EDBT 2026 Demo / reviewers in the wild / expert
Xiao Dai
dblp:351/7282
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2023
0000-0001-9591-0039ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 50% Software testing · 50% | |
| Network and information security
1 paper |
Blockchain and cryptocurrency security · 50% Security and privacy of machine learning · 50% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning › adversarial attack › backdoor attack › backdoor defense
backdoor detection |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Blockchain and cryptocurrency security
smart contract security |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Program analysis › static analysis
datalog-based analysis |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Software testing › fuzzing
directed fuzzing |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Software testing
fuzzing |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Program analysis
static analysis |
0.7 | 1 | 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts · ACM Trans. Softw. Eng. Methodol. 2023 |
Methods — techniques the papers use, named apart from their topics
directed fuzzing · 1.3datalog analysis · 1.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token ContractsabstractWith the development of decentralized networks, smart contracts, especially those for ERC tokens, are attracting more and more Dapp users to implement their applications. There are some functions in ERC token contracts that only a specific group of accounts could invoke. Among those functions, some even can influence other accounts or the whole system without prior notice or permission. These functions are referred to as contract backdoors. Once exploited by an attacker, they can cause property losses and harm users’ privacy. In this work, we propose Pied-Piper, a hybrid analysis method that integrates datalog analysis and directed fuzzing to detect backdoor threats in Ethereum ERC token contracts. First, datalog analysis is applied to abstract the data structures and identification rules related to the threats for preliminary static detection. Then, directed fuzzing is applied to eliminate false positives caused by the static analysis. We first evaluated Pied-Piper on 200 smart contracts, which are injected with different types of backdoors. It reported all problems without false positives, and none of the injected problems was missed. Then, we applied Pied-Piper on 13,484 real token contracts deployed on Ethereum. Pied-Piper reported 189 confirmed problems, four of which have been assigned unique CVE ids while others are still in the review process. Each contract takes 8.03 seconds for datalog analysis on average, and the fuzzing engine can eliminate the false positives within one minute. Fuchen Ma, Lerong Ouyang, Yuanliang Chen, Juan Zhu, Ting Chen 0002, Yingli Zheng, Xiao Dai, Yu Jiang 0001, Jia-Guang Sun 0001 |
ACM Trans. Softw. Eng. Methodol. | 8 |