VLDB 2026 Research / reviewers in the wild / expert
Yiyuan Guo
dblp:322/7631
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Optimizer-Friendly Instrumentation for Event Quantification with PRUE AlgorithmabstractEvent quantification provides frequency information for runtime events and is widely used to build fast, secure, and reliable software and systems. It is usually achieved through instrumentation that introduces new instructions into programs but has significant runtime overhead. A key challenge in developing efficient instrumentation is that the instrumentation can barely benefit from modern compiler optimizations because the additional instructions introduce side effects that complicate the optimization process. Hao Ling, Yiyuan Guo, Charles Zhang 0001 |
ASPLOS (2) | 2 |
| 2026 | Accurate and efficient HiChIP interaction detection by modeling restriction enzyme cut site density as biological signalabstractHiChIP enables high-resolution chromatin interaction mapping, but existing methods generally overlook restriction enzyme (RE) cut site density or treat it as a technical bias requiring normalization or removal, discarding chromatin accessibility information that distinguishes functional regulatory elements. Here we introduce sintHiChIP to address this methodological gap. sintHiChIP explicitly models RE cut site density as a biological signal and integrates Gaussian kernel smoothing with distance-dependent statistics, allowing detection of chromatin loops while capturing local regulatory heterogeneity. Moreover, the algorithm employs adaptive probability distributions to resolve inherent data overdispersion and sparsity dynamically. Validation against independent datasets and comparison with existing methods demonstrate that sintHiChIP reliably recovers canonical chromatin loops, exhibiting distinct superiority in regulatory H3K27ac environments and comparable accuracy in structural cohesin contexts. Notably, sintHiChIP achieves exceptional precision in predicting CRISPRi experiments and reveals highly coherent cell-type-specific genetic regulatory networks. Executing efficiently on standard workstations, our method delivers a promising analytical framework for functional 3D genomic studies. Weiyue Ding, Quanhong Liu, Yiyuan Guo, Chiping Zhang, Shuilin Jin |
Briefings Bioinform. | 4 |
| 2024 | Precise Compositional Buffer Overflow Detection via Heap DisjointnessabstractStatic analysis techniques for buffer overflow detection still struggle with being scalable for millions of lines of code, while being precise enough to have an acceptable false positive rate. The checking of buffer overflow necessitates reasoning about the heap reachability and numerical relations, which are mutually dependent. Existing techniques to resolve the dependency cycle either sacrifice precision or efficiency due to their limitations in reasoning about symbolic heap location, i.e., heap location with possibly symbolic numerical offsets. A symbolic heap location potentially aliases a large number of other heap locations, leading to a disjunction of heap states that is particularly challenging to reason precisely. Acknowledging the inherent difficulties in heap and numerical reasoning, we introduce a disjointness assumption into the analysis by shrinking the program state space so that all the symbolic locations involved in memory accesses are disjoint from each other. The disjointness property permits strong updates to be performed at symbolic heap locations, significantly improving the precision by incorporating numerical information in heap reasoning. Also, it aids in the design of a compositional analysis to boost scalability, where compact and precise function summaries are efficiently generated and reused. We implement the idea in the static buffer overflow detector Cod. When applying it to large, real-world software such as PHP and QEMU, we have uncovered 29 buffer overflow bugs with a false positive rate of 37%, while projects of millions of lines of code can be successfully analyzed within four hours. Yiyuan Guo, Peisen Yao, Charles Zhang 0001 |
ISSTA | 1 |
| 2024 | Titan : Efficient Multi-target Directed Greybox FuzzingabstractModern directed fuzzing often faces scalability issues when analyzing multiple targets in a program simultaneously. We observe that the root cause is that directed fuzzers are unaware of the correlations among the targets, thereby could degenerate into a target-undirected method. As a result, directed fuzzing suffers severely from efficiency when reproducing multiple targets.This paper presents Titan, which enables fuzzers to distinguish correlations among various targets in the program and, thus, optimizes the input generation to reproduce multiple targets effectively. Leveraging these correlations, Titan differentiates seeds’ potential of reaching each target for the scheduling and identifies bytes that can be changed simultaneously for the mutation. We compare our approach to eight state-of-the-art (directed) fuzzers. The evaluation demonstrates that Titan outperforms existing approaches by efficiently detecting multiple targets, achieving a 21.4x speedup and requiring 95.0% fewer number of executions. In addition, Titan detects nine incomplete fixes, which cannot be detected by other directed fuzzers, in the latest versions of the benchmark programs with two CVE IDs assigned. Heqing Huang 0002, Peisen Yao, Hung-Chun Chiu, Yiyuan Guo, Charles Zhang 0001 |
SP | 4 |
| 2022 | Precise Divide-By-Zero Detection with Affirmative EvidenceabstractThe static detection of divide-by-zero, a common programming error, is particularly prone to false positives because conventional static analysis reports a divide-by-zero bug whenever it cannot prove the safety property --- the divisor variable is not zero in all executions. When reasoning the program semantics over a large number of under-constrained variables, conventional static analyses significantly loose the bounds of divisor variables, which easily fails the safety proof and leads to a massive number of false positives. We propose a static analysis to detect divide-by-zero bugs taking additional evidence for under-constrained variables into consideration. Based on an extensive empirical study of known divide-by-zero bugs, we no longer arbitrarily report a bug once the safety verification fails. Instead, we actively look for affirmative evidences, namely source evidence and bound evidence, that imply a high possibility of the bug to be triggerable at runtime. When applying our tool Wit to the real-world software such as the Linux kernel, we have found 72 new divide-by-zero bugs with a low false positive rate of 22%. Yiyuan Guo, Jinguo Zhou, Peisen Yao, Qingkai Shi, Charles Zhang 0001 |
ICSE | 1 |
| 2022 | BEACON: Directed Grey-Box Fuzzing with Provable Path PruningabstractUnlike coverage-based fuzzing that gives equal attention to every part of a code, directed fuzzing aims to direct a fuzzer to a specific target in the code, e.g., the code with potential vulnerabilities. Despite much progress, we observe that existing directed fuzzers are still not efficient as they often symbolically or concretely execute a lot of program paths that cannot reach the target code. They thus waste a lot of computational resources. This paper presents BEACON, which can effectively direct a grey-box fuzzer in the sea of paths in a provable manner. That is, assisted by a lightweight static analysis that computes abstracted preconditions for reaching the target, we can prune 82.94% of the executing paths at runtime with negligible analysis overhead (<5h) but with the guarantee that the pruned paths must be spurious with respect to the target. We have implemented our approach, BEACON, and compared it to five state-of-the-art (directed) fuzzers in the application scenario of vulnerability reproduction. The evaluation results demonstrate that BEACON is 11.50x faster on average than existing directed grey-box fuzzers and it can also improve the speed of the conventional coverage-guided fuzzers, AFL, AFL++, and Mopt, to reproduce specific bugs with 6.31x, 11.86x, and 10.92x speedup, respectively. More interestingly, when used to test the vulnerability patches, BEACON found 14 incomplete fixes of existing CVE-identified vulnerabilities and 8 new bugs while 10 of them are exploitable with new CVE ids assigned. Heqing Huang 0002, Yiyuan Guo, Qingkai Shi, Peisen Yao, Rongxin Wu, Charles Zhang 0001 |
SP | 2 |