EDBT 2026 Demo / reviewers in the wild / expert
Eric Liu 0001
dblp:54/6550-1
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0001-3980-2364ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PSan: Towards Hybrid Metadata Scheme for Efficient Pointer CheckingabstractMemory safety remains at risk for programs written in unsafe languages like C. Pointer-checking schemes provide memory safety protection by attaching metadata for each pointer and checking them before dereference. Previously, sanitizers maintaining large per-pointer metadata (e.g., pointer bounds) were stuck with shadow memory for metadata storage, which incurs high overhead. Although fat pointers (i.e., instrumenting programs to inline metadata with pointers) incur less overhead, they introduce incompatibility issues to the instrumented programs, and are thus not considered by software-only sanitizers yet. In this paper, we push the status quo on adopting fat pointers for software-only pointer checking schemes and evaluate the benefit of this approach. We present PSan (short for “Pointer Sanitizer”), the first memory safety sanitizer that enables both inline and shadow memory metadata simultaneously in the same program. To reduce the overhead from shadow memory, PSan uses whole-program analysis and transformation to inline the metadata whenever possible, while using shadow memory only when necessary for compatibility. PSan-instrumented programs preserve binary compatibility with third-party uninstrumented code. In addition, PSan's framework decouples metadata management from checking, facilitating its augmentation with additional checkers. We evaluate the benefit of metadata inlining and observe that PSan's hybrid scheme reduces the runtime and memory overhead. Specifically, PSan incurs 40% lower overhead than popular memory checker SoftBoundCETS, which utilizes only shadow memory. Predictably, using inline metadata has a higher performance improvement when it can be applied to the majority of pointers in the program. Shengjie Xu 0001, Eric Liu 0001, Wei Huang 0027, Ilya Grishchenko, David Lie |
ACSAC | 2 |
| 2025 | EvoCrawl: Exploring Web Application Code and State using Evolutionary Search
Akshay Kawlay, Eric Liu 0001, David Lie |
NDSS | 3 |
| 2023 | FLUX: Finding Bugs with LLVM IR Based Unit Test CrossoversabstractOptimizing compilers are as ubiquitous as they are crucial to software development. However, bugs in compilers are not uncommon. Among the most serious are bugs in compiler optimizations, which can cause unexpected behavior in compiled binaries. Existing approaches for detecting such bugs have focused on end-to-end compiler fuzzing, which limits their ability for targeted exploration of a compiler's optimizations. This paper proposes FLUX (Finding bugs with LLVM IR based Unit test cross(X)overs), a fuzzer that is designed to generate test cases that stress compiler optimizations. Previous compiler fuzzers are overly constrained by having to construct well-formed inputs. FLUX sidesteps this constraint by using human-written unit test suites as a starting point, and then selecting random combinations of them to generate new tests. We hypothesize that tests generated this way will be able to explore new execution paths through compiler optimizations and find new bugs. Our evaluation of FLUX on LLVM indicates that it is able to increase path coverage over the baseline LLVM unit test suite and explores more edge coverage than previous work. Further, we demonstrate FLUX's ability to generate miscompiled and crash-producing IR on LLVM's optimizations. After a month of fuzzing, FLUX found 28 unique bugs in LLVM's active development branch. We have reported 11 of these bugs which led to 6 of them being patched by LLVM developers. 22 of these are crashes that are triggered by well-formed input programs, and 6 of these are miscompilation bugs that silently produced incorrect code. Eric Liu 0001, Shengjie Xu 0001, David Lie |
ASE | 1 |
| 2023 | MIFP: Selective Fat-Pointer Bounds Compression for Accurate Bounds CheckingabstractBounds compression for fat pointers can reduce the memory and performance overhead of maintaining pointer bounds and is necessary for efficient hardware implementation. However, compression can introduce inaccuracy to the bounds, making certain out-of-bounds accesses undetectable. Although the security threat can be mitigated by padding the objects, no known mitigations can detect these out-of-bounds accesses deterministically. Shengjie Xu 0001, Eric Liu 0001, Wei Huang 0027, David Lie |
RAID | 2 |