EDBT 2026 Demo / reviewers in the wild / expert
Tianyuan Hu
dblp:253/0857
· DBLP profile ↗
17ranked-venue papers
5as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 3 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A curriculum-guided semi-supervised learning framework for joint entity and relation extraction
Haodong Song, Tianyuan Hu, Yuanfei Dai |
Knowl. Based Syst. | 3 |
| 2026 | Integrating Historical Rules and Curriculum-Enhanced Embeddings for Temporal Knowledge Graph ForecastingabstractTemporal knowledge graph forecasting (TKGF) has become a crucial tool for predicting future facts based on temporal knowledge graphs. Traditional methods face inherent limitations: rule-based reasoning approaches are restricted to exploring events that are related to historical rules and fail to fully utilize global graph information. In contrast, although embedding-based methods have the ability to capture global graph information through vector representations, they struggle to effectively incorporate historical rules. To address these issues, this article proposes a novel framework that combines historical rule-based reasoning with embedding-based prediction enhanced by curriculum learning (CL) to predict unknown events. The framework consists of two complementary modes: the rule mode, which extracts temporal rules through time-filtered weighted sampling and applies them for prediction, and the embedding mode, which progressively represents entities, relations, and time as vectors from simple to complex through CL and generates predictions based on these embedding vectors. The framework effectively integrates rules with the entire graph information by combining the predictions from two models, resulting in a more comprehensive prediction. Extensive experiments on multiple public datasets demonstrate that the proposed method outperforms state-of-the-art approaches in terms of performance, validating the effectiveness of its hybrid approach, and highlighting the significant potential of CL in TKGF. Weizhou Wang, Aichun Zhu, Tianyuan Hu, Shiping Wang, Yuanfei Dai |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2025 | Towards Task-Harmonious Vulnerability Assessment Based on LLMabstractSoftware vulnerabilities seriously jeopardize software security. It would be highly beneficial if developers could receive severity reminders regarding vulnerabilities when developing software systems. Therefore, when handling numerous vulnerabilities, it's crucial to prioritize the most critical ones and assess their severity early for effective resolution. Vulnerability assessment needs to train multiple assessment tasks simultaneously. Previous works suffer from task-disharmonious issues when conducting vulnerability assessments because they fail to balance the magnitude of gradients across multiple tasks and the conflicts in gradient directions. Additionally, they use identical code embedding for all classifiers without extracting task-related features. In this study, we are the first to conduct vulnerability assessment in a task-harmonious way by harmonizing gradient direction and magnitude, and filtering out task-specific features for each classifier. In addition, we use finer-grained contextual information than existing works by program slicing to further boost the model performance. According to experiment results, our model has demonstrated state-of-the-art performance at both the commit and function levels. Specifically, in function-level tasks, our model achieves an average of 0.819 in F1-Score and 0.742 in MCC, outperforming all baseline models. For commitlevel, our model enhances the average performance of the best baseline model by 29.6 % and 64.7 % in F1-Score and MCC, respectively. Zaixing Zhang, Jianming Chang, Tianyuan Hu, Lulu Wang 0001, Bixin Li |
ICPC | 3 |
| 2025 | Dynamic information utilization for securing Ethereum smart contracts: A literature review
Tianyuan Hu, Bixin Li |
Inf. Softw. Technol. | 1 |
| 2025 | Why Smart Contracts Reported as Vulnerable Were Not Exploited?abstractSmart contract security is crucial for blockchain applications. While studies suggest that only a small fraction of reported vulnerabilities are exploited, no follow-up research has investigated the reasons behind this. Our goal is to understand the factors contributing to the low exploitation rate to improve vulnerability detection and defense mechanisms. We collected 136,969 real-world smart contracts and analyzed them using seven vulnerability detectors. We applied Strauss’ grounded theory to gain insights into exploitability and analyzed transaction logs to trace the historic exploitations. Among the 4,364 smart contracts flagged as vulnerable, a significant 75.25% were found to be unexploitable, meaning they were either false positives or posed no security risk. We identified ten reasons for reporting unexploitable vulnerabilities. Furthermore, we found that only 66 out of 1,080 (6%) exploitable contracts had been exploited. We compared the characteristics of exploited versus non-exploited vulnerabilities and identified five factors that may reduce the likelihood of exploitation. Our findings highlight the importance of not treating smart contracts as conventional object-oriented (OO) applications. Researchers must account for the unique features of Solidity, smart contract design principles, and execution environments. Based on these insights, we propose six recommendations to improve smart contract vulnerability detection, prioritization, and mitigation. Tianyuan Hu, Jingyue Li, Bixin Li, André Storhaug |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | VulFinder: Exploring Chaincode Vulnerabilities More Effectively and Efficiently Using Knowledge Graph Based Defect Pattern MatchingabstractHyperledger Fabric is an open-source project of Linux Foundation, it is a modular blockchain framework and has become an unofficial standard for enterprise blockchain platforms. In Hyperledger Fabric, smart contract is also known as chaincode, which are usually written using general-purpose languages, including Go, Java or Node.js etc. Although there are some vulnerability detection methods for Java and Node.js, there are very few vulnerability detection methods for Go, especially when it is used as a smart contract programming language in Hyperledger Fabric.In this article, we propose a knowledge graph based defect pattern matching method and develop a tool calledVulFinderto detect vulnerabilities in chaincode, i.e. the smart contracts written using Go language. Knowledge graph is used because it can fully retain the syntax and logic information of smart contracts. The method consists of two key steps: a knowledge graph is constructed fromGo language specificationand chaincode source code, including the definition of ontology layer and the construction of instance layer; the defect patterns are defined and SPARQL query statements are used to match and locate vulnerabilities on the knowledge graph. To evaluate the detection effectiveness and efficiency ofVulFinder, we construct two datasets through manual analysis and vulnerabilities injection due to the lack of public datasets. Experimental results show thatVulFindercan detect 22 kinds of typical vulnerabilities of chaincode effectively, and therecallis as high as 98.87%, while thefalse negative rateis as low as 1.13% . Bixin Li, Tianyuan Hu, Xiangfei Xu, Lulu Wang 0001 |
IEEE Trans. Software Eng. | 2 |
| 2024 | SoliTester: Detecting exploitable external-risky vulnerability in smart contracts using contract account triggering methodabstractAbstract The vulnerability in smart contracts (SCs) on the blockchain system may lead to severe security compromises. The SC can be invoked from an externally owned account (EOA) or a contract account (CA). The account a user creates to receive or send ether is an EOA. A CA contains codes that can interact with SCs. In Solidity SC, some vulnerabilities can only be exploited by the interactions between CAs and vulnerable SCs, which can be named external‐risky vulnerabilities. Most state‐of‐the‐art (SOTA) detectors detect external‐risky vulnerabilities by executing contract codes as an EOA user, thus reporting many unexploitable vulnerabilities. Therefore, we propose a CA‐triggering method to identify exploitable external‐risky vulnerabilities in Solidity SCs. We first designed agent contracts to simulate CAs' interactions with the target SCs in the real blockchain environment. We then detect vulnerability exploitation by analyzing transaction logs between agent contracts and target SCs and identifying successful exploits. We implemented the CA‐triggering method in a tool named SoliTester and evaluated it using three benchmark datasets, which contain three types of external‐risky vulnerabilities, namely, Reentancy (RE), Unchecked Call (UcC), and TxOrigin (TO). The results show that SoliTester can efficiently detect exploitable external‐risky vulnerabilities with significantly better precisions and recalls than SOTA detectors. Tianyuan Hu, Jingyue Li, Xiangfei Xu, Bixin Li |
J. Softw. Evol. Process. | 1 |
| 2024 | Detect Defects of Solidity Smart Contract Based on the Knowledge GraphabstractSmart contract security is one of the core issues in any application based on blockchain. There are many techniques focusing on smart contract security, however, due to the diversity of Solidity versions and limitations of detection time, it is difficult for them to comprehensively localize defects in different versions of smart contracts. In this article, we propose a static defect detection method based on the knowledge graph of the Solidity language and present a defect detection tool calledSoliDetector. First, we define the ontology layer of the knowledge graph and construct the instance layer in which syntactic and logical relationships are captured. Second, we introduce the defect pattern to describe each defect and design inference rules to infer complex relationships and judge whether a defect exists. Finally, we localize defects by executing SPARQL queries.SoliDetectorcan support the detection of 20 kinds of defects and the automatic SPARQL query generation. We conducted several experiments on multiple datasets.SoliDetectorobtains a highF-score(i.e., 92.97% on Dataset1 and 91.54% on the SmartBug dataset). To compareSoliDetectorwithSmartCheck,Slither, andMythril, we conducted experiments on a labeled benchmark Dataset3 and real-world contracts.SoliDetectorhas a highF-scoreof 94.04% and is faster than other tools with an average time of 0.37 s for each contract. Tianyuan Hu, Bixin Li, Zhenyu Pan |
IEEE Trans. Reliab. | 1 |
| 2023 | CCDetector: Detect Chaincode Vulnerabilities Based on Knowledge Graph
Xiangfei Xu, Tianyuan Hu, Bixin Li |
COMPSAC | 2 |
| 2023 | Efficient Avoidance of Vulnerabilities in Auto-completed Smart Contract Code Using Vulnerability-constrained DecodingabstractAuto-completing code enables developers to speed up coding significantly. Recent advances in transformer-based large language model (LLM) technologies have been applied to code synthesis. However, studies show that many of such synthesized codes contain vulnerabilities. We propose a novel vulnerability-constrained decoding approach to reduce the amount of vulnerable code generated by such models. Using a small dataset of labeled vulnerable lines of code, we fine-tune an LLM to include vulnerability labels when generating code, acting as an embedded classifier. Then, during decoding, we deny the model to generate these labels to avoid generating vulnerable code. To evaluate the method, we chose to automatically complete Ethereum Blockchain smart contracts (SCs) as the case study due to the strict requirements of SC security. We first fine-tuned the 6-billion-parameter GPT-J model using 186,397 Ethereum SCs after removing the duplication from 2,217,692 SCs. The fine-tuning took more than one week using ten GPUs. The results showed that our fine-tuned model could synthesize SCs with an average BLEU (BiLingual Evaluation Understudy) score of 0.557. However, many codes in the auto-completed SCs were vulnerable. Using the code before the vulnerable line of 176 SCs containing different types of vulnerabilities to auto-complete the code, we found that more than 70% of the auto-completed codes were insecure. Thus, we further fine-tuned the model on other 941 vulnerable SCs containing the same types of vulnerabilities and applied vulnerability-constrained decoding. The fine-tuning took only one hour with four GPUs. We then auto-completed the 176 SCs again and found that our approach could identify 62% of the code to be generated as vulnerable and avoid generating 67% of them, indicating the approach could efficiently and effectively avoid vulnerabilities in the auto-completed code. André Storhaug, Jingyue Li, Tianyuan Hu |
ISSRE | 3 |
| 2023 | Detection of continuous hierarchical heterogeneity by single-cell surface antigen analysis in the prognosis evaluation of acute myeloid leukaemiaabstractBACKGROUND: Acute myeloid leukaemia (AML) is characterised by the malignant accumulation of myeloid progenitors with a high recurrence rate after chemotherapy. Blasts (leukaemia cells) exhibit a complete myeloid differentiation hierarchy hiding a wide range of temporal information from initial to mature clones, including genesis, phenotypic transformation, and cell fate decisions, which might contribute to relapse in AML patients. METHODS: Based on the landscape of AML surface antigens generated by mass cytometry (CyTOF), we combined manifold analysis and principal curve-based trajectory inference algorithm to align myelocytes on a single-linear evolution axis by considering their phenotype continuum that correlated with differentiation order. Backtracking the trajectory from mature clusters located automatically at the terminal, we recurred the molecular dynamics during AML progression and confirmed the evolution stage of single cells. We also designed a 'dispersive antigens in neighbouring clusters exhibition (DANCE)' feature selection method to simplify and unify trajectories, which enabled the exploration and comparison of relapse-related traits among 43 paediatric AML bone marrow specimens. RESULTS: The feasibility of the proposed trajectory analysis method was verified with public datasets. After aligning single cells on the pseudotime axis, primitive clones were recognized precisely from AML blasts, and the expression of the inner molecules before and after drug stimulation was accurately plotted on the trajectory. Applying DANCE to 43 clinical samples with different responses for chemotherapy, we selected 12 antigens as a general panel for myeloblast differentiation performance, and obtain trajectories to those patients. For the trajectories with unified molecular dynamics, CD11c overexpression in the primitive stage indicated a good chemotherapy outcome. Moreover, a later initial peak of stemness heterogeneity tended to be associated with a higher risk of relapse compared with complete remission. CONCLUSIONS: In this study, pseudotime was generated as a new single-cell feature. Minute differences in temporal traits among samples could be exhibited on a trajectory, thus providing a new strategy for predicting AML relapse and monitoring drug responses over time scale. Chenshuo Ren, Tianyuan Hu, Dianbing Wang, Xiaofan Zhu, Yingchi Zhang, Xian-En Zhang |
BMC Bioinform. | 3 |
| 2023 | A survey of blockchain consensus safety and security: State-of-the-art, challenges, and future work
Qihao Bao, Bixin Li, Tianyuan Hu, Xueyong Sun |
J. Syst. Softw. | 3 |
| 2022 | Model Checking the Safety of Raft Leader Election AlgorithmabstractWith the wide application of the Raft consensus algorithm in blockchain systems, its safety has attracted more and more attention. However, although some researchers have formally verified the safety of the Raft consensus algorithm in most scenarios, there are still some safety problems with Raft consensus algorithm in some special scenarios, and cause problems now and then. For example, as a core part of the Raft consensus algorithm, the Raft leader election algorithm usually faces some safety problems in following scenarios: if the network communication between some nodes is abnormal, the leader node could be unstable or even cannot be elected, or the log entry cannot be updated, etc. In this paper, we model check the safety of the Raft leader election algorithm throughly using Spin. We use Promela language to model the Raft leader election algorithm and use Linear-time Temporal Logic (LTL) formulae to characterize three safety properties including stability, liveness, and uniqueness. The verification results show that the Raft leader election algorithm does not hold stability and liveness when some nodes are faulty and node log entries are inconsistent. For these safety problems, we give the suggestions for improving safety by analyzing counter examples. Qihao Bao, Bixin Li, Tianyuan Hu, Dongyu Cao |
QRS | 3 |
| 2022 | A BiLSTM-Attention Model for Detecting Smart Contract Defects More AccuratelyabstractSmart contracts are applications running on the blockchain which control many virtual currencies. Since smart contracts are composed of code, they inevitably have defects. In recent years, many smart contract defects have caused lots of economic losses and harmful impacts. A contract that has defects may have some errors that cause unwanted results. As smart contracts cannot be modified once deployed, it is necessary to ensure that they are free from defects. In this paper, we focus on eleven defects of smart contracts and construct a deep learning-based model to detect these contract defects more accurately. Our model regards the smart contract’s operation codes as a sequential sentence and uses an Attention-based bidirectional long short term memory (BiLSTM-Attention) model to find smart contract defects. We evaluate our model’s and other models’ performance on 45622 real-world smart contracts. The experimental results show that our model can achieve higher accuracy (95.40%) and F1-score (95.38%). In addition, our model is highly efficient and can quickly detect large numbers of contracts. Tianyuan Hu, Bixin Li |
QRS | 2 |
| 2022 | ReDefender: Detecting Reentrancy Vulnerabilities in Smart Contracts AutomaticallyabstractAs one of the most complex types of vulnerabilities, reentrancy poses a significant threat to smart contract development. Indeed, millions of dollars have evaporated due to reentrancy vulnerabilities of smart contracts in past years. In this article, we propose a new approach to detect reentrancy vulnerabilities using fuzz testing and develop a novel tool named ReDefender. Our approach consists of three main steps: 1)preprocess contract to be detected:when a contract is uploaded, its source code will be preprocessed to extract candidate pool for fuzzing and dependency graph which guides the automatic deployment of contracts; 2)fuzzing input generation:fuzzing input is generated to constitute transactions which will be sent to an agent contract to stimulate attacks, where runtime information is collected and recorded in the execution log during each execution; and 3)vulnerability verification:the execution log is analyzed to determine whether a reentrancy process occurs and whether the reentrancy process is malicious. We conduct comparative experiments on 204 tagged smart contracts and 90 injected contracts. The results show higher accuracy and lower false negative rate of ReDefender than that of the other three famous tools. Moreover, we conduct an experiment on 4776 real-world contracts demonstrating the ability of ReDefender to find reentrancy vulnerabilities that really cause economic losses. Bixin Li, Zhenyu Pan, Tianyuan Hu |
IEEE Trans. Reliab. | 3 |
| 2021 | ReDefender: A Tool for Detecting Reentrancy Vulnerabilities in Smart Contracts EffectivelyabstractReentrancy, one of the most complex type of vulner-abilities, poses significant threat to smart contract development. Indeed, millions of dollars have evaporated due to reentrancy vulnerabilities of smart contracts in past years. In this paper, we propose a new approach to detect reentrancy vulnerabilities using fuzz testing and develop a novel tool named ReDefender. Our approach and tool consists of four main steps: (1)preprocess contract to be detected: when a contract uploaded, its source code will be preprocessed by ReDefender to extract candidate pool for fuzzing; (2) generate fuzzing input: fuzzing input will be generated by fuzz engine; (3) collect runtime information: an agent contract is constructed to interact with and attack all contracts to be detected. Runtime information is collected during the execution of every fuzzing input; (4) analyze execution log and find reentrancy: the execution log is analyzed to determine whether a malicious reentrancy occurs. We conduct experiments on 204 tagged smart contracts and show the higher accuracy and lower false positive rate of ReDefender than that of other three famous tools. Moreover, we conduct a new experiment and find 4 reentrancy vulnerabilities in 395 on-chain contract accounts which have managed more than 1000 transactions. Zhenyu Pan, Tianyuan Hu, Bixin Li |
QRS | 2 |
| 2021 | SolDetector: Detect Defects Based on Knowledge Graph of Solidity Smart ContractabstractSmart contract security is one of core security issues in the application of blockchain.In recent years, attacks on smart contracts occur frequently, there are a lot of researches concerning on smart contract security issues.However, almost all solutions proposed in these researches are low precision and high False Negative Rate(FNR).In this paper, we propose a defect detection method for checking security of Solidity smart contract based on knowledge graph.Therefore, we first construct knowledge graph of smart contracts by fully integrating syntax and semantic information of Solidity source code; then, we define defect patterns by analyzing defect characteristics; furthermore, we define inference rules for defects based on knowledge graph and defect patterns; finally, we detect defects by SPARQL query.We also implement a tool named SolDetector and perform experiment on three different datasets, which shows that SolDetector is effective and efficient. Tianyuan Hu, Zhenyu Pan, Bixin Li |
SEKE | 1 |