VLDB 2026 Research / reviewers in the wild / expert
Haichuan Xu
dblp:268/6595
· DBLP profile ↗
13ranked-venue papers
5as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and Reuse
David Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao, Haichuan Xu, Jeman Park 0001, Amit Kumar Sikder, Brendan Saltaformaggio |
NDSS | 5 |
| 2026 | Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory Forensics
Haichuan Xu, David Oygenblik, Mingxuan Yao, Brendan Saltaformaggio |
SP | 1 |
| 2025 | Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesabstractThe Android accessibility (a11y) service has been widely utilized by malware to abuse benign services.To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites.However, a misalignment of a11y protection mechanisms exists between them.Prior research has focused on attacking and defending a11y information embedded in native Android apps.However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users.To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps.Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views.SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively.The leaked elements contain sensitive personal identifiable information.Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content. Haichuan Xu, Mingxuan Yao, David Oygenblik, Jeman Park 0001, Brendan Saltaformaggio |
CCS | 1 |
| 2025 | Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment Reuse
Mingxuan Yao, Haichuan Xu, Omar Alrawi, Jeman Park 0001, Brendan Saltaformaggio |
NDSS | 3 |
| 2025 | Identifying Incoherent Search Sessions: Search Click Fraud Remediation Under Real-World ConstraintsabstractSearch engines and advertisers continuously suffer substantial financial losses from click fraud, which poses challenges to existing detection algorithms. Even more concerning, despite ongoing advancements, our understanding of click fraud remains limited, leaving room for sophisticated fraudulent techniques to bypass existing detection measures. In this study, we pivot from examining individual search requests to analyzing search sessions, defined as sequences of consecutive search queries made by the same user. We found that benign users exhibit coherent behavior patterns within these sessions, which contrast clearly with those of fraudulent actors. Specifically, legitimate users tend to conduct searches focused on a single topic at a time. In contrast, fraudsters or automated bots often exhibit diverse, illogical, and incoherent search behaviors within a session. To address this behavioral distinction, we propose CoSeC, a system designed to quantify the “incoherence index” of search sessions. CoSeC integrates literal semantic, temporal, and ad-click behavioral features to evaluate sessions' coherence quantitatively. Our evaluation of CoSeC demonstrates high efficacy, achieving a precision of 95.79% and a recall of 92.40% in identifying incoherent sessions, highlighting CoSeC's substantial potential to enhance real-world click fraud detection. Ranjita Pai Sridhar, Mingxuan Yao, David Oygenblik, Haichuan Xu, Vacha Dave, Cormac Herley, Paul England, Brendan Saltaformaggio |
SP | 6 |
| 2025 | Secure bipartite consensus of leader-follower multi-agent systems under denial-of-service attacks via observer-based dynamic event-triggered control
Haichuan Xu, Fanglai Zhu, Xufeng Ling |
Neurocomputing | 1 |
| 2025 | Adaptive Semi-Global Bipartite Average Tracking of Nonlinear Multi-Agent Systems With Input Saturation via Observer-Based ApproachabstractThis paper addresses adaptive semi-global bipartite average tracking (SGBAT) for nonlinear multi-agent systems (MASs) with input saturation under two different low-gain feedback based control protocols via observer-based approach. A state observer and an average signal estimator (ASE) are designed for estimating actual states and obtaining auxiliary outputs. By using the estimated states and the auxiliary outputs, a continuous distributed control protocol is first proposed with adaptive gains. By constructing appropriate Lyapunov function, the adaptive SGBAT can be guaranteed for saturated nonlinear MASs by using low-gain feedback technique. Then, for reducing the communication load, an adaptive dynamic event-triggered control (DETC) protocol is developed with two dynamic event-triggered mechanisms (DETMs). Finally, for verifying the effectiveness of the two control protocols, an application simulation example of multiple satellite systems is displayed. Note to Practitioners—The control of nonlinear MASs with input saturation remains a significant challenge in engineering applications, such as formation of multiple satellite systems, synchronization of robot systems, etc. In practical systems, input saturation can lead to performance degradation if not properly addressed. Meanwhile, considering that actual system states are often unmeasured in these scenarios, further complexity arises. To solve the problem, this paper introduces an adaptive observer-based control protocol with a boundary layer function firstly. However, continuous communication between agents can lead to excessive communication overhead in systems with limited resources. To address this, an observer-based DETC protocol is further developed to reduce the communication load without sacrificing control performance. The proposed control schemes, which account for control inputs constrained by maximum and minimum values, are particularly applicable to scenarios like multiple satellite systems, where utilization rate of communication resources and tracking performance under input saturation are critical. The effectiveness of the control protocols is demonstrated through simulation, showcasing its potential for broader application in similar engineering challenges. Haichuan Xu, Fanglai Zhu |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2025 | SSFold: Learning to Fold Arbitrary Crumpled Cloth Using Graph Dynamics From Human DemonstrationabstractRobotic cloth manipulation poses significant challenges due to the fabric’s complex dynamics and the high dimensionality of configuration spaces. Previous approaches have focused on isolated smoothing or folding tasks and relied heavily on simulations, often struggling to bridge the sim-to-real gap. This gap arises as simulated cloth dynamics fail to capture real-world properties such as elasticity, friction, and occlusions, causing accuracy loss and limited generalization. To tackle these challenges, we propose a two-stream architecture with sequential and spatial pathways, unifying smoothing and folding tasks into a single adaptable policy model. The sequential stream determines pick-and-place positions, while the spatial stream, using a connectivity dynamics model, constructs a visibility graph from partial point cloud data, enabling the model to infer the cloth’s full configuration despite occlusions. To address the sim-to-real gap, we integrate real-world human demonstration data via a hand-tracking detection algorithm, enhancing real-world performance across diverse cloth configurations. Our method, validated on a UR5 robot across six distinct cloth folding tasks, consistently achieves desired folded states from arbitrary crumpled initial configurations, with success rates of 100.0%, 100.0%, 83.3%, 66.7%, 83.3%, and 66.7%. It outperforms state-of-the-art cloth manipulation techniques and generalizes to unseen fabrics with diverse colors, shapes, and stiffness. Project page: https://zcswdt.github.io/SSFold/. Changshi Zhou, Haichuan Xu, Jiarui Hu 0005, Feng Luan, Zhipeng Wang 0006, Yanchao Dong, Yanmin Zhou, Bin He 0003 |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2024 | Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudabstractCriminals, using crypto wallets referred to as Deceptive Creator Wallets (DCWs), have orchestrated fraudulent activities by luring victims to transfer funds to fraud smart contracts. Since it is almost impossible to reverse the transactions or pinpoint the true identity of the criminals, the industry has turned to flagging such contracts as user warnings. However, current mitigation efforts focus on individual contracts, overlooking the DCWs behind the scenes. Consequently, our research found that this oversight allows fraud to thrive. To address this, we developed CoCo, an automated forensic analysis pipeline that processes a single fraud contract and generates evidence that the legal authorities need to mitigate the fraud. Applying CoCo to 157 confirmed fraud contracts, our research uncovered 1,283,198 associated contracts linked to 91 DCWs, responsible for 2,638,752 ETH ($2,089,504,682) in illicit profits. More alarmingly, CoCo traces the fraudulent activities back to September 2017. In response, we are closely collaborating with Etherscan and the FBI to combat the fraud identified in our study. Mingxuan Yao, Haichuan Xu, Shih-Huan Chou, Paturi Varun Chowdhary, Amit Kumar Sikder, Brendan Saltaformaggio |
SP | 3 |
| 2024 | DVa: Extracting Victims and Abuse Vectors from Android Accessibility Malware
Haichuan Xu, Mingxuan Yao, Mohamed Moustafa Dawoud, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 1 |
| 2023 | Observer-Based Dynamic Event-Triggered Semiglobal Bipartite Consensus of Linear Multi-Agent Systems With Input SaturationabstractObserver-based dynamic event-triggered semiglobal bipartite consensus (SGBC) is investigated for linear multi-agent systems (MASs) with input saturation under a competitive network. Based on the estimated relative information and low-gain feedback technology, distributed dynamic event-triggered control (DETC) protocols are proposed for solving the observer-based SGBC problems for MASs under a fixed topology and a jointly connected topology, respectively. It is turned out that the SGBC of MASs can be achieved under the proposed protocols. By using gauge transformation and the Lyapunov theory, the bipartite consensus conditions are obtained. Moreover, Zeno behaviors will be excluded. Finally, two simulation examples are presented to verify the theoretical results efficiently. Chengjie Xu, Haichuan Xu, Zhi-Hong Guan |
IEEE Trans. Cybern. | 2 |
| 2021 | C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationabstractCurrent techniques to monitor botnets towards disruption or takedown are likely to result in inaccurate data gathered about the botnet or be detected by C&C orchestrators. Seeking a covert and scalable solution, we look to an evolving pattern in modern malware that integrates standardized over-permissioned protocols, exposing privileged access to C&C servers. We implement techniques to detect and exploit these protocols from over-permissioned bots toward covert C&C server monitoring. Our empirical study of 200k malware captured since 2006 revealed 62,202 over-permissioned bots (nearly 1 in 3) and 443,905 C&C monitoring capabilities, with a steady increase of over-permissioned protocol use over the last 15 years. Due to their ubiquity, we conclude that even though over-permissioned protocols allow for C&C server infiltration, the efficiency and ease of use they provide continue to make them prevalent in the malware operational landscape. This paper presents C3PO, a pipeline that enables our study and empowers incident responders to automatically identify over-permissioned protocols, infiltration vectors to spoof bot-to-C&C communication, and C&C monitoring capabilities that guide covert monitoring post infiltration. Our findings suggest the over-permissioned protocol weakness provides a scalable approach to covertly monitor C&C servers, which is a fundamental enabler of botnet disruptions and takedowns. Jonathan Fuller 0001, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu, Berat Arik, Ehsan Asdar, Brendan Saltaformaggio |
CCS | 4 |
| 2020 | Disturbance-observer based consensus of linear multi-agent systems with exogenous disturbance under intermittent communication
Chengjie Xu, Haichuan Xu, Housheng Su |
Neurocomputing | 2 |