5 papers
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
Ronghao Ni, Mihai Christodorescu, Limin Jia
The rapidly evolving Nodejs ecosystem currently includes millions of packages and is a critical part of modern software supply chains, making vulnerability detection of Nodej…
On the Difficulty of Selecting Few-Shot Examples for Effective LLM-based Vulnerability Detection
Md Abdul Hannan, Ronghao Ni, Chi Zhang +3
Large language models (LLMs) have demonstrated impressive capabilities across a wide range of coding tasks, including summarization, translation, completion, and code generation. D…
Learning to Triage Vulnerability Reports from Program Analysis: An Empirical Study in Node.js
Ronghao Ni, Aidan Z. H. Yang, Min-Chien Hsu +5
Program analysis tools often produce large volumes of candidate vulnerability reports that require costly manual review, creating a practical challenge: how can security analysts p…
CFT-Forensics: High-Performance Byzantine Accountability for Crash Fault Tolerant Protocols
Weizhao Tang, Peiyao Sheng, Ronghao Ni +4
Crash fault tolerant (CFT) consensus algorithms are commonly used in scenarios where system components are trusted -- e.g., enterprise settings and government infrastructure. Howev…
Mixture-of-Linear-Experts for Long-term Time Series Forecasting
Ronghao Ni, Zinan Lin, Shuaiqi Wang +1
Long-term time series forecasting (LTSF) aims to predict future values of a time series given the past values. The current state-of-the-art (SOTA) on this problem is attained in so…