VLDB 2026 Research / reviewers in the wild / expert
Kaiwen Shen
dblp:245/2568
· DBLP profile ↗
13ranked-venue papers
2as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 7 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LLMThief: Evaluating Configuration Leaking Risks in Commercial LLM App Stores
Pinji Chen, Jinlong Jiang, Jianjun Chen 0005, Feiran Qin, Hai-Xin Duan, Kaiwen Shen |
SP | 8 |
| 2026 | GASE: Generalized adaptive static enhancement for temporal sentence grounding
Ran Ran 0001, Kaiwen Shen, Jiwei Wei, Ruikun Chai, Shiyuan He, Zeyu Ma 0002, Malu Zhang, Yang Yang 0002 |
Knowl. Based Syst. | 2 |
| 2026 | PROPHET: Efficient and Intelligent Orchestrator for Microservices Scheduling and ScalingabstractMicroservices are popular and widely used in the cloud. However, realizing cost-effective and high-performance microservice orchestration is challenging for Cloud Service Providers (CSPs). Current orchestration mechanisms have limited flexibility and resource efficiency in scheduling and would cause sluggishness in scaling, which brings unnecessary costs to CSP. This paper presents PROPHET, a microservice orchestrator for optimizing service scheduling and scaling. To improve scheduling flexibility and resource utilization, we propose aranking-based p-batch scheduling mechanism, which adopts a pairwise ranker to obtain resource-efficient scheduling plans for large-scale microservice applications rapidly. To advance the scaling agility, we design aproactive prediction-based scaling mechanism, which performs scaling in advance based on resource usage prediction. Our evaluations are conducted on a real-world cluster with the public Alibaba cluster dataset and datasets collected from the cluster. The results indicate that PROPHET can significantly reduce the number of nodes running in the cluster and improve scaling. This shows great potential in achieving cost-effective and high-performance microservice orchestration. Xue Leng, Chengxuan Zhu, Fengming Zhu, Kaiwen Shen, Tiantian Zhu 0001, Yan Chen 0004 |
IEEE Trans. Netw. | 4 |
| 2025 | Poster: An Obfuscation Framework for Mitigating Topology Probing Attacks in Cloud-Native SystemsabstractIn cloud-native systems, microservices communicate with each other through remote calls. This communication side channel contains various information that can be leveraged to carry out topology probing attacks, DDoS attacks, etc. To defend against these attacks, researchers conducted work on critical path analysis and topology obfuscation. However, these works can not be applied to cloud-native scenarios because of limited flexibility and the long calculation time. In this paper, we propose MeshGuard, a novel obfuscation framework for mitigating topology probing attacks in cloud-native systems. Specifically, we construct a service-level dynamic labyrinth to achieve adaptive topology obfuscation. To avoid leaking traffic patterns when obfuscating topology, we disguise obfuscated traffic with tailored parameters. Finally, we design a tag-based obfuscation mechanism to avoid affecting normal microservices. The preliminary results show that MeshGuard can effectively protect the critical path and services with acceptable resource overhead. Xue Leng, Kaiwen Shen, Chengxuan Zhu, Xing Li 0001 |
CCS | 2 |
| 2024 | Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the Wild
Yuejia Liang, Jianjun Chen 0005, Run Guo, Kaiwen Shen, Man Hou, Hai-Xin Duan |
CCS | 4 |
| 2024 | ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing
Linkai Zheng, Xiang Li 0108, Chuhan Wang 0001, Run Guo, Hai-Xin Duan, Jianjun Chen 0005, Chao Zhang 0008, Kaiwen Shen |
NDSS | 8 |
| 2022 | HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP ImplementationsabstractThe Internet has become a complex distributed network with numerous middle-boxes, where an end-to-end HTTP request is often processed by multiple intermediate servers before it reaches its destination. However, a general problem in this distributed network is the semantic gap attack, which is defined as inconsistent semantic interpretations in the processing chain. While some studies have found individual semantic gap attacks, most of them are based on ad-hoc manual analysis, which is inadequate for fundamentally enhancing the security assurance of a system as complex as the HTTP network.In this work, we propose HDiff, a novel semi-automatic detecting framework, systematically exploring semantic gap attacks in HTTP implementations. We designed a documentation analyzer that employs natural language processing techniques to extract rules from specifications, and utilized differential testing to discover semantic gap attacks. We implemented and evaluated it to find three kinds of semantic gap attacks in 10 popular HTTP implementations. In total, HDiff found 14 vulnerabilities and 29 affected server pairs covering all three types of attacks. In particular, HDiff also discovered three new types of attack vectors. We have already duly reported all identified vulnerabilities to the involved HTTP software vendors and obtained 7 new CVEs from well-known HTTP software, including Apache, Tomcat, Weblogic, and Microsoft IIS Server. Kaiwen Shen, Jianyu Lu, Jianjun Chen 0005, Mingming Zhang 0010, Hai-Xin Duan, Jia Zhang 0004 |
DSN | 1 |
| 2022 | Rev: A Video Engine for Object Re-identification at the City ScaleabstractObject re-identification (Re ID) is a key application of city-scale cameras on the edge. It is challenged by the limited accuracy of vision algorithms and the large video volume. We present Rev, a practical ReID engine that builds upon three new techniques. (1) Rev formulates ReID as a spatiotemporal query. Instead of retrieving all the images of a target object, it looks for locations and times in which the target object appeared. (2) Rev makes robust assessment of the target object occurrences by clustering unreliable object features. Each resultant cluster represents the general impression of a distinct object. (3) Rev samples cameras strategically in order to maximize its spatiotemporal coverage at low compute cost. Through an evaluation on 25 hours of videos from 25 cameras, Rev reached a high accuracy of 0.87 (recall at 5) across 70 queries. It runs at 830 × of video realtime in achieving high accuracy. Tiantu Xu, Kaiwen Shen, Humphrey Shi, Felix Xiaozhu Lin |
SEC | 2 |
| 2022 | A Large-scale and Longitudinal Measurement Study of DKIM Deployment
Chuhan Wang 0001, Kaiwen Shen, Minglei Guo, Mingming Zhang 0010, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan |
USENIX Security Symposium | 2 |
| 2021 | Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Chaoyi Lu, Baojun Liu 0002, Shuang Hao 0001, Hai-Xin Duan, Qingfeng Pan, Min Yang 0002 |
USENIX Security Symposium | 1 |
| 2020 | Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksabstractHTTPS is principally designed for secure end-to-end communication, which adds confidentiality and integrity to sensitive data transmission. While several man-in-the-middle attacks (e.g., SSL Stripping) are available to break the secured connections, state-of-the-art security policies (e.g., HSTS) have significantly increased the cost of successful attacks. However, the TLS certificates shared by multiple domains make HTTPS hijacking attacks possible again. Mingming Zhang 0010, Kaiwen Shen, Ziqiao Kong, Chaoyi Lu, Yu Wang 0288, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Min Yang 0002 |
CCS | 3 |
| 2020 | CDN Backfired: Amplification Attacks Based on HTTP Range RequestsabstractContent Delivery Networks (CDNs) aim to improve network performance and protect against web attack traffic for their hosting websites. And the HTTP range request mechanism is majorly designed to reduce unnecessary network transmission. However, we find the specifications failed to consider the security risks introduced when CDNs meet range requests. In this study, we present a novel class of HTTP amplification attack, Range-based Amplification (RangeAmp) Attacks. It allows attackers to massively exhaust not only the outgoing bandwidth of the origin servers deployed behind CDNs but also the bandwidth of CDN surrogate nodes. We examined the RangeAmp attacks on 13 popular CDNs to evaluate the feasibility and real-world impacts. Our experiment results show that all these CDNs are affected by the RangeAmp attacks. We also disclosed all security issues to affected CDN vendors and already received positive feedback from 12 vendors. Kaiwen Shen, Run Guo, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Shuang Hao 0001, Xiarun Chen |
DSN | 2 |
| 2020 | CDN Judo: Breaking the CDN DoS Protection with Itself
Run Guo, Baojun Liu 0002, Shuang Hao 0001, Jia Zhang 0004, Hai-Xin Duan, Kaiwen Shen, Jianjun Chen 0005, Ying Liu 0024 |
NDSS | 7 |