Yue Li 0037

dblp:61/500-37 · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0002-4137-619XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 9 · 1 first-author · 6 since 2021Security and privacy · 7 · 2 first-author · 5 since 2021Systems, architecture and hardware · 4 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Towards Secure Oracle Usage: Understanding and Detecting the Vulnerabilities in Oracle Contracts
Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Jiakun Hao, Anming Xie, Zhi Guan, Zhong Chen 0001
SANER2
2026 Heimdall: A Decentralized Access Control Scheme With Time-Based Secret Management and Private Access Policies
abstract
Decentralized Access Control (DAC) manages access through multiple entities, consisting of two modules: decentralized secret management and access policies. However, existing DAC schemes lack support for managing secrets with time-based conditions, such as triggering secret release after a certain time bound. In this case, users may gain access to information before the designated time, which is undesirable in scenarios involving time-sensitive data. Moreover, current DAC schemes mainly focus on identity confidentiality and lack support for policy confidentiality, which may lead to leakage of sensitive information in access policies. To address these challenges, we propose Heimdall, a decentralized access control scheme with time-based secret management and private access policies. The core of our solution is the dhNIZK protocol, an efficient non-interactive zero-knowledge protocol designed for the verifiable incorporation of time conditions into threshold cryptosystems. We utilize this dhNIZK protocol and homomorphic time-lock puzzles to enable time-based secret management, improving the efficiency of secret reconstruction through batch puzzle-solving techniques. Furthermore, we enhance the garbling scheme’s encoding algorithm to ensure policy confidentiality while maintaining identity confidentiality. Finally, we implement Heimdall and present experimental results demonstrating its superior performance compared to the state-of-the-art solutions.
Libin Xia, Yue Li 0037, Jiashuo Zhang 0001, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Understanding and Detecting Privacy Leakage Vulnerabilities in Hyperledger Fabric Chaincodes
abstract
The application on a blockchain cannot maintain secrecy because its data is replicated across all peers in the network. To remedy this problem, Hyperledger Fabric introduces private data collection (PDC) into its smart contract (i.e. chaincode) to facilitate applications that require privacy. However, recent studies have revealed that PDC is too complex for chaincode developers to fully understand and use correctly, leading to privacy leaks vulnerabilities. In this paper, we present an empirical study on the prevalence of PDC misuse in chaincodes by extracting privacy leakage cases from StackOverflow posts and Hyperledger Fabric repositories on GitHub. Subsequently, we systematically categorize the misuse of PDC into three categories of vulnerabilities resulting in the leakage of private data and provide formal definitions for them. Furthermore, we develop PDChecker, an automated security analysis framework for identifying the privacy and security vulnerabilities in Fabric chaincodes. We evaluated PDChecker on 956 real-world chaincodes applying PDC and found that 67.78% of them contain at least one privacy leakage vulnerability. In addition, PDChecker uncovered 10 zero-day vulnerabilities documented by the China National Vulnerability Database.
Yue Li 0037, Jianbo Gao 0003, Jiashuo Zhang 0001, Ke Wang 0061, Jian-bin Hu, Zhi Guan, Zhong Chen 0001
ISSRE2
2024 SolaSim: Clone Detection for Solana Smart Contracts via Program Representation
abstract
The open-source nature of smart contracts provides the facility for developers to clone contracts and introduces the risk of vulnerability proliferation as well. Despite intensive research on smart contract clone detection in recent years, existing techniques are still unsatisfactory in detecting Solana smart contracts. To fill this gap, in this paper, we designed a clone detection tool SolaSim for Solana smart contracts and conducted an empirical study to understand the code reuse in the Solana ecosystem. Specifically, SolaSim is based on the semantic metadata extractor and the similarity checker. For each contract, the semantic metadata extractor generates an instruction-level weighted Attributed Control Flow Graph (ACFG) and its semantic metadata (i.e., a combination of high-level semantic and structure information) based on Rust Mid-level Intermediate Representation. The similarity checker adopts a combinatorial optimization algorithm to compute the statistical similarity of a pair of contracts. The evaluation results demonstrated the effectiveness of SolaSim in identifying clones with 94.3% accuracy and it can identify up to Type-3 clone level. Notably, we found there are over 50% clone ratios in the Solana smart contracts ecosystem, in which most of them are cloned from famous open-sourced projects.
Yue Li 0037, Jianbo Gao 0003, Ke Wang 0061, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001
ICPC2
2024 Accelerating block lifecycle on blockchain via hardware transactional memory
abstract
The processing of block lifecycles is essential to the efficiency of a blockchain, which consists of four steps: creation, execution, consensus, and validation. The permissionless blockchain systems typically had very limited transaction throughput because of the performance bottleneck of consensus protocols. With recent advances in consensus protocols, the execution and validation of transactions have become the new performance bottleneck. We propose a novel framework, called FastBlock, to speed up the execution and validation steps by introducing fine-grained concurrency. Our early design of FastBlock supported three key modules: (1) a symbolic execution-based analyzer that automatically identifies minimal atomic sections in each transaction; (2) a concurrent execution step that executes possibly conflicting transactions in parallel using hardware transactional memory; (3) a concurrent validation step that introduces a happen-before relation to deterministically re-execute transactions. The improved FastBlock presented in this article supports the nonce mechanism to schedule concurrent transactions from the same account. Moreover, we empirically study the impact of concurrency on Ethereum except for performance and shed light on potential optimizations of FastBlock. Finally, we implemented FastBlock and then evaluated the performance of FastBlock. Our result shows that the FastBlock outperforms state-of-art solutions significantly in performance: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model, respectively, with eight concurrent threads. In addition, we evaluated the impact of the nonce mechanism, and the result shows that the performance loss caused by this mechanism is acceptable in practice.
Yue Li 0037, Han Liu 0010, Jianbo Gao 0003, Jiashuo Zhang 0001, Zhi Guan, Zhong Chen 0001
J. Parallel Distributed Comput.1
2024 DeCloak: Enable Secure and Cheap Multi-Party Transactions on Legacy Blockchains by a Minimally Trusted TEE Network
abstract
The crucial blockchain privacy and scalability demand has boosted off-chain contract execution frameworks for years. Some have recently extended their capabilities to transition blockchain states by off-chain multi-party computation while ensuring public verifiability. This new capability is defined as acrfull mpt. However, existing MPT solutions lack at least one of the following properties crucially valued by communities: data availability, financial fairness, delivery fairness, and delivery atomicity. This paper proposes a novel MPT-enabled off-chain contract execution framework, Decloak. Using TEEs, Decloak solves identified properties with lower gas costs and a weaker assumption. Notably, Decloak is the first to achieve data availability and also achieve all of the above properties. This achievement is coupled with its ability to tolerate all-but-one Byzantine parties and TEE executors. Evaluating 10 MPTs in different businesses, Decloak reduces the gas cost of the SOTA, Cloak, by 65.6%. This efficiency advantage further amplifies with an increasing number of MPT’s parties. Consequently, we establish an elevated level of secure and cheap MPT, being the first to demonstrate the feasibility of achieving gas costs comparable to Ethereum transactions while evaluating MPTs.
Qian Ren, Yue Li 0037, Yingjun Wu, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
IEEE Trans. Inf. Forensics Secur.2
2023 Hades: Practical Decentralized Identity with Full Accountability and Fine-grained Sybil-resistance
abstract
Decentralized identity (DID), the idea of giving users complete control over their identity-related data, is being used to solve the privacy tension in the identity management of decentralized applications (Dapps). While existing approaches do an excellent job of solving the privacy tension, they have not adequately addressed the accountability and Sybil-resistance issues. Moreover, these approaches have a considerable gas overhead, making them impractical for Dapps.
Ke Wang 0061, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ACSAC5
2023 DFHelper: Help clients to participate in federated learning tasks
Zhenhao Wu, Jianbo Gao 0003, Jiashuo Zhang 0001, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001
Appl. Intell.4
2022 Cloak: Transitioning States on Legacy Blockchains Using Secure and Publicly Verifiable Off-Chain Multi-Party Computation
abstract
In recent years, the confidentiality of smart contracts has become a fundamental requirement for practical applications. While many efforts have been made to develop architectural capabilities for enforcing confidential smart contracts, a few works arise to extend confidential smart contracts to Multi-Party Computation (MPC), i.e., multiple parties jointly evaluate a transaction off-chain and commit the outputs on-chain without revealing their secret inputs/outputs to each other. However, existing solutions lack public verifiability and require O(n) transactions to enable negotiation or resist adversaries, thus suffering from inefficiency and compromised security.
Qian Ren, Yingjun Wu, Han Liu 0010, Yue Li 0037, Anne Victor, Hong Lei 0001, Lei Wang 0031, Bangdao Chen
ACSAC4
2022 POLYBRIDGE: A Crosschain Bridge For Heterogeneous Blockchains
abstract
While the Bitcoin and Ethereum are still leading the world of permissionless blockchains, we are increasingly seeing a multipolar ecosystem where new blockchains keep emerging instead of migrating to the two big players. As a result, it is highly desired to enable multiple blockchains to interoperate, e.g., move assets from one blockchain to the other. The crosschain bridge service, as a solution to the blockchain interoperability problem, has been offered by a wide range of service providers. However, the existing bridges either rely on centralised notaries or require complicated preparations, therefore are far from sufficient in practice. In this demo proposal, we highlight the Poly Bridge for heterogeneous blockchains to interoperate with cryptocurrencies. In specific, Poly Bridge is based on an un-derlying Poly Chain and a pair of relays to confirm crosschain transactions and form consensus among relevant parties. More importantly, Poly Bridge delivers extensibility to flexibly inter-face to blockchains with different consensus models and atomicity as well in a way that a sequence of crosschain operations are either all confirmed or all rejected. Poly Bridge is now available as a web application to support crosschain requests with over 200 types of cryptocurrencies on 18 blockchains.
Yue Li 0037, Han Liu 0008
ICBC1
2022 TBFT: Efficient Byzantine Fault Tolerance Using Trusted Execution Environment
abstract
With the rapid development of blockchain, Byzantine fault-tolerant protocols have attracted revived interest recently. To overcome the theoretical bounds of Byzantine fault tolerance, many protocols attempt to use Trusted Execution Environment (TEE) to prevent equivocation and improve fault tolerance from less than 1/3 to minority. However, due to the broken quorum intersection assumption caused by the reduction of replica number, most improvements introduce higher communication complexity or more protocol phases, which affects the performance and scalability of existing TEE-based protocols and prevents them to be applied to large-scale blockchain systems. In this paper, we propose TBFT, an efficient Byzantine fault-tolerant protocol in the partial synchrony setting, which has O(n) message complexity and only two protocol phases in normal-case. The key insight behind TBFT is introducing novel TEE-assisted primitives to limit malicious behaviors of replicas including not only equivocation but also message log forgery and message history forgery, therefore both the communication complexity and protocol phases can be reduced. We have implemented TBFT and evaluated it through systematic analysis and experiments, and the results show that TBFT has better performance and scalability compared to other protocols.
Jiashuo Zhang 0001, Jianbo Gao 0003, Ke Wang 0061, Zhenhao Wu, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ICC5
2022 Xscope: Hunting for Cross-Chain Bridge Attacks
abstract
Cross-Chain bridges have become the most popular solution to support asset interoperability between heterogeneous blockchains. However, while providing efficient and flexible cross-chain asset transfer, the complex workflow involving both on-chain smart contracts and off-chain programs causes emerging security issues. In the past year, there have been more than ten severe attacks against cross-chain bridges, causing billions of loss. With few studies focusing on the security of cross-chain bridges, the community still lacks the knowledge and tools to mitigate this significant threat. To bridge the gap, we conduct the first study on the security of cross-chain bridges. We document three new classes of security bugs and propose a set of security properties and patterns to characterize them. Based on those patterns, we design Xscope, an automatic tool to find security violations in cross-chain bridges and detect real-world attacks. We evaluate Xscope on four popular cross-chain bridges. It successfully detects all known attacks and finds suspicious attacks unreported before. A video of Xscope is available at https://youtu.be/vMRO_qOqtXY.
Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Zhi Guan, Zhong Chen 0001
ASE3
2022 Smifier: A Smart Contract Verifier for Composite Transactions
abstract
Ensuring functional correctness of smart contracts is a pressing security concern to blockchain-based systems.With the development of blockchain application, the trading scenarios and function implementation of smart contracts have become increasing complex, containing several interacted contracts or related functions.However, the existing contracts verifiers for proving functional correctness focus on verifying isolated contract or function but ignore the interactions between them, which makes it difficult to verify correctness of composite transactions, i.e., complex transaction scenarios that invoke multiple contracts or trigger a set of transactions.In this paper, we present SMIFIER, a formal verification tool for smart contracts to prove functional properties in composite transactions.SMIFIER defines a set of specifications for composite transactions and can automatically specify properties in these multiple complex transactions.Based on states extraction and mapping, SMIFIER translates annotated Solidity program into Boogie program and verifies relations between functions and properties for interacted contracts.Our experimental evaluation on 12 real-world projects and 65 properties, demonstrates that SMIFIER is practically effective in ensuring functional correctness of properties in composite transactions.
Yue Li 0037, Dongqi Cui, Jianbo Gao 0003, Zhi Guan, Zhong Chen 0001
SEKE2
2021 FASTBLOCK: Accelerating Blockchains via Hardware Transactional Memory
abstract
The efficiency of block lifecycle determines the performance of blockchain, which is critically affected by the execution, mining and validation steps in blockchain lifecycle. To accelerate blockchains, many works focus on optimizing the mining step while ignoring other steps. In this paper, we propose a novel blockchain framework-FastBlock to speed up the execution and validation steps by introducing efficient concurrency. To efficiently prevent the potential concurrency violations, FastBlock utilizes symbolic execution to identify minimal atomic sections in each transaction and guarantees the atomicity of these sections in execution step via an efficient concurrency control mechanism-hardware transactional memory (HTM). To enable a deterministic validation step, FastBlock concurrently re-executes transactions based on a happen-before graph without increasing block size. Finally, we implement FastBlock and evaluate it in terms of conflicting transactions rate, number of transactions per block, and varying thread number. Our results indicate that FastBlock is efficient: the execution step and validation step speed up to 3.0x and 2.3x on average over the original serial model respectively with eight concurrent threads.
Yue Li 0037, Han Liu 0010, Yuanliang Chen, Jianbo Gao 0003, Zhenhao Wu, Zhi Guan, Zhong Chen 0001
ICDCS1
2021 Demo: Cloak: A Framework For Development of Confidential Blockchain Smart Contracts
abstract
In recent years, as blockchain adoption has been expanding across a wide range of domains, e.g., digital asset, supply chain finance, etc., the confidentiality of smart contracts is now a fundamental demand for practical applications. However, while new privacy protection techniques keep coming out, how existing ones can best fit development settings is little studied. Suffering from limited architectural support in terms of programming interfaces, state-of-the-art solutions can hardly reach general developers. In this paper, we proposed the CLOAK framework for developing confidential smart contracts. The key capability of Cloak is allowing developers to implement and deploy practical solutions to multi-party transaction (MPT) problems, i.e., transact with secret inputs and states owned by different parties by simply specifying it. To this end, CLOAK introduced a domain-specific annotation language for declaring privacy specifications and further automatically generating confidential smart contracts to be deployed with trusted execution environment (TEE) on blockchain. In our evaluation on both simple and real-world applications, developers managed to deploy business services on blockchain in a concise manner by only developing CLOAK smart contracts whose size is less than 30% of the deployed ones.
Qian Ren, Han Liu 0010, Yue Li 0037, Hong Lei 0001
ICDCS3
2020 SafePay on Ethereum: A Framework For Detecting Unfair Payments in Smart Contracts
abstract
Smart contracts on the Ethereum blockchain are notoriously known as vulnerable to external attacks. Many of their issues led to a considerably large financial loss as they resulted from broken payments by digital assets, e.g., cryptocurrency. Existing research focused on specific patterns to find such problems, e.g., reentrancy bug, nondeterministic recipient etc., yet may lead to false alarms or miss important issues. To mitigate these limitations, we designed the SafePay analysis framework to find unfair payments in Ethereum smart contracts. Compared to existing analyzers, SafePay can detect potential blockchain transactions with feasible exploits thus effectively avoid false reports. Specifically, the detection is driven by a systematic search for violations on fair value exchange (FVE), i.e., a new security invariant introduced in SafePay to indicate that each party “fairly” pays to others. The preliminary evaluation validated the efficacy of SafePay by reporting previously unknown issues and decreasing the number of false alarms.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
ICDCS1
2020 Kaya: A Testing Framework for Blockchain-based Decentralized Applications
abstract
In recent years, many decentralized applications based on blockchain (DApp) have been developed. Some development tools provide testing functions, but only for developers to write unit tests for smart contracts rather than test DApp as a whole. Moreover, due to the difficulty for testers to understand the implementation details of smart contracts, insufficient functional testing causes some DApps not to meet functional design expectations. The inherent complexity of DApp, inconvenient pre-state setting, and not-so-readable logs make DApp testing challenging. In this paper, we propose Kaya, a testing framework for DApps to bridge these gaps. Firstly, Kaya formulate automatically executed test cases that cover both front-end behaviors and back-end logics with simple setting. Secondly, Kaya provides a flexible and convenient way for test engineers to set the blockchain pre-states. Thirdly, Kaya transforms incomprehensible addresses into readable variables for easier comprehension. Besides, to fit the various application environments, we provide both GUI and CLI for test engineers to use Kaya. Our case study and preliminary human study demonstrates the potential of Kaya in helping test engineers to test DApps more easily. A demo video is at https://youtu.be/7DyI_EpVZFw.
Zhenhao Wu, Jiashuo Zhang 0001, Jianbo Gao 0003, Yue Li 0037, Qingshan Li, Zhi Guan, Zhong Chen 0001
ICSME4
2020 EShield: protect smart contracts against reverse engineering
abstract
Smart contracts are the back-end programs of blockchain-based applications and the execution results are deterministic and publicly visible. Developers are unwilling to release source code of some smart contracts to generate randomness or for security reasons, however, attackers still can use reverse engineering tools to decompile and analyze the code. In this paper, we propose EShield, an automated security enhancement tool for protecting smart contracts against reverse engineering. EShield replaces original instructions of operating jump addresses with anti-patterns to interfere with control flow recovery from bytecode. We have implemented four methods in EShield and conducted an experiment on over 20k smart contracts. The evaluation results show that all the protected smart contracts are resistant to three different reverse engineering tools with little extra gas cost.
Wentian Yan, Jianbo Gao 0003, Zhenhao Wu, Yue Li 0037, Zhi Guan, Qingshan Li, Zhong Chen 0001
ISSTA4
2020 Protect Your Smart Contract Against Unfair Payment
abstract
While smart contracts have enabled a wide range of applications in many public blockchains, e.g., Ethereum, their security issues have been raising an increasing number of threats on the stability of blockchain ecosystem. In practice, many external attacks on smart contracts result from broken payments with digital assets, e.g., cryptocurrencies. While an increasing number of research works have been focusing on such problems, many of them adopted pattern-based heuristics (e.g., reentrancy) to find payment-related attacks thus can incur a considerably large portion of both false positives and negatives. To overcome these limitations and achieve better payment security on blockchain, we introduced a new class of payment attacks in this paper, i.e., unfair payment (UP). Compared to existing heuristics, UP semantically captures a wider range of payment attacks. Furthermore, we highlighted the general framework SAFEPAY to systematically detect UP. The key insight behind is a novel security invariant, i.e., fair value exchange (FVE), which models the fairness for blockchain payments between multiple parties. More specifically, SAFEPAY systematically explores the transaction space of a given smart contract and generates a bounded set of transaction sequences. For each of the sequence, SAFEPAY reports a UP attack once a violation on FVE is confirmed. We have further instantiated SAFEPAY for Ethereum and applied it in real-world smart contracts. In the empirical evaluation, SAFEPAY managed to identify previously unreported UP attacks and effectively avoid false alarms compared to analyzers in the literature as well.
Yue Li 0037, Han Liu 0010, Qian Ren, Lei Wang 0031, Bangdao Chen
SRDS1
2019 Understanding Out of Gas Exceptions on Ethereum
Chao Liu 0032, Jianbo Gao 0003, Yue Li 0037, Zhong Chen 0001
BlockSys3
2019 Towards automated testing of blockchain-based decentralized applications
abstract
Blockchain-based decentralized applications (DApp) have been widely adopted in different areas and trusted by more and more users due to the fact that the back end code of a DApp is publicly run on the blockchain and cannot be modified implicitly. However, there are few effective methods and tools for testing DApps and bugs can be easily introduced by inexperienced developers. The existing testing techniques either focus on testing front-end programs or back-end code but ignore the interaction between them, which makes it difficult to apply the techniques directly on DApp. In this paper, we present an automated testing technique for DApps which works in a two-phase manner. First, we employ random events to infer an abstract relation between browser-side events and blockchain-side contracts. Second, our technique generates a set of test cases under the guidance of inferred relations and orders the test cases based on a read-write graph. We also use taint analysis to track data flow of the smart contract and feed it to the generation procedure for following test cases. We have developed a tool called Sungari to implement our approach, and evaluated it on representative real-world DApps. The preliminary evaluation results demonstrated the potential of Sungari in achieving a significant optimization compared to random testing approaches.
Jianbo Gao 0003, Han Liu 0010, Yue Li 0037, Chao Liu 0032, Qingshan Li, Zhi Guan, Zhong Chen 0001
ICPC3