VLDB 2026 Research / reviewers in the wild / expert
Xiaofan Li 0009
dblp:50/3937-9
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Blockchain and cryptocurrency security · 67% Systems and software security · 33% | |
| Software engineering, system software, and programming languages
2 papers |
Software maintenance and evolution · 100% | |
| Computer networks
1 paper |
Software-defined and programmable networks · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Blockchain and cryptocurrency security
smart contract security |
0.8 | 1 | 2024 | Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024 |
Systems and software security
software supply chain security |
0.8 | 1 | 2024 | Toward Understanding the Security of Plugins in Continuous Integration Services · CCS 2024 |
Blockchain and cryptocurrency security › smart contract
upgradeable smart contract |
0.8 | 1 | 2024 | Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024 |
Software maintenance and evolution
software ecosystems |
0.8 | 1 | 2024 | Toward Understanding the Security of Plugins in Continuous Integration Services · CCS 2024 |
Software-defined and programmable networks
SDN security |
0.7 | 1 | 2023 | SDN Application Backdoor: Disrupting the Service via Poisoning the Topology · INFOCOM 2023 |
Software maintenance and evolution
software updates |
0.2 | 1 | 2024 | Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024 |
Methods — techniques the papers use, named apart from their topics
transaction analysis · 1.5large-scale measurement · 1.5bytecode analysis · 1.5attack vector analysis · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Secretscout: Effective Hard-Coded Secrets Detection in Ci Configuration FilesabstractContinuous Integration (CI) has been widely adopted for automated software building and testing. In CI workflows, various third-party services can be integrated to enhance functionalities. During the integration process, secrets such as tokens and credentials are often used for authentication and authorization. Unfortunately, secret leakage regularly occurs, potentially causing serious consequences. Existing secret scanners detect secrets by matching tokens and credentials through regular expressions, which suffer from low recall rates. In this paper, we identify several issues in regular expression-based secret detectors and propose SecretScout, a new method for scanning hard-coded secrets by detecting their names. SecretScout contains carefully designed detectors to extract candidates. It considers special flags where secrets might exist, and further applies filters to reduce false positives. SecretScout can detect secrets in both structured files (e.g., CI configuration files) and unstructured files (e.g., log files). To demonstrate the effectiveness, we evaluate SecretScout and different versions of GitLeaks and TruffleHog using labeled configuration files. The results show that SecretScout achieves$7.3 \times$and$100 \times$higher recall rates compared to the default versions of GitLeaks and TruffleHog, respectively. We also conduct a measurement study on open-source projects' configuration files, and demonstrate that many true secrets might be leaked. Chu Qiao, Yacong Gu, Xiaofan Li 0009, Xing Gao 0001 |
SRDS | 3 |
| 2024 | Toward Understanding the Security of Plugins in Continuous Integration ServicesabstractMainstream Continuous Integration (CI) platforms have provided the plugin functionality to accelerate the development of CI pipelines. Unfortunately, CI plugins, which are essentially reusable code snippets, also expose new attack surfaces as plugins might be developed by less trusted users. In this paper, we present an in-depth study to understand potential security risks in existing CI plugins. We conduct a comprehensive analysis of plugin implementations on four mainstream CI platforms (GitHub Actions, GitLab CI, CircleCI, and Azure Pipelines), and investigate several weak links in existing plugin distributions and isolation mechanisms. We investigate seven attack vectors that can enable attackers to hijack plugins and distribute malicious code without plugins users being aware, and further exploit hijacked plugins to manipulate the workflow execution. Additionally, we find that plugin dependency (a plugin references other plugins) might further amplify the attack impact of our disclosed attacks. To evaluate the potential impact, we conduct a large-scale measurement on GitHub and GitLab, covering a total of 1,328,912 repositories using the aforementioned CI platforms. Our measurement results show that a large number of repositories and existing plugins, including many widely used ones, are potentially vulnerable to the proposed attacks. We have duly reported the identified vulnerabilities and received positive responses. Xiaofan Li 0009, Yacong Gu, Chu Qiao, Zhenkai Zhang 0002, Daiping Liu, Lingyun Ying, Hai-Xin Duan, Xing Gao 0001 |
CCS | 1 |
| 2024 | Characterizing Ethereum Upgradable Smart Contracts and Their Security ImplicationsabstractUpgradeable smart contracts (USCs) have been widely adopted to enable modifying deployed smart contracts. While USCs bring great flexibility to developers, improper usage might introduce new security issues, potentially allowing attackers to hijack USCs and their users. In this paper, we conduct a large-scale measurement study to characterize USCs and their security implications in the wild. We summarize six commonly used USC patterns and develop a tool, USCDetector, to identify USCs without needing source code. Particularly, USCDetector collects various information such as bytecode and transaction information to construct upgrade chains for USCs and disclose potentially vulnerable ones. We evaluate USCDetector using verified smart contracts (i.e., with source code) as ground truth and show that USCDetector can achieve high accuracy with a precision of 96.26%. We then use USCDetector to conduct a large-scale study on Ethereum, covering a total of 60,251,064 smart contracts. USCDetecor constructs 10,218 upgrade chains and discloses multiple real-world USCs with potential security issues. Xiaofan Li 0009, Yuzhe Tang, Xing Gao 0001 |
WWW | 1 |
| 2023 | SDN Application Backdoor: Disrupting the Service via Poisoning the TopologyabstractSoftware-Defined Networking (SDN) enables the deployment of diversified networking applications by providing global visibility and open programmability on a centralized controller. As SDN enters its second decade, several well-developed open source controllers have been widely adopted in industry, and various commercial SDN applications are built to meet the surging demand of network innovation. This complex ecosystem inevitably introduces new security threats, as malicious applications can significantly disrupt network operations. In this paper, we introduce a new vulnerability in existing SDN controllers that enable adversaries to create a backdoor and further deploy malicious applications to disrupt network service via a series of topology poisoning attacks. The root cause of this vulnerability is that SDN systems simply process received Packet-In messages without checking the integrity, and thus can be misguided by manipulated messages. We discover that five popular SDN controllers (i.e., Floodlight, ONOS, OpenDaylight, POX and Ryu) are potentially vulnerable to the disclosed attack, and further propose six new attacks exploiting this vulnerability to disrupt SDN services from different layers. We evaluate the effectiveness of these attacks with experiments in real SDN testbeds, and discuss feasible countermeasures. Shuhua Deng, Xian Qing, Xiaofan Li 0009, Xing Gao 0001, Xieping Gao 0001 |
INFOCOM | 3 |