Jiaping Gui

dblp:119/1083 · DBLP profile ↗
← Back
28ranked-venue papers
7as first author
16since 2021 · last 2026
0009-0001-4272-9604ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 3 first-author · 9 since 2021Artificial intelligence and machine learning · 6 · 5 since 2021Software engineering, systems software and programming languages · 5 · 1 first-authorDatabases, data management, data science and information retrieval · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 On the (In-)Security of the Shuffling Defense in the Transformer Secure Inference
abstract
Zhengyi Li, Yakai Wang, Jingwen Leng, Kang Yang, Yu Yu, Jiaping Gui, Yu Feng, Ning Liu, Minyi Guo. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Zhengyi Li 0002, Yakai Wang, Jingwen Leng, Kang Yang 0002, Yu Yu 0001, Jiaping Gui, Yu Feng 0007, Ning Liu 0007, Minyi Guo
ACL (1)6
2026 SnipleyFuzz: Enhancing Black-Box Fuzzing of IoT Devices with Shapley-Based Priority Selection
Futai Zou, Jiaping Gui
DSN3
2026 FluxZK: Scalable and Efficient Zero-Knowledge Proof Computation via GPU Acceleration
abstract
Zero-knowledge succinct non-interactive arguments of knowledge (zkSNARKs) are a key technology to privacy-preserving applications today. The complexity of proof generation, however, heavily constrains throughput in latency-sensitive environments. The computational burden primarily stems from two fundamental algorithms: Multi-Scalar Multiplication (MSM) and the Number Theoretic Transform (NTT). We propose a series of optimizations for these two kernels, including computation-transfer pipelining, load balancing, and memory access fusion, achieving 1.97 × to 2.16 × proof generation speedup over a state-of-the-art open source GPU acceleration library. Our design also supports out-of-core computation, enabling the generation of large-scale ZKP proofs.
Xinwei Qiang, Liukun Yu, Zhengyi Li 0002, Shixuan Sun, Jingwen Leng, Chen Chen 0067, Jiaping Gui, Zhenzhe Zheng 0001, Jin Dong 0004, Minyi Guo
HPDC8
2026 KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
Yuhan Meng, Shaofei Li, Jiaping Gui, Peng Jiang 0007, Ding Li 0001
NDSS3
2025 R+R: From Claims to Crashes: A Systematic Re-evaluation of Graph-Based Network Intrusion Detection Systems
abstract
Graph-based Network Intrusion Detection Systems (GIDS) are increasingly used to model complex communication patterns and detect sophisticated enterprise threats, yet the reproducibility and replicability of GIDS research remain underexplored, limiting the reliability and generalizability of published results. We present a rigorous reproduction and replication of five state-of-the-art GIDS across four public datasets and a new large-scale enterprise dataset. Even with original code and configurations, reproducing claimed performance is difficult; detection metrics vary by up to 40 percent due to undocumented assumptions, preprocessing discrepancies, and hyperparameter sensitivity. Models also fail to generalize to real-world enterprise traffic, exhibiting high false positive rates and scalability issues. We identify key implementation factors: graph snapshot size and threshold-setting strategies significantly affect detection performance but are inconsistently documented, and several GIDS are vulnerable to evasion attacks. Beyond confirming known challenges (e.g., parameter sensitivity), our results expose a critical reproducibility crisis in the GIDS literature: without transparent and systematic evaluation, reported results may mislead researchers and practitioners. We provide recommendations to improve reproducibility, replicability, and robustness, and urge the community to adopt rigorous standards for empirical evaluation.
Pujia Zheng, Jiaping Gui, Cunqing Hua, Wajih Ul Hassan
ACSAC3
2025 SRVul: A High-Quality Self-Restrained Vulnerable Code Dataset for Vulnerability Detection
abstract
Automated software vulnerability detection using learning-based approaches has been a focal point in the field of software engineering. However, the training and benchmarking of software vulnerability detection models are significantly influenced by the quality of the training data. Existing solutions have made limited efforts in addressing data quality issues due to limited and challenging data collection. Publicly available datasets have been found to suffer from data quality problems, hindering effective model training and performance evaluation. Although awareness of the potential negative impact of software vulnerability data quality is increasing, to the best of our knowledge, no systematic solution has been proposed to improve data quality during the automated labeling process. In this paper, we propose a data collection and cleansing framework that first collects the latest vulnerabilities and patches from publicly available vulnerability databases. Then, a rule-based filter is applied to classify function-level vulnerability fixing modifications into three categories: high quality, unknown quality, and low quality. Subsequently, a semantic filter trained on high-quality samples is used to filter samples of unknown quality, resulting in a cleansed version of the raw dataset. This is the first framework that distinguishes the quality of function-level modification samples for software vulnerability fixes and performs data cleansing, without solely relying on traditional heuristic label assignment strategies. In our experiments, we evaluate the properties of SRVul, the effectiveness of the framework, and the feasibility of using it for training vulnerability detection models. SRVul outperforms existing works on multiple metrics, demonstrating the best combination of dataset scale and quality, with a well-designed and effective framework and components. Training the advanced LineVul model with SRVul yields improved performance on benchmark datasets, indicating that SRVul is well-suited for the effective training of vulnerability detection models.
Hongjun Huang, Futai Zou, Jiaping Gui, Tianming Zheng, Yue Wu 0010
IJCNN3
2025 A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan
INFOCOM1
2025 BackdoorMBTI: A Backdoor Learning Multimodal Benchmark Tool Kit for Backdoor Defense Evaluation
abstract
Over the past few years, the emergence of backdoor attacks has presented significant challenges to deep learning systems, allowing attackers to insert backdoors into neural networks. When data with a trigger is processed by a backdoor model, it can lead to mispredictions targeted by attackers, whereas normal data yields regular results. The scope of backdoor attacks is expanding beyond computer vision and encroaching into areas such as natural language processing and speech recognition. Nevertheless, existing backdoor defense methods are typically tailored to specific data modalities, restricting their application in multimodal contexts. While multimodal learning proves highly applicable in facial recognition, sentiment analysis, action recognition, visual question answering, the security of these models remains a crucial concern. Specifically, there are no existing backdoor benchmarks targeting multimodal applications or related tasks.
Jiaping Gui, Pengyang Wang, Pengzhou Cheng, Ping Yi, Yue Wu 0010
KDD (1)3
2025 FedQS: Optimizing Gradient and Model Aggregation for Semi-Asynchronous Federated Learning
abstract
Federated learning (FL) enables collaborative model training across multiple parties without sharing raw data, with semi-asynchronous FL (SAFL) emerging as a balanced approach between synchronous and asynchronous FL. However, SAFL faces significant challenges in optimizing both gradient-based (e.g., FedSGD) and model-based (e.g., FedAvg) aggregation strategies, which exhibit distinct trade-offs in accuracy, convergence speed, and stability. While gradient aggregation achieves faster convergence and higher accuracy, it suffers from pronounced fluctuations, whereas model aggregation offers greater stability but slower convergence and suboptimal accuracy. This paper presents FedQS, the first framework to theoretically analyze and address these disparities in SAFL. FedQS introduces a *divide-and-conquer strategy* to handle client heterogeneity by classifying clients into four distinct types and adaptively optimizing their local training based on data distribution characteristics and available computational resources. Extensive experiments on computer vision, natural language processing, and real-world tasks demonstrate that FedQS achieves the highest accuracy, attains the lowest loss, and ranks among the fastest in convergence speed, outperforming state-of-the-art baselines. Our work bridges the gap between aggregation strategies in SAFL, offering a unified solution for stable, accurate, and efficient federated learning. The code and datasets are available at https://github.com/bkjod/FedQS_.
Yunbo Li, Jiaping Gui, Zhihang Deng, Yue Wu 0010
NeurIPS2
2025 DISTR: Detecting multi-stage IoT botnets through contextual traffic and causal analytics
Jiaping Gui, Futai Zou, Yunbo Li, Yue Wu 0010
Comput. Secur.2
2025 ProvAudit: Enhance High-Level Privacy Inference Through System Provenance Data
abstract
Companies such as CrowdStrike now offer cloud-based services for provenance analysis, which collects low-level system events from a customer's device and compiles them onto a centralized platform to detect APT attacks. Despite the effectiveness of such solutions, their privacy implications remain unclear. To assess the privacy implications of system provenance analysis, we employ the Website Fingerprinting (WF) of The Onion Router (Tor) browsers as the real-world attack scenario. In contrast to conventional, network traffic-based WF techniques, we have designed ProvAudit, a fully automated solution that audits the web browsing history of Tor browsers based on system provenance data. We conduct the first systematic case study to demonstrate the feasibility of inferring the websites visited by Tor browsers solely based on the collected system provenance data, particularly system call traces. The evaluation results show that our approach achieves a precision of 0.74 in the open-world scenario, higher than the state-of-the-art robust WF technique. In practice, ProvAudit consumes approximately 23 MB of memory and 4% CPU to audit system provenance data. Our approach is more robust against simple adversarial methods, more accurate, and less expensive than existing solutions. Overall, our case study reveals that provenance data is susceptible to privacy breaches, potentially exposing more high-level information than anticipated.
Ding Li 0001, Jifan Xiao, Peng Jiang 0007, Jiaping Gui, Dongjin Song, Yun Ma 0002, Gang Huang 0001, Xuanzhe Liu
IEEE Trans. Dependable Secur. Comput.4
2025 Solving Data Contamination in DDoS Detection: A Method Based on Hierarchical Federated Learning
Jiaping Gui, Ruiwen Ji, Haishi Huang, Jianan Hong, Cunqing Hua
IEEE Trans. Inf. Forensics Secur.1
2024 ProvIoT : Detecting Stealthy Attacks in IoT through Federated Edge-Cloud Security
Kunal Mukherjee, Josh Wiedemeier, Qi Wang 0017, Junpei Kamimura, Junghwan Rhee, James Wei, Zhichun Li, Xiao Yu 0007, Lu-An Tang, Jiaping Gui, Kangkook Jee
ACNS (3)10
2024 HFL-AD: A Hierarchical Federated Learning Framework for Solving Data Contamination in DDoS Detection
abstract
Distributed denial-of-service (DDoS) attacks can cause significant damage to network applications. A crucial step in combating these attacks lies in promptly and accurately detecting DDoS attack traffic. However, due to data insufficiency (imbalance) and contamination, existing solutions fail to yield satisfactory results for DDoS detection. Furthermore, current methods typically require access to raw data for training, posing a significant privacy risk. To tackle these challenges, we propose HFL-AD, a hierarchical federated learning framework specifically designed for detecting DDoS attack traffic. In our approach, a federation of lower layer clients train local anomaly detection models using diverse raw data. A selected few clients, possessing a small supplementary dataset, serve as upper layer clients, responsible for excluding model updates trained on contaminated datasets. Experimental results demonstrate that HFL-AD outperforms baseline solutions in DDoS detection, particularly when some training datasets are contaminated.
Haishi Huang, Jiaping Gui, Jianan Hong, Cunqing Hua
TrustCom2
2024 FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive Learning
Yifeng Cai, Jiaping Gui, Xiaoke Zhao, Ding Li 0001
USENIX Security Symposium3
2021 Structural Temporal Graph Neural Networks for Anomaly Detection in Dynamic Graphs
abstract
Detecting anomalies in dynamic graphs is a vital task, with numerous practical applications in areas such as security, finance, and social media. Existing network embedding based methods have mostly focused on learning good node representations, whereas largely ignoring the subgraph structural changes related to the target nodes in a given time window. In this paper, we propose StrGNN, an end-to-end structural temporal Graph Neural Network model for detecting anomalous edges in dynamic graphs. In particular, we first extract the h-hop enclosing subgraph centered on the target edge and propose a node labeling function to identify the role of each node in the subgraph. Then, we leverage the graph convolution operation and Sortpooling layer to extract the fixed-size feature from each snapshot/timestamp. Based on the extracted features, we utilize the Gated Recurrent Units to capture the temporal information for anomaly detection. We fully implement StrGNN and deploy it into a real enterprise security system, and it greatly helps detect advanced threats and optimize the incident response. Extensive experiments on six benchmark datasets also demonstrate the effectiveness of StrGNN.
Zhengzhang Chen, Chen Luo 0003, Jiaping Gui, Jingchao Ni, Ding Li 0001
CIKM4
2020 This is Why We Can't Cache Nice Things: Lightning-Fast Threat Hunting using Suspicion-Based Hierarchical Storage
abstract
Recent advances in the causal analysis can accelerate incident response time, but only after a causal graph of the attack has been constructed. Unfortunately, existing causal graph generation techniques are mainly offline and may take hours or days to respond to investigator queries, creating greater opportunity for attackers to hide their attack footprint, gain persistency, and propagate to other machines. To address that limitation, we present Swift, a threat investigation system that provides high-throughput causality tracking and real-time causal graph generation capabilities. We design an in-memory graph database that enables space-efficient graph storage and online causality tracking with minimal disk operations. We propose a hierarchical storage system that keeps forensically-relevant part of the causal graph in main memory while evicting rest to disk. To identify the causal graph that is likely to be relevant during the investigation, we design an asynchronous cache eviction policy that calculates the most suspicious part of the causal graph and caches only that part in the main memory. We evaluated Swift on a real-world enterprise to demonstrate how our system scales to process typical event loads and how it responds to forensic queries when security alerts occur. Results show that Swift is scalable, modular, and answers forensic queries in real-time even when analyzing audit logs containing tens of millions of events.
Wajih Ul Hassan, Ding Li 0001, Kangkook Jee, Xiao Yu 0007, Kexuan Zou, Zhengzhang Chen, Zhichun Li, Junghwan Rhee, Jiaping Gui, Adam Bates 0001
ACSAC10
2020 APTrace: A Responsive System for Agile Enterprise Level Causality Analysis
abstract
While backtracking analysis has been successful in assisting the investigation of complex security attacks, it faces a critical dependency explosion problem. To address this problem, security analysts currently need to tune backtracking analysis manually with different case-specific heuristics. However, existing systems fail to fulfill two important system requirements to achieve effective backtracking analysis. First, there need flexible abstractions to express various types of heuristics. Second, the system needs to be responsive in providing updates so that the progress of backtracking analysis can be frequently inspected, which typically involves multiple rounds of manual tuning. In this paper, we propose a novel system, APTrace, to meet both of the above requirements. As we demonstrate in the evaluation, security analysts can effectively express heuristics to reduce more than 99.5% of irrelevant events in the backtracking analysis of real-world attack cases. To improve the responsiveness of backtracking analysis, we present a novel execution-window partitioning algorithm that significantly reduces the waiting time between two consecutive updates (especially, 57 times reduction for the top 1% waiting time).
Jiaping Gui, Ding Li 0001, Zhengzhang Chen, Junghwan Rhee, Xusheng Xiao, Mu Zhang 0001, Kangkook Jee, Zhichun Li
ICDE1
2020 Anomaly Detection on Web-User Behaviors Through Deep Learning
Jiaping Gui, Zhengzhang Chen, Xiao Yu 0007, Cristian Lumezanu
SecureComm (1)1
2020 A Generic Edge-Empowered Graph Convolutional Network via Node-Edge Mutual Enhancement
abstract
Graph Convolutional Networks (GCNs) have shown to be a powerful tool for analyzing graph-structured data. Most of previous GCN methods focus on learning a good node representation by aggregating the representations of neighboring nodes, whereas largely ignoring the edge information. Although few recent methods have been proposed to integrate edge attributes into GCNs to initialize edge embeddings, these methods do not work when edge attributes are (partially) unavailable. Can we develop a generic edge-empowered framework to exploit node-edge enhancement, regardless of the availability of edge attributes? In this paper, we propose a novel framework EE-GCN that achieves node-edge enhancement. In particular, the framework EE-GCN includes three key components: (i) Initialization: this step is to initialize the embeddings of both nodes and edges. Unlike node embedding initialization, we propose a line graph-based method to initialize the embedding of edges regardless of edge attributes. (ii) Feature space alignment: we propose a translation-based mapping method to align edge embedding with node embedding space, and the objective function is penalized by a translation loss when both spaces are not aligned. (iii) Node-edge mutually enhanced updating: node embedding is updated by aggregating embedding of neighboring nodes and associated edges, while edge embedding is updated by the embedding of associated nodes and itself. Through the above improvements, our framework provides a generic strategy for all of the spatial-based GCNs to allow edges to participate in embedding computation and exploit node-edge mutual enhancement. Finally, we present extensive experimental results to validate the improved performances of our method in terms of node classification, link prediction, and graph classification.
Pengyang Wang, Jiaping Gui, Zhengzhang Chen, Junghwan Rhee, Yanjie Fu
WWW2
2019 Progressive processing of system-behavioral query
abstract
System monitoring has recently emerged as an effective way to analyze and counter advanced cyber attacks. The monitoring data records a series of system events and provides a global view of system behaviors in an organization. Querying such data to identify potential system risks and malicious behaviors helps security analysts detect and analyze abnormal system behaviors caused by attacks. However, since the data volume is huge, queries could easily run for a long time, making it difficult for system experts to obtain prompt and continuous feedback. To support interactive querying over system monitoring data, we propose ProbeQ, a system that progressively processes system-behavioral queries. It allows users to concisely compose queries that describe system behaviors and specify an update frequency to obtain partial results progressively. The query engine of ProbeQ is built based on a framework that partitions ProbeQ queries into sub-queries for parallel execution and retrieves partial results periodically based on the specified update frequency. We concretize the framework with three partition strategies that predict the workloads for sub-queries, where the adaptive workload partition strategy (AdWd) dynamically adjusts the predicted workloads for subsequent sub-queries based on the latest execution information. We evaluate the prototype system of ProbeQ on commonly used queries for suspicious behaviors over real-world system monitoring data, and the results show that the ProbeQ system can provide partial updates progressively (on average 9.1% deviation from the update frequencies) with only 1.2% execution overhead compared to the execution without progressive processing.
Jiaping Gui, Xusheng Xiao, Ding Li 0001
ACSAC1
2019 Heterogeneous Graph Matching Networks for Unknown Malware Detection
abstract
Information systems have widely been the target of malware attacks. Traditional signature-based malicious program detection algorithms can only detect known malware and are prone to evasion techniques such as binary obfuscation, while behavior-based approaches highly rely on the malware training samples and incur prohibitively high training cost. To address the limitations of existing techniques, we propose MatchGNet, a heterogeneous Graph Matching Network model to learn the graph representation and similarity metric simultaneously based on the invariant graph modeling of the program's execution behaviors. We conduct a systematic evaluation of our model and show that it is accurate in detecting malicious program behavior and can help detect malware attacks with less false positives. MatchGNet outperforms the state-of-the-art algorithms in malware detection by generating 50% less false positives while keeping zero false negatives.
Shen Wang 0005, Zhengzhang Chen, Xiao Yu 0007, Ding Li 0001, Jingchao Ni, Lu-An Tang, Jiaping Gui, Zhichun Li, Philip S. Yu
IJCAI7
2017 An Empirical Study of Local Database Usage in Android Applications
abstract
Local databases have become an important component within mobile applications. Developers use local databases to provide mobile users with a responsive and secure service for data storage and access. However, using local databases comes with a cost. Studies have shown that they are one of the most energy consuming components on mobile devices and misuseof their APIs can lead to performance and security problems. In this paper, we report the results of a large scale empirical study on 1,000 top ranked apps from the Google Play app store. Our results present a detailed look into the practices, costs, and potential problems associated with local database usage in deployed apps. We distill our findings into actionable guidance for developers and motivate future areas of research related to techniques to support mobile app developers.
Yingjun Lyu, Jiaping Gui, Mian Wan, William G. J. Halfond
ICSME2
2017 Detecting display energy hotspots in Android apps
abstract
Summary The energy consumption of mobile apps has become an important consideration for developers as the underlying mobile devices are constrained by battery capacity. Display represents a significant portion of an app's energy consumption—up to 60% of an app's total energy consumption. However, developers lack techniques to identify the user interfaces in their apps for which energy needs to be improved. This paper presents a technique for detecting display energy hotspots—user interfaces of a mobile app whose energy consumption is greater than optimal. The technique leverages display power modeling and automated display transformation techniques to detect these hotspots and prioritize them for developers. The evaluation of the technique shows that it can predict display energy consumption to within 14% of the ground truth and accurately rank display energy hotspots. Furthermore, the approach found 398 display energy hotspots in a set of 962 popular Android apps, showing the pervasiveness of this problem. For these detected hotspots, the average power savings that could be realized through better user interface design was 30%. Taken together, these results indicate that the approach represents a potentially impactful technique for helping developers to detect energy related problems and reduce the energy consumption of their mobile apps.
Mian Wan, Ding Li 0001, Jiaping Gui, Sonal Mahajan, William G. J. Halfond
Softw. Test. Verification Reliab.4
2016 Automated energy optimization of HTTP requests for mobile applications
abstract
Energy is a critical resource for apps that run on mobile devices. Among all operations, making HTTP requests is one of the most energy consuming. Previous studies have shown that bundling smaller HTTP requests into a single larger HTTP request can be an effective way to improve energy efficiency of network communication, but have not defined an automated way to detect when apps can be bundled nor to transform the apps to do this bundling. In this paper we propose an approach to reduce the energy consumption of HTTP requests in Android apps by automatically detecting and then bundling multiple HTTP requests. Our approach first detects HTTP requests that can be bundled using static analysis, then uses a proxy based technique to bundle HTTP requests at runtime. We evaluated our approach on a set of real world marketplace Android apps. In this evaluation, our approach achieved an average energy reduction of 15% for the subject apps and did not impose a significant runtime overhead on the optimized apps.
Ding Li 0001, Yingjun Lyu, Jiaping Gui, William G. J. Halfond
ICSE3
2015 Truth in Advertising: The Hidden Cost of Mobile Ads for Software Developers
abstract
The "free app" distribution model has been extremely popular with end users and developers. Developers use mobile ads to generate revenue and cover the cost of developing these free apps. Although the apps are ostensibly free, they in fact do come with hidden costs. Our study of 21 real world Android apps shows that the use of ads leads to mobile apps that consume significantly more network data, have increased energy consumption, and require repeated changes to ad related code. We also found that complaints about these hidden costs are significant and can impact the ratings given to an app. Our results provide actionable information and guidance to software developers in weighing the tradeoffs of incorporating ads into their mobile apps.
Jiaping Gui, Stuart McIlroy, Meiyappan Nagappan, William G. J. Halfond
ICSE (1)1
2014 An Empirical Study of the Energy Consumption of Android Applications
abstract
Energy is a critical resource for smartphones. However, developers who create apps for these platforms lack quantitative and objective information about the behavior of apps with respect to energy consumption. In this paper, we describe the results of our source-line level energy consumption study of 405 real-world market applications. Based on our study, we discover several interesting observations. For example, we find on average apps spend 61% of their energy in idle states, network is the most energy consuming component, and only a few APIs dominate non-idle energy consumption. The results of this study provide developers with objective information about how energy is consumed by a broad sample of mobile applications and can guide them in their efforts of improving the energy efficiency of their applications.
Ding Li 0001, Shuai Hao 0002, Jiaping Gui, William G. J. Halfond
ICSME3
2012 Cost based routing in delay tolerant networks
abstract
Delay tolerant networks (DTNs) attempt to minimize the possible adverse impacts due to limitations and anomalies in intermittently connected networks. Routing in such sparse and dynamic networks is difficult as the source has little information about the destination, rendering a key challenge to find one simple and effective message delivery mechanism. In this paper, we propose PriCost, a protocol based on the cost for efficient routing of messages, and use the node's past interactions with others to determine the cost of potential routing, in the absence of any other information. Our simulations show that PriCost performs better than MaxProp with reduced complexity. The evaluations also show different cost based metrics hardly affect the performance provided they depend on the same feature extraction algorithm.
Jiaping Gui, Yue Wu 0010, Chenji Pan, Futai Zou
PIMRC1