Haoyi Liu

dblp:400/4617 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2025
0009-0005-4907-7337ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 100%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
1.122025
Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea · CCS 2025
Be Careful of What You Embed: Demystifying OLE Vulnerabilities · NDSS 2025
Systems and software security › vulnerability discovery
fuzzing
0.912025
Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea · CCS 2025
Systems and software security
operating system security
0.912025
Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea · CCS 2025
Systems and software security › information flow control
information leak detection
0.312025
Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea · CCS 2025

Methods — techniques the papers use, named apart from their topics

static analysis · 0.9record-and-replay fuzzing · 0.9mutation-based fuzzing · 0.9fuzzing · 0.9
YearPublicationVenuePosition
2025 Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC Sea
abstract
Windows services utilizing Remote Procedure Call (RPC) and Component Object Model (COM) technology over the underlying Advanced Local Procedure Call (ALPC) transport present a significant attack surface. However, previous research often focused on known vulnerability patterns or required time-consuming reverse engineering, which hinders scalable vulnerability discovery. We developed a tool designed to automate and scale the fuzzing of ALPC communications. It employs a record-and-replay based strategy, capturing live system-wide ALPC traffic and replaying mutated payloads directly at the ALPC layer, thereby overcoming the scalability barrier posed by the manual preparation required with conventional methods. Furthermore, it integrates dedicated detection techniques to identify information leakage vulnerabilities that crash-centric fuzzers often miss. After evaluating various versions of Windows operating systems, we discovered 12 vulnerabilities confirmed by Microsoft, 10 of which have already been assigned CVE numbers.
Haoyi Liu, Feng Dong 0008, Yunpeng Tian, Mu Zhang 0001, Fangming Gu, Zhiniang Peng, Haoyu Wang 0001
CCS1
2025 Be Careful of What You Embed: Demystifying OLE Vulnerabilities
Yunpeng Tian, Feng Dong 0008, Haoyi Liu, Zhiniang Peng, Zesen Ye, Shenghui Li, Xiapu Luo, Haoyu Wang 0001
NDSS3