VLDB 2026 Research / reviewers in the wild / expert
Jielun Wu
dblp:392/3340
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0004-3581-6832ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 100% | |
| Computer networks
1 paper |
Network management and operations · 50% Routing and switching · 50% | |
| Software engineering, system software, and programming languages
2 papers |
Program analysis · 79% Program synthesis and code generation · 21% |
Topics — the 7 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › software protection
source code privacy |
1.0 | 2 | 2025 | Poster: Protecting Source Code Privacy When Hunting Bugs · CCS 2024 Protecting Source Code Privacy When Hunting Memory Bugs · ASE 2025 |
Routing and switching › routing protocol
interior gateway protocol |
0.9 | 1 | 2025 | Validating Interior Gateway Routing Protocols via Equivalent Topology Synthesis · CCS 2025 |
Systems and software security › memory safety
memory error detection |
0.9 | 1 | 2025 | Protecting Source Code Privacy When Hunting Memory Bugs · ASE 2025 |
Systems and software security
software protection |
0.8 | 1 | 2024 | Poster: Protecting Source Code Privacy When Hunting Bugs · CCS 2024 |
Program analysis › static analysis
bug detection |
0.8 | 1 | 2024 | Poster: Protecting Source Code Privacy When Hunting Bugs · CCS 2024 |
Program synthesis and code generation
semantics-guided synthesis |
0.3 | 1 | 2025 | Validating Interior Gateway Routing Protocols via Equivalent Topology Synthesis · CCS 2025 |
Program analysis
static analysis |
0.2 | 1 | 2024 | Poster: Protecting Source Code Privacy When Hunting Bugs · CCS 2024 |
Methods — techniques the papers use, named apart from their topics
program synthesis · 1.7network simulation · 1.7differential testing · 1.7debug information reduction · 1.5binary stripping · 1.5type minimization · 0.9set cover reduction · 0.9selective pruning · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Validating Interior Gateway Routing Protocols via Equivalent Topology SynthesisabstractRouters, relying on routing protocols to determine how data packets travel across the Internet, serve as the backbone of modern networks. Vulnerable routing protocols can lead to serious consequences, including data leaks and network congestion. This work focuses on validating the implementation of a key class of routing protocols known as Interior Gateway Protocols (IGPs). Unlike communication protocols such as TCP/IP, which define structured data packets and state machines to facilitate communication, IGPs are designed to automatically manage the network topology. Thus, conventional techniques, which primarily focus on communication correctness, cannot be applied directly to IGPs. We propose ToDiff, a differential validation technique to uncover IGP bugs in three steps: (1) it uses a network generation algorithm to create random yet valid IGP networks, (2) it applies a semantics-guided program synthesizer to generate equivalent topological programs, and (3) it simulates the network via the equivalent topological programs, with any discrepancies suggesting the presence of a potential bug. We have evaluated ToDiff on the implementation of two common IGP protocols, OSPF and IS-IS. The results demonstrate that ToDiff outperforms existing approaches. To date, our tool has successfully identified 26 bugs, all confirmed or fixed by developers. Bing Shui, Jielun Wu, Baowen Xu, Qingkai Shi |
CCS | 3 |
| 2025 | Towards understanding the security issues of Python programsabstractPython programming language has witnessed a steady increase in popularity over the past few decades.Renowned for its conciseness and readability, as well as its ease of learning and use, Python is widespread adoption has inevitably exposed it to a higher likelihood of encountering issues.Given that numerous code modifications exhibit repetitive and analogous patterns, an extensive examination of Python code-fixing patterns becomes imperative.Among these patterns, security-related issues hold significant importance due to their heightened risks and potential for substantial impact.Consequently, conducting research on security-related matters assumes utmost significance.In this paper, we conduct a thorough investigation to gain insights into the security issues prevalent in Python programs.Our approach involves collecting 413 popular open-source Python projects from GitHub and identifying 9,782 bug reports related to security concerns and their corresponding bug fixes.We employ automated clustering and manual summarization techniques, ultimately classifying them into 12 distinct categories, with six categories being of notable prevalence.We analyze the bug reports and commits within each high-frequency category, examining aspects such as severity, root causes, and employed fixing patterns.Leveraging the empirical findings, we discuss the broader implications drawn from the study and offer guidance to software developers, facilitating proactive avoidance of such issues in their projects. Hongcheng Fan, Di Liu 0021, Jielun Wu, Yang Feng 0003, Qingkai Shi, Baowen Xu |
Internetware | 3 |
| 2025 | Protecting Source Code Privacy When Hunting Memory BugsabstractWhen proving to a third party that a software system is free from critical memory bugs, software vendors often face the problem of having to reveal their source code, so that the third party can scan the source code using static analysis tools. However, such transparency poses a significant threat to vendors, as the source code typically contains proprietary algorithms, core technical innovations, or trade secrets, exposing them to potential intellectual property risks. In this paper, we present a solution that offers a balance between transparency and code privacy, allowing software vendors to provide minimal source code information while justifying the sufficiency of bug detection. To this end, we propose DIReducer, which reduces source code information, a.k.a. debug information, from non-stripped binaries while preserving its utility for memory bug detection. DIReducer consists of two components: selective pruning and type minimization. The former eliminates redundant debug information, and the latter is proven to be NP-hard and minimizes type-related debug information by reducing it to the classic set-cover problem, which offers a near-optimal solution. Experimental results show that we can reduce 95% of debug information while maintaining similar bug detection capability compared to using full debug information or the source code. Jielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu, Rongxin Wu, Yang Feng 0003, Baowen Xu, Qingkai Shi |
ASE | 1 |
| 2024 | Poster: Protecting Source Code Privacy When Hunting BugsabstractWhen proving to a third party that a software system is of high quality or bug-free, a software vendor may have to reveal the source code such that the third party can use a public or their own static code analyzer to check the code. However, revealing source code seriously damages the interests of software vendors as the source code often contains core technical details or even secrets. In this work, we propose a win-win solution that can help software vendors protect source code privacy to the greatest extent and, meanwhile, maximize the bug-detection capability of the third party. Our key idea is that a majority of source code information is not useful for bug detection. Thus, a software vendor only needs to reveal a little source code information --- a stripped binary together with minimal debug information (which is the carrier of source code information) --- to prove the software's quality. To realize this win-win solution, we propose an approach that minimizes critical debug information in a non-stripped binary while maintaining its positive impact on static bug detection. Evaluation results demonstrate that our approach can significantly reduce the size of debug information and retain only a minimal amount of source-level private information. Jielun Wu, Qingkai Shi |
CCS | 1 |