EDBT 2026 Demo / reviewers in the wild / expert
Chenke Luo
dblp:204/8454
· DBLP profile ↗
7ranked-venue papers
3as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Beyond Tag Collision: Cluster-based Memory Management for Tag-based Sanitizers
Mengfei Xie, Yan Lin 0003, Jianming Fu, Chenke Luo, Guojun Peng |
CCS | 5 |
| 2025 | Retrofitting XoM for Stripped Binaries without Embedded Data Relocation
Chenke Luo, Jiang Ming 0002, Mengfei Xie, Guojun Peng, Jianming Fu |
NDSS | 1 |
| 2025 | MemoryTrap: Booby Trapping Memory to Counter Memory Disclosure Attacks with Hardware Support
Chenke Luo, Jiang Ming 0002, Dongpeng Xu 0001, Guojun Peng, Jianming Fu |
USENIX ATC | 1 |
| 2025 | Egalitarian Randomization for Multi-Language Applications on ARM64abstractDue to the inevitable information loss during IR lowering, compile-time metadata collection can provide more precise auxiliary information than binary analysis to achieve reliable fine-grained randomization. However, existing schemes build on deep modifications of compilers, making it challenging to provide consistent randomization protection for different high-level languages. Additionally, they are inadequate for securing widely used smartphones and embedded devices, since only ×86-64 applications are currently supported. In this paper, we present MLARandom, a compiler-assisted function-level randomization scheme designed for Multi-Language ARM64 applications. MLARandom employs a lightweight compilation standardization strategy that allows for uniform information collection at the assembly level, regardless of the high-level language or compiler used. Further, it combines ARM64 architecture specifications and collected relocation types to accurately repair all ARM64 pointers after randomization. Our experimental results show that MLARandom can equally randomize modules developed in different languages (e.g., C/C++, Rust, Fortran, Cangjie) with negligible runtime overhead (0.51%), to effectively counter against traditional Code Reuse Attacks as well as advanced Cross-Language Attacks. Although randomization approaches based on reassembly can achieve similar goals, our empirical evaluation highlights the imprecise pointer identification as a major obstacle to their practical deployment. Mengfei Xie, Yan Lin 0003, Jianming Fu, Chenke Luo, Guojun Peng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | PointerScope: Understanding Pointer Patching for Code RandomizationabstractVarious fine-grained randomization schemes have been designed to increase the entropy of process space, while none of them can rise from an academic exercise to industrial deployment like Address Space Layout Randomization (ASLR). One of the critical reasons is the incorrectness of randomization caused by the mismatch between their pointer collection capabilities and the high accuracy requirements of the pointer patching task. In this article, we present PointerScope, an accurate compile-time pointer collection scheme deriving from a group of novel observations. The success of PointerScope relies on the complete tracing of the pointer generation process, including the compilation chain from compiler to static linker and the interface specification between them. From this view, PointerScope identifies four types of pointer-related static linker behaviors and clarifies five types of inherent addressing modes in the x86-64 architecture. The vague understanding of them causes the Compiler-assisted Code Randomization (CCR) to incorrectly collect pointers and patch them to the wrong values after randomization. Further, we measure the pointer collection capability of augmented binary analysis, the experimental results show that they can mitigate challenges from the traditional binary analysis by the given premises, but additional heuristics still need to be designed to support the fine-grained randomization. Mengfei Xie, Yan Lin 0003, Chenke Luo, Guojun Peng, Jianming Fu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Reverse Engineering of Obfuscated Lua Bytecode via Interpreter Semantics TestingabstractAs an efficient and multi-platform scripting language, Lua is gaining increasing popularity in the industry. Unfortunately, Lua’s unique advantages also catch cybercriminals’ attention. A growing number of IoT malware authors switch to Lua for malicious payload development and then distribute malware in bytecode form. To impede malware code analysis, malware authors obfuscate standard Lua bytecode into a customized bytecode specification. Only the attached interpreter can execute that particular bytecode file. Rapid recovery of Lua obfuscated bytecode is essential for a swift response to new malware threats. However, existing generic code deobfuscation approaches cannot keep up with the pace of emerging threats. In this paper, we present a novel reverse engineering technique, calledinterpreter semantics testing. Given a customized interpreter used to execute obfuscated Lua bytecode, we construct a set ofLuaGadgetsthat can adapt to the customized interpreter. Each LuaGadget contains a carefully chosen opcode sequence to fulfill an observable calculation—it is designed to test one or two particular opcodes at a time. Next, we mutate unknown opcode values to generate a bunch of test cases and run them using the customized interpreter; we can observe the expected result only when the mutation hits the opcode’s right value. We perform test case prioritization to cost-effectively recover the semantics of all obfuscated opcodes. Our approach makes no assumptions about the interpreter’s structure and is free from analyzing the numerous execution traces of opcode handlers. We have evaluated our tool,LuaHunt, with Lua malware variants and real-world applications. LuaHunt is able to recover the obfuscated bytecode’s semantics within 90 seconds for each test case, and all of our deobfuscation results can pass the correctness testing. The encouraging results demonstrate that LuaHunt is a promising tool to lighten the burden of security analysts. Chenke Luo, Jiang Ming 0002, Jianming Fu, Guojun Peng, Zhetao Li |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | JTaint: Finding Privacy-Leakage in Chrome Extensions
Mengfei Xie, Jianming Fu, Chenke Luo, Guojun Peng |
ACISP | 4 |