Kai Li 0017

dblp:181/2853-17 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-6040-0220ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Toward Automated Discovery of Asymmetric Mempool DoS in Blockchains
abstract
In blockchains, mempool controls transaction flow before consensus, denial of whose service hurts the health and security of blockchain networks. This paper presents MPFUZZ, the first mempool fuzzer to find asymmetric DoS bugs by exploring the space of symbolized mempool states and optimistically estimating the promisingness of an intermediate state in reaching bug oracles. Compared to the baseline blockchain fuzzers, MPFUZZ achieves a > 100× speedup in finding known DETER exploits. Running MPFUZZ on major Ethereum clients leads to discovering new mempool vulnerabilities, which exhibit a wide variety of sophisticated patterns, including stealthy mempool eviction and mempool locking. Rule-based mitigation schemes are proposed against all newly discovered vulnerabilities.
Yibo Wang 0006, Yuzhe Tang, Kai Li 0017, Wanning Ding
IEEE Trans. Software Eng.3
2024 Characterizing Ethereum Address Poisoning Attack
abstract
This paper presents the first comprehensive analysis of the address poisoning attack surged on the Ethereum blockchain. This phishing attack typically exploits the address shortening feature of Ethereum explorers and digital wallets (e.g., Etherscan and MetaMask) by crafting token transfer events with a seemingly correct address to poison victims' transfer history, waiting for them to mistakenly transfer assets to the attacker's address.
Kai Li 0017
CCS2
2024 Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful Fuzzing
Yibo Wang 0006, Yuzhe Tang, Kai Li 0017, Wanning Ding, Zhihua Yang
USENIX Security Symposium3
2023 Understanding the Security Risks of Decentralized Exchanges by Uncovering Unfair Trades in the Wild
abstract
DEX, or decentralized exchange, is a prominent class of decentralized finance (DeFi) applications on blockchains, attracting a total locked value worth tens of billions of USD today.This paper presents the first large-scale empirical study that uncovers unfair trades on popular DEX services on Ethereum and Binance Smart Chain (BSC). By joining and analyzing 60 million transactions, we find 671, 400 unfair trades on all six measured DEXes, including Uniswap, Balancer, and Curve. Out of these unfair trades, we attribute 55, 000 instances, with high confidence, to token thefts that cause a value loss of more than 3.88 million USD. Furthermore, the measurement study uncovers previously unknown causes of extractable value and real-world adaptive strategies to these causes. Finally, we propose countermeasures to redesign secure DEX protocols and to harden deployed services against the discovered security risks.
Yibo Wang 0006, Wanning Ding, Yuzhe Tang, XiaoFeng Wang 0001, Kai Li 0017
EuroS&P7
2023 Towards Saving Blockchain Fees via Secure and Cost-Effective Batching of Smart-Contract Invocations
abstract
This paper presentsiBatch, a middleware system running on top of an operational Ethereum network to enable secure batching of smart-contract invocations against an untrusted relay server off-chain.iBatchdoes so at a low overhead by validating the server's batched invocations in smart contracts without additional states of user nonces. TheiBatchmechanism supports a variety of policies, ranging from conservative to aggressive batching, and can be configured adaptively to the current workloads.iBatchautomatically rewrites smart contracts to integrate with legacy applications and support large-scale deployment. We built an evaluation platform for fast and cost-accurate transaction replaying and constructed real transaction benchmarks on popular Ethereum applications. With a functional prototype ofiBatch, we conduct extensive cost evaluations, which showsiBatchsaves$14.6\%\sim {}59.1\%$Gas cost per invocation with a moderate 2-minute delay and$19.06\%\sim {}31.52\%$Ether cost per invocation with a delay of$0.26\sim {}1.66$blocks.
Yibo Wang 0006, Kai Li 0017, Yuzhe Tang, Qi Zhang 0009, Xiapu Luo, Ting Chen 0002
IEEE Trans. Software Eng.2
2021 DETER: Denial of Ethereum Txpool sERvices
abstract
On an Ethereum node, txpool (a.k.a. mempool) is a buffer storing unconfirmed transactions and controls what downstream services can see, such as mining and transaction propagation. This work presents the first security study on Ethereum txpool designs.
Kai Li 0017, Yibo Wang 0006, Yuzhe Tang
CCS1
2021 TopoShot: uncovering Ethereum's network topology leveraging replacement transactions
abstract
Ethereum relies on a peer-to-peer overlay network to propagate information. The knowledge of Ethereum network topology holds the key to understanding Ethereum's security, availability, and user anonymity. However, an Ethereum network's topology is stored in individual nodes' internal routing tables, measuring which poses challenges and remains an open research problem in the existing literature.
Kai Li 0017, Yuzhe Tang, Yibo Wang 0006, Xianghong Liu
Internet Measurement Conference1
2021 As Strong As Its Weakest Link: How to Break Blockchain DApps at RPC Service
Kai Li 0017, Xianghong Liu, Yuzhe Tang, XiaoFeng Wang 0001, Xiapu Luo
NDSS1
2021 iBatch: saving Ethereum fees via secure and cost-effective batching of smart-contract invocations
abstract
This paper presents iBatch, a middleware system running on top of an operational Ethereum network to enable secure batching of smart-contract invocations against an untrusted relay server off-chain. iBatch does so at a low overhead by validating the server's batched invocations in smart contracts without additional states. The iBatch mechanism supports a variety of policies, ranging from conservative to aggressive batching, and can be configured adaptively to the current workloads. iBatch automatically rewrites smart contracts to integrate with legacy applications and support large-scale deployment.
Yibo Wang 0006, Qi Zhang 0009, Kai Li 0017, Yuzhe Tang, Xiapu Luo, Ting Chen 0002
ESEC/SIGSOFT FSE3
2020 Cost-Effective Data Feeds to Blockchains via Workload-Adaptive Data Replication
abstract
Feeding external data to a blockchain, a.k.a. data feed, is an essential task to enable blockchain interoperability and support emerging cross-domain applications. Given the data-intensive nature of real-life feeds (e.g., high-frequency price updates) and the high cost of using blockchain, namely Gas, it is imperative to reduce the Gas cost of data feeds. Motivated by the constant-changing workloads in financial applications, this work aims at designing a dynamic, workload-aware approach for Gas cost optimization. This design space is understudied in existing blockchain research which has so far focused on static data placement.
Kai Li 0017, Yuzhe Tang, Zhehu Yuan, Cheng Xu 0004, Jianliang Xu
Middleware1
2019 Secure Consistency Verification for Untrusted Cloud Storage by Public Blockchains
Kai Li 0017, Yuzhe Tang, Beom Heyn Kim, Jianliang Xu
SecureComm (1)1
2019 Authenticated LSM Trees with Minimal Trust
Yuzhe Tang, Kai Li 0017, Ju Chen
SecureComm (2)2
2018 ChainFS: Blockchain-Secured Cloud Storage
abstract
This work presents ChainFS, a middleware system that secures cloud storage services using a minimally trusted Blockchain. ChainFS hardens the cloud-storage security against forking attacks. The ChainFS middleware exposes a file-system interface to end users. Internally, ChainFS stores data files in the cloud and exports minimal and necessary functionalities to the Blockchain for key distribution and file operation logging. We implement the ChainFS system on Ethereum and S3FS and closely integrate it with FUSE clients and Amazon S3 cloud storage. We measure the system performance and demonstrate low overhead.
Yuzhe Tang, Qiwu Zou, Ju Chen, Kai Li 0017, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE CLOUD4