Danjun Liu

dblp:52/1376 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 4 since 2021Systems, architecture and hardware · 4 · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
YearPublicationVenuePosition
2026 Instruction-conditioned visual token sparsification for efficient vision-language model inference
Danjun Liu, Yongqiang Xie, Zhongbo Li
Knowl. Based Syst.4
2025 SimFuzz: Conflict-Aware Parallel Fuzzing via Incremental Path Similarity Clustering
abstract
Parallel fuzzing boosts throughput by distributing testcase generation across multiple fuzzing instances. However, this architecture often suffers from task conflict—redundant exploration of similar execution paths—due to the lack of path-level awareness in seed scheduling. These conflicts waste computation and limit overall effectiveness.We present SIMFUZZ, a conflict-aware scheduling framework that mitigates redundancy by integrating path similarity into the fuzzing workflow. SIMFUZZ encodes seeds as branch-level coverage bitmaps and incrementally clusters them based on execution path overlap. It then applies a two-stage scheduling policy that assigns similar seeds to the same instance, while preserving global prioritization for high-potential inputs.We evaluate SIMFUZZ on 19 real-world programs and benchmark targets. Compared to a state-of-the-art baseline, it achieves a 6.7% average increase in branch coverage and reduces task conflict by 3.9%. In several cases, it also discovers substantially more unique crashes. Additionally, SIMFUZZ has uncovered 15 previously unknown vulnerabilities in widely used software projects, all of which have been assigned CVE identifiers.
Xuan Meng, Danjun Liu, Xu Zhou 0004, Peihong Lin, Chenyifan Liu, Lei Zhou 0023, Wei Xie 0007
ISSRE2
2025 SyzOrch: An Orchestration Framework for Resource-Aware and Composable Kernel Fuzzing
abstract
Kernel fuzzing plays a critical role in uncovering vulnerabilities, reproducing bugs, and testing patches in operating systems. While integrating external resources such as symbolic execution engines, static analyzers, and language models has proven effective in areas such as enhancing path exploration, optimizing seed generation, and improving seed mutation, existing approaches remain tightly coupled and task-specific, hindering the reuse, migration, scheduling, and composition of these external resources. This limitation further restricts the ability of researchers to explore flexible hybrid fuzzing strategies and hinders industry efforts to build stronger and more adaptable kernel fuzzers. We present SyzOrch to address this limitation. SyzOrch (1) decouples the kernel fuzzing workflow; (2) provides event-driven coordination between external resources and the fuzzer; (3) abstracts heterogeneous external resources through a generalized behavior model; and (4) supports user-defined dynamic control via a programmable DSL runner. We evaluate SyzOrch across diverse kernel fuzzing scenarios and show that it achieves a 30% speedup of directed kernel fuzzing by migrating existing techniques, improves coverage by 8.6% through hybrid composition with multiple external resources, and discovers previously unknown kernel bugs, including one assigned a CNNVD identifier. These results demonstrate SyzOrch’s effectiveness in orchestrating external resources to enhance kernel fuzzing.
Lukai Xu, Bo Yu 0008, Boyu Chang, Shouling Ji, Danjun Liu, Lei Zhou 0023, Yaojia Yang
ISSRE7
2025 Constructing arbitrary write via puppet objects and delivering gadgets in Linux kernel
Danjun Liu, Xuan Meng, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007
Comput. Secur.1
2025 Yesterday Once MorE: Facilitating Linux Kernel Bug Reproduction via Reverse Fuzzing
abstract
The Linux kernel remains vulnerable to numerous bugs, with approximately 65% detected by Syzkaller lacking Proof-of-Concept (PoC), hampering risk mitigation efforts. These bugs, termed irreproducible kernel bugs, highlight the challenge of statefulness issue-related irreproducibility in kernel fuzzing, which is an open research without definitive solutions. Our investigation reveals that suboptimal seed quality distribution in fuzzing is the root obstacle preventing effective tracking of the states leading to crashes. Inspired by this insight, we introduce Reverse Fuzzing (RF), an innovative approach that infers hard-to- reach states by continuously reverse-oriented deriving from subsequently encountered bridge states to increase reproduction probability. RF differentiates between the “trigger” seed, which directly causes crashes, and “activator” seeds, which establish the necessary preconditions, prioritizing exploration around trigger while simultaneously regenerating and maintaining activators during fuzzing, which effectively facilitate to restructure such elusive states from “yesterday”. We implement YOME, a prototype leveraging RF to strike a balance between fuzzing efficiency and effectiveness through customized scheduling and mutation strategies, armed with a refinement mechanism to improve seed quality distribution. Our evaluations validate that YOME reproduce 110% more bugs than previous kernel fuzzers and demonstrate its practicality in real-world scenarios. YOME generated 125 PoCs (30.1% of the total) and uncovered 23 unique bugs, with 40 confirmed and 5 assigned CVEs.
Xingwei Li, Yan Kang 0002, Chenggang Wu 0002, Danjun Liu, Jiming Wang, Zehui Wu, Yunchao Wang, Rongkuan Ma
IEEE Trans. Inf. Forensics Secur.4
2024 Speed is Not All You Need When Fuzzing Stateful Network Servers
abstract
Current network protocol fuzzing is an efficient mechanism for uncovering protocol vulnerabilities, yet it faces several challenges. For instance, bugs in stateful protocols can significantly hinder the generation of effective fuzzing testcases. Additionally, factors such as network transmission and session synchronization can lead to substantial delays in the fuzzing process. However, we have observed a common phenomenon that existing fuzzing techniques often focus on optimizing either execution speed or state inference, but not both, which limits their overall effectiveness in analyzing protocol defects. We verify such a common issue by experimental analysis and seek to understand the specific reasons behind this. Then, we design an enhanced network protocol fuzzer that harnesses shared memory-based message transmission and session state synchronization to alleviate the heavy post-execution analysis in StateAFL state inference, named S2fuzzer, to optimize both speed and state inference simultaneously. Our experiments reveal that S2fuzzer enhances execution speed by 4.7x compared to StateAFL. Simultaneously, we find that S2Fuzzer can infer a more comprehensive state model. This leads to a 9.38% increase in code coverage and 371 additional crashes (1.42x) compared to StateAFL across tested programs. This state inference amplification, which has not been discovered in previous research, allows S2fuzzer to reach nearly equivalent coverage and superior bug finding ability, even if its execution speed is merely 1/10 of HNPFuzzer, the latest speedup scheme.
Lei Zhou 0023, Xu Zhou 0004, Danjun Liu
HPCC5
2024 Instiller: Toward Efficient and Realistic RTL Fuzzing
abstract
Bugs exist in hardware, such as CPU. Unlike software bugs, these hardware bugs need to be detected before deployment. Previous fuzzing work in CPU bug detection has several disadvantages, e.g., the length of RTL input instructions keeps growing, and longer inputs are ineffective for fuzzing. In this paper, we propose INSTILLER (Instruction Distiller), an RTL fuzzer based on ant colony optimization (ACO). First, to keep the input instruction length short and efficient in fuzzing, it distills input instructions with a variant of ACO (VACO). Next, related work cannot simulate realistic interruptions well in fuzzing, and INSTILLER solves the problem of inserting interruptions and exceptions in generating the inputs. Third, to further improve the fuzzing performance of INSTILLER, we propose hardware-based seed selection and mutation strategies. We implement a prototype and conduct extensive experiments against state-of-the-art fuzzing work in real-world target CPU cores. In experiments, INSTILLER has 29.4% more coverage than DiFuzzRTL. In addition, 17.0% more mismatches are detected by INSTILLER. With the VACO algorithm, INSTILLER generates 79.3% shorter input instructions than DiFuzzRTL, demonstrating its effectiveness in distilling the input instructions. In addition, the distillation leads to a 6.7% increase in execution speed on average.
Gen Zhang, Pengfei Wang 0010, Tai Yue, Danjun Liu, Yubei Guo, Kai Lu 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2023 VulHawk: Cross-architecture Vulnerability Detection with Entropy-based Binary Code Search
Zhenhao Luo, Pengfei Wang 0010, Yong Tang 0005, Wei Xie 0007, Xu Zhou 0004, Danjun Liu, Kai Lu 0001
NDSS7
2023 From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel
abstract
Vulnerability fixing is time-consuming, hence, not all of the discovered vulnerabilities can be fixed timely. In reality, developers prioritize vulnerability fixing based on exploitability. Large numbers of vulnerabilities are delayed to patch or even ignored as they are regarded as “unexploitable” or underestimated owing to the difficulty in exploiting the weak primitives. However, exploits may have been in the wild. In this paper, to exploit the weak primitives that traditional approaches fail to exploit, we propose a versatile exploitation strategy that can transform weak exploit primitives into strong exploit primitives. Based on a special object in the kernel named Thanos object, our approach can exploit a UAF vulnerability that does not have function pointer dereference and an OOB write vulnerability that has limited write length and value. Our approach overcomes the shortage that traditional exploitation strategies heavily rely on the capability of the vulnerability. To facilitate using Thanos objects, we devise a tool namedTAODEto automatically search for eligible Thanos objects from the kernel. Then, it evaluates the usability of the identified Thanos objects by the complexity of the constraints. Finally, it pairs vulnerabilities with eligible Thanos objects. We have evaluated our approach with real-world kernels.TAODEsuccessfully identified numerous Thanos objects from Linux. Using the identified Thanos objects, we proved the feasibility of our approach with 20 real-world vulnerabilities, most of which traditional techniques failed to exploit. Through the experiments, we find that in addition to exploiting weak primitives, our approach can sometimes bypass the kernel SMAP mechanism (CVE-2016-10150, CVE-2016-0728), better utilize the leaked heap pointer address (CVE-2022-25636), and even theoretically break certain vulnerability patches (e.g., double-free).
Danjun Liu, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Zhenhao Luo, Tai Yue
IEEE Trans. Inf. Forensics Secur.1
2018 Automated Vulnerability Detection in Embedded Devices
Danjun Liu, Yong Tang 0005, Wei Xie 0007, Bo Yu 0008
IFIP Int. Conf. Digital Forensics1
2005 Spare Instance: an Adaptive Mechanism for Managing Cluster Applications
abstract
Some measurements of performance have been conducted in Dawning 4000 cluster. We measured the elapsed time of putting the spare instance into use to be 0.12 sec by redirection, while taking the old policy, the time for an Apache instance takes 1.05 sec. For an Oracle 10G, the cost is 7.69 sec. The spare servers contribute to a public spare resource pool. In the case of the master instance's failure, the spare instance avoids service gap and provide non-stop service. For the SLA violation incurred by the short time overload, the available resource could be enlarged instantaneously, much quickly than launching a new instance temporarily. In the best case, the service capacity may be enhanced one time, thus the QoS performance could be guaranteed. Furthermore, for the workload fluctuation, the overhead of frequently launching and terminating instance has been cut down. By introducing the spare instance, the adaptive capacity of the application has been greatly improved in the case of short-term overload and the workload fluctuation
Danjun Liu
CLUSTER3
2005 Adaptive Management of a Utility Computing
abstract
The complexity of the high performance Web-based application challenges the traditional approaches, which fail to guarantee the reliability and real-time performance required. In this paper, we have studied the adaptive mechanisms for managing such applications and explained them based on a prototype of an adaptive application management system (AMUS) in cluster. AMUS is composed of the SLA event-driven global resource manager, the server resource manager and the self-adapting application systems based on feedback control theory. The adoption of feedback control theory supports the application resource control in the case of the resource contention and the guarantee of the QoS performance in the changing environment
Dan Meng 0002, Danjun Liu, Jianfeng Zhan
CLUSTER4
2000 Office message center - a spoken dialogue system
Jiang Han, Yonghong Yan 0002, Danjun Liu
INTERSPEECH6
2000 Using HPSG to represent multi-modal grammar in multi-modal dialogue
Crusoe Mao, Tony Tuo, Danjun Liu
INTERSPEECH3