VLDB 2026 Research / reviewers in the wild / expert
Qian Sang
dblp:55/7141
· DBLP profile ↗
4ranked-venue papers
3as first author
2since 2021 · last 2024
0000-0001-7377-7812ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 first-authorSecurity and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Program analysis · 100% | |
| Network and information security
2 papers |
Systems and software security · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
1.3 | 2 | 2024 | AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024 HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022 |
Program analysis
dynamic analysis |
0.9 | 2 | 2024 | AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024 HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022 |
Program analysis › static analysis
taint analysis |
0.8 | 1 | 2024 | AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024 |
Systems and software security › vulnerability discovery
fuzzing |
0.6 | 1 | 2022 | HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022 |
Program analysis › dynamic analysis
instrumentation |
0.2 | 1 | 2024 | AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024 |
Methods — techniques the papers use, named apart from their topics
instruction-level emulation · 1.5basic block-level abstraction · 1.5coverage-guided fuzzing · 1.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | AirTaint: Making Dynamic Taint Analysis Faster and EasierabstractDynamic Taint Analysis (DTA) is a widely used data flow tracking technique and helps security researchers in various applications, such as fuzzing and vulnerability analysis. One critical problem that affects its practicability is the significant overhead. According to our analysis, in some scenarios, the state-of-the-art works even slow the program execution efficiency by more than 100x. The high overhead is mainly because most of them conduct taint analysis at the instruction level and use just-in-time instrumentation methods to insert the tracking codes into the original program.In this paper, we propose AirTaint, a novel approach that combines the basic block-level abstraction of taint rules and assembly code-level instrumentation to conduct high-level dynamic taint analysis. Specifically, AirTaint leverages instruction-level emulation to identify the in and out operands (i.e., registers and memory variables) of each basic block, and then uses the existing taint engine to infer the taint rule abstraction for each basic block. Finally, it inserts the assembly code of the taint rule abstraction into the original program. While running, the program will execute the inserted taint analysis code quickly. In our evaluation based on 14 CVEs in 9 real-world applications, AirTaint detects all these vulnerabilities successfully. And in the comparison experiments, AirTaint performs much better than the existing tools in efficiency on 29 real-world applications, with maximum improvements of 931.0x, 5.97x, and 328.3x than libdft, SelectiveTaint, and TaintRabbit, respectively. Qian Sang, Yuwei Liu 0001, Xiangkun Jia, Tiffany Bao, Purui Su |
SP | 1 |
| 2022 | HTFuzz: Heap Operation Sequence Sensitive FuzzingabstractHeap-based temporal vulnerabilities (i.e., use-after-free, double-free and null pointer dereference) are highly sensitive to heap operation (e.g., memory allocation, deallocation and access) sequences. To efficiently find such vulnerabilities, traditional code coverage-guided fuzzing solutions could be promoted by integrating heap operation sequence feedback. But current sequence sensitive solutions have limitations in practice. Yuanping Yu, Xiangkun Jia, Yuwei Liu 0001, Qian Sang, Chao Zhang 0008, Purui Su |
ASE | 5 |
| 2016 | Learning automata for image segmentation
Qian Sang, Zongli Lin, Scott T. Acton |
Pattern Recognit. Lett. | 1 |
| 2015 | A grid-based tracker for erratic targets
Qian Sang, Zongli Lin, Scott T. Acton |
Pattern Recognit. | 1 |