Hushuang Zeng

dblp:282/5945 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Post-quantum auditing for outsourced storage with probabilistic guarantees
abstract
Auditing outsourced data is a fundamental mechanism for detecting data loss or corruption in untrusted storage environments. Existing auditing schemes rely on public-key primitives based on classical hardness assumptions, which are not secure against quantum adversaries. In this paper, we investigate the issue of post-quantum auditing of outsourced data. We design the PQ-Audit auditing scheme, which utilizes a hash-based signature construction. Specifically, PQ-Audit consists of a small number of hash-based signatures and a hypertree to verify the authenticity of the outsourced data. The data owner signs each outsourced data object before storing it, and the storage server saves these signed data objects for subsequent auditing purposes. However, considering the large size of post-quantum signatures, directly auditing all certified data objects is inefficient. To address this issue, PQ-Audit introduces a sampling-based auditing mechanism that draws inspiration from the provable data possession principle. Audits are conducted on a randomly selected subset of outsourced data objects, which reduces the communication and verification costs during the auditing process and enables efficient auditing. The security analysis demonstrates that PQ-Audit can detect data loss or damage with a probability proportional to the sampling parameter, thereby achieving post-quantum security. Additionally, we conducted a large number of experiments, and the results show that PQ-Audit can efficiently audit large-scale outsourced datasets.
Hushuang Zeng, Lina Chen, Zhede Gu, Shanghao Wu, Jiajie Pan, Yongguang Yan
Peer Peer Netw. Appl.1
2025 Cluster-Based Device Scheduling Design for Semi-Asynchronous Federated Learning in Mobile Edge Computing Networks
abstract
In mobile edge computing (MEC) networks, federated learning (FL) has emerged as the leading distributed framework for training a shared machine learning model, primarily benefiting from its ability to exchange the information of edge devices (EDs) while safeguarding their privacy. However, in MEC networks, the heterogeneity of communication, computation, and data can result in challenges such as stragglers and data imbalances, thereby impeding the training process of FL. To address these challenges, we propose a Semi-Asynchronous Federated Learning (Semi-AFL) framework with cluster-based scheduling. In Semi-AFL, the EDs can perform local training at their own pace using different stale global models to tackle the straggler effect. Considering the asynchronousity of Semi-AFL and data heterogeneity, we propose a cluster-based scheduling strategy that includes device clustering and device selection. Specifically, it performs clustering based on the label distribution and obtains device-to-cluster information. We further select devices based on clustering information as well as model staleness and contribution, aiming to reduce variance and bias and accelerate model convergence. Experiment results demonstrate the effectiveness of the proposed method in reducing the latency of FL.
Hushuang Zeng, Xiuhua Li 0001, Guozeng Xu, Jinlong Hao, Xiaofei Wang 0001, Victor C. M. Leung
ICC1
2021 Mining API Constraints from Library and Client to Detect API Misuses
abstract
Calling Application Programming Interfaces (APIs) shall follow various constraints (e.g., call orders). If these con-straints are violated, API misuses are introduced to code, and such misuses can cause severe bugs. To effectively detect API misuses, most prior approaches mine constraints from client code, and assume that the violations of constraints are potential misuses. However, as client code only illustrates a small portion of API usages, constraints mined from client code are typically incomplete. As a result, when mined constraints are used to detect bugs, many violations of constraints turn out to be false positives. In this paper, our research purpose is to find more misuses and to reduce false positives. As library code contains many details on APIs, we propose an approach that mines API constraints from both client and library code. From client code, our approach builds API usage graphs and uses a frequent subgraph mining algorithm to mine frequent usage patterns as API constraints. From library code, our approach derives various types of constraints with our predefined strategies. With constraints from both sources, our graph matching algorithm can detect API misuses. As a result, our approach takes advantage from both the comprehensiveness and informativeness of library-based constraints and the accuracy of client-based patterns. We compared our approach with MuDetect on the MuBench dataset. Our results show that it significantly improves the detection effectiveness of MuBench from 39.5% to 50.2% of the recall, and from 30.6% to 41.7% of the precision.
Hushuang Zeng, Jingxin Chen, Beijun Shen, Hao Zhong 0001
APSEC1
2021 Locating Faulty Methods with a Mixed RNN and Attention Model
abstract
IR-based fault localization approaches achieves promising results when locating faulty files by comparing a bug report with source code. Unfortunately, they become less effective to locate faulty methods. We conduct a preliminary study to explore its challenges, and identify three problems: the semantic gap problem, the representation sparseness problem, and the single revision problem.To tackle these problems, we propose MRAM, a mixed RNN and attention model, which combines bug-fixing features and method structured features to explore both implicit and explicit relevance between methods and bug reports for method level fault localization task. The core ideas of our model are: (1) constructing code revision graphs from code, commits and past bug reports, which reveal the latent relations among methods to augment short methods and as well provide all revisions of code and past fixes to train more accurate models; (2) embedding three method structured features (token sequences, API invocation sequences, and comments) jointly with RNN and soft attention to represent source methods and obtain their implicit relevance with bug reports; and (3) integrating multi-revision bug-fixing features, which provide the explicit relevance between bug reports and methods, to improve the performance.We have implemented MRAM and conducted a controlled experiment on five open-source projects. Comparing with state-of-the-art approaches, our MRAM improves MRR values by 3.8-5.1% (3.7-5.4%) when the dataset contains (does not contain) localized bug reports. Our statistics test shows that our improvements are significant.
Shouliang Yang, Junming Cao, Hushuang Zeng, Beijun Shen, Hao Zhong 0001
ICPC3
2020 BugPecker: Locating Faulty Methods with Deep Learning on Revision Graphs
abstract
Given a bug report of a project, the task of locating the faults of the bug report is called fault localization. To help programmers in the fault localization process, many approaches have been proposed, and have achieved promising results to locate faulty files. However, it is still challenging to locate faulty methods, because many methods are short and do not have sufficient details to determine whether they are faulty. In this paper, we present BugPecker, a novel approach to locate faulty methods based on its deep learning on revision graphs. Its key idea includes (1) building revision graphs and capturing the details of past fixes as much as possible, and (2) discovering relations inside our revision graphs to expand the details for methods and calculating various features to assist our ranking. We have implemented BugPecker, and evaluated it on three open source projects. The early results show that BugPecker achieves a mean average precision (MAP) of 0.263 and mean reciprocal rank (MRR) of 0.291, which improve the prior approaches significantly. For example, BugPecker improves the MAP values of all three projects by five times, compared with two recent approaches such as DNNLoc-m and BLIA 1.5.
Junming Cao, Shouliang Yang, Hushuang Zeng, Beijun Shen, Hao Zhong 0001
ASE4