Wenfeng Lin

dblp:29/2261 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 1 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 SVRM: Composing Various Network Service Fuzzing Corpus with One Single Model
abstract
Discovering vulnerabilities in network service is of great significance. Currently, coverage-guided fuzzing (CGF) is widely regarded as the most effective method. However, the efficiency of CGF depends on the quality of initial corpus. The initial corpus is a set of valid input examples used to initiate the fuzzing process. Constructing high-quality initial corpus typically requires manual efforts to understand the implementation details and corresponding protocol specifications, making it difficult to generalize across different protocol implementations.To generate high-quality corpus tailored to service under test (SUT), this paper proposes a protocol-independent smart generation method. The paper introduces a novel service communication model and utilizes active learning algorithms to automatically construct the model. By analyzing the minimum spanning tree of the model, we achieve automatic generation of high-quality corpus that adapts to the SUT.We conduct experiment by generating adaptive corpus for 6 targets of 6 different protocols in ProFuzzBench. Compared to the corpus provided by ProFuzzBench, the corpus generated by our system improve the state coverage of modern protocol fuzzers by 37.1% and discover known real protocol vulnerabilities at a speed 2.47x faster.
Wenfeng Lin, Zhiyuan Jiang, Fangliang Xu, Yunfei Su, Lingchu Mao, Chaojing Tang
ICASSP1
2025 ProAnalyzer: Inferring Network Service's Fuzzing Format with Grey-Box Metric
Wenfeng Lin, Yunfei Su, Chaojing Tang
ICIC (4)1
2025 RPFUZZ: Efficient network service fuzzing via pruning redundant mutation
abstract
Coverage-guided fuzzing (CGF) has proven its outstanding performance on vulnerability detection. However, existing approaches exhibit limitations when handling network service. Restricted by network I/O duration and chronology, long packet sequences crafted by fuzzers incur a substantial execution cost. Test cases with such non-coverage-improving mutations (i.e. redundant mutation) can significantly reduce fuzzing throughput and compromise vulnerability discovery. To address this issue, we propose RPFUZZ, a novel network fuzzing framework designed to systematically reduce redundant mutations: (1) We propose redundant mutation pruning for network service fuzzing. By early terminating redundant mutations’ execution, RPFUZZ can achieve higher throughput. (2) To detect redundant mutation, we propose redundant mutation oracle. This oracle dynamically judges whether a test case is redundant according to current code coverage and value of service-related variables (SRVs). (3)To identify SRVs, we propose an integrated approach combining dynamic call stack analysis with static value-flow graph (VFG) analysis. To evaluate the performance of RPFUZZ, we implement a prototype on top of NYX-NET. We conduct thorough experiments on ProFuzzBench, a benchmark that consists of 12 real-world network services. The results indicate that RPFUZZ achieves over 185% improvement in throughput and 1.02% rise in code coverage compared with NYX-NET. Besides, RPFUZZ has successfully uncovered 1753 unique crashes across 6 network services, including an unreported vulnerability (assigned to CVE-2024-57392) in ProFTPD, which has been well tested. • We propose redundant mutation pruning technique for network service fuzzing. By pruning mutated suffix packet sequence which is non-coverage-improving, network service fuzzer can achieve higher throughout. This is achieved by redundant mutation oracle, which leverage code coverage and identified service-related variables’ (SRVs) value to decide whether continuing current execution is advisable. • To precisely identify SRVs in network services, we propose an identification method combining with call stack analysis and value-flow graph analysis. This method is based on SRV’s programming features, which can be applied in various network service. • Based on technique above, We implement RPFUZZ. RPFUZZ achieved more than 185.92% (average 56.39%) throughput enhancement over NYX-NET, while improving maximum 4.27% code coverage (average +1.02%). It successfully identified 1753 unique crashes across 6 targets without ASAN and a buffer overflow vulnerability in ProFTPD (assigned CVE-2024-57392).
Wenfeng Lin, Fangliang Xu, Zhiyuan Jiang, Chaojing Tang
Comput. Secur.1
2023 Towards Automatic and Precise Heap Layout Manipulation for General-Purpose Programs
Runhao Li, Jiongyi Chen, Wenfeng Lin, Chao Feng 0002, Chaojing Tang
NDSS4
2007 Scaled Matched Filter Based Iterative Receiver for Coded MIMO-OFDM Systems
abstract
In this paper, we propose a reduced complexity iterative receiver for coded multiple-input multiple-output (MIMO) orthogonal frequency division multiplexing (OFDM) systems. We apply the matched filter (MF) in the proposed scheme, which is a popular alternative to the minimum mean square error (MMSE) detector due to its lower computational complexity. We improve the well studied MF-based iterative MIMO soft-detector by scaling the value of the a priori information from a soft-in soft-out (SISO) channel decoder. The scaling factor is optimized according to the extrinsic information transfer (EXIT) chart of the SISO detector. Simulation results show that the proposed MF- based iterative receiver significantly outperforms the conventional one with little additional cost in computational complexity and achieves bit error rate (BER) performance comparable to that of the MMSE-based iterative receiver with much lower complexity.
Wenfeng Lin
GLOBECOM1
2007 A Low Complexity Iterative Receiver for Coded MIMO-OFDM Systems
abstract
A novel low-complexity iterative receiver for coded multiple-input multiple-output (MIMO) orthogonal frequency division multiplexing (OFDM) systems is proposed in this paper. The soft-in soft-out (SISO) detector is simply a parallel interference cancellation (PIC) -maximum ratio combining (MRC) operation. Usually, the probability density function (PDF) of PIC-MRC detector output is approximated as Gaussian, whose variance is calculated with soft information fed back from the channel decoder. With this approximation, the log likelihood ratios (LLRs) of transmitted bits are under-estimated. Thus the LLRs are multiplied by a constant factor to achieve a performance gain. The constant factor is optimized according to the extrinsic information transfer (EXIT) chart of the channel decoder. Simulation results show that the proposed iterative receiver can significantly improve the system performance and converge to the matched filter bound (MFB) with low computational complexity at high signal-to-noise ratios (SNRs).
Wenfeng Lin
ICASSP (3)1