Jiangan Ji

dblp:384/6060 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0008-2807-5641ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability Discovery
Jiangan Ji, Chao Zhang 0008, Shuitao Gan, Lin Jian, Hangtian Liu, Tieming Liu, Zhipeng Jia
NDSS1
2024 Formatted Stateful Greybox Fuzzing of TLS Server
abstract
The TLS protocol is one of the most crucial foundations for ensuring internet security. Consequently, vulnerabilities within the TLS protocol have a significant impact on the Internet security. This paper aims to explore more efficient methods of discovering vulnerabilities in the TLS protocol. Fuzzing stands out as one of the most important techniques for vulnerability discovery in the TLS protocol. To tackle the high complexity of the TLS protocol, stateful greybox fuzzers such as AFLnet have been introduced to enable stateful fuzzing of TLS servers. However, these mutation-based fuzzers often encounter chal-lenges in preserving the message format information during the mutation process, which can undermine the testing results. As a result, this paper proposes a novel approach that incorporates a formatted mutation strategy into the stateful greybox fuzzing process, with the aim of achieving more efficient mutation results. The evaluation process involves four mainstream fuzzers, with OpenSSL's TLS server serving as the target. The results demonstrate that the proposed method significantly enhances the quality of generated seeds, code coverage, and state coverage across all four fuzzers.
Jiangan Ji, Hui Shu, Zheming Li, Tieming Liu, Chao Zhang 0008
ICST2
2024 Crash Deduplication using Hybrid Runtime Features and Multi-Structure Neural Network
abstract
Fuzzing, widely used across the industry, is a dynamic method to detect vulnerabilities by generating test cases causing program crashes.However, its random mutation often produces duplicate Proof-of-Concept (PoC) test cases, which can be frustrating for researchers.Modern fuzzing methods use execution feedback to deduplicate PoCs, termed crash deduplication.However, inaccurate crash deduplication may miss unique PoCs or increase the analysis workload.Existing approaches rely on limited metrics or models, thus impacting accuracy.We propose a data-driven approach, which leverages hybrid runtime features for crash deduplication.We specifically extract hybrid runtime features, including runtime register, stack, and heap operation features, using the Magma benchmark and a customized dynamic binary translator to construct a training dataset.We also introduce a Multi-Structure Neural Network (MSNN) model to handle hybrid runtime features and optimize it using contrastive learning.Experimental results show our prototype significantly outperforms mainstream industry crash deduplication methods, excelling in both deduplication rate and bug retention.
Jiangan Ji, Jianshan Peng
SEKE2
2024 Graphuzz: Data-driven Seed Scheduling for Coverage-guided Greybox Fuzzing
abstract
Seed scheduling is a critical step of greybox fuzzing, which assigns different weights to seed test cases during seed selection, and significantly impacts the efficiency of fuzzing. Existing seed scheduling strategies rely on manually designed models to estimate the potentials of seeds and determine their weights, which fails to capture the rich information of a seed and its execution and thus the estimation of seeds’ potentials is not optimal. In this article, we introduce a new seed scheduling solution, Graphuzz, for coverage-guided greybox fuzzing, which utilizes deep learning models to estimate the potentials of seeds and works in a data-driven way. Specifically, we propose an extended control flow graph called e-CFG to represent the control-flow and data-flow features of a seed's execution, which is suitable for graph neural networks (GNN) to process and estimate seeds’ potential. We evaluate each seed's code coverage increment and use it as the label to train the GNN model. Further, we propose a self-attention mechanism to enhance the GNN model so that it can capture overlooked features. We have implemented a prototype of Graphuzz based on the baseline fuzzer AFLplusplus. The evaluation results show that our model can estimate the potential of seeds and has the robust capability to generalize to different targets. Furthermore, the evaluation using 12 benchmarks from FuzzBench shows that Graphuzz outperforms AFLplusplus and the state-of-the-art seed scheduling solution K-Scheduler and other coverage-guided fuzzers in terms of code coverage, and the evaluation using 8 benchmarks from Magma shows that Graphuzz outperforms the baseline fuzzer AFLplusplus and SOTA solutions in terms of bug detection.
Shuitao Gan, Chao Zhang 0008, Zheming Li, Jiangan Ji, Baojian Chen
ACM Trans. Softw. Eng. Methodol.6