VLDB 2026 Research / reviewers in the wild / expert
Hengkai Ye
dblp:290/9011
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow Integrity
Zhechang Zhang, Hengkai Ye, Hong Hu 0004 |
NDSS | 2 |
| 2025 | Too Subtle to Notice: Investigating Executable Stack Issues in Linux Systems
Hengkai Ye, Hong Hu 0004 |
NDSS | 1 |
| 2023 | VIPER: Spotting Syscall-Guard Variables for Data-Only Attacks
Hengkai Ye, Zhechang Zhang, Hong Hu 0004 |
USENIX Security Symposium | 1 |
| 2022 | BET: black-box efficient testing for convolutional neural networksabstractIt is important to test convolutional neural networks (CNNs) to identify defects (e.g. error-inducing inputs) before deploying them in security-sensitive scenarios. Although existing white-box testing methods can effectively test CNN models with high neuron coverage, they are not applicable to privacy-sensitive scenarios where full knowledge of target CNN models is lacking. In this work, we propose a novel Black-box Efficient Testing (BET) method for CNN models. The core insight of BET is that CNNs are generally prone to be affected by continuous perturbations. Thus, by generating such continuous perturbations in a black-box manner, we design a tunable objective function to guide our testing process for thoroughly exploring defects in different decision boundaries of the target CNN models. We further design an efficiency-centric policy to find more error-inducing inputs within a fixed query budget. We conduct extensive evaluations with three well-known datasets and five popular CNN structures. The results show that BET significantly outperforms existing white-box and black-box testing methods considering the effective error-inducing inputs found in a fixed query/inference budget. We further show that the error-inducing inputs found by BET can be used to fine-tune the target model, improving its accuracy by up to 3%. Jialai Wang, Han Qiu 0001, Hengkai Ye, Qi Li 0002, Zongpeng Li, Chao Zhang 0008 |
ISSTA | 4 |
| 2021 | Interpreting Deep Learning-based Vulnerability Detector Predictions Based on Heuristic SearchingabstractDetecting software vulnerabilities is an important problem and a recent development in tackling the problem is the use of deep learning models to detect software vulnerabilities. While effective, it is hard to explain why a deep learning model predicts a piece of code as vulnerable or not because of the black-box nature of deep learning models. Indeed, the interpretability of deep learning models is a daunting open problem. In this article, we make a significant step toward tackling the interpretability of deep learning model in vulnerability detection. Specifically, we introduce a high-fidelity explanation framework, which aims to identify a small number of tokens that make significant contributions to a detector’s prediction with respect to an example. Systematic experiments show that the framework indeed has a higher fidelity than existing methods, especially when features are not independent of each other (which often occurs in the real world). In particular, the framework can produce some vulnerability rules that can be understood by domain experts for accepting a detector’s outputs (i.e., true positives) or rejecting a detector’s outputs (i.e., false-positives and false-negatives). We also discuss limitations of the present study, which indicate interesting open problems for future research. Deqing Zou, Yawei Zhu, Shouhuai Xu, Zhen Li 0027, Hai Jin 0001, Hengkai Ye |
ACM Trans. Softw. Eng. Methodol. | 6 |