EDBT 2026 Demo / reviewers in the wild / expert
Qinying Wang
dblp:156/1247
· DBLP profile ↗
16ranked-venue papers
2as first author
16since 2021 · last 2026
0000-0002-0010-0592ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 2 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain Attacks
Yiming Tao, Qinying Wang, Chunming Wu 0001, Mingde Hu, Yizhi Ren, Shouling Ji |
NDSS | 3 |
| 2026 | SYSYPHUZZ: the Pressure of More Coverage
Zezhong Ren, Han Zheng 0006, Zhiyao Feng, Qinying Wang, Marcel Busch, Yuqing Zhang 0001, Chao Zhang 0008, Mathias Payer |
NDSS | 4 |
| 2026 | SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime Environment
Meng Wang 0071, Qinying Wang, Ali Abbasi 0002, Thorsten Holz |
SP | 4 |
| 2026 | MPS-Fuzz: An Enhanced Fine-Grained Fuzzing Based on Units With Multiple Inputs and OutputsabstractEdge coverage-guided fuzzing has demonstrated remarkable achievements in vulnerability discovery. Some studies with fine-grained coverage metrics have been proposed to enhance the vulnerability mining capabilities of fuzzing by capturing more program paths. However, this refinement often results in a significant increase in seeds, which are highly homogeneous and may limit vulnerability detection. Additionally, finer granularity requires more bitmap hits, increasing the risk of hash collisions. To address these shortages, the paper proposes the structure of a basic block unit with multiple predecessors and successors (referred to as MPS). Then, a fine-grained coverage method called MPS-Fuzz is designed based on the MPS structure. In this approach, it is convenient to exclude basic blocks involving loop structures when determining MPS units, which helps reduce seed homogeneity. Additionally, we introduce an additional bitmap to record the coverage status of MPS units, ensuring that the collision rate of the edge bitmap does not increase. Moreover, these additional operations do not incur excessive time overhead. To demonstrate the properties of the MPS-Fuzz, we implement our approach on AFL and conduct experiments on 16 benchmarks from FuzzBench and Unifuzz. The result indicates that, after 24-hour fuzzing, MPS-Fuzz explores an average of 9.6% more edges and an average of 25.7% more bugs than AFL. Compared to other fine-grained coverage methods (N-gram and PathAFL), MPS-Fuzz also achieves better performance. Moreover, MPS-Fuzz has discovered a previously unknown bug on real-world program and got a CVE assigned. Ximing Fan, Yong Fang 0002, Peng Jia 0005, Hongwei Li 0001, Yijia Xu, Qinying Wang, Shouling Ji |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | A Comprehensive Memory Safety Analysis of Bootloaders
Meng Wang 0071, Qinying Wang, Nils Langius, Ali Abbasi 0002, Thorsten Holz |
NDSS | 3 |
| 2025 | Unveiling Security Vulnerabilities in Git Large File Storage ProtocolabstractAs an extension to the Git version control system that optimizes the handling of large files and binary content, Git Large File Storage (LFS) has been widely adopted by nearly all Git platforms. While Git LFS offers significant improvements in managing large files, it introduces new security implications that remain largely unexplored. This paper presents the first comprehensive security analysis of Git LFS, identifying 11 critical security properties that LFS servers must uphold. Building on our analysis of these property violations, we propose four new attack vectors: Private LFS File Leakage, LFS File Replacement, Quota-based Denial of Service (DoS), and Quota Escape. These attacks exploit weaknesses in practical LFS server implementations and can lead to serious consequences, including unauthorized access to sensitive files, malware injection, denial of service affecting all public repositories, and resource abuse. To evaluate the security of LFS implementations, we develop a semi-automated black-box testing tool and apply it to 14 major Git platforms. We uncover 36 previously unknown vulnerabilities and have responsibly disclosed them to the respective platform maintainers, receiving positive feedback and over $1800 in bug bounty rewards. Qinying Wang, Yong Yang 0017, Yuanchao Chen, Yuwei Li 0002, Shouling Ji |
SP | 2 |
| 2025 | AidFuzzer: Adaptive Interrupt-Driven Firmware Fuzzing via Run-Time State Recognition
Qinying Wang, Tobias Scharnowski, Simon Wörner, Thorsten Holz |
USENIX Security Symposium | 2 |
| 2024 | Pluggable Watermarking of Deepfake Models for Deepfake Detection
Xuhong Zhang 0002, Qinying Wang, Kangming Liang, Zonghui Wang, Shouling Ji, Wenzhi Chen |
IJCAI | 3 |
| 2024 | MOCK: Optimizing Kernel Fuzzing Mutation with Context-aware Dependency
Jiacheng Xu 0006, Xuhong Zhang 0002, Shouling Ji, Yuan Tian 0001, Qinying Wang, Peng Cheng 0001, Jiming Chen 0001 |
NDSS | 6 |
| 2024 | SyzTrust: State-aware Fuzzing on Trusted OS Designed for IoT DevicesabstractTrusted Execution Environments (TEEs) embedded in IoT devices provide a deployable solution to secure IoT applications at the hardware level. By design, in TEEs, the Trusted Operating System (Trusted OS) is the primary component. It enables the TEE to use security-based design techniques, such as data encryption and identity authentication. Once a Trusted OS has been exploited, the TEE can no longer ensure security. However, Trusted OSes for IoT devices have received little security analysis, which is challenging from several perspectives: (1) Trusted OSes are closed-source and have an unfavorable environment for sending test cases and collecting feedback. (2) Trusted OSes have complex data structures and require a stateful workflow, which limits existing vulnerability detection tools.To address the challenges, we present SyzTrust, the first state-aware fuzzing framework for vetting the security of resource-limited Trusted OSes. SyzTrust adopts a hardware-assisted framework to enable fuzzing Trusted OSes directly on IoT devices as well as tracking state and code coverage non-invasively. SyzTrust utilizes composite feedback to guide the fuzzer to effectively explore more states as well as to increase the code coverage. We evaluate SyzTrust on Trusted OSes from three major vendors: Samsung, Tsinglink Cloud, and Ali Cloud. These systems run on Cortex M23/33 MCUs, which provide the necessary abstraction for embedded TEEs. We discovered 70 previously unknown vulnerabilities in their Trusted OSes, receiving 10 new CVEs so far. Furthermore, compared to the baseline, SyzTrust has demonstrated significant improvements, including 66% higher code coverage, 651% higher state coverage, and 31% improved vulnerability-finding capability. We report all discovered new vulnerabilities to vendors and open source SyzTrust. Qinying Wang, Boyu Chang, Shouling Ji, Yuan Tian 0001, Xuhong Zhang 0002, Chenyang Lyu, Mathias Payer, Wenhai Wang, Raheem A. Beyah |
SP | 1 |
| 2024 | One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT FirmwareabstractCurrently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implementFirmSec, which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based onFirmSec, we present the first large-scale analysis of the security risks raised by TPCs on 34,136 firmware images. We successfully detect 584 TPCs and identify 128,757 vulnerabilities caused by 429 CVEs. Our in-depth analysis reveals the diversity of security risks in firmware and discovers some well-known vulnerabilities are still rooted in firmware. Besides, we explore the geographical distribution of vulnerable devices and confirm that the security situation of devices in different regions varies. Our analysis also indicates that vulnerabilities caused by TPCs in firmware keep growing with the boom of the IoT ecosystem. Further analysis shows 2,478 commercial firmware images have potentially violated GPL/AGPL licensing terms. Shouling Ji, Jiacheng Xu 0006, Yuan Tian 0001, Qiuyang Wei, Qinying Wang, Chenyang Lyu, Xuhong Zhang 0002, Changting Lin, JingZheng Wu, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | MILG: Realistic lip-sync video generation with audio-modulated image inpaintingabstractExisting lip synchronization (lip-sync) methods generate accurately synchronized mouths and faces in a generated video. However, they still confront the problem of artifacts in regions of non-interest (RONI), e.g. , background and other parts of a face, which decreases the overall visual quality. To solve these problems, we innovatively introduce diverse image inpainting to lip-sync generation. We propose Modulated Inpainting Lip-sync GAN (MILG), an audio-constraint inpainting network to predict synchronous mouths. MILG utilizes prior knowledge of RONI and audio sequences to predict lip shape instead of image generation , which can keep the RONI consistent. Specifically, we integrate modulated spatially probabilistic diversity normalization (MSPD Norm) in our inpainting network, which helps the network generate fine-grained diverse mouth movements guided by the continuous audio features. Furthermore, to lower the training overhead, we modify the contrastive loss in lip-sync to support small-batch-size and few-sample training. Extensive experiments demonstrate that our approach outperforms the existing state-of-the-art of image quality and authenticity while keeping lip-sync. Xuhong Zhang 0002, Qinying Wang, Kangming Liang, Zonghui Wang, Shouling Ji, Wenzhi Chen |
Vis. Informatics | 3 |
| 2023 | MINER: A Hybrid Data-Driven Approach for REST API Fuzzing
Chenyang Lyu, Jiacheng Xu 0006, Shouling Ji, Xuhong Zhang 0002, Qinying Wang, Peng Cheng 0001, Raheem A. Beyah |
USENIX Security Symposium | 5 |
| 2023 | UVSCAN: Detecting Third-Party Component Usage Violations in IoT Firmware
Shouling Ji, Xuhong Zhang 0002, Yuan Tian 0001, Qinying Wang, Yuwen Pu, Chenyang Lyu, Raheem A. Beyah |
USENIX Security Symposium | 5 |
| 2022 | A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareabstractAs the core of IoT devices, firmware is undoubtedly vital. Currently, the development of IoT firmware heavily depends on third-party components (TPCs), which significantly improves the development efficiency and reduces the cost. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will turn back influence the security of IoT firmware. Currently, existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement FirmSec, which leverages syntactical features and control-flow graph features to detect the TPCs at version-level in firmware, and then recognizes the corresponding vulnerabilities. Based on FirmSec, we present the first large-scale analysis of the usage of TPCs and the corresponding vulnerabilities in firmware. More specifically, we perform an analysis on 34,136 firmware images, including 11,086 publicly accessible firmware images, and 23,050 private firmware images from TSmart. We successfully detect 584 TPCs and identify 128,757 vulnerabilities caused by 429 CVEs. Our in-depth analysis reveals the diversity of security issues for different kinds of firmware from various vendors, and discovers some well-known vulnerabilities are still deeply rooted in many firmware images. We also find that the TPCs used in firmware have fallen behind by five years on average. Besides, we explore the geographical distribution of vulnerable devices, and confirm the security situation of devices in several regions, e.g., South Korea and China, is more severe than in other regions. Further analysis shows 2,478 commercial firmware images have potentially violated GPL/AGPL licensing terms. Shouling Ji, Jiacheng Xu 0006, Yuan Tian 0001, Qiuyang Wei, Qinying Wang, Chenyang Lyu, Xuhong Zhang 0002, Changting Lin, JingZheng Wu, Raheem A. Beyah |
ISSTA | 6 |
| 2021 | MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging Protocols
Qinying Wang, Shouling Ji, Yuan Tian 0001, Xuhong Zhang 0002, Yuhong Kan, Zhaowei Lin, Changting Lin, Shuiguang Deng, Alex X. Liu, Raheem A. Beyah |
USENIX Security Symposium | 1 |