VLDB 2026 Research / reviewers in the wild / expert
Xiang Li 0078
dblp:40/1491-78
· DBLP profile ↗
13ranked-venue papers
2as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 4 since 2021Computer networks · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Large language models-driven fuzzing: A systematic survey
Yuxian Wan, Minhuan Huang, Xiang Li 0078, Yuanping Nie, Wenyu Zhen |
Eng. Appl. Artif. Intell. | 3 |
| 2024 | ECFuzz: Effective Configuration Fuzzing for Large-Scale SystemsabstractA large-scale system contains a huge configuration space because of its large number of configuration parameters. This leads to a combination explosion among configuration parameters when exploring the configuration space. Existing configuration testing techniques first use fuzzing to generate different configuration parameters, and then directly inject them into the program under test to find configuration-induced bugs. However, they do not fully consider the complexity of large-scale systems, resulting in low testing effectiveness. In this paper, we propose ECFuzz, an effective configuration fuzzer for large-scale systems. Our core approach consists of (i) Multi-dimensional configuration generation strategy. ECFuzz first designs different mutation strategies according to different dependencies and selects multiple configuration parameters from the candidate configuration parameters to effectively generate configuration parameters; (ii) Unit-testing-oriented configuration validation strategy. ECFuzz introduces unit testing into configuration testing techniques to filter out configuration parameters that are unlikely to yield errors before executing system testing, and effectively validate generated configuration parameters. We have conducted extensive experiments in real-world large-scale systems including HCommon, HDFS, HBase, ZooKeeper and Alluxio. Our evaluation shows that ECFuzz is effective in finding configuration-induced crash bugs. Compared with the state-of-the-art configuration testing tools including ConfTest, ConfErr and ConfDiagDetector, ECFuzz finds 60.3--67 more unexpected failures when the same 1000 testcases are injected into the system with an increase of 1.87x--2.63x. Moreover, ECFuzz has exposed 14 previously unknown bugs, and 5 of them have been confirmed. Senyi Li, Keyao Li, Falin Luo, Hong-Fang Yu, Shanshan Li 0001, Xiang Li 0078 |
ICSE | 7 |
| 2024 | Suitable is the Best: Task-Oriented Knowledge Fusion in Vulnerability DetectionabstractDeep learning technologies have demonstrated remarkable performance in vulnerability detection. Existing works primarily adopt a uniform and consistent feature learning pattern across the entire target set. While designed for general-purpose detection tasks, they lack sensitivity towards target code comprising multiple functional modules or diverse vulnerability subtypes. In this paper, we present a knowledge fusion-based vulnerability detection method (KF-GVD) that integrates specific vulnerability knowledge into the Graph Neural Network feature learning process. KF-GVD achieves accurate vulnerability detection across different functional modules of the Linux kernel and vulnerability subtypes without compromising general task performance. Extensive experiments demonstrate that KF-GVD outperforms SOTAs on function-level and statement-level vulnerability detection across various target tasks, with an average increase of 40.9% in precision and 26.1% in recall. Notably, KF-GVD discovered 9 undisclosed vulnerabilities when employing on C/C++ open-source projects without ground truth. Minhuan Huang, Yuanping Nie, Xiang Li 0078, Qianjin Du, Xiaohui Kuang |
NeurIPS | 4 |
| 2023 | Fine-Grained Software Vulnerability Detection via Neural Architecture Search
Qianjin Du, Xiaohui Kuang, Xiang Li 0078 |
DASFAA (4) | 3 |
| 2023 | Automated Software Vulnerability Detection via Curriculum LearningabstractWith the development of deep learning, software vulnerability detection methods based on deep learning have achieved great success, which outperform traditional methods in efficiency and precision. At the training stage, all training samples are treated equally and presented in random order. However, in software vulnerability detection tasks, the detection difficulties of different samples vary greatly. Similar to the human learning mechanism following an easy-to-difficult curriculum learning procedure, vulnerability detection models can also benefit from the easy-to-hard curriculums. Motivated by this observation, we introduce curriculum learning for automated software vulnerability detection, which is capable of arranging easy-to-difficult training samples to learn better detection models without any human intervention. Experimental results show that our method achieves obvious performance improvements compared to baseline models. Qianjin Du, Wei Kun, Xiaohui Kuang, Xiang Li 0078 |
ICME | 4 |
| 2023 | Fine-Grained Source Code Vulnerability Detection via Graph Neural Networks (S)abstractAlthough the number of exploitable vulnerabilities in software continues to increase, the speed of bug fixes and software updates have not increased accordingly.It is therefore crucial to analyze the source code and identify vulnerabilities in the early phase of software development.However, vulnerability location in most of the current machine learning-based methods tends to concentrate at the function level.It undoubtedly imposes a burden on further manual code audits when faced with largescale source code projects.In this paper, a fine-grained source code vulnerability detection model based on Graph Neural Networks (GNNs) is proposed with the aim of locating vulnerabilities at the function level and line level.Our empirical evaluation on different C/C++ datasets demonstrated that our proposed model outperforms the state-of-the-art methods and achieves significant improvements even when faced with more complex, real-project source code. Minhuan Huang, Yuanping Nie, Xiaohui Kuang, Xiang Li 0078, Wenjing Zhong |
SEKE | 5 |
| 2022 | Group-based corpus scheduling for parallel fuzzingabstractParallel fuzzing relies on hardware resources to guarantee test throughput and efficiency. In industrial practice, it is well known that parallel fuzzing faces the challenge of task division, but most works neglect the important process of corpus allocation. In this paper, we proposed a group-based corpus scheduling strategy to address these two issues, which has been accepted by the LLVM community. And we implement a parallel fuzzer based on this strategy called glibFuzzer. glibFuzzer first groups the global corpus into different subsets and then assigns different energy scores and different scores to them. The energy scores were mainly determined by the seed size and the length of coverage information, and the difference score can describe the degree of difference in the code covered by different subsets of seeds. In each round of key local corpus construction, the master node selects high-quality seeds by combining the two scores to improve test efficiency and avoid task conflict. To prove the effectiveness of the strategy, we conducted an extensive evaluation on the real-world programs and FuzzBench. After 4×24 CPU-hours, glibFuzzer covered 22.02% more branches and executed 19.42 times more test cases than libFuzzer in 18 real-world programs. glibFuzzer showed an average branch coverage increase of 73.02%, 55.02%, 55.86% over AFL, PAFL, UniFuzz, respectively. More importantly, glibFuzzer found over 100 unique vulnerabilities. Taotao Gu, Xiang Li 0078, Shuaibing Lu, Jianwen Tian, Yuanping Nie, Xiaohui Kuang, Zhechao Lin, Chenyifan Liu, Jie Liang 0006, Yu Jiang 0001 |
ESEC/SIGSOFT FSE | 2 |
| 2022 | ICDF: Intrusion collaborative detection framework based on confidenceabstractMany machine-learning-based intrusion detection methods have been proposed, however there is a lack of collaboration among these methods. Faced with a cascade of malicious behaviors and various running environments, coupled with the endless emergence of new malicious activities, it is difficult for us to choose an algorithm manually that is suitable for all scenarios. In addition, usually the binary detection models are applied that only “normal” or “abnormal” decision is made, and it is difficult for us to know how much confidence we have in the prediction model. In this study, we propose an intrusion collaborative detection framework (ICDF), an ICDF that allows heterogeneous detection models to effectively work together which have complementary expertise. A multialgorithm model ensemble learning method with confidence interval is adopted. In this process, each algorithm model only makes prediction judgments on its own credible probability interval and refuses to predict outside the interval. The final result is generated by voting based on the confidence of multiple models. Ten detection algorithms were tested on three different data sets. Compared with different single algorithms, ICDF could achieve high precision and recall rate, and the best F1 scores. Zhi Wang 0014, Leshi Shao, Yuanzhao Liu, Jianan Jiang, Yuanping Nie, Xiang Li 0078, Xiaohui Kuang |
Int. J. Intell. Syst. | 7 |
| 2020 | Defending Application Layer DDoS Attacks via Multidimensional ParallelotopeabstractThe Internet is more and more integrated into people’s life; because of the complexity and fragility of the network environment, network attack presents a more and more serious trend. Application Layer DDoS (AL-DDoS) attack is the most complex form of DDoS attack, which is hindering the availability for the legitimate users by taking up a large number of requests of web server. The paper introduced the concept of behavior utility to portray the network. The concept of attack and defense utility was defined by a specific property which was the manifestation of the network risk after the offset of attack and defense. In the utility model, traffic metrics were mapped to the multidimensional parallelotope in the Euclidean space to express as a diagonal matrix. To determine the threshold status, the defense strategies of load balancing and limiting the maximum number of connections were used with different attack scales. Finally, the attack and defense utility value was calculated to evaluate the network risk level. The proposed method can master the capacity of network system against each attack means and the defense capability of network system. Its availability and accuracy are verified by comparing with the relevant works. Xiang Li 0078, Jingfeng Xue, Yaoyuan Liang, Mingzhe Pei |
Secur. Commun. Networks | 3 |
| 2020 | BMOP: Bidirectional Universal Adversarial Learning for Binary OpCode FeaturesabstractFor malware detection, current state-of-the-art research concentrates on machine learning techniques. Binary n -gram OpCode features are commonly used for malicious code identification and classification with high accuracy. Binary OpCode modification is much more difficult than modification of image pixels. Traditional adversarial perturbation methods could not be applied on OpCode directly. In this paper, we propose a bidirectional universal adversarial learning method for effective binary OpCode perturbation from both benign and malicious perspectives. Benign features are those OpCodes that represent benign behaviours, while malicious features are OpCodes for malicious behaviours. From a large dataset of benign and malicious binary applications, we select the most significant benign and malicious OpCode features based on the feature SHAP value in the trained machine learning model. We implement an OpCode modification method that insert benign OpCodes into executables as garbage codes without execution and modify malicious OpCodes by equivalent replacement preserving execution semantics. The experimental results show that the benign and malicious OpCode perturbation (BMOP) method could bypass malicious code detection models based on the SVM, XGBoost, and DNN algorithms. Xiang Li 0078, Yuanping Nie, Zhi Wang 0014, Xiaohui Kuang, Kefan Qiu |
Wirel. Commun. Mob. Comput. | 1 |
| 2015 | A clustering approach based on convergence degree chain for wireless sensor networksabstractAbstract Wireless sensor networks (WSNs) play an important role in pervasive and ubiquitous systems. The energy consumption, scalability, stability, and lifetime are still open issues in WSNs. Clustering approach has been considered one of the most effective measures and has received tremendous attention in this research area. But most clustering algorithms of the previous related works adopt the idea of periodically and globally regrouping cluster nodes that may cause the improper energy consumption and link state instability during the clustering procedure. Aiming to decrease energy consumption of sensor node and increase WSNs stability, a novel Energy‐efficient Clustering Approach based on Convergence Degree chain, which is termed as ECACD, is proposed in this paper. ECACD protocol can improve stability of topology by using convergence degree and residual energy for cluster head election, reduce energy consumption of member node by cluster joining policy for cluster formation, and decrease communication cost by rotating cluster head according to convergence degree chain generated at initial stage. Analysis and simulation results show the advantage and effectiveness of our approach in terms of the cluster header characteristics and the network life time. According to the comparison with HEED (Hybrid Energy‐Efficient Distributed clustering), which is an energy‐efficient approach for clustering nodes in sensor networks by periodically selecting cluster heads according to a hybrid of their residual energy and a secondary parameter, ECACD increases the stability and extends the network life by 26% and 85%. Copyright © 2014 John Wiley & Sons, Ltd. Xiaohui Kuang, Xiang Li 0078 |
Secur. Commun. Networks | 4 |
| 2011 | An Overview of Bootkit Attacking ApproachesabstractBoot kit, as an innovative root kit technology, transfer its storage location from the file system to the hardware store, and activates itself while or even before the operating system kernel is loaded. Therefore, boot kit can tamper the operating system and control the whole computer system. Compared to classic malware, it achieves a more powerful capability of hiding and controlling. This paper takes an overview of existing various boot kit technologies and summarizes their technical characteristics. This opens a door to the malware defenders for preventing the computer systems from boot kit. Xiang Li 0078, Yan Wen 0001, Minhuan Huang |
MSN | 1 |
| 2011 | Towards a Flaw Function Heuristic Vulnerability Static Analysis Framework for Executable FileabstractThe misuse of flaw functions is one of the key reasons causing software vulnerabilites. In our study, this type of vulnerability is termed as MFFV (Vulnerability of Flaw Function Misusing). In this paper, we propose a novel framework for analyzing the flaw function heuristic vulnerabilities. In this framework, the procedure to analyze MFFV is composed of three stages: firstly, MFFV pre-analysis engine builds the intermediate representation via reverse engineering technique, and meanwhile the flaw functions are identified according to the function signature technology. Secondly, MFFV analysis engine picks up the suspicious hot points, and attaches a label to each of them. The label records the code slice, flaw function information and context. In the third stage, MFFV scheduler invokes a series of related checkers to perform precise checks on all the hot points. Besides, we implement a prototype to verify the feasibility of our proposed framework. Yan Wen 0001, Xiang Li 0078 |
MSN | 4 |