VLDB 2026 Research / reviewers in the wild / expert
Shiyao Zhou
dblp:338/9671
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2025
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LWDIFF: an LLM-Assisted Differential Testing Framework for Webassembly RuntimesabstractWebAssembly (Wasm) runtimes execute Wasm programs, a popular low-level language for efficiently executing high-level languages in browsers, with broad applications across diverse domains. The correctness of those runtimes is critical for both functionality and security of Wasm execution, motivating testing approaches that target Wasm runtimes specifically. However, existing Wasm testing frameworks fail to generate test cases that effectively test all three phases of runtime, i.e., decoding, validation, and execution. To address this research gap, we propose a new differential testing framework for Wasm runtimes, which leverages knowledge from the Wasm language specification that prior techniques overlooked, enhancing comprehensive testing of runtime functionality. Specifically, we first use a large language model to extract that knowledge from the specification. We use that knowledge in the context of multiple novel mutation operators that generate test cases with diverse features to test all three runtime phases. We evaluate LWDIFF by applying it to eight Wasm runtimes. Compared with the state-of-the-art Wasm testers, LWDIFF achieves the highest branch coverage and identifies the largest number of bugs. In total, LWDIFF discovers 31 bugs across eight runtimes, all of which are confirmed, with 25 of them previously undiscovered. Shiyao Zhou, He Ye, Hao Zhou 0043, Claire Le Goues, Xiapu Luo |
ICSE | 1 |
| 2025 | Fuzzy Adaptive Event-Triggered Economic Operation for Multiarea Robust Frequency Regulation Under Unsecured Communication ChannelabstractThis article studies the frequency fluctuation problems of a multiarea power system with decentralized control strategy for economic operation under load disturbance and unsecured communication channel. To address the above issues, decentralized bandwidth-aware fuzzy adaptive event triggered mechanism (DBFA-ETM) is proposed to compromise between the utilization of bandwidth resources and the frequency regulation performance by intelligently adjusting the threshold. Then, the decentralized LFC power system model with DBFA-ETM is reconstructed under the mixed attacks. By applying an improved looped-functional, feasible solutions are obtained according to Lyapunov stability theory to ensure that the power system is asymptotically stable with the prescribed$H_{\infty }$performance index level. In addition, the frequency regulation performance is optimized by using the particle swarm optimization (PSO) algorithm. Simulation results on a New-England IEEE 39-bus system with quantitative analyses illustrate that the proposed method has the effectiveness and potential on engineering application in the aspect of economic operation. Shiyao Zhou, Hao Chen 0021, Shouming Zhong |
IEEE Internet Things J. | 1 |
| 2025 | SCFMUNet: A fusion architecture based on multi-scale state space model and channel attention for medical image segmentation
Zhiyong Huang 0004, Mingyang Hou, Shiyao Zhou, Jiahong Wang, Yan Yan 0022, Yushi Liu 0001, Hans Gregersen |
Neural Networks | 5 |
| 2025 | Attention-guided fusion of transformers and CNNs for enhanced medical image segmentation
Shiyao Zhou, Zhiyong Huang 0004, Yuqin He, Yunlan Zhao |
Vis. Comput. | 1 |
| 2023 | Demystifying Privacy Policy of Third-Party Libraries in Mobile AppsabstractThe privacy of personal information has received significant attention in mobile software. Although researchers have designed methods to identify the conflict between app behavior and privacy policies, little is known about the privacy compliance issues relevant to third-party libraries (TPLs). The regulators enacted articles to regulate the usage of personal information for TPLs (e.g., the CCPA requires businesses clearly notify consumers if they share consumers' data with third parties or not). However, it remains challenging to investigate the privacy compliance issues of TPLs due to three reasons: 1) Difficulties in collecting TPLs' privacy policies. In contrast to Android apps, which are distributed through markets like Google Play and must provide privacy policies, there is no unique platform for collecting privacy policies of TPLs. 2) Difficulties in analyzing TPL's user privacy access behaviors. TPLs are mainly provided in binary files, such as jar or aar, and their whole functionalities usually cannot be executed independently without host apps. 3) Difficulties in identifying consistency between TPL's functionalities and privacy policies, and host app's privacy policy and data sharing with TPLs. This requires analyzing not only the privacy policies of TPLs and host apps but also their functionalities. In this paper, we propose an automated system named ATPChecker to analyze whether Android TPLs comply with the privacy-related regulations. We construct a data set that contains a list of 458 TPLs, 247 TPL's privacy policies, 187 TPL's binary files and 641 host apps and their privacy policies. Then, we analyze the bytecode of TPLs and host apps, design natural language processing systems to analyze privacy policies, and implement an expert system to identify TPL usage-related regulation compliance. The experimental results show that 23% TPLs violate regulation requirements for providing privacy policies. Over 47% TPLs miss disclosing data usage in their privacy policies. Over 65% host apps share user data with TPLs while 65% of them miss disclosing interactions with TPLs. Our findings remind developers to be mindful of TPL usage when developing apps or writing privacy policies to avoid violating regulations, Kaifa Zhao, Xian Zhan, Le Yu 0002, Shiyao Zhou, Hao Zhou 0043, Xiapu Luo, Haoyu Wang 0001, Yepang Liu 0001 |
ICSE | 4 |
| 2023 | WADIFF: A Differential Testing Framework for WebAssembly RuntimesabstractWebAssembly (Wasm) runtime provides a virtual machine that can execute the WebAssembly modules and is widely used in different areas (e.g., browsers, edge computing, blockchain). Thus, the precision and reliability of the WebAssembly runtime are important and deserve our attention. To ensure the correctness and detect potential bugs in WebAssembly runtimes, we propose WADIFF, a differential testing framework, which consists of a sufficient test case generator and a deterministic differential testing engine. To evaluate the effectiveness of WADIFF, we apply it to seven popular WebAssembly runtimes and found 417 inconsistent instructions due to bugs and different implementations in the runtimes. Furthermore, we identify 21 bugs from 7 WebAssembly runtimes, and 8 of them are confirmed by their developers. Shiyao Zhou, Muhui Jiang, Hao Zhou 0043, Haoyu Wang 0001, Xiapu Luo |
ASE | 1 |
| 2022 | A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant IdentificationabstractPrivacy protection raises great attention on both legal levels and user awareness.To protect user privacy, countries enact laws and regulations requiring software privacy policies to regulate their behavior.However, privacy policies are written in natural languages with many legal terms and software jargon that prevent users from understanding and even reading them.It is desirable to use NLP techniques to analyze privacy policies for helping users understand them.Furthermore, existing datasets ignore law requirements and are limited to English.In this paper, we construct the first Chinese privacy policy dataset, namely CA4P-483, to facilitate the sequence labeling tasks and regulation compliance identification between privacy policies and software.Our dataset includes 483 Chinese Android application privacy policies, over 11K sentences, and 52K fine-grained annotations.We evaluate families of robust and representative baseline models on our dataset.Based on baseline performance, we provide findings and potential research directions on our dataset.Finally, we investigate the potential applications of CA4P-483 1 combing regulation requirements and program analysis. Kaifa Zhao, Le Yu 0002, Shiyao Zhou, Jing Li 0049, Xiapu Luo, Aemon Yat Fei Chiu |
EMNLP | 3 |
| 2021 | Robust Android Malware Detection against Adversarial Example AttacksabstractAdversarial examples pose severe threats to Android malware detection because they can render the machine learning based detection systems useless. How to effectively detect Android malware under various adversarial example attacks becomes an essential but very challenging issue. Existing adversarial example defense mechanisms usually rely heavily on the instances or the knowledge of adversarial examples, and thus their usability and effectiveness are significantly limited because they often cannot resist the unseen-type adversarial examples. In this paper, we propose a novel robust Android malware detection approach that can resist adversarial examples without requiring their instances or knowledge by jointly investigating malware detection and adversarial example defenses. More precisely, our approach employs a new VAE (variational autoencoder) and an MLP (multi-layer perceptron) to detect malware, and combines their detection outcomes to make the final decision. In particular, we share a feature extraction network between the VAE and the MLP to reduce model complexity and design a new loss function to disentangle the features of different classes, hence improving detection performance. Extensive experiments confirm our model’s advantage in accuracy and robustness. Our method outperforms 11 state-of-the-art robust Android malware detection models when resisting 7 kinds of adversarial example attacks. Heng Li 0008, Shiyao Zhou, Wei Yuan 0001, Xiapu Luo, Cuiying Gao, Shuiyan Chen |
WWW | 2 |