VLDB 2026 Research / reviewers in the wild / expert
Xiarun Chen
dblp:271/6009
· DBLP profile ↗
10ranked-venue papers
1as first author
9since 2021 · last 2026
0009-0002-1789-4584ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forging the Unknown: Open-Set Deepfake Attribution via Adaptive Fingerprint Learning
Yizhi Fang, Boxuan Han, Xiandang Luo, Siyu Peng, Xiarun Chen, Weiping Wen, Sai Cheng |
ICPR (4) | 6 |
| 2025 | Emotional Text-to-Speech via Style Decoder with Emotion Shared Styleformer Block and RoPE Prior Encoder
Wenhan Yao, Fen Xiao, Xiarun Chen, Weiping Wen |
ICANN (3) | 5 |
| 2025 | Pureformer-VC: Non-parallel Voice Conversion with Pure Stylized Transformer Blocks and Triplet Discriminative TrainingabstractAs a foundational technology for intelligent human-computer interaction, voice conversion (VC) seeks to transform speech from any source timbre into any target timbre. Traditional voice conversion methods based on Generative Adversarial Networks (GANs) encounter significant challenges in precisely encoding diverse speech elements and effectively synthesising these elements into natural-sounding converted speech. To overcome these limitations, we introduce Pureformer-VC, an encoder-decoder framework that utilizes Conformer blocks to build a disentangled encoder and employs Zipformer blocks to create a style transfer decoder. We adopt a variational decoupled training approach to isolate speech components using a Variational Autoencoder (VAE), complemented by triplet discriminative training to enhance the speaker’s discriminative capabilities. Furthermore, we incorporate the Attention Style Transfer Mechanism (ASTM) with Zipformer’s shared weights to improve the style transfer performance in the decoder. We conducted experiments on two multi-speaker datasets. The experimental results demonstrate that the proposed model achieves comparable subjective evaluation scores while significantly enhancing objective metrics compared to existing approaches in many-to-many and many-to-one VC scenarios. Wenhan Yao, Fen Xiao, Xiarun Chen, YongQiang He, Weiping Wen |
IJCNN | 3 |
| 2025 | SPBA: Utilizing Speech Large Language Model for Backdoor Attacks on Speech Classification ModelsabstractDeep speech classification tasks, including keyword spotting and speaker verification, are vital in speech-based human-computer interaction. Recently, the security of these technologies has been revealed to be susceptible to backdoor attacks. Specifically, attackers use noisy disruption triggers and speech element triggers to produce poisoned speech samples that train models to become vulnerable. However, these methods typically create only a limited number of backdoors due to the inherent constraints of the trigger function. In this paper, we propose that speech backdoor attacks can strategically focus on speech elements such as timbre and emotion, leveraging the Speech Large Language Model (SLLM) to generate diverse triggers. Increasing the number of triggers may disproportionately elevate the poisoning rate, resulting in higher attack costs and a lower success rate per trigger. We introduce the Multiple Gradient Descent Algorithm (MGDA) as a mitigation strategy to address this challenge. The proposed attack is called the Speech Prompt Backdoor Attack (SPBA). Building on this foundation, we conducted attack experiments on two speech classification tasks, demonstrating that SPBA shows significant trigger effectiveness and achieves exceptional performance in attack metrics. Wenhan Yao, Fen Xiao, Xiarun Chen, YongQiang He, Weiping Wen |
IJCNN | 3 |
| 2025 | LFBA: Latent-Space Frame-Level Backdoor Attacks on Keyword Spotting SystemsabstractModern deep learning models increasingly rely on third-party data processing, exposing vulnerabilities to backdoor attacks. Existing audio backdoor methods often compromise stealthiness by introducing perceptible modifications. This paper proposes Latent-space Frame-level Backdoor Attacks (LFBA), a novel framework that manipulates frame-level features in latent space to achieve imperceptible and effective backdoor injection. Our approach extracts and transforms frame-level features to subtly alter rhythmic patterns, such as compressing or expanding temporal segments, without modifying semantic content or speaker characteristics. Evaluations demonstrate excellent attack effectiveness while maintaining near-original audio quality. Our attack evades human perception and automated detection, maintaining robustness even after defensive fine-tuning. This work reveals critical risks in outsourced speech model training and establishes a new paradigm for stealthy, latent-space poisoning in speech-controlled systems. Wenhan Yao, Jinsu Yang, Zedong Xing, Xiarun Chen, Fen Xiao, Weiping Wen |
SMC | 6 |
| 2025 | DynamicFuzz: Confidence-based directed greybox fuzzing for programs with unreliable call graphs
Hao Jiang 0038, Xiarun Chen, Weiping Wen |
Comput. Secur. | 7 |
| 2023 | Finding Missing Security Operation Bugs via Program Slicing and Differential Check
Yeqi Fu, Yongzhi Liu, Xiarun Chen, Chenglin Xie, Weiping Wen |
ICICS | 5 |
| 2021 | VulChecker: Achieving More Effective Taint Analysis by Identifying Sanitizers AutomaticallyabstractThe automatic detection of vulnerabilities in Web applications using taint analysis is a hot topic. However, existing taint analysis methods for sanitizers identification are too simple to find available taint transmission chains effectively. These methods generally use pre-constructed dictionaries or simple keywords to identify, which usually suffer from large false positives and false negatives. No doubt, it will have a greater impact on the final result of the taint analysis. To solve that, we summarise and classify the commonly used sanitizers in Web applications and propose an identification method based on semantic analysis. Our method can accurately and completely identify the sanitizers in the target Web applications through static analysis. Specifically, we analyse the natural semantics and program semantics of existing sanitizers, use semantic analysis to find more in Web applications. Besides, we implemented the method prototype in PHP and achieved a vulnerability detection tool called VulChecker. Then, we experimented with some popular open-source CMS frameworks. The results show that Vulchecker can accurately identify more sanitizers. In terms of vulnerability detection, VulChecker also has a lower false positive rate and a higher detection rate than existing methods. Finally, we used VulChecker to analyse the latest PHP applications. We identified several new suspicious taint data propagation chains. Before the paper was completed, we have identified four unreported vulnerabilities. In general, these results show that our approach is highly effective in improving vulnerability detection based on taint analysis. Xiarun Chen, Qien Li, Yongzhi Liu, Shaosen Shi, Chenglin Xie, Weiping Wen |
TrustCom | 1 |
| 2021 | EnvFaker: A Method to Reinforce Linux Sandbox Based on Tracer, Filter and Emulator against Environmental-Sensitive MalwareabstractSandbox is an excellent tool for dynamic malware analysis. However, the sandbox detection techniques are increasingly adopted to develop malwares, which has been a significant threat to sandbox analysis. These malwares can detect the running environment and show different behaviors in corresponding environments. So far, there have been several studies about countermeasures, but most of them concentrate on Windows OS. Environmental features in Linux sandbox have not been summarized yet. Besides, existing popular sandboxes can hardly combat against sandbox detecting techniques. In this paper, we focus on Linux sandbox. We firstly propose Linux environmental features from six aspects and implement an effective tool to collect features from running environment to tell the discrepancy among physical machine, virtual machine and sandbox. More importantly, we present EnvFaker, an effective method to reinforce Linux sandbox against environmental-sensitive malware. This method uses tracer to track child process and injected process, filters to intercept sandbox detecting behaviors, and emulator to disguise wear-and-tear and network environment. The experimental results further demonstrate that our method is effective against detecting techniques for Linux sandbox. Chenglin Xie, Shaosen Shi, Yu Sheng, Xiarun Chen, Weiping Wen |
TrustCom | 5 |
| 2020 | CDN Backfired: Amplification Attacks Based on HTTP Range RequestsabstractContent Delivery Networks (CDNs) aim to improve network performance and protect against web attack traffic for their hosting websites. And the HTTP range request mechanism is majorly designed to reduce unnecessary network transmission. However, we find the specifications failed to consider the security risks introduced when CDNs meet range requests. In this study, we present a novel class of HTTP amplification attack, Range-based Amplification (RangeAmp) Attacks. It allows attackers to massively exhaust not only the outgoing bandwidth of the origin servers deployed behind CDNs but also the bandwidth of CDN surrogate nodes. We examined the RangeAmp attacks on 13 popular CDNs to evaluate the feasibility and real-world impacts. Our experiment results show that all these CDNs are affected by the RangeAmp attacks. We also disclosed all security issues to affected CDN vendors and already received positive feedback from 12 vendors. Kaiwen Shen, Run Guo, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Shuang Hao 0001, Xiarun Chen |
DSN | 8 |