VLDB 2026 Research / reviewers in the wild / expert
Changxiang Shen
dblp:02/5636
· DBLP profile ↗
12ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0007-7840-0337ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 1 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorSystems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An efficient and commercial proof of storage scheme supporting dynamic data updates
Zhenwu Xu, Xingshu Chen, Liangguo Chen, Xiao Lan, Hao Ren 0001, Changxiang Shen |
Comput. Secur. | 6 |
| 2025 | Efficient privacy-preserving federated logistic regression with poor-quality users
Xingshu Chen, Hao Ren 0001, Changxiang Shen |
Peer Peer Netw. Appl. | 5 |
| 2025 | Gupacker: Generalized Unpacking Framework for Android MalwareabstractAndroid malware authors often use packers to evade analysis. Although many unpacking tools have been proposed, they face two significant challenges: 1) They are easily impeded by anti-analysis techniques employed by packers, preventing efficient collection of hidden Dex data. 2) They are typically designed to unpack a specific packer and cannot handle malware packed with mixed packers. Consequently, many packed malware samples evade detection. To bridge this gap, we propose Gupacker, a novel generalized unpacking framework. Gupacker offers a generic solution for first-generation holistic packer by customizing the Android system source code. It identifies the type of packer and selects an appropriate unpacking function, constructs a deeper active call chain to achieve generic unpacking of second-generation function extraction packers, and usesJNIfunction and instruction monitoring to handle third-generation virtual obfuscation packer. On this basis, we counteract a diverse array of anti-analysis techniques. We conduct extensive experiments on 5K packed Android malware samples, comparing Gupacker with 2 commercial and 4 state-of-the-art academic unpacking tools. The results demonstrate that Gupacker significantly improves the efficiency of Android malware unpacking with acceptable system overhead. We analyze real packed applications based on Gupacker and found several are second-packed by attackers, including WPS for Android, with tens of millions of users. We receive and responsibly report 13 0day vulnerabilities and also assist in the remediation of all vulnerabilities. Qiyu Hou, Xingshu Chen, Hao Ren 0001, Meng Li 0006, Hongwei Li 0001, Changxiang Shen |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Empowering Data Owners: An Efficient and Verifiable Scheme for Secure Data Deletion
Zhenwu Xu, Xingshu Chen, Xiao Lan, Rui Tang 0020, Shuyu Jiang, Changxiang Shen |
Comput. Secur. | 6 |
| 2024 | RESTLess: Enhancing State-of-the-Art REST API Fuzzing With LLMs in Cloud Service ComputingabstractREST API Fuzzing is an emerging approach for automated vulnerability detection in cloud services. However, existing SOTA fuzzers face challenges in generating lengthy sequences comprising high-semantic requests, so that they may hardly trigger hard-to-reach states within a cloud service. To overcome this problem, we propose RESTLess, a flexible and efficient approach with hybrid optimization strategies for REST API fuzzing enhancement. Specifically, to pass the cloud gateway syntax semantic checking, we construct a dataset of valid parameters of REST API with Large Language Model named RTSet, then utilize it to develop an efficient REST API specification semantic enhancement approach. To detect vulnerability hidden under complex API operations, we design a flexible parameter rendering order optimization algorithm to increase the length and type of request sequences. Evaluation results highlight that RESTLess manifests noteworthy enhancements in the semantic quality of generated sequences in comparison to existing tools, thereby augmenting their capabilities in detecting vulnerabilities effectively. We also apply RESTLess to nine real-world cloud service such as Microsoft Azure, Amazon Web Services, Google Cloud, etc., and detecte 38 vulnerabilities, of which 16 have been confirmed and fixed by the relevant vendors. Jinqiao Dai, Shuyu Jiang, Xingshu Chen, Changxiang Shen |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | A dual-system trusted computing node construction method based on ARM multi-core CPU architectureabstractSummary Computer node security is the source and foundation of information system security. Trusted computing dual system architecture is an important implementation method to solve the security assurance by establishing the dual system of computing nodes, on the one hand, to achieve isolation on the other hand to achieve the active metrics of the system. This article systematically analyzes the dual architecture of trusted computing, summarizes the security assurance implementation of the dual architecture of trusted computing as the problem of trusted platform control module (TPCM) trusted root parallel access bus, and designs and implements it using ARM multi‐core CPU architecture, and designs the basic hardware security assurance capabilities such as TPCM resource isolation, active metrics, secure communication and other key components of trusted cryptography module and trusted software base based on it, thus implementing the two core mechanisms of trustworthy computing, namely, trust chain construction and dynamic metrics, are implemented. The design of system integration in computing node devices based on this ARM multi‐core CPU architecture is proposed, and the related design and implementation methods are proposed, and finally, the prototype implementation and test verification are performed on the Phytium CPU platform. Yu Hong 0003, Changxiang Shen |
Concurr. Comput. Pract. Exp. | 4 |
| 2011 | Edge Self-Monitoring for Wireless Sensor NetworksabstractLocal monitoring is an effective mechanism for the security of wireless sensor networks (WSNs). Existing schemes assume the existence of sufficient number of active nodes to carry out monitoring operations. Such an assumption, however, is often difficult for a large-scale sensor network. In this work, we focus on designing an efficient scheme integrated with good self-monitoring capability as well as providing an infrastructure for various security protocols using local monitoring. To the best of our knowledge, we are the first to present the formal study on optimizing network topology for edge self-monitoring in WSNs. We show that the problem is NP-complete even under the unit disk graph (UDG) model and give the upper bound on the approximation ratio in various graph models. We provide polynomial-time approximation scheme (PTAS) algorithms for the problem in some specific graphs, for example, the monitoring-set-bounded graph. We further design two distributed polynomial algorithms with provable approximation ratio. Through comprehensive simulations, we evaluate the effectiveness of our design. Dezun Dong, Xiangke Liao, Yunhao Liu 0001, Changxiang Shen, Xinbing Wang |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2010 | Research on trusted computing and its development
Changxiang Shen, Huanguo Zhang, Bo Zhao 0023, Fei Yan 0008, Fajiang Yu, Mingdi Xu |
Sci. China Inf. Sci. | 1 |
| 2007 | Design of secure operating systems with high security levels
Sihan Qing, Changxiang Shen |
Sci. China Ser. F Inf. Sci. | 2 |
| 2007 | Survey of information security
Changxiang Shen, Huanguo Zhang, Dengguo Feng, Zhenfu Cao, Jiwu Huang |
Sci. China Ser. F Inf. Sci. | 1 |
| 2006 | Trust Extended Dynamic Security Model and Its Application in Network
Changxiang Shen |
MSN | 5 |
| 2006 | A Trust-Based Routing Framework in Energy-Constrained Wireless Sensor Networks
Wei-Fang Cheng, Xiangke Liao, Changxiang Shen, Shanshan Li 0001, Shaoliang Peng |
WASA | 3 |