VLDB 2026 Research / reviewers in the wild / expert
Chengfeng Ye
dblp:332/5984
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0002-9529-3410ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Semantic-Aware Binary Diffing with High-Confidence Dynamic Instruction Alignment
Chengfeng Ye, Anshunkang Zhou, Charles Zhang 0001 |
NDSS | 1 |
| 2024 | Manta: Hybrid-Sensitive Type Inference Toward Type-Assisted Bug Detection for Stripped BinariesabstractStatic binary bug detection has been a prominent approach for ensuring the security of binaries used in our daily lives. However, the type information lost in binaries prevents the improvement opportunity for a static analyzer to utilize type information to prune away infeasible facts and increase analysis precision. To make binary bug detection more practical with higher precision, in this work, we propose the first hybrid-sensitive type inference, Manta, that combines data-flow analysis with different sensitivities to complement each other and infer precise types for many variables. The inferred types are then used to assist with bug detection by pruning infeasible indirect call targets and data dependencies. Our experiments indicate Manta outperforms prior work by inferring types with 78.7% precision and 97.2% recall. Based on the inferred types, we can prune away 63.9% more infeasible indirect-call targets compared to existing type analysis techniques and perform program slicing on binaries with 61.1% similarity to that on source code. Moreover, Manta has led to 86 new developer-confirmed vulnerabilities in many popular IoT firmware, with 64 CVE/PSV IDs assigned. Chengfeng Ye, Yuandao Cai, Anshunkang Zhou, Heqing Huang 0002, Hao Ling, Charles Zhang 0001 |
ASPLOS (4) | 1 |
| 2024 | Plankton: Reconciling Binary Code and Debug InformationabstractStatic analysis has been widely used in large-scale software defect detection. Despite recent advances, it is still not practical enough because it requires compilation interference to obtain analyzable code. Directly translating the binary code using a binary lifter mitigates this practicality problem by being non-intrusive to the building system. However, existing binary lifters cannot produce precise enough code for rigorous static analysis even in the presence of the debug information. In this paper, we propose a new binary lifter Plankton together with two new algorithms that can fill the gaps between the low- and high-level code to produce high-quality LLVM intermediate representations (IRs) from binaries with debug information, enabling full-fledged static analysis with minor precision loss. Plankton shows comparable static analysis results with traditional compilation interference solutions, producing only 17.2% differences while being much more practical, outperforming existing lifters by 76.9% on average. Anshunkang Zhou, Chengfeng Ye, Heqing Huang 0002, Yuandao Cai, Charles Zhang 0001 |
ASPLOS (2) | 2 |
| 2024 | When Threads Meet Interrupts: Effective Static Detection of Interrupt-Based Deadlocks in Linux
Chengfeng Ye, Yuandao Cai, Charles Zhang 0001 |
USENIX Security Symposium | 1 |
| 2023 | Place Your Locks Well: Understanding and Detecting Lock Misuse Bugs
Yuandao Cai, Peisen Yao, Chengfeng Ye, Charles Zhang 0001 |
USENIX Security Symposium | 3 |
| 2022 | Peahen: fast and precise static deadlock detection via context reductionabstractDeadlocks still severely inflict reliability and security issues upon software systems of the modern age. Worse still, as we note, in prior static deadlock detectors, good precision does not go hand-in-hand with high scalability --- their approaches are either context-insensitive, thereby engendering many false positives, or suffer from the calling context explosion to reach context-sensitive, thus compromising good efficiency. In this paper, we advocate Peahen, geared towards precise yet also scalable static deadlock detection. At its crux, Peahen decomposes the computational effort for embracing high precision into two cooperative analysis stages: (i) context-insensitive lock-graph construction, which selectively encodes the essential lock-acquisition information on each edge, and (ii) three precise yet lazy refinements, which incorporate such edge information into progressively refining the deadlock cycles in the lock graph only for a few interesting calling contexts. Yuandao Cai, Chengfeng Ye, Qingkai Shi, Charles Zhang 0001 |
ESEC/SIGSOFT FSE | 2 |