Enze Wang

dblp:70/8419 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 5 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 League of LLMs: A Benchmark-Free Paradigm for Mutual Evaluation of Large Language Models
abstract
Qianhong Guo, Wei Xie, Xiaofang Cai, Enze Wang, Shuoyoucheng Ma, Xiaobing Sun, Tian Xia, Kai Chen, Xiaofeng Wang, Baosheng Wang. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Qianhong Guo, Wei Xie 0007, Xiaofang Cai, Enze Wang, Shuoyoucheng Ma
ACL (1)4
2026 Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Enze Wang, Jianjun Chen 0005, Qi Wang 0094, Hai-Xin Duan, Wei Xie 0007
NDSS2
2025 AIPsychoBench: Understanding the Psychometric Differences between LLMs and Humans
Wei Xie 0007, Shuoyoucheng Ma, Enze Wang, Hanying Tong
CogSci6
2025 Do Large Language Models Truly Grasp Mathematics? An Empirical Exploration from Cognitive Psychology
Shuoyoucheng Ma, Wei Xie 0007, Enze Wang, Hanying Tong
CogSci6
2025 Self-Persuasion: A Novel Cognitive Approach to Effective LLM Jailbreaking
Wei Xie 0007, Shuoyoucheng Ma, Zhihua Wen, Enze Wang
CogSci7
2025 UNICOM: Unified, foreground-aware, and context-realistic deep image composition with diffusion model
Yuanhao Wang 0017, Enze Wang, Ziyang Zhao, Yanqi He, Zexian Song
Neurocomputing4
2024 Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications
abstract
Server-Side Request Forgery (SSRF) vulnerability poses significant security risks to web applications, enabling adversaries to exploit web applications as stepping stones for unauthorized access of internal-only services or even performing arbitrary commands. Despite its recent emergence as a distinct category in the 2021 OWASP Top 10 web security risks and its increasing prevalence in modern web applications, there remains a lack of effective approaches to detect SSRF vulnerabilities systematically.We present a novel methodology, SSRFuzz, to effectively identify SSRF vulnerability in PHP web applications. Our methodology consists of three phases. In the initial phase, we designed an SSRF oracle to examine functions in PHP manuals and identify sinks that provide server-side request capabilities. This process yielded a total of 86 sensitive PHP sinks out of 2101 PHP functions. The second stage involves dynamic taint inference and the utilization of the identified sinks to examine the source code of target web applications, pinpointing all feasible input points that could trigger these sinks. The final phase employs fuzzing techniques. We generate testing HTTP requests with SSRF payloads, send them to the previously identified input points within the target web applications, and detect if an SSRF vulnerability is triggered. We implemented a prototype of SSRFuzz and evaluated it on 27 real-world applications, including Joomla and WordPress. In total, we discovered 28 SSRF vulnerabilities, 25 of which were previously unreported. We reported all the vulnerabilities to the affected vendors, and 16 new CVE IDs were assigned.
Enze Wang, Jianjun Chen 0005, Wei Xie 0007, Chuhan Wang 0001, Hai-Xin Duan, Yang Liu 0003
SP1
2022 Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT Devices
abstract
Recent years have seen increased attacks targeting embedded web applications of IoT devices. An important target of such attacks is the hidden interface of embedded web applications, which employs no protection but exposes security-critical actions and sensitive information to illegitimate users. With the severity and the pervasiveness of this issue, it is crucial to identify the vulnerable hidden interfaces, shed light on best practices and raise public awareness.
Wei Xie 0007, Jiongyi Chen, Chao Feng 0002, Enze Wang, Kai Lu 0001
WWW5
2021 XHunter: Understanding XXE Vulnerability via Automatic Analysis
Wei Xie 0007, Yong Tang 0005, Enze Wang
SecureComm (2)5
2020 EcoFuzz: Adaptive Energy-Saving Greybox Fuzzing as a Variant of the Adversarial Multi-Armed Bandit
Tai Yue, Pengfei Wang 0010, Yong Tang 0005, Enze Wang, Bo Yu 0008, Kai Lu 0001, Xu Zhou 0004
USENIX Security Symposium4
2010 A Delay-Based Dynamic Load Balancing Method and Its Stability Analysis and Simulation
Qingyang Meng, Jianzhong Qiao, Shukuan Lin, Enze Wang
Euro-Par (1)4
2010 An Inframarginal Analysis Based Resource Allocation Method in Distributed Computing
abstract
The key of distributed computing is to fully utilize computing resources. However, the efficiency of distributed computing can always be affected by volatility of available nodes and uncertainty of network environment. In order to enhance resource allocation efficiency in distributed computing, this paper presents an inframarginal analysis based resource allocation method, which distributes computing task to the node with more comparative advantage carrying on the task. Simulation results proved that it is effective on resource allocation in the distributed computing environment.
Jun Liu 0033, Enze Wang, Jianzhong Qiao, Shukuan Lin
ISPA2