Zhiyuan Fu

dblp:358/0879 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Network-Compute Trade-offs in Resource Depletion Attacks on LLM Inference Services
Zhiyuan Fu, Ruidong Li 0001, Qiuling Yue, Yuqing Zhang 0001
INFOCOM1
2026 BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw Detection
Lan Zhang 0008, Zhiyuan Fu, Jice Wang, Shangru Zhao, Qi Li 0002, Ruidong Li 0001, He Wang 0014, Yuqing Zhang 0001
NDSS4
2026 CtxFuzz: Discovering heap-based memory vulnerabilities through context heap operation sequence guided fuzzing
Cheng Wen 0002, Zhiyuan Fu, Shengchao Qin
Sci. Comput. Program.3
2025 MAAP: A Self-Evolving Multi-Agent Automated Vulnerability Repair Framework for Python
abstract
Automating vulnerability repair (AVR) in Python remains constrained by low accuracy, long feedback loops, and rapidly escalating token spend when large repositories must be reasoned about. These challenges are amplified by the prevalence of multi-file, environment-dependent CVEs whose fixes span configuration, tests, and cross-module semantics. We introduce MAAP, a self-evolving, role-specialized LLM architecture for end-to-end automated patch synthesis in Python codebases. MAAP decomposes a vulnerable repository into fine-grained, dependency-aware subtasks and dispatches them via a contextual-bandit router that jointly optimizes correctness, latency, and cost. An experience-centric knowledge base surfaces successful semantic exemplars and failure signals to prune search. An agent factory dynamically spawns, retires, or coordinates agents when novel patterns or degraded rewards emerge. We evaluate MAAP on 120 real-world Python CVEs. MAAP achieves a 70.3% patch success rate, surpassing the SWE-agent baseline, which has a 56.7% success rate. This improvement incurs a 62.8% higher average token cost, but it results in a $\mathbf{1 5. 5 \%}$ lower cost per successful patch. Ablation studies show substantial drops in success when disabling the router, knowledge base, or cooperative spawning, underscoring the necessity of each component. Collectively, these results indicate that MAAP’s design can deliver robust, largely hands-free vulnerability repair for Python at practical cost envelopes and is readily extensible to other language ecosystems.
Zhiyuan Fu, Ruidong Li 0001, Yuqing Zhang 0001
APSEC2
2025 FDLLM: A Dedicated Detector for Black-Box LLMs Fingerprinting
abstract
The proliferation of black-box Large Language Models (LLMs) makes source attribution essential for accountability and security. Yet, progress is limited by the lack of a large multilingual benchmark and by fragile or computationally intensive methods. We introduce FD-Dataset, a bilingual benchmark of 90,000 samples from 20 major LLMs, and FDLLM, a LoRA-adapted detector that extracts persistent decoding fingerprints from a foundation model. LoRA induces intra-model clustering and inter-model separation in representation space, explaining its effectiveness for fingerprinting. On FD-Dataset, FDLLM surpasses the strongest baseline by 22.1% Macro F1, generalizes to newly released models with 95% accuracy, and remains robust to polishing, translation, and synonym substitution, reducing average attack success rate from 49.2% (LM-D) to 23.9%.
Zhiyuan Fu, Lan Zhang 0008, Ruidong Li 0001, Peng Liu 0005, Jice Wang, Fannv He, Yuqing Zhang 0001
TrustCom1
2025 OSSDetector: Towards a More Accurate Approach for C/C++ Third-Party Library Detection
abstract
In today’s software development environment, third-party libraries (TPLs) enhance productivity but also introduce security risks. Effective Software Composition Analysis (SCA) is crucial for managing these risks. Yet, existing SCA tools for C/C++ projects struggle with challenges like detecting modified and nested TPLs, precise version representation, and comprehensive TPL databases. In modern software development, third-party libraries (TPLs) are commonly used to boost functionality and save development time. However, this convenience introduces security risks. We introduce OSSDetector, a new SCA tool that addresses these issues. OSSDetector uses sliding window and fuzzy hashing techniques to generate detailed signatures, improving detection of modified TPLs. It features a "Nested TPL Function Filtering" algorithm to accurately identify and filter nested TPL functions, and a "TPL Recognition" algorithm based on import ratios and function paths to determine the TPLs used in the software. It also addresses version representation by using function weights and release times. To overcome the lack of a comprehensive TPL database, we have developed a large database with 29,416 C/C++ TPLs and 767,405 versions. Experimental results demonstrate that OSSDetector surpasses state-of-the-art tools, achieving better precision (85.52%), recall (79.82%), and F1 score (82.57%), and higher precision (84.27%) at the library version level.
Xiang Hai, Zhiyuan Fu, Yansong Shi, Jice Wang, Fannv He, Yuqing Zhang 0001
TrustCom3
2025 Ferroelectric materials, devices, and chips technologies for advanced computing and memory applications: development and challenges
abstract
Abstract Hafnium (Hf) oxide-based ferroelectric materials have emerged as a transformative platform for next-generation non-volatile memory and advanced computing technologies. This review comprehensively examines the development, challenges, and applications of HfO 2 ferroelectrics, emphasizing their CMOS compatibility, scalability, and robust polarization at nanoscale dimensions. Breakthroughs in doping strategies, stress engineering, and VO control have stabilized the metastable orthorhombic phase, enabling high-performance devices such as ferroelectric RAM (FeRAM), ferroelectric field-effect transistors (FeFETs), and ferroelectric tunnel junctions (FTJs). These devices offer ultrafast switching, low power consumption, and multi-level storage, driving innovations in neuromorphic computing, in-memory processing, and cryogenic systems; nonetheless, they face ongoing challenges in reliability, such as fatigue and imprint effects, and scalability at sub-5 nm technology nodes. Emerging frontiers, such as wurtzite-structured nitrides (e.g., AlScN) and antiferroelectric ZrO 2 -based systems, have garnered significant attention due to their exceptionally high remanent polarization and promising potential for enhanced endurance, respectively. Further addressing the reliability issues of these emerging ferroelectric materials and the challenges associated with large-scale integration processes through interdisciplinary efforts will unlock the full potential of ferroelectric technologies, positioning them as pivotal enablers of post-Moore computing architectures and sustainable AI-driven applications.
Ni Zhong, Tianjiao Xin, Tiancheng Gong, Jiezhi Chen, Zhiyuan Fu, Kechao Tang, Xiuyan Li, Xinqiang Wang, Anquan Jiang, Peiyuan Du, Chengji Jin, Haoji Qian, Siying Zheng, Haiwen Xu, Bochang Li, Zheng-Dong Luo, Jiuren Zhou, Genquan Han
Sci. China Inf. Sci.10
2024 IMCE: An In-Memory Computing and Encrypting Hardware Architecture for Robust Edge Security
abstract
Edge devices deployed in unsupervised scenarios employ Physical Unclonable Functions (PUFs) for identity authentication and embedded XOR encoding for data encryption. However, on the one hand, the existing strong PUFs such as CMOS-based XOR Arbiter PUFs and NVM-based RRAM PUFs are vulnerable to various machine learning (ML) modeling attacks. On the other hand, the transmission of keys for embedded XOR encoding also faces the risk of being eavesdropped in unsecured channels. In response to these challenges, this paper proposes a high-security In-Memory Computing and Encrypting (IMCE) hardware architecture based on a FeFET macro, featuring both a PUF mode for identity authentication and an encrypted CIM mode with in-situ decryption. The PUF mode ensures a prediction accuracy close to 50% (equivalent to random guessing attack) under various ML models due to the proposed Hamming distance comparison used in challenge-response pairs (CRPs) generation. In addition, by utilizing the CRPs generated in PUF mode as encryption keys, the CIM mode of IMCE achieves robust security through public-key cryptography via CRPs-masked key transfer, preventing the leakage of keys and data. Therefore, by applying a novel CRPs generation scheme and reusing the generated CRPs for in-situ CIM decryption, the security of both PUF and encrypted CIM mode is enhanced concurrently. In addition, IMCE significantly reduces the power overhead thanks to the high energy efficiency of ferroelectric FETs (FeFETs), making it highly suitable for secure applications in edge computing devices.
Hanyong Shao, Boyi Fu, Jinghao Yang, Wenpu Luo, Zhiyuan Fu, Kechao Tang, Ru Huang 0001
DATE6
2024 MemSpate: Memory Usage Protocol Guided Fuzzing
Zhiyuan Fu, Cheng Wen 0002, Zhiwu Xu 0001, Shengchao Qin
ICFEM1
2024 Research on Lifecycle-Driven Government Data Security Model and Data Grouping Technology
abstract
In the context of the information age, promoting digital government and smart cities has made government data sharing a key trend. Given its special nature, securing government data requires an effective security system for safe and efficient management. This paper explores government data security and technical systems, examines China's current data management situation, and compares management strategies in China, the EU, and the US. This paper adopts a data lifecycle-driven security management approach and leverages two widely recognized frameworks to propose a system that balances data openness and security. Finally, we propose an integrated learning method based on BERT and Random Forest, use real data sets to verify the feasibility of data grouping, and promote the integration of government data management and efficient technology.
Jingfeng Rong, Zhiyuan Fu, Qiuling Yue, Anmin Fu, Xujie Liu, Anshun Zhou, Yuqing Zhang 0001
TrustCom3
2024 Computation EE Fairness for a UAV-Enabled Wireless Powered MEC Network With Hybrid Passive and Active Transmissions
abstract
Energy-efficient computation is an inevitable trend for unmanned aerial vehicles (UAV)-enabled wireless powered mobile edge computing (MEC), while it has not been investigated when the hybrid passive and active transmissions (ATs) are considered for Internet of Things (IoT) nodes’ task offloading. In this paper, we study the computation energy efficiency (EE) fairness among IoT nodes in a UAV-enabled wireless powered MEC network with hybrid passive and ATs, where the UAV serves as a dynamic energy source to support IoT nodes for backscatter communication (BackCom) and AT. Specifically, we formulate an optimization problem to maximize the computation EE of the worst IoT node by jointly optimizing the UAV’s transmit power and trajectory, the IoT nodes’ BackCom time and reflection coefficients, the IoT nodes’ AT power and time, as well as the IoT nodes’ local computing time and frequencies. The formulated problem is highly non-convex and difficult to be solved optimally. To address it, we first obtain the closed-form expressions for the UAV’s transmit power and the IoT nodes’ local computing time by means of the proof by contradiction to simplify the problem, and then propose a Dinkelbach-based iterative algorithm to obtain the solution of other optimization variables. Specifically, based on the Dinkelbach’s method, the original fractional problem is transformed into the problem with the subtractive objective function. Then we further decouple the transformed problem into two subproblems based on the block-coordinated-decent (BCD) method and solve the transformed problem by the proposed BCD-based iterative algorithm, where the above two subproblems are solved by means of the existing convex optimization tools and the proposed successive convex approximation (SCA)-based iterative algorithm alternatively. Simulation results show that the proposed algorithms have a fast rate of convergence and that the proposed scheme outperforms other baseline schemes in terms of the computation EE fairness.
Zhiyuan Fu, Liqin Shi, Yinghui Ye, Gan Zheng 0001
IEEE Internet Things J.1