5 citations · 6 across the 5 of their papers we have counts for
5 papers
ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy
Yiheng Huang, Zhijia Zhao, Bihuan Chen +6
Open source software is vulnerable to supply-chain attacks through transitive dependencies, especially malicious code injected into NPM packages. Existing detectors often inadequat…
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
Yiheng Huang, Zhijia Zhao, Bihuan Chen +5
The model context protocol (MCP) standardizes how LLMs connect to external tools and data sources, enabling faster integration but introducing new attack vectors. Despite the growi…
VulWeaver: Weaving Broken Semantics for Grounded Vulnerability Detection
Yiheng Cao, Yihao Chen, Xin Hu +9
Detecting vulnerabilities in source code remains critical yet challenging, as conventional static analysis tools construct inaccurate program representations, while existing LLM-ba…
Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain
Kaifeng Huang, Bihuan Chen, You Lu +7
Large language models (LLMs) have sparked significant impact with regard to both intelligence and productivity. Numerous enterprises have integrated LLMs into their applications to…
Detecting and Fixing Violations of Modification Terms in Open Source Licenses during Forking
Kaifeng Huang, Yingfeng Xia, Bihuan Chen +3
Open source software brings benefit to software community, but also introduces legal risks caused by license violations, which result in serious consequences such as lawsuits and f…