Yong Yu 0002

dblp:43/5685-2 · DBLP profile ↗
← Back
9ranked-venue papers in the field
2as first author
4since 2021 · last 2024
—ORCID · conflict

Domains — venue-derived; a paper can count in several

Other / Interdisciplinary · 5 (2 first)Knowledge Engineering, Semantic Web & Information Systems · 4
YearPublicationVenuePosition
2024 Security Analysis of Large Language Models on API Misuse Programming Repair
abstract
Application programming interface (API) misuse refers to misconceptions or carelessness in the anticipated usage of APIs, threatening the software system’s security. Moreover, API misuses demonstrate significant concealment and are challenging to uncover. Recent advancements have explored enhanced LLMs in a variety of software engineering (SE) activities, such as code repair. Nonetheless, the security implications of using LLMs for these purposes remain underexplored, particularly concerning the issue of API misuse. In this paper, we present an empirical study to observe the bug‐fixing capabilities of LLMs in addressing API misuse related to monitoring resource management (MRM API misuse). Initially, we propose APImisRepair, a real‐world benchmark for repairing MRM API misuse, including buggy programs, corresponding fixed programs, and descriptions of API misuse. Subsequently, we assess the performance of several LLMs using the APImisRepair benchmark. Findings reveal the vulnerabilities of LLMs in repairing MRM API misuse and find several reasons, encompassing factors such as fault localization and a lack of awareness regarding API misuse. Additionally, we have insights on improving LLMs in terms of their ability to fix MRM API misuse and introduce a crafted approach, APImisAP. Experimental results demonstrate that APImisAP exhibits a certain degree of improvement in the security of LLMs.
Rui Zhang 0106, Ziyue Qiao, Yong Yu 0002
Int. J. Intell. Syst.3
2023 Trustworthy sealed-bid auction with low communication cost atop blockchain
Yong Yu 0002, Jiguo Yu, Lei Wang 0118
Inf. Sci.2
2022 Privacy protection in social applications: A ciphertext policy attribute-based encryption with keyword search
abstract
In a highly evolved big data era, intelligent data analysis can improve social operation efficiency and save resources. However, it also brings masses of conflicts, such as malicious mining and abuse of personal privacy information. This paper introduces a privacy protection scheme for social applications. In this scheme, attribute based searchable encryption is used to defend the security of confidential data and ensure the availability of data. Moreover, the access control structure of ciphertext strategy can meet the needs of data sharing in social applications. Security analysis shows that the scheme does not disclose privacy information in index ciphertext, search trapdoor, and equality test. Compared with plaintext information upload and sharing, the additional performance overhead caused by the scheme is acceptable. The scheme can be actually deployed in social applications.
Junbin Shi, Qiming Yu, Yong Yu 0002, Lianhai Wang
Int. J. Intell. Syst.3
2021 DRBFT: Delegated randomization Byzantine fault tolerance consensus protocol for blockchains
Baocang Wang, Rongxing Lu, Yong Yu 0002
Inf. Sci.4
2019 Efficient attribute-based encryption with attribute revocation for assured data deletion
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Xiaojiang Du, Bo Yang 0003
Inf. Sci.2
2019 Machine learning based privacy-preserving fair data trading in big data market
Yanqi Zhao, Yong Yu 0002, Yannan Li 0001, Xiaojiang Du
Inf. Sci.2
2014 Security pitfalls of an efficient threshold proxy signature scheme for mobile agents
Yong Yu 0002, Yi Mu 0001, Willy Susilo, Man Ho Au
Inf. Process. Lett.1
2007 Provably Secure Identity-Based Threshold Unsigncryption Scheme
Bo Yang 0003, Yong Yu 0002, Fagen Li
ATC2
2007 Efficient Identity-Based Signcryption Scheme for Multiple Receivers
Yong Yu 0002, Bo Yang 0003, Xinyi Huang 0001, Mingwu Zhang
ATC1