Junyao He

dblp:388/5685 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Services computing and microservices · 50% Operating systems · 50%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery
static analysis
0.912025
Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications · SP 2025
Systems and software security › information flow tracking
taint analysis
0.912025
Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications · SP 2025
Systems and software security
vulnerability discovery
0.912025
Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications · SP 2025
Services computing and microservices
microservice architecture
0.312025
Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications · SP 2025
Operating systems › system security › operating system security › protection mechanism › isolation
security isolation
0.312025
Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications · SP 2025

Methods — techniques the papers use, named apart from their topics

service dependence graph · 1.7gateway-centric analysis · 1.7distance-guided selective context-sensitive taint analysis · 1.7
YearPublicationVenuePosition
2026 UniMAT: A multi-attention joint detection and tracking framework for robust multi-object tracking
Junyao He
Expert Syst. Appl.1
2025 Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications
abstract
Microservice architecture has been becoming increasingly popular for building scalable and maintainable applications. A microservice-structured web application (shortened to microservice application) enhances security by providing a loose-coupling design and enforcing the security isolation between different microservices. However, in this paper, our study shows microservice applications still suffer from taint-style vulnerability, one of the most serious vulnerabilities. We propose a novel security analysis approach, named MScan, that can effectively detect taint-style vulnerabilities in real-world evolving-fast microservice applications. Our approach mainly consists of three phases. First, MScan identifies the entry points accessible to external malicious users by applying a gateway-centric analysis. Second, MScan utilizes a new data structure, i.e. service dependence graph, to bridge inter-service communication. Finally, MScan employs a distance-guided strategy for selective context-sensitive taint analysis to detect vulnerabilities. By applying MScan on 25 open-source microservice applications and 5 industrial microservice applications from a world-leading fintech company, we found MScan can effectively vet these applications with the discovery of 59 high-risk 0-day vulnerabilities. We have conducted responsible vulnerability disclosure. Up to now, 31 CVE identifiers have been issued.
Yuan Zhang 0009, Youkun Shi, Guangliang Yang 0001, Min Yang 0002, Junyao He
SP8