Python package security is largely source-centric, yet Python runtimes can execute bytecode directly through .pyc files, compiled-only modules, and marshalled code objects, creating an inspection-execution gap. We present an empirical study of Python bytecode as a security artifact. We measure bytecode exposure in PyPI...
Extended Berkeley Packet Filter (eBPF) is a security-critical in-kernel execution framework, yet its vulnerability landscape remains fragmented across components, semantic gaps, and testing techniques. We present an empirical study of observed eBPF vulnerabilities. We construct a multi-source dataset from Linux kernel...
Bai-Hong Chen, Ming Hua, Wei-Feng Pan et al.· 0 citations
The results show that explicit dependency, event, and property semantics expose consequential runtime failures across API boundaries and execution modes at release scale.
Static analysis of Python packages must recover both program structure and object flow across first-class functions, dynamic dispatch, implicit protocol calls, exceptions, closures, and module execution. Native CPython bytecode provides the executable lowering of these behaviors, but its instruction, call, stack, and e...
A study of import-related bugs and security vulnerabilities in Python software, which combines security advisories with PyPI project histories and uses source and patch evidence to confirm how import activates cases, why the problem occurs, how developers fix it, and what program information is needed to explain the be...
A structural abstraction is proposed that uses a static call graph as a shared backbone and projects driver-specific dynamic coverage onto it to derive driver-induced subgraphs and shows that multi-driver fuzzing is fundamentally a structural exploration problem.
Bai-Hong Chen, Ming Hua, Wei-Feng Pan et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.