VLDB 2026 Research / reviewers in the wild / expert
Baijun Cheng
dblp:323/9441
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2024
0000-0003-1792-9396ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Semantic-Enhanced Indirect Call Analysis with Large Language ModelsabstractIn contemporary software development, the widespread use of indirect calls to achieve dynamic features poses challenges in constructing precise control flow graphs (CFGs), which further impacts the performance of downstream static analysis tasks. To tackle this issue, various types of indirect call analyzers have been proposed. However, they do not fully leverage the semantic information of the program, limiting their effectiveness in real-world scenarios. Baijun Cheng, Cen Zhang, Kailong Wang 0001, Ling Shi 0002, Yang Liu 0003, Haoyu Wang 0001, Yao Guo 0001, Ding Li 0001, Xiangqun Chen |
ASE | 1 |
| 2024 | Beyond Fidelity: Explaining Vulnerability Localization of Learning-Based DetectorsabstractVulnerability detectors based on deep learning (DL) models have proven their effectiveness in recent years. However, the shroud of opacity surrounding the decision-making process of these detectors makes it difficult for security analysts to comprehend. To address this, various explanation approaches have been proposed to explain the predictions by highlighting important features, which have been demonstrated effective in domains such as computer vision and natural language processing. Unfortunately, there is still a lack of in-depth evaluation of vulnerability-critical features, such as fine-grained vulnerability-related code lines, learned and understood by these explanation approaches. In this study, we first evaluate the performance of ten explanation approaches for vulnerability detectors based on graph and sequence representations, measured by two quantitative metrics including fidelity and vulnerability line coverage rate. Our results show that fidelity alone is insufficent for evaluating these approaches, as fidelity incurs significant fluctuations across different datasets and detectors. We subsequently check the precision of the vulnerability-related code lines reported by the explanation approaches, and find poor accuracy in this task among all of them. This can be attributed to the inefficiency of explainers in selecting important features and the presence of irrelevant artifacts learned by DL-based detectors. Baijun Cheng, Shengming Zhao, Kailong Wang 0001, Meizhen Wang, Guangdong Bai, Yao Guo 0001, Lei Ma 0003, Haoyu Wang 0001 |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2022 | MSDetector: A Static PHP Webshell Detection System Based on Deep-Learning
Baijun Cheng, Guosheng Xu 0001 |
TASE | 1 |