Jianhao Xu

dblp:302/1583 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Fully utilizing cross modal features to achieve precise segmentation of brain gliomas
Weiye Cao, Kaiyan Zhu, Jianhao Xu, Yue Liu 0005
Multim. Syst.3
2026 CLower: Detecting Compiler Pessimization Bugs through Redundant Memory Accesses
abstract
Compilers are expected to generate optimized code, but they sometimes introduce pessimizations, quality-degrading redundant instructions. These bugs not only incur performance overhead but also, critically, expand the attack surface by introducing unexpected side effects (e.g., redundant memory accesses) without breaking compilation correctness. Existing bug-finding methods are neither designed for nor effective at identifying such security-sensitive pessimizations. This paper presents CLower, a novel, black-box approach for automatically detecting compiler pessimizations via redundant memory accesses. CLower’s core insight is that any extra global memory accesses in a fully optimized binary, compared to the source, indicate a pessimization. To reliably distinguish compiler-introduced redundancy from source-level redundancy, we generate random C programs in which each global variable has a predetermined, controlled number of memory accesses. CLower then executes the instrumented binary and verifies whether superfluous accesses have been introduced during compilation. We applied CLower to GCC and LLVM, reporting 23 unique bugs (21 in GCC, 2 in Clang), with 16 confirmed as new pessimization bugs. Our evaluation shows that CLower accurately detects diverse, impactful pes-simization bugs, the majority of which (75%) also manifest for heap-allocated objects, demonstrating that the underlying compiler flaws are general and not limited to global memory. Furthermore, we identify a systematic conflict between compiler optimizations and pessimization bugs, which causes many such bugs to remain hidden in compiler versions. This study sheds light on the under-explored area of compiler pessimization and provides a practical tool for improving compiler quality.
Jianhao Xu, Kunbo Zhang, Mathias Payer, Kangjie Lu, Bing Mao 0001
Proc. ACM Program. Lang.1
2024 YoloOW: A Spatial Scale Adaptive Real-Time Object Detection Neural Network for Open Water Search and Rescue From UAV Aerial Imagery
abstract
Personnel and boat detection in Unmanned Aerial Vehicles (UAVs) imagery plays a crucial role in Open Water Search and Rescue Missions. The diverse perspectives and altitudes of UAV images often result in significant variations in the imagery’s appearance and dimensions of personnel and boats, and the false detections arising from water surface flares are acknowledged as a great challenge as well. Existing deep learning-based detection methods employ convolutional blocks with fixed kernel sizes to extract features from the imagery at a fixed spatial scale, which will lead to missed and false detections, and severely affect detection accuracy when there are substantial differences in the appearance and size of the target objects. In this paper, a spatial scale adaptive real-time object detection neural network, namely YoloOW, was proposed to tackle the challenge of personnel and boat detection amidst the diverse UAV imagery, which comprises a feature extractor, a feature enhancer, and a postprocessor. The OaohRep convolutional block was proposed as a pivotal component in constructing the YoloOW and applied to the feature extractor and the feature enhancer. Compared with general convolution blocks, the OaohRep convolution block can extract image features across a wide range of spatial scales, show better scale adaptability, and achieve faster detection speed due to its unique merged convolution layer design. OaohRepBi-PAN was proposed in the feature enhancer, which imitated the architecture of the classic algorithm SIFT and was successfully applied to deep learning models, showing better scale adaptability. A novel UAV detection box filter (UDBF) module was proposed in the postprocessor, which can effectively remove false detections caused by water surface flares. Experimental results demonstrate that our YoloOW model achieves 37.18% mAP on the SeaDronesSee dataset, surpassing the baseline by 8.43%. This notable improvement positions our model at the first of the leaderboard. The code will be available at https://github.com/Xjh-UCAS/YoloOW.
Jianhao Xu, Xiangtao Fan, Hongdeng Jian, Chen Xu 0012, Weijia Bei, Qifeng Ge
IEEE Trans. Geosci. Remote. Sens.1
2023 WarpAttack: Bypassing CFI through Compiler-Introduced Double-Fetches
abstract
Code-reuse attacks are dangerous threats that attracted the attention of the security community for years. These attacks aim at corrupting important control-flow transfers for taking control of a process without injecting code. Nowadays, the combinations of multiple mitigations (e.g., ASLR, DEP, and CFI) drastically reduced this attack surface, making running code-reuse exploits more challenging.Unfortunately, security mitigations are combined with compiler optimizations, that do not distinguish between security-related and application code. Blindly deploying code optimizations over code-reuse mitigations may undermine their security guarantees. For instance, compilers may introduce double-fetch vulnerabilities that lead to concurrency issues such as Time-Of-Check to Time-Of-Use (TOCTTOU) attacks.In this work, we propose a new attack vector, called WarpAttack, that exploits compiler-introduced double-fetch optimizations to mount TOCTTOU attacks and bypass code-reuse mitigations. We study the mechanism underlying this attack and present a practical proof-of-concept exploit against the last version of Firefox. Additionally, we propose a lightweight analysis to locate vulnerable double-fetch code (with 3% false positives) and conduct research over six popular applications, five operating systems, and four architectures (32 and 64 bits) to study the diffusion of this threat. Moreover, we study the implication of our attack against six CFI implementations. Finally, we investigate possible research lines for addressing this threat and propose practical solutions to be deployed in existing projects.
Jianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao 0001, Mathias Payer
SP1
2023 Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs
Jianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding, Linke Li, Qiushi Wu, Mathias Payer, Bing Mao 0001
USENIX Security Symposium1
2021 POMP++: Facilitating Postmortem Program Diagnosis with Value-Set Analysis
abstract
With the emergence of hardware-assisted processor tracing, execution traces can be logged with lower runtime overhead and integrated into the core dump. In comparison with an ordinary core dump, such a new post-crash artifact provides software developers and security analysts with more clues to a program crash. However, existing works only rely on the resolved runtime information, which leads to the limitation in data flow recovery within long execution traces. In this work, we propose POMP++, an automated tool to facilitate the analysis of post-crash artifacts. More specifically, POMP++ introduces a reverse execution mechanism to construct the data flow that a program followed prior to its crash. Furthermore, POMP++ utilizes Value-set Analysis, which helps to verify memory alias relation, to improve the ability of data flow recovery. With the restored data flow, POMP++ then performs backward taint analysis and highlights program statements that actually contribute to the crash. We have implemented POMP++ for Linux system on x86-32 platform, and tested it against various crashes resulting from 31 distinct real-world security vulnerabilities. The evaluation shows that, our work can pinpoint the root causes in 29 cases, increase the number of recovered memory addresses by 12 percent and reduce the execution time by 60 percent compared with existing reverse execution. In short, POMP++ can accurately and efficiently pinpoint program statements that truly contribute to the crashes, making failure diagnosis significantly convenient.
Dongliang Mu, Yunlan Du, Jianhao Xu, Jun Xu 0024, Xinyu Xing 0001, Bing Mao 0001, Peng Liu 0005
IEEE Trans. Software Eng.3