most citedTowards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments

13 citations · 25 across the 7 of their papers we have counts for

collaborators

7 papers

cs.SE2025

LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?

Bin Liu, Yanjie Zhao, Guoai Xu +1

Large language model (LLM) agents have demonstrated remarkable capabilities in software engineering and cybersecurity tasks, including code generation, vulnerability discovery, and…

cs.SE2025

CommitShield: Tracking Vulnerability Introduction and Fix in Version Control Systems

Zhaonan Wu, Yanjie Zhao, Chen Wei +3

Version control systems are commonly used to manage open-source software, in which each commit may introduce new vulnerabilities or fix existing ones. Researchers have developed va…

cs.CR2024

PathSeeker: Exploring LLM Security Vulnerabilities with a Reinforcement Learning-Based Jailbreak Approach

Zhihao Lin, Wei Ma, Mingyi Zhou +5

In recent years, Large Language Models (LLMs) have gained widespread use, raising concerns about their security. Traditional jailbreak attacks, which often rely on the model intern…

cs.SE20242 cited

Bridging Design and Development with Automated Declarative UI Code Generation

Ting Zhou, Yanjie Zhao, Xinyi Hou +3

Declarative UI frameworks have gained widespread adoption in mobile app development, offering benefits such as improved code readability and easier maintenance. Despite these advan…

cs.CR20249 cited

Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs

Jian Zhao, Shenao Wang, Yanjie Zhao +6

The proliferation of pre-trained models (PTMs) and datasets has led to the emergence of centralized model hubs like Hugging Face, which facilitate collaborative development and reu…

cs.CR202413 cited

Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments

Xinyi Zheng, Chen Wei, Shenao Wang +5

The exponential growth of open-source package ecosystems, particularly NPM and PyPI, has led to an alarming increase in software supply chain poisoning attacks. Existing static ana…