Xuebo Qiu

dblp:325/4833 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
10since 2021 · last 2026
0009-0003-3140-9917ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Improving Region Representation Learning from Urban Imagery with Noisy Long-Caption Supervision
abstract
Region representation learning plays a pivotal role in urban computing by extracting meaningful features from unlabeled urban data. Analogous to how perceived facial age reflects an individual's health, the visual appearance of a city serves as its "portrait", encapsulating latent socio-economic and environmental characteristics. Recent studies have explored leveraging Large Language Models (LLMs) to incorporate textual knowledge into imagery-based urban region representation learning. However, two major challenges remain: i) difficulty in aligning fine-grained visual features with long captions, and ii) suboptimal knowledge incorporation due to noise in LLM-generated captions. To address these issues, we propose a novel pre-training framework called UrbanLN that improves Urban region representation learning through Long-text awareness and Noise suppression. Specifically, we introduce an information-preserved stretching interpolation strategy that aligns long captions with fine-grained visual semantics in complex urban scenes. To effectively mine knowledge from LLM-generated captions and filter out noise, we propose a dual-level optimization strategy. At the data level, a multi-model collaboration pipeline automatically generates diverse and reliable captions without human intervention. At the model level, we employ a momentum-based self-distillation mechanism to generate stable pseudo-targets, facilitating robust cross-modal learning under noisy conditions. Extensive experiments across four real-world cities and various downstream tasks demonstrate the superior performance of our UrbanLN.
Yimei Zhang 0003, Guojiang Shen, Kaili Ning, Tongwei Ren, Xuebo Qiu, Mengmeng Wang 0005, Xiangjie Kong 0001
AAAI5
2026 PG-MoE: Provenance-Based Intrusion Detection via Graph Mixture-of-Experts and Spatio-Temporal Contrastive Learning
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Qijie Song, Tieming Chen
DASFAA (5)1
2026 APT-CGLP: Advanced Persistent Threat Hunting via Contrastive Graph-Language Pre-Training
abstract
Provenance-based threat hunting identifies Advanced Persistent Threats (APTs) on endpoints by correlating attack patterns described in Cyber Threat Intelligence (CTI) with provenance graphs derived from system audit logs. A fundamental challenge in this paradigm lies in the modality gap —the structural and semantic disconnect between provenance graphs and CTI reports. Prior work addresses this by framing threat hunting as a graph matching task: 1) extracting attack graphs from CTI reports, and 2) aligning them with provenance graphs. However, this pipeline incurs severe information loss during graph extraction and demands intensive manual curation, undermining scalability and effectiveness.
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Tieming Chen, Tiantian Zhu 0001, Qijie Song, Shouling Ji
KDD (1)1
2026 ProHunter: A comprehensive APT hunting system based on whole-system provenance
Xuebo Qiu, Mingqi Lv, Tiantian Zhu 0001, Yimei Zhang 0003, Tieming Chen
Comput. Secur.1
2026 UniProv: A unified pretraining framework for provenance graph representation learning
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Qijie Song, Tiantian Zhu 0001, Tieming Chen
Neurocomputing1
2026 Provenance-based advanced persistent threat detection via holistic contrastive learning with heuristic augmentation
Xuebo Qiu, Mingqi Lv, Tiantian Zhu 0001, Qijie Song, Tieming Chen
J. Inf. Secur. Appl.1
2026 Zoomer: An APT TTP Recognition System via Deep & Wide Provenance Graph Learning
abstract
Advanced Persistent Threats (APTs) commonly manifest through a sequence of attack steps, known as Tactics, Techniques, and Procedures (TTPs). Recent studies identify TTPs by converting audit logs into causal provenance graphs and applying expert-driven mappings that correlate low-level system events with high-level TTP patterns. However, these methods face persistent challenges: determining the impact boundaries of TTP activities, adapting to evolving TTP stacks, and recognizing fine-grained TTP semantics for deeper forensic insights. To address these challenges, we presentZoomer, a novel TTP recognition framework that segments provenance graphs into multiple TTP subgraphs with multi-granular annotations (i.e., tactics, techniques, and sub-techniques). First, we devise a heuristic subgraph sampling algorithm guided by anomalous node detection to precisely delineate the scope of TTP activities. Second, we introduce a dual-tower Deep & Wide architecture that integrates contextual behavior semantics from provenance graphs and domain-informed features to learn expressive TTP representations. Finally, we adopt a prototypical network that reformulates TTP recognition as a few-shot pattern matching task, thereby enhancing adaptability and accuracy under limited supervision. To advance future research, we built and released the first TTP-annotated provenance dataset, encompassing the most comprehensive collection of TTP instances to date. Extensive experiments show thatZoomerachieves TTP recognition with 88% accuracy at the sub-technique level and 94% at the tactic level, significantly outperforming state-of-the-art baselines.
Xuebo Qiu, Mingqi Lv, Tieming Chen, Tiantian Zhu 0001, Qijie Song, Zhiling Zhu
IEEE Trans. Dependable Secur. Comput.1
2025 Provenance-Based Intrusion Detection via Multi-scale Graph Representation Learning
Xuebo Qiu, Mingqi Lv, Tieming Chen, Tiantian Zhu 0001, Qijie Song
ICICS (2)1
2025 Kellect: A Kernel-based efficient and lossless event log collector for windows security
Tieming Chen, Qijie Song, Tiantian Zhu 0001, Xuebo Qiu, Zhiling Zhu, Mingqi Lv
Comput. Secur.4
2024 TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning
abstract
APT (Advanced Persistent Threat) with the characteristics of persistence, stealth, and diversity is one of the greatest threats against cyber-infrastructure. As a countermeasure, existing studies leverage provenance graphs to capture the complex relations between system entities in a host for effective APT detection. In addition to detecting single attack events as most existing work does, understanding the tactics / techniques (e.g., Kill-Chain, ATT&CK) applied to organize and accomplish the APT attack campaign is also important for security operations. Existing studies try to manually design a set of rules to map low-level system events to high-level APT tactics / techniques. However, the rule based methods are coarse-grained and lack generalization ability. Thus, they can only recognize APT tactics and have difficulty in identifying APT techniques. They also cannot adapt to mutant behaviors of existing APT tactics / techniques.
Mingqi Lv, Hongzhe Gao, Xuebo Qiu, Tieming Chen, Tiantian Zhu 0001, Jinyin Chen, Shouling Ji
CCS3