VLDB 2026 Research / reviewers in the wild / expert
Chi Zhang 0046
dblp:91/195-46
· DBLP profile ↗
14ranked-venue papers
4as first author
13since 2021 · last 2025
0000-0002-3162-6271ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 3 first-author · 9 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DialTest-EA: An Enhanced Fuzzing Approach With Energy Adjustment for Dialogue Systems via Metamorphic TestingabstractABSTRACT Deep neural networks (DNNs) possess potent feature learning capability, enabling them to comprehend natural language, which strongly support developing dialogue systems. However, dialogue systems usually perform incorrect behaviours in some corner cases, which may cause misunderstanding or economic loss. To test and debug dialogue systems, a popular fuzzing framework by metamorphic testing with Gini impurity guidance is proposed, namely, DialTest. However, DialTest treats all seeds (the initial test inputs to generate the mutated test inputs) equally during the fuzzing process and does not differentiate seeds, resulting in a certain limitation to its incorrect behaviour detection capability. In this paper, we propose to enhance the DialTest by applying a lightweight energy adjustment strategy called DialTest with Energy Adjustment (DialTest‐EA). DialTest‐EA employs the ant colony optimization algorithm (ACO) to adjust the mutation energy of each seed adaptively, ensuring that potential seeds have more opportunities to generate subsequent test inputs. To evaluate the effectiveness of the proposed DialTest‐EA, we conduct a series of comparisons with the original DialTest and random mutation strategy. The experimental results show that the proposed DialTest‐EA outperforms the compared methods both in the intent detection and slot filling tasks. Compared with the original DialTest, the intent detection accuracy of generated test cases by the proposed method is reduced by more than 14%, and the slot filling accuracy is reduced by more than 8%. Haibo Chen 0005, Jinfu Chen 0001, Saihua Cai, Rubing Huang, Shengran Wang, Chi Zhang 0046 |
Softw. Test. Verification Reliab. | 8 |
| 2024 | TR-Fuzz: A syntax valid tool for fuzzing C compilers
Chi Zhang 0046, Jinfu Chen 0001, Saihua Cai, Rexford Nii Ayitey Sosu, Haibo Chen 0005 |
Sci. Comput. Program. | 1 |
| 2024 | A novel defect prediction method based on semantic feature enhancementabstractSummary Although cross‐project defect prediction (CPDP) techniques that use traditional manual features to build defect prediction model have been well‐developed, they usually ignore the semantic and structural information inside the program and fail to capture the hidden features that are critical for program category prediction, resulting in poor defect prediction results. Researchers have proposed using deep learning to automatically extract the semantic features of programs and fuse them with traditional features as training data. However, in practice, it is important to explore the effective representation of the semantic features in the programs and how the fusion of a reasonable ratio between the two types of features can maximize the effectiveness of the model. In this paper, we propose a semantic feature enhancement‐based defect prediction framework (SFE‐DP), which augments the semantic feature set extracted from the program code with data. We also introduce a layer of self‐attentive mechanism and a matching layer to filter low‐efficiency and non‐critical semantic features in the model structure. Finally, we combine the idea of hybrid loss function to iteratively optimize the model parameters. Extensive experiments validate that SFE‐DP can outperform the baseline approaches on 90 pairs of CPDP tasks formed by 10 open‐source projects. Chi Zhang 0046, Jinfu Chen 0001, Saihua Cai, Rexford Nii Ayitey Sosu |
J. Softw. Evol. Process. | 1 |
| 2023 | Minimal Rare Pattern-Based Outlier Detection Approach For Uncertain Data Streams Under Monotonic ConstraintsabstractAbstract Existing association-based outlier detection approaches were proposed to seek for potential outliers from huge full set of uncertain data streams ($UDS$), but could not effectively process the small scale of $UDS$ that satisfies preset constraints; thus, they were time consuming. To solve this problem, this paper proposes a novel minimal rare pattern-based outlier detection approach, namely Constrained Minimal Rare Pattern-based Outlier Detection (CMRP-OD), to discover outliers from small sets of $UDS$ that satisfy the user-preset succinct or convertible monotonic constraints. First, two concepts of ‘maximal probability’ and ‘support cap’ are proposed to compress the scale of extensible patterns, and then the matrix is designed to store the information of each valid pattern to reduce the scanning times of $UDS$, thus decreasing the time consumption. Second, more factors that can influence the determination of outlier are considered in the design of deviation indices, thus increasing the detection accuracy. Extensive experiments show that compared with the state-of-the-art approaches, CMRP-OD approach has at least 10% improvement on detection accuracy, and its time cost is also almost reduced half. Saihua Cai, Jinfu Chen 0001, Haibo Chen 0005, Chi Zhang 0046, Qian Li 0042, Dengzhou Shi |
Comput. J. | 4 |
| 2023 | A memory-related vulnerability detection approach based on vulnerability model with Petri Net
Jinfu Chen 0001, Chi Zhang 0046, Saihua Cai |
J. Log. Algebraic Methods Program. | 2 |
| 2023 | A novel combinatorial testing approach with fuzzing strategyabstractSummary Combinatorial testing (CT) is considered as a practical approach to detect software faults, which has arisen from the interaction between factors affecting the software behavior. However, most of the traditional algorithms on CT generation did not take advantage of the execution results of the earlier test cases, as well as neglect the impact of the nonequilibrium input parameter model (NE‐IPM) effect on redundant test cases, which bring a deleterious effect to the detection accuracy of the software faults. To solve these problems, we propose a novel CT approach with fuzzing strategy called CTAF. Based on the idea that fuzzing is performed during execution, CTAF exploits the execution results of earlier tests to provide guidance for subsequent test generation thereby reducing the redundant test cases without compromising the diversity of test cases. And then, we designed three experiments on real subjects of six open source software systems, and the experimental results show that the proposed CTAF approach can effectively improve the NE‐IPM effect and enhance the detection accuracy of software faults. Jinfu Chen 0001, Saihua Cai, Haibo Chen 0005, Chi Zhang 0046 |
J. Softw. Evol. Process. | 5 |
| 2022 | A Novel Coverage-guided Greybox Fuzzing based on Power Schedule Optimization with Time ComplexityabstractCoverage-guided Greybox fuzzing is regarded as a practical approach to detect software vulnerabilities, which targets to expand code coverage as much as possible. A common implementation is to assign more energy to such seeds which find new edges with less execution time. However, solely considering new edges may be less effective because some hard-to-find branches often exist in the complex code of program. Code complexity is one of the key indicators to measure the code security. Compared to the code with simple structure, the program with higher code complexity is more likely to find more branches and cause security problems. In this paper, we propose a novel fuzzing method which further uses code complexity to optimize power schedule process in AFL (American Fuzzy Lop) and AFLFAST (American Fuzzy Lop Fast). The goal of our method is to generate inputs which are more biased toward the code with higher complexity of the program under test. In addition, we conduct a preliminary empirical study under three widely used real-world programs, and the experimental results show that the proposed approach can trigger more crashes as well as improve the coverage discovery. Jinfu Chen 0001, Shengran Wang, Saihua Cai, Chi Zhang 0046, Haibo Chen 0005 |
ASE | 4 |
| 2022 | Malware recognition approach based on self-similarity and an improved clustering algorithmabstractAbstract The recognition of malware in network traffic is an important research problem. However, existing solutions addressing this problem rely heavily on the source code and misrecognise vulnerabilities (i.e. incur a high false positive rate (FPR)) in some cases. In this paper, we initially use the K‐means clustering algorithm to extract malware patterns under user to root attacks in network traffic. Since the traditional K‐means algorithm needs to determine the number of clusters in advance and it is easily affected by the initial cluster centres, we propose an improved K‐means clustering algorithm (NIKClustering algorithm) for cluster analysis. Furthermore, we propose the use of self‐similarity and our improved clustering algorithm to recognise buffer overflow vulnerabilities for malware in network traffic. This motivates us to design and implement a recognition approach for buffer overflow vulnerabilities based on self‐similarity and our improved clustering algorithm, called Reliable Self‐Similarity with Improved K‐means Clustering (RSS‐IKClustering). Extensive experiments conducted on two different datasets demonstrate that the RSS‐IKClustering can achieve much fewer false positives than other notable approaches while increasing accuracy. We further apply our RSS‐IKClustering approach on a public dataset (Center for Applied Internet Data Analysis), which also exhibited a high accuracy and low FPR of 96% and 1.5%, respectively. Jinfu Chen 0001, Chi Zhang 0046, Saihua Cai, Zufa Zhang, Longxia Huang |
IET Softw. | 2 |
| 2021 | Fuzzing Methods Recommendation Based on Feature VectorsabstractFuzzing is a technique that aims to detect vulnerabilities or exceptions through unexpected input and has found tremendous recent interest in both academia and industry. Although these fuzzing methods have great advantages in the field of vulnerability detection, they also have their own disadvantages in the face of different target programs. It is obviously impractical for a fuzzing test method to adapt to all the target programs. Therefore, we study how to select the appropriate fuzzing methods for different target programs. Specifically, we first analyze the program, and then extract the feature vectors of the target program to get the information of the program, such as syntax, context and so on. Next, we build a matching model to match the similarity of target program and the fuzzing algorithm to select the fuzzing algorithm with higher matching degree. Through our matching model, we get a more suitable fuzzing algorithm to improve the detection efficiency, precision, recall, F-measure, and other statistical measures. Chi Zhang 0046, Jinfu Chen 0001 |
ASE | 1 |
| 2021 | An Efficient Network Intrusion Detection Model Based on Temporal Convolutional NetworksabstractNetwork intrusion detection plays an important role in the network security, but the increasingly complex network environment brings a serious challenge to intrusion detection. Although the existing efficient Convolutional Neural Network (CNN)-based network traffic intrusion detection models do not require manual design of the traffic features, but they do not make full use of the structured information of network traffic. In this paper, we propose a novel network intrusion detection model based on Temporal Convolutional Networks (TCN), it extracts the key features in the dataset through exploiting the characteristics of byte sequence in the network traffic packets. Compared with traditional recurrent neural networks (RNN), TCN shows a better performance in sequence modeling tasks and it can process the sequences in parallel for faster training. To solve the problem of poor detection accuracy caused by the “death” of some neurons on ReLU during the training stage, we use the ELU activation function in the TCN instead of ReLU. Finally, we compare our proposed TCN-based intrusion detection model with the state-of-the-art methods on the CTU public dataset, and the experimental results show that the use of TCN can obtain higher performance within less time consumption, in terms of higher average accuracy, higher average recall and higher average F1-measure. Jinfu Chen 0001, Shang Yin, Saihua Cai, Chi Zhang 0046, Yemin Yin |
QRS | 4 |
| 2021 | An efficient anomaly detection method for uncertain data based on minimal rare patterns with the consideration of anti-monotonic constraints
Saihua Cai, Jinfu Chen 0001, Haibo Chen 0005, Chi Zhang 0046, Qian Li 0042, Rexford Nii Ayitey Sosu, Shang Yin |
Inf. Sci. | 4 |
| 2021 | An efficient outlier detection method for data streams based on closed frequent patterns by considering anti-monotonic constraints
Saihua Cai, Rubing Huang, Jinfu Chen 0001, Chi Zhang 0046, Bo Liu 0048, Shang Yin, Ye Geng |
Inf. Sci. | 4 |
| 2021 | A Detection Approach for Vulnerability Exploiter Based on the Features of the ExploiterabstractWith the wide application of software system, software vulnerability has become a major risk in computer security. The on-time detection and proper repair for possible software vulnerabilities are of great importance in maintaining system security and decreasing system crashes. The Control Flow Integrity (CFI) can be used to detect the exploit by some researchers. In this paper, we propose an improved Control Flow Graph with Jump (JCFG) based on CFI and develop a novel Vulnerability Exploit Detection Method based on JCFG (JCFG-VEDM). The detection method of the exploit program is realized based on the analysis results of the exploit program. Then the JCFG is addressed through combining the features of the exploit program and the jump instruction. Finally, we implement JCFG-VEDM and conduct the experiments to verify the effectiveness of the proposed method. The experimental results show that the proposed detection method (JCFG-VEDM) is feasible and effective. Jinchang Hu, Jinfu Chen 0001, Sher Ali, Bo Liu 0048, Chi Zhang 0046 |
Secur. Commun. Networks | 6 |
| 2020 | iTES: Integrated Testing and Evaluation System for Software Vulnerability Detection MethodsabstractTo find software vulnerabilities using software vulnerability detection technology is an important way to ensure the system security. Existing software vulnerability detection methods have some limitations as they can only play a certain role in some specific situations. To accurately analyze and evaluate the existing vulnerability detection methods, an integrated testing and evaluation system (iTES) is designed and implemented in this paper. The main functions of the iTES are:(1) Vulnerability cases with source codes covering common vulnerability types are collected automatically to form a vulnerability cases library; (2) Fourteen methods including static and dynamic vulnerability detection are evaluated in iTES, involving the Windows and Linux platforms; (3) Furthermore, a set of evaluation metrics is designed, including accuracy, false positive rate, utilization efficiency, time cost and resource cost. The final evaluation and test results of iTES have a good guiding significance for the selection of appropriate software vulnerability detection methods or tools according to the actual situation in practice. Chi Zhang 0046, Jinfu Chen 0001, Saihua Cai, Bo Liu 0048, Yiming Wu 0012, Ye Geng |
TrustCom | 1 |