EDBT 2026 Demo / reviewers in the wild / expert
Tianning Zhang
dblp:71/2377
· DBLP profile ↗
9ranked-venue papers
6as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorComputer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SSEFormer: A sign-sensitive transformer with semantic fusion for link sign prediction
Tianning Zhang, Maojun Wang |
Neurocomputing | 1 |
| 2022 | eSROP Attack: Leveraging Signal Handler to Implement Turing-Complete Attack Under CFI Defense
Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
SecureComm | 1 |
| 2022 | SigGuard: Hardening Vulnerable Signal Handling in Commodity Operating SystemsabstractSignal is a useful mechanism provided by many commodity operating systems. However, current signal handling has serious security concerns due to vulnerable design in missing integrity protections for signal handling control flow. Security weaknesses caused by vulnerable design are exploited by adversaries to mount dangerous control-flow attacks. To tackle these issues, this paper investigates root causes of signal-related attacks and proposes SigGuard to harden vulnerable signal handling mechanism. To protect unsafe signal handler execution flow, we design a customized signal handler CFI framework which supports low-cost, reentrant, online CFI analysis and enforcement. To secure signal handler return control flow, we propose an efficient, software-based, intra-process memory isolation method to ensure signal frame data integrity. We evaluate SigGuard with both security and performance experiments. In security experiments, SigGuard successfully thwarts four signal-based attacks, including two proof-of-concept exploits and two realistic attacks conducted in Nginx and Apache server programs, respectively. We also evaluate SigGuard key techniques with a series of microbenchmarks and real-world applications. Experimental results suggest that key defense techniques used in SigGuard introduce reasonable performance costs. Miao Cai 0001, Junru Shen, Tianning Zhang, Hao Huang 0011 |
SRDS | 3 |
| 2022 | SeBROP: blind ROP attacks without returns
Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
Frontiers Comput. Sci. | 1 |
| 2020 | De-randomizing the Code Segment with Timing Function AttackabstractRecently, many effective defensive methods (e.g., ASLR, execute-only-memory) have been proposed to defeat the code reuse attack in the software system. These approaches provide strong system protection through address randomization or memory access restriction. However, this paper identifies a new weak point in these approaches, i.e., missing time protection. We propose a new attack method called timing function attack, which can initiate a code reuse attack even against the state-of-the-art defense techniques. Previous solutions utilize various techniques to hide the spatial information. However, we still can obtain critical security information through the time channel. Specifically, we leverage the function execution time to conduct a side-channel attack. Further, we de-randomize the code segment layout with the timing-channel attack result. Finally, we perform a code-reuse attack with gadgets gathered in previous steps, compromising the whole system. To validate our timing function attack in the real world, we conduct two attacks on two JavaScript engines, i.e., ChakraCore and Chrome v8. Evaluation results show that our attack can successfully bypass the existing defense techniques, such as function-granularity ASLR and XOM, and escalate the privilege. Besides, we also discuss some solutions to prevent and defend our proposed timing function attack. Tianning Zhang, Miao Cai 0001, Diming Zhang, Hao Huang 0011 |
TrustCom | 1 |
| 2020 | A Model-Based Test Case Prioritization Approach Based on Fault Urgency and SeverityabstractWith the aggrandizement scale of software system, the number of test cases has grown explosively. Test case prioritization (TCP) has been widely used in software testing to effectively improve testing efficiency. However, traditional TCP methods are mostly based on software code and they are difficult to apply to model-based testing. Moreover, existing model-based TCP techniques often do not take the likely distribution of faults into consideration, yet software faults are not often equally distributed in the system, and test cases that cover more fault prone modules are more likely to reveal faults so that they should be run with a higher priority. Therefore, in this paper, we provide a TCP approach based on Hidden Markov Model (HMM), to detect faults as earlier as possible and reduce the cost of modification. This approach consists of the following main parts: (1) transforming the Unified Modeling Language (UML) sequence diagram to HMM; (2) estimating the fault urgency according to fault priority and probability; (3) estimating the fault severity by analyzing the weight of the state in the HMM; (4) generating test case priority from fault urgency and fault severity, then prioritizing test case. The proposed approach is implemented on unmanned aerial vehicles (UAV) flight control system to perform TCP. The experimental results show that our proposed TCP approach can effectively enhance the probability of earlier fault detection and improve the efficiency and stability as compared to other prioritization techniques, such as original prioritization, random prioritization, additional prioritization and EPS-UML. Qingying Sun, Xingqi Wang 0001, Tianning Zhang |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2018 | Test Case Prioritization Technique Based on Error Probability and Severity of UML ModelsabstractTest case prioritization is one of the most useful activities in testing. Most existing test case prioritization techniques are based on code coverage, which requires access to source code. However, code-based testing comes late in the software development life cycle, when errors are detected, the cost of testing is very high. Therefore, in this paper, we provide a test case prioritization technique based on Unified Modeling Language (UML) model, built before coding, to detect errors as earlier as possible and reduce the cost of modification. The technique consists of the following main parts: (1) using C&K metrics to estimate the error probability of class; (2) using dependences, obtained from the model slicing, to estimate error severity; (3) generating test case priority from error probability and severity, then prioritizing the test case. With our technique, test engineers need the UML model only and the test cases can be prioritized automatically. To evaluate our technique, we applied our technique to unmanned aerial vehicles (UAV) flight control system and performed test case prioritization. The results show that the error can be detected effectively and stability can be increased significantly as compared to the current code-based techniques. Tianning Zhang, Xingqi Wang 0001, Jinglong Fang |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 1997 | Java-Based Intelligent Mobil Agents for Open System ManagementabstractTraditional approaches for network and service management are not suitable for heterogeneous, rapidly changing and extending telecommunications environments. The paper discusses the use of Java based intelligent mobile agents in the field of open system management It first presents a Java based mobile agent platform supporting the mobile management agents. Based on the mobility framework, the paper then describes an intelligence platform which supports the specification and processing of management solution knowledge implemented as intelligent mobile agents. The management solutions are viewed as Java based rules, which are organized into a hierarchy by the specialization/generalization relationships among the network situations which the management solutions are developed for. The proposed intelligence paradigm and the associated knowledge processing mechanism offer the advantages of object oriented development in a widely distributed telecommunications environment. The paper introduces an appealing alternative or extension to the current network management solutions. Stefan Covaci, Tianning Zhang, Ingo Busse |
ICTAI | 2 |
| 1996 | The Semantics of Network Management InformationabstractSemantics plays an important role in the context of network management, both for clearing out ambiguities and for supporting management decisions. The current behavior-oriented semantic frameworks do not find wide acceptance in this context due to their complexity and lack of support for management applications. We propose a new semantic approach to network management. The semantics is defined by context-specific restrictions representing relationships between situations. By structuring the situation descriptions in a hierarchy, we build up a semantic framework for the network management which corresponds to the object-oriented development style and benefits from features like reusability, abstraction support, and accumulative developments. Tianning Zhang, Stefan Covaci |
INFOCOM | 1 |