Chenlin Wang

dblp:324/6554 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential Fuzzing
Chenlin Wang, Wei Meng 0001
SP1
2025 BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web Applications
abstract
Broken-Access-Control (BAC) vulnerabilities have consistently been ranked among the most critical security risks in web applications, occupying the top positions in the OWASP Top 10 over the past several years. These vulnerabilities allow attackers to bypass access control mechanisms and perform unauthorized operations, posing serious security and privacy threats to sensitive business and user data. Despite substantial attention given to BAC vulnerabilities, effective and reliable approaches to detecting these issues remain limited. In this work, we present BACScan, a novel black-box approach to detect BAC vulnerabilities in web applications. Unlike existing response similarity-based oracles that check only unauthorized read accesses, BACScan introduces an innovative feedback-driven oracle, which determines whether unauthorized read or modification operations have occurred by inferring operationally-dependent web pages and analyzing the operational feedback. We evaluated BACScan on 20 real-world applications and successfully identified 89 vulnerabilities, including 54 previously unreported ones, outperforming state-of-the-art tools. We reported all newly identified vulnerabilities to the affected vendors. To date, 35 new CVE IDs have been assigned.
Yuan Zhang 0009, Enhao Li, Wei Meng 0001, Youkun Shi, Qianheng Wang, Chenlin Wang, Min Yang 0002
CCS7
2025 VLM-PI: Power Inspection System Based on Visual Large Models
abstract
The inspection of large-scale power transmission towers is crucial for ensuring the safe, stable, and reliable operation of the power grid. Traditional manual inspections pose significant risks. To address this, recent research has explored the use of unmanned aerial vehicles (UAVs) to optimize the inspection process. The emergence of interaction methods between large models and UAVs has greatly enhanced the intelligence of UAV frameworks. Furthermore, the advent of large vision models has simultaneously tackled the challenge of lacking visual input in UAV control interactions and the demand for training resources in visual recognition, making fully automated UAV inspections feasible. This paper proposes a power infrastructure inspection system based on large vision models. The system leverages large vision models to provide primary control strategies for UAVs, complemented by traditional large models and deep learning networks to achieve UAV inspection control. Additionally, we propose a deep learning-based training strategy to improve the efficiency of training large vision models.
Chenlin Wang, Qingyun Sun, Zhuohang Chen
CSCWD2
2025 Predator: Directed Web Application Fuzzing for Efficient Vulnerability Validation
abstract
Web application vulnerabilities continue to pose a significant challenge. Static analysis is currently the mainstream approach to this issue, while dynamic analysis is not as widely used in comparison. However, both techniques have their limitations. While current static analysis tools are plagued by high false-positive rates, necessitating fine-grained analysis and substantial expertise, it is also the case that dynamic analysis tools are underdeveloped. Current fuzzing-based tools are often limited by inefficiency in exploring deeper code locations. Moreover, state-of-the-art grey-box fuzzers often struggle to capture effective parameters from user interfaces, thereby failing to explore the input space efficiently. In this paper, we propose Predator, a directed fuzzing framework equipped with selective dynamic instrumentation for effective and efficient web application vulnerability detection and validation. We use static analysis techniques and dynamic analysis techniques to complement each other. Our lightweight static analysis provides relevant URLs and parameters of the directed fuzzing targets and thus facilitates dynamic validation of static analysis reports. Additionally, we propose a runtime distance supplementation mechanism and tailored mutation strategies to address the dynamic features of interpreted languages like PHP. The evaluation shows Predator effectively triggers more vulnerabilities and outperforms state-of-the-art grey-box fuzzers by up to 43.8 times in terms of time to exposure. Moreover, Predator detects 26 previously unknown vulnerabilities in real-world applications, further demonstrating its effectiveness. At the time of writing, 7 of the 26 vulnerabilities have been confirmed and patched by the corresponding vendors.
Chenlin Wang, Wei Meng 0001, Changhua Luo, Penghui Li 0001
SP1
2025 LSBT-Net: A lightweight framework for fault diagnosis of bearings based on an interpretable spatial-temporal model
Yicheng Duan, Tongguang Yang, Chenlin Wang, Qingkai Han, Shuangping Guo
Expert Syst. Appl.3
2024 Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis
abstract
Symbolic execution for dynamic web applications is challenging due to their multilingual nature. Prior solutions often fall short in limited syntax support and excessive engineering costs. We propose a novel approach called symbolic interpreter analysis (SIA) for web applications written in interpreted languages. SIA tackles the limitations by leveraging the comprehensive syntax support of language interpreters and incorporating established engineering from existing symbolic execution engines. Since web application logic is handled by the interpreter, SIA leverages an off-the-shelf symbolic execution engine to analyze the corresponding interpreter code to symbolically comprehend the behavior of the web application. Indeed, SIA entails solving several technical challenges in web application symbolic execution such as web application exploration, database interactions, etc.We have implemented our approach in SymPHP, a concolic execution engine for PHP-based web applications. Our extensive evaluation shows that SymPHP could effectively explore web application code with comprehensive PHP syntax support and high code coverage. It achieved high code coverage and successfully identified 77.23% of known vulnerabilities in our dataset, significantly outperforming prior approaches. The hybrid fuzzing framework built atop SymPHP significantly boosted fuzzing and detected ten new vulnerabilities.
Penghui Li 0001, Wei Meng 0001, Mingxue Zhang 0001, Chenlin Wang, Changhua Luo
SP4
2022 Spotlight on Video Piracy Websites: Familial Analysis Based on Multidimensional Features
Chenlin Wang, Yonghao Yu 0003, Ao Pu
KSEM (3)1