EDBT 2026 Demo / reviewers in the wild / expert
Zichao Wei
dblp:241/4857
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0007-5718-3935ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 87% Blockchain and cryptocurrency security · 13% | |
| Software engineering, system software, and programming languages
2 papers |
Software maintenance and evolution · 79% Program synthesis and code generation · 21% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
security patch analysis |
0.8 | 1 | 2024 | Unveiling the Characteristics and Impact of Security Patch Evolution · ASE 2024 |
Systems and software security
vulnerability discovery |
0.8 | 1 | 2024 | Unveiling the Characteristics and Impact of Security Patch Evolution · ASE 2024 |
Software maintenance and evolution
software evolution |
0.8 | 1 | 2024 | Unveiling the Characteristics and Impact of Security Patch Evolution · ASE 2024 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
0.2 | 1 | 2024 | Unveiling the Characteristics and Impact of Security Patch Evolution · ASE 2024 |
Program synthesis and code generation › code language model
pre-trained code models |
0.2 | 1 | 2023 | An Extensive Study on Adversarial Attack against Pre-trained Models of Code · ESEC/SIGSOFT FSE 2023 |
Methods — techniques the papers use, named apart from their topics
patch presence testing · 1.5empirical study · 1.5beam search · 0.7adversarial example generation · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Unveiling the Characteristics and Impact of Security Patch EvolutionabstractThe number of disclosed vulnerabilities in open-source projects has been increasing steadily over the years, and thus it is important to deploy patches to repair vulnerabilities in a timely manner. However, due to the widespread reuse and customization of open-source software, there are often multiple versions or branches of the same project that co-exist in the ecosystem. Therefore, it is often challenging and tricky to guarantee that an exposed vulnerability can be repaired thoroughly. Driven by this, plenty of 1-day vulnerability analysis tools have been proposed recently, such as function-level vulnerability detection and patch presence test tools. Despite the fact that code evolution is common for open-source projects, existing analysis tools often neglect the important fact that the patched code is also constantly evolving. In this study, we take the first look to systematically investigate the phenomenon of security patch evolution in open-source projects. In particular, we performed extensive experiments on a large-scale dataset containing 1,046 distinct CVEs with 2,633 patches collected from popular open-source projects (e.g., linux, openssl). This study reveals interesting yet important findings with respect to the aspects of patch evolution frequency, patch evolution patterns, and the evolution impact on downstream 1-day vulnerability analysis tools. We believe that this study can shed important light on future researches on patch analysis. Zifan Xie, Ming Wen 0001, Zichao Wei, Hai Jin 0001 |
ASE | 3 |
| 2023 | An Extensive Study on Adversarial Attack against Pre-trained Models of CodeabstractTransformer-based pre-trained models of code (PTMC) have been widely utilized and have achieved state-of-the-art performance in many mission-critical applications. However, they can be vulnerable to adversarial attacks through identifier substitution or coding style transformation, which can significantly degrade accuracy and may further incur security concerns. Although several approaches have been proposed to generate adversarial examples for PTMC, the effectiveness and efficiency of such approaches, especially on different code intelligence tasks, has not been well understood. To bridge this gap, this study systematically analyzes five state-of-the-art adversarial attack approaches from three perspectives: effectiveness, efficiency, and the quality of generated examples. The results show that none of the five approaches balances all these perspectives. Particularly, approaches with a high attack success rate tend to be time-consuming; the adversarial code they generate often lack naturalness, and vice versa. To address this limitation, we explore the impact of perturbing identifiers under different contexts and find that identifier substitution within for and if statements is the most effective. Based on these findings, we propose a new approach that prioritizes different types of statements for various tasks and further utilizes beam search to generate adversarial examples. Evaluation results show that it outperforms the state-of-the-art ALERT in terms of both effectiveness and efficiency while preserving the naturalness of the generated adversarial examples. Xiaohu Du, Ming Wen 0001, Zichao Wei, Shangwen Wang, Hai Jin 0001 |
ESEC/SIGSOFT FSE | 3 |