VLDB 2026 Research / reviewers in the wild / expert
Xiaohui Kuang
dblp:18/1267
· DBLP profile ↗
69ranked-venue papers
3as first author
45since 2021 · last 2026
0000-0003-3816-402XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 17 · 15 since 2021Computer networks · 14 · 1 first-author · 7 since 2021Security and privacy · 13 · 1 first-author · 9 since 2021Databases, data management, data science and information retrieval · 9 · 1 first-author · 7 since 2021Systems, architecture and hardware · 6 · 3 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DataFactory: Collaborative multi-agent framework for advanced table question answeringabstractTable Question Answering (TableQA) enables natural language interaction with structured tabular data. However, existing large language model (LLM) approaches face critical limitations: context length constraints that restrict data handling capabilities, hallucination issues that compromise answer reliability, and single-agent architectures that struggle with complex reasoning scenarios involving semantic relationships and multi-hop logic. This paper introduces DataFactory, a multi-agent framework that addresses these limitations through specialized team coordination and automated knowledge transformation. The framework comprises a Data Leader employing the ReAct paradigm for reasoning orchestration, together with dedicated Database and Knowledge Graph teams, enabling the systematic decomposition of complex queries into structured and relational reasoning tasks. We formalize automated data-to-knowledge graph transformation via the mapping function T : D × S × R → G , and implement natural language-based consultation that—unlike fixed workflow multi-agent systems—enables flexible inter-agent deliberation and adaptive planning to improve coordination robustness; we also apply context engineering strategies that integrate historical patterns and domain knowledge to reduce hallucinations and improve query accuracy. Across TabFact, WikiTableQuestions, and FeTaQA, using eight LLMs from five providers, results show consistent gains. Our approach improves accuracy by 20.2% (TabFact) and 23.9% (WikiTQ) over baselines, with significant effects (Cohen’s d>1). Team coordination also outperforms single-team variants (+5.5% TabFact, +14.4% WikiTQ, +17.1% FeTaQA ROUGE-2). The framework offers design guidelines for multi-agent collaboration and a practical platform for enterprise data analysis through integrated structured querying and graph-based knowledge representation. Tong Wang 0042, Xiaohui Kuang |
Inf. Process. Manag. | 5 |
| 2025 | Refusal-Aware Red Teaming: Exposing Inconsistency in Safety EvaluationsabstractThe responsible deployment of Large Language Models (LLMs) necessitates rigorous safety evaluations.However, a critical challenge arises from inconsistencies between an LLM's internal refusal decisions and external safety assessments, hindering effective validation.This paper introduces the concept of the 'refusal gap' to formally define these discrepancies.We then present a novel, refusal-aware red teaming framework designed to automatically generate test cases that expose such gaps.Our framework employs 'refusal probes', which leverage the target model's hidden states, to detect internal model refusals.These are subsequently contrasted with judgments from an external safety evaluator.The identified discrepancy serves as a signal to guide a red-teaming model in crafting test cases that maximize this refusal gap.To further enhance test case diversity and address challenges related to sparse rewards, we introduce a hierarchical, curiositydriven mechanism that incentivizes both refusal gap maximization and broad topic exploration.Empirical results demonstrate that our method significantly outperforms existing reinforcement learning-based approaches in generating diverse test cases and achieves a substantially higher discovery rate of refusal gaps. Xiaohu Du, Xiaotian Zou, Chongyang Zhao 0004, Xiaohui Kuang |
EMNLP | 7 |
| 2025 | Density Boosts Everything: A One-stop Strategy for Improving Performance, Robustness, and Sustainability of Malware Detectors
Jianwen Tian, Debin Gao, Taotao Gu, Kefan Qiu, Zhi Wang 0014, Xiaohui Kuang |
NDSS | 8 |
| 2025 | Reward-Guided Many-Shot Jailbreaking
Xiaotian Zou, Tong Wang 0042, Jianwen Tian, Xiaohui Kuang |
NLPCC (1) | 6 |
| 2025 | CacheAlarm: Monitoring Sensitive Behaviors of Android Apps Using Cache Side ChannelabstractMalware attack has been a serious threat to the security and privacy of both individual and corporation users of the Android platform. Business entities seek to protect themselves by means of monitoring privacy-related sensitive behaviors conducted on company-issued Android devices. However, due to Android’s own access control and privacy protection policies, this is difficult to be done with third-party apps using only normal privileges. Existing works proposed using side-channel readings from leaky APIs and system virtual files to speculate runtime app behaviors, which could be unreliable due to future system updates (that ban exploited resources), hardware jittering, etc. In this paper, we argue that a more traditional side-channel attack strategy, namely the CPU-cache-based side channel, could be exploited in the benign scenario of app behavior surveillance. Specifically, we propose CacheAlarm, a sensitive app behavior monitor and foreground app identification system, which works by measuring cache side-channel readings of selected methods within the Android framework, and conducted in-lab and in-the-wild user studies to compare the effectiveness of our scheme against SideNet, a previous Android app behavior surveillance scheme using API-based side channels. Results of the studies suggested that CacheAlarm outperforms SideNet on the accuracy of detecting sensitive behaviors in addition to gaining the capability of detecting apps running at foreground of the user device. Jianwen Tian, Debin Gao, Xiaohui Kuang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | A New Perspective of Deep Learning Testing Framework: Human-Computer Interaction Based Neural Network TestingabstractDeep learning models have revolutionized various domains but have also raised concerns regarding their security and reliability. Adversarial attacks and coverage-based testing have been extensively studied to assess and enhance the dependability of deep neural networks. However, current research in this area has reached a state of stagnation. Adversarial attacks focus on exploiting vulnerabilities in models, while coverage-based testing aims to achieve comprehensive testing but overlooks application scenarios. Moreover, evaluating test cases solely based on their fault-revealing capability is insufficient. To address these limitations, we propose an innovative interdisciplinary framework that incorporates human-computer interaction methods in deep learning security testing. By considering the attributes of model application scenarios, we can design more effective test suites that intend to reveal the model's behavior across various scenarios, aiding in the identification of potential defects. Consequently, the test suite plays a crucial role in the testing process of deep learning models, contributing to the assurance of model robustness and reliability. Additionally, we establish a comprehensive evaluation metric for test suite quality, considering factors such as diversity and naturalness. This framework promotes reliable and secure deployment of deep learning models, fostering interdisciplinary collaboration between artificial intelligence and human-computer interaction. Qianjin Du, Huayang Cao, Xiaohui Kuang |
ICRA | 5 |
| 2024 | Dance of the ADS: Orchestrating Failures through Historically-Informed Scenario FuzzingabstractAs autonomous driving systems (ADS) advance towards higher levels of autonomy, orchestrating their safety verification becomes increasingly intricate. This paper unveils ScenarioFuzz, a pioneering scenario-based fuzz testing methodology. Designed like a choreographer who understands the past performances, it uncovers vulnerabilities in ADS without the crutch of predefined scenarios. Leveraging map road networks, such as OPENDRIVE, we extract essential data to form a foundational scenario seed corpus. This corpus, enriched with pertinent information, provides the necessary boundaries for fuzz testing in the absence of starting scenarios. Our approach integrates specialized mutators and mutation techniques, combined with a graph neural network model, to predict and filter out high-risk scenario seeds, optimizing the fuzzing process using historical test data. Compared to other methods, our approach reduces the time cost by an average of 60.3%, while the number of error scenarios discovered per unit of time increases by 103%. Furthermore, we propose a self-supervised collision trajectory clustering method, which aids in identifying and summarizing 54 high-risk scenario categories prone to inducing ADS faults. Our experiments have successfully uncovered 58 bugs across six tested systems, emphasizing the critical safety concerns of ADS. Tong Wang 0042, Taotao Gu, Xiaohui Kuang |
ISSTA | 5 |
| 2024 | Suitable is the Best: Task-Oriented Knowledge Fusion in Vulnerability DetectionabstractDeep learning technologies have demonstrated remarkable performance in vulnerability detection. Existing works primarily adopt a uniform and consistent feature learning pattern across the entire target set. While designed for general-purpose detection tasks, they lack sensitivity towards target code comprising multiple functional modules or diverse vulnerability subtypes. In this paper, we present a knowledge fusion-based vulnerability detection method (KF-GVD) that integrates specific vulnerability knowledge into the Graph Neural Network feature learning process. KF-GVD achieves accurate vulnerability detection across different functional modules of the Linux kernel and vulnerability subtypes without compromising general task performance. Extensive experiments demonstrate that KF-GVD outperforms SOTAs on function-level and statement-level vulnerability detection across various target tasks, with an average increase of 40.9% in precision and 26.1% in recall. Notably, KF-GVD discovered 9 undisclosed vulnerabilities when employing on C/C++ open-source projects without ground truth. Minhuan Huang, Yuanping Nie, Xiang Li 0078, Qianjin Du, Xiaohui Kuang |
NeurIPS | 8 |
| 2024 | Enhancing Adversarial Robustness through Self-Supervised Confidence-Based DenoisingabstractDeep Neural Networks (DNNs) have been found to be susceptible to adversarial examples, prompting the investigation of strategies aimed at enhancing their robustness against such attacks. Despite the proposition of preprocessing methods designed to mitigate the impact of adversarial perturbations, their adaptability to continuously evolving attack strategies remains a significant challenge. In response to this, we introduce a novel methodology, termed Self-Supervised Confidence-based Perturbation Denoising (SCPD). This approach capitalizes on self-supervised adversarial training to remove adversarial perturbations and restore natural examples. SCPD exploits the association between natural and adversarial examples, utilizing confidence as a guidance in the generation of adversarial features that are effectively generalizable. Specifically, adversarial examples are constructed by maximizing the distortion of confidence, without ground-truth labels. Subsequently, a denoising network is trained with the aim of projecting adversarial examples closer to their natural counterparts. Through a series of comprehensive experiments, we provide evidence that SCPD surpasses existing adversarial training and preprocessing methodologies in terms of robustness against both unseen and adaptive attacks. Tong Wang 0042, Taotao Gu, Guiling Cao, Xiaohui Kuang |
TrustCom | 6 |
| 2024 | Dynamic loss yielding more transferable targeted adversarial examples
Ming Zhang 0021, Xiaohui Kuang |
Neurocomputing | 5 |
| 2023 | Test Suite Generation Based on Context-Adapted Structural Coverage for Testing DNN
Qianjin Du, Huayang Cao, Jianwen Tian, Xiaohui Kuang |
APNOMS | 7 |
| 2023 | Fine-Grained Software Vulnerability Detection via Neural Architecture Search
Qianjin Du, Xiaohui Kuang, Xiang Li 0078 |
DASFAA (4) | 2 |
| 2023 | A Study on Vulnerability Code Labeling Method in Open-Source C Programs
Yaning Zheng, Dongxia Wang 0001, Huayang Cao, Xiaohui Kuang, Honglin Zhuang |
DEXA (1) | 5 |
| 2023 | Joint Geometrical and Statistical Domain Adaptation for Cross-domain Code Vulnerability DetectionabstractIn code vulnerability detection tasks, a detector trained on a label-rich source domain fails to provide accurate prediction on new or unseen target domains due to the lack of labeled training data on target domains.Previous studies mainly utilize domain adaptation to perform cross-domain vulnerability detection.But they ignore the negative effect of private semantic characteristics of the target domain for domain alignment, which easily causes the problem of negative transfer.In addition, these methods forcibly reduce the distribution discrepancy between domains and do not take into account the interference of irrelevant target instances for distributional domain alignment, which leads to the problem of excessive alignment.To address the above issues, we propose a novel cross-domain code vulnerability detection framework named MN-CRI.Specifically, we introduce mutual nearest neighbor contrastive learning to align the source domain and target domain geometrically, which could align the common semantic characteristics of two domains and separate out the private semantic characteristics of each domain.Furthermore, we introduce an instance re-weighting scheme to alleviate the problem of excessive alignment.This scheme dynamically assign different weights to instances, reducing the contribution of irrelevant instances so as to achieve better domain alignment.Finally, extensive experiments demonstrate that MNCRI significantly outperforms state-of-the-art cross-domain code vulnerability detection methods by a large margin. Qianjin Du, Shiji Zhou, Xiaohui Kuang, Jidong Zhai |
EMNLP | 3 |
| 2023 | Automated Software Vulnerability Detection via Curriculum LearningabstractWith the development of deep learning, software vulnerability detection methods based on deep learning have achieved great success, which outperform traditional methods in efficiency and precision. At the training stage, all training samples are treated equally and presented in random order. However, in software vulnerability detection tasks, the detection difficulties of different samples vary greatly. Similar to the human learning mechanism following an easy-to-difficult curriculum learning procedure, vulnerability detection models can also benefit from the easy-to-hard curriculums. Motivated by this observation, we introduce curriculum learning for automated software vulnerability detection, which is capable of arranging easy-to-difficult training samples to learn better detection models without any human intervention. Experimental results show that our method achieves obvious performance improvements compared to baseline models. Qianjin Du, Wei Kun, Xiaohui Kuang, Xiang Li 0078 |
ICME | 3 |
| 2023 | ADV-POST: Physically Realistic Adversarial Poster for Attacking Semantic Segmentation Models in Autonomous Driving
Minhuan Huang, Tong Wang 0042, Jianwen Tian, Xiaohui Kuang |
ICONIP (13) | 7 |
| 2023 | Risk Scenario Generation for Autonomous Driving Systems based on Scenario Evaluation ModelabstractThe development of deep learning-based au-tonomous driving systems is becoming increasingly prevalent in recent times, however, several safety concerns have emerged. In certain uncommon situations, the generalization and robustness of deep learning have resulted in safety crises and accidents. To address this, it is crucial to comprehensively cover a range of possible conditions in simulators and identify risk scenarios within the system, which poses a significant high-dimensional search problem. To efficiently, accurately, and comprehensively generate diverse risk scenarios, we propose a scenario evaluation model. This model can learn the distribution of risk factors from a limited number of scenario samples and provide pre-evaluation to guide the generation process. The experimental results show that that our method can generate an average of 40.6% more risk scenarios compared to other generation methods, while also requiring 63.6% fewer simulations. The method based on the scenario evaluation model can effectively improve efficiency, accuracy, and the identification of more risk scenarios, thus providing a more thorough evaluation of the safety performance of autonomous driving systems. Tong Wang 0042, Xiaohui Kuang, Taotao Gu, Jianwen Tian |
IJCNN | 2 |
| 2023 | Driving into Danger: Adversarial Patch Attack on End-to-End Autonomous Driving Systems Using Deep LearningabstractDeep learning-based autonomous driving systems have been extensively researched due to their superior performance compared to traditional methods. Specifically, end-to-end deep learning systems have been developed, which directly output control signals for vehicles using various sensor inputs. However, deep learning techniques are vulnerable to security issues, generating adversarial examples that can attack the output of the relevant model. This paper proposes an adversarial example generation method that applies a patch to pedestrians' clothing, which can generate dangerous behaviors when the pedestrian appears within the camera lens, thereby attacking the end-to-end autonomous driving system. The proposed method is validated using the CARLA simulator, and the results demonstrate successful attacks in various weather and lighting conditions, exposing the security vulnerabilities of this type of system. This study highlights the need for further research to address these vulnerabilities and ensure the safety of autonomous driving systems. Tong Wang 0042, Xiaohui Kuang, Qianjin Du, Zhanhao Hu |
ISCC | 2 |
| 2023 | Fine-Grained Source Code Vulnerability Detection via Graph Neural Networks (S)abstractAlthough the number of exploitable vulnerabilities in software continues to increase, the speed of bug fixes and software updates have not increased accordingly.It is therefore crucial to analyze the source code and identify vulnerabilities in the early phase of software development.However, vulnerability location in most of the current machine learning-based methods tends to concentrate at the function level.It undoubtedly imposes a burden on further manual code audits when faced with largescale source code projects.In this paper, a fine-grained source code vulnerability detection model based on Graph Neural Networks (GNNs) is proposed with the aim of locating vulnerabilities at the function level and line level.Our empirical evaluation on different C/C++ datasets demonstrated that our proposed model outperforms the state-of-the-art methods and achieves significant improvements even when faced with more complex, real-project source code. Minhuan Huang, Yuanping Nie, Xiaohui Kuang, Xiang Li 0078, Wenjing Zhong |
SEKE | 4 |
| 2023 | Sparsity Brings Vulnerabilities: Exploring New Metrics in Backdoor Attacks
Jianwen Tian, Kefan Qiu, Debin Gao, Zhi Wang 0014, Xiaohui Kuang |
USENIX Security Symposium | 5 |
| 2023 | When Moving Target Defense Meets Attack Prediction in Digital Twins: A Convolutional and Hierarchical Reinforcement Learning ApproachabstractWith rapid development of emerging technologies for Internet of Things (IoT), digital twins (DT) have been proposed to support a wide variety of applications. A mobile network is expected to be integrated with DT to form a DT mobile network (DTMN). Unfortunately, DTMN still faces security threats, which have attracted great research attention. Current defense mechanisms are mostly static, i.e., responding after attacks happening. To solve the aforementioned problem, moving target defense (MTD) has been proposed as an innovative solution. However, there exist three major challenges when applying MTD into DTMN. Firstly, less emphasis was paid to collaborative scheduling between multiple MTD schemes, which can improve the security of DTMN. Secondly, MTD schemes require lots of network resources, but few works focus on the time allocation of multiple MTD schemes to reduce network resource consumption. Thirdly, existing defense strategies only rely on current information, but do not consider future information. In this paper, we propose a collaborative mutation-based MTD (CM-MTD) in DTMN. We mainly consider two MTD schemes called host address mutation (HAM) and route mutation (RM), respectively, which adjust network properties and invalidate different stages of cyber kill chain. We firstly formulate a semi-Markov decision process (SMDP) to model time-varying security events and dynamic deployment of multiple MTD schemes. Then, security events are predicted by long short-term memory (LSTM), which are regarded as network states in SMDP. Next, infeasible actions that do not satisfy network constraints will be removed from the action space of the SMDP. Lastly, we design a hierarchical deep reinforcement learning algorithm for collaborative scheduling. Simulation results highlight the effectiveness of CM-MTD compared with baseline solutions. Tao Zhang 0063, Changqiao Xu, Yibo Lian, Haijiang Tian, Jiawen Kang 0001, Xiaohui Kuang, Dusit Niyato |
IEEE J. Sel. Areas Commun. | 6 |
| 2023 | A Mutation-Enabled Proactive Defense Against Service-Oriented Man-in-The-Middle Attack in KubernetesabstractKubernetes (K8s) has become a core technology for cloud-native applications. However, a design flaw of the external IP in K8s leads to the service-oriented man-in-the-middle attack. Existing solutions (e.g., script monitor) attempt to address it passively, which allows attackers enough analysis time to bypass these static rule reviews. Differently, we propose a mutation-enabled proactive defense mechanism, aiming to change the asymmetry between attackers and defenders. It involves the address mutation (i.e., network identification) module and the connection ID (i.e., communication identification) mutation module. In the former module, we analyze mutation constraints and prove the corresponding mutation grouping problem to be NP-hard. Then, a maximally coloring-driven mutation grouping algorithm is developed. Since the address allocation time grows linearly with the service size, we design a prefetched address allocation algorithm. After designing the interaction flow between modules, we present a randomized algorithm in the latter module. Thus our mechanism does not affect methods oriented to other attacks. Eventually, it can continuously interrupt the attack and keep the service connection by incrementally updating K8s and the transport layer protocol. Experiments in the Alibaba cloud demonstrate that it can effectively defend against the attack with an acceptable performance loss. Tengchao Ma, Changqiao Xu, Qingzhao An, Xiaohui Kuang, Luigi Alfredo Grieco |
IEEE Trans. Computers | 6 |
| 2023 | Towards Attack-Resistant Service Function Chain Migration: A Model-Based Adaptive Proximal Policy Optimization ApproachabstractNetwork function virtualization (NFV) supports the rapid development of service function chain (SFC), which efficiently connects a sequence of network virtual function instances (VNFIs) placed into physical infrastructures. Current SFC migration mechanisms usually keep static SFC deployment after finishing certain objectives, and deployment methods mostly provide static resource allocation for VNFIs. Therefore, the adversary has enough time to plan for devastating attacks for in-service SFCs. Fortunately, moving target defense (MTD) was proposed as a game-changing solution to dynamically adjust network configurations. However, existing MTD methods mostly depend on attack-defense models, and lack adaptive mutation period. In this article, we propose an Intelligence-Driven Service Function Chain Migration (ID-SFCM) scheme. First, we model a Markov decision process (MDP) to formulate the dynamic arrival or departure of SFCs. To remove infeasible actions from the action space of MDP, we formalize the SFC deployment as a constrained satisfaction problem. Then, we design a deep reinforcement learning (DRL) algorithm named model-based adaptive proximal policy optimization (MA-PPO) to enable attack-resistant migration decisions and adaptive migration period. Finally, we evaluate the defense performance by multiple attack strategies and two realistic datasets called CICIDS-2017 and LYCOS-IDS2017 respectively. Simulation results highlight the effectiveness of ID-SFCM compared with representative solutions. Tao Zhang 0063, Changqiao Xu, Bingchi Zhang, Xiaohui Kuang, Luigi Alfredo Grieco |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | A Multi-Shuffler Framework to Establish Mutual Confidence for Secure Federated LearningabstractAlbeit the popularity of federated learning (FL), recently emerging model-inversion and poisoning attacks arouse extensive concerns towards privacy or model integrity, which catalyzes the developments of secure federated learning (SFL) methods. Nonetheless, the collisions between its privacy and integrity, two equally crucial elements in collaborative learning scenarios, are relatively underexplored. Individuals’ wish to “hide in the crowd” for privacy frequently clashes with aggregators’ need to resist abnormal participants for integrity (i.e., the incompatibility between Byzantine robustness and differential privacy). The dilemma prompts researchers to reflect on how to build mutual confidence between individuals and aggregators. Against the backdrop, this paper proposes a multi-shuffler secure federated learning (MSFL) framework, based on which we further propound three modules (hierarchical shuffling mechanism, malice evaluation module, and composite defense strategy) to jointly guarantee strong privacy protection, efficient poisoning resistance, and agile adversary elimination. Extensive experiments on standard datasets exhibited the method's effectiveness in thwarting different FL poisoning attack paradigms with a minimal cost of privacy breaches. Zan Zhou 0001, Changqiao Xu, Ming-Ze Wang, Xiaohui Kuang, Yirong Zhuang, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | How to Disturb Network Reconnaissance: A Moving Target Defense Approach Based on Deep Reinforcement LearningabstractWith the explosive growth of Internet traffic, large sensitive and valuable information is at risk of cyber attacks, which are mostly preceded by network reconnaissance. A moving target defense technique called host address mutation (HAM) helps facing network reconnaissance. However, there still exist several fundamental problems in HAM: 1) current approaches cannot be self-adaptive to adversarial strategies; 2) network state is time-varying because each host decides whether to mutate IP address; and 3) most methods mainly focus on enhancing security, but ignore the survivability of existing connections. In this paper, an Intelligence-Driven Host Address Mutation (ID-HAM) scheme is proposed to address aforementioned challenges. We firstly model a Markov decision process (MDP) to describe the mutation process, and design a seamless mutation mechanism. Secondly, to remove infeasible actions from the action space of MDP, we formulate address-to-host assignments as a constrained satisfaction problem. Thirdly, we design an advantage actor-critic algorithm for HAM, which aims to learn from scanning behaviors. Finally, security analysis and extensive simulations highlight the effectiveness of ID-HAM. Compared with state-of-the-art solutions, ID-HAM can decrease maximum 25% times of scanning hits while only influencing communication slightly. We also implemented a proof-of-concept prototype system to conduct experiments with multiple scanning tools. Tao Zhang 0063, Changqiao Xu, Xiaohui Kuang, Luigi Alfredo Grieco |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | How to Mitigate DDoS Intelligently in SD-IoV: A Moving Target Defense ApproachabstractSoftware defined Internet of Vehicles (SD-IoV) is an emerging paradigm for accomplishing Industrial Internet of Things (IIoT). Unfortunately, SD-IoV still faces security challenges. Traditional solutions respond after attacks happening, which is low-effective. To cope with this problem, moving target defense (MTD) was proposed to modify network configurations dynamically. However, current MTD for IIoT has several drawbacks: 1) it cannot handle highly dynamic environments; 2) MTD strategy lacks intelligence because it needs attack–defense models; 3) they are difficult to trace sources. In this article, we propose an intelligent MTD scheme to defend against distributed denial-of-service in SD-IoV. Firstly, we model the configuration mutation of roadside units as a Markov decision process (MDP), and adopt deep reinforcement learning to solve the optimal configuration. Next, we evaluate the trust of vehicles after shuffling, which can distinguish spy vehicles. Finally, extensive simulation results confirm the effectiveness of our solution compared with representative methods. Tao Zhang 0063, Changqiao Xu, Haijiang Tian, Xiaohui Kuang, Lujie Zhong, Dusit Niyato |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | A Proactive Defense Strategy Against SGX Side-channel Attacks via self-checking DRL in the CloudabstractIntel software guard extensions (SGX) technology allows cloud vendors to provide customers with an independent and trusted execution environment (TEE). It protects critical data confidentiality and integrity from malicious software. However, more and more SGX side-channel attacks have appeared, which seriously undermine the confidence of tenants in cloud security. The related research focuses on system hardware and SGX compiler solutions for specific attacks, which also has difficulties in deployment. Differently, we propose an intelligent-driven proactive defense strategy, which is based on live migration. To the best of our knowledge, this is the first proactive defense against SGX side-channel attacks. We adopt the Markov decision process to solve the migration programming problem. The innovative deep reinforcement learning (DRL) solves problems of the unknown state transition probability and large machine load states, which is called self-checking proximal policy optimization (SPPO). It changes the reward pattern, improving the convergence speed and stability of DRL. In prototype experiments, we deploy the strategy in the OpenStack platform agilely to prove the defense performance and low virtual machine costs. Tengchao Ma, Changqiao Xu, Qingzhao An, Xiaohui Kuang, Lujie Zhong, Luigi Alfredo Grieco |
ICC | 4 |
| 2022 | Detecting Backdoor Attacks on Deep Neural Networks Based on Model Parameters AnalysisabstractWith the introduction of the backdoor in deep neural networks (DNNs), much research focuses on backdoor attacks and defenses against DNNs. Since many DNN models are developed based on public datasets and pre-trained models often published by untrusted third parties, backdoors can be easily injected. The defender usually cannot access training data and does not know the target class or the triggers of the backdoor injected by the attacker. All these make it challenging to guarantee the security of decision guidance and support systems. In this paper, we proposed to detect backdoor attacks on DNNs based on model parameters analysis (MPA). We extracted and selected parameters related to the backdoor in the model's hidden layer and decision layer and trained the MPA classifier based on these parameters. We evaluated the effectiveness of the MPA classifier on various target models. The results show that the area under the receiver operating characteristic curve of the MPA classifier reaches 0.96 and 0.86 on the CIFAR10 and Troj target models, respectively. The MPA classifier improved the detection rate of backdoor attacks by 2%-6% compared with other advanced methods, with less prior knowledge and more relaxed constraints. Mingyuan Ma, Xiaohui Kuang |
ICTAI | 3 |
| 2022 | Improving Transferability of Adversarial Examples with Virtual Step and Auxiliary GradientsabstractDeep neural networks have been demonstrated to be vulnerable to adversarial examples, which fool networks by adding human-imperceptible perturbations to benign examples. At present, the practical transfer-based black-box attacks are attracting significant attention. However, most existing transfer-based attacks achieve only relatively limited success rates. We propose to improve the transferability of adversarial examples through the use of a virtual step and auxiliary gradients. Here, the “virtual step” refers to using an unusual step size and clipping adversarial perturbations only in the last iteration, while the “auxiliary gradients” refer to using not only gradients corresponding to the ground-truth label (for untargeted attacks), but also gradients corresponding to some other labels to generate adversarial perturbations. Our proposed virtual step and auxiliary gradients can be easily integrated into existing gradient-based attacks. Extensive experiments on ImageNet show that the adversarial examples crafted by our method can effectively transfer to different networks. For single-model attacks, our method outperforms the state-of-the-art baselines, improving the success rates by a large margin of 12%~28%. Our code is publicly available at https://github.com/mingcheung/Virtual-Step-and-Auxiliary-Gradients. Ming Zhang 0021, Xiaohui Kuang, Zhendong Wu, Yuanping Nie |
IJCAI | 2 |
| 2022 | StinAttack: A Lightweight and Effective Adversarial Attack Simulation to Ensemble IDSs for Satellite- Terrestrial Integrated NetworkabstractEffective adversarial attacks simulation is essential for the deployment of ensemble Intrusion Detection Systems (en- semble IDSs) in Satellite-Terrestrial Integrated Network (STIN). This is because it can automatically generate a large amount of adversarial samples to evaluate the robustness of different classifiers. Based on the result, it can further guide the STIN engineers to select proper classifiers in ensemble IDSs. Moreover, it can help the IDSs improve detect performance by their self- learning property in the adversarial attack process. However, the existing adversarial attack approaches suffer from the problems of low success rate and high overhead of communication and calculation due to the limited computing resources and long communication links of STIN. This results in their inefficiency in STIN. To address the above problems, we provide StinAttack as a robustness evaluation scheme for STIN. First, StinAttack provides a comprehensive and automatic robustness evaluation framework for IDSs in STIN with only few times interactions between terrestrial and satellite nodes. Second, StinAttack proposes an effective adversarial attack simulation based on lightweight gradient evaluation for ensemble IDSs. Third, we conduct experiments on 11 typical IDSs, 4 baseline popular adversarial attacks and our StinAttack. Experimental results show that our approach can effectively attack ensemble IDSs and the evaluation results based on real STIN dataset are instructive for designing secure networks. Shangyuan Zhuang, Jiyan Sun, Hangsheng Zhang, Xiaohui Kuang, Ling Pang, Haitao Liu 0006, Yinlong Liu |
ISCC | 4 |
| 2022 | Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial RemovalabstractVision transformers (ViTs) have demonstrated impressive performance and stronger adversarial robustness compared to Convolutional Neural Networks (CNNs). On the one hand, ViTs' focus on global interaction between individual patches reduces the local noise sensitivity of images. On the other hand, the neglect of noise sensitivity differences between image regions by existing decision-based attacks further compromises the efficiency of noise compression, especially for ViTs. Therefore, validating the black-box adversarial robustness of ViTs when the target model can only be queried still remains a challenging problem. In this paper, we theoretically analyze the limitations of existing decision-based attacks from the perspective of noise sensitivity difference between regions of the image, and propose a new decision-based black-box attack against ViTs, termed Patch-wise Adversarial Removal (PAR). PAR divides images into patches through a coarse-to-fine search process and compresses the noise on each patch separately. PAR records the noise magnitude and noise sensitivity of each patch and selects the patch with the highest query value for noise compression. In addition, PAR can be used as a noise initialization method for other decision-based attacks to improve the noise compression efficiency on both ViTs and CNNs without introducing additional calculations. Extensive experiments on three datasets demonstrate that PAR achieves a much lower noise magnitude with the same number of queries. Yahong Han, Yu-an Tan 0001, Xiaohui Kuang |
NeurIPS | 4 |
| 2022 | Group-based corpus scheduling for parallel fuzzingabstractParallel fuzzing relies on hardware resources to guarantee test throughput and efficiency. In industrial practice, it is well known that parallel fuzzing faces the challenge of task division, but most works neglect the important process of corpus allocation. In this paper, we proposed a group-based corpus scheduling strategy to address these two issues, which has been accepted by the LLVM community. And we implement a parallel fuzzer based on this strategy called glibFuzzer. glibFuzzer first groups the global corpus into different subsets and then assigns different energy scores and different scores to them. The energy scores were mainly determined by the seed size and the length of coverage information, and the difference score can describe the degree of difference in the code covered by different subsets of seeds. In each round of key local corpus construction, the master node selects high-quality seeds by combining the two scores to improve test efficiency and avoid task conflict. To prove the effectiveness of the strategy, we conducted an extensive evaluation on the real-world programs and FuzzBench. After 4×24 CPU-hours, glibFuzzer covered 22.02% more branches and executed 19.42 times more test cases than libFuzzer in 18 real-world programs. glibFuzzer showed an average branch coverage increase of 73.02%, 55.02%, 55.86% over AFL, PAFL, UniFuzz, respectively. More importantly, glibFuzzer found over 100 unique vulnerabilities. Taotao Gu, Xiang Li 0078, Shuaibing Lu, Jianwen Tian, Yuanping Nie, Xiaohui Kuang, Zhechao Lin, Chenyifan Liu, Jie Liang 0006, Yu Jiang 0001 |
ESEC/SIGSOFT FSE | 6 |
| 2022 | Dynamic and Diverse Transformations for Defending Against Adversarial ExamplesabstractIt is demonstrated that deep neural networks can be easily fooled by adversarial examples. To improve the robustness of neural networks against adversarial attacks, substantial research on adversarial defenses is being carried out, of which input transformation is a typical category of defenses. However, because the transformation also has an impact on the accuracy of clean examples, the existing transformation-based defenses usually adopt minor transformations such as shift and scaling, which limits the defense effect of the transformation to some extent. To this end, we propose a method by using dynamic and diverse transformations for defending against adversarial attacks. Firstly, we constructed a transformation pool that contains both minor and major transformations (e.g., flip, rotate). Secondly, we retrained the model with the data transformed by major transformations to ensure that the performance of model itself is not affected. Finally, we dynamically select transformations to preprocess the input of the model to defend against adversarial examples. We conducted extensive experiments on MNIST and CIFAR-10 datasets and compared our method with the state-of-the-art adversarial training and transformation-based defenses. The experimental results show that our proposed method outperforms the existing methods, improving the robustness of the model against adversarial examples greatly while maintaining high accuracy on clean examples. Our code is available at https://github.com/byerose/DynamicDiverseTransformations. Ming Zhang 0021, Xiaohui Kuang, Xuhong Zhang 0002, Han Zhang 0009 |
TrustCom | 4 |
| 2022 | Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect Attacks
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Zhiyun Qian, Xiaohui Kuang, Chuanpu Fu, Ke Xu 0002 |
USENIX Security Symposium | 6 |
| 2022 | Multidomain security authentication for the Internet of thingsabstractSummary With the rapid development of Internet of Things (IoT) information technology, the IoT has become a key infrastructure for telemedicine, smart home, and intelligent transportation. One of the key technologies for these applications is information sharing and interoperation among multiple domains. However, the security and privacy issues of multidomain interaction face severe security challenges. Aiming at these problems, an certificateless multidomain authentication technology is proposed for IoT. Bilinear mapping and short signature technology are used to realize mutual authentication among entities in different domains, which protects secure data sharing and secure interoperability among domains. Certificateless multidomain authentication can avoid inherent security risks of key escrow in existing identity‐based authentication. And it also solves complex certificate management and network bottlenecks problems in traditional certificate‐based authentication. The proof and analysis show that the proposed scheme has good security and performance, it supports anonymous authentication among entities, and it is also suitable for large‐scale distributed network security alliance authentication mechanism. Qikun Zhang, Kunyuan Zhao, Xiaohui Kuang, Yongjiao Li, Yuanpan Zheng, Junling Yuan |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | An intelligent proactive defense against the client-side DNS cache poisoning attack via self-checking deep reinforcement learningabstractA new class of poisoning attacks has recently emerged targeting the client-side Domain Name System (DNS) cache. It allows users to visit fake websites unconsciously, thereby revealing their information, such as passwords. However, the current DNS defense architecture does not include DNS clients. Although relative encryption solutions can mitigate this attack, they require the cooperation of multiple parties, and the deployment speed is slow. Therefore, we propose an intelligent-driven proactive defense strategy. First, we model the offensive and defensive process as a stochastic game based on moving target defense. Second, we adopt and optimize Proximal Policy Optimization (PPO), a deep reinforcement learning method, to solve problems caused by uncertain attack strategies and unknown state transition probability. Third, we design a self-checking component in PPO to solve the uncertainty of action space caused by game state constraints based on our previous work. Thus the convergence speed and stability of PPO are improved. Finally, to the best of our knowledge, we are the first to game with intelligent attackers besides three conventional ones. Our strategy does not require any modifications to the DNS architecture. Through an extensive experimental campaign, the prototype system is proved to be effective against multiple attack modes. Its success rate is 98.5% approximately, and network round-trip time is about 55 ms. Even for random attackers, our method can achieve the theoretical maximum defensive success rate. Tengchao Ma, Changqiao Xu, Xiaohui Kuang, Luigi Alfredo Grieco |
Int. J. Intell. Syst. | 5 |
| 2022 | ICDF: Intrusion collaborative detection framework based on confidenceabstractMany machine-learning-based intrusion detection methods have been proposed, however there is a lack of collaboration among these methods. Faced with a cascade of malicious behaviors and various running environments, coupled with the endless emergence of new malicious activities, it is difficult for us to choose an algorithm manually that is suitable for all scenarios. In addition, usually the binary detection models are applied that only “normal” or “abnormal” decision is made, and it is difficult for us to know how much confidence we have in the prediction model. In this study, we propose an intrusion collaborative detection framework (ICDF), an ICDF that allows heterogeneous detection models to effectively work together which have complementary expertise. A multialgorithm model ensemble learning method with confidence interval is adopted. In this process, each algorithm model only makes prediction judgments on its own credible probability interval and refuses to predict outside the interval. The final result is generated by voting based on the confidence of multiple models. Ten detection algorithms were tested on three different data sets. Compared with different single algorithms, ICDF could achieve high precision and recall rate, and the best F1 scores. Zhi Wang 0014, Leshi Shao, Yuanzhao Liu, Jianan Jiang, Yuanping Nie, Xiang Li 0078, Xiaohui Kuang |
Int. J. Intell. Syst. | 8 |
| 2022 | Toward Attack-Resistant Route Mutation for VANETs: An Online and Adaptive Multiagent Reinforcement Learning ApproachabstractVehicular Ad hoc Networks (VANETs) are prone to packet drop attacks because of their inherent distributed architecture and dynamic topology. Existing security schemes mainly focus on multi-path and trust-based routing. Unfortunately, the former causes high energy consumption and the latter requires trust assessment, which is not easy to implement in practice. Route mutation (RM) is emerging as an active defense technology that changes routes periodically. Traditional RM is conceived for fixed network topologies, and needs a centralized controller, so that it cannot be applied to VANETs. Therefore, the present contribution investigates RM in VANETs by proposing a Grid-based extended Joint Action Learning approach (Grid-eJAL). To the best of our knowledge, this is the first contribution that designs an online and adaptive multi-agent reinforcement learning (MARL) for RM to mitigate attacks in VANETs. Differently from existing MARL schemes, Grid-eJAL allows vehicles to share parameters to accelerate the convergence speed of learning. In Grid-eJAL, the area of interest is split in equally sized grids and, when a vehicle transmits packets, the next hop with the minimum angle of mobility is selected within the grid considered as optimal by the learning policy. The convergence of Grid-eJAL is proved theoretically. Finally, extensive simulation results highlight the effectiveness of Grid-eJAL compared to representative state-of-the-art solutions. Tao Zhang 0063, Changqiao Xu, Bingchi Zhang, Xiaohui Kuang, Luigi Alfredo Grieco |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2021 | Free Adversarial Training with Layerwise Heuristic Learning
Benyu Dong, Yahong Han, Yuanzhang Li 0001, Xiaohui Kuang |
ICIG (2) | 6 |
| 2021 | PPO-RM: Proximal Policy Optimization Based Route Mutation for Multimedia ServicesabstractThe growing multimedia services have brought unprecedented challenges to the traditional static network architecture. Moving Target Defense (MTD) has been proposed to solve the inherent disadvantages of existing defense techniques. As an important area of MTD research, Route Mutation (RM) can dynamically change the forwarding routes in the network. In our previous work, we applied Reinforcement Learning (RL) to RM. However, there are still two problems that need to be addressed. 1) We consider too few constraints to reflect the actual network situation. 2) Due to the slow rate of convergence, it becomes difficult for efficient deployment. In this paper, we propose a Proximal Policy Optimization Based Route Mutation (PPO-RM) scheme to solve these problems. Firstly, we utilize the Satisfiability Module Theory (SMT) to formalize the space of all possible mutated routes. Then, we design an RM algorithm based on Proximal Policy Optimization (PPO) and implement it in the SDN controller. Finally, we simulate on Mininet to validate our method. The experiment results show that PPO-RM achieves the improvement in terms of convergence rate, defense performance, and network performance. Tao Zhang 0063, Bingchi Zhang, Weixiao Ji, Xiaohui Kuang, Changqiao Xu |
IWCMC | 5 |
| 2021 | Context-Aware Adaptive Route Mutation Scheme: A Reinforcement Learning ApproachabstractMoving target defense (MTD) is an emerging proactive defense technology, which can reduce the risk of vulnerabilities exploited by attacker. As a crucial component of MTD, route mutation (RM) faces a few fundamental problems defending against sophisticated Distributed-Denial of Service (DDoS) attacks: 1) it is unable to make optimal mutation selection due to insufficient learning in attack behaviors and 2) because network situation is time varying, RM also lacks self-adaptation in mutation parameters. In this article, we propose a context-aware Q-learning algorithm for RM (CQ-RM) that can learn attack strategies to optimize the selection of mutated routes. We first integrate four representative attack strategies into a unified mathematical model and formalize multiple network constraints. Then, taking above network constraints into considerations, we model RM process as a Markov decision process (MDP). To look for the optimal policy of MDP, we develop a context estimation mechanism and further propose the CQ-RM scheme, which can adjust learning rate and mutation period adaptively. Correspondingly, the optimal convergence of CQ-RM is proved theoretically. Finally, extensive experimental results highlight the effectiveness of our method compared to representative solutions. Changqiao Xu, Tao Zhang 0063, Xiaohui Kuang, Zan Zhou 0001, Shui Yu 0001 |
IEEE Internet Things J. | 3 |
| 2021 | A discrete cosine transform-based query efficient attack on black-box object detectors
Xiaohui Kuang, Xianfeng Gao, Lianfang Wang, Lishan Ke, Quanxin Zhang 0001 |
Inf. Sci. | 1 |
| 2021 | Towards a physical-world adversarial patch for blinding object detection models
Xiaohui Kuang, Yu-an Tan 0001, Quanxin Zhang 0001 |
Inf. Sci. | 3 |
| 2021 | An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers
Yutian Zhou, Yu-an Tan 0001, Quanxin Zhang 0001, Xiaohui Kuang, Yahong Han |
Mob. Networks Appl. | 4 |
| 2021 | Oblivious Transfer for Privacy-Preserving in VANET's Feature MatchingabstractIn the feature matching of some Vehicular Ad Hoc Network (VANET) technologies, users' privacy disclosure issue has seriously threatened personal safety and caused considerable economic loss. In this paper, we proposed Oblivious Transfer (OT) protocol and Private Set Intersection (PSI) protocol to protect the users' privacy in the situation of VANET's feature matching. In our schema, an efficient k-out-of- n OT protocol is constructed. Then, this OT protocol is adopted to give a PSI protocol with equality test. Based on the PSI protocol, the two parties of VANET can obtain the intersection of their characteristic sets and any information outside such intersection is unavailable. Accordingly, internal attacker fails to get any useful information from the two parties in the feature matching, and the two parties cannot obtain extra data of each other. Moreover, to reduce the computational cost of the OT protocol, the non-communicative algebraic structure-group ring Zq[Sm] is employed. In addition, we analyzed that the proposed scheme does not use complex calculations and can resist against the current quantum attacks. Xianmin Wang, Xiaohui Kuang, Jin Li 0002, Jing Li 0045, Xiaofeng Chen 0001, Zheli Liu |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2020 | Intelligent-driven Adapting Defense Against the Client-side DNS Cache Poisoning in the CloudabstractA new Domain Name System (DNS) cache poisoning attack aiming at clients has emerged recently. It induced cloud users to visit fake web sites and thus reveal information such as account passwords. However, the design of current DNS defense architecture does not formally consider the protection of clients. Although the DNS traffic encryption technology can alleviate this new attack, its deployment is as slow as the new DNS architecture. Thus we propose a lightweight adaptive intelligent defense strategy, which only needs to be deployed on the client without any configuration support of DNS. Firstly, we model the attack and defense process as a static stochastic game with incomplete information under bounded rationality conditions. Secondly, to solve the problem caused by uncertain attack strategies and large quantities of game states, we adopt a deep reinforcement learning (DRL) with guaranteed monotonic improvement. Finally, through the prototype system experiment in Alibaba Cloud, the effectiveness of our method is proved against multiple attack modes with a success rate of 97.5% approximately. Tengchao Ma, Changqiao Xu, Zan Zhou 0001, Xiaohui Kuang, Lujie Zhong, Luigi Alfredo Grieco |
GLOBECOM | 4 |
| 2020 | Multi-vNIC Intelligent Mutation: A Moving Target Defense to thwart Client-side DNS Cache AttackabstractAs massive research efforts are poured into server-side DNS security enhancement in online cloud service platforms, sophisticated APTs tend to develop client-side DNS attacks, where defenders only have limited resources and abilities. The collaborative DNS attack is a representative newest client-side paradigm to stealthily undermine user cache by falsifying DNS responses. Different from existing static methods, in this paper, we propose a moving target defense solution named multi-vNIC intelligent mutation to free defenders from arduous work and thwart elusive client-side DNS attack in the meantime. Multiple virtual network interface cards are created and switched in a mutating manner. Thus attackers have to blindly guess the actual NIC with a high risk of exposure. Firstly, we construct a dynamic game-theoretic model to capture the main characteristics of both attacker and defender. Secondly, a reinforcement learning mechanism is developed to generate adaptive optimal defense strategy. Experiment results also highlight the security performance of our defense method compared to several state-of-the-art technologies. Zan Zhou 0001, Changqiao Xu, Tengchao Ma, Xiaohui Kuang |
ICC | 4 |
| 2020 | Two-Way Feature-Aligned And Attention-Rectified Adversarial TrainingabstractAdversarial training increases robustness by augmenting training data with adversarial examples. However, vanilla adversarial training may be overfitting to certain adversarial attacks. Small perturbations in images bring in error which is gradually amplified when forwarded through the model so that the error leads to wrong classification. Besides, small perturbations will also distract classifier's attention to significant features that are relevant to the true label. In this paper, we propose a novel two-way feature-aligned and attention-rectified adversarial training (FAAR) to improve adversarial training (AT). FAAR utilizes two-way feature alignment and attention rectification to mitigate the problems mentioned above. FAAR effectively suppresses perturbations in lowlevel, high-level and global features by moving features of perturbed images towards those of clean images with twoway feature alignment. It also leads the model into focusing more on useful features which are correlated with true label through rectifying gradient-weighted attention. Besides, feature alignment activates attention rectification by reducing perturbations in high-level feature. Our proposed method FAAR surpasses other existing AT methods in three aspects. First, it pushes the model to keep invariant when dealing with different adversarial attacks and different magnitude of perturbations. Second, it can be applied to any convolution neural networks. Third, the training process is end-to-end. For experiments, FAAR shows promising defense performance on CIFAR-10 and ImageNet. Fan Jia 0006, Quanxin Zhang 0001, Yahong Han, Xiaohui Kuang, Yu-an Tan 0001 |
ICME | 5 |
| 2020 | Non-norm-bounded Attack for Generating Adversarial Examples
Ming Zhang 0021, Xiaohui Kuang, Yuanping Nie, Zhendong Wu |
ICONIP (5) | 3 |
| 2020 | A Study on Mesh Hybrid Memory Cube NetworkabstractThe following topics are dealt with: cache storage; learning (artificial intelligence); parallel processing; neural nets; graphics processing units; power aware computing; storage management; microprocessor chips; multiprocessing systems; benchmark testing. Ming Zhang 0021, Xiaohui Kuang |
ISPASS | 3 |
| 2020 | DQ-RM: Deep Reinforcement Learning-based Route Mutation Scheme for Multimedia ServicesabstractIncreasingly growing various multimedia services (e.g., interactive live video and so on) have brought tremendous pressure on existing static defense techniques. To cope with inherent drawback of static defense techniques, Network Moving Target Defense (NMTD) such as route mutation (RM) was proposed. What's more, applying reinforcement learning (RL) into RM has been proved feasible in our previous work. But two main problems still need to be considered in this combination of RL with RM: 1) It lacks the consideration of multiple flows situation. 2) With the state-action space grow larger, current solution can't handle efficiently. In this paper, we propose a deep Q-learning method for RM (DQ-RM) to solve above two problems. Firstly, benefited from the satisfiability module theory, we formalize RM space considering single flow and multiple flows concurrently. Then we further propose a deep reinforcement learning-based RM scheme based on our previous work, which is suitable for large-scale state-action space. Finally, extensive experimental results highlight the improvement of DQ-RM in defense performance and convergence speed compared to the representative solution. Tao Zhang 0063, Changqiao Xu, Bingchi Zhang, Xiaohui Kuang, Gabriel-Miro Muntean |
IWCMC | 4 |
| 2020 | A Hybrid Interface Recovery Method for Android Kernels FuzzingabstractAndroid kernel fuzzing is a research area of interest specifically for detecting kernel vulnerabilities which may allow attackers to obtain the root privilege. The number of Android mobile phones is increasing rapidly with the explosive growth of Android kernel drivers. Interface aware fuzzing is an effective technique to test the security of kernel driver. Existing researches rely on static analysis with kernel source code. However, in fact, there exist millions of Android mobile phones without public accessible source code. In this paper, we propose a hybrid interface recovery method for fuzzing kernels which can recover kernel driver interface no matter the source code is available or not. In white box condition, we employ a dynamic interface recover method that can automatically and completely identify the interface knowledge. In black box condition, we use reverse engineering to extract the key interface information and use similarity computation to infer argument types. We evaluate our hybrid algorithm on on 12 Android smartphones from 9 vendors. Empirical experimental results show that our method can effectively recover interface argument lists and find Android kernel bugs. In total, 31 vulnerabilities are reported in white and black box conditions. The vulnerabilities were responsibly disclosed to affected vendors and 9 of the reported vulnerabilities have been already assigned CVEs. Shuaibing Lu, Xiaohui Kuang, Yuanping Nie, Zhechao Lin |
QRS | 2 |
| 2020 | Enhancing Randomization Entropy of x86-64 Code while Preserving Semantic ConsistencyabstractCode randomization is considered as the basis of mitigation against code reuse attacks, fundamentally supporting some recent proposals such as execute-only memory (XOM) that aims at dynamic return-oriented programming (ROP) attacks. However, existing code randomization methods are hard to achieve a good balance between high-randomization entropy and semantic consistency. In particular, they always ignore code semantic consistency, incurring performance loss and incompatibility with current security schemes, e.g., control flow integrity (CFI). In this paper, we present an enhanced code randomization method termed as HCRESC, which can improve the randomization entropy significantly, meanwhile ensure the semantic consistency between variants and the original code. HCRESC reschedules instructions within the range of functions rather than basic blocks, thus producing more variants of the original code and preserving the code's semantic. We implement HCRESC on Linux platform of x86-64 architecture and demonstrate that HCRESC can increase the randomization entropy of x86-64 code over than 120% compared with existing methods while ensuring control flow and size of the code unaltered. Xuewei Feng, Dongxia Wang 0001, Zhechao Lin, Xiaohui Kuang |
TrustCom | 4 |
| 2020 | Privacy preservation for machine learning training and classification based on homomorphic encryption schemes
Xiaohui Kuang, Shujie Lin |
Inf. Sci. | 2 |
| 2020 | An adversarial attack on DNN-based black-box object detectors
Yu-an Tan 0001, Wenjiao Zhang, Yuhang Zhao 0003, Xiaohui Kuang |
J. Netw. Comput. Appl. | 5 |
| 2020 | Adaptive iterative attack towards explainable adversarial robustness
Yahong Han, Quanxin Zhang 0001, Xiaohui Kuang |
Pattern Recognit. | 4 |
| 2020 | BMOP: Bidirectional Universal Adversarial Learning for Binary OpCode FeaturesabstractFor malware detection, current state-of-the-art research concentrates on machine learning techniques. Binary n -gram OpCode features are commonly used for malicious code identification and classification with high accuracy. Binary OpCode modification is much more difficult than modification of image pixels. Traditional adversarial perturbation methods could not be applied on OpCode directly. In this paper, we propose a bidirectional universal adversarial learning method for effective binary OpCode perturbation from both benign and malicious perspectives. Benign features are those OpCodes that represent benign behaviours, while malicious features are OpCodes for malicious behaviours. From a large dataset of benign and malicious binary applications, we select the most significant benign and malicious OpCode features based on the feature SHAP value in the trained machine learning model. We implement an OpCode modification method that insert benign OpCodes into executables as garbage codes without execution and modify malicious OpCodes by equivalent replacement preserving execution semantics. The experimental results show that the benign and malicious OpCode perturbation (BMOP) method could bypass malicious code detection models based on the SVM, XGBoost, and DNN algorithms. Xiang Li 0078, Yuanping Nie, Zhi Wang 0014, Xiaohui Kuang, Kefan Qiu |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | An Intelligent Route Mutation Mechanism against Mixed Attack Based on Security AwarenessabstractStatic network defense technologies are always in a passive defense state because of their disadvantages in cost, time and information. So Network Moving Target Defense (NMTD) is proposed as a kind of proactive defense technology. As an important research direction of NMTD, route mutation techniques still have limitations that they can not learn attack strategies and be adaptive in dynamical security situation. In this paper, we propose a novel route mutation mechanism based on reinforcement learning. We firstly investigate four different attack strategies and introduce a mixed attack strategy with entropy constraints. Then we formulate the network requirements using Satisfiability Module Theory (SMT) logic to acquire the route mutation space. We further propose a security-awareness Q- learning algorithm to select routes from the mutation space iteratively and conduct security awareness to adjust learning rate adaptively. Meanwhile, the optimal convergence of our algorithm is proved theoretically. Finally, experimental results highlight the effectiveness as defense performance, network overhead and convergence speed of our method compared to the representative solution. Tao Zhang 0063, Xiaohui Kuang, Zan Zhou 0001, Hongquan Gao, Changqiao Xu |
GLOBECOM | 2 |
| 2019 | An Efficient and Agile Spatio-Temporal Route Mutation Moving Target Defense MechanismabstractFor the reasons that defect remedy is an endless arduous work for static network defense technologies and cyberspace security remains unguaranteed, moving target defense (MTD) is proposed to stem the tide. Whereas, as an important branch of MTD, route mutation technologies still have limitations against some sophisticated adversaries like Advanced Persistent Threat (APT), multiple-step complex or combined attacks. In this paper, we propose a new spatio-temporal route mutation method based on MTD. We first take the maximization of resistibility towards not only multiple forms of attacks but also attackers' long-term background knowledge into consideration. We also formulate the problem into a stochastic optimization model and make it possible to agilely generate the satisfying mutation route meets the demands of various parties jointly by only solving one uniform problem. Thus, network Security is guaranteed from both flows(users) and nodes(infrastructure) perspectives. Experimental results highlight the security advantages as traffic dispersion, potential victim number and attack failure rates of our method compared to existing solutions. Zan Zhou 0001, Changqiao Xu, Xiaohui Kuang, Tao Zhang 0063, Limin Sun 0001 |
ICC | 3 |
| 2019 | Neuron Selecting: Defending Against Adversarial Examples in Deep Neural Networks
Ming Zhang 0021, Xiaohui Kuang, Ling Pang, Zhendong Wu |
ICICS | 3 |
| 2019 | Untargeted Adversarial Attack via Expanding the Semantic GapabstractRecent studies have demonstrated deep neural network-based image classifiers are vulnerable to adversarial examples. Although many existing methods could obtain outstanding attack performance, they often require certain information about the attacked model, e.g., the output category scores. Meanwhile, the optimization-based methods need many steps to generate adversarial examples. In practice, we could obtain the output label but the category scores. Besides, compared to those samples with large semantic category gaps, e.g., Panda and Gibbon, most existing methods are not easy to find adversarial examples on samples with small semantic category gaps, e.g., Tabby Cat and Egyptian Cat. Thus, we propose an untargeted adversarial attack method via expanding the semantic gap, which only relies on the output label. And we use the optimization-based method to generate adversarial examples. On five normally trained models and five state-of-the-art attack methods, extensive experiments show that our method is effective and obtains better attack performance. Aming Wu, Yahong Han, Quanxin Zhang 0001, Xiaohui Kuang |
ICME | 4 |
| 2019 | SE-PSO: Resource Scheduling Strategy for Multimedia Cloud Platform Based on Security Enhanced Virtual MigrationabstractIn the multimedia cloud platform, the resource scheduling performance directly affects the energy consumption, resource utilization of the active physical machine (PM) and virtual machine (VM) security. Besides, service level agreement (SLA) violation rate also fluctuates with the strategy. Many optimization methods have been launched to cope with this scheduling task, while none of them accommodate all the above aspects in a uniform manner to our best knowledge. In this paper, aiming at optimizing the four sides performance, we propose a new resource scheduling strategy called Security Enhanced Particle Swarm Optimization (SE-PSO) based on VM migration which uses Particle Swarm Optimization (PSO) as a kernel part. Firstly, the inertia factor and the learning factor are dynamically adapted to improve the search performance of SE-PSO. Then, by periodically predicting physical hotspots with the exponential smoothing model, we reduce unnecessary migrations and thus minimize the VM migration security risk. Finally, roulette wheel idea is applied to achieve long-term optimization of the platform resources. The experiments conducted in CloudSim with real-world dataset also show that SE-PSO has a good overall performance in energy consumption, resource utilization, SLA violation rate and migration security compared with the mainstream PSO algorithm. Tengchao Ma, Changqiao Xu, Zan Zhou 0001, Xiaohui Kuang, Lujie Zhong |
IWCMC | 4 |
| 2019 | Detecting adversarial examples via prediction difference for deep neural networks
Qingjie Zhao, Xiaohui Kuang, Jianwei Zhang 0001, Yahong Han, Yu-an Tan 0001 |
Inf. Sci. | 4 |
| 2019 | The security of machine learning in an adversarial setting: A survey
Xianmin Wang, Jing Li 0045, Xiaohui Kuang, Yu-an Tan 0001, Jin Li 0002 |
J. Parallel Distributed Comput. | 3 |
| 2018 | Balancing the QOS and Security in Dijkstra Algorithm by SDN Technology
Jinjing Zhao, Ling Pang, Xiaohui Kuang |
NPC | 3 |
| 2015 | A clustering approach based on convergence degree chain for wireless sensor networksabstractAbstract Wireless sensor networks (WSNs) play an important role in pervasive and ubiquitous systems. The energy consumption, scalability, stability, and lifetime are still open issues in WSNs. Clustering approach has been considered one of the most effective measures and has received tremendous attention in this research area. But most clustering algorithms of the previous related works adopt the idea of periodically and globally regrouping cluster nodes that may cause the improper energy consumption and link state instability during the clustering procedure. Aiming to decrease energy consumption of sensor node and increase WSNs stability, a novel Energy‐efficient Clustering Approach based on Convergence Degree chain, which is termed as ECACD, is proposed in this paper. ECACD protocol can improve stability of topology by using convergence degree and residual energy for cluster head election, reduce energy consumption of member node by cluster joining policy for cluster formation, and decrease communication cost by rotating cluster head according to convergence degree chain generated at initial stage. Analysis and simulation results show the advantage and effectiveness of our approach in terms of the cluster header characteristics and the network life time. According to the comparison with HEED (Hybrid Energy‐Efficient Distributed clustering), which is an energy‐efficient approach for clustering nodes in sensor networks by periodically selecting cluster heads according to a hybrid of their residual energy and a secondary parameter, ECACD increases the stability and extends the network life by 26% and 85%. Copyright © 2014 John Wiley & Sons, Ltd. Xiaohui Kuang, Xiang Li 0078 |
Secur. Commun. Networks | 1 |
| 2014 | On Effectiveness of Clustering Principles in Maximizing Wireless Sensor Network Lifespan
Xiaohui Kuang |
WASA | 1 |
| 2011 | Research on survivability metrics based on survivable process of network systemabstractSurvivability is a necessary property of network system in disturbed environment. A survivable network always experience five phases, i.e., normal phase, resistance phase, destroyed phase, recovery phase, and adaptation and evolution phase, in its survivable process. This paper concludes the network survivability into four basic attributes: availability, controllability, robustness, and adaptability. According to these four attributes and five phases of a survivable network, this paper provides four novel quantifiable survivability metrics, i.e., Process-Weighted Average Availability (PWAA), Process-Weighted Average Controllability (PWAC), Process-Weighted Average Robustness (PWAR), and Process-Weighted Average Adaptability (PWAD). Analysis and Experiment results show that, these four quantitative metrics describe the meaning of network survivability properly, and can be used to test and evaluate survivability of network during the survivable process. Liang Ming, Minhuan Huang, Dongxia Wang 0001, Xiaohui Kuang, Xuewei Feng |
SIN | 4 |
| 2009 | Research on Technologies of Building Experimental Environment for Network Worm SimulationabstractThe worm experimental environment is a pivotal foundation for the worm research. In this paper, with a comprehensive analysis of existing technologies for building worm experimental environment, including analytical model, packet-level simulation, network simulation, hybrid method, and so on, we present a novel virtual-real hybrid worm simulation model. This model integrates the advantages of network simulation and packet-level simulation, and thus achieves a preferable balance between the fidelity and scalability. Our model builds a promising foundation for constructing a flexible and extensible worm experimental environment. Minhuan Huang, Xiaohui Kuang, Yan Wen 0001 |
ICPADS | 2 |