EDBT 2026 Demo / reviewers in the wild / expert
Zheyuan He
dblp:270/2519
· DBLP profile ↗
20ranked-venue papers
5as first author
19since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 8 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 6 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Light into Darkness: Demystifying Profit Strategies Throughout the MEV Bot Lifecycle
Feng Luo 0009, Zihao Li 0001, Wenxuan Luo, Zheyuan He, Xiapu Luo, Zuchao Ma, Shuwei Song, Ting Chen 0002 |
NDSS | 4 |
| 2025 | Denial of Sequencing Attacks in Ethereum Layer 2 RollupsabstractLayer 2 rollups offer promising solutions to address Ethereum's scalability issues. However, the centralized nature of the sequencer in these rollups makes them vulnerable to denial of service attacks, in which adversaries overwhelm the sequencer with invalid transactions that cannot be included in blocks, thereby exhausting its computational resources for transaction processing. To mitigate such threat, layer 2 rollups implement the legality check mechanism to filter out invalid transactions before they reach the sequencer. Zihao Li 0001, Zheyuan He, Jinzhao Chu, Hao Zhou 0043, Xiapu Luo, Ting Chen 0002, Yinqian Zhang |
CCS | 3 |
| 2025 | Maat: Analyzing and Optimizing Overcharge on Blockchain Storage
Zheyuan He, Zihao Li 0001, Ao Qiao, Jingwei Li 0001, Feng Luo 0009, Gelei Deng, Shuwei Song, Xiaosong Zhang 0001, Ting Chen 0002, Xiapu Luo |
FAST | 1 |
| 2025 | Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in Blockchain
Zheyuan He, Zihao Li 0001, Jiahao Luo, Feng Luo 0009, Junhan Duan, Jingwei Li 0001, Shuwei Song, Xiapu Luo, Ting Chen 0002, Xiaosong Zhang 0001 |
USENIX Security Symposium | 1 |
| 2025 | Finding Correctness Issues on Ethereum Verkle Tries via Preimage-Aware Differential TestingabstractStateless Ethereum is proposed to address the challenges of unbounded state growth, which poses centralization risks to Ethereum by imposing considerable operational costs on network participants. This approach enables Ethereum clients to verify and maintain blockchain using only block witnesses, eliminating the need for the underlying state data. Verkle Tries, as the next-generation state trie structure for Ethereum, are set to replace Merkle Patricia Tries to facilitate the stateless Ethereum by significantly reducing the size of block witnesses. Besides, since blockchain maintenance and verification entail intensive read and update operations on state data, ensuring the correctness of state access in Verkle Tries is crucial.In this study, we conduct the first systematic study on the correctness issues in Ethereum Verkle Tries, and define two kinds of such issues. Besides, we design VERDIFF, the first tool for automatically identifying correctness issues in Ethereum Verkle Tries through preimage-aware differential testing. To facilitate the identification of interpretable and reproducible issues, we proposePAL, the first domain-specific language designed to construct semantically valid trie access statements as test inputs for Verkle Tries. During the preimage-aware differential testing, these statements are iteratively generated and mutated based on our novel feedback mechanisms for inducing diverse behaviors when accessing states across varied regions in Verkle Tries at the preimage level. Moreover, we define new correctness issue oracles based on our definitions of these issues to ensure their accurate identification. We implement VERDIFF on Ethereum clients, and conduct extensive experiments to evaluate its effectiveness in identifying correctness issues. Through our evaluation, VERDIFF can uncover eight critical correctness issues, spanning four distinct classes, in Ethereum Verkle Tries across three major Ethereum clients (Go-ethereum, Nethermind, and EthereumJS). Additionally, it achieves at least 23.3% higher code path coverage compared to two baselines. Furthermore, we empirically analyze the security risks posed by the identified correctness issues, and explore their potential security implications, highlighting the critical role of VERDIFF in securing Ethereum Verkle Tries. Zihao Li 0001, Zheyuan He, Xiapu Luo, Ting Chen 0002, Xiaosong Zhang 0001 |
IEEE Trans. Software Eng. | 2 |
| 2024 | fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupabstractZero-knowledge layer 2 protocols emerge as a compelling approach to overcoming blockchain scalability issues by processing transactions through the transaction finalization process. During this process, transactions are efficiently processed off the main chain. Besides, both the transaction data and the zero-knowledge proofs of transaction executions are reserved on the main chain, ensuring the availability of transaction data as well as the correctness and verifiability of transaction executions. Hence, any bugs that cause the transaction finalization failure are crucial, as they impair the usability of these protocols and the scalability of blockchains. Zihao Li 0001, Xinghao Peng, Zheyuan He, Xiapu Luo, Ting Chen 0002 |
CCS | 3 |
| 2024 | Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource Modelsabstractnial-of-Service (DoS) attacks at the execution layer represent one of the most severe threats to blockchain systems, compromising availability by depleting the resources of victims. To counteract these attacks, many blockchains have implemented unique resource models that incorporate transaction fees. Nevertheless, historical incidents of DoS attacks demonstrate that these resource model designs remain inadequate. Although there are studies that manually craft DoS attacks on specific blockchains in isolation, none of them can discover DoS weaknesses in blockchains automatically. In this paper, we provide an insight into DoS weaknesses in blockchain resource models, and present a generic and systematic approach to uncover these weaknesses. In our approach, we first identify DoS weaknesses by DoSVER, a novel tool that reasons feasible DoS weaknesses against blockchain resource models by formal verification. The identified DoS weaknesses will be further validated by DoSDET, a new framework that automates the attack synthesis in exploiting the identified DoS weaknesses. We conduct a comprehensive and systematic evaluation by extensive experiments on nine diverse and widely-used blockchains, and discovered 12 DoS weaknesses with corresponding exploitation across the nine blockchains, 10 of which were unveiled for the first time. Feng Luo 0009, Huangkun Lin, Zihao Li 0001, Xiapu Luo, Ruijie Luo, Zheyuan He, Shuwei Song, Ting Chen 0002, Wenxuan Luo |
CCS | 6 |
| 2024 | SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention NetworkabstractSmart contracts are integral to blockchain's growth, but their vulnerabilities pose a significant threat. Traditional vulnerability detection methods rely heavily on expert-defined complex rules that are labor-intensive and dificult to adapt to the explosive expansion of smart contracts. Some recent studies of neural network-based vulnerability detection also have room for improvement. Therefore, we propose SCVHunter, an extensible framework for smart contract vulnerability detection. Specifically, SCVHunter designs a heterogeneous semantic graph construction phase based on intermediate representations and a vulnerability detection phase based on a heterogeneous graph attention network for smart contracts. In particular, SCVHunter allows users to freely point out more important nodes in the graph, leveraging expert knowledge in a simpler way to aid the automatic capture of more information related to vulnerabilities. We tested SCVHunter on reentrancy, block info dependency, nested call, and transaction state dependency vulnerabilities. Results show remarkable performance, with accuracies of 93.72%, 91.07%, 85.41%, and 87.37% for these vulnerabilities, surpassing previous methods. Feng Luo 0009, Ruijie Luo, Ting Chen 0002, Ao Qiao, Zheyuan He, Shuwei Song, Yu Jiang 0001, Sixing Li |
ICSE | 5 |
| 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced AnalysisabstractMove, a programming language for smart contracts, stands out for its focus on security. However, the practical security efficacy of Move contracts remains an open question. This work conducts the first comprehensive empirical study on the security of Move contracts. Our initial step involves collaborating with a security company to manually audit 652 contracts from 92 Move projects. This process reveals eight types of defects, with half previously unreported. These defects present potential security risks, cause functional flaws, mislead users, or waste computational resources. To further evaluate the prevalence of these defects in real-world Move contracts, we present MoveScan, an automated analysis framework that translates bytecode into an intermediate representation (IR), extracts essential meta-information, and detects all eight defect types. By leveraging MoveScan, we uncover 97,028 defects across all 37,302 deployed contracts in the Aptos and Sui blockchains, indicating a high prevalence of defects. Experimental results demonstrate that the precision of MoveScan reaches 98.85%, with an average project analysis time of merely 5.45 milliseconds. This surpasses previous state-of-the-art tools MoveLint, which exhibits an accuracy of 87.50% with an average project analysis time of 71.72 milliseconds, and Move Prover, which has a recall rate of 6.02% and requires manual intervention. Our research also yields new observations and insights that aid in developing more secure Move contracts. Shuwei Song, Jiachi Chen, Ting Chen 0002, Xiapu Luo, Wenwu Yang, Leqing Wang, Feng Luo 0009, Zheyuan He |
ISSTA | 10 |
| 2024 | Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationabstractBlockchains, with intricate architectures, encompass various components, e.g., consensus network, smart contracts, decentralized applications, and auxiliary services. While offering numerous advantages, these components expose various attack surfaces, leading to severe threats to blockchains. In this study, we unveil a novel attack surface, i.e., the state storage, in blockchains. The state storage, based on the Merkle Patricia Trie, plays a crucial role in maintaining blockchain state. Besides, we design Nurgle, the first Denial-of-Service attack targeting the state storage. By proliferating intermediate nodes within the state storage, Nurgle forces blockchains to expend additional resources on state maintenance and verification, impairing their performance. We conduct a comprehensive and systematic evaluation of Nurgle, including the factors affecting it, its impact on blockchains, its financial cost, and practically demonstrating the resulting damage to blockchains. The implications of Nurgle extend beyond the performance degradation of blockchains, potentially reducing trust in them and the value of their cryptocurrencies. Additionally, we further discuss three feasible mitigations against Nurgle. At the time of writing, the vulnerability exploited by Nurgle has been confirmed by six mainstream blockchains, and we received thousands of USD bounty from them. Zheyuan He, Zihao Li 0001, Ao Qiao, Xiapu Luo, Xiaosong Zhang 0001, Ting Chen 0002, Shuwei Song, Dijun Liu, Weina Niu |
SP | 1 |
| 2023 | Demystifying DeFi MEV Activities in Flashbots BundleabstractDecentralized Finance, mushrooming in permissionless blockchains, has attracted a recent surge in popularity. Due to the transparency of permissionless blockchains, opportunistic traders can compete to earn revenue by extracting Miner Extractable Value (MEV), which undermines both the consensus security and efficiency of blockchain systems. The Flashbots bundle mechanism further aggravates the MEV competition because it empowers opportunistic traders with the capability of designing more sophisticated MEV extraction. In this paper, we conduct the first systematic study on DeFi MEV activities in Flashbots bundle by developing ActLifter, a novel automated tool for accurately identifying DeFi actions in transactions of each bundle, and ActCluster, a new approach that leverages iterative clustering to facilitate us to discover known/unknown DeFi MEV activities. Extensive experimental results show that ActLifter can achieve nearly 100% precision and recall in DeFi action identification, significantly outperforming state-of-the-art techniques. Moreover, with the help of ActCluster, we obtain many new observations and discover 17 new kinds of DeFi MEV activities, which occur in 53.12% of bundles but have not been reported in existing studies. Zihao Li 0001, Jianfeng Li 0006, Zheyuan He, Xiapu Luo, Ting Wang 0006, Xiaoze Ni, Wenwu Yang, Ting Chen 0002 |
CCS | 3 |
| 2023 | Poster: SigRec - Automatic Recovery of Function Signatures in Smart ContractsabstractMillions of contracts deployed onto Ethereum provide various services that can be invoked. For this purpose, blockchain users need to know and specify the function signature of a callee, which includes its function id and the parameter types. Function signatures are crucial in several applications, such as recognizing the services that contracts provide. In this poster, we propose a novel solution that leverages how functions are handled by Ethereum virtual machine (EVM) to automatically recover function signatures from contract bytecode, without the need of source code and function signature databases. The extensive experimental results show that our solution outperforms all existing tools, achieving an unprecedented 98.7% accuracy within 0.074 seconds. We further demonstrate the usefulness of our solution in attack detection, fuzzing and reverse engineering of contract bytecode. Ting Chen 0002, Zihao Li 0001, Xiapu Luo, XiaoFeng Wang 0001, Ting Wang 0006, Zheyuan He, Kezhao Fang, Yufei Zhang 0002, Hongwei Li 0001, Xiaosong Zhang 0001 |
ICDCS | 6 |
| 2023 | BlockExplorer: Exploring Blockchain Big Data Via Parallel ProcessingabstractToday's blockchain systems store detailed runtime information in the format of transactions and blocks, which are valuable not only to understand the finance of blockchain-based ecosystems but also to audit the security of on-chain applications. However, exploring this blockchain “big data” is challenging due to data heterogeneity and the huge amount. Existing blockchain exploration techniques are either incomplete or inefficient, making them inapt in time-sensitive applications. This paper presents ${\sf BlockExplorer}$ , an efficient and flexible blockchain exploration system for Ethereum. ${\sf BlockExplorer}$ builds on a master-slave architecture, where the master partitions all blocks into multiple non-overlapped sets and each slave simultaneously processes Ethereum big data based on a set of blocks. ${\sf BlockExplorer}$ implements a transaction-based partitioning approach to address load balance among slaves, and a code instrumentation approach to acquire complete Ethereum big data. The evaluation shows that ${\sf BlockExplorer}$ accelerates the data acquisition performance of the state-of-the-art by 4.1×, while the workload difference among slaves is up to 18%. To demonstrate the application of ${\sf BlockExplorer}$ , we develop three apps upon ${\sf BlockExplorer}$ to detect real-life attacks against Ethereum and show that our apps can detect attacks in a large range of blocks (e.g., ten million) within a short time (e.g., multiple hours). Jingwei Li 0001, Yuxing Tang, Xiapu Luo, Zheyuan He, Zihao Li 0001, Yang Bai 0011, Ting Chen 0002, Yuzhe Tang, Zhe Liu 0001, Xiaosong Zhang 0001 |
IEEE Trans. Computers | 5 |
| 2023 | TokenAware: Accurate and Efficient Bookkeeping Recognition for Token Smart ContractsabstractTokens have become an essential part of blockchain ecosystem, so recognizing token transfer behaviors is crucial for applications depending on blockchain. Unfortunately, existing solutions cannot recognize token transfer behaviors accurately and efficiently because of their incomplete patterns and inefficient designs. This work proposes TokenAware , a novel online system for recognizing token transfer behaviors. To improve accuracy, TokenAware infers token transfer behaviors from modifications of internal bookkeeping of a token smart contract for recording the information of token holders (e.g., their addresses and shares). However, recognizing bookkeeping is challenging, because smart contract bytecode does not contain type information. TokenAware overcomes the challenge by first learning the instruction sequences for locating basic types and then deriving the instruction sequences for locating sophisticated types that are composed of basic types. To improve efficiency, TokenAware introduces four optimizations. We conduct extensive experiments to evaluate TokenAware with real blockchain data. Results show that TokenAware can automatically identify new types of bookkeeping and recognize 107,202 tokens with 98.7% precision. TokenAware with optimizations merely incurs 4% overhead, which is 1/345 of the overhead led by the counterpart with no optimization. Moreover, we develop an application based on TokenAware to demonstrate how it facilitates malicious behavior detection. Zheyuan He, Shuwei Song, Yang Bai 0011, Xiapu Luo, Ting Chen 0002, Hongwei Li 0001, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2023 | Large-Scale Empirical Study of Inline Assembly on 7.6 Million Ethereum Smart ContractsabstractBeing the most popular programming language for developing Ethereum smart contracts, Solidity allows using inline assembly to gain fine-grained control. Although many empirical studies on smart contracts have been conducted, to the best of our knowledge, none has examined inline assembly in smart contracts. To fill the gap, in this paper, we conduct the first large-scale empirical study of inline assembly on more than 7.6 million open-source Ethereum smart contracts from three aspects, namely, source code, bytecode, and transactions after designing new approaches to tackle several technical challenges. Through a thorough quantitative and qualitative analysis of the collected data, we obtain many new observations and insights. Moreover, by conducting a questionnaire survey on using inline assembly in smart contracts, we draw new insights from the valuable feedback. This work sheds light on the development of smart contracts as well as the evolution of Solidity and its compilers. Zhou Liao, Shuwei Song, Xiapu Luo, Zheyuan He, Renkai Jiang, Ting Chen 0002, Jiachi Chen, Tao Zhang 0001, Xiaosong Zhang 0001 |
IEEE Trans. Software Eng. | 5 |
| 2022 | TokenCat: Detect Flaw of Authentication on ERC20 TokensabstractThe development of blockchain has promoted the prosperity of the cryptocurrency ecosystem. The majority of cryptocurrencies are ERC20 tokens implemented based on Ethereum contracts. The major role of ERC20 tokens is to carry out various trades and loans in decentralized applications (DApps). To participate in DApps, users must grant the DApps permission to spend tokens on user behalf. However, if the authorization logic of token contract is flawed implementation, the holder of token will suffer tremendous financial losses. In this work, we detect the authentication implementation of the flaws in ERC20 token, which has not been done before. We find the authentication process of the token is implemented by operating the authentication data structure of the token. Therefore, we capture the operations of the authentication data structure in token contract to infer authentication behaviors and detect authentication defects. However, it’s not a simple task as most smart contracts are not open source and the bytecode of token contract lacks type information. To tackle these problems, we utilize symbolic execution on the token bytecode, then identify the authentication data structure and capture the operations by parsing the symbolic expressions, and finally detect authentication defects through the inferred authentication behavior. To best our knowledge, this is the first work to detect the flaws in the implementation of authentication in ERC20 Token. To automate the analysis, we implement our approach in a new tool named TokenCat and use it to inspect 245,822 tokens. As a result, the TokenCat found 491 ERC20 token authentication implementation flaws with 94% precision. Zheyuan He, Zhou Liao, Feng Luo 0009, Dijun Liu, Ting Chen 0002, Zihao Li 0001 |
ICC | 1 |
| 2022 | Attacker Traceability on Ethereum through Graph AnalysisabstractSince the Ethereum virtual machine is Turing complete, Ethereum can implement various complex logics such as mutual calls and nested calls between functions. Therefore, Ethereum has suffered a lot of attacks since its birth, and there are still many attackers active in Ethereum transactions. To this end, we propose a traceability method on Ethereum, using graph analysis to track attackers. We collected complete user transaction data to construct the graph and analyzed data on several harmful attacks, including reentry attacks, short address attacks, DDoS attacks, and Ponzi contracts. Through graph analysis, we found accounts that are strongly associated with these attacks and are still active. We have done a systematic analysis of these accounts to analyze their threats. Finally, we also analyzed the correlation between the information collected through RPC and these accounts and finally found that some accounts can find their IP addresses. Weina Niu, Xuhan Liao, Xiaosong Zhang 0001, Beibei Li 0002, Zheyuan He |
Secur. Commun. Networks | 7 |
| 2022 | Velocity Distribution Inversion Method Based on the RANS Equations Using Microwave Doppler RadarabstractMicrowave Doppler radar has been used to make non-contact river flow measurements and offers a high resolution and a wide range. However, discharge estimation with microwave Doppler radar is challenging due to the inability to measure flow velocity below the river surface based on the Doppler shift. To address this problem, a velocity distribution inversion method based on the Reynolds-Averaged Navier-Stokes (RANS) equations is proposed. A classical two-region model which divides the flow into the inner region and the outer region is applied. Velocity at the inner-outer boundary is estimated using surface velocity and the log law is used to estimate velocity distribution of the inner region. Taking velocities at the surface and the inner-outer boundary as boundary conditions, the velocity distribution in the outer region is derived by solving the RANS equations. Discharge is calculated by combining the proposed method with the velocity-area method. The results illustrated that the velocity distribution obtained by the proposed method and measured by an acoustic instrument are in reasonable agreement. Discharge estimated using the obtained velocity distribution has an error less than 10%. The work indicates the potential of microwave Doppler radar to retrieve the river cross section velocity distribution and estimate discharge. Zezong Chen, Zheyuan He, Chen Zhao 0003, Tao Wang 0157 |
IEEE Trans. Geosci. Remote. Sens. | 2 |
| 2022 | SigRec: Automatic Recovery of Function Signatures in Smart ContractsabstractMillions of smart contracts have been deployed onto Ethereum for providing various services, whose functions can be invoked. For this purpose, the caller needs to know thefunction signatureof a callee, which includes its function id and parameter types. Such signatures arecriticalto many applications focusing on smart contracts, e.g., reverse engineering, fuzzing, attack detection, and profiling. Unfortunately, it is challenging to recover the function signatures from contract bytecode, since neither debug information nor type information is present in the bytecode. To address this issue, prior approaches rely on source code, or a collection of known signatures from incomplete databases or incomplete heuristic rules, which, however, are far from adequate and cannot cope with the rapid growth of new contracts. In this paper, we propose a novel solution that leverages how functions are handled by Ethereum virtual machine (EVM) to automatically recover function signatures. In particular, we exploit how smart contracts determine the functions to be invoked to locate and extract function ids, and propose a new approach namedtype-awaresymbolic execution (TASE) that utilizes the semantics of EVM operations on parameters to identify the number and the types of parameters. Moreover, we developSigRec, a new tool for recovering function signatures from contract bytecode without the need of source code and function signature databases. The extensive experimental results show thatSigRecoutperforms all existing tools, achieving an unprecedented 98.7 percent accuracy within 0.074 seconds. We further demonstrate that the recovered function signatures are useful in attack detection, fuzzing and reverse engineering of EVM bytecode. Ting Chen 0002, Zihao Li 0001, Xiapu Luo, XiaoFeng Wang 0001, Ting Wang 0006, Zheyuan He, Kezhao Fang, Yufei Zhang 0002, Hongwei Li 0001, Xiaosong Zhang 0001 |
IEEE Trans. Software Eng. | 6 |
| 2020 | SODA: A Generic Online Detection Framework for Smart Contracts
Ting Chen 0002, Rong Cao, Xiapu Luo, Guofei Gu, Yufei Zhang 0002, Zhou Liao, Zheyuan He, Yuxing Tang, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
NDSS | 10 |