VLDB 2026 Research / reviewers in the wild / expert
Zhiling Zhu
dblp:321/8700
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Zoomer: An APT TTP Recognition System via Deep & Wide Provenance Graph LearningabstractAdvanced Persistent Threats (APTs) commonly manifest through a sequence of attack steps, known as Tactics, Techniques, and Procedures (TTPs). Recent studies identify TTPs by converting audit logs into causal provenance graphs and applying expert-driven mappings that correlate low-level system events with high-level TTP patterns. However, these methods face persistent challenges: determining the impact boundaries of TTP activities, adapting to evolving TTP stacks, and recognizing fine-grained TTP semantics for deeper forensic insights. To address these challenges, we presentZoomer, a novel TTP recognition framework that segments provenance graphs into multiple TTP subgraphs with multi-granular annotations (i.e., tactics, techniques, and sub-techniques). First, we devise a heuristic subgraph sampling algorithm guided by anomalous node detection to precisely delineate the scope of TTP activities. Second, we introduce a dual-tower Deep & Wide architecture that integrates contextual behavior semantics from provenance graphs and domain-informed features to learn expressive TTP representations. Finally, we adopt a prototypical network that reformulates TTP recognition as a few-shot pattern matching task, thereby enhancing adaptability and accuracy under limited supervision. To advance future research, we built and released the first TTP-annotated provenance dataset, encompassing the most comprehensive collection of TTP instances to date. Extensive experiments show thatZoomerachieves TTP recognition with 88% accuracy at the sub-technique level and 94% at the tactic level, significantly outperforming state-of-the-art baselines. Xuebo Qiu, Mingqi Lv, Tieming Chen, Tiantian Zhu 0001, Qijie Song, Zhiling Zhu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | DockInsight: A Knowledge-Augmented Dependency Extraction Approach for DockerfileabstractDevOps enhances software production through IT automation, continuous integration, and deployment, with Docker as a key tool that packages applications and their environments into standardized images for consistent and efficient deployment. Dockerfiles, which are text-based configuration files, define the composition and runtime actions of these images. Mismanagement of dependencies between Dockerfile instructions can cause build failures, highlighting the need for accurate dependency parsing. Current methods often miss implicit dependencies due to the complex syntax and logic of Dockerfile instructions. To address this, we propose DockInsight, a novel tool that uses a rule-based approach and semantic analysis to determine Dockerfile dependencies accurately. DockInsight features a unified feature structure representation, DVector, and a dependency type table to facilitate precise dependency determination. Evaluations demonstrate that DockInsight achieves 99.44% accuracy, significantly outperforming keyword matching and large language model methods by 64.84% and 55.74%, respectively. Additionally, DockInsight maintains stable processing times across various Dockerfile lengths, proving its efficiency and scalability. Our ablation study further highlights the importance of semantic information supplementation, particularly for RUN instructions, in enhancing accuracy. DockInsight’s robust performance makes it a valuable tool for developers and DevOps engineers, contributing to more reliable and maintainable Dockerfiles. Zhiling Zhu, Tieming Chen, Yunjin Zhong, Qijie Song |
ICSR | 1 |
| 2025 | Kellect: A Kernel-based efficient and lossless event log collector for windows security
Tieming Chen, Qijie Song, Tiantian Zhu 0001, Xuebo Qiu, Zhiling Zhu, Mingqi Lv |
Comput. Secur. | 5 |
| 2025 | A Joint Learning Framework for Bridging Defect Prediction and InterpretationabstractUnderstanding why defect predictors classify software components as defective or clean is essential for software engineers that helps identify the root causes of defects and develop actionable bug-fixing plans. Existing solutions employ various explainable artificial intelligence methods to clarify the decision-making processes of defect predictors. However, these post hoc explanation techniques have two main limitations: first, the interpretation results do not accurately reflect the model’s decision logic, and second, they do not contribute to improving the performance of defect predictors. To address these limitations, we treat defect prediction and its corresponding interpretation as two distinct but closely related tasks, proposing a joint learning framework that trains the predictor and its interpreter simultaneously. The novelty of our approach lies in two main aspects: first, we design a feedback loop that transfers decision logic from the predictor to the interpreter, ensuring a high degree of conciseness for both components. Second, we incorporate interpretation results as a penalty term in the loss function of the joint learning framework. This not only enhances the accuracy of the predictor but also proposes a stronger constraint on the reliability of the interpreter. We validate our method against several existing explainable software defect predictors across multiple datasets. The results demonstrate its effectiveness. Guifang Xu, Chengbin Feng, Xingcheng Guo, Zhiling Zhu, Wei Wang 0390 |
IEEE Trans. Reliab. | 4 |
| 2024 | ThreatResponder: Dynamic Markov-Based Defense Mechanism for Real-Time Cyber Threats
Zhiling Zhu, Tieming Chen, Qijie Song, Yiheng Lu, Yulin Zheng |
ICDF2C (2) | 1 |
| 2024 | DocSecKG: A Systematic Approach for Building Knowledge Graph to Understand the Relationship Between Docker Image and Vulnerability
Zhiling Zhu, Tieming Chen, Haobin Kong, Yunjin Zhong, Qijie Song |
ICIC (13) | 1 |
| 2024 | The Software Genome Project: Unraveling Software Through Genetic PrinciplesabstractOpen-source software is crucial to modern development, but its complexity creates challenges in quality, security, and management. Current governance approaches excel at collaboration but struggle with decentralized management and security. With the rise of large language models (LLM)-based software engineering, the need for a finer-grained understanding of software composition is more urgent than ever. To address these challenges, inspired by the Human Genome Project, we treat the software source code as software DNA and propose the Software Genome Project (SGP), which is geared towards the secure monitoring and exploitation of open-source software. By identifying and labeling integrated and classified code features at a fine-grained level, and effectively identifying safeguards for functional implementations and nonfunctional requirements at different levels of granularity, the SGP could build a comprehensive set of software genome maps to help developers and managers gain a deeper understanding of software complexity and diversity. By dissecting and summarizing functional and undesirable genes, SGP could help facilitate targeted software optimization, provide valuable insight and understanding of the entire software ecosystem, and support critical development tasks such as open source governance. SGP could also serve as a comprehensive dataset with abundant semantic labeling to enhance the training of LLMs for code. Based on these, we expect SGP to drive the evolution of software development towards more efficient, reliable, and sustainable software solutions. Yueming Wu 0001, Zhengzi Xu, Lyuye Zhang, Zhiling Zhu, Yang Liu 0003 |
ASE | 6 |
| 2024 | CoreCast: Leveraging Project Metrics to Predict Core Contributor Trends in Open Source C57abstractThe collaborative model of open-source software (OSS) development significantly enhances efficiency and fosters innovation by enabling diverse global contributors to collaborate seamlessly.Core contributors, who provide the majority of code commits, are crucial for maintaining project direction, quality, and momentum.Despite their importance, there is limited research on the dynamics and prediction of changes in core contributors over time, which is essential for sustaining project growth and stability.To bridge this gap, we introduce CoreCast, an innovative predictive model designed to forecast future core contributor numbers using comprehensive project data.By analyzing multidimensional metrics from high-quality OSS projects, CoreCast trains models that outperform traditional methods, achieving a mean absolute error (MAE) of 0.7866.Our findings reveal seven significant growth trends that are crucial for understanding and sustaining OSS project development.All data and scripts are open-sourced, providing valuable resources for future research and further advancements in the field. Zhiling Zhu, Tieming Chen, Lizi Wu, Qijie Song |
SEKE | 1 |