VLDB 2026 Research / reviewers in the wild / expert
Kefan Qiu
dblp:254/7430
· DBLP profile ↗
11ranked-venue papers
0as first author
8since 2021 · last 2025
0000-0001-7816-8258ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 5 since 2021Security and privacy · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Density Boosts Everything: A One-stop Strategy for Improving Performance, Robustness, and Sustainability of Malware Detectors
Jianwen Tian, Debin Gao, Taotao Gu, Kefan Qiu, Zhi Wang 0014, Xiaohui Kuang |
NDSS | 6 |
| 2025 | StreamForest: Efficient Online Video Understanding with Persistent Event MemoryabstractMultimodal Large Language Models (MLLMs) have recently achieved remarkable progress in video understanding. However, their effectiveness in real-time streaming scenarios remains limited due to storage constraints of historical visual features and insufficient real-time spatiotemporal reasoning. To address these challenges, we propose StreamForest, a novel architecture specifically designed for streaming video understanding. Central to StreamForest is the Persistent Event Memory Forest, a memory mechanism that adaptively organizes video frames into multiple event-level tree structures. This process is guided by penalty functions based on temporal distance, content similarity, and merge frequency, enabling efficient long-term memory retention under limited computational resources. To enhance real-time perception, we introduce a Fine-grained Spatiotemporal Window, which captures detailed short-term visual cues to improve current scene perception. Additionally, we present OnlineIT, an instruction-tuning dataset tailored for streaming video tasks. OnlineIT significantly boosts MLLM performance in both real-time perception and future prediction. To evaluate generalization in practical applications, we introduce ODV-Bench, a new benchmark focused on real-time streaming video understanding in autonomous driving scenarios. Experimental results demonstrate that StreamForest achieves the state-of-the-art performance, with accuracies of 77.3% on StreamingBench, 60.5% on OVBench, and 55.6% on OVO-Bench. In particular, even under extreme visual token compression (limited to 1024 tokens), the model retains 96.8% of its average accuracy in eight benchmarks relative to the default setting. These results underscore the robustness, efficiency, and generalizability of StreamForest for streaming video understanding. Xiangyu Zeng 0004, Kefan Qiu, Xinhao Li 0004, Ziang Yan, Xinhai Zhao, Yi Wang 0074, Limin Wang 0002 |
NeurIPS | 2 |
| 2024 | Bypassing software-based remote attestation using debug registersabstractRemote attestation (RA) is an essential feature in many security protocols to verify the memory integrity of remote embedded devices susceptible to malware infections.The attestation process needs to be consecutive and atomic to prevent a self-relocating malware from evading detection.Most of the prior attestation techniques disable interrupts during execution to prevent another process from interrupting the integrity check.This paper investigates the shortcomings of existing software-based attestation techniques and stresses the threat of debug exceptions to existing software-based attestation.We present Debug Register-based Self-relocating Attack (DRSA), a novel self-relocating malware against software-based attestation based on debug registers.DRSA gains control of the checksum function by raising debug exceptions and erasing itself before the next attestation.We further implement DRSA on commodity OSes and validate its effectiveness based on two existing software-based proposals.Our evaluation demonstrates that DRSA incurs low overhead, and it is extremely difficult for the verifier to detect it.can bypass the attestation with very little attack overhead. Zheng Zhang 0060, Jingfeng Xue, Tianshi Mu, Kefan Qiu, Yuanzhang Li 0001 |
Connect. Sci. | 5 |
| 2023 | Sparsity Brings Vulnerabilities: Exploring New Metrics in Backdoor Attacks
Jianwen Tian, Kefan Qiu, Debin Gao, Zhi Wang 0014, Xiaohui Kuang |
USENIX Security Symposium | 2 |
| 2023 | Microservice combination optimisation based on improved gray wolf algorithmabstractMicroservices architecture is a new paradigm for application development.The problem of optimising the performance of microservice architectures from a non-functional perspective is a typical Nondeterministic Polynomial (NP) problem.Therefore, aiming to quantify the non-functional requirements of computing microservice systems, while solving the problem of latency in computing the best combination of services with the maximum QoS objective function value, this paper proposes a microservice combination approach based on the QoS model and a CGWO algorithm for optimisation computation for this model.The experimental results verify that the error rate of the method is only 0.528% on the non-functional combination optimisation problem, and the computational efficiency of the algorithm increases by 97.29% when the complexity of the problem search space increases, while CGWO improves 65.97% and 81.25% respectively in the accuracy of optimisation compared to the prototype of the algorithm (GWO), and has a stable optimisation performance, aspect.It proves that the research in this paper has a high advantage in automatically searching for the best QoS for the microservice combination problem. Xiaojun Xu 0001, Jin Hao, Xiuqi Yang, Kefan Qiu, Yuanzhang Li 0001 |
Connect. Sci. | 5 |
| 2022 | Towards robust and stealthy communication for wireless intelligent terminalsabstractFifth-generation (5G) wireless systems provide an opportunity for improving the existing Voice over Internet Protocol communication service's user experience. To mitigate the security risk of 5G data leakage, building covert channel is an alternative approach of providing confidential data transmission. Due to the high transmission rate of 5G, the interpacket intervals become small and derandomized, this caused the encoding phase of the covert timing channel imports relatively large modulation errors. rearranging is a widespread phenomenon that is occurred over the data communications. In this paper, we propose a rearrangement covert channel approach named Hybrid Variable-length Packet Rearrangement Covert Timing Channel (HVPR-CTC), which artificially chooses the delimiter packets and identification (ID) packets from the overt traffics, and encodes the packet sending order between adjacent delimiter packets according to a generated hybrid variable-length codeword dictionary, and embeds the secret message by rearranging the sending order of the ID packets. The experiments demonstrate that the HVPR-CTC scheme can effectively perform strategy adjustment: its minimum Location Square Deviation is 0.832 and minimum Swap Deviation is 139. the maximum throughput reaches 14.37 bps, and the optimal Bit Error Rate is 3.27% and 9.70% for low-channel noise and high-channel noise communication conditions, respectively. Kefan Qiu, Zheng Zhang 0060, Yuanzhang Li 0001 |
Int. J. Intell. Syst. | 2 |
| 2022 | Hybrid isolation model for device application sandboxing deployment in Zero Trust architectureabstractWith recent cyber security attacks, the “border defense” security protection mechanism has often penetrated and broken through, and the “borderless” security defense idea—Zero Trust was proposed. The device application sandbox deployment model is one of the four essential Zero Trust architecture device deployment models. The isolation of the application sandbox directly affects the security of trusted applications. Given the security risks, such as sandbox escape in the sandbox application, we propose a hybrid isolation model based on access behavior and give the formal definition and security characteristics of the model. The model dynamically determines the security identity of the subject according to the access behavior and controls the access operation of the application sandbox. Therefore, the sandbox meets the characteristics of autonomous security, domain isolation, and integrity, ensuring that the system is always in an isolated safe state and easy to use. Finally, we implement the security model based on the container and Linux security module, and test the network and disk performance of this model. What is more, we make security comparison experiments based on the same container escape vulnerability. The experimental results show that the security model proposed in this paper effectively enhances the security of the device application sandboxing deployment model in Zero Trust architecture, and has a better performance compared with Container-SELinux. Jingci Zhang, Jun Zheng 0007, Zheng Zhang 0060, Kefan Qiu, Quanxin Zhang 0001, Yuanzhang Li 0001 |
Int. J. Intell. Syst. | 5 |
| 2021 | Deep-Learning-Based App Sensitive Behavior Surveillance for Android Powered Cyber-Physical SystemsabstractAndroid as an operating system is now increasingly being adopted in industrial information systems, especially with cyber-physical systems (CPS). This also puts Android devices onto the front line of handling security-related data and conducting sensitive behaviors, which could be misused by the increasing number of polymorphic and metamorphic malicious applications targeting the platform. The existence of such malware threats, therefore, call for more accurate identification and surveillance of sensitive Android app behaviors, which is essential to the security of CPS and Internet of Things (IoT) devices powered by Android. Nevertheless, achieving dynamic app behavior monitoring and identification on real CPS powered by Android is challenging because of restrictions from the security and privacy model of the platform. In this article, the authors investigate how the latest advances in deep learning could address this security problem with better accuracy. Specifically, a deep learning engine is proposed that detects sensitive app behaviors by classifying patterns of system-wide statistics, such as available storage space and transmitted packet volume, using a customized deep neural network based on existing models called Encoder and ResNet. Meanwhile, to handle resource limitations on typical CPS and IoT devices, sparse learning is adopted to reduce the amount of valid parameters in the trained neural network. Evaluations show that the proposed model outperforms a well-established group of baselines on time series classification in identifying sensitive app behaviors with background noise and the targeted behaviors potentially overlapping. Jianwen Tian, Kefan Qiu, David Lo 0001, Debin Gao, Daoyuan Wu, Chunfu Jia, Thar Baker |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | AttriChain: Decentralized traceable anonymous identities in privacy-preserving permissioned blockchain
Chunfu Jia, Yunkai Xu, Kefan Qiu, Yituo He |
Comput. Secur. | 4 |
| 2020 | LSC: Online auto-update smart contracts for fortifying blockchain-based log systems
Zhi Wang 0014, Kefan Qiu, Chunfu Jia |
Inf. Sci. | 4 |
| 2020 | BMOP: Bidirectional Universal Adversarial Learning for Binary OpCode FeaturesabstractFor malware detection, current state-of-the-art research concentrates on machine learning techniques. Binary n -gram OpCode features are commonly used for malicious code identification and classification with high accuracy. Binary OpCode modification is much more difficult than modification of image pixels. Traditional adversarial perturbation methods could not be applied on OpCode directly. In this paper, we propose a bidirectional universal adversarial learning method for effective binary OpCode perturbation from both benign and malicious perspectives. Benign features are those OpCodes that represent benign behaviours, while malicious features are OpCodes for malicious behaviours. From a large dataset of benign and malicious binary applications, we select the most significant benign and malicious OpCode features based on the feature SHAP value in the trained machine learning model. We implement an OpCode modification method that insert benign OpCodes into executables as garbage codes without execution and modify malicious OpCodes by equivalent replacement preserving execution semantics. The experimental results show that the benign and malicious OpCode perturbation (BMOP) method could bypass malicious code detection models based on the SVM, XGBoost, and DNN algorithms. Xiang Li 0078, Yuanping Nie, Zhi Wang 0014, Xiaohui Kuang, Kefan Qiu |
Wirel. Commun. Mob. Comput. | 5 |