EDBT 2026 Demo / reviewers in the wild / expert
Jiongyi Chen
dblp:224/2480
· DBLP profile ↗
26ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0003-0776-4073ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 3 first-author · 13 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LASGen: Synergistic Harness-Seed Co-Synthesis for High-Coverage Library FuzzingabstractLibrary fuzzing is essential for identifying vulnerabilities in software libraries. However, achieving high coverage remains challenging due to the difficulty of generating effective harness and seed inputs. We present LASGen, an automated framework that integrates static analysis and large language models (LLMs) to generate high-quality fuzzing inputs for arbitrary library functions. LASGen generates coupled harnesses and initial seeds, treating them as a unified task rather than separate steps. This design ensures the seeds are highly compatible with the harness, enabling deeper path exploration. To achieve this, LASGen extracts function-level context via slicing and data-flow analysis, then embeds it into structured prompts to guide LLMs during synthesis, ensuring that the outputs are valid. LASGen also incorporates a self-repair mechanism and seed validation loop to ensure correctness and effectiveness. Experiments on 11 libraries with 127 known vulnerabilities show that LASGen achieves 77.17% vulnerability coverage and 55.61% edge coverage, outperforming state-of-the-art fuzzers while maintaining a lower false-positive rate. When applied to 17 real-world libraries, LASGen discovered 33 previously unknown vulnerabilities, 26 of which have been confirmed and patched, including eight assigned CNVD IDs. Yujie Xing, Jiongyi Chen, Wenrui Diao |
AsiaCCS | 3 |
| 2026 | OSmartPro: a large language model-assisted option fuzzing approachabstractAbstract Program options provide flexible software functionality control but complicate fuzz testing, as triggering many behaviors require specific option combinations. Although existing option-aware fuzzing approaches attempt to mutate options as inputs or leverage AI technologies to extract option relationships from documentation, these methods have limitations. Documentation is often incomplete, and some option dependencies are embedded deeply within program logic via data or control flows, making these methods challenging to detect all possible dependencies. This paper introduces OSmartPro , an advanced option-fuzzing approach that directly extracts options and infers option dependencies from source code. Given LLM’s capabilities to interpret program semantics, OSmartPro employs LLM-assisted static analysis to handle diverse option-parsing structures and extract comprehensive options. Through control and data dependency analysis, it constructs option impact graph , which it uses to guide fuzzing strategies. The tool successfully extracted complete options from all 59 programs in our test set, uncovering undocumented options in over 66% of them. Additionally, OSmartPro inferred 14,701 option combinations, identified 45.03% more execution paths compared to AFL++, and uncovered 54 zero-day vulnerabilities, of which 18 awarded CVE IDs. Lastly, in a benchmark comparison against four option-aware fuzzers, OSmartPro achieved higher line coverage in 66.7% (20 out of 30) of the programs. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Jiongyi Chen, Yan Cai 0001, Chao Feng 0002, Chaojing Tang, Guojun Peng |
Cybersecur. | 6 |
| 2025 | FirmProj: Detecting Firmware Leakage in IoT Update Processes via Companion App AnalysisabstractThe rapid growth of the Internet of Things (IoT) has led to the widespread use of companion apps for device management. However, these apps expose a critical vulnerability in the IoT ecosystem: insufficient verification procedures during device firmware updates (DFU), often resulting in firmware leakage. Once leaked, the firmware reveals sensitive design details, creating a straightforward path for attackers to reverse-engineer devices. To address this issue, we designed an automated analysis tool called FirmProj. It systematically evaluates firmware leakage risks by examining IoT companion apps. FirmProj combines advanced static analysis techniques with large language models to identify DFU modules, extract firmware files, and detect security vulnerabilities. In a large-scale study involving 10,047 IoT companion apps, FirmProj successfully retrieved 3,434 firmware files, uncovering severe flaws in DFU implementations that can lead to firmware leakage. These findings resulted in the assignment of 35 CVE IDs. Our results highlight the urgent need to strengthen firmware protection mechanisms throughout the IoT ecosystem. Wenzhi Li, Jialong Guo, Jiongyi Chen, Yujie Xing, Yanbo Xu, Shishuai Yang, Wenrui Diao |
ASE | 3 |
| 2025 | Chat4seed: Semantic-Awareness Highly Structured Seed Generation for FuzzingabstractFuzzing, one of the most popular methods for enhancing software security and quality, relies heavily on the quality of its initial seed corpus to effectively uncover vulnerabilities. Traditional methods for generating initial seed corpora, whether crawl-based or generation-based, struggle with programs that handle highly structured formats with complex semantics, leading to low testing coverage and reduced fuzzer effectiveness. Although researchers have proposed leveraging Large Language Models (LLMs) to create high-quality seed corpora, current approaches are limited to text-based seed files, such as JavaScript code. To address the limitations, we propose Chat4Seed, a novel approach that extends the capabilities of LLMs to produce not only text but also highly-structured binary seed files. Chat4Seed leverages LLMs to extract and interpret the semantic constraints embedded within formatspecific branches of programs. While existing approaches focus solely on generating text-based seeds, Chat4Seed goes further by utilizing LLMs to generate functional library invocation code to produce binary seeds. It also employs binarylevel manipulation to handle unsupported corner cases, achieving robust seed generation for both text and binary formats. Our experiments and evaluations on 12 real-world programs demonstrate that after 48 hours of fuzz testing using AFL++, the seed corpus generated by Chat4Seed achieves an average increase in coverage of 28.78% compared to traditional crawl-based methods and 39.98% compared to generation-based methods. Additionally, it facilitates the discovery of 84.24% and 392.7% more crashes than seed corpus generated by traditional approaches, respectively, underscoring the potential of Chat4Seed to enhance the efficacy of fuzzing. Jiarui Chen, Jiongyi Chen, Runhao Li, Chaojing Tang |
QRS | 3 |
| 2025 | FirmPass: Identifying Broken Password Management in Linux-Based IoT Firmware Through Query-Driven ApproachesabstractPassword management is a fundamental aspect of security for Internet of Things (IoT) devices. However, despite the availability of established guidelines and best practices, the implementation of password management in IoT firmware often falls short, leading to vulnerabilities and potential breaches. Because of the lack of automated tools, the severity and pervasiveness of broken password management of IoT firmware has been less understood. In this paper, we present FIRMPASS, a new tool to identify broken password management of Linuxbased IoT firmware. Particularly, we establish general password management models for Linux-based IoT devices based on password management processes and related vulnerabilities. To automatically identify the vulnerabilities, FIRMPASS employs a query-driven approach to locate the firmware that violate the properties of correct password management. Specifically, we manually define four rules that should be complied with, encode the rules with queries, and check the queries in the firmware, which leads to the discovery of four types of vulnerabilities. Evaluation of 615 IoT firmware images uncovers 67 vulnerabilities, including 37 previously unknown issues. Our work underscores the urgent need for assessment solutions for IoT firmware. Jiongyi Chen, Zheng Qin 0001, Yupeng Hu 0004 |
IEEE Internet Things J. | 2 |
| 2025 | CGIFuzz: Enabling Gray-Box Fuzzing for Web CGI of IoT DevicesabstractFuzz testing for Internet of Things (IoT) devices has become a critical area of research, as these devices play an increasingly vital role in modern networks and infrastructure. While significant efforts have been made, the Common Gateway Interface (CGI) programs that serve as an important component within these devices remain underexplored. Despite their extensive use in IoT web services, the specific characteristics of CGI programs have posed technical challenges to existing fuzzing infrastructures. To address these gaps, we propose CGIFuzz, the first gray-box fuzzing framework tailored for CGI programs in Linux-based IoT devices. CGIFuzz initially enables dynamic instrumentation of CGI programs throughRelay-Pass Instrumentation, then leverages Large Language Models (LLM) for assisting high-quality fuzz test input generation. Furthermore, CGIFuzz devises oracles for detecting command injection and memory corruption vulnerabilities by leveraging multiple critical features during program execution. Our evaluation of CGIFuzz on ten popular IoT devices demonstrates superior coverage exploration and vulnerability detection capabilities compared to the state-of-the-art fuzzers. Notably, CGIFuzz discovered 69 vulnerabilities, including 13 previously unknown ones for which 9 CVEs were assigned. Jiongchi Yu, Ziming Zhao 0008, Jiongyi Chen, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | OSmart: Whitebox Program Option FuzzingabstractProgram options are ubiquitous and serve as a fundamental mechanism for configuring and customizing software behaviors. Given their widespread use, testing program options becomes essential to ensure that the software behaves as expected across various configurations. Existing option-aware fuzzers either mutate options as if they were standard program inputs or employ NLP techniques to deduce relationships among options from the documentation. However, there has not been a whitebox approach that generates option combinations by capturing the inherent execution logic of the program. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Yan Cai 0001, Jiongyi Chen, Chao Feng 0002, Chaojing Tang |
CCS | 6 |
| 2024 | LiftFuzz: Validating Binary Lifters through Context-aware Fuzzing with GPTabstractAnalyzing binary code is vital for software engineering and security research, particularly when the source code is unavailable. However, understanding, modifying, and retargeting binary code can be complex tasks. To counter these difficulties, binary lifters have been introduced. These tools translate binary code into Intermediate Representations (IRs), providing several advantages, such as enabling modifications to executables without source code and facilitating code retargetability. So far, accurately developing binary lifters for modern ISAs is universally acknowledged as challenging and error-prone. Existing validation methods mainly concentrate on isolated instructions, overlooking interactions among instructions. In this paper, we introduce LiftFuzz, a novel framework that leverages instruction context-aware fuzzing to validate binary lifters. LiftFuzz harnesses an assembly language model to learn interactions among instructions and generates test cases with the knowledge. LiftFuzz greatly outperforms the baseline, requiring only 1/1000 of the test cases used by the baseline to identify 26 inconsistencies, including a previously uncovered category. LiftFuzz significantly contributes to enhancing the performance of binary lifters, which are frequently employed in binary security applications. Zirui Song, Ke Zhang 0039, Jiongyi Chen, Kehuan Zhang |
CCS | 5 |
| 2024 | FIRMRES: Exposing Broken Device-Cloud Access Control in IoT Through Static Firmware AnalysisabstractDevice-cloud interfaces are a critical component of IoT given their centrality of the cloud-side control over the connected devices, which has attracted an increasing number of attacks exploiting their access control. Regrettably, there is a lack of techniques to facilitate the examination of such a critical interface, primarily hindered by the challenges of dynamic firmware analysis to reconstruct device-cloud messages and generate testing cues. This paper presents FIRMRES, a principled static approach that automatically reconstructs device-cloud messages by modeling message construction semantics in IoT firmware. At the center of FIRMRES is a message field tree which is formed of the backward data flows from message delivery callsites to the potential sources of message fields. By walking through, transforming, and contextual learning from this tree, device-cloud messages are automatically reconstructed and a set of semantics during “message construction” such as the message format, the field semantics, and the order of the fields are inferred. Facilitated with the messages reconstructed by FIRMRES, we were able to manually examine the access control of device-cloud interfaces. FIRMRES reconstructed 246 effective messages from the firmware of 20 IoT devices, leading to the discovery of 13 previously-unknown vulnerabilities in their clouds. Jiongyi Chen, Yupeng Hu 0004 |
DSN | 2 |
| 2023 | Towards Automatic and Precise Heap Layout Manipulation for General-Purpose Programs
Runhao Li, Jiongyi Chen, Wenfeng Lin, Chao Feng 0002, Chaojing Tang |
NDSS | 3 |
| 2023 | HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
Kong Huang, Ke Zhang 0039, Jiacen Xu 0001, Jiongyi Chen, Di Tang 0001, Kehuan Zhang |
USENIX Security Symposium | 5 |
| 2023 | Automated Exploitable Heap Layout Generation for Heap Overflows Through Manipulation Distance-Guided Fuzzing
Jiongyi Chen, Runhao Li, Chao Feng 0002, Ruilin Li 0002, Chaojing Tang |
USENIX Security Symposium | 2 |
| 2022 | SEVulDet: A Semantics-Enhanced Learnable Vulnerability DetectorabstractRecent years have seen increased attention to deep learning-based vulnerability detection frameworks that leverage neural networks to identify vulnerability patterns. Considerable efforts have been made; still, existing approaches are less ac-curate in practice. Prior works fail to comprehensively capture semantics from source code or adopt the appropriate design of neural networks. This paper presents SEVulDet, a Semantics-Enhanced learnable Vulnerability Detector that can accurately pinpoint vulnerability patterns by preserving path semantics into gadgets and learning from flexible-length codes. SEVulDet has two main characteristics: (i) SEVulDet employs a path-sensitive code slicing approach to extract sufficient path semantics and control flow logic into code gadgets. (ii) by inserting a spatial pyramidal pooling layer into the Convolutional Neural Network (CNN) with a well-designed multilayer attention mechanism, SEVulDet can handle gadgets of flexible-length semantics to avoid semantics loss incurred by traditional truncating or padding operations, and thus learn more potential vulnerability patterns. Comprehensive experimental results show that SEVulDet significantly outperforms classical static approaches and excels with state-of-the-art deep learning-based solutions by improving F1-measure to roughly 94.5%. Particularly, the elaborate design of the SEVulDet architecture helps us identify more real-world vulnerabilities than existing technologies. Zhiquan Tang, Qiao Hu 0005, Wenxin Kuang, Jiongyi Chen |
DSN | 5 |
| 2022 | Demystifying Android Non-SDK APls: Measurement and UnderstandingabstractDuring the Android app development, the SDK is essential, which provides rich APIs to facilitate the implementations of functionalities. However, in the Android framework, there still exist plenty of non-SDK APIs that are not well documented. These non-SDK APIs can be invoked through unconventional ways, such as Java reflection. On the other hand, these APIs are not stable and may be changed or even removed in future Android versions, providing no guarantee for compatibility. From Android 9 (API level 28), Google began to strictly restrict the use of non-SDK APIs, and the corresponding checking mechanism has been integrated into the Android OS. Shishuai Yang, Rui Li 0102, Jiongyi Chen, Wenrui Diao, Shanqing Guo |
ICSE | 3 |
| 2022 | Default: Mutual Information-based Crash Triage for Massive CrashesabstractWith the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished. Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang |
ICSE | 2 |
| 2022 | Cast Away: On the Security of DLNA Deployments in the SmartTV EcosystemabstractThe casting service on SmartTV has been increasingly used for home entertainment and business, given the convenience offered in media broadcast and screen sharing. Among the underlying protocols that support TV cast, DLNA (Digital Living Networking Alliance) – established by a group of tech giants – has become a prevailing standard in the consumer market. Although DLNA has launched the market for years, concerns may arise about whether its real-world deployment has been clearly understood.In this work, we systematically evaluate the security of DLNA deployments in the SmartTV ecosystem. Specifically, we identify a series of critical security issues in the interactions between SmartTVs and casting apps on the smartphone, ranging from non-mandatory encryption to unauthorized file access. The identified security risks can be exploited by a malicious app on the victim’s phone, without requesting sensitive permissions, to launch multiple attacks, including arbitrary command execution, data theft, MITM (man-in-the-middle) attack, and DoS (denial-of-service) attack. To measure the impact of the identified security issues, we designed semi-automated analysis solutions to facilitate the measurements and conducted real-world experiments on 10 on-shelf TV boxes. The results show that most DLNA implementations of products and apps in the wild are insecure. In the end, we provide immediate improvement solutions to mitigate the identified security issues. Guangwei Tian, Jiongyi Chen, Kailun Yan, Shishuai Yang, Wenrui Diao |
QRS | 2 |
| 2022 | Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesabstractRecent years have seen increased attacks targeting embedded web applications of IoT devices. An important target of such attacks is the hidden interface of embedded web applications, which employs no protection but exposes security-critical actions and sensitive information to illegitimate users. With the severity and the pervasiveness of this issue, it is crucial to identify the vulnerable hidden interfaces, shed light on best practices and raise public awareness. Wei Xie 0007, Jiongyi Chen, Chao Feng 0002, Enze Wang, Kai Lu 0001 |
WWW | 2 |
| 2022 | Authorisation inconsistency in IoT third-party integrationabstractAbstract Today's IoT platforms provide rich functionalities by integrating with popular third‐party services. Due to the complexity, it is critical to understand whether the IoT platforms have properly managed the authorisation in the cross‐cloud IoT environments. In this study, the authors report the first systematic study on authorisation management of IoT third‐party integration by: (1) presenting two attacks that leak control permissions of the IoT device in the integration of third‐party services; (2) conducting a measurement study over 19 real‐world IoT platforms and three major third‐party services. Results show that eight of the platforms are vulnerable to the threat. To educate IoT developers, the authors provide in‐depth discussion about existing design principles and propose secure design principles for IoT cross‐cloud control frameworks. Jiongyi Chen, Fenghao Xu, Shuaike Dong, Kehuan Zhang |
IET Inf. Secur. | 1 |
| 2021 | Understanding the Brains and Brawn of Illicit Streaming App
Kong Huang, Ke Zhang 0039, Jiongyi Chen, Menghan Sun, Di Tang 0001, Kehuan Zhang |
ICDF2C | 3 |
| 2021 | Reducing Test Cases with Attention Mechanism of Neural Networks
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Yunfei Su, Jing Lei 0001, Chaojing Tang |
USENIX Security Symposium | 2 |
| 2020 | Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT TrafficabstractThe IoT (Internet of Things) technology has been widely adopted in recent years and has profoundly changed the people's daily lives. However, in the meantime, such a fast-growing technology has also introduced new privacy issues, which need to be better understood and measured. In this work, we look into how private information can be leaked from network traffic generated in the smart home network. Although researchers have proposed techniques to infer IoT device types or user behaviors under clean experiment setup, the effectiveness of such approaches become questionable in the complex but realistic network environment, where common techniques like Network Address and Port Translation (NAPT) and Virtual Private Network (VPN) are enabled. To this aim, we propose a traffic analysis framework based on sequence-learning techniques like LSTM and leveraged the temporal relations between packets for the attack of device identification. We evaluated it under different environment settings (e.g., pure-IoT and noisy environment with multiple non-IoT devices). The results showed our framework was able to differentiate device types with a high accuracy. This result suggests IoT network communications pose prominent challenges to users' privacy, even when they are protected by encryption and morphed by the network gateway. As such, new privacy protection methods on IoT traffic need to be developed towards mitigating this new issue. Shuaike Dong, Zhou Li 0001, Di Tang 0001, Jiongyi Chen, Menghan Sun, Kehuan Zhang |
AsiaCCS | 4 |
| 2019 | Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and UsersabstractNowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control. Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang |
DSN | 1 |
| 2019 | BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth Peripherals
Fenghao Xu, Wenrui Diao, Zhou Li 0001, Jiongyi Chen, Kehuan Zhang |
NDSS | 4 |
| 2019 | CryptoREX: Large-scale Analysis of Cryptographic Misuse in IoT Devices
Li Zhang 0039, Jiongyi Chen, Wenrui Diao, Shanqing Guo, Jian Weng 0001, Kehuan Zhang |
RAID | 2 |
| 2018 | IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang |
NDSS | 1 |
| 2018 | Vetting Single Sign-On SDK Implementations via Symbolic Reasoning
Ronghai Yang, Wing Cheong Lau, Jiongyi Chen, Kehuan Zhang |
USENIX Security Symposium | 3 |