EDBT 2026 Demo / reviewers in the wild / expert
Kunsong Zhao
dblp:276/3918
· DBLP profile ↗
21ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0001-9886-0460ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 9 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Smart Contract Vulnerability Detection Empowered by LLM: Can It Really Work?
Kunsong Zhao, Xiapu Luo, Yuzhe Tang |
ICBC | 2 |
| 2025 | Soleker: Uncovering Vulnerabilities in Solana Smart ContractsabstractSolana has rapidly evolved into a leading next generation platform for supporting decentralized applications due to its high performance and low transaction costs. Its new contract execution model, which decouples code logic from states, gives rise to new vulnerability threats that can result in significant financial losses for users within the ecosystem. However, existing studies towards detecting vulnerabilities are predominantly tailored for Ethereum smart contracts, which are unsuitable for Solana platform because of the variations in implementation languages and runtime semantics. In this paper, we propose Soleker, a novel approach that leverages learning-based techniques to automatically identifying potential vulnerabilities in Solana smart contract bytecode. More specifically, Soleker captures runtime semantic information from instructions that are associated with blockchain interactions and extracts vulnerability-specific localized features. Then, a prefix-guided graph learning model is introduced to learn and integrate extracted features, enabling effective vulnerability detection. We conduct experiments on a newly constructed contract dataset and the results demonstrate that Soleker significantly outperforms the baseline methods, achieving an average effectiveness improvement of 126.4% and a 335× boost in efficiency. Kunsong Zhao, Yunpeng Tian, Zuchao Ma, Xiapu Luo |
ASE | 1 |
| 2025 | Automated Soundness and Completeness Vetting of Polygon zkEVM
Xinghao Peng, Kunsong Zhao, Zuchao Ma, Zihao Li 0001, Jinan Jiang, Xiapu Luo, Yinqian Zhang |
USENIX Security Symposium | 3 |
| 2024 | VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability AnalysesabstractAccompanying the successes of learning-based defensive software vulnerability analyses is the lack of large and quality sets of labeled vulnerable program samples, which impedes further advancement of those defenses. Existing automated sample generation approaches have shown potentials yet still fall short of practical expectations due to the high noise in the generated samples. This paper proposes VGX, a new technique aimed for large-scale generation of high-quality vulnerability datasets. Given a normal program, VGX identifies the code contexts in which vulnerabilities can be injected, using a customized Transformer featured with a new value-flow-based position encoding and pre-trained against new objectives particularly for learning code structure and context. Then, VGX materializes vulnerability-injection code editing in the identified contexts using patterns of such edits obtained from both historical fixes and human knowledge about real-world vulnerabilities. Yu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao, Xiapu Luo, Feng Chen 0001, Haipeng Cai |
ICSE | 4 |
| 2024 | Question-Directed Reasoning With Relation-Aware Graph Attention Network for Complex Question Answering Over Knowledge GraphabstractComplex knowledge graph question answering (KGQA) aims at answering natural language questions by entities retrieving from a knowledge graph (KG). Recently, the relation path-based models have shown the unique advantage for complex KGQA. However, these existing models ignore the dependency between different relation paths, which leads to aimless reasoning over the KG. To resolve this issue, we propose the question-directed reasoning with relation-aware graph attention network (QRGAT) that encodes the reasoning process as a reasoning graph. The relation-aware GAT can recognize neighbor entities along with the corresponding relations for each entity. With the relation-aware GAT stacked in multiple layers, it can collaboratively capture the dependency of different relation paths for each entity. The question-directed reasoning utilizes the information learned by the relation-aware GAT to solve the aimless reasoning on the KG by constructing a reasoning graph. Extensive experiments demonstrate that our QRGAT outperforms the baseline models on both popular datasets WebQuestionsSP and ComplexWebQuestions. Compared with the strong GNN-based baseline NSM$_{+h}$, our QRGAT achieves the performance improvements of 2.3% on WebQuestionsSP and 3.6% on ComplexWebQuestions by the metric Hits@1. Geng Zhang 0002, Jin Liu 0016, Guangyou Zhou, Kunsong Zhao, Zhiwen Xie, Bo Huang 0014 |
IEEE ACM Trans. Audio Speech Lang. Process. | 4 |
| 2023 | DeepInfer: Deep Type Inference from Smart Contract BytecodeabstractSmart contracts play an increasingly important role in Ethereum platform. It provides various functions implementing numerous services, whose bytecode runs on Ethereum Virtual Machine. To use services by invoking corresponding functions, the callers need to know the function signatures. Moreover, such signatures provide crucial information for many downstream applications, e.g., identifying smart contracts, fuzzing, detecting vulnerabilities, etc. However, it is challenging to infer function signatures from the bytecode due to a lack of type information. Existing work solving this problem depended heavily on limited databases or hard-coded heuristic patterns. However, these approaches are hard to be adapted to semantic differences in distinct languages and various compiler versions when developing smart contracts. In this paper, we propose a novel framework DeepInfer that first leverages deep learning techniques to automatically infer function signatures and returns. The novelties of DeepInfer are: 1) DeepInfer lifts the bytecode into the Intermediate Representation (IR) to preserve code semantics; 2) DeepInfer extracts the type-related knowledge (e.g., critical data flows, constant values, and control flow graphs) from the IR to recover function signatures and returns. We conduct experiments on Solidity and Vyper smart contracts and the results show that DeepInfer performs faster and more accurate than existing tools, while being immune to changes in different languages and various compiler versions. Kunsong Zhao, Zihao Li 0001, Jianfeng Li 0006, He Ye, Xiapu Luo, Ting Chen 0002 |
ESEC/SIGSOFT FSE | 1 |
| 2023 | Extended Abstract of Graph4Web: A Relation-Aware Graph Attention Network for Web Service ClassificationabstractSoftware reuse, as a means to develop new software products with similar functions by virtue of existing software components, has become a popular way during the software development process. In particular, as the service-oriented architecture became popular, web services turned into an indispensable part in modem software development Web services provide a basic composition with high cohesion and loose coupling to support responses among heterogeneous software components, which is the valuable resources for software reuse. The popular web service repositories, such as Programmable Web, contain a mass of web services for beginners and developers to choose from. Nevertheless, the large number of web services also makes it difficult to select the suitable services. Thus, the key to reuse software components lies in how to find appropriate web services from repositories to meet developers requirements in specific application scenarios. Kunsong Zhao, Jin Liu 0016, Zhou Xu 0003, Xiao Liu 0004, Lei Xue 0001, Zhiwen Xie, Xin Wang 0114 |
SANER | 1 |
| 2023 | The impact of class imbalance techniques on crashing fault residence prediction models
Kunsong Zhao, Zhou Xu 0003, Meng Yan 0001, Tao Zhang 0001, Lei Xue 0001, Ming Fan 0002, Jacky W. Keung |
Empir. Softw. Eng. | 1 |
| 2023 | Detecting multi-type self-admitted technical debt with generative adversarial network-based neural networks
Jiaojiao Yu 0001, Zhou Xu 0003, Xiao Liu 0004, Jin Liu 0016, Zhiwen Xie, Kunsong Zhao |
Inf. Softw. Technol. | 6 |
| 2022 | Effort-aware cross-project just-in-time defect prediction framework for mobile apps
Tian Cheng 0004, Kunsong Zhao, Muhammad Mateen, Junhao Wen 0001 |
Frontiers Comput. Sci. | 2 |
| 2022 | A compositional model for effort-aware Just-In-Time defect prediction on android appsabstractAbstract Android apps have played important roles in daily life and work. To meet the new requirements from users, the apps encounter frequent updates, which involves a large quantity of code commits. Previous studies proposed to apply Just‐in‐Time (JIT) defect prediction for apps to timely identify whether the new code commits can introduce defects into apps, aiming to assure their quality. In general, high‐quality features are benefits for improving the classification performance. In addition, the number of defective commit instances is much fewer than that of clean ones, that is the defect data is class imbalanced. In this study, a novel compositional model, called KPIDL, is proposed to conduct the JIT defect prediction task for Android apps. More specifically, KPIDL first exploits a feature learning technique to preprocess original data for obtaining better feature representation, and then introduces a state‐of‐the‐art cost‐sensitive cross‐entropy loss function into the deep neural network to alleviate the class imbalance issue by considering the prior probability of the two types of classes. The experiments were conducted on a benchmark defect data consisting of 15 Android apps. The experimental results show that the proposed KPIDL model performs significantly better than 25 comparative methods in terms of two effort‐aware performance indicators in most cases. Kunsong Zhao, Zhou Xu 0003, Meng Yan 0001, Lei Xue 0001, Wei Li 0121, Gemma Catolino |
IET Softw. | 1 |
| 2022 | Exploiting gated graph neural network for detecting and explaining self-admitted technical debts
Jiaojiao Yu 0001, Kunsong Zhao, Jin Liu 0016, Xiao Liu 0004, Zhou Xu 0003, Xin Wang 0114 |
J. Syst. Softw. | 2 |
| 2022 | Graph4Web: A relation-aware graph attention network for web service classification
Kunsong Zhao, Jin Liu 0016, Zhou Xu 0003, Xiao Liu 0004, Lei Xue 0001, Zhiwen Xie, Xin Wang 0114 |
J. Syst. Softw. | 1 |
| 2022 | Dual Gated Graph Attention Networks with Dynamic Iterative Training for Cross-Lingual Entity AlignmentabstractCross-lingual entity alignment has attracted considerable attention in recent years. Past studies using conventional approaches to match entities share the common problem of missing important structural information beyond entities in the modeling process. This allows graph neural network models to step in. Most existing graph neural network approaches model individual knowledge graphs (KGs) separately with a small amount of pre-aligned entities served as anchors to connect different KG embedding spaces. However, this characteristic can cause several major problems, including performance restraint due to the insufficiency of available seed alignments and ignorance of pre-aligned links that are useful in contextual information in-between nodes. In this article, we propose DuGa-DIT, a dual gated graph attention network with dynamic iterative training, to address these problems in a unified model. The DuGa-DIT model captures neighborhood and cross-KG alignment features by using intra-KG attention and cross-KG attention layers. With the dynamic iterative process, we can dynamically update the cross-KG attention score matrices, which enables our model to capture more cross-KG information. We conduct extensive experiments on two benchmark datasets and a case study in cross-lingual personalized search. Our experimental results demonstrate that DuGa-DIT outperforms state-of-the-art methods. Zhiwen Xie, Runjie Zhu, Kunsong Zhao, Jin Liu 0016, Guangyou Zhou, Jimmy Huang 0001 |
ACM Trans. Inf. Syst. | 3 |
| 2022 | Effort-Aware Just-in-Time Bug Prediction for Mobile Apps Via Cross-Triplet Deep Feature EmbeddingabstractJust-in-time (JIT) bug prediction is an effective quality assurance activity that identifies whether a code commit will introduce bugs into the mobile app, aiming to provide prompt feedback to practitioners for priority review. Since collecting sufficient labeled bug data is not always feasible for some mobile apps, one possible approach is to leverage cross-app models. In this work, we propose a new cross-triplet deep feature embedding method, called CDFE, for cross-app JIT bug prediction task. The CDFE method incorporates a state-of-the-art cross-triplet loss function into a deep neural network to learn high-level feature representation for the cross-app data. This loss function adapts to the cross-app feature learning task and aims to learn a new feature space to shorten the distance of commit instances with the same label and enlarge the distance of commit instances with different labels. In addition, this loss function assigns higher weights to losses caused by cross-app instance pairs than that by intra-app instance pairs, aiming to narrow the discrepancy of cross-app bug data. We evaluate our CDFE method on a benchmark bug dataset from 19 mobile apps with two effort-aware indicators. The experimental results on 342 cross-app pairs show that our proposed CDFE method performs better than 14 baseline methods. Zhou Xu 0003, Kunsong Zhao, Tao Zhang 0001, Chunlei Fu, Meng Yan 0001, Zhiwen Xie, Xiaohong Zhang 0002, Gemma Catolino |
IEEE Trans. Reliab. | 2 |
| 2021 | Predicting Crash Fault Residence via Simplified Deep Forest Based on A Reduced Feature SetabstractThe software inevitably encounters the crash, which will take developers a large amount of effort to find the fault causing the crash (short for crashing fault). Developing automatic methods to identify the residence of the crashing fault is a crucial activity for software quality assurance. Researchers have proposed methods to predict whether the crashing fault resides in the stack trace based on the features collected from the stack trace and faulty code, aiming at saving the debugging effort for developers. However, previous work usually neglected the feature preprocessing operation towards the crash data and only used traditional classification models. In this paper, we propose a novel crashing fault residence prediction framework, called ConDF, which consists of a consistency based feature subset selection method and a state-of-the-art deep forest model. More specifically, first, the feature selection method is used to obtain an optimal feature subset and reduce the feature dimension by reserving the representative features. Then, a simplified deep forest model is employed to build the classification model on the reduced feature set. The experiments on seven open source software projects show that our ConDF method performs significantly better than 17 baseline methods on three performance indicators. Kunsong Zhao, Jin Liu 0016, Zhou Xu 0003, Li Li 0029, Meng Yan 0001, Jiaojiao Yu 0001 |
ICPC | 1 |
| 2021 | A comprehensive investigation of the impact of feature selection techniques on crashing fault residence prediction models
Kunsong Zhao, Zhou Xu 0003, Meng Yan 0001, Tao Zhang 0001, Dan Yang 0001, Wei Li 0121 |
Inf. Softw. Technol. | 1 |
| 2021 | Simplified Deep Forest Model Based Just-in-Time Defect Prediction for Android Mobile AppsabstractThe popularity of mobile devices has led to an explosive growth in the number of mobile apps in which Android mobile apps are the mainstream. Android mobile apps usually undergo frequent update due to new requirements proposed by users. Just-in-time (JIT) defect prediction is appropriate for this scenario for quality assurance because it can provide timely feedback by determining whether a new code commit will introduce defects into the apps. As defect-prediction performance usually relies on the quality of the data representation and the used classification model, in this work, we propose a model, called Simplified Deep Forest (SDF), to conduct JIT defect prediction for Android mobile apps. SDF modifies a state-of-the-art deep forest model by removing the multigrained scanning operation that is designed for data with a high-dimensional feature space. It uses a cascade structure with ensemble forests for representation learning and classification. We conduct experiments on 10 Android mobile apps and experimental results show that SDF performs significantly better than comparative methods in terms of 3 performance indicators. Kunsong Zhao, Zhou Xu 0003, Tao Zhang 0001, Yutian Tang, Meng Yan 0001 |
IEEE Trans. Reliab. | 1 |
| 2020 | A Contextual Alignment Enhanced Cross Graph Attention Network for Cross-lingual Entity AlignmentabstractCross-lingual entity alignment, which aims to match equivalent entities in KGs with different languages, has attracted considerable focus in recent years.Recently, many graph neural network (GNN) based methods are proposed for entity alignment and obtain promising results.However, existing GNN-based methods consider the two KGs independently and learn embeddings for different KGs separately, which ignore the useful pre-aligned links between two KGs.In this paper, we propose a novel Contextual Alignment Enhanced Cross Graph Attention Network (CAECGAT) for the task of cross-lingual entity alignment, which is able to jointly learn the embeddings in different KGs by propagating cross-KG information through pre-aligned seed alignments.We conduct extensive experiments on three benchmark cross-lingual entity alignment datasets.The experimental results demonstrate that our proposed method obtains remarkable performance gains compared to state-of-the-art methods. Zhiwen Xie, Runjie Zhu, Kunsong Zhao, Jin Liu 0016, Guangyou Zhou, Jimmy Huang 0001 |
COLING | 3 |
| 2020 | Simplified Deep Forest Model based Just-In-Time Defect Prediction for Android Mobile AppsabstractThe popularity of mobile devices has led to an explosive growth in the number of mobile apps in which Android mobile apps are the mainstream. Android mobile apps usually undergo frequent update due to new requirements proposed by users. Just-In-Time (JIT) defect prediction is appropriate for this scenario for quality assurance because it can provide timely feedback by determining whether a new code commit will introduce defects into the apps. As defect prediction performance usually relies on the quality of the data representation and the used classification model, in this work, we modify a state-of-the-art model, called Simplified Deep Forest (SDF) to conduct JIT defect prediction for Android mobile apps. This method uses a cascade structure with ensemble forests for representation learning and classification. We conduct experiments on 10 Android mobile apps and experimental results show that SDF performs significantly better than comparative methods in terms of three performance indicators. Kunsong Zhao, Zhou Xu 0003, Tao Zhang 0001, Yutian Tang |
QRS | 1 |
| 2020 | Imbalanced metric learning for crashing fault residence prediction
Zhou Xu 0003, Kunsong Zhao, Meng Yan 0001, Peipei Yuan, Yan Lei 0005, Xiaohong Zhang 0002 |
J. Syst. Softw. | 2 |