VLDB 2026 Research / reviewers in the wild / expert
Shuangxiang Kan
dblp:349/0810
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-2807-1420ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MUTATO: Enhancing Fuzz Drivers with Adaptive API Option Mutation
Shuangxiang Kan, Yuekang Li |
NDSS | 1 |
| 2026 | PufferDoS: Efficient and Effective Attack String Generation for Regular Expression Denial of Service Vulnerabilities
Shangzhi Xu, Yuekang Li, Nan Sun 0002, Benjamin Turnbull, Shuangxiang Kan, Siqi Ma 0001 |
SP | 7 |
| 2026 | Multi-Component Fault Tolerance and Path Construction in Interconnection NetworksabstractIn the realm of interconnection networks, reliability analysis is of utmost importance, especially considering the increasing vulnerability of components as the network scales. Fault tolerance is a key aspect in this regard, and extra connectivity and component connectivity are two crucial metrics for its assessment. In this paper, we establish a theoretical framework for multi-component fault tolerance in the augmentedk-aryn-cubeAQn,k, a hypercube-derived interconnection network commonly used in distributed-memory architectures. We derive a general result for ther-component connectivity ofAQn,kas$4n(n - 1) - \lfloor{\frac{{5{{(r - 1)}^2}}}{2}}\rfloor$(n≥ 4,k≥ 4, and 2 ≤r≤n). Furthermore, we extend the result to explore theh-extrar-component connectivity ofAQn,kas (8n− 10)(r−1) −2(r−2) (n≥ 4,k≥ 4,h= 1 and 2≤r≤n). Based on these theoretical results, we propose a novel fault-tolerant path algorithm forAQn,kthat handlesh-extrar-component faults. The algorithm first preprocesses and classifies fault-free components, which efficiently determines whether two fault-free nodes belong to the same component, thereby avoiding ineffective path searches. When two fault-free nodes are in the same component, we employ a hybrid greedy-BFS algorithm to construct fault-free paths between them. To validate the algorithm, we conduct comprehensive simulations onAQn,kwith varying parameters. The experimental results demonstrate that the proposed algorithm achieves constant-time path existence queries after preprocessing, significantly reduces path discovery time in multi-query scenarios compared to conventional methods, and maintains near-optimal path lengths while exhibiting superior scalability as network dimensions increase. Furthermore, the algorithm demonstrates robust and highly efficient performance even under fault conditions significantly exceeding theoretical connectivity limits. Additionally, the greedy strategy effectively resolves the vast majority of pathfinding scenarios, confirming its effectiveness underh-extrar-component fault conditions. Xueli Sun, Shuangxiang Kan, Jianxi Fan, Weibei Fan, Zhenjiang Dong |
IEEE Trans. Computers | 2 |
| 2026 | A Graph Neural Network Approach for Hybrid Node-Edge Fault Diagnosis in Interconnection Networks Under the HPMC* ModelabstractFault diagnosis is crucial for ensuring the reliability of interconnection networks. Traditional diagnostic models usually assume that edges connected to faulty nodes are fault-free, which is unrealistic in practice where both node and edge failures can occur simultaneously. The recently proposed HPMC* diagnostic model provides a more realistic framework by considering both node and edge failures simultaneously, but existing diagnostic approaches under this model have significant limitations in handling complex fault scenarios. This paper proposes HYBRID-GNN, the first graph neural network-based approach for hybrid fault diagnosis under the HPMC* model. HYBRID-GNN employs an edge-enhanced GraphSAGE with comprehensive feature engineering that extracts diagnostic characteristics from HPMC* syndrome data and enables joint training for node and edge fault prediction. HYBRID-GNN learns complex fault patterns from syndrome data, overcoming traditional diagnosability constraints. Experiments on multiple interconnection network topologies show that HYBRID-GNN matches the traditional algorithm in node fault diagnosis (achieving over 99% accuracy within the hybrid diagnosability bound), while delivering substantially higher performance in link fault diagnosis (with accuracy above 97%). Even beyond the diagnosability bound, HYBRID-GNN remains robust, maintaining over 98% node accuracy and over 83% link precision under high fault rates. Furthermore, results on real-world networks further validate its practical effectiveness, achieving over 99% node accuracy and over 95% link accuracy. Xueli Sun, Shuangxiang Kan, Weibei Fan, Zhenjiang Dong, Jianxi Fan |
IEEE Trans. Netw. | 2 |
| 2026 | Spectre: Automated Aliasing Specification Generation for Library APIs with FuzzingabstractStatic program analysis of real-world software that integrates numerous library Application Programming Interfaces (APIs) faces significant challenges due to inaccessible or highly complex source code. A common workaround is to use specifications that summarize the key behaviors of these APIs for analysis. However, manually writing specifications is labor-intensive and requires a deep understanding of API semantics, while existing automated specification generation techniques struggle when source code is inaccessible or partially available. This article introduces Spectre , an automated framework that leverages fuzzing techniques to generate aliasing specifications for library APIs. Spectre operates efficiently and precisely both with and without source code access. When source code is unavailable, Spectre integrates alias-check observers into the driver program after the API call site and performs black-box fuzzing to explore different API behaviors. If a check is satisfied, the corresponding aliasing specification is generated. When source code is available, Spectre incorporates new grey-box fuzzing features specifically tailored for aliasing specification inference, further enhancing its ability to generate aliasing specifications. We conducted extensive experiments to evaluate the performance of Spectre . Without source code access, Spectre demonstrated its specification generation capability across both Musl, a lightweight C standard library, and eight C third-party libraries. For Musl, Spectre recovered 96.7% of correct manually written specifications and identified 40.0% more aliasing specifications than those written by external experts. For C third-party libraries, all Spectre -generated aliasing specifications were validated as correct through static analysis of the API source code. Spectre is also more complete than other specification inference tools, generating 16.7% more correct specifications for third-party libraries. The practicality of the generated specifications was confirmed, as they improved aliasing analysis in static pointer analysis of client code while maintaining a balance between accuracy and efficiency. The effectiveness of the tailored grey-box fuzzing features was demonstrated by Spectre , identifying 20% more specifications compared to when these features were disabled. These results show that Spectre is an effective tool for inferring aliasing specifications and facilitating static analysis. Shuangxiang Kan, Yuekang Li, Weigang He, Zhenchang Xing, Liming Zhu 0001, Yulei Sui |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2025 | Interactive Cross-Language Pointer Analysis for Resolving Native Code in Java ProgramsabstractJava offers the Java Native Interface (JNI), which allows programs running in the Java Virtual Machine to invoke and be manipulated by native applications and libraries written in other languages, typically C. While JNI mechanism significantly enhances the Java platform's capabilities, it also presents challenges for static analysis of Java programs due to the complex behaviors introduced by native code. Therefore, effectively resolving the interactions between Java and native code is crucial for static analysis. In this paper, we introduce JNIFER, the first interactive cross-language pointer analysis for resolving native code in Java programs. JNIFER integrates both Java and C pointer analyses, equipped with advanced native call and JNI function analyses, enabling the simultaneous analysis of both Java and native code. During the analysis of crosslanguage interactions, the two analyzers interact with each other, constructing cross-language points-to relations and call graphs, thereby approximating the runtime behavior at the interaction sites. Our evaluation shows that JNIFER outperforms state-of-the-art approaches in terms of soundness while maintaining high precision and comparable efficiency, as evidenced by extensive experiments on OpenJDK and real-world Java applications. Yufei Liang, Tian Tan 0001, Chang Xu 0001, Shuangxiang Kan, Yulei Sui, Yue Li 0006 |
ICSE | 5 |
| 2024 | Cross-Language Taint Analysis: Generating Caller-Sensitive Native Code Specification for JavaabstractCross-language programming is a common practice within the software development industry, offering developers a multitude of advantages such as expressiveness, interoperability, and cross-platform compatibility, for developing large-scale applications. As an important example, JNI (Java Native Interface) programming is widely used in diverse scenarios where Java interacts with code written in other programming languages, such as C or C++. Conventional static analysis based on a single programming language faces challenges when it comes to tracing the flow of values across multiple modules that are coded in different programming languages. In this paper, we introduce CSS, a newCaller-Sensitive Specificationapproach designed to enhance the static taint analysis of Java programs employing JNI to interface with C/C++ code. In contrast to conservative specifications, this approach takes into consideration the calling context of the invoked C/C++ functions (or cross-language context), resulting in more precise and concise specifications for the side effects of native code. Furthermore, CSS specifically enhances the capabilities of Java analyzers, enabling them to perform precise static taint analysis across language boundaries into native code. The experimental results show that CSS can accurately summarize value-flow information and enhance the ability of Java monolingual static analyzers for cross-language taint flow tracking. Shuangxiang Kan, Yuhao Gao, Zexin Zhong, Yulei Sui |
IEEE Trans. Software Eng. | 1 |
| 2023 | Component Reliability of a Class of Regular Networks and Its ApplicationsabstractWith the continuous attention to the parallel computing system, the reliability of the system, which is mainly measured by two parameters, connectivity and diagnosability, needs to be constantly studied and improved. At present, the component connectivities of some networks have been extensively studied, while the component diagnosabilities of these networks have rarely involved in. In this article, some networks with common characteristics are summarized as a class of regular networks. The definition of this kind of networks is given, and its reliability based on component failures is determined. To be specific, we prove that$c\kappa _{m+1}(G)=m(k-1)-\binom{m}{2}+1$for$1\leq m\leq k-2$and$ct_{m+1}(G)=(m+1)k-\binom{m}{2}-2\ m$for$1\leq m\leq k-2$under the PMC model, where$c\kappa _{m+1}(G)$and$ct_{m+1}(G)$represent the$(m+1)$-component connectivity and the$(m+1)$-component diagnosability of such networks$G$, respectively. Based on this, we design a low time complexity component diagnosis algorithm for this kind of networks. As applications, the above two component reliability parameters of many famous networks are explored. Furthermore, the proposed diagnosis algorithm is simulated on these networks, and the results show that the algorithm has high diagnosis accuracy for various networks. Xueli Sun, Jianxi Fan, Shuangxiang Kan, Weibei Fan, Xiaohua Jia |
IEEE Trans. Reliab. | 3 |