EDBT 2026 Demo / reviewers in the wild / expert
Bingyu Shen 0002
dblp:190/3392-2
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2024
0000-0001-5518-3594ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Effective Bug Detection with Unused DefinitionsabstractUnused definitions are values assigned to variables but not used. Since unused definitions are usually considered redundant code causing no severe consequences except for wasting CPU cycles, system developers usually treat them as mild warnings and simply remove them. In this paper, we reevaluate the effect of unused definitions and discover that some unused definitions could indicate non-trivial bugs like security issues or data corruption, which calls for more attention from developers. Chengcheng Xiang, Haochen Huang, Bingyu Shen 0002, Eric Mugnier, Yuanyuan Zhou 0001 |
EuroSys | 4 |
| 2023 | Protecting Data Integrity of Web Applications with Database Constraints Inferred from Application CodeabstractDatabase-backed web applications persist a large amount of production data and have high requirements for integrity. To protect data integrity against application code bugs and operator mistakes, most RDBMSes allow application developers to specify various types of integrity constraints. Unfortunately, applications (e.g., e-commerce web apps) often do not take full advantage of this capability and miss specifying many database constraints, resulting in many severe consequences, such as crashing the order placement page and corrupting the store inventory data. Haochen Huang, Bingyu Shen 0002, Yuanyuan Zhou 0001 |
ASPLOS (2) | 2 |
| 2023 | Improving Logging to Reduce Permission Over-Granting Mistakes
Bingyu Shen 0002, Tianyi Shan, Yuanyuan Zhou 0001 |
USENIX Security Symposium | 1 |
| 2023 | Multiview: Finding Blind Spots in Access-Deny Issues Diagnosis
Bingyu Shen 0002, Tianyi Shan, Yuanyuan Zhou 0001 |
USENIX Security Symposium | 1 |
| 2021 | Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission Model
Bingyu Shen 0002, Chengcheng Xiang, Yudong Wu, Mingyao Shen, Yuanyuan Zhou 0001, Xinxin Jin |
USENIX Security Symposium | 1 |
| 2019 | Towards Continuous Access Control Validation and ForensicsabstractAccess control is often reported to be "profoundly broken" in real-world practices due to prevalent policy misconfigurations introduced by system administrators (sysadmins). Given the dynamics of resource and data sharing, access control policies need to be continuously updated. Unfortunately, to err is human-sysadmins often make mistakes such as over-granting privileges when changing access control policies. With today's limited tooling support for continuous validation, such mistakes can stay unnoticed for a long time until eventually being exploited by attackers, causing catastrophic security incidents. We present P-DIFF, a practical tool for monitoring access control behavior to help sysadmins early detect unintended access control policy changes and perform postmortem forensic analysis upon security attacks. P-DIFF continuously monitors access logs and infers access control policies from them. To handle the challenge of policy evolution, we devise a novel time-changing decision tree to effectively represent access control policy changes, coupled with a new learning algorithm to infer the tree from access logs. P-DIFF provides sysadmins with the inferred policies and detected changes to assist the following two tasks: (1) validating whether the access control changes are intended or not; (2) pinpointing the historical changes responsible for a given security attack. We evaluate P-DIFF with a variety of datasets collected from five real-world systems, including two from industrial companies. P-DIFF can detect 86%-100% of access control policy changes with an average precision of 89%. For forensic analysis, P-DIFF can pinpoint the root-cause change that permits the target access in 85%-98% of the evaluated cases. Chengcheng Xiang, Yudong Wu, Bingyu Shen 0002, Mingyao Shen, Haochen Huang, Tianyin Xu, Yuanyuan Zhou 0001, Cindy Moore, Xinxin Jin, Tianwei Sheng |
CCS | 3 |
| 2017 | Offloading in HCNs: Congestion-Aware Network Selection and User Incentive DesignabstractTo accommodate exponentially increasing traffic demands, operators are seeking to offload cellular traffic to small base stations (BSs) in heterogeneous cellular networks (HCNs), which is promising in alleviating traffic congestion. In HCNs, operators are eager to balance the traffic globally, where users may be pushed to less preferred small BSs, resulting in possible conflict with user local preference. Thus, it is a big challenge to achieve dynamic load balancing for operators and provide participation incentive for users simultaneously. Due to the dynamics of network state and user traffic demand, we are inspired to utilize Lyapunov optimization to develop a congestion-aware cellular offloading scheme. Specifically, an operator profit maximization problem involving network selection and rate control is formulated. To achieve long-term network stability, we propose a congestion-aware network selection algorithm, obtaining the BS alternative set that maintains traffic congestion constraint. By exploring the heterogeneity of user quality sensitivity, we devise the optimal quality-price contract, which maximizes operator profit. With effective pricing and resource allocation, users are motivated to make proper association strategy chosen from the BS alternative set. Simulation results demonstrate the effectiveness of our scheme in improving operator profit. User incentive and network stability are also validated. Yuqing Li 0001, Bingyu Shen 0002, Jinbei Zhang, Xiaoying Gan, Xinbing Wang |
IEEE Trans. Wirel. Commun. | 2 |