VLDB 2026 Research / reviewers in the wild / expert
Yuzhou Fang
dblp:276/7404
· DBLP profile ↗
8ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Symbolic Execution of Software Under Fault AttacksabstractWe propose a symbolic execution method for analyzing the safety of software under fault attacks both accurately and efficiently. Fault attacks leverage physically injected hardware faults in an embedded system to break the safety of a software program. While there are existing methods for analyzing the impact of maliciously injected hardware faults on the embedded software, they suffer from inaccurate fault modeling and inefficient fault analysis. To overcome these limitations, we propose two novel techniques. First, we propose a new fault modeling technique that leverages automated program transformation to add symbolic variables to the original program, to accurately model the new program behavior induced by the injected faults. This new fault modeling approach has two advantages over existing techniques: (a) the fault-induced program behavior is closely related to what attackers exploit in practice and (b) the automatically transformed program may be analyzed by any downstream fault analysis algorithm. Second, we propose an efficient symbolic execution algorithm that is designed specifically for conducting fault analysis on the transformed program. It leverages two pruning techniques to mitigate path explosion, which is the main performance bottleneck of symbolic execution in general and, in this particular application, is exacerbated by the additional fault-induced program behavior. We have implemented the proposed method and evaluated it on a variety of benchmark programs. The experimental results show that our method significantly outperforms the state-of-the-art techniques. Specifically, our method not only drastically reduces the overall running time of symbolic execution but also retains its error detection capabilities. Compared to the current state-of-the-art, it is able to detect previously-missed safety violations and at the same time avoid bogus violations. Furthermore, compared to the baseline algorithm, our optimized symbolic execution algorithm can be orders-of-magnitude faster. Yuzhou Fang, Chenyu Zhou 0008, Jingbo Wang 0006, Chao Wang 0001 |
ECOOP | 1 |
| 2025 | An Incremental Algorithm for Algebraic Program AnalysisabstractWe propose a method for conducting algebraic program analysis (APA) incrementally in response to changes of the program under analysis. APA is a program analysis paradigm that consists of two distinct steps: computing a path expression that succinctly summarizes the set of program paths of interest, and interpreting the path expression using a properly-defined semantic algebra to obtain program properties of interest. In this context, the goal of an incremental algorithm is to reduce the analysis time by leveraging the intermediate results computed before the program changes. We have made two main contributions. First, we propose a data structure for efficiently representing path expression as a tree together with a tree-based interpreting method. Second, we propose techniques for efficiently updating the program properties in response to changes of the path expression. We have implemented our method and evaluated it on thirteen Java applications from the DaCapo benchmark suite. The experimental results show that both our method for incrementally computing path expression and our method for incrementally interpreting path expression are effective in speeding up the analysis. Compared to the baseline APA and two state-of-the-art APA methods, the speedup of our method ranges from 160× to 4761× depending on the types of program analyses performed. Chenyu Zhou 0008, Yuzhou Fang, Jingbo Wang 0006, Chao Wang 0001 |
Proc. ACM Program. Lang. | 2 |
| 2023 | Beyond "Protected" and "Private": An Empirical Security Analysis of Custom Function Modifiers in Smart ContractsabstractA smart contract is a piece of application-layer code running on blockchain ledgers and it provides programmatic logic via transaction-based execution of pre-defined functions. Smart contract functions are by default invokable by any party. To safeguard them, the mainstream smart contract language, i.e., Solidity of the popular Ethereum blockchain, proposed a unique language-level keyword called “modifier,” which allows developers to define custom function access control policies beyond the traditional “protected” and “private” modifiers in classic programming languages. Yuzhou Fang, Daoyuan Wu, Xiao Yi, Shuai Wang 0011, Mengjie Chen, Yang Liu 0003, Lingxiao Jiang |
ISSTA | 1 |
| 2023 | BlockScope: Detecting and Investigating Propagated Vulnerabilities in Forked Blockchain Projects
Xiao Yi, Yuzhou Fang, Daoyuan Wu, Lingxiao Jiang |
NDSS | 2 |
| 2023 | ESM2-Tree: An maintenance efficient authentication data structure in blockchainabstractBlockchain technology is gaining broader attention. Owing to its immutability property and byzantine fault-tolerance consensus protocol, blockchain offers a brand new trusted data-sharing solution. Some researchers use blockchain to drive autonomous collaboration among smart devices, which face massive spatial data updates and usage. The key challenge lies in designing an authenticated data structure (ADS) that can efficiently process spatial data and queries. However, the previous schemes could not handle spatial data efficiently or did not consider the efficiency of frequent data updates. In this paper, we take a step toward implementing a maintenance-efficient ADS on the blockchain, called ESM2-Tree, which is not only good at processing spatial data but also effective in supporting authenticated spatial queries by partitioning and merging data at different granularities. Theoretical analysis and empirical evaluation validate the performance of our ADS, which reduces the overall data structure maintenance overhead by about 50% in a uniform data distribution scenario. Yuzhou Fang, Liang Cai 0003, Weiwei Qiu, Fanglei Huang, Huaihai Hui |
SSDBM | 1 |
| 2022 | An empirical study of blockchain system vulnerabilities: modules, types, and patternsabstractBlockchain, as a distributed ledger technology, becomes increasingly popular, especially for enabling valuable cryptocurrencies and smart contracts. However, the blockchain software systems inevitably have many bugs. Although bugs in smart contracts have been extensively investigated, security bugs of the underlying blockchain systems are much less explored. In this paper, we conduct an empirical study on blockchain’s system vulnerabilities from four representative blockchains, Bitcoin, Ethereum, Monero, and Stellar. Specifically, we first design a systematic filtering process to effectively identify 1,037 vulnerabilities and their 2,317 patches from 34,245 issues/PRs (pull requests) and 85,164 commits on GitHub. We thus build the first blockchain vulnerability dataset, which is available at https://github.com/VPRLab/BlkVulnDataset. We then perform unique analyses of this dataset at three levels, including (i) file-level vulnerable module categorization by identifying and correlating module paths across projects, (ii) text-level vulnerability type clustering by natural language processing and similarity-based sentence clustering, and (iii) code-level vulnerability pattern analysis by generating and clustering code change signatures that capture both syntactic and semantic information of patch code fragments. Xiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang, Kehuan Zhang, Wei Zhang 0122 |
ESEC/SIGSOFT FSE | 4 |
| 2021 | A novel framework for detecting social bots with deep neural networks and active learning
Yuhao Wu 0006, Yuzhou Fang, Shuaikang Shang, Haizhou Wang 0001 |
Knowl. Based Syst. | 2 |
| 2020 | Detecting Social Spammers in Sina Weibo Using Extreme Deep Factorization Machine
Yuhao Wu 0006, Yuzhou Fang, Shuaikang Shang, Haizhou Wang 0001 |
WISE (1) | 2 |