VLDB 2026 Research / reviewers in the wild / expert
Aokun Chen
dblp:191/3105
· DBLP profile ↗
9ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-5100-3821ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Security and privacy · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | From image to report: automating lung cancer screening interpretation and reporting with vision-language models
Tien-Yu Chang, Qinglin Gou, Leyi Zhao, Tiancheng Zhou, Dong Yang 0005, Huiwen Ju, Kaleb E. Smith, Chengkun Sun, Jinqian Pan, Yu Huang 0018, Xing He 0003, Xuhong Zhang 0001, Daguang Xu, Jie Xu 0012, Jiang Bian 0001, Aokun Chen |
J. Biomed. Informatics | 17 |
| 2024 | Generative large language models are all-purpose text analytics engines: text-to-text learning is all your needabstractOBJECTIVE: To solve major clinical natural language processing (NLP) tasks using a unified text-to-text learning architecture based on a generative large language model (LLM) via prompt tuning. METHODS: We formulated 7 key clinical NLP tasks as text-to-text learning and solved them using one unified generative clinical LLM, GatorTronGPT, developed using GPT-3 architecture and trained with up to 20 billion parameters. We adopted soft prompts (ie, trainable vectors) with frozen LLM, where the LLM parameters were not updated (ie, frozen) and only the vectors of soft prompts were updated, known as prompt tuning. We added additional soft prompts as a prefix to the input layer, which were optimized during the prompt tuning. We evaluated the proposed method using 7 clinical NLP tasks and compared them with previous task-specific solutions based on Transformer models. RESULTS AND CONCLUSION: The proposed approach achieved state-of-the-art performance for 5 out of 7 major clinical NLP tasks using one unified generative LLM. Our approach outperformed previous task-specific transformer models by ∼3% for concept extraction and 7% for relation extraction applied to social determinants of health, 3.4% for clinical concept normalization, 3.4%-10% for clinical abbreviation disambiguation, and 5.5%-9% for natural language inference. Our approach also outperformed a previously developed prompt-based machine reading comprehension (MRC) model, GatorTron-MRC, for clinical concept and relation extraction. The proposed approach can deliver the "one model for all" promise from training to deployment using a unified generative LLM. Cheng Peng 0009, Xi Yang 0015, Aokun Chen, Zehao Yu 0001, Kaleb E. Smith, Anthony B. Costa, Mona Flores, Jiang Bian 0001, Yonghui Wu 0001 |
J. Am. Medical Informatics Assoc. | 3 |
| 2024 | Model tuning or prompt Tuning? a study of large language models for clinical concept and relation extraction
Cheng Peng 0009, Xi Yang 0015, Kaleb E. Smith, Zehao Yu 0001, Aokun Chen, Jiang Bian 0001, Yonghui Wu 0001 |
J. Biomed. Informatics | 5 |
| 2023 | Contextualized medication information extraction using Transformer-based deep learning architectures
Aokun Chen, Zehao Yu 0001, Xi Yang 0015, Yi Guo 0005, Jiang Bian 0001, Yonghui Wu 0001 |
J. Biomed. Informatics | 1 |
| 2022 | Impacts of Eligibility Criteria on Trial Participants' Age in Alzheimer's Disease Clinical Trials
Aokun Chen, Qian Li 0034, Xing He 0003, Michael Jaffee, William R. Hogan, Fei Wang 0001, Yi Guo 0005, Jiang Bian 0001 |
AMIA | 1 |
| 2022 | Learning Fast and Slow: Propedeutica for Real-Time Malware DetectionabstractExisting malware detectors on safety-critical devices have difficulties in runtime detection due to the performance overhead. In this article, we introduce Propedeutica, a framework for efficient and effective real-time malware detection, leveraging the best of conventional machine learning (ML) and deep learning (DL) techniques. In Propedeutica, all software start executions are considered as benign and monitored by a conventional ML classifier for fast detection. If the software receives a borderline classification from the ML detector (e.g., the software is 50% likely to be benign and 50% likely to be malicious), the software will be transferred to a more accurate, yet performance demanding DL detector. To address spatial-temporal dynamics and software execution heterogeneity, we introduce a novel DL architecture (DeepMalware) for Propedeutica with multistream inputs. We evaluated Propedeutica with 9115 malware samples and 1338 benign software from various categories for the Windows OS. With a borderline interval of [30%, 70%], Propedeutica achieves an accuracy of 94.34% and a false-positive rate of 8.75%, with 41.45% of the samples moved for DeepMalwareanalysis. Even using only CPU, Propedeutica can detect malware within less than 0.1 s. Ruimin Sun, Xiaoyong Yuan, Pan He, Qile Zhu, Aokun Chen, André Ricardo Abed Grégio, Daniela Oliveira 0001, Xiaolin Li 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2018 | FAROS: Illuminating In-memory Injection Attacks via Provenance-Based Whole-System Dynamic Information Flow TrackingabstractIn-memory injection attacks are extremely challenging to reverse engineer because they operate stealthily without leaving artifacts in the system or in any easily observable events from outside of a virtual machine. Because these attacks perform their actions in memory only, current malware analysis solutions cannot expose their behavior. This paper introduces FAROS^1 a reverse engineering tool for Windows malware analysis based on dynamic information flow tracking (DIFT), which can flag stealthy in-memory-only malware injection attacks by leveraging the synergy of: (i) whole-system taint analysis; (ii) per security policy-based handling of the challenge of indirect flows via the application of tags of different types, and (iii) the use of tags with fine-grained provenance information. We evaluated FAROS with six advanced in-memory-injecting malware and it flagged the attacks for all samples. We also analyzed FAROS' false positive rate with 90 non-injecting malware samples and 14 benign software from various categories. FAROS presented a very low false positive rate of 2%, which shows its potential towards practical solutions against advanced in-memory-only anti-reverse-engineering attacks. Meisam Navaki Arefi, Geoffrey Alexander, Hooman Rokham, Aokun Chen, Michalis Faloutsos, Xuetao Wei, Daniela Oliveira 0001, Jedidiah R. Crandall |
DSN | 4 |
| 2016 | Bear: A Framework for Understanding Application Sensitivity to OS (Mis) BehaviorabstractApplications are generally written assuming a predictable and well-behaved OS. In practice, they experience unpredictable misbehavior at the OS level and across OSes: different OSes can handle network events differently, APIs can behave differently across OSes, and OSes may be compromised or buggy. This unpredictability is challenging because its sources typically manifest during deployment and are hard to reproduce. This paper introduces Bear, a framework for statistical analysis of application sensitivity to OS unpredictability that can help developers build more resilient software, discover challenging bugs and identify the scenarios that most need validation. Bear analyzes a program with a set of perturbation strategies on a set of commonly used system calls in order to discover the most sensitive system calls for each application, the most impactful strategies, and how they predict abnormal program outcome. We evaluated Bear with 113 CPU and IO-bound programs, and our results show that null memory dereferencing and erroneous buffer operations are the most impactful strategies for predicting abnormal program execution and that their impacts increase ten-fold with workload increase (e.g. number of network requests from 10 to 1000). Generic system calls are more sensitive than specialized system calls-for example, write and sendto can both be used to send data through a socket, but the sensitivity of write is twice that of sendto. System calls with an array parameter (e.g. read) are more sensitive to perturbations than those having a struct parameter with a buffer (e.g readv). Moreover, the fewer parameters a system call has, the more sensitive it is. Ruimin Sun, Aokun Chen, Donald E. Porter, Matt Bishop, Daniela Oliveira 0001 |
ISSRE | 3 |
| 2016 | Cross-layer personalization as a first-class citizen for situation awareness and computer infrastructure securityabstractWe propose a new security paradigm that makes cross-layer personalization a premier component in the design of security solutions for computer infrastructure and situational awareness. This paradigm is based on the observation that computer systems have a personalized usage profile that depends on the user and his activities. Further, it spans the various layers of abstraction that make up a computer system, as if the user embedded his own DNA into the computer system. To realize such a paradigm, we discuss the design of a comprehensive and cross-layer profiling approach, which can be adopted to boost the effectiveness of various security solutions, e.g., malware detection, insider attacker prevention and continuous authentication. The current state-of-the-art in computer infrastructure defense solutions focuses on one layer of operation with deployments coming in a "one size fits all" format, without taking into account the unique way people use their computers. The key novelty of our proposal is the cross-layer personalization, where we derive the distinguishable behaviors from the intelligence of three layers of abstraction. First, we combine intelligence from: a) the user layer, (e.g., mouse click patterns); b) the operating system layer; c) the network layer. Second, we develop cross-layer personalized profiles for system usage. We will limit our scope to companies and organizations, where computers are used in a more routine and one-on-one style, before we expand our research to personally owned computers. Our preliminary results show that just the time accesses in user web logs are already sufficient to distinguish users from each other,with users of the same demographics showing similarities in their profiles. Our goal is to challenge today's paradigm for anomaly detection that seems to follow a monoculture and treat each layer in isolation. We also discuss deployment, performance overhead, and privacy issues raised by our paradigm. Aokun Chen, Pratik Prabhanjan Brahma, Dapeng Oliver Wu, Natalie C. Ebner, Brandon Matthews, Jedidiah R. Crandall, Xuetao Wei, Michalis Faloutsos, Daniela Oliveira 0001 |
NSPW | 1 |