VLDB 2026 Research / reviewers in the wild / expert
Kaixuan Luo
dblp:164/0299
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-6387-8043ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau |
SP | 1 |
| 2025 | User Preference Based on Data Caching Strategy in Edge Computing for Intelligent Transportation
Kaixuan Luo, Chuanxiang Ma |
ICA3PP (2) | 1 |
| 2025 | Multidimensional Dynamic Trust Evaluation towards Intelligent TransportationabstractThe accelerated advancement of intelligent connected vehicles (ICVs) has introduced unprecedented conveniences and functional capabilities. Nevertheless, ICVs have simultaneously emerged as prime targets for cyber adversaries, confronting substantial risks from malicious vehicular attacks. Consequently, establishing robust methodologies to evaluate vehicular trustworthiness and promptly detect malicious entities represents a critical research imperative. To address these security challenges, this work introduces an integrated framework for identity authentication and trust evaluation in ICVs. The proposed solution comprises two core components. The initial component is a privacy-preserving authentication mechanism that safeguards the vehicle’s real identity through the dynamic generation of pseudoidentities, partial keys, and message signatures. Subsequently, a multidimensional trust evaluation model is established, incorporating direct, indirect, contextual, and comprehensive trust factors. This model is enhanced by an adaptive threshold mechanism designed to dynamically discriminate between anomalous and malicious behaviors. Empirical evaluations under common attack vectorsincluding man-in-the-middle, selective misbehavior, and coordinated attacksdemonstrate the superiority of the proposed framework. When benchmarked against established algorithms such as BTCMV, MSTFM, and TOW, our method achieves consistently higher performance, with precision, recall, and F-score metrics all sustaining values above 82 percent. Kaixuan Luo, Chuanxiang Ma |
TrustCom | 1 |
| 2025 | Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau, Julien Lecomte |
USENIX Security Symposium | 1 |
| 2024 | Living a Lie: Security Analysis of Facial Liveness Detection Systems in Mobile Apps
Xianbo Wang, Kaixuan Luo, Wing Cheong Lau |
ACNS (3) | 2 |
| 2024 | SWIDE: A Semantic-aware Detection Engine for Successful Web Injection AttacksabstractWeb attacks, a primary vector for system breaches, pose a significant challenge within the cybersecurity landscape. The growing intensity of web attack attempts has led to "alert fatigue" where enterprises are inundated by excessive alerts. Although extensive research is being conducted on automated methods for detecting web attacks, it remains an open problem to identify whether the attacks are successful. Towards this end, we present SWIDE (Successful Web Injection Detection Engine), an engine to pinpoint successful web injection attacks (e.g., PHP command injection, SQL injection). This enables enterprises to focus exclusively on those crucial threats. Our methodology builds on two insights: Firstly, while attackers tend to apply payload obfuscation techniques to evade detection, all successful web injection attacks must comply with the programming language syntax to be executable; Secondly, these attacks inevitably produce observable effects, such as returning execution result or creating backdoors for future access by the attacker. Consequently, we leverage advanced syntactic and semantic analysis to 1) detect malicious syntax features in obfuscated payloads and 2) perform semantic analysis of the payload to recover the intention of the attack. With a two-stage design, namely, attack identification and confirmation mechanisms, SWIDE can accurately identify successful attacks, even amidst intricate obfuscations. Unlike proof-of-concept studies, SWIDE has been deployed and validated in real-world environments through collaborations with a cybersecurity firm. Serving 5,045 enterprise users, our system identifies that roughly 15% of enterprises have suffered from successful attacks on a weekly basis - an alarmingly high rate. Moreover, we perform a detailed analysis of six months' data and discover 60 zero-day vulnerabilities exploited in the wild, including 12 high-risk ones acknowledged by relevant authorities. These findings underscore the practical effectiveness of SWIDE. Ronghai Yang, Xianbo Wang, Kaixuan Luo, Jiayuan Xin, Wing Cheong Lau |
CCS | 3 |
| 2023 | Effective Isolation of Fault-Correlated Variables via Statistical and Mutation AnalysisabstractIt is a widely-adopted strategy for developers to monitor the values of program variables when debugging in practice. In particular, developers often set breakpoints at specific locations or execute the program step by step in the debugging mode to inspect if abnormal values or status will be observed for concerned variables. Such a practical debugging strategy can facilitate developers in understanding and localizing the target fault. This study aims to identify suspicious program variables of a given fault (i.e., denoted asfault-correlated variables) automatically, thus facilitating the debugging activities for developers. To the best of our knowledge, this is the finest granularity in fault localization (FL) so far, which can address the limitations of being coarse-grained as faced by existing FL techniques. However, isolating fault-correlated variables precisely is challenging since there are usually substantially different variables used or defined in a program, and plenty of them are in the same basic block which cannot be well discriminated from each other since they will be either executed or not against the given test suite. To address such challenges, this study presentsIsoVar, a two-phase model to isolate fault-correlated variables. Specifically,IsoVar first performs statistical analysis based onvariable execution matrices, which is a novel concept proposed in this study, to identify a set of suspicious variables. It then observes the impacts of those variables on the program dynamically after applying subtle mutations at the bytecode level, to further isolate fault-correlated variables. Extensive experiments on Defects4J and Bears demonstrate thatIsoVar can outperform state-of-the-art techniques significantly ($13.0\%$for MAP and$19.3\%$for MRR). More importantly, we incorporatedIsoVar into 11 existing FL techniques as well as 14 automated program repair techniques, and found thatIsoVar can significantly boost their performance. Ming Wen 0001, Zifan Xie, Kaixuan Luo, Xiao Chen 0026, Yibiao Yang, Hai Jin 0001 |
IEEE Trans. Software Eng. | 3 |