VLDB 2026 Research / reviewers in the wild / expert
Zeqin Liao
dblp:291/2034
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0003-0306-7465ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 4 first-author · 6 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detecting and Analyzing Fine-grained Third-party Library Dependencies in Solidity Smart ContractsabstractSolidity is the primary programming language for writing smart contracts. As a lightweight language, Solidity does not have a unified way to manage third-party library (TPL) dependencies. Instead, the copy-and-paste pattern and other dependency managers such as NPM and Git submodules have become alternatives. However, these mechanisms significantly increase the complexity of TPL usage with security concerns. Similar to other programming language ecosystems, incorrect TPL usage can influence the reliability of contracts and even introduce vulnerabilities from outdated versions. Therefore, there is an urgent need to understand and comprehend Solidity TPL dependencies. In this work, we conduct a comprehensive study on TPL dependency usage in Solidity. To achieve this, we first present SPADE , which leverages additional metadata (e.g., package and remapping configurations) to infer fine-grained TPL dependencies with version and contract details in various Solidity projects. With SPADE , we investigate a broad spectrum of 5,242 Solidity repositories to understand the TPL dependencies, including their landscape and version-level usage. Our research reveals a set of interesting and important findings that can be beneficial to the Solidity ecosystem. In particular, TPL dependencies are prevalent in Solidity, but the version management remains inadequate. The propagation of vulnerability is severe, affecting 8.87% of the repositories. Finally, we use on-chain contracts to validate the findings and provide suggestions for future research and development on Solidity TPL dependencies. Sicheng Hao 0001, Yuhong Nan, Zeqin Liao, Juan Zhai, Zibin Zheng |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | VRExplorer: A Model-based Approach for Semi-Automated Testing of Virtual Reality ScenesabstractWith the proliferation of Virtual Reality (VR) markets, VR applications are rapidly expanding in scale and complexity, thereby driving an urgent need for assuring VR software quality. Different from traditional mobile applications and computer software, VR testing faces unique challenges due to diverse interactions with virtual objects, complex 3D virtual environments, and intricate sequences to complete tasks. All of these emerging challenges hinder existing VR testing tools from effectively and systematically testing VR applications. In this paper, we present VRExplorer, a novel model-based testing tool to effectively interact with diverse virtual objects and explore complex VR scenes. Particularly, we design the Entity, Action, and Task (EAT) framework for modeling diverse VR interactions in a generic way. Built upon the EAT framework, we then present the VRExplorer agent, which can achieve effective scene exploration by incorporating meticulously designed path-finding algorithms into Unity’s NavMesh. Moreover, the VRExplorer agent can also systematically execute interaction decisions on top of the Probabilistic Finite State Machine (PFSM). Experimental evaluation on 11 representative VR projects shows that VRExplorer consistently outperforms the state-of-the-art (SOTA) approach VRGuide by achieving significantly higher coverage and better efficiency. Specifically, VRExplorer yields up to 122.8% and 52.8% improvements over VRGuide in terms of executable lines of code (ELOC) coverage and method (function) coverage, respectively. Furthermore, ablation results also verify the essential contributions of each designed module. More importantly, our VRExplorer has successfully detected two functional bugs and one non-functional bug from real-world projects. Zhengyang Zhu, Hongning Dai, Hanyang Guo, Zeqin Liao, Zibin Zheng |
ASE | 4 |
| 2025 | Augmenting Smart Contract Decompiler Output Through Fine-Grained Dependency Analysis and LLM-Facilitated Semantic RecoveryabstractDecompiler is a specialized type of reverse engineering tool extensively employed in program analysis tasks, particularly in program comprehension and vulnerability detection. However, current Solidity smart contract decompilers face significant limitations in reconstructing the original source code. In particular, the bottleneck of SOTA decompilers lies in inaccurate function identification, incorrect variable type recovery, and missing contract attributes. These deficiencies hinder downstream tasks and understanding of the program logic. To address these challenges, we propose SmartHalo, a new framework that enhances decompiler output by combining static analysis (SA) and large language models (LLM). SmartHalo leverages the complementary strengths of SA’s accuracy in control and data flow analysis and LLM’s capability in semantic prediction. More specifically, SmartHalo constructs a new data structure - Dependency Graph (DG), to extract semantic dependencies via static analysis. Then, it takes DG to create prompts for LLM optimization. Finally, the correctness of LLM outputs is validated through symbolic execution and formal verification. Evaluation on a dataset consisting of 465 randomly selected smart contract functions shows that SmartHalo significantly improves the quality of the decompiled code, compared to SOTA decompilers (e.g., Gigahorse). Notably, integrating GPT-4o mini with SmartHalo further enhances its performance, achieving a precision of 91.32% and a recall of 87.38% for function boundaries, a precision of 90.40% and a recall of 88.82% for variable types, and a precision of 80.66% and a recall of 91.78% for contract attributes. Zeqin Liao, Yuhong Nan, Zixu Gao, Henglong Liang, Sicheng Hao 0001, Peifan Reng, Zibin Zheng |
IEEE Trans. Software Eng. | 1 |
| 2025 | Satellite: Detecting and Analyzing Smart Contract Vulnerabilities Caused by Subcontract MisuseabstractCode reuse is a common practice in software engineering. Developers of smart contracts pervasively reuse subcontracts to improve development efficiency. Like any program language, such subcontract reuse may unexpectedly include, or introduce vulnerabilities to the end-point smart contract. Indeed, prior empirical studies have identified a number of issues caused by code reuse in smart contracts. Unfortunately, automatically detecting such issues poses several unique challenges. Particularly, in most cases, smart contracts are compiled as bytecode, whose class-level information (e.g., inheritance, virtual function table), and even semantics (e.g., control flow and data flow) are fully obscured as a single smart contract after compilation. Therefore, it is rather difficult to identify the reused parts of subcontract from a given smart contract, not to mention finding potential vulnerabilities caused by subcontract misuse.In this paper, we propose Satellite, a new bytecode-level static analysis framework for subcontract misuse vulnerability (SMV) detection in smart contracts. Satellite incorporates a series of novel designs to enhance its overall effectiveness.. Particularly, Satellite utilizes a transfer learning method to recover the inherited methods, which are critical for identifying subcontract reuse in smart contracts. Further, Satellite extracts a set of fine-grained method-level features and performs a method-level comparison, for identifying the reuse part of subcontract in smart contracts. Finally, Satellite summarizes a set of SMV indicators according to their types, and hence effectively identifies SMVs. To evaluate Satellite, we construct a dataset consisting of 58 SMVs derived from real-world attacks and collect additional 56 SMV patterns from SOTA studies. Experiment results indicate that Satellite exhibits good performance in identifying SMV, with a precision rate of 84.68% and a recall rate of 92.11%. In addition, Satellite successfully identifies 14 new/unknown SMV over 10,011 realworld smart contracts, affecting a total amount of digital assets worth 201,358 USD. Zeqin Liao, Yuhong Nan, Zixu Gao, Henglong Liang, Sicheng Hao 0001, Jiajing Wu, Zibin Zheng |
IEEE Trans. Software Eng. | 1 |
| 2023 | SmartState: Detecting State-Reverting Vulnerabilities in Smart Contracts via Fine-Grained State-Dependency AnalysisabstractSmart contracts written in Solidity are widely used in different blockchain platforms such as Ethereum, TRON and BNB Chain. One of the unique designs in Solidity smart contracts is its statereverting mechanism for error handling and access control. Unfortunately, a number of recent security incidents showed that adversaries also utilize this mechanism to manipulate critical states of smart contracts, and hence, bring security consequences such as illegal profit-gain and Deny-of-Service (DoS). In this paper, we call such vulnerabilities as the State-reverting Vulnerability (SRV). Automatically identifying SRVs poses unique challenges, as it requires an in-depth analysis and understanding of the state-dependency relations in smart contracts. Zeqin Liao, Sicheng Hao 0001, Yuhong Nan, Zibin Zheng |
ISSTA | 1 |
| 2022 | SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityabstractWith the increasing popularity of blockchain, automatically detecting vulnerabilities in smart contracts is becoming a significant problem. Prior research mainly identifies smart contract vulnerabilities without considering the interactions between multiple contracts. Due to the lack of analyzing the fine-grained contextual information during cross-contract invocations, existing approaches often produced a large number of false positives and false negatives. This paper proposes SmartDagger, a new framework for detecting cross-contract vulnerability through static analysis at the bytecode level. SmartDagger integrates a set of novel mechanisms to ensure its effectiveness and efficiency for cross-contract vulnerability detection. Particularly, SmartDagger effectively recovers the contract attribute information from the smart contract bytecode, which is critical for accurately identifying cross-contract vulnerabilities. Besides, instead of performing the typical whole-program analysis which is heavy-weight and time-consuming, SmartDagger selectively analyzes a subset of functions and reuses the data-flow results, which helps to improve its efficiency. Our further evaluation over a manually labelled dataset showed that SmartDagger significantly outperforms other state-of-the-art tools (i.e., Oyente, Slither, Osiris, and Mythril) for detecting cross-contract vulnerabilities. In addition, running SmartDagger over a randomly selected dataset of 250 smart contracts in the real-world, SmartDagger detects 11 cross-contract vulnerabilities, all of which are missed by prior tools. Zeqin Liao, Zibin Zheng, Yuhong Nan |
ISSTA | 1 |
| 2021 | Dynamic Collaborative Charging Algorithm for Mobile and Static Nodes in Industrial Internet of ThingsabstractIndustrial Internet of Things inevitably leads to the implementation of highly data-intensive devices, where the associated sensing nodes accelerate the energy consumption rate, which ultimately produces an energy bottleneck. To address this issue, this article proposes adynamic collaborative charging algorithmthat acts on both the mobile nodes and the static nodes in a sensing node network. The proposed scheme is to design a collaborative group of charging robots that can rendezvous with the sensing nodes. The group includes aerial charging vehicles (ACVs)—able to charge the underpowered mobile nodes, and terrestrial charging vehicles (TCVs), which charge their targeted static nodes. The aim of this study is to optimize the charging effect and the energy cost in the rendezvous process. This approach consists of two subalgorithms: 1) a charging algorithm for mobile nodes (CAMNs) and 2) a charging algorithm for static nodes (CASNs). The CAMNs is designed so that each underpowered mobile node can be charged by a dedicated ACV. For this purpose, a deep learning model is trained to divide the underpowered mobile nodes into appropriate clusters, each of which is equipped with a mobile base station. The rendezvous process is then constructed as a mixed continuous/discrete optimization problem, which is solved by using the firefly algorithm. In addition, the CASNs ensures that the TCVs traverse their routes, charging static nodes as they proceed. This traversing process was formulated as a multiobjective optimization problem, solved by using genetic algorithm. Through various experiments and case studies, the results have demonstrated both the feasibility and the efficiency of the proposed algorithms. Guangjie Han, Zeqin Liao, Miguel Martinez-Garcia, Yu Zhang 0001, Yan Peng 0001 |
IEEE Internet Things J. | 2 |
| 2021 | Multistation-Based Collaborative Charging Strategy for High-Density Low-Power Sensing Nodes in Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) involves the use of large numbers of sensing nodes, which should meet the requirements for industrial use, such as real-time performance monitoring and high reliability and stability. However, owing to single-station allocation, inappropriate mobile charger (MC) allocation and unreasonable route planning, conventional methods may lead to local blockages, incomplete charging coverage, and high energy consumption because of additional movement. Hence, we propose a multistation-based collaborative charging strategy, termed MCCS, to overcome these problems. In MCCS, the energy sources are static charging stations. Furthermore, MCs that consist of primary and senior chargers act as the transmission media. Specifically, the senior chargers, which are charged by the stations, transmit energy to the primary chargers, which then transmit energy to the sensor nodes. The following steps are involved in MCCS. To begin with, MCCS divides the sensor nodes into various categories based on a self-organizing feature mapping neural network in order to ensure appropriate primary charger allocation. Next, a genetic algorithm is used to generate the optimal routes for the MCs. Finally, MCCS allocates the senior chargers and sets up the charging stations. Simulations were conducted to evaluate MCCS, which exhibited better performance in terms of efficiency, energy consumed in movement, and charging energy loss as compared with existing strategies. Zeqin Liao, Guangjie Han, Hao Wang 0047, Li Liu 0022 |
IEEE Internet Things J. | 1 |