EDBT 2026 Demo / reviewers in the wild / expert
Jiaxuan Han
dblp:250/2542
· DBLP profile ↗
17ranked-venue papers
7as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | δ-SCALPEL: Docker Image Slimming Based on Source Code Static AnalysisabstractContainerization is the mainstream of current software development, which enables software to be used across platforms without additional configuration of running environment. However, many images created by developers are redundant and contain unnecessary code, packages, and components. This excess not only leads to bloated images that are cumbersome to transmit and store but also increases the attack surface, making them more vulnerable to security threats. Therefore, image slimming has emerged as a significant area of interest. Nevertheless, existing image slimming technologies face challenges, particularly regarding the incomplete extraction of environment dependencies required by project code. In this paper, we present a novel image slimming model named δ–SCALPEL. This model employs static data dependency analysis to extract the environment dependencies of the project code and utilizes a directed graph named command link directed graph for modeling the image’s file system. We select 30 NPM projects and two official Docker Hub images to construct a dataset for evaluating δ-SCALPEL. The evaluation results show that δ–SCALPEL is robust and can reduce image sizes by up to 61.4% while ensuring the normal operation of these projects. Jiaxuan Han, Cheng Huang 0003, Tianwei Zhang 0004 |
IEEE Trans. Software Eng. | 1 |
| 2025 | LowPTor: A lightweight method for detecting extremely low-proportion darknet traffic
Qiang Zhang 0057, Cheng Huang 0003, Jiaxuan Han, Shuyi Jiang |
Comput. Secur. | 3 |
| 2025 | LineJLocRepair: A line-level method for Automated Vulnerability Repair based on joint training
Jiaxuan Han, Cheng Huang 0003, Lerong Li |
Future Gener. Comput. Syst. | 2 |
| 2025 | DeepVulHunter: enhancing the code vulnerability detection capability of LLMs through multi-round analysis
Yutong Jiao, Jiaxuan Han, Cheng Huang 0003 |
J. Intell. Inf. Syst. | 2 |
| 2025 | CoExpMiner: An AHIN-Based Vulnerability Co-Exploitation Mining FrameworkabstractVulnerability is a significant security threat to information systems, drawing widespread concern from researchers. In recent years, owing to continuous advancements in defense technologies, the success rate of exploiting a single N-day vulnerability for attacking has gradually decreased. Attackers are now attempting to exploit multiple vulnerabilities simultaneously to achieve their objectives. This phenomenon is referred to as the vulnerability co-exploitation. Limited by strict vulnerability triggering conditions, successful attacks via vulnerability co-exploitation are infrequent. Due to the low proportion of co-exploitation cases among all vulnerabilities, few studies have focused on co-exploitation relationships or investigated co-exploitation under the condition of extreme data imbalance. In additon, existing work lacks sufficient multidimensional features, which are crucial for accurately identifying and understanding co-exploitation scenarios. However, the prediction of vulnerability co-exploitation remains valuable as it aids practitioners in identifying potential critical risk points within the system. In this article, we propose a framework named CoExpMiner, based on the attributed heterogeneous information network, for mining potential vulnerability co-exploitation under the extreme data imbalance condition. CoExpMiner utilizes structure and attribute features of the attributed heterogeneous graph to predict vulnerability co-exploitation, with employing a prefilter structure to accelerate the process and reduce the computational cost. Experimental results demonstrate that CoExpMiner can effectively predict co-exploitation despite the challenges posed by extreme data imbalance. Shuyi Jiang, Cheng Huang 0003, Jiaxuan Han |
IEEE Trans. Reliab. | 3 |
| 2025 | Wolf in Sheep's Clothing: Shearing the Camouflage of Malicious Java Components in MavenabstractIn recent years, software supply chain attacks have become increasingly prevalent, prompting considerable research into detecting malicious packages within relevant repositories. With the popularity bolstered by the widespread adoption of open-source practices, Java become one of the preferred languages among modern developers. However, the issue of malware detection in Java components remains unresolved. Most prior approaches suffer from insufficient code coverage and coarse-grained representation, making them unsuitable for Java components.In this paper, we propose an innovative solution calledSheartailored for detecting malicious Java components.Shearfirstly analyzes all methods in the component and locates potential malicious code snippets based on sensitive calls, as slice-level analysis provides a better understanding of the specific malicious activities. Secondly, statements depending on sensitive call sites are extracted and embedded into vectors for further detection instead of function-level representation which is coarse-grained facing the dynamic features in Java. The corresponding experimental results show thatSheareffectively identifies the malicious semantics hidden in the code slices by leveraging the neural network model, outperforming currently available tools to a great extent. Through real-world validation,Sheardetected 51 components with malicious characteristics out of 68,273, demonstrating its practical feasibility. This study introduces the first Java malicious component detection method suitable for real-world scenarios, carrying considerable practical significance in bolstering defenses within the software supply chain. Yutong Zeng, Cheng Huang 0003, Jiaxuan Han, Genpei Liang, Shuyi Jiang |
IEEE Trans. Software Eng. | 3 |
| 2024 | Building and Evaluating a WebApp for Effortless Deep Learning Model Deployment
Ruikun Wu, Jiaxuan Han, Jerome Ramos, Aldo Lipani |
ECIR (5) | 2 |
| 2024 | DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge Mapping
Cheng Huang 0003, Lingzi Li, Qianchong Zhao, Jiaxuan Han |
USENIX Security Symposium | 8 |
| 2024 | bjCnet: A contrastive learning-based framework for software defect prediction
Jiaxuan Han, Cheng Huang 0003 |
Comput. Secur. | 1 |
| 2024 | VioDroid-Finder: automated evaluation of compliance and consistency for Android apps
Cheng Huang 0003, Jiaxuan Han |
Empir. Softw. Eng. | 3 |
| 2024 | bjEnet: a fast and accurate software bug localization method in natural language semantic space
Jiaxuan Han, Cheng Huang 0003 |
Softw. Qual. J. | 1 |
| 2023 | Digital Twins of Distributed Energy Resources for Real-Time Monitoring: Data Reporting Rate ConsiderationsabstractThis paper analyzes the requirements for the reporting rate of the live data source to support the operation of Digital Twins (DTs) of Distributed Energy Resources (DERs) for real-time power systems monitoring applications. The visibility of distribution networks is currently limited due to the lack of sufficient measurement and communication infrastructures. With the rapid increase of DERs, it becomes increasingly important to improve the visibility of the distribution networks to ensure the critical system operating constrains are continuously met. DTs are virtual replicas of physical systems, and with certain live measurement data, they can be used to accurately represent the real-time dynamics of the physical entities. The features of DTs could therefore be applied to increase the visibility of network and potentially support real-time decisions making. This paper presents the investigation of the impact of data reporting rate on DT accuracy, based on which, the paper presents a method that could be used to quantify the minimum requirements for data reporting rate to adequately support the DT operation, which provides valuable learning for specifying measurement devices and communication networks to enable DTs-based solutions. Jiaxuan Han, Qiteng Hong, Zhiwang Feng, Graeme M. Burt, Campbell D. Booth |
IECON | 1 |
| 2023 | bjXnet: an improved bug localization model based on code property graph and attention mechanism
Jiaxuan Han, Cheng Huang 0003, Zhonglin Liu |
Autom. Softw. Eng. | 1 |
| 2023 | Cloud-Edge Hosted Digital Twins for Coordinated Control of Distributed Energy ResourcesabstractThis article presents a novel approach for realizing coordinated control of Distributed Energy Resources (DERs) based on cloud-hosted and edge-hosted digital twins (DTs) of DERs. DERs are playing an increasingly important role in supporting the frequency regulation of power systems with massive integration of renewable resources. However, due to the significant differences in DERs’ capability and characteristics, individual and un-coordinated responses from DERs could lead to a less effective overall response with undesirable traits, e.g., slow response, severe overshoots, etc. Therefore, the coordination of DERs is critical to ensure the desirable aggregated overall response. A major shortcoming of conventional centralized or distributed approaches is their significant reliance on real-time communications. This article addresses the challenges by the application of DTs that can be hosted in the cloud for the centralized control approach and the edge for the distributed approach to minimize the need for real-time communications, while being able to achieve the overall coordination among DERs. The proposed DT-based coordinated control is validated using a realistic real-time simulation test setup, and the results demonstrate that the DT-based coordinated control can significantly improve the aggregated DERs’ response, thus offering effective support to the grid during contingency events. Jiaxuan Han, Qiteng Hong, Mazheruddin H. Syed, Md Asif Uddin Khan, Guangya Yang, Graeme M. Burt, Campbell D. Booth |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | GraphXSS: An efficient XSS payload detection approach based on graph convolutional network
Zhonglin Liu, Yong Fang 0002, Cheng Huang 0003, Jiaxuan Han |
Comput. Secur. | 4 |
| 2020 | Covert timing channel detection method based on time interval and payload length analysis
Jiaxuan Han, Cheng Huang 0003, Fan Shi 0003 |
Comput. Secur. | 1 |
| 2019 | Automatic Identification of Honeypot Server Using Machine Learning TechniquesabstractTraditional security strategies are powerless when facing novel attacks in the complex network environment, such as advanced persistent threat (APT). Compared with traditional security detection strategies, the honeypot system, especially on the Internet of things research area, is intended to be attacked and automatically monitor potential attacks by analyzing network packages or log files. The researcher can extract exactly threat actor tactics, techniques, and procedures from these data and then generate more effective defense strategies. But for normal security researchers, it is an urgent topic how to improve the honeypot mechanism which could not be recognized by attackers, and silently capture their behaviors. So, they need awesome intelligent techniques to automatically check remotely whether the server runs honeypot service or not. As the rapid progress in honeypot detection using machine learning technologies, the paper proposed a new automatic identification model based on random forest algorithm with three group features: application-layer feature, network-layer feature, and other system-layer feature. The experiment datasets are collected from public known platforms and designed to prove the effectiveness of the proposed model. The experiment results showed that the presented model achieved a high area under curve (AUC) value with 0.93 (area under the receiver operating characteristic curve), which is better than other machine learning algorithms. Cheng Huang 0003, Jiaxuan Han |
Secur. Commun. Networks | 2 |