EDBT 2026 Demo / reviewers in the wild / expert
Yituo He
dblp:281/0784
· DBLP profile ↗
3ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0003-0563-9022ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021Security and privacy · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
binary analysis |
0.9 | 1 | 2025 | Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive Emulation · Proc. ACM Program. Lang. 2025 |
Systems and software security › binary analysis
cryptographic function identification |
0.9 | 1 | 2025 | Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive Emulation · Proc. ACM Program. Lang. 2025 |
Program analysis
binary analysis |
0.9 | 1 | 2025 | Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive Emulation · Proc. ACM Program. Lang. 2025 |
Program analysis › program comparison
code similarity |
0.9 | 1 | 2025 | Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive Emulation · Proc. ACM Program. Lang. 2025 |
Methods — techniques the papers use, named apart from their topics
path-insensitive analysis · 1.7interval domain · 1.7emulation · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Binary Cryptographic Function Identification via Similarity Analysis with Path-Insensitive EmulationabstractIt becomes an essential requirement to identify cryptographic functions in binaries due to their widespread application in modern software. The technology fundamentally supports numerous software security analyses, such as malware analysis, blockchain forensics, etc. Unfortunately, the existing methods still struggle to strike a balance between analysis accuracy, efficiency, and code coverage, which hampers their practical application. In this paper, we propose BinCrypto, a method of emulation-based code similarity analysis on the interval domain, to identify cryptographic functions in binary files. It produces accurate results because it relies on the behavior-related code features collected during emulation. On the other hand, the emulation is performed in a path-insensitive manner, where the emulated values are all represented as intervals. As such, it is able to analyze every basic block only once, accomplishing the identification efficiently, and achieve complete block coverage simultaneously. We conduct the experiments with nine real-world cryptographic libraries. The results show that BinCrypto achieves the average accuracy of 83.2%, nearly twice that of WheresCrypto, the state-of-the-art method. BinCrypto is also able to successfully complete the tasks, including statically-linked library analysis, cross-library analysis, obfuscated code analysis, and malware analysis, demonstrating its potential for practical applications. Yikun Hu 0003, Yituo He, Wenyu He, Shuai Wang 0011, Dawu Gu |
Proc. ACM Program. Lang. | 2 |
| 2023 | RGDroid: Detecting Android Malware with Graph Convolutional Networks against Structural AttacksabstractThe rapid growth of Android malware calls for anti-malware systems to detect malware automatically. Detecting malware effectively is a non-trivial problem due to the high overlap in behaviors between malware and benign apps. Most existing automated Android malware detection methods use statistic features extracted from apps or graphs generated from method calls to identify malware. However, the methods that only use statistic features lead to false positives due to ignoring program semantics. Existing graph-based approaches suffer scalability problems due to the heavy-weight program analysis and time-consuming graph matching. In addition, graph-based approaches could be evaded by modifying dependencies among method calls. As a result, crafted malicious apps resemble the benign ones.In this paper, we propose a novel deep learning-based detection system, named RGDroid, which is capable of detecting malware under graph structural attacks. It combines API information extracted from Android document and learns behavior features from function call graph by graph neural network. Specifically, to defend against graph adversarial attacks, RGDroid reduces the connectivity of different functional parts to mitigate the effect of structural modifications on the final graph embedding. To comprehensively evaluate the robustness of RGDroid, we implement four influential graph adversarial attacks to simulate current capabilities and knowledge of Android malware attackers. The attack success rate (ASR) of two state-of-the-art detection systems (i.e., MaMaDroid, MalScan) is above 70.0% while the ASR of RGDroid under the four graph attacks is below 6.1%. Yakang Li, Yikun Hu 0003, Yizhuo Wang 0003, Yituo He, Haining Lu, Dawu Gu |
SANER | 4 |
| 2020 | AttriChain: Decentralized traceable anonymous identities in privacy-preserving permissioned blockchain
Chunfu Jia, Yunkai Xu, Kefan Qiu, Yituo He |
Comput. Secur. | 6 |