EDBT 2026 Demo / reviewers in the wild / expert
Naipeng Dong
dblp:82/9243
· DBLP profile ↗
39ranked-venue papers
4as first author
20since 2021 · last 2026
0000-0002-8248-3362ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 21 · 1 first-author · 10 since 2021Security and privacy · 11 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-agent reinforcement curriculum learning for real unmanned ground vehiclesabstractThis paper investigates the use of deep reinforcement learning (DRL) for the control of mobile robot teams within the context of navigation and task-based collaborative scenarios. We apply a DRL policy with a tailored neural network architecture as a solution to control, path planning, and higher-level guidance tasks. Our network architecture was trained using a unique multi-stage curriculum that progresses from single-agent navigation, to multi-agent pathfinding with obstacles, and finally to a complex collaborative firefighting scenario. This structured approach accelerates training convergence by systematically building sophisticated collaborative behaviours upon foundational skills, which enhances training stability and guides the agents towards learning effective and coordinated strategies The policy evaluation was conducted in both simulation and hybrid simulation-physical demonstrations utilising a real unmanned ground vehicle (UGV). The policy presented is capable of achieving multi-agent navigation tasks with a 95.83% accuracy in our testing environments, and has demonstrated emergent multi-agent behaviours. In more complex collaborative firefighting scenarios, the policy also demonstrated superior performance than baselines in reaching goals, e.g., navigating and extinguishing two fires with a 99.67% success rate, suggesting its strong potential for real-world deployment. Timothy Mead, Zhe Wang 0001, Ernest Foo, Jin Song Dong 0001, Naipeng Dong, Ryan Kok Leong Ko, Abigail M. Y. Koay, Kien Nguyen Thanh, Yue Xu 0001, Junae Kim, Stephen Bornstein |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | SEED: A Minimal‑Footprint TEE Framework for Verifiable, Confidential Microservice DeploymentabstractWe present SEED, a system that enables the deployment of distributed privacy-preserving micro-services in the cloud while maintaining the secrecy of user code and data and ensuring correct, complete results. Unlike prior approaches that minimize the TCB by pushing large parts of the software stack outside the enclave, SEED includes the entire container software stack—from the application layer up to the operating system—inside the TCB. This holistic design protects proprietary software, datasets, and optional ML models from exposure; prevents leakage of sensitive inputs or queries; and thwarts metadata-inference attacks that could reveal workload identity or versioning. Yet we achieve an optimized TCB (22 MB in total), over 30× smaller than the typical 690 MB TCB for confidential privacy-enhancing VMs. In practice, SEED runs on AMD SEV-SNP–capable machines and supports real container workloads (i.e., TensorFlow, OpenVINO inference, PyTorch training, Redis, NGINX, Apache httpd). We demonstrate that SEEDCore matches or outperforms mainstream runtime workload deployment, staying within 5% of native throughput and reaching up to 6× higher performance on CPU-bound jobs. Finally, we conduct a thorough privacy and security evaluation against 11 cloud attack vectors and show that SEED blocks or confines every exploit that remains possible even under the state-of-the-art Gramine-TDX model, thanks to late binding, per-container PCR chains, and continuous in-TEE attestation throughout the workload’s lifetime. Omar Jarkas, Ryan Kok Leong Ko, Naipeng Dong, Md. Redowan Mahmud |
Proc. Priv. Enhancing Technol. | 3 |
| 2026 | Benchmarking Deepfake Attacks on Deep Face Recognition SystemsabstractModern deep face recognition systems are crucial for identity verification and authentication in high-stakes sectors such as security, finance, and law enforcement. However, their reliability is increasingly threatened by the rapid advancement of deepfake technology. Despite considerable attention, comprehensive evaluation of how emerging deepfake generation methods affect reliability of face recognition systems remains lacking. In this paper, we introduce a principled taxonomy and a benchmarking framework that structure deepfake attacks by intent and generative mechanism, enabling consistent and comprehensive assessment. Numerous results show that diverse deepfake attacks commonly exceed 70% success and, in some regimes, surpass 90%. Built on this foundation, we investigate the underlying mechanisms across different deepfake techniques, providing not only broad empirical evaluation but also valuable insight into what drives attack success. Our in-depth analysis reveals that success is not governed by visual quality, but rather by the degree of identity controllability. Shu Peng, Naipeng Dong, Wanying Dai, Guangdong Bai |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | A Large-Scale Analysis of Privacy Labels in Child-Accessible Mobile Applications
Fengqi Yu, Fuman Xie, Naipeng Dong, Guangdong Bai |
ADMA (2) | 3 |
| 2025 | Model Checking Nondeterministic Behaviours in the Tendermint Byzantine Fault Tolerant Blockchain Consensus Protocol
Yisong Yu, Naipeng Dong, Jin Song Dong 0001 |
ICECCS | 3 |
| 2025 | EP-Detector: Automatic Detection of Error-Prone Operation Anomalies in Android ApplicationsabstractAndroid applications are pervasively adopted and heavily relied on in our daily life, leading to the growing demand for enhanced user experiences, such as ease for operation and robustness. Nevertheless, developers continue to prioritize traditional functionality and performance, overlooking the pivotal role of user experience in real-world scenarios. For example, poorly designed page elements can lead to user confusion, resulting in unexpected outcomes, termed as the error-prone operation anomalies (EPAs). In this work, we undertake the first effort to uncover the underlying essence of the EPA problem. To achieve this objective, we investigated the root causes of EPAs from three dimensions, i.e., subject, object and environment. These causes were identified by multi-stage attribute capturing and precise similarity computation. In this process, the causes are categorized into fine-grained classes, namely confusing behaviours, unsuitable layout, and resource overload. Building upon these insights, we propose a dynamic GUI-based testing tool EP-Detector to facilitate detecting the EPAs in real-world apps. The EP-Detector is equipped with widget-exploration based target navigation and automatic test oracle, enabling it to detect error-prone page elements and simulate events with both comprehensiveness and precision. To systematically study the prevalence and severity of real-world EPAs, we conducted experiments on 53 popular Android apps with EP-Detector. The confirmed results not only validate the high precision and completeness of EP-Detector but also highlight that EPAs are prevalent in current apps, with at least one EPA existing in every two page widgets on average, and 28.3% of them may lead to security and functionality issues or risks. The EP-Detector is available at https://github.com/WordDealer/EP-Detector. Chenkai Guo, Qianlu Wang, Naipeng Dong, Lingling Fan 0003, Tianhong Wang 0010, Enbao Chen, Zheli Liu |
ICSE | 3 |
| 2025 | Harnessing LLMs for Document-Guided Fuzzing of OpenCV LibraryabstractThe combination of computer vision and artificial intelligence is fundamentally transforming a broad spectrum of industries by enabling machines to interpret and act upon visual data with high levels of accuracy. As the biggest and by far the most popular open-source computer vision library, OpenCV library provides an extensive suite of programming functions supporting real-time computer vision. Bugs in the OpenCV library can affect the downstream computer vision applications, and it is critical to ensure the reliability of the OpenCV library. This paper introduces VistaFuzz, a novel technique for harnessing large language models (LLMs) for document-guided fuzzing of the OpenCV library. Vistafuzz utilizes LLMs to parse API documentation and obtain standardized API information. Based on this standardized information, Vista Fuzz extracts constraints on individual input parameters and dependencies between these. Using these constraints and dependencies, VistaFuzz then generates new input values to systematically test each target API. We evaluate the effectiveness of Vistafuzz in testing 330 APIs in the OpenCV library, and the results show that Vistafuzz detected 17 new bugs, where 10 bugs have been confirmed, and 5 of these have been fixed. Bin Duan 0004, Tarek Mahmud, Meiru Che, Yan Yan 0002, Naipeng Dong, Dong Seong Kim 0001, Guowei Yang 0001 |
ICSME | 5 |
| 2025 | XAMT: Cross-Framework API Matching for Testing Deep Learning LibrariesabstractDeep learning powers critical applications such as autonomous driving, healthcare, and finance, where the correctness of underlying libraries is essential. Bugs in widely used deep learning APIs can propagate to downstream systems, causing serious consequences. While existing fuzzing techniques detect bugs through intra-framework testing across hardware backends (CPU vs. GPU), they may miss bugs that manifest identically across backends and thus escape detection under these strategies. To address this problem, we propose XAMT, a cross-framework fuzzing method that tests deep learning libraries by matching and comparing functionally equivalent APIs across different frameworks. XAMT matches APIs using similarity-based rules based on names, descriptions, and parameter structures. It then aligns inputs and applies variance-guided differential testing to detect bugs. We evaluated XAMT on five popular frameworks, including PyTorch, TensorFlow, Keras, Chainer, and JAX. XAMT matched 839 APIs and identified 238 matched API groups, and detected 17 bugs, 12 of which have been confirmed. Our results show that XAMT uncovers bugs undetectable by intraframework testing, especially those that manifest consistently across backends. XAMT offers a complementary approach to existing methods and offers a new perspective on the testing of deep learning libraries. Bin Duan 0004, Ruican Dong, Naipeng Dong, Dong Seong Kim 0001, Guowei Yang 0001 |
ISSRE | 3 |
| 2025 | Don't Mess with Bro's Cheese! An Empirical Study of Resource Conflict in Android Multi-windowabstractThe multi-window mode in Android has greatly improved productivity and usability by allowing multiple apps to run concurrently. However, alongside the advantages, such mode also introduces unforeseen risks in both functionality and security. In this work, we present the first systematic study to identify a previously unexplored class of issues, termed Multi-window Resource Conflicts (MRCs). Such conflicts occur when multiple app windows access the same system resource concurrently, potentially leading to crashes, functionality failures or unintended behaviors. To enhance the robustness and security of Android multi-window execution, we conduct a systematic and in-depth empirical study on the MRCs. We begin with a comprehensive root cause analysis, categorizing MRCs into three fundamental types based on their triggering patterns and affected resource states. To enable large-scale detection, we develop MRC-Detector, a static analysis framework that automatically identifies MRC issues in Android apps. Our manual verification confirms its high accuracy and effectiveness. We apply the MRC-Detector to the detection of over 150k real-world apps from F-droid and Google Play, uncovering the prevalence of MRC risks. Additionally, the distribution of MRC issues is analyzed in depth across multiple dimensions, including MRC type, APK size, app source and security classification. We further investigated the recognition and confirmation from developers and received 14 positive responses from vendors and project maintainers. Finally, comprehensive mitigation strategies are discussed. The materials of the study are available at: https://github.com/Huimilia/MRC. Chenkai Guo, Tianhong Wang 0010, Naipeng Dong, Qingqing Dong, Jiarui Che, Yaqiong Qiao, Xiangyang Luo 0001, Zheli Liu |
ASE | 4 |
| 2025 | FracFace: Breaking the Visual Clues - Fractal-Based Privacy-Preserving Face RecognitionabstractFace recognition is essential for identity authentication, but the rich visual clues in facial images pose significant privacy risks, highlighting the critical importance of privacy-preserving solutions. For instance, numerous studies have shown that generative models are capable of effectively performing reconstruction attacks that result in the restoration of original visual clues. To mitigate this threat, we introduce FracFace, a fractal-based privacy-preserving face recognition framework. This approach effectively weakens the visual clues that can be exploited by reconstruction attacks by disrupting the spatial structure in frequency domain features, while retaining the vital visual clues required for identity recognition. To achieve this, we craft a Frequency Channels Refining module that reduces sparsity in the frequency domain. It suppresses visual clues that could be exploited by reconstruction attacks, while preserving features indispensable for recognition, thus making these attacks more challenging. More significantly, we design a Frequency Fractal Mapping module that obfuscates deep representations by remapping refined frequency channels into a fractal-based privacy structure. By leveraging the self-similarity of fractals, this module preserves identity relevant features while enhancing defense capabilities, thereby improving the overall robustness of the protection scheme. Experiments conducted on multiple public face recognition benchmarks demonstrate that the proposed FracFace significantly reduces the visual recoverability of facial features, while maintaining high recognition accuracy, as well as the superiorities over state-of-the-art privacy protection approaches. Wanying Dai, Beibei Li 0002, Naipeng Dong, Guangdong Bai, Jin Song Dong 0001 |
NeurIPS | 3 |
| 2025 | Fratricide! Hijacking in Android Multi-WindowabstractAndroid's multi-window solutions allow several apps to coexist on one screen, providing powerful functionalities and appealing visuals for modern mobile devices. However, this opens the door for potential malware hijacking attacks. In our study, we unveiled Android's insufficient security measures against malware activity in multi-window modes, and identified strategies on how to bypass these measures. We first introduced long-term monitoring methods through background services or malicious sub-window activities, and then designed and implemented 7 multi-window hijacking strategies to achieve multi-window hijacking in the three mainstream multi-window modes. To evaluate the effectiveness and impact of the attacks, we ran the hijacking in different system versions supporting multi-window solutions, and simulated the hijacking on 262 popular apps. All of the apps suffer from at least two types of multi-window hijacking attacks, and more than 65% of them can be attacked by all the 7 multi-window hijacking attacks. Furthermore, we designed and distributed a questionnaire to gather user opinions towards these attacks. 85% of respondents believe that the multi-window hijacking is highly covert and difficult to defend against. Of significance, we received acknowledgement and award fund from development teams of impactful apps. Chenkai Guo, Tianhong Wang 0010, Qianlu Wang, Naipeng Dong, Xiangyang Luo 0001, Zheli Liu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Formal Verification Techniques for Post-quantum Cryptography: A Systematic Review
Yuexi Xu, Zhenyuan Li, Naipeng Dong, Veronika Kuchta, Dongxi Liu |
ICECCS | 3 |
| 2024 | Model Checking Concurrency in Smart Contracts with a Case Study of Safe Remote Purchase
Yisong Yu, Naipeng Dong, Jin Song Dong 0001 |
ICFEM | 2 |
| 2024 | PQS-BC: Comparative Analysis of NIST Post-quantum Signatures for Blockchain
Wan Kai Wong, Naipeng Dong, Cong Minh Dinh |
NSS | 2 |
| 2023 | Quantitative Explainable AI For Face RecognitionabstractFace recognition is widely adopted in our daily life in recent years. It usually relies on sophisticated techniques to achieve high accuracy in identifying or verifying the identities of given face images. Artificial intelligence (AI), especially deep learning, is a popular technique used in face recognition due to its high accuracy, known as the deep face recognition. However, the reliability of the deep face recognition models becomes a concern, especially in security-critical applications. The main challenge is the "black-box" nature of the sophisticated internal structure of the models. Explainable AI has emerged as a solution that provides meaningful explanations to help humans understand the complicated internal structure of the deep learning models, and increase the transparency and interpretability of the "black box". However, this is often at the cost of model accuracy. In this paper, we propose an approach to increasing both the accuracy and interpretation of quantitatively explainable AI models for face recognition. It increases the accuracy of the explainable face recognition models by applying improved loss functions and enhances quantitative interpretability by adding a new visualisation feature. The proposed approach is validated using advanced deep face recognition models and is compared with existing approaches to demonstrate its better performance. Shu Peng, Naipeng Dong, Guangdong Bai |
ICECCS | 2 |
| 2023 | Adversarial Detection from Derived ModelsabstractDeep Neural Networks (DNNs) can be easily fooled by inputs that are crafted by adversaries. For example, an adversarial image can be forged by adding to an image a tiny perturbation which is often unnoticeable by human eyes, though the semantic interpretations of the original image and the adversarial image, which are represented as outputs of a DNN, may be drastically different. This weakness can potentially lead to serious consequences in security-critical applications such as medical diagnostic tests and self-driving vehicles. Most existing approaches for adversarial detection only have satisfactory performance for specific types of attacks. These methods do not generalize their performances when applied to a broad range of attacks, models or datasets. In this work, we propose a new adversarial detection method called Adversarial Detection from Derived Models (ADDM), which applies derived models to “simulate” the functionality of a DNN, and analyzes the distribution for the neuron activation values in the derived models as indicators for adversarial inputs. In order to further enhance performance, we propose a heuristic that selects neurons from the derived models that are sensitive to perturbations. We compare our approach with six existing adversarial detection approaches of different methodologies, and the experimental result confirms that the proposed approach has generally better performance regarding stability over different types of adversarial attacks on a variety of tested DNN models and datasets. Fangzhen Zhao, Chenyi Zhang 0001, Naipeng Dong |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2023 | QoS-Aware Diversified Service SelectionabstractIn QoS-aware service selection, merely considering the prediction accuracy of QoS is prone to redundant results, which hinders practical service composition and also undermines user's preference for rich service attributes. To address the problem, a novel diversity-aware graph-based QoS prediction model—DSSN (Diversified Service Selection Network) is proposed in this work. DSSN alleviates selection redundancy through enhancing the selection diversity besides QoS prediction accuracy. To improve the model performance, techniques like high-order message propagation and multi-task structure are integrated into the graph based neural network model. And to enhance the service diversity, a service distance based attention mechanism is designed to embed the users in the model, so that users are connected to services with diverse attributes. We evaluate DSSN on a public dataset via extensive comparison experiments with both diversity-aware and non-diversified service selection models. In the comparison experiments, the DSSN: 1) clearly outperforms the state-of-the-art diversity-aware models in both accuracy and diversity; 2) achieves concrete diversity improvement at the cost of an acceptable decrease in the QoS prediction compared to non-diversified baselines. The results demonstrate that DSSN is more suitable for diversity-aware service selection with ambiguous user requirements than traditional QoS-centric selection scenarios. Chenkai Guo, Naipeng Dong, Zheli Liu, Yang Xiang 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | DALT: Deep Activity Launching Test via Intent-Constraint ExtractionabstractThe frequent usage of the activity and intent in Android app development makes activity launching communication the focus of app analysis, which inspires the proposal of Activity Launching Test (ALT). Existing static analysis approaches are limited in test case generation and crash triggering of ALT, due to their path-insensitive nature and insufficient intent attribute exploration. This work proposes DALT, an activity test frame-work for launching-related bug detection, which empowers an inter-procedural, context-, flow- and path-sensitive static analysis to generate proper intents as test cases. By tailoring symbolic execution for intent propagation, DALT is able to explore statements in deep code position and extract conditional constraints in diverse launching-related execution paths. Consequently, invalid test paths are substantially reduced via the guidance of the extracted constraints. DALT also supports significantly more intent attribute types and value types of attributes, by reformatting them to be compatible with the commonly used constraint solvers. Extensive comparison experiments have been conducted from diverse validation dimensions. The results demonstrate that compared to the state-of-the-art approach, DALT is more effective in successfully launching activities and detecting bugs hiding in deep positions of the program paths. Ao Liu 0007, Chenkai Guo, Naipeng Dong, Yinjie Wang, Jing Xu 0008 |
ISSRE | 3 |
| 2022 | A Uniform Framework for Anomaly Detection in Deep Neural Networks
Fangzhen Zhao, Chenyi Zhang 0001, Naipeng Dong, Zefeng You |
Neural Process. Lett. | 3 |
| 2021 | Callback2Vec: Callback-aware hierarchical embedding for mobile application
Chenkai Guo, Dengrong Huang, Naipeng Dong, Jing Xu 0008 |
Inf. Sci. | 3 |
| 2020 | An Analytics Framework for Heuristic Inference Attacks against Industrial Control SystemsabstractIndustrial control systems (ICS) of critical infrastructure are increasingly connected to the Internet for remote site management at scale. However, cyber attacks against ICS - especially at the communication channels between human-machine interface (HMIs) and programmable logic controllers (PLCs) - are increasing at a rate which outstrips the rate of mitigation. In this paper, we introduce a vendor-agnostic analytics framework which allows security researchers to analyse attacks against ICS systems, even if the researchers have zero control automation domain knowledge or are faced with a myriad of heterogenous ICS systems. Unlike existing works that require expertise in domain knowledge and specialised tool usage, our analytics framework does not require prior knowledge about ICS communication protocols, PLCs, and expertise of any network penetration testing tool. Using `digital twin' scenarios comprising industry-representative HMIs, PLCs and firewalls in our test lab, our framework's steps were demonstrated to successfully implement a stealthy deception attack based on false data injection attacks (FDIA). Furthermore, our framework also demonstrated the relative ease of attack dataset collection, and the ability to leverage well-known penetration testing tools. We also introduce the concept of `heuristic inference attacks', a new family of attack types on ICS which is agnostic to PLC and HMI brands/models commonly deployed in ICS. Our experiments were also validated on a separate ICS dataset collected from a cyber-physical scenario of water utilities. Finally, we utilized time complexity theory to estimate the difficulty for the attacker to conduct the proposed packet analyses, and recommended countermeasures based on our findings. Taejun Choi, Guangdong Bai, Ryan Kok Leong Ko, Naipeng Dong, Wenlu Zhang, Shunyao Wang |
TrustCom | 4 |
| 2020 | Early prediction for mode anomaly in generative adversarial network training: An empirical study
Chenkai Guo, Dengrong Huang, Jing Xu 0008, Guangdong Bai, Naipeng Dong |
Inf. Sci. | 6 |
| 2019 | AutoPer: Automatic Recommender for Runtime-Permission in Android ApplicationsabstractPermission mechanisms serve as the main measure to protect users privacy and security in Android applications. Modern smartphone operating systems (Android 6.0 and later versions) prompt users to regulate permissions using ask-on-first-use policy. Much research has been done to dynamically regulate permissions depending on user preferences and contexts in modern operation systems. However, all these techniques have limitations-they heavily rely on users' current or historical decisions on granting permissions, ignoring the fact that users are not experts on privacy protection, i.e., whether a permission shall be granted. In this work, we propose a system to automatically recommend runtime-permission to users. The main idea behind is that the application descriptions reflecting functional information can be used to analyze whether a permission is needed by the application. In more details, using description mining, we extract multiple topics and build a topic-permission mapper. Given an application as input, we first decide which topics it belongs to and then recommend the permissions according to the topic-permission mapper. As the output, besides binary recommendation of "allow" or "deny" recommendations, we provide explanations for the recommendations to uncover the reason for users. We implemented our approach in a tool- AutoPer, and evaluated the approach using 28,850 Android applications from Google Play. The experiments show that our approach achieves a fairly good performance with an accuracy of 81.0%, which demonstrates the effectiveness of AutoPer for permission recommendation. Hongcan Gao, Chenkai Guo, Naipeng Dong, Xiaolei Hou, Sihan Xu, Jing Xu 0008 |
COMPSAC (1) | 4 |
| 2019 | Deep Attentive Factorization Machine for App Recommendation ServiceabstractRecommendation service in mobile app markets decently helps users choose their preferred apps. Though a lot of recommendation service models are proposed in recent years, it is still challenging to tackle extreme sparse app data and get a relatively satisfactory recommendation performance. The reason can be concluded as that traditional recommendation models either focus on limited features or stand aside from deep training. In this paper, we propose knowledge-based deep factorization machine (KDFM), a recommendation model inspired by techniques of factorization machine and attentive deep learning, and apply it in the recommendation service for mobile apps. The KDFM aims to make full use of the rich categorical and textual knowledge in the app market for better performance. To achieve this goal, a topical attention representation component, which contains three typical parts (Word2Vec, BiLSTM and Topical Attention), is constructed. Such representation not only avoids the dimension explosion brought by traditional models, but also preserves the textual semantics for better recommendation. Through extensive experiments conducted on a large number of collected app samples, the KDFM achieves better performance compared with state-of-art rating recommendation models in terms of the rating prediction. In addition, the benefits brought by the usage of attention mechanism and topical representation are confirmed through the comparison experiments. Chenkai Guo, Xiaolei Hou, Naipeng Dong, Jing Xu 0008, Quanqi Ye |
ICWS | 4 |
| 2019 | LightSense: A Novel Side Channel for Zero-permission Mobile User Tracking
Quanqi Ye, Guangdong Bai, Naipeng Dong, Zhenkai Liang, Jin Song Dong 0001, Haoyu Wang 0001 |
ISC | 4 |
| 2019 | Deep Review SharingabstractReview-Based Software Improvement (RBSI for short) has drawn increasing research attentions in recent years. Relevant efforts focus on how to leverage the underlying information within reviews to obtain a better guidance for further updating. However, few efforts consider the Projects Without sufficient Reviews (PWR for short). Actually, PWR dominates the software projects, and the lack of PWR-based RBSI research severely blocks the improvement of certain software. In this paper, we make the first attempt to pave the road. Our goal is to establish a generic framework for sharing suitable and informative reviews to arbitrary PWR. To achieve this goal, we exploit techniques of code clone detection and review ranking. In order to improve the sharing precision, we introduce Convolutional Neural Network (CNN) into our clone detection, and design a novel CNN based clone searching module for our sharing system. Meanwhile, we adopt a heuristic filtering strategy to reduce the sharing time cost. We implement a prototype review sharing system RSharer and collect 72,440 code-review pairs as our ground knowledge. Empirical experiments on hundreds of real code fragments verify the effectiveness of RSharer. RSharer also achieves positive response and evaluation by expert developers. Chenkai Guo, Dengrong Huang, Naipeng Dong, Quanqi Ye, Jing Xu 0008, Yaqing Fan |
SANER | 3 |
| 2019 | Systematic Comprehension for Developer Reply in Mobile System ForumabstractReview-based software development has become increasingly prevalent in recent years. Existing efforts aiming at either informative evaluation or sentiment analysis are mainly from the perspective of the reviewers, while neglecting the attitude and behavior of the developers. Such efforts inevitably suffer from recommendation bias in practice, and thus benefit little for the improvement of user reviews.In this paper, we attempt to bridge the gap between user review and developer reply, and conduct a systematic study for review reply in development forums, especially in Chinese mobile system forums. To this end, we concentrate on three research questions: 1) should a targeted review be replied; 2) how long time it should be replied; 3) does traditional review analysis help to pursue a reply for certain review? To answer such questions, given certain review datasets, we perform a systematical study including the following three stages: 1) a binary classification for reply behavior prediction, 2) a regression for prediction of reply time, 3) a systematic factor study for the relationship between traditional review analysis and reply performance. To enhance the accuracy of prediction and analysis, we proposed a CNN-based weak-supervision analysis framework, which exploits manifold techniques from NLP and deep learning. We validate our approach via extensive comparison experiments. The results show that our analysis framework is effective. More importantly, we have uncovered several interesting findings, which provide valuable guidance for further review improvement and recommendation. Chenkai Guo, Weijing Wang, Naipeng Dong, Quanqi Ye, Jing Xu 0008 |
SANER | 4 |
| 2018 | A Projection-Based Approach for Memory Leak DetectionabstractOne of the major software safety issues is memory leak. Moreover, detecting memory leak vulnerabilities is challenging in static analysis. Existing static detection tools find bugs by collecting programs' information in the process of scanning source code. However, the current detection tools are weak in efficiency and accuracy, especially when the targeted program contains complex branches. This paper proposes a projection-based approach to detect memory leaks in C source code with complex control flows. According to the features of memory allocation and deallocation in C source code, this approach projects the original control flow graph of a program to a simpler one, and it reduces the analysis complexity. Besides, this paper implements a memory-leak detection tool-PML_Checker, and evaluates the tool by comparing with three open-source static detection tools on both public benchmarks and study test cases. The experimental results show that PML_Checker reports the most memory leak vulnerabilities among the four existing tools with complex control flows and complex data types, and PML_Checker obtains higher efficiency and accuracy on public benchmarks. Sihan Xu, Chenkai Guo, Jing Xu 0008, Naipeng Dong, Xiujuan Ji |
COMPSAC (2) | 5 |
| 2018 | Formal Analysis of a Proof-of-Stake BlockchainabstractBlockchain technology relies on consensus algorithms to resolve conflicts in Byzantine environments. New blockchain algorithms are rapidly designed and implemented without a properly conducted formal analysis and verification. In this paper, we conducted a study on Tendermint which is a proof-of-stake consensus algorithm. We verified that the consensus protocol is deadlock-free and is able to reach consensus when at least 2/3 of the network is in agreement. We also proved that a minority set of nodes that compose more than 1/3 of the network is enough to censor the majority of the network and prevent the network from reaching consensus and conclude that the algorithm has some shortcomings on availability. Wai Yan Maung Maung Thin, Naipeng Dong, Guangdong Bai, Jin Song Dong 0001 |
ICECCS | 2 |
| 2018 | The Foul Adversary: Formal Models
Naipeng Dong, Tim Muller |
ICFEM | 1 |
| 2018 | Verification of Strong Nash-equilibrium for Probabilistic BAR Systems
Dileepa Fernando, Naipeng Dong, Cyrille Jégourel, Jin Song Dong 0001 |
ICFEM | 2 |
| 2017 | A Verification Framework for Stateful Security Protocols
Li Li 0044, Naipeng Dong, Jun Pang 0001, Jun Sun 0001, Guangdong Bai, Yang Liu 0003, Jin Song Dong 0001 |
ICFEM | 2 |
| 2017 | A Framework for Formal Analysis of Privacy on SSO Protocols
Kailong Wang 0001, Guangdong Bai, Naipeng Dong, Jin Song Dong 0001 |
SecureComm | 3 |
| 2017 | Inferring Implicit Assumptions and Correct Usage of Mobile Payment Protocols
Quanqi Ye, Guangdong Bai, Naipeng Dong, Jin Song Dong 0001 |
SecureComm | 3 |
| 2017 | Formal modelling and analysis of receipt-free auction protocols in applied pi
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
Comput. Secur. | 1 |
| 2016 | Verification of Nash-Equilibrium for Probabilistic BAR SystemsabstractA BAR system specifies a cooperation between agents who can be altruistic when they follow the specified behaviours, Byzantine when they randomly deviate from specifications and rational when they deviate to increase their own benefits. We consider whether a rational agent indeed follows the specification of a probabilistic BAR system as verifying whether the system is a Nash-equilibrium in the corresponding stochastic games. In this article, we propose an intuitive specification for probabilistic BAR systems and an algorithm to automatically verify Nash-equilibrium. To validate our implementation of the algorithm, we present two case studies – the three-player Rock-paper-scissors game and a probabilistic secret sharing protocol. Dileepa Fernando, Naipeng Dong, Cyrille Jégourel, Jin Song Dong 0001 |
ICECCS | 2 |
| 2016 | Automatic Construction of Callback Model for Android ApplicationabstractThe heavy use of event-callback mechanism in frameworks like Android causes challenges for static analysis. Modelling of callback mechanisms for Android applications (app for short) is becoming a major method to address such challenges. In this work, we aim to construct a generic callback-related model that supports path-sensitive analysis. We consider three unresolved challenges in the existing modelling approaches: 1) building connections between different components; 2) identifying path-sensitive conditions; 3) handling the system-driven callbacks and fine-grained lifecycle callbacks. We propose algorithms for constructing a generic path-sensitive callback model and present a prototype model constructor, AndroChecker, to validate our approach. We evaluate 20 real-world apps using AndroChecker. The evaluation result shows that our method and tool have a strong capability in modelling path conditions and inter-component invocations. Chenkai Guo, Quanqi Ye, Naipeng Dong, Guangdong Bai, Jin Song Dong 0001, Jing Xu 0008 |
ICECCS | 3 |
| 2013 | Enforcing Privacy in the Presence of Others: Notions, Formalisations and Relations
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
ESORICS | 1 |
| 2012 | Formal Analysis of Privacy in an eHealth Protocol
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
ESORICS | 1 |