EDBT 2026 Demo / reviewers in the wild / expert
Rujin Liang
dblp:331/8522
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2023
0009-0004-3104-3051ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Blockchain and cryptocurrency security · 87% Systems and software security · 13% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Blockchain and cryptocurrency security
smart contract security |
0.7 | 1 | 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning · IEEE Trans. Software Eng. 2023 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
0.7 | 1 | 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning · IEEE Trans. Software Eng. 2023 |
Program analysis
dynamic analysis |
0.7 | 1 | 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning · IEEE Trans. Software Eng. 2023 |
Program analysis
symbolic execution |
0.7 | 1 | 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning · IEEE Trans. Software Eng. 2023 |
Systems and software security › vulnerability discovery
machine-learning-based vulnerability detection |
0.2 | 1 | 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning · IEEE Trans. Software Eng. 2023 |
Methods — techniques the papers use, named apart from their topics
symbolic execution · 1.3multiple instance learning · 1.3hybrid attention · 1.3control flow graph · 1.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance LearningabstractWith the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle. Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002 |
IEEE Trans. Software Eng. | 5 |
| 2022 | SmartFast: an accurate and robust formal analysis tool for Ethereum smart contracts
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Rui Xue 0001, Wenqiu Ma, Rujin Liang, Ziming Zhao 0008, Sheng Gao 0002 |
Empir. Softw. Eng. | 6 |