VLDB 2026 Research / reviewers in the wild / expert
Zhiying Wu
dblp:36/10644
· DBLP profile ↗
18ranked-venue papers
7as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 3 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TGweaver: Synthesizing Transaction Graphs for De-anonymization AnalysisabstractMixing services run on blockchain trading systems, enhancing the transaction privacy of blockchain users. Yet, in recent years, the mixing services provide fertile ground for concealing illicit fund flows. Therefore, security experts make great efforts to find an effective de-anonymization of mixing services. Unfortunately, current de-anonymization technologies are constrained by a fundamental issue, i.e., the lack of a comprehensive, extensive, and reliably labeled benchmark dataset. To address this problem, we propose a new method for acquiring mixing transaction data. We design and implement a method named TGweaver, which actively executes the complete mixing workflow within a simulated blockchain environment. Furthermore, to enhance the realism of the dataset, we introduce a ''behavioral fingerprint'' mapping strategy. Ultimately, the proposed dataset includes over 891K transactions, scaling existing benchmark sizes by 2 to 4 orders of magnitude. In experiments, we use the proposed data to systematically evaluate existing de-anonymization techniques. Experimental results reveal that the current mixing address linking methods, based on heuristic rules, lacks generalization capability in complex scenarios, exhibiting low precision. In contrast, the methods utilizing supervised learning demonstrate significant advantages. Fajie Wu, Jiajing Wu, Zhiying Wu, Longjian He, Weiqiang Wang 0002 |
WWW | 3 |
| 2026 | SolPhishHunter: Toward Detecting and Understanding Phishing on SolanaabstractSolana is a rapidly evolving blockchain platform that has attracted an increasing number of users. However, this growth has also drawn the attention of malicious actors, with some phishers extending their reach into the Solana ecosystem. Unlike platforms such as Ethereum, Solana has distinct designs of accounts and transactions, leading to the emergence of new types of phishing transactions that we term SolPhish. We define three types of SolPhish and develop a detection tool called SolPhishHunter. Utilizing SolPhishHunter, we detect a total of 8,058 instances of SolPhish and conduct an empirical analysis of these detected cases. Our analysis explores the distribution and impact of SolPhish, the characteristics of the phishers, and the relationships among phishing gangs. Particularly, the detected SolPhish transactions have resulted in nearly $1.1 million in losses for victims. We report our detection results to the community and construct SolPhishDataset, thefirstSolana phishing-related dataset in academia. Zigui Jiang, Zhiying Wu, Jiajing Wu, Zibin Zheng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | CCIHunter: Enhancing Smart Contract Code-Comment Inconsistencies Detection via Two-Stage Pre-TrainingabstractSmart contracts are self-executing computer programs on blockchains. With the development of blockchain technology, the number of smart contracts has grown rapidly, as has the concern for their security. Regrettably, inconsistencies between the logic implemented in the code and the intentions described in the comments, known as Code–Comment Inconsistencies (CCI), are frequently present in some smart contracts. These inconsistencies can mislead readers in understanding the contract code and, in severe cases, may lead to vulnerabilities and economic losses. Existing learning-based methods are not tailored for smart contract languages, overlook the issue of insufficient context information caused by comment references and nested intentions, and rely on large-scale labeled data; whereas rule-based methods struggle to accommodate the flexibility with which developers express intentions, often resulting in false positives. To tackle the challenges posed by insufficient context information and the scarcity of labeled data, we introduce CCIHunter, a tool designed to detect CCIs in smart contracts. CCIHunter addresses the issue of insufficient context information during data modeling and incorporates a two-stage pre-training process that does not depend on labeled data to enhance its detection capabilities. Specifically, CCIHunter enhances comments based on templates and models code as a heterogeneous graph based on function calls. It utilizes CodeBERT and UniMp to generate embeddings for comments and code, respectively, and then calculates the similarity between these two embeddings. Consistency is judged by combining code embeddings, comment embeddings, and similarity scores. Notably, CCIHunter undergoes a two-stage pre-training that includes contrastive learning and mutation analysis, aiming to improve its ability to bridge the gap between code and comments and to focus on code elements at different granularities. Experimental results demonstrate that CCIHunter achieves a precision of 0.95, a recall of 0.90, and an F1 score of 0.93, outperforming existing tools. Jiajing Wu, Zhiying Wu, Dongcheng Tan, Weipeng Zou, Zigui Jiang, Yi Zhen, Zibin Zheng |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | F2PASeg: Feature Fusion for Pituitary Anatomy Segmentation in Endoscopic Surgery
Lumin Chen, Zhiying Wu, Tianye Lei, Xuexue Bai, Ming Feng, Yuxi Wang 0001, Gaofeng Meng, Zhen Lei 0001, Hongbin Liu 0001 |
MICCAI (9) | 2 |
| 2025 | Safeguarding Blockchain Ecosystem: Understanding and Detecting Attack Transactions on Cross-chain BridgesabstractCross-chain bridges are essential decentralized applications (DApps) to facilitate interoperability between different blockchain networks. Unlike regular DApps, the functionality of cross-chain bridges relies on the collaboration of information both on and off the chain, which exposes them to a wider risk of attacks. According to our statistics, attacks on cross-chain bridges have resulted in losses of nearly 4.3 billion since 2021. Therefore, it is particularly necessary to understand and detect attacks on cross-chain bridges. In this paper, we collect the largest number of cross-chain bridge attack incidents to date, including 49 attacks that occurred between June 2021 and September 2024, of which 22 were attacks on cross-chain bridge business logic. Our analysis reveal that attacks against cross-chain business logic cause significantly more damage than those that do not. These cross-chain attacks exhibit different patterns compared to normal transactions in terms of call structure, which effectively indicates potential attack behaviors. Given the significant losses in these cases and the scarcity of related research, this paper aims to detect attacks against cross-chain business logic, and propose the BridgeGuard tool. Specifically, BridgeGuard models cross-chain transactions from a graph perspective, and employs a two-stage detection framework comprising global and local graph mining to identify attack patterns in cross-chain transactions. We conduct multiple experiments on the datasets with 203 attack transactions and 40,000 normal cross-chain transactions. The results show that BridgeGuard's reported recall score is 36.32% higher than that of state-of-the-art tools and can detect unknown attack transactions. Jiajing Wu, Kaixin Lin, Dan Lin 0007, Bozhao Zhang, Zhiying Wu, Jianzhong Su |
WWW | 5 |
| 2025 | Hunting in the Dark Forest: A Pre-trained Model for On-chain Attack Transaction Detection in Web3abstractIn recent years, a large number of on-chain attacks have emerged in the blockchain empowered Web3 ecosystem. In the year of 2023 alone, on-chain attacks have caused losses of over 585 million. Attackers use blockchain transactions to carry out on-chain attacks, for example, exploiting vulnerabilities or business logic flaws in Web3 applications. A wealth of efforts have been devoted to detecting on-chain attack transactions through expert patterns and machine learning techniques. However, in this ever-evolving ecosystem, the performance of current methods is limited in detecting new on-chain attacks, due to the obsoleting of attack recognition patterns or the reliance on on-chain attack samples. In this paper, we propose a universal approach for detecting on-chain attacks even when there are few or even no new on-chain attack samples. Specifically, an in-depth analysis of the transaction characteristics is conducted, and we propose a new insight to train a generic attack transaction detecting model, i.e., transaction reconstruction. Particularly, to overcome the over-fitting in the transaction reconstruction task, we use the web-scale function comments related to transactions as supervision information, rather than expert-confirmed labels. Experimental results demonstrate that the proposed approach surpasses the supervised state-of-the-art by 13% in AUC, with just 30 known on-chain attack samples. Moreover, without any known attack samples, our method can still detect new on-chain attacks in the wild (with a precision of 61.83%). Among attacks detected in the wild, we confirm 1,692 address poisoning attacks, a new type of on-chain attack targeting token holders. Our code is available at: https://github.com/wuzhy1ng/attack_trans_detection_www25. Zhiying Wu, Jiajing Wu, Hui Zhang 0002, Zibin Zheng, Weiqiang Wang 0002 |
WWW | 1 |
| 2025 | Malo in the Code Jungle: Explainable Fault Localization for Decentralized ApplicationsabstractDecentralized applications (DApps) have long been sitting ducks for hackers due to their valuable cryptocurrency assets, exposing them to various security risks. When a DApp is attacked, promptly identifying faults is crucial to minimizing financial losses and ensuring effective fault repair. However, existing fault localization methods, which mostly rely on code coverage, often fall short for DApps, particularly when dealing with only one fault case. Furthermore, according to a prior survey, most developers expect fault localization tools to provide reasonable explanations.In this paper, we present Malo, a method for DApp-specific explainable fault localization. It identifies fault functions throughsuspicious token transfer-guided analysis, and then employs Large Language Models (LLMs) to generate explanations for these identified fault functions. Specifically, Malo examines function call traces and source codes of fault cases to acquireinternal knowledge, and also retrieves relevant project documents from the Web to obtainexternal knowledge. By integrating internal and external knowledge, Malo generates reasonable explanations for faults in DApps. Our evaluation on a dataset of 68 real-world DApp faults demonstrates that Malo can locate 62% of faults within the Top-5, 9% higher than the state-of-the-art method. The experiment results also demonstrate a remarkable alignment accuracy of 71% between the explanations generated by Malo and the ground truth. In addition, we conduct a user study, which confirms that explanations generated by Malo can aid developers in comprehending the root cause of faults. Our code and dataset are available online: https://github.com/SodalimeZero/Malo_Code.git. Hui Zhang 0002, Jiajing Wu, Zhiying Wu, Dan Lin 0007, Jiachi Chen, Zibin Zheng |
IEEE Trans. Software Eng. | 3 |
| 2024 | Bubble or Not: An Analysis of Ethereum ERC721 and ERC1155 Non-fungible Token EcosystemabstractThe non-fungible token (NFT) is an emergent type of cryptocurrency that has garnered extensive attention since its inception. The uniqueness, indivisibility, and humanistic value of NFTs are the key characteristics that distinguish them from traditional tokens. The market capitalization of NFT reached 21.5 billion USD in 2021, almost 200 times that of all previous transactions. However, the subsequent rapid decline in NFT market fever in the second quarter of 2022 casts doubt on the ostensible boom in the NFT market. To date, there has been no comprehensive and systematic study of the NFT trade market or of the NFT bubble and hype phenomenon. To address this gap, we conduct an in-depth investigation of the entire Ethereum ERC721 and ERC1155 NFT ecosystems by dividing the NFT ecosystem participants into three categories: creators, transferors, and holders, to understand their manipulations of NFTs and infer their intentions. We examine the differences between NFT and ERC20 traders and then analyze the possible reasons behind these differences, leading us to gain insights into the varying degrees of market bubble associated with the two kinds of tokens. Through the construction and analysis of the NFT transfer graph (NTG), we uncover certain anomalous behaviors related to bubbles, along with quantifying the proportion of these anomalous behaviors, to reveal the degree of bubbles within the entire ecosystem. Yixiang Tan, Zhiying Wu, Jieli Liu, Jiajing Wu, Ting Chen 0002, Kaixin Lin |
ISCAS | 2 |
| 2024 | DAppFL: Just-in-Time Fault Localization for Decentralized Applications in Web3abstractWeb3 describes an idea for the next evolution of the Internet, where blockchain technology enables the Internet of Value. As Web3 software, decentralized applications (DApps) have emerged in recent years. There exists a natural link between DApps and cryptocurrencies, where faults in DApps could directly lead to monetary losses associated with cryptocurrencies. Hence, efficient fault localization technology is of paramount importance for urgent DApp rescue operations and the mitigation of financial losses. However, fault localization methods applied in traditional applications are not well-suited for this specific field, due to their inability to identify DApp-specific fault features, e.g., a substantial amount of cryptocurrency is transferred from DApps to hackers. In order to explore the root cause of DApp faults, some researchers try to identify suspicious code snippets through mutation testing. Nonetheless, applying mutation testing for DApp fault localization is time-consuming and thus limited in practice. This paper conducts the first comprehensive study of DApp fault localization. We introduce DAppFL, a learning-based DApp fault localization tool that performs reverse engineering to gather executed source code and then trace cryptocurrency flow to assist in locating faulty functions. We also present the inaugural dataset for DApp fault localization, providing a new benchmark for this domain.Our experimental results demonstrate that DAppFL locates 63% of faults within the Top-5, 23% more than the state-of-the-art method. To facilitate further research, our code and dataset are freely available online: https://github.com/xplanet-sysu/awesome-works#dappfl. Zhiying Wu, Jiajing Wu, Hui Zhang 0002, Jiachi Chen, Zibin Zheng, Qing Xia 0007, Gang Fan, Yi Zhen |
ISSTA | 1 |
| 2024 | Fishing for Fraudsters: Uncovering Ethereum Phishing Gangs With Blockchain DataabstractAs one of the most typical cybercrime types, phishing scams have extended the devil’s hand to the emerging blockchain ecosystem in recent years. Especially, huge economic losses have been caused by phishing scams in Ethereum, the second-largest blockchain system. Existing approaches for Ethereum phishing detection, however, typically use machine learning or transaction graph embedding methods to identify phishers in isolation and do not effectively uncover the group of transaction accounts linked to scams (which we term a “gang”). Since accounts are pseudonymous in Ethereum, these undisclosed conspirator accounts have potential risks to the system. In this paper, we conduct the first study that characterizes and detects Ethereum phishing gangs. We first investigate the transaction behaviors in phishing gangs from the perspectives of individuals, pairs, and higher-order patterns. Our analysis reveals that although the Ethereum transaction graph is sparse with a highly skewed degree distribution, phishing accounts in the same gang have closer relationships and share specific transaction patterns. Based on our findings, we formalize the phishing gang detection problem and introduce a novel detection model named PGDetector. Given a risky phishing account as a seed, PGDetector can find out the potential risky accounts sharing close relationships within the seed’s community based on genetic algorithm optimization. Experimental results on large-scale Ethereum transaction data demonstrate the effectiveness of PGDetector. Jieli Liu, Jinze Chen, Jiajing Wu, Zhiying Wu, Junyuan Fang, Zibin Zheng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | 2DynEthNet: A Two-Dimensional Streaming Framework for Ethereum Phishing Scam DetectionabstractIn recent years, phishing scams have emerged as one of the most serious crimes on Ethereum. Existing phishing scam detection methods typically model public transaction records on the blockchain as a graph, and then identify phishing addresses through manual feature extraction or graph learning frameworks. Meanwhile, these methods model transactions within a period as a static network for analysis. Therefore, these methods lack the ability to capture fine-grained time dynamics, and on the other hand, they cannot handle the large-scale and continuously growing transaction data on the Ethereum blockchain, resulting in lower scalability and efficiency. In this paper, we propose a two-dimensional streaming framework 2DynEthNet for Ethereum phishing scam detection. First, we cast the transaction series into 6 slices according to block numbers, treating each as a separate task. In the first dimension, we treat transaction features as edge features instead of node features within one task, allowing each transaction to be streamed in 2DynEthNet, aiming to capture the evolutionary features of the Ethereum transaction network at a fine-grained level in continuous time. In the second dimension, we adopt the strategy of incremental information training between tasks, which utilizes meta-learning to quickly update the model parameters under new slices, thus effectively improving the scalability of the model. Finally, experimental results on large-scale real Ethereum phishing scam datasets show that our 2DynEthNet outperforms the state-of-the-art methods with 28.44% average Recall and achieves the most efficient training speed, proving the effectiveness of both temporal edge representation and meta-learning. In addition, we provide an Ethereum large-scale dynamic graph transaction dataset, ETGraph, which aligns with the data distribution in real transaction scenarios without sampling and filtering unlabeled accounts. Wenjia Yu, Jiajing Wu, Dan Lin 0007, Zhiying Wu, Zibin Zheng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Financial Loan Overdue Risk Detection via Meta-path-based Graph Neural NetworkabstractOverdue risk detection of consumer loans is a critical issue faced by consumer finance companies. Unlike other types of loans, such as mortgage loans and guaranteed loans, consumer loans only regard personal credit as collateral. As a high overdue rate will result in economic losses to financial companies, it is of great significance for lenders to accurately detect risky customers. However, the large volume of credit data and the variety of customer characteristics make the risk detection via manual expert analysis rather challenging. Additionally, previous loan risk detection approaches based on machine learning classification neglect the relations between different customers, and traditional graph neural networks lack the exploration of loan overdue patterns. In this paper, we construct a heterogeneous graph based on real credit data from a consumer finance company. We analyze the distribution of meta-paths and propose a meta-path-based graph neural network that combines both lower-order and higher-order features. Experimental results show that our model is able to detect more risky customers by exploring overdue patterns and can achieve the best effect in the loan overdue detection task. Jinze Chen, Jieli Liu, Zhiying Wu, Shanhe Zhao, Quanzhong Li 0001, Jiajing Wu |
ISCAS | 3 |
| 2023 | Know Your Transactions: Real-time and Generic Transaction Semantic Representation on Blockchain & Web3 EcosystemabstractWeb3, based on blockchain technology, is the evolving next generation Internet of value. Massive active applications on Web3, e.g. DeFi and NFT, usually rely on blockchain transactions to achieve value transfer as well as complex and diverse custom logic and intentions. Various risky or illegal behaviors such as financial fraud, hacking, money laundering are currently rampant in the blockchain ecosystem, and it is thus important to understand the intent behind the pseudonymous transactions. To reveal the intent of transactions, much effort has been devoted to extracting some particular transaction semantics through specific expert experiences. However, the limitations of existing methods in terms of effectiveness and generalization make it difficult to extract diverse transaction semantics in the rapidly growing and evolving Web3 ecosystem. In this paper, we propose the Motif-based Transaction Semantics representation method (MoTS), which can capture the transaction semantic information in the real-time transaction data workflow. To the best of our knowledge, MoTS is the first general semantic extraction method in Web3 blockchain ecosystem. Experimental results show that MoTS can effectively distinguish different transaction semantics in real-time, and can be used for various downstream tasks, giving new insights to understand the Web3 blockchain ecosystem. Our codes are available at https://github.com/wuzhy1ng/MoTS. Zhiying Wu, Jieli Liu, Jiajing Wu, Zibin Zheng, Xiapu Luo, Ting Chen 0002 |
WWW | 1 |
| 2023 | Attention-aware temporal-spatial graph neural network with multi-sensor information fusion for fault diagnosis
Zhe Wang 0035, Zhiying Wu, Xingqiu Li, Haidong Shao, Te Han, Min Xie 0001 |
Knowl. Based Syst. | 2 |
| 2023 | TRacer: Scalable Graph-Based Transaction Tracing for Account-Based Blockchain Trading SystemsabstractSecurity incidents such as scams and hacks have become a major threat to the health of the blockchain ecosystem, resulting in billions of dollars in losses to blockchain users each year. To reveal the real-world entities behind pseudonymous blockchain accounts and recover stolen funds from massive transaction data, much effort has recently been put into tracing illicit financial flows in blockchain by academia and industry. However, most of the current blockchain fund tracing methods are heuristics and taint analysis methods that are designed on the basis of expert experience and specific events, which have limitations in terms of universality, effectiveness and efficiency. This paper models blockchain transaction records as a transaction graph and tackles blockchain transaction tracing as a graph search task. To achieve efficient and effective tracing of fund transfers on the transaction graphs, we propose a scalable transaction tracing tool, TRacer, which to the best of our knowledge is thefirstintelligent transaction tracing tool that is generalized to multiple account-based blockchain platforms and can handle complex transaction behavior in decentralized finance (DeFi). Particularly, we tackle the transaction tracing task via a subgraph searching approach which employ a novel ranking method to infer the relevance between accounts during the graph search process in the multi-relational blockchain transaction graph. Theoretical analysis and experimental results on datasets from multiple blockchain platforms demonstrate that TRacer can efficiently perform the transaction tracing task at a lower cost and achieve better tracing results than existing methods or even expert manual audits. Zhiying Wu, Jieli Liu, Jiajing Wu, Zibin Zheng, Ting Chen 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Dynamic event-triggered L∞ control for networked control systems under deception attacks: a switching method
Zhiying Wu, Junlin Xiong, Min Xie 0001 |
Inf. Sci. | 1 |
| 2021 | A Switching Method to Event-Triggered Output Feedback Control for Unmanned Aerial Vehicles Over Cognitive Radio NetworksabstractThis article investigates the event-triggered output feedback control problem for unmanned aerial vehicle (UAV) systems over cognitive radio (CR) networks. A periodic event-triggered scheme is proposed in the presence of CR networks. By modeling the CR network as anon–offswitch, a new switched time-delay system model is developed for the event-triggered UAV. Based on the new model, the exponential stability and$H_{\infty }$performance criteria are derived by using the constructed Lyapunov function. Then, a co-design method is proposed to obtain mode-dependent controller gains and trigger parameters simultaneously. Finally, the proposed scheme is verified by a UAV system. Zhiying Wu, Junlin Xiong, Min Xie 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2020 | Adaptive Event-Triggered Observer-Based Output Feedback ℒ∞ Load Frequency Control for Networked Power SystemsabstractThis article investigates the event-triggered observer-based output feedback load frequency control (LFC) problem for power systems. To reduce the amount of the transmitted signals, a dynamic event-triggered scheme is proposed by adding an exponential term. Moreover, an adaptive event-triggered scheme is proposed to provide a balance between the control performance and the number of the transmitted signals. Under the proposed schemes, a new model is formulated for the observer-based output feedback LFC system via a time-delay system method. By employing the Lyapunov functional method, sufficient conditions are derived for global asymptotical stability and$\mathcal L_{\infty }$performance. Then, a controller design method is developed. Finally, two examples are given to illustrate the effectiveness of the proposed schemes. Zhiying Wu, Huadong Mo, Junlin Xiong, Min Xie 0001 |
IEEE Trans. Ind. Informatics | 1 |