VLDB 2026 Research / reviewers in the wild / expert
Yuliang Lu
dblp:194/4924 · also Yu-liang Lu
· DBLP profile ↗
57ranked-venue papers
0as first author
36since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 21 · 7 since 2021Security and privacy · 18 · 13 since 2021Artificial intelligence and machine learning · 10 · 10 since 2021Computer networks · 8 · 6 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CT-Sketch: Persistent Item Lookup Based on Collision Statistics and Thresholds
Lailong Luo, Yuliang Lu, Qianzhen Zhang, Guozheng Yang |
IWQoS | 3 |
| 2026 | Demystifying the Access Control Mechanism of ESXi VMKernel
Zexiang Zhang, Jiaxun Zhu, Jiaqing Huang, Wenbo Shen, Yuliang Lu, Min Zhang 0054, Zulie Pan |
NDSS | 8 |
| 2026 | Debapt: Ontology-driven multi-agent debate for APT adversary profile construction from cyber threat intelligenceabstractCyber threat intelligence (CTI) reports contain rich information about advanced persistent threat (APT) groups. This information is useful for adversary profile construction. However, turning long and fragmented CTI reports into structured adversary profiles remains difficult. Existing methods mainly rely on named entity and relation extraction pipelines or single large language models (LLMs). These methods often lack explicit semantic constraints for profile-oriented tasks. They are also prone to omission and hallucination when processing long reports. In this paper, we study APT adversary profile construction from CTI reports. We formulate this task as an ontology-constrained profile information extraction task. To support this task, we develop VICTOR, a domain-specific ontology that organizes profile-relevant information into six dimensions. We then propose Debapt, an ontology-driven multi-agent debate framework. Guided by VICTOR, Debapt performs APT adversary profile construction through two debate loops in the entity extraction phase and relation extraction phase. In each loop, role-specialized agents iteratively extract, review, and adjudicate candidate profile-relevant facts under moderator supervision. These extracted results can be further aggregated across reports to support actor-centric adversary profile construction. To evaluate Debapt, we re-annotate three public CTI datasets under a unified profiling schema. Experimental results show that Debapt improves profile-oriented entity and relation extraction over competitive baselines. It extracts more complete and better grounded profile-relevant facts from CTI reports. Case studies further show that these extracted results can support the construction of analytically useful adversary profiles. Xinyun Zhao, Lanlan Qi, Yongheng Zhang 0002, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010 |
Comput. Secur. | 6 |
| 2026 | Autonomous penetration testing using reinforcement learning: A review and perspectivesabstractPenetration testing (pentesting) assesses cybersecurity through controlled, authorized attacks, but traditional manual methods demand considerable human and time resources. Reinforcement learning (RL), with its agent-environment interaction paradigm, offers a promising approach for autonomous pentesting. Despite remarkable advancements in this field, there is a lack of comprehensive reviews and perspectives on RL-based autonomous pentesting. To address this gap, this paper presents a systematic review of RL-based autonomous pentesting research. We outline the key challenges faced when applying RL in autonomous pentesting and categorize the existing literature into two main areas: attack path planning and autonomous pentesting frameworks, based on the research objectives and hypotheses. Additionally, we offer an in-depth analysis of the latest advancements and limitations in this field, while proposing a perspective on future research directions in the field of RL-based autonomous pentesting. We hope that our work will provide valuable insights for researchers, contributing to the advancement of autonomous pentesting and its practical application in the complex and diverse scenarios of the real world. Jingju Liu, Yue Zhang 0049, Shicheng Zhou, Jiahai Yang 0001, Yuliang Lu, Xiaofeng Zhong |
Expert Syst. Appl. | 5 |
| 2026 | Unreachable Features? Exposing the Security Risks of Invisible Interfaces in Embedded Web Services of IoT DevicesabstractIoT devices, now integral to our daily routines, offer unparalleled convenience but also face mounting security threats. Embedded web services, prevalent in public networks, pose a major risk to these devices. While research has focused on detecting vulnerabilities in IoT embedded web services, it has overlooked the presence of invisible interfaces, which have emerged as significant security threats. In this paper, we propose InvRadar, a novel framework for detecting vulnerabilities in invisible interfaces of embedded web services in IoT devices. Specifically, InvRadar identifies invisible interfaces by analyzing the differences between the front-end visible interface keywords and the back-end interface keywords through a correlation analysis method. Subsequently, InvRadar uses a static taint analysis method to detect the vulnerabilities that can be triggered by the invisible interfaces. To validate the performance of InvRadar, we conduct extensive experiments and compare InvRadar with the state-of-the-art methods. In testing 13 device firmware, InvRadar identifies 1,793 invisible interfaces and detects 124 vulnerabilities, including 53 newly discovered ones, with 34 receiving new CVE/CNVD IDs. Additionally, InvRadar outperforms the state-of-the-art methods in interface keyword extraction, border binary and data ingestion function identification. Yuanchao Chen, Yuwei Li 0002, Yi Shen 0012, Yu Chen 0053, Yang Li 0215, Taiyan Wang, Yuliang Lu, Zulie Pan, Shouling Ji |
IEEE Internet Things J. | 7 |
| 2026 | A general and efficient biometric template protection based on a novel secret sharing
Yongqiang Yu, Yuliang Lu, Wei Yan 0014, Xuehu Yan |
Inf. Sci. | 2 |
| 2026 | MM-AttacKG: A multimodal approach to attack graph construction with large language modelsabstractCyber Threat Intelligence (CTI) parsing aims to extract key threat information from massive data, transform it into actionable intelligence, enhance threat detection and defense efficiency, including attack graph construction, intelligence fusion, and indicator extraction. Among these research topics, Attack Graph Construction (AGC) is essential for visualizing and understanding the potential attack paths of threat events from CTI reports. Existing approaches primarily construct the attack graphs purely from the textual data to reveal the logical threat relationships between entities within the attack behavioral sequence. However, they typically overlook the specific threat information inherent in visual modalities, which preserves key threat details from inherently multimodal CTI reports. Inspired by the remarkable multimodal understanding capabilities of Multimodal Large Language Models (MLLMs), we explore their potential in enhancing multimodal attack graph construction. To be specific, we propose a novel framework, MM-AttacKG, which can effectively extract key information from threat images and integrate it into attack graph construction, thereby enhancing the comprehensiveness and accuracy of attack graphs. It first employs a threat image parsing module to extract critical threat information from images and generate textual descriptions using MLLMs. Subsequently, it builds an iterative question-answering pipeline tailored for image parsing to refine the understanding of threat images. Finally, it achieves content-level integration between attack graphs and image-based answers through MLLMs, completing threat information enhancement. We construct a new multimodal dataset, AG-LLM-mm, and conduct extensive experiments to evaluate the effectiveness of MM-AttacKG. The results demonstrate that MM-AttacKG can accurately identify key information in threat images and significantly improve the quality of multimodal attack graph construction, effectively addressing the shortcomings of existing methods in utilizing image-based threat information. The code and the corresponding dataset will be released upon acceptance. Yongheng Zhang 0002, Xinyun Zhao, Yunshan Ma 0002, Haokai Ma, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010 |
Knowl. Based Syst. | 7 |
| 2026 | DPC: Dynamic purification chain for adaptive adversarial defense
Zeshan Pang, Yuyuan Sun, Rongtao Liao, Xuehu Yan, Shasha Guo 0001, Yuliang Lu |
Neural Networks | 6 |
| 2026 | Password Guessing Based on Hidden Weak Password AnalysisabstractPassword has become the mainstream method of authentication today. To improve password security, researchers evaluate the strength of target password datasets through early brute-force attacks to current password guessing methods, aiming to help users reduce the use of weak passwords. With users becoming more aware of security, they make local variations on weak passwords to improve the password strength while being easy to remember. These transformations render passwords more complex and enhance the score in password strength meter. However, such variations do not genuinely enhance password security, as human habits tend to converge. This allows attackers to deduce the modification patterns and consequently crack these passwords. Motivated by this, this paper defines the hidden weak passwords, a local variant of explicit weak passwords, which appear to enhance password security yet remain vulnerable. We systematically analyze transformation behavior between explicit and hidden weak passwords. Then we design an automated rule generation algorithm to identify hidden weak passwords and generate transformation rules. Based on automatically mined rules, we generate a large number of password guesses and fuses them with existing methods to improve password guessing performance. Finally, we demonstrate the effectiveness of the proposed method through password guessing experiments on eight real-world datasets, where the cracking rate improves on all five state-of-the-art methods. Min Zhang 0054, Zhijie Xie, Shasha Guo 0001, Yuliang Lu, Fan Shi 0003, Yi Shen 0012 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Colorization-Driven Generative Secret Image SharingabstractTo enhance shares visual quality and security, meaningful secret image sharing relies on pre-input cover images to endow shadow images with interpretable semantics. However, the recently proposed schemes often yield shadows with mediocre visual quality and compromised security, such as vulnerability to statistical analysis or information leakage. Generative SIS (GSIS) introduces image generation or other operations, either to generate high-quality shadows or to eliminate the need for pre-input covers. Our prior \((2,2)\) -GSIS generated meaningful shares without covers but incurred non-critical leakage and did not support lossless reconstruction. Grayscale image colorization, being a widely adopted image processing operation, offers a promising route for GSIS by enriching semantics through chrominance synthesis. We introduce a colorization-driven GSIS. Chrominance components are shared via a \((k,n)\) -threshold SIS. Near-neutral chrominance from color templates provides structural priors that guide the synthesis of share pixels. The generated chrominance supersedes the template values and directly participates in colorization. This dynamic constraint departs from the linear modification paradigm of cover-based schemes, yielding shares that are visually natural and semantically preserved, without information leakage, and enabling lossless recovery from any \( k \) of \( n \) shares. Theoretical analysis and experiments validate the effectiveness and advantages of the framework. Xuehu Yan, Zhankai Li, Yongqiang Yu, Yuliang Lu, Tao Liu 0049 |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2025 | A3: Few-shot Prompt Learning of Unlearnable Examples with Cross-Modal Adversarial Feature AlignmentabstractIn the age of pervasive machine learning applications, protecting digital content from unauthorized use has become a pressing concern. Unlearnable examples (UEs)—data modified with imperceptible perturbations to inhibit model training while preserving human usability—have emerged as a promising approach. However, existing UE methods assume unauthorized trainers have extensive exposure to UEs or that models are trained from scratch, which may not hold in practical scenarios, This paper investigates the effectiveness of UEs under the few-shot learning paradigm, pitching it against prompt learning (PL) models that leverage pretrained vision-language models (VLMs), like CLIP, capable of generalizing to new classes with minimal data. To address this, we introduce an adaptive UE framework to generate unlearnable examples that specifically target the PL process. In addition, we propose a novel UE countermeasure, A3, with cross-modal adversarial feature alignment, specifically designed to circumvent UEs under few-shot PL. Experimental evaluations on 7 datasets show that A3outperforms existing PL methods, achieving up to 33% higher performance in learning from UEs. For example, in the scenario involving ω→-bounded EM perturbations, A3has an average harmonic mean accuracy across 7 datasets of 82.43%, compared to CoCoOp’s baseline of 65.47%. Our findings highlight the limitations of existing UEs against PL and lay the foundation for future data protection mechanisms. Xuan Wang 0029, Dongping Liao, Tianrui Qin, Yuliang Lu, Cheng-Zhong Xu 0001 |
CVPR | 5 |
| 2025 | MTD-Net: Moving Target Defense for Defending Neural Networks Adversarial AttacksabstractDeep learning models face the threat of adversarial attacks, which challenges their application. Moving Target Defense (MTD) is a defense paradigm that thwarts attacks by constantly changing the targets’ features and restricting the predictability of targets. Recent works have applied MTD in adversarial defense but rely on maintaining a model set and assuming a weak adversary, which causes extra storage and unreliable evaluation of the robustness of the methods. This paper proposes the MTD-Net that realizes MTD in a single neural network. In the training stage, MTD-Net parameters are randomly disabled to ensure desirable accuracy on diversified parameter groups. During each query, MTD-Net dynamically chooses several groups of parameters and aggregates their inference results for final prediction. The parameters MTD-Net chooses for inference are unpredictable, even for adversaries possessing the model’s weights. Thus, MTD-Net achieves factual unpredictability under strong whitebox attacks. We evaluate MTD-Net on two widely used datasets, i.e., GTSRB and CIFAR10. The experimental results demonstrate that MTD-Net achieves superior performance compared to existing MTD defense under adversarial attacks and is applicable to multiple architectures. Zeshan Pang, Shasha Guo 0001, Yuyuan Sun, Rongtao Liao, Xuehu Yan, Yuliang Lu |
IJCNN | 6 |
| 2025 | Lie Detector: Unified Backdoor Detection via Cross-Examination FrameworkabstractInstitutions with limited data and computing resources often outsource model training to third-party providers in a semi-honest setting, assuming adherence to prescribed training protocols with pre-defined learning paradigm (e.g., supervised or semi-supervised learning). However, this practice can introduce severe security risks, as adversaries may poison the training data to embed backdoors into the resulting model. Existing detection approaches predominantly rely on statistical analyses, which often fail to maintain universally accurate detection accuracy across different learning paradigms. To address this challenge, we propose a unified backdoor detection framework in the semi-honest setting that exploits cross-examination of model inconsistencies between two independent service providers. Specifically, we integrate central kernel alignment to enable robust feature similarity measurements across different model architectures and learning paradigms, thereby facilitating precise recovery and identification of backdoor triggers. We further introduce backdoor fine-tuning sensitivity analysis to distinguish backdoor triggers from adversarial perturbations, substantially reducing false positives. Extensive experiments demonstrate that our method achieves superior detection performance, improving accuracy by 4.4%, 1.7%, and 10.6% over SoTA baselines across supervised, self-supervised, and autoregressive learning tasks, respectively. Notably, it is the first to effectively detect backdoors in multimodal large language models, further highlighting its broad applicability and advancing secure deep learning. Xuan Wang 0029, Siyuan Liang 0004, Dongping Liao, Aishan Liu, Xiaochun Cao, Yuliang Lu, Ee-Chien Chang |
NeurIPS | 7 |
| 2025 | DerandomPre: An LLM-based Stability Enhancement Method for Network Protocol FuzzingabstractAs essential components for communication, network protocol programs are highly security-critical, making it crucial to identify their vulnerabilities. Fuzzing is one of the most popular software vulnerability discovery techniques, being highly efficient and having low false-positive rates. However, current network protocol fuzzing is hindered by the randomness in programs. The current solutions primarily rely on the manual modification of programs, which is inefficient and prone to omissions. In this paper, we propose DerandomPre, a novel stability enhancement method for stateful network protocol programs, which leverages large language model’s code- and text-understanding capabilities to analyze derandomization knowledge and optimize the stability enhancing of programs for fuzzing. DerandomPre automatically eliminates randomness in programs to ensure higher stability and fuzzing effectiveness. We implement a prototype of DerandomPre. The evaluation demonstrates that DerandomPre significantly enhances fuzzing performance by eliminating program randomness. Specifically, compared to unmodified programs, DerandomPremodified versions achieved an average stability improvement of 64.88%; relative to ProFuzzBench-modified programs, DerandomPre yielded a further 13.08% stability gain. Moreover, DerandomPre demonstrates good scalability, thus is applicable to various network protocol programs. Kailong Zhu, Zixiong Li, Yuliang Lu, Yingchun Chen |
TrustCom | 5 |
| 2025 | AttacKG+: Boosting attack graph construction with Large Language ModelsabstractAttack graph construction seeks to convert textual cyber threat intelligence (CTI) reports into structured representations, portraying the evolutionary traces of cyber attacks. Even though previous research has proposed various methods to construct attack graphs, they generally suffer from limited generalization capability to diverse knowledge types as well as requirement of expertise in model design and tuning. Addressing these limitations, we seek to utilize Large Language Models (LLMs), which have achieved enormous success in a broad range of tasks given exceptional capabilities in both language understanding and zero-shot task fulfillment. Thus, we propose a fully automatic LLM-based framework to construct attack graphs named: AttacKG + . Our framework consists of four consecutive modules: rewriter, parser, identifier, and summarizer, each of which is implemented by instruction prompting and in-context learning empowered by LLMs. Furthermore, we upgrade the existing attack knowledge schema and propose a comprehensive version. We represent a cyber attack as a temporally unfolding event, each temporal step of which encapsulates three layers of representation, including behavior graph, MITRE TTP labels, and state summary. Extensive evaluation demonstrates that: (1) our formulation seamlessly satisfies the information needs in threat event analysis, (2) our construction framework is effective in faithfully and accurately extracting the information defined by AttacKG + . and (3) our attack graph directly benefits downstream security practices such as attack reconstruction. All the code and datasets will be released upon acceptance. Yongheng Zhang 0002, Tingwen Du, Yunshan Ma 0002, Xiang Wang 0010, Guozheng Yang, Yuliang Lu, Ee-Chien Chang |
Comput. Secur. | 7 |
| 2025 | SCRIPT: A Scalable Continual Reinforcement Learning Framework for Autonomous Penetration Testing
Shicheng Zhou, Jingju Liu, Yuliang Lu, Jiahai Yang 0001, Yue Zhang 0049, Bo Lin 0011, Xiaofeng Zhong, Shulong Hu |
Expert Syst. Appl. | 3 |
| 2025 | Multi-image secret sharing for general access structure without size expansion
Yuliang Lu, Rui Wang 0127, Yongqiang Yu, Xuehu Yan |
J. Inf. Secur. Appl. | 2 |
| 2025 | Mind the Gap: towards generalizable autonomous penetration testing via domain randomization and meta-reinforcement learningabstractWith the increasing number of vulnerabilities exposed on the Internet, autonomous penetration testing (pentesting) has emerged as a promising research area. Reinforcement learning (RL) is a natural fit for studying this topic. However, two key challenges limit the applicability of RL-based autonomous pentesting in real-world scenarios: the training environment dilemma—training agents in simulated environments is sample-efficient while ensuring that their realism remains challenging; poor generalization ability—agents’ policies often perform poorly when transferred to unseen scenarios, with even slight changes potentially causing a significant generalization gap. To address both challenges, we propose a generalizable autonomous pentesting framework termed GAP, which aims to achieve efficient policy training in realistic environments and train generalizable agents capable of drawing inferences about other cases from one instance. GAP introduces a real-to-sim-to-real pipeline that enables end-to-end policy learning in unknown real environments while constructing realistic simulations and improves agents’ generalization ability by leveraging domain randomization and meta-RL learning. We are among the first to apply domain randomization in autonomous pentesting and propose a large language model-powered domain randomization method for synthetic environment generation. We further apply meta-RL to improve agents’ generalization ability in unseen environments by leveraging synthetic environments. Combining the two methods effectively bridges the generalization gap and improves agents’ policy adaptation performance. Simulations are conducted on various vulnerable virtual machines, with results showing that GAP can enable policy learning in various realistic environments, achieve zero-shot policy transfer in similar environments, and achieve rapid policy adaptation in dissimilar environments. Shicheng Zhou, Jingju Liu, Yuliang Lu, Jiahai Yang 0001, Yue Zhang 0049, Jie Chen 0079 |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2025 | EBF: An Event-Based Bilateral Filter for Effective Neuromorphic Vision Sensor Denoising
Shasha Guo 0001, Chenyang Shi, Lei Wang 0011, Yuliang Lu |
IEEE Trans. Circuits Syst. Video Technol. | 5 |
| 2025 | APRIL: Towards Scalable and Transferable Autonomous Penetration Testing in Large Action Space via Action EmbeddingabstractPenetration testing (pentesting) assesses cybersecurity through simulated attacks, while the conventional manual-based method is costly, time-consuming, and personnel-constrained. Reinforcement learning (RL) provides an agent-environment interaction learning paradigm, making it a promising way for autonomous pentesting. However, agents’ scalability in large action spaces and policy transferability across scenarios limit the applicability of RL-based autonomous pentesting. To address these challenges, we present a novel autonomous pentesting framework based on reinforcement learning (namely APRIL) to train agents that are scalable and transferable in large action spaces. In APRIL, we construct realistic, bounded, host-level state space via embedding techniques to avoid the complexities of dealing with unbounded network-level information. We employ semantic correlations between pentesting actions as prior knowledge to represent discrete action space into a continuous and semantically meaningful embedding space. Agents are then trained to reason over actions within the action embedding space, where two key methods are applied: an upper-confidence bound-based action refinement method to encourage efficient exploration, and a distance-aware loss to improve learning efficiency and generalization performance. We conduct experiments in simulated scenarios constructed based on virtualized vulnerable environments. The results demonstrate APRIL's scalability in large action spaces and its ability to facilitate policy transfer across diverse scenarios. Shicheng Zhou, Jingju Liu, Yuliang Lu, Jiahai Yang 0001, Dongdong Hou, Yue Zhang 0049, Shulong Hu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Understanding the Security Risks of Websites Using Cloud Storage for Direct User File UploadsabstractWith the rising demand for website data storage, leveraging cloud storage services for vast user file storage has become prevalent. Nowadays, a new file upload scenario has been introduced, allowing web users to upload files directly to the cloud storage service. This new scenario offers convenience but involves more roles (i.e., web users, web servers, and cloud storage services) and their interactions, bringing new security threats. In this paper, we perform the first systematic security study in this scenario. With in-depth analysis, we identify six new types of vulnerabilities and conduct large-scale real-world measurements on the top 500 Alexa Rank websites. Among these websites, 182 (36.4%) use cloud storage services, illustrating the widespread use of the cloud. Then, we perform a detailed analysis of 28 popular websites that allow user upload. Surprisingly, they all have at least one of the six vulnerabilities. Totally, we discover 79 new vulnerabilities and responsibly report them to the websites. Many popular websites respond positively, including Google, Reddit, and CSDN. We discuss the root causes of these vulnerabilities and propose possible mitigation methods. In summary, our work offers significant value in understanding the security risks of cloud storage services for websites and facilitating future research. Yuanchao Chen, Yuwei Li 0002, Yuliang Lu, Zulie Pan, Shouling Ji, Yu Chen 0053, Yang Li 0103, Yi Shen 0012 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Yama: Precise Opcode-Based Data Flow Analysis for Detecting PHP Applications VulnerabilitiesabstractWeb applications encompass various aspects of daily life, including online shopping, e-learning, and internet banking. Once there is a vulnerability, it can cause severe societal and economic damage. Due to its ease of use, PHP has become the preferred server-side programming language for web applications, making PHP applications a primary target for attackers. Data flow analysis is widely used for vulnerability detection before deploying web applications because of its efficiency. However, the high complexity of the PHP language makes it difficult to achieve precise data flow analysis, resulting in higher rates of false positives and false negatives in vulnerability detection. In this paper, we present Yama, a context-sensitive and path-sensitive interprocedural data flow analysis method for PHP, designed to detect taint-style vulnerabilities in PHP applications. We have found that the precise semantics and clear control flow of PHP opcodes enable data flow analysis to be more precise and efficient. Leveraging this observation, we established parsing rules for PHP opcodes and implemented a precise understanding of PHP program semantics in Yama. This enables Yama to precisely address the high complexity of the PHP language, including type inference, dynamic features, and built-in functions. We evaluated Yama from three dimensions: basic data flow analysis capabilities, complex semantic analysis capabilities, and the ability to discover vulnerabilities in real-world applications, demonstrating Yama’s advancement in vulnerability detection. Specifically, Yama possesses context-sensitive and path-sensitive interprocedural analysis capabilities, achieving a 99.1% true positive rate in complex semantic analysis experiments related to type inference, dynamic features, and built-in functions. It discovered and reported 38 zero-day vulnerabilities across 24 projects on GitHub with over 1,000 stars each, assigning 34 new CVE IDs. We have released the source code of the prototype implementation and the parsing rules for PHP opcodes to facilitate future research. Jiazhen Zhao, Kailong Zhu, Yuliang Lu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | SGES: A General and Space-efficient Framework for Graphlet Counting in Graph StreamsabstractGraphlets are small, connected, and non-isomorphic induced subgraphs that describe the topological structure of a graph. Counting graphlets is a fundamental task in graph mining and social network analysis. It has numerous applications in many fields, including dense subgraph discovery, anomaly detection, etc. Most existing work assumes a static graph. However, graphs are dynamic in the real world, which can be described as graph streams. Counting graphlets in graph streams is a challenge due to the streaming nature of the input. While there have been several studies on counting graphlets in graph streams, these works are limited to simple graphlets like triangles and butterflies. In this paper, we propose SGES algorithm to estimate more complex graphlets in graph streams. In SGES, we first propose an unbiased sampling strategy to maintain fixed-size sampled edges, which in turn allows us to unbiasedly estimate the number of subgraphs and then count graphlets based on the combinational relationship between the number of subgraphs and the number of graphlets. Extensive experiments over large real-world graph streams prove that our algorithm can obtain accurate estimation values of graphlet counts with high throughput. Lailong Luo, Yuliang Lu, Chu Huang, Qianzhen Zhang, Guozheng Yang, Deke Guo |
CIKM | 3 |
| 2024 | ZBanner: Fast Stateless Scanning Capable of Obtaining Responses over TCPabstractFast large-scale network scanning is an important way to understand internet service configurations and security in real time, among which stateless scan is representative. Existing stateless scanners can perform single-packet scans for internet-wide network measurements but are limited to host discovery or port scanning. To obtain further information over TCP, slower stateful scanners must be used in conjunction which spend more time and memory because of connection state maintenance. This paper proposes a novel stateless scanning method, which can establish TCP connections and obtain further responses in a completely stateless manner. Based on this method, we implement a stateless scanner named ZBanner. Experiments show that ZBanner performs better than current state-of-the-art solutions in terms of scan rate and memory usage. ZBanner achieves a scan rate at least three times faster than current tools for generic ports and over 90 times faster for open ports while keeping a minimum and stable memory usage. Chiyu Chen, Yuliang Lu, Guozheng Yang, Shasha Guo 0001 |
IPCCC | 2 |
| 2024 | Destruction and Reconstruction Chain: An Adaptive Adversarial Purification FrameworkabstractAdversarial attacks can cause abnormal behavior in deep neural networks by adding imperceptible perturbations to input data. Adversarial purification is an effective defense method by transforming adversarial data into clean data. Existing purification methods utilize only simple corruptions and specified reconstructors to eliminate perturbations, and thus are non-adaptive to different attack algorithms. To address this challenge, we propose an adaptive adversarial purification framework, which combines multiple Destruction and Reconstruction (D&R) operations to form a multi-stage D&R chain. The Destruction operations consist of corruptions in both spatial and frequency domains. The Reconstruction operations are implemented by deep networks trained respectively for corresponding corruptions to restore images. The D&R chain is constructed dynamically during purification based on the link probabilities of D&R operations with a self-supervised search algorithm. We test our framework on CIFAR10 datasets under five attacks. The experiment results indicate that the proposed framework can adapt to a wide range of attacks and achieve comparable performance. Zeshan Pang, Shasha Guo 0001, Xuehu Yan, Yuliang Lu |
TrustCom | 4 |
| 2024 | A robust defense for spiking neural networks against adversarial examples via input filtering
Shasha Guo 0001, Lei Wang 0011, Yuliang Lu |
J. Syst. Archit. | 4 |
| 2024 | Invisible backdoor learning in regional transform domain
Yuyuan Sun, Yuliang Lu, Xuehu Yan, Xuan Wang 0029 |
Neural Comput. Appl. | 2 |
| 2024 | URadar: Discovering Unrestricted File Upload Vulnerabilities via Adaptive Dynamic TestingabstractUnrestricted file upload (UFU) vulnerabilities, especially unrestricted executable file upload (UEFU) vulnerabilities, pose severe security risks to web servers. For instance, attackers can leverage such vulnerabilities to execute arbitrary code to gain the control of a whole web server. Therefore, it is significant to develop effective and efficient methods to detect UFU and UEFU vulnerabilities. Towards this, most state-of-the-art methods are designed based on dynamic testing. Nevertheless, they still entail two critical limitations. 1) They heavily rely on manual efforts, which are error-prone and have poor adaptability. 2) They seldom leverage effective information to guide the testing, resulting in generating a large number of invalid test cases. Such limitations severely hinder the performance of UFU vulnerability detection. In this paper, we propose URadar, an adaptive dynamic testing-based method for detecting UFU and UEFU vulnerabilities. There are three core designs in URadar, including file upload interface identification, file type restriction inference, and invalid mutation combination filtration, which can effectively solve the two limitations of existing methods. To evaluate the performance of URadar, we conduct extensive experiments and compare URadar with state-of-the-art methods (e.g., FUSE, RIPS). In testing 18 web applications, URadar discovers 26 UEFU vulnerabilities, where 8 are new, and 6 have been assigned new CVE/CNNVD IDs. By contrast, FUSE and RIPS find 14 and 2 UEFU vulnerabilities, respectively. To discover the same number of UFU vulnerabilities, FUSE needs to send 73,261 request packets with a time cost of 2,791.1s on average, 23.43 and 20.53 times of the requirements for URadar. The above results demonstrate that URadar significantly outperforms the state-of-the-art methods. In addition, we have open-sourced URadar to facilitate future research on UFU vulnerability detection. Yuanchao Chen, Yuwei Li 0002, Zulie Pan, Yuliang Lu, Juxing Chen, Shouling Ji |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | HSS: A Memory-Efficient, Accurate, and Fast Network Measurement Framework in Sliding WindowsabstractNetwork measurement is indispensable to network management. This paper focuses on three fundamental network measurement tasks: membership query, frequency query, and heavy hitter query. Existing solutions, such as sketches, sliding window algorithms, and the Sliding Sketch framework, struggle to simultaneously achieve memory efficiency, accuracy, real-time operation, and generic application. Accordingly, this paper proposes the Half Sliding Sketch (HSS), an improvement over the state-of-the-art Sliding Sketch framework. The HSS framework is applied to five contemporary sketches for the three aforementioned query tasks. Theoretical analysis reveals that our framework is faster, more memory-efficient and more accurate than the state-of-the-art Sliding Sketch while still being generic. Extensive experimental results reveal that HSS significantly enhances the accuracy for the three query tasks, achieving improvements of$2\times $to$28.7\times $,$1.5\times $to$9\times $, and$2.4\times $to$3.6\times $, respectively. Moreover, in terms of speed, HSS is$1.2\times $to$1.5\times $faster than the Sliding Sketch. Zijun Hang, Yuliang Lu |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Backdoor Learning on Siamese Networks Using Physical Triggers: FaceNet as a Case Study
Zeshan Pang, Yuyuan Sun, Shasha Guo 0001, Yuliang Lu |
ICDF2C (1) | 4 |
| 2023 | Flow-MAE: Leveraging Masked AutoEncoder for Accurate, Efficient and Robust Malicious Traffic ClassificationabstractMalicious traffic classification is crucial for Intrusion Detection Systems (IDS). However, traditional Machine Learning approaches necessitate expert knowledge and a significant amount of well-labeled data. Although recent studies have employed pre-training models from the Natural Language Processing domain, such as ET-BERT, for traffic classification, their effectiveness is impeded by limited input length and fixed Byte Pair Encoding. Zijun Hang, Yuliang Lu |
RAID | 2 |
| 2022 | Generative Text Steganography via Multiple Social Network Channels Based on Transformers
Long Yu 0003, Yuliang Lu, Xuehu Yan |
NLPCC (1) | 2 |
| 2021 | A novel (k1, k2, n)-threshold two-in-one secret image sharing scheme for multiple secrets
Lintao Liu, Yuliang Lu, Xuehu Yan |
J. Vis. Commun. Image Represent. | 2 |
| 2021 | BAT: real-time inaudible sound capture with smartphones
Dingwei Tan, Yuliang Lu, Xuehu Yan |
Multim. Tools Appl. | 2 |
| 2021 | A Common Method of Share Authentication in Image Secret SharingabstractBecause of the importance of digital images and their extensive application to digital watermarking, block chain, access control, identity authentication, distributive storage in the cloud and so on, image secret sharing (ISS) is attracting ever-increasing attention. Share authentication is an important issue in its practical application. However, most ISS schemes with share authentication ability require a dealer to participate in the authentication (namely, dealer participatory authentication). In this paper, we design an ISS for a$(k,n)$-threshold with separate share authentication abilities of both dealer participatory authentication and dealer nonparticipatory authentication. The advantages of polynomial-based ISS and visual secret sharing (VSS) are skillfully fused to achieve these two authentication abilities without sending a share by using a screening operation. In addition, the designed scheme has the characteristics of low decryption (authentication) complexity, lossless decryption and no pixel expansion. Experiments and theoretical analyses are performed to show the effectiveness of the designed scheme. Xuehu Yan, Yuliang Lu, Ching-Nung Yang, Xinpeng Zhang 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2021 | Robust Secret Image Sharing Resistant to Noise in SharesabstractA secret image is split into shares in the generation phase of secret image sharing (SIS) for a threshold. In the recovery phase, the secret image is recovered when any or more shares are collected, and each collected share is generally assumed to be lossless in conventional SIS during storage and transmission. However, noise will arise during real-world storage and transmission; thus, shares will experience data loss, which will also lead to data loss in the secret image being recovered. Secret image recovery in the case of lossy shares is an important issue that must be addressed in practice, which is the overall subject of this article. An SIS scheme that can recover the secret image from lossy shares is proposed in this article. First, robust SIS and its definition are introduced. Next, a robust SIS scheme for a threshold without pixel expansion is proposed based on the Chinese remainder theorem (CRT) and error-correcting codes (ECC). By screening the random numbers, the share generation phase of the proposed robust SIS is designed to implement the error correction capability without increasing the share size. Particularly in the case of collecting noisy shares, our recovery method is to some degree robust to some noise types, such as least significant bit (LSB) noise, JPEG compression, and salt-and-pepper noise. A theoretical proof is presented, and experimental results are examined to evaluate the effectiveness of our proposed method. Xuehu Yan, Lintao Liu, Yuliang Lu |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2020 | Application of random elements in ISSabstractThe ‐threshold image secret sharing (ISS) encodes a secret image into n shares. When k or more shares are obtained, the secret image can be decoded; however, less than k shares could decode none of the secret image. ISS primarily includes polynomial‐based ISS and visual secret sharing (VSS). In this study, the authors find that the random elements in ISS can be used not only to hide information but also to obtain more features such as multiple decryptions and comprehensible share. They have established an application model of random elements that is suitable for both polynomial‐based ISS and VSS. On the basis of the model, they have extended three algorithms to achieve information hiding, multiple decryptions and comprehensible share. Experiments indicate the effectiveness of these algorithms. Xuehu Yan, Yuliang Lu, Lintao Liu, Jingju Liu, Guozheng Yang |
IET Image Process. | 2 |
| 2020 | XOR-ed visual secret sharing scheme with robust and meaningful shadows based on QR codesabstractAbstract Quick response (QR) codes are becoming increasingly popular in various areas of life due to the advantages of the error correction capacity, the ability to be scanned quickly and the capacity to contain meaningful content. The distribution of dark and light modules of a QR code looks random, but the content of a code can be decoded by a standard QR reader. Thus, a QR code is often used in combination with visual secret sharing (VSS) to generate meaningful shadows. There may be some losses in the process of distribution and preservation of the shadows. To recover secret images with high quality, it is necessary to consider the scheme’s robustness. However, few studies examine robustness of VSS combined with QR codes. In this paper, we propose a robust (k, n)-threshold XOR-ed VSS (XVSS) scheme based on a QR code with the error correction ability. Compared with OR-ed VSS (OVSS), XVSS can recover the secret image losslessly, and the amount of computation needed is low. Since the standard QR encoder does not check if the padding codewords are correct during the encoding phase, we replace padding codewords by initial shadows shared from the secret image using XVSS to generate QR code shadows. As a result, the shadows can be decoded normally, and their error correction abilities are preserved. Once all the shadows have been collected, the secret image can be recovered losslessly. More importantly, if some conventional image attacks, including rotation, JPEG compression, Gaussian noise, salt-and-pepper noise, cropping, resizing, and even the addition of camera and screen noises are performed on the shadows, the secret image can still be recovered. The experimental results and comparisons demonstrate the effectiveness of our scheme. Longdan Tan, Yuliang Lu, Xuehu Yan, Lintao Liu, Xuan Zhou 0006 |
Multim. Tools Appl. | 2 |
| 2020 | Visual secret sharing scheme with (n, n) threshold for selective secret content based on QR codes
Song Wan, Lanlan Qi, Guozheng Yang, Yuliang Lu, Xuehu Yan |
Multim. Tools Appl. | 4 |
| 2020 | Weighted visual cryptographic scheme with improved image quality
Xuehu Yan, Feng Liu 0032, Wei Qi Yan 0001, Guozheng Yang, Yuliang Lu |
Multim. Tools Appl. | 5 |
| 2020 | Penrose tiling for visual secret sharing
Xuehu Yan, Wei Qi Yan 0001, Lintao Liu, Yuliang Lu |
Multim. Tools Appl. | 4 |
| 2020 | On the Value of Order Number and Power in Secret Image SharingabstractShadow images generated from Shamir’s polynomial-based secret image sharing (SSIS) may leak the original secret image information, which causes a significant risk. The occurrence of this risk is closely related to the basis of secret image sharing, Shamir’s polynomial. Shamir’s polynomial plays an essential role in secret sharing, but there are relatively few studies on the power and order number of Shamir’s polynomial. In order to improve the security and effectiveness of SSIS, this paper mainly studies the utility of two parameters in Shamir’s polynomial, order number and power. Through the research of this kind of utility, the choice of order number and power can be given under different security requirements. In this process, an effective shadow image evaluation algorithm is proposed, which can measure the security of shadow images generated by SSIS. The user can understand the influence rule of the order number and power in SSIS, so that the user can choose the appropriate order number and power according to different security needs. Yongqiang Yu, Yuliang Lu, Xuehu Yan |
Secur. Commun. Networks | 3 |
| 2020 | Secret image sharing with separate shadow authentication ability
Xuehu Yan, Qinghong Gong, Guozheng Yang, Yuliang Lu, Jingju Liu |
Signal Process. Image Commun. | 5 |
| 2020 | Reversible Image Secret SharingabstractIn reversible image secret sharing (RISS), the cover image can be recovered to some degree, and a share can be comprehensible rather than noise-like. Reversible cover images play an important role in law enforcement and medical diagnosis. The comprehensible share can not only reduce the suspicion of attackers but also improve the management efficiency of shares. In this paper, we first provide a formal definition of RISS. Then, we propose an RISS algorithm for a (k, n)-threshold based on the principle of the Chinese remainder theorem-based ISS (CRTISS). In the proposed RISS, the secret image is losslessly decoded by a modular operation, and the original cover image is recovered by a binarization operation, both of which are just simple operations. Theoretical analyses and experiments are provided to validate the proposed definition and algorithm. Xuehu Yan, Yuliang Lu, Lintao Liu, Xianhua Song |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Security analysis and classification of image secret sharing
Xuehu Yan, Lintao Liu, Yuliang Lu, Qinghong Gong |
J. Inf. Secur. Appl. | 3 |
| 2019 | Generalized general access structure in secret image sharing
Xuehu Yan, Yuliang Lu |
J. Vis. Commun. Image Represent. | 2 |
| 2019 | Polynomial-based extended secret image sharing scheme with reversible and unexpanded covers
Lintao Liu, Yuliang Lu, Xuehu Yan |
Multim. Tools Appl. | 2 |
| 2019 | A general progressive secret image sharing construction method
Xuehu Yan, Yuliang Lu, Lintao Liu |
Signal Process. Image Commun. | 2 |
| 2018 | Partial secret image sharing for (k, n) threshold based on image inpainting
Xuehu Yan, Yuliang Lu, Lintao Liu, Shen Wang 0004 |
J. Vis. Commun. Image Represent. | 2 |
| 2018 | Greyscale-images-oriented progressive secret sharing based on the linear congruence equation
Lintao Liu, Yuliang Lu, Xuehu Yan, Huaixi Wang |
Multim. Tools Appl. | 2 |
| 2018 | Progressive visual secret sharing for general access structure with multiple decryptions
Xuehu Yan, Yuliang Lu |
Multim. Tools Appl. | 2 |
| 2018 | Robust Visual Secret Sharing Scheme Applying to QR CodeabstractDifferent color patterns of quick response (QR) codes, such as RGB, grayscale, and binary QR codes, are widely used in applications. In this paper, we propose a novel XOR-based visual secret sharing (VSS) scheme using grayscale QR codes as cover images and binary QR code as secret image. First, all the codewords of the secret QR code image are encoded into n temporary binary QR code images, which are substituted for the second significant bit planes of the grayscale QR code cover images to generate n shares. Each share is a grayscale QR code image, which can be decoded by a standard QR code decoder, so that it may not attract the attention of potential attackers when distributed in the public channel. The secret image can be recovered by XORing the codewords regions of QR codes which are extracted from the second significant bit planes of the grayscale shares. More importantly, the proposed scheme is robust to JPEG compression, addition of different noises, rotation, resizing, and cropping, which is useful in practice. The effectiveness and robustness of our scheme are shown by the experimental results. The application of QR code is suitable for wireless multimedia data security. Longdan Tan, Kesheng Liu, Xuehu Yan, Lintao Liu, Jinrui Chen, Feng Liu 0032, Yuliang Lu |
Secur. Commun. Networks | 8 |
| 2017 | Partial Secret Image Sharing for (n, n) Threshold Based on Image Inpainting
Xuehu Yan, Yuliang Lu, Lintao Liu, Shen Wang 0004, Song Wan, Wanmeng Ding |
ICIG (3) | 2 |
| 2017 | Secret Image Sharing for (k, k) Threshold Based on Chinese Remainder Theorem and Image Characteristics
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan, Wanmeng Ding |
PSIVT | 2 |
| 2016 | Random Grids-Based Threshold Visual Secret Sharing with Improved Visual Quality
Xuehu Yan, Yuliang Lu, Lintao Liu, Song Wan |
IWDW | 2 |
| 2016 | A Progressive Threshold Secret Image Sharing with Meaningful Shares for Gray-Scale ImageabstractSecret image sharing is a mechanism to protect a secret image among a group of participants by encrypting the secret into shares and decrypting the secret with sufficient shares. Conventional secret sharing schemes have limitations of lossy recovery and pixel expansion for binary images, or complex computation and "All-or-Nothing" for greyscale images. In this paper, a novel progressive secret image sharing(PSS) scheme with threshold and lossless recovery is proposed to overcome these problems. Meanwhile, its meaningful shadows with the same size as secret are beneficial to identify and decrease the suspicion, and it can be directly applied to share grayscale images. Simulations show the advantages and effectiveness of the proposed scheme. Lintao Liu, Yuliang Lu, Xuehu Yan, Song Wan |
MSN | 2 |
| 2016 | Visual Secret Sharing Scheme with (k, n) Threshold Based on QR CodesabstractIn this paper, a novel visual secret sharing (VSS) scheme with using QR codes is investigated. The proposed visual secret sharing scheme based on QR codes(VSSQR) can visually reveal secret image by stacking k or more shares (shadow images) from all the n QR codes as well as scan the QR code by a QR code reader. Our VSSQR exploits the error correction mechanism in the QR code structure, to embed the bits corresponding to shares generated by VSS from a secret bit into the same locations of QR codes in the processing of encoding QR. Each output share is a valid QR code, which may reduce the likelihood of attracting the attention of potential attackers, that can be scanned and decoded utilizing a QR code reader. The secret image can be recovered by stacking for case (k, n) based on the human visual system without any computation. In addition, it can assist alignment for VSS recovery. The experiment results show the effectiveness of our scheme. Song Wan, Yuliang Lu, Xuehu Yan, Lintao Liu |
MSN | 2 |