Rundong Zhou

dblp:148/1300 · DBLP profile ↗
← Back
9ranked-venue papers
0as first author
3since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 79% Cyber-physical and IoT security · 21%
Software engineering, system software, and programming languages
2 papers
Program analysis · 95% Operating systems · 5%

Topics — the 9 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.412020
SAVIOR: Towards Bug-Driven Hybrid Testing · SP 2020
Program analysis › symbolic execution
dynamic symbolic execution
0.412020
SAVIOR: Towards Bug-Driven Hybrid Testing · SP 2020
Systems and software security › binary analysis
binary code similarity detection
0.212016
Scalable Graph-based Bug Search for Firmware Images · CCS 2016
Cyber-physical and IoT security
iot firmware security
0.212016
Scalable Graph-based Bug Search for Firmware Images · CCS 2016
Systems and software security › vulnerability discovery
vulnerability search
0.212016
Scalable Graph-based Bug Search for Firmware Images · CCS 2016
Program analysis
dynamic analysis
0.212014
Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014
Program analysis › binary analysis
dynamic binary analysis
0.212014
Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014
Program analysis › static analysis
taint analysis
0.212014
Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014
Operating systems › virtualization
virtual machine introspection
0.112014
Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014

Methods — techniques the papers use, named apart from their topics

fuzz testing · 0.9concolic execution · 0.9SMT constraints · 0.9hashing · 0.2graph matching · 0.2control-flow graph embedding · 0.2just-in-time virtual machine introspection · 0.2instruction-level tainting · 0.2event-driven programming · 0.2
YearPublicationVenuePosition
2026 A three-dimensional multi-sensor fusion convolutional network for bearing fault diagnosis under complex small sample conditions
Rundong Zhou, Xinyu Zhai
Eng. Appl. Artif. Intell.2
2024 Minute-Scale and Mesoscale Atmospheric Motion Vectors Retrieved From Fengyun-4B Geostationary Satellite High-Speed Imager Measurements
abstract
Atmospheric motion vectors (AMVs) from satellite measurements serve as critical indicators of atmospheric dynamics, playing an essential role in enhancing the prediction precision of numerical weather prediction (NWP) models through data assimilation (DA). The implementation of finer satellite-derived vector products has the potential to significantly augment the accuracy of atmospheric flow field data in high-resolution regional NWP model simulations, thereby fulfilling the burgeoning requirements of operational weather nowcasting and forecasting. This study is focused on the development of mesoscale AMV (MAMV) products, which are distinguished by their exceptional quality and spatiotemporal resolution, leveraging data from the geostationary high-speed imager aboard the Fengyun-4B geostationary meteorological satellite (FY-4B/GHI). MAMVs of FY-4B/GHI feature an enhanced horizontal resolution of 3 km, enabling more accurate identification and monitoring of nongeostrophic flow patterns of mesoscale weather systems, as well as their fast-evolving dynamical structures and characteristics. Furthermore, a comparative analysis with radiosonde measurements highlights the precision of MAMV products, as evidenced by a speed bias (SB) of 0.37 m/s, a speed root mean square error (sRMSE) of 4.68 m/s, and a direction root mean square error (dRMSE) of 26.35°. The prospects of high-resolution satellite wind field data hold great potential for propelling scientific advancement and enriching our comprehension of atmospheric dynamics. This is particularly valuable in the context of typhoon monitoring and forecasting, where such data can lead to significant improvements in predictive capabilities.
Pan Xia, Min Min, Jun Li 0026, Na Xu 0001, Rundong Zhou, Bo Li 0145, Yan-An Liu
IEEE Trans. Geosci. Remote. Sens.6
2024 Efficient Vehicle-Infrastructure Collaborative Perception Based on Vehicle Re-Identification and Mini-ICP Algorithm
abstract
The efficient exchange of perception information between vehicles and infrastructure is crucial for implementing vehicle-infrastructure (VI) collaborative intelligent driving. To address the high real-time requirements of VI communication and lack of intelligence and flexibility in VI cooperation, this study proposes an efficient collaborative perception method based on vehicle re-identification for VI collaboration scenarios. The real-time requirements of such scenarios are addressed and a lightweight vehicle re-identification network called ShuffleBNLSH is designed. This network is combined with a hash algorithm to quickly generate ID information for collaborative sensing targets. Based on the state of the VI communication channel, the network can adaptively extract the bit features of the perceived vehicle target, adjust the feature length, and quickly perform feature matching for vehicle target re-identification. To rapidly fuse the VI collaborative perception information combined with the re-identification results and LiDAR 3D perception information from the vehicle and infrastructure, we designed a mini-ICP algorithm that can automatically select feature points and perform point-cloud registration. Experimental results show that the amount of data transmitted by a single target in cooperative sensing can be as small as hundreds of bits during the fusion of sensing targets on the vehicle and infrastructure sides. This reduces the bandwidth requirements for fusing perception targets, accelerates feature transmission and matching, and expands the perception range of VI collaborative autonomous vehicles without GPS information.
Chenyang Sun, Yang Wang 0029, Yanfei Deng, Huafu Li, Rundong Zhou, Junqi Guo
IEEE Trans. Intell. Transp. Syst.5
2020 SAVIOR: Towards Bug-Driven Hybrid Testing
abstract
Hybrid testing combines fuzz testing and concolic execution. It leverages fuzz testing to test easy-to-reach code regions and uses concolic execution to explore code blocks guarded by complex branch conditions. As a result, hybrid testing is able to reach deeper into program state space than fuzz testing or concolic execution alone. Recently, hybrid testing has seen significant advancement. However, its code coverage-centric design is inefficient in vulnerability detection. First, it blindly selects seeds for concolic execution and aims to explore new code continuously. However, as statistics show, a large portion of the explored code is often bug-free. Therefore, giving equal attention to every part of the code during hybrid testing is a non-optimal strategy. It slows down the detection of real vulnerabilities by over 43%. Second, classic hybrid testing quickly moves on after reaching a chunk of code, rather than examining the hidden defects inside. It may frequently miss subtle vulnerabilities despite that it has already explored the vulnerable code paths.We propose SAVIOR, a new hybrid testing framework pioneering a bug-driven principle. Unlike the existing hybrid testing tools, SAVIOR prioritizes the concolic execution of the seeds that are likely to uncover more vulnerabilities. Moreover, SAVIOR verifies all vulnerable program locations along the executing program path. By modeling faulty situations using SMT constraints, SAVIOR reasons the feasibility of vulnerabilities and generates concrete test cases as proofs. Our evaluation shows that the bug-driven approach outperforms mainstream automated testing techniques, including state-of-the-art hybrid testing systems driven by code coverage. On average, SAVIOR detects vulnerabilities 43.4% faster than DRILLER and 44.3% faster than QSYM, leading to the discovery of 88 and 76 more unique bugs, respectively. According to the evaluation on 11 well fuzzed benchmark programs, within the first 24 hours, SAVIOR triggers 481 UBSAN violations, among which 243 are real bugs.
Yaohui Chen 0001, Jun Xu 0024, Shengjian Guo, Rundong Zhou, Tao Wei 0002, Long Lu
SP5
2019 Learning Binary Representation for Automatic Patch Detection
abstract
Binary-only bug search has already drawn a lot attentions recently, due to the increasing growth of security breaches. Most of existing work focuses on searching by checking the similarity of code snippets. It is further required to check whether the function is patched or not. Unfortunately, this is still a manual effort for all existing code search based approaches. In this paper, we propose a novel approach for automatic patch detection. we build a patch detector by learning the feature representation from the patched code in the binary format. We utilize the feature encoding technique to make the binary code trainable, and build our neural network model to learn the patch feature for increasing detection accuracy. We have implemented a prototype called PATCHDETECTOR, and systematically evaluated its performance in terms of the accuracy and efficiency by using 1,600 OpenSSL binaries of 216,000 functions. Experimental results have shown that PATCHDETECTOR can effectively detect whether the target binary function is patched or not with the detection accuracy of 92% on average.
Rundong Zhou, Yanhui Zhao, Jia Ma, Xudong Jin, Ahmed M. Azab, Peng Ning
CCNC2
2017 Extracting Conditional Formulas for Cross-Platform Bug Search
abstract
With the recent increase in security breaches in embedded systems and IoT devices, it becomes increasingly important to search for vulnerabilities directly in binary executables in a cross-platform setting. However, very little has been explored in this domain. The existing efforts are prone to producing considerable false positives, and their results cannot provide explainable evidence for human analysts to eliminate these false positives. In this paper, we propose to extract conditional formulas as higher-level semantic features from the raw binary code to conduct the code search. A conditional formula explicitly captures two cardinal factors of a bug: 1) erroneous data dependencies and 2) missing or invalid condition checks. As a result, binary code search on conditional formulas produces significantly higher accuracy and provide meaningful evidence for human analysts to further examine the search results. We have implemented a prototype, XMATCH, and evaluated it using well-known software, including OpenSSL and BusyBox. Experimental results have shown that XMATCH outperforms the existing bug search techniques in terms of accuracy. Moreover, by evaluating 5 recent vulnerabilities, XMATCH provides clear evidence for human analysts to determine if a matched candidate is indeed vulnerable or has been patched.
Mu Zhang 0001, Rundong Zhou, Andrew Henderson, Heng Yin 0001
AsiaCCS4
2016 Scalable Graph-based Bug Search for Firmware Images
abstract
Because of rampant security breaches in IoT devices, searching vulnerabilities in massive IoT ecosystems is more crucial than ever. Recent studies have demonstrated that control-flow graph (CFG) based bug search techniques can be effective and accurate in IoT devices across different architectures. However, these CFG-based bug search approaches are far from being scalable to handle an enormous amount of IoT devices in the wild, due to their expensive graph matching overhead. Inspired by rich experience in image and video search, we propose a new bug search scheme which addresses the scalability challenge in existing cross-platform bug search techniques and further improves search accuracy. Unlike existing techniques that directly conduct searches based upon raw features (CFGs) from the binary code, we convert the CFGs into high-level numeric feature vectors. Compared with the CFG feature, high-level numeric feature vectors are more robust to code variation across different architectures, and can easily achieve realtime search by using state-of-the-art hashing techniques. We have implemented a bug search engine, Genius, and compared it with state-of-art bug search approaches. Experimental results show that Genius outperforms baseline approaches for various query loads in terms of speed and accuracy. We also evaluated Genius on a real-world dataset of 33,045 devices which was collected from public sources and our system. The experiment showed that Genius can finish a search within 1 second on average when performed over 8,126 firmware images of 420,558,702 functions. By only looking at the top 50 candidates in the search result, we found 38 potentially vulnerable firmware images across 5 vendors, and confirmed 23 of them by our manual analysis. We also found that it took only 0.1 seconds on average to finish searching for all 154 vulnerabilities in two latest commercial firmware images from D-LINK. 103 of them are potentially vulnerable in these images, and 16 of them were confirmed.
Rundong Zhou, Brian Testa, Heng Yin 0001
CCS2
2016 Semantics-Preserving Dissection of JavaScript Exploits via Dynamic JS-Binary Analysis
Xunchao Hu, Aravind Prakash, Rundong Zhou, Heng Yin 0001
RAID4
2014 Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform
abstract
Dynamic binary analysis is a prevalent and indispensable technique in program analysis. While several dynamic binary analysis tools and frameworks have been proposed, all suffer from one or more of: prohibitive performance degradation, semantic gap between the analysis code and the program being analyzed, architecture/OS specificity, being user-mode only, lacking APIs, etc. We present DECAF, a virtual machine based, multi-target, whole-system dynamic binary analysis framework built on top of QEMU. DECAF provides Just-In-Time Virtual Machine Introspection combined with a novel TCG instruction-level tainting at bit granularity, backed by a plugin based, simple-to-use event driven programming interface. DECAF exercises fine control over the TCG instructions to accomplish on-the-fly optimizations. We present 3 platform-neutral plugins - Instruction Tracer, Keylogger Detector, and API Tracer, to demonstrate the ease of use and effectiveness of DECAF in writing cross-platform and system-wide analysis tools. Implementation of DECAF consists of 9550 lines of C++ code and 10270 lines of C code and we evaluate DECAF using CPU2006 SPEC benchmarks and show average overhead of 605% for system wide tainting and 12% for VMI.
Andrew Henderson, Aravind Prakash, Lok-Kwong Yan, Xunchao Hu, Xujiewen Wang, Rundong Zhou, Heng Yin 0001
ISSTA6