Rong Ren

dblp:67/9545 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ArguMath: AI-Simulated Environment for Pre-service Teacher Training in Orchestrating Classroom Mathematics Argumentation
Jiwon Chun, Yuling Zhuang, Armanto Sutedjo, Colin Xu, Rong Ren, Meng Xia 0002
AIED (5)5
2026 Convolutional neural network-based vulnerability detection using image representations fused from key code slice text features and complex network metrics
Bing Zhang 0011, Ni Liao, Wenqi Xue, Rong Ren, Xu Kang 0001
Eng. Appl. Artif. Intell.5
2026 Vul2image: A quick image-inspired and CNN-based vulnerability detection system
Rong Ren, Mushi Zhou, Ni Liao, Bing Zhang 0011, Guoyan Huang, Haitao He, Qian Wang 0009
Expert Syst. Appl.1
2026 TPP: A temporal-enhanced propagation probability model for identifying influential nodes in complex networks
Bing Zhang 0011, Rong Ren, Jiadong Ren, Qian Wang 0009
Expert Syst. Appl.3
2026 SSRFinder: SSRF vulnerability detection and validation based on program dependency graphs and pre-trained models
Bing Zhang 0011, Chenhua Lou, Yanxuan Lou, Rong Ren, Qian Wang 0009
Expert Syst. Appl.4
2026 PRWHA: RGB Image-Based Hybrid Attention for Cross-File SQLI/XSS Vulnerability Detection in PHP Web Applications
abstract
As the most widely used server-side programming language for web applications, PHP has a large number of SQL injection (SQLI) and cross-site scripting (XSS) vulnerabilities that are exploited maliciously, making the detection of such vulnerabilities increasingly critical. Existing source code detection methods suffer from issues such as uncleaned redundant information, limited representation dimensions and poor detection performance. To address these challenges, we propose a PHP vulnerability detection method based on RGB image representation and hybrid attention mechanisms — PHP ResNet with Hybrid Attention (PRWHA). First, PRWHA marks the input sources and sensitive functions, constructs data flow and control flow graphs between source and sink points and adds function call edges. This method uniquely identifies nodes in the graph using filenames and line numbers to enable inter-procedural and cross-file detection. Next, it leverages both the topological information (including data flow, control flow and function call relationships) and textual information of the code’s graph structure to generate RGB images. These images are then processed by a ResNet-50 model enhanced with a hybrid attention layer to detect SQLI and XSS vulnerabilities. To validate the effectiveness of PRWHA, we evaluated it on both publicly available datasets and real-world software datasets. The results demonstrate that PRWHA outperforms traditional methods as well as other machine learning, deep learning and Large Language Model (LLM)-based detection approaches. On the public dataset, PRWHA achieved an accuracy of 99.00% and an F1-score of 97.13% on the test set. On the real-world software dataset, it achieved an accuracy of 73% and a vulnerability detection rate of approximately 83.67%.
Rong Ren, Qingyu Song 0006, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang
Int. J. Softw. Eng. Knowl. Eng.1
2026 HVDet: Heap Vulnerability Detection Method Based on P-PDG Representation and Bi-GRU Algorithm
abstract
Heap vulnerabilities pose a significant risk to software, leading to stability issues such as slowdown and resource depletion. These vulnerabilities can potentially disrupt critical operations and compromise the overall system performance, especially in the case of automated control systems implemented in C/C[Formula: see text] language. While various artificial intelligence-based detection methods have been studied, there has been limited analysis of the detection process and the structural and semantic features, resulting in lower detection efficiency. This paper proposes a novel heap vulnerability detection (HVDet) method based on the Pointer Program Dependency Graph (P-PDG) representation and Bidirectional Gated Recurrent Unit (Bi-GRU) algorithm for software. Through inter-procedural analysis, the P-PDG serves as an innovative code representation model that places emphasis on pointer operations, which are closely associated with heap vulnerabilities. It leads to a reduction in code size while simultaneously capturing a broader range of structural and semantic features of the source code. Subsequently, a mixed feature matrix incorporating these features from code slices is generated as input for the Bi-GRU algorithm. When compared with 7 state-of-the-art (SOTA) vulnerability detection tools, HVDet demonstrates superior performance. It successfully identified three heap vulnerabilities in real-world software such as Linux Kernel, Espruino and LibreDWG.
Rong Ren, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang
Int. J. Softw. Eng. Knowl. Eng.1
2025 Interprocedural Call Graph Embedding with GAT for Memory safety Vulnerability Detection
abstract
Memory safety vulnerabilities remain a critical threat to software security, often leading to system crashes, data leakage, and service disruptions. Existing deep learning-based detection methods mainly rely on intra-procedural analysis, which limits their ability to capture complex memory behaviors involving pointer variable flows across function boundaries. This study proposes IpGAT, an InterProcedural memory vulnerability detection framework based on Graph Attention Network (GAT) that aims to overcome the limitations of intra-procedural approaches by modeling cross-function data flows of pointer variables. IpGAT constructs an Interprocedural Program Call Graph (IpCG) that integrates Abstract Syntax Trees (AST), Control Flow Graphs (CFG), and Data Flow Graphs (DFG) to represent memory-sensitive function interactions. The IpCG is embedded using Word2Vec and then fed into a GAT for vulnerability classification. Experimental results show that IpGAT achieves an accuracy of 88.9%, a precision of 86.5%, and an F1-score of 89.1%, significantly outperforming six state-of-the-art tools and intra-procedural baselines. Furthermore, IpGAT successfully identified eight real-world memory safety vulnerabilities in open-source projects such as ffdshow, Libav, Seamonkey, and VLC, all of which have been confirmed in the CVE database. By incorporating interprocedural analysis and graph-based learning, IpGAT effectively captures the semantics of memory-sensitive operations and demonstrates strong generalizability across both benchmark datasets and real-world software.
Rong Ren, JingYi Wu, HongBo Jin, QingYu Song, Bing Zhang 0011, Qian Wang 0009
TrustCom1
2025 A Systematic Literature Review of Software Vulnerability Mining Approaches Based on Symbolic Execution
abstract
With the rapid development of the software industry, the escalating issue of software vulnerabilities has posed significant risks to users. Symbolic execution as a vulnerability mining technology offers a high-test coverage. The existing reviews of symbolic execution methods focus on summarizing various techniques and tools. While some studies have analyzed the technical challenges, classification frameworks and development trends of these methods, they lack a comprehensive and systematic review. This study aims to address the gap in existing reviews by providing a comprehensive, systematic analysis of symbolic execution techniques for vulnerability mining. We conducted a detailed review of 60 peer-reviewed papers published between 2005 and 2024, focusing on symbolic execution techniques for vulnerability mining. First, we reviewed the main techniques used in the symbolic execution process, including program instrumentation, path selection strategy and constraint-solving techniques. Second, we extracted the main information from the selected papers, and the detailed information on the symbolic execution tools is in the form of a table. Compared and analyzed the research object, the execution process at the same time, the software architecture and the application on different system platforms. Finally, we present a comprehensive and systematic summary of current challenges and corresponding solutions in the field. This study provides an in-depth analysis of vulnerability detection technologies based on symbolic execution, serving as a valuable guide for researchers in this domain.
Lining Li, Rong Ren, Bing Zhang 0011, Xu Kang 0001
Int. J. Softw. Eng. Knowl. Eng.2
2025 MalRGBDet: Windows Malware Detection Method Based on RGB Image Representation and Heterogeneous Neural Network
abstract
As the world’s most widely used operating system, Windows has long been a primary target for malware attacks, causing severe economic losses and threats to data security for users and enterprises. Existing detection methods often struggle with low accuracy when dealing with complex malware, suffering from high false-negative and false-positive rates. Additionally, malware detection in Windows faces challenges such as limited datasets, a lack of benign sample contrast and insufficient original feature information. To address these issues, we propose a malware detection method based on RGB image representation and heterogeneous neural network (MalRGBDet). First, we collected malware samples from the GitHub and VirusShare platforms, along with benign software from Windows systems, to build a dataset named MalDet. This data set contains unprocessed malicious and benign samples, providing original feature information and addressing the lack of benign samples in existing data sets. Next, we extracted three key features from the malware samples: code sections, data sections and API call sequences. These features closely relate to the behavior of malware and accurately describe its operations. We then transformed these features into uniformly sized RGB images, which helped reveal hidden patterns. Finally, we employ a heterogeneous neural network that integrates ResNet and AlexNet for classification. ResNet, with its deep architecture and residual learning mechanism, significantly enhances the model’s representation capability and classification performance, thereby improving detection accuracy. Meanwhile, AlexNet’s Dropout regularization strategy effectively boosts the model’s generalization ability. In our data set of 1952 Windows software samples, MalRGBDet achieved more than 95% in accuracy, precision, recall and F1-score, improving these metrics by up to 4% compared to the latest methods. Furthermore, false-negative and false-positive rates were kept below 5%.
Rong Ren, Hongchang Zhang, Bing Zhang 0011, Haitao He, Guoyan Huang, Qian Wang 0009
Int. J. Softw. Eng. Knowl. Eng.1
2025 DRacv: Detecting and auto-repairing vulnerabilities in role-based access control in web application
Bing Zhang 0011, Jingyue Li, Haitao He, Rong Ren, Jiadong Ren
J. Netw. Comput. Appl.5
2025 Enhancing Java Web Application Security: Injection Vulnerability Detection via Interprocedural Analysis and Deep Learning
abstract
Injection attacks exploit vulnerabilities in how applications handle user input, allowing malicious code to infiltrate the execution environment of web applications, leading to severe consequences, such as data leaks and system crashes. Traditional dynamic and static detection methods suffer from limitations in manual rule or pattern design and intraprocedural analysis, lacking the capability to automatically learn complex features. Meanwhile, deep learning models encounter challenges, such as feature redundancy and inefficiency, in processing long code sequences. Here, we propose a prototype for detectingInjectionVulnerabilities in Java web applications based onInterprocedural analysis and the bidirectional encoder representations from transformersBERT-BiLSTM-CRF model (IVIB), effectively transforming vulnerability detection into text sequence annotation. IVIB employs interprocedural analysis to trace complete program data flow, control flow, method and class dependencies, reducing redundancy through a system dependency graph. Then, we develop intermediate language representation rules and conversion mechanisms specifically for Java programs, symbolically representing code snippets and annotating them to construct a corpus. IVIB achieves remarkable results, with over 96% accuracy, precision, recall, and F1-score in binary classification, surpassing other state-of-the-art models in multiclassification performance. Evaluation on real-world projects demonstrates IVIB's effectiveness, detecting 28 vulnerabilities out of 30 vulnerable slices with low false positives and no false negatives.
Bing Zhang 0011, Xu Zhi, Rong Ren
IEEE Trans. Reliab.4
2024 Joint Resource Allocation for Multiplexing eMBB, URLLC and mMTC Traffics Based on DRL
abstract
In 5G networks and beyond, enhanced Mobile Broadband (eMBB) service targets at providing extremely high throughput, Ultra-Reliable and Low Latency Communications (URLLC) service supports high reliability and low latency while massive machine-type communication (mMTC) aims at high connection density. Different types of traffic have different requirements, which brings difficultity to serve different users on the same resource block. In this paper, we investigate the co-existence of eMBB, URLLC and mMTC services based on superposition scheme in the 5G downlink scenario. To minimize the average data rate loss of eMBB users while satisfying the latency and reliability constraints of URLLC and mMTC users, we formulate a mixed-integer nonlinear program (MINLP) problem which is non-convex. We propose Successive Convex Approximation (SCA) Method and Proximal Policy Optimization (PPO), an advanced deep reinforcement learning (DRL) algorithm, to solve the non-convex problem. In the proposed algorithm, the agent seeks for the optimal user pairing and power allocation policy when the URLLC traffic arrives sporadically. Simulation results depicts the performance of our proposed PPO based superposition scheme nears to SCA-based method with lower complexity.
Rong Ren, Jie Wang 0105, Jingming Yu, Xuetao Wan, Hua Lu 0012
VTC Spring1
2024 Approach to Detect Windows Malware Based on Malicious Tendency Image and ResNet Algorithm
abstract
Timely detection of self-replicating malware in the high market share Windows operating system can effectively prevent personal or corporate financial losses. The form and characteristics of malware are constantly evolving, leading to a concept drift issue that gradually decreases the effectiveness of traditional detection methods. Therefore, we propose WinMDet, a Windows malware detection method based on malicious tendency image and ResNet algorithm. First, to tackle the complexity and difficulty in accurately characterizing malware features, WinMDet retains detailed malware features and encodes them into malicious tendency images to better describe malware across different periods. Secondly, WinMDet utilizes previously generated malicious tendency images to train the initial detection model. Then, to alleviate the issue of malware concept drift, WinMDet employs Local Maximum Mean Discrepancy (LMMD) as the criterion for model transfer, enhancing the initial detection model’s ability to distinguish between malware and benign software. We conducted a comprehensive evaluation of WinMDet using common metrics such as accuracy, precision and recall. The results indicate that WinMDet performs remarkably well in terms of accuracy, exceeding 82%. Additionally, significant improvements were observed in precision and recall, surpassing 82.42% and 82.06%, respectively. After employing our LMMD-based transfer method, the initial detection model improved the detection accuracy of malware in 2021 and 2022 by approximately 4.22% to 8.06%. The false negative rate decreased by at most 4.34%, and the false positive rate decreased by at most 4.61%.
Bing Zhang 0011, Hongchang Zhang, Rong Ren, Qian Wang 0009
Int. J. Softw. Eng. Knowl. Eng.3
2024 SQLPsdem: A Proxy-Based Mechanism Towards Detecting, Locating and Preventing Second-Order SQL Injections
abstract
Due to well-hidden and stage-triggered properties of second-order SQL injections in web applications, current approaches are ineffective in addressing them and still report high false negatives and false positives. To reduce false results, we propose a Proxy-based static analysis and dynamic execution mechanism towards detecting, locating and preventing second-order SQL injections (SQLPsdem). The static analysis first locates SQL statements in web applications and identifies all data sources and injection points (e.g., Post, Sessions, Database, File names) that injection attacks can exploit. After that, we reconstruct the SQL statements and use attack engines to jointly generate attacks to cover all the state-of-the-art attack patterns so as to exploit these applications. We then use proxy-based dynamic execution to capture the data transmitted between web applications and their databases. The data are the reconstructed SQL statements with variable values from the attack payloads. If a web application is vulnerable, the data will contain malicious attacks on the database. We match the data with rules formulated by attack patterns to detect first and second-order SQL injection vulnerabilities in web applications, particularly the second-order ones. We use a representative and complete coverage of attack patterns and precise matching rules to reduce false results. By escaping and truncating malicious payloads in the data transmitted from the web application to the database, we can eliminate the possible negative impact of the data on the database. In the evaluation, by generating 52,771 SQL injection attacks using four attack generators, SQLPsdem successfully detects 26 second-order (including 13 newly discovered ones) and 375 first-order SQL injection vulnerabilities in 12 open-source web applications. SQLPsdem can also 100% eliminate the malicious impact of the data with negligible overhead.
Bing Zhang 0011, Rong Ren, Mingcai Jiang, Jiadong Ren, Jingyue Li
IEEE Trans. Software Eng.2
2013 A PMC-driven methodology for energy estimation in RVC-CAL video codec specifications
Rong Ren, Jianguo Wei, Eduardo Juárez Martínez, Matías J. Garrido, César Sanz, Fernando Pescador
Signal Process. Image Commun.1
2004 Traffic engineering with constraint-based routing in DiffServ/MPLS network
abstract
This paper develops a novel mechanism for traffic engineering, which combines differentiated services (DiffServ) and constraint-based routing together to meet the different QoS requirements, while preserving load balancing simultaneously. Simulation results illustrate the advantage of this mechanism. The proposed MPLS-TE mechanism can guarantee QoS requirements of the traffic flows and outperforms the traditional methods in terms of load balancing and throughout, so that the capability of the network is improved in evidence.
Bingqing Yang, Rong Ren, Yanhui Geng, Nenghai Yu
LANMAN3