VLDB 2026 Research / reviewers in the wild / expert
Sihan Xu
dblp:168/6400
· DBLP profile ↗
34ranked-venue papers
8as first author
24since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 17 · 5 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 9 · 2 first-author · 8 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Immediate Activation: Temporally Decoupled Backdoor Attacks on Time Series ForecastingabstractExisting backdoor attacks on multivariate time series (MTS) forecasting enforce strict temporal and dimensional coupling between triggers and target patterns, requiring synchronous activation at fixed positions across variables. However, realistic scenarios often demand delayed and variable-specific activation. We identify this critical unmet need and propose TDBA, a temporally decoupled backdoor attack framework for MTS forecasting. By injecting triggers that encode the expected location of the target pattern, TDBA enables the activation of the target pattern at any positions within the forecasted data, with the activation position flexibly varying across different variable dimensions. TDBA introduces two core modules: (1) a position-guided trigger generation mechanism that leverages smoothed Gaussian priors to generate triggers that are position-related to the predefined target pattern; and (2) a position-aware optimization module that assigns soft weights based on trigger completeness, pattern coverage, and temporal offset, facilitating targeted and stealthy attack optimization. Extensive experiments on real-world datasets show that TDBA consistently outperforms existing baselines in effectiveness while maintaining good stealthiness. Ablation studies confirm the controllability and robustness of its design. Xuanlin Liu, Sihan Xu, Yaqiong Qiao, Ying Zhang 0015, Xiangrui Cai |
AAAI | 3 |
| 2026 | Rethinking software misconfigurations in the real world: an empirical study and literature analysis
Yuhao Liu 0007, Yingnan Zhou, Hanfeng Zhang, Zhiwei Chang, Sihan Xu, Yan Jia 0009, Wei Wang 0012, Juncheng Hu 0002, Zheli Liu |
Empir. Softw. Eng. | 5 |
| 2025 | LFT4POI: Multimodal POI Recommendation via Large Language Model Fine-Tuning
Chuanchang Zhang, Xuan Pan, Sihan Xu, Xiangrui Cai |
WISA | 4 |
| 2025 | 4D-LRM: Large Space-Time Reconstruction Model From and To Any View at Any TimeabstractCan we scale 4D pretraining to learn general space-time representations that reconstruct an object from a few views at some times to any view at any time? We provide an affirmative answer with 4D-LRM, the first large-scale 4D reconstruction model that takes input from unconstrained views and timestamps and renders arbitrary novel view-time combinations. Unlike prior 4D approaches, e.g., optimization-based, geometry-based, or generative, that struggle with efficiency, generalization, or faithfulness, 4D-LRM learns a unified space-time representation and directly predicts per-pixel 4D Gaussian primitives from posed image tokens across time, enabling fast, high-quality rendering at, in principle, infinite frame rate. Our results demonstrate that scaling spatiotemporal pretraining enables accurate and efficient 4D reconstruction. We show that 4D-LRM generalizes to novel objects, interpolates across time, and handles diverse camera setups. It reconstructs 24-frame sequences in one forward pass with less than 1.5 seconds on a single A100 GPU. Ziqiao Ma 0001, Xuweiyi Chen, Shoubin Yu, Sai Bi, Kai Zhang 0045, Sihan Xu, Zexiang Xu, Kalyan Sunkavalli, Mohit Bansal, Joyce Y. Chai, Hao Tan 0002 |
NeurIPS | 7 |
| 2025 | A learning-based algorithm for turn-based orbital pursuit-evasion problem with reaction-time delay
Liran Zhao, Qinbo Sun, Sihan Xu, Zhaohui Dang |
Eng. Appl. Artif. Intell. | 3 |
| 2024 | Inversion-Free Image Editing with Language-Guided Diffusion ModelsabstractDespite recent advances in inversion-based editing, text-guided image manipulation remains challenging for diffusion models. The primary bottlenecks include 1) the time-consuming nature of the inversion process; 2) the struggle to balance consistency with accuracy; 3) the lack of compatibility with efficient consistency sampling methods used in consistency models. To address the above issues, we start by asking ourselves if the inversion process can be eliminated for editing. We show that when the initial sample is known, a special variance schedule reduces the denoising step to the same form as the multi-step consistency sam- pling. We name this Denoising Diffusion Consistent Model (DDCM), and note that it implies a virtual inversion strat-egy without explicit inversion in sampling. We further unify the attention control mechanisms in a tuning-free framework for text-guided editing. Combining them, we present inversion-free editing (InfEdit), which allows for consistent and faithful editing for both rigid and non-rigid semantic changes, catering to intricate modifications without compromising on the image's integrity and explicit inversion. Through extensive experiments, InfEdit shows strong performance in various editing tasks and also maintains a seamless workflow (less than 3 seconds on one single A40), demonstrating the potential for real-time applications. Sihan Xu, Yidong Huang, Jiayi Pan 0002, Ziqiao Ma 0001, Joyce Y. Chai |
CVPR | 1 |
| 2024 | Multi-Object Hallucination in Vision Language ModelsabstractLarge vision language models (LVLMs) often suffer from object hallucination, producing objects not present in the given images.
While current benchmarks for object hallucination primarily concentrate on the presence of a single object class rather than individual entities, this work systematically investigates multi-object hallucination, examining how models misperceive (e.g., invent nonexistent objects or become distracted) when tasked with focusing on multiple objects simultaneously.
We introduce Recognition-based Object Probing Evaluation (ROPE), an automated evaluation protocol that considers the distribution of object classes within a single image during testing and uses visual referring prompts to eliminate ambiguity.
With comprehensive empirical studies and analysis of potential factors leading to multi-object hallucination, we found that (1) LVLMs suffer more hallucinations when focusing on multiple objects compared to a single object.
(2) The tested object class distribution affects hallucination behaviors, indicating that LVLMs may follow shortcuts and spurious correlations.
(3) Hallucinatory behaviors are influenced by data-specific factors, salience and frequency, and model intrinsic behaviors.
We hope to enable LVLMs to recognize and reason about multiple objects that often occur in realistic visual scenes, provide insights, and quantify our progress towards mitigating the issues. Xuweiyi Chen, Ziqiao Ma 0001, Xuejun Zhang 0003, Sihan Xu, Shengyi Qian 0001, David F. Fouhey, Joyce Y. Chai |
NeurIPS | 4 |
| 2024 | Low-cost fuzzing drone control system for configuration errors threatening flight safety in edge terminals
Zhiwei Chang, Hanfeng Zhang, Yan Jia 0009, Sihan Xu, Tong Li 0011, Zheli Liu |
Comput. Commun. | 4 |
| 2024 | LAN: Learning Adaptive Neighbors for Real-Time Insider Threat DetectionabstractEnterprises and organizations are faced with potential threats from insider employees that may lead to serious consequences. Previous studies on insider threat detection (ITD) mainly focus on detecting abnormal users or abnormal time periods (e.g., a week or a day). However, a user may have hundreds of thousands of activities in the log, and even within a day there may exist thousands of activities for a user, requiring a high investigation budget to verify abnormal users or activities given the detection results. On the other hand, existing works are mainly post-hoc methods rather than real-time detection, which can not report insider threats in time before they cause loss. In this paper, we conduct the first study towards real-time ITD at activity level, and present a fine-grained and efficient framework LAN. Specifically, LAN simultaneously learns the temporal dependencies within an activity sequence and the relationships between activities across sequences with graph structure learning. Moreover, to mitigate the data imbalance problem in ITD, we propose a novel hybrid prediction loss, which integrates self-supervision signals from normal activities and supervision signals from abnormal activities into a unified loss for anomaly detection. We evaluate the performance of LAN on two widely used datasets, i.e., CERT r4.2 and CERT r5.2. Extensive and comparative experiments demonstrate the superiority of LAN, outperforming 9 state-of-the-art baselines by at least 8.43% and 6.35% in AUC for real-time ITD on CERT r4.2 and r5.2, respectively. Moreover, LAN can be also applied to post-hoc ITD, surpassing 8 competitive baselines by at least 7.70% and 4.03% in AUC on two datasets. Finally, the ablation study, parameter analysis, and compatibility analysis evaluate the impact of each module and hyper-parameter in LAN. The source code can be obtained fromhttps://github.com/Li1Neo/LAN. Xiangrui Cai, Yang Wang 0128, Sihan Xu, Hao Li 0027, Ying Zhang 0015, Zheli Liu, Xiaojie Yuan |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | GeoCo: Geographical Correlation Enhanced Network for POI RecommendationabstractUser mobility behaviors frequently exhibit a spatial clustering phenomenon, wherein points of interest (POIs) visited by the same user tend to be in close proximity. Consequently, leveraging geographical influences for user preference modeling remains a prevalent approach in POI recommendation tasks. However, existing studies often overlook users’ hidden geographical habits for the following reasons: (1) Geographical features are commonly approximated by manually partitioned regions or fixed distributions, inadequately capturing the nuanced spatial proximity among POIs. (2) POIs with high geographical correlations are not explicitly incorporated as feedback signals during the training process, resulting in a lack of spatial clustering pattern learning within users’ preference representations. This paper introduces GeoCo, aGeographicalCorrelation enhanced network for POI recommendation. First, we model POIs’ geographical features using fine-grained hierarchical sequences to capture multilevel spatial relations. Subsequently, we propose a pre-training network that employs the sentence similarity assessment technique to comprehend the semantics of geographical correlations. Second, we introduce a novel multi-objective training process that intuitively learns spatial clustering patterns through user mobility behaviors. Extensive experiments conducted on two location-based social network (LBSN) datasets, Gowalla and Foursquare, demonstrate the superiority of our proposed model over fourteen state-of-the-art baseline models in POI recommendation tasks. Compared with the baselines, GeoCo has achieved a performance improvement of at least 5$\%$in Rec@5 and HR@5 on both datasets. Furthermore, we verify the effectiveness of pre-trained location vectors and the multi-objective training process in enhancing the model's understanding of geographical correlations for user preference construction. Xuan Pan, Xiangrui Cai, Sihan Xu, Ying Zhang 0015, Xiaojie Yuan |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2024 | Can Coverage Criteria Guide Failure Discovery for Image Classifiers? An Empirical StudyabstractQuality assurance of deep neural networks (DNNs) is crucial for the deployment of DNN-based software, especially in mission- and safety-critical tasks. Inspired by structural white-box testing in traditional software, many test criteria have been proposed to test DNNs, i.e., to exhibit erroneous behaviors by activating new test units that have not been covered, such as new neurons, values, and decision paths. Many studies have been done to evaluate the effectiveness of DNN test coverage criteria. However, existing empirical studies mainly focused on measuring the effectiveness of DNN test criteria for improving the adversarial robustness of DNNs, while ignoring the correctness property when testing DNNs. To fill in this gap, we conduct a comprehensive study on 11 structural coverage criteria, 6 widely-used image datasets, and 9 popular DNNs. We investigate the effectiveness of DNN coverage criteria over natural inputs from four aspects: (1) the correlation between test coverage and test diversity; (2) the effects of criteria parameters and target DNNs; (3) the effectiveness to prioritize in-distribution natural inputs that lead to erroneous behaviors; and (4) the capability to detect out-of-distribution natural samples. Our findings include: (1) For measuring the diversity, coverage criteria considering the relationship between different neurons are more effective than coverage criteria that treat each neuron independently. For instance, the neuron-path criteria (i.e., SNPC and ANPC) show high correlation with test diversity, which is promising to measure test diversity for DNNs. (2) The hyper-parameters have a big influence on the effectiveness of criteria, especially those relevant to the granularity of test criteria. Meanwhile, the computational complexity is one of the important issues to be considered when designing deep learning test coverage criteria, especially for large-scale models. (3) Test criteria related to data distribution (i.e., LSA and DSA, SNAC, and NBC) can be used to prioritize both in-distribution natural faults and out-of-distribution inputs. Furthermore, for OOD detection, the boundary metrics (i.e., SNAC and NBC) are also effective indicators with lower computational costs and higher detection efficiency compared with LSA and DSA. These findings motivate follow-up research on scalable test coverage criteria that improve the correctness of DNNs. Sihan Xu, Lingling Fan 0003, Xiangrui Cai, Linyu Li 0002, Zheli Liu |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2024 | Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party LibrariesabstractDevelopers usually use third-party libraries (TPLs) to facilitate the development of their projects to avoid reinventing the wheels, however, the vulnerable TPLs indeed cause severe security threats. The majority of existing research only considered whether projects used vulnerable TPLs but neglected whether the vulnerable code of the TPLs was indeed used by the projects, which inevitably results in false positives and further requires additional patching efforts and maintenance costs (e.g., dependency conflict issues after version upgrades). To mitigate such a problem, we proposeVAScanner, which can effectively identify vulnerable root methods causing vulnerabilities in TPLs and further identify all vulnerable APIs of TPLs used by Java projects. Specifically, we first collect the initial patch methods from the patch commits and extract accurate patch methods by employing a patch-unrelated sifting mechanism, then we further identify the vulnerable root methods for each vulnerability by employing an augmentation mechanism. Based on them, we leverage backward call graph analysis to identify all vulnerable APIs for each vulnerable TPL version and construct a database consisting of 90,749 (2,410,779 with library versions) vulnerable APIswith 1.45% false positive proportion with a 95% confidence interval (CI) of [1.31%, 1.59%] from 362 TPLs with 14,775 versions. The database serves as a reference database to help developers detect vulnerable APIs of TPLs used by projects. Our experiments showVAScannereliminates 5.78% false positives and 2.16% false negatives owing to the proposed sifting and augmentation mechanisms. Besides, it outperforms the state-of-the-art method-level vulnerability detection tool in analyzing direct dependencies, Eclipse Steady, achieving more effective detection of vulnerable APIs. Furthermore, to investigate the real impact of vulnerabilities on real open-source projects, we exploitVAScannerto conduct a large-scale analysis on 3,147 projects that depend on vulnerable TPLs, and find only 21.51% of projects (with 1.83% false positive proportion and a 95% CI of [0.71%, 4.61%]) were threatened through vulnerable APIs, demonstrating thatVAScannercan potentially reduce false positives significantly. Lingling Fan 0003, Sen Chen 0001, Miaoying Cai, Sihan Xu, Lida Zhao |
IEEE Trans. Software Eng. | 5 |
| 2023 | Compatibility Issue Detection for Android Apps Based on Path-Sensitive Semantic AnalysisabstractAndroid API-related compatibility issues have be-come a severe problem and significant challenge for app devel-opers due to the well-known Android fragmentation issues. To address this problem, many effective approaches such as app-based and API lifetime-based methods have been proposed to identify incompatible API usages. However, due to the various implementations of API usages and different API invoking paths, there is still a significant weakness of existing approaches, i.e., introducing a massive number of false positives (FP) and false negatives (FN). To this end, in this paper, we propose PSDroid, an automated compatibility detection approach for Android apps, which aims to reduce FPs and FNs by overcoming several technical bottlenecks. Firstly, we make substantial efforts to carry out a preliminary study to summarize a set of novel API usages with diverse checking implementations. Secondly, we construct a refined API lifetime database by leveraging a semantic resolving analysis on all existing Android SDK frameworks. Based on the above two key phases, we design and implement a novel path-sensitive semantic approach to effectively and automatically detect incompatibility issues. To demonstrate the performance, we compared with five existing approaches (i.e., FicFinder, ACRYL, CIDER, IctAPIFinder, and CID) and the results show that PSDroid outperforms existing tools. We also conducted an in-depth root cause analysis to comprehensively explain the ability of PSDroid in reducing FPs and FNs. Finally, 18/30 reported issues have been confirmed and further fixed by app developers. Sen Chen 0001, Lingling Fan 0003, Sihan Xu, Zhanwei Hui |
ICSE | 4 |
| 2023 | LiResolver: License Incompatibility Resolution for Open Source SoftwareabstractOpen source software (OSS) licenses regulate the conditions under which OSS can be legally reused, distributed, and modified. However, a common issue arises when incorporating third-party OSS accompanied with licenses, i.e., license incompatibility, which occurs when multiple licenses exist in one project and there are conflicts between them. Despite being problematic, fixing license incompatibility issues requires substantial efforts due to the lack of license understanding and complex package dependency. In this paper, we propose LiResolver, a fine-grained, scalable, and flexible tool to resolve license incompatibility issues for open source software. Specifically, it first understands the semantics of licenses through fine-grained entity extraction and relation extraction. Then, it detects and resolves license incompatibility issues by recommending official licenses in priority. When no official licenses can satisfy the constraints, it generates a custom license as an alternative solution. Comprehensive experiments demonstrate the effectiveness of LiResolver, with 4.09% false positive (FP) rate and 0.02% false negative (FN) rate for incompatibility issue localization, and 62.61% of 230 real-world incompatible projects resolved by LiResolver. We discuss the feedback from OSS developers and the lessons learned from this work. All the datasets and the replication package of LiResolver have been made publicly available to facilitate follow-up research. Sihan Xu, Lingling Fan 0003, Linyu Li 0002, Xiangrui Cai, Zheli Liu |
ISSTA | 1 |
| 2023 | LiSum: Open Source Software License Summarization with Multi-Task LearningabstractOpen source software (OSS) licenses regulate the conditions under which users can reuse, modify, and distribute the software legally. However, there exist various OSS licenses in the community, written in a formal language, which are typically long and complicated to understand. In this paper, we conducted a 661-participants online survey to investigate the perspectives and practices of developers towards OSS licenses. The user study revealed an indeed need for an automated tool to facilitate license understanding. Motivated by the user study and the fast growth of licenses in the community, we propose the first study towards automated license summarization. Specifically, we released the first high quality text summarization dataset and designed two tasks, i.e., license text summarization (LTS), aiming at generating a relatively short summary for an arbitrary license, and license term classification (LTC), focusing on the attitude inference towards a predefined set of key license terms (e.g., Distribute). Aiming at the two tasks, we present LiSum, a multi-task learning method to help developers overcome the obstacles of understanding OSS licenses. Comprehensive experiments demonstrated that the proposed jointly training objective boosted the performance on both tasks, surpassing state-of-the-art baselines with gains of at least 5 points w.r.t. F1 scores of four summarization metrics and achieving 95.13% micro average F1 score for classification simultaneously. We released all the datasets, the replication package, and the questionnaires for the community. Linyu Li 0002, Sihan Xu, Yang Liu 0003, Xiangrui Cai, Jiarun Wu, Wenli Song, Zheli Liu |
ASE | 2 |
| 2023 | CycleNet: Rethinking Cycle Consistency in Text-Guided Diffusion for Image ManipulationabstractDiffusion models (DMs) have enabled breakthroughs in image synthesis tasks but lack an intuitive interface for consistent image-to-image (I2I) translation. Various methods have been explored to address this issue, including mask-based methods, attention-based methods, and image-conditioning. However, it remains a critical challenge to enable unpaired I2I translation with pre-trained DMs while maintaining satisfying consistency. This paper introduces Cyclenet, a novel but simple method that incorporates cycle consistency into DMs to regularize image manipulation. We validate Cyclenet on unpaired I2I tasks of different granularities. Besides the scene and object level translation, we additionally contribute a multi-domain I2I translation dataset to study the physical state changes of objects. Our empirical studies show that Cyclenet is superior in translation consistency and quality, and can generate high-quality images for out-of-domain distributions with a simple change of the textual prompt. Cyclenet is a practical framework, which is robust even with very limited training data (around 2k) and requires minimal computational resources (1 GPU) to train. Project homepage: https://cyclenetweb.github.io/ Sihan Xu, Ziqiao Ma 0001, Yidong Huang, Honglak Lee, Joyce Y. Chai |
NeurIPS | 1 |
| 2023 | Metapath-aggregated heterogeneous graph neural network for drug-target interaction predictionabstractDrug-target interaction (DTI) prediction is an essential step in drug repositioning. A few graph neural network (GNN)-based methods have been proposed for DTI prediction using heterogeneous biological data. However, existing GNN-based methods only aggregate information from directly connected nodes restricted in a drug-related or a target-related network and are incapable of capturing high-order dependencies in the biological heterogeneous graph. In this paper, we propose a metapath-aggregated heterogeneous graph neural network (MHGNN) to capture complex structures and rich semantics in the biological heterogeneous graph for DTI prediction. Specifically, MHGNN enhances heterogeneous graph structure learning and high-order semantics learning by modeling high-order relations via metapaths. Additionally, MHGNN enriches high-order correlations between drug-target pairs (DTPs) by constructing a DTP correlation graph with DTPs as nodes. We conduct extensive experiments on three biological heterogeneous datasets. MHGNN favorably surpasses 17 state-of-the-art methods over 6 evaluation metrics, which verifies its efficacy for DTI prediction. The code is available at https://github.com/Zora-LM/MHGNN-DTI. Xiangrui Cai, Sihan Xu, Hua Ji |
Briefings Bioinform. | 3 |
| 2023 | LiDetector: License Incompatibility Detection for Open Source SoftwareabstractOpen-source software (OSS) licenses dictate the conditions, which should be followed to reuse, distribute, and modify software. Apart from widely-used licenses such as the MIT License, developers are also allowed to customize their own licenses (called custom license), whose descriptions are more flexible. The presence of such various licenses imposes challenges to understand licenses and their compatibility. To avoid financial and legal risks, it is essential to ensure license compatibility when integrating third-party packages or reusing code accompanied with licenses. In this work, we propose LiDetector , an effective tool that extracts and interprets OSS licenses (including both official licenses and custom licenses), and detects license incompatibility among these licenses. Specifically, LiDetector introduces a learning-based method to automatically identify meaningful license terms from an arbitrary license, and employs Probabilistic Context-Free Grammar (PCFG) to infer rights and obligations for incompatibility detection. Experiments demonstrate that LiDetector outperforms existing methods with 93.28% precision for term identification, and 91.09% accuracy for right and obligation inference, and can effectively detect incompatibility with 10.06% FP rate and 2.56% FN rate. Furthermore, with LiDetector , our large-scale empirical study on 1,846 projects reveals that 72.91% of the projects are suffering from license incompatibility, including popular ones such as the MIT License and the Apache License. We highlighted lessons learned from perspectives of different stakeholders and made all related data and the replication package publicly available to facilitate follow-up research. Sihan Xu, Lingling Fan 0003, Zheli Liu, Yang Liu 0003, Hua Ji |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2023 | Multi-Misconfiguration Diagnosis via Identifying Correlated Configuration ParametersabstractSoftware configuration requires that the user sets appropriate values to specified variables, known as configuration parameters, which potentially affect the behaviors of software system. It is an essential means for software reliability, but how to ensure correct configurations remains a great challenge, especially when a large number of parameter settings are involved. Existing studies on misconfiguration diagnosis treat all configurations independently, ignoring the constraints and correlations among different configurations. In this article, we reveal the phenomenon of multi-misconfigurations and present a tool, MMD, for multi-misconfigurations diagnosis. Specifically, MMD consists of two modules: Correlated Configurations Analysis and Primary Misconfigurations Diagnosis. The former determines the correlation among each pair of configurations by analyzing the control and data flows related to each configuration. The latter is responsible for collecting a list of configurations ranked according to their suspiciousness. Combining the outputs of two modules, MMD is able to assist the user in multi-misconfigurations diagnosis. We evaluate MMD on seven popular Java projects: Randoop, Soot, Synoptic, Hdfs, Hbase, Yarn, and Zookeeper. MMD identifies 510 configuration correlations with a 4.9% false positive rate. Furthermore, it effectively diagnoses 22 multi-misconfigurations collected from StackOverflow, outperforming two state-of-the-art baselines. Yingnan Zhou, Sihan Xu, Yan Jia 0009, Yuhao Liu 0007, Guangquan Xu, Wei Wang 0012, Shaoying Liu, Thar Baker |
IEEE Trans. Software Eng. | 3 |
| 2022 | Contrastive Meta-Learning for Drug-Target Binding Affinity PredictionabstractEffective drug-target binding affinity (DTA) prediction is essential for drug discovery and development. The development of machine learning techniques considerably advances it. However, the cold-start problems in DTA prediction are still under-explored, which significantly degrades prediction performances on novel drugs and novel targets. In this paper, we propose a contrastive meta-learning (CML) framework to address these issues. We define drug-anchored tasks and target-anchored tasks, which enables the employment of meta-learning to accumulate common knowledge from various tasks so as to adapt to new tasks faster and better. Besides, we utilize a task inequality loss to measure task disparities and enhance model sensitivities to new tasks. We also propose a contrastive learning block (CLB) to explore correlations among drug-target pairs across tasks, which facilitates DTA prediction performance improvements. We compare CML with various baselines on two benchmarks and comparison results show that CML outperforms or achieves competitive results to its competitors. Sihan Xu, Xiangrui Cai, Zhong Zhang 0001, Hua Ji |
BIBM | 2 |
| 2022 | Heterogeneous Graph Attention Network for Drug-Target Interaction PredictionabstractIdentification of drug-target interactions (DTIs) is crucial for drug discovery and drug repositioning. Existing graph neural network (GNN) based methods only aggregate information from directly connected nodes restricted in a drug-related or a target-related network, and are incapable of capturing long-range dependencies in the biological heterogeneous graph. In this paper, we propose the heterogeneous graph attention network (HGAN) to capture the complex structures and rich semantics in the biological heterogeneous graph for DTI prediction. HGAN enhances heterogeneous graph structure learning from both the intra-layer perspective and the inter-layer perspective. Concretely, we develop an enhanced graph attention diffusion layer (EGADL), which efficiently builds connections between node pairs that may not be directly connected, enabling information passing from important nodes multiple hops away. By stacking multiple EGADLs, we further enlarge the receptive field from the inter-layer perspective. HGAN advances 15 state-of-the-art methods on two heterogeneous biological datasets, achieving the results near to 1 in terms of AUC and AUPR. We also find that enlarging receptive fields from the inter-layer perspective (stacking layers) is more effective than that from the intra-layer perspective (attention diffusion) for HGAN to achieve promising DTI prediction performances. The code is available at https://github.com/Zora-LM/HGAN-DTI. Xiangrui Cai, Linyu Li 0002, Sihan Xu, Hua Ji |
CIKM | 4 |
| 2022 | BadPrompt: Backdoor Attacks on Continuous PromptsabstractThe prompt-based learning paradigm has gained much research attention recently. It has achieved state-of-the-art performance on several NLP tasks, especially in the few-shot scenarios. While steering the downstream tasks, few works have been reported to investigate the security problems of the prompt-based models. In this paper, we conduct the first study on the vulnerability of the continuous prompt learning algorithm to backdoor attacks. We observe that the few-shot scenarios have posed a great challenge to backdoor attacks on the prompt-based models, limiting the usability of existing NLP backdoor methods. To address this challenge, we propose BadPrompt, a lightweight and task-adaptive algorithm, to backdoor attack continuous prompts. Specially, BadPrompt first generates candidate triggers which are indicative for predicting the targeted label and dissimilar to the samples of the non-targeted labels. Then, it automatically selects the most effective and invisible trigger for each sample with an adaptive trigger optimization algorithm. We evaluate the performance of BadPrompt on five datasets and two continuous prompt models. The results exhibit the abilities of BadPrompt to effectively attack continuous prompts while maintaining high performance on the clean test sets, outperforming the baseline models by a large margin. The source code of BadPrompt is publicly available. Xiangrui Cai, Haidong Xu, Sihan Xu, Ying Zhang 0015, Xiaojie Yuan |
NeurIPS | 3 |
| 2022 | DeepSuite: A Test Suite Optimizer for Autonomous VehiclesabstractDeep learning (DL) brings autonomous vehicles (AVs) close to reality. However, the witness of many safety issues has raised a big concern about the reliability of AVs. To solve this problem, much research has been done to test deep learning-driven AVs. Generally, once a test input is produced, a developer needs to manually check its expected output. However, there often exists massive unlabeled test data (e.g., raw context traces in the real world). It is impractical to manually label all test inputs. Despite some works on automatic generation of test oracles, they are either task-specific or constrained to synthetic inputs. In this paper, we present a general and extensible framework,DeepSuite, to mitigate the manual effort of generating test oracles. The intuition behind is that not all test inputs are equally worth labelling. With limited testing budget, it is desirable to label a test suite with high diversity and a reasonable size. Due to the large search space, to optimize such test suites is of great challenge. To address it,DeepSuiteemploys a three-phase optimization method (i.e., selection, crossover, and mutation) to iteratively select representative but non-redundant test suites. Such conflicting profit/cost objectives are attained through a genetic algorithm with a well-defined multi-objective fitness function. In the experiments, we first show that the diversity of tests can be revealed by test criteria. Then, experiments on three widely-used datasets demonstrated the effectiveness ofDeepSuitein generating test suites with competitive testing coverage and 68.42% smaller size, which greatly improves the data collection efficiency of testing DL-driven autonomous vehicles. Sihan Xu, Lingling Fan 0003, Xiangrui Cai, Hua Ji, Siau-Cheng Khoo, Brij B. Gupta |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2021 | Effective Multi-Fault Localization Based on Fault-Relevant StatisticsabstractFault localization can facilitate software debugging and thus is a key technology in software maintenance. Spectrum-based fault localization (SBFL) has been known as an effective and lightweight approach. Nevertheless, the existence of multiple faults within the same system is still the bottleneck of SBFL. Inspired by feature selection in data mining, this paper improves the Relief algorithm and proposes fault-relevant statistics (FRS) to calculate the suspiciousness of program elements. Specifically, it takes test cases as samples, execution results as labels, and spectrum information as features, so that the problem of multi-fault localization can be viewed as a feature selection problem. Unlike the clustering method, this paper only takes into account the closest failing and successful case for each sampled test case when computing FRS. Experiments on open source software systems show that FRS improves the efficiency of fault localization with low computational cost. Sihan Xu, Xiangrui Cai, Hua Ji |
COMPSAC | 1 |
| 2020 | Respiratory Sound Classification Based on BiGRU-Attention Network with XGBoostabstractIn recent years, the mortality rate of respiratory diseases ranks high among the major diseases. Early detection of respiratory diseases is a key factor in reducing the mortality rate and curing diseases. In this paper, we propose the BiGRU Attention-XGBoost model to classify respiratory sounds, in order to assist doctors in the early diagnosis of respiratory diseases. Specifically, we first extract two sets of features, i.e., the time domain and spectral features to encode respiratory sounds. Then, we apply the Gradient Boosting Decision Tree algorithm to select important features for classification. Based on the temporal characteristics of respiratory sounds, we design the BiGRU Attention-XGBoost model to classify them. Finally, to enlarge the training dataset and address the problem of data imbalance, we also implement Griffifin-Lim and WORLD Vocoder, two data augmentation methods. Extensive experiments show the superiority of the proposed model compared to seven state-of the-art models in terms of classification accuracy and Fl-score. Xuesong Zhao, Yanbo Shao, Juanyun Mai, Airu Yin, Sihan Xu |
BIBM | 5 |
| 2019 | AutoPer: Automatic Recommender for Runtime-Permission in Android ApplicationsabstractPermission mechanisms serve as the main measure to protect users privacy and security in Android applications. Modern smartphone operating systems (Android 6.0 and later versions) prompt users to regulate permissions using ask-on-first-use policy. Much research has been done to dynamically regulate permissions depending on user preferences and contexts in modern operation systems. However, all these techniques have limitations-they heavily rely on users' current or historical decisions on granting permissions, ignoring the fact that users are not experts on privacy protection, i.e., whether a permission shall be granted. In this work, we propose a system to automatically recommend runtime-permission to users. The main idea behind is that the application descriptions reflecting functional information can be used to analyze whether a permission is needed by the application. In more details, using description mining, we extract multiple topics and build a topic-permission mapper. Given an application as input, we first decide which topics it belongs to and then recommend the permissions according to the topic-permission mapper. As the output, besides binary recommendation of "allow" or "deny" recommendations, we provide explanations for the recommendations to uncover the reason for users. We implemented our approach in a tool- AutoPer, and evaluated the approach using 28,850 Android applications from Google Play. The experiments show that our approach achieves a fairly good performance with an accuracy of 81.0%, which demonstrates the effectiveness of AutoPer for permission recommendation. Hongcan Gao, Chenkai Guo, Naipeng Dong, Xiaolei Hou, Sihan Xu, Jing Xu 0008 |
COMPSAC (1) | 6 |
| 2018 | High-Frequency Keywords to Predict Defects for Android ApplicationsabstractAndroid defect prediction has proved to be useful to reduce the manual testing effort for finding bugs. In recent years, researchers design metrics related to defects and analyze historical information to predict whether files contain defects using machine learning. However, those models learn to predict defects based on the characteristics of programs while ignoring the internal information, e.g., the functional and semantic information within the source code. This paper proposes a model, HIRER, to learn the functional and semantic information to predict whether files contain defects automatically for Android applications. Specifically, HIRER learns internal information within the source code based on the high-frequency keywords extracted from programs' Abstract Syntax Trees (ASTs). It gets rule-based programming patterns from high-frequency keywords and uses Deep Belief Network (DBN), a deep neutral network, to learn functional and semantic features from the programming patterns. We implement a defect testing system with five machine learning techniques based on HIRER to predict defective files in source code automatically. Then, we apply it on four open source Android applications. The results show that learned functional and semantic features can predict more defects than traditional metrics. In different versions of MMS, Gallery2, Bluetooth, Calendar open source applications, HIRER improves the AUC of the predicted results respectively in average. Yaqing Fan, Xinya Cao, Jing Xu 0008, Sihan Xu |
COMPSAC (2) | 4 |
| 2018 | TRAC: A Therapeutic Regimen-Oriented Access Control Model in HealthcareabstractAccess control is a significant strategy to protect security and privacy. Due to electronization of health information, medical access control attracts lots of attention in the research community. The existing medical access control approaches mainly focus on doctors' roles and behaviors, such as role-based access control (RBAC) and risk-based access control. However, various therapeutic regimens can also lead to unauthorized access. The current researches do not consider access control authorization in terms of therapeutic regimens. In this work, we present an access control model based on therapeutic regimen. Our model, TRAC, proposes an access strategy by analyzing feasibility of therapeutic regimens. Our experiments show the effectiveness of TRAC in terms of precision. Moreover, our model also contributes to choosing better therapeutic regimens for patients. Hongcan Gao, Sihan Xu, Chenkai Guo, Xiaolei Hou, Jing Xu 0008 |
COMPSAC (2) | 3 |
| 2018 | A Projection-Based Approach for Memory Leak DetectionabstractOne of the major software safety issues is memory leak. Moreover, detecting memory leak vulnerabilities is challenging in static analysis. Existing static detection tools find bugs by collecting programs' information in the process of scanning source code. However, the current detection tools are weak in efficiency and accuracy, especially when the targeted program contains complex branches. This paper proposes a projection-based approach to detect memory leaks in C source code with complex control flows. According to the features of memory allocation and deallocation in C source code, this approach projects the original control flow graph of a program to a simpler one, and it reduces the analysis complexity. Besides, this paper implements a memory-leak detection tool-PML_Checker, and evaluates the tool by comparing with three open-source static detection tools on both public benchmarks and study test cases. The experimental results show that PML_Checker reports the most memory leak vulnerabilities among the four existing tools with complex control flows and complex data types, and PML_Checker obtains higher efficiency and accuracy on public benchmarks. Sihan Xu, Chenkai Guo, Jing Xu 0008, Naipeng Dong, Xiujuan Ji |
COMPSAC (2) | 2 |
| 2017 | An Inferential Metamorphic Testing Approach to Reduce False Positives in SQLIV Penetration TestabstractSQL Injection Vulnerability (SQLIV) has been the top-ranked threat to the Web security consistently for many years. Penetration tests, which are a most widely adopted technique to detect SQLIV, are usually affected by testing inaccuracy. This problem is even worse in inferencebased, blind penetration tests for online Web sites, where Web page variations (such as those caused by inbuilt dynamic modules or user interactions) may lead to a large number of False Positives (FP). We present a novel approach called Inferential Metamorphic Testing (IMT) to reduce FP in SQLIV penetration tests. First, we define the notion of Inferential Metamorphic Relations (IMR), which is inherited from Mutational Metamorphic Testing (MMT). Second, we present a set of logic operators and mutation operators for generating IMR and deducting the background testing context. Finally, we present an iterative IMT process, which is based on the heuristic IMR generation and the background testing context deduction. Our empirical study demonstrates the effectiveness of our approach by a comparison to three famous SQLIV penetration test tools. Guoxin Su, Jing Xu 0008, Jiehui Kang, Sihan Xu, Guannan Si |
COMPSAC (1) | 6 |
| 2017 | GEMS: An Extract Method Refactoring RecommenderabstractExtract Method is a widely used refactoring operation to improve method comprehension and maintenance. Much research has been done to extract codefragments within the method body to form a new method. Criteria used for identifying extractable code is usually centered around degrees of cohesiveness, coupling and length of the method. However, automatic method extraction techniques have not been highly successful, since it can be hard to concretizethe criteria. In this work, we present a novel system that learns these criteria for Extract Method refactorings from open source repositories. We extractstructural and functional features, which encode the concepts of complexity, cohesion and coupling in our learning model, and train it to extract suitablecode fragments from a given source of a method. Our tool, GEMS, recommends a ranked list of code fragments with high accuracy and greatspeed. We evaluated our approach on several open source repositories and compared it against three state-of-the-art approaches-SEMI, JExtract andJDeodorant. The results on these open-source data show the superiority of our machine-learning-based approach in terms of effectiveness. We develop GEMS asan Eclipse plugin, with the intention to support software reliability through method extraction. Sihan Xu, Aishwarya Sivaraman, Siau-Cheng Khoo, Jing Xu 0008 |
ISSRE | 1 |
| 2016 | An Effective Penetration Test Approach Based on Feature Matrix for Exposing SQL Injection VulnerabilityabstractAmong all the Web application security issues, SQL Injection Vulnerability (SQLIV) is one of the most serious problems. How to test SQLIV effectively is of great importance. To address this issue, this paper describes a novel approach that is the utilization of Feature Matrix (FM) model for SQLIV black-box penetration test. Firstly, FM is introduced, which integrates the general SQLIV penetration test features for SQLIV. Each row of the matrix is defined as a test pattern, named Global Test Pattern (GTP). Then, GTP Selection (GTPS) process is used to select legal GTPs for general SQLIV penetration test. Secondly, to find out the optimum FM during SQLIV penetration test procedure automatically, Dynamic Matrix Selection (DMS) algorithm is described, which is based on dynamic tree pruning. Finally, a prototype tool SQLEXP is developed, the experiments of which are carried out under the context of two target Web applications and about 30000 real Internet URLs. The results show that the proposed approach can effectively improve the testing effect for SQLIV penetration test compared with two benchmarking testing tools. Jing Xu 0008, Chenkai Guo, Jiehui Kang, Sihan Xu, Guannan Si |
COMPSAC | 6 |
| 2016 | Fuzzy linguistic induced OWA Minkowski distance operator and its application in group decision making
Sidong Xian, Weijie Sun 0007, Sihan Xu |
Pattern Anal. Appl. | 3 |
| 2015 | An Improvement to Fault Localization Technique Based on Branch-Coverage SpectraabstractFor trust in software, developers spend much effort debugging to ensure that software behaviors as expected. Spectrum-based fault localization techniques (SFL) make use of runtime coverage of program elements, like statements, branches and du-pairs, and then check codes in the order of the rank of suspiciousness. So, correct elements with higher suspiciousness than faulty elements cause the loss of precision. In this paper, we focus on a situation where suspiciousness calculated according to coverage and outcome, i.e. Successful or failing, is higher than it should be. It is found that when a branch structure is repeatedly executed, which is normal in real-life programs, and all of its branches are covered within a run, a branch related to faults could lead other branches to be doubted. To reduce effects between branches, we do the following things: First, we utilize branches to monitor program behaviors, second, we take test cases with high similarities as triggered by the same fault, third, for branches mentioned, we propose an algorithm to infer which branch is more likely to be faulty in the failure, finally, experiments based on Siemens benchmark set and flex show that our approach is useful to heighten the ranking of faulty elements by reducing suspiciousness of correct branches. Sihan Xu, Jing Xu 0008, Jufeng Yang, Chenkai Guo, Liying Yuan, Wenli Song, Guannan Si |
COMPSAC | 1 |