VLDB 2026 Research / reviewers in the wild / expert
Shangru Zhao
dblp:253/1264
· DBLP profile ↗
7ranked-venue papers
0as first author
6since 2021 · last 2026
0009-0009-1883-7750ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 5 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw Detection
Lan Zhang 0008, Zhiyuan Fu, Jice Wang, Shangru Zhao, Qi Li 0002, Ruidong Li 0001, He Wang 0014, Yuqing Zhang 0001 |
NDSS | 7 |
| 2026 | TrustFed-IDS: A trust-aware federated hybrid MLP-LSTM framework for robust intrusion detection in wireless sensor networks
Sukumarn Sankeawthong, Xudong Cao, Shangru Zhao, Yuqing Zhang 0001 |
Comput. Networks | 3 |
| 2025 | LLM-Assisted IDOR Detection in Hospital Mini-Programs: Risks to PII and PHIabstractHospital mini-programs have become widely adopted as lightweight portals for medical services, handling large volumes of personally identifiable information (PII) and protected health information (PHI). Among the most critical threats to such systems is the insecure direct object reference (IDOR) vulnerability, which allows unauthorized access to sensitive resources due to improper object–level access control. However, systematic detection of IDOR in the wild, especially within hospital mini-programs, remains underexplored due to restricted server access and stringent ethical regulations. To address this challenge, we propose a black–box detection framework designed for hospital mini-programs operating in sensitive data environments. Our framework introduces a novel token–substitution probing strategy that adheres to ethical standards and pioneers the use of Large Language Models (LLMs) for automated IDOR vulnerability detection in API endpoints, enabling token field identification, request classification and differential response analysis. We evaluated the framework on 80 real-world mini-programs and identified 114 vulnerable endpoints across 38 applications. Among these, 55 involved sensitive data disclosure, and 34 enabled unauthorized execution of sensitive operations. All findings were responsibly disclosed to the CNVD, and 15 cases have been officially confirmed. Jiawen Sun, Shangru Zhao, Xiangming Zhou, He Wang 0014, Yuqing Zhang 0001 |
TrustCom | 3 |
| 2025 | Log Intelligent Knowledge Base Construction Method Based On Streaming Graph FusionabstractAgainst the backdrop of rapid development in digital transformation and cloud-native architectures, the massive, multi-source, and heterogeneous logs generated by enterpriselevel IT systems have imposed higher requirements on real-time analysis and intelligent operation and maintenance. While traditional ELK stacks facilitate centralized log storage and retrieval, they exhibit significant bottlenecks in complex causal reasoning and dynamic format adaptation. To address these limitations, this paper proposes an intelligent log knowledge base construction method based on a "data classification-hierarchization-graphization" pipeline. Specifically, we design an ELK-Neo4j streaming fusion architecture, a dynamic ontology-driven semantic enhancement mechanism, and a sensitivity-aware hierarchical graph governance model. The system achieves millisecond-level bidirectional synchronization between Elasticsearch and Neo4j through Kafka Connect. Incorporated with template drift detection and relationship weight learning, it enables online ontology evolution and adaptive expansion. For compliance, sensitive fields are identified via regular expressions and NLP, while RBAC+ABAC mechanisms are introduced to achieve triple-level access control. Experiments on HDFS, BGL, and custom security log datasets show that our method significantly outperforms static ontology and batch processing schemes in template extraction F1-score, field recall, graph query latency, synchronization delay, and root cause localization efficiency. The proposed framework can be widely applied in finance, healthcare, and cloud-native scenarios, effectively improving fault diagnosis efficiency and data governance accuracy. Xinzhuo Xue, Shangru Zhao, Yuqing Zhang 0001 |
TrustCom | 2 |
| 2025 | FBFISADetector: A Method based on Filter Mechanism to detect the Instruction Set Architecture of Monolithic FirmwareabstractFirmware identification is a core component of firmware analysis technology, whose primary purpose is to provide sufficient information for subsequent analysis processes. Among such information, Instruction Set Architecture (ISA) information is particularly critical – without it, reverse engineering and firmware simulation cannot be carried out. However, currently there is no effective tool for identifying the ISA of monolithic firmware. This paper presents an new identification method based on a filter mechanism to address the issue of ISA identification for monolithic firmware. By studying multiple instances of instruction set architectures, our key observation is that certain instructions appear in pairs, and we summarize the concept of Instruction Pairs and develop a mechanism to extract and filter binary blocks, which integrates instruction pairs and the logical correctness analysis of the P-Code Intermediate Representation (IR). Furthermore, we build a prototype of FBFISADetector, a monolithic firmware ISA identification system based on the filter mechanism. This system uses the aforementioned methods to extract and filter binary blocks and determines the ISA of tested firmware by the number of remaining binary blocks. Finally, we evaluate our work, and the results show that: In the test of 870 ARM-Cortex M architecture samples from the monolithic firmware dataset, the identification accuracy reaches 98%; in the test of more than 15,000 ELF files covering 5 ISAs (ARM, RISC-V64, MIPS, POWERPC, TRICORE), the overall identification accuracy is as high as 99%. Meanwhile, we verify the code region hit effect of the instruction pair filtering mechanism and the IR analysis filtering mechanism based on the above ELF file dataset. The experimental results demonstrate that the final binary blocks have high credibility regarding their attribution to the current ISA. Shangru Zhao, Yuqing Zhang 0001 |
TrustCom | 2 |
| 2025 | DataLineage RCA: Root Cause Diagnosis for Data Lineage Issues Using Large Language Model-Based AgentsabstractData is increasingly recognized as one of the most critical assets for enterprises. Data lineage graphs, serving as a key foundation of data governance, articulate the evolution of data and the lineage relationships among diverse datasets. By leveraging data lineage graphs, developers can efficiently trace the root causes of anomalies in data metrics. However, as the volume of data within organizations continues to expand, troubleshooting through such graphs has grown increasingly complex. The rise of large language models (LLMs) has been driving significant advances in software engineering, data management, and related disciplines, motivating us to explore their application in root cause analysis for data lineage anomalies. At the same time, due to commercial confidentiality and privacy compliance requirements, the field of data governance suffers from a pronounced scarcity of open datasets—particularly those featuring comprehensive data lineage relationships with annotated anomalies. To address the lack of labeled anomaly data grounded in data lineage, we designed a synthetic data generation process based on the TPC‑H benchmark, creating a specialized dataset that includes four types of anomalies: null field values, unexpected field values, empty tables, and anomalous data distributions— comprising 100 cases in total. For the task of root cause diagnosis in data lineage anomalies, we developed a multi-agent framework powered by a large language model to evaluate its performance on this task. Our study explores the potential of LLMs in diagnosing data lineage anomalies, and results demonstrate that our approach successfully resolves 90% of the constructed cases. Shangru Zhao, Yuqing Zhang 0001 |
TrustCom | 2 |
| 2020 | Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsabstractWith the increasing popularity of the Internet of Things (IoT), many IoT cloud platforms have emerged to help the IoT manufacturers connect their devices to their users. Serving the device-user communication is general messaging protocol deployed on the platforms. Less clear, however, is whether such protocols, which are not designed to work in the adversarial environment of IoT, introduce new risks. In this paper, we report the first systematic study on the protection of major IoT clouds (e.g., AWS, Microsoft, IBM) put in place for the arguably most popular messaging protocol - MQTT. We found that these platforms' security additions to the protocol are all vulnerable, allowing the adversary to gain control of the device, launch a large-scale denial-of-service attack, steal the victim's secrets data and fake the victim's device status for deception. We successfully performed end-to-end attacks on these popular IoT clouds and further conducted a measurement study, which demonstrates that the security impacts of our attacks are real, severe and broad. We reported our findings to related parties, which all acknowledged the importance. We further propose new design principles and an enhanced access model MOUCON. We implemented our protection on a popular open-source MQTT server. Our evaluation shows its high effectiveness and negligible performance overhead. Yan Jia 0009, Luyi Xing, Yuhang Mao, Dongfang Zhao 0010, XiaoFeng Wang 0001, Shangru Zhao, Yuqing Zhang 0001 |
SP | 6 |