VLDB 2026 Research / reviewers in the wild / expert
Meng Wang 0071
dblp:93/6765-71
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0004-7552-392XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Anota: Identifying Business Logic Vulnerabilities via Annotation-Based Sanitization
Meng Wang 0071, Philipp Görz, Joschua Schilling, Keno Hassler, Thorsten Holz, Ali Abbasi 0002 |
NDSS | 1 |
| 2026 | SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime Environment
Meng Wang 0071, Qinying Wang, Ali Abbasi 0002, Thorsten Holz |
SP | 3 |
| 2025 | TWINFUZZ: Differential Testing of Video Hardware Acceleration Stacks
Matteo Leonelli, Addison Crump, Meng Wang 0071, Florian Bauckholt, Keno Hassler, Ali Abbasi 0002, Thorsten Holz |
NDSS | 3 |
| 2025 | A Comprehensive Memory Safety Analysis of Bootloaders
Meng Wang 0071, Qinying Wang, Nils Langius, Ali Abbasi 0002, Thorsten Holz |
NDSS | 2 |
| 2021 | Spinner: Automated Dynamic Command Subsystem PerturbationabstractInjection attacks have been a major threat to web applications. Despite the significant effort in thwarting injection attacks, protection against injection attacks remains challenging due to the sophisticated attacks that exploit the existing protection techniques' design and implementation flaws. In this paper, we develop Spinner, a system that provides general protection against input injection attacks, including OS/shell command, SQL, and XXE injection. Instead of focusing on detecting malicious inputs, Spinner constantly randomizes underlying subsystems so that injected inputs (e.g., commands or SQL queries) that are not properly randomized will not be executed, hence prevented. We revisit the design and implementation choices of previous randomization-based techniques and develop a more robust and practical protection against various sophisticated input injection attacks. To handle complex real-world applications, we develop a bidirectional analysis that combines forward and backward static analysis techniques to identify in-tended commands or SQL queries to ensure the correct execution of the randomized target program. We implement Spinner for the shell command processor and two different database engines(MySQL and SQLite) and in diverse programming languages including C/C++, PHP, JavaScript and Lua. Our evaluation results on 42real-world applications including 27 vulnerable ones show that it effectively prevents a variety of input injection attacks with low runtime overhead (around 5%). Meng Wang 0071, Chijung Jung, Ali Ahad, Yonghwi Kwon 0001 |
CCS | 1 |