VLDB 2026 Research / reviewers in the wild / expert
Ximing Fan
dblp:321/4955
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fuzz4Cuda: Fuzzing your NVIDIA GPU libraries through debug interface
Peng Jia 0005, Ximing Fan |
Comput. Secur. | 4 |
| 2026 | MPS-Fuzz: An Enhanced Fine-Grained Fuzzing Based on Units With Multiple Inputs and OutputsabstractEdge coverage-guided fuzzing has demonstrated remarkable achievements in vulnerability discovery. Some studies with fine-grained coverage metrics have been proposed to enhance the vulnerability mining capabilities of fuzzing by capturing more program paths. However, this refinement often results in a significant increase in seeds, which are highly homogeneous and may limit vulnerability detection. Additionally, finer granularity requires more bitmap hits, increasing the risk of hash collisions. To address these shortages, the paper proposes the structure of a basic block unit with multiple predecessors and successors (referred to as MPS). Then, a fine-grained coverage method called MPS-Fuzz is designed based on the MPS structure. In this approach, it is convenient to exclude basic blocks involving loop structures when determining MPS units, which helps reduce seed homogeneity. Additionally, we introduce an additional bitmap to record the coverage status of MPS units, ensuring that the collision rate of the edge bitmap does not increase. Moreover, these additional operations do not incur excessive time overhead. To demonstrate the properties of the MPS-Fuzz, we implement our approach on AFL and conduct experiments on 16 benchmarks from FuzzBench and Unifuzz. The result indicates that, after 24-hour fuzzing, MPS-Fuzz explores an average of 9.6% more edges and an average of 25.7% more bugs than AFL. Compared to other fine-grained coverage methods (N-gram and PathAFL), MPS-Fuzz also achieves better performance. Moreover, MPS-Fuzz has discovered a previously unknown bug on real-world program and got a CVE assigned. Ximing Fan, Yong Fang 0002, Peng Jia 0005, Hongwei Li 0001, Yijia Xu, Qinying Wang, Shouling Ji |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | ENZZ: Effective N-gram coverage assisted fuzzing with nearest neighboring branch estimation
Peng Jia 0005, Ximing Fan |
Inf. Softw. Technol. | 3 |
| 2025 | Directed fuzzing based on path constraints and deviation path correction
Hongsheng Zuo, Yong Fang 0002, Peng Jia 0005, Ximing Fan, Yijia Xu |
Inf. Softw. Technol. | 4 |