VLDB 2026 Research / reviewers in the wild / expert
Mingyuan Huang
dblp:326/7483
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2025
0009-0002-0546-7083ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | To healthier Ethereum: a comprehensive and iterative smart contract weakness enumerationabstractWith the increasing popularity of cryptocurrencies and blockchain technologies, smart contracts have become a prominent feature in developing decentralized applications. However, these smart contracts are susceptible to vulnerabilities that hackers can exploit, resulting in significant financial losses. In response to this growing concern, various initiatives have emerged. Notably, the Smart Contract Weakness Classification (SWC) list plays an important role in raising awareness and understanding of smart contract weaknesses. However, the SWC list lacks maintenance and has not been updated with new vulnerabilities since 2020. To address this gap, this paper introduces the Smart Contract Weakness Enumeration (SWE), a comprehensive and practical vulnerability list up until 2023. We collect 273 vulnerability descriptions from 86 top conference papers and journal papers, employing the open card-sorting method to deduplicate and categorize these descriptions. This process results in the identification of 40 common contract weaknesses, which are further classified into 20 sub-research fields through thorough discussion and analysis. The SWE provides a systematic and comprehensive list of smart contract vulnerabilities, covering existing and emerging vulnerabilities in the last few years. Moreover, the SWE is a scalable and continuously iterative program. We propose two update mechanisms for the maintenance of the SWE. Regular updates involve the inclusion of new vulnerabilities from future top papers, while irregular updates enable individuals to report new weaknesses for review and potential addition to the SWE. Jiachi Chen, Mingyuan Huang, Zewei Lin, Peilin Zheng, Zibin Zheng |
Blockchain Res. Appl. | 2 |
| 2024 | Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart ContractsabstractSmart contracts are Turing-complete programs that execute on the blockchain. Developers can implement complex contracts, such as auctions and lending, on Ethereum using the Solidity programming language. As an object-oriented language, Solidity provides libraries within its syntax to facilitate code reusability and reduce development complexity. Library misuse refers to the incorrect writing or usage of libraries, resulting in unexpected results, such as introducing vulnerabilities during library development or incorporating an unsafe library during contract development. Library misuse could lead to contract defects that cause financial losses. Currently, there is a lack of research on library misuse. To fill this gap, we collected more than 500 audit reports from the official websites of five audit companies and 223,336 real-world smart contracts from Etherscan to measure library popularity and library misuse. Then, we defined eight general patterns for library misuse; three of them occurring during library development and five during library utilization, which covers the entire library lifecycle. To validate the practicality of these patterns, we manually analyzed 1,018 real-world smart contracts and publicized our dataset. We identified 905 misuse cases across 456 contracts, indicating that library misuse is a widespread issue. Three patterns of misuse are found in more than 50 contracts, primarily due to developers lacking security awareness or underestimating negative impacts. Additionally, our research revealed that vulnerable libraries on Ethereum continue to be employed even after they have been deprecated or patched. Our findings can assist contract developers in preventing library misuse and ensuring the safe use of libraries. Mingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin Zheng |
ICSE | 1 |
| 2024 | Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsabstractReentrancy, a notorious vulnerability in smart contracts, has led to millions of dollars in financial loss. However, current smart contract vulnerability detection tools suffer from a high false positive rate in identifying contracts with reentrancy vulnerabilities. Moreover, only a small portion of the detected reentrant contracts can actually be exploited by hackers, making these tools less effective in securing the Ethereum ecosystem in practice. Shuo Yang 0012, Jiachi Chen, Mingyuan Huang, Zibin Zheng, Yuan Huang 0002 |
ICSE | 3 |
| 2022 | Defending Data Poisoning Attack via Trusted Platform Module and Blockchain OracleabstractWith the development of Internet of Things (IoT) technology, the digital pill has been employed as an IoT system for emerging remote health monitoring to detect the impact of medicine intake on patients’ biological index. The medical data is then used for model training with federated learning. An adversary can launch poisoning attacks by tampering with patients’ medical data, which will lead to misdiagnosis of the patients’ conditions. Lots of studies have been conducted to defend against poisoning attacks based on blockchain or hardware. However, 1) Blockchain-based schemes can only exploit on-chain data to deal with poisoning attacks due to the lack of off-chain trusted entities. 2) Typical hardware-based schemes have the bottleneck of single point of failure. To overcome these defects, we propose a defense scheme via multiple Trusted Platform Modules (TPMs) and blockchain oracle. Benefitting from multiple TPMs verification results, a distributed blockchain oracle is proposed to obtain off-chain verification results for smart contracts. Then, the smart contracts could utilize the off-chain verification result to identify poisoning attacks and store the unique identifiers of the non-threatening IoT device immutably on the blockchain as a whitelist of federated learning participants. Finally, we analyze the security features and evaluate the performance of our scheme, which shows the robustness and efficiency of the proposed work. Mingyuan Huang, Xiong Li 0002, Ke Huang 0002, Xiaosong Zhang 0001 |
ICC | 1 |
| 2022 | Help from Meta-Path: Node and Meta-Path Contrastive Learning for Recommender SystemsabstractRecently, contrastive learning alleviates data sparsity issues and improves the performance of the Graph Neural Network (GNN) recommender models by employing graph structure dropout augmentations. However, these models still face following limitations: (1) Information loss. Dropout may discard helpful information. (2) Insufficient utilization of path-level information. Meta-path is carried numerous high-order information, which has not been well considered in these models. To this end, in this paper, we propose a novel framework, Node and Meta-Path Contrastive Learning for Recommender Systems (NPCRS), which utilizes meta-path to capture path-level information for model learning. Specifically, our approach first generates a meta-path view on the user-item bipartite graph by leveraging meta-path instead of random dropout. Then, we learn the node representation on a user-item bipartite graph and meta-path view to capture both node and path-level information simultaneously. Further, a multi-positive sample mechanism is introduced to define positive and negative samples for contrastive learning. Finally, NPCRS utilizes contrastive learning to learn a more informative node representation. We evaluate the proposed model using three real-world datasets and our experimental results show that our model significantly outperforms the state-of-the-art approaches. Mingyuan Huang, Pengpeng Zhao 0001, Xuefeng Xian, Jianfeng Qu, Guanfeng Liu 0001, Yanchi Liu, Victor S. Sheng |
IJCNN | 1 |