Pengfei Jing

dblp:226/7196 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 2Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Vehicular Intrusion Detection System for Controller Area Network: A Comprehensive Survey and Evaluation
abstract
The progress of automotive technologies has made cybersecurity a crucial focus, leading to various cyber attacks. These attacks primarily target the Controller Area Network (CAN) and specialized Electronic Control Units (ECUs). In order to mitigate these attacks and bolster the security of vehicular systems, numerous defense solutions have been proposed. These solutions aim to detect diverse forms of vehicular attacks. However, the practical implementation of these solutions still presents certain limitations and challenges. In light of these circumstances, this paper undertakes a thorough examination of existing vehicular attacks and defense strategies employed against the CAN and ECUs. The objective is to provide valuable insights and inform the future design of Vehicular Intrusion Detection Systems (VIDS). The findings of our investigation reveal that the examined VIDS primarily concentrate on particular categories of attacks, neglecting the broader spectrum of potential threats. Moreover, we provide a comprehensive overview of the significant challenges encountered in implementing a robust and feasible VIDS. Additionally, we put forth several defense recommendations based on our study findings, aiming to inform and guide the future design of VIDS in the context of vehicular security.
Lei Xue 0001, Sishan Wang, Xiapu Luo, Kaifa Zhao, Pengfei Jing, Xiaobo Ma 0001, Yajuan Tang, Haiying Zhou
IEEE Trans. Intell. Transp. Syst.6
2024 EFCC-IeT: Cross-Modal Electronic File Content Correlation via Image-Enhanced Text
Pengfei Jing, Jiguo Liu, Meimei Li
KSEM (1)1
2024 Revisiting Automotive Attack Surfaces: a Practitioners' Perspective
abstract
As modern vehicles become increasingly complex in terms of both external attack surfaces and internal in-vehicle network (IVN) topology, ensuring their cybersecurity remains a challenge. Existing standards and regulations, such as WP29 R155e and ISO 21434, attempt to establish a baseline for automotive cybersecurity, but their sufficiency in addressing the evolving threats is unclear. To fill in this gap, we first carried out an in-depth interview study with 15 experts in automotive cybersecurity, uncovering the particular challenges encountered during security activities and the limitations of current regulations. We identified 20 key insights from the interview data, ranging from the challenges and gaps in the existing automotive security industry to the limitations and recommendations for current regulations. Notably, we discovered that the quality of threat cases provided by existing regulations is unsatisfactory, and the Threat Analysis and Risk Assessment (TARA) process is often highly inefficient due to the lack of automatic tools. In response to the above limitations, we first built an improved threat database for automotive systems using the collected interview data, which enhanced the existing database both quantitatively and qualitatively. Additionally, we present CarVal, a datalog-based approach designed to infer multi-stage attack paths in IVNs and calculate risk values, thereby making TARA more efficient for automotive systems. By applying CarVal to five real vehicles, we performed extensive security analysis based on the generated attack paths and successfully exploited the corresponding attack chains in the newly gateway-segmented IVN, uncovering new automotive attack surfaces that previous research failed to cover, including the in-vehicle browser, official mobile app, backend server, and in-vehicle malware.
Pengfei Jing, Yingjie Cao, Le Yu 0002, Yuefeng Du 0006, Chenxiong Qian, Xiapu Luo, Sen Nie, Shi Wu
SP1
2022 Towards Automatically Reverse Engineering Vehicle Diagnostic Protocols
Le Yu 0002, Pengfei Jing, Xiapu Luo, Lei Xue 0001, Kaifa Zhao, Yajin Zhou, Ting Wang 0006, Guofei Gu, Sen Nie, Shi Wu
USENIX Security Symposium3
2021 Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted Perturbations
Pengfei Jing, Qiyi Tang 0003, Yuefeng Du 0006, Lei Xue 0001, Xiapu Luo, Ting Wang 0006, Sen Nie, Shi Wu
USENIX Security Symposium1
2020 Sadroid: A Deep Classification Model For Android Malware Detection Based On Semantic Analysis
abstract
Previous works have designed many deep learning models for Android malware detection using various features (e.g. permissions, APIs et.) to achieve better classification performance. However, these methods usually input each feature into the classifier independently and completely (using One-Hot Encoding) so that features are orthogonal to each other. This discrete representation is difficult to preserve the semantic information of features. In this paper, we design two feature segmentation methods to enhance the semantics of the features in preprocessing. Besides that, we propose a malware detection model that consists of a distributed representation process for Android features and an optimized convolutional neural network for classification, named Semantic Analysis Detection (SADroid). In SADroid, the distance between features with similar semantics is closer in vector space. It provides the semantic information of features to the classifier to improve the classification performance. In the evaluation, SADroid outperforms the advanced models in detection accuracy on a data set of 19,600 applications, while maintaining a low computational cost.
Dali Zhu, Pengfei Jing, Qing Xia 0007, Di Wu 0004, Yiming Zhang 0011
WCNC3
2019 A Transparent and Multimodal Malware Detection Method for Android Apps
abstract
While recent works have shown that deep learning method can improve the malware classification accuracy, the lack of the transparency has restricted its application in anti-virus scan engines. Existing researches have attempted to provide solutions to give high-fidelity explanations of the model's decision. However, current methods are not optimized for application security task, leading to a poor performance in Android malware detection. In this paper, we propose a backtracking method to infer suspicious features of the apps to explain the reason of classification. Besides, we also propose a malware detection model based on the fusion convolutional neural network using different types of features (e.g., permission, API, URL, etc.). For maximizing the benefits of encompassing multiple feature types, our framework trains the sub-models for each type of features separately and merges them at the end of the system to obtain a comprehensive classification result. The experimental results show that the backtracking method has a significant improvement in fidelity level compared with existing methods. Furthermore, we evaluate the performance of the proposed framework with other existing works. Leveraging the backtracking method, our framework has better performance in classification and significantly reduces detection time by 69% compared with prior approaches.
Dali Zhu, Pengfei Jing, Di Wu 0004, Qing Xia 0007, Yiming Zhang 0011
MSWiM3