VLDB 2026 Research / reviewers in the wild / expert
Wenwei Lan
dblp:368/1884
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | BaSFuzz: Fuzz testing based on difference analysis for seed bytes
Wenwei Lan, Li Li 0114, Zhanqi Cui |
J. Syst. Softw. | 1 |
| 2024 | SDA-FirmFuzz: Fuzz Testing IoT Device Firmwares Based on Seed Differential AnalysisabstractIn recent years, as the Internet of Things (IoT) devices have been widely used in many fields.There have been attackers taking advantage of the vulnerabilities that exist in the firmware to take control of the devices.As a result, it is important to ensure that the secure of the firmware.Fuzz testing techniques have been proposed for testing firmwares which significantly improved the efficiency of detecting vulnerabilities.Existing firmware fuzz testing techniques mainly focused on the static analysis of firmware before fuzzing, improving the generality of emulation tools, and increasing emulation throughput to improve efficiency of fuzzing.In general, the quality of test cases (seeds) significantly affects the result of fuzz testing; and high-quality seeds can cover more edges and trigger more crashes.Therefore, this paper proposes a fuzz testing method SDA-FirmFuzz (Fuzz Testing IoT Device Firmware Based on Seed Differential Analysis) for IoT device firmwares base on seed differentiation analysis.By analyzing the difference of the seeds before fuzz testing, SDA-FirmFuzz enables the seeds with higher degree of difference are prioritized to be executed.Firstly, a similarity matrix of seeds is constructed based on the cosine similarities.Secondly, a weight matrix is obtained based on the similarity matrix calculation to obtain the similarity scores of the seeds.Finally, the seeds are reordered based on the similarity scores, after which a new seed queue is used to fuzzing the IoT device firmware.Experiments are carried out on six IoT device firmwares, and the experimental results show that SDA-FirmFuzz is able to cover 1.26 times more edges and trigger 32 more unique crashes than Firm-AFL on average. Zheng-Wu Wang, Wenwei Lan, Zhanqi Cui |
SEKE | 2 |
| 2023 | Fuzz Testing Based on Seed Diversity AnalysisabstractFuzz testing is a widely used technique to detect software defects and vulnerabilities. Coverage-guided fuzzing aims to improve code coverage by generating offspring test cases through mutation, executing the program under test, and retaining interesting seeds for subsequent mutations using customized genetic algorithms. However, existing fuzzing tools rarely consider the similarity between seeds during mutation. Mutating similar seeds frequently generates similar offspring test cases, which results in similar coverage and reduces the efficiency of fuzz testing. To alleviate the impact of this problem on fuzz testing, this paper proposes a fuzz testing method based on seed diversity analysis, which focuses on the characteristics of seeds and uses byte sequences as a feature to measure the similarity between seeds. It collects seeds that can cover new edges and constructs a shorter seed queue with significant differences based on this feature, which replaces the original seed queue for mutation. Based on the proposed method, we implement the prototype tools AFL-Varied and Neuzz-Varied. Compared with AFL and Neuzz on six projects, the edge coverage and basic block coverage can be increased by 214.57% and 233.33 % at most, respectively. Wenwei Lan, Zhanqi Cui, Jiaming Zhang 0008, Xiguo Gu |
SMC | 1 |
| 2023 | Statement-Level Software Bug Localization Based on Information Retrieval and SpectrumabstractAccording to whether the program under test is executed, software bug localization methods can be divided into static bug localization and dynamic bug localization. Among them, Information Retrieval-based Bug Localization (IRBL) and Spectrum-based Fault Localization (SFL) are widely used static and dynamic bug localization methods, respectively. But the localization granularity of IRBL is coarse and the localization accuracy of SFL is easily reduced by the information which is unrelated to the bug. In order to refine the localization granularity of IRBL and improve the localization accuracy of SFL, this paper proposes ISBL (Combine Information Retrieval and Spectrum for Bug Localization), a statement-level software bug localization method based on information retrieval and spectrum. Firstly, the suspicious files are filtered using information retrieval technique, and then the suspicious files are used to reduce spectrum information for statement-level bug localization. To evaluate the performance of ISBL, experiments were conducted on the Defects4J dataset, and MRR and TOP@N were used as metrics for evaluation. As the experimental results show, for MRR, ISBL increased 3.0% and 3.1% compared to Ochiai and DStar, respectively; for TOP@1, ISBL locates 4 more bug statements than Ochiai and DStar. Wenwei Lan, Zhanqi Cui |
SMC | 3 |