VLDB 2026 Research / reviewers in the wild / expert
Xianbo Wang
dblp:231/6763 · also Xian-Bo Wang
· DBLP profile ↗
24ranked-venue papers
6as first author
21since 2021 · last 2026
0000-0002-0463-2983ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ProtoGenesis: Prototype Training with Zero Local Samples for Heterogeneous Clients in Fully Decentralized Federated SystemsabstractDecentralized federated learning (DFL) enables collaborative training through peer-to-peer (P2P) communication, removing reliance on a central coordinator and thereby improving fault tolerance and scalability. In practical DFL deployments, clients differ substantially in data distributions, computational resources, and network bandwidth. Consequently, enforcing a single model architecture across all clients is often infeasible or inefficient, motivating model-heterogeneous DFL. Prior heterogeneous approaches typically exchange distilled knowledge (e.g., logits, soft labels, or class prototypes) rather than model weights; however, under label-distribution skew they often improve performance primarily on locally observed (seen) classes and generalize poorly to locally missing (unseen) classes. We propose ProtoGenesis, a model-heterogeneous DFL framework that improves clients' recognition of unseen classes by combining (i) a semantic-preserving autoencoder trained on public data to support privacy-oriented sample reconstruction from compact latent embeddings and (ii) prototype-based regularization to stabilize representation learning. Clients proactively request lowdimensional embeddings and prototype statistics for selected classes from neighboring peers, reconstruct class-consistent samples locally, and augment training without exchanging raw data or full model parameters. We evaluate ProtoGenesis on image and text classification tasks using CIFAR-10, CIFAR-100, and DBpedia under heterogeneous model-mixing and non-IID settings. ProtoGenesis achieves comparable accuracy on seen classes while improving accuracy on unseen classes form near 0% to up to 70%. Privacy analysis shows that sensitive information cannot be reconstructed from shared embeddings. Moreover, ProtoGenesis reduces communication overhead by about 1500 × and demonstrates low inference and communication latency on a real-world Jetson-based DFL system. Xianbo Wang, Shan Chang, Minghui Dai, Yunnan Tu, Hongzi Zhu, Bo Li 0001 |
ICDCS | 1 |
| 2026 | Baro2Talk: Reconstructing Spectrograms from Ear Canal Pressure for Voice-free Communication
Luo Zhou, Shan Chang, Han Wang 0032, Xianbo Wang, Hongzi Zhu |
INFOCOM | 4 |
| 2026 | Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau |
SP | 2 |
| 2025 | PRISAM: Efficient Personalization via BN Masks in Heterogeneous Decentralized Federated LearningabstractDecentralized Federated Learning (DFL) removes the central server in traditional Centralized FL, eliminating performance and security bottlenecks while improving scalability for large-scale cross-device federated scenarios. In these scenarios, devices are heterogeneous in computation, storage, and data distribution, requiring personalized models. A common strategy for personalized DFL is for each device to collaborate with others having similar data distributions to train a federated model and then perform local pruning. However, in the absence of a central server, along with privacy concerns and the limited inference capabilities of low-end devices, challenges emerge in terms of communication, computation, and model convergence. This paper presents an efficient personalized DFL method, named PRISAM, based on BN (Batch Normalization) masks. Each device adaptively adjusts its BN mask, enabling effective structured pruning with minimal performance loss. By exchanging BN masks, communication overhead for similarity comparison is reduced by a factor of 100,000, comparing to exchanging an entire model, while computational costs are also significantly lowered. Extensive experiments show that PRISAM significantly improves personalized model performance on three datasets across two models, outperforming state-of-the-art methods, while greatly reducing computational and communication overhead. Shan Chang, Xianbo Wang, Denghui Li, Guanghao Liang, Hongzi Zhu, Bo Li 0001 |
ICDCS | 2 |
| 2025 | Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau, Julien Lecomte |
USENIX Security Symposium | 2 |
| 2025 | Review of intelligent fault diagnosis for rotating machinery under imperfect data conditions
Hao Chen 0099, Jiaming Li 0019, Xianbo Wang, Lianqing Yu, Zhi-Xin Yang 0001 |
Expert Syst. Appl. | 3 |
| 2025 | Physical-Knowledge-Guided and Interpretable Deep Neural Networks for Gear Fault Severity Level DiagnosisabstractWhile deep-learning (DL) models have achieved significant achievements in fault diagnosis, their inherent opacity for human users often hinders practical applications in risk-sensitive scenarios. Fortunately, the advent of class activation mapping (CAM) significantly enhanced the transparency of DL models by illuminating the specific input areas that contribute more to the classification results. Nevertheless, CAM fails to enhance diagnostic accuracy and actively leverage interpretability due to its passively explanatory property for the trained models. To address this issue, in this article, a physically meaningful regularization (PMR) term is proposed by using gradient-weighted CAM, to guide the models in focusing on the same frequency bands of the input spectra and ignoring other parts of noisy and irrelevant signals. Based on the PMR term, a two-step back propagation training algorithm is accordingly designed to train the diagnostic models embedded with physical knowledge. Consequently, the obtained physical-knowledge-guided and interpretable DL models can offer not only strong interpretability but also a higher diagnostic accuracy for the noised test samples. Finally, the proposed diagnostic method is validated in two datasets containing multiple fault severity levels. The diagnostic results, along with the saliency analysis, substantiate the efficacy of the proposed method. Jiaming Li 0019, Xianbo Wang, Hao Chen 0099, Zhi-Xin Yang 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Living a Lie: Security Analysis of Facial Liveness Detection Systems in Mobile Apps
Xianbo Wang, Kaixuan Luo, Wing Cheong Lau |
ACNS (3) | 1 |
| 2024 | SWIDE: A Semantic-aware Detection Engine for Successful Web Injection AttacksabstractWeb attacks, a primary vector for system breaches, pose a significant challenge within the cybersecurity landscape. The growing intensity of web attack attempts has led to "alert fatigue" where enterprises are inundated by excessive alerts. Although extensive research is being conducted on automated methods for detecting web attacks, it remains an open problem to identify whether the attacks are successful. Towards this end, we present SWIDE (Successful Web Injection Detection Engine), an engine to pinpoint successful web injection attacks (e.g., PHP command injection, SQL injection). This enables enterprises to focus exclusively on those crucial threats. Our methodology builds on two insights: Firstly, while attackers tend to apply payload obfuscation techniques to evade detection, all successful web injection attacks must comply with the programming language syntax to be executable; Secondly, these attacks inevitably produce observable effects, such as returning execution result or creating backdoors for future access by the attacker. Consequently, we leverage advanced syntactic and semantic analysis to 1) detect malicious syntax features in obfuscated payloads and 2) perform semantic analysis of the payload to recover the intention of the attack. With a two-stage design, namely, attack identification and confirmation mechanisms, SWIDE can accurately identify successful attacks, even amidst intricate obfuscations. Unlike proof-of-concept studies, SWIDE has been deployed and validated in real-world environments through collaborations with a cybersecurity firm. Serving 5,045 enterprise users, our system identifies that roughly 15% of enterprises have suffered from successful attacks on a weekly basis - an alarmingly high rate. Moreover, we perform a detailed analysis of six months' data and discover 60 zero-day vulnerabilities exploited in the wild, including 12 high-risk ones acknowledged by relevant authorities. These findings underscore the practical effectiveness of SWIDE. Ronghai Yang, Xianbo Wang, Kaixuan Luo, Jiayuan Xin, Wing Cheong Lau |
CCS | 2 |
| 2024 | Health assessment of wind turbine gearbox via parallel ensemble and fuzzy derivation collaboration approach
Weixiong Jiang, Jun Wu 0012, Chengjie Wang 0013, Haiping Zhu 0001, Xianbo Wang |
Adv. Eng. Informatics | 5 |
| 2024 | Privacy-preserving intelligent fault diagnostics for wind turbine clusters using federated stacked capsule autoencoder
Hao Chen 0099, Xianbo Wang, Zhi-Xin Yang 0001, Jiaming Li 0019 |
Expert Syst. Appl. | 2 |
| 2024 | Dynamic Focusing Network for Semisupervised Mechanical Fault Diagnosis of Rotating MachineryabstractThe key components of the rotating machinery, such as gears and bearings, are prone to damage owing to long-term complex and harsh working situations. This study investigates the weight distribution of neural networks, and finds that the response of the network to the input is uneven, indicating that data-driven models tend to learn more information from certain local parts of the input. Based on this discovery, a novel attention mechanism, namely dynamic focusing, is proposed. The dynamic focusing mechanism highlights local information with important features to extract the discriminative features of key frequency bands. In addition, insufficient labeled data presents challenges for fault diagnosis in the practical. A semisupervised learning method based on mutual information is proposed to solve this problem. The effectiveness of the proposed method is verified by the Case Western Reserve University public dataset as well as the Gearbox Dynamic Simulator dataset obtained in our laboratory. The experimental results show that the proposed method has considerable advantages compared to existing deep learning methods, with test accuracy ranging from 95.31% to 100%. Hao Chen 0099, Xianbo Wang, Jiaming Li 0019, Zhi-Xin Yang 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Wind Turbine Fault Diagnosis for Class-Imbalance and Small-Size Data Based on Stacked Capsule AutoencoderabstractWind power is of strategic importance for reducing carbon dioxide emissions, minimizing environmental pollution, and enhancing the sustainability of energy supply. Health monitoring of wind turbines is a crucial technology to ensure the quality of grid-connected power. Insufficient labeled data and class imbalance problems are two critical issues for intelligent fault diagnosis of wind turbines. In this article, an intelligent fault diagnosis method based on stacked capsule autoencoders is proposed to address the issues of inadequate labeled data and class imbalance. A prior knowledge-based convolution layer is applied to optimize the initialization of capsules, making it more conducive to learning spectral information. The pose representations of parts and objects can be improved, and a method for embedding spectral templates is proposed. The stacked capsule autoencoder in this study can learn partial templates unsupervised through likelihood estimation and establish the mapping between capsules and fault types. The experimental results, obtained from the CWRU dataset and a private dataset from a wind turbine drive-train simulation platform, demonstrate that the proposed method is robust to imbalanced and small-sized datasets. It can perform stable and effective unsupervised training by utilizing a sufficient amount of normal class data to expedite learning convergence. Xianbo Wang, Hao Chen 0099, Jing Zhao 0010, Chonghui Song, Zhi-Xin Yang 0001, Pak-Kin Wong 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | GKE-TUNet: Geometry-Knowledge Embedded TransUNet Model for Retinal Vessel Segmentation Considering Anatomical TopologyabstractAutomated retinal vessel segmentation is crucial for computer-aided clinical diagnosis and retinopathy screening. However, deep learning faces challenges in extracting complex intertwined structures and subtle small vessels from densely vascularized regions. To address these issues, we propose a novel segmentation model, called Geometry-Knowledge Embedded TransUNet (GKE-TUNet), which incorporates explicit embedding of topological features of retinal vessel anatomy. In the proposed GKE-TUNet model, a skeleton extraction network is pre-trained to extract the anatomical topology of retinal vessels from refined segmentation labels. During vessel segmentation, the dense skeleton graph is sampled as a graph of key-points and connections and is incorporated into the skip connection layer of TransUNet. The graph vertices are used as node features and correspond to positions in the low-level feature maps. The graph attention network (GAT) is used as the graph convolution backbone network to capture the shape semantics of vessels and the interaction of key locations along the topological direction. Finally, the node features obtained by graph convolution are read out as a sparse feature map based on their corresponding spatial coordinates. To address the problem of sparse feature maps, we employ convolution operators to fuse sparse feature maps with low-level dense feature maps. This fusion is weighted and connected to deep feature maps. Experimental results on the DRIVE, CHASE-DB1, and STARE datasets demonstrate the competitiveness of our proposed method compared to existing ones. Yunlong Qiu, Chonghui Song, Xianbo Wang |
IEEE J. Biomed. Health Informatics | 6 |
| 2022 | PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on Android
Xianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong Lau |
NDSS | 1 |
| 2022 | Health Condition Assessment for Pumped Storage Units Using Multihead Self-Attentive Mechanism and Improved Radar ChartabstractA novel health assessment method for pumped storage units (PSUs) is presented in this article. First, multihead self-attentive mechanism (MSM) combined with quantile regression neural network (QRNN) are proposed to establish a health benchmark model for PSUs to reveal the intricate relationship between the vibration and its multiple influencing factors. Especially, MSM automatically learns the complex interaction features among multiple influencing factors, while QRNN explores the upper bounds of health vibration under specific operational parameters. Then, a fuzzy dimensionless function is constructed to map the deviation of the currently measured vibration from the predicted health vibration to the performance degradation indexes. Finally, an improved radar chart method is proposed to visually illustrate the health condition of multiple measurement locations and give comprehensive health assessment for PSUs. The proposed method is applied in a PSU in Zhejiang province of China. The results of comparative experiments illustrate its effectiveness and feasibility. Yajun Jiang, Xianbo Wang, Chaoshun Li |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Distributed Adaptive Consensus Protocol for Connected Vehicle Platoon With Heterogeneous Time-Varying Delays and Switching TopologiesabstractThis paper studies the distributed consensus protocol for the connected vehicle platoon with heterogeneous time-varying delays and switching topologies. A third-order dynamics model with powertrain inertial lag is proposed to characterize the node longitudinal dynamics of vehicles in platoon. A novel distributed adaptive consensus protocol considering the time-varying delays and the random switched inter-vehicular communication topologies is designed to stabilize the heterogeneous vehicle platoon in the presence of external disturbance. The delay-range-dependent approach is used to deal with the system heterogeneous time-varying delays by considering the characteristics of the heterogeneous platoon. Directed graphs are adopted to describe the accessible information flow among vehicles. The necessary and sufficient conditions for the unified closed-loop vehicle platoon system are derived by using matrix analysis and Lyapunov-Krasovskii approach. Numerical simulations demonstrate the proposed method is effective. Guokuan Yu, Pak-Kin Wong 0001, Jing Zhao 0010, Xianbo Wang, Zhi-Xin Yang 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2021 | Breaking and Fixing Third-Party Payment Service for Mobile Apps
Shangcheng Shi, Xianbo Wang, Wing Cheong Lau |
ACNS (2) | 2 |
| 2021 | An Empirical Study on Mobile Payment Credential Leaks and Their Exploits
Shangcheng Shi, Xianbo Wang, Kyle Zeng, Ronghai Yang, Wing Cheong Lau |
SecureComm (2) | 2 |
| 2021 | Scalable Detection of Promotional Website Defacements in Black Hat SEO Campaigns
Ronghai Yang, Xianbo Wang, Siming Pang, Wing Cheong Lau |
USENIX Security Symposium | 2 |
| 2021 | Automatic representation and detection of fault bearings in in-wheel motors under variable load conditions
Xianbo Wang, Luqing Luo, Lulu Tang, Zhi-Xin Yang 0001 |
Adv. Eng. Informatics | 1 |
| 2020 | Ensemble extreme learning machines for compound-fault diagnosis of rotating machinery
Xianbo Wang, Jun Wu 0012 |
Knowl. Based Syst. | 1 |
| 2019 | MoSSOT: An Automated Blackbox Tester for Single Sign-On Vulnerabilities in Mobile ApplicationsabstractMobile applications today increasingly integrate Single Sign-On (SSO) into their account management mechanisms. Unfortunately, the involved multi-party protocol, i.e., OAuth 2.0, was originally designed to serve websites for authorization purpose. Due to the complexity of the adapted protocol, a large number of insecure SSO implementations still exist in the wild. Although the security testing for real-world SSO deployments has attracted considerable attention in recent years, existing work either focuses on websites or relies on the manual discovery of specific and previously-known vulnerabilities. In the paper, we design and implement MoSSOT (Mobile SSO Tester), an automated blackbox security testing tool for Android applications utilizing the SSO services from three mainstream service providers. The tool detects the vulnerabilities within the practical SSO implementations by fuzzing related network messages. We used MoSSOT to examine over 500 first-tier third-party Android applications from US and Chinese app markets. According to the test result, around 72% of the tested applications incorrectly implement SSO and are thus vulnerable. Besides, our test identifies an unknown vulnerability as well as a new variant, in addition to four known ones. The vulnerabilities enable the attacker to illegally log into the mobile applications as the victims or gain access to the protected resources. MoSSOT has been released as an open-source project. Shangcheng Shi, Xianbo Wang, Wing Cheong Lau |
AsiaCCS | 2 |
| 2018 | Single and Simultaneous Fault Diagnosis With Application to a Multistage Gearbox: A Versatile Dual-ELM Network ApproachabstractHigh-precision fault diagnosis is vital for widely used multistage gearbox systems. Intelligent monitoring is difficult due to the fuzzy boundaries and a variety of unseen single or simultaneous faults of such complex machinery. To solve this problem, local mean decomposition is applied to extract features effectively from the original nonstationary and nonlinear vibration signals. By exploiting the diverse functionalities of extreme learning machines (ELM) in both regression and classification, a novel dual-ELM network is proposed, in which one ELM is employed to count the number of faults and the other is used to identify the specific single- or simultaneous-fault scenarios. The proposed dual-ELM-based multilabel classifier does not rely on an empirically specified threshold. Thus, it is more self-adaptive than the existing probabilistic-based classifiers. In addition, by inheriting the advantages of the original ELM, the dual-ELMs do not require iterative fine-tuning of parameters. Finally, the training speed of the dual-ELMs is much faster than other combinations of the existing classifiers. Experimental results under various loading conditions show that the proposed dual-ELM-based fault diagnostic framework is versatile at detecting single and simultaneous faults accurately and quickly. Zhi-Xin Yang 0001, Xianbo Wang, Pak-Kin Wong 0001 |
IEEE Trans. Ind. Informatics | 2 |