EDBT 2026 Demo / reviewers in the wild / expert
Yi Yang 0100
dblp:33/4854-100
· DBLP profile ↗
7ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0002-2628-3737ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Uncovering the iceberg from the tip: Generating API Specifications for Bug Detection via Specification Propagation Analysis
Miaoqian Lin, Kai Chen 0012, Yi Yang 0100 |
NDSS | 3 |
| 2025 | Generating API Parameter Security Rules with LLM for API Misuse Detection
Yi Yang 0100, Kai Chen 0012, Miaoqian Lin |
NDSS | 2 |
| 2025 | The Midas Touch: Triggering the Capability of LLMs for RM-API Misuse Detection
Yi Yang 0100, Kai Chen 0012, Miaoqian Lin |
NDSS | 1 |
| 2025 | What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors
Chang Yue, Kai Chen 0012, Zhixiu Guo, Jun Dai 0001, Xiaoyan Sun 0003, Yi Yang 0100 |
NDSS | 6 |
| 2023 | Jeu de mots paronomasia: a StackOverflow-driven bug discovery approachabstractAbstract Locating bug code snippets (short for BugCode) has been a complex problem throughout the history of software security, mainly because the constraints that define BugCode are obscure and hard to summarize. Previously, security analysts attempted to define such constraints manually (e.g., limiting buffer size to detect overflow), but were limited to the types of BugCode. Recent researchers address this problem by extracting constraints from program documentation, which shows the potential for API misuse. But for bugs beyond the scope of API misuse, such an approach becomes less effective since the corresponding constraints are not defined in documents, not to mention the programs without documentation In this paper, inspired by the fact that expert programmers often correct the BugCode on open forums such as StackOverflow, we design an approach to automatically extract knowledge from StackOverflow and leverage it to detect BugCode. As we all know, the contexts in StackOverflow come from ordinary developers. Their writing tends to be loosely organized and in various styles, which are more challenging to analyze than program documentation. To address the challenges, we design a custom tokenization approach to segment sentences and employ sentiment analysis to find the Controversial Sentences (CSs) that typically contain the constraints we need for code analysis. Then we use constituency parsing to extract knowledge from CSs, which helps locate BugCode. We evaluated our system on 41,144 comments from the questions tagged with Java and Android. The results show that our approach achieves 95.5% precision in discovering CSs. We have discovered 276 pieces of BugCode proved to be true through manual validation including an assigned CVE. 89.3% of the discovered bugs remained in the current version of answers, which are unknown to users. Yi Yang 0100, Ying Li 0104, Kai Chen 0012 |
Cybersecur. | 1 |
| 2020 | RTFM! Automatic Assumption Discovery and Verification Derivation from Library Document for API Misuse DetectionabstractTo use library APIs, a developer is supposed to follow guidance and respect some constraints, which we call integration assumptions (IAs). Violations of these assumptions can have serious consequences, introducing security-critical flaws such as use-after-free, NULL-dereference, and authentication errors. Analyzing a program for compliance with IAs involves significant effort and needs to be automated. A promising direction is to automatically recover IAs from a library document using Natural Language Processing (NLP) and then verify their consistency with the ways APIs are used in a program through code analysis. However, a practical solution along this line needs to overcome several key challenges, particularly the discovery of IAs from loosely formatted documents and interpretation of their informal descriptions to identify complicated constraints (e.g., data-/control-flow relations between different APIs). Ruishi Li, Yi Yang 0100, Kai Chen 0012, Xiaojing Liao, XiaoFeng Wang 0001, Peiwei Hu, Luyi Xing |
CCS | 3 |
| 2018 | Detecting telecommunication fraud by understanding the contents of a callabstractTelecommunication fraud has continuously been causing severe financial loss to telecommunication customers in China for several years. Traditional approaches to detect telecommunication frauds usually rely on constructing a blacklist of fraud telephone numbers. However, attackers can simply evade such detection by changing their numbers, which is very easy to achieve through VoIP (Voice over IP). To solve this problem, we detect telecommunication frauds from the contents of a call instead of simply through the caller’s telephone number. Particularly, we collect descriptions of telecommunication fraud from news reports and social media. We use machine learning algorithms to analyze data and to select the high-quality descriptions from the data collected previously to construct datasets. Then we leverage natural language processing to extract features from the textual data. After that, we build rules to identify similar contents within the same call for further telecommunication fraud detection. To achieve online detection of telecommunication frauds, we develop an Android application which can be installed on a customer’s smartphone. When an incoming fraud call is answered, the application can dynamically analyze the contents of the call in order to identify frauds. Our results show that we can protect customers effectively. Kai Chen 0012, Tongxin Li 0002, Yi Yang 0100, XiaoFeng Wang 0001 |
Cybersecur. | 4 |