Shiwen Song

dblp:312/9461 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0009-0008-7885-1135ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 54% Malware analysis · 46%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis › mobile malware detection
android malware detection
1.012026
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection · IEEE Trans. Software Eng. 2026
Malware analysis › malware detection
malicious package detection
1.012026
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages · WWW 2026
Systems and software security
software supply chain security
1.012026
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages · WWW 2026
Systems and software security
vulnerability discovery
0.312026
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages · WWW 2026

Methods — techniques the papers use, named apart from their topics

retrieval-augmented generation · 1.0multi-objective feedback · 1.0large language model · 1.0knowledge base · 1.0dependency-aware crossover and mutation · 1.0
YearPublicationVenuePosition
2026 Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
abstract
Open-source ecosystems such as NPM and PyPI are increasingly targeted by supply chain attacks, yet existing detection methods either depend on fragile handcrafted rules or data-driven features that fail to capture evolving attack semantics. We present IntelGuard, a retrieval-augmented generation (RAG) based framework that integrates expert analytical reasoning into automated malicious package detection. IntelGuard constructs a structured knowledge base from over 8,000 threat intelligence reports, linking malicious code snippets with behavioral descriptions and expert reasoning. When analyzing new packages, it retrieves semantically similar malicious examples and applies LLM-guided reasoning to assess whether code behaviors align with intended functionality. Experiments on 4,027 real-world packages show that IntelGuard achieves 99% accuracy and a 0.50% false positive rate, while maintaining 96.5% accuracy on obfuscated code. Deployed on PyPI.org, it discovered 54 previously unreported malicious packages, demonstrating interpretable and robust detection guided by expert knowledge.
Wenbo Guo 0011, Shiwen Song, Jiaxun Guo, Zhengzi Xu, Haoran Ou, Mengmeng Ge 0003, Yang Liu 0003
WWW2
2026 FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
abstract
Graph-based detection methods leveraging Function Call Graph (FCG) have shown promise for Android malware detection (AMD) due to their semantic insights. However, the deployment of malware detectors in dynamic and hostile environments raises significant concerns about their robustness. While recent approaches evaluate the robustness of FCG-based detectors using adversarial attacks, their effectiveness is constrained by the vast perturbation space, particularly across diverse models and features. To address these challenges, we introduce FCGHUNTER, a novel robustness testing framework for FCG-based AMD systems. Specifically, FCGHUNTER employs innovative techniques to enhanceexplorationandexploitationwithin this huge search space. Initially, it identifies critical areas within the FCG related to malware behaviors to narrow down the perturbation space. We then develop a dependency-aware crossover and mutation method to enhance thevalidityanddiversityof perturbations, generating diverse FCGs. Furthermore, FCGHUNTER leverages multi-objective feedback to select perturbed FCGs, significantly improving the search process with interpretation-based feature change feedback. Extensive evaluations across 40 scenarios demonstrate that FCGHUNTER achieves an average attack success rate of 87.9%, significantly outperforming baselines by at least 40.9%. Notably, FCGHUNTER achieves a 100% success rate on robust models (e.g., AdaBoost with MalScan), where baselines achieve less than 24% or are inapplicable.
Shiwen Song, Xiaofei Xie, Sen Chen 0001
IEEE Trans. Software Eng.1
2021 Visible Forensic Investigation for Android Applications by Using Attack Scenario Reconstruction
abstract
With the widespread use of Android devices, research on their security has attracted increasing attention. However, at present, digital forensics for investigating attacks, such as social engineering attacks and phishing that target Android users, remains a challenging and time-consuming task. To help discover the existence of an attack and conduct effective investigations, we propose a top-down digital forensic tool for Android applications to reconstruct attack scenarios by considering both high-level user interface (UI) elements and low-level system events. Thus, we can explain the nature of an attack from a visual and global perspective. The tested evaluation results show that our tool can successfully reconstruct scenarios on Android devices for phishing attacks.
Shiwen Song, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM1