VLDB 2026 Research / reviewers in the wild / expert
Chaoyi Lu
dblp:223/6794
· DBLP profile ↗
30ranked-venue papers
5as first author
23since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 1 first-author · 12 since 2021Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Computer networks · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification Attack
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Qingfeng Pan, Jun Shao 0001 |
NDSS | 2 |
| 2026 | Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking
Yuxiao Wu, Chaoyi Lu |
NDSS | 3 |
| 2026 | Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action
Shibo Cui, Mingxuan Liu 0006, Baojun Liu 0002, Hai-Xin Duan, Ruixuan Li 0008, Chaoyi Lu, Jinghua Bai |
WWW | 6 |
| 2026 | FedPSA: Modeling behavioral staleness in asynchronous federated learning
Chaoyi Lu, Zhichuan Yang, Jinqian Chen, Dongfu Yin, Jihua Zhu |
Expert Syst. Appl. | 1 |
| 2026 | HyperPoint: Multimodal 3D foundation model in hyperbolic space
Haozhe Cheng, Chaoyi Lu, Zhengqiao Li, Minghong Wu, Huimin Lu 0001, Jihua Zhu |
Pattern Recognit. | 3 |
| 2026 | Curve3D: Curvature-aware masked autoencoder for self-supervised point cloud understanding
Chaoyi Lu, Haozhe Cheng, Huimin Lu 0001, Jihua Zhu |
Pattern Recognit. | 2 |
| 2026 | Traffic Shadowing: A Global Investigation of Internet Traffic Observation and User Data Reutilization
Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Ruixuan Li 0008, Hai-Xin Duan |
IEEE Trans. Netw. | 2 |
| 2025 | Corrected with the Latest Version: Make Robust Asynchronous Federated Learning PossibleabstractAs an emerging paradigm of federated learning, asynchronous federated learning offers significant speed advantages over traditional synchronous federated learning. Unlike synchronous federated learning, which requires waiting for all clients to complete updates before aggregation, asynchronous federated learning aggregates the models that have arrived in real-time, greatly improving training speed. However, this mechanism also introduces the issue of client model version inconsistency. When the differences between models of different versions during aggregation become too large, it may lead to conflicts, thereby reducing the model’s accuracy. To address this issue, this paper proposes an asynchronous federated learning version correction algorithm based on knowledge distillation, named FedADT. FedADT applies knowledge distillation before aggregating gradients, using the latest global model to correct outdated information, thus effectively reducing the negative impact of outdated gradients on the training process. Additionally, FedADT introduces an adaptive weighting function that adjusts the knowledge distillation weight according to different stages of training, helps mitigate the misleading effects caused by the poorer performance of the global model in the early stages of training. This method significantly improves the overall performance of asynchronous federated learning without adding excessive computational overhead. We conducted experimental comparisons with several classical algorithms, and the results demonstrate that FedADT achieves significant improvements over other asynchronous methods and outperforms all methods in terms of convergence speed. Chaoyi Lu, Zhichuan Yang |
IJCNN | 1 |
| 2025 | Understanding and Characterizing Intermediate Paths of Email Delivery: The Hidden DependenciesabstractIn the cloud era, hosting-based email services have become a common business model. Various entities can participate in the email delivery process. However, the intermediate paths of email delivery have received little attention. In particular, the vulnerabilities and centralization of email intermediate paths have already posed real-world security threats. This paper conducts the first systematic analysis of intermediate paths of email delivery, aiming to understand dependence patterns and characterize the centralization. In collaboration with a large email service provider, we collected Received headers from email reception logs spanning nine months and reconstructed the complete intermediate paths of 105M clean emails. Our results reveal that Microsoft is the dominant provider of intermediate paths, participating in 66.4% of emails. We find that 86.9M (82.7%) emails rely on third-party providers in intermediate paths, and 9.1M (8.7%) paths involve multiple providers. Email signature providers frequently appear in cross-vendor intermediate paths. In addition, we reveal significant differences in the regional dependencies and centralization of email intermediate paths across countries and continents. The centralization observed in email intermediate paths also differs from incoming and outgoing servers. We hope our work prompts more attention to email intermediate paths to enhance the security of the email ecosystem. Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Hai-Xin Duan, Qingfeng Pan, Jun Shao 0001 |
IMC | 2 |
| 2025 | HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Geng Hong, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan, Min Yang 0002, Jun Shao 0001 |
NDSS | 2 |
| 2025 | Rethinking Regressor in 3D Gaussian Pretraining
Xingguang Han, Chaoyi Lu |
PRCV (10) | 3 |
| 2025 | AFBS: buffer gradient selection in semi-asynchronous federated learning
Chaoyi Lu, Jinqian Chen, Zhichuan Yang, Jiangming Pan, Jihua Zhu |
Knowl. Based Syst. | 1 |
| 2024 | Yesterday Once More: Global Measurement of Internet Traffic Shadowing BehaviorsabstractWe present a global, large-scale measurement of Internet traffic shadowing, a less-studied yet covert format of on-path manipulation. As part of pervasive monitoring, data within packets is silently observed, retained, and then leveraged to produce additional, unsolicited requests. To depict the landscape of such behaviors, we generate a collection of decoy traffic that lures on-path exhibitors, spread them via 4,364 vantage points recruited from commercial VPN providers, and capture unsolicited requests triggered by them. We find traffic shadowing against DNS, HTTP, and TLS protocols; DNS queries to several public resolvers are most susceptible, by being observed on a wide range of Internet paths. Through hop-by-hop tracerouting, we find observers of DNS queries associated with destinations, while HTTP messages are mostly observed on the wire. User data can be retained for long, e.g., over 10 days, and can be leveraged for more than once. While a notable portion of unsolicited requests originate from addresses labeled by blocklists, we find most of them are performing reconnaissance, and we see no evidence of exploits attempted in the collected traffic. Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Junzhe Sun, Zhou Li 0001 |
IMC | 2 |
| 2024 | Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan |
NDSS | 4 |
| 2024 | A Worldwide View on the Reachability of Encrypted DNS ServicesabstractTo protect user DNS privacy, four DNS over Encryption (DoE) protocols have been proposed, including DNS over TLS (DoT), DNS over HTTPS (DoH), DNS over QUIC (DoQ), and DNS over HTTP/3 (DoH3). Ensuring reachability stands as a prominent prerequisite for the proper functionality of these DoE protocols, driving considerable efforts in this domain. However, existing studies predominantly concentrate on a limited number of DoT/DoH domains or employ a restricted subset of vantage points (VPs). Ruixuan Li 0008, Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Jun Shao 0001 |
WWW | 3 |
| 2024 | Investigating Deployment Issues of DNS Root Server Instances From a China-Wide ViewabstractDNS root servers are the starting point of most DNS queries. To ensure their security and stability, multiple anycast instances are operated worldwide, and new root instances have been rapidly deployed in recent years. Apart from authorized instances managed by Root Server System, some networks equip unauthorized instances to hijack queries from clients. Despite various root instances handling queries within their residing networks, few studies have focused on the deployment issues of these instances. In this paper, we provide the first study to reveal the deployment issues of root instances from a nationwide view. With the support of 7,860 vantage points, we utilized a suite of methodologies to identify the deployment of unauthorized instances. 54 vantage points witnessed the evidence of unauthorized instances, and 70.4% of them further observed security issues of unauthorized instances, including DoS, unavailability of DNSSEC validation, and vulnerable DNS software. Additionally, we utilized the side-channel information of censorship mechanisms to measure the catchment area of authorized instances. We found that most authorized instances in the Chinese mainland serve with limited catchment areas due to restricted BGP policies. Through discussions with ISPs and network operators, we make recommendations to improve the deployment status of different root instances. Fenglu Zhang, Baojun Liu 0002, Chaoyi Lu, Yunpeng Xing, Hai-Xin Duan, Ying Liu 0024, Liyuan Chang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersabstractIn this paper, we present a new DNS amplification attack, named TsuKing. Instead of exploiting individual DNS resolvers independently to achieve an amplification effect, TsuKing deftly coordinates numerous vulnerable DNS resolvers and crafted queries together to form potent DoS amplifiers. We demconstrate that with TsuKing, an initial small amplification factor can inrease exponentially through the internal layers of coordinated amplifiers, resulting in an extremely powerful amplification attack. TsuKing has three variants, including DNSRetry, DNSChain, and DNSLoop, all of which exploit a suite of inconsistent DNS implementations to achieve enormous amplification effect. With comprehensive measurements, we found that about 14.5% of 1.3M open DNS resolvers are potentially vulnerable to TsuKing. Real-world controlled evaluations indicated that attackers can achieve a packet amplification factor of at least 3,700X (DNSChain). We have reported vulnerabilities to affected vendors and provided them with mitigation recommendations. We have received positive responses from 6 vendors, including Unbound, MikroTik, and AliDNS, and 3 CVEs were assigned. Some of them are implementing our recommendations. Wei Xu 0064, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Jia Zhang 0004, Jianjun Chen 0005, Tao Wan 0004 |
CCS | 3 |
| 2023 | Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersabstractAuthoritative nameservers are delegated to provide the final resource record. Since the security and robustness of DNS are critical to the general operation of the Internet, domain name owners are required to deploy multiple candidate nameservers for traffic load balancing. Once the load balancing mechanism is compromised, an adversary can manipulate a large number of legitimate DNS requests to a specified candidate nameserver. As a result, it may not only bypass the defense mechanisms used to filter malicious traffic that can overload the victim nameserver, but also lowers the bar for DNS traffic hijacking and cache poisoning attacks. Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Jianjun Chen 0005, Chaoyi Lu, Linjian Song, Ying Liu 0024, Hai-Xin Duan, Min Yang 0002 |
CCS | 5 |
| 2023 | The Maginot Line: Attacking the Boundary of DNS Caching Protection
Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Qifan Zhang 0002, Zhou Li 0001, Hai-Xin Duan, Qi Li 0002 |
USENIX Security Symposium | 2 |
| 2022 | Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case Study
Fenglu Zhang, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Ying Liu 0024 |
PAM | 2 |
| 2021 | Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemabstractHTTPS secures communications in the web and heavily relies on the Web PKI for authentication. In the Web PKI, Certificate Authorities (CAs) are organizations that provide trust and issue digital certificates. Web clients rely on public root stores maintained by operating systems or browsers, with hundreds of audited CAs as trust anchors. However, as reported by security incidents, hidden root CAs beyond the public root programs have been imported into local root stores, which allows adversaries to gain trust from web clients. Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Zaifeng Zhang |
CCS | 3 |
| 2021 | From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
Chaoyi Lu, Baojun Liu 0002, Yiming Zhang 0009, Zhou Li 0001, Fenglu Zhang, Hai-Xin Duan, Ying Liu 0024, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao 0001, Min Yang 0002 |
NDSS | 1 |
| 2021 | Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Chaoyi Lu, Baojun Liu 0002, Shuang Hao 0001, Hai-Xin Duan, Qingfeng Pan, Min Yang 0002 |
USENIX Security Symposium | 5 |
| 2020 | Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in ChinaabstractFake base station (FBS) has been exploited by criminals to attack mobile users by spamming fraudulent messages for over a decade. Despite that prior work has proposed several techniques to mitigate this issue, FBS spam is still a long-standing challenging issue in some countries, such as China, and causes billions of dollars of financial loss every year. Therefore, understanding and exploring the thematic strategies in the FBS spam ecosystem at a large scale would improve the defense mechanisms. Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Mingxuan Liu 0006, Ying Liu 0024 |
CCS | 3 |
| 2020 | Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksabstractHTTPS is principally designed for secure end-to-end communication, which adds confidentiality and integrity to sensitive data transmission. While several man-in-the-middle attacks (e.g., SSL Stripping) are available to break the secured connections, state-of-the-art security policies (e.g., HSTS) have significantly increased the cost of successful attacks. However, the TLS certificates shared by multiple domains make HTTPS hijacking attacks possible again. Mingming Zhang 0010, Kaiwen Shen, Ziqiao Kong, Chaoyi Lu, Yu Wang 0288, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Min Yang 0002 |
CCS | 5 |
| 2020 | Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding Devices
Chaoyi Lu, Qiushi Yang, Dongjie Zhou, Baojun Liu 0002, Keyu Man, Shuang Hao 0001, Hai-Xin Duan, Zhiyun Qian |
USENIX Security Symposium | 2 |
| 2019 | TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS AnalysisabstractIllicit traffic monetization is a type of Internet fraud that hijacks users' web requests and reroutes them to a traffic network (e.g., advertising network), in order to unethically gain monetary rewards. Despite its popularity among Internet fraudsters, our understanding of the problem is still limited. Since the behavior is highly dynamic (can happen at any place including client-side, transport-layer and server-side) and selective (could target a regional network), prior approaches like active probing can only reveal a small piece of the entire ecosystem. So far, questions including how this fraud works at a global scale and what fraudsters' preferred methods are, still remain unanswered. To fill the missing pieces, we developed TraffickStop the first system that can detect this fraud passively. Our key contribution is a novel algorithm that works on large-scale DNS logs and efficiently discovers abnormal domain correlations. TraffickStop enables the first landscape study of this fraud, and we have some interesting findings. By analyzing over 231 billion DNS logs of two weeks, we discovered 1,457 fraud sites. Regarding its scale, the fraud sites receive more than 53 billion DNS requests within one year, and a company could lose up to 53K dollars per day due to fraud traffic. We also discovered two new strategies that are leveraged by fraudsters to evade inspection. Our work provides new insights into illicit traffic monetization, raises its public awareness, and contributes to a better understanding and ultimate elimination of this threat. Baojun Liu 0002, Zhou Li 0001, Peiyuan Zong, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Sumayah A. Alrwais, XiaoFeng Wang 0001, Shuang Hao 0001, Yaoqi Jia, Yiming Zhang 0009, Kai Chen 0012, Zaifeng Zhang |
EuroS&P | 4 |
| 2019 | An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?abstractDNS packets are designed to travel in unencrypted form through the Internet based on its initial standard. Recent discoveries show that real-world adversaries are actively exploiting this design vulnerability to compromise Internet users' security and privacy. To mitigate such threats, several protocols have been proposed to encrypt DNS queries between DNS clients and servers, which we jointly term as DNS-over-Encryption. While some proposals have been standardized and are gaining strong support from the industry, little has been done to understand their status from the view of global users. Chaoyi Lu, Baojun Liu 0002, Zhou Li 0001, Shuang Hao 0001, Hai-Xin Duan, Mingming Zhang 0010, Chunying Leng, Ying Liu 0024, Zaifeng Zhang |
Internet Measurement Conference | 1 |
| 2018 | A Reexamination of Internationalized Domain Names: The Good, the Bad and the UglyabstractInternationalized Domain Names (IDNs) are domain names containing non-ASCII characters. Despite its installation in DNS for more than 15 years, little has been done to understand how this initiative was developed and its security implications. In this work, we aim to fill this gap by studying the IDN ecosystem and cyber-attacks abusing IDN. In particular, we performed by far the most comprehensive measurement study using IDNs discovered from 56 TLD zone files. Through correlating data from auxiliary sources like WHOIS, passive DNS and URL blacklists, we gained many insights. Our discoveries are multi-faceted. On one hand, 1.4 million IDNs were actively registered under over 700 registrars, and regions within east Asia have seen prominent development in IDN registration. On the other hand, most of the registrations were opportunistic: they are currently not associated with meaningful websites and they have severe configuration issues (e.g., shared SSL certificates). What is more concerning is the rising trend of IDN abuse. So far, more than 6K IDNs were determined as malicious by URL blacklists and we also identified 1,516 and 1,497 IDNs showing high visual and semantic similarity to reputable brand domains (e.g., apple.com). Meanwhile, brand owners have only registered a few of these domains. Our study suggests the development of IDN needs to be re-examined. New solutions and proposals are needed to address issues like its inadequate usage and new attack surfaces. Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Ying Liu 0024, Hai-Xin Duan, Shuang Hao 0001, Zaifeng Zhang |
DSN | 2 |
| 2018 | Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution Path
Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Zhou Li 0001, Shuang Hao 0001, Min Yang 0002 |
USENIX Security Symposium | 2 |