VLDB 2026 Research / reviewers in the wild / expert
Wei Zhang 0122
dblp:10/4661-122
· DBLP profile ↗
14ranked-venue papers
0as first author
7since 2021 · last 2026
0000-0002-1658-0236ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 since 2021Computer networks · 4 · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Differential Privacy Space Decomposition Algorithm Based on Hierarchical ModelabstractChoosing an appropriate division method is crucial for partitioning two-dimensional spatial data under the constraints of differential privacy. The current mainstream partitioning methods include grid-based partitioning and hierarchical partitioning. In order to optimize query accuracy while satisfying differential privacy conditions, it remains challenge to achieve the sum minimization of noise error and uniformity assumption error. To address this issue, we propose the HOLG (Hierarchical Optimization of Logical Grids) algorithm, employing a ”divide-merge-divide” approach. It begins with fine-grained grid partitioning of the data domain, followed by heuristic merging of grids with similar data distributions. After determining the scale of the query domain, the merged regions are further subdivided into smaller regions with similar query probabilities, constructing a hierarchical structure to reduce uniformity assumption errors. Additionally, we design a novel noise injection method and introduce consistency constraints to further minimize noise errors. To reduce the time complexity of the HOLG partitioning method, Huffman trees is employed to optimize the processing of the hierarchical tree set generated by HOLG, ensuring query utility while effectively reducing the query response time for the partitioning algorithm. Experimental results on large-scale spatial datasets demonstrate that HOLG outperforms similar algorithms in query accuracy. Furthermore, when combined with the Huffman tree optimization, it effectively reduces query response time. Haiping Huang, Chaorun Sun, Zhenqi Shi, Wei Zhang 0122, Jiyun Cang, Fu Xiao 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Exposed by Default: A Security Analysis of Home Router Default Settings and BeyondabstractWith the popularity of the Internet, home routers have become crucial for the security of home networks. However, according to the results of our user survey, home routers are often deployed with minimal changes to the factory default settings, which may pose risks to user security and privacy. To systematically evaluate potential risks, we designed a threat-model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers from 14 brands. We found a variety of security issues, among which incorrect implementation of TLS is the most common. To improve the efficiency of manually detecting TLS certificate validation vulnerabilities without real routers, we proposed a heuristic method that can narrow down the search scope in firmware and proved its effectiveness with 30 available firmware images of the routers we purchased. Moreover, we evaluated the security of custom remote management protocols and found several cryptographic misuses. Finally, we proposed several recommendations for extending the analysis framework and discussed our ideas about automatically detecting security issues to highlight the need for heightened scrutiny of default settings and inspire other researchers. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
IEEE Internet Things J. | 6 |
| 2025 | Integrated codec decomposed Transformer for long-term series forecasting
Benhan Li, Wei Zhang 0122, Mingxin Lu |
Neural Networks | 2 |
| 2024 | Exposed by Default: A Security Analysis of Home Router Default SettingsabstractWith ubiquitous Internet connectivity, home routers have become a cornerstone of our digital lives, often deployed with minimal changes to the factory default settings. However, if left unexamined, these settings can pose risks to user security and privacy. To systematically evaluate potential risks, we developed a threat model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers, representative of recent models across 14 brands. We surveyed 81 parameters and behaviors including default and deep default settings. We identified a variety of security flaws including the exposure of IPv6 local devices due to a lack of firewall protection, vulnerable Wi-Fi security protocols, open Wi-Fi networks and trivial admin passwords for "plug-and-play" routers, and unencrypted firmware update communications. We also discovered concealed WPS PIN support --- at times associated with a trivial PIN. In total, we are reporting 30 exploitable vulnerabilities to the vendors. This paper highlights the need for heightened scrutiny of default router settings, providing valuable insights to both manufacturers and consumers for enhancing home network security. Our findings underscore the importance of meticulous device configuration, advocating for proactive measures from all stakeholders to mitigate the threats posed by insecure router default settings. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
AsiaCCS | 6 |
| 2024 | Shaped Quota: More Efficient and More Versatile Congestion ControlabstractCongestion control is one of the fundamental techniques for ensuring the stability and reliability of high-performance network applications. During the research on congestion control strategies for existing high-speed RDMA networks, it was observed that the current strategies are primarily applied in structured and stable data center networks, which are difficult to generalize to network environments with slightly poorer performance and packet loss. In this paper, we implement and analyze a receiver-driven end-to-end congestion control scheme called Shaped Quota for complex networks. Shaped Quota achieves rate control by actively evaluating the network congestion status of each flow at the receiver and providing feedback to the corresponding sender. Building upon this research, this paper further refines the design of the Shaped Quota and implements the algorithm for the first time in a simulated environment, followed by comprehensive testing. The experiments demonstrate that in lossless networks, Shaped Quota can provide superior transmission efficiency compared to existing congestion control schemes. Under lossy network conditions, Shaped Quota improves the reliability and stability of network transmission. Compared to DCQCN, Timely, and HPCC, Shaped Quota achieves an average reduction of 45.26% in Flow Completion Time (FCT) in lossless networks. In lossy networks, the flow completion rate of Shaped Quota is significantly higher, reaching 29.33 times and 29.24 times that of DCQCN and Timely, respectively. Compared to HPCC, which exhibits better queue length control, Shaped Quota reduces the queue length by more than 40%. Zhefan Fan, Wei Zhang 0122, Yunfang Chen, Wanting Tian, Chao Tu, Yunqu Liu |
WCNC | 2 |
| 2022 | An empirical study of blockchain system vulnerabilities: modules, types, and patternsabstractBlockchain, as a distributed ledger technology, becomes increasingly popular, especially for enabling valuable cryptocurrencies and smart contracts. However, the blockchain software systems inevitably have many bugs. Although bugs in smart contracts have been extensively investigated, security bugs of the underlying blockchain systems are much less explored. In this paper, we conduct an empirical study on blockchain’s system vulnerabilities from four representative blockchains, Bitcoin, Ethereum, Monero, and Stellar. Specifically, we first design a systematic filtering process to effectively identify 1,037 vulnerabilities and their 2,317 patches from 34,245 issues/PRs (pull requests) and 85,164 commits on GitHub. We thus build the first blockchain vulnerability dataset, which is available at https://github.com/VPRLab/BlkVulnDataset. We then perform unique analyses of this dataset at three levels, including (i) file-level vulnerable module categorization by identifying and correlating module paths across projects, (ii) text-level vulnerability type clustering by natural language processing and similarity-based sentence clustering, and (iii) code-level vulnerability pattern analysis by generating and clustering code change signatures that capture both syntactic and semantic information of patch code fragments. Xiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang, Kehuan Zhang, Wei Zhang 0122 |
ESEC/SIGSOFT FSE | 6 |
| 2022 | Secure, Efficient, and Weighted Access Control for Cloud-Assisted Industrial IoTabstractIn the cloud-assisted Industrial Internet of Things (IIoT), ciphertext-policy attribute-based encryption (CP-ABE) could help the data owner (DO) share his sensitive data via the cloud under self-defined access structures. Among general CP-ABE schemes, the decryption overhead, the key generation cost, and the ciphertext length increase with the number of involved attributes. Additionally, only regular attributes are taking into consideration rather than weighted attributes. In this article, we proposed a secure, efficient, and weighted access control scheme (SEWAC) for cloud-assisted IIoT applications. SEWAC enables the DO to formulate any fine-grained access structure over weighted attributes without making it more complicated. Furthermore, such weighted attributes would not add the length of ciphertext. SEWAC also supports online/offline key generation to alleviate the computational cost of the authority from answering mass key requests in the online phase, while most computational tasks are executed in the offline phase. The heavy decryption overhead is offloaded to the cloud. To ensure the cloud to honestly execute the process of outsourced decryption, we design an efficient batch verification method, which allows the user to spend only three bilinear pairing operations in checking the correctness of batch results. We also give the formal security proof of the proposed scheme. Comprehensive comparisons and implementation results indicate that SEWAC can better achieve weighted access control, compressed ciphertext length, efficient key generation, and the assurance of the outsourced decryption result. Qi Li 0011, Haiping Huang, Wei Zhang 0122, Wei Chen 0006, Huaqun Wang |
IEEE Internet Things J. | 4 |
| 2020 | UI Obfuscation and Its Effects on Automated UI Analysis for Android AppsabstractThe UI driven nature of Android apps has motivated the development of automated UI analysis for various purposes, such as app analysis, malicious app detection, and app testing. Although existing automated UI analysis methods have demonstrated their capability in dissecting apps' UI, little is known about their effectiveness in the face of app protection techniques, which have been adopted by more and more apps. In this paper, we take a first step to systematically investigate UI obfuscation for Android apps and its effects on automated UI analysis. In particular, we point out the weaknesses in existing automated UI analysis methods and design 9 UI obfuscation approaches. We implement these approaches in a new tool named UIObfuscator after tackling several technical challenges. Moreover, we feed 3 kinds of tools that rely on automated UI analysis with the apps protected by UIObfuscator, and find that their performances severely drop. This work reveals limitations of automated UI analysis and sheds light on app protection techniques. Hao Zhou 0043, Ting Chen 0002, Haoyu Wang 0001, Le Yu 0002, Xiapu Luo, Ting Wang 0006, Wei Zhang 0122 |
ASE | 7 |
| 2020 | Community Detection Based on DeepWalk Model in Large-Scale NetworksabstractThe large-scale and complex structure of real networks brings enormous challenges to traditional community detection methods. In order to detect community structure in large-scale networks more accurately and efficiently, we propose a community detection algorithm based on the network embedding representation method. Firstly, in order to solve the scarce problem of network data, this paper uses the DeepWalk model to embed a high-dimensional network into low-dimensional space with topology information. Then, low-dimensional data are processed, with each node treated as a sample and each dimension of the node as a feature. Finally, samples are fed into a Gaussian mixture model (GMM), and in order to automatically learn the number of communities, variational inference is introduced into GMM. Experimental results on the DBLP dataset show that the model method of this paper can more effectively discover the communities in large-scale networks. By further analyzing the excavated community structure, the organizational characteristics within the community are better revealed. Yunfang Chen, Li Wang 0073, Dehao Qi, Tinghuai Ma, Wei Zhang 0122 |
Secur. Commun. Networks | 5 |
| 2019 | Detection of Trojaning Attack on Neural Networks via Cost of Sample ClassificationabstractTo overcome huge resource consumption of neural networks training, MLaaS (Machine Learning as a Service) has become an irresistible trend, just like SaaS (Software as a Service), PaaS (Platform as a Service), and IaaS (Infrastructure as a Service) have been. But it comes with some security issues of untrustworthy third-party services. Especially machine learning providers may deploy trojan backdoors in provided models for the pursuit of extra profit or other illegal purposes. Against the redundant nodes-based trojaning attack on neural networks, we proposed a novel detecting method, which only requires the untrusted model to be tested and a small batch of legitimate dataset. By comparing different processes of neural networks training, we found that the embedding of malicious nodes will make their parameter configuration abnormal. Moreover, by analysing the cost distribution of test dataset on network nodes, we successfully detect the trojaned nodes in the neural networks. As far as we know, the research on the defence against trojaning attack on neural networks is still in its infancy, and our research may shed light on the security of MLaaS in real-life scenarios. Yunfang Chen, Wei Zhang 0122 |
Secur. Commun. Networks | 3 |
| 2018 | Enhanced Keystroke Recognition Based on Moving Distance of Keystrokes Through WiFi
Yunfang Chen, Yihong Zhu, Hao Zhou 0043, Wei Chen 0006, Wei Zhang 0122 |
NSS | 5 |
| 2018 | Differentially Private High-Dimensional Data Publication via Markov Network
Fengqiong Wei, Wei Zhang 0122, Yunfang Chen |
SecureComm (1) | 2 |
| 2016 | Differentially Private Network Data Release via Stochastic Kronecker Graph
Dai Li, Wei Zhang 0122, Yunfang Chen |
WISE (2) | 2 |
| 2015 | Time-series prediction based on global fuzzy measure in social networksabstractSocial network analysis (SNA) is among the hottest topics of current research. Most measurements of SNA methods are certainty oriented, while in reality, the uncertainties in relationships are widely spread to be overridden. In this paper, fuzzy concept is introduced to model the uncertainty, and a similarity metric is used to build a fuzzy relation model among individuals in the social network. The traditional social network is transformed into a fuzzy network by replacing the traditional relations with fuzzy relation and calculating the global fuzzy measure such as network density and centralization. Finally, the trend of fuzzy network evolution is analyzed and predicted with a fuzzy Markov chain. Experimental results demonstrate that the fuzzy network has more superiority than the traditional network in describing the network evolution process. Wei Zhang 0122, Yunfang Chen |
Frontiers Inf. Technol. Electron. Eng. | 2 |