Zuxin Chen

dblp:336/2531 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 VN-GT: Optimizing Virtual Network Deployment via Game Theory
abstract
The static and homogeneous nature of traditional networks presents a significant challenge for our defense efforts. These characteristics enable an experienced attacker to quickly determine our network topology and gather detailed information about the internal hosts through systematic scanning techniques. Implementing a virtual network view can mitigate this by simulating a virtual topology, thereby consuming the attacker’s resources and time. However, deploying a virtual network view reduces network throughput and increase latency. Additionally, an improperly configured virtual network view can waste resources and degrade Quality of Service (QoS). Most existing studies have focused solely on the defender’s perspective, resulting in overly idealistic solutions that are ineffective in real-world scenarios. To address this, we propose VN-GT, a game-theoretic based model that optimizes virtual network deployment by considering both attackers and defenders. We provide a detailed example scenario, analyze the game’s equilibrium, and validate the effectiveness of our method through a real attack and defense experiment.
Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Zuxin Chen, Siyuan Li 0014, Min Yu 0001, Weiqing Huang, Degang Sun
ICASSP4
2025 Exp-Arch: A Novel LLM-Powered Approach for Facilitating Exploit Primitive Assessment in the Linux Kernel
abstract
Transforming Linux kernel exploit primitives into full Privilege Escalation (PE) exploits is a critical, expertiseintensive, and time-consuming challenge, especially with constantly evolving kernel mitigations. While previous research has advanced automated kernel exploit development, these efforts often focused on specialized scenarios rather than providing a generalized, end-to-end framework for diverse primitives. This limitation restricts the exploration of a primitive's true exploit potential. This paper introduces Exp-Arch, a novel approach leveraging Large Language Models (LLMs) for the automated, end-to-end generation of PE exploits from kernel primitives. This process includes comprehensive initial assessment and subsequent exploitation. Exp-Arch's LLM-powered workflow systematically performs an in-depth semantic analysis of the input primitive, devises an intelligent strategic plan for the exploitation route, and then automates the synthesis and iterative closed-loop validation of the final PE exploit code. Exp-Arch offers accurate assessment of a primitive's exploitability and significantly accelerates the exploit development lifecycle. We evaluated ExpArch using various primitives from public Linux kernel 1-day vulnerabilities with commercial LLMs. The results show that Exp-Arch effectively converted 73 % (11 out of 15) of test cases into working kernel exploits, demonstrating its effectiveness in primitive evaluation.
Zuxin Chen, Zhi Li 0018, Zhanwei Song, Zhiqiang Shi, Limin Sun 0001
ICPADS1
2025 TransferFuzz: Fuzzing with Historical Trace for Verifying Propagated Vulnerability Code
abstract
Code reuse in software development frequently facilitates the spread of vulnerabilities, making the scope of affected software in CVE reports imprecise. Traditional methods primarily focus on identifying reused vulnerability code within target software, yet they cannot verify if these vulnerabilities can be triggered in new software contexts. This limitation often results in false positives. In this paper, we introduce TransferFuzz, a novel vulnerability verification framework, to verify whether vulnerabilities propagated through code reuse can be triggered in new software. Innovatively, we collected runtime information during the execution or fuzzing of the basic binary (the vulnerable binary detailed in CVE reports). This process allowed us to extract historical traces, which proved instrumental in guiding the fuzzing process for the target binary (the new binary that reused the vulnerable function). TransferFuzz introduces a unique Key Bytes Guided Mutation strategy and a Nested Simulated Annealing algorithm, which transfers these historical traces to implement trace-guided fuzzing on the target binary, facilitating the accurate and efficient verification of the propagated vulnerability. Our evaluation, conducted on widely recognized datasets, shows that TransferFuzz can quickly validate vulnerabilities previously unverifiable with existing techniques. Its verification speed is 2.5 to 26.2 times faster than existing methods. Moreover, TransferFuzz has proven its effectiveness by expanding the impacted software scope for 15 vulnerabilities listed in CVE reports, increasing the number of affected binaries from 15 to 53. The datasets and source code used in this article are available at https://github.com/Siyuan-Li201/TransferFuzz.
Siyuan Li 0014, Yuekang Li, Zuxin Chen, Chaopeng Dong, Yongpan Wang, Hong Li 0004, Yongle Chen, Hongsong Zhu
ICSE3
2025 PREXP: Uncovering and Exploiting Security-Sensitive Objects in the Linux Kernel
abstract
Security-Sensitive Objects (SSOs) are often critical components in the exploitation of Linux kernel memory corruption vulnerabilities. While existing research has advanced SSOs identification and classification, there remains a significant gap in systematically understanding how these objects can be effectively exploited in real-world security analysis. To address this challenge, we present PREXP, a novel approach to analyzing SSOs exploitability and automating the transformation of Proof-of-Concept (PoC) into exploitable states. Our approach encompasses three key techniques: (1) capability analysis and attribute modeling of vulnerable object (2) extraction and filtering of target SSOs and (3) automatically augmenting PoCs with SSO-specific code to create exploitation capabilities. To evaluate our approach, we tested our prototype on 30 public CVEs, successfully parsing vulnerable object in 22 cases (73.3%) and achieving accurate SSO matches in 18 (60.0%). PREXP outperformed state-of-the-art tools such as SCAVY and AlphaEXP in structure-matching, and enabled the generation of new Control Flow Hijacking Primitives (CFHPs) for 3 previously unexploited vulnerabilities, demonstrating its practical value in real-world exploit development.
Zuxin Chen, Yaowen Zheng, Hong Li 0004, Siyuan Li 0014, Weijie Wang 0005, Dongliang Fang, Zhiqiang Shi, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Generative artificial intelligence-enabled dynamic detection of rat nicotine-related circuits
Changwei Gong, Changhong Jing, Xin-an Liu, Victoria X. Wang, Cheuk Ying Tang, Paul J. Kenny, Zuxin Chen, Shuqiang Wang
Neural Comput. Appl.8
2024 LibAM: An Area Matching Framework for Detecting Third-Party Libraries in Binaries
abstract
Third-party libraries (TPLs) are extensively utilized by developers to expedite the software development process and incorporate external functionalities. Nevertheless, insecure TPL reuse can lead to significant security risks. Existing methods, which involve extracting strings or conducting function matching, are employed to determine the presence of TPL code in the target binary. However, these methods often yield unsatisfactory results due to the recurrence of strings and the presence of numerous similar non-homologous functions. Furthermore, the variation in C/C++ binaries across different optimization options and architectures exacerbates the problem. Additionally, existing approaches struggle to identify specific pieces of reused code in the target binary, complicating the detection of complex reuse relationships and impeding downstream tasks. And, we call this issue the poor interpretability of TPL detection results. In this article, we observe that TPL reuse typically involves not just isolated functions but also areas encompassing several adjacent functions on the Function Call Graph (FCG). We introduce LibAM, a novel Area Matching framework that connects isolated functions into function areas on FCG and detects TPLs by comparing the similarity of these function areas, significantly mitigating the impact of different optimization options and architectures. Furthermore, LibAM is the first approach capable of detecting the exact reuse areas on FCG and offering substantial benefits for downstream tasks. To validate our approach, we compile the first TPL detection dataset for C/C++ binaries across various optimization options and architectures. Experimental results demonstrate that LibAM outperforms all existing TPL detection methods and provides interpretable evidence for TPL detection results by identifying exact reuse areas. We also evaluate LibAM’s scalability on large-scale, real-world binaries in IoT firmware and generate a list of potential vulnerabilities for these devices. Our experiments indicate that the Area Matching framework performs exceptionally well in the TPL detection task and holds promise for other binary similarity analysis tasks. Last but not least, by analyzing the detection results of IoT firmware, we make several interesting findings, for instance, different target binaries always tend to reuse the same code area of TPL. The datasets and source code used in this article are available at https://github.com/Siyuan-Li201/LibAM .
Siyuan Li 0014, Yongpan Wang, Chaopeng Dong, Shouguo Yang, Hong Li 0004, Hao Sun 0028, Zhe Lang, Zuxin Chen, Weijie Wang 0005, Hongsong Zhu, Limin Sun 0001
ACM Trans. Softw. Eng. Methodol.8
2023 VN-SMT: An SMT-based Construction Method on Virtual Network to Defend Insider Reconnaissance
abstract
Due to networks’ static and homomorphic nature, experienced attackers can quickly get the target network’s topology and internal host information by scanning. The virtual network view prevents network reconnaissance by simulating a virtual network topology for the network hosts, to consume the attacker’s attack resources and time. However, deploying a virtual network view will reduce network throughput and increase network latency, and an unreasonable virtual network view configuration will waste resources and reduce Quality of Services(QoS). We, therefore, propose a method VN-SMT that can rationally configure virtual network view. This method generates an optimal virtual network view base on existing host configuration, risk constraints, and budget constraints. We define metrics for deception, concealment, and resource consumption to measure the effectiveness of virtual network views. We conduct simulations to verify the effectiveness and feasibility of VN-SMT.
Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Qiujian Lv, Zuxin Chen, Siyuan Li 0014
WCNC5
2023 TA-GAN: transformer-driven addiction-perception generative adversarial network
Changhong Jing, Changwei Gong, Zuxin Chen, Bai Ying Lei, Shuqiang Wang
Neural Comput. Appl.3