VLDB 2026 Research / reviewers in the wild / expert
Mingxuan Liu 0006
dblp:253/7461-6
· DBLP profile ↗
22ranked-venue papers
6as first author
18since 2021 · last 2026
0000-0002-2163-6505ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 6 first-author · 14 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases
Mengying Wu, Geng Hong, Jiatao Chen, Baojun Liu 0002, Mingxuan Liu 0006, Min Yang 0002 |
NDSS | 5 |
| 2026 | Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon Detection
Zhifan Jiang, Mingxuan Liu 0006, Baojun Liu 0002 |
SP | 2 |
| 2026 | Unveiling the Resilience of LLM-Enhanced Search Engines against Black-Hat SEO ManipulationabstractThe emergence of Large Language Model-enhanced Search Engines (LLMSEs) has revolutionized information retrieval by integrating web-scale search capabilities with AI-powered summarization. While these systems demonstrate improved efficiency over traditional search engines, their security implications against well-established black-hat Search Engine Optimization (SEO) attacks remain unexplored. In this paper, we present the first systematic study of SEO attacks targeting LLMSEs. Specifically, we examine ten representative LLMSE products (e.g., ChatGPT, Gemini) and construct SEO-Bench, a benchmark comprising 1,000 real-world black-hat SEO websites, to evaluate both open- and closed-source LLMSEs. Our measurements show that LLMSEs mitigate over 99.78% of traditional SEO attacks, with the phase of retrieval serving as the primary filter, intercepting the vast majority of malicious queries. We further propose and evaluate seven LLMSEO attack strategies, demonstrating that off-the-shelf LLMSEs are vulnerable to LLMSEO attacks, i.e., rewritten-query stuffing and segmented texts double the manipulation rate compared to the baseline. This work offers the first in-depth security analysis of the LLMSE ecosystem, providing practical insights for building more resilient AI-driven search systems. We have responsibly reported the identified issues to major vendors. Geng Hong, Mengying Wu, Mingxuan Liu 0006, Baojun Liu 0002, Mi Zhang 0001, Min Yang 0002 |
WWW | 6 |
| 2026 | Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action
Shibo Cui, Mingxuan Liu 0006, Baojun Liu 0002, Hai-Xin Duan, Ruixuan Li 0008, Chaoyi Lu, Jinghua Bai |
WWW | 2 |
| 2025 | Email Cloaking: Deceiving Users and Spam Email Detectors with Invisible HTML Settings
Bingyang Guo, Mingxuan Liu 0006, Yihui Ma, Ruixuan Li 0008, Fan Shi 0003, Min Zhang 0054, Baojun Liu 0002, Chengxi Xu, Hai-Xin Duan, Geng Hong, Min Yang 0002, Qingfeng Pan |
ESORICS (4) | 2 |
| 2025 | Dive into the Cloud: Unveiling the (Ab)Usage of Serverless Cloud Function in the WildabstractServerless cloud functions transfer server management responsibilities to service providers, offering scalability and cost-efficiency. This convenience not only facilitates normal activities but also raises abuse concerns. So far, public understanding of real-world cloud functions remains limited. To fill this gap, we conducted an in-depth measurement study to uncover their practical usage and abuse. Through empirical analysis of nine leading providers (e.g., AWS, Tencent), we identified 531,089 function domains from a passive DNS dataset spanning April 2022 to March 2024. We first investigated the usage status of serverless cloud functions, showing the different practices between providers. Additionally, based on active requests to these functions, we pointed out privacy risks of unauthorized access and identified four abuse types, including covert C2 communication, hosting malicious websites, promoting illicit services, and abusing egress nodes as IP proxies. Alarmingly, 4.89% of cloud functions are being abused, with over 614k invocations recorded. Only four abused functions were flagged by existing threat intelligence systems, indicating critical gaps in security monitoring for serverless environments. Our work offers insights into the serverless cloud ecosystem and provides recommendations for better management. With responsible disclosure, we hope to raise awareness and improve protective measures against abuses among cloud function providers. Yijing Liu 0007, Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Jia Zhang 0004, Geng Hong, Hai-Xin Duan, Min Yang 0002 |
IMC | 2 |
| 2025 | Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version Identification
Mengying Wu, Geng Hong, Baichao An, Mingxuan Liu 0006, Lei Zhang 0096, Baojun Liu 0002, Hai-Xin Duan, Min Yang 0002 |
USENIX Security Symposium | 5 |
| 2025 | NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines
Mingxuan Liu 0006, Lijie Wu, Baojun Liu 0002, Geng Hong, Yiming Zhang 0009, Jia Zhang 0004, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003, Min Yang 0002 |
USENIX Security Symposium | 1 |
| 2024 | ChatScam: Unveiling the Rising Impact of ChatGPT on Domain Name AbuseabstractSince 2022, ChatGPT has been a big breakthrough in technology, creating lots of discussions online. It has had big effects in different areas, but in cybersecurity, it is both good and bad. There has been a lot of misuse, especially with squatting domains. Our research aims to understand this misuse and the potential threats it poses. We develop a novel method that looks at historical Passive DNS (PDNS) data. Based on the two-stage identification, our method can efficiently and accurately collect ChatGPT-related squatting domains. In the end, we found over 1.3 million ChatGPT-related squatting domains, part of which were shared with the security community. Our findings show that these squatting domains are increasing quickly. This is the case whether the keywords related to ChatG PT are registered with the domain registrar or set up on sub domains. Even though the number of domains is increasing, only 5.3 % set up meaningful content on their websites. After digging into their web contents, we found that these web sites show various signs of misuse, such as promotion on illegal underground websites and emerging fraudulent activities related to dialogue features. The security community is not fully aware of these threats yet. We are the first to conduct a large-scale quantitative analysis of ChatGPT-related abusive behavior. We believe that our work unveils the abuse ecosystem surrounding ChatGPT-related squatting domains. We hope to underscore the urgent need for increased attention and protective measures against ChatGPT-related domain abuse. Mingxuan Liu 0006, Zhenglong Jin, Jiahai Yang 0001, Baoiun Liu, Hai-Xin Duan, Ying Liu 0024, Ximeng Liu, Shujun Tang |
DSN | 1 |
| 2024 | Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan |
NDSS | 1 |
| 2024 | Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu 0007, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan, Mingxuan Liu 0006, Ruixuan Li 0008 |
USENIX Security Symposium | 6 |
| 2024 | Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEO
Mingxuan Liu 0006, Baojun Liu 0002, Yiming Zhang 0009, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003 |
USENIX Security Symposium | 2 |
| 2023 | Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the WildabstractCryptocurrency mining is a crucial operation in blockchains, and miners often join mining pools to increase their chances of earning rewards. However, the energy-intensive nature of PoW cryptocurrency mining has led to its ban in New York State of the United States, China, and India. As a result, mining pools, serving as a central hub for mining activities, have become prime targets for regulatory enforcement. Furthermore, cryptojacking malware refers to self-owned stealthy mining pools to evade detection techniques and conceal profit wallet addresses. However, no systematic research has been conducted to analyze it, largely due to a lack of full understanding of the protocol implementation, usage, and port distribution of the stealth mining pool. Zhenrui Zhang, Geng Hong, Xiang Li 0108, Zhuoqun Fu, Jia Zhang 0004, Mingxuan Liu 0006, Chuhan Wang 0001, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Chao Zhang 0008, Min Yang 0002 |
CCS | 6 |
| 2023 | Automatic Generation of Adversarial Readable Chinese TextsabstractNatural language processing (NLP) models are known vulnerable to adversarial examples, similar to image processing models. Studying adversarial texts is an essential step to improve the robustness of NLP models. However, existing studies mainly focus on generating adversarial texts for English, with no prior knowledge that whether those attacks could be applied to Chinese. After analyzing the differences between Chinese and English, we propose a novel adversarial Chinese text generation solution Argot, by utilizing the method for adversarial English examples and several novel methods developed on Chinese characteristics. Argot could effectively and efficiently generate adversarial Chinese texts with good readability in both white-box and black-box settings. Argot could also automatically generatetargetedChinese adversarial texts, achieving a high success rate and ensuring the readability of the generated texts. Furthermore, we apply Argot to the spam detection task in both local detection models and a public toxic content detection system from a well-known security company. Argot achieves a relatively high bypass success rate with fluent readability, which proves that the real-world toxic content detection system is vulnerable to adversarial example attacks. We also evaluate some available defense strategies, and the results indicate that Argot can still achieve high attack success rates. Mingxuan Liu 0006, Yiming Zhang 0009, Chao Zhang 0008, Zhou Li 0001, Qi Li 0002, Hai-Xin Duan, Donghong Sun |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan |
ESORICS (3) | 1 |
| 2022 | ValCAT: Variable-Length Contextualized Adversarial Transformations Using Encoder-Decoder Language ModelabstractChuyun Deng, Mingxuan Liu, Yue Qin, Jia Zhang, Hai-Xin Duan, Donghong Sun. Proceedings of the 2022 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2022. Chuyun Deng, Mingxuan Liu 0006, Jia Zhang 0004, Hai-Xin Duan, Donghong Sun |
NAACL-HLT | 2 |
| 2022 | Encrypted Malware Traffic Detection via Graph-based Network AnalysisabstractMalicious activities on the Internet continue to grow in volume and damage, posing a serious risk to society. Malware with remote control capabilities is considered one of the most threatening malicious activities, as it can enable arbitrary types of cyber-attacks. As a countermeasure, many malware detection methods are proposed to identify malicious behaviours based on traffic characteristics. However, the emerging encryption and evasion techniques pose substantial barriers to the full exploitation of network information. This significantly impairs the effectiveness of existing malware detection methods relying on a singular type of characteristics. In this paper, we propose ST-Graph to resolve this issue. In addition to traditional stream attributes, ST-Graph explores spatial and temporal characteristics of network behaviours based on a graph representation learning algorithm and integrates all available information to boost the detection decision. To illustrate the effectiveness of ST-Graph, we evaluate it on two datasets. Experimental results demonstrate that ST-Graph outperforms state-of-the-art malware detection systems and also shows good performance in efficiency, generalizability, and robustness. Specifically, it achieves over 99% precision and recall, and its False Positive Rate is even two orders of magnitude lower than (nearly 0.02 times) that of baseline models. Meanwhile, the deployment of ST-Graph in two real network scenarios for around one year shows an outstanding efficiency with only 160 seconds time cost for 5-minute traffic in 1.7 Gbps bandwidth. Zhuoqun Fu, Mingxuan Liu 0006, Jia Zhang 0004, Yuan Zou, Qilei Yin, Qi Li 0002, Hai-Xin Duan |
RAID | 2 |
| 2021 | Detecting and Characterizing SMS Spearphishing AttacksabstractAlthough spearphishing is a well-known security issue and has been widely researched, it is still an evolving threat with emerging forms. In recent years, Short Message Service (SMS) has been revealed as a new distribution channel for spearphishing messages, which already has caused a serious impact in the real world, but has not yet attracted enough attention from the academic community. In this paper, we report the first systemic study to spotlight this emerging threat, SMS spearphishing attack. Through cooperating with a leading security vendor, we obtain 31.96M real-world spam messages that span three months. We design and implement a novel NLP-based detection algorithm, and uncover 90,801 spearphishing messages on the entire dataset. And then, a large-scale measurement was performed on the detected messages to reveal and understand the characteristics of SMS spearphishing attack. Our findings are multi-fold. We discover that SMS spearphishing has a significant negative impact on the real-world, and a large number of victims have been affected. And the distribution of active illicit types between spearphishing message and common spam is quite inconsistent. At the micro-level, to evade detection and increase the probability of success, adversary campaigns have evolved a set of sophisticated strategies. Our research highlights the impact of SMS spearphishing attack is prominent. We call on different communities to work together to mitigate this emerging security threat. Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Zhou Li 0001, Hai-Xin Duan, Donghong Sun |
ACSAC | 1 |
| 2020 | Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in ChinaabstractFake base station (FBS) has been exploited by criminals to attack mobile users by spamming fraudulent messages for over a decade. Despite that prior work has proposed several techniques to mitigate this issue, FBS spam is still a long-standing challenging issue in some countries, such as China, and causes billions of dollars of financial loss every year. Therefore, understanding and exploring the thematic strategies in the FBS spam ecosystem at a large scale would improve the defense mechanisms. Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Mingxuan Liu 0006, Ying Liu 0024 |
CCS | 7 |
| 2020 | Argot: Generating Adversarial Readable Chinese TextsabstractNatural language processing (NLP) models are known vulnerable to adversarial examples, similar to image processing models. Studying adversarial texts is an essential step to improve the robustness of NLP models. However, existing studies mainly focus on analyzing English texts and generating adversarial examples for English texts. There is no work studying the possibility and effect of the transformation to another language, e.g, Chinese. In this paper, we analyze the differences between Chinese and English, and explore the methodology to transform the existing English adversarial generation method to Chinese. We propose a novel black-box adversarial Chinese texts generation solution Argot, by utilizing the method for adversarial English samples and several novel methods developed on Chinese characteristics. Argot could effectively and efficiently generate adversarial Chinese texts with good readability. Furthermore, Argot could also automatically generate targeted Chinese adversarial text, achieving a high success rate and ensuring readability of the Chinese. Mingxuan Liu 0006, Chao Zhang 0008, Yiming Zhang 0009, Zhou Li 0001, Qi Li 0002, Hai-Xin Duan, Donghong Sun |
IJCAI | 2 |
| 2019 | Casino royale: a deep exploration of illegal online gamblingabstractThe popularity of online gambling could bring negative social impact, and many countries ban or restrict online gambling. Taking China for example, online gambling violates Chinese laws and hence is illegal. However, illegal online gambling websites are still thriving despite strict restrictions, since they are able to make tremendous illicit profits by trapping and cheating online players. In this paper, we conduct the first deep analysis on illegal online gambling targeting Chinese to unveil its profit chain. After successfully identifying more than 967,954 suspicious illegal gambling websites, we inspect these illegal gambling websites from five aspects, including webpage structure similarity, SEO (Search Engine Optimization) methods, the abuse of Internet infrastructure, third-party online payment, and gambling group. Then we conduct a measurement study on the profit chain of illegal online gambling, investigating the upstream and downstream of these illegal gambling websites. We mainly focus on promotion strategies, third-party online payment, the abuse of third-party live chat services, and network infrastructures. Our findings shed the light on the ecosystem of online gambling and help the security community thwart illegal online gambling. Kun Du, Yubao Zhang, Shuang Hao 0001, Zhou Li 0001, Mingxuan Liu 0006, Haining Wang 0001, Hai-Xin Duan, Yazhou Shi, XiaoDong Su, Zhifeng Geng |
ACSAC | 6 |
| 2019 | TL;DR Hazard: A Comprehensive Study of Levelsquatting Scams
Kun Du, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Yuxiao Ye, Mingxuan Liu 0006, XiaoDong Su, Zhifeng Geng, Zaifeng Zhang, Jinjin Liang |
SecureComm (2) | 8 |