Yuqi Qiu

dblp:343/8672 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing Vulnerabilities
Yuqi Qiu, Xiang Li 0108, Zheli Liu
SP1
2025 RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
abstract
DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective. In this work, we introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that has not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers. We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of ECS verification and DNS extension implementations, revealing new security risks introduced by them.
Xiang Li 0108, Mingming Zhang 0010, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan
CCS5
2025 MLSBOX: Automated Sandbox for Fine-Grained Isolation of Multiple Third-Party Libraries*
abstract
In the development process, utilizing the existing functions and interfaces of third-party libraries can significantly reduce development time and resources. However, the introduction of third-party libraries also brings security risks. These libraries may contain defects or vulnerabilities and can even conceal malicious code. Introducing vulnerable third-party libraries can compromise the security of the entire software system. Although existing solutions can provide sandbox environments for libraries, they require extensive modifications to the source code to implement isolation. Furthermore, current sandboxes cannot support the simultaneous isolation of multiple libraries, including memory and privilege isolation. To address these issues, we propose MLSBOX, the first automated sandboxing framework designed to provide fine-grained isolation for multiple untrusted third-party libraries. This sandbox leverages Attribute Program Dependence Graph (APDG) analysis to identify data dependencies from different libraries. It automatically modifies the program at the compiler level to partition the program into multiple independent isolation domains, enforcing memory and privilege isolation for each domain to enhance overall program security. We have successfully implemented a prototype of MLSBOX on LLVM and conducted rigorous functional and performance evaluations on third-party libraries such as OpenSSL and Zlib. MLSBOX provides the most fine-grained memory and permission isolation currently available. In terms of runtime efficiency, MLSBOX incurs an average overhead of 2.50%. For isolating multi-threaded programs, such as a program with 8 threads, MLSBOX incurs a minimal runtime overhead of just 0.80%, significantly lower than that of the current state-of-the-art solution, Cali (365.70%).
Yuqi Qiu, Chenjun Ma, Yunfeng Kang
TrustCom1
2024 rTPM: A Native Firmware-Based Trusted Platform Module for RISC-V
abstract
The Trusted Platform Module (TPM) enhances system security by offering features such as a root of trust, secure storage, and authentication mechanisms. While TPM has been widely adopted, there has been no detailed exploration of a firmware-based TPM implementation specifically designed for the RISC-V architecture. In this paper, we present the design and implementation of a firmware TPM system for RISC-V, named rTPM. rTPM leverages DRAM latency-based Physical Unclonable Functions (PUFs) and PMP (Physical Memory Protection) to achieve secure NVRAM storage. Addressing challenges such as the need for additional security hardware extensions and the requirement for a Trusted Execution Environment (TEE) in firmware-based TPMs, we develop a secure communication mechanism across different privilege levels, tailored to the RISC-V security architecture. In addition, we proposed new solutions to address rollback attacks and the absence of secure clocks. Our prototype demonstrates that, although rTPM incurs approximately 200 ms of additional overhead during startup and data read/write operations, it significantly improves message transmission efficiency. As a result, rTPM achieves a performance enhancement of nearly 2-3 times compared to TPM emulators when executing related instructions, while also providing enhanced security.
Xibin Wang, Juan Wang 0006, Yunhao Jia, Delong Jiang, Yuqi Qiu, Mohan Liu, Zhidong Shen
HPCC7
2023 Generalizable Reinforcement Learning-Based Coarsening Model for Resource Allocation over Large and Diverse Stream Processing Graphs
abstract
Resource allocation for stream processing graphs on computing devices is critical to the performance of stream processing. Efficient allocations need to balance workload distribution and minimize communication simultaneously and globally. Since this problem is known to be NP-complete, recent machine learning solutions were proposed based on an encoder-decoder framework, which predicts the device assignment of computing nodes sequentially as an approximation. However, for large graphs, these solutions suffer from the deficiency in handling long-distance dependency and global information, resulting in suboptimal predictions. This work proposes a new paradigm to deal with this challenge, which first coarsens the graph and conducts assignments on the smaller graph with existing graph partitioning methods. Unlike existing graph coarsening works, we leverage the theoretical insights in this resource allocation problem, formulate the coarsening of stream graphs as edge-collapsing predictions, and propose an edge-aware coarsening model. Extensive experiments on various datasets show that our framework significantly improves over existing learning-based and heuristic-based baselines with up to 56% relative improvement on large graphs.
Lanshun Nie, Yuqi Qiu, Mo Yu, Jing Li 0025
IPDPS2
2023 Before Toasters Rise Up: A View into the Emerging DoH Resolver's Deployment Risk
abstract
As an encryption protocol for DNS queries, DNS-over-HTTPS (DoH) is becoming increasingly popular, and it mainly addresses the last-mile privacy protection problem. However, the security of DoH is in urgent need of measurement and analysis due to its reliance on certificates and upstream servers. In this paper, we focus on the DoH ecosystem and conduct a one-month measurement to analyze the current deployment of DoH resolvers. Our findings indicate that some of these resolvers use invalid certificates, which can compromise the security and privacy advantages of the protocol. Furthermore, we found that many providers are at risk of certificate outages, which could cause significant disruptions to the DoH ecosystem. Additionally, we observed that the centralization of DoH resolvers and upstream DNS servers is a potential issue that needs addressing to ensure the stability of the ecosystem.
Yuqi Qiu, Baiyang Li, Zhiqian Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001
ISCC1
2022 Detection of DoH Tunnels with Dual-Tier Classifier
abstract
DNS over HTTPS (DoH) has been deployed to provide confidentiality in the DNS resolution process. However, encryption is a double-edged sword in providing security while increasing the risk of data tunneling attacks. Current approaches for plaintext DNS tunnel detection are disabled. Due to the diversity of tunneling tool variations and the low proportion of tunneled traffic in real situations, detecting malicious behaviors is becoming more and more challenging. In this paper, we propose a novel behavior-based model with Dual-Tier Tunnel Classifier (DTC) for tool-level DoH tunneling detection. The major advantage of DTC is that it can not only capture existing tunneling tools but also explore unknown ones in the wild. In particular, DTC considers data imbalance, which improves robustness of the model in the open environment. Our method has been proven successful in both closed and open scenarios, achieving 99.99 % accuracy in detecting known malicious DoH traffic, 96.93% accuracy in unknown and 95.31 % accuracy in identifying malicious DoH tunnel tools.
Yuqi Qiu, Baiyang Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001
MSN1