Geng Liang

dblp:83/58 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2023 Detecting Flash Loan Based Attacks in Ethereum
abstract
Decentralized Finance (DeFi) ecosystem has grown rapidly in the past few years. In the DeFi ecosystem, flash loan is a novel type of uncollateralized loan with nearly negligible lending costs. Malicious attackers can easily borrow a large number of crypto assets, and utilize them to disrupt the price of crypto assets to make a profit. Many flash loan based price manipulation attacks have been reported recently, and caused immense economic losses, e.g., 30 million USD in a single attack. In this paper, we conduct an empirical study on real-world flash loan based attacks in the past two years and present three attack patterns for price manipulation attacks. Then, we propose an approach, LeiShen, to automatically detect price manipulation attacks with asset transfers. We evaluate LeiShen on the first 14,500,000 blocks in Ethereum, and detect 180 attacks with a precision of 78.9%. Among our newly-found attacks, the severest attack has caused a total loss of more than 6.1 million USD.
Qing Xia 0007, Zhirong Huang, Wensheng Dou, Yafeng Zhang, Fengjun Zhang, Geng Liang, Chun Zuo
ICDCS6
2022 STPChain: a Crowdsourced Software Engineering Method for Software Traceability and Fine-grained Privacy Based on Blockchain
abstract
Crowdsourced software engineering (CSE) has be-come an increasingly popular way of software development owing to its flexibility. There exist two types of CSE participants: the requester, who posts a task including a set of requirements, and workers, including developers and testers, completing the task. Due to the centralized architecture, traditional CSE systems have raised the concern of untrustfulness since participants may collude with centralized platforms and behave maliciously to grab illegitimate interests. Some researches have utilized blockchain to solve the problem. Still, they either lack software traceability, which is significant for ensuring software quality, or cannot guar-antee users' transaction privacy owing to blockchain's openness. We propose STPChain, a CSE method for §_oftware Traceability and Privacy based on blockChain. To maintain software traceability, we articulate the process flow of CSE and implement it with smart contracts adapted to software development. The smart contracts ensure that every submission will automatically leave tamper-proof records. Credible software traceability links are realized through the records. To alleviate the transaction privacy leakage, we propose FGCA, a fine-grained CA (Certificate Authority) updating mechanism in consortium blockchain. Based on the finding that a traceability link belongs within a task, FGCA refines the digital certificates from user-level to task-level to conceal the connection between tasks and users. While guaranteeing transaction privacy, FGCA also keeps the traceability links by storing the relations between users' identifier and certificates. Security analysis demonstrates that STPChain can prevent malicious misbehaviors of participants in CSE. Case study illustrates that our method can be utilized to maintain traceability and save more than 70% of time when positioning relevant workers in CSE without transaction privacy leakage related to data openness. Performance experiments show the applicability of STPChain under CSE scenarios.
Li Yang 0015, Qing Xia 0007, Mingzhe Fang, Geng Liang, Chun Zuo
COMPSAC5
2022 AUGER: automatically generating review comments with pre-training models
abstract
Code review is one of the best practices as a powerful safeguard for software quality. In practice, senior or highly skilled reviewers inspect source code and provide constructive comments, consider- ing what authors may ignore, for example, some special cases. The collaborative validation between contributors results in code being highly qualified and less chance of bugs. However, since personal knowledge is limited and varies, the efficiency and effectiveness of code review practice are worthy of further improvement. In fact, it still takes a colossal and time-consuming effort to deliver useful review comments. This paper explores a synergy of multiple practical review comments to enhance code review and proposes AUGER (AUtomatically GEnerating Review comments): a review comments generator with pre-training models. We first collect empirical review data from 11 notable Java projects and construct a dataset of 10,882 code changes. By leveraging Text-to-Text Transfer Transformer (T5) models, the framework synthesizes valuable knowledge in the training stage and effectively outperforms baselines by 37.38% in ROUGE-L. 29% of our automatic review comments are considered useful according to prior studies. The inference generates just in 20 seconds and is also open to training further. Moreover, the performance also gets improved when thoroughly analyzed in case study.
Lingwei Li, Li Yang 0015, Huaxi Jiang, Tiejian Luo, Zihan Hua, Geng Liang, Chun Zuo
ESEC/SIGSOFT FSE7
2021 DeepRelease: Language-agnostic Release Notes Generation from Pull Requests of Open-source Software
abstract
The release note is an essential software artifact of open-source software that documents crucial information about changes, such as new features and bug fixes. With the help of release notes, both developers and users could have a general understanding of the latest version without browsing the source code. However, it is a daunting and time-consuming job for developers to produce release notes. Although prior studies have provided some automatic approaches, they generate release notes mainly by extracting information from code changes. This will result in language-specific and not being general enough to be applicable. Therefore, helping developers produce release notes effectively remains an unsolved challenge. To address the problem, we first conduct a manual study on the release notes of 900 GitHub projects, which reveals that more than 54% of projects produce their release notes with pull requests. Based on the empirical finding, we propose a deep learning based approach named DeepRelease (Deep learning based Release notes generator) to generate release notes according to pull requests. The process of release notes generation in DeepRelease includes the change entries generation and the change category (i.e., new features or bug fixes) generation, which are formulated as a text summarization task and a multi-class classification problem, respectively. Since DeepRelease fully employs text information from pull requests to summarize changes and identify the change category, it is language-agnostic and can be used for projects in any language. We build a dataset with over 46K release notes and evaluate DeepRelease on the dataset. The experimental results indicate that DeepRelease outperforms four baselines and can generate release notes similar to those manually written ones in a fraction of the time.
Huaxi Jiang, Li Yang 0015, Geng Liang, Chun Zuo
APSEC4
2021 The Impact Analysis of Multiple Miners and Propagation Delay on Selfish Mining
abstract
Bitcoin has emerged as a popular decentralized cryptocurrency and attracted much attention from the public. Bitcoin embodies the Nakamoto consensus to reach an agreement about its blockchain ledger. However, the Nakamoto consensus can suffer from selfish mining attacks. Existing studies on selfish mining usually assume that the total mining power is divided into two parts (i.e., honest and selfish), and ignore propagation delay among miners. The assumptions cannot reflect real-world scenarios, in which multiple miners generate blocks at a fixed interval and propagate them with certain delay. Therefore, it is unknown how the practical factors, i.e., multiple miners and propagation delay, can affect selfish mining.In this paper, we explore the impact of multiple miners and propagation delay on selfish mining. First, we propose a new selfish mining strategy that can handle these factors. Second, we design a simulation approach to analyze the performance of the new selfish mining strategy. From our empirical study we observe many interesting findings that can be utilized in combating selfish mining. For example, the blockchain system with a higher orphan rate is more vulnerable to the selfish mining attack.
Qing Xia 0007, Wensheng Dou, Fengjun Zhang, Jun Wei 0001, Geng Liang
COMPSAC7
2021 The Performance of Selfish Mining in GHOST
abstract
The blockchain technology is regarded as a significant trust-building technology and has attracted much attention from the public. The longest chain rule has been widely applied in blockchain systems to reach consensus on the distributed ledger. However, the longest chain rule cannot support a higher transaction throughput due to its lower security. As an alternative solution to the longest chain rule, GHOST is proposed as a safer consensus rule. Existing studies show that the longest chain rule can suffer from selfish mining attacks. However, it is unclear how selfish mining attacks perform on GHOST. In this paper, we explore the performance of selfish mining on GHOST. We first propose the original selfish mining (GHOST-SM) and stubborn mining (GHOST-StuM) for GHOST. We then evaluate these two selfish mining strategies on our blockchain simulation system. The experimental result shows that GHOST achieves better security than the longest chain rule. However, when the block generation rate increases, the security of GHOST is close to the longest chain rule. For example, the threshold for selfish mining attacks of GHOST is increased by 47.55% and 0.60% compared to the longest chain rule corresponding to the block generation interval of 1 second and 15 seconds.
Qing Xia 0007, Wensheng Dou, Fengjun Zhang, Geng Liang
TrustCom4