Yaowen Zheng

dblp:190/2868 · DBLP profile ↗
← Back
39ranked-venue papers
4as first author
35since 2021 · last 2026
0000-0002-8953-0782ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 1 first-author · 13 since 2021Security and privacy · 12 · 2 first-author · 9 since 2021Computer networks · 6 · 1 first-author · 5 since 2021Systems, architecture and hardware · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing
Weicheng Lin, Laile Xi, Yaowen Zheng, Shenghao Lin, Jiaxing Cheng, Zhen Wang 0043, Shizhao Tian, Tianheng Qu, Hongsong Zhu
INFOCOM3
2026 An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context Knowledge
Tianci Pan, Huan Qian, Yaowen Zheng, Haining Wang 0001, Peng Zhang 0044, Jiaxing Cheng, Ge Chu, Ke Li 0042, Ming Zhou 0010
INFOCOM3
2026 User-Space Dependency-Aware Rehosting for Linux-Based Firmware Binaries
Cen Zhang, Yaowen Zheng, Puzhuo Liu, Jian Zhang 0087, Yeting Li, Yang Liu 0003, Limin Sun 0001
NDSS3
2026 ADGFUZZ: Assignment Dependency-Guided Fuzzing for Robotic Vehicles
Yaowen Zheng, Puzhuo Liu, Dongliang Fang, Jiaxing Cheng, Dingyi Shi, Limin Sun 0001
NDSS2
2026 Be Responsible in Your Answers! Monitoring Out-of-Domain Behaviors in Domain-Specific LLMs
Boquan Li 0002, Chenzhe Lou, Zhe Ren, Peixin Zhang 0001, Zirui Fu, Jun Sun 0001, Yaowen Zheng
WWW7
2026 Breaking Cross-modal Alignment in Embodied Intelligence: A Multimodal Adversarial Attack Framework for Vision-Language-Action Models
abstract
Vision–Language–Action (VLA) models underpin robotic and other embodied agents by mapping visual observations and language instructions into executable actions. Their wide adoption through open web model repositories, however, introduces new supply-chain risks: adversaries can launch adversarial attacks to manipulate the action outputs of VLAs, potentially leading to harmful real-world outcomes for embodied agents. To exploit this vulnerability, we propose MAVLA, a novel multimodal adversarial attack framework. MAVLA serves as a modular front-end that integrates seamlessly with a target VLA model, injecting perturbations into task-relevant and structure-sensitive image regions to disrupt cross-modal alignment and induce deviations in the generated action instructions. To balance attack effectiveness with stealth, we design four loss functions that jointly maximize multimodal misalignment while preserving visual stealthiness. Extensive evaluations in simulated and real-world scenarios show that at a 40% perturbation ratio, the task success rate of VLAs drops by about 70%. Compared to conventional attack baselines, MAVLA achieves superior attack effectiveness and stealthiness with low overhead. Our work reveals a practical and previously underexplored threat to embodied systems, and offers a red-team baseline to inform future defensive strategies and promote safer VLA deployment.
Xiaorong Dong, Yaowen Zheng, Yimo Ren, Hangbei Cheng, Yongle Chen, Limin Sun 0001
WWW3
2026 Network Intrusion Detection System Based on Enhanced Dual Gaussian Mixture Variational Autoencoders for Internet of Vehicles
abstract
The Internet of Vehicles (IoV) is highly vulnerable to attacks due to its open communication environment, with new types of attacks continuously emerging. However, existing Network Intrusion Detection Systems (NIDS) often fall short in accuracy, recall rates, false positive rates, and they frequently prove ineffective in detecting new attacks. In this paper, we propose a NIDS for IoV based on Enhanced Dual Gaussian Mixture Variational Autoencoders (EDGMVAE) to detect various attack behaviors, including new attacks. We employ two separate Gaussian Mixture Variational Autoencoders (GMVAE) to conduct unsupervised reconstruction training on normal traffic and known attack traffic. During detection, we obtain the tested traffic’s reconstruction probabilities using these GMVAEs and determine whether an attack has occurred through logical fusion operation. We use two datasets for evaluation, i.e.,the Car Hacking Dataset (CHD) for in-vehicle communication and the UNSW-NB15 Dataset (UBD) for external network communication. The results demonstrate that our method achieves remarkable performance in detecting known attacks, with an accuracy rate of 98.54% on the CHD and 98.59% on the UBD. Moreover, it outperforms other state-of-the-art methods in detecting new attacks. Specifically, on the CHD, the accuracy of the method is 6.66% to 12.83% higher than other methods, while on the UBD, the accuracy is 5.13% to 21.91% higher than other methods.
Shizhao Tian, Yaowen Zheng, Laile Xi, Shenghao Lin, Hongsong Zhu
IEEE Trans. Intell. Transp. Syst.2
2026 OptRCA: A More Efficient and Accurate Approach for Automated Root Cause Analysis and Explanation
abstract
With the development of automated software testing technology, software developers can get a large number of crash test cases in a short period of time. However, analyzing these crash test cases and finding their root cause is a time-consuming and labor-intensive task. Techniques based on reverse execution and backward taint analysis are proposed to locate the root cause, but can’t provide context information or explanation of the underlying fault. To address these two limitations, researchers have proposed an automated root cause analysis technique called AURORA. Although this technique provides powerful root cause analysis capabilities, it also have two obvious shortcomings. First, the results of root cause analysis are not accurate enough. Second, the efficiency of root cause analysis is not high enough. In order to improve these two shortcomings, we propose OptRCA, a more efficient and accurate approach for root cause analysis and explanation. Like AURORA’s fuzzing strategy, OptRCA is also designed based on AFL’s crash mode. The difference between them is mainly reflected in three points. First of all, the goal pursued by OptRCA is different from that of normal fuzzing technology. OptRCA pursues maximum correlation to ensure that as many crash test cases as possible are related to the same root cause. This test case with maximum correlation can greatly improve the accuracy of root cause analysis. Second, OptRCA proposed a more efficient non-crash test case retention strategy, which we named “Hill-Climbing Retention.” Using the hill-climbing retention method, OptRCA can obtain sufficient root cause information while retaining only a few non-crash test cases. Since the number of test cases is greatly reduced, the efficiency of OptRCA’s subsequent root cause analysis process is also greatly improved. In addition, OptRCA also optimizes the analysis formula to obtain more accurate analysis results. In the evaluation experimental results, OptRCA is significantly better than AURORA in terms of accuracy and efficiency. Quantitative analysis shows that OptRCA is 65% more accurate and 61% more efficient than AURORA.
Jingquan Ge, Yaowen Zheng, Yuekang Li, Wei Ma 0014, Sheikh Mahbub Habib, Praveen Kakkolangara, Gabriel Byman, Yang Liu 0003
ACM Trans. Softw. Eng. Methodol.2
2025 ScenarioFuzz-LLM: Enhancing Diversity in Autonomous Driving Scenario Fuzzing with LLMs
abstract
As Autonomous Driving Systems (ADS) are increasingly deployed, ensuring their safety in edge cases becomes critical to preventing catastrophic failures. However, the limited ADS test scenario diversity often hinders the discovery of new defects, especially in complex and rare situations. This paper presents ScenarioFuzz- Llm,a novel method that leverages Large Language Models (LLMs) to enhance the diversity of ADS test scenarios. By incorporating LLMs into a genetic algorithm-based testing framework, ScenarioFuzz- Llmdirects the mutation to address diversity bottlenecks, thereby enabling the exploration of a broader range of edge cases. Our experiments demonstrate that ScenarioFuzz- Llmenhances the number of violation sce-narios by 10.51 % outperforming the state-of-the-art methods, and uncovers 24 unique defects in ADS, three of which are previously undiscovered. These results highlight the superiority of our approach in enhancing ADS testing through more diverse and comprehensive simulation scenarios, ultimately improving the safety of ADS.
Shenghao Lin, Fansong Chen, Laile Xi, Kaiyu Xie, Yaowen Zheng, Haiqiang Fei, Yuyan Sun, Hongsong Zhu
CSCWD5
2025 RoboClarify: Clarifying Ambiguous Instructions Through Scenario-Guided Risk Assessment for Home Embodied Agents
Yaowen Zheng, Yongle Chen, Limin Sun 0001
ICA3PP (4)3
2025 Lares: LLM-driven Code Slice Semantic Search for Patch Presence Testing
abstract
In modern software ecosystems, 1-day vulnerabilities pose significant security risks due to extensive code reuse. Identifying vulnerable functions in target binaries alone is insufficient; it is also crucial to determine whether these functions have been patched. Existing methods, however, suffer from limited usability and accuracy. They often depend on the compilation process to extract features, requiring substantial manual effort and failing for certain software. Moreover, they cannot reliably differentiate between code changes caused by patches or compilation variations.To overcome these limitations, we propose Lares, a scalable and accurate method for patch presence testing. Lares introduces Code Slice Semantic Search, which directly extracts features from the patch source code and identifies semantically equivalent code slices in the pseudocode of the target binary. By eliminating the need for the compilation process, Lares improves usability, while leveraging large language models (LLMs) for code analysis and SMT solvers for logical reasoning to enhance accuracy. Experimental results show that Lares achieves superior precision, recall, and usability. Furthermore, it is the first work to evaluate patch presence testing across optimization levels, architectures, and compilers. The datasets and source code used in this article are available at https://github.com/Siyuan-Li201/Lares.
Siyuan Li 0014, Yaowen Zheng, Hong Li 0004, Jingdong Guo, Chaopeng Dong, Chunpeng Yan, Weijie Wang 0005, Yimo Ren, Limin Sun 0001, Hongsong Zhu
ASE2
2025 Automated Flaw Detection for Industrial Robot RESTful Service
Puzhuo Liu, Yaowen Zheng, Dongliang Fang, Shuaizong Si, Zhiwen Pan, Limin Sun 0001
VMCAI (2)3
2025 ICSPFuzzer: An Efficient Fuzzing Technique for ICS Protocols
Zhanwei Song, Dongliang Fang, Shunchao Xu, Yaowen Zheng, Hong Li 0004, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
WASA (2)4
2025 Mission: Impossible - Image-Based Geolocation with Large Vision Language Models
abstract
In the age of ubiquitous smartphone use and widespread image sharing on social platforms, geolocation poses a critical privacy concern. Images often carry sensitive spatial and temporal details—such as street signs, architectural styles, or landmarks—that can inadvertently disclose the precise whereabouts of individuals and organizations. Recent advances in large vision-language models (LVLMs) present an emerging threat by enabling users, regardless of technical expertise, to extract location cues from seemingly benign photos. While existing AI-driven geolocation solutions often focus on narrow datasets or specialized contexts, the generalizable performance and privacy implications of zero-shot LVLMs in real-world settings remain critical questions. In this paper, we investigate the geolocation capabilities of state-of-the-art LVLMs. Our findings reveal that while these models demonstrate a non-negligible capability for image-based geolocation even without specialized training, their accuracy in absolute terms is often low, exposing clear limitations in their current state. We then introduce ETHAN, a framework integrating chain-of-thought (CoT) reasoning. Although ETHAN shows improved performance (e.g., 28.7% accuracy at the 1km threshold) and an 85.4% win rate on GeoGuessr, these results primarily highlight the potential trajectory of such technologies rather than their current widespread, high-accuracy applicability. Our study underscores the dual nature of LVLMs in this domain: they uncover an emerging privacy risk due to their inherent, albeit limited, geolocation abilities, yet also demonstrate significant constraints. We conclude by calling for further research into the limitations and risks of LVLM-based geolocation and the development of effective mitigation strategies to protect sensitive location data.
Yi Liu 0069, Gelei Deng, Junchen Ding, Yuekang Li, Tianwei Zhang 0004, Weisong Sun, Yaowen Zheng, Jingquan Ge
Proc. Priv. Enhancing Technol.7
2025 PREXP: Uncovering and Exploiting Security-Sensitive Objects in the Linux Kernel
abstract
Security-Sensitive Objects (SSOs) are often critical components in the exploitation of Linux kernel memory corruption vulnerabilities. While existing research has advanced SSOs identification and classification, there remains a significant gap in systematically understanding how these objects can be effectively exploited in real-world security analysis. To address this challenge, we present PREXP, a novel approach to analyzing SSOs exploitability and automating the transformation of Proof-of-Concept (PoC) into exploitable states. Our approach encompasses three key techniques: (1) capability analysis and attribute modeling of vulnerable object (2) extraction and filtering of target SSOs and (3) automatically augmenting PoCs with SSO-specific code to create exploitation capabilities. To evaluate our approach, we tested our prototype on 30 public CVEs, successfully parsing vulnerable object in 22 cases (73.3%) and achieving accurate SSO matches in 18 (60.0%). PREXP outperformed state-of-the-art tools such as SCAVY and AlphaEXP in structure-matching, and enabled the generation of new Control Flow Hijacking Primitives (CFHPs) for 3 previously unexploited vulnerabilities, demonstrating its practical value in real-world exploit development.
Zuxin Chen, Yaowen Zheng, Hong Li 0004, Siyuan Li 0014, Weijie Wang 0005, Dongliang Fang, Zhiqiang Shi, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.2
2025 Open Source AI-based SE Tools: Opportunities and Challenges of Collaborative Software Learning
abstract
Large language models (LLMs) have become instrumental in advancing software engineering (SE) tasks, showcasing their efficacy in code understanding and beyond. AI code models have demonstrated their value not only in code generation but also in defect detection, enhancing security measures and improving overall software quality. They are emerging as crucial tools for both software development and maintaining software quality. Like traditional SE tools, open source collaboration is key in realizing the excellent products. However, with AI models, the essential need is in data. The collaboration of these AI-based SE models hinges on maximizing the sources of high-quality data. However, data, especially of high quality, often hold commercial or sensitive value, making them less accessible for open source AI-based SE projects. This reality presents a significant barrier to the development and enhancement of AI-based SE tools within the SE community. Therefore, researchers need to find solutions for enabling open source AI-based SE models to tap into resources by different organizations. Addressing this challenge, our position article investigates one solution to facilitate access to diverse organizational resources for open source AI models, ensuring that privacy and commercial sensitivities are respected. We introduce a governance framework centered on federated learning (FL), designed to foster the joint development and maintenance of open source AI code models while safeguarding data privacy and security. Additionally, we present guidelines for developers on AI-based SE tool collaboration, covering data requirements, model architecture, updating strategies, and version control. Given the significant influence of data characteristics on FL, our research examines the effect of code data heterogeneity on FL performance. We consider six different scenarios of data distributions and include four code models. We also include four most common FL algorithms. Our experimental findings highlight the potential for employing FL in the collaborative development and maintenance of AI-based SE models. We also discuss the key issues to be addressed in the co-construction process and future research directions.
Wei Ma 0014, Tao Lin 0004, Yaowen Zheng, Jingquan Ge, Jun Wang 0020, Jacques Klein, Tegawendé F. Bissyandé, Yang Liu 0003, Li Li 0029
ACM Trans. Softw. Eng. Methodol.4
2025 LLM-Powered Static Binary Taint Analysis
abstract
This article proposes LATTE , the first static binary taint analysis that is powered by a large language model (LLM). LATTE is superior to the state of the art (e.g., Emtaint, Arbiter, Karonte) in three aspects. First, LATTE is fully automated while prior static binary taint analyzers need rely on human expertise to manually customize taint propagation rules and vulnerability inspection rules. Second, LATTE is significantly effective in vulnerability detection, demonstrated by our comprehensive evaluations. For example, LATTE has found 37 new bugs in real-world firmware, which the baselines failed to find. Moreover, 10 of them have been assigned CVE numbers. Lastly, LATTE incurs remarkably low engineering cost, making it a cost-efficient and scalable solution for security researchers and practitioners. We strongly believe that LATTE opens up a new direction to harness the recent advance in LLMs to improve vulnerability analysis for binary programs.
Puzhuo Liu, Chengnian Sun, Yaowen Zheng, Xuan Feng 0005, Zhi Li 0018, Peng Di, Yu Jiang 0001, Limin Sun 0001
ACM Trans. Softw. Eng. Methodol.3
2024 How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation
abstract
Fuzz drivers are essential for library API fuzzing. However, automatically generating fuzz drivers is a complex task, as it demands the creation of high-quality, correct, and robust API usage code. An LLM-based (Large Language Model) approach for generating fuzz drivers is a promising area of research. Unlike traditional program analysis-based generators, this text-based approach is more generalized and capable of harnessing a variety of API usage information, resulting in code that is friendly for human readers. However, there is still a lack of understanding regarding the fundamental issues on this direction, such as its effectiveness and potential challenges. To bridge this gap, we conducted the first in-depth study targeting the important issues of using LLMs to generate effective fuzz drivers. Our study features a curated dataset with 86 fuzz driver generation questions from 30 widely-used C projects. Six prompting strategies are designed and tested across five state-of-the-art LLMs with five different temperature settings. In total, our study evaluated 736,430 generated fuzz drivers, with 0.85 billion token costs ($8,000+ charged tokens). Additionally, we compared the LLM-generated drivers against those utilized in industry, conducting extensive fuzzing experiments (3.75 CPU-year). Our study uncovered that: 1) While LLM-based fuzz driver generation is a promising direction, it still encounters several obstacles towards practical applications; 2) LLMs face difficulties in generating effective fuzz drivers for APIs with intricate specifics. Three featured design choices of prompt strategies can be beneficial: issuing repeat queries, querying with examples, and employing an iterative querying process; 3) While LLM-generated drivers can yield fuzzing outcomes that are on par with those used in the industry, there are substantial opportunities for enhancement, such as extending contained API usage, or integrating semantic oracles to facilitate logical bug detection. Our insights have been implemented to improve the OSS-Fuzz-Gen project, facilitating practical fuzz driver generation in industry.
Cen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li, Wei Ma 0014, Xiaofei Xie, Yuekang Li, Limin Sun 0001, Yang Liu 0003
ISSTA2
2024 Medusa: Unveil Memory Exhaustion DoS Vulnerabilities in Protocol Implementations
abstract
Web services have brought great convenience to our daily lives. Meanwhile, they are vulnerable to Denial-of-Service (DoS) attacks. DoS attacks launched via vulnerabilities in the services can cause great harm. The vulnerabilities in protocol implementations are especially important because they are the keystones of web services. One vulnerable protocol implementation can affect all the web services built on top of it. Compared to the vulnerabilities that cause the target service to crash, resource exhaustion vulnerabilities are equally if not more important. This is because such vulnerabilities can deplete the system resources, leading to the unavailability of not only the vulnerable service but also other services running on the same machine. Despite the significance of this type of vulnerability, there has been limited research in this area.
Zhengjie Du, Yuekang Li, Yaowen Zheng, Cen Zhang, Yi Liu 0069, Sheikh Mahbub Habib, Xinghua Li 0001, Linzhang Wang, Yang Liu 0003, Bing Mao 0001
WWW3
2024 An empirical study of attack-related events in DeFi projects development
Dongming Xiang, Yuanchang Lin, Liming Nie, Yaowen Zheng, Zhengzi Xu, Zuohua Ding, Yang Liu 0003
Empir. Softw. Eng.4
2024 Battling against Protocol Fuzzing: Protecting Networked Embedded Devices from Dynamic Fuzzers
abstract
N etworked E mbedded D evices (NEDs) are increasingly targeted by cyberattacks, mainly due to their widespread use in our daily lives. Vulnerabilities in NEDs are the root causes of these cyberattacks. Although deployed NEDs go through thorough code audits, there can still be considerable exploitable vulnerabilities. Existing mitigation measures like code encryption and obfuscation adopted by vendors can resist static analysis on deployed NEDs, but are ineffective against protocol fuzzing. Attackers can easily apply protocol fuzzing to discover vulnerabilities and compromise deployed NEDs. Unfortunately, prior anti-fuzzing techniques are impractical as they significantly slow down NEDs, hampering NED availability. To address this issue, we propose Armor—the first anti-fuzzing technique specifically designed for NEDs. First, we design three adversarial primitives–delay, fake coverage, and forged exception–to break the fundamental mechanisms on which fuzzing relies to effectively find vulnerabilities. Second, based on our observation that inputs from normal users consistent with the protocol specification and certain program paths are rarely executed with normal inputs, we design static and dynamic strategies to decide whether to activate the adversarial primitives. Extensive evaluations show that Armor incurs negligible time overhead and effectively reduces the code coverage (e.g., line coverage by 22%-61%) for fuzzing, significantly outperforming the state of the art.
Puzhuo Liu, Yaowen Zheng, Chengnian Sun, Hong Li 0004, Zhi Li 0018, Limin Sun 0001
ACM Trans. Softw. Eng. Methodol.2
2023 FITS: Inferring Intermediate Taint Sources for Effective Vulnerability Analysis of IoT Device Firmware
abstract
Finding vulnerabilities in firmware is vital as any firmware vulnerability may lead to cyberattacks to the physical IoT devices. Taint analysis is one promising technique for finding firmware vulnerabilities thanks to its high coverage and scalability. However, sizable closed-source firmware makes it extremely difficult to analyze the complete data-flow paths from taint sources (i.e., interface library functions such as recv) to sinks.
Puzhuo Liu, Yaowen Zheng, Chengnian Sun, Dongliang Fang, Mingdong Liu, Limin Sun 0001
ASPLOS (4)2
2023 PumpChannel: An Efficient and Secure Communication Channel for Trusted Execution Environment on ARM-FPGA Embedded SoC
abstract
ARM TrustZone separates the system into the rich execution environment (REE) and the trusted execution environment (TEE). Data can be exchanged between REE and TEE through the communication channel, which is based on shared memory and can be accessed by both REE and TEE. Therefore, when the REE OS kernel is untrusted, the security of the communication channel cannot be guaranteed. The proposed schemes to protect the communication channel have high performance overhead and are not secure enough. In this paper, we propose PumpChannel, an efficient and secure communication channel implemented on ARM-FPGA embedded SoC. PumpChannel avoids the use of secret keys, but utilizes a hardware and software collaborative pump to enhance the security and performance of the communication channel. Besides, PumpChannel implements a hardware-based hook integrity monitor to ensure the integrity of all hook code. Security and performance evaluation results show that PumpChannel is more secure than the encrypted channel countermeasures and has better performance than all other evaluated schemes.
Jingquan Ge, Yuekang Li, Yang Liu 0003, Yaowen Zheng, Yi Liu 0069, Lida Zhao
DATE4
2023 Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias Analysis
abstract
Although the importance of using static taint analysis to detect taint-style vulnerabilities in Linux-based embedded firmware is widely recognized, existing approaches are plagued by following major limitations: (a) Existing works cannot properly handle indirect call on the path from attacker-controlled sources to security-sensitive sinks, resulting in lots of false negatives. (b) They employ heuristics to identify mediate taint source and it is not accurate enough, which leads to high false positives.
Yaowen Zheng, Le Guan, Peng Liu 0005, Hong Li 0004, Hongsong Zhu, Kejiang Ye, Limin Sun 0001
ISSTA2
2023 Automata-Guided Control-Flow-Sensitive Fuzz Driver Generation
Cen Zhang, Yuekang Li, Hao Zhou 0043, Yaowen Zheng, Xian Zhan, Xiaofei Xie, Xiapu Luo, Xinghua Li 0001, Yang Liu 0003, Sheikh Mahbub Habib
USENIX Security Symposium5
2023 UCRF: Static analyzing firmware to generate under-constrained seed for fuzzing SOHO router
Jiaqian Peng, Puzhuo Liu, Yaowen Zheng, Limin Sun 0001
Comput. Secur.4
2023 Automated GUI widgets classification
Kabir S. Said, Liming Nie, Yuanchang Lin, Yaowen Zheng, Zuohua Ding
Frontiers Comput. Sci.4
2023 A systematic mapping study for graphical user interface testing on mobile apps
abstract
Abstract Mobile apps with tested Graphical User Interface (GUI) tend to have higher downloads in the apps store. In recent years, few efforts were made to analyse the research community and research status of the literature for GUI testing on mobile apps, which brings an obstacle to characterise and understand this field. In this study, the authors propose a systematic mapping study to gain insights into the field. First, the authors conduct an extensive search of relevant literature over seven popular digital libraries. From 4427 candidate studies, 114 primary studies published between January 2011 and September 2022 were selected. Next, the authors analyse these primary studies from the perspectives of bibliometric and qualitative analysis. For the bibliometric analysis, first, the authors analyse the popular research topics and their relationships. Second, the authors study the authors' community. For the qualitative analysis, the authors analyse the objectives, approaches and evaluation metrics employed in these primary studies. Their investigation reports several major findings: (1) there are relatively more studies on two topics, that is, test case generation and the automated test; (2) the most productive authors tend to collaborate and often have relatively broad research interests; (3) the functionality is the main objective of GUI testing; the model‐based approach is the most widely used.
Liming Nie, Kabir S. Said, Lingfei Ma, Yaowen Zheng
IET Softw.4
2022 IPSpex: Enabling Efficient Fuzzing via Specification Extraction on ICS Protocol
Shichao Lv, Jianzhou You, Yuyan Sun, Xin Chen 0123, Yaowen Zheng, Limin Sun 0001
ACNS6
2022 Efficient greybox fuzzing of applications in Linux-based IoT devices via enhanced user-mode emulation
abstract
Greybox fuzzing has become one of the most effective vulnerability discovery techniques. However, greybox fuzzing techniques cannot be directly applied to applications in IoT devices. The main reason is that executing these applications highly relies on specific system environments and hardware. To execute the applications in Linux-based IoT devices, most existing fuzzing techniques use full-system emulation for the purpose of maximizing compatibility. However, compared with user-mode emulation, full-system emulation suffersfrom great overhead. Therefore, some previous works, such as Firm-AFL, propose to combine full-system emulation and user-mode emulation to speed up the fuzzing process. Despite the attempts of trying to shift the application towards user-mode emulation, no existing technique supports to execute these applications fully in the user-mode emulation. To address this issue, we propose EQUAFL, which can automatically set up the execution environment to execute embedded applications under user-mode emulation. EQUAFL first executes the application under full-system emulation and observe for the key points where the program may get stuck or even crash during user-mode emulation. With the observed information, EQUAFL can migrate the needed environment for user-mode emulation. Then, EQUAFL uses an enhanced user-mode emulation to replay system calls of network, and resource management behaviors to fulfill the needs of the embedded application during its execution. We evaluate EQUAFL on 70 network applications from different series of IoT devices. The result shows EQUAFL outperforms the state-of-the-arts in fuzzing efficiency (on average, 26 times faster than AFL-QEMU with full-system emulation, 14 times than Firm-AFL). We have also discovered ten vulnerabilities including six CVEs from the tested firmware images.
Yaowen Zheng, Yuekang Li, Cen Zhang, Hongsong Zhu, Yang Liu 0003, Limin Sun 0001
ISSTA1
2022 Inferring Device Interactions for Attack Path Discovery in Smart Home IoT
Mengjie Sun, Ke Li 0042, Yaowen Zheng, Hong Li 0004, Limin Sun 0001
WASA (1)3
2022 Fuzzing proprietary protocols of programmable controllers to find vulnerabilities that affect physical control
Puzhuo Liu, Yaowen Zheng, Zhanwei Song, Dongliang Fang, Shichao Lv, Limin Sun 0001
J. Syst. Archit.2
2021 ICS3Fuzzer: A Framework for Discovering Protocol Implementation Bugs in ICS Supervisory Software by Fuzzing
abstract
The supervisory software is widely used in industrial control systems (ICSs) to manage field devices such as PLC controllers. Once compromised, it could be misused to control or manipulate these physical devices maliciously, endangering manufacturing process or even human lives. Therefore, extensive security testing of supervisory software is crucial for the safe operation of ICS. However, fuzzing ICS supervisory software is challenging due to the prevalent use of proprietary protocols. Without the knowledge of the program states and packet formats, it is difficult to enter the deep states for effective fuzzing.
Dongliang Fang, Zhanwei Song, Le Guan, Puzhuo Liu, Anni Peng, Yaowen Zheng, Peng Liu 0005, Hongsong Zhu, Limin Sun 0001
ACSAC7
2021 Automatic Inference of Taint Sources to Discover Vulnerabilities in SOHO Router Firmware
Dongliang Fang, Huizhao Wang, Yaowen Zheng, Limin Sun 0001
SEC5
2021 Reviewing IoT Security via Logic Bugs in IoT Platforms and Systems
abstract
In recent years, Internet-of-Things (IoT) platforms and systems have been rapidly emerging. Although IoT is a new technology, new does not mean simpler (than existing networked systems). Contrarily, the complexity (of IoT platforms and systems) is actually being increased in terms of the interactions between the physical world and cyberspace. The increased complexity indeed results in new vulnerabilities. This article seeks to provide a review of the recently discovered logic bugs that are specific to IoT platforms and systems and discuss the lessons we learned from these bugs. In particular, 20 logic bugs and one weakness falling into seven categories of vulnerabilities are reviewed in this survey.
Wei Zhou 0026, Chen Cao 0004, Dongdong Huo, Lan Zhang 0008, Le Guan, Yan Jia 0009, Yaowen Zheng, Yuqing Zhang 0001, Limin Sun 0001, Yazhe Wang, Peng Liu 0005
IEEE Internet Things J.9
2019 An Efficient Greybox Fuzzing Scheme for Linux-based IoT Programs Through Binary Static Analysis
abstract
With the rapid growth of Linux-based IoT devices such as network cameras and routers, the security becomes a concern and many attacks utilize vulnerabilities to compromise the devices. It is crucial for researchers to find vulnerabilities in IoT systems before attackers. Fuzzing is an effective vulnerability discovery technique for traditional desktop programs, but could not be directly applied to Linux-based IoT programs due to the special execution environment requirement. In our paper, we propose an efficient greybox fuzzing scheme for Linux-based IoT programs which consist of two phases: binary static analysis and IoT program greybox fuzzing. The binary static analysis is to help generate useful inputs for efficient fuzzing. The IoT program greybox fuzzing is to reinforce the IoT firmware kernel greybox fuzzer to support IoT programs. We implement a prototype system and the evaluation results indicate that our system could automatically find vulnerabilities in real-world Linux-based IoT programs efficiently.
Yaowen Zheng, Zhanwei Song, Yuyan Sun, Hongsong Zhu, Limin Sun 0001
IPCCC1
2019 FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process Emulation
Yaowen Zheng, Ali Davanian, Heng Yin 0001, Chengyu Song, Hongsong Zhu, Limin Sun 0001
USENIX Security Symposium1
2018 DTaint: Detecting the Taint-Style Vulnerability in Embedded Device Firmware
abstract
A rising number of embedded devices are reachable in the cyberspace, such as routers, cameras, printers, etc. Those devices usually run firmware whose code is proprietary with few public documents. Furthermore, most of the firmware images cannot be analyzed in dynamic analysis due to various hardware-specific peripherals. As a result, it hinders traditional static analysis and dynamic analysis techniques. In this paper, we propose a static binary analysis approach, DTaint, to detect taint-style vulnerabilities in the firmware. The taint-style vulnerability is a typical class of weakness, where the input data reaches a sensitive sink through an unsafe path. Specifically, we generate data dependency in a bottom-up manner through traversing callees before callers. To reduce the influence of the binary firmware, DTaint identifies pointer aliasing, interprocedural data flow, and similarity of the data structure layout. We have implemented a prototype of DTaint and conducted experiments to evaluate its performance. Our results show that DTaint discovers more vulnerabilities in less time, compared with the existing techniques. Furthermore, we illustrate the effectiveness of DTaint through applying it over six firmware images from four manufacturers. We have found 21 vulnerabilities, where 13 of them are previously-unknown and zero-day vulnerabilities.
Qiang Li 0007, Yaowen Zheng, Limin Sun 0001, Zhenkai Liang
DSN5
2016 A Lightweight Method for Accelerating Discovery of Taint-Style Vulnerabilities in Embedded Systems
Yaowen Zheng, Zhi Li 0018, Shiran Pan, Hongsong Zhu, Limin Sun 0001
ICICS1