ASE 2025
Sun 16 - Thu 20 November 2025 Seoul, South Korea

This program is tentative and subject to change.

Wed 19 Nov 2025 16:30 - 16:40 at Grand Hall 5 - Security 7

Despite great progress in fuzzing browser APIs, systematic approaches for testing web storage techniques remain absent. IndexedDB, the most popular NoSql database in modern browsers, brings unique challenges for fuzzing its API due to its asynchronous event-driven feature and strict phase separation. Current browser fuzzing techniques frequently struggle to generate nested event flows and invocations, which significantly impacts semantic correctness. Moreover, they often rely heavily on try-catch block to suppress exceptions, which introduces substantial performance overhead. We propose IDBFuzz, the first fuzzing approach tailored for the IndexedDB API, which effectively tackles the challenge of capturing the execution context and event semantics inherent to IndexedDB, as well as handling large persistent objects. We design a seed generator based on intermediate representation (IR) that decouples layered IR skeletons from input object generation. With the aid of a global database snapshot, IDBFuzz can generate semantically controllable seeds, enabling the efficient production of high-quality test cases that significantly improve coverage.

This program is tentative and subject to change.

Wed 19 Nov

Displayed time zone: Seoul change

16:00 - 17:00
16:00
10m
Talk
RAML: Toward Retrieval-Augmented Localization of Malicious Payloads in Android Apps
NIER Track
Tiezhu Sun University of Luxembourg, Marco Alecci University of Luxembourg, Yewei Song University of Luxembourg, Xunzhu Tang University of Luxembourg, Kisub Kim DGIST, Jordan Samhi University of Luxembourg, Luxembourg, Tegawendé F. Bissyandé University of Luxembourg, Jacques Klein University of Luxembourg
16:10
10m
Talk
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
Industry Showcase
16:20
10m
Talk
JSidentify-V2: Dynamic Memory Fingerprinting for Mini-Game Plagiarism Detection
Industry Showcase
Zhihao Li Tencent Inc., Chaozheng Wang The Chinese University of Hong Kong, Li Zongjie Hong Kong University of Science and Technology, Xinyong Peng Tencent Inc., Qun Xia Tencent Inc., Haochuan Lu Tencent, Ting Xiong Tencent Inc., Shuzheng Gao Chinese University of Hong Kong, Cuiyun Gao Harbin Institute of Technology, Shenzhen, Shuai Wang Hong Kong University of Science and Technology, Yuetang Deng Tencent, Huafeng Ma Tencent Inc.
16:30
10m
Talk
IDBFuzz: Web Storage DataBase Fuzzing with Controllable Semantics
NIER Track
Jingyi Chen Jiangsu University, Jinfu Chen Jiangsu University, Saihua Cai Jiangsu University, Shengran Wang Jiangsu University
16:40
10m
Talk
SCOPE: Evaluating and Enhancing Permission Explanation Transparency in Mobile Apps
Industry Showcase
Liu Wang Beijing University of Posts and Telecommunications, Tianshu Zhou Beijing University of Posts and Telecommunications, Haoyu Wang Huazhong University of Science and Technology, Xiyuan Liu Freshippo-Alibaba Group, Yi Wang
16:50
10m
Talk
ApkArmor: Low-Cost Lightweight Anti-Decompilation Techniques for Android Apps
Industry Showcase
Jiayang Liu Huazhong University of Science and Technology, Yanjie Zhao Huazhong University of Science and Technology, Pengcheng Xia Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology