EDBT 2026 Demo / reviewers in the wild / expert
Liang He 0011
dblp:42/963-11
· DBLP profile ↗
12ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-6627-4691ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 2 since 2021Computer networks · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OSmartPro: a large language model-assisted option fuzzing approachabstractAbstract Program options provide flexible software functionality control but complicate fuzz testing, as triggering many behaviors require specific option combinations. Although existing option-aware fuzzing approaches attempt to mutate options as inputs or leverage AI technologies to extract option relationships from documentation, these methods have limitations. Documentation is often incomplete, and some option dependencies are embedded deeply within program logic via data or control flows, making these methods challenging to detect all possible dependencies. This paper introduces OSmartPro , an advanced option-fuzzing approach that directly extracts options and infers option dependencies from source code. Given LLM’s capabilities to interpret program semantics, OSmartPro employs LLM-assisted static analysis to handle diverse option-parsing structures and extract comprehensive options. Through control and data dependency analysis, it constructs option impact graph , which it uses to guide fuzzing strategies. The tool successfully extracted complete options from all 59 programs in our test set, uncovering undocumented options in over 66% of them. Additionally, OSmartPro inferred 14,701 option combinations, identified 45.03% more execution paths compared to AFL++, and uncovered 54 zero-day vulnerabilities, of which 18 awarded CVE IDs. Lastly, in a benchmark comparison against four option-aware fuzzers, OSmartPro achieved higher line coverage in 66.7% (20 out of 30) of the programs. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Jiongyi Chen, Yan Cai 0001, Chao Feng 0002, Chaojing Tang, Guojun Peng |
Cybersecur. | 3 |
| 2025 | Novel and Efficient Rainbow Signature Scheme Based on Circulant and Toeplitz Matrices for Intelligent IoTabstractQuantum computing increases the security risks of data in intelligent Internet of Things (IoT) based on traditional cryptography. Multivariate public key cryptography has the security advantage of resisting quantum computing and Rainbow is an important research focus in it. However, the Rainbow algorithm’s secret keys are too large to suitable for resource-constrained IoT system. We propose an efficient Rainbow signature scheme based on circulant and Toeplitz matrices for intelligent IoT. In our scheme, the variable matrices of polynomials have special forms constructed from circulant and Toeplitz matrices. Every variable matrix of central maps and public key polynomials is divided into four submatrices. Three submatrices of variable matrices are generated using seeds randomly chosen. The fourth submatrix is generated by an affine map and three submatrices. Therefore, the public key consists of seeds and variables in the fourth submatrices, rather than all variables of polynomials. Then, the correctness of our scheme has been proved and we provide a security analysis. More specifically, it is proved that the scheme can resist five attacks against Rainbow, such as Direct attacks, Unbalanced oil vinegar attacks, MinRank attacks, HighRank attacks, and Rainbow-band-separation attacks. At last, according to the experimental results, our system’s public key sizes are 97.96% smaller and private key size are 92.12% than the key sizes of the standard Rainbow scheme. Additionally, compare with other Rainbow-like schemes, the comparison analysis and experimental results show that our scheme has less communication costs and small key size than those in the similar literatures for IoT. Yulong Gao 0003, Wenxuan Feng, Liang He 0011, Mianxiong Dong |
IEEE Internet Things J. | 3 |
| 2024 | OSmart: Whitebox Program Option FuzzingabstractProgram options are ubiquitous and serve as a fundamental mechanism for configuring and customizing software behaviors. Given their widespread use, testing program options becomes essential to ensure that the software behaves as expected across various configurations. Existing option-aware fuzzers either mutate options as if they were standard program inputs or employ NLP techniques to deduce relationships among options from the documentation. However, there has not been a whitebox approach that generates option combinations by capturing the inherent execution logic of the program. Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Yan Cai 0001, Jiongyi Chen, Chao Feng 0002, Chaojing Tang |
CCS | 3 |
| 2024 | Reorder Pointer Flow in Sound Concurrency Bug PredictionabstractDue to the non-determinism of thread interleaving, predicting concurrency bugs has long been an extremely difficult task. Recently, several sound bug-detecting approaches were proposed. These approaches are based on local search, i.e., mutating the sequential order of the observed trace and predicting whether the mutated sequential order can trigger a bug. Surprisingly, during this process, they never consider reordering the data flow of the pointers, which can be the key point to detecting many complex bugs. To alleviate this weakness, we propose a new flow-sensitive point-to analysis technique ConPTA to help actively reorder the pointer flow during the sequential order mutation process. Based on ConPTA, we further propose a new sound predictive bug-detecting approach Eagle to predict four types of concurrency bugs. They are null pointer dereference (NPD), uninitialized pointer use (UPU), use after free (UAF), and double free (DF). By actively reordering the pointer flow, Eagle can explore a larger search space of the thread interleaving during the mutation and thus detect more concurrency bugs. Our evaluation of Eagle on 10 real-world multi-threaded programs shows that Eagle significantly outperforms four state-of-the-art bug-detecting approaches UFO, ConVul, ConVulPOE and Period in both effectiveness and efficiency. Yuqi Guo 0002, Yan Cai 0001, Liang He 0011, Jian Zhang 0001 |
ICSE | 4 |
| 2023 | One Simple API Can Cause Hundreds of Bugs An Analysis of Refcounting Bugs in All Modern Linux KernelsabstractReference counting (refcounting) is widely used in Linux kernel. However, it requires manual operations on the related APIs. In practice, missing or improperly invoking these APIs has introduced too many bugs, known as refcounting bugs. To evaluate the severity of these bugs in history and in future, this paper presents a comprehensive study on them. Liang He 0011, Purui Su, Chao Zhang 0008, Yan Cai 0001, Jinxin Ma |
SOSP | 1 |
| 2022 | FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on Binaries
Liang He 0011, Hong Hu 0004, Purui Su, Yan Cai 0001, Zhenkai Liang |
USENIX Security Symposium | 1 |
| 2020 | Partial-SMT: Core-scheduling Protection Against SMT Contention-based AttacksabstractNumerous recent works in side-channel attacks have experimentally shown that Simultaneous Multi-Threading (SMT) inherently has a broader attack surface as it exposes more microarchitecture components per-core than cross-core. Existing mechanisms that protect against these attacks either incur high execution costs or are ineffective against certain attack variants. In this paper, we propose Partial-SMT, a system based on core-scheduling that protects security-critical programs from all contention-based attacks due to SMT. Partial-SMT allocates some complete physical cores for the exclusive use of the individual applications and provides a user-level threading library linked into each application to control the placement of their threads on dedicated cores, thereby preventing the attacker from accessing shared CPU resources simultaneously on the victim's core. The key insight is that by limiting ourselves to SMT contention-based side channels, we can translate the protection into an allocation policy that allocates or frees computing resources with a granularity of one physical core. Security-critical applications can be implemented on-demand and coexist with existing applications. We demonstrate that Partial-SMT effectively defeats typical SMT contention-based attacks. We modify AES and SPEC 2006 to use Partial-SMT, and they all incur the slight negligible performance overhead. Yeping He, Qiming Zhou, Hengtai Ma, Liang He 0011, Wenhao Wang 0001 |
TrustCom | 5 |
| 2020 | Resource Race Attacks on AndroidabstractSmartphones are frequently involved in accessing private user data. Although many studies have been done to prevent malicious apps from leaking private user data, only a few recent works examine how to remove the sensitive information from the data collected by smartphone hardware resources (e.g., camera). Unfortunately, none of them investigates whether a malicious app can obtain such sensitive information when (or right before/after) a legitimate app collects such data (e.g., taking photos). To fill in the gap, in this paper, we model such attacks as the Resource Race Attack (RRAttack) based on races between two apps during their requests to exclusive resources to access sensitive information. RRAttacks have three categories according to when a race on requesting resources occurs: Pre-Use, In-Use, and Post-Use attacks. We further conduct the first systematic study on the feasibility of launching the RRAttacks on two heavily used exclusive Android resources: camera and touchscreen. In details, we perform Proof-of-Concept (PoC) attacks to reveal that, (a) camera is highly vulnerable to both In-Use and Post-Use attacks; and (b) touchscreen is vulnerable to Pre-Use attacks. Particularly, we demonstrate successful RRAttacks on them to steal private information, to cause financial loss, and to steal user passwords from Android 6 to the latest Android Q. Moreover, our analyses on 1,000 apps indicate that most of them are vulnerable to one to three RRAttacks. Finally, we propose a set of defense strategies against RRAttacks for user apps, system apps, and Android system itself. Yan Cai 0001, Yutian Tang, Haicheng Li, Le Yu 0002, Hao Zhou 0043, Xiapu Luo, Liang He 0011, Purui Su |
SANER | 7 |
| 2019 | Detecting concurrency memory corruption vulnerabilitiesabstractMemory corruption vulnerabilities can occur in multithreaded executions, known as concurrency vulnerabilities in this paper. Due to non-deterministic multithreaded executions, they are extremely difficult to detect. Recently, researchers tried to apply data race detectors to detect concurrency vulnerabilities. Unfortunately, these detectors are ineffective on detecting concurrency vulnerabilities. For example, most (90%) of data races are benign. However, concurrency vulnerabilities are harmful and can usually be exploited to launch attacks. Techniques based on maximal causal model rely on constraints solvers to predict scheduling; they can miss concurrency vulnerabilities in practice. Our insight is, a concurrency vulnerability is more related to the orders of events that can be reversed in different executions, no matter whether the corresponding accesses can form data races. We then define exchangeable events to identify pairs of events such that their execution orders can be probably reversed in different executions. We further propose algorithms to detect three major kinds of concurrency vulnerabilities. To overcome potential imprecision of exchangeable events, we also adopt a validation to isolate real vulnerabilities. We implemented our algorithms as a tool ConVul and applied it on 10 known concurrency vulnerabilities and the MySQL database server. Compared with three widely-used race detectors and one detector based on maximal causal model, ConVul was significantly more effective by detecting 9 of 10 known vulnerabilities and 6 zero-day vulnerabilities on MySQL (four have been confirmed). However, other detectors only detected at most 3 out of the 16 known and zero-day vulnerabilities. Yan Cai 0001, Biyun Zhu, Ruijie Meng, Hao Yun, Liang He 0011, Purui Su, Bin Liang 0002 |
ESEC/SIGSOFT FSE | 5 |
| 2017 | Automatically assessing crashes from heap overflowsabstractHeap overflow is one of the most widely exploited vulnerabilities, with a large number of heap overflow instances reported every year. It is important to decide whether a crash caused by heap overflow can be turned into an exploit. Efficient and effective assessment of exploitability of crashes facilitates to identify severe vulnerabilities and thus prioritize resources. In this paper, we propose the first metrics to assess heap overflow crashes based on both the attack aspect and the feasibility aspect. We further present HCSIFTER, a novel solution to automatically assess the exploitability of heap overflow instances under our metrics. Given a heap-based crash, HCSIFTER accurately detects heap overflows through dynamic execution without any source code or debugging information. Then it uses several novel methods to extract program execution information needed to quantify the severity of the heap overflow using our metrics. We have implemented a prototype HCSIFTER and applied it to assess nine programs with heap overflow vulnerabilities. HCSIFTER successfully reports that five heap overflow vulnerabilities are highly exploitable and two overflow vulnerabilities are unlikely exploitable. It also gave quantitatively assessments for other two programs. On average, it only takes about two minutes to assess one heap overflow crash. The evaluation result demonstrates both effectiveness and efficiency of HC Sifter. Liang He 0011, Yan Cai 0001, Hong Hu 0004, Purui Su, Zhenkai Liang, Yi Yang 0040, Huafeng Huang, Jia Yan 0004, Xiangkun Jia, Dengguo Feng |
ASE | 1 |
| 2017 | Capability-Based Security Enforcement in Named Data NetworkingabstractNamed data networking (NDN) enhances traditional IP networking by supporting in-network content caching for better bandwidth usage and location-independent data accesses for multi-path forwarding. However, NDN also brings new security challenges. For example, an adversary can arbitrarily inject packets to NDN to poison content cache, or access content packets without any restrictions. We propose capability-based security enforcement architecture (CSEA), a capability-based security enforcement architecture that enables data authenticity in NDN in a distributed manner. CSEA leverages capabilities to specify the access rights of forwarded packets. It allows NDN routers to verify the authenticity of forwarded packets, and throttles flooding-based DoS attacks from unsolicited packets. We further develop a lightweight one-time signature scheme for CSEA to ensure the timeliness of packets and support efficient verification. We prototype CSEA on the open-source CCNx platform, and evaluate CSEA via testbed and Planetlab experiments. Our experimental results show that CSEA only incurs around 4% of additional delays in retrieving data packets. Qi Li 0002, Patrick P. C. Lee, Peng Zhang 0011, Purui Su, Liang He 0011, Kui Ren 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2013 | OSNGuard: Detecting Worms with User Interaction Traces in Online Social Networks
Liang He 0011, Dengguo Feng, Purui Su, Lingyun Ying, Yi Yang 0040, Huafeng Huang, Huipeng Fang |
ICICS | 1 |