EDBT 2026 Demo / reviewers in the wild / expert
Yingjie Mao
dblp:368/3676
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Blockchain and cryptocurrency security · 68% Systems and software security · 32% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
1.9 | 2 | 2026 | Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes · IEEE Trans. Dependable Secur. Comput. 2026 Penetrating the Hostile: Detecting DeFi Protocol Exploits Through Cross-Contract Analysis · IEEE Trans. Inf. Forensics Secur. 2025 |
Systems and software security
vulnerability discovery |
1.0 | 1 | 2026 | Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes · IEEE Trans. Dependable Secur. Comput. 2026 |
Program analysis › binary analysis
bytecode analysis |
1.0 | 1 | 2026 | Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes · IEEE Trans. Dependable Secur. Comput. 2026 |
Program analysis
static analysis |
1.0 | 1 | 2026 | Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes · IEEE Trans. Dependable Secur. Comput. 2026 |
Blockchain and cryptocurrency security
smart contract security |
0.3 | 1 | 2026 | Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes · IEEE Trans. Dependable Secur. Comput. 2026 |
Methods — techniques the papers use, named apart from their topics
control flow graph · 2.9static single assignment · 2.0function signature inference · 2.0attention mechanism · 2.0symbolic execution · 0.9deep learning · 0.9cross-contract static data flow analysis · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Interaction-Aware Vulnerability Detection in Smart Contract BytecodesabstractThe detection of vulnerabilities in smart contracts remains a significant challenge. While numerous tools are available for analyzing smart contracts in source code, only about 1.79% of smart contracts on Ethereum are open-source. For existing tools that target bytecodes, most of them only consider the semantic logic context and disregard function interface information in the bytecodes. In this paper, we proposeCOBRA, a novel framework that integrates semantic context and function interfaces to detect vulnerabilities in bytecodes of the smart contract. To our best knowledge,COBRAis the first framework that combines these two features. Moreover, to infer the function signatures that are not present in signature databases, we proposeSRIF, automatically learn the rules of function signatures from the smart contract bytecodes. The bytecodes associated with the function signatures are collected by constructing a control flow graph (CFG) for theSRIFtraining. We optimize the semantic context using the operation code in the static single assignment (SSA) format. Finally, we integrate the context and function interface representations in the latent space as the contract feature embedding. The contract features in the hidden space are decoded for vulnerability classifications with a decoder and attention module. Experimental results demonstrate thatSRIFcan achieve 94.76% F1-score for function signature inference. Furthermore, when the ground truth ABI exists,COBRAachieves 93.45% F1-score for vulnerability classification. In the absence of ABI, the inferred function feature fills the encoder, and the system accomplishes an 89.46% recall rate. Xiaoqi Li 0001, Yingjie Mao, Yuqing Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Penetrating the Hostile: Detecting DeFi Protocol Exploits Through Cross-Contract AnalysisabstractDecentralized finance (DeFi) protocols are crypto projects developed on the blockchain to manage digital assets. Attacks on DeFi have been frequent and have resulted in losses exceeding $80 billion. Current tools detect and locate possible vulnerabilities in contracts by analyzing the state changes that may occur during malicious events. However, this victim-only approaches seldom possess the capability to cover the attacker’s interaction intention logic. Furthermore, only a minuscule percentage of DeFi protocols experience attacks in real-world scenarios, which poses a significant challenge for these detection tools to demonstrate practical effectiveness. In this paper, we propose DeFiTail, thefirstframework that utilizes deep learning technology for access control and flash loan exploit detection. Through feeding the cross-contract static data flow, DeFiTail automatically learns the attack logic in real-world malicious events that occur on DeFi protocols, capturing the threat patterns between attacker and victim contracts. Since the DeFi protocol events involve interactions with multi-account transactions, the execution path with external and internal transactions requires to be unified. Moreover, to mitigate the impact of mistakes in Control Flow Graph (CFG) connections, DeFiTail validates the data path by employing the symbolic execution stack. Furthermore, we feed the data paths through our model to achieve the inspection of DeFi protocols. Comparative experiment results indicate that DeFiTail achieves the highest accuracy, with 98.39% in access control and 97.43% in flash loan exploits. DeFiTail also demonstrates an enhanced capability to detect malicious contracts, identifying 86.67% accuracy from the CVE dataset. By monitoring existing contracts, we identified five distinct categories of vulnerabilities: repetition abuse, unsafe unintended exploitation, signature violated exploitation, insecure interfaces exploitation, and unrestricted token transfer. Xiaoqi Li 0001, Zhiquan Liu 0001, Yuqing Zhang 0001, Yingjie Mao |
IEEE Trans. Inf. Forensics Secur. | 5 |