EDBT 2026 Demo / reviewers in the wild / expert
Chiheng Wang
dblp:144/1478
· DBLP profile ↗
7ranked-venue papers
3as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | IoTtracer: greybox fuzzing for Linux-based IoT devices with low-cost coverage tracingabstractAbstract Fuzzing, especially coverage-guided greybox (CG) fuzzing, has been demonstrated to be effective in discovering software security vulnerabilities. Code coverage achieved through instrumentation plays a vital role in this. However, closed-source software within IoT devices cannot easily perform binary instrumentation to trace coverage like traditional computers efficiently. To address this problem, we propose IoTtracer, an IoT CG fuzzing framework using low-cost coverage tracing. Unlike the state-of-the-art IoT CG fuzzers (e.g. AFLIoT and GDBFuzz), IoTtracer does not rely on complex binary-level rewrite or limited hardware breakpoints for instrumentation, but directly instruments the binary in a Linux-based IoT device through the software interrupts. To avoid frequently trapping into interrupts during fuzzing and reduce the overhead of collecting coverage, we also design a discrete instrumentation strategy and distributed adaptive coverage tracing for IoTtracer. We evaluated IoTtracer on multiple benchmarks containing real-world IoT devices. IoTtracer enables efficient and accurate tracing of full coverage in IoT devices by inserting probes into only an average of 37.8% of the binary’s basic blocks. In addition, IoTtracer’s throughput is 1.28–2.77× higher than AFLIoT. These results show that IoTtracer can more efficiently obtain the target’s coverage in IoT devices and effectively guide fuzzing to detect their potential vulnerabilities. Chiheng Wang, Jianshan Peng, Han Qiu 0004, Junhu Zhu |
Comput. J. | 1 |
| 2025 | AugPersist: Automatically augmenting the persistence of coverage-based greybox fuzzing for persistent software
Chiheng Wang, Jianshan Peng, Junhu Zhu |
Comput. Secur. | 1 |
| 2024 | KVFL: Key-Value-Based Persistent Fuzzing for IoT Web ServersabstractAbstract As the number of Internet of Thing (IoT) devices increases, attacks against their vulnerabilities have become a serious threat. The web servers (WSs) in IoT devices provide management services for end-users, which are currently the major attack surface. Several fuzzing solutions for identifying vulnerabilities in IoT devices have been proposed, but there is currently no grey-box fuzzer specifically designed for the unique features of WSs in IoT to effectively detect memory corruption vulnerabilities. We design and implement KVFL, an efficient grey-box fuzzer, to address the issues of low throughput and slow exploration of deep code when fuzzing for IoT WSs. Firstly, KVFL employs a delicate hooking technology that heuristically hijacks and emulates hardware-dependent functions, ensuring WSs can be accurately and efficiently emulated in user-mode. On this basis, KVFL fully utilizes the loop parsing HTTP requests feature of WSs through a redesigned fork-server, to minimize nonessential rebooting losses of the target, thereby significantly improving fuzzing throughput. Secondly, KVFL leverages code coverage feedback to automatically infer a set of valid Keys and derive a Key-Value mutation. This enables the generation of high-quality test cases that can facilitate deeper code exploration of WSs. The evaluation results show that compared to the state-of-the-art IoT grey-box fuzzer FIRM-AFL, KVFL improves the throughput by over 2× and explores 4.5× more edges. Additionally, it identifies all 1-day vulnerabilities with over 7× faster speed than the baseline and detects three previously unknown 0-day vulnerabilities. These all indicate that KVFL is effective and efficient at fuzzing IoT WSs. Chiheng Wang, Shibin Zhao, Jianshan Peng, Junhu Zhu |
Comput. J. | 1 |
| 2021 | Semantics-Aware Privacy Risk Assessment Using Self-Learning Weight Assignment for Mobile AppsabstractMost of the existing mobile application (app) vetting mechanisms only estimate risks at a coarse-grained level by analyzing app syntax but not semantics. We propose a semantics-aware privacy risk assessment framework (SPRisk), which considers the sensitivity discrepancy of privacy-related factors at semantic level. Our framework can provide qualitative (i.e., risk level) and quantitative (i.e., risk score) assessment results, both of which help users make decisions to install an app or not. Furthermore, to find the reasonable weight distribution of each factor automatically, we exploit a self-learning weight assignment method, which is based on fuzzy clustering and knowledge dependency theory. We implement a prototype system and evaluate the effectiveness of SPRisk with 192,445 normal apps and 7,111 malicious apps. A measurement study further reveals some interesting findings, such as the privacy risk distribution of Google Play Store, the diversity of official and unofficial marketplaces, which provide insights into understanding the seriousness of privacy threat in the Android ecosystem. Jing Chen 0003, Chiheng Wang, Kun He 0008, Ziming Zhao 0001, Min Chen 0003, Ruiying Du, Gail-Joon Ahn |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Uncovering the Face of Android Ransomware: Characterization and Real-Time DetectionabstractIn recent years, we witnessed a drastic increase of ransomware, especially on popular mobile platforms including Android. Ransomware extorts victims for a sum of money by taking control of their devices or files. In light of their rapid growth, there is a pressing need to develop effective countermeasure solutions. However, the research community is still constrained by the lack of a comprehensive data set, and there exists no insightful understanding of mobile ransomware in the wild. In this paper, we focus on the Android platform and aim to characterize existing Android ransomware. Specifically, we have managed to collect 2,721 ransomware samples that cover the majority of existing Android ransomware families. Based on these samples, we systematically characterize them from several aspects, including timeline and malicious features. In addition, the detection results of existing anti-virus tools are rather disappointing, which clearly calls for customized anti-mobile-ransomware solutions. To detect ransomware that extorts users by encrypting data, we propose a novel real-time detection system, called RansomProber. By analyzing the user interface widgets of related activities and the coordinates of users' finger movements, RansomProber can infer whether the file encryption operations are initiated by users. The experimental results show that RansomProber can effectively detect encrypting ransomware with high accuracy and acceptable runtime performance. Jing Chen 0003, Chiheng Wang, Ziming Zhao 0001, Kai Chen 0012, Ruiying Du, Gail-Joon Ahn |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | A Survey of Security Network Coding toward Various AttacksabstractAs one of the emerging technologies with most potential for developing, Network Coding (NC) has gained significant momentum. Due to encode-and-forward model, NC has natural privacy in communication, but it also induces that attackers become more imperceptible and impact on NC caused by them becomes more far-reaching. This requires that the security schemes should consider the characteristics of different attacks in NC. In this paper, we provide a survey of secure network coding toward various attacks. First of all, we summarize four types of representative attacks in NC system including entropy attack, Byzantine attack, pollution attack and eavesdropping attack, and compare the differences of these attacks between in traditional store-and-forward mode and network coding mode. Secondly, we give a comprehensive investigation of numerous defense approaches and mechanisms classified by these attacks. Finally, for stimulating stream of thoughts about secure network coding schemes, several open issues are proposed and discussed. Shixiong Yao, Jing Chen 0003, Ruiying Du, Lan Deng, Chiheng Wang |
TrustCom | 5 |
| 2013 | Fault-Tolerant Topology Control Based on Artificial Immune Theory in WMNs
Jing Chen 0003, Ruiying Du, Chiheng Wang, Minghui Zheng, Yang Xiang 0001 |
NSS | 4 |