VLDB 2026 Research / reviewers in the wild / expert
Lifang Xiao
dblp:244/3321
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Vaccine: Injection vulnerabilities mitigation through dynamic process control with eBPF
Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
Comput. Secur. | 3 |
| 2026 | Globally and locally constrained non-negative Tucker decomposition for enhanced tensor clustering
Lifang Xiao, Dongyan Shang |
Neurocomputing | 1 |
| 2026 | Heterogeneous information disentangling via low-rank splitting non-negative matrix factorization with adaptive graph learning
Lifang Xiao, Wenshu Liang |
Inf. Sci. | 3 |
| 2025 | CASPR: Context-Aware Security Policy Recommendation
Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
NDSS | 1 |
| 2024 | MLCAC: Dynamic Authorization and Intelligent Decision-making towards Insider ThreatsabstractNowadays, the situation of data security is ever-increasing severity, however, the most damaging security threats do not originate from malicious outsiders but from malfeasant and negligent insiders. Generally, insider threats are prone to cause incalculable losses and serious issues due to that the insiders have the authority to access sensitive information. Therefore, how to effectively prevent and respond to insider threats is a significant challenge. Undoubtedly, the key to defending against insider threats is restricting access permissions and optimizing access control policies in real-time. To enhance data security, we propose MLCAC, a multi-layered collaborative access control model, which focuses on protecting sensitive data. A key insight is the design of a decentralized optimization for domain and authority. MLCAC prohibits unauthorized behavior and continuously monitors access logs which are analyzed by using the co-occurrence matrix to make intelligent decisions and dynamically adjust the access control policy in real time. In experiments, we collected 12574 access logs about 1753 system software and analyzed the correlation between software by using the co-occurrence matrix algorithm, including 824 groups co-occurring software of which the highest frequency is 12. The experiments indicate that the accuracy of the policy generated by intelligent decision-making is 89.55%. Therefore, the algorithm is significantly efficient for intelligent decision-making, which is the foundation of automatically generating policies and dynamic authorization. Lifang Xiao, Lixin Zhao, Dan Meng 0002 |
CSCWD | 1 |
| 2024 | SPRT: Automatically Adjusting SELinux Policy for Vulnerability MitigationabstractNowadays, SELinux has been widely applied in Linux systems to enforce security policy and provide flexible MAC. However, improperly configured rules in policies may cause illegal operations and serious security problems to the system. Up till now, it is a challenging task to analyze and modify anomalous rules in policy, since policy rules are massive and semantically complex. In this paper, we propose SPRT, an architecture for adjusting SELinux policy automatically to mitigate vulnerabilities caused by misconfigured policy. Based on the features of security description text of the vulnerabilities in CVE repository, we innovatively propose a criteria for classification of vulnerabilities and adjust SELinux policy according to the classification results, providing a new perspective on the field of policy adjustment. SPRT uses NLP techniques to train the prototype network model to automatically classify vulnerabilities into three categories. Furthermore, SPRT constructs a knowledge base to identify the mapping of policy, vulnerabilities and rules to be modified. It helps modify the rules in policy based on the classification results and audit logs to mitigate the potential impact of vulnerabilities. Our evaluation shows SPRT is effective in vulnerability mitigation, both in terms of fixing misconfigured policies and suppressing attacks generated by vulnerabilities. We collect policies in SELinux that involve the file-label mapping relationship, type transition policy rules and type enforcement policy rules, amounting to around 130,000 rules in all. Additionally, we analyze more than 400 security description texts of vulnerabilities. In our experiments, we compare other three supervised learning models with SPRT and demonstrate that SPRT can automatically classify vulnerabilities with a high accuracy of 92.84%. Additionally, SPRT provides effective policy adjustment to mitigate the damage that 90.47% of vulnerabilities resulting from misconfigured policies cause. Lifang Xiao, Jin Li 0043 |
SACMAT | 3 |
| 2024 | Fast-SegNet: fast semantic segmentation network for small objects
Guoping Xu, Wentao Liao, Lifang Xiao, Jiang Yan, Hanshuo Xing |
Multim. Tools Appl. | 5 |
| 2024 | FGNet: Fixation guidance network for salient object detection
JunBin Yuan, Lifang Xiao, Kanoksak Wattanachote, Qingzhen Xu, Yongyi Gong |
Neural Comput. Appl. | 2 |