VLDB 2026 Research / reviewers in the wild / expert
Deliang Chang
dblp:238/0160
· DBLP profile ↗
8ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0003-0552-9352ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the Wild
Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan, Deliang Chang, Yishen Li, Shujun Tang |
NDSS | 5 |
| 2025 | Decoding DNS Centralization: Measuring and Identifying NS Domains Across Hosting ProvidersabstractThe Domain Name System (DNS) is designed to be distributed, which aims to provide services with low latency and great reliability. However, after decades of development and changes in Internet business models, various aspects of the DNS ecosystem have begun to show signs of centralization. To investigate the centralization from the viewpoint of hosting service providers, we develop an automated method based on similarity among NS domains and co-hosting relationship to identify the hosting providers for authoritative name servers, so that we can identify hosting providers in DNS zone file to count the number of domains which a hosting provider host. This tool demonstrates greater accuracy than previous methods and our testing demonstrates the ability to identify hosting service providers for most domains in real-world measurement tasks. Using this tool, we conducted measurements on the dataset combined with .com, .net and .org TLD zones. We find that the top 10 providers collectively host over 54.19% of domains while top 100 providers host over 82.99% domains, which shows a significant level of centralization in hosting service providers within the DNS. Through an analysis of NSone’s NS domains and a statistical examination of top providers’ NS domains, we find that directly identifying the base domain as the provider is inappropriate. Furthermore, we discover relationships among hosting providers and between hosting providers and infrastructure that are more complex than previously anticipated. Finally, based on our research findings, we offer corresponding suggestions to mitigate the continued development of centralization. Qihang Peng, Mingming Zhang 0010, Deliang Chang, Jia Zhang 0004, Baojun Liu 0002, Hai-Xin Duan |
DSN | 3 |
| 2025 | Poster: A First Look at Large Language Model Applications in the Wild from Dual PerspectivesabstractLarge language models (LLMs) have become the foundational technology for numerous applications. Various self-hosted LLM-related applications are deployed on the Internet for purposes such as intelligent assistants. However, their Internet exposure can introduce new security risks. To address this issue, this study conducts a large-scale, long-term measurement of LLM application exposure in the wild through active probing. Numerous publicly accessible instances of various LLM applications, such as Ollama, are deployed without authentication, posing risks of unauthorized access or data leakage. Meanwhile, this paper deploys a series of honeypots that mimic LLM applications to uncover the behaviors and strategies of scanners targeting online LLM applications. Deliang Chang, Xuedong Wu, Xiang Li 0108, Zhengpeng Yang 0001, Asiya, Shujun Tang |
IMC | 1 |
| 2025 | Poster: RMap: Uncovering Risky DNS Resolution Chains and MisconfigurationsabstractIn recent years, large-scale network outages caused by DNS misconfigurations have become increasingly common. The intricate inter-domain dependencies, along with emerging mechanisms (Such as DNSSEC, EDNS, and 0x20), have made DNS resolution increasingly complex and fault localization more challenging. We present RMap, a tool that rapidly probes all potential resolution chains of a domain, reveals its resolution dependency topology, and detects security risks. We experimentally demonstrate the effectiveness of RMap and its broad applicability. Our findings reveal that domain configurations in real-world environments remain concerning, with potential issues observed even in several well-known top-level domains. RMap is avaliable in https://github.com/ahlien/rmap. Fasheng Miao, Shuying Zhuang, Xiang Li 0108, Changqing An, Deliang Chang, Baojun Liu 0002, Jia Zhang 0004, Jilong Wang 0001 |
IMC | 5 |
| 2025 | BLMProbe: Enhancing Internet-Connected Device Discovery by Automated Device Labeling and Label Migrationabstract10.1109/TIFS.2025.3587211 Zhenhao Tian, Yi He 0020, Nuo Zhang, Qixiao Lin, Hetian Shi, Jianwei Zhuge, Deliang Chang |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsabstractDNS can be compared to a game of chess in that its rules are simple, yet the possibilities it presents are endless. While the fundamental rules of DNS are straightforward, DNS implementations can be extremely complex. In this study, we intend to explore the complexities and vulnerabilities in DNS response pre-processing by systematically analyzing DNS RFCs and DNS software implementations. We present the discovery of three new types of logic vulnerabilities, leading to the proposal of three novel attacks, namely the TuDoor attack. These attacks involve the use of malformed DNS response packets to carry out DNS cache poisoning, denial- of-service, and resource consuming attacks. By performing comprehensive experiments, we demonstrate the attack’s feasibility and significant real-world impacts of TUDOOR. In total, 24 mainstream DNS software, including BIND, PowerDNS, and Microsoft DNS, are affected by TuDoor. Attackers can instigate cache poisoning and denial-of-service attacks against vulnerable resolvers using a handful of crafted packets within 1 second or circumvent the query limit to deplete resolution resources (e.g., CPU). Besides, to determine the vulnerable resolver population in the wild, we collect and evaluate 16 popular Wi-Fi routers, 6 prevalent router OSes, 42 public DNS services, and around 1.8M open DNS resolvers. Our measurement results indicate that TUDOOR could exploit 7 routers (OSes), 18 public DNS services, and 424,652 (23.1%) open DNS resolvers. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors, and 18 of them, including BIND, Chrome, Cloudflare, and Microsoft, have acknowledged our findings and discussed mitigation solutions with us. Furthermore, 33 CVE IDs are assigned to our discovered vulnerabilities, and we provide an online detection tool as one of the mitigation measures. Our research highlights the urgent need for standardization of DNS response pre-processing logic to enhance the security of DNS. Xiang Li 0108, Wei Xu 0064, Baojun Liu 0002, Mingming Zhang 0010, Zhou Li 0001, Jia Zhang 0004, Deliang Chang, Chuhan Wang 0001, Jianjun Chen 0005, Hai-Xin Duan, Qi Li 0002 |
SP | 7 |
| 2022 | Hide and Seek: Revisiting DNS-based User TrackingabstractDomain name system (DNS) is the address book of the Internet and domain names are queried before almost every network activity. Since the entities like recursive resolvers can monitor users' DNS queries, privacy concerns such as user tracking arise. Though a number of prior works have looked into this issue, they all focus on the closed-world setting, which means that victim users must be known to the adversary. We argue that it does not reflect the adversary's true capabilities. Moreover, there lacks an effective approach to defend against DNS-based user tracking. In this work, we revisit these issues by investigating the attack surface in both open-world and closed-world settings and studying how to protect users. First, we introduce a new tracking mechanism DSCorr which incorporates domain-based word embedding to capture the fine-grained distance between domain names, and automatic threshold generation for fine-tuning the attack outcome. The evaluation result on a real-world DNS dataset shows DSCorr is able to outperform the existing works by a large margin especially in the open-world setting. On the defense side, we develop a system called LDPResolve, which incorporates a recently proposed differential privacy notion ULDP (Utility-optimized Local Differential Privacy) and a new technique named parallel domain resolving, to provide privacy guarantees without damaging the utility of legitimate applications. The evaluation result on the same dataset shows the DNS-based user tracking can be effectively curbed, e.g., tracking accuracy degraded from 93% to 10.1%. Deliang Chang, Joann Qiongna Chen, Zhou Li 0001, Xing Li 0001 |
EuroS&P | 1 |
| 2019 | On the classification and false alarm of invalid prefixes in RPKI based BGP route origin validation
Deliang Chang, Xing Li 0001 |
IM | 2 |