VLDB 2026 Research / reviewers in the wild / expert
Hanbo Yu
dblp:287/6984
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-6680-7240ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security risk assessment of android automotive OS software supply chain using firmware reverse engineeringabstractAs Android Automotive OS (AAOS) becomes the in-vehicle platform of choice for infotainment and domain-controller functions in modern passenger cars, its software supply chain has emerged as a critical security frontier. AAOS spans both infotainment and vehicle-control domains within the automotive electronics architecture by supporting media streaming, over-the-air updates, navigation, and sensor fusion. Its open-source foundations and reliance on third-party libraries introduce risks, from outdated components to malicious modules, that can undermine vehicle functionality and passenger safety. In recognition of these threats, ISO/SAE 21434 and UNECE WP.29 R155 mandate structured security assessments for vehicular systems to prevent software-chain vulnerabilities from compromising safety. In this study, we apply a shift-right security analysis via firmware reverse engineering to AAOS images from four leading OEMs. We unpack each firmware image, extract software bills of materials (SBOMs), map Common Vulnerabilities and Exposures (CVE) to components, and characterize system-level attack surfaces across infotainment and control subsystems. Proof-of-concept exploits were developed for high-risk vulnerabilities. One critical CVE was successfully triggered, while others were mitigated by missing dependencies or built-in protections. Our work delivers a reproducible firmware-analysis workflow for automotive supply-chain risk assessment, a comparative survey of third-party and proprietary component management, and the evidence of inconsistent security postures in AAOS-based vehicular electronics. These vulnerabilities underscore the need for harmonized SBOM practices and targeted hardening in next-generation in-vehicle systems. Hanbo Yu, Faiyaz Khan, Steven H. H. Ding, Natalia Stakhanova, Benjamin C. M. Fung |
Comput. Secur. | 1 |
| 2025 | ProvSpider: A Robust and Universal Toolkit for Binary Provenance Analysis Using Deep LearningabstractBinary provenance analysis recovers essential information, such as architecture, structure, and toolchain, from executables lacking reliable metadata. This is crucial for reverse engineering. However, provenance recovery from binaries is highly challenging, due to three key factors: (1) binaries span diverse CPU architectures; (2) Raw byte sequences are often extremely long without clear boundaries; and (3) Compilation alters control flow, register usage, and memory layout, obscuring the original code structure and complicating analysis. To address these challenges, we propose a novel and robust analysis toolset, namely ProvSpider, to identify segment boundaries, types of segments as well as target CPU architectures, bitness, and endianness based on code-only sections. ProvSpider is built based on a convolutional neural network (CNN) to learn local execution patterns. We embed byte sequences into eight-dimensional vectors to capture bytes’ global dependencies. The gating mechanism after convolutional layers filters out noise and keeps most representative features. At last, the sliding window divides lengthy byte sequences into fixedlength processable chunks. Our model achieves high accuracy in all five analysis tasks, significantly outperforming the state-of-the-art models. By providing a universal and robust approach, ProvSpider lays the foundation for advancing binary provenance analysis, facilitating future improvements in binary analysis and reverse engineering. Zhiwei Fu, Hanbo Yu, Steven H. H. Ding, Furkan Alaca, Philippe Charland |
NCA | 2 |
| 2025 | PulseAnomaly: Unsupervised Anomaly Detection on Avionic Platforms With Seasonality and Trend Modeling in Transformer NetworksabstractFor communication within military avionic platforms (e.g., F-15 and F-35), the US Department of Defense established MIL-STD-1553 military standard. It has been released for more than 50 years and is still used in platforms other than military avionics. It was originally produced to be used with military avionics, but in the following decades, it was adopted into all branches of the armed forces, as well as spacecraft and commercial avionics. However, potential attacks against the MIL-STD-1553 may exist due to the demand for internet communication between planes and the lack of security. The current study presentsPulseAnomaly, a novel unsupervised anomaly detection model for the MIL-STD-1553 bus that utilizes time-feature and message sequences. Our model demonstrates better performance compared to baseline models in the test, achieving a higher F1-score and showing excellent AUROC compared to existing methods. Additionally, we have used data from a recently developed open-source MIL-STD-1553 real-time bus simulator, which features a more diverse range of attacks and data points that more closely resemble real-world scenarios. Evaluation results show that our model outperforms existing unsupervised solutions. Hanbo Yu, Sudipta Acharya, Steven H. H. Ding, Mohammad Zulkernine |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | TDRLM: Stylometric learning for authorship verification by Topic-Debiasing
Weihan Ou, Sudipta Acharya, Steven H. H. Ding, Ryan D'Gama, Hanbo Yu |
Expert Syst. Appl. | 6 |