Bao Wen

dblp:364/8657 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0004-4750-6516ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Efficient Instruction Vulnerability Prediction With Heterogeneous SDC Propagation Knowledge Graph
Bao Wen, Jingjing Gu, Dazhong Shen, Qiang Zhou 0007, Fuzhen Zhuang, Yang Liu 0390, Haocheng Song, Xinyi Huang 0001
IEEE Trans. Dependable Secur. Comput.1
2026 Exploring the Vulnerability of Basic Blocks for Control Flow Error Detection
abstract
Control flow errors (CFEs) pose a serious threat to the reliability of embedded systems, particularly under increasing integration density and shrinking feature sizes. Existing CFE detection techniques typically rely on coarse-grained analysis and uniform checking strategies, lacking fine-grained awareness of structural and runtime characteristics. This limitation often leads to considerable overhead, making such approaches less suitable for resource-constrained embedded systems. To tackle this shortcoming, we propose a CFE Detection approach guided by Basic block Vulnerability Analysis (CDBVA) that aims to strike a balance between the detection effectiveness and the overhead. Specifically, we first extract the CFE-related structural and execution features to characterize basic block vulnerability. Then, we train a learning-based model to predict basic blocks that are vulnerable to CFEs. Finally, we design a hybrid signature checking strategy that performs appropriate checks on vulnerable and non-vulnerable basic blocks separately. Experimental results demonstrate that CDBVA achieves an average prediction accuracy of 86.2% and an average CFE coverage of 95.79%, outperforming state-of-the-art approaches. While maintaining high CFE coverage, CDBVA improves the evaluation factor by 12.14%–20.82%, achieving a favorable tradeoff between detection effectiveness and overhead. In addition, CDBVA demonstrates stable performance across diverse input conditions and heterogeneous hardware architectures.
Yang Liu 0390, Jingjing Gu, Bao Wen, Qiang Zhou 0007, Zhiteng Dong, Yi Zhuang 0002
ACM Trans. Embed. Comput. Syst.4
2025 Towards Generalizable Instruction Vulnerability Prediction via LLM-Enhanced Code Representation
abstract
Discovering potential vulnerabilities has long been a fundamental goal in software security. Among them, bit flips, caused by hardware or environmental disturbances, are increasingly recognized as a new type of vulnerabilities that threaten program reliability at the instruction level. However, existing work is often restricted to individual programs and requires retraining when applied to unseen code, severely limiting their practicality and responsiveness. In this paper, we propose CIVP, a novel framework for context-aware instruction vulnerability prediction, generalizing to unseen programs without retraining. Specifically, to capture the rich contextual semantics of instructions, CIVP first leverages Large Language Models (LLMs) to accurately extract semantic embeddings of instructions. Then, CIVP further constructs an instruction execution graph containing complex relations of program execution, which implicates the potential path of error propagation. To improve instruction representation for vulnerability prediction, CIVP enhances GraphSAGE with multi-hop diffusion to capture inter-program structural patterns and contextual dependencies, and adopts pseudo-labeling to improve the model’s generalization for vulnerable instructions. Extensive experiments on a dataset of 26 real-world programs demonstrate that CIVP significantly outperforms the state-of-the-art approaches, achieving up to 20.5%↑ Recall and 18.5%↑ F1-score improvements. Notably, CIVP generalizes well to unseen programs, offering an efficient and scalable solution for proactive instruction-level hardening before software deployment.
Bao Wen, Jingjing Gu, Yang Liu 0390, Pengfei Yu 0002, Yanchao Zhao
ASE1
2025 Exploring and Mitigating Failure Behavior of Large Language Model Training Workloads in HPC Systems
abstract
The exponential growth of Large Language Model (LLM) training demands in HPC systems has exposed critical reliability challenges, particularly from transient faults. Unlike resilience studies in conventional DNN inference, the massive parameter scale and iterative updates in LLM training trigger more complex failure patterns. To address these challenges, we introduce LLMFI, a new fault injection tool, and reveal six distinct failure behaviors through 300K+ fault injection experiments (exceeding 5K GPU node-hours). Our key insight is that, while most injected faults are eventually masked by the training iteration mechanism, a critical subset leads to catastrophic failures or performance degradation. Further, we propose LLMFT, a novel machine-learning-based fault tolerance framework that implements closed-loop error control via heuristic feature extraction, fault detector, and dual recovery mechanisms. Extensive evaluation demonstrates that LLMFT achieves an average of 97.61% F1-score in fault detection with only 0.01%–0.05% additional GPU memory overhead, effectively mitigating LLM training failures.
Pengfei Yu 0002, Jingjing Gu, Dazhong Shen, Bao Wen, Yang Liu 0390
SC5
2025 Instruction Vulnerability Prediction for WebAssembly with Semantic Enhanced Code Property Graph
abstract
WebAssembly (Wasm) is a universal low-level bytecode designed to build modern web systems. Recent studies have shown that technologies such as voltage scaling and RowHammer attacks are expected to increase the likelihood of bit flips, which may cause unacceptable or catastrophic system failures. This raises concerns about the impact of bit flips on Wasm programs, which run as instructions in web systems, and it is an undeveloped topic since the features of Wasm differ from traditional programs. In this paper, we propose a novel paradigm, namely IVPSEG, to understand the error propagation of bit flips within Wasm programs. Specifically, we first use Large Language Models (LLMs) to automatically extract instruction embeddings containing semantic knowledge of each instruction's context. Then, we exploit these embeddings and program structure (control execution and data transfer) to construct a semantic enhanced code property graph, which implicates the potential path of error propagation. Based on this graph, we utilize graph neural networks and attention diffusion to optimize instruction embeddings by capturing different error propagation patterns for instruction vulnerability prediction. In particular, we build a Wasm compilation and fault generation system to simulate bit flips at Wasm runtime. Our experimental results with 14 benchmark programs and test cases show IVPSEG outperforms the state-of-the-art methods in terms of accuracy (average 13.06%ͽ ), F1-score (average 14.93%↑), and model robustness.
Bao Wen, Jingjing Gu, Pengfei Yu 0002, Yang Liu 0390
WWW1
2025 CEDAR: Silent Control Flow Error Detection via Heterogeneous Relation Learning
abstract
Control flow errors (CFEs) are prevalent and de-structive runtime faults that compromise software reliability and security. Existing CFE detection approaches either perform coarse-grained modeling at the basic-block level, missing fine-grained implicit features, or rely on exhaustive fault injection for detailed error patterns. These limitations hinder efficient detection, especially for silent CFEs, where branches deviate from correct paths, yet still follow compiler-defined ones. To bridge this gap, we propose CEDAR, a novel CFE detection approach, which detects silent CFEs by localizing and hardening vulnerable instructions. Specifically, we first conduct multi-level control flow analysis with limited fault injection, enhanced by dynamic data propagation, to construct a dual-layer heterogeneous graph representation of the program. Subsequently, we employ Graph Neural Networks (GNNs) to learn silent CFE-relevant embeddings and develop a model to localize vulnerable instructions. Finally, targeted program hardening mechanisms are integrated to detect silent CFEs and improve overall CFE coverage. Experiments demonstrate that CEDAR achieves 92.28% coverage of silent CFEs and 96.47% on average for overall CFEs. While maintaining high coverage, it improves the Evaluation Factor (EF) by 21.97% over the state-of-the-art approach, achieving a favorable trade-off between effectiveness and overhead. More-over, it demonstrates robustness across diverse input scenarios and Instruction Set Architectures (ISAs).
Yang Liu 0390, Jingjing Gu, Bao Wen, Yi Zhuang 0002
IEEE Trans. Software Eng.4