Yamin Xie

dblp:362/2686 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2026
0009-0007-2170-7434ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain
Qihang Zhou, Shaowen Xu, Yamin Xie, Xiaoqi Jia
DSN5
2026 FlexClave: An Extensible and Secure Trusted Execution Environment Framework
abstract
As computer system software stacks become increasingly complex, the associated security risks also escalate. Trusted Execution Environments (TEEs) have emerged as a mainstream security solution to enhance system security. TEEs can be categorized into user-level TEEs, OS-level TEEs, and hybrid TEEs. However, these TEEs typically possess fixed security boundaries and isolation domains, limiting their adaptability to varying security requirements and dynamic scenarios. Moreover, the design of Trusted Computing Base (TCB) components in TEE frameworks often operates at the highest privilege levels of the architecture. This concentration of critical code at the highest privilege level increases the whole platform’s security risk due to the growing amount of code as more security functions are added. In this paper, we propose FlexClave, an extensible and secure TEE framework designed to address these issues. FlexClave leverages hardware primitives to create secure isolation boundaries tailored to different use cases. Additionally, our framework distributes TCB components across various privilege levels, reducing the concentration of security functions at the highest privilege levels and mitigating the risks associated with running extensive code in a single, highly privileged context. We implement two prototypes on ARMv9-A Fixed Virtual Platform and ARMv8 RK3399 SoC, each with two use cases (container and virtual machine), to evaluate the system’s security and performance.
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shaowen Xu, Jiayun Chen, Haichao Du, Yamin Xie, Peijie Yin, Shengzhi Zhang, Peng Liu 0005
IEEE Trans. Computers10
2025 EMHunter: An Evasive Malware Detection Approach to Improve Dynamic Analysis Efficiency
abstract
Currently, a growing number of malware employ evasion techniques to hinder security analysts from analyzing their dynamic behavior, making them more likely to evade detection and pose a threat to users. The above malware is classified as Evasive Malware. To address this issue, we collect a dataset of labeled samples and propose a novel analysis method for evasive malware detection called EMHunter (Evasive Malware Hunter). After injecting samples into a specially designed software environment, EMHunter modifies the section table to launch from a designated location, and alters the export table to disable evasion-related behavior via identifying 48 commonly used APIs. When the malicious code attempts evasive actions, such as detecting if it's running in an analysis environment, the software cooperates with the dynamic analysis environment to determine the malware's key characteristics. It then selects appropriate countermeasures to lure the malicious code into continued execution, thereby exposing more malicious behavior and improving the accuracy of dynamic analysis. Our dataset consists of 12,543 samples, experiments show that this method successfully induced 4084 samples to exhibit their behavior. Furthermore, we integrated EMHunter into the open-source sandbox CAPE, enabling it to gather more behavioral information from the samples. Finally, we evaluated our approach using a LightGBM model, achieving the accuracy of 96.61%.
Yamin Xie, Zhengcai Chen, Haichao Du, Xiaoqi Jia, Jianwu Ni
CSCWD1
2024 vASP: Full VM Life-cycle Protection Based on Active Security Processor Architecture
abstract
Cloud computing has been applied on a large scale due to its competitive advantages. However, the introduction of virtualization brings new risks, which can come from within the VM and the host. Due to the abstraction of hardware resources by the hypervisor, traditional trusted computing methods, such as TPM and ASP, are no longer available in cloud environments. Existing work focusing on enabling trusted computing in cloud computing is primarily based on TPM and vTPM, but there are still issues such as the trusted chain not covering all stages of the VM life cycle and the integrity measurement operation potentially causing high overhead. In this paper, we present the vASP architecture, which solves the limitation of the ASP architecture in a cloud environment. Using customization features provided by the ASP, we customize interfaces for the vASP architecture and pass the trusted relationship to the upper layer to form a complete chain of trust. The vASP front-end plugs into the hypervisor actively and regularly operates the dynamic measurement process of the guest to ensure that data from the guest machine are not tampered with. With the introduction of vASP in the cloud computing platform, the security of vASP components during VM operation is also a concern. As a result, we propose a full VM life-cycle protection method through verification and measurement mechanisms that cannot be bypassed to ensure that vASP maintains a match with specific VMs. We have implemented the vASP architecture on a commercial platform deployed with ASP architecture and evaluated it. The result shows that the vASP architecture can protect VM integrity well during full life-cycle and has very low overhead compared to the native virtualization architecture.
Jiayun Chen, Qihang Zhou, Weijuan Zhang, Yamin Xie, Xiaoqi Jia
CCGrid5
2024 Structure-Sensitive Pointer Analysis for Multi-structure Objects
abstract
Static analysis is a method within software analysis, and pointer analysis is an important component of static analysis. An important dimension of pointer analysis is field-sensitivity, which has been proven to effectively enhance the accuracy of pointer analysis results. A crucial area of research within field-sensitivity is structure-sensitivity. Structure-sensitivity has been shown to further enhance the precision of pointer analysis. However, existing structure-sensitive methods cannot handle cases where an object possesses multiple structures.
Xun An, Xiaoqi Jia, Haichao Du, Yamin Xie
Internetware4
2024 Malware Classification Method Based on Dynamic Features with Sensitive Behaviors
abstract
Traditional malware classification methods often just scratch the surface by analyzing the sequence of system commands (API calls) used by malware during its operation. These approaches miss out on deeper, complex behaviors that could significantly enhance accuracy in identifying different malware types. To address this, we introduce SenBeMC, a method that delves deeper into the behaviors exhibited by malware. SenBeMC combine API call information vectors with behavioral information to enhance the deep semantic information of input features, enriching the hierarchical structure of feature representation. SenBeMC stands out by employing soft thresholding and attention mechanisms to sift through the noise — extraneous information that can mask the malware's true nature, and a BiLSTM model that excels in understanding the sequence and timing of actions, crucial for spotting sophisticated threats. Experimental evaluations on real-world datasets affirm that SenBeMC effectively improves feature representation and accuracy of malware classification when compared to other contemporary state-of-the-art models.
Yamin Xie, Siyuan Li 0014, Zhengcai Chen, Haichao Du, Xiaoqi Jia, Yuejin Du
SMC1
2024 SecureNet-AWMI: Safeguarding Network with Optimal Feature Selection Algorithm
abstract
Deep learning has emerged as a leading method for detecting network intrusion threats. However, processing large volumes of data increases computational time costs, and noise in the data can reduce detection rates. To address these challenges, feature selection algorithms are essential for balancing time efficiency and detection accuracy. Feature selection algorithms for intrusion detection systems (IDS) face two primary challenges: selecting the most suitable features for the model and managing data imbalances. Traditional methods often rely on manual selection based on feature importance, which can lead to significant computational errors. And they cannot detect attacks with smaller proportions in complex and variable network traffic. We design a secure network intrusion detection framework SecureNet-AWMI to balance attack distribution by augmenting the low-frequency attack samples and reducing the high-frequency attack samples. The core of SecureNet-AWMI is a feature selection component that uses mutual information theory and adjusts weights to account for different types of attacks. To enhance threat detection and classification, we employ an advanced Convolutional Neural Network (CNN) model enhanced with Bidirectional Long Short-Term Memory (BiLSTM) and an attention mechanism. Comparative experiments on three public datasets – CICIDS2017, UNSW-NB15, and NSL-KDD – show that SecureNet-AWMI outperforms current mainstream feature selection and threat classification techniques.
Ming Zhou 0010, Zhijian Zheng, Peng Zhang 0044, Sixue Lu, Yamin Xie, Zhongfeng Jin
TrustCom5
2023 Log2Policy: An Approach to Generate Fine-Grained Access Control Rules for Microservices from Scratch
abstract
Microservice application architecture is one of the most widely used service architectures in the industry. To prevent a compromised microservice from abusing other microservices, authorization policy is applied to regulate the access among them. However, configuring access control policy manually is challenging due to the complexity and dynamic nature of microservice applications. In this paper, we present Log2Policy, a novel approach to generate microservice authorization policy based on access logs. Our approach consists of three fundamental techniques: (1) a log-based topological graph generation mechanism that automatically infers the invocation logic among microservices, (2) a machine learning based attributes mining method that extracts the relevant attributes of requests, and (3) a policy upgrade mechanism based on traffic management that can significantly reduce the upgrade time. We have implemented a prototype of Log2Policy on mainstream microservice infrastructures and have evaluated it with several microservice applications. The results show that Log2Policy can generate fine-grained and effective access control rules and upgrade them with negligible overhead.
Shaowen Xu, Qihang Zhou, Heqing Huang 0001, Xiaoqi Jia, Haichao Du, Yamin Xie
ACSAC7