VLDB 2026 Research / reviewers in the wild / expert
Xiangpu Song
dblp:366/4093
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2026
0009-0001-9714-1752ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu 0002, Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu 0013, Qingchuan Zhao, Shanqing Guo |
NDSS | 1 |
| 2026 | SGAFuzzer: Stateful GraphQL API fuzzing
Jingge Sun, Xiangpu Song, Xiaofeng Liu 0013, Shanqing Guo, Chengyu Hu 0001 |
Softw. Qual. J. | 2 |
| 2025 | MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT Brokers
Xiangpu Song, Jianliang Wu 0002, Yingpei Zeng, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo |
USENIX Security Symposium | 1 |
| 2025 | CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback
Xiangpu Song, Yingpei Zeng, Jianliang Wu 0002, Hao Li 0092, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo |
Comput. Secur. | 1 |
| 2025 | Improving seed quality with historical fuzzing results
Yingpei Zeng, Xiangpu Song, Shanqing Guo |
Inf. Softw. Technol. | 3 |
| 2025 | HSPFuzzer: High-Speed Network Protocol Fuzzing With Connection ReuseabstractFuzzing is a fundamental technique for detecting vulnerabilities in network protocols. However, existing approaches suffer from low fuzzing throughput caused by the overhead associated with server under test (SUT) restarts and connection setup. In this article, we present HSPFuzzer, a High-Speed Protocol Fuzzer that leverages connection reuse to reduce SUT restarts and connection re-establishments. To enable efficient connection reuse, it incorporates a prefix message identification algorithm to determine the essential packets required within a connection and a coverage monitoring mechanism to detect abnormal execution states. Additionally, HSPFuzzer employs an innovative message provision method that ensures input messages are delivered to the SUT with minimal delay within the same connection. HSPFuzzer also eliminates the need for manually implementing message-splitting logic by connection reuse. We evaluate HSPFuzzer on 12 widely used servers and experimental results show that HSPFuzzer achieves fuzzing throughput$1062{\times }$faster than AFLNet, whereas other state-of-the-art fuzzers, including AFLNet, SnapFuzz, HNPFuzzer, and AFL++, achieve, at most, a$12{\times }$speedup over AFLNet. Furthermore, HSPFuzzer attains an average code coverage increase of 25.1% compared to AFLNet, while competing fuzzers achieve, at most, 2.13% more coverage. Notably, HSPFuzzer also discovers more vulnerabilities, which further proves its effectiveness. Zhewei Xia, Yingpei Zeng, Xiangpu Song, Shanqing Guo, Ting Wu 0001 |
IEEE Internet Things J. | 3 |
| 2024 | FISFuzzer: A Grey-Box Protocol Fuzzer Based on Field Inference and Scheduling
Xiangpu Song, Shanqing Guo, Xing Yang 0004 |
SecureComm (3) | 2 |
| 2024 | TLS-DeepDiffer: Message Tuples-Based Deep Differential Fuzzing for TLS Protocol ImplementationsabstractLogic vulnerabilities associated with TLS protocol implementations often do not exhibit explicit erroneous behaviors, making them difficult to detect by testers. However, these vulnerabilities can pose serious security threats. While testing for TLS protocols lacks uniform test oracles, differential fuzzing effectively addresses this issue. Unfortunately, most of these vulnerabilities are triggered in deep protocol states, and no existing work on differential fuzzing targeting these states exists. In this paper, we propose a deep differential fuzzing framework that focuses on detecting logic issues in deep TLS protocol states. Our approach is based on the message tuples we proposed, which are semi-automatically extracted from RFCs using NLP techniques. We address the problem of test interruptions during early handshakes caused by original data inconsistencies by redefining the consistency determination to achieve deep differential fuzzing. In addition, we use encoding classification statistics to achieve quick and efficient analysis of the massive test results. Based on our approach, we implemented TLS-DeepDiffer and used it to test nine kinds of popular TLS libraries. We found four historical CVEs, one newly discovered high-risk vulnerability, and 24 security or implementation issues, demonstrating the usefulness of our approach. Xiangpu Song, Qiuyu Zhong, Yingpei Zeng, Chengyu Hu 0001, Shanqing Guo |
SANER | 2 |
| 2023 | DeepDiffer: Find Deep Learning Compiler Bugs via Priority-guided Differential FuzzingabstractRecently, Deep learning (DL) compilers have been widely developed to optimize the deployment of DL models. These DL compilers transform DL models into high-level intermediate representation (IR) and then into low-level IR, ultimately generating optimized codes for different hardware targets. However, DL compilers are not immune to generating incorrect code, leading to potentially severe consequences. Testing techniques for low-level IR are limited, and efficient approaches for detecting some categories of non-crashing bugs are lacking. In this paper, we address the limitations of existing low-level IR DL compiler testing techniques and introduce DeepDiffer, a priority-guided differential testing framework designed to detect bugs resulting from low-level optimizations in the DL compiler, specifically TVM. We propose a novel DL compiler coverage metric and establish an optimization goal to maximize the detection of valuable differences between DL compilers. Our experiments demonstrate that DeepDiffer outperforms existing low-level IR fuzzers, detecting a wider range of bug types. In fact, DeepDiffer has successfully identified 13 bugs in TVM, which can be categorized into 9 distinct root causes, and 9 bugs are first found. We have submitted these bugs to the TVM community, where they have been confirmed. Kuiliang Lin, Xiangpu Song, Yingpei Zeng, Shanqing Guo |
QRS | 2 |