EDBT 2026 Demo / reviewers in the wild / expert
Leqing Wang
dblp:386/4225
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2024
0009-0005-5599-1790ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% | |
| Network and information security
1 paper |
Blockchain and cryptocurrency security · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Blockchain and cryptocurrency security
smart contract security |
0.8 | 1 | 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced Analysis · ISSTA 2024 |
Program analysis › binary analysis
bytecode analysis |
0.8 | 1 | 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced Analysis · ISSTA 2024 |
Program analysis
static analysis |
0.8 | 1 | 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced Analysis · ISSTA 2024 |
Blockchain and cryptocurrency security › smart contract analysis
smart contract auditing |
0.2 | 1 | 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced Analysis · ISSTA 2024 |
Methods — techniques the papers use, named apart from their topics
meta-information extraction · 1.5intermediate representation · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced AnalysisabstractMove, a programming language for smart contracts, stands out for its focus on security. However, the practical security efficacy of Move contracts remains an open question. This work conducts the first comprehensive empirical study on the security of Move contracts. Our initial step involves collaborating with a security company to manually audit 652 contracts from 92 Move projects. This process reveals eight types of defects, with half previously unreported. These defects present potential security risks, cause functional flaws, mislead users, or waste computational resources. To further evaluate the prevalence of these defects in real-world Move contracts, we present MoveScan, an automated analysis framework that translates bytecode into an intermediate representation (IR), extracts essential meta-information, and detects all eight defect types. By leveraging MoveScan, we uncover 97,028 defects across all 37,302 deployed contracts in the Aptos and Sui blockchains, indicating a high prevalence of defects. Experimental results demonstrate that the precision of MoveScan reaches 98.85%, with an average project analysis time of merely 5.45 milliseconds. This surpasses previous state-of-the-art tools MoveLint, which exhibits an accuracy of 87.50% with an average project analysis time of 71.72 milliseconds, and Move Prover, which has a recall rate of 6.02% and requires manual intervention. Our research also yields new observations and insights that aid in developing more secure Move contracts. Shuwei Song, Jiachi Chen, Ting Chen 0002, Xiapu Luo, Wenwu Yang, Leqing Wang, Feng Luo 0009, Zheyuan He |
ISSTA | 7 |