VLDB 2026 Research / reviewers in the wild / expert
Shih-Kun Huang
dblp:72/7017
· DBLP profile ↗
14ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0002-6766-4683ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-authorComputer networks · 2Databases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2Security and privacy · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Fuzzing Command-line Interface by Edge Coverage Guided Combinatorial Testing and Input ClusteringabstractWith the development of fuzz testing, many studies have been dedicated to improving the efficiency and finding more in-depth bugs. In this paper, we propose a new seed-selection approach, where K-means clustering is employed to partition the entire seed pool into several disjoint groups, aiming to disperse the paths taken by the fuzzer in different rounds of fuzzing. Additionally, our fuzzer evaluates the usefulness of each group of seeds at runtime and favors the groups that are more useful than one another so that the input which can lead to new paths will be selected. We also refer to a fuzzing technique called “command-line interface fuzzing.” This technique adds a mutation stage that generates the command-line arguments the target program uses, enabling our fuzzer to detect more vulnerabilities and resolve the path explosion problems in combinatorial testing. We combine multiple command-line arguments fuzzing with seed selection to deal with the problem where specific sets of command-line parameters appear too frequently. Based on AFL, we have designed our fuzzer: Yuan-fuzz. Yuan-Fuzz visited 1.7 times more edge coverage than the state-of-theart fuzzers of AFL and AFLfast and found 30 previously unknown and recognized vulnerabilities from various open-source projects using our fuzzer, 21 of which have been assigned CVE identifiers. Han-Lin Lu, Zong-Yuan Wu, Guan-Zhong Wang, Shih-Kun Huang |
QRS | 5 |
| 2022 | Pain Pickle: Bypassing Python Restricted Unpickler for Automatic Exploit GenerationabstractPickle is a built-in library in Python that can serialize and deserialize Python objects and data structures. However, the process of pickle deserialization has been confirmed as a hazardous operation. Marco Slaviero uncovered its dangerous vulnerability and proposed exploitation methods in BlackHat 2011. As a result, corresponding defense methods have also been generated. Restricting Globals was proposed in the official Python documentation as a defensive approach.We find that defense implementations are incorrect in some cases. Therefore, we conducted a large-scale analysis of 7543 open-source Python projects with more than 100 stars to find that 36 projects have implemented defense strategies. Among them, nine projects were not correctly implemented. Furthermore, we investigated the root causes of their failures for automatic exploit generation from these projects. Nan-Jung Huang, Chih-Jen Huang, Shih-Kun Huang |
QRS | 3 |
| 2021 | REST API Fuzzing by Coverage Level Guided Blackbox TestingabstractWith the growth of web applications, REST APIs have become the primary communication method between services. In order to ensure system reliability and security, software quality can be assured by effective testing methods. Black box fuzz testing is one of the effective methods to perform tests on a large scale. However, conventional black box fuzz testing generates random data without judging the quality of the input. We implement a black box fuzz testing method for REST APIs. It resolves the issues of blind mutations without knowing the effectiveness by Test Coverage Level feedback. We also enhance the mutation strategies by reducing the testing complexity for REST APIs, generating more appropriate test cases to cover possible paths. We evaluate our method by testing two large open-source projects and 89 bugs are reported and confirmed. In addition, we find 351 bugs from 64 remote API services in APIs.guru. The work is in https://github.com/iasthc/hsuan-fuzz. Chung-Hsuan Tsai, Shi-Chun Tsai, Shih-Kun Huang |
QRS | 3 |
| 2020 | Testing Convolutional Neural Network using Adversarial Attacks on Potential Critical PixelsabstractConvolutional neural networks (CNNs) are known to be vulnerable to adversarial attacks. Well-crafted perturbations to the inputs can mislead a state-of-the-art CNN to make wrong decisions. Therefore, there is a pressing need for the development of methods that can test or detect the vulnerability of CNNs. In this study, we propose an adversarial attack method, called Dual Iterative Fusion (DIF) with potential critical pixels, for CNN testing to reveal the vulnerability of CNNs. DIF modifies as few as 5 pixels out of 32x32 images in this study and achieves faster, less noticeable, and more targeted attacks to a CNN. Testing CNNs with DIF, we observed that some classes are more vulnerable than the others within many classical CNNs for image classification. In other words, some classes are susceptible to misclassification due to adversarial attacks. For example, in VGG19 trained with CIFAR10 data set, the vulnerable class is "Cat". The successfully-targeted attack rate of class "Cat" in VGG19 is obviously higher than the others, 57.01% versus 25%. In the ResNet18, the vulnerable class is "Plane", with a successfully-targeted attack rate of 37.08% while the other classes are lower than 12%. These classes should be considered as vulnerabilities in the CNNs, and are pinpointed by generating test images using DIF. The issues can be mitigated through retraining the CNNs with the adversarial images generated by DIF, and the misclassification rate of the vulnerable classes declines at most from 61.67% to 6.37% after the retraining. Bo-Ching Lin, Hwai-Jung Hsu, Shih-Kun Huang |
COMPSAC | 3 |
| 2015 | CRAXfuzz: Target-Aware Symbolic Fuzz TestingabstractVulnerabilities are caused by implementation bugs, such as buffer overflow, integer overflow, uncontrolled format strings, and command injection flaws. They are often exploited to intrude software systems. In order to reduce software bugs, testing techniques are proposed. The recent technique to discover security-related bugs is fuzz testing. However, traditional fuzzers can only find bugs when program exceptions, especially crashes, raised. Some security threats may pass these tests due to insufficient code coverage. In this paper, we introduce a software testing framework based on symbolic execution using S2E, a whole system symbolic execution engine. When a program executes our pre-defined security sensitive functions, such as malloc, strcpy or printf, our framework will initiate a triage process. The process will determine whether any related security vulnerabilities would possibly occur in these functions automatically. We successfully and efficiently reproduce 12 previously known vulnerabilities from normal input data within 100 seconds for large applications such as Tiff, VIM, and MPlayer. Our tool can help developers locate bugs faster, and improve the efficiency of software quality maintenance. Chao-Chun Yeh, Hsiang Chung, Shih-Kun Huang |
COMPSAC | 3 |
| 2014 | Software Crash Analysis for Automatic Exploit Generation on Binary ProgramsabstractThis paper presents a new method, capable of automatically generating attacks on binary programs from software crashes. We analyze software crashes with a symbolic failure model by performing concolic executions following the failure directed paths, using a whole system environment model and concrete address mapped symbolic memory in S2E. We propose a new selective symbolic input method and lazy evaluation on pseudo symbolic variables to handle symbolic pointers and speed up the process. This is an end-to-end approach able to create exploits from crash inputs or existing exploits for various applications, including most of the existing benchmark programs, and several large scale applications, such as a word processor (Microsoft office word), a media player (mpalyer), an archiver (unrar), or a pdf reader (foxit). We can deal with vulnerability types including stack and heap overflows, format string, and the use of uninitialized variables. Notably, these applications have become software fuzz testing targets, but still require a manual process with security knowledge to produce mitigation-hardened exploits. Using this method to generate exploits is an automated process for software failures without source code. The proposed method is simpler, more general, faster, and can be scaled to larger programs than existing systems. We produce the exploits within one minute for most of the benchmark programs, including mplayer. We also transform existing exploits of Microsoft office word into new exploits within four minutes. The best speedup is 7,211 times faster than the initial attempt. For heap overflow vulnerability, we can automatically exploit the unlink() macro of glibc, which formerly requires sophisticated hacking efforts. Shih-Kun Huang, Min-Hsiang Huang, Po-Yen Huang, Han-Lin Lu, Chung-Wei Lai |
IEEE Trans. Reliab. | 1 |
| 2013 | A black-box based android GUI testing systemabstractIn Android system, black box testing has risen to three key issues: S1: There is no source code and for tester to know the internal logic of the testing App. S2: There is no testing criterion for tester to know the correct behavior and testing scope of the testing App. S3: It is difficult to measure the testing coverage without instrumentation the testing App. In this paper, we provide a approach to analyze the GUI model during the testing process, implement the a black-box based android GUI testing system and select 7 Apps for evaluation. Finally we compare our result of our system with the monkey tool and discuss the inner App's properties that influence on the testing result. Chao-Chun Yeh, Shih-Kun Huang, Sung-Yen Chang |
MobiSys | 2 |
| 2011 | Improved convertible authenticated encryption scheme with provable security
Han-Yu Lin, Chien-Lung Hsu, Shih-Kun Huang |
Inf. Process. Lett. | 3 |
| 2007 | Detection and Diagnosis of Control Interception
Chang-Hsien Tsai, Shih-Kun Huang |
ICICS | 2 |
| 2005 | A testing framework for Web application security assessment
Yao-Wen Huang, Chung-Hung Tsai, Tsung-Po Lin, Shih-Kun Huang, D. T. Lee, Sy-Yen Kuo |
Comput. Networks | 4 |
| 2003 | Web application security assessment by fault injection and behavior monitoringabstractAs a large and complex application platform, the World Wide Web is capable of delivering a broad range of sophisticated applications. However, many Web applications go through rapid development phases with extremely short turnaround time, making it difficult to eliminate vulnerabilities. Here we analyze the design of Web application security assessment mechanisms in order to identify poor coding practices that render Web applications vulnerable to attacks such as SQL injection and cross-site scripting. We describe the use of a number of software-testing techniques (including dynamic analysis, black-box testing, fault injection, and behavior monitoring), and suggest mechanisms for applying these techniques to Web applications. Real-world situations are used to test a tool we named the Web Application Vulnerability and Error Scanner (WAVES, an open-source project available at http://waves.sourceforge.net) and to compare it with other tools. Our results show that WAVES is a feasible platform for assessing Web application security. Yao-Wen Huang, Shih-Kun Huang, Tsung-Po Lin, Chung-Hung Tsai |
WWW | 2 |
| 2000 | Dyadic Wavelet-Based Nonlinear Conduction Equation: Theory and ApplicationsabstractWe proposed a new dyadic wavelet-based conduction approach to take the place of the nonlinear diffusion equation for selective image smoothing. We also proved that the proposed iterated system always satisfies the so-called maximum-minimum principle no matter what kind of wavelet basis is used. Since the proposed approach does not require one to solve a partial differential equation (PDE), it is therefore more efficient and accurate than the conventional nonlinear diffusion/conduction-based methods. Experimental results using 1-D synthetic data and a real image demonstrated that the proposed method can efficiently remove noise and preserve real data. Chwen-Jye Sze, Hong-Yuan Mark Liao, Shih-Kun Huang, Chun-Shien Lu |
ICIP | 3 |
| 2000 | Cocktail Watermarking for Digital Image ProtectionabstractA novel image protection scheme called "cocktail watermarking" is proposed in this paper. We analyze and point out the inadequacy of the modulation techniques commonly used in ordinary spread spectrum watermarking methods and the visual model-based ones. To resolve the inadequacy, two watermarks which play complementary roles are simultaneously embedded into a host image. We also conduct a statistical analysis to derive the lower bound of the worst likelihood that the better watermark (out of the two) can be extracted. With this "high" lower bound, it is ensured that a "better" extracted watermark is always obtained. From extensive experiments, results indicate that our cocktail watermarking scheme is remarkably effective in resisting various attacks, including combined ones. Chun-Shien Lu, Shih-Kun Huang, Chwen-Jye Sze, Hong-Yuan Mark Liao |
IEEE Trans. Multim. | 2 |
| 1992 | Two-way coloring approaches for method dispatching in object-oriented programming systemsabstractIn object-oriented systems, heavy message sending has slowed down the execution efficiency. Most of the current solutions are based on message tables according to a class-hierarchy to develop more efficient method searching algorithms. An approach with little space overhead and constant dispatch time is proposed. The general strategy is called the two-way coloring technique. The algorithm can be applied in both typed and untyped object-oriented languages. For typed languages, the space overhead is not greater than the conventional approaches, but it can dispatch methods in the same situations as untyped languages. For untyped languages, the constraint for dispatch is not decreased and the space overhead is not much higher, but it can dispatch methods in constant time. Based on the comparison with conventional approaches, the proposed approach demonstrates its advantages on space overhead, dispatching speed, and applicability. Several case studies are presented as a comparison with existing run time dispatch mechanisms.> Shih-Kun Huang, Deng-Jyi Chen |
COMPSAC | 1 |