VLDB 2026 Research / reviewers in the wild / expert
Qingtian Zou
dblp:130/2484
· DBLP profile ↗
6ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0002-1412-4800ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Analysis of neural network detectors for network attacksabstractWhile network attacks play a critical role in many advanced persistent threat (APT) campaigns, an arms race exists between the network defenders and the adversary: to make APT campaigns stealthy, the adversary is strongly motivated to evade the detection system. However, new studies have shown that neural network is likely a game-changer in the arms race: neural network could be applied to achieve accurate, signature-free, and low-false-alarm-rate detection. In this work, we investigate whether the adversary could fight back during the next phase of the arms race. In particular, noticing that none of the existing adversarial example generation methods could generate malicious packets (and sessions) that can simultaneously compromise the target machine and evade the neural network detection model, we propose a novel attack method to achieve this goal. We have designed and implemented the new attack. We have also used Address Resolution Protocol (ARP) Poisoning and Domain Name System (DNS) Cache Poisoning as the case study to demonstrate the effectiveness of the proposed attack. Qingtian Zou, Lan Zhang 0008, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 1 |
| 2022 | Deep learning for detecting logic-flaw-exploiting network attacks: An end-to-end approachabstractNetwork attacks have become a major security concern for organizations worldwide. A category of network attacks that exploit the logic (security) flaws of a few widely-deployed authentication protocols has been commonly observed in recent years. Such logic-flaw-exploiting network attacks often do not have distinguishing signatures, and can thus easily evade the typical signature-based network intrusion detection systems. Recently, researchers have applied neural networks to detect network attacks with network logs. However, public network data sets have major drawbacks such as limited data sample variations and unbalanced data with respect to malicious and benign samples. In this paper, we present a new end-to-end approach based on protocol fuzzing to automatically generate high-quality network data, on which deep learning models can be trained for network attack detection. Our findings show that protocol fuzzing can generate data samples that cover real-world data, and deep learning models trained with fuzzed data can successfully detect the logic-flaw-exploiting network attacks. Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 1 |
| 2022 | DeepSyslog: Deep Anomaly Detection on Syslog Using Sentence Embedding and MetadataabstractAnomaly events indicating the unhealthy status of the computer system are recorded in the system log (Syslog). Therefore, Syslog-based anomaly event detection is crucial for diagnosing system issues and problems. However, existing log-based anomaly detection approaches use raw and unstructured log entriesindependentlyandincompletely, i.e., without considering the context of each event and event metadata in the logs. They employ incomplete representation of unstructured log data, limiting the deep learning model’s capacity in the early stage, which tends to omit anomaly events and cause false alarms. In this work, we propose DeepSyslog, which represents Syslog with the context of log events and event metadata in the logs. Inspired by the sequence nature of the log stream, we employ unsupervised sentence embedding to extract the semantic and context information hidden in the log stream, rather than word embedding or one-hot embedding, which only capture the similarities between log words. The sentence embedding is further integrated with event metadata to form complete representations of Syslog, which can distinguish the anomaly caused by the correlated log entries and exceptional event metadata in the log. The simulation results on widely used log datasets show that DeepSyslog achieves high performance compared with the existing log-based anomaly event detection approaches. Junwei Zhou 0002, Yijia Qian, Qingtian Zou, Peng Liu 0005, Jianwen Xiang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Deep Learning for Detecting Network Attacks: An End-to-End Approach
Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
DBSec | 1 |
| 2020 | Using deep learning to solve computer security challenges: a surveyabstractAbstract Although using machine learning techniques to solve computer security challenges is not a new idea, the rapidly emerging Deep Learning technology has recently triggered a substantial amount of interests in the computer security community. This paper seeks to provide a dedicated review of the very recent research works on using Deep Learning techniques to solve computer security challenges. In particular, the review covers eight computer security problems being solved by applications of Deep Learning: security-oriented program analysis, defending return-oriented programming (ROP) attacks, achieving control-flow integrity (CFI), defending network attacks, malware classification, system-event-based anomaly detection, memory forensics, and fuzzing for software security. Yoon-Ho Choi, Peng Liu 0005, Zitong Shang, Lan Zhang 0008, Junwei Zhou 0002, Qingtian Zou |
Cybersecur. | 8 |
| 2016 | Low-Power Variation-Tolerant Nonvolatile Lookup Table DesignabstractEmerging nonvolatile memories (NVMs), such as MRAM, PRAM, and RRAM, have been widely investigated to replace SRAM as the configuration bits in field-programmable gate arrays (FPGAs) for high security and instant power ON. However, the variations inherent in NVMs and advanced logic process bring reliability issue to FPGAs. This brief introduces a low-power variation-tolerant nonvolatile lookup table (nvLUT) circuit to overcome the reliability issue. Because of large ROFF/RON, 1T1R RRAM cell provides sufficient sense margin as a configuration bit and a reference resistor. A single-stage sense amplifier with voltage clamp is employed to reduce the power and area without impairing the reliability. Matched reference path is proposed to reduce the parasitic RC mismatch for reliable sensing. Evaluation shows that 22% reduction in delay, 38% reduction in power, and the tolerance of variations of 2.5× typical RONor ROFFin reliability are achieved for proposed nvLUT with six inputs. Xiaoyong Xue, Yinyin Lin, Ryan Huang, Qingtian Zou, Jingang Wu |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |