VLDB 2026 Research / reviewers in the wild / expert
Qiyu Hou
dblp:345/8416
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 81% Malware analysis · 19% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 5 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
1.0 | 1 | 2026 | ${\mathsf{KubeSec}} $KubeSec: Automatic Detection of Takeover Risks Introduced by Third-Party Apps in the Kubernetes Ecosystem · IEEE Trans. Dependable Secur. Comput. 2026 |
Malware analysis
android malware |
0.9 | 1 | 2025 | Gupacker: Generalized Unpacking Framework for Android Malware · IEEE Trans. Inf. Forensics Secur. 2025 |
Systems and software security
software protection |
0.9 | 1 | 2025 | Gupacker: Generalized Unpacking Framework for Android Malware · IEEE Trans. Inf. Forensics Secur. 2025 |
Systems and software security › binary analysis
unpacking |
0.9 | 1 | 2025 | Gupacker: Generalized Unpacking Framework for Android Malware · IEEE Trans. Inf. Forensics Secur. 2025 |
Program analysis
dynamic analysis |
0.3 | 1 | 2025 | Gupacker: Generalized Unpacking Framework for Android Malware · IEEE Trans. Inf. Forensics Secur. 2025 |
Methods — techniques the papers use, named apart from their topics
call chain construction · 1.7JNI function monitoring · 1.7static analysis · 1.0code dependency analysis · 1.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ${\mathsf{KubeSec}} $KubeSec: Automatic Detection of Takeover Risks Introduced by Third-Party Apps in the Kubernetes EcosystemabstractThird-party applications (TPAs) are integral components of managed Kubernetes clusters, but are also frequently exploited in takeover attacks. Recent incidents have demonstrated that TPAs can be weaponized to gain control over clusters. Given their critical role within the Kubernetes ecosystem, it is essential to explore the potential attack surfaces associated with various types of TPAs. To address this, we propose${\sf KubeSec}$, a framework that systematically investigates these risks by analyzing application permission configurations and component code dependencies. This investigation revealed a significant number of insecure RBAC binding patterns, uncovering 562 such patterns and identifying 375 vulnerabilities linked to 134 CVEs. These vulnerabilities impact millions of users, with an average remediation time exceeding 10 months. All findings have been reported to the relevant teams, leading to the assignment of 21 new CVEs by the community. These results highlight substantial security risks associated with TPAs in Kubernetes clusters and emphasize the urgent need for further research to develop more secure cluster management practices. Qiyu Hou, Hao Ren 0001, Xingshu Chen, Gelei Deng, Tianwei Zhang 0004, Guowen Xu, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | TABLET: Table Structure Recognition Using Encoder-only Transformers
Qiyu Hou, Jun Wang 0018 |
ICDAR (5) | 1 |
| 2025 | Gupacker: Generalized Unpacking Framework for Android MalwareabstractAndroid malware authors often use packers to evade analysis. Although many unpacking tools have been proposed, they face two significant challenges: 1) They are easily impeded by anti-analysis techniques employed by packers, preventing efficient collection of hidden Dex data. 2) They are typically designed to unpack a specific packer and cannot handle malware packed with mixed packers. Consequently, many packed malware samples evade detection. To bridge this gap, we propose Gupacker, a novel generalized unpacking framework. Gupacker offers a generic solution for first-generation holistic packer by customizing the Android system source code. It identifies the type of packer and selects an appropriate unpacking function, constructs a deeper active call chain to achieve generic unpacking of second-generation function extraction packers, and usesJNIfunction and instruction monitoring to handle third-generation virtual obfuscation packer. On this basis, we counteract a diverse array of anti-analysis techniques. We conduct extensive experiments on 5K packed Android malware samples, comparing Gupacker with 2 commercial and 4 state-of-the-art academic unpacking tools. The results demonstrate that Gupacker significantly improves the efficiency of Android malware unpacking with acceptable system overhead. We analyze real packed applications based on Gupacker and found several are second-packed by attackers, including WPS for Android, with tens of millions of users. We receive and responsibly report 13 0day vulnerabilities and also assist in the remediation of all vulnerabilities. Qiyu Hou, Xingshu Chen, Hao Ren 0001, Meng Li 0006, Hongwei Li 0001, Changxiang Shen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Synthesizing Realistic Data for Table Recognition
Qiyu Hou, Jun Wang 0018, Meixuan Qiao, Lujun Tian |
ICDAR (1) | 1 |
| 2023 | Structure Diagram Recognition in Financial Announcements
Meixuan Qiao, Jun Wang 0018, Junfu Xiang, Qiyu Hou, Ruixuan Li 0001 |
ICDAR (1) | 4 |