VLDB 2026 Research / reviewers in the wild / expert
Xiangfei Xu
dblp:353/5558
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0007-2931-4109ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | VulFinder: Exploring Chaincode Vulnerabilities More Effectively and Efficiently Using Knowledge Graph Based Defect Pattern MatchingabstractHyperledger Fabric is an open-source project of Linux Foundation, it is a modular blockchain framework and has become an unofficial standard for enterprise blockchain platforms. In Hyperledger Fabric, smart contract is also known as chaincode, which are usually written using general-purpose languages, including Go, Java or Node.js etc. Although there are some vulnerability detection methods for Java and Node.js, there are very few vulnerability detection methods for Go, especially when it is used as a smart contract programming language in Hyperledger Fabric.In this article, we propose a knowledge graph based defect pattern matching method and develop a tool calledVulFinderto detect vulnerabilities in chaincode, i.e. the smart contracts written using Go language. Knowledge graph is used because it can fully retain the syntax and logic information of smart contracts. The method consists of two key steps: a knowledge graph is constructed fromGo language specificationand chaincode source code, including the definition of ontology layer and the construction of instance layer; the defect patterns are defined and SPARQL query statements are used to match and locate vulnerabilities on the knowledge graph. To evaluate the detection effectiveness and efficiency ofVulFinder, we construct two datasets through manual analysis and vulnerabilities injection due to the lack of public datasets. Experimental results show thatVulFindercan detect 22 kinds of typical vulnerabilities of chaincode effectively, and therecallis as high as 98.87%, while thefalse negative rateis as low as 1.13% . Bixin Li, Tianyuan Hu, Xiangfei Xu, Lulu Wang 0001 |
IEEE Trans. Software Eng. | 3 |
| 2024 | SoliTester: Detecting exploitable external-risky vulnerability in smart contracts using contract account triggering methodabstractAbstract The vulnerability in smart contracts (SCs) on the blockchain system may lead to severe security compromises. The SC can be invoked from an externally owned account (EOA) or a contract account (CA). The account a user creates to receive or send ether is an EOA. A CA contains codes that can interact with SCs. In Solidity SC, some vulnerabilities can only be exploited by the interactions between CAs and vulnerable SCs, which can be named external‐risky vulnerabilities. Most state‐of‐the‐art (SOTA) detectors detect external‐risky vulnerabilities by executing contract codes as an EOA user, thus reporting many unexploitable vulnerabilities. Therefore, we propose a CA‐triggering method to identify exploitable external‐risky vulnerabilities in Solidity SCs. We first designed agent contracts to simulate CAs' interactions with the target SCs in the real blockchain environment. We then detect vulnerability exploitation by analyzing transaction logs between agent contracts and target SCs and identifying successful exploits. We implemented the CA‐triggering method in a tool named SoliTester and evaluated it using three benchmark datasets, which contain three types of external‐risky vulnerabilities, namely, Reentancy (RE), Unchecked Call (UcC), and TxOrigin (TO). The results show that SoliTester can efficiently detect exploitable external‐risky vulnerabilities with significantly better precisions and recalls than SOTA detectors. Tianyuan Hu, Jingyue Li, Xiangfei Xu, Bixin Li |
J. Softw. Evol. Process. | 3 |
| 2023 | CCDetector: Detect Chaincode Vulnerabilities Based on Knowledge Graph
Xiangfei Xu, Tianyuan Hu, Bixin Li |
COMPSAC | 1 |