Yongji Liu

dblp:172/1514 · DBLP profile ↗
← Back
18ranked-venue papers
0as first author
17since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 7 since 2021Computer networks · 5 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT Firmware
Jiaqian Peng, Puzhuo Liu, Yicheng Zeng, Yongji Liu, Hongsong Zhu
SP5
2025 HG-Ghost: A Lightweight and Accurate Pose Estimation Network for Biometric Recognition
Yongji Liu
ICIG (2)2
2025 Beyond Macro-Actions: A Bio-Inspired Framework for Fine-Grained Micro-Action Recognition
abstract
Human Action Recognition (HAR) is pivotal in advancing applications from surveillance to healthcare, but predominantly focuses on easily observable, macro-level actions such as running or jumping. Micro-Action Recognition (MAR), however, delves into the subtle, often involuntary motions like postural shifts, brief gestures, or faint facial twitches, which are critical for revealing underlying emotional states, intentions, or stress levels. MAR presents unique challenges due to the ephemeral nature of micro-actions, their fine-grained inter-class similarities, and significant class imbalance. To overcome these obstacles, our approach draws inspiration from the hierarchical and context-sensitive capabilities of the human visual system. We propose a biologically motivated, multi-pathway framework that cohesively integrates global context analysis, rapid temporal scanning, and meticulous fine-grained scrutiny. This framework combines skeletal dynamics, subtle motion amplitude cues, and RGB-based contextual features to enable a comprehensive and robust recognition of micro-actions, even in unconstrained environments. Our experimental results on the MA-52 dataset demonstrate leading performance, significantly advancing MAR research and broadening the spectrum of applications that require a nuanced understanding of human behavior.
Yiwei Ru, Churan Yu, Dongsen Zhang, Mupei Li, Yongji Liu, Zhaofeng He 0001
ICME5
2025 Contextualizing Borderline ECG Analysis via Multi-Modal Feature Extraction and Large Language Model Inference
abstract
Borderline electrocardiograms (ECGs) pose a significant diagnostic challenge, as their waveforms often exhibit subtle deviations that overlap with both normal and pathological patterns. Conventional deep learning models, while adept at detecting common arrhythmias, struggle with these ambiguous cases due to sparse annotations and complex signal morphologies. To address this gap, we propose a multi-modal framework that combines structured feature extraction and large language model (LLM) inference for robust ECG classification. First, we employ specialized libraries to derive morphological markers, interval measurements, and heart rate variability (HRV) parameters from raw ECG data. These features, along with demographic metadata, are then seamlessly integrated into prompts for LLM-based few-shot learning. By embedding quantitative signals into textual templates, the model acquires a contextual understanding that transcends static, threshold-based judgments. Our method not only excels at detecting arrhythmias but also demonstrates enhanced performance in classifying borderline ECGs, guided by expert-validated annotations. Experimental results show that the proposed pipeline effectively mitigates class imbalance and improves interpretability, offering a scalable solution that bridges the divide between conventional signal processing and advanced medical-language reasoning. This integration of numeric features with textual prompts paves the way for more accurate, transparent, and adaptable cardiac diagnostics.
Yanlin Xu, Yiwei Ru, Dongsen Zhang, Yongji Liu, Zhenan Sun
ICME4
2025 CLANet: A Denoising-Driven Framework for Robust mmWave Radar Vital Sign Monitoring
Yiwei Ru, Yongji Liu, Mupei Li, Dongsen Zhang, Zhaofeng He 0001, Zhenan Sun
PRCV (3)2
2025 When LLMs meet cybersecurity: a systematic literature review
abstract
Abstract The rapid development of large language models (LLMs) has opened new avenues across various fields, including cybersecurity, which faces an evolving threat landscape and demand for innovative technologies. Despite initial explorations into the application of LLMs in cybersecurity, there is a lack of a comprehensive overview of this research area. This paper addresses this gap by providing a systematic literature review, covering the analysis of over 300 works, encompassing 25 LLMs and more than 10 downstream scenarios. Our comprehensive overview addresses three key research questions: the construction of cybersecurity-oriented LLMs, the application of LLMs to various cybersecurity tasks, the challenges and further research in this area. This study aims to shed light on the extensive potential of LLMs in enhancing cybersecurity practices and serve as a valuable resource for applying LLMs in this field. We also maintain and regularly update a list of practical guides on LLMs for cybersecurity at https://github.com/tmylla/Awesome-LLM4Cybersecurity .
Jie Zhang 0121, Haoyu Bu, Hui Wen 0001, Yongji Liu, Haiqiang Fei, Rongrong Xi, Hongsong Zhu
Cybersecur.4
2024 AS-Fuzzer: An Optimized ADS Fuzzing Method via Scenario Segmentation and Parallel Evolution
abstract
Autonomous Driving Systems (ADS) hold significant potential for enhancing travel convenience. Ensuring the reliability of ADS through efficient and comprehensive simulation testing has garnered substantial attention from researchers. In recent years, various search-based automated test scenario generation methods have been proposed to identify potential ADS defects. However, these methods still face challenges in balancing efficiency with comprehensive testing and suffer from a lack of diversity. To address these challenges, we propose AS-Fuzzer, an optimized ADS fuzzing method based on composite traffic scenario generation. AS- Fuzzer introduces a scenario slicing technique based on traffic road structures, allowing each sliced scenario to evolve independently and in parallel, enhancing interaction rates and balancing efficiency with comprehensive testing. A novel scenario generation method Co-Evolutionary Genetic Algorithms (CEGA), is applied within AS-Fuzzer to improve the diversity of generated scenarios, thereby exploring a wider range of ADS defects. Experimental results demonstrate that the proposed method improves test scenario generation efficiency by 120% compared to the state-of-the-art baseline method. Additionally, in the simulation testing of the proposed method, the interaction rate between the ADS vehicle and non-player characters is 2.79 times that of the baseline method, thereby further enhancing ADS testing efficiency. Furthermore, within the same time frame, the proposed method uncovered 19 types of ADS defects that other baseline methods did not explore, achieving higher ADS defect diversity.
Fansong Chen, Shenghao Lin, Weicheng Lin, Laile Xi, Yongji Liu, Hongsong Zhu
APSEC5
2024 Crafting Binary Protocol Reversing via Deep Learning With Knowledge-Driven Augmentation
abstract
Protocol reverse engineering (PRE) serves as an instrumental tool in various security research, such as protocol fuzzing and intrusion detection. Its primary objective lies in uncovering the format, semantics, and behavior of an unknown protocol without prior information. This paper presents DL-ProS2, a deep learning-based approach for binary protocol reversing, focusing on format segmentation and semantic inference from network traffic. Our approach is underpinned by highlighting the effectiveness of multi-scale features within the network traffic for identifying various types of fields and semantics. Based on this, DL-ProS2 employs a comprehensive end-to-end model that integrates U-Net, siamese network, and BiLSTM-CRF, which enables the effective analysis of unknown protocol traffic to extract the field boundaries and semantics. Meanwhile, to address the issue of limited data diversity and coverage, we implement an innovative knowledge-driven traffic simulation technique. This method harnesses the ChatGPT to extract protocol knowledge from publicly available protocol documents, such as RFCs, as the foundational rules for the simulation. Empirical results substantiate the efficacy of our approach, demonstrating precision rates exceeding 0.95 and recall rates surpassing 0.97 for partially unknown protocol format segmentation and semantic inference. It also retains effectiveness in the inference of completely unknown protocols, with average precision and recall rates of 0.69 and 0.62 for format segmentation, and 0.43 and 0.47 for semantic inference, respectively.
Shouguo Yang, Zhen Wang 0043, Yongji Liu, Hongsong Zhu, Limin Sun 0001
IEEE/ACM Trans. Netw.4
2023 An Enhanced Vulnerability Detection in Software Using a Heterogeneous Encoding Ensemble
abstract
Detecting vulnerabilities in source code is essential to prevent cybersecurity attacks. Deep learning-based vulnerability detection is an active research topic in software security. However, existing deep learning-based vulnerability detectors (VD) are limited to using either serialization-based or graph-based methods, which do not combine serialized global and structured local information at the same time. As a result, a single method cannot perform well for semantic information that exists in complex source code, leading to low detection accuracy. In this paper, we present EL-VDetect, a stacked ensemble learning approach for vulnerability detection that eliminates these issues. EL-VDetect enhances feature selection techniques to represent the best relevant vulnerability features with the slice code and subgraphs, reducing redundant information of vulnerabilities. Our model combines serialization-based and graph-based neural networks to successfully capture the global and local context information of source code, effectively understands code semantics, and focuses on vulnerable nodes based on the attention mechanism to accurately detect vulnerabilities. To evaluate EL-VDetect's effectiveness, we crawl a real-world dataset from CVEDetails, consisting of functions for eight applications. A comprehensive performance analysis of the real-world dataset shows that EL-VDetect achieves 90.72% accuracy, outperforming baseline deep learning models by 1.75-26.21 %. Our proposed model can better identify vulnerabilities in software than other existing vulnerability detection models.
Hao Sun 0028, Yongji Liu, Zhenquan Ding, Yang Xiao 0011, Zhiyu Hao, Hongsong Zhu
ISCC2
2023 HEMC: a dynamic behaviour analysis system for malware based on hardware virtualisation
abstract
Since many malwares disguise themselves by encrypting, obfuscating and recompiling, it is not easy for static analysis methods to recognise new or unknown malwares. This paper proposes a novel dynamic analysis technology based on hardware virtualisation to analyse more malwares with lower computational resources. Firstly, it intercepts the system-call functions to achieve on-demand behaviour analysis by setting special permissions in their physical addresses, which can be dynamically acquired when system-call functions are loaded into memory, as well as only monitoring high-risk functions, which take a small part of the whole functions. Then, this paper utilises copy-on-write technique and incremental image capability to reduce hard drive consumption and hard disk replication time. Finally, this paper proposes a novel approach to capture the return value of system-call functions to deeply analyse the poisoned results of malware samples. Meanwhile, a prototype system, called HEMC, is implemented based on QEMU/KVM . The experiments demonstrate that proposed methods outperform existing methods in efficiency and performance on malware dynamic analysis.
Zhenquan Ding, Lei Cui 0003, Haiqiang Fei, Yongji Liu, Zhiyu Hao
Int. J. Inf. Comput. Secur.5
2023 eHotSnap: An Efficient and Hot Distributed Snapshots System for Virtual Machine Cluster
abstract
With the popularity of IaaS clouds, many distributed and networked applications are running in virtual machine cluster (VMC). The distributed snapshots of VMC are a practical approach to guarantee system reliability. It rewinds the system to an intermediate state from failures so that the applications can continue execution from a point near the failure. However, the applications running in the VMC suffer from long disruption and significant performance degradation due to the heavy cost distributed snapshots, especially when designed to guarantee global consistency of VMC snapshots. This article presents eHotSnap, which takes distributed snapshots of a VMC efficiently. eHotSnap divides the native snapshot into light cost transient snapshot and heavy cost memory snapshot and then coordinates the VM snapshots immediately after transient snapshots. In this way, it decouples coordination from heavy cost snapshots so that the distributed snapshots are taken (completed in logic) within a second. Then, it performs memory snapshot and optimizes it with a two-layer optimization, which first employs de-duplication to reduce the amount of snapshot data and then leverages priority queue to serve guest write operations preferentially. In addition to presenting eHotSnap, we have implemented a prototype on QEMU/KVM. The experimental results demonstrate the effectiveness and efficiency of the proposed approach.
Bo Li 0005, Lei Cui 0003, Zhiyu Hao, Yongji Liu, Yongnan Li
IEEE Trans. Parallel Distributed Syst.5
2022 MalPro: Learning on Process-Aware Behaviors for Malware Detection
abstract
Malware continuously evolve and become more and more sophisticated. Learning on execution behavior is proven to be effective for malware detection. In this paper, we present MalPro, a DNN based malware detection approach that performs learning on process-aware behaviors for Windows programs. It first employs logistic regression-based weighting method to assess the sensitivity of an API to malicious behavior, and weights the API following run-time arguments with varying degrees of sensitivities. Then, it constructs the process graph of inter-process interactions from which a set of attributes are extracted, for characterizing the relationship of various processes in term of invoke actions. Finally, it feeds the weighted API sequences and the process graph attributes into the DNN for training a binary classifier to detect malware. Moreover, we have implemented and evaluated MalPro on two datasets. The results demonstrate that our method outperforms naive models, verifying the effectiveness of MalPro.
Ying Tong, Chunlai Du, Yongji Liu, Zhenquan Ding, Qingyun Ran, Lei Cui 0003, Zhiyu Hao
ISCC4
2022 CodeDiff: A Malware Vulnerability Detection Tool Based on Binary File Similarity for Edge Computing Platform
Zihao Chu, Yonghe Guo, Yongji Liu, Lei Cui 0003, Zhiyu Hao
WASA (3)5
2022 An empirical study of vulnerability discovery methods over the past ten years
Lei Cui 0003, Jiancong Cui, Zhiyu Hao, Zhenquan Ding, Yongji Liu
Comput. Secur.6
2022 Black box attack and network intrusion detection using machine learning for malicious traffic
Yiran Zhu, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
Comput. Secur.5
2022 CruParamer: Learning on Parameter-Augmented API Sequences for Malware Detection
abstract
Learning on execution behaviour, i.e., sequences of API calls, is proven to be effective in malware detection. In this paper, we present CruParamer, a deep neural network based malware detection approach for Windows platform that performs learning on sequences of parameter-augmented APIs. It first employs rule-based and clustering-based classification to assess the sensitivity of a parameter to malicious behaviour, and further labels the API following the run-time parameters with varying degrees of sensitivities. Then, it encodes the APIs by concatenating the native embedding and the sensitive embedding of labelled APIs, for characterizing the relationship between successive labelled APIs and their correspondence in terms of security semantics. Finally, it feeds the sequences of API embedding into the deep neural network for training a binary classifier to detect malware. In addition to presenting the design, we have implemented CruParamer and evaluated it on two datasets. The results demonstrate that CruParamer outperforms naïve models when taking raw APIs as input, proving the effectiveness of CruParamer. Moreover, we have evaluated the impact ofmimicryand adversarial attacks on our model, and the results verify the robustness of CruParamer.
Zhiyu Hao, Lei Cui 0003, Yiran Zhu, Zhenquan Ding, Yongji Liu
IEEE Trans. Inf. Forensics Secur.7
2021 EmuIoTNet: An Emulated IoT Network for Dynamic Analysis
Qin Si, Lei Cui 0003, Zhenquan Ding, Yongji Liu, Zhiyu Hao
ICICS (1)5
2017 Surviving screen-off battery through out-of-band Wi-Fi coordination
abstract
This paper identifies two energy saving opportunities of Wi-Fi interface emerged during smartphone's screen-off periods. Exploiting the opportunities, we propose a new power saving strategy, BackPSM, for screen-off Wi-Fi communications. BackPSM regulates client to send and receive packets in batches and coordinates multiple clients to communicate at different slots (i.e., beacon interval). The core problem in BackPSM is how to coordinate client without incurring extra traffic overheads. To handle the problem, we propose a novel paradigm, Out-of-Band Communication (OBC), for client-to-client direct communications. OBC exploits the TIM (Traffic Indication Map) field of Wi-Fi Beacon to create a free side-channel between clients. It is based upon the observation that a client may control 1 → 0 appearing on TIM bit by locally regulating packet receiving operations. We adopt this 1 → 0 as the basic signal, and leverage the time length in between two signals to encode information. We demonstrate that OBC can be used to convey coordination information with close to 100% accuracy. We have implemented and evaluated BackPSM on a testbed. The results show that BackPSM reduces screen-off energy by up to 60%, and outperforms state-of-the-art strategies by 16%-42%.
Xianjin Xia, ShiNing Li, Yu Zhang 0034, Tao Gu 0001, Yongji Liu, Yan Pan 0003
INFOCOM6