chen 0034, Yibin Yao, Wanqiang Yao |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2020 | Integrity: Finding Integer Errors by Targeted Fuzzing
Yuyang Rong, Peng Chen 0034, Hao Chen 0003 |
SecureComm (1) | 2 |
| 2020 | GREYONE: Data Flow Sensitive Fuzzing
Shuitao Gan, Chao Zhang 0008, Peng Chen 0034, Bodong Zhao, Xiaojun Qin, Zuoning Chen |
USENIX Security Symposium | 3 |
| 2019 | Matryoshka: Fuzzing Deeply Nested BranchesabstractGreybox fuzzing has made impressive progress in recent years, evolving from heuristics-based random mutation to approaches for solving individual branch constraints. However, they have difficulty solving path constraints that involve deeply nested conditional statements, which are common in image and video decoders, network packet analyzers, and checksum tools. We propose an approach for addressing this problem. First, we identify all the control flow-dependent conditional statements of the target conditional statement. Next, we select the taint flow-dependent conditional statements. Finally, we use three strategies to find an input that satisfies all conditional statements simultaneously. We implemented this approach in a tool called Matryoshka and compared its effectiveness on 13 open source programs against other state-of-the-art fuzzers. Matryoshka has significantly higher cumulative line and branch coverage than AFL, QSYM, and Angora. We manually classified the crashes found by Matryoshka into 41 unique new bugs and obtained 12 CVEs. Our evaluation also uncovered the key technique contributing to Matryoshka's impressive performance: it collects only the nesting constraints that may cause the target conditional statement unreachable, which greatly simplifies the path constraints that it has to solve. Peng Chen 0034, Jianzhong Liu, Hao Chen 0003 |
CCS | 1 |
| 2018 | Angora: Efficient Fuzzing by Principled SearchabstractFuzzing is a popular technique for finding software bugs. However, the performance of the state-of-the-art fuzzers leaves a lot to be desired. Fuzzers based on symbolic execution produce quality inputs but run slow, while fuzzers based on random mutation run fast but have difficulty producing quality inputs. We propose Angora, a new mutation-based fuzzer that outperforms the state-of-the-art fuzzers by a wide margin. The main goal of Angora is to increase branch coverage by solving path constraints without symbolic execution. To solve path constraints efficiently, we introduce several key techniques: scalable byte-level taint tracking, context-sensitive branch count, search based on gradient descent, and input length exploration. On the LAVA-M data set, Angora found almost all the injected bugs, found more bugs than any other fuzzer that we compared with, and found eight times as many bugs as the second-best fuzzer in the program who. Angora also found 103 bugs that the LAVA authors injected but could not trigger. We also tested Angora on eight popular, mature open source programs. Angora found 6, 52, 29, 40 and 48 new bugs infile,jhead,nm,objdumpandsize, respectively. We measured the coverage of Angora and evaluated how its key techniques contribute to its impressive performance. Peng Chen 0034, Hao Chen 0003 |
IEEE Symposium on Security and Privacy | 1 |
| 2016 | POSTER: Security Analysis of Personal Unmanned Aerial Vehicles
Peng Chen 0034, Hao Chen 0003 |
SecureComm | 1 |
| 2014 | An Improved Iterative Algorithm for 3-D Ionospheric Tomography ReconstructionabstractThe computerized ionospheric tomography usually involves solving an ill-posed inversion problem. The sparsity of Global Positioning System (GPS) stations and the limitation of projection angles lead to insufficient data acquisition, thereby preventing the accurate reconstruction of ionospheric-electron-density distributions. In this paper, we investigate and propose a 3-D iterative reconstruction algorithm based on the minimization of total variation under quiescent and disturbed ionospheric conditions. Numerical experiments on GPS simulation data and real data are discussed. In contrast to the improved algebraic reconstruction technique, the proposed algorithm exhibits significantly reconstruction accuracy. Yibin Yao, Jun Tang 0004, Peng Chen 0034 |
IEEE Trans. Geosci. Remote. Sens. | 3 |