VLDB 2026 Research / reviewers in the wild / expert
Xiaorui Gong
dblp:33/10782
· DBLP profile ↗
37ranked-venue papers
1as first author
24since 2021 · last 2026
0009-0005-8203-1496ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 13 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Regularity of the Generalized Birthday Problem
Lili Tang, Xiaorui Gong |
CRYPTO (6) | 3 |
| 2026 | BACHunter: An Automated Fuzzing Framework for Discovering Broken Access Control Vulnerabilities in Java Web Applications
Xiaorui Gong |
ICIC (11) | 2 |
| 2026 | FAVDisco: Modeling and Discovering File Access VulnerabilitiesabstractFile access vulnerabilities (FAVs) are one type of security weakness arising from adversary manipulations of file access inputs, posing significant threats to system integrity. Despite their prevalence, FAVs remain underexplored due to limited understanding, complex triggering scenarios, and stealthy and diverse manifestations; these challenges render current detection approaches incomplete and inaccurate. To this end, we conducted an in-depth empirical study across 204 file-related CVEs, uncovering the root cause and trigger mechanisms of FAVs. Based on these findings, we propose an exhaustive accessing model and a specialized threat model that define the adversary and attack surface for FAVs, enabling systematic attribution and analysis of file operations. Furthermore, we propose FAVDisco , a novel framework for discovering FAVs by mutating, triggering, and analyzing file operations. It employs a File Mutator to simulate diverse execution scenarios and an FAV Checker that integrates a model-based adversary controllable checker with pattern-based detection rules to identify FAVs. Implemented on Windows, FAVDisco achieves remarkable performance with 92.1% precision and 83.3% recall on the disclosed FAV detection task, outperforming state-of-the-art methods. Moreover, it uncovers 13 zero-day FAVs in 10 widely used services, with six assigned new CVEs and earning a reward of $29,000 from Microsoft Security Response Center. Beibei Zhao, Wenjie Feng 0001, Qingli Guo, Yingli Sun, Fangming Gu, Xiaorui Gong, Hong Li 0004 |
ACM Trans. Softw. Eng. Methodol. | 7 |
| 2025 | Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields
Jian Liu 0008, Jie Lu 0009, Shaomin Chen, Tianshuo Han, Xiaorui Gong |
CCS | 7 |
| 2025 | SCMDetector: Smart Contract Malicious Detection Technique based on GLM and ABLSTM-AabstractExisting static detection methods often fail to cap-ture dynamic interactions in smart contracts, resulting in low detection accuracy. Noise from irrelevant data can also affect the precision of vulnerability detection. This paper introduces a new method for detecting malicious smart contracts-GLM-ABLSTM-A, which integrates a General Language Model (GLM) with an Attention-based Long Short-Term Memory (ABLSTM) network. The method aims to address the limitations of static detection techniques, such as low accuracy and limited practicality, focusing on the interactivity and collaboration of smart contract systems. It compiles malicious contract code into Java and labels it, then preprocesses the code with GLM to ex-tract relevant textual information, reducing noise in the detection process. Finally, the extracted feature vectors are fed into the ABLSTM-A classifier. This technique introduces a feature extraction framework based on GLM, combined with the ABLSTM-A classifier, which enhances both the accuracy and efficiency of malicious contract detection and improves the in-teractivity and adaptability of the detection system. Jingyu Huang, Xiaorui Gong |
CSCWD | 2 |
| 2025 | ETHNetPRecover: Ethereum Network Topology Recovering via Passive Transaction MonitoringabstractEthereum is a decentralized blockchain system that relies on a peer-to-peer (P2P) network. Understanding the topology of this P2P network is crucial for assessing the security, reliability, and user anonymity of Ethereum (ETH). However, the routing table of Ethereum network nodes is private and inaccessible, making the Ethereum network topology hidden. Safeguarding the topology is essential to protecting Ethereum's privacy and security. Therefore, attempting to measure the entire ETH network's topology is a crucial foundation. This paper proposes a completely passive method called ETHNetPRecover, which only requires monitoring transactions to recover the entire ETH network's topology. This method can determine the presence of an edge between two nodes with 96.8% precision. We compared our method's performance with similar approaches and found it recovers the Ethereum network topology faster without additional transaction costs. Using the recovered topology, we tracked and marked transaction entry nodes in the Ethereum Mainnet over seven days. We discovered that 93% of the transactions during this period entered the Ethereum Mainnet network through 30 entry nodes. Through our evaluation, we found that our method has high precision, is efficient, and incurs no additional costs, making it a relatively effective approach. Xiaorui Gong |
CSCWD | 3 |
| 2025 | ADGE: Automated Directed GUI Explorer for Android ApplicationsabstractWith the continuous growth in the number of Android applications and the size of their codebases, it has become increasingly difficult for testers to manually analyze and trigger the functionalities of interest in each application. For instance, it is hard to trigger vulnerability points reported by scanners or reproduce captured crash scenarios. On the other hand, most existing automated exploration techniques exhibit slow performance when triggering specified targets due to the extensive exploration of different paths. Target-directed techniques can effectively address this issue but are relatively underexplored in existing research. The only target-directed exploration tool, GOALEXPLORER, is constrained by the limitations in the precision of its static analysis, which negatively impacts both exploration efficiency and effectiveness. To boost the efficiency of target-directed exploration, we propose an automated GUI testing method guided by target functions called Automated Directed GUI Explorer (ADGE). Specifically, ADGE first generates a tainted Inter-procedural Control Flow Graph with the GUI widgets by modeling the role of GUI widgets in the control flow as well as their relationship with the target using static analysis. In the dynamic exploration phase, ADGE constructs the real-time model of the fragments and menus on the current screen to guide its exploration decisions with the knowledge of static model. To validate the effectiveness of ADGE, we conduct extensive comparisons of ADGE with the state-of-the-art baseline GOALEXPLORER on 55 benchmark applications. The results demonstrate that ADGE reduced the average time to trigger targets by 44% compared to GOALEXPLORER, while also successfully triggering more than 5.24% targets. Furthermore, during the testing process, ADGE successfully triggered 5 crash events. Xiaobo Xiang, Qingli Guo, Xiaorui Gong |
ICST | 5 |
| 2025 | Sheep's Clothing, Wolf's Data: Detecting Server-Induced Client Vulnerabilities in Windows Remote IPC
Fangming Gu, Qingli Guo, Qinghe Xie, Beibei Zhao, Kangjie Lu, Xiaorui Gong |
NDSS | 8 |
| 2024 | DBridger: Discovering Vulnerable Data Sharing Paths in Embedded Firmware
Linyu Li 0004, Qingli Guo, Jun Guan, Xiaorui Gong |
Inscrypt (1) | 7 |
| 2024 | LSD Attack: Exploiting Inconsistencies between Design and Implementation of Ethereum ProtocolsabstractIn the network layer of the Ethereum network, the Discv5 protocol is introduced to improve the node discovery process and enhance resistance to common P2P network attacks such as Sybil Attacks, Partition Attacks, and Eclipse Attacks. However, the practical effectiveness of the new security mechanisms introduced by the Discv5 protocol has not been evaluated through engineering assessments. In this paper, we identify inconsistencies between the design and implementation of the Discv5 protocol and propose a new attack pattern: the Leveraging Service Diversity (LSD) Attack. The LSD Attack targets networks where different services are indiscriminately mixed. Through detailed measurements of the Consensus Layer (CL) discovery network, we evaluate the impact of the LSD Attack on newly joined network nodes and on the services of honest nodes within the network. Our experiments demonstrate significant deviations between the Discv5 protocol’s current implementation and its original design, which can lead to a substantial reduction in the network’s security under the influence of service diversity. This study contributes to a deeper understanding of the security implications of the Discv5 protocol and highlights the need for further evaluation and improvement of the network layer protocols in Ethereum. Xueping Liang, Xiaorui Gong |
TrustCom | 4 |
| 2024 | CARDSHARK: Understanding and Stablizing Linux Kernel Concurrency Bugs Against the Odds
Tianshuo Han, Xiaorui Gong, Jian Liu 0008 |
USENIX Security Symposium | 2 |
| 2024 | ReIFunc: Identifying Recurring Inline Functions in Binary CodeabstractFunction inlining, although a common phenomenon, can greatly hinder the readability of the binary code obtained through decompilation. Identifying inline functions in the binary code is additionally challenging as there is no clear boundary between an inlined function and its caller function, the instructions of the same function might differ during inline expansion, and existing graph-schema methods for inline function identification cannot handle the vast number of functions involved due to their complexity. To address the challenge, in this paper, we propose an effective inline function identification solution named ReIFunc, which combines subgraph isomorphism and deep learning to identify these recurring inline functions (RIFs). Our evaluation shows that ReIFunc can effectively match functions within a broad candidate set with a high precision rate exceeding 99% while maintaining an acceptable recall, thus getting rid of the constraints imposed by the limited size of the candidate set. Qingli Guo, Dongsong Yu, Jiawei Yin, Xiaorui Gong |
SANER | 6 |
| 2024 | Combating alert fatigue with AlertPro: Context-aware alert prioritization using reinforcement learning for multi-step attack detection
Xueping Liang, Xiaorui Gong |
Comput. Secur. | 6 |
| 2023 | Reverse Engineering Workload Measure based on Function ClassificationabstractReverse engineering(RE) is the most basic task of network security companies, but how to quantify the workload of the RE is lack of research.Many related researches focus on developing extensive array of tools to support RE or using RE to discover new vulnerabilities.Therefore, we focus on developing a tool to help analysts or the comanpanies to measure their RE workload as well as understanding the binaries in a statistical way.We classify the functions in binary files into 7 types,apply the function classification in our dataset and obtain some findings which can help analysts master the workload of binary files to be reversed in a statistical way. Qingli Guo, Xiaorui Gong |
CSCWD | 5 |
| 2023 | FSmell: Recognizing Inline Function in Binary Code
Wei Lin 0004, Qingli Guo, Jiawei Yin, Xiangyu Zuo, Rongqing Wang, Xiaorui Gong |
ESORICS (2) | 6 |
| 2023 | AppChainer: investigating the chainability among payloads in android applicationsabstractAbstract Statistics show that more than 80 applications are installed on each android smartphone. Vulnerability research on Android applications is of critical importance. Recently, academic researchers mainly focus on single bug patterns, while few of them investigate the relations between multiple bugs. Industrial researchers proposed a series of logic exploit chains leveraging multiple logic bugs. However, there is no general model to evaluate the chaining abilities between bugs. This paper presents a formal model to elucidate the relations between multiple bugs in Android applications. To prove the effectiveness of the model, we design and implement a prototype system named AppChainer. AppChainer automatically identifies attack surfaces of Android applications and investigates whether the payloads entering these attack surfaces are “chainable”. Experimental results on 2138 popular Android applications show that AppChainer is effective in identifying and chaining attacker-controllable payloads. It identifies 14467 chainable payloads and constructs 5458 chains both inside a single application and among various applications. The time cost and resource consumption of AppChainer are also acceptable. For each application, the average analysis time is 317 s, and the average memory consumed is 2368 MB. Compared with the most relevant work Jandroid, the experiment results on our custom DroidChainBench show that AppChainer outperforms Jandroid at the precision rate and performs equally with Jandroid at the recall rate. Xiaobo Xiang, Qingli Guo, Xiaorui Gong, Baoxu Liu |
Cybersecur. | 5 |
| 2022 | ModX: Binary Level Partially Imported Third-Party Library Detection via Program Modularization and Semantic MatchingabstractWith the rapid growth of software, using third-party libraries (TPLs) has become increasingly popular. The prosperity of the library usage has provided the software engineers with a handful of methods to facilitate and boost the program development. Unfortunately, it also poses great challenges as it becomes much more difficult to manage the large volume of libraries. Researches and studies have been proposed to detect and understand the TPLs in the software. However, most existing approaches rely on syntactic features, which are not robust when these features are changed or deliberately hidden by the adversarial parties. Moreover, these approaches typically model each of the imported libraries as a whole, therefore, cannot be applied to scenarios where the host software only partially uses the library code segments. Zhengzi Xu, Hongxu Chen 0001, Yang Liu 0003, Xiaorui Gong, Baoxu Liu |
ICSE | 5 |
| 2022 | COMRace: Detecting Data Race Vulnerabilities in COM Objects
Fangming Gu, Qingli Guo, Zhiniang Peng, Xiaorui Gong |
USENIX Security Symposium | 7 |
| 2021 | Ghost in the Binder: Binder Transaction Redirection Attacks in Android System ServicesabstractBinder, the main mechanism for Android applications to access system services, adopts a client-server role model in its design, assuming the system service as the server and the application as the client. However, a growing number of scenarios require the system service to act as a Binder client and to send queries to a Binder server possibly instantiated by the application. Departing from this role-reversal possibility, this paper proposes the Binder Transaction Redirection (BiTRe) attacks, where the attacker induces the system service to transact with a customized Binder server and then attacks from the Binder server---an often unprotected direction. We demonstrate the scale of the attack surface by enumerating the utilizable Binder interfaces in BiTRe, and discover that the attack surface grows with the Android release version. In Android 11, more than 70% of the Binder interfaces are affected by or can be utilized in BiTRe. We prove the attacks' feasibility by (1) constructing a prototype system that can automatically generate executable programs to reach a substantial part of the attack surface, and (2) identifying a series of vulnerabilities, which are acknowledged by Google and assigned ten CVEs. Xiaobo Xiang, Ren Zhang 0003, Hanxiang Wen, Xiaorui Gong, Baoxu Liu |
CCS | 4 |
| 2021 | Towards Automated Detection of Higher-Order Memory Corruption Vulnerabilities in Embedded DevicesabstractThe rapid growth and limited security protection of the networked embedded devices put the threat of remote code execution related memory corruption attacks front and center among security concerns. Current detection approaches can detect single-step and single-process memory corruption vulnerabilities well by fuzzing tests, and often assume that data stored in the current embedded device or even the embedded device connected to it is safe. However, an adversary might corrupt memory via multi-step exploits if she manages first to abuse the embedded application to store the attack payload and later use this payload in a security-critical operation on memory. These exploits usually lead to persistent code execution attacks and complete control of the device in practice but are rarely covered in state-of-the-art dynamic testing techniques. To address these stealthy yet harmful threats, we identify a large class of such multi-step memory corruption attacks and define them as higher-order memory corruption vulnerabilities (HOMCVs). We can abstract the detailed multi-step exploit models for these vulnerabilities and expose various attacker-controllable data stores (ACDS) that contribute to memory corruption. Aided by the abstract models, a dynamic data flow tracking (DDFA) based solution is developed to detect data stores that would be transferred to memory and then identify HOMCVs. Our proposed method is validated on an experimental embedded system injected with different variants of higher-order memory corruption vulnerabilities and two real-world embedded devices. We demonstrate that successful detection can be accomplished with an automatic system named Higher-Order Fuzzing Framework (HOFF) which realizes the DDFA-based solution. Linyu Li 0004, Houhua He, Xiaorui Gong |
DATE | 6 |
| 2021 | Auto-Recon: An Automated Network Reconnaissance System Based on Knowledge Graph
Qingli Guo, Xiaorui Gong |
ICA3PP (3) | 4 |
| 2021 | MAAC: Novel Alert Correlation Method To Detect Multi-step AttackabstractWith the continuous improvement of attack methods, there are more and more distributed, complex, targeted attacks in which the attackers use combined attack methods to achieve the purpose. Advanced cyber attacks include multiple stages to achieve the ultimate goal. Traditional intrusion detection systems such as endpoint security management tools, firewalls, and other monitoring tools generate a large number of alerts during the attack. These alerts include attack clues, as well as many false positives unrelated to attacks. Security analysts need to analyze a large number of alerts and find useful clues from them and reconstruct attack scenarios. However, most traditional security monitoring tools cannot correlate alerts from different sources, so many multi-step attacks are still completely unnoticed, requiring manual analysis by security analysts like finding a needle in a haystack. We propose MAAC, a multi-step attack alert correlation system, which reduces repeated alerts and combines multi-step attack paths based on alert semantics and attack stages. The evaluation results of the real-world datasets show that MAAC can effectively reduce the alerts by 90% and find attack paths from a large number of alerts. Xiaorui Gong, Lei Yu 0006, Jian Liu 0008 |
TrustCom | 2 |
| 2021 | MAZE: Towards Automated Heap Feng Shui
Chao Zhang 0008, Xiaorui Gong |
USENIX Security Symposium | 5 |
| 2021 | SEPAL: Towards a Large-scale Analysis of SEAndroid Policy CustomizationabstractNowadays, SEAndroid has been widely deployed in Android devices to enforce security policies and provide flexible mandatory access control (MAC), for the purpose of narrowing down attack surfaces and restricting risky operations. Generally, the original SEAndroid security policy rules are carefully and strictly written and maintained by the Android community. However, in practice, mobile device manufacturers usually have to customize these policy rules and add their own new rules to satisfy their functionality extensions, which breaks the integrity of SEAndroid and causes serious security issues. Still, up to now, it is a challenging task to identify these security issues due to the large and ever-increasing number of policy rules, as well as the complexity of policy semantics. Dongsong Yu, Guangliang Yang 0001, Guozhu Meng, Xiaorui Gong, Xiaobo Xiang, Kai Chen 0012, Wenke Lee, Wenchang Shi |
WWW | 4 |
| 2020 | Rolling Attack: An Efficient Way to Reduce Armors of Office Automation Devices
Linyu Li 0004, Jie Gou, Jiawei Yin, Xiaorui Gong |
ACISP | 6 |
| 2020 | HAEPG: An Automatic Multi-hop Exploitation Generation Framework
Xiaorui Gong |
DIMVA | 3 |
| 2020 | RouAlign: Cross-Version Function Alignment and Routine Recovery with Graphlet Edge Embedding
Jian Liu 0008, Mengxia Luo, Xiaorui Gong, Baoxu Liu |
SEC | 4 |
| 2019 | PPIDS: A Pyramid-Like Printer Intrusion Detection System Based on ATT&CK Framework
Houhua He, Weixia Cai, Xiaorui Gong |
Inscrypt | 5 |
| 2019 | Wi-Fi Secure Access Control System Based on Geo-fenceabstractWith the rapid spread and development of the wireless network, secure access control has caught significant attention. The existing Wi-Fi network system access control methods, mainly based on the static password, the MAC address or the username/password, are prone to spoofing attacks, such as malicious users forge the authentication information to access the network and realize the penetration attack of Intranet. In this paper, we propose a new secure access control model based on Geo-fence to solve the above problems, further strengthening the security of the wireless network system. Our novel solution facilitates 1) providing convenient wireless network service in the trusted zone without authentication 2) isolating cyber-attacks outside the security zone 3) monitoring the access smart mobile device real time without affecting users' using the wireless network. Furthermore, we present the consideration of the smart mobile device heterogeneity in our model. Through using three different smart mobile devices to experiment, the analytical and experimental results demonstrate that the difference among the devices have a great impact on the device localization and the final access control effect. Haofeng Jiang, Xiaorui Gong |
ISCC | 2 |
| 2019 | FuncNet: A Euclidean Embedding Approach for Lightweight Cross-platform Binary Recognition
Mengxia Luo, Xiaorui Gong |
SecureComm (1) | 3 |
| 2019 | Memory access integrity: detecting fine-grained memory access errors in binary codeabstractAs one of the most notorious programming errors, memory access errors still hurt modern software security. Particularly, they are hidden deeply in important software systems written in memory unsafe languages like C/C++. Plenty of work have been proposed to detect bugs leading to memory access errors. However, all existing works lack the ability to handle two challenges. First, they are not able to tackle fine-grained memory access errors, e.g., data overflow inside one data structure. These errors are usually overlooked for a long time since they happen inside one memory block and do not lead to program crash. Second, most existing works rely on source code or debugging information to recover memory boundary information, so they cannot be directly applied to detection of memory access errors in binary code. However, searching memory access errors in binary code is a very common scenario in software vulnerability detection and exploitation. In order to overcome these challenges, we propose Memory Access Integrity (MAI), a dynamic method to detect fine-grained memory access errors in off-the-shelf binary executables. The core idea is to recover fine-grained accessing policy between memory access behaviors and memory ranges, and then detect memory access errors based on the policy. The key insight in our work is that memory accessing patterns reveal information for recovering the boundary of memory objects and the accessing policy. Based on these recovered information, our method maintains a new memory model to simulate the life cycle of memory objects and report errors when any accessing policy is violated. We evaluate our tool on popular CTF datasets and real world softwares. Compared with the state of the art detection tool, the evaluation result demonstrates that our tool can detect fine-grained memory access errors effectively and efficiently. As the practical impact, our tool has detected three 0-day memory access errors in an audio decoder. Wenjie Li 0006, Dongpeng Xu 0001, Xiaorui Gong, Xiaobo Xiang, Fangming Gu, Qianxiang Zeng |
Cybersecur. | 4 |
| 2019 | From proof-of-concept to exploitableabstractExploitability assessment of vulnerabilities is important for both defenders and attackers. The ultimate way to assess the exploitability is crafting a working exploit. However, it usually takes tremendous hours and significant manual efforts. To address this issue, automated techniques can be adopted. Existing solutions usually explore in depth the crashing paths , i.e., paths taken by proof-of-concept (PoC) inputs triggering vulnerabilities, and assess exploitability by finding exploitable states along the paths. However, exploitable states do not always exist in crashing paths. Moreover, existing solutions heavily rely on symbolic execution and are not scalable in path exploration and exploit generation. In this paper, we propose a novel solution to generate exploit for userspace programs or facilitate the process of crafting a kernel UAF exploit. Technically, we utilize oriented fuzzing to explore diverging paths from vulnerability point. For userspace programs, we adopt a control-flow stitching solution to stitch crashing paths and diverging paths together to generate exploit. For kernel UAF, we leverage a lightweight symbolic execution to identify, analyze and evaluate the system calls valuable and useful for exploiting vulnerabilities. We have developed a prototype system and evaluated it on a set of 19 CTF (capture the flag) programs and 15 realworld Linux kernel UAF vulnerabilities. Experiment results showed it could generate exploit for most of the userspace test set, and it could also facilitate security mitigation bypassing and exploitability evaluation for kernel test set. Wei Wu 0010, Chao Zhang 0008, Xinyu Xing 0001, Xiaorui Gong |
Cybersecur. | 5 |
| 2018 | Revery: From Proof-of-Concept to ExploitableabstractAutomatic exploit generation is an open challenge. Existing solutions usually explore in depth the crashing paths, i.e., paths taken by proof-of-concept (POC) inputs triggering vulnerabilities, and generate exploits when exploitable states are found along the paths. However, exploitable states do not always exist in crashing paths. Moreover, existing solutions heavily rely on symbolic execution and are not scalable in path exploration and exploit generation. In addition, few solutions could exploit heap-based vulnerabilities. In this paper, we propose a new solution revery to search for exploitable states in paths diverging from crashing paths, and generate control-flow hijacking exploits for heap-based vulnerabilities. It adopts three novel techniques:(1) a digraph to characterize a vulnerability's memory layout and its contributor instructions;(2) a fuzz solution to explore diverging paths, which have similar memory layouts as the crashing paths, in order to search more exploitable states and generate corresponding diverging inputs;(3) a stitch solution to stitch crashing paths and diverging paths together, and synthesize EXP inputs able to trigger both vulnerabilities and exploitable states. We have developed a prototype of revery based on the binary analysis engine angr, and evaluated it on a set of 19 real world CTF (capture the flag) challenges. Experiment results showed that it could generate exploits for 9 (47%) of them, and generate EXP inputs able to trigger exploitable states for another 5 (26%) of them. Chao Zhang 0008, Xiaobo Xiang, Wenjie Li 0006, Xiaorui Gong, Bingchang Liu, Kaixiang Chen |
CCS | 6 |
| 2018 | FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free Vulnerabilities
Wei Wu 0010, Yueqi Chen 0001, Jun Xu 0024, Xinyu Xing 0001, Xiaorui Gong |
USENIX Security Symposium | 5 |
| 2017 | State-of-the-Art: Security Competition in Talent Education
Baoxu Liu, Xiaorui Gong |
Inscrypt | 3 |
| 2015 | A TOA-Based Geolocation Algorithm Utilizing Convex CombinationabstractIn the wireless position techniques for cellular networks, the traditional geolocation algorithms have been researched because of the advantage low complexity, however the representative LLOP algorithm does not well performed in the cellular networks since it is constrained with the geometry relationship between mobile station and the base stations. For the low accuracy problem of LLOP algorithm, we have proposed a TOA-based geolocation algorithm utilizing convex combination. The method introduces convex combination theory, which the convex combination of a set of coarse position estimations can be used to generate position estimation with higher accuracy, and proposes a linearized procedure to calculate the convex combination coefficients. Simulation results verify that the proposed algorithm decreases the position error by 6.19%, 7.51% and 40.97% compared with LLS- MLE algorithm, LLOP-LS algorithm and LLOP algorithm respectively when the number of base stations is 5 and the measurement noise standard deviation is 50m. Xiaorui Gong, Jianhua Peng, Kaizhi Huang |
VTC Spring | 1 |
| 2011 | Poster: temporal attribute-based encryption in clouds
Yan Zhu 0010, Hongxin Hu, Gail-Joon Ahn, Xiaorui Gong, Shimin Chen |
CCS | 4 |