Yifei Zhang 0001

dblp:55/5266-1 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
1since 2021 · last 2021
0000-0002-5177-0465ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 3 first-author · 1 since 2021Security and privacy · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
3 papers
Program analysis · 37% Compilers and program optimization · 27% Software testing · 20%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Compilers and program optimization › compiler construction
ahead-of-time compilation
0.512021
Towards a Serverless Java Runtime · ASE 2021
Runtime systems and virtual machines › virtual machine implementation
java virtual machine
0.512021
Towards a Serverless Java Runtime · ASE 2021
Compilers and program optimization › dynamic optimization
profile-guided optimization
0.512021
Towards a Serverless Java Runtime · ASE 2021
Software testing
GUI testing
0.412019
Event trace reduction for effective bug replay of Android apps via differential GUI state analysis · ESEC/SIGSOFT FSE 2019
Software testing › test optimization
test case reduction
0.412019
Event trace reduction for effective bug replay of Android apps via differential GUI state analysis · ESEC/SIGSOFT FSE 2019
Program analysis › dynamic analysis › trace analysis
trace reduction
0.412019
Event trace reduction for effective bug replay of Android apps via differential GUI state analysis · ESEC/SIGSOFT FSE 2019
Program analysis › static analysis › pointer analysis
context-sensitive pointer analysis
0.312018
Launch-mode-aware context-sensitive activity transition analysis · ICSE 2018
Program analysis › static analysis
pointer analysis
0.312018
Launch-mode-aware context-sensitive activity transition analysis · ICSE 2018
Program analysis
static analysis
0.312018
Launch-mode-aware context-sensitive activity transition analysis · ICSE 2018
Debugging and program repair › software debugging
bug replay
0.112019
Event trace reduction for effective bug replay of Android apps via differential GUI state analysis · ESEC/SIGSOFT FSE 2019

Methods — techniques the papers use, named apart from their topics

just-in-time compilation · 0.5class data sharing · 0.5differential GUI state analysis · 0.4object-sensitive pointer analysis · 0.3context-sensitive pointer analysis · 0.3
YearPublicationVenuePosition
2021 Towards a Serverless Java Runtime
abstract
Java virtual machine (JVM) has the well-known slow startup and warmup issues. This is because the JVM needs to dynamically create many runtime data before reaching peak performance, including class metadata, method profile data, and just-in-time (JIT) compiled native code, for each run of even the same application. Many techniques are then proposed to reuse and share these runtime data across different runs. For example, Class Data Sharing (CDS) and Ahead-of-time (AOT) compilation aim to save and share class metadata and compiled native code, respectively. Unfortunately, these techniques are developed independently and cannot leverage the ability of each other well. This paper presents an approach that systematically reuses JVM runtime data to accelerate application startup and warmup. We first propose and implement JWarmup, a technique that can record and reuse JIT compilation data (e.g., compiled methods and their profile data). Then, we feed JIT compilation data to the AOT compiler to perform profile-guided optimization (PGO). We also integrate existing CDS and AOT techniques to further optimize application startup. Evaluation on real-world applications shows that our approach can bring a 41.35% improvement to the application startup. Moreover, our approach can trigger JIT compilation in advance and reduce CPU load at peak time.
Yifei Zhang 0001, Tianxiao Gu, Wei Kuai, Sanhong Li
ASE1
2019 Event trace reduction for effective bug replay of Android apps via differential GUI state analysis
abstract
Existing Android testing tools, such as Monkey, generate a large quantity and a wide variety of user events to expose latent GUI bugs in Android apps. However, even if a bug is found, a majority of the events thus generated are often redundant and bug-irrelevant. In addition, it is also time-consuming for developers to localize and replay the bug given a long and tedious event sequence (trace).
Yulei Sui, Yifei Zhang 0001, Wei Zheng 0006, Manqing Zhang, Jingling Xue
ESEC/SIGSOFT FSE2
2018 Launch-mode-aware context-sensitive activity transition analysis
abstract
Existing static analyses model activity transitions in Android apps context-insensitively, making it impossible to distinguish different activity launch modes, reducing the pointer analysis precision for an activity's callbacks, and potentially resulting in infeasible activity transition paths. In this paper, we introduce Chime, a launch-mode-aware context-sensitive activity transition analysis that models different instances of an activity class according to its launch mode and the transitions between activities context-sensitively, by working together with an object-sensitive pointer analysis.
Yifei Zhang 0001, Yulei Sui, Jingling Xue
ICSE1
2018 Ripple: Reflection analysis for Android apps in incomplete information environments
abstract
Summary Reflection poses grave problems for static security analysis, despite its widespread use in Android apps. In general, string inference has been mainly used to handle reflection, resulting in significantly missed security vulnerabilities. In this work, we bring forward the ubiquity of incomplete information environments (IIEs) for Android apps, where some critical dataflows are missing during static analysis and the need for resolving reflective calls under IIEs. We present Ripple, the first IIE‐aware static reflection analysis for Android apps that resolves reflective calls more soundly than string inference. Validation with 17 popular Android apps from Google Play demonstrates the effectiveness of Ripple in discovering reflective targets with a low false positive rate (due to its trade‐off made among soundness, precision, and scalability). As a result, Ripple enables FlowDroid, a taint analysis for Android apps, to find hundreds of sensitive data leakages that would otherwise be missed. As a fundamental analysis, Ripple will be valuable for many security analysis clients, since more program behaviors can now be analyzed under IIEs.
Yifei Zhang 0001, Yue Li 0006, Tian Tan 0001, Jingling Xue
Softw. Pract. Exp.1
2017 Ripple: Reflection Analysis for Android Apps in Incomplete Information Environments
abstract
Despite its widespread use in Android apps, reflection poses graving problems for static security analysis. Currently, string inference is applied to handle reflection, resulting in significantly missed security vulnerabilities. In this paper, we bring forward the ubiquity of incomplete information environments (IIEs) for Android apps, where some critical data-flows are missing during static analysis, and the need for resolving reflective calls under IIEs. We present Ripple, the first IIE-aware static reflection analysis for Android apps that resolves reflective calls more soundly than string inference. Validation with 17 popular Android apps from Google Play demonstrates the effectiveness of Ripple in discovering reflective targets with a low false positive rate. As a result, Ripple enables FlowDroid to find hundreds of sensitive data leakages that would otherwise be missed.
Yifei Zhang 0001, Tian Tan 0001, Yue Li 0006, Jingling Xue
CODASPY1
2016 Program Tailoring: Slicing by Sequential Criteria
abstract
Protocol and typestate analyses often report some sequences of statements ending at a program point P that needs to be scrutinized, since P may be erroneous or imprecisely analyzed. Program slicing focuses only on the behavior at P by computing a slice of the program affecting the values at P. In this paper, we propose to restrict our attention to the subset of that behavior at P affected by one or several statement sequences, called a sequential criterion (SC). By leveraging the ordering information in a SC, e.g., the temporal order in a few valid/invalid API method invocation sequences, we introduce a new technique, program tailoring, to compute a tailored program that comprises the statements in all possible execution paths passing through at least one sequence in SC in the given order. With a prototyping implementation, Tailor, we show why tailoring is practically useful by conducting two case studies on seven large real-world Java applications. For program debugging and understanding, Tailor can complement program slicing by removing SC-irrelevant statements. For program analysis, Tailor can enable a pointer analysis, which is unscalable to a program, to perform a more focused and therefore potentially scalable analysis to its specific parts containing hard language features such as reflection.
Yue Li 0006, Tian Tan 0001, Yifei Zhang 0001, Jingling Xue
ECOOP3