Yingli Zhang

dblp:319/7759 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Towards a comprehensive framework for verifying open-source software license compatibility
Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou
Empir. Softw. Eng.3
2026 The Effects of Pronoun Usage and Context on Human Psychological Consequences When Interacting With Conversational Agents
abstract
Users increasingly expect conversational agents (CAs) to communicate effectively by adjusting language strategies to different contexts and providing personalized responses. Using a 2 (context: service vs. emergency) × 3 (second-person pronoun usage: informal “you,” formal “you,” vs. no pronoun) between-subjects design, this study investigated how second-person pronouns used by CAs influenced users’ perceptions through an online survey with 1242 valid responses. To facilitate the customized design of CAs, demographic factors (e.g., age, gender) are also considered. Results indicated that subtle shifts in pronoun usage triggered significant differences in psychological consequences, with both forms of “you” providing fewer benefits than omitting pronouns across contexts. Users in the emergency context exhibited lower purchase willingness than those in the service context. Age, gender, and education also significantly predicted users’ perceptions. Overall, the findings highlight the psychological impacts of second-person pronouns and inform the design of interaction strategies for CAs.
Yingli Zhang, Chunxi Huang, Hao Tan 0001
Int. J. Hum. Comput. Interact.1
2025 LLM-SZZ: Novel Vulnerability-Inducing Commit Identification Driven by Large Language Model and CVE Description
abstract
The SZZ method and its variants are widely employed to identify vulnerability-affected ranges by analyzing vulnerability-fixing commits to trace back vulnerability-inducing commits. However, these methods generally suffer from low precision due to several key factors: 1) Current static method-based variants often incorrectly consider too many irrelevant lines and files in a commit. While methods that extract file references from vulnerability discussions can help narrow down relevant files, obtaining bug discussions for every CVE is often difficult. 2) Learning-based approaches focus exclusively on code to capture semantic relationships for identifying root cause lines. However, these models utilize limited information and demonstrate insufficient capacity for effective capture. 3) The reliance on line mapping algorithms results in inadequate tracing capabilities for complex vulnerabilities, especially when vulnerability-inducing commits are obscured in earlier software versions. To address these issues, this paper innovatively incorporates semantic information from descriptive text and the nature of CVEs derived from vulnerability-fixing commit diffs. By leveraging large language models (LLMs), this approach aims to capture the true root cause lines of vulnerabilities more accurately and enhance the tracing capabilities of the SZZ method, thereby achieving precise localization of the vulnerability impact range. Experimental results indicate that our proposed LLM-SZZ method outperforms existing state-of-the-art approaches, achieving over a 18 % increase in precision across datasets in various programming languages, demonstrating a significant performance advantage.
Siqi Fan 0005, Xin Liu 0050, Yingli Zhang, Yuan Tan 0003, Luxing Yin, Zhaorun Chen, Song Li 0006, Rui Zhou 0005
ICSME3
2025 ISGraphVD: Precise Vulnerability Detection for IoT Supply Chains Based on Identifier Sensitive Graph
abstract
Open-source software (OSS) is widely reused in Internet of Things (IoT) devices, leading to widespread N-Day vulnerabilities when outdated components remain unpatched. Existing methods typically encode features of different Common Vulnerabilities and Exposures (CVEs) within a shared representation space. However, the model’s limited capacity, combined with the new vulnerability features, can disrupt previously learned patterns. Minimal code modifications in tiny-patch vulnerabilities are often overshadowed by variations introduced by different compilation settings, making it more difficult to distinguish vulnerable functions from their patched counterparts. This paper introduces ISGraphVD, a novel graph-based and function-level vulnerability detection approach that supports cross-compilation settings and enhances detection accuracy. By modeling each CVE independently through a one-model-per-CVE strategy, ISGraphVD reduces feature interference and improves detection accuracy across diverse CVEs. To better detect tinypatch vulnerability, we propose ISGraph, a fine-grained graph representation that models variable dependencies within and across basic blocks by integrating control flow analysis. Then, ISGraphVD utilizes a Graph Matching Network (GMN) with a cross-graph attention mechanism to identify critical vulnerability patterns. Experiments on IoT OSS projects show that ISGraphVD outperforms state-of-the-art methods, achieving a 6.3 percentage-point (pp) accuracy improvement over the strongest baseline, and real-world tests further validate its effectiveness in IoT supply chains.
Yingli Zhang, Xin Liu 0050, Ziang Liu 0006, Song Li 0006, Weina Niu, Rui Zhou 0005, Qingguo Zhou
ISSRE1
2024 LiScopeLens: An Open-Source License Incompatibility Analysis Tool Based on Scope Representation of License Terms
abstract
Open-source software has emerged as a pivotal force in the advancement of information technology. Robust open-source compliance governance is essential for the sustainable and healthy growth of both open-source software and its communities. License incompatibility analysis, in particular, represents a critical challenge hindering the progress of open-source software. Traditional methods of incompatibility analysis often fail to account for diverse usage scenarios or are tailored to a limited subset of scenarios. This limitation obstructing their ability to handle the intricate compatibility arising from varied programming language interactions, leading to a high false positives. Our study embarks from an examination of license exceptions, delving into the incompatibility analysis challenges through extensive empirical research on these exceptions. We discovered that the majority of exceptions are, in fact, detectable. Leveraging this empirical insight, our research further develops the license compatibility analysis model by introducing a new, refined legal terminology representation alongside a novel method for license compatibility reasoning. This approach begins with modeling different scenarios to represent license compatibility variably. Furthermore, based on these modeling outcomes, we have designed and implemented LiScopeLens, a tool capable of discerning dependency behaviors for granular compatibility assessment, starting with binary dependencies. Our experimental findings affirm that LiScopeLens proficiently determines the license compatibility status of open-source software across various usage scenarios, demonstrating its significant practical utility.
Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou
ISSRE3
2023 An Efficient Smart Contract Vulnerability Detector Based on Semantic Contract Graphs Using Approximate Graph Matching
abstract
The Internet of Things (IoT) has become a focus of information infrastructure development in recent years. The smart blockchain can provide various solutions for trust, security, and privacy (TSP) challenges to protect IoT data, and smart contracts are the foundation of blockchain intelligence, and greatly enhance the ability of smart blockchain to solve TSP problems. So, the security of smart contracts must be addressed. We propose an efficient smart contract vulnerability detector to improve the safety of smart contracts. It comprises a graph extraction method and a complete vulnerability detection process. The graph extraction method consists of vulnerability pattern extraction and a graph generation process. The vulnerability detection process first uses the approximate graph matching algorithm to select representative SCGraphs from the data set to build vulnerability SCGraph libraries. Second, determine whether the contract contains vulnerabilities by calculating the similarity between the SCGraphs generated from the contracts to be detected and the SCGraphs in the vulnerability library. Experiments show that our approach achieves an inspiring high detection rate and is the fastest among existing vulnerability detection tools, which indicates that it can provide good vulnerability detection for smart contracts.
Yingli Zhang, Xin Liu 0050, Guodong Ye, Qun Jin, Jianhua Ma 0002, Qingguo Zhou
IEEE Internet Things J.1
2022 TCN enhanced novel malicious traffic detection for IoT devices
abstract
With the development of IoT technology, more and more IoT devices are connected to the network. Due to the hardware constraints of IoT devices themselves, it is difficult for developers to embed security software into them. Therefore, it is better to protect IoT devices at the traffic level. The effect of malicious traffic detection based on neural networks is promising. Still, the slow computation brings some difficulties to deploying AI-based detection systems on edge servers. Time Convolutional Network (TCN) is a high-speed neural network suitable for massively parallel computation. In this paper, we propose Multi-class S-TCN, an improved network supporting multiple classifications based on TCN for the practical needs of IoT scenarios. Besides, we implement a complete IoT traffic security detection procedure based on deep packet inspection and protocol analysis. The proposed Multi-class S-TCN significantly improves the detection speed without degrading the detection effect. Experiments show that this work has better detection performance and faster detection speed compared to existing approaches, proving the effectiveness of the proposed detection flow and Multi-class S-TCN in IoT scenarios.
Xin Liu 0050, Ziang Liu 0006, Yingli Zhang, Dong Lv, Qingguo Zhou
Connect. Sci.3
2021 MLCOR Model for Suppressing the Cascade of Edge Failures in Complex Network
abstract
As a decisive parameter of network robustness and network economy, the capacity of network edges can directly affect the operation stability and the construction cost of the network. This paper proposes a multilevel load–capacity optimal relationship (MLCOR) model that can substantially improve the network economy on the premise of network safety. The model is verified in artificially created networks including free-scale networks, small-world networks, and in the real network structure of the Shanghai Metro network as well. By numerical simulation, it is revealed that under the premise of ensuring the stability of the network from the destruction caused by initial internal or external damage on edge, the MLCOR model can effectively reduce the cost of the entire network compared to the other two linear load–capacity models regardless of what extent of the destruction that the network edges suffer initially. It is also proved that there exists an optimal tunable parameter and the corresponding optimal network cost for any BA and NW network topology, which can provide the reference for setting reasonable capacities for network edges in a real network at the stage of network planning and construction, promoting security and stability of network operation.
Dan Cui, Ai Zhong Shen, Yingli Zhang
Int. J. Pattern Recognit. Artif. Intell.3