Kairan Sun

dblp:85/10699 · DBLP profile ↗
← Back
18ranked-venue papers
9as first author
5since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 8 · 3 first-authorComputer networks · 5 · 3 first-authorSoftware engineering, systems software and programming languages · 5 · 3 first-author · 5 since 2021
YearPublicationVenuePosition
2025 Learning from the Past: Real-World Exploit Migration for Smart Contract PoC Generation
abstract
Smart contract vulnerabilities continue to cause significant financial losses, despite the implementation of security measures such as manual audits and bug bounty platforms. A critical component often required by these security measures is the proof-of-concept (PoC) exploit, which validates vulnerability exploitability, assesses impact severity, and guides developers in fixes. Existing tools have explored automated PoC generation with techniques like symbolic execution, fuzzing, and program synthesis. However, these approaches frequently fail to generate PoCs for vulnerabilities exploited in real-world incidents, primarily due to their limitations in handling complex transaction dependencies, navigating vast on-chain state spaces, or requiring extensive manual specifications. Our migration-based approach extracts critical information from documented security incidents and applies it to generate PoCs for similar vulnerable code. This approach leverages proven exploit patterns rather than generating PoCs from scratch. This approach is motivated by two key observations: the prevalence of code reuse in smart contracts (up to 90% at the function level) and the increasing availability of documented PoCs for real-world incidents. Our approach operates in three phases: (1) abstracting essential components (i.e., environment properties, attack logic, and verification checks) from existing PoCs into templates, (2) given a new target contract, selecting suitable templates with adapted values through clone-detection and property-feasibility analysis, and (3) generating and validating PoCs in simulated environments. Our evaluation demonstrates effectiveness and efficiency across multiple scales. Our approach successfully generates valid PoCs for 62 out of 67 manually validated cases without false positives and completes analysis in 3.8 hours compared to 133.2 and 210.5 hours required by existing tools. Large-scale evaluation on 979,512 contracts identifies 256 vulnerable contracts across blockchain networks with 64 cross-chain cases, demonstrating real-world applicability.
Kairan Sun, Zhengzi Xu, Kaixuan Li 0002, Lyuye Zhang, Yebo Feng, Daoyuan Wu, Yang Liu 0003
ASE1
2025 Faultseeker: LLM-Empowered Framework for Blockchain Transaction Fault Localization
abstract
Web3 applications, particularly decentralized finance (DeFi) protocols, have grown rapidly with over $100 billion locked in smart contracts, attracting sophisticated attacks causing billions in losses. When attack occur, security analysts need to perform fault localization to identify vulnerable functions and understand attack vectors. This critical process currently requires an average of 16.7 analyst hours per incident due to complex blockchain execution models, rapidly evolving protocol interactions, and multi-contract attack patterns that exceed existing analytical capabilities. Despite its critical importance, blockchain fault localization has received limited attention due to fundamental challenges requiring semantic understanding of economic models and protocol-specific logic. Existing blockchain-specific tools target only single vulnerability types, while the only comprehensive solution, DAppFL, relies on machine learning model that may miss sophisticated exploits and lacks interpretability in results. Recent advances in large language models (LLMs) demonstrate remarkable code comprehension capabilities, but existing applications focus on proactive vulnerability detection with minimal exploration of post-incident fault localization.We present FaultSeeker, an LLM-empowered framework for blockchain transaction fault localization. Our two-stage architecture combines transaction-level forensics for strategic scoping with coordinated specialist agents for sustained reasoning. This design provides long-term memory management via orchestrator agents and specialized attention allocation through coordinated workers, enabling comprehensive analysis across complex multi-contract transactions without context loss. We evaluate Fault-Seeker on a compiled dataset of 115 real-world malicious transactions with expert-validated annotations spanning diverse attack patterns and complexity levels. Results demonstrate that FaultSeeker significantly outperforms existing approaches, including DAppFL and leading native LLMs (GPT-4o, Claude 3.7 Sonnet, DeepSeek R1), while maintaining practical efficiency (4.4- 8.6 minutes) and cost-effectiveness ($1.55-$4.53 per transaction).
Kairan Sun, Zhengzi Xu, Kaixuan Li 0002, Lyuye Zhang, Yuqiang Sun 0001, Liwei Tan, Yang Liu 0003
ASE1
2025 ACFix: Guiding LLMs With Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
abstract
Smart contracts are susceptible to various security issues, among which access control (AC) vulnerabilities are particularly critical. While existing research has proposed multiple detection tools, automatic and appropriate repair of AC vulnerabilities in smart contracts remains a challenge. Unlike commonly supported vulnerability types by existing repair tools, such as reentrancy, which are usually fixed by template-based approaches, the main obstacle of repairing AC vulnerabilities lies in identifying the appropriate roles or permissions amid a long list of non-AC-related source code to generate proper patch code, a task that demands human-level intelligence.In this paper, we employ the state-of-the-art GPT-4 model and enhance it with a novel approach called ACFIX. The key insight is that we can mine common AC practices for major categories of code functionality and use them to guide LLMs in fixing code with similar functionality. To this end, ACFIX involves offline and online phases. In the offline phase, ACFIX mines a taxonomy of common Role-based Access Control practices from 344,251 on-chain contracts, categorizing 49 role-permission pairs from the top 1,000 unique samples. In the online phase, ACFIX tracks AC-related elements across the contract and uses this context information along with a Chain-of-Thought pipeline to guide LLMs in identifying the most appropriate role-permission pair for the subject contract and subsequently generating a suitable patch. To evaluate ACFIX, we built the first benchmark dataset of 118 real-world AC vulnerabilities, and our evaluation revealed that ACFIX successfully repaired 94.92% of them, a major improvement compared to the baseline GPT-4 at only 52.54%. We also conducted a human study to understand the value of ACFIX’s repairs and their differences from human repairs.
Lyuye Zhang, Kaixuan Li 0002, Kairan Sun, Daoyuan Wu, Ye Liu 0012, Haoye Tian, Yang Liu 0003
IEEE Trans. Software Eng.3
2023 OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting Functions
abstract
Third-party libraries (TPLs) are frequently used in software to boost efficiency by avoiding repeated developments. However, the massive using TPLs also brings security threats since TPLs may introduce bugs and vulnerabilities. Therefore, software composition analysis (SCA) tools have been proposed to detect and manage TPL usage. Unfortunately, due to the presence of common and trivial functions in the bloated feature dataset, existing tools fail to precisely and rapidly identify TPLs in C/C++ real-world projects. To this end, we propose OSSFP, a novel SCA framework for effective and efficient TPL detection in large-scale real-world projects via generating unique fingerprints for open source software. By removing common and trivial functions and keeping only the core functions to build the fingerprint index for each TPL project, OSSFP significantly reduces the database size and accelerates the detection process. It also improves TPL detection accuracy since noises are excluded from the fingerprints. We applied OSSFP on a large data set containing 23,427 C/C++ repositories, which included 585,683 versions and 90 billion lines of code. The result showed that it could achieve 90.84% of recall and 90.34% of precision, which outperformed the state-of-the-art tool by 35.31% and 3.71%, respectively. OSSFP took only 0.12 seconds on average to identify all TPLs per project, which was 22 times faster than the other tool. OSSFP has proven to be highly scalable on large-scale datasets.
Zhengzi Xu, Lyuye Zhang, Yueming Wu 0001, Chengyue Liu, Kairan Sun, Lida Zhao, Yang Liu 0003
ICSE7
2023 Demystifying the Composition and Code Reuse in Solidity Smart Contracts
abstract
As the development of Solidity smart contracts has increased in popularity, the reliance on external sources such as third-party packages increases to reduce development costs. However, despite the use of external sources bringing flexibility and efficiency to the development, they could also complicate the process of assuring the security of downstream applications due to the lack of package managers for standardized ways and sources. While previous studies have only focused on code clones without considering how the external components are introduced, the compositions of a smart contract and their characteristics still remain puzzling.
Kairan Sun, Zhengzi Xu, Kaixuan Li 0002, Yang Liu 0003
ESEC/SIGSOFT FSE1
2018 MPC-Based Delay-Aware Fountain Codes for Real-Time Video Communication
abstract
With the prevalence of smart mobile devices and surveillance cameras, the traffic load within the Internet of Things (IoT) has shifted away from nonmultimedia data to multimedia traffics, particularly, the video content. However, the explosive demand for real-time video communication over wireless networks in IoT is constantly challenging both video coding and communication research communities. The state-of-the-art answer to this challenge is sliding-window-based delay-aware fountain (DAF) codes, which combine the channel-adaptive feature in rateless coding and the delay-aware feature in video coding. However, the high computational cost and large delay make it impractical for real-time streaming. To address this issue, we integrate the model predictive control (MPC) technique into DAF codes, so the complexity is lowered to an affordable level so that real-time video encoding is supported. Two schemes are developed in this paper: 1) DAF-S, the smallhorizon DAF codes and 2) DAF-O, the MPC-based DAF using video bit rate prediction. The advantages of both designs are validated through theoretical analysis and comprehensive experiments. The results of simulation experiments show that the decoding ratio of DAF-S is close to the global optimum in DAF codes, and higher than the other existing schemes; DAF-O outperforms the state-of-the-art real-time video communication algorithms.
Kairan Sun, Huazi Zhang, Dapeng Oliver Wu, Hongcheng Zhuang
IEEE Internet Things J.1
2017 Unequal error protection for video streaming using delay-aware fountain codes
abstract
Recently, the forward error correction (FEC) codes are gaining popularity in video transmission community because of its capability of recovering lost packets in lossy wireless networks. The state-of-the-art scheme for FEC video transmission are the delay-aware fountain codes (DAF), which combine the ratelessness of fountain codes with the property of video coding. However, DAF assumes that all the data in the video has the same importance, thus every packet should have the equal chance to be decoded. In this work, in order to further adapt DAF to real-world video coding, we propose a method to integrate the unequal error protection (UEP) into DAF to provide additional protection for important bits. Different from the existing schemes, the proposed scheme does not impose any restriction on the importance profile, and it does not rely on any specific video coding standard. Most importantly, the proposed scheme is designed within the framework of DAF, so it neither requires any change on the DAF decoder or the protocol, nor any additional coordination between encoder and decoder. Simulation experiments show the proposed system achieves higher decoding ratios and PSNR compared to equal error protection (EEP) under the same network conditions.
Kairan Sun, Dapeng Oliver Wu
ICC1
2016 MPC-based Delay-Aware Fountain codes for live video streaming
abstract
The explosive demand for live video streaming over wireless networks is constantly calling for innovations in both video coding and wireless communities. The state-of-the-art answer to this challenge are sliding-window-based Delay-Aware Fountain (DAF) codes, which combine the channel-adaptive feature in rateless coding and the delay-aware feature in video coding. However, a high computational cost is incurred during the per-window optimization of sampling pattern, making DAF codes impractical for live streaming. To solve this issue, we propose a novel online algorithm for DAF codes. By integrating the Model Predictive Control (MPC) technique into DAF codes, a finite length of horizon is imposed on the optimization algorithm. As a result, the complexity is lowered to an affordable level such that real-time video encoding is supported. Two schemes are developed in this paper: (i) DAF-M, the MPC-based DAF codes, and (ii) DAF-O, the online variant of DAF-M based on video bit rate prediction. The advantages of both designs are validated through comprehensive experiments. The results of simulation experiments show that the decoding ratio of DAF-M is close to the global optimum in DAF codes, and higher than the other existing schemes; DAF-O outperforms the state-of-the-art live streaming algorithms.
Kairan Sun, Dapeng Oliver Wu
ICC1
2016 FUN Coding: Design and Analysis
abstract
Joint FoUntain coding and Network coding (FUN) is proposed to boost information spreading over multi-hop lossy networks. The novelty of our FUN approach lies in combining the best features of fountain coding, intra-session network coding, and cross-next-hop network coding. This paper provides an in-depth study of FUN codes. First, we theoretically analyze the throughput of FUN codes. Second, we identify several practical issues that may undermine the actual performance, such as buffer overflow, and quantify the resulting throughput degradation. Finally, we propose a systematic design to overcome these issues. Simulation results in TDMA multi-hop networks show that our methods yield near-optimal throughput and are significantly better than fountain codes and existing network coding schemes.
Huazi Zhang, Kairan Sun, Qiuyuan Huang, Yonggang Wen 0001, Dapeng Oliver Wu
IEEE/ACM Trans. Netw.2
2015 Video rate control strategies for cloud gaming
Kairan Sun, Dapeng Oliver Wu
J. Vis. Commun. Image Represent.1
2014 Efficient DCT-based image retargeting in compressed domain
abstract
With the increasing requirement of efficient image retargeting, many algorithms have been proposed for adapting images contents to various display settings. However, most of these algorithms work in spatial domain of raw images. Since images are mostly stored in DCT-based compressed format such as JPEG, it will be very attractive to realize the image retargeting in compressed domain. In this paper, we propose a new low complexity DCT-based image retargeting method, which is completely performed in compressed domain. This proposed algorithm is based on the construction of block level importance map and calculation of block level forward energy. Experimental results prove that our proposed algorithm is able to significantly reduce image decoding complexity as well as image retargeting complexity, while providing the satisfying image retargeting quality compared with other methods.
Ke Li 0010, Bo Yan 0001, Liu Liu 0006, Kairan Sun
ICME4
2014 Just FUN: a joint fountain coding and network coding approach to loss-tolerant information spreading
abstract
To address the problem of information spreading over lossy communication channels, this paper proposes a joint FoUntain coding and Network coding (FUN) approach. Different from the Transmission Control Protocol (TCP), our FUN approach is a mechanism of Forward Error Correction (FEC), which does not use retransmission for recovery of lost packets. The novelty of our FUN approach lies in combining the best features of fountain coding, intra-session network coding, and cross-next-hop network coding. As such, our FUN approach is capable of achieving unprecedented high throughput over lossy channels. Experimental results demonstrate that our FUN approach achieves higher throughput than the existing schemes for multihop wireless networks.
Qiuyuan Huang, Kairan Sun, Dapeng Oliver Wu
MobiHoc2
2013 Efficient seam carving for object removal
abstract
This paper introduces a new object removal approach for images based on discontinuous seam carving. Existing seam carving based object removal methods generally are time-consuming and oftentimes cause image distortion or cutting off many more seams than is necessary. In order to solve these limitations, our proposed method only considers the energy of all the pixels outside the target region. Firstly, based on the discontinuous seam carving, we calculate the energy map of both directions, up-down and bottom-up. Then we carve the seam respectively from the upper bound of the target region to up, from the lower bound of the target region to down and the middle part within the region. Experimental results prove that our proposed method outperform others in terms of efficiency and image quality significantly.
Bo Yan 0001, Yiqi Gao, Kairan Sun
ICIP3
2013 Matching-Area-Based Seam Carving for Video Retargeting
abstract
This paper presents a video retargeting method considering both spatial and temporal coherence for resizing videos. Our algorithm is based on a novel matching-area-based temporal energy adjustment that allows per-frame seam carving to remove the optimal pixels to achieve spatially and temporally continuous resized videos. The temporal energy adjustment allows the seam to track the object it previously carved, and avoid carving the seam on different objects in two consecutive frames to achieve both spatial and temporal coherence. Our method outperforms other state-of-the-art retargeting systems, as demonstrated in the results and widely supported by the conducted user study.
Bo Yan 0001, Kairan Sun, Liu Liu 0006
IEEE Trans. Circuits Syst. Video Technol.2
2012 Lowcomplexity content-aware image retargeting
abstract
Image retargeting plays a more and more significant role recently, thanks to the escalating diversity of display devices. In this paper, we present a novel low complexity content-aware image retargeting method, which can provide both high efficiency and quality. Specifically, the importance map is used as the basis of our method. The important regions tend to preserve its original size. Our method performs inter-row coherence filtering on importance maps in order to maintain the spatial coherence, and then directly utilizes the filtered importance maps to generate the scaling map. Experimental results show the proposed algorithm improves the efficiency significantly compared with other existing methods. At the same time, the resized image quality of our algorithm is as good as, if not better than, that of the other methods. As a result, our method possesses huge practical significance.
Kairan Sun, Bo Yan 0001, Yiqi Gao
ICIP1
2012 Joint Complexity Estimation of I-Frame and P-Frame for H.264/AVC Rate Control
abstract
Rate control plays a significant role for high quality video coding. This paper presents a rate control method for H.264/AVC, using a new bit allocation scheme for both I-frame and P-frame. This scheme is based on our proposed frame complexity measurement and estimation model. The measurement model considers not only the absolute complexity of I-frame and P-frame, respectively, but also the complexity relationship between I-frame and P-frame. Our proposed bit allocation scheme is able to allocate bit rate more efficiently for both I-frame and P-frame in order to achieve a relatively steady visual quality. Experimental results show that our proposed method is capable of providing more stable video quality than other existing methods.
Bo Yan 0001, Kairan Sun
IEEE Trans. Circuits Syst. Video Technol.2
2011 Efficient P-frame complexity estimation for frame layer rate control of H.264/AVC
abstract
Rate control plays a significant role for high quality video coding. This paper presents a rate control method for H.264/AVC using a new bit allocation scheme for P-frame. This scheme is based on our proposed P-frame complexity measurement and estimation model. The measurement model considers not only the absolute complexity of the picture via average gradient, but also the relative histogram difference between two frames. Our proposed bit allocation scheme is able to allocate bitrate more efficiently for P-frame, which means allocating more bits to high-complexity frames and less bits to low-complexity ones. Experimental results show that our proposed method is able to achieve better quality than the original JVT-G012 and other existing methods.
Kairan Sun, Bo Yan 0001
ICIP1
2011 Selective pixel interpolation for spatial error concealment
abstract
This paper proposes an effective algorithm for spatial error concealment with accurate edge detection and partitioning interpolation. Firstly, a new method is used for detecting possible edge pixels and their matching pixels around the lost block. Then, the true edge lines can be determined, with which the lost block is partitioned. Finally, based on the partition result, each lost pixel can be interpolated with correct reference pixels, which are in the same region with the lost pixel. Experimental results show that the proposed spatial error concealment method is obviously superior to the previous methods for different sequences by up to 4.04 dB.
Yi Ge, Bo Yan 0001, Kairan Sun, Hamid Gharavi
MMSP3