Jiaqian Peng

dblp:299/7707 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2026
0009-0002-8073-4057ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT Firmware
Jiaqian Peng, Puzhuo Liu, Yicheng Zeng, Yongji Liu, Hongsong Zhu
SP1
2024 Symerge: Replacing Calls in Under-Constrained Symbolic Execution and Find Vulnerabilities
Yicheng Zeng, Jiaqian Peng, Jiami Lin, Rongrong Xi, Hongsong Zhu
SecureComm (2)2
2024 Active Defense Simulation Evaluation of Industrial Control Systems Based on Attack-Defense Graph
Qun Xiao, Shouguo Yang, Jiaqian Peng, Jingfei Bian, Shichao Lv, Limin Sun 0001, Zhiqiang Shi
WASA (2)3
2023 UCRF: Static analyzing firmware to generate under-constrained seed for fuzzing SOHO router
Jiaqian Peng, Puzhuo Liu, Yaowen Zheng, Limin Sun 0001
Comput. Secur.2
2022 SIFOL: Solving Implicit Flows in Loops for Concolic Execution
abstract
Concolic execution is widely used for binary analysis and is commonly embedded in hybrid fuzzing to find bugs. However, implicit flows in loops can hinder concolic execution and lead to the reduction of code coverage. The implicit flow variables cannot be symbolized and will block the constraint solver from generating new inputs. We propose a new approach to mitigate the problem. We obtain the implicit flow variables by taint analysis in advance and symbolize them during the concolic execution. Then, when the symbols of the variables are in the path constraints and need to be solved, we backtrack to the corresponding loops and perform static symbolic executions in the loops. During the static symbolic executions, we relate the variables with the input symbols by state merging and solve the constraints to generate inputs for new execution paths. We present SIFOL, a hybrid fuzzer based on Driller, and evaluate it on CB-multios. Results show that SIFOL has 5.4% higher code coverage than Driller and finds 5.9% more crashes. Furthermore, after manually adding implicit flows and checks to the target programs, SIFOL only drops 2.6% on coverage and 5.6% on the crash number, while Driller is severely affected (drops 46.1% on coverage and 47.1% on the crash number).
Yicheng Zeng, Jiaqian Peng, Zhanwei Song, Hongsong Zhu, Limin Sun 0001
IPCCC2