VLDB 2026 Research / reviewers in the wild / expert
Zhiqiang Shi
dblp:19/6306
· DBLP profile ↗
36ranked-venue papers
3as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 7 · 7 since 2021Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Vercation: Precise Vulnerable Open-Source Software Version Identification Based on Static Analysis and LLMabstractOpen-source software (OSS) has experienced a surge in popularity, attributed to its collaborative development model and cost-effective nature. However, the adoption of specific software versions in development projects may introduce security risks when these versions bring along vulnerabilities. Current methods of identifying vulnerable versions typically analyze and extract the code features involved in vulnerability patches using static analysis with pre-defined rules. They then use code clone detection to identify the vulnerable versions. These methods are hindered by imprecision due to (1) the exclusion of vulnerability-irrelevant code in the analysis and (2) the inadequacy of code clone detection. This paper presents VERCATION, an approach designed to identify vulnerable versions of OSS written in C/C++. VERCATION combines program slicing with a Large Language Model (LLM) to identify vulnerability-relevant code from vulnerability patches. It then backtracks historical commits to gather previous modifications of identified vulnerability-relevant code. We propose code clone detection based on expanded and normalized ASTs to compare the differences between pre-modification and post-modification code, thereby locating the vulnerability-introducing commit (vic) and enabling the identification of the vulnerable versions between the vulnerability-fixing commit and thevic. We curate a dataset linking 122 OSS vulnerabilities and 1,211 versions to evaluate VERCATION. On this dataset, our approach achieves an F1 score of 93.1%, outperforming current state-of-the-art methods. More importantly, VERCATION detected 202 incorrect vulnerable OSS versions in NVD reports. Yiran Cheng, Ting Zhang 0011, Lwin Khin Shar, Shouguo Yang, Chaopeng Dong, David Lo 0001, Shichao Lv, Zhiqiang Shi, Limin Sun 0001 |
IEEE Trans. Software Eng. | 8 |
| 2025 | Exp-Arch: A Novel LLM-Powered Approach for Facilitating Exploit Primitive Assessment in the Linux KernelabstractTransforming Linux kernel exploit primitives into full Privilege Escalation (PE) exploits is a critical, expertiseintensive, and time-consuming challenge, especially with constantly evolving kernel mitigations. While previous research has advanced automated kernel exploit development, these efforts often focused on specialized scenarios rather than providing a generalized, end-to-end framework for diverse primitives. This limitation restricts the exploration of a primitive's true exploit potential. This paper introduces Exp-Arch, a novel approach leveraging Large Language Models (LLMs) for the automated, end-to-end generation of PE exploits from kernel primitives. This process includes comprehensive initial assessment and subsequent exploitation. Exp-Arch's LLM-powered workflow systematically performs an in-depth semantic analysis of the input primitive, devises an intelligent strategic plan for the exploitation route, and then automates the synthesis and iterative closed-loop validation of the final PE exploit code. Exp-Arch offers accurate assessment of a primitive's exploitability and significantly accelerates the exploit development lifecycle. We evaluated ExpArch using various primitives from public Linux kernel 1-day vulnerabilities with commercial LLMs. The results show that Exp-Arch effectively converted 73 % (11 out of 15) of test cases into working kernel exploits, demonstrating its effectiveness in primitive evaluation. Zuxin Chen, Zhi Li 0018, Zhanwei Song, Zhiqiang Shi, Limin Sun 0001 |
ICPADS | 4 |
| 2025 | Moye: A Wallbreaker for Monolithic FirmwareabstractAs embedded devices become increasingly popular, monolithic firmware, known for its execution efficiency and simplicity, is widely used in resource-constrained devices. Different from ordinary firmware, the monolithic firmware image is packed without the file that indicates its format, which challenges the reverse engineering of monolithic firmware. Function identification is the prerequisite of monolithic firmware's analysis. Prior works on function identification are less effectiveness when applied to monolithic firmware due to their heavy reliance on file formats. In this paper, we propose Moye, a novel method to identify functions in monolithic firmware. We leverage the important insight that the use of registers must conform to some constraints. In particular, our approach segments the firmware, locate code sections and output the instructions. We use a masked language model to learn hiding relationships among the instructions to identify the function boundaries. We evaluate Moye using 1,318 monolithic firmware images, including 48 samples collected from widely used devices. The evaluation demonstrates that our approach significantly outperforms current works, achieving a precision greater than 98 % and a recall rate greater than 97 % across most datasets, showing robustness to complicated compilation options. Kai Yang 0037, Gaosheng Wang, Zhiqiang Shi, Zhiwen Pan, Shichao Lv, Limin Sun 0001 |
ICSE | 4 |
| 2025 | Exploiting Binary Semantics: Enhancing Function Name Inference in Stripped Binaries via LLMsabstractFunction name inference in stripped binaries is a crucial task that supports various security applications, including vulnerability detection and malware analysis. Existing methods suffer from limited model capacity and insufficient exploitation of function semantics, which constrains their ability to comprehend binary code and leads to poor generalization on unseen binaries. To address these problems, we propose BinLLM, a novel framework that leverages large language models (LLMs) to exploit the semantic potential of binary code, thereby enhancing function name inference. Specially, BinLLM integrates three key innovations: (1) source code semantics-guided function name refinement, which mitigates the negative effects of low-quality semantic identifiers during training; (2) A context-aware data collection algorithm that seeks richer semantic dependencies to improve model training and inference performance; (3) parameter-efficient fine-tuning on a domain-specific dataset enriched with semantic knowledge to enhance the model's understanding of binary semantics. These components collectively enhance the model's performance in function name inference on unseen binaries. We evaluate BinLLM on a large-scale dataset comprising$2,864,719$functions across four architectures (x86-64, x86-32, ARM, MIPS) and four optimization levels ($\mathrm{O} 0-\mathrm{O} 3$). Experimental results show that BinLLM achieves substantial improvements over state-of-the-art (SOTA) methods, with relative gains of$320.1 \%, 274.8 \%$, and 297.6 % in precision, recall, and F1-score. Ablation studies further validate the effectiveness of each component in enhancing overall performance. Kailong Wang 0007, Dongliang Fang, Zhongwei Gu, Zhanwei Song, Yongle Chen, Zhiqiang Shi, Limin Sun 0001 |
IPCCC | 7 |
| 2025 | Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationabstractProtocol reverse engineering (PRE) aims to infer the protocol formats of unknown protocols. Existing techniques, whether Network-Trace based or Execution-Trace based methods, face two main limitations: a reliance on the quality and scale of traffic datasets, which often leads to low accuracy and poor generalization; and a failure to adequately consider the multi-format characteristic prevalent in real-world protocols (i.e., the same protocol may support multiple different formats).To address these challenges, we propose ProbePRE—a PRE tool that performs multi-format extraction on protocol handlers by autonomously generating packets. ProbePRE employs three key techniques: (1) an execution tracing strategy enhanced with implicit data flow analysis to obtain more detailed execution information; (2) constraint extraction methods tailored for different program structures to pass protocol validation; and (3) an innovative constraint combination algorithm to construct effective packets that guide the protocol handler to execute diverse protocol parsing paths. In our experimental evaluation, we compared ProbePRE with 4 state-of-the-art PRE tools in terms of field segmentation accuracy. The results demonstrated that ProbePRE achieved an F1 score of 0.88, significantly outperforming existing methods. Furthermore, evaluations on 6 protocol handlers indicated that ProbePRE attained 83% completeness in multi-format extraction tasks. Notably, in basic block coverage tests, ProbePRE achieved a 67% improvement over traditional traffic dataset methods, which fully validates the effectiveness of its path exploration capabilities. Dingzhao Xue, Yibo Qu, Xin Chen 0123, Shuaizong Si, Shichao Lv, Zhiqiang Shi, Limin Sun 0001 |
ASE | 7 |
| 2025 | ICSPFuzzer: An Efficient Fuzzing Technique for ICS Protocols
Zhanwei Song, Dongliang Fang, Shunchao Xu, Yaowen Zheng, Hong Li 0004, Shichao Lv, Zhiqiang Shi, Limin Sun 0001 |
WASA (2) | 7 |
| 2025 | PREXP: Uncovering and Exploiting Security-Sensitive Objects in the Linux KernelabstractSecurity-Sensitive Objects (SSOs) are often critical components in the exploitation of Linux kernel memory corruption vulnerabilities. While existing research has advanced SSOs identification and classification, there remains a significant gap in systematically understanding how these objects can be effectively exploited in real-world security analysis. To address this challenge, we present PREXP, a novel approach to analyzing SSOs exploitability and automating the transformation of Proof-of-Concept (PoC) into exploitable states. Our approach encompasses three key techniques: (1) capability analysis and attribute modeling of vulnerable object (2) extraction and filtering of target SSOs and (3) automatically augmenting PoCs with SSO-specific code to create exploitation capabilities. To evaluate our approach, we tested our prototype on 30 public CVEs, successfully parsing vulnerable object in 22 cases (73.3%) and achieving accurate SSO matches in 18 (60.0%). PREXP outperformed state-of-the-art tools such as SCAVY and AlphaEXP in structure-matching, and enabled the generation of new Control Flow Hijacking Primitives (CFHPs) for 3 previously unexploited vulnerabilities, demonstrating its practical value in real-world exploit development. Zuxin Chen, Yaowen Zheng, Hong Li 0004, Siyuan Li 0014, Weijie Wang 0005, Dongliang Fang, Zhiqiang Shi, Limin Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | DeLink: Source File Information Recovery in BinariesabstractProgram comprehension can help analysts understand the primary behavior of a binary and enhance the efficiency of reverse engineering analysis. The existing works focus on instruction translation and function name prediction. However, they are limited in understanding the entire program. The recovered source file information can offer insights into the primary behavior of a binary, serving as high-level program summaries. Nevertheless, the files recovered by the function clustering-based approach contain binary functions with discontinuous distributions, resulting in low accuracy. Additionally, there is no existing research related to predicting the names of these recovered files. To this end, we propose a framework for source file information recovery in binaries, DeLink. This framework first leverages a file structure recovery approach based on boundary location to recognize files within a binary. Then, it utilizes an encoder-decoder model to predict the names of these files. The experimental results show that our file structure recovery approach achieves an average improvement of 14% across six evaluation metrics and requires only an average time of 16.74 seconds, outperforming the state-of-the-art work in both recovery quality and efficiency. Additionally, our file name prediction model achieves 70.09% precision and 63.91% recall. Moreover, we demonstrate the effective application of DeLink in malware homology analysis. Zhe Lang, Zhengzi Xu, Shichao Lv, Zhanwei Song, Zhiqiang Shi, Limin Sun 0001 |
ISSTA | 6 |
| 2024 | TaiE: Function Identification for Monolithic FirmwareabstractThe principal tasks of program analysis, including bug searching and code similarity detection, are executed at the function level. However, the accurate identification of functions within stripped binary files poses a significant challenge. This difficulty is exacerbated by unformatted monolithic firmware images typically found in industrial controlling device, rendering existing methods ineffective due to their dependence on specific metadata, which may be absent. Kai Yang 0037, Gaosheng Wang, Zhiqiang Shi, Shichao Lv, Limin Sun 0001 |
ICPC | 4 |
| 2024 | Active Defense Simulation Evaluation of Industrial Control Systems Based on Attack-Defense Graph
Qun Xiao, Shouguo Yang, Jiaqian Peng, Jingfei Bian, Shichao Lv, Limin Sun 0001, Zhiqiang Shi |
WASA (2) | 7 |
| 2024 | Asteria-Pro: Enhancing Deep Learning-based Binary Code Similarity Detection by Incorporating Domain KnowledgeabstractWidespread code reuse allows vulnerabilities to proliferate among a vast variety of firmware. There is an urgent need to detect these vulnerable codes effectively and efficiently. By measuring code similarities, AI-based binary code similarity detection is applied to detecting vulnerable code at scale. Existing studies have proposed various function features to capture the commonality for similarity detection. Nevertheless, the significant code syntactic variability induced by the diversity of IoT hardware architectures diminishes the accuracy of binary code similarity detection. In our earlier study and the tool Asteria , we adopted a Tree-LSTM network to summarize function semantics as function commonality, and the evaluation result indicates an advanced performance. However, it still has utility concerns due to excessive time costs and inadequate precision while searching for large-scale firmware bugs. To this end, we propose a novel deep learning-enhancement architecture by incorporating domain knowledge-based pre-filtration and re-ranking modules, and we develop a prototype named Asteria-Pro based on Asteria . The pre-filtration module eliminates dissimilar functions, thus reducing the subsequent deep learning-model calculations. The re-ranking module boosts the rankings of vulnerable functions among candidates generated by the deep learning model. Our evaluation indicates that the pre-filtration module cuts the calculation time by 96.9%, and the re-ranking module improves MRR and Recall by 23.71% and 36.4%, respectively. By incorporating these modules, Asteria-Pro outperforms existing state-of-the-art approaches in the bug search task by a significant margin. Furthermore, our evaluation shows that embedding baseline methods with pre-filtration and re-ranking modules significantly improves their precision. We conduct a large-scale real-world firmware bug search, and Asteria-Pro manages to detect 1,482 vulnerable functions with a high precision 91.65%. Shouguo Yang, Chaopeng Dong, Yang Xiao 0011, Yiran Cheng, Zhiqiang Shi, Zhi Li 0018, Limin Sun 0001 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2023 | SeHBPL: Behavioral Semantics-Based Patch Presence Test for Binaries
Gaosheng Wang, Zhiqiang Shi, Fei Lv 0010, Shichao Lv |
SETTA | 3 |
| 2023 | VERI: A Large-scale Open-Source Components Vulnerability Detection in IoT Firmware
Yiran Cheng, Shouguo Yang, Zhe Lang, Zhiqiang Shi, Limin Sun 0001 |
Comput. Secur. | 4 |
| 2023 | Towards Practical Binary Code Similarity Detection: Vulnerability Verification via Patch Semantic AnalysisabstractVulnerability is a major threat to software security. It has been proven that binary code similarity detection approaches are efficient to search for recurring vulnerabilities introduced by code sharing in binary software. However, these approaches suffer from high false-positive rates (FPRs) since they usually take the patched functions as vulnerable, and they usually do not work well when binaries are compiled with different compilation settings. To this end, we propose an approach, named Robin , to confirm recurring vulnerabilities by filtering out patched functions. Robin is powered by a lightweight symbolic execution to solve the set of function inputs that can lead to the vulnerability-related code. It then executes the target functions with the same inputs to capture the vulnerable or patched behaviors for patched function filtration. Experimental results show that Robin achieves high accuracy for patch detection across different compilers and compiler optimization levels respectively on 287 real-world vulnerabilities of 10 different software. Based on accurate patch detection, Robin significantly reduces the false-positive rate of state-of-the-art vulnerability detection tools (by 94.3% on average), making them more practical. Robin additionally detects 12 new potentially vulnerable functions. Shouguo Yang, Zhengzi Xu, Yang Xiao 0011, Zhe Lang, Yang Liu 0003, Zhiqiang Shi, Hong Li 0004, Limin Sun 0001 |
ACM Trans. Softw. Eng. Methodol. | 7 |
| 2022 | Gradient-Based Adversarial Attacks Against Malware Detection by Instruction Replacement
Jiapeng Zhao, Zhongjin Liu, Xiaoling Zhang 0009, Zhiqiang Shi, Shichao Lv, Hong Li 0004, Limin Sun 0001 |
WASA (1) | 5 |
| 2022 | ShadowPLCs: A Novel Scheme for Remote Detection of Industrial Process Control AttacksabstractIndustrial Control System (ICS) security has become increasingly important as attacks targeting ICSs are more prominent. Although many off-the-shelf industrial network intrusion detection mechanisms have been presented in the past, attackers have always found unique disguisable ways to bypass detections and disrupt actual industrial control processes. To mitigate this deficiency, we present a novel scheme for the detection of industrial process control attacks, calledShadowPLCs. Specifically, the scheme first automatically analyzes the PLC control code, then extracts key parameters of the PLCs including valid register addresses, valid range of values, and control logic rules as a basis for evaluating attacks. The attack behavior is detected in real-time from different perspectives through active communication with PLCs and passive monitoring of the network traffic. We implemented a prototype system with Siemens S7-300 series PLCs as a case study. Our scheme was evaluated using two Siemens S7-300 PLCs deployed on a gas pipeline network platform. Experiments demonstrate that the presented scheme can accurately detect process control attacks in real-time without affecting the normal operations of PLCs. Compared with the other four representative detection models, our scheme has better detection performance with detection accuracy of 97.3 percent. Junjiao Liu, Xiaodong Lin 0001, Xin Chen 0123, Hui Wen 0001, Hong Li 0004, Zhiqiang Shi, Limin Sun 0001 |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2021 | Asteria: Deep Learning-based AST-Encoding for Cross-platform Binary Code Similarity DetectionabstractBinary code similarity detection is a fundamental technique for many security applications such as vulnerability search, patch analysis, and malware detection. There is an increasing need to detect similar code for vulnerability search across architectures with the increase of critical vulnerabilities in IoT devices. The variety of IoT hardware architectures and software platforms requires to capture semantic equivalence of code fragments in the similarity detection. However, existing approaches are insufficient in capturing the semantic similarity. We notice that the abstract syntax tree (AST) of a function contains rich semantic information. Inspired by successful applications of natural language processing technologies in sentence semantic understanding, we propose a deep learning-based AST-encoding method, named ASTERIA, to measure the semantic equivalence of functions in different platforms. Our method leverages the Tree-LSTM network to learn the semantic representation of a function from its AST. Then the similarity detection can be conducted efficiently and accurately by measuring the similarity between two representation vectors. We have implemented an open-source prototype of ASTERIA. The Tree-LSTM model is trained on a dataset with 1,022,616 function pairs and evaluated on a dataset with 95,078 function pairs. Evaluation results show that our method outperforms the AST-based tool Diaphora and the-state-of-art method Gemini by large margins with respect to the binary similarity detection. And our method is several orders of magnitude faster than Diaphora and Gemini for the similarity calculation. In the application of vulnerability search, our tool successfully identified 75 vulnerable functions in 5,979 IoT firmware images. Shouguo Yang, Long Cheng 0005, Yicheng Zeng, Zhe Lang, Hongsong Zhu, Zhiqiang Shi |
DSN | 6 |
| 2021 | PMatch: Semantic-based Patch Detection for Binary ProgramsabstractBinary function matching has been proposed to detect the known vulnerabilities. However, the high similarity between the vulnerable and patched versions leads to a large of false positives. Patch detection is proposed to improve the accuracy of function matching by identifying the patched functions from matching results. However, the accuracy of existing methods decreases significantly due to the function changes introduced by high compiler optimization levels.In this paper, we propose PMatch, a method based on code semantic similarity to detect the patched binary functions. Firstly, PMatch extracts patch-affected code snippets from the patched binary function. Secondly, PMatch leverages a novel unsupervised sentence embedding technique in Natural Language Processing (NLP) to generate the semantic representations of binary code. Finally, PMatch matches the patch-affected code snippets with target blocks obtained by function diffing. To evaluate PMatch, we collect 101 CVEs and compile 304 binary programs with 4 different optimization levels. PMatch achieves an 86.43% average accuracy in detecting the patched functions, which outperforms the state-of-the-art work, and costs only 65.14ms per function. Besides, at the O3 high optimization level, PMatch achieves an accuracy improvement of over 20%. Zhe Lang, Shouguo Yang, Yiran Cheng, Xiaoling Zhang 0009, Zhiqiang Shi, Limin Sun 0001 |
IPCCC | 5 |
| 2021 | Transformer-XL With Graph Neural Network for Source Code SummarizationabstractSource code summarization is the task of generating a readable natural language to describe the functionality of source code. Code summarization is rapidly expanding, especially as the research takes great advantage of advances in neural networks and artificial intelligence technologies. Some mainstream methods input the structural information (abstract syntax tree (AST)) of the source code into the language model to generate relatively satisfactory comments. However, existing methods can not capture code’s long dependencies from AST for effective code summarization. In this paper, we provide a novel way to generate code summaries by combining a graph-based neural network and a Transformer-XL network. We utilize the graph-based neural network to better capture the structure information of AST, and the Transformer-XL network to learn important tokens in the AST and alleviate the problem of long dependency. We evaluate our technique on the standard Java dataset. The experimental results show that the effectiveness of our model is remarkable. It pushes the precision score to 60.73% (5.21% absolute improvement) and the F1 score to 51.06%. Xiaoling Zhang 0009, Shouguo Yang, Luqian Duan, Zhe Lang, Zhiqiang Shi, Limin Sun 0001 |
SMC | 5 |
| 2021 | A Robust IoT Device Identification Method with Unknown Traffic Detection
Xiao Hu 0004, Hong Li 0004, Zhiqiang Shi, Hongsong Zhu, Limin Sun 0001 |
WASA (1) | 3 |
| 2020 | A Scalable High-interaction Physical Honeypot Framework for Programmable Logic ControllerabstractProgrammable logic controller (PLC) is an industrial digital computer that has been ruggedized and adapted for the control of manufacturing processes, such as automobile manufacture, or gas pipelines, or power generation. Due to closed source and vendor-specific proprietary firmware, it is difficult to develop a scalable high-interaction honeypot for PLCs. In this paper, we present and discuss a new scalable high-interaction PLC honeypot framework based on physical devices. This framework aims to solve the problems of existing physical honeypots while providing the advantages of virtual honeypots. Specially, we first introduce the main gap existing in virtual PLC honeypots. Then, we present a cheap, flexible, and large-scale-deployment solution for physical PLC honeypots according to the concrete problems. Finally, we evaluated our framework based on Siemens S7-300 PLCs. Our experiment shows that physical PLC honeypots have the absolute advantage in interaction capability and it is entirely feasible to extend the deployment scope with low response delay. Jianzhou You, Shichao Lv, Lian Zhao, Mengyao Niu, Zhiqiang Shi, Limin Sun 0001 |
VTC Fall | 5 |
| 2019 | Understand Code Style: Efficient CNN-Based Compiler Optimization Recognition SystemabstractCompiler optimization level recognition can be applied to vulnerability discovery and binary analysis. Due to the exists of many different compilation optimization options, the difference in the contents of the binary file is very complicated. There are thousands of compiler optimization algorithms and multiple different processor architectures, so it is very difficult to manually analyze binary files and recognize its compiler optimization level with rules. This paper first proposes a CNN-based compiler optimization level recognition model: BinEye. The system extracts semantic and structural differences and automatically recognize the compiler optimization levels. The model is designed to be very suitable for binary file processing and is easy to understand. We built a dataset containing 80028 binary files for the model training and testing. Our proposed model achieves an accuracy of over 97%. At the same time, BinEye is a fully CNN-based system and it has a faster forward calculation speed, at least 8 times faster than the normal RNN-based model. Through our analysis of the model output, we successfully found the difference in assembly codes caused by the different compiler optimization level. This means that the model we proposed is interpretable. Based on our model, we propose a method to analyze the code differences caused by different compiler optimization levels, which has great guiding significance for analyzing closed source compilers and binary security analysis. Shouguo Yang, Zhiqiang Shi, Limin Sun 0001 |
ICC | 2 |
| 2018 | Multi-Dimensional Data Fusion Intrusion Detection for Stealthy Attacks on Industrial Control SystemsabstractThe security of Industrial Control Systems (ICS) is closely related to national security. With secret exploration and analysis of a target ICS, highly-skilled attackers can gain enough key knowledge about the system (e.g., the physical model of the system and the corresponding detection threshold), and then launch stealthy attacks by keeping the detection indicator under its threshold, thus bypasses existing intrusion detection mechanisms. However, we discover that all devices in industrial control systems consume energy at run time and the energy consumption varies according to different operation types and system states. Therefore, there exists relationships between control operation, system state and energy consumption of the device. Accordingly, we put forward a novel ICS intrusion detection approach based on multi-dimensional data fusion. This approach collects information about power consumption of physical devices, control operation and system state, and then identifies stealthy attacks by feeding the multi-dimensional information into a cascade detection algorithm. Experimental results verify that our approach has a better detection performance than other detection methods. An Yang, Xiaoshan Wang, Yuyan Sun, Zhiqiang Shi, Limin Sun 0001 |
GLOBECOM | 5 |
| 2018 | Sbsd: Detecting the Sequence Attack through Sensor Data in ICSsabstractThe Industrial Control System (ICS) refers to the national critical infrastructure, such as Energy and Water facility, which is significant for the national security. Sequence attack is a unique attack type in ICS, and many detection approaches have been proposed. A common and unrealistic hypothesis of these approaches is that they have gained the command sequences. In the real world, we can only obtain the observations from sensors. The single observation detection technique is a common approach to find anomalies by the observations. However, the highly skilled attacker can compromise some Programmable Logic Controllers (PLCs) in ICS and fake their sensor measurements. Under this circumstance, this detection approach becomes invalid and increases the false-negative rate. In this paper, we first analyze the sequence attack by their attack capability in ICS. Then we propose a State-Based Sequence Detection approach (SBSD). The SBSD uses the equipment's observation information, belonging to many PLCs, to create Hidden Markov Models (HMMs) for detecting the sequence attack. The experiment results in an ICS testbed have shown the effectiveness of SBSD. An Yang, Limin Sun 0001, Zhiqiang Shi, Yuyan Sun |
ICC | 3 |
| 2018 | Robust Network-Based Binary-to-Vector Encoding for Scalable IoT Binary File Retrieval
Hong Li 0004, Zhiqiang Shi, Limin Sun 0001 |
WASA | 4 |
| 2017 | CovertMIMO: A covert uplink transmission scheme for MIMO systemsabstractThe covert communication in the physical layer and WiFi network is an important tendency for the current research on covert channel. On the other hand, the MIMO beamforming technique used in the physical layer of WiFi networks provides great potential for developing covert transmission scheme. To fill this gap, this paper presents a novel covert channel based on the coordinated operations in the control channel and data channel of MIMO system, called CovertMIMO. Under this scheme, the covert transmitter can make some slight modification on the normal uplink process, such that the recovered physical layer signal at the receiver side deviates from the pre-agreed overt signal. Through the deviation, some covert information can be encoded and delivered. To implementing CovertMIMO, this paper considers two kinds of wardens that follow the minimum principle and distribution principle respectively. Against them, the parameter identification is transformed into solving an optimization problem or nonlinear equation set. The transmission capacity and undetectability of CovertMIMO are also analyzed in detail. At last, the effectiveness of CovertMIMO is validated through extensive experiments. Xiaoshan Wang, Yao Liu 0007, Xiang Lu 0004, Shichao Lv, Zhiqiang Shi, Limin Sun 0001 |
ICC | 5 |
| 2017 | IHB: A scalable and efficient scheme to identify homologous binaries in IoT firmwaresabstractDue to the extensive code reuse and the widespread use of third-party SDKs, homologous binaries are widely found in IoT firmwares. Once a vulnerability is found in one firmware, other firmwares sharing the similar piece of codes are at high risk. Thus, homologous binary search is of great significance to IoT firmware security analysis. However, there are still no scalable and efficient homologous binary search methods for IoT firmwares. The time complexity of the state-of-the-art method is O(N), and it is not scalable for large-scale IoT firmwares. In this paper, we design, implement, and evaluate a scalable and efficient homologous binary search scheme (termed as IHB) for IoT firmwares with time complexity O(1). The main idea of our methodology is to leverage readable strings in binaries to calculate the similarities between different IoT firmwares. Furthermore, we employ a string filter and the string-based MinHash to achieve both accuracy and efficiency. We test both our scheme and the state-of-the-art methods on a real dataset containing 1024 binary files. The results show that our method is three orders of magnitude more efficient than the existing methods. Meanwhile, our method has a higher true positive rate (92.88%) and a lower false positive rate (2.83%). In the interest of open science, we also make our tools and datasets publicly available to seed future improvements. Hong Li 0004, Zhongjin Liu, Zhiqiang Shi |
IPCCC | 6 |
| 2017 | Defense Against Advanced Persistent Threats with Expert System for Internet of Things
Shichao Lv, Zhiqiang Shi, Limin Sun 0001, Liang Xiao 0003 |
WASA | 3 |
| 2015 | A Privacy-Preserving Fuzzy Localization Scheme with CSI FingerprintabstractCSI fingerprint localization is an advanced and promising technique for indoor localization, which identifies the user's location by mapping his measured CSI against the server's CSI fingerprint database. This approach is highlighted due to its high granularity for location distinction and strong robustness to noise disturbances, but it also causes potential privacy leakage for the three participants in localization process: the user, the server, and the AP. Currently, there has been little research done on this issue, and the existing work often ignores the privacy concern on the AP. To fill the gap, this paper develops a privacypreserving fuzzy localization scheme with CSI fingerprint. On one hand, it leverages the property of CSI training to guarantee the randomness and independence of the user's measurement in each time of localization, and uses homomorphic encryption to achieve the data transmission and measurement comparison in cipher. These operations enable our scheme to preserve the location privacy of the user and APs as well as the data privacy of the server. On the other hand, the adoption of CSI fingerprint and fuzzy logic enhances the localization accuracy greatly. Through simulation experiments performed on CRAWDAD database, the efficiency of our proposed scheme is validated. Xiaoshan Wang, Yao Liu 0007, Zhiqiang Shi, Xiang Lu 0004, Limin Sun 0001 |
GLOBECOM | 3 |
| 2015 | Cryptanalysis and improvement of two RFID-OT protocols based on quadratic residuesabstractThe ownership transfer of RFID tag means a tagged product changes control over the supply chain. Recently, Doss et al. proposed two secure RFID tag ownership transfer (RFID-OT) protocols based on quadratic residues. However, we find that they are vulnerable to the desynchronization attack. The attack is probabilistic. As the parameters in the protocols are adopted, the successful probability is 93.75%. We also show that the use of the pseudonym of the tag h(TID) and the new secret key KTIDare not feasible. In order to solve these problems, we propose the improved schemes. Security analysis shows that the new protocols can resist in the desynchronization attack and other attacks. By optimizing the performance of the new protocols, it is more practical and feasible in the large-scale deployment of RFID tags. Yongming Jin, Hongsong Zhu, Zhiqiang Shi, Xiang Lu 0004, Limin Sun 0001 |
ICC | 3 |
| 2014 | Image Completion Using Global Patch Matching and Optimal Seam SynthesisabstractThis paper presented a global exemplar-based image completion method for filling large missing or damaged regions in an image. Based on three proposed completion rules, the image completion problem is formulated as a global discrete optimization problem with a well-defined energy function. The energy function can evaluate image consistency globally and is minimized with an expectation-maximization (EM) like algorithm, which considers patch matching and patch synthesis in a unified way. In the algorithm, M step and E step are achieved by fast coherent searching and optimal seam synthesis respectively. Moreover, E step combines image patch synthesis and coherent correction simultaneously. We analyzed our global energy function and optimization method in theory. Simulation comparisons with other state-of-the-art methods show the superiority of our proposed method in ensuring global coherent and avoiding image blurring. Shiming Ge, Kaixuan Xie, Zhiqiang Shi |
ICPR | 4 |
| 2013 | ST-XCP: A Stable XCP ProtocolabstractXCP is one of the most commonly used protocols in modern congestion control implementations. XCP can provide the available transmission rate to applications. It is well known fact that one of the issues of XCP is that the time-delay of its traditional implementation (TR-XCP) is twice the time-delay of its flow model. This leads to unstable behaviors when controlling the congestion in networks with heterogeneous propagation delays. This paper proposes an improvement of TR-XCP called the stable XCP (ST-XCP). ST-XCP decreases the control interval of XCP implementations and brings the behavior of the congestion control system back to the stability region. It is demonstrated in this paper, theoretically and through simulations, that ST-XCP outperforms TR-XCP as far as the queue size is concerned, and that it is also stable even while controlling the congestion in networks with heterogeneous propagation delays. Zhiqiang Shi, Dan Ionescu, Dongli Zhang |
ICCCN | 1 |
| 2011 | Congestion Control in Networks with Mixed IP and P2P TrafficabstractServices such as multimedia, VoIP, video-conferencing, social networking and others impose new requirements on providers and constraints on network designers. Fair Queueing algorithms like CSFQ or Stochastic Fair BLUE have been used to improve the quality of the packet transmission. Such mechanisms usually supervise the bandwidth consumption per-flow and become helpless in the presence of P2P traffic. In quest for high quality transmission, multimedia applications are designed to use more and more P2P paradigms. As P2P traffic is also exposed to congestion, few works address congestion control in mixed traditional IP (for short called IP traffic) and P2P traffic. In this paper, we propose a model flow for the mixture of the two and present a principle and a method based on per-subscriber flow control, for congestion control. An architecture based on the Token-Based Traffic Control for P2P applications is introduced. The token resource consumed by each subscriber is counted and controls for both core and edge routers are generated in the case of IP and P2P traffic. The traffic is measured at core routers and the measurement data is conveyed to edge routers. They label the Token-Level on incoming packets according to the congestion index, and police the total input token of each P2P subscriber. Simulations results and the analysis of the impact on the performance of this approach on some P2P experiments are given. Zhiqiang Shi, Dan Ionescu, Dongli Zhang |
ICCCN | 1 |
| 2009 | Mobility support using the mobile port mappingabstractAs wireless communication infrastructures such as 3G, WIFI and WIMAX networks are widely deployed, mobile IP communications are expected to grow rapidly. Although there are many mobile IP communication solutions such as GPRS Tunneling Protocol, Mobile IP and so on, they are still unable to provide large-scale mobile communication services in IPv4 networks because of the exhaustion of IPv4 addresses. In this paper, we present an Identifier/Locator split technique called the Mobile Port Mapping (MPM) which supports steady connections at the Transport layer when handover occurs. A MPM based SIP architecture (MPM-SIP) is proposed, in which part ports of a global IPv4 address is allocated to a particular mobile terminal instead of the total IPv4 address. MPM-SIP not only avoids the exhaustion of global IPv4 Addresses, but also provides backward compatibility to correspondence nodes. The architecture is verified and the performance is tested, which demonstrates that it is a promising technique to provide transparent mobility in IPv4 networks. Zhiqiang Shi, Yuansong Qiao, Adrian Matthews, Gregory Hayes, Anthony Cunningham, Enda Fallon |
IWCMC | 1 |
| 2005 | A Discovery Algorithm for Physical Topology in Switched EthernetsabstractAccurate and up-to-date knowledge of topology serves as the base of a number of network management functions, such as performance monitoring and evaluation, fault detection and location, resource allocation and etc. In the paper, the topology of a switched Ethernet is abstract to a tree and the relationship between any two network nodes is determined as a lineal connection or collateral connection by aid of a set of theorems. Based on the theorems, a practical algorithm to automatically discover the physical topology of switched Ethernets is proposed based on the incomplete address forwarding tables (AFTs). As an important part of the network management system of community broadband integrated services network (CBISNMS), this mechanism is working successfully. Yantao Sun, Zhiqiang Shi, Zhimei Wu |
LCN | 2 |
| 2001 | Acoustic emission classification using signal subspace projectionsabstractIn using acoustic emissions (AE) for mechanical diagnostics, one major problem is the differentiation of events due to crack growth in a component from noise of various origins. This work presents two algorithms for automatic clustering and separation of AE events based on multiple features extracted from experimental data. The first algorithm consists of two steps. In the first step, the noise is separated from the events of interest and subsequently removed using a combination of covariance analysis, principal component analysis (PCA), and differential time delay estimates. The second step processes the remaining data using a self-organizing map (SOM), which outputs the noise and AE signals into separate neurons. The algorithm is verified with two sets of data, and a correct classification ratio of over 95% is achieved. The second algorithm characterizes the AE signal subspace based on the principal eigenvectors of the covariance matrix of an ensemble of the AE signals. The latter algorithm has a correct classification ratio over 90%. Vahid Emamian, Zhiqiang Shi, Mostafa Kaveh, Ahmed H. Tewfik |
ICASSP | 2 |