VLDB 2026 Research / reviewers in the wild / expert
Zewen Shang
dblp:337/8236
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | STLIB: An information bottleneck-guided LLM-spatiotemporal framework for traffic forecasting
Zewen Shang, Xuewei Li 0001, Zhiqiang Liu 0002, Yingzhou Sun, Mei Yu 0004 |
Knowl. Based Syst. | 1 |
| 2025 | A Novel Network for Short-Term Wind Speed Prediction: Mitigating Distribution Shift and Feature LossabstractAccurate wind speed forecasting is essential for mitigating the challenges of wind power grid integration. However, existing wind speed prediction models overlook the distributional shift problem within wind speed series, and this time-varying distribution can significantly impact wind prediction accuracy. In this paper, we propose the Distribution Shift and Feature Decoupling Network (DSFD-Net), which addresses the issue of distributional shifts occurring both within the input series and between the input and predicted series through a distribution matching model and distribution mapping module, respectively. Additionally, we introduce a feature decoupling module to mitigate the feature loss encountered in our work. We conduct extensive experiments on two datasets, and comprehensive experimental results demonstrate that DSFD-Net achieves at least a 4.1% reduction in error metrics compared to other wind speed forecasting models, indicating superior performance. Mei Yu 0004, Shengkang Dong, Xuewei Li 0001, Zewen Shang, Yingzhou Sun, Zhiqiang Liu 0002 |
ICASSP | 4 |
| 2025 | Short-term wind speed prediction method based on prior wind direction knowledge and multi-period decoupling
Zewen Shang, Xuewei Li 0001, Zhiqiang Liu 0002, Yingzhou Sun, Jian Yu 0003, Mei Yu 0004 |
Eng. Appl. Artif. Intell. | 1 |
| 2025 | 5Ghoul: Unleashing Chaos on 5G Edge Devices via Stateful Multi-Layer FuzzingabstractIn this paper, we present5Ghoul, a framework to systematically discover and replicate security vulnerabilities on arbitrary 5 G edge devices (UE). At the core of5Ghoulis a stateful fuzzing strategy that provides full control to arbitrarily manipulate any packet down to the data link layer. Moreover,5Ghoulautomatically constructs the protocol state machines to guide the fuzzing process and employs novel strategies to reliably exploit vulnerabilities on commercial-off-the-shelf (COTS) UEs over-the-air. The design choices in5Ghoulwere carefully taken to allow packet manipulation in real-time, which, in turn allowed us to fuzz down to data link layer. As of today, we have evaluated5Ghoulwith seven COTS 5 G UEs (smartphones and USB modems) and one open source framework (OpenAirInterface).5Ghoulhas uncovered 12 unknown security vulnerabilities (14 in total) out of which ten exist in COTS UEs (ten CVEs assigned) from major vendors (e.g., Qualcomm and MediaTek). Moreover, of these COTS UE vulnerabilities have been confirmed to have high severity. We also won a bug bounty of over 20 K USD from Qualcomm and MediaTek for discovering these vulnerabilities. We envision5Ghoulto open the door for 5G security testing at scale. Matheus E. Garbelini, Zewen Shang, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | U-Fuzz: Stateful Fuzzing of IoT Protocols on COTS DevicesabstractInternet-of-Things (IoT) devices have become widely popular and are being increasingly utilized in both home and industrial environments. Such devices use a variety of different protocols for communication. Considering the complex and stateful nature of these protocols, their implementations may contain security vulnerabilities and are subject to remote exploitation. To address this, we present U-Fuzz, a framework to systematically discover and replicate security vulnerabilities on arbitrary wired and wireless IoT protocol implementations. Given only a network capture file which contains the packet traces of normal (i.e., benign) communication, U-Fuzz automatically constructs a protocol state machine. Subsequently, this state machine is leveraged via a stateful fuzzing engine to arbitrarily manipulate and replay communicated packets. U-Fuzz carefully disintegrates the design of state machine construction from the fuzzing actions and optimizations, allowing U-Fuzz to work with an arbitrary number of protocols without any change in the stateful fuzzing engine. U-Fuzz does not require any access to the source code of the protocol and it also does not involve any instrumentation. This makes U-Fuzz to applicable out-of-the-box for fuzzing arbitrary IoT devices employing a variety of protocols. We implemented U-Fuzz and applied it against ten subject implementations including implementations on five commercial-off-the-shelf (COTS) devices employing three popular IoT protocols: 5G NR, Zigbee, and CoAP. As of today, U-Fuzz discovered a total of 11 new vulnerabilities (out of 16) and CVEs have already been assigned to all of them. Zewen Shang, Matheus E. Garbelini, Sudipta Chattopadhyay 0001 |
ICST | 1 |
| 2024 | U-Fuzz: A Tool Prototype for Stateful Fuzzing of IoT Protocols on COTS DevicesabstractInternet-of-Things (IoT) devices have become widely popular and are being increasingly utilized in both home and industrial environments. Such devices use a variety of protocols for communication. Considering the complex and stateful nature of these protocols, their implementations may contain security vulnerabilities. To address this, we present u-Fuzz, a framework to automatically generate state machine and systematically discover security vulnerabilities on arbitrary wired and wireless IoT protocol implementations. U- Fuzz only takes a network capture file, which contains the packet traces of normal (i.e., benign) communication for the state machine construction and it does not require any access to the source code of the protocol. U-Fuzz does not demand any instrumentation. This makes U-Fuzz to applicable out-of-the-box for constructing state machine for fuzzing arbitrary IoT devices employing a variety of protocols. Evaluation of U - Fuzz with three popular IoT protocols (5G NR, Zigbee, and CoAP) reveals 11 new vulnerabilities (11 CVEs) and a total of 16 security flaws. Zewen Shang, Matheus E. Garbelini, Sudipta Chattopadhyay 0001 |
ICST | 1 |
| 2023 | Analysis to Creation: Using the ADDIE Model to Develop an Educational Game for ChildrenabstractCreating educational games for children is a notable emphasis, especially when using the ADDIE model as a game development framework. Furthermore, we introduce the ADDIE model, a recognized instructional design framework, to illustrate its potential in the video game industry. In this study, by using constructivist and social learning theories, educational play can be fostered through exploration, cooperation, and reflection. Hence, we create a children's educational video game using the ADDIE model to explore creating suitable educational games. Striking the right balance between education and entertainment necessitates a comprehensive grasp of how children learn and develop. By leveraging this knowledge, developers and educators can create video games that are both enjoyable and promote learning and development in children. Nurul Nadwa Zulkifli, Ahmad Fauzi Mohd Ayub, Zewen Shang |
ICCE | 4 |
| 2022 | Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the AirabstractRecent rise in the mobile network communication vulnerabilities highlights the need for systematic security testing frameworks for communication protocols. In this paper, we propose a real-time framework to fully manipulate the 4G and 5G data-link and network communication to the base station (eNB/gNB). This is for experimenting and testing the security of data-link protocols such as Media Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and network protocols such as Radio Resource Control (RRC) and Non-access stratum (NAS). Although we focus on the base station, our framework is equally applicable for manipulating the communication to the user equipment (UE). An appealing feature of our framework is that it automatically constructs the protocol state machine during normal communication. This allows us to validate the response from the base station when it is subjected to unexpected packet sequences. Our framework also exposes an application programming interfaces (APIs) for designers to install custom attack scenarios. We have implemented our framework and used it to generate several (adversarial) scenarios that include injection of malformed and out-of-order packets as well as flooding certain packets. Our evaluation revealed crashes in OpenAirInterface (OAI) UE and gNB, as well as in Open5GS core network. Additionally, we guide our validation via the automatically constructed state machine and have caught most adversarial scenarios during our evaluation. We envision our proposed framework to provide the foundation for automated security testing of 4G/5G data-link protocol implementation. Matheus E. Garbelini, Zewen Shang, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
GLOBECOM | 2 |