Wai Kin Wong

dblp:277/4886 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 No More Translation at Runtime: LLM-Empowered Static Binary Translation
abstract
While AArch64 CPUs are becoming strong market contenders, their software ecosystem lags behind the mature x86-64 environment, hindering the adoption of the new architectures and impacting user experience. Binary translation bridges this divide by converting binary code from one architecture (e.g., x86-64) to run on another (e.g., AArch64), allowing legacy software to benefit from modern hardware's performance and energy efficiency advantages.
Zhibo Liu 0001, Huaijin Wang 0001, Wai Kin Wong, Daoyuan Wu, Shuai Wang 0011
EuroSys3
2025 Extraction and Mutation at a High Level: Template-Based Fuzzing for JavaScript Engines
abstract
JavaScript (JS) engines implement complex language semantics and optimization strategies to support the dynamic nature of JS, making them difficult to test thoroughly and prone to subtle, security-critical bugs. Existing fuzzers often struggle to generate diverse and valid test cases. They either rely on syntax-level mutations that lack semantic awareness or perform limited, local mutations on concrete code, thus failing to explore deeper, more complex program behaviors. This paper presents TemuJs , a novel fuzzing framework that performs extraction and mutation at a high level, operating on abstract templates derived from real-world JS programs. These templates capture coarse-grained program structures with semantic placeholders, enabling semantics-aware mutations that preserve the high-level intent of the original code while diversifying its behavior. By decoupling mutation from concrete syntax and leveraging a structured intermediate representation for the templates, TemuJs explores a broader and more meaningful space of program behaviors. Evaluated on three major JS engines, namely, V8, SpiderMonkey, and JavaScriptCore, TemuJs discovers 44 bugs and achieves a 10.3% relative increase in edge coverage compared to state-of-the-art fuzzers on average. Our results demonstrate the efficacy of high-level, template-mutation fuzzing in testing JS engines.
Wai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Yiteng Peng, Daoyuan Wu, Shuai Wang 0011
Proc. ACM Program. Lang.1
2024 BinAug: Enhancing Binary Similarity Analysis with Low-Cost Input Repairing
abstract
Binary code similarity analysis (BCSA) is a fundamental building block for various software security, reverse engineering, and re-engineering applications. Existing research has applied deep neural networks (DNNs) to measure the similarity between binary code, following the major breakthrough of DNNs in processing media data like images. Despite the encouraging results of DNN-based BCSA, it is however not widely deployed in the industry due to the instability and the black-box nature of DNNs.
Wai Kin Wong, Huaijin Wang 0001, Zongjie Li, Shuai Wang 0011
ICSE1
2024 Evaluating C/C++ Vulnerability Detectability of Query-Based Static Application Security Testing Tools
abstract
In recent years, query-based static application security testing (Q-SAST) tools such as CodeQL have gained popularity due to their ability to codify vulnerability knowledge into SQL-like queries and search for vulnerabilities in the database derived from the software. The industry has made considerable progress in building Q-SAST tools, facilitating their integration into the continuous integration (CI) pipeline, and sustaining an active community. However, we do not have a systematic understanding of their vulnerability detection capability in comparison to conventional SAST tools. We conduct the first in-depth study of Q-SAST to demystify their C/C++ vulnerability detectability. Our study is conducted from three complementary aspects. We first use a synthetic CWE test suite and a real-world CVE test suite, totaling almost 30K programs with known CWE/CVE, to assess popular (commercial) Q-SAST and industry-leading SAST (requiring no queries). Then, we gather defect-fixing pull requests (PRs) since the release dates of three popular Q-SAST tools, characterizing historically-fixed defects and comparing them to pitfalls exposed in our CWE/CVE study. To enhance vulnerability detection, we design SAST-MT, a metamorphic testing framework to detect false positives (FPs) and false negatives (FNs) of Q-SAST. Findings of SAST-MT can be used to easily expose the root causes of Q-SAST's FPs and FNs. We summarize lessons from our study that can benefit both users and developers of Q-SAST.
Zongjie Li, Zhibo Liu 0001, Wai Kin Wong, Pingchuan Ma 0004, Shuai Wang 0011
IEEE Trans. Dependable Secur. Comput.3
2023 Skillful Radar-Based Heavy Rainfall Nowcasting Using Task-Segmented Generative Adversarial Network
abstract
Accurate and timely rainfall nowcasting is important for protecting the public from heavy rainfall-induced disasters. In recent years, deep-learning models have been demonstrated to significantly outperform traditional methods in heavy rainfall nowcasting. However, the performance of existing deep-learning-based nowcasting models is still restricted by limited forecast skill, and the rapid growth of blurriness increases in forecast time. In this work, we propose a novel heavy rainfall nowcasting model based on an innovative task-segmented architecture, namely the TS-RainGAN, consisting of two modules: the MaskPredNet predicts the spatial coverage of different rainfall categories to provide bounding for rainfall with various intensities, and the IntensityGAN predicts the intensity of rainfall based on the rainfall coverage produced by the MaskPredNet. The TS-RainGAN can accurately capture the spatiotemporal features and evolutions of rainfall systems and provide skillful precipitation prediction with high skill scores up to 2 hours compared with the results of the widely used baseline models. Meanwhile, the blurriness of the predicted images is significantly reduced. This enables district-level heavy rainfall nowcasting with competitive forecast skills.
Rui Wang 0104, Wai Kin Wong, Alexis Kai-Hon Lau, Jimmy C. H. Fung
IEEE Trans. Geosci. Remote. Sens.3
2022 Deceiving Deep Neural Networks-Based Binary Code Matching with Adversarial Programs
abstract
Deep neural networks (DNNs) have achieved a major success in solving challenging tasks such as social networks analysis and image classification. Despite the prosperous development of DNNs, recent research has demonstrated the feasibility of exploiting DNNs using adversarial examples, in which a small distortion is added into the input data to largely mislead prediction of DNNs.Determining the similarity of two binary codes is the foundation for many reverse engineering, re-engineering, and security applications. Currently, the majority of binary code matching tools are based on DNNs, the dependability of which has not been completely studied. In this research, we present an attack that perturbs software in executable format to deceive DNN-based binary code matching. Unlike prior attacks which mostly change non-functional code components to generate adversarial programs, our approach proposes the design of several semantics-preserving transformations directly toward the control flow graph of binary code, making it particularly effective to deceive DNNs. To speedup the process, we design a framework that leverages gradient- or hill climbing-based optimizations to generate adversarial examples in both white-box and black-box settings. We evaluated our attack against two popular DNN-based binary code matching tools, asm2vec and ncc, and achieve reasonably high success rates. Our attack toward an industrial-strength DNN-based binary code matching service, BinaryAI, shows that the proposed attack can fool remote APIs in challenging black-box settings with a success rate of over 16.2% (on average). Furthermore, we show that the generated adversarial programs can be used to augment robustness of two white-box models, asm2vec and ncc, reducing the attack success rates by 17.3% and 6.8% while preserving stable, if not better, standard accuracy.
Wai Kin Wong, Huaijin Wang 0001, Pingchuan Ma 0004, Shuai Wang 0011, Mingyue Jiang, Tsong Yueh Chen, Qiyi Tang 0003, Sen Nie, Shi Wu
ICSME1