Yingpei Zeng

dblp:63/7663 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
8since 2021 · last 2026
0000-0002-6294-4889ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 5 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic Verification
Xiangpu Song, Longjia Pei, Jianliang Wu 0002, Yingpei Zeng, Gaoshuo He, Chaoshun Zuo, Xiaofeng Liu 0013, Qingchuan Zhao, Shanqing Guo
NDSS4
2025 MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT Brokers
Xiangpu Song, Jianliang Wu 0002, Yingpei Zeng, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo
USENIX Security Symposium3
2025 CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback
Xiangpu Song, Yingpei Zeng, Jianliang Wu 0002, Hao Li 0092, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo
Comput. Secur.2
2025 Improving seed quality with historical fuzzing results
Yingpei Zeng, Xiangpu Song, Shanqing Guo
Inf. Softw. Technol.2
2025 HSPFuzzer: High-Speed Network Protocol Fuzzing With Connection Reuse
abstract
Fuzzing is a fundamental technique for detecting vulnerabilities in network protocols. However, existing approaches suffer from low fuzzing throughput caused by the overhead associated with server under test (SUT) restarts and connection setup. In this article, we present HSPFuzzer, a High-Speed Protocol Fuzzer that leverages connection reuse to reduce SUT restarts and connection re-establishments. To enable efficient connection reuse, it incorporates a prefix message identification algorithm to determine the essential packets required within a connection and a coverage monitoring mechanism to detect abnormal execution states. Additionally, HSPFuzzer employs an innovative message provision method that ensures input messages are delivered to the SUT with minimal delay within the same connection. HSPFuzzer also eliminates the need for manually implementing message-splitting logic by connection reuse. We evaluate HSPFuzzer on 12 widely used servers and experimental results show that HSPFuzzer achieves fuzzing throughput$1062{\times }$faster than AFLNet, whereas other state-of-the-art fuzzers, including AFLNet, SnapFuzz, HNPFuzzer, and AFL++, achieve, at most, a$12{\times }$speedup over AFLNet. Furthermore, HSPFuzzer attains an average code coverage increase of 25.1% compared to AFLNet, while competing fuzzers achieve, at most, 2.13% more coverage. Notably, HSPFuzzer also discovers more vulnerabilities, which further proves its effectiveness.
Zhewei Xia, Yingpei Zeng, Xiangpu Song, Shanqing Guo, Ting Wu 0001
IEEE Internet Things J.2
2025 AutoFuzz: automatic fuzzer-sanitizer scheduling with multi-armed bandit
Yijia Gao, Wenrui Zeng, Yingpei Zeng
Softw. Qual. J.4
2024 TLS-DeepDiffer: Message Tuples-Based Deep Differential Fuzzing for TLS Protocol Implementations
abstract
Logic vulnerabilities associated with TLS protocol implementations often do not exhibit explicit erroneous behaviors, making them difficult to detect by testers. However, these vulnerabilities can pose serious security threats. While testing for TLS protocols lacks uniform test oracles, differential fuzzing effectively addresses this issue. Unfortunately, most of these vulnerabilities are triggered in deep protocol states, and no existing work on differential fuzzing targeting these states exists. In this paper, we propose a deep differential fuzzing framework that focuses on detecting logic issues in deep TLS protocol states. Our approach is based on the message tuples we proposed, which are semi-automatically extracted from RFCs using NLP techniques. We address the problem of test interruptions during early handshakes caused by original data inconsistencies by redefining the consistency determination to achieve deep differential fuzzing. In addition, we use encoding classification statistics to achieve quick and efficient analysis of the massive test results. Based on our approach, we implemented TLS-DeepDiffer and used it to test nine kinds of popular TLS libraries. We found four historical CVEs, one newly discovered high-risk vulnerability, and 24 security or implementation issues, demonstrating the usefulness of our approach.
Xiangpu Song, Qiuyu Zhong, Yingpei Zeng, Chengyu Hu 0001, Shanqing Guo
SANER4
2023 DeepDiffer: Find Deep Learning Compiler Bugs via Priority-guided Differential Fuzzing
abstract
Recently, Deep learning (DL) compilers have been widely developed to optimize the deployment of DL models. These DL compilers transform DL models into high-level intermediate representation (IR) and then into low-level IR, ultimately generating optimized codes for different hardware targets. However, DL compilers are not immune to generating incorrect code, leading to potentially severe consequences. Testing techniques for low-level IR are limited, and efficient approaches for detecting some categories of non-crashing bugs are lacking. In this paper, we address the limitations of existing low-level IR DL compiler testing techniques and introduce DeepDiffer, a priority-guided differential testing framework designed to detect bugs resulting from low-level optimizations in the DL compiler, specifically TVM. We propose a novel DL compiler coverage metric and establish an optimization goal to maximize the detection of valuable differences between DL compilers. Our experiments demonstrate that DeepDiffer outperforms existing low-level IR fuzzers, detecting a wider range of bug types. In fact, DeepDiffer has successfully identified 13 bugs in TVM, which can be categorized into 9 distinct root causes, and 9 bugs are first found. We have submitted these bugs to the TVM community, where they have been confirmed.
Kuiliang Lin, Xiangpu Song, Yingpei Zeng, Shanqing Guo
QRS3
2020 Improved Single-Key Attacks on 2-GOST
abstract
GOST, known as GOST-28147-89, was standardized as the Russian encryption standard in 1989. It is a lightweight-friendly cipher and suitable for the resource-constrained environments. However, due to the simplicity of GOST’s key schedule, it encountered reflection attack and fixed point attack. In order to resist such attacks, the designers of GOST proposed a modification of GOST, namely, 2-GOST. This new version changes the order of subkeys in the key schedule and uses concrete S-boxes in round function. But regarding single-key attacks on full-round 2-GOST, Ashur et al. proposed a reflection attack with data of 2 32 on a weak-key class of size 2 224 , as well as the fixed point attack and impossible reflection attack with data of 2 64 for all possible keys. Note that the attacks applicable for all possible keys need the entire plaintext space. In other words, these are codebook attacks. In this paper, we propose single-key attacks on 2-GOST with only about 2 32 data instead of codebook. Firstly, we apply 2-dimensional meet-in-the-middle attack combined with splice-cut technique on full-round 2-GOST. This attack is applicable for all possible keys, and its data complexity reduces from previous 2 64 to 2 32 . Besides that, we apply splice-cut meet-in-the-middle attack on 31-round 2-GOST with only data of 2 32 . In this attack, we only need 8 bytes of memory, which is negligible.
Qiuhua Zheng, Yinhao Hu, Tao Pei, Shengwang Xu, Junzhe Yu, Ting Wu 0001, Yanzhao Shen, Yingpei Zeng, Tingting Cui
Secur. Commun. Networks8
2018 Deep Packet Inspection with Delayed Signature Matching in Network Auditing
Yingpei Zeng, Shanqing Guo
ICICS1
2018 DRLgencert: Deep Learning-Based Automated Testing of Certificate Verification in SSL/TLS Implementations
abstract
The Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are the foundation of network security. The certificate verification in SSL/TLS implementations is vital and may become the "weak link" in the whole network ecosystem. In previous works, some research focused on the automated testing of certificate verification, and the main approaches rely on generating massive certificates through randomly combining parts of seed certificates for fuzzing. Although the generated certificates could meet the semantic constraints, the cost is quite heavy, and the performance is limited due to the randomness. To fill this gap, in this paper, we propose DRLGENCERT, the first framework of applying deep reinforcement learning to the automated testing of certificate verification in SSL/TLS implementations. DRLGENCERT accepts ordinary certificates as input and outputs newly generated certificates which could trigger discrepancies with high efficiency. Benefited by the deep reinforcement learning, when generating certificates, our framework could choose the best next action according to the result of a previous modification, instead of simple random combinations. At the same time, we developed a set of new techniques to support the overall design, like new feature extraction method for X.509 certificates, fine-grained differential testing, and so forth. Also, we implemented a prototype of DRLGENCERT and carried out a series of real-world experiments. The results show DRLGENCERT is quite efficient, and we obtained 84,661 discrepancy-triggering certificates from 181,900 certificate seeds, say around 46.5% effectiveness. Also, we evaluated six popular SSL/TLS implementations, including GnuTLS, MatrixSSL, MbedTLS, NSS, OpenSSL, and wolfSSL. DRLGENCERT successfully discovered 23 serious certificate verification flaws, and most of them were previously unknown.
Wenrui Diao, Yingpei Zeng, Shanqing Guo, Chengyu Hu 0001
ICSME3
2013 Secure localization and location verification in wireless sensor networks: a survey
Yingpei Zeng, Jiannong Cao 0001, Jue Hong, Shigeng Zhang, Li Xie 0001
J. Supercomput.1
2010 On accuracy of region based localization algorithms for wireless sensor networks
Shigeng Zhang, Jiannong Cao 0001, Yingpei Zeng, Zhuo Li 0003, Lijun Chen 0006, Daoxu Chen
Comput. Commun.3
2010 Random-walk based approach to detect clone attacks in wireless sensor networks
abstract
Wireless sensor networks (WSNs) deployed in hostile environments are vulnerable to clone attacks. In such attack, an adversary compromises a few nodes, replicates them, and inserts arbitrary number of replicas into the network. Consequently, the adversary can carry out many internal attacks. Previous solutions on detecting clone attacks have several drawbacks. First, some of them require a central control, which introduces several inherent limits. Second, some of them are deterministic and vulnerable to simple witness compromising attacks. Third, in some solutions the adversary can easily learn the critical witness nodes to start smart attacks and protect replicas from being detected. In this paper, we first show that in order to avoid existing drawbacks, replica-detection protocols must be non-deterministic and fully distributed (NDFD), and fulfill three security requirements on witness selection. To our knowledge, only one existing protocol, Randomized Multicast, is NDFD and fulfills the requirements, but it has very high communication overhead. Then, based on random walk, we propose two new NDFD protocols, RAndom WaLk (RAWL) and Table-assisted RAndom WaLk (TRAWL), which fulfill the requirements while having only moderate communication and memory overheads. The random walk strategy outperforms previous strategies because it distributes a core step, the witness selection, to every passed node of random walks, and then the adversary cannot easily find out the critical witness nodes. We theoretically analyze the required number of walk steps for ensuring detection. Our simulation results show that our protocols outperform an existing NDFD protocol with the lowest overheads in witness selection, and TRAWL even has lower memory overhead than that protocol. The communication overheads of our protocols are higher but are affordable considering their security benefits.
Yingpei Zeng, Jiannong Cao 0001, Shigeng Zhang, Shanqing Guo, Li Xie 0001
IEEE J. Sel. Areas Commun.1
2009 A Location-free Prediction-based Sleep Scheduling Protocol for Object Tracking in Sensor Networks
abstract
Sleep scheduling protocols are widely used in wireless sensor networks for saving energy in sensor nodes. However, without considering the special requirements of object tracking, conventional sleep scheduling protocols may lead to intolerable degradation of tracking qualities when they are used in object tracking applications. To handle this problem, sleep scheduling protocols tailed for object tracking have been proposed recently. For saving energy while maintaining satisfactory tracking qualities, these protocols pro-actively awaken sensors according to the prediction of objects' movement. Such sleep scheduling protocols are called the prediction-based sleep scheduling protocols. Most existing prediction-based sleep scheduling protocols require sensor nodes to know the locations of themselves, which may not always be available. In this paper we propose a Location-free Prediction-based Sleep Scheduling protocol (LPSS) for object tracking in sensor networks. LPSS guarantees the coverage level, an important tracking quality in most applications, which is defined as the number of sensors simultaneously detecting the object. In LPSS, when a sensor detects the object, it will emit a signal, namely the sensing stimulus. Sensors decide to wake up or not based on only the received sensing stimulus, the prediction models and the required coverage level, without the requirement of location information. We implement LPSS with two most popular prediction models: the Circle-based and the Probability-based prediction models. Experiment results show that LPSS not only provides qualified coverage levels, but also saves about 40% to 70% energy compared with existing location-free protocols. Moreover, the energy cost of LPSS is close to the ideal approach using accurate location information in terms of the number of awakened nodes.
Jue Hong, Jiannong Cao 0001, Yingpei Zeng, Sanglu Lu, Daoxu Chen, Zhuo Li 0003
ICNP3
2009 Secure localization and location verification in wireless sensor networks
abstract
Sensors' locations are important to many wireless sensor networks (WSNs). When WSNs are deployed in hostile environments, two issues about sensors' locations need to be considered. First, the attackers may attack the localization process to make the estimated locations incorrect. Second, since sensor nodes may be compromised, the base station may not trust the locations reported by sensor nodes. Researchers have proposed two techniques, secure localization and location verification, to solve the two issues respectively. In this paper we describe the attacks against localization and location verification, and survey the state of research of both secure localization and location verification.
Yingpei Zeng, Jiannong Cao 0001, Jue Hong, Li Xie 0001
MASS1
2009 SecMCL: A Secure Monte Carlo Localization Algorithm for Mobile Sensor Networks
abstract
Recently with the emergence of mobile sensor networks, localization for such networks has gained much attention, and many localization algorithms have been proposed. Among them the Sequential Monte Carlo (SMC) based algorithms are very popular because of their simplicity and efficiency. However, most current SMC-based localization algorithms implicitly assume there is no attacker in the network, which may not be true in real applications. The attackers, if any, may send false information by themselves or through compromised nodes to disturb the localization. In this paper, we present the design and evaluation of a Secure Monte Carlo Localization algorithm, SecMCL. SecMCL provides authentication to messages and employs a new sampling method to defeat attacks. Simulation results show that SecMCL greatly improves the localization accuracy of existing SMC-based localization method when there are attacks. Also, compared with existing SMC localization method, SecMCL incurs no communication cost (in terms of number of messages) and achieves the same localization accuracy when there is no attack.
Yingpei Zeng, Jiannong Cao 0001, Jue Hong, Shigeng Zhang, Li Xie 0001
MASS1
2009 SWCA: a secure weighted clustering algorithm in wireless ad hoc networks
abstract
Clustering has been widely used in wireless ad hoc networks for various purposes such as routing, broadcasting and Qos. Many clustering algorithms have been proposed. However, most of them implicitly assume that nodes behave honestly in the clustering process. In practice, there might be some malicious nodes trying to manipulate the clustering process to make them serve as clusterheads, which can obtain some special power, e.g., eavesdropping more messages. In this paper we present a secure weighted clustering algorithm (SWCA). SWCA uses the weighted clustering algorithm (WCA) for clustering and TELSA for efficiently authenticating packets. We propose a novel neighbor verification scheme to check whether the values of election-related features (e.g., node degree) are forged by malicious nodes. Also, we theoretically analyze the probability for a malicious node to tamper node degree without being detected and derive a lower bound on the probability. Finally, simulation results show that SWCA is secure but still has comparable performance with WCA. To the best of our knowledge, SWCA is the first algorithm considering the security of 1-hop type clustering (in this type only the clusterhead can communicate with ordinary members directly) in ad hoc networks.
Yingpei Zeng, Jiannong Cao 0001, Shanqing Guo, Li Xie 0001
WCNC1
2009 Pollution attack: a new attack against localization in wireless sensor networks
abstract
Many secure localization algorithms have been proposed. In these algorithms, collusion attack is usually considered as the strongest attack when evaluating their performance. Also, for ensuring correct localization under the collusion attack, a necessary number of normal beacons are needed and a lower bound on this number has been established (assuming the errors of distance measurements are ignorable). In this paper, we introduce pollution attack, a more powerful attack which can succeed even when the number of normal beacons is more than the lower bound. In this attack, victim node is misled to a special chosen location, which results in a confusion of compromised beacon with normal beacon. We propose a new metric to measure the vulnerability of a normal location reference set to pollution attack, and develop two algorithms to efficiently compute the value of the proposed metric. We also present a method to judge whether the output of the localization algorithm is credible under pollution attack. Simulation results show that the pollution attack can succeed with high probability.
Yingpei Zeng, Jiannong Cao 0001, Shigeng Zhang, Shanqing Guo, Li Xie 0001
WCNC1