Xiao Yi

dblp:55/3437 · DBLP profile ↗
← Back
20ranked-venue papers
5as first author
16since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 first-author · 5 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 AGChain: A Blockchain-based Gateway for Trustworthy App Delegation from Mobile App Markets
abstract
The popularity of smartphones has led to the growth of mobile app markets, creating a need for enhanced transparency, global access, and secure downloading. This article introduces AGChain, a blockchain-based gateway that enables trustworthy app delegation within existing markets. AGChain ensures that markets can continue providing services while users benefit from permanent, distributed, and secure app delegation. During its development, we address two key challenges: significantly reducing smart contract gas costs and enabling fully distributed IPFS-based file storage. Additionally, we tackle three system issues related to security and sustainability. We have implemented a prototype of AGChain on Ethereum and Polygon blockchains, achieving effective security and decentralization with a minimal gas cost of around 0.0028 USD per app upload (no cost for app download). AGChain also exhibits reasonable performance with an average overhead of 12%.
Mengjie Chen, Xiao Yi, Daoyuan Wu, Jianliang Xu, Yingjiu Li, Debin Gao
Distributed Ledger Technol. Res. Pract.2
2026 A Tale of 1001 LoC: Potential Runtime Error-Guided Specification Synthesis for Verifying Large-Scale Programs
abstract
Fully automated verification of large-scale software and hardware systems is arguably the holy grail of formal methods. Large language models (LLMs) have recently demonstrated their potential for enhancing the degree of automation in formal verification by, e.g., generating formal specifications as essential to deductive verification, yet exhibit poor scalability due to long-context reasoning limitations and, more importantly, the difficulty of inferring complex, interprocedural specifications. This paper presents Preguss – a modular, finegrained framework for automating the generation and refinement of formal specifications. Preguss synergizes between static analysis and deductive verification by steering two components in a divide-and-conquer fashion: (i) potential runtime error-guided construction and prioritization of verification units, and (ii) LLM-aided synthesis of interprocedural specifications at the unit level. We show that Preguss substantially outperforms state-of-the-art LLM-based approaches and, in particular, it enables highly automated RTE-freeness verification for real-world programs with over a thousand LoC, with a reduction of 80.6%~88.9% human verification effort.
Zhongyi Wang 0004, Tengjie Lin, Mingshuai Chen, Haokun Li, Mingqi Yang, Xiao Yi, Shengchao Qin, Yixing Luo, Liqiang Lu, Jianwei Yin
Proc. ACM Program. Lang.6
2026 Guard Against Infringement: An Anti-Distillation Federated Learning Watermarking Framework
abstract
To balance the gap between data privacy and the need for data fusion, federated learning (FL) has been proposed and has become a hot-point method to address data silos and privacy issues. However, AI models exchanged in FL face risks such as illegal copying, redistribution and/or free-riding. To address these risks, FL watermarking frameworks have been proposed to assert and protect the intellectual property (IP) of models, which are resistant to popular watermark removal attacks. Knowledge distillation has recently been of significant contribution to FL convergence performance optimization but brings vulnerability to FL watermark robustness with distillation attack, which enables attackers to maintain high performance on the main task while erasing the watermarks. In response, we introduce a new FL watermarking framework called FedRW, which focuses specifically on anti-distillation. FedRW employs model regularization techniques to bind the main task parameters with the watermark task parameters, thereby enhancing resistance to distillation attacks. Extensive experiments confirm the threat of distillation attacks in FL and demonstrate that FedRW is more resistant to distillation compared to existing FL watermarking frameworks.
Xiao Yi, Hengrun Zhang 0001, Huiqun Yu, Guisheng Fan, Haojin Zhu
IEEE Trans. Dependable Secur. Comput.1
2025 FinPTA: An Effective Model for Financial Sentiment Analysis
Xiao Yi, Guisheng Fan, Huiqun Yu, Hengrun Zhang 0004
ICECCS2
2025 Optimized methods for basic probability assignments in evidence theory: Applications to fault diagnosis
Haotian Yu, Xiao Yi
Eng. Appl. Artif. Intell.3
2025 Parf: An Adaptive Abstraction-Strategy Tuner for Static Analysis
Zhongyi Wang 0004, Mingshuai Chen, Teng-Jie Lin, Linyu Yang, Junhao Zhuo, Qiu-Ye Wang, Shengchao Qin, Xiao Yi, Jianwei Yin
J. Comput. Sci. Technol.8
2025 Toward Dimension-Enriched Underwater Image Quality Assessment
abstract
The absorption and scattering of light in the water medium naturally impair the quality of underwater images, leading to multiple degradation effects including color casts, reduced visibility, and blurriness. Underwater Image Enhancement (UIE) techniques strive to mitigate these issues, yet the efficacy of different UIE algorithms remains highly variable. This variability underscores the necessity for an objective quality metric capable of precisely assessing the visual quality of underwater images. Traditional quality metrics, which primarily rely on a single score to depict the overall quality level, are insufficiently comprehensive to describe the complex degradation characteristics intrinsic to underwater environments and the multi-dimensional nature of underwater image quality. To address this issue, we construct the first UIE quality evaluation dataset with multi-dimensional quality annotations, broadening the subjective labels from a single overall quality score to multiple specific degradation-related scores. The dataset is known as an enhanced version of our previous Subjectively Annotated UIE Benchmark Dataset (SAUD) and is called SAUD2.0 hereinafter. Based on the SAUD2.0 dataset, we also introduce a Multi-stream COllaborative LEarning network (MCOLE) tailored for quality evaluation of enhanced underwater images. MCOLE capitalizes on the multi-dimensional quality annotations within SAUD2.0, facilitating the training of three specialized networks focused on extracting distinct sets of features: color, visibility, and semantic. These extracted features are then interacted and cohesively merged for quality prediction. Comprehensive experiments conducted on two benchmark datasets reveal that the proposed MCOLE outperforms current underwater image quality metrics. These results clearly validate the efficacy of exploring the multi-dimensional nature of underwater image quality and integrating such multi-dimensional quality annotations into underwater image quality evaluation. Our dataset and code are available athttps://github.com/0117Tzx/MCOLE.
Qiuping Jiang, Xiao Yi, Li Ouyang, Jingchun Zhou, Zhihua Wang 0002
IEEE Trans. Circuits Syst. Video Technol.2
2024 MtdScout: Complementing the Identification of Insecure Methods in Android Apps via Source-to-Bytecode Signature Generation and Tree-based Layered Search
abstract
Modern Android apps consist of both host app code and third-party libraries. Traditional static analysis tools conduct taint analysis for API misuses on the entire app code, while third-party library (TPL) detection tools focus solely on library code. Both approaches, however, are prone to some inherent false negatives: taint analysis tools may neglect third-party libraries or face timeouts/errors in whole app-based analysis, and TPL detection tools are not designed for pinpointing specific vulnerable methods. These challenges underscore the need for enhanced identification of insecure methods in Android apps, particularly for app markets addressing open-source security incidents. In this paper, we aim to complement the identification of missed false negatives in both TPL detection and taint analysis by directly identifying clones of insecure methods, regardless of whether they are in the host app code or a shrunk library. We propose MtdScout, a novel crosslayer, method-level clone detection tool for Android apps. MtdScout generates bytecode signatures for flawed source methods using compiler-style interpretation and abstraction, and efficiently matches them with target app bytecode using signature-mapped search trees. Our experiment using ground-truth apps shows that MtdScout achieves the highest accuracy among three tested clone detection tools, with a precision of 92.5% and recall of 87.2%. A large-scale experiment with 23.9K apps from Google Play demonstrates MtdScout's effectiveness in complementing both LibScout and CryptoGuard by identifying numerous false negatives they missed due to app shrinking, method-only cloning, and inherent timeouts and failures in expensive taint analysis. Additionally, our experiment uncovers four security findings that highlight the disparities between MtdScout's methodlevel clone detection and package-level library detection.
Daoyuan Wu, Debin Gao, Xiao Yi, Lingxiao Jiang
EuroS&P5
2024 Parf: Adaptive Parameter Refining for Abstract Interpretation
abstract
Abstract interpretation is a key formal method for the static analysis of programs. The core challenge in applying abstract interpretation lies in the configuration of abstraction and analysis strategies encoded by a large number of external parameters of static analysis tools. To attain low false-positive rates (i.e., accuracy) while preserving analysis efficiency, tuning the parameters heavily relies on expert knowledge and is thus difficult to automate. In this paper, we present a fully automated framework called Parf to adaptively tune the external parameters of abstract interpretation-based static analyzers. Parf models various types of parameters as random variables subject to probability distributions over latticed parameter spaces. It incrementally refines the probability distributions based on accumulated intermediate results generated by repeatedly sampling and analyzing, thereby ultimately yielding a set of highly accurate parameter settings within a given time budget. We have implemented Parf on top of Frama-C/Eva - an off-the-shelf open-source static analyzer for C programs - and compared it against the expert refinement strategy and Frama-C/Eva's official configurations over the Frama-C OSCS benchmark. Experimental results indicate that Parf achieves the lowest number of false positives on 34/37 (91.9%) program repositories with exclusively best results on 12/37 (32.4%) cases. In particular, Parf exhibits promising performance for analyzing complex, large-scale real-world programs.
Zhongyi Wang 0004, Linyu Yang, Mingshuai Chen, Yixuan Bu, Qiuye Wang, Shengchao Qin, Xiao Yi, Jianwei Yin
ASE8
2023 A Hybrid Kernel Pruning Approach for Efficient and Accurate CNNs
Xiao Yi, Shengbai Luo, Lizhou Wu, Kenli Li 0001, Sheng Ma
ICA3PP (7)1
2023 Beyond "Protected" and "Private": An Empirical Security Analysis of Custom Function Modifiers in Smart Contracts
abstract
A smart contract is a piece of application-layer code running on blockchain ledgers and it provides programmatic logic via transaction-based execution of pre-defined functions. Smart contract functions are by default invokable by any party. To safeguard them, the mainstream smart contract language, i.e., Solidity of the popular Ethereum blockchain, proposed a unique language-level keyword called “modifier,” which allows developers to define custom function access control policies beyond the traditional “protected” and “private” modifiers in classic programming languages.
Yuzhou Fang, Daoyuan Wu, Xiao Yi, Shuai Wang 0011, Mengjie Chen, Yang Liu 0003, Lingxiao Jiang
ISSTA3
2023 BlockScope: Detecting and Investigating Propagated Vulnerabilities in Forked Blockchain Projects
Xiao Yi, Yuzhou Fang, Daoyuan Wu, Lingxiao Jiang
NDSS1
2022 SparG: A Sparse GEMM Accelerator for Deep Learning Applications
Sheng Ma, Yuan Yuan 0034, Xiang Hou, Xiao Yi
ICA3PP7
2022 An empirical study of blockchain system vulnerabilities: modules, types, and patterns
abstract
Blockchain, as a distributed ledger technology, becomes increasingly popular, especially for enabling valuable cryptocurrencies and smart contracts. However, the blockchain software systems inevitably have many bugs. Although bugs in smart contracts have been extensively investigated, security bugs of the underlying blockchain systems are much less explored. In this paper, we conduct an empirical study on blockchain’s system vulnerabilities from four representative blockchains, Bitcoin, Ethereum, Monero, and Stellar. Specifically, we first design a systematic filtering process to effectively identify 1,037 vulnerabilities and their 2,317 patches from 34,245 issues/PRs (pull requests) and 85,164 commits on GitHub. We thus build the first blockchain vulnerability dataset, which is available at https://github.com/VPRLab/BlkVulnDataset. We then perform unique analyses of this dataset at three levels, including (i) file-level vulnerable module categorization by identifying and correlating module paths across projects, (ii) text-level vulnerability type clustering by natural language processing and similarity-based sentence clustering, and (iii) code-level vulnerability pattern analysis by generating and clustering code change signatures that capture both syntactic and semantic information of patch code fragments.
Xiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang, Kehuan Zhang, Wei Zhang 0122
ESEC/SIGSOFT FSE1
2022 A node screening algorithm for wireless sensor network based on threshold measurement
abstract
The normal operation of nodes ensures the realisation of network functions. When abnormal nodes appear in the network, the network may be in chaos. A node screening algorithm based on threshold measurement is proposed to solve the problem of nodes screening in wireless sensor networks. First, the membership and non-membership of nodes are determined by using the correlation distance values calculated by the node attribute vector constructed through quantised node network attributes and the threshold vector. Second, an intuitionistic fuzzy set is constructed by the membership. Finally, the screening of wireless sensor network nodes is completed through similarity function. Simulation experiment and analysis show that this algorithm dramatically improves the detection probability compared with the node detection algorithm based on fuzzy theory.
Xiao Yi, Dongning Zhao
Int. J. Inf. Comput. Secur.2
2022 A novel systolic array processor with dynamic dataflows
Sheng Ma, Guoyi Zhu, Xiao Yi
Integr.4
2020 Enhanced Darknet53 Combine MLFPN Based Real-Time Defect Detection in Steel Surface
Xiao Yi, Yonghong Song, Yuanlin Zhang 0001
PRCV (1)1
2018 Grey relational analysis between hesitant fuzzy sets with applications to pattern recognition
Guidong Sun, Xiao Yi
Expert Syst. Appl.3
2018 Belief intervals aggregation
abstract
The combination rule is the core of Dempster-Shafer theory (DST), and there is no uniform aggregation rule adapting to all conditions. The construction of such a rule is still an open and hot topic. In this article, we focus on this point. We focus on the belief interval, which is made up of belief function and plausibility function, in the form of [belief function, plausibility function], instead of basic belief assignment, to represent the DST. We aim at exploring a belief interval combination rule as the combination rule of DST. To do this, we contrast the belief interval with the intuitionistic fuzzy sets and construct the belief interval combination rule based on the intuitionistic fuzzy weighted averaging (IFWA) operator, which opens the door for DST combination rules to the aggregation operator perspective. Further, we find that directly using the IFWA operator as the belief interval combination rule poses three problems: the “‘one’ veto problem,” converge easily close to [1, 1] and the belief function from the belief interval combination rule is not normalized. To solve these problems, we add a normalization process in the belief interval combination rule to modify it, which can address all these three problems well. We also set up a series of examples to illustrate the belief interval combination rule, including a multisensor fusion scenario to compare it with some of the existing rules, which shows its superiorities in better stability and lower operational load.
Guidong Sun, Xiao Yi
Int. J. Intell. Syst.3
2005 Attribute measure recognition approach and its applications to emitter recognition
Xiao Yi
Sci. China Ser. F Inf. Sci.3