Internetware 2026
Sat 18 - Mon 20 July 2026 Gold Coast, Australia
Sat 18 Jul 2026 11:40 - 11:55 at Ballroom - Session 1: Software Vulnerabilities and Security I Chair(s): Yi Song

Developers frequently utilize third-party libraries to improve productivity, which also introduces potential security risks. To enhance program security, existing approaches generate tests for public functions to trigger library vulnerabilities from client programs, yet they depend on proof-of-concepts (PoCs), which are often unavailable. In this paper, we propose a new approach, LiveFuzz, based on directed greybox fuzzing (DGF) to trigger library vulnerabilities from client programs without PoCs, thereby detecting their exploitability from the clients. LiveFuzz exploits a target tuple to extend existing DGF techniques to cross-program scenarios. Based on the target tuple, LiveFuzz introduces a novel Abstract Path Mapping mechanism to project execution paths, mitigating the preference for shorter paths. LiveFuzz also proposes a risk-based adaptive mutation to mitigate excessive mutation. To evaluate LiveFuzz, we construct a new dataset including 61 cases of library vulnerabilities exploited from client programs. Results show that LiveFuzz increases the number of target-reachable paths compared with all baselines and improves the average speed of vulnerability exposure. Three vulnerabilities are triggered exclusively by LiveFuzz.

Sat 18 Jul

Displayed time zone: Brisbane change

11:40 - 12:40
Session 1: Software Vulnerabilities and Security IResearch Track at Ballroom
Chair(s): Yi Song School of Computer Science, Wuhan University
11:40
15m
Talk
LiveFuzz: Detecting Exploitable Library Vulnerabilities from Client Programs via Directed Greybox Fuzzing
Research Track
Yukai Zhao , Menghan Wu Zhejiang University, Xing Hu Zhejiang University, Shaohua Wang Central University of Finance and Economics, Meng Luo The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Xin Xia Zhejiang University
11:55
15m
Talk
ATTAIN: Automated Exploit Failure Analysis through Trace-Driven Diff Analysis
Research Track
Xinwei Mao Zhejiang University, Zirui Chen Zhejiang University, Xing Hu Zhejiang University, Xin Xia Zhejiang University
Pre-print
12:10
15m
Talk
VulnForge: Building Enhanced OSS Vulnerability Datasets via Uncertainty-based Patch Analysis
Research Track
Li Lu Huazhong University of Science and Technology, Xinyu She Huazhong University of Science and Technology, Shengming Zhao Fudan University, Ningke Li National University of Singapore, Yanjie Zhao Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology
12:25
15m
Talk
RelocSC: Compiler-Driven Generation of Self-Relocating Linux Shellcode
Research Track
Ruimin Wang Information Engineering University, Jintao Bao Information Engineering University, Jian Lin Information Engineering University, Guoan Liu Information Engineering University, Shuai Ren Information Engineering University