VLDB 2026 Research / reviewers in the wild / expert
Dazhi Zhan
dblp:199/9363
· DBLP profile ↗
13ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0003-2766-3405ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 5 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SHIELD: Semantic-guided graph contrastive learning for malware detection
Tong Han, Dazhi Zhan, Zhisong Pan 0003, Shize Guo |
Expert Syst. Appl. | 3 |
| 2026 | From simulation to learning: A comprehensive review of multi-agent systems in emergency management
Tengjiao Guo, Dazhi Zhan |
Neurocomputing | 3 |
| 2026 | MalPDT: Backdoor Attack Against Static Malware Detection With Plug-and-Play Dynamic TriggersabstractThe Deep Neural Network (DNN) based detection model’s dependency on third-party crowdsourced sources poses a new security threat from backdoor attacks against malware detectors. Attackers attempt to inject hidden backdoors into the target model, allowing it to perform well on clean samples. Once the attacker-defined trigger activates the hidden backdoor, the model predictions for poisoned samples are maliciously altered. Different from existing backdoor attacks either utilize fixed triggers or generate sample-specific triggers, we explore a novel backdoor attack paradigm in malware domain and propose MalPDT, in which backdoor triggers achieve dynamic variability in trigger patterns and retain compatibility across malware samples. We train a generator capable of hiding information to produce dynamically variable encoded byte segments, which are then injected as triggers into the unused regions of PE malware in a functionality-preserving manner. In MalPDT, any combination of a malware sample and a trigger can form a poisoned sample capable of activating the backdoor, enabling plug-and-play capability. We conduct extensive experiments to validate the effectiveness of MalPDT in attacking models with or without defenses. Dazhi Zhan, Xin Liu 0042, Zhisong Pan 0003, Shize Guo |
IEEE Trans. Computers | 1 |
| 2025 | Practical clean-label backdoor attack against static malware detection
Dazhi Zhan, Xin Liu 0042, Tong Han, Zhisong Pan 0003, Shize Guo |
Comput. Secur. | 1 |
| 2025 | GAME-RL: Generating Adversarial Malware Examples Against API Call Based Detection via Reinforcement LearningabstractThe adversarial example presents new security threats to trustworthy detection systems. In the context of evading dynamic detection based on API call sequences, a practical approach involves inserting perturbing API calls to modify these sequences. The type of inserted API calls and their insertion locations are crucial for generating an effective adversarial API call sequence. Existing methods either optimize the inserted API calls while neglecting the insertion positions or treat these optimizations as separate processes. This can lead to inefficient attacks that insert a large number of unnecessary API calls. To address this issue, we propose a novel reinforcement learning (RL) framework, dubbed GAME-RL, which simultaneously optimizes both the perturbing APIs and their insertion positions. Specifically, we define malware modification through IAT (Import Address Table) hooking as a sequential decision-making process. We introduce an invalid action masking and an auto-regressive policy head within the RL framework, ensuring the feasibility of IAT hooking and capturing the inherent relationship between factors. GAME-RL learns more effective evasion strategies, taking into account functionality preservation and the black-box setting. We conduct comprehensive experiments on various target models, demonstrating that GAME-RL significantly improves the evasion rate while maintaining acceptable levels of adversarial overhead. Dazhi Zhan, Xin Liu 0042, Wei Li 0116, Shize Guo, Zhisong Pan 0003 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Provable Acceleration of Nesterov's Accelerated Gradient Method over Heavy Ball Method in Training Over-Parameterized Neural Networks
Xin Liu 0042, Wei Tao 0002, Wei Li 0116, Dazhi Zhan, Zhisong Pan 0003 |
IJCAI | 4 |
| 2024 | MalPatch: Evading DNN-Based Malware Detection With Adversarial PatchesabstractStatic analysis is a crucial protection layer that enables modern antivirus systems to address the rampant proliferation of malware. These systems are increasingly relying on deep neural networks (DNNs) to automatically extract reliable features and achieve outstanding detection accuracy. Since DNNs are known to be vulnerable to adversarial examples, several studies have proposed practical evasion attacks to generate adversarial perturbations that can evade malware detectors. These attacks, however, require specific designs for the given input sample, prohibiting them from large-scale deployment. Therefore, it is more practical to generate sample-agnostic perturbations that do not involve recalculations regardless of the input malware sample. To this end, we leverage an adversarial patch attack, which is a special type of adversarial attack that dose not know the sample being modified during the attack construction process. In particular, we propose a new adversarial attack against malware detection systems called MalPatch. It locates the nonfunctional part of malware for adversarial patch injection to protect its executability while generating adversarial examples based on different strategies. The generated patch can be injected into any malware sample, fooling the detector into classifying it as benign. Experimental results demonstrate that MalPatch is effective under different attack settings. In the white-box setting, MalPatch achieves 69%-78% success rates against DNN detectors based on raw byte features and 47%-96% success rates against four grayscale detectors based on image features. In the black-box setting, the success rates of MalPatch against the same models reach 54%-74% and 27%-42%, respectively. We conclude by discussing several of its potential countermeasures and the generality of our approach. Dazhi Zhan, Yexin Duan, Yue Hu 0016, Shize Guo, Zhisong Pan 0003 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | PSP-Mal: Evading Malware Detection via Prioritized Experience-based Reinforcement Learning with Shapley PriorabstractWith the widespread application of machine learning techniques in malware detection, researchers have proposed various adversarial attack methods to generate adversarial examples (AEs) of malware, thereby evading detection. Previous studies have shown that the reinforcement learning (RL) framework can enable black-box attacks by performing a sequence of function-preserving operations, which produces functional evasive malware samples. However, it is difficult to obtain the useful guidance and feedbacks from the environment for agent training in the black-box scenario, which results in the RL framework being unable to learn the effective evasion policy. In this paper, we propose the Shapley prior and establish a prior-guidance-based RL framework, namely PSP-Mal, to generate AEs against Portable Executable (PE) malware detectors. Our framework improves on existing methods in three aspects: 1) We explore feature effects of the black-box model by computing Shapley values and further propose the Shapley prior to represent the expected impact of operations. 2) A novel prioritized experience utilization mechanism is established regarding the Shapley prior guidance in the RL framework. 3) The actions are expanded into item-content pairs and we use the Thompson sampling to choose effective content, which helps to reduce randomness and ensure repeatability. We compare the attack performance of our framework with other methods, and experimental results demonstrate that our algorithm is more effective. The evasion rates of PSP-Mal against the LightGBM models trained on EMBER and SOREL-20M reach 76.88% and 72.03%, respectively. Dazhi Zhan, Xin Liu 0042, Yue Hu 0016, Lei Zhang 0126, Shize Guo, Zhisong Pan 0003 |
ACSAC | 1 |
| 2023 | AMGmal: Adaptive mask-guided adversarial attack against malware detection with minimal perturbation
Dazhi Zhan, Yexin Duan, Yue Hu 0016, Lujia Yin, Zhisong Pan 0003, Shize Guo |
Comput. Secur. | 1 |
| 2023 | Towards robust CNN-based malware classifiers using adversarial examples generated based on two saliency similarities
Dazhi Zhan, Yue Hu 0016, Shize Guo, Zhisong Pan 0003 |
Neural Comput. Appl. | 1 |
| 2022 | Adversarial attack via dual-stage network erosion
Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Zhengyun He, Dazhi Zhan, Jin Zhang 0024, Zhisong Pan 0003 |
Comput. Secur. | 6 |
| 2017 | PSF Smooth Method based on Simple Lens Imaging
Dazhi Zhan, Zhihui Xiong, Mi Wang, Maojun Zhang |
ICPRAM | 1 |
| 2017 | Blur kernel estimation using normal sinh-arcsinh model based on simple lens systemabstractFocused images captured by the lens system suffer image degradation due to factors, such as aberration, caused by the optical structure. In the simple lens system, aberration is more severe because of the simplification of the imaging system. In the existing imaging model, the blur kernel of the image is usually described by the point spread function. A few studies have shown that the blur kernel of the simple lens is close to the spatially deformed wedge. In the present study, a more reasonable normal sinh-arcsinh model is used to fit the blur kernel, and the parametric blur kernel is obtained by Powell algorithm. Finally, the clear image is restored and compared with other models to prove the advantages of our method. Dazhi Zhan, Xiangrong Zeng, Yu Liu 0008, Zhihui Xiong |
MMSP | 1 |