VLDB 2026 Research / reviewers in the wild / expert
Yebo Feng
dblp:247/4848
· DBLP profile ↗
42ranked-venue papers
7as first author
40since 2021 · last 2026
0000-0002-7235-2377ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 5 first-author · 17 since 2021Computer networks · 11 · 2 first-author · 10 since 2021Software engineering, systems software and programming languages · 8 · 8 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowledge Graph-Augmented Reasoning for Robust Multi-modal Document Attack Detection
Teng Li 0003, Shengkai Zhang, Yebo Feng, Zhuo Ma 0001, Jianfeng Ma 0001 |
ACISP (2) | 4 |
| 2026 | Resisting Manipulative Bots in Meme Coin Copy Trading: A Multi-Agent Approach with Chain-of-Thought ReasoningabstractCopy trading has become the dominant entry strategy in meme coin markets. However, due to the market's extremely illiquid and volatile nature, the strategy exposes an exploitable attack surface: adversaries deploy manipulative bots to front-run trades, conceal positions, and fabricate sentiment, systematically extracting value from naïve copiers at scale. Despite its prevalence, bot-driven manipulation remains largely unexplored, and no robust defensive framework exists. We propose a manipulation-resistant copy-trading system based on a multi-agent architecture powered by a multi-modal large language model (LLM) and chain-of-thought (CoT) reasoning. Our approach outperforms zero-shot and most statistic-driven baselines in prediction accuracy as well as all baselines in economic performance, achieving an average copier return of 3% per meme coin investment under realistic market frictions. Overall, our results demonstrate the effectiveness of agent-based defenses and predictability of trader profitability in adversarial meme coin markets, providing a practical foundation for robust copy trading. Yebo Feng, Jiahua Xu 0002, Yang Liu 0003 |
WWW | 2 |
| 2026 | Fake news detection with GAN-augmented contrastive learning and multimodal attentionabstractAbstract The rapid proliferation of fake news in digital media has emerged as a major threat to information credibility and public trust. Although recent advances have explored multimodal learning for fake news detection, existing models often fail to effectively integrate heterogeneous data sources and remain vulnerable to adversarial manipulations. To address these challenges, we propose (Multimodal Adversarial Deep Semantic Learning), a robust multimodal fake news detection framework that unifies generative adversarial networks (GANs) with supervised contrastive learning. Specifically, employs a multi-layer joint attention mechanism to align and fuse textual and visual features, while adversarial training encourages the extraction of event-invariant representations, enhancing generalizability across unseen news events. Additionally, contrastive learning with adversarial perturbations further strengthens feature discrimination and robustness against attacks. Extensive experiments on benchmark Twitter and Weibo datasets demonstrate that achieves state-of-the-art accuracy (85.3%) and maintains stable performance with only a 1.1% drop under adversarial conditions, outperforming existing methods in both detection accuracy and resilience. These results underscore ’s effectiveness in advancing robust multimodal fake news detection and promoting digital information integrity. Cong Wu 0003, Jing Chen 0003, Yebo Feng, Ju Jia, Zijian Zhang 0001, Jiahua Xu 0002, Teng Li 0003, Yang Liu 0003 |
Cybersecur. | 3 |
| 2026 | CANDICE: An explainable and intelligent framework for network intrusion detection
Ruiying Du, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Yebo Feng |
Future Gener. Comput. Syst. | 6 |
| 2026 | AdaptiveShield: Dynamic Defense Against Decentralized Federated Learning Poisoning AttacksabstractFederated learning allows decentralized devices to collaboratively train a shared model while keeping data local, enhancing the privacy and security of the training process. However, it is vulnerable to poisoning attacks, where malicious participants inject false data to corrupt the global model. To address this, we propose AdaptiveShield, a dynamic hybrid defense approach designed to protect decentralized federated learning against such attacks. AdaptiveShield employs dynamic detection strategies that consider multiple risk factors to assess the maliciousness index and dynamically adjust the detection thresholds, which is able to adapt to various attack scenarios. In addition to attack detections, AdaptiveShield minimizes the negative impact on the global model from missed attackers by dynamically adjusting hyperparameters, thereby enhancing the robustness of the defense. It also dissociates user identities from their uploaded local models through a hierarchical shuffle mechanism, providing an extra layer of privacy protection for both the users and their local models. We evaluate AdaptiveShield across various experimental environments, attack settings, and datasets, demonstrating that it outperforms state-of-the-art approaches by achieving over 0.1 improvement in training accuracy while incurring negligible time overhead. Yebo Feng, Baichuan Zheng, Teng Li 0003, Cong Wu 0003, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Unveiling Ethereum Mixing Services Using Enhanced Graph Structure LearningabstractAs cryptocurrency prices continue to recover, crypto crimes such as money laundering are becoming increasingly rampant. Mixing services such as Tornado Cash have become the primary tools for obfuscating illegal financial transactions due to their inherent anonymity mechanisms. Tornado Cash is a non-custodial, smart contract-based mixing service (SC-CMS) that breaks the direct mapping between deposit and withdrawal accounts, hindering regulators from tracking illicit fund flows. Existing deanonymization methods for Tornado Cash suffer from several challenges, including vague theoretical concepts, evolving mixing mechanisms, and insufficient labeled samples. To address these concerns, this paper proposes the first formal concept of SC-CMS to facilitate and evaluate the deanonymization efforts systematically. We design a novel linkability attack, LASC, based on enhanced graph structure learning, to associate mixing accounts on Tornado Cash and mathematically prove its feasibility. Comprehensive experiments on real Ethereum transactions demonstrate that LASC outperforms state-of-the-art works in both performance and efficiency. Yan Wu 0014, Cong Wu 0003, Yebo Feng, Jiahang Sun, Zijian Zhang 0001, Jincheng An, Zhitao Guan, Liehuang Zhu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | MagLive: Robust Voice Liveness Detection on Smartphones Using Magnetic Pattern ChangesabstractVoice authentication has been widely used on smartphones. However, it remains vulnerable to spoofing attacks, where the attacker replays recorded voice samples from authentic humans using loudspeakers to bypass the voice authentication system. In this paper, we present MagLive, a robust voice liveness detection scheme designed for smartphones to mitigate such spoofing attacks. MagLive leverages the differences in magnetic pattern changes generated by different speakers (i.e., humans or loudspeakers) when speaking for liveness detection, which are captured by the built-in magnetometer on smartphones. To extract effective and robust magnetic features, MagLive utilizes a TF-CNN-SAF model as the feature extractor, which includes a time-frequency convolutional neural network (TF-CNN) combined with a self-attention-based fusion (SAF) model. Supervised contrastive learning is then employed to achieve user-irrelevance, device-irrelevance, and content-irrelevance. MagLive imposes no additional burden on users and does not rely on active sensing or specialized hardware. We conducted comprehensive experiments with various settings to evaluate the security and robustness of MagLive. Our results demonstrate that MagLive effectively distinguishes between humans and attackers (i.e., loudspeakers), achieving an average balanced accuracy (BAC) of 99.01% and an equal error rate (EER) of 0.77%. Xiping Sun, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Haozhe Xu, Yebo Feng, Ruiying Du, Xianhao Chen |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | AeroGuard: Towards Real-Time UAV Fault Detection With Hybrid ModelsabstractUnmanned Aerial Vehicles (UAVs) are increasingly deployed in safety-critical applications, yet their operations in complex environments make them vulnerable to diverse faults. This paper presents AeroGuard, a lightweight hybrid frame work for real-time UAV fault detection. AeroGuard combines Long Short-Term Memory (LSTM) and AutoRegressive with eXogenous input (ARX) models, with residual-driven adaptive weighting to balance their strengths. Faults are identified through Z-score and Sequential Probability Ratio Test (SPRT) applied to prediction residuals, ensuring accurate and timely detection. Extensive experiments on public datasets, real UAV flight logs, and outdoor flights confirm AeroGuard's robustness, particularly in detecting drift and bias faults where existing methods degrade. AeroGuard achieves up to 95.8% precision, representing about 10% improvement over prior work, while maintaining sub-5ms latency on Raspberry Pi 4B with modest resource usage, and sub second detection on Pi Zero for low-speed UAVs. We also discuss current limitations, noting that evaluation on hardware-induced faults (e.g., motor seizure) will be pursued in future work. Teng Li 0003, Zhili Wei, Yebo Feng, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001, Yang Liu 0003 |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Decentralized and Adaptive Internet of Vehicles: A Blockchain-Based ApproachabstractThe Internet of Vehicles (IoV) enhances road safety and supports autonomous driving through real-time communication, but current methods face key challenges: rigid resource allocation due to static architectures, communication failures in low-signal areas from infrastructure reliance, and passive defense mechanisms struggle to counter coordinated attacks, while high-latency encryption algorithms further compromise framework real-time performance. To address this, we propose a blockchain-based dynamically adaptive restructuring framework. It enables real-time IoV cluster restructuring by splitting overloaded IoVs to reduce communication overhead, or merging nearby IoVs to optimize resource utilization. In infrastructure-sparse zones, vehicles establish temporary multi-hop communication links based on relative mobility to ensure continuous connectivity. A multi-layered security mechanism integrates physical validation, event verification, and majority voting, achieving over 95% resistance to data tampering. Compared to Raft, PoS, and PBFT, our framework improves consensus speed by 27.06%–38.56%, and reduces transaction latency by 7%–35%, 15%–54%, and 27%–66%, respectively. It also maintains high robustness under dense traffic, high mobility, and weak signals, offering a proactive, adaptive security paradigm for intelligent transportation frameworks. Yebo Feng, Konglin Zhu, Tingda Shen, Lin Zhang 0013 |
ACM Trans. Internet Techn. | 2 |
| 2026 | EquiLink Bridge: A Semi-Custodial Approach to Cross-Chain Transactions via TEEabstractThe rising demand for blockchain interoperability is accelerating advancements in cross-chain bridge technologies, which are crucial for a seamless information transfer in multi-blockchain ecosystems. Existing blockchain bridges are typically classified into two categories: custodial and non-custodial. Custodial bridges use a trusted third party for easier and faster transactions but depend on custodian trust, while non-custodial bridges enhance transparency and control with smart contracts but increased complexity and latency. Currently, no bridge design successfully combines the benefits of both while avoiding their drawbacks. This paper presents EquiLink, a semi-custodial bridge that combines the benefits of both custodial and non-custodial methods. EquiLink employs a smart contract, known as the EquiLink Service, to initiate cross-chain transfers. It then uses the EquiLink Network, a system composed of remote-attested Trusted Execution Environments (TEEs), to verify and issue these transfers between two blockchains. Any eligible participants validated through remote attestation can join the EquiLink Network and contribute to the bridge’s functionality. Additionally, participants are regulated by an economic model, providing an extra layer of security through economic incentives. This semi-custodial bridge enhances transparency and control for users. Meanwhile, it mitigates the risks associated with centralized custody and decentralization. In the evaluation, EquiLink is resilient against both replay and physical attacks. Additionally, it operates efficiently, reducing transaction costs by 14.1% and latency by 18.9% Tingda Shen, Yebo Feng, Jin Dong 0004, Konglin Zhu, Lei Jiao 0002, Lin Zhang 0013 |
IEEE Trans. Serv. Comput. | 2 |
| 2025 | Benchmarking LLMs and LLM-based Agents in Practical Vulnerability Detection for Code RepositoriesabstractAlperen Yildiz, Sin G Teo, Yiling Lou, Yebo Feng, Chong Wang, Dinil Mon Divakaran. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Alperen Yildiz, Sin G. Teo, Yiling Lou, Yebo Feng, Chong Wang 0013, Dinil Mon Divakaran |
ACL (1) | 4 |
| 2025 | Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningabstractAdvanced Persistent Threats (APTs) represent sophisticated cyberattacks characterized by their ability to remain undetected within the victim system for extended periods, aiming to exfiltrate sensitive data or disrupt operations. Existing detection approaches often struggle to effectively identify these complex threats, construct the attack chain for defense facilitation, or resist adversarial attacks. To overcome these challenges, we propose Slot, an advanced APT detection approach based on provenance graphs and graph reinforcement learning. Slot excels in uncovering multi-level hidden relationships, such as causal, contextual, and indirect connections, among system behaviors through provenance graph mining. Slot implements semi-supervised learning with limited labels through efficient label similarity computation, significantly enhancing both detection performance and model robustness. By pioneering the integration of graph reinforcement learning, Slot dynamically adapts to new user activities and evolving attack strategies, enhancing its resilience against adversarial attacks. Additionally, Slot automatically constructs the attack chain according to detected attacks with clustering algorithms, providing precise identification of attack paths and facilitating the development of defense strategies. Evaluations with real-world datasets demonstrate Slot's outstanding accuracy, efficiency, adaptability, and robustness in APT detection, with most metrics surpassing state-of-the-art methods. Additionally, case studies conducted to assess Slot's effectiveness in supporting APT defense further establish it as a practical and reliable tool for cybersecurity protection. Wei Qiao 0005, Yebo Feng, Teng Li 0003, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001, Yang Liu 0003 |
CCS | 2 |
| 2025 | Piercing the Veil of TVL: DeFi Reappraised
Yebo Feng, Jiahua Xu 0002, Paolo Tasca |
FC (2) | 2 |
| 2025 | AMM-based DEX on the XRP LedgerabstractAutomated Market Maker (AMM)-based Decentralized Exchanges (DEXs) are crucial in Decentralized Finance (DeFi), but Ethereum implementations suffer from high transaction costs and price synchronization challenges. To address these limitations, we compare the XRP Ledger (XRPL)-AMM-Decentralized Exchange (DEX), a protocol-level implementation, against a Generic AMM-based DEX (G-AMM-DEX) on Ethereum, akin to Uniswap’s V2 AMM implementation, through agent-based simulations using real market data and multiple volatility scenarios generated via Geometric Brownian Motion (GBM). Results demonstrate that the XRPL-AMM-DEX achieves superior price synchronization, reduced slippage, and improved returns due to XRPL’s lower fees and shorter block times, with benefits amplifying during market volatility. The integrated Continuous Auction Mechanism (CAM) further mitigates impermanent loss by redistributing arbitrage value to Liquidity Providers (LPs). To the best of our knowledge, this study represents the first comparative analysis between protocol-level and smart contract AMM-based DEX implementations and the first agent-based simulation validating theoretical auction mechanisms for AMM-based DEXs. Walter Hernandez Cruz, Firas Dahi, Yebo Feng, Jiahua Xu 0002, Aanchal Malhotra, Paolo Tasca |
ICBC | 3 |
| 2025 | LLMs Meet Library Evolution: Evaluating Deprecated API Usage in LLM-Based Code CompletionabstractLarge language models (LLMs), pre-trained or fine-tuned on large code corpora, have shown effectiveness in generating code completions. However, in LLM-based code completion, LLMs may struggle to use correct and up-to-date Application Programming Interfaces (APIs) due to the rapid and continuous evolution of libraries. While existing studies have highlighted issues with predicting incorrect APIs, the specific problem of deprecated API usage in LLM-based code completion has not been thoroughly investigated. To address this gap, we conducted the first evaluation study on deprecated API usage in LLM-based code completion. This study involved seven advanced LLMs, 145 API mappings from eight popular Python libraries, and$\mathbf{2 8, 1 2 5}$completion prompts. The study results reveal the status quo (i.e., API usage plausibility and deprecated usage rate) of deprecated API and replacing API usage in LLM-based code completion from the perspectives of model, prompt, and library, and indicate the root causes behind. Based on these findings, we propose two lightweight fixing approaches, Replaceapi and InsertPrompt, which can serve as baseline approaches for future research on mitigating deprecated API usage in LLM-based completion. Additionally, we provide implications for future research on integrating library evolution with LLMdriven software development. Chong Wang 0013, Kaifeng Huang 0001, Jian Zhang 0087, Yebo Feng, Lyuye Zhang, Yang Liu 0003, Xin Peng 0001 |
ICSE | 4 |
| 2025 | StealthHub: Utxo-Based Stealth Address ProtocolabstractPrivacy remains a significant challenge in public blockchain ecosystems. Mainstream add-on privacy solutions, such as Stealth Address Protocols (SAPs) and Zero-Knowledge Proof (ZKP)-based mixers, have recently attracted considerable attention. However, existing SAPs offer only ephemeral anonymity for users' transaction data, and their implementation and evaluation within the highly concurrent Unspent Transaction Output (UTXO) model remain largely unexplored. ZKP-based mixers are limited to native coin transfers with fixed denominations and require additional security assumptions, employing out-of-band encrypted channels to transmit notes. To overcome these challenges, we unify the core principles underlying both SAPs and ZKP mixers and formally introduce StealthHub, a UTXObased SAP. Compared with the widely adopted dual-key-based Umbra protocol prevalent on Ethereum Virtual Machine (EVM)-compatible chains, StealthHub reduces computational overhead for the prepare and scan announcements stages by over 71% and 32%, respectively. Furthermore, by leveraging Merkle Mountain Range (MMR) commitments and off-chain batch aggregation, our StealthHub implementation lowers deposit and shielded transfer transaction costs to approximately 76% of those for a standard transfer, substantially improving practical usability. Hanze Guo, Yebo Feng, Cong Wu 0003, Zengpeng Li 0001, Jiahua Xu 0002 |
ICWS | 2 |
| 2025 | Learning from the Past: Real-World Exploit Migration for Smart Contract PoC GenerationabstractSmart contract vulnerabilities continue to cause significant financial losses, despite the implementation of security measures such as manual audits and bug bounty platforms. A critical component often required by these security measures is the proof-of-concept (PoC) exploit, which validates vulnerability exploitability, assesses impact severity, and guides developers in fixes. Existing tools have explored automated PoC generation with techniques like symbolic execution, fuzzing, and program synthesis. However, these approaches frequently fail to generate PoCs for vulnerabilities exploited in real-world incidents, primarily due to their limitations in handling complex transaction dependencies, navigating vast on-chain state spaces, or requiring extensive manual specifications. Our migration-based approach extracts critical information from documented security incidents and applies it to generate PoCs for similar vulnerable code. This approach leverages proven exploit patterns rather than generating PoCs from scratch. This approach is motivated by two key observations: the prevalence of code reuse in smart contracts (up to 90% at the function level) and the increasing availability of documented PoCs for real-world incidents. Our approach operates in three phases: (1) abstracting essential components (i.e., environment properties, attack logic, and verification checks) from existing PoCs into templates, (2) given a new target contract, selecting suitable templates with adapted values through clone-detection and property-feasibility analysis, and (3) generating and validating PoCs in simulated environments. Our evaluation demonstrates effectiveness and efficiency across multiple scales. Our approach successfully generates valid PoCs for 62 out of 67 manually validated cases without false positives and completes analysis in 3.8 hours compared to 133.2 and 210.5 hours required by existing tools. Large-scale evaluation on 979,512 contracts identifies 256 vulnerable contracts across blockchain networks with 64 cross-chain cases, demonstrating real-world applicability. Kairan Sun, Zhengzi Xu, Kaixuan Li 0002, Lyuye Zhang, Yebo Feng, Daoyuan Wu, Yang Liu 0003 |
ASE | 5 |
| 2025 | STGraph: Spatio-Temporal Graph Mining for Anomaly Detection in Distributed System LogsabstractSystem logs are crucial sources of information for engineers to analyze and resolve anomalies and faults in large-scale software systems. However, logs on a distributed system are often fragmented, making it challenging to achieve unified processing and comprehension. Traditional methods for log-based anomaly detection often employ machine learning algorithms with a focus on log event counts or log sequences. However, traditional methods fall short of fully leveraging the temporal and spatial structures inherent in distributed system logs, leading to issues of false positives and unstable performance in anomaly detection. In this paper, we propose a novel log anomaly detection method based on the construction of distributed system workflow graphs. This method extracts spatio-temporal information from distributed system logs and constructs event workflow graphs. These graphs accurately reflect the execution of the system and provide more comprehensive support for anomaly detection based on distributed system logs. The experimental results demonstrated that STGraph achieved F1 scores of 0.959,0.979, and 0.959 on HDFS, BGL, and OpenStack datasets respectively, outperforming LogRobust, PLELog, and NeuralLog by 1.2%-18.6% across precision/recall metrics. Notably, it attained 0.985 recall on BGL and maintained >0.935 F1 scores under 30% noise interference, 21.8% higher than LogRobust. Teng Li 0003, Shengkai Zhang, Yebo Feng, Jiahua Xu 0002, Zexu Dang, Yang Liu 0003, Jianfeng Ma 0001 |
RAID | 3 |
| 2025 | SoK: Design, vulnerabilities, and security measures of cryptocurrency wallets
Yimika Erinle, Yathin Kethepalli, Yebo Feng, Jiahua Xu 0002 |
Comput. Networks | 3 |
| 2025 | HeteroSample: Meta-Path Guided Sampling for Heterogeneous Graph Representation LearningabstractThe rapid expansion of Internet of Things (IoT) has resulted in vast, heterogeneous graphs that capture complex interactions among devices, sensors, and systems. Efficient analysis of these graphs is critical for deriving insights in IoT scenarios, such as smart cities, industrial IoT, and intelligent transportation systems. However, the scale and diversity of IoT-generated data present significant challenges, and existing methods often struggle with preserving the structural integrity and semantic richness of these complex graphs. Many current approaches fail to maintain the balance between computational efficiency and the quality of the insights generated, leading to potential loss of critical information necessary for accurate decision-making in IoT applications. We introduce HeteroSample, a novel sampling method designed to address these challenges by preserving the structural integrity, node and edge type distributions, and semantic patterns of IoT-related graphs. HeteroSample works by incorporating the novel top-leader selection, balanced neighborhood expansion, and meta-path guided sampling strategies. The key idea is to leverage the inherent heterogeneous structure and semantic relationships encoded by meta-paths to guide the sampling process. This approach ensures that the resulting subgraphs are representative of the original data while significantly reducing computational overhead. Extensive experiments demonstrate that HeteroSample outperforms state-of-the-art methods, achieving up to 15% higher F1 scores in tasks, such as link prediction and node classification, while reducing runtime by 20%. These advantages make HeteroSample a transformative tool for scalable and accurate IoT applications, enabling more effective and efficient analysis of complex IoT systems, ultimately driving advancements in smart cities, industrial IoT, and beyond. Jing Chen 0003, Ruiying Du, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001 |
IEEE Internet Things J. | 5 |
| 2025 | DynaShard: Secure and Adaptive Blockchain Sharding Protocol With Hybrid Consensus and Dynamic Shard ManagementabstractBlockchain sharding has emerged as a promising solution to the scalability challenges in traditional blockchain systems by partitioning the network into smaller, manageable subsets called shards. Despite its potential, existing sharding solutions face significant limitations in handling dynamic workloads, ensuring secure cross-shard transactions, and maintaining system integrity. To address these gaps, we propose DynaShard, a dynamic and secure cross-shard transaction processing mechanism designed to enhance blockchain sharding efficiency and security. DynaShard combines adaptive shard management, a hybrid consensus approach, plus an efficient state synchronization and dispute resolution protocol. Our performance evaluation, conducted using a robust experimental setup with real-world network conditions and transaction workloads, demonstrates DynaShard's superior throughput, reduced latency, and improved shard utilization compared to the fast transaction scheduling in blockchain sharding (FTSBS) method. Specifically, DynaShard achieves up to a 42.6% reduction in latency and a 78.77% improvement in shard utilization under high transaction volumes and varying cross-shard transaction ratios. These results highlight DynaShard's ability to outperform state-of-the-art sharding methods, ensuring scalable and resilient blockchain systems. We believe that DynaShard's innovative approach will significantly impact future developments in blockchain technology, paving the way for more efficient and secure distributed systems. Jing Chen 0003, Kun He 0008, Ruiying Du, Jiahua Xu 0002, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001 |
IEEE Internet Things J. | 7 |
| 2025 | Log2Evt: Constructing high-level events for IoT Systems through log-code execution path correlation
Teng Li 0003, Baichuan Zheng, Yebo Feng, Xiaowen Quan, Jiahua Xu 0002, Yang Liu 0003, Jianfeng Ma 0001 |
J. Syst. Archit. | 3 |
| 2025 | Environment-Adaptive Representation Interaction for Privacy-Perturbed Graphs Against Deceptive OOD AttacksabstractGraph neural networks (GNNs) have gained increasing popularity in understanding graph-structured data due to their ability to derive meaningful representations by aggregating complicated topological information. However, privacy operations such as differential privacy mechanisms that inject noise into node features or graph structures to protect sensitive information, and distribution shifts in graph data pose tremendous security risks for the wide application of GNN models. Current researches mainly focus on defending the out-of-distribution (OOD) attacks through robust adversarial training and graph structure purification. Nonetheless, privacy perturbations of graph structures may render OOD attacks more deceptive by obfuscating the distinctiveness of nodes, leading to the failure of existing defense methods. To address these shortcomings, we propose an environment-adaptive representation interaction (EARI) scheme that strengthens the privacy perception of GNNs. Specifically, our scheme leverages the interaction between non-private and private data to enable targeted embedding propagation by the guidance of confidence score feedback. Subsequently, the representation-enriched topological aggregation is implemented to capture more discriminative features by exploiting multi-hop neighborhoods rather than stacked multilayers. Finally, the generalization-enhanced cluster-wise adaptation learning is leveraged to highlight the invariant correlations from nodes across different environments. Extensive experimental results demonstrate that our scheme can enhance the capability of learning representations from privacy-protected graph data, enabling GNNs to effectively defend against deceptive OOD attacks on various graph-structured datasets. Moreover, we reveal that the utilization of interactive topological aggregation can extremely enrich the diversity and guarantee the effectiveness for graph representations. Ju Jia, Cong Wu 0003, Yebo Feng, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | SauronEyes: Disentangling Voluminous Logs to Unveil Camouflaged Attack Intentions
Wei Qiao 0005, Weiheng Wu, Yebo Feng, Teng Li 0003, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | SCR-Auth: Secure Call Receiver Authentication on Smartphones Using Outer Ear EchoesabstractReceiving calls is one of the most universal functions of smartphones, involving sensitive information and critical operations. Unfortunately, to prioritize convenience, the current call receiving process bypasses smartphone authentication mechanisms (e.g., passwords, fingerprint recognition, and face recognition), leaving a significant security gap. To address this issue, we propose SCR-Auth, a secure call receiver authentication scheme for smartphones that leverages outer ear echoes. It sends inaudible acoustic signals through the earpiece speaker to actively sense the call receiver’s outer ear structure and records the resulting echoes using the top microphone. These echoes are then analyzed to extract unique outer ear biometric information for authentication. It operates implicitly, without requiring extra hardware or imposing additional burden. Comprehensive experiments conducted under diverse conditions demonstrate SCR-Auth’s effectiveness and security, showing an average balanced accuracy of 96.95% and resilience against potential attacks. Xiping Sun, Jing Chen 0003, Kun He 0008, Zhixiang He, Ruiying Du, Yebo Feng, Qingchuan Zhao, Cong Wu 0003 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Profit or Deceit? Mitigating Pump and Dump in DeFi via Graph and Contrastive LearningabstractPump-and-Dump (PD) schemes pose a significant threat to the stability and fairness of Decentralized Finance (DeFi) markets, often resulting in substantial financial losses for investors. The early and accurate detection of these schemes is crucial for preserving trust in the rapidly expanding cryptocurrency ecosystem. However, existing detection methods primarily rely on post-event analysis and heuristic-based approaches, which are often inadequate for real-time and precise identification of PD activities. In this paper, we present PUMPWATCHER, an innovative framework that employs Graph Neural Networks (GNNs) and contrastive learning to detect PD schemes by modeling transaction behaviors within temporal graphs. PUMPWATCHER integrates advanced transaction graph construction, temporal GNNs, and contrastive learning techniques to enhance node and edge representations, thereby improving the detection of intricate and covert PD operations. We validate PUMPWATCHER on a dataset from Uniswap, encompassing 924,508 transactions across 858 tokens within December 2022. The results show that PUMPWATCHER outperforms state-of-the-art models, achieving a superior balanced accuracy of 92.3%, while significantly minimizing false positives and negatives. These outcomes highlight its potential to set a new standard in real-time detection of market manipulation, paving the way for more secure and resilient DeFi ecosystems. Cong Wu 0003, Jing Chen 0003, Jiahua Xu 0002, Ju Jia, Yebo Feng, Yang Liu 0003, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | CryptIF: Toward Cloud-Based IoT Anomaly Detection Over Encrypted Feature Streams
Teng Li 0003, Zejian Lin, Yebo Feng, Chong Wang 0013, Zhuo Ma 0001, Bin Xiao 0002, Jianfeng Ma 0001, Yang Liu 0003 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2025 | CSIPose: Unveiling Human Poses Using Commodity WiFi Devices Through the WallabstractThe popularity of WiFi devices and the development of WiFi sensing have alerted people to the threat of WiFi sensing-based privacy leakage, especially the privacy of human poses. Existing work on human pose estimation is deployed in indoor scenarios or simple occlusion (e.g., a wooden screen) scenarios, which are less privacy-threatening in attack scenarios. To reveal the risk of leakage of the pose privacy to users from commodity WiFi devices, we propose CSIPose, a privacy-acquisition attack that passively estimates dynamic and static human poses in through-the-wall scenarios. We design a three-branch network based on transfer learning, auto-encoder, and self-attention mechanisms to realize the supervision of video frames over CSI frames to generate human pose skeleton frames. Notably, we designAveCSI, a unified framework for preprocessing and feature extraction of CSI data corresponding to dynamic and static poses. This framework uses the average of CSI measurements to generate CSI frames to mitigate the instability of passively collected CSI data, and utilizes a self-attention mechanism to enhance key features. We evaluate the performance of CSIPose across different room layouts, subjects, devices, subject locations, and device locations. Evaluation results emphasize the generalizability of CSIPose. Finally, we discuss measures to mitigate this attack. Yangyang Gu, Jing Chen 0003, Congrui Chen, Kun He 0008, Ju Jia, Yebo Feng, Ruiying Du, Cong Wu 0003 |
IEEE Trans. Mob. Comput. | 6 |
| 2025 | Teaching Code LLMs to Use Autocompletion Tools in Repository-Level Code GenerationabstractRecent code large language models (LLMs) have shown promising performance in generating standalone functions. However, they face limitations in repository-level code generation due to their lack of awareness of repository-level dependencies ( e.g., user-defined attributes), resulting in dependency errors such as undefined-variable and no-member errors. In this work, we introduce ToolGen , an approach that integrates autocompletion tools into the code LLM generation process to address these dependencies. ToolGen comprises two main phases: Trigger Insertion and Model Fine-tuning (Offline), and Tool-integrated Code Generation (Online). During the offline phase, ToolGen augments functions within a given code corpus with a special mark token, indicating positions to trigger autocompletion tools. These augmented functions, along with their corresponding descriptions, are then used to fine-tune a selected code LLM. In the online phase, ToolGen iteratively generates functions by predicting tokens step-by-step using the fine-tuned LLM. Whenever a mark token is encountered, ToolGen invokes the autocompletion tool to suggest code completions and selects the most appropriate one through constrained greedy search. We conduct comprehensive experiments to evaluate ToolGen ’s effectiveness in repository-level code generation across three distinct code LLMs: CodeGPT, CodeT5, and CodeLlama. To facilitate this evaluation, we create a benchmark comprising 671 real-world code repositories and introduce two new dependency-based metrics: Dependency Coverage and Static Validity Rate . The results demonstrate that ToolGen significantly improves Dependency Coverage by 31.4% to 39.1% and Static Validity Rate by 44.9% to 57.7% across the three LLMs, while maintaining competitive or improved performance in widely recognized similarity metrics such as BLEU-4, CodeBLEU, Edit Similarity, and Exact Match. On the CoderEval dataset, ToolGen achieves improvements of 40.0% and 25.0% in test pass rate (Pass@1) for CodeT5 and CodeLlama, respectively, while maintaining the same pass rate for CodeGPT. ToolGen also demonstrates high efficiency in repository-level code generation, with latency ranging from 0.63 to 2.34 seconds for generating each function. Furthermore, our generalizability evaluation confirms ToolGen ’s consistent performance when applied to diverse code LLMs, encompassing various model architectures and scales. Chong Wang 0013, Jian Zhang 0087, Yebo Feng, Tianlin Li, Weisong Sun, Yang Liu 0003, Xin Peng 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | Auto.gov: Learning-Based Governance for Decentralized Finance (DeFi)abstractDecentralized finance (DeFi) is an integral component of the blockchain ecosystem, enabling a range of financial activities through smart-contract-based protocols. Traditional Decentralized finance (DeFi) governance typically involves manual parameter adjustments by protocol teams or token holder votes, and is thus prone to human bias and financial risks, undermining the system's integrity and security. While existing efforts aim to establish more adaptive parameter adjustment schemes, there remains a need for a governance model that is both more efficient and resilient to significant market manipulations. In this paper, we introduce “Auto.gov”, a learning-based governance framework that employs a Deep Q-network (DQN) Reinforcement learning (RL) strategy to perform semi-automated, data-driven parameter adjustments. We create a DeFi environment with an encoded action-state space akin to the Aave lending protocol for simulation and testing purposes, where Auto.gov has demonstrated the capability to retain funds that would have otherwise been lost to price oracle attacks. In tests with real-world data, Auto.gov outperforms the benchmark approaches by at least 14% and the static baseline model by tenfold, in terms of the preset performance metric—protocol profitability. Overall, the comprehensive evaluations confirm that Auto.gov is more efficient and effective than traditional governance methods, thereby enhancing the security, profitability, and ultimately, the sustainability of DeFi protocols. Jiahua Xu 0002, Yebo Feng, Daniel Perez 0001, Benjamin Livshits |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | SecPLF: Secure Protocols for Loanable Funds against Oracle Manipulation AttacksabstractThe evolving landscape of Decentralized Finance (DeFi) has raised critical security concerns, especially pertaining to Protocols for Loanable Funds (PLFs) and their dependency on price oracles, which are susceptible to manipulation. The emergence of flash loans has further amplified these risks, enabling increasingly complex oracle manipulation attacks that can lead to significant financial losses. Responding to this threat, we first dissect the attack mechanism by formalizing the standard operational and adversary models for PLFs. Based on our analysis, we propose SecPLF, a robust and practical solution designed to counteract oracle manipulation attacks efficiently. SecPLF operates by tracking a price state for each cryptoasset, including the recent price and the timestamp of its last update. By imposing price constraints on the price oracle usage, SecPLF ensures a PLF only engages a price oracle if the last recorded price falls within a defined threshold, thereby negating the profitability of potential attacks. Our evaluation based on historical market data confirms SecPLF's efficacy in providing high-confidence prevention against arbitrage attacks that arise due to minor price differences. SecPLF delivers proactive protection against oracle manipulation attacks, offering ease of implementation, oracle-agnostic property, and resource and cost efficiency. Sanidhay Arora, Yingjiu Li, Yebo Feng, Jiahua Xu 0002 |
AsiaCCS | 3 |
| 2024 | Heuristic-based Parsing System for Big Data LogabstractLogs play a crucial role in recording valuable system runtime information, extensively utilized by service providers and users for effective service management. A typical approach in service management, based on log analysis, involves parsing the original log messages initially presented in an unstructured format. Subsequently, a data mining model is employed to extract critical system behavior information, aiding in service management. As the volume of logs rapidly increases, training models using current log resolution methods post-log collection becomes excessively time-consuming, leading to decreased accuracy. Manual analysis of extensive logs is both time-intensive and inefficient. This article introduces Aclog, an automated log parsing tool tailored for large-scale log analysis, storage, and management. Aclog operates by storing and managing logs in a structured and unified format, thereby offering a cohesive database for comprehensive log auditing of computing systems. Key components of Aclog encompass the log updater, log parser, log storage, and log querier. In this paper, we utilize a realworld, large-scale public log dataset to showcase the capabilities of Aclog. We evaluate the log files generated by ten popular systems. Teng Li 0003, Shengkai Zhang, Yebo Feng, Jiahua Xu 0002, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001 |
GLOBECOM | 3 |
| 2024 | DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsabstractAlthough Decentralized Finance (DeFi) applications facilitate tamper-proof transactions among multiple anonymous users, since attackers can access the smart contract bytecode directly, vulnerabilities in the transaction mechanism, contract code, or third-party components can be easily exploited to manipulate token prices, leading to financial losses. Since price manipulation often relies on specific states and complex trading sequences, existing detection tools have limitations in addressing this problem. In addition, to swiftly identify the root cause of an attack and implement targeted defense and remediation measures, auditors typically prioritize understanding the methodology behind the attack, emphasizing 'how' it occurred rather than simply confirming its existence. To address these problems, this paper presents a novel automatic price manipulation detection and analysis framework, named DeFort, which contains a price manipulation behavior model to guide on-chain detection, multiple price monitoring strategies to detect pools with abnormal token prices, and various profit calculation mechanisms to confirm attacks. Based on behavioral models, DeFort can automatically locate transactions and functions that cause abnormal price fluctuations and identify attackers and victims. Experimental results demonstrate that DeFort can outperform state-of-the-art price manipulation detection methods. Furthermore, after monitoring 441 real-world projects for two months, DeFort successfully detected five price manipulation attacks. Maoyi Xie, Ming Hu 0003, Ziqiao Kong, Cen Zhang, Yebo Feng, Haijun Wang 0002, Yue Xue, Hao Zhang 0004, Ye Liu 0012, Yang Liu 0003 |
ISSTA | 5 |
| 2024 | CToMP: a cycle-task-oriented memory protection scheme for unmanned systems
Chengyan Ma 0001, Ning Xi 0002, Di Lu 0001, Yebo Feng, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 4 |
| 2024 | On Explainable and Adaptable Detection of Distributed Denial-of-Service TrafficabstractLaunched from numerous end-hosts throughout the Internet, a distributed denial-of-service (DDoS) attack can exhaust the network bandwidth or other resources of a victim, cripple its service, and make it unavailable to legitimate clients. Recently many learning-based approaches attempt to detect DDoS attacks, but their results are often hardly explainable to users and their models are seldom adaptable to new environments. In this paper, we propose a new learning-based DDoS detection approach. It detects DDoS attacks via an enhanced k-nearest neighbors (KNN) algorithm, which utilizes a k-dimensional (KD) tree to speed up the detection process, and classifies DDoS sources at a fine granularity according to each IP's risk level. Compared to previous DDoS detection approaches, this approach outputs explanatory information that enables network administrators to easily inspect detection results and make necessary interventions. Moreover, this approach is adaptable in that users do not need to retrain the detection model to have it fit with a new network environment. We evaluated this approach in both simulated environments and the real world, achieving more than 95.6% accuracy in detecting DDoS attacks at line speed. In addition, we carried out a human subject study on its explainability, demonstrating that the outputs can help people better understand the attack and make interventions precisely and promptly. Yebo Feng, Jun Li 0001, Devkishen Sisodia, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Reap the Harvest on Blockchain: A Survey of Yield Farming ProtocolsabstractYield farming represents an immensely popular asset management activity in decentralized finance (DeFi). It involves supplying, borrowing, or staking crypto assets to earn an income in forms of transaction fees, interest, or participation rewards at different DeFi marketplaces. In this systematic survey, we present yield farming protocols as an aggregation-layer constituent of the wider DeFi ecosystem that interact with primitive-layer protocols such as decentralized exchanges (DEXs) and loanable funds (PLFs) protocol for loanable funds (PLF). We examine the yield farming mechanism by first studying the operations encoded in the yield farming smart contracts, and then performing stylized, parameterized simulations on various yield farming strategies. We conduct a thorough literature review on related work, and establish a framework for yield farming protocols that takes into account pool structure, accepted token types, and implemented strategies. Using our framework, we characterize major yield aggregators in the market including Yearn Finance, Beefy, and Badger DAO. Moreover, we discuss anecdotal attacks against yield aggregators and generalize a number of risks associated with yield farming. Jiahua Xu 0002, Yebo Feng |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | I Can Still Observe You: Flow-level Behavior Fingerprinting for Online Social NetworkabstractThe privacy of online social networks (OSNs) remains a major concern for today's Internet. Researchers have demonstrated that by analyzing inter-packet or packet-level network traffic, a third-party analyzer is able to fingerprint a user's OSN behavior information even when the traffic is encrypted. In this paper, we propose a learning-based approach that steps further to perform OSN behavior fingerprinting only through highly compressed, flow-level network traffic (e.g., NetFlow). By preprocessing flow records, segmenting traffic flows into bursts, and leveraging a long short-term memory network to classify the bursts, our approach can identify major OSN behaviors (e.g., Facebook post, Twitter Read, Weibo video, etc.) with nearly 90% accuracy. Compared with packet-level fingerprinting approaches, our approach significantly improves the fingerprinting efficiency in evaluations, making large-scale OSN usage monitoring feasible only with limited computing resources and coarse-grained network traffic. This work also reveals the huge risks facing privacy of OSN users on today's Internet today. Yebo Feng, Jian-Zhen Luo, Chengyan Ma 0001, Teng Li 0003, Liang Hui |
GLOBECOM | 1 |
| 2022 | CJ-Sniffer: Measurement and Content-Agnostic Detection of Cryptojacking TrafficabstractWith the continuous appreciation of cryptocurrency, cryptojacking, the act by which computing resources are stolen to mine cryptocurrencies, is becoming more rampant. In this paper, we conduct a measurement study on cryptojacking network traffic and propose CryptoJacking-Sniffer (CJ-Sniffer), an easily deployable, privacy-aware approach to protecting all devices within a network against cryptojacking. Compared with existing approaches that suffer from privacy concerns or high overhead, CJ-Sniffer only needs to access anonymized, content-agnostic metadata of network traffic from the gateway of the network to efficiently detect cryptojacking traffic. In particular, while cryptojacking traffic is also cryptocurrency mining traffic, CJ-Sniffer is the first approach to distinguishing cryptojacking traffic from user-initiated cryptocurrency mining traffic, making it possible to only filter cryptojacking traffic, rather than blindly filtering all cryptocurrency mining traffic as commonly practiced. After constructing a statistical model to identify all the cryptocurrency mining traffic, CJ-Sniffer extracts variation vectors from packet intervals and utilizes a long short-term memory (LSTM) network to further identify cryptojacking traffic. We evaluated CJ-Sniffer with a packet-level cryptomining dataset. Our evaluation results demonstrate that CJ-Sniffer achieves an accuracy of over 99% with reasonable delays. Yebo Feng, Jun Li 0001, Devkishen Sisodia |
RAID | 1 |
| 2022 | CoAvoid: Secure, Privacy-Preserved Tracing of Contacts for Infectious DiseasesabstractTo fight against infectious diseases (e.g., SARS, COVID-19, Ebola, etc.), government agencies, technology companies and health institutes have launched various contact tracing approaches to identify and notify the people exposed to infection sources. However, existing tracing approaches can lead to severe privacy and security concerns, thereby preventing their secure and widespread use among communities. To tackle these problems, this paper proposesCoAvoid, an edge-based, privacy-preserved contact tracing system that features good dependability and usability.CoAvoidleverages the Google/Apple Exposure Notification (GAEN) API to achieve decent device compatibility and operating efficiency. It utilizes Bluetooth Low Energy (BLE) to detect close contact with other people and leverages GPS with fine-grained matching algorithms to verify user information. In addition, to enhance privacy protection,CoAvoidapplies fuzzification and obfuscation measures to shelter sensitive data, making both servers and users agnostic to information of both low and high-risk populations. The evaluation demonstrates good efficacy and security of CoAvoid. Compared with four state-of-the-art contact tracing applications,CoAvoidcan reduce the size of upload data by at least 90% and reduce the verification time by 92%. More importantly,CoAvoidcan preserve user privacy and resist replay and wormhole attacks in all analysis scenarios. Teng Li 0003, Siwei Yin, Yebo Feng, Lei Jiao 0002, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2021 | Towards Learning-Based, Content-Agnostic Detection of Social Bot TrafficabstractWith the fast-growing popularity of online social networks (OSNs), the security and privacy of OSN ecosystems becomes essential for the public. Among threats OSNs face, malicious social bots have become the most common and detrimental. They are often employed to violate users’ privacy, distribute spam, and disturb the financial market, posing a compelling need for effective social bot detection solutions. Unlike traditional social bot detection approaches that have strict requirements on data sources (e.g., private payload information, social relationships, or activity histories), this article proposes a method called BotFlowMon that relies only on content-agnostic flow-level data as input to identify OSN bot traffic. BotFlowMon introduces several new algorithms and techniques to classify social bot traffic from real OSN user traffic, including aggregating network flow records to obtain OSN transaction data, fusing transaction data to extract features and visualize flows, and an innovative density-valley-based clustering algorithm to subdivide each transaction into individual actions. The evaluation shows BotFlowMon can identify the traffic from social bots with a 96.1 percent accuracy, which, based on the worst case study on a testing machine, only takes no more than 0.71 seconds on average after it sees the traffic. Yebo Feng, Jun Li 0001, Lei Jiao 0002, Xintao Wu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | POSTER: Content-Agnostic Identification of Cryptojacking in Network TrafficabstractIn this paper, we propose a method that detects cryptojacking activities by analyzing content-agnostic network traffic flows. Our method first distinguishes crypto-mining activities by profiling the traffic with fast Fourier transform at each time window. It then generates the variation vectors between adjacent time windows and leverages a recurrent neural network to identify the cryptojacking patterns. Compared with the existing approaches, this method is privacy-preserving and can identify both browser-based and malware-based cryptojacking activities. Additionally, this method is easy to deploy. It can monitor all the devices within a network by accessing packet headers from the gateway router. Yebo Feng, Devkishen Sisodia, Jun Li 0001 |
AsiaCCS | 1 |
| 2020 | Application-Layer DDoS Defense with Reinforcement LearningabstractApplication-layer distributed denial-of-service (L7 DDoS) attacks, by exploiting application-layer requests to overwhelm functions or components of victim servers, have become a rising major threat to today's Internet. However, because the traffic from an L7 DDoS attack appears legitimate in transport and network layers, it is difficult for traditional DDoS solutions to detect and defend against an L7 DDoS attack. In this paper, we propose a new, reinforcement-learning-based approach to L7 DDoS attack defense. We introduce a multiobjective reward function to guide a reinforcement learning agent to learn the most suitable action in mitigating L7 DDoS attacks. Consequently, while actively monitoring and analyzing the victim server, the agent can apply different strategies under different conditions to protect the victim: When an L7 DDoS attack is overwhelming, the agent will aggressively mitigate as many malicious requests as possible, thereby keeping the victim server functioning (even at the cost of sacrificing a small number of legitimate requests); otherwise, the agent will conservatively mitigate malicious requests instead, with a focus on minimizing collateral damage to legitimate requests. The evaluation shows that our approach can achieve minimal collateral damage when the L7 DDoS attack is tolerable and mitigate 98.73 % of the malicious application messages when the victim is brought to its knees. Yebo Feng, Jun Li 0001 |
IWQoS | 1 |