Wei Xie 0007

dblp:87/1010-7 · DBLP profile ↗
← Back
22ranked-venue papers
4as first author
19since 2021 · last 2026
0009-0005-1667-4995ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Computer networks · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 League of LLMs: A Benchmark-Free Paradigm for Mutual Evaluation of Large Language Models
abstract
Qianhong Guo, Wei Xie, Xiaofang Cai, Enze Wang, Shuoyoucheng Ma, Xiaobing Sun, Tian Xia, Kai Chen, Xiaofeng Wang, Baosheng Wang. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Qianhong Guo, Wei Xie 0007, Xiaofang Cai, Enze Wang, Shuoyoucheng Ma
ACL (1)2
2026 Multi-layer Representation Editing for Rejection Behavior Control in Large Language Models
Wei Xie 0007, Shuoyoucheng Ma, Hanying Tong
ICIC (11)2
2026 Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Enze Wang, Jianjun Chen 0005, Qi Wang 0094, Hai-Xin Duan, Wei Xie 0007
NDSS7
2026 Not All Paths Are Equal: Multi-path Optimization for Directed Hybrid Fuzzing
abstract
Directed Grey-Box Fuzzing (DGF) can improve bug exposure efficiency by stressing bug-prone areas. Recent studies have modeled DGF as the problem of finding and optimizing paths to reach target sites. However, they still face the “ multi-path ” challenge. When a target site is reachable by multiple paths, it is crucial to comprehensively evaluate and effectively select these paths, as this affects the fuzzer’s choice between reaching target sites via optimal paths and enhancing path diversity toward targets to expose hidden bugs in non-optimal paths. In this article, we propose MultiGo, a directed hybrid fuzzer designed for multi-path optimization. First, we propose a new fitness metric called path difficulty to comprehensively evaluate the promising paths. This metric uses the Poisson distribution to estimate the probability of exploring basic blocks along execution paths based on statistical block frequency, distinguishing between optimal and challenging paths. With path difficulty as a key factor, a customized Contextual Multi-Armed Bandit (CMAB) model is employed to efficiently optimize path scheduling by comprehensively considering the impact of testing conditions on path scheduling. We introduce the concept of the fuzzing context to represent and evaluate testing conditions, which encompass factors such as path characteristics (e.g., path difficulty), the testing agent (e.g., fuzzing or symbolic execution), and the testing goal (e.g., path exploitation or exploration). Then, the CMAB model predicts the expected rewards for scheduling paths under different testing agents and goals, thereby optimizing path scheduling. By leveraging the CMAB model, MultiGo enhances DGF’s capability to explore easier paths and symbolic execution’s capacity to handle more complex ones, enabling efficient target reaching through optimal paths while ensuring sufficient coverage of non-optimal paths. MultiGo is evaluated on 136 target sites of 41 real-world programs from 3 benchmarks. The experimental results show that MultiGo outperforms the state-of-the-art directed fuzzers (AFLGo, SelectFuzz, Beacon, WindRanger, and DAFL) and hybrid fuzzers (SymCC and SymGo) in reaching target sites and exposing known vulnerabilities. Moreover, MultiGo also discovered 14 undisclosed vulnerabilities.
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Kai Lu 0001
ACM Trans. Softw. Eng. Methodol.4
2025 AIPsychoBench: Understanding the Psychometric Differences between LLMs and Humans
Wei Xie 0007, Shuoyoucheng Ma, Enze Wang, Hanying Tong
CogSci1
2025 Do Large Language Models Truly Grasp Mathematics? An Empirical Exploration from Cognitive Psychology
Shuoyoucheng Ma, Wei Xie 0007, Enze Wang, Hanying Tong
CogSci2
2025 Self-Persuasion: A Novel Cognitive Approach to Effective LLM Jailbreaking
Wei Xie 0007, Shuoyoucheng Ma, Zhihua Wen, Enze Wang
CogSci2
2025 Learning from the Packet Sequences: Diffusion Model-Based Protocol Greybox Fuzzing
abstract
Network protocol fuzzing is crucial for ensuring the security and stability of protocols. Traditional specification-based methods face severe challenges to generate test cases in scenarios where protocols are complex and specifications are unavailable. Furthermore, the statefulness of protocol implementations requires input packets to satisfy sequential dependencies, further complicates fuzzing. To address these challenges, we developed SPIREFuzz, a novel fuzzer that automatically learns protocol formats and temporal relationships directly from real traffic. SPIREFuzz uses reverse engineering to build a session pattern dataset and employs a Discrete Denoising Diffusion Probabilistic Model (D3PM) to generate packet sequences. Leveraging the model's strengths in stable training and mitigating mode collapse, the method achieves an optimal balance between the accuracy and diversity of generated sequences, which is crucial for generating high-fidelity and state-compliant patterns and simultaneously ensures enhanced state space exploration. Experimental results indicate that on 10 protocols SPIREFuzz's key field identification capability is superior to NetPlier. In fuzzing targeting 8 protocol implementations, compared to AFLNet, NSFuzz, and GANFuzz, its average state coverage, average state transitions, average bitmap coverage, and average unique crashes achieved improvements of up to$\text{78.57 \%}, \text{73.91 \%}, \text{3.94 \%}$, and 216.67 % respectively.
Peihong Lin, Xu Zhou 0004, Wei Xie 0007
IPCCC5
2025 SimFuzz: Conflict-Aware Parallel Fuzzing via Incremental Path Similarity Clustering
abstract
Parallel fuzzing boosts throughput by distributing testcase generation across multiple fuzzing instances. However, this architecture often suffers from task conflict—redundant exploration of similar execution paths—due to the lack of path-level awareness in seed scheduling. These conflicts waste computation and limit overall effectiveness.We present SIMFUZZ, a conflict-aware scheduling framework that mitigates redundancy by integrating path similarity into the fuzzing workflow. SIMFUZZ encodes seeds as branch-level coverage bitmaps and incrementally clusters them based on execution path overlap. It then applies a two-stage scheduling policy that assigns similar seeds to the same instance, while preserving global prioritization for high-potential inputs.We evaluate SIMFUZZ on 19 real-world programs and benchmark targets. Compared to a state-of-the-art baseline, it achieves a 6.7% average increase in branch coverage and reduces task conflict by 3.9%. In several cases, it also discovers substantially more unique crashes. Additionally, SIMFUZZ has uncovered 15 previously unknown vulnerabilities in widely used software projects, all of which have been assigned CVE identifiers.
Xuan Meng, Danjun Liu, Xu Zhou 0004, Peihong Lin, Chenyifan Liu, Lei Zhou 0023, Wei Xie 0007
ISSRE7
2025 When Control Flows Deviate: Directed Grey-box Fuzzing with Probabilistic Reachability Analysis
abstract
Directed grey-box fuzzing (DGF) steers testing toward high-value targets, but developing effective DGF for commercial off-the-shelf (COTS) binaries is challenging due to the lack of accurate structural information (e.g., control-flow graphs and call graphs), which can cause control flows to deviate and misguide DGF’s reachability analysis. In this paper, we introduce BinGo, a tailored binary-level directed grey-box fuzzer, which can accommodate the flawed control-flow graphs (CFGs) of COTS binaries and enable accurate and efficient reachability analysis. First, to quantify the inevitable inaccuracies of uncovered indirect edges and analyze their impact on the reachability of basic blocks, we propose a Bayesian-based method. This method combines prior knowledge from static analysis with dynamic observations from fuzzing to estimate the confidence in correctly recovering indirect edges. Then, we present a new concept called a region, which redefines granularity for efficient reachability analysis by transforming the CFG into a region graph. Using the Bayesian results and region graph, we propose a custom fitness metric for binary-level DGF, termed probabilistic reachability. This metric, based on a dynamically updated region graph and reachability scores, is adaptive, lightweight, and accommodates inaccurate binary-level CFGs. We implemented a prototype tool, BinGo, and evaluated it on the CGC dataset, CVE-Benchmark, and UniBench benchmark. Experimental results show that BinGo surpasses baseline fuzzers (AFL++, AFLGo, PDGF, UAFuzz, and 1dVul) in reaching target locations and exposing known vulnerabilities. Additionally, BinGo discovered three new vulnerabilities in the real-world application cscope-15.9.
Peihong Lin, Xu Zhou 0004, Wei Xie 0007, Kai Lu 0001
ASE4
2025 Constructing arbitrary write via puppet objects and delivering gadgets in Linux kernel
Danjun Liu, Xuan Meng, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007
Comput. Secur.5
2024 DeepGo: Predictive Directed Greybox Fuzzing
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Kai Lu 0001
NDSS4
2024 Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications
abstract
Server-Side Request Forgery (SSRF) vulnerability poses significant security risks to web applications, enabling adversaries to exploit web applications as stepping stones for unauthorized access of internal-only services or even performing arbitrary commands. Despite its recent emergence as a distinct category in the 2021 OWASP Top 10 web security risks and its increasing prevalence in modern web applications, there remains a lack of effective approaches to detect SSRF vulnerabilities systematically.We present a novel methodology, SSRFuzz, to effectively identify SSRF vulnerability in PHP web applications. Our methodology consists of three phases. In the initial phase, we designed an SSRF oracle to examine functions in PHP manuals and identify sinks that provide server-side request capabilities. This process yielded a total of 86 sensitive PHP sinks out of 2101 PHP functions. The second stage involves dynamic taint inference and the utilization of the identified sinks to examine the source code of target web applications, pinpointing all feasible input points that could trigger these sinks. The final phase employs fuzzing techniques. We generate testing HTTP requests with SSRF payloads, send them to the previously identified input points within the target web applications, and detect if an SSRF vulnerability is triggered. We implemented a prototype of SSRFuzz and evaluated it on 27 real-world applications, including Joomla and WordPress. In total, we discovered 28 SSRF vulnerabilities, 25 of which were previously unreported. We reported all the vulnerabilities to the affected vendors, and 16 new CVE IDs were assigned.
Enze Wang, Jianjun Chen 0005, Wei Xie 0007, Chuhan Wang 0001, Hai-Xin Duan, Yang Liu 0003
SP3
2024 HyperGo: Probability-based directed hybrid fuzzing
Peihong Lin, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Kai Lu 0001, Gen Zhang
Comput. Secur.4
2023 VulHawk: Cross-architecture Vulnerability Detection with Entropy-based Binary Code Search
Zhenhao Luo, Pengfei Wang 0010, Yong Tang 0005, Wei Xie 0007, Xu Zhou 0004, Danjun Liu, Kai Lu 0001
NDSS5
2023 From Release to Rebirth: Exploiting Thanos Objects in Linux Kernel
abstract
Vulnerability fixing is time-consuming, hence, not all of the discovered vulnerabilities can be fixed timely. In reality, developers prioritize vulnerability fixing based on exploitability. Large numbers of vulnerabilities are delayed to patch or even ignored as they are regarded as “unexploitable” or underestimated owing to the difficulty in exploiting the weak primitives. However, exploits may have been in the wild. In this paper, to exploit the weak primitives that traditional approaches fail to exploit, we propose a versatile exploitation strategy that can transform weak exploit primitives into strong exploit primitives. Based on a special object in the kernel named Thanos object, our approach can exploit a UAF vulnerability that does not have function pointer dereference and an OOB write vulnerability that has limited write length and value. Our approach overcomes the shortage that traditional exploitation strategies heavily rely on the capability of the vulnerability. To facilitate using Thanos objects, we devise a tool namedTAODEto automatically search for eligible Thanos objects from the kernel. Then, it evaluates the usability of the identified Thanos objects by the complexity of the constraints. Finally, it pairs vulnerabilities with eligible Thanos objects. We have evaluated our approach with real-world kernels.TAODEsuccessfully identified numerous Thanos objects from Linux. Using the identified Thanos objects, we proved the feasibility of our approach with 20 real-world vulnerabilities, most of which traditional techniques failed to exploit. Through the experiments, we find that in addition to exploiting weak primitives, our approach can sometimes bypass the kernel SMAP mechanism (CVE-2016-10150, CVE-2016-0728), better utilize the leaked heap pointer address (CVE-2022-25636), and even theoretically break certain vulnerability patches (e.g., double-free).
Danjun Liu, Pengfei Wang 0010, Xu Zhou 0004, Wei Xie 0007, Gen Zhang, Zhenhao Luo, Tai Yue
IEEE Trans. Inf. Forensics Secur.4
2022 Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT Devices
abstract
Recent years have seen increased attacks targeting embedded web applications of IoT devices. An important target of such attacks is the hidden interface of embedded web applications, which employs no protection but exposes security-critical actions and sensitive information to illegitimate users. With the severity and the pervasiveness of this issue, it is crucial to identify the vulnerable hidden interfaces, shed light on best practices and raise public awareness.
Wei Xie 0007, Jiongyi Chen, Chao Feng 0002, Enze Wang, Kai Lu 0001
WWW1
2021 ARGUS: Assessing Unpatched Vulnerable Devices on the Internet via Efficient Firmware Recognition
abstract
Assessing unpatched devices affected by a specified vulnerability is a vital but unsolved issue. Using a proof-of-concept tool on the Internet is illegal, while identifying vulnerable device models and firmware versions via fingerprints is a safer method. However, device search engines such as Shodan do not claim to accurately identify device models or versions, and existing works on firmware online recognition neglect the efficiency challenge of scanning redundant fingerprints. Consequently, this fingerprint-checking method has few real-world verifications on the Internet.
Wei Xie 0007, Chao Zhang 0008, Pengfei Wang 0010
AsiaCCS1
2021 XHunter: Understanding XXE Vulnerability via Automatic Analysis
Wei Xie 0007, Yong Tang 0005, Enze Wang
SecureComm (2)2
2019 6Tree: Efficient dynamic discovery of active addresses in the IPv6 address space
Zhizhu Liu, Yinqiao Xiong, Wei Xie 0007, Peidong Zhu
Comput. Networks4
2018 Automated Vulnerability Detection in Embedded Devices
Danjun Liu, Yong Tang 0005, Wei Xie 0007, Bo Yu 0008
IFIP Int. Conf. Digital Forensics4
2017 Vulnerability Detection in IoT Firmware: A Survey
abstract
With the development of Internet of Things(IoT), more and more smart devices are connected into the Internet. The security and privacy issues of IoT devices have received increasingly academic and industrial attentions. Vulnerability detection is the key technology to protect IoT devices from zero-day attacks. However, traditional methods and tools of vulnerability detection cannot be directly used in analyzing IoT firmware. This paper firstly reviews related works on vulnerability detection in IoT firmware, previous researches are classified into four types i.e. static analysis, symbolic execution, fuzzing on emulators and comprehensive testing. Then, this paper points out that the specificity of vulnerability detection in IoT firmware is to detect logical flaws in embedded binaries which are built on the MIPS architecture. Finally, this paper proposes a method based on fuzzing and static analysis to detect authentication bypass flaws in IoT embedded binary servers. The proposed method is proved to be effective by verifying known CVEs as well as discovering unknown ones.
Wei Xie 0007, Yikun Jiang, Yong Tang 0005, Yuanming Gao
ICPADS1