Zhengjie Ji

dblp:289/2109 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0008-0900-6456ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FIS-FL: Interpretable Data Poisoning Detection in Federated Learning via Feature Importance Shift
Shu-Di Bao, Meng Chen 0013, Zhengjie Ji
ICIC (4)4
2026 RustXec: A Vulnerability Reproduction Dataset for Assessing Security Risks in Open-Source Rust Applications
abstract
Despite Rust’s memory safety guarantees, developers can still introduce security vulnerabilities due to limited security awareness and training. Assessing the security risks of such vulnerabilities is challenging, especially when the resulting failures are not directly observable in the application’s runtime behavior. However, the Rust ecosystem currently lacks reproducible vulnerability datasets, and many vulnerability advisories do not provide proof-of-vulnerability (PoV) examples to demonstrate the issue. As a result, reproducing vulnerabilities from advisory information alone is technically difficult and time-consuming, which limits developers’ ability to recognize and understand security risks in practice.
Zhengjie Ji, Lingxiang Wang, Fan Yang 0023, Ying Zhang 0066
MSR1
2026 How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. Such attacks are known as software supply chain attacks, the documented number of which has increased 742% in 2022. Researchers and developers created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they need code or evidence to demonstrate how library vulnerabilities lead to security exploits, in order to assess vulnerability severity and modification necessity. Unfortunately, manually crafting demos of application-specific attacks is challenging and timeconsuming, and there is insufficient tool support to automate that procedure.To help developers enhance software security, in this study, we systematically explored the usage of a large language model (LLM)–ChatGPT-4.0–to generate security tests, which unit tests demonstrate how vulnerable library dependencies facilitate the supply chain attacks to givenApps. In our exploration, we defined prompt templates to take in the various vulnerability-relevant information we manually collected, and generated prompts from those templates to query ChatGPT for security test generation. We found that ChatGPT-generated tests demonstrated 24 evidence or proof of vulnerability for 49 Apps. To assess the consistency of test generation, we also evaluated another five state-of-the-art LLMs. All the models generated security tests for at least 17 cases that successfully demonstrate the vulnerabilities. We filed six reports for the newly revealed vulnerabilities in Apps, and got four Common Vulnerability Entries (CVEs) assigned. Our use of ChatGPT outperformed two state-of-the-art security test generators (TRANSFER and SIEGE), by generating a lot more tests and achieving more attacks. Our research will shed light on new research in security test generation.
Ying Zhang 0066, Wenjia Song, Zhengjie Ji, Danfeng Yao, Na Meng 0001
IEEE Trans. Software Eng.3
2023 PrivMon: A Stream-Based System for Real-Time Privacy Attack Detection for Machine Learning Models
abstract
Machine learning (ML) models can expose the private information of training data when confronted with privacy attacks. Specifically, a malicious user with black-box access to a ML-as-a-service platform can reconstruct the training data (i.e., model inversion attacks) or infer the membership information (i.e., membership inference attacks) simply by querying the ML model. Despite the pressing need for effective defenses against privacy attacks with black-box access, existing approaches have mostly focused on enhancing the robustness of the ML model via modifying the model training process or the model prediction process. These defenses can compromise model utility and require the cooperation of the underlying AI platform (i.e., platform-dependent). These constraints largely limit the real-world applicability of existing defenses.
Myeongseob Ko, Zhengjie Ji, Hoang Anh Just, Peng Gao 0008, Ruoxi Jia 0001
RAID3
2022 A Knowledge Base Question Answering System for Cyber Threat Knowledge Acquisition
abstract
Open-source cyber threat intelligence (OSCTI) provides a form of evidence-based knowledge about cyber threats, enabling businesses to gain visibility into the fast-evolving threat landscape. Despite the pressing need for high-fidelity threat knowledge, existing cyber threat knowledge acquisition systems have primarily focused on providing low-level, isolated indicators. These systems have ignored the rich higher-level threat knowledge entities and their relationships presented in OSCTI reports, and do not provide a flexible and intuitive way for threat analysts to acquire the desired knowledge. To bridge the gap, we propose ThreatQA, a system that facilitates cyber threat knowledge acquisition via knowledge base question answering. Particularly, ThreatQA uses a combination of AI-based techniques to (1) automatically harvest comprehensive knowledge about trending threats from massive OSCTI reports from various sources and construct a large threat knowledge base, and (2) intelligently respond to an input natural language threat knowledge acquisition question by fetching the answer from the threat knowledge base via question answering.
Zhengjie Ji, Edward Choi 0002, Peng Gao 0008
ICDE1