VLDB 2026 Research / reviewers in the wild / expert
Qiguang Zhang
dblp:155/8291
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2026
0009-0005-9408-3445ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnet
Qiguang Zhang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Christopher Morales, Xinwen Fu |
NDSS | 1 |
| 2024 | Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingabstractBuilding Automation Systems (BAS) play a pivotal role in modern smart buildings, integrating sensors, controllers, and software to manage crucial functions such as HVAC, lighting, and more. The global smart building market is on the rise, underscoring the importance of securing BAS networks. This paper introduces the Building Automation System Evaluator (BASE), a specialized fuzzer designed to assess the security of BAS networks. BAS networks typically involve a BAS client communicating with a BAS server through BAS protocols (e.g., BACnet, KNX), each presenting unique challenges in BAS network fuzzing. These challenges encompass complex packet structures and sequencing in BAS protocols, closed-source clients with indeterminable code coverage, and unobservable server status with limited throughput. BASE automatically identifies protocol structures, dynamically instruments clients for code coverage analysis, and monitors responses for new coverage areas. Collected timestamps are used to estimate the input scan intervals of servers, optimizing throughput. We evaluated BASE on various BAS servers and clients, uncovering 13 new vulnerabilities. Furthermore, we present three attack case studies, highlighting the real-world security implications of these vulnerabilities in BAS systems, such as delayed fire detection, loss of climate control, and security breaches. We reported our findings to the respective vendors, who acknowledged the implications, and some have subsequently patched their systems based on our reports. Yue Zhang 0025, Zhen Ling 0001, Michael Cash, Qiguang Zhang, Christopher Morales, Qun Zhou 0002, Xinwen Fu |
CCS | 4 |