EDBT 2026 Demo / reviewers in the wild / expert
Jianwei Zhuge
dblp:15/3840
· DBLP profile ↗
26ranked-venue papers
2as first author
13since 2021 · last 2026
0009-0005-9570-3335ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 1 first-author · 10 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Identifying Logical Vulnerabilities in QUIC Implementations
Kaihua Wang, Jianjun Chen 0005, Pinji Chen, Jianwei Zhuge, Jiaju Bai, Hai-Xin Duan |
NDSS | 4 |
| 2025 | ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance Graphs
Jun Zeng 0006, Qixiao Lin, Jiahao Liu 0005, Jianwei Zhuge, Zhenkai Liang |
NDSS | 7 |
| 2025 | The Silent Danger in HTTP: Identifying HTTP Desync Vulnerabilities with Gray-box Testing
Keran Mu, Jianjun Chen 0005, Jianwei Zhuge, Qi Li 0002, Hai-Xin Duan, Nick Feamster |
USENIX Security Symposium | 3 |
| 2025 | BLMProbe: Enhancing Internet-Connected Device Discovery by Automated Device Labeling and Label Migrationabstract10.1109/TIFS.2025.3587211 Zhenhao Tian, Yi He 0020, Nuo Zhang, Qixiao Lin, Hetian Shi, Jianwei Zhuge, Deliang Chang |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment DetectorsabstractEmail attachments have become a favored delivery vector for malware campaigns. In response, email attachment detectors are widely deployed to safeguard email security. However, an emerging threat arises when adversaries exploit parsing discrepancies between email detectors and clients to evade detection. Currently, uncovering these vulnerabilities still depends on manual, ad hoc methods. In this paper, we perform the first systematic evaluation of email attachment detection against parsing ambiguity vulnerabilities. We propose a novel testing methodology, MIMEminer, to systematically discover evasion vulnerabilities in email systems. We evaluated our methodology against 16 content detectors of popular email services like Gmail and iCloud, and 7 popular email clients like Outlook and Thunderbird. In total, we discovered 19 new evasion methods affecting all tested email services and clients. We further analyzed these vulnerabilities and identified three primary categories of malware evasions. We have responsibly reported those identified vulnerabilities to the affected providers to help with the remediation of such vulnerabilities and received acknowledgments from Google Gmail, Apple iCloud, Coremail, Tencent, Amavis and Perl MIME-tools. Jianjun Chen 0005, Qi Wang 0094, Chuhan Wang 0001, Jianwei Zhuge, Hai-Xin Duan |
CCS | 6 |
| 2024 | Demystifying the Security Implications in IoT Device Rental Services
Yi He 0020, Yunchao Guan, Ruoyu Lun, Shangru Song, Jianwei Zhuge, Jianjun Chen 0005, Zehui Wu, Hetian Shi, Qi Li 0002 |
USENIX Security Symposium | 6 |
| 2023 | Discovering and Understanding the Security Flaws of Authentication and Authorization in IoT Cloud APIs for Smart Home
Minglei Guo, Zhenghang Xiao, Jianwei Zhuge |
SecureComm (1) | 4 |
| 2023 | CV2XFuzzer: C-V2X Parsing Vulnerability Discovery System Based on Fuzzing
Yishen Li, Jihu Zheng, Jianwei Zhuge |
SecureComm (2) | 4 |
| 2023 | Code classification with graph neural networks: Have you ever struggled to make it work?
Xin Liu 0050, Qingguo Zhou, Jianwei Zhuge, Chunming Wu 0001 |
Expert Syst. Appl. | 4 |
| 2022 | PG-VulNet: Detect Supply Chain Vulnerabilities in IoT Devices using Pseudo-code and GraphsabstractBackground: With the boosting development of IoT technology, the supply chains of IoT devices become more powerful and sophisticated, and the security issues introduced by code reuse are becoming more prominent. Therefore, the detection and management of vulnerabilities through code similarity detection technology is of great significance for protecting the security of IoT devices. Aim: We aim to propose a more accurate, parallel-friendly, and realistic software supply chain vulnerability detection solution for IoT devices. Method: This paper presents PG-VulNet, standing for Vulnerability-detection Network based on Pseudo-code Graphs. It is a ”multi-model” cross-architecture vulnerability detection solution based on pseudo-code and Graph Matching Network (GMN). PG-VulNet extracts both behavioral and structural features of pseudo-code to build customized feature graphs and then uses GMN to detect supply chain vulnerabilities based on these graphs. Results: The experiments show that PG-VulNet achieves an average detection accuracy of 99.14%, significantly higher than existing approaches like Gemini, VulSeeker, FIT, and Asteria. In addition to this, PG-VulNet also excels in detection overhead and false alarms. In the real-world evaluation, PG-VulNet detected 690 known vulnerabilities in 1,611 firmwares. Conclusions: PG-VulNet can effectively detect the vulnerabilities introduced by software supply chain in IoT firmwares and is well suited for large-scale detection. Compared with existing approaches, PG-VulNet has significant advantages. Xin Liu 0050, Yixiong Wu, Shangru Song, Qingguo Zhou, Jianwei Zhuge |
ESEM | 7 |
| 2022 | Trampoline Over the Air: Breaking in IoT Devices Through MQTT BrokersabstractMQTT is widely adopted by IoT devices because it allows for the most efficient data transfer over a variety of communication lines. The security of MQTT has received increasing attention in recent years, and several studies have demonstrated the configurations of many MQTT brokers are insecure. Adversaries are allowed to exploit vulnerable brokers and publish malicious messages to subscribers. However, little has been done to understanding the security issues on the device side when devices handle unauthorized MQTT messages. To fill this research gap, we propose a fuzzing framework named ShadowFuzzer to find client-side vulnerabilities when processing incoming MQTT messages. To avoiding ethical issues, ShadowFuzzer redirects traffic destined for the actual broker to a shadow broker under the control to monitor vulnerabilities. We select 15 IoT devices communicating with vulnerable brokers and leverage ShadowFuzzer to find vulnerabilities when they parse MQTT messages. For these devices, ShadowFuzzer reports 34 zero-day vulnerabilities in 11 devices. We evaluated the exploitability of these vulnerabilities and received a total of 44,000 USD bug bounty rewards. And 16 CVE/CNVD/CN-NVD numbers have been assigned to us. Huikai Xu, Qinsheng Hou, Zhenbang Ma, Hai-Xin Duan, Jianwei Zhuge, Baojun Liu 0002 |
EuroS&P | 8 |
| 2022 | jTrans: jump-aware transformer for binary code similarity detectionabstractBinary code similarity detection (BCSD) has important applications in various fields such as vulnerabilities detection, software component analysis, and reverse engineering. Recent studies have shown that deep neural networks (DNNs) can comprehend instructions or control-flow graphs (CFG) of binary code and support BCSD. In this study, we propose a novel Transformer-based approach, namely jTrans, to learn representations of binary code. It is the first solution that embeds control flow information of binary code into Transformer-based language models, by using a novel jump-aware representation of the analyzed binaries and a newly-designed pre-training task. Additionally, we release to the community a newly-created large dataset of binaries, BinaryCorp, which is the most diverse to date. Evaluation results show that jTrans outperforms state-of-the-art (SOTA) approaches on this more challenging dataset by 30.5% (i.e., from 32.0% to 62.5%). In a real-world task of known vulnerability searching, jTrans achieves a recall that is 2X higher than existing SOTA baselines. Hao Wang 0226, Wenjie Qu 0001, Gilad Katz, Wenyu Zhu, Han Qiu 0001, Jianwei Zhuge, Chao Zhang 0008 |
ISSTA | 7 |
| 2021 | From Exposed to Exploited: Drawing the Picture of Industrial Control Systems Security Status in the Internet Age
Yixiong Wu, Jianwei Zhuge, Tingting Yin, Junmin Zhu, Guannan Guo, Jianju Hu |
ICISSP | 2 |
| 2020 | Adapting to Local Conditions: Similarities and Differences in Anonymous Online Market Between Chinese and English Speaking Communities
Gengqian Zhou, Jianwei Zhuge |
ICDF2C | 2 |
| 2020 | FANS: Fuzzing Android Native System Services via Automated Interface Analysis
Baozheng Liu, Chao Zhang 0008, Guang Gong, Yishun Zeng, Haifeng Ruan, Jianwei Zhuge |
USENIX Security Symposium | 6 |
| 2020 | A Market in Dream: the Rapid Development of Anonymous Cybercrime
Gengqian Zhou, Jianwei Zhuge, Yunqian Fan, Kun Du, Shuqiang Lu |
Mob. Networks Appl. | 2 |
| 2019 | Fuzzing IPC with Knowledge InferenceabstractSandboxing provides a strong security guarantee for applications, by isolating untrusted code into separated compartments. Untrusted code could only use IPC (inter-process communication) to launch sensitive actions, which are implemented in trusted (and maybe privileged) code. IPC-related security bugs in trusted code could facilitate jailbreaks of sandboxing, and thus are becoming high-value targets. However, finding vulnerabilities that could be triggered by IPC is challenging, due to the fact that IPC communication is stateful and format-sensitive. In this paper, we propose a new fuzzing solution to discover IPC bugs in IPC services without source code, by combining static analysis and dynamic analysis. We use static analysis to recognize format checks and help construct IPC messages of valid formats. We then use dynamic analysis to infer the constraints between IPC messages, and model the stateful logic with a probability matrix. Therefore, we are able to generate high-quality IPC messages to test IPC services, and discover deep and complex IPC bugs. Without loss of generality, we implemented a prototype MachFuzzer, for a specific complicated and crucial IPC service, i.e., WindowServer in macOS. This prototype helps us find 12 previously unknown vulnerabilities in WindowServer in 48 hours. Among them, three vulnerabilities are confirmed exploitable, and could be exploited to escape the sandbox and gain root privilege. Chao Zhang 0008, Jianwei Zhuge, Hai-Xin Duan |
SRDS | 4 |
| 2018 | ICUFuzzer: Fuzzing ICU Library for Exploitable Bugs in Multiple Software
Chao Zhang 0008, Jianwei Zhuge, Hai-Xin Duan |
ISC | 4 |
| 2016 | A Tool for Volatile Memory Acquisition from Android Devices
Haiyu Yang, Jianwei Zhuge, Huiming Liu |
IFIP Int. Conf. Digital Forensics | 2 |
| 2014 | JShield: towards real-time and vulnerability-based detection of polluted drive-by download attacksabstractDrive-by download attacks, which exploit vulnerabilities of web browsers to control client computers, have become a major venue for attackers. To detect such attacks, researchers have proposed many approaches such as anomaly-based [22, 23] and vulnerability-based [44, 50] detections. However, anomaly-based approaches are vulnerable to data pollution, and existing vulnerability-based approaches cannot accurately describe the vulnerability condition of all the drive-by download attacks. Yinzhi Cao, Yan Chen 0004, Jianwei Zhuge |
ACSAC | 4 |
| 2014 | IntentFuzzer: detecting capability leaks of android applicationsabstractCapability leak is a vulnerability in Android applications, which violates the enforcement of permission model and threatens the secure usage of Android phone users. Malicious applications can launch permission escalation attacks with this vulnerability. In this paper, we propose a dynamic Intent fuzzing mechanism to uncover vulnerable applications in both Android markets and closed source ROMs. We built a prototype called IntentFuzzer. With it, we analyzed more than 2000 Android applications in Google Play and hundreds of in-rom applications inside two closed source ROMs. We found that 161 applications in Google Play have at least one permission leak, and 26 permissions in Xiaomi Hongmi phone and 19 permissions in Lenovo K860i stock phone are leaked. Finally, we give several cases of exploitation to verify our analysis result. Jianwei Zhuge, Yongke Wang, Lujue Zhou, Hai-Xin Duan |
AsiaCCS | 2 |
| 2014 | SBE - A Precise Shellcode Detection Engine Based on Emulation and Support Vector Machine
Yonggan Hou, Jianwei Zhuge, Dan Xin, Wenya Feng |
ISPEC | 2 |
| 2011 | WebPatrol: automated collection and replay of web-based malware scenariosabstractTraditional remote-server-exploiting malware is quickly evolving and adapting to the new web-centric computing paradigm. By leveraging the large population of (insecure) web sites and exploiting the vulnerabilities at client-side modern (complex) browsers (and their extensions), web-based malware becomes one of the most severe and common infection vectors nowadays. While traditional malware collection and analysis are mainly focusing on binaries, it is important to develop new techniques and tools for collecting and analyzing web-based malware, which should include a complete web-based malicious logic to reflect the dynamic, distributed, multi-step, and multi-path web infection trails, instead of just the binaries executed at end hosts. This paper is a first attempt in this direction to automatically collect web-based malware scenarios (including complete web infection trails) to enable fine-grained analysis. Based on the collections, we provide the capability for offline "live" replay, i.e., an end user (e.g., an analyst) can faithfully experience the original infection trail based on her current client environment, even when the original malicious web pages are not available or already cleaned. Our evaluation shows that WebPatrol can collect/cover much more complete infection trails than state-of-the-art honeypot systems such as PHoneyC [11] and Capture-HPC [1]. We also provide several case studies on the analysis of web-based malware scenarios we have collected from a large national education and research network, which contains around 35,000 web sites. Kevin Zhijie Chen, Guofei Gu, Jianwei Zhuge, Jose Nazario, Xinhui Han |
AsiaCCS | 3 |
| 2010 | Preventing drive-by download via inter-module communication monitoringabstractDrive-by download attack is one of the most severe threats to Internet users. Typically, only visiting a malicious page will result in compromise of the client and infection of malware. By the end of 2008, drive-by download had already become the number one infection vector of malware [5]. The downloaded malware may steal the users' personal identification and password. They may also join botnet to send spams, host phishing site or launch distributed denial of service attacks. Chengyu Song, Jianwei Zhuge, Xinhui Han, Zhiyuan Ye |
AsiaCCS | 2 |
| 2007 | Collecting Autonomous Spreading Malware Using High-Interaction Honeypots
Jianwei Zhuge, Thorsten Holz, Xinhui Han, Chengyu Song |
ICICS | 1 |
| 2003 | Security mechanisms for wireless home networkabstractIn this paper, we discuss the security issue in wireless home network (WHN) and give solution. First, we summarize the security threats and requirements of WHN, and analyze the characteristics of WHN and their influences to the design of security mechanisms. Then, based on the security threats and requirements that we have analyzed, we introduce some security mechanisms to protect the WHN. Furthermore, some alternative mechanisms are proposed for the variety of devices to choose according to their security requirements and capabilities, for example, the security delegation service (SDS) provides an efficient solution for wireless devices with low computation capability and resources to use the widely applied security protocols such as LPSEC and TLS. Finally, the security analysis is presented to demonstrate that the proposed security mechanisms are robust and efficient to secure the WHN. Jianwei Zhuge, Richard Yao |
GLOBECOM | 1 |