VLDB 2026 Research / reviewers in the wild / expert
Cunqing Ma
dblp:119/3613
· DBLP profile ↗
27ranked-venue papers
2as first author
10since 2021 · last 2025
0009-0000-6475-9524ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 first-author · 3 since 2021Computer networks · 5 · 2 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 3Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | FedTP: Traceable Passport-Based Ownership Verification for Federated Deep Neural Network Models
QiRui Sa, Weijing You, Cunqing Ma, WeiYang Qiu |
ICANN (1) | 4 |
| 2024 | BRITD: behavior rhythm insider threat detection with time awareness and user adaptationabstractAbstract Researchers usually detect insider threats by analyzing user behavior. The time information of user behavior is an important concern in internal threat detection. Existing works on insider threat detection fail to make full use of the time information, which leads to their poor detection performance. In this paper, we propose a novel behavioral feature extraction scheme: we implicitly encode absolute time information in the behavioral feature sequences and use a feature sequence construction method taking covariance into account to make our scheme adaptive to users. We select Stacked Bidirectional LSTM and Feedforward Neural Network to build a deep learning-based insider threat detection model: Behavior Rhythm Insider Threat Detection (BRITD). BRITD is universally applicable to various insider threat scenarios, and it has good insider threat detection performance: it achieves an AUC of 0.9730 and a precision of 0.8072 with the CMU CERT dataset, which exceeds all baselines. Graphical Abstract Neng Gao, Cunqing Ma |
Cybersecur. | 4 |
| 2023 | Learning to Select Prototypical Parts for Interpretable Sequential Data ModelingabstractPrototype-based interpretability methods provide intuitive explanations of model prediction by comparing samples to a reference set of memorized exemplars or typical representatives in terms of similarity. In the field of sequential data modeling, similarity calculations of prototypes are usually based on encoded representation vectors. However, due to highly recursive functions, there is usually a non-negligible disparity between the prototype-based explanations and the original input. In this work, we propose a Self-Explaining Selective Model (SESM) that uses a linear combination of prototypical concepts to explain its own predictions. The model employs the idea of case-based reasoning by selecting sub-sequences of the input that mostly activate different concepts as prototypical parts, which users can compare to sub-sequences selected from different example inputs to understand model decisions. For better interpretability, we design multiple constraints including diversity, stability, and locality as training objectives. Extensive experiments in different domains demonstrate that our method exhibits promising interpretability and competitive accuracy. Neng Gao, Cunqing Ma |
AAAI | 3 |
| 2023 | ImCT: A Feasible Scheme for Deploying Implicit Certificates with Certificate Transparency in IoTabstractData security has become a major concern in end-to-end communication of Internet of Things (IoT) devices. To establish an encrypted and trusted channel, certificate-based authentication is broadly adopted in many resource-constrained IoT environments, especially Elliptic Curve Qu-Vanstone (ECQV) implicit certificates, optimized for bandwidth and processing time compared to X.509 certificates. However, certificates in Public Key Infrastructure (PKI) inherently face the security problem that Certificate Authorities (CAs) with absolute trust might issue fraudulent certificates maliciously/unintentionally. To mitigate this problem, Certificate Transparency (CT) has been widely deployed, but it brings more transmission and validation overhead, posing new challenges for IoT devices. To inherit the advantage of implicit certificates and make CT more friendly to resource-restricted IoT systems, this paper proposes ImCT, the first feasible and efficient scheme for deploying ECQV implicit certificates with CT in IoT. It (1) offers an ingenious and compact design of certificate extension for integrating CT into implicit certificates, ensuring sufficiently small memory use and low validation cost; (2) provides a generic Bloom Filter-based solution to efficiently deploy ImCT in interactive protocols with compatibility with existing CT validation rules; (3) allows for incremental deployment and deploys to TLS 1.3 easily with only a few self-defined TLS extensions. The security of ImCT is also analyzed, and the performance evaluation shows its practicality and high efficiency. Huiqing Wan, Qiongxiao Wang, Yajun Teng, Cunqing Ma, Jingqiang Lin 0001 |
ICCCN | 4 |
| 2023 | ESCORT: Efficient Status Check and Revocation Transparency for Linkage-Based Pseudonym Certificates in VANETsabstractThe security, privacy, and trust are the critical concerns in Vehicular Ad Hoc Networks (VANETs). The Security Credential Management System (SCMS) is one of the most promising PKI-based solutions, which adopts linkage-based pseudonym certificates and has been standardized by IEEE. This paper aims to address the issues of certificate revocation in the SCMS architecture. We propose ESCORT, achieving: (i) a privacy-preserving revocation transparency for linkage-based pseudonym certificates, enhancing the reliability of the SCMS architecture; (ii) an efficient certificate status check for vehicles, eliminating complicated computations in checking CRLs. We analyze the security and feasibility of ESCORT, and experimental results indicate its superior efficiency. Huiqing Wan, Qiongxiao Wang, Cunqing Ma, Yajun Teng, Jingqiang Lin 0001, Dingfeng Ye |
ISCC | 3 |
| 2023 | Enhanced Ticket Transparency (eTT) Framework for Single Sign-On Services with PseudonymsabstractRecently, a series of vulnerabilities occurred to divulge or forge single sign-on tickets, such as the famous SolarWinds incident Once malicious attackers obtain fraudulent tickets, they can pry into user privacy as well as compromise the system by impersonating the victim user. Inspired by certificate transparency, a ticket transparency (TT) framework for detecting fraudulent tickets is proposed. However, it suffers from inefficiency and potential failure. In this paper, we further propose an enhanced ticket transparency (eTT) scheme, which ensures that all fraudulent tickets can be detected efficiently through a novel dual-backup structure to store ticket entries in the public log. Meanwhile, we design specific calculations for pairwise pseudonymous identifiers (PPIDs), to support fraudulent-detection towards tickets in which user identifiers are pseudonyms. We implemented the prototype system, and the experimental evaluation shows that eTT framework introduces acceptable overheads in the sign-on process. Guangqi Liu, Jingqiang Lin 0001, Dawei Chu, Qiongxiao Wang, Cunqing Ma, Fengjun Li, Dingfeng Ye |
TrustCom | 6 |
| 2023 | The Broken Verifying: Inspections at Verification Tools for Windows Code-Signing SignaturesabstractTerminal users can deploy verification tools to verify Windows code-signing signatures and check their details (signing time, certificate chain, etc). Some representative verification tools are also adopted in related studies, which take tools’ outputs as contributing factors to analyse malicious software or certificate ecosystems. However, as code-signing signature verification is related to multiple dimensions, such as certificate status and system policies, getting accurate signature status and details is essential but rather complicated. And performance of different tools in verifications has not been well studied and compared with.We provide a novel methodology to inspect Windows code-signing verification tools, checking that if they print consistent results and details. We choose four representative tools to verify massive samples (more than 26 million) and collect their outputs. During the verification, we deploy a two-step verification method, which efficiently excludes 78.8% of samples (not signed). We write scripts to read each line of outputs, learning tools’ output structures. Then we can precisely locate and extract interested code-signing fields from outputs. After that, we compare these essential fields from different tools, and analyze inconsistent cases. Finally, we present three types of inconsistent cases: verifying neglect, timestamp disturbance, and compatibility/robustness issues. We find some verification tools may assert code-signing signatures as invalid due to external factors, such as unexpected signing or invalid timestamp. Guangqi Liu, Qiongxiao Wang, Cunqing Ma, Jingqiang Lin 0001, Yanduo Fu, Bingyu Li 0003, Dingfeng Ye |
TrustCom | 3 |
| 2022 | Gait2Vec: Continuous Authentication of Smartphone Users Based on Gait BehaviorabstractSince gait is hard to imitate and can be easily collected by smartphone inertial sensors, it can be applied to user authentication. Traditional neural network based methods tend to train feature extractor and classifier together for each user in user authentication. These methods are difficult to guarantee that the feature extractor designed for specific users is suitable for other users. The accuracy is low when the sample size of a legitimate user is small, and the time overhead is heavy when the total amount of legitimate users is large. Besides, there are often strong constraints on sensor position, walking route, walking speed and external scenario when collecting gait data. In this paper, in order to reduce the cost of time and improve the robustness of the model, we use the idea of transfer learning to design our Gait2Vec feature extractor. It is pre-trained in the user identification task and then transferred to user authentication task for feature extraction. Meanwhile, a gait dataset of 21 subjects is collected under weak constraints in 2 scenarios for experimental purposes. Extensive analysis demonstrates that our models achieve a high performance with the accuracy over 94% in user identification and 97% in user authentication. Langyue He, Cunqing Ma, Chenyang Tu |
CSCWD | 2 |
| 2022 | BiGNN: A Bilateral-Branch Graph Neural Network to Solve Popularity Bias in RecommendationabstractTraditional recommendation methods aim to recom-mend personalized items by analyzing user's history interaction data. They ignore the fact that the data follows a long-tail distribution, which means that a small number of popular items account for most of the interaction records. This phenomenon causes the model to recommend more popular items, resulting in a severe popularity bias. In order to pay more attention to the long-tail items and debias the popular bias, we propose a Bilateral-Branch Graph Neural Network(BiGNN). In the long- tail branch, we construct a separate long-tail sub graph by eliminating the popular items with high degree. When the Graph Neural Network(GNN) aggregates information layer by layer in the subgraph, the receptive field of the single hop becomes larger, which increases the exposure of the long-tail items. Besides, another branch takes the original interaction graph as input to learn the general data distribution and generate the global embeddings of users and items. The two branches use the same GNN structure and share parameters. We employ the point-wise mutual information (PMI) strategy to indicate interaction between users and reconstruct the long-tail sub graph. The two branches are aggregated through an accumulated learning module, which makes the model first learn the conventional patterns and then pay attention to the long-tail data gradually. Extensive experiments on three real-world datasets show that BiGNN evidently outperforms the state-of- the-art methods consistently. Yingshuai Kou, Neng Gao, Chenyang Tu, Cunqing Ma |
ICTAI | 5 |
| 2021 | CMVCG: Non-autoregressive Conditional Masked Live Video Comments Generation ModelabstractThe blooming of live comment videos leads to the need of automatic live video comment generating task. Previous works focus on autoregressive live video comments generation and can only generate comments by giving the first word of the target comment. However, in some scenes, users need to generate comments by their given prompt keywords, which can't be solved by the traditional live video comment generation methods. In this paper, we propose a Transformer based non-autoregressive conditional masked live video comments generation model called CMVCG model. Our model considers not only the visual and textual context of the comments, but also time and color information. To predict the position of the given prompt keywords, we also introduce a keywords position predicting module. By leveraging the conditional masked language model, our model achieves non-autoregressive live video comment generation. Furthermore, we collect and introduce a large-scale real-world live video comment dataset called Bili-22 dataset. We evaluate our model in two live comment datasets and the experiment results present that our model outperforms the state-of-the-art models in most of the metrics. Zehua Zeng, Chenyang Tu, Neng Gao, Cunqing Ma, Yiwei Shan |
IJCNN | 5 |
| 2020 | Boosting Entropy Extraction of PDL-based RO PUF by High-order Difference MethodabstractRing Oscillator-based Physically Unclonable Function (RO PUF) is widely concerned because of its simple structure and good properties. Unfortunately, in order to maintain high reliability, the traditional RO PUF can only extract 1 bit entropy by comparing the frequency's magnitude of two selected ring oscillators (ROs), which is far from enough, especially in PUF-based key generation scenarios. In this paper, we propose an efficient and concise RO PUF response generation scheme based on FPGA platform by using high-order difference method, which significantly improves the response generation rate and entropy extraction rate of an RO pair by the fine control of Programmable Delay Lines (PDLs) in Look-Up Tables (LUTs). In addition, we build loop delay models and conduct extensive experiments on Xilinx's 28nm FPGAs (Kintex-7, Virtex-7 and Zynq-7000) to prove the effectiveness of our scheme. Liang Zheng 0005, Changting Li, Zongbin Liu, Cunqing Ma |
ACM Great Lakes Symposium on VLSI | 4 |
| 2020 | Flush-Detector: More Secure API Resistant to Flush-Based Spectre Attacks on ARM Cortex-A9abstractARM series processors are increasingly used in IoT and cloud services because of their high performance and flexibility of hardware design, especially Cortex-A9 MPCore processor. However, they also suffer from various types of security threats, typically such as flush-based cache attacks. Among these attacks, flush-based Spectre attacks(using Flush + Reload for Spectre attacks) represent a serious threat to system. They usually induce the victim to speculatively perform operations that would not occur during the correct program execution, and then leak the victim’s confidential information to the adversary via cache side channel attacks. So far, there is no widely accepted solution to defend against Spectre attacks. The proposed solutions either lead to large performance losses or sacrifice transparency. In this paper, we propose a secure flush operation API named Flush-Detector to mitigate flush-based Spectre attacks. We present the design and implement of Flush-Detector to detect and defend against flush-based Spectre attacks on ARM Cortex-A9 MPCore. The attack experimental results show that Flush-Detector can detect flush-based Spectre attacks in real time and reduce the attack success rate to less than 1%. Moreover, performance test results demonstrate that the time consumption of Flush-Detector API is about 17.7% longer than the original cache flush API. Cunqing Ma, Jingquan Ge, Neng Gao, Chenyang Tu |
ISCC | 2 |
| 2020 | A Hardware/Software Collaborative SM4 Implementation Resistant to Side-channel Attacks on ARM-FPGA Embedded SoCabstractThe SM4 algorithm is the first commercial cryptographic algorithm officially announced in China for wireless local area network products. It is suitable for scenarios that require high real-time performance, such as wireless communication and IoT sensor nodes. It can be seen that the security research of the SM4 algorithm is of great significance to wireless devices in the IoT. Like other symmetric encryption algorithms, the SM4 algorithm faces some security threats, such as side-channel attacks. Among them, cache timing attacks and power/electromagnetic analysis attacks are becoming more and more threatening due to their low execution difficulty and powerful attack capabilities. Most implementations of anti-side channel attacks against the SM4 algorithm can only resist one of above two attacks. However, side-channel leakages associated with above attacks often coexist.Therefore in this paper, we present a hardware/software collaborative SM4 implementation on ARM-FPGA embedded SoC which can resist above two types of attacks simultaneously. It randomly divides the 32 rounds of SM4 encryption into three stages: the beginning software stage, the middle hardware stage, and the final software stage. Besides, we shuffle the order of some independent operations in each round of the software stages and add dummy rounds to the hardware stage. Finally, we conduct above two types of attacks on unprotected software/hardware SM4, shuffled software SM4 and our scheme, then evaluate their performance respectively. The data throughput of our scheme is 0.86 times that of the original software SM4, while the FPGA resource requirements of our scheme are 0.87 times that of the unprotected hardware implementation. Ping Peng, Cunqing Ma, Jingquan Ge, Neng Gao, Chenyang Tu |
ISCC | 2 |
| 2020 | Flush+Time: A High Accuracy and High Resolution Cache Attack On ARM-FPGA Embedded SoCabstractFlush based cache attacks have become a practical threat to data privacy and information security due to their advantages such as high accuracy and resolution. However, their accuracy and resolution still has room for improvement. In addition, although most of the attacks have been demonstrated on x86 processors, few of them have been executed on ARM devices. We propose a high accuracy, high resolution flush based cache attack, Flush+Time. This technique solves two important challenges for cache attacks on ARM: how to flush cache lines and how to achieve precise timing. Experiments show that Flush+Time increases accuracy from 95.1% of Flush+Reload, the most powerful general cache attack so far, to 99.3%. Flush+Time has a 30.5% higher resolution than Flush+Reload, but its execution time is only 0.59 times that of Spectre. Churan Tang, Pengkun Liu, Cunqing Ma, Zongbin Liu, Jingquan Ge |
VTS | 3 |
| 2020 | MACM: How to Reduce the Multi-Round SCA to the Single-Round Attack on the Feistel-SP NetworksabstractSince the master key length becomes longer and longer in ciphers, an adversary often needs to preform the multi-round side channel analysis (SCA) in order to recover the master key by enough round keys. Traditional multi-round SCA is launched by adaptive manner in practice, which means that the input of each round is calculated in an on-the-fly way based on all round keys of anterior rounds. However, compared to the classical single-round SCA, the multi-round SCA in adaptive manner is severely limited in several practical scenarios, because all round keys of anterior rounds must be properly recovered before the attack against the next round. In this paper, we focus on the Feistel-SP networks, break the interdependency between the alternating measurement and analysis phases, propose a Multi-round non-Adaptive Chosen Message (MACM) approach, which can reduce the multi-round SCA to the single-round attack. In MACM, the set of plaintexts applied to multiple rounds is calculated in an off-line way. We also prove that the revealed round keys by MACM are adequate to recover the master key. Furthermore, we carefully analyze the advantages of MACM regarding to robustness and compatibility. In order to further manifest the validity of MACM, we perform extensive experiments on three typical Feistel-SP ciphers, Camellia, CLEFIA and SM4, the master keys are recovered as expected, and the number of traces in MACM is at least 25% less than that in the adaptive manner. Chenyang Tu, Zeyi Liu 0002, Neng Gao, Cunqing Ma, Jingquan Ge, Lingchen Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | A Low Overhead Error Correction Algorithm Using Random Permutation for SRAM PUFs
Liang Zheng 0005, Donglei Han, Zongbin Liu, Cunqing Ma, Lingchen Zhang, Churan Tang |
ACISP | 4 |
| 2019 | A Privacy Enhancing Scheme for Mobile Devices Based Secure Multi-party Computation System
Xueyi Yang, Cunqing Ma |
Inscrypt | 4 |
| 2019 | SecFlush: A Hardware/Software Collaborative Design for Real-Time Detection and Defense Against Flush-Based Cache Attacks
Churan Tang, Zongbin Liu, Cunqing Ma, Jingquan Ge, Chenyang Tu |
ICICS | 3 |
| 2019 | KPaM: A Key Protection Framework for Mobile Devices Based on Two-party ComputationabstractKey protection on mobile devices is attracting more attention with the rapid growth of mobile payment. There are many key protection methods proposed in academia from the following three aspects. The first is from algorithmic perspective, such as white-box cryptography. The second is from physical protection perspective, such as secure element (SE). The last is from key escrow perspective, such as cloud secure element (Cloud SE). The security of the white box cryptography has not yet reached an agreement in academia, and SE cannot defend against unknown side channel attacks in the future since it can hardly be updated. With regard to Cloud SE, the user has to totally trust the cloud, including the cloud provider, the cloud environment, etc. However, with the development of attack methods, the complete credibility of the cloud has gradually become an excessive requirement. In this paper, we propose KPaM, a low-cost and flexible key protection framework for mobile devices, which can mitigate the issues described above. The main idea of KPaM is inspired by emerging two-party computation algorithm. The private key is split into two parts, stored and used in the mobile device and the cloud respectively. The cloud does not store the complete key, so there is no need to worry about the abuse of the user's private key. On the mobile side, we get rid of SE and use TEE (trusted execution environment) to perform cryptographic operations and access control mechanism, which realizes the functions of secure storage and trust path. At last, we take SM2 algorithm as an example to validate KPaM and evaluate its security and efficiency. Zongbin Liu, Cunqing Ma, Lingchen Zhang, Donglei Han |
ISCC | 3 |
| 2018 | Implementation of High Throughput XTS-SM4 Module for Data Storage Devices
Liang Zheng 0005, Changting Li, Zongbin Liu, Lingchen Zhang, Cunqing Ma |
SecureComm (2) | 5 |
| 2017 | A Plausibly Deniable Encryption Scheme Utilizing PUF's Thermo-Sensitivity
Changting Li, Zongbin Liu, Lingchen Zhang, Cunqing Ma, Liang Zheng 0005 |
ICICS | 4 |
| 2017 | A PUF and Software Collaborative Key Protection Scheme
Changting Li, Zongbin Liu, Lingchen Zhang, Cunqing Ma, Liang Zheng 0005 |
ICICS | 4 |
| 2016 | HPAZ: A high-throughput pipeline architecture of ZUC in hardware
Zongbin Liu, Cunqing Ma, Changting Li, Jiwu Jing |
DATE | 3 |
| 2016 | FROPUF: How to Extract More Entropy from Two Ring Oscillators in FPGA-Based PUFs
Zongbin Liu, Cunqing Ma, Changting Li, Lingchen Zhang |
SecureComm | 3 |
| 2015 | Bit Error Probability Evaluation of RO PUFs
Zongbin Liu, Cunqing Ma, Jiwu Jing |
ISC | 3 |
| 2012 | Efficient Missing Tag Detection in a Large RFID SystemabstractMissing tag detection is an important problem for large RFID application systems (e.g., inventory control), and is drawing more and more attention from the research community in recent years. Li et al. proposed the Iterative ID-free Protocol (IIP) to identify the missing tags in a large RFID system, achieving high time efficiency. However, our analysis and experiments show that the time efficiency of IIP drops sharply when the missing rate increases. By exploiting information contained in the expected singleton slots, we propose IIPS to improve IIP, achieving high and steady time efficiency under both high and low missing rates. Furthermore, by identifying the missing tags in the expected collision slots and dynamically computing the missing rate through estimation of the present tags and statistics about the missing tags, we propose IIPS-CP and IIPS-CM, achieving higher time efficiency than IIPS under high missing rates. Our simulations show that, compared with IIP, when the number of total tags is 10000 and the missing rate is 80%, IIPS, IIPS-CP and IIPS-CM reduce the average time for identifying each tag by 84.8%, 88.9% and 89.3%, respectively. Cunqing Ma, Jingqiang Lin 0001, Yuewu Wang |
TrustCom | 1 |
| 2012 | Offline RFID Grouping Proofs with Trusted TimestampsabstractWith the wide deployment of RFID applications, RFID security issues are drawing more and more attention. The RFID grouping proof aims to provide a verifiable evidence that two or more RFID tags were scanned simultaneously. It extends the yoking proof for two RFID tags, to prove the coexistence of a set of tags (e.g., some drugs can only be sold in the existence of a prescription). In many grouping proof scenarios, the time when the grouping proof was generated is critical to judge whether a transaction is legal or not, and the protocol usually should work in offline mode. Although lots of grouping proof protocols with various features have been proposed, they either work in online mode or have difficulties in generating a grouping proof with the precise transaction time in offline mode. Therefore, we propose a protocol to generate offline RFID grouping proofs with trusted timestamps, where the verifier can obtain the precise transaction time. As far as we know, it is the first practical offline grouping proof protocol that includes the precise transaction time. Properties, performance evaluation and security analysis of our design are also presented in this paper. Cunqing Ma, Jingqiang Lin 0001, Yuewu Wang, Ming Shang |
TrustCom | 1 |