EDBT 2026 Demo / reviewers in the wild / expert
Jiashuo Liang
dblp:277/8159
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0003-0410-5515ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Poster: Black-box Attacks on Multimodal Large Language Models through Adversarial ICC ProfilesabstractDespite their remarkable performance on vision-language tasks, multimodal large language models (MLLMs) remain vulnerable to adversarial examples. However, most existing attacks rely on gradient-based pixel perturbations and require white-box access to model parameters. In this paper, we propose ICCAdv, a novel black-box attack that requires no access to model parameters or gradients. The core idea of ICCAdv is to exploit the discrepancy between human and model perception of images during input processing. This discrepancy arises from the color management process, as human observers perceive rendered images based on ICC profile transformations, whereas most MLLMs circumvent this process and operate directly on raw RGB values. By embedding adversarial ICC profiles into image files, ICCAdv manipulates the perceived color semantics of MLLMs while preserving the natural visual appearance for human observers. Preliminary experiments indicate that ICCAdv can effectively attack state-of-the-art MLLMs while maintaining a natural visual appearance to human observers. Chengbin Sun, Hailong Sun 0001, Guancheng Li, Jiashuo Liang |
CCS | 4 |
| 2023 | RaceBench: A Triggerable and Observable Concurrency Bug BenchmarkabstractConcurrency bugs are one of the most harmful and hard-to-address issues in multithreaded software. Such bugs are hard to discover, reproduce, diagnose or fix due to their non-deterministic nature. Although more and more bug discovery solutions are proposed in recent years, it is difficult to evaluate them with existing concurrency bug datasets. The demand for building a high-quality benchmark of concurrency bugs emerges. Jiashuo Liang, Ming Yuan 0003, Zhanzhao Ding, Siqi Ma 0001, Xinhui Han, Chao Zhang 0008 |
AsiaCCS | 1 |
| 2023 | DDRace: Finding Concurrency UAF Vulnerabilities in Linux Drivers with Directed Fuzzing
Ming Yuan 0003, Bodong Zhao, Penghui Li 0001, Jiashuo Liang, Xinhui Han, Xiapu Luo, Chao Zhang 0008 |
USENIX Security Symposium | 4 |
| 2022 | Poster: MSILDiffer - A Security Patch Analysis Framework Based on Microsoft Intermediate Language for Large SoftwareabstractIn this poster, we proposed a .NET patch analysis framework named MSILDiffer based on Microsoft Intermediate Language (MSIL). First, MSILDiffer directly extracts MSIL instructions from the .NET assemblies, and retrieves the hierarchy of classes as well as their internal class methods. Then, with coarse and fine granularity feature extraction and comparison, MSILDiffer quickly filters out the code with substantial changes after patch. Besides, we build a dataset of patch analysis containing 24.46 million class methods based on the Microsoft Exchange mail system security patches. With the assistance of MSILDiffer, we generated 32 call paths and crafted corresponding POCs for 1-day vulnerabilities in the dataset. Through the experiment evaluation, MSILDiffer is superior to JustAssembly in terms of coverage, accuracy and time consumption of patch difference analysis. Can Huang 0001, Cheng Li 0045, Jiashuo Liang, Xinhui Han |
CCS | 3 |
| 2020 | RIPT - An Efficient Multi-Core Record-Replay SystemabstractGiven the same input, a program may not behave the same in two runs due to some non-deterministic features, e.g., context switch and randomization. Such behaviors would cause non-deterministic program bugs which are hard to discover or diagnose. Record-and-replay is a promising technique to address such issues, however, performance and transparency are the main obstacles of existing works. In this poster, we propose a novel record-and-replay system named RIPT. RIPT utilizes Intel Processor Trace to record control flow information with very low overhead, and transparently captures non-deterministic sources such as system calls and signals with a kernel module. During replay, RIPT recovers the effect of non-deterministic events from the collected information, and makes target programs behave the same as recorded. We evaluate it with real-world program bugs and show that RIPT works well in practice. Jiashuo Liang, Guancheng Li, Chao Zhang 0008, Ming Yuan 0003, Xingman Chen, Xinhui Han |
CCS | 1 |