VLDB 2026 Research / reviewers in the wild / expert
Shaocong Feng
dblp:242/7243
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0009-0007-6503-944XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DeRed: Enhancing third-party library detection in binaries via deceptive reuse mitigation
Shengjia Chang, Shouguo Yang, Baojiang Cui, Shaocong Feng |
Comput. Secur. | 8 |
| 2026 | Adaptive Target Device Model Identification Attack in 5G Mobile NetworkabstractEnhanced system capacity is one of 5G goals. This will lead to massive heterogeneous devices in mobile networks. Mobile devices that lack basic security capability have chipset, operating system or software vulnerability. Attackers can perform Advanced Persistent Threat (APT) Attack for specific device models. In this paper, we propose an Adaptive Target Device Model Identification Attack (ATDMIA) that provides the prior knowledge for exploiting baseband vulnerability to perform targeted attacks. We discovered Globally Unique Temporary Identity (GUTI) Reuse in Evolved Packet Switching Fallback (EPSFB) and Leakage of User Equipment (UE) Capability vulnerability. Utilizing silent calls, an attacker can capture and correlate the signaling traces of the target subscriber from air interface within a specific geographic area. In addition, we design an adaptive identification algorithm which utilizes both invisible and explicit features of UE capability information to efficiently identify device models. We conducted an empirical study using 105 commercial devices, including network configuration, attack efficiency, time overhead and open-world evaluation experiments. The experimental results showed that ATDMIA can accurately correlate the EPSFB signaling traces of target victim and effectively identify the device model or manufacturer. Shaocong Feng, Baojiang Cui, Junsong Fu 0001, Meiyi Jiang, Shengjia Chang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | BinFuse: Binary Code Similarity Detection via Lightweight Fused Semantic EmbeddingabstractBinary code similarity detection (BCSD) is critical for ensuring software security and reliability; however, current approaches often fall short in capturing comprehensive program semantics. Existing methods typically rely on isolated code or structural embeddings; others apply naive strategies to combine these embeddings, which limits their effectiveness—particularly in complex scenarios such as cross-architecture and cross-optimization binary comparisons. To address these limitations, we propose BinFuse, a lightweight framework designed for high-performance BCSD through the efficient fusion of code and structural semantics. BinFuse introduces a novel Markov matrix construction for fine-grained code feature extraction and employs an enhanced concrete autoencoder (CAE) for optimal feature selection. These extracted features are then assigned as node attributes to construct a fused semantic control flow graph (FSCFG), which is then jointly modeled by a Siamese network to enable accurate and efficient code similarity detection. Experimental results show that BinFuse achieves an impressive accuracy of 96.3% in complex scenarios, significantly outperforming established baselines such as Asm2Vec and Gemini in multiple evaluation metrics. Notably, BinFuse achieves accuracy comparable to the state-of-the-art IoTSim while reducing the detection time by 15%. The favorable balance between accuracy and efficiency achieved by BinFuse underscores its potential as a practical and scalable solution for BCSD in complex scenarios, thereby contributing to the development of more secure and trustworthy software systems. Shengjia Chang, Baojiang Cui, Shaocong Feng |
TrustCom | 3 |
| 2025 | NGAP Feature Fusion Hybrid Network Attack Detection for 5G Edge SecurityabstractThe fifth-generation (5G) mobile network is a critical infrastructure for cellular communication, requiring the confidentiality, integrity and availability of services. However, the inherent vulnerabilities of Radio Access Network (RAN) allow the attacker to exploit vulnerabilities in 3GPP specifications or implementation to compromise user privacy and disrupt services. Existing defense methods are limited by the reliance on manual analysis and rule-based detection, which fails to detect novel and evolving threats. We propose NGAPAD, the first system designed to automatically monitor and analyze 5G edge attack based on Next Generation Application Protocol (NGAP). NGAPAD provides a feasible solution to overcome challenges of threat pattern universality, protocol specificity and data efficiency in 5G edge security. We design a new NGAP telemetry format and a dual-branch hybrid network to achieve precise and efficient attack detection. We constructed a high-quality dataset and evaluated it experimentally on 5G simulation network. NGAPAD achieved the optimal performance metrics by sequence length tuning, achieving 99.31% F1 Score with the length of 12. The system successfully detected 18 out of 22 known edge attacks and achieved 98.3% Accuracy against unknown attacks generated by fuzzing of NGAP protocol. Shaocong Feng, Baojiang Cui, Shengjia Chang, Yuqi Huo |
IEEE Internet Things J. | 1 |