Levi Taiji Li

dblp:332/3196 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 ICSTracker: Backtracking Intrusions in Modern Industrial Control Systems
abstract
Applying "provenance analysis" to industrial control systems (ICS) is challenging. Existing research struggles with recovering the physical semantics of controller logic, managing inconsistent state transitions, tracking cross-domain causality, and practical implementation. In this paper, we introduce ICS Tracker, a comprehensive approach that addresses these gaps by using digital twins to collect logs, automatically recovering physical semantics, reconstructing data dependencies, and linking controller operations to OS-level events. Tested on ten attack scenarios across two testbeds, ICSTracker outperforms previous methods, capturing all attack activities where earlier techniques missed 56%.
Md. Raihan Ahmed, Jainta Paul, Levi Taiji Li, Luis Garcia 0001, Mu Zhang 0001
DSN3
2024 VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" Vulnerabilities
Levi Taiji Li, Ningyu He, Haoyu Wang 0001, Mu Zhang 0001
NDSS1
2023 Automated Generation of Security-Centric Descriptions for Smart Contract Bytecode
abstract
Smart contract and DApp users are taking great risks, as they do not obtain necessary knowledge that can help them avoid using vulnera- ble and malicious contract code. In this paper, we develop a novel system Tx2TXT that can automatically create security-centric textual descriptions directly from smart contract bytecode. To capture the security aspect of financial applications, we formally define a funds transfer graph to model critical funds flows in smart contracts. To ensure the expressiveness and conciseness of the descriptions de- rived from these graphs, we employ a GCN-based model to identify security-related condition statements and selectively add them to our graph models. To convert low-level bytecode instructions to human- readable textual scripts, we leverage robust API signatures to recover bytecode semantics. We have evaluated Tx2TXT on 890 well-labeled vulnerable, malicious and safe contracts where developer-crafted descriptions are available. Our results have shown that Tx2TXT out- performs state-of-the-art solutions and can effectively help end users avoid risky contracts
Zhichao Xu 0001, Levi Taiji Li, Yunhe Yang, Mu Zhang 0001
ISSTA3
2022 Poster: EOSDFA: Data Flow Analysis of EOSIO Smart Contracts
abstract
As an efficient blockchain platform, EOSIO is becoming increasingly popular. However, it has exposed many security problems and caused a large amount of financial losses. In the past, the difficulty of collecting open-source EOSIO smart contracts and analyzing WebAssembly (Wasm) bytecode compiled by EOSIO smart contracts, making few researchers proposed static analysis tools for EOSIO smart contracts, and tools capable of dataflow analysis have not yet appeared. In this work, we first propose a dataflow analysis method for EOSIO smart contracts. Based on Octopus, we designed an efficient dataflow analysis method, which can generate Static Single Assignment (SSA) form intermediate representation (IR) for the objective function and its variables to obtain the results of dataflow. We further proved the effectiveness of the proposed method through experiments on our collected data sets.
Levi Taiji Li, Mu Zhang 0001
CCS1