VLDB 2026 Research / reviewers in the wild / expert
Chu Qiao
dblp:352/6204
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-entity time series anomaly detection method based on graph attention and cross-correlation analysis
Chu Qiao, Xuejing Fu |
Expert Syst. Appl. | 1 |
| 2025 | Secretscout: Effective Hard-Coded Secrets Detection in Ci Configuration FilesabstractContinuous Integration (CI) has been widely adopted for automated software building and testing. In CI workflows, various third-party services can be integrated to enhance functionalities. During the integration process, secrets such as tokens and credentials are often used for authentication and authorization. Unfortunately, secret leakage regularly occurs, potentially causing serious consequences. Existing secret scanners detect secrets by matching tokens and credentials through regular expressions, which suffer from low recall rates. In this paper, we identify several issues in regular expression-based secret detectors and propose SecretScout, a new method for scanning hard-coded secrets by detecting their names. SecretScout contains carefully designed detectors to extract candidates. It considers special flags where secrets might exist, and further applies filters to reduce false positives. SecretScout can detect secrets in both structured files (e.g., CI configuration files) and unstructured files (e.g., log files). To demonstrate the effectiveness, we evaluate SecretScout and different versions of GitLeaks and TruffleHog using labeled configuration files. The results show that SecretScout achieves$7.3 \times$and$100 \times$higher recall rates compared to the default versions of GitLeaks and TruffleHog, respectively. We also conduct a measurement study on open-source projects' configuration files, and demonstrate that many true secrets might be leaked. Chu Qiao, Yacong Gu, Xiaofan Li 0009, Xing Gao 0001 |
SRDS | 1 |
| 2024 | Toward Understanding the Security of Plugins in Continuous Integration ServicesabstractMainstream Continuous Integration (CI) platforms have provided the plugin functionality to accelerate the development of CI pipelines. Unfortunately, CI plugins, which are essentially reusable code snippets, also expose new attack surfaces as plugins might be developed by less trusted users. In this paper, we present an in-depth study to understand potential security risks in existing CI plugins. We conduct a comprehensive analysis of plugin implementations on four mainstream CI platforms (GitHub Actions, GitLab CI, CircleCI, and Azure Pipelines), and investigate several weak links in existing plugin distributions and isolation mechanisms. We investigate seven attack vectors that can enable attackers to hijack plugins and distribute malicious code without plugins users being aware, and further exploit hijacked plugins to manipulate the workflow execution. Additionally, we find that plugin dependency (a plugin references other plugins) might further amplify the attack impact of our disclosed attacks. To evaluate the potential impact, we conduct a large-scale measurement on GitHub and GitLab, covering a total of 1,328,912 repositories using the aforementioned CI platforms. Our measurement results show that a large number of repositories and existing plugins, including many widely used ones, are potentially vulnerable to the proposed attacks. We have duly reported the identified vulnerabilities and received positive responses. Xiaofan Li 0009, Yacong Gu, Chu Qiao, Zhenkai Zhang 0002, Daiping Liu, Lingyun Ying, Hai-Xin Duan, Xing Gao 0001 |
CCS | 3 |
| 2023 | Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesabstractContinuous Integration (CI) is a widely-adopted software development practice for automated code integration. A typical CI workflow involves multiple independent stakeholders, including code hosting platforms (CHPs), CI platforms (CPs), and third party services. While CI can significantly improve development efficiency, unfortunately, it also exposes new attack surfaces. As the code executed by a CI task may come from a less-trusted user, improperly configured CI with weak isolation mechanisms might enable attackers to inject malicious code into victim software by triggering a CI task. Also, one insecure stakeholder can potentially affect the whole process. In this paper, we systematically study potential security threats in CI workflows with multiple stakeholders and major CP components considered. We design and develop an analysis tool, CInspector, to investigate potential vulnerabilities in seven popular CPs, when integrated with three mainstream CHPs. We find that all CPs have the risk of token leakage caused by improper resource sharing and isolation, and many of them utilize over-privileged tokens with improper validity periods. We further reveal four novel attack vectors that allow attackers to escalate their privileges and stealthy inject malicious code by executing a piece of code in a CI task. To understand the potential impact, we conduct a large-scale measurement on the three mainstream CHPs, scrutinizing over 1.69 million repositories. Our quantitative analysis demonstrates that some very popular repositories and large organizations are affected by these attacks. We have duly reported the identified vulnerabilities to CPs and received positive responses. Yacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao, Hai-Xin Duan, Xing Gao 0001 |
SP | 4 |