VLDB 2026 Research / reviewers in the wild / expert
Lixin Zhao
dblp:181/8082
· DBLP profile ↗
22ranked-venue papers
3as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 7 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SLGParser: Practical and Efficient Label-Free Log Parsing Using Large Language Models
Yibing Hu, Lixin Zhao |
ICDE | 3 |
| 2026 | Vaccine: Injection vulnerabilities mitigation through dynamic process control with eBPF
Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
Comput. Secur. | 4 |
| 2026 | LogNER: Enhancing log semantics with LLM-driven entity recognition
Chentong Zhao, Jinpeng Xiang, Lixin Zhao, Dan Meng 0002 |
J. Syst. Softw. | 3 |
| 2026 | DriftTrace: Combating Concept Drift in Security Applications Through Detection and Explanation
Yuedong Pan, Lixin Zhao, Tao Leng, Zhexi Luo, Dan Meng 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | When Pre-Training Meets Contrast Learning: Few-Shot Encrypted Traffic Classification With Novelty DetectionabstractEncrypted traffic classification plays an important role on network security and network management. However, existing methods face two key limitations: they require large volumes of labeled data and are typically designed under the closed-world assumption. This paper presents a novel approach combining pre-training techniques with contrast learning to address the challenges of open-world encrypted traffic classification. Our method utilizes a BERT-based pre-training model to learn generic traffic representations from large-scale unlabeled encrypted traffic. In this stage, two pre-training tasks, the Masked BURST Model (MBM) and BURST Context Prediction (BCP), are introduced to capture both structural and contextual features of the traffic. Following this, a contrast learning strategy is applied on a small labeled dataset to learn a discriminative feature space, where traffic from the same category is clustered closely, and traffic from different categories is largely separated. This strong discriminative property enables high-accuracy classification of known traffic categories while detecting novel ones. Experimental results on five encrypted traffic classification tasks demonstrate that: (1) under full data conditions, our approach outperforms state-of-the-art methods with up to an 11.60% improvement in F1 score in both closed- and open-world scenarios; (2) even when working in a few-shot mode, our method achieves the best performance in three out of five tasks in the closed-world setting and consistently outperforms the best methods by up to 9.99% in terms of F1 score in the open-world scenario. Lixin Zhao, Changhao Wu |
IEEE Trans. Netw. | 1 |
| 2025 | CBARMM: Cluster-Based Association Rule Mining Method for Attribute-Based Access ControlabstractAttribute-Based Access Control (ABAC) technology utilizes the inherent attributes of subjects, environments, and objects for effective access control. It is characterized by dynamic flexibility, strong scalability, granularity, and automated decision-making, making it an ideal solution for data security in big data environments. However, transitioning from traditional access control models, such as Access Control Lists (ACL) and Role-Based Access Control (RBAC), to ABAC can be a time-consuming, labor-intensive, and error-prone process, particularly when configuring security policies. Based on this, we propose the cluster-based association rule mining method (CBARMM) to automatically generate security policies from access logs and attribute files, thereby simplifying the model migration process. First, we employ the random forest algorithm to select attributes and evaluate their impact on authorization decisions. Next, we apply weight based K-modes and SD-map algorithms to extract attribute relationship filters and attribute value filters. Finally, the policy is continuously optimized through two methods of policy refinement. The experimental results demonstrate that our proposed method holds significant research and application value in the mining of attribute-based access control policies. Haihua Gao, Lixin Zhao |
CSCWD | 3 |
| 2025 | VDPST: Enhancing Line-Level Vulnerability Detection with Patch Slicing and TransformersabstractVulnerability detection is essential for ensuring software security. In recent years, deep learning has seen widespread adoption in this domain due to its capacity to automatically extract features from vulnerable code, showcasing significant potential. However, existing approaches still struggle to accurately focus on vulnerability-relevant portions within vulnerable functions, and most solutions typically offering coarse-grained localization, usually at the function level. In this paper, we propose VDPST, a novel deep learning-based approach that achieves effective vulnerability detection through program slicing and an enhanced Transformer model. VDPST introduces a patch-based denoising strategy to eliminate irrelevant code information, improving detection accuracy. Additionally, the model integrates a Transformer architecture with residual inputs and cross-attention mechanisms to preserve the contextual integrity of code snippets and enhance the detection of vulnerability-specific features. Experimental results demonstrate that VDPST outper-forms existing state-of-the-art methods on public benchmark datasets, offering superior detection accuracy and fine-grained vulnerability localization capabilities. Shirun Liu, Zhengkai Qin, Lixin Zhao, Haihua Gao |
CSCWD | 3 |
| 2025 | ET-Former: Robust Transformer-Based Representation for Encrypted Traffic ClassificationabstractEncrypted traffic classification requires capturing robust and effective traffic representations from data that lack explicit patterns and clear semantics, which is crucial for network management and cybersecurity. Existing methods heavily rely on large amounts of labeled data or expert-designed features and struggle to generalize across different classification scenarios. Leveraging unlabeled traffic data to learn universal representations of encrypted traffic remains a key challenge. In this paper, we propose a novel traffic representation model called ET-Former. ET-Former learns universal representations of various encrypted traffic from large-scale unlabeled data and can be fine-tuned with a small amount of labeled data for specific tasks. ET-Former achieves state-of-the-art performance in four of five encrypted traffic classification tasks, demonstrating exciting features such as robustness, generalization, and accuracy. Changhao Wu, Lixin Zhao, Dan Meng 0002 |
CSCWD | 2 |
| 2025 | CASPR: Context-Aware Security Policy Recommendation
Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
NDSS | 4 |
| 2025 | LLMPEx: Automatic Extraction of ABAC Policies from Natural Language Documents Using LLMsabstractIn the domain of enterprise security, the management and implementation of access control policies are critical for safeguarding sensitive information and maintaining system integrity. Current security standard documents and internal authorization specifications typically adopt unstructured formats with highly specialized terminology, creating challenges for non-specialist personnel such as system administrators who struggle to translate complex technical terms and logical rules into Attribute-Based Access Control (ABAC) policies due to insufficient professional expertise. These challenges often lead to misinterpretations and conversion errors that significantly undermine policy accuracy and effectiveness. To address this issue, we introduce LLMPEx, an innovative framework that leverages the semantic capabilities of large language models (LLMs) to automatically convert Natural Language Access Control Policies (NLACPs) into ABAC policies. LLMPEx integrates three core modules: a text classification module for identifying Access Control Policy (ACP) statements, an entity recognition module for extracting entity information from natural language texts, and a policy generation module that uses LLMs to automatically extract ABAC policies based on the texts and the identified entity information. The experimental results validate the effectiveness of LLMPEx in both text recognition and policy generation tasks, demonstrating that it enhances the reliability in ABAC policy creation while reducing manual efforts and potential human errors. Haihua Gao, Lixin Zhao |
SMC | 2 |
| 2025 | TaintAttack: rapid attack investigation based on information flow trackingabstractAbstract The perpetual battle between defenses and attacks in computing systems keeps evolving. In response to the growing complexity of attacks, data provenance has emerged as a vital solution for analysing alarms and conducting attack investigation by capturing intricate relationships among system entities. Despite its potential, the challenges of dealing with large-scale provenance graphs and a high volume of alarms persist, leading to inefficiencies in alarm analysis and attack investigation. To tackle these challenges, we present TaintAttack, an innovative approach for attack investigation. When performing provenance graph construction, TaintAttack conducts real-time tagging for system entities. To emphasize the critical threats, TaintAttack quantifies the threat levels of alarms based on event rarity, contextual features, and impact severity. Furthermore, guided by information flow tagging, TaintAttack commences attack investigation from alarms with high threat levels, greatly enhancing the overall efficiency of the investigation process. The evaluation results on 12 multi-stage attacks show that TaintAttack performs better in attack investigation compared to existing studies, reducing the investigation time by 2 orders of magnitude. Yuedong Pan, Lixin Zhao, Tao Leng, Chaofei Li |
Comput. J. | 2 |
| 2024 | MLCAC: Dynamic Authorization and Intelligent Decision-making towards Insider ThreatsabstractNowadays, the situation of data security is ever-increasing severity, however, the most damaging security threats do not originate from malicious outsiders but from malfeasant and negligent insiders. Generally, insider threats are prone to cause incalculable losses and serious issues due to that the insiders have the authority to access sensitive information. Therefore, how to effectively prevent and respond to insider threats is a significant challenge. Undoubtedly, the key to defending against insider threats is restricting access permissions and optimizing access control policies in real-time. To enhance data security, we propose MLCAC, a multi-layered collaborative access control model, which focuses on protecting sensitive data. A key insight is the design of a decentralized optimization for domain and authority. MLCAC prohibits unauthorized behavior and continuously monitors access logs which are analyzed by using the co-occurrence matrix to make intelligent decisions and dynamically adjust the access control policy in real time. In experiments, we collected 12574 access logs about 1753 system software and analyzed the correlation between software by using the co-occurrence matrix algorithm, including 824 groups co-occurring software of which the highest frequency is 12. The experiments indicate that the accuracy of the policy generated by intelligent decision-making is 89.55%. Therefore, the algorithm is significantly efficient for intelligent decision-making, which is the foundation of automatically generating policies and dynamic authorization. Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
CSCWD | 4 |
| 2024 | EntityParser: A Log Analytics Parser for Identifying Entities from System LogsabstractSystem logs are used to record the operating system and application program runtime status, constituting a form of semi-structured text. Analyzing these logs becomes pivotal in addressing failures or abnormalities within the operating system or application. However, the substantial volume of log data necessitates extensive manual analysis. To overcome this problem, researchers propose an automated log parsing method that reduces the volume of logs by parsing them into templates. However, a profound understanding of these templates still requires domain-specific knowledge. Therefore, this paper proposes EntityParser, which aims at enhancing log semantics. EntityParser identifies entities within log templates, mapping abstract log messages to specific, meaningful entities, thereby enhancing the readability of the logs. Additionally, EntityParser maintains two high-quality knowledge bases and can enrich them through self-iteration.Finally, in order to validate the efficacy of EntityParser, we conduct experiments on the LogHub dataset and the Linux system log dataset collected from real production environments. The results demonstrate the effectiveness of the proposed method in improving log semantics, discovering new entities, and proving its generalization. Furthermore, it enables the discovery of all potential entities within the current log through self-iteration. Chentong Zhao, Jinpeng Xiang, Lixin Zhao, Jiangang Ma |
CSCWD | 3 |
| 2024 | ATKHunter: Towards Automated Attack Detection by Behavior Pattern Learning
Yuedong Pan, Lixin Zhao, Chaofei Li, Tao Leng, Dan Meng 0002 |
ICDF2C (1) | 2 |
| 2024 | Early Detection of Fileless Attacks Based on Multi-Feature Fusion of Complex Attack VectorsabstractThe initial manifestations of fileless attacks were predominantly document-based attacks, extensively leveraged in Advanced Persistent Threat (APT) campaigns and cybercriminal activities. Malicious documents leveraging macros, DDE, template injection, and other attack vectors evade conventional signature-based detection techniques. Additionally, the constant influx of new samples undermines models trained only on single attack vector features. Herein, we introduce DocInspect, a methodological framework predicated on the multi-feature fusion of complex attack vectors. Through observational analyses of attack vectors, static analysis extracts keywords and indicators of compromise from vectors like macro code, simulated execution retrieves shellcode function calls and parameters, and deceptive images and text are concurrently extracted. These multi-dimensional features are then fused to construct feature vectors. Ultimately, leveraging the Extra Trees model on our latest sample set, we achieve an F1 score of 99.96%, while demonstrating commendable robustness. Tao Leng, Lixin Zhao, Yuedong Pan, Dan Meng 0002 |
ISCC | 2 |
| 2024 | Ranker: Early Ransomware Detection Through Kernel-Level Behavioral AnalysisabstractRansomware is a rapidly evolving type of malware crafted to encrypt user files, rendering them inaccessible and demanding a ransom. The impact of ransomware attacks on both enterprises and individuals is significant. However, early detection of such malware remains a formidable challenge with current detection methods. In this paper, we propose Ranker, a real-time approach designed for early ransomware detection through kernel-level behavioral analysis. Analyzing various ransomware families, we discovered that half of these attacks exhibit stealthy behaviors preceding the actual attack. Extracting insights from the pre-attack malicious behavior proves effective for early detection of ransomware. For ransomware families that encrypt files directly, considering that interacting with user files is their goal, our focus is on monitoring file changes during the attack, hoping to detect ransomware when fewer files are lost. Therefore, Ranker systematically characterizes the kernel-level behavior of ransomware during the pre-attack and attack stages, identifying general and essential characteristics. Ranker also introduces a lightweight detector for real-time ransomware detection. Extensive experiments demonstrate that Ranker achieves an average F1 score of 99.43% in ransomware detection, with a mere 0.11% false positives across 68 distinct ransomware families. Notably, Ranker detects 95% of ransomware attacks with no more than one file encrypted and attains a 97.16% accuracy in identifying 22 previously unseen ransomware families. Lixin Zhao, Dan Meng 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | MemInspect: Memory Forensics for investigating Fileless AttacksabstractTraditional security solutions focus on identifying threats that leave traces on the system’s hard drive. However, fileless attacks have become increasingly popular among cybercriminals due to their ability to evade detection and persist undetected for prolonged periods. In response, memory forensics facilitates the extraction of system memory activities, presenting an opportunity to detect fileless attacks executed directly in memory. This paper presents MemInspect, a specialized memory forensics approach designed to extract features and accurately identify and locate suspicious memory regions, effectively aiding analysts in investigating fileless malware attacks. Specifically, By Utilizing virtual address descriptor nodes as samples, MemInspect constructs a comprehensive set of 42 features to detect code injection, script-based attacks, and living off the land attacks. Subsequently, these features are employed for classification using ensemble learning algorithms. In this study, we meticulously designed comprehensive attack experiments, accurately simulating three prevalent types of fileless attacks. Through rigorous analysis and extensive training on the experimental data, MemInspect demonstrates remarkable performance, achieving an impressive Area Under the Curve (AUC) value of 98%. Additionally, the paper provides two detailed analysis cases of attack investigations, furnishing concrete evidence of MemInspect’s efficacy in detecting fileless attacks. Tao Leng, Yuedong Pan, Lixin Zhao, Dan Meng 0002 |
TrustCom | 3 |
| 2022 | AttackMiner: A Graph Neural Network Based Approach for Attack Detection from Audit Logs
Yuedong Pan, Tao Leng, Lixin Zhao, Jiangang Ma, Dan Meng 0002 |
SecureComm | 4 |
| 2021 | Towards Open World Traffic Classification
Lixin Zhao, Dan Meng 0002 |
ICICS (1) | 3 |
| 2021 | DeepHunter: A Graph Neural Network Based Approach for Robust Cyber Threat Hunting
Renzheng Wei, Lixin Zhao, Dan Meng 0002 |
SecureComm (1) | 3 |
| 2020 | A Study on the Factors Influencing the Participation of Face-to-Face Discussion and Online Synchronous Discussion in Class
Lixin Zhao, Xiaoxia Shen, Wu-Yuin Hwang, Timothy K. Shih |
ITS | 1 |
| 2019 | Prototype-Based Malware Traffic Classification with Novelty Detection
Lixin Zhao, Zhen Xu 0009, Dan Meng 0002 |
ICICS | 1 |