VLDB 2026 Research / reviewers in the wild / expert
Jifan Xiao
dblp:375/7414
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2025
0000-0003-3318-1904ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Robust, Efficient, and Widely Available Greybox Fuzzing for COTS Binaries with System Call Pattern Feedback
Jifan Xiao, Peng Jiang 0007, Zixi Zhao, Ruizhe Huang, Ding Li 0001 |
USENIX Security Symposium | 1 |
| 2025 | ProvAudit: Enhance High-Level Privacy Inference Through System Provenance DataabstractCompanies such as CrowdStrike now offer cloud-based services for provenance analysis, which collects low-level system events from a customer's device and compiles them onto a centralized platform to detect APT attacks. Despite the effectiveness of such solutions, their privacy implications remain unclear. To assess the privacy implications of system provenance analysis, we employ the Website Fingerprinting (WF) of The Onion Router (Tor) browsers as the real-world attack scenario. In contrast to conventional, network traffic-based WF techniques, we have designed ProvAudit, a fully automated solution that audits the web browsing history of Tor browsers based on system provenance data. We conduct the first systematic case study to demonstrate the feasibility of inferring the websites visited by Tor browsers solely based on the collected system provenance data, particularly system call traces. The evaluation results show that our approach achieves a precision of 0.74 in the open-world scenario, higher than the state-of-the-art robust WF technique. In practice, ProvAudit consumes approximately 23 MB of memory and 4% CPU to audit system provenance data. Our approach is more robust against simple adversarial methods, more accurate, and less expensive than existing solutions. Overall, our case study reveals that provenance data is susceptible to privacy breaches, potentially exposing more high-level information than anticipated. Ding Li 0001, Jifan Xiao, Peng Jiang 0007, Jiaping Gui, Dongjin Song, Yun Ma 0002, Gang Huang 0001, Xuanzhe Liu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Detecting Malicious Websites From the Perspective of System Provenance AnalysisabstractMalicious websites are considered one of the top threats to the modern Internet. Thus, it is critical to effectively detect malicious websites for the security of the Internet. Conventional technologies typically rely on URL blacklists, or static and dynamic code analysis, which are known to have limitations. In order to effectively detect malicious websites, in this paper, we study malicious websites from the perspective of system provenance analysis for the first time. We first conduct a systematic feature engineering study on thousands of benign and malicious websites from the perspective of system provenance data. In our study, we discover eight useful features for malicious website detection. Based on these eight features, we propose ProvWeb, a novel non-intrusive system provenance-based tool, for malicious website detection. In our evaluation, ProvWeb can achieve an F1 score of 93.7% ∼ 99.7% for the four combinations of browsers and OSes (Windows Chrome, Windows Firefox, Linux Chrome, Linux Firefox). This result confirms that the features discovered in provenance graphs are effective in detecting malicious websites. Peng Jiang 0007, Jifan Xiao, Ding Li 0001, Hongyi Yu, Yao Guo 0001, Xiangqun Chen |
IEEE Trans. Dependable Secur. Comput. | 2 |