VLDB 2026 Research / reviewers in the wild / expert
Zheming Li
dblp:62/7776
· DBLP profile ↗
13ranked-venue papers
0as first author
12since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Mooncake: Trading More Storage for Less Computation - A KVCache-centric Architecture for Serving LLM Chatbot
Ruoyu Qin, Zheming Li, Weiran He, Jialei Cui, Feng Ren, Yongwei Wu 0001, Xinran Xu |
FAST | 2 |
| 2025 | Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
Zheyu Ma, Qiang Liu 0034, Zheming Li, Tingting Yin, Wende Tan, Chao Zhang 0008, Mathias Payer |
NDSS | 3 |
| 2024 | Formatted Stateful Greybox Fuzzing of TLS ServerabstractThe TLS protocol is one of the most crucial foundations for ensuring internet security. Consequently, vulnerabilities within the TLS protocol have a significant impact on the Internet security. This paper aims to explore more efficient methods of discovering vulnerabilities in the TLS protocol. Fuzzing stands out as one of the most important techniques for vulnerability discovery in the TLS protocol. To tackle the high complexity of the TLS protocol, stateful greybox fuzzers such as AFLnet have been introduced to enable stateful fuzzing of TLS servers. However, these mutation-based fuzzers often encounter chal-lenges in preserving the message format information during the mutation process, which can undermine the testing results. As a result, this paper proposes a novel approach that incorporates a formatted mutation strategy into the stateful greybox fuzzing process, with the aim of achieving more efficient mutation results. The evaluation process involves four mainstream fuzzers, with OpenSSL's TLS server serving as the target. The results demonstrate that the proposed method significantly enhances the quality of generated seeds, code coverage, and state coverage across all four fuzzers. Jiangan Ji, Hui Shu, Zheming Li, Tieming Liu, Chao Zhang 0008 |
ICST | 4 |
| 2024 | EnclaveFuzz: Finding Vulnerabilities in SGX Applications
Zheming Li, Zheyu Ma, Yuan Li 0061, Baojian Chen, Chao Zhang 0008 |
NDSS | 2 |
| 2024 | Graphuzz: Data-driven Seed Scheduling for Coverage-guided Greybox FuzzingabstractSeed scheduling is a critical step of greybox fuzzing, which assigns different weights to seed test cases during seed selection, and significantly impacts the efficiency of fuzzing. Existing seed scheduling strategies rely on manually designed models to estimate the potentials of seeds and determine their weights, which fails to capture the rich information of a seed and its execution and thus the estimation of seeds’ potentials is not optimal. In this article, we introduce a new seed scheduling solution, Graphuzz, for coverage-guided greybox fuzzing, which utilizes deep learning models to estimate the potentials of seeds and works in a data-driven way. Specifically, we propose an extended control flow graph called e-CFG to represent the control-flow and data-flow features of a seed's execution, which is suitable for graph neural networks (GNN) to process and estimate seeds’ potential. We evaluate each seed's code coverage increment and use it as the label to train the GNN model. Further, we propose a self-attention mechanism to enhance the GNN model so that it can capture overlooked features. We have implemented a prototype of Graphuzz based on the baseline fuzzer AFLplusplus. The evaluation results show that our model can estimate the potential of seeds and has the robust capability to generalize to different targets. Furthermore, the evaluation using 12 benchmarks from FuzzBench shows that Graphuzz outperforms AFLplusplus and the state-of-the-art seed scheduling solution K-Scheduler and other coverage-guided fuzzers in terms of code coverage, and the evaluation using 8 benchmarks from Magma shows that Graphuzz outperforms the baseline fuzzer AFLplusplus and SOTA solutions in terms of bug detection. Shuitao Gan, Chao Zhang 0008, Zheming Li, Jiangan Ji, Baojian Chen |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2023 | Landmark-based Partial Multi-label Learning with Noise ProcessingabstractMulti-label learning (MLL) assumes that all labels are ground-truth, which can be costly or difficult to implement in practice. Partial multi-label learning (PML) provides an alternative by recognizing that each instance corresponds to a set of candidate labels, with only one subset representing the ground-truth label set. However, accurately identifying the ground-truth labels from the candidate set, which may be contaminated with noise, is the main challenge of PML. To address this challenge, we propose a landmark-based PML approach called LbPML, which incorporates noise recognition and space structure processing. We evaluate LbPML against three PML algorithms and three MLL algorithms using datasets from six different domains, and assess its performance using five commonly used evaluation criteria. Our extensive experimental results provide compelling evidence of the effectiveness of our proposed method. Zheming Li, Landong Liu, Zhenwu Wang |
IJCNN | 2 |
| 2023 | Adversarial example generation with adabelief optimizer and crop invariance
Bo Yang 0049, Hengwei Zhang, Zheming Li, Kaiyong Xu, Jindong Wang 0002 |
Appl. Intell. | 3 |
| 2022 | PrIntFuzz: fuzzing Linux drivers via automated virtual device simulationabstractLinux drivers share the same address space and privilege with the core of the kernel but have a much larger code base and attack surface. The Linux drivers are not well tested and have weaker security guarantees than the kernel. Missing support from hardware devices, existing fuzzing solutions fail to cover a large portion of the driver code, e.g., the initialization code and interrupt handlers. In this paper, we present PrIntFuzz, an efficient and universal fuzzing framework that can test the overlooked driver code, including the PRobing code and INTerrupt handlers. PrIntFuzz first extracts knowledge from the driver through inter-procedural field-sensitive, path-sensitive, and flow-sensitive static analysis. Then it utilizes the information to build a flexible and efficient simulator, which supports device probing, hardware interrupts emulation and device I/O interception. Lastly, PrIntFuzz applies a multi-dimension fuzzing strategy to explore the overlooked code. We have developed a prototype of PrIntFuzz and successfully simulated 311 virtual PCI (Peripheral Component Interconnect) devices, 472 virtual I2C (Inter-Integrated Circuit) devices, 169 virtual USB (Universal Serial Bus) devices, and found 150 bugs in the corresponding device drivers. We have submitted patches for these bugs to the Linux kernel community, and 59 patches have been merged so far. In a control experiment of Linux 5.10-rc6, PrIntFuzz found 99 bugs, while the state-of-the-art fuzzer only found 50. PrIntFuzz covers 11,968 basic blocks on the latest Linux kernel, while the state-of-the-art fuzzer Syzkaller only covers 2,353 basic blocks. Zheyu Ma, Bodong Zhao, Letu Ren, Zheming Li, Siqi Ma 0001, Xiapu Luo, Chao Zhang 0008 |
ISSTA | 4 |
| 2022 | StateFuzz: System Call-Based State-Aware Linux Driver Fuzzing
Bodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma, Ming Yuan 0003, Wenyu Zhu, Zhihong Tian, Chao Zhang 0008 |
USENIX Security Symposium | 2 |
| 2022 | Improving chronic disease management for children with knowledge graphs and artificial intelligenceabstractChronic diseases for children pose serious challenges from a health management perspective. When not implemented in a well-designed manner, an inefficient management platform can have a significant negative impact on patients and the utilization of health care resources. Innovations of recent years in information technology, artificial intelligence and machine learning provide possibilities to design and implement knowledge-based systems and platforms that follow-up, monitor and advise child patients with a chronic disease in an automated manner. In this article we propose the Artificial Intelligence Chronic Management System that combines artificial intelligence, knowledge graph, big data and internet of things in a platform to offer an optimized solution from the perspective of treatment and utilization of resources. The system includes patient and hospital clients, data storage and analytic tools for decision support relying on AI-based services. We illustrate the functionality of the system through different situations frequently occurring in pediatric wards. To assess the feasibility of the AI component, we utilize real life health care data from a hospital in China to develop a classification model for patients with asthma. To provide a more qualitative assessment at the same time, we discuss how the Artificial Intelligence Chronic Management System conforms to the requirements set forth by the standard Chronic Care Model. Mohammad Tabatabaei, József Mezei, Qianhui Zhong, Zheming Li, Liqi Shu, Qiang Shu |
Expert Syst. Appl. | 6 |
| 2021 | iDEV: exploring and exploiting semantic deviations in ARM instruction processingabstractARM has become the most competitive processor architecture. Many platforms or tools are developed to execute or analyze ARM instructions, including various commercial CPUs, emulators, and binary analysis tools. However, they have deviations when processing the same ARM instructions, and little attention has been paid to systematically analyze such semantic deviations, not to mention the security implications of such deviations. In this paper, we conduct an empirical study on the ARM Instruction Semantic Deviation (ISDev) issue. First, we classify this issue into several categories and analyze the security implications behind them. Then, we further demonstrate several novel attacks which utilize the ISDev issue, including stealthy targeted attacks and targeted defense evasion. Such attacks could exploit the semantic deviations to generate malware that is specific to certain platforms or able to detect and bypass certain detection solutions. We have developed a framework iDEV to systematically explore the ISDev issue in existing ARM instructions processing tools and platforms via differential testing. We have evaluated iDEV on four hardware devices, the QEMU emulator, and five disassemblers which could process the ARMv7-A instruction set. The evaluation results show that, over six million instructions could cause dynamic executors (i.e., CPUs and QEMU) to present different runtime behaviors, and over eight million instructions could cause static disassemblers yielding different decoding results, and over one million instructions cause inconsistency between dynamic executors and static disassemblers. After analyzing the root causes of each type of deviation, we point out they are mostly due to ARM unpredictable instructions and program defects. Shisong Qin, Chao Zhang 0008, Kaixiang Chen, Zheming Li |
ISSTA | 4 |
| 2021 | Identification of pediatric respiratory diseases using a fine-grained diagnosis system
Zhongzhi Yu, Yemin Shi 0001, Yingshuo Wang, Zheming Li, Yonggen Zhao, Fenglei Sun, Yizhou Yu, Qiang Shu |
J. Biomed. Informatics | 6 |
| 2020 | Adversarial active learning for the identification of medical concepts and annotation inconsistency
Xuying Wang, Huachun Zhen, Guoping He, Zheming Li, Yonggen Zhao, Qiang Shu, Liqi Shu |
J. Biomed. Informatics | 6 |