Skip to menu Skip to content Skip to footer

2026

Journal Article

VulRTex: A Reasoning-Guided Approach to Identify Vulnerabilities from Rich-Text Issue Report

Jiang, Ziyou, Li, Mingyang, Yang, Guowei, Shi, Lin, Wang, Junjie and Wang, Qing (2026). VulRTex: A Reasoning-Guided Approach to Identify Vulnerabilities from Rich-Text Issue Report. ACM Transactions on Software Engineering and Methodology 3801149. doi: 10.1145/3801149

VulRTex: A Reasoning-Guided Approach to Identify Vulnerabilities from Rich-Text Issue Report

2026

Journal Article

Automated update of Android deprecated API usages with large language models

Mahmud, Tarek, Duan, Bin, Che, Meiru, Yasmin, Awatif, Ngu, Anne H.H. and Yang, Guowei (2026). Automated update of Android deprecated API usages with large language models. IEEE Transactions on Software Engineering, 52 (1), 70-85. doi: 10.1109/TSE.2025.3627897

Automated update of Android deprecated API usages with large language models

2026

Journal Article

FENSE: Feedback-Driven Incremental Symbolic Execution for Redundant Path Elimination

Du, Pengbo, Yi, Qiuping, Liang, Hongliang and Yang, Guowei (2026). FENSE: Feedback-Driven Incremental Symbolic Execution for Redundant Path Elimination. IEEE Transactions on Software Engineering, PP (99), 1-17. doi: 10.1109/TSE.2026.3667998

FENSE: Feedback-Driven Incremental Symbolic Execution for Redundant Path Elimination

2025

Conference Publication

XAMT: cross-framework API matching for testing deep learning libraries

Duan, Bin, Dong, Ruican, Dong, Naipeng, Kim, Dan Dongseong and Yang, Guowei (2025). XAMT: cross-framework API matching for testing deep learning libraries. 2025 IEEE 36th International Symposium on Software Reliability Engineering (ISSRE), São Paulo, Brazil, 21-24 October 2025. Piscataway, NJ United States: Institute of Electrical and Electronics Engineers. doi: 10.1109/issre66568.2025.00030

XAMT: cross-framework API matching for testing deep learning libraries

2025

Journal Article

Why android app testing falls short: empirical insights from open-source projects and a practitioner survey

Mahmud, Tarek, Che, Meiru, Ngu, Anne and Yang, Guowei (2025). Why android app testing falls short: empirical insights from open-source projects and a practitioner survey. Empirical Software Engineering, 30 (6) 163, 1-32. doi: 10.1007/s10664-025-10726-x

Why android app testing falls short: empirical insights from open-source projects and a practitioner survey

2025

Conference Publication

Harnessing LLMs for document-guided fuzzing of OpenCV library

Duan, Bin, Mahmud, Tarek, Che, Meiru, Yan, Yan, Dong, Naipeng, Kim, Dan Dongseong and Yang, Guowei (2025). Harnessing LLMs for document-guided fuzzing of OpenCV library. 2025 IEEE International Conference on Software Maintenance and Evolution (ICSME), Auckland, New Zealand, 7-12 September 2025. Piscataway, NJ, United States: IEEE. doi: 10.1109/icsme64153.2025.00017

Harnessing LLMs for document-guided fuzzing of OpenCV library

2025

Conference Publication

Testing Android Third Party Libraries with LLMs to Detect Incompatible APIs

Mahmud, Tarek, Duan, Bin, Che, Meiru, Ngu, Anne and Yang, Guowei (2025). Testing Android Third Party Libraries with LLMs to Detect Incompatible APIs. 2nd International Conference on AI Foundation Models and Software Engineering-FORGE, Ottawa, Canada, 27-28 April 2025. Los Alamitos, CA, United States: IEEE. doi: 10.1109/forge66646.2025.00039

Testing Android Third Party Libraries with LLMs to Detect Incompatible APIs

2025

Conference Publication

Mimicking the familiar: dynamic command generation for information theft attacks in LLM tool-learning system

Jiang, Ziyou, Li, Mingyang, Yang, Guowei, Wang, Junjie, Huang, Yuekai, Chang, Zhiyuan and Wang, Qing (2025). Mimicking the familiar: dynamic command generation for information theft attacks in LLM tool-learning system. 63rd Association for Computational Linguistics Meeting-ACL-Annual, Vienna, Austria, 27 July-1 August 2025. Stroudsburg, PA, United States: Association for Computational Linguistics. doi: 10.18653/v1/2025.acl-long.672

Mimicking the familiar: dynamic command generation for information theft attacks in LLM tool-learning system

2024

Journal Article

An empirical study on compatibility issues in Android API field evolution

Mahmud, Tarek, Che, Meiru and Yang, Guowei (2024). An empirical study on compatibility issues in Android API field evolution. Information and Software Technology, 175 107530. doi: 10.1016/j.infsof.2024.107530

An empirical study on compatibility issues in Android API field evolution

2024

Conference Publication

An empirical investigation on android app testing practices

Mahmud, Tarek, Che, Meiru, Ngu, Anne H. H. and Yang, Guowei (2024). An empirical investigation on android app testing practices. 2024 IEEE 35th International Symposium on Software Reliability Engineering (ISSRE), Tsukuba, Japan, 28-31 October 2024. Piscataway, NJ, United States: Institute of Electrical and Electronics Engineers. doi: 10.1109/issre62328.2024.00042

An empirical investigation on android app testing practices

2024

Conference Publication

PatUntrack: automated generating patch examples for issue reports without tracked insecure code

Jiang, Ziyou, Shi, Lin, Yang, Guowei and Wang, Qing (2024). PatUntrack: automated generating patch examples for issue reports without tracked insecure code. 39th ACM/IEEE International Conference on Automated Software Engineering (ASE), Sacramento, CA, United States, 28 October-1 November 2024. New York, United States: Association for Computing Machinery. doi: 10.1145/3691620.3694982

PatUntrack: automated generating patch examples for issue reports without tracked insecure code

2024

Conference Publication

MTD in plain sight: hiding network behavior in moving target defenses

Moghaddam, Tina, Yang, Guowei, Thapa, Chandra, Camtepe, Seyit and Kim, Dan Dongseong (2024). MTD in plain sight: hiding network behavior in moving target defenses. 2024 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, Brisbane, QLD, Australia, 24-27 June 2024. Piscataway, NJ, United States: IEEE. doi: 10.1109/dsn-s60304.2024.00022

MTD in plain sight: hiding network behavior in moving target defenses

2024

Journal Article

Compatible branch coverage driven symbolic execution for efficient bug finding

Yi, Qiuping, Yu, Yifan and Yang, Guowei (2024). Compatible branch coverage driven symbolic execution for efficient bug finding. Proceedings of the ACM on Programming Languages, 8 (PLDI) 213, 1633-1655. doi: 10.1145/3656443

Compatible branch coverage driven symbolic execution for efficient bug finding

2024

Conference Publication

APICIA: An API Change Impact Analyzer for Android Apps

Mahmud, Tarek, Che, Meiru, Rouijel, Jihan, Khan, Mujahid and Yang, Guowei (2024). APICIA: An API Change Impact Analyzer for Android Apps. IEEE/ACM 46th International Conference on Software Engineering, Lisbon, Portugal, 14 - 20 April 2024. New York, NY United States: Association for Computing Machinery. doi: 10.1145/3639478.3640041

APICIA: An API Change Impact Analyzer for Android Apps

2024

Conference Publication

Concrete constraint guided symbolic execution

Sun, Yue, Yang, Guowei, Lv, Shichao, Li, Zhi and Sun, Limin (2024). Concrete constraint guided symbolic execution. ICSE '24: IEEE/ACM 46th International Conference on Software Engineering, Lisbon, Portugal, 14 - 20 April 2024. Washington, DC, United States: IEEE Computer Society. doi: 10.1145/3597503.3639078

Concrete constraint guided symbolic execution

2023

Conference Publication

SJFuzz: seed and mutator scheduling for JVM fuzzing

Wu, Mingyuan, Ouyang, Yicheng, Lu, Minghai, Chen, Junjie, Zhao, Yingquan, Cui, Heming, Yang, Guowei and Zhang, Yuqun (2023). SJFuzz: seed and mutator scheduling for JVM fuzzing. 31st ACM Joint Meeting of the European Software Engineering Conference / Symposium on the Foundations-of-Software-Engineering (ESEC/FSE), San Francisco, CA USA, 3-9 December 2023. New York, NY USA: Association for Computing Machinery. doi: 10.1145/3611643.3616277

SJFuzz: seed and mutator scheduling for JVM fuzzing

2023

Conference Publication

SCPatcher: mining crowd security discussions to enrich secure coding practices

Jiang, Ziyou, Shi, Lin, Yang, Guowei and Wang, Qing (2023). SCPatcher: mining crowd security discussions to enrich secure coding practices. 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), Echternach, Luxembourg, 11-15 September 2023. Los Alamitos, CA USA: Institute of Electrical and Electronics Engineers. doi: 10.1109/ase56229.2023.00040

SCPatcher: mining crowd security discussions to enrich secure coding practices

2023

Conference Publication

POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking

Moghaddam, Tina, Yang, Guowei, Thapa, Chandra, Camtepe, Seyit and Kim, Dan Dongseong (2023). POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking. 18th ACM ASIA Conference on Computer and Communications Security (ASIA CCS), Melbourne, VIC, Australia, 10-14 July 2023. New York, NY, United States: ACM. doi: 10.1145/3579856.3592825

POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking

2023

Journal Article

Detecting android API compatibility issues with API differences

Mahmud, Tarek, Che, Meiru and Yang, Guowei (2023). Detecting android API compatibility issues with API differences. IEEE Transactions on Software Engineering, 49 (7), 3857-3871. doi: 10.1109/tse.2023.3274153

Detecting android API compatibility issues with API differences

2023

Journal Article

Analyzing the impact of API changes on Android apps

Mahmud, Tarek, Che, Meiru and Yang, Guowei (2023). Analyzing the impact of API changes on Android apps. Journal of Systems and Software, 200 111664, 1-19. doi: 10.1016/j.jss.2023.111664

Analyzing the impact of API changes on Android apps