EDBT 2026 Demo / reviewers in the wild / expert
Youkun Shi
dblp:331/2215
· DBLP profile ↗
12ranked-venue papers
6as first author
12since 2021 · last 2026
0009-0004-0763-4732ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 9 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LinkGuard: A Lightweight State-Aware Runtime Guard Against Link Following Attacks in Windows File System
Bocheng Xiang, Youkun Shi |
NDSS | 5 |
| 2026 | Measuring and Understanding Expectation Inconsistency in Java Libraries
Yuan Zhang 0009, Letian Yuan, Guangliang Yang 0001, Youkun Shi, Min Yang 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | BACScan: Automatic Black-Box Detection of Broken-Access-Control Vulnerabilities in Web ApplicationsabstractBroken-Access-Control (BAC) vulnerabilities have consistently been ranked among the most critical security risks in web applications, occupying the top positions in the OWASP Top 10 over the past several years. These vulnerabilities allow attackers to bypass access control mechanisms and perform unauthorized operations, posing serious security and privacy threats to sensitive business and user data. Despite substantial attention given to BAC vulnerabilities, effective and reliable approaches to detecting these issues remain limited. In this work, we present BACScan, a novel black-box approach to detect BAC vulnerabilities in web applications. Unlike existing response similarity-based oracles that check only unauthorized read accesses, BACScan introduces an innovative feedback-driven oracle, which determines whether unauthorized read or modification operations have occurred by inferring operationally-dependent web pages and analyzing the operational feedback. We evaluated BACScan on 20 real-world applications and successfully identified 89 vulnerabilities, including 54 previously unreported ones, outperforming state-of-the-art tools. We reported all newly identified vulnerabilities to the affected vendors. To date, 35 new CVE IDs have been assigned. Yuan Zhang 0009, Enhao Li, Wei Meng 0001, Youkun Shi, Qianheng Wang, Chenlin Wang, Min Yang 0002 |
CCS | 5 |
| 2025 | Detecting Taint-Style Vulnerabilities in Microservice-Structured Web ApplicationsabstractMicroservice architecture has been becoming increasingly popular for building scalable and maintainable applications. A microservice-structured web application (shortened to microservice application) enhances security by providing a loose-coupling design and enforcing the security isolation between different microservices. However, in this paper, our study shows microservice applications still suffer from taint-style vulnerability, one of the most serious vulnerabilities. We propose a novel security analysis approach, named MScan, that can effectively detect taint-style vulnerabilities in real-world evolving-fast microservice applications. Our approach mainly consists of three phases. First, MScan identifies the entry points accessible to external malicious users by applying a gateway-centric analysis. Second, MScan utilizes a new data structure, i.e. service dependence graph, to bridge inter-service communication. Finally, MScan employs a distance-guided strategy for selective context-sensitive taint analysis to detect vulnerabilities. By applying MScan on 25 open-source microservice applications and 5 industrial microservice applications from a world-leading fintech company, we found MScan can effectively vet these applications with the discovery of 59 high-risk 0-day vulnerabilities. We have conducted responsible vulnerability disclosure. Up to now, 31 CVE identifiers have been issued. Yuan Zhang 0009, Youkun Shi, Guangliang Yang 0001, Min Yang 0002, Junyao He |
SP | 4 |
| 2025 | MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web ApplicationsabstractJava web applications have been extensively utilized for hosting and powering high-value commercial websites. However, their intricate complexities leave them susceptible to a critical security flaw, named Missing-Owner-Check (MOC), that may expose websites to unauthorized access and data breaches. However, the research on identifying and analyzing MOC vulnerabilities has been limited over the years. In this work, we propose a novel end-to-end vulnerability analysis approach, called MOCGuard, that can effectively vet Java web applications against MOC issues. Different from related techniques, MOCGuard pinpoints MOC vulnerabilities from a new perspective of database-centric analysis. MOCGuard first applies database structure analysis to infer user table and user-owned data. Then, MOCGuard conducts insecure access checks across both the Java and SQL layers. To thoroughly evaluate the effectiveness of MOCGuard, we collaborated with a world-leading tech company. Through our evaluation of 30 high-profile open-source Java web applications and 7 industrial Java web applications, we demonstrate that MOCGuard is automatic and effective. Consequently, it successfully uncovered 161 (confirmed) 0-day MOC vulnerabilities, leading to the assignment of 73 CVE identifiers. Youkun Shi, Yuan Zhang 0009, Guangliang Yang 0001, Enhao Li, Min Yang 0002 |
SP | 2 |
| 2025 | Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based Agents
Yuan Zhang 0009, Jiaqi Luo, Jiarun Dai, Letian Yuan, Zhengmin Yu, Youkun Shi, Chengyuan Zhou, Hao Chen 0003, Min Yang 0002 |
USENIX Security Symposium | 8 |
| 2025 | XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent Fuzzing
Youkun Shi, Yuan Zhang 0009, Tianhao Bai, Jiarun Dai, Lei Zhang 0096, Xiapu Luo, Min Yang 0002 |
USENIX Security Symposium | 1 |
| 2025 | Facilitating Access Control Vulnerability Detection in Modern Java Web Applications With Accurate Permission Check Identification
Youkun Shi, Guangliang Yang 0001, Yuan Zhang 0009, Yinzhi Cao, Enhao Li, Xiapu Luo, Min Yang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | PHPJoy: A Novel Extended Graph-Based PHP Code Analysis FrameworkabstractNowadays, the PHP language is widely used in web development. Owing to PHP’s inherent flexibility and dynamic language features (e.g., cross-module dependencies and runtime polymorphism), PHP applications are prone to various security vulnerabilities, such as XSS and SQL injection. As an effective PHP semantic understanding and security vetting technique, static program analysis has been widely applied. However, prior work faced difficulties in dealing with diverse and dynamic PHP features, which caused serious false negatives (e.g., call target missing).In this paper, we propose a novel extended graph-based program analysis approach, calledPHPJoy, that can effectively and universally learn the semantic landscape of the target PHP program and conduct security validations. Specifically,PHPJoyfirst performs fine-grained program analysis (i.e., cross-module analysis and field-level analysis) for the purpose of learning the extended semantic graphs. Then, based on the graph-based semantic information,PHPJoyuniversally models various security issues by efficiently utilizing a new security-oriented graph query framework, which provides rich and easy-to-use graph query APIs and a high-performance cache-and-prefetch strategy.We evaluatePHPJoyon 333 popular PHP programs. The results show thatPHPJoycan effectively discover 269,901,982 semantic graph edges, improving by 23.76% when compared to the existing analysis tools. Our further analysis also shows that the runtime analysis overhead is reduced by 76.54%. Furthermore,PHPJoysuccessfully hunts 53 zero-day security vulnerabilities in the wild, which verifies the practicality ofPHPJoy. Youkun Shi, Yuan Zhang 0009, Tianhan Luo, Guangliang Yang 0001, Shengke Ye, Xiapu Luo, Min Yang 0002 |
IEEE Trans. Software Eng. | 1 |
| 2024 | RecurScan: Detecting Recurring Vulnerabilities in PHP Web ApplicationsabstractDetecting recurring vulnerabilities has become a popular means of static vulnerability detection in recent years because they do not require labor-intensive vulnerability modeling. Recently, a body of work, with HiddenCPG as a representative, has redefined the problem of statically identifying recurring vulnerabilities as the subgraph isomorphism problem. More specifically, these approaches represent known vulnerable code as graph-based structures (e.g., PDG or CPG), and then identify subgraphs within target applications that match the vulnerable graphs. However, since these methods are highly sensitive to changes in the code graph, they may miss a significant number of recurring vulnerabilities with slight code differences from known vulnerabilities. Youkun Shi, Yuan Zhang 0009, Tianhao Bai, Lei Zhang 0096, Min Yang 0002 |
WWW | 1 |
| 2022 | Precise (Un)Affected Version Analysis for Web VulnerabilitiesabstractWeb applications are attractive attack targets given their popularity and large number of vulnerabilities. To mitigate the threat of web vulnerabilities, an important piece of information is their affected versions. However, it is non-trivial to build accurate affected version information because confirming a version as affected or unaffected requires security expertise and huge efforts, while there are usually hundreds of versions to examine. As a result, such information is maintained in a low-quality manner in almost every public vulnerability database. Therefore, it is extremely useful to have a tool that can automatically and precisely examine a large part (even if not all) of the software versions as affected or unaffected. Youkun Shi, Yuan Zhang 0009, Tianhan Luo, Min Yang 0002 |
ASE | 1 |
| 2022 | Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches
Youkun Shi, Yuan Zhang 0009, Tianhan Luo, Yinzhi Cao, Yudi Zhao, Zongan Huang, Min Yang 0002 |
USENIX Security Symposium | 1 |