Zhongru Wang

dblp:220/5388 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
5since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 CrossGuard: Runtime-Adaptive LLM Fuzzing for Cross-Contract Vulnerabilities Detection
abstract
ABSTRACT Smart contract transactions are increasingly interspersed with cross‐contract calls, creating intricate vulnerabilities that current tools frequently neglect. Cross‐contract vulnerabilities, stemming from interactions among many contracts, are notably difficult to identify, as existing methodologies are restricted to the analysis of only two contracts simultaneously. The growing number of transaction sequences and the larger area to search due to multiple contracts working together make it very hard to find these vulnerabilities. Traditional fuzzing methods are good at finding simple errors within a single contract, but they struggle to detect problems that come from complex interactions between multiple contracts, such as how they call each other and depend on each other's states. This work presents CrossGuard, a fuzz testing‐based approach aimed at effectively identifying cross‐contract vulnerabilities by addressing the shortcomings of conventional tools. Instead of using random transaction sequences like earlier fuzzers, CrossGuard uses smart fuzzing that learns from large language models (LLMs) to better explore important paths. We evaluate CrossGuard against top tools like CrossFuzz and xFuzz using 500 cross‐contracts that have vulnerabilities such as reentrancy, integer overflow, and block dependency. CrossGuard consistently achieves higher coverage and excels at detecting reentrancy and block dependency vulnerabilities. However, its performance on integer overflow detection is currently lower than that of CrossFuzz; this contrast underscores both the potential and the current limitations of LLM‐guided fuzzing. Natural language reasoning is highly effective for path‐sensitive, stateful vulnerabilities, but less precise for numeric edge cases where mutational fuzzing remains strong.
Ghazi Mergani Ahmead Ali, Hongsong Chen, Zhongru Wang, Chunlai Du
Concurr. Comput. Pract. Exp.3
2023 Framework for understanding intention-unbreakable malware
Tiantian Ji, Binxing Fang, Xiang Cui, Zhongru Wang, Shouyou Song
Sci. China Inf. Sci.4
2023 Intrusion Detection and Network Information Security Based on Deep Learning Algorithm in Urban Rail Transit Management System
abstract
The exploration of the intrusion detection effect of urban rail transit management system aims to further improve the safety performance of the traffic field in urban construction. Thus, the deep convolution neural network model AlexNet with more network layers and stronger learning ability is adopted and improved, to ensure the safe operation of urban rail transit. Meanwhile, the GRU (Gate Recurrent Unit) neural network is introduced into the improved AlexNet to build an intrusion detection model of urban rail transit management system. Finally, the model performance is verified through the collected data and simulation experiments. Through the comparative analysis of the model and other scholars’ models in related fields, the recognition accuracy of intrusion detection of the intrusion detection model reaches 96.00%, which is at least 1.55% higher than that of other neural network models. Besides, its training time is stable at about 55.05 seconds, and the test time is stable at about 22.17 seconds. Moreover, the analysis result of data transmission security performance indicates that the data message delivery rate of this model is more than 80%, the data message leakage rate and packet loss rate are less than 10%, and the average delay is basically stable at about 350 milliseconds. Therefore, the constructed model can achieve high data transmission security performance under the premise of ensuring prediction accuracy, which can provide experimental basis for improving the safety performance of rail transit systems in smart cities.
Zhongru Wang, Xinzhou Xie, Shouyou Song
IEEE Trans. Intell. Transp. Syst.1
2022 From Passive to Active: Near-optimal DNS-based Data Exfiltration Defense Method Based on Sticky Mechanism
abstract
DNS-based data exfiltration has become increasingly popular among advanced persistent threat (APT) attackers owing to the ubiquity and penetrability of the DNS protocol. AI-powered methods solve the defect that attackers can easily bypass because of the fixed threshold and weight in rule matching while still suffer from several issues. Such as the lack of malware samples for training, the amplified impact of even low FPR present enormous obstacles to applying the model in real-world detection.We present a method to generate malicious traffic covering an extensive sample space based on Tactics, Techniques, and Procedures (TTPs). We then propose a sticky mechanism, which transforms certain decision-making into dynamic human-computer interaction decision-making, to verify the suspicious hosts recognized by the AI model. The experimental results demonstrate the superiority of our model by identifying eight kinds of real attacks precisely. The good performance on real-world traffic shows our method is a solid foothold for applying AI-powered detection to practical applications.
Jiawen Diao, Binxing Fang, Xiang Cui, Zhongru Wang, Shouyou Song
TrustCom4
2021 Multi-level Directed Fuzzing for Detecting Use-after-Free Vulnerabilities
abstract
Greybox fuzzing has been widely used in vulnerabilities detection. Most greybox fuzzing tools are coverage-based, which usually use basic block transition to gain code coverage and focus on improving it to trigger more bugs. However, only increasing code coverage is insufficient to find some heap-based vulnerabilities such as use-after-free (UAF) and double-free (DF). This is because, to trigger these vulnerabilities, one needs not only to cover more code, but also to execute special heap operations to satisfy a particular temporal constraint (i.e., allocating heap memory, free memory, and accessing the heap memory). In this paper, we propose an approach, namely MDFuzz, to detect heap-based vulnerabilities adopting multi-level directed greybox fuzzing. The key idea is identifying different targets to guide the fuzzing process to cover specific heap operations without wasting resources exploring unrelated program components. We first perform a static analysis to automatically recognize three critical targets related to heap operations and then calculate each basic block's distance to the targets. Moreover, we propose a probability-based multi-level seed queue and a novel seed selection strategy to augment the guidance of directed fuzzing. To evaluate MDFuzz, we have performed an evaluation on 7 real-world applications. The experimental results demonstrate that MDFuzz significantly outperforms the state-of-the-art fuzzers, including AFL, AFLFast and VUzzer, in terms of the time consumed to discover heap-based vulnerabilities. Moreover, MD-Fuzz found 4 previously unknown vulnerabilities in real-world programs.
Zhongru Wang, Weiqiang Yu, Binxing Fang
TrustCom2
2020 AFLPro: Direction sensitive fuzzing
Tiantian Ji, Zhongru Wang, Zhihong Tian 0001, Binxing Fang, Qiang Ruan, Haichen Wang, Wei Shi 0001
J. Inf. Secur. Appl.2
2019 Correction to: Application of combined kernel function artificial intelligence algorithm in mobile communication network security authentication mechanism
Zhongru Wang, Binxing Fang
J. Supercomput.1