Xihan Xiong

dblp:278/9106 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0009-0002-1604-0114ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 6 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 SoK of RWA Tokenization: A Systematization of Concepts, Architectures, and Legal Interoperability
Junliang Luo, Xihan Xiong, Zonglun Li, Hong Kang, Xue (Steve) Liu, William J. Knottenbelt, Katrin Tinn
ICBC2
2026 Understanding Post-Exploit Laundering Behavior on Ethereum
abstract
Money laundering enables malicious actors to integrate illegal profits into the legitimate economy and has long been a central concern in financial regulation. Blockchain systems introduce new channels for laundering through decentralized, pseudonymous, and cross-border asset transfers. In this context, blockchain exploiters often rely on laundering to conceal fund origins and enable cash-out.
Xihan Xiong, Junliang Luo
WWW1
2025 Decoding SEC Actions: Enforcement Trends through Analyzing Blockchain Litigation using LLM-based Thematic Factor Mapping
abstract
Blockchain’s potential for both financial and societal benefits is affected by regulatory ambiguities and enforcement actions against blockchain entities. Evolving regulatory frameworks emphasize the need for insights to protect users, small investors, and ensure equitable participation. Currently, the lack of systematic analysis creates barriers to understanding trends and making informed decisions about participation. This study proposes methods to analyze litigation drivers by the U.S. Securities and Exchange Commission (SEC), to facilitate regular users’ understanding of regulatory trends to make informed decisions about blockchain participation. Utilizing pretrained language models and large language models, we systematically map all SEC complaints against blockchain companies from 2012 to 2024 to thematic factors conceptualized to delineate the factors that drive SEC actions. We quantify the thematic factors and assess their influence on the legal Acts cited within the complaints on an annual basis, allowing us to discern the regulatory emphasis, patterns and conduct trend analysis.
Junliang Luo, Xihan Xiong, William J. Knottenbelt, Xue (Steve) Liu
ICAIL2
2025 RegKYC: Supporting Privacy and Compliance Enforcement for KYC in Blockchains
Xihan Xiong, Michael Huth 0001, William J. Knottenbelt
ICBC1
2025 Leverage Staking with Liquid Staking Derivatives (LSDs): Opportunities and Risks
Xihan Xiong, Zhipeng Wang 0009, Xi Chen 0015, William J. Knottenbelt, Michael Huth 0001
ICBC1
2025 Toxic Ink on Immutable Paper: Content Moderation for Ethereum Input Data Messages (IDMs)
abstract
Decentralized communication is becoming an important use case within Web3. On Ethereum, users can repurpose the transaction input data field to embed natural-language messages, commonly known as Input Data Messages (IDMs). However, as IDMs gain wider adoption, there has been a growing volume of toxic content on-chain. This trend is concerning, as Ethereum provides no protocol-level support for content moderation.We propose two moderation frameworks for Ethereum IDMs: (i) BUILDERMOD, where builders perform semantic checks during block construction; and (ii) USERMOD, where users proactively obtain moderation proofs from external classifiers and embed them in transactions. Our evaluation reveals that BUILDERMOD incurs high block-time overhead, which limits its practicality. In contrast, USERMOD enables lower-latency validation and scales more effectively, making it a more practical approach in moderation-aware Ethereum environments.Our study lays the groundwork for protocol-level content governance in decentralized systems, and we hope it contributes to the development of a decentralized communication environment that is safe, trustworthy, and socially responsible.
Xihan Xiong, Zhipeng Wang 0009, Qin Wang 0008, William J. Knottenbelt
TrustCom1
2024 Exploring the Market Dynamics of Liquid Staking Derivatives (LSDs)
abstract
Staking has emerged as a crucial concept following Ethereum’s transition to Proof-of-Stake consensus. The introduction of Liquid Staking Derivatives (LSDs) has effectively addressed the illiquidity issue associated with solo staking, gaining significant market attention. This paper analyzes the LSD market dynamics from the perspectives of both liquidity takers (LTs) and liquidity providers (LPs). We first quantify the price discrepancy between the LSD primary and secondary markets. Then we investigate and empirically measure how LTs can leverage such discrepancy to exploit arbitrage opportunities, unveiling the potential barriers to LSD arbitrages. In addition, we evaluate the financial profit and losses experienced by LPs who supply LSDs for liquidity provision. Our results show that 66% of LSD liquidity positions generate returns lower than those from simply holding the corresponding LSDs.
Xihan Xiong, Zhipeng Wang 0009, Qin Wang 0008
ICBC1
2023 SoK: Decentralized Finance (DeFi) Attacks
abstract
Within just four years, the blockchain-based Decentralized Finance (DeFi) ecosystem has accumulated a peak total value locked (TVL) of more than 253 billion USD. This surge in DeFi’s popularity has, unfortunately, been accompanied by many impactful incidents. According to our data, users, liquidity providers, speculators, and protocol operators suffered a total loss of at least 3.24 billion USD from Apr 30, 2018 to Apr 30, 2022. Given the blockchain’s transparency and increasing incident frequency, two questions arise: How can we systematically measure, evaluate, and compare DeFi incidents? How can we learn from past attacks to strengthen DeFi security?In this paper, we introduce a common reference frame to systematically evaluate and compare DeFi incidents, including both attacks and accidents. We investigate 77 academic papers, 30 audit reports, and 181 real-world incidents. Our data reveals several gaps between academia and the practitioners’ community. For example, few academic papers address "price oracle attacks" and "permissonless interactions", while our data suggests that they are the two most frequent incident types (15% and 10.5% correspondingly). We also investigate potential defenses, and find that: (i) 103 (56%) of the attacks are not executed atomically, granting a rescue time frame for defenders; (ii) bytecode similarity analysis can at least detect 31 vulnerable/23 adversarial contracts; and (iii) 33 (15.3%) of the adversaries leak potentially identifiable information by interacting with centralized exchanges.
Liyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos, Zhipeng Wang 0009, Kanye Ye Wang, Kaihua Qin, Roger Wattenhofer, Dawn Song, Arthur Gervais
SP2