VLDB 2026 Research / reviewers in the wild / expert
Haoqiang Wang
dblp:332/4313
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TGNN: Enhancing Pixel Tracking Detection via LLM-driven Annotation and GAT-powered Structural RepresentationabstractWeb tracking is increasingly pervasive, raising serious concerns about user privacy and security. Among existing techniques, pixel tracking is particularly stealthy and cost-effective, embedding invisible images that exfiltrate user activities to third-party servers. Current defenses, including filter list blocking and conventional machine learning, often fail to capture the cross-site associations that enable pixel tracking to evade detection. Shenping Xiong, Xutong Wang, Ze Jin, Xinyu Liu 0019, Haoqiang Wang, Ru Tan, Qixu Liu |
WWW | 5 |
| 2025 | PORTIA: A Multi-Granularity APT Detection Model Based on Provenance GraphsabstractAdvanced Persistent Threats (APTs) have become a major cybersecurity threat due to their stealthy attack methods and long latency periods. Traditional signature-based detection struggles to detect novel attacks, and while unsupervised methods using Graph Neural Networks (GNNs) can model system behavior, they face challenges in handling large-scale provenance graphs and accurately incorporating system operational states for detection.This paper presents PORTIA, a multi-granularity APT detection model based on graph representation learning. PORTIA constructs provenance graphs by integrating temporal information from audit logs and uses a graph mask autoencoder to model normal system behavior, detecting anomalies through embedding shifts. As an unsupervised model, PORTIA can swiftly identify anomalous system states without relying on attack signatures, achieving fine-grained detection by incorporating system operational states. Evaluations on multiple datasets show that PORTIA detects both standard and APT attacks with high precision, outperforming existing detection systems. Haoqiang Wang, Zhou Zhou 0007, Chengxiang Si, Qingyun Liu 0001 |
IJCNN | 3 |
| 2025 | MOLE: Provenance Graph Generation Framework Based on LLM PromptingabstractIn the increasingly complex landscape of cyber-attacks, logs have become a critical source of data for detecting system threats. Currently, most log-based detection systems rely on converting audit logs into provenance graphs during the process of attack investigation. However, this construction process is still heavily dependent on manually written code with regular expressions tailored to each specific log type. In this paper, we propose MOLE, a provenance graph generation framework based on prompting with large language models (LLMs). Unlike traditional approaches, MOLE does not rely on prior knowledge and is adaptable to diverse types of log data. The framework automatically generates provenance graph extraction templates through instruction generation and parses logs locally to produce the final provenance graph.MOLE leverages the log patterns and structures learned by LLMs from large-scale data during training. As a result, tasks that previously required several days of manual coding to generate a provenance graph can now be completed in just a few minutes. Furthermore, when processing 50 million log entries, the entire provenance graph generation process consumed only 20k tokens. Haoqiang Wang, Zhou Zhou 0007, Chengxiang Si, Qingyun Liu 0001 |
IJCNN | 2 |
| 2025 | Hidden and Lost Control: on Security Design Risks in IoT User-Facing Matter Controller
Haoqiang Wang, Yiwei Fang, Ze Jin, Emma Delph, Xiaojiang Du, Qixu Liu, Luyi Xing |
NDSS | 1 |
| 2025 | RBAClock: Contain RBAC Permissions through Secure SchedulingabstractKubernetes has emerged as the de facto standard for container orchestration. However, existing container scheduling strategies prioritize QoS, leading to the co-location of pods with varying permission levels on the same node. This not only introduces risks of privilege escalation but also facilitates the spread of pods with risky permissions across the cluster, exacerbating the potential for attackers to elevate their privileges. In this work, our goal is to mitigate permission disparity among pods on each node, thereby reducing the risk of privilege escalation from co-location attack and curbing the spread of high-risk permissions across the cluster. We introduce a novel metric, Extraneous Risk Privileges (ERP), to quantify additional privileges derived from the combination of RBAC permissions and cluster parameters that are utilized by other pods on the node but not by the target pod itself. The RBAClock scheduling framework is designed to minimize ERP increase during pod placement, prioritizing the aggregation of pods with similar risk profiles and isolation of those with divergent privileges. Experimental evaluations across 24 CNCF applications demonstrate that, compared to the default scheduler, RBAClock alone achieves an average reduction of 41.46% in aggregated privileges in cluster, 64.63% in privilege escalation risk, and 34.59% in high-privilege nodes proportion, with an 8% performance tradeoff. Notably, our investigation uncovered privilege escalation risks in the Kubernetes services of two major cloud providers, Alibaba Cloud and Tencent Cloud, and demonstrated that RBAClock can effectively mitigate these threats. Qingwang Chen, Ru Tan, Yuqi Shu, Zhou Tong, Haoqiang Wang, Ze Jin, Qixu Liu |
RAID | 6 |
| 2025 | Chaos of Functionalities: Understanding Security Risks in Heterogeneity of IoT Matter ControllersabstractThe Matter protocol has rapidly become the new standard for secure and interoperable IoT connectivity, adopted by major industry players and integrated into millions of devices. A core feature of Matter is its ability to support device sharing across users and controllers. However, as vendors independently implement Matter and blend it with their proprietary ecosystems, significant inconsistencies emerge. These inconsistencies result in heterogeneous user capabilities depending on which Matter Controller (MC) or OEM app is used, introducing a new and largely unexplored class of security risks. In this work, we present the first systematic study on security risks stemming from heterogeneous Matter controller implementations in shared device environments. We analyze 18 major IoT vendors and uncover a novel category of vulnerabilities, which we term MCG (Matter Controller Gaps), where differences in controller capabilities can enable unauthorized access or stealthy device manipulation. To uncover these flaws at scale, we develop MCG-Checker, a semi-automated analysis tool that combines large language models and UI automation to detect control disparities across Matter controllers and OEM apps. Using MCG-Checker, we evaluate 14 Matter controllers and 8 OEM apps, discovering 5 previously unknown attack vectors affecting top vendors such as Google, Apple, and Amazon Alexa. Our work reveals critical design and implementation issues in current Matter deployments. We offer concrete recommendations for protocol designers, vendors, and end users to address these gaps, contributing to more secure and predictable IoT ecosystems. Yiwei Fang, Haoqiang Wang, Ze Jin, Qixu Liu |
TrustCom | 2 |
| 2023 | Cross-Modal Retrieval for Motion and Text via DropTriple LossabstractCross-modal retrieval of image-text and video-text is a prominent research area in computer vision and natural language processing. However, there has been insufficient attention given to cross-modal retrieval between human motion and text, despite its wide-ranging applicability. To address this gap, we utilize a concise yet effective dual-unimodal transformer encoder for tackling this task. Recognizing that overlapping atomic actions in different human motion sequences can lead to semantic conflicts between samples, we explore a novel triplet loss function called DropTriple Loss. This loss function discards false negative samples from the negative sample set and focuses on mining remaining genuinely hard negative samples for triplet training, thereby reducing violations they cause. We evaluate our model and approach on the HumanML3D and KIT Motion-Language datasets. On the latest HumanML3D dataset, we achieve a recall of 62.9% for motion retrieval and 71.5% for text retrieval (both based on R@10). The source code for our approach is publicly available at https://github.com/eanson023/rehamot. Yang Liu 0264, Haoqiang Wang, Mengyuan Liu 0001, Hong Liu 0008 |
MMAsia | 3 |