EDBT 2026 Demo / reviewers in the wild / expert
Fangming Gu
dblp:06/6808
· DBLP profile ↗
15ranked-venue papers
2as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unsupervised semantic-calibrated cache model for scene recognition
Linbin Wang, Sheng-Sheng Wang 0001, Fangming Gu, Congming Li |
Neurocomputing | 5 |
| 2026 | FAVDisco: Modeling and Discovering File Access VulnerabilitiesabstractFile access vulnerabilities (FAVs) are one type of security weakness arising from adversary manipulations of file access inputs, posing significant threats to system integrity. Despite their prevalence, FAVs remain underexplored due to limited understanding, complex triggering scenarios, and stealthy and diverse manifestations; these challenges render current detection approaches incomplete and inaccurate. To this end, we conducted an in-depth empirical study across 204 file-related CVEs, uncovering the root cause and trigger mechanisms of FAVs. Based on these findings, we propose an exhaustive accessing model and a specialized threat model that define the adversary and attack surface for FAVs, enabling systematic attribution and analysis of file operations. Furthermore, we propose FAVDisco , a novel framework for discovering FAVs by mutating, triggering, and analyzing file operations. It employs a File Mutator to simulate diverse execution scenarios and an FAV Checker that integrates a model-based adversary controllable checker with pattern-based detection rules to identify FAVs. Implemented on Windows, FAVDisco achieves remarkable performance with 92.1% precision and 83.3% recall on the disclosed FAV detection task, outperforming state-of-the-art methods. Moreover, it uncovers 13 zero-day FAVs in 10 widely used services, with six assigned new CVEs and earning a reward of $29,000 from Microsoft Security Response Center. Beibei Zhao, Wenjie Feng 0001, Qingli Guo, Yingli Sun, Fangming Gu, Xiaorui Gong, Hong Li 0004 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2025 | Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC SeaabstractWindows services utilizing Remote Procedure Call (RPC) and Component Object Model (COM) technology over the underlying Advanced Local Procedure Call (ALPC) transport present a significant attack surface. However, previous research often focused on known vulnerability patterns or required time-consuming reverse engineering, which hinders scalable vulnerability discovery. We developed a tool designed to automate and scale the fuzzing of ALPC communications. It employs a record-and-replay based strategy, capturing live system-wide ALPC traffic and replaying mutated payloads directly at the ALPC layer, thereby overcoming the scalability barrier posed by the manual preparation required with conventional methods. Furthermore, it integrates dedicated detection techniques to identify information leakage vulnerabilities that crash-centric fuzzers often miss. After evaluating various versions of Windows operating systems, we discovered 12 vulnerabilities confirmed by Microsoft, 10 of which have already been assigned CVE numbers. Haoyi Liu, Feng Dong 0008, Yunpeng Tian, Mu Zhang 0001, Fangming Gu, Zhiniang Peng, Haoyu Wang 0001 |
CCS | 6 |
| 2025 | AW-SARIMA: Efficient Hybrid Framework for Nonstationary Time Series Forecasting via DWT and Adaptive Thresholding
Fangming Gu, LuyangZhang, Yixing Song |
ICIC (7) | 3 |
| 2025 | Filtering with Time-Frequency Analysis: An Adaptive and Lightweight Model for Sequential Recommender Systems Based on Discrete Wavelet Transform
Mingxi Ge, Jiuyi Zhang, Wanli Zhu, Guanjin Li, Fangming Gu |
ICIC (20) | 6 |
| 2025 | Sheep's Clothing, Wolf's Data: Detecting Server-Induced Client Vulnerabilities in Windows Remote IPC
Fangming Gu, Qingli Guo, Qinghe Xie, Beibei Zhao, Kangjie Lu, Xiaorui Gong |
NDSS | 1 |
| 2024 | Negative Samples Selection Can Improve Graph Contrastive Learning in Collaborative Filtering
Yifan Shao, Fangming Gu, Ximing Li 0002 |
ICIC (13) | 3 |
| 2024 | WPML3CP: Wasserstein Partial Multi-Label Learning with Dual Label Correlation Perspectives
Ximing Li 0002, Yuanchao Dai, Bing Wang 0018, Changchun Li, Renchu Guan, Fangming Gu, Jihong Ouyang |
IJCAI | 6 |
| 2024 | Semi-supervised Multi-label Learning with Balanced Binary Angular Margin LossabstractSemi-supervised multi-label learning (SSMLL) refers to inducing classifiers using a small number of samples with multiple labels and many unlabeled samples. The prevalent solution of SSMLL involves forming pseudo-labels for unlabeled samples and inducing classifiers using both labeled and pseudo-labeled samples in a self-training manner. Unfortunately, with the commonly used binary type of loss and negative sampling, we have empirically found that learning with labeled and pseudo-labeled samples can result in the variance bias problem between the feature distributions of positive and negative samples for each label. To alleviate this problem, we aim to balance the variance bias between positive and negative samples from the perspective of the feature angle distribution for each label. Specifically, we extend the traditional binary angular margin loss to a balanced extension with feature angle distribution transformations under the Gaussian assumption, where the distributions are iteratively updated during classifier training. We also suggest an efficient prototype-based negative sampling method to maintain high-quality negative samples for each label. With this insight, we propose a novel SSMLL method, namely Semi-Supervised Multi-Label Learning with Balanced Binary Angular Margin loss (S$^2$ML$^2$-BBAM). To evaluate the effectiveness of S$^2$ML$^2$-BBAM, we compare it with existing competitors on benchmark datasets. The experimental results validate that S$^2$ML$^2$-BBAM can achieve very competitive performance. Ximing Li 0002, Silong Liang, Changchun Li, Fangming Gu |
NeurIPS | 5 |
| 2024 | Enhancing signed social recommendation via extracting auxiliary textual information
XuanMiao Li, Sheng-Sheng Wang 0001, Fangming Gu, Zhanbo Lin |
Multim. Tools Appl. | 3 |
| 2022 | COMRace: Detecting Data Race Vulnerabilities in COM Objects
Fangming Gu, Qingli Guo, Zhiniang Peng, Xiaorui Gong |
USENIX Security Symposium | 1 |
| 2022 | Static Detection of File Access Control Vulnerabilities on Windows SystemabstractSummary Traditional applications have been developed for decades. Most of the security research around them have focused on the detection of memory corruption vulnerabilities, such as buffer overflow, double fetch, and integer overflow. On the contrary, logic bugs, a kind of flaws caused by unreasonable application logic, attract much less attention. Files are the most common media for programs to persist their data in the system. As the file owners, programs are responsible for protecting their files from malicious users' tampering by leveraging access control mechanisms. However, if a program configures their access control mechanisms in wrong ways and causes evil users to bypass security checks to access files, there exists a file access control vulnerability. As a branch of logic flaws, file access control vulnerabilities are less popular with researchers. Thus, to mitigate the harm of the file access control vulnerabilities on Windows system, our team conducted first‐step research on them. We first classified file access control bugs into two types and codified some bug patterns. Then we formalized file access control vulnerabilities to propose a scalable detection method and implemented a lightweight analysis system StaticFAC. After evaluating StaticFAC in real‐world Windows software, we discovered 15 0‐day bugs. Jiadong Lu, Fangming Gu, Jiahui Chen 0002, Zhiniang Peng, Sheng Wen |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | Memory access integrity: detecting fine-grained memory access errors in binary codeabstractAs one of the most notorious programming errors, memory access errors still hurt modern software security. Particularly, they are hidden deeply in important software systems written in memory unsafe languages like C/C++. Plenty of work have been proposed to detect bugs leading to memory access errors. However, all existing works lack the ability to handle two challenges. First, they are not able to tackle fine-grained memory access errors, e.g., data overflow inside one data structure. These errors are usually overlooked for a long time since they happen inside one memory block and do not lead to program crash. Second, most existing works rely on source code or debugging information to recover memory boundary information, so they cannot be directly applied to detection of memory access errors in binary code. However, searching memory access errors in binary code is a very common scenario in software vulnerability detection and exploitation. In order to overcome these challenges, we propose Memory Access Integrity (MAI), a dynamic method to detect fine-grained memory access errors in off-the-shelf binary executables. The core idea is to recover fine-grained accessing policy between memory access behaviors and memory ranges, and then detect memory access errors based on the policy. The key insight in our work is that memory accessing patterns reveal information for recovering the boundary of memory objects and the accessing policy. Based on these recovered information, our method maintains a new memory model to simulate the life cycle of memory objects and report errors when any accessing policy is violated. We evaluate our tool on popular CTF datasets and real world softwares. Compared with the state of the art detection tool, the evaluation result demonstrates that our tool can detect fine-grained memory access errors effectively and efficiently. As the practical impact, our tool has detected three 0-day memory access errors in an audio decoder. Wenjie Li 0006, Dongpeng Xu 0001, Xiaorui Gong, Xiaobo Xiang, Fangming Gu, Qianxiang Zeng |
Cybersecur. | 7 |
| 2011 | Efficient Filter Algorithms for Reverse k-Nearest Neighbor Query
Sheng-Sheng Wang 0001, Qiannan Lv, Dayou Liu, Fangming Gu |
WAIM | 4 |
| 2007 | Channel Characterization and Link Quality Assessment of IEEE 802.15.4-Compliant Radio for Factory EnvironmentsabstractWireless sensors have started being utilized for process monitoring in factory environments, which are typically harsh for low-power wireless communication due to their complicated layout and plentiful stationary/moving obstacles. Sensor radios available so far have been engineered for consumer-grade applications, featuring low cost, low power, and minimal radio complexity. In order to utilize such radios for factory applications, their channel characteristics and link quality must be investigated for optimal design and reliability assessment. In this paper, a series of measurements were made with IEEE 802.15.4-compliant sensor radios to study both their spatial and temporal characteristics with respect to the factory surroundings found in a university machine shop. Critical communication properties were investigated in terms of received signal strength, link quality indication, and packet error rate. It is found that received signal strength shows dependency on surrounding structures, radio link qualities with respect to received signal strength and link quality indication are stable before a grey zone is reached, and average link quality indicator serves as a better packet success rate indication than average received signal strength indication. The findings in this paper provide a useful guidance to the ongoing explorations for a methodology to predict radio performance at any location within a given factory floor plan and to online assess the time-variant link qualities. Kuang-Ching Wang, Fangming Gu |
IEEE Trans. Ind. Informatics | 4 |