EDBT 2026 Demo / reviewers in the wild / expert
Lin Wang 0042
dblp:17/6729-42
· DBLP profile ↗
5ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0001-7030-7831ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Locating Security Patch Variants With Two-Dimensional Code Commit FeaturesabstractSecurity patches play a crucial role in the battle against Open Source Software (OSS) vulnerabilities. Meanwhile, to facilitate the development of OSS projects, both upstream and downstream developers often maintain multiple branches. Due to the different code contexts among branches, multiple security patch variants exist for the same vulnerability. Hence, to ease the management of OSS vulnerabilities, locating all patch variants of an OSS vulnerability is pretty important. However, existing works are mainly designed for locating a patch or several patches for a vulnerability but cannot locate all its patch variants. In this paper, we study the problem of how to accurately locate all variants of a given security patch. We motivate the problem with a preliminary study, which shows that it is rather challenging to locate all patch variants, even with a reference patch, due to the diverse practice of OSS developers in backporting patches. To overcome these challenges, we propose a new patch location method to locate all variants of a patch in a code repository (e.g., a software or a specific version). Based on our findings in the preliminary study, our method employs a rule-based model and incorporates two-dimensional code commit features that are specifically designed for the task of patch variant location: similarity features and representative features. With a ground truth patch variants dataset, our method achieves a precision of 99.68% and a recall of 98.81% and significantly outperforms two state-of-the-art baselines (PATCHSCOUT and TRACER). Besides, our method shows strong capability in locating patch variants at both upstream and downstream code repositories. Lin Wang 0042, Yuan Zhang 0009, Min Yang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | New PHP Language Features Make Your Static Code Analysis Tools Miss VulnerabilitiesabstractDue to the nature of directly interacting with user inputs, PHP applications are susceptible to taint-style vulnerabilities. To detect such vulnerabilities, Static Code Analysis Tools (SCATs) are widely used for their broad code coverage and scalability. Modeling language features (i.e., to represent and simulate the behavior of program codes) is the keystone of SCATs' vulnerability detection capabilities. Meanwhile, being an actively maintained language, the PHP community introduces several new language features almost every year, rendering many unmodeled features. Though efforts have been made to reduce the number of unmodeled features, e.g., proposing new modeling methods, the impact of the introduction of new PHP features on SCAT during the language evolution is not well-conscious and systematically assessed. To fill the gap, this paper performs a systematic study of new language features and their impact on the ability of SCATs to detect taint-style vulnerabilities in PHP codes. To be specific, we identify 25 widely-used new language features that potentially compromise SCATs' vulnerability detection capabilities. Besides, we assess the impact of these new features on five open-source SCATs and show that the vulnerability detection ability is significantly compromised, with each SCAT affected by 10 features on average. To mitigate the impact, we conduct a theoretical analysis to diagnose the underlying reasons and propose several effective adaptation strategies. Finally, we provide key insights and implications for various stakeholders in static code analysis, emphasizing the need for them to recognize and proactively address the potential effects of language evolution. Lin Wang 0042, Yuan Zhang 0009, Shengke Ye, Min Yang 0002 |
ICSME | 1 |
| 2024 | Applying Fuzz Driver Generation to Native C/C++ Libraries of OEM Android Framework: Obstacles and SolutionsabstractFuzz driver generation (FDG) is a fundamental technique for fuzzing library software. Existing FDG approaches have been highly successful with open-source libraries. However, in practice, due to the complex nature of OEM Android frameworks (e.g., customized compilation toolchains, extensive codebases, diverse C/C++ language features), it is not straightforward to integrate existing fuzz driver generation tools with OEM Android libraries. To address this challenge, we first systematically summarize the obstacles to applying existing tools (e.g., FuzzGen) to libraries of an OEM Android (i.e., ColorOS), including compatibility, usability, and effectiveness issues. Following this, we developed a new fuzz driver generation tool, namely FuzzGen++, specifically designed to tackle these obstacles one by one. In our evaluation, we demonstrate the advantages of FuzzGen++ in real-world OEM Android frameworks. FuzzGen++ is compatible with OEM Android and can generate fuzz drivers for all its libraries which are not supported by existing works. The additional analysis of the OEM Android code also enhances its usability within the system. Overall, FuzzGen++ has helped automatically generate 21,457 fuzz drivers. Additionally, through fuzz driver ranking and selection solution, FuzzGen++ figured out cut off 95% fuzz drivers which are less useful. FuzzGen++ supports sophisticated C/C++ features in code analysis, ensuring effectiveness. Compared to hand-written fuzz drivers, FuzzGen++ could generate and select fuzz drivers providing a 107.92% coverage improvement. Furthermore, they discovered 6 bugs, showcasing the capability of FuzzGen++ to find real-world issues. Shiyan Peng, Yuan Zhang 0009, Jiarun Dai, Zhuoxiang Shen, Lin Wang 0042, Lei Ai, Xianfeng Lu, Min Yang 0002 |
ASE | 7 |
| 2021 | Log-based Anomaly Detection from Multi-view by Associating Anomaly Scores with User TrustabstractLogs, prevalent among nearly all computer systems, contain rich information that helps with troubleshooting or root cause analysis. Therefore, logs are excellent information sources for anomaly detection. Since logs are diverse and heterogeneous, to deal with all of them requires maintenance personnel to check detection results one by one, which is troublesome. This paper applies an ensemble method that combines the output of different results of log anomaly detection and generates a unified output to reduce the burden of maintenance personnel. Since logs are recorded according to user behavior, they often have non-fixed intervals. We apply a trust computational model to transform the unevenly distributed data into a regularly spaced time series. To our best knowledge, this is the first work to employ the trust in the data processing. Futhermore, there are some parameters introduced by the trust computational model. We take advantage of the parametric ensemble technique to address the issue of parameter choice and finally improve the accuracy of anomaly detection. In this way, our method allows one to track a user from multi-view by logs with ease. The experiment shows that our method could achieve a good performance in detecting anomalies of user behavior from multiple kinds of logs. Lin Wang 0042, Kun Zhang 0016, Chen Li 0066, Bibo Tu |
TrustCom | 1 |
| 2018 | Simau: A Dynamic Privilege Management Mechanism for Host in Cloud Datacenters
Lin Wang 0042, Bibo Tu |
ICICS | 1 |