VLDB 2026 Research / reviewers in the wild / expert
Jun Dai 0001
dblp:38/8202-1
· DBLP profile ↗
22ranked-venue papers
2as first author
16since 2021 · last 2026
0000-0002-6890-6429ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 8 since 2021Computer networks · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack
Xue Tan, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 4 |
| 2026 | Was My Data Used for Training? Membership Inference in Open-Source LLMs via Neural Activations
Xue Tan, Mingyu Luo, Zhuyang Yu, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 5 |
| 2026 | Characterizing Security and Privacy Risks in Smart Home IoT Device Access SharingabstractSmart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats. Yinxin Wan, Tran Ngoc Bao Huynh, Jun Dai 0001, Xiaoyan Sun 0003, Kuai Xu, Guoliang Xue |
SenSys | 4 |
| 2026 | EMPalm: Exfiltrating Palm Biometric Data via Electromagnetic Side-Channel
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Alexander M. Wyglinski, Xiaoyan Sun 0003 |
SenSys | 5 |
| 2026 | SQLaser: Detecting database management system (DBMS) logic bugs with clause-guided fuzzingabstractDatabase management systems (DBMSs) are vital components in modern data-driven systems. Their complexity often leads to logic bugs, which are implementation errors within the DBMSs that can lead to incorrect query results, data exposure, unauthorized access, etc., without necessarily causing visible system failures. Existing detection employs two strategies: rule-based bug detection and coverage-guided fuzzing. In general, rule specification itself is challenging; as a result, rule-based detection is limited to specific and simple rules. Coverage-guided fuzzing blindly explores code paths or blocks, many of which are unlikely to contain logic bugs; therefore, this strategy is cost-ineffective. In this paper, we design SQLaser, a SQL-clause-guided fuzzer for detecting logic bugs in DBMSs. Through a comprehensive examination of existing logic bugs across four distinct DBMSs, excluding those causing system crashes, we have identified 35 logic-bug patterns. These patterns manifest as certain SQL clause combinations that commonly result in logic bugs, and behind these clause combinations are a sequence of functions. We therefore model logic-bug patterns as error-prone function chains (i.e., sequences of functions). We further develop a directed fuzzer with a new path-to-path distance-calculation mechanism for effectively testing these chains and discovering additional logic bugs. This mechanism enables SQLaser to swiftly navigate to target sites and uncover potential bugs emerging from these paths. Our evaluation, conducted on SQLite, MySQL, PostgreSQL, and TiDB, demonstrates that SQLaser significantly accelerates bug discovery compared to other fuzzing approaches, reducing detection time by approximately 60%. As a standalone fuzzer, SQLaser identified 22 bugs spanning 18 of the 35 logic-bug patterns, outperforming contemporary fuzzers such as SQLRight, which only uncovered two logic bugs across two patterns within the same testing period (i.e., 60 days) when testing SQLite. Notably, four of the bugs discovered by SQLaser are zero-day, all of which have been reported to and confirmed by vendors. Ping Chen 0003, Kangjie Lu, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 4 |
| 2026 | Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF FingerprintingabstractWhile supervised deep neural networks (DNNs) have proven effective for device authentication via radio frequency (RF) fingerprinting, they are hindered by domain shift issues and the scarcity of labeled data. The success of large language models has led to increased interest in self-supervised pre-trained models (PTMs), which offer better generalization and do not require labeled datasets, potentially addressing the issues mentioned above. However, the inherent vulnerabilities of PTMs in RF fingerprinting remain insufficiently explored. In this paper, we unveil the potential threat by thoroughly investigating data-free backdoor attacks on such PTMs for RF fingerprinting, focusing on a practical scenario where attackers lack access to downstream data, label information, and training processes. To realize the backdoor attack, we carefully design a set of triggers and predefined output representations (PORs) for the PTMs. By mapping triggers and PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream RF fingerprinting tasks without requiring prior knowledge. Extensive experiments demonstrate the wide applicability of our proposed backdoor attack to various input domains, protocols, and PTMs. Furthermore, we explore potential detection and defense methods, illustrating the difficulty of fully safeguarding against our proposed data-free backdoor attack. Tianya Zhao, Junqing Zhang, Jun Dai 0001, Xiaoyan Sun 0003, Xuyu Wang |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Towards Development of Ready-to-Use Hands-on Labs with Portable Operating Environments for Digital Forensics EducationabstractDigital forensics is a critical field that plays an essential role in investigating cyber crimes, security incidents, and other crimes utilizing digital devices. Despite the heightened need for more experts in this field, the workforce faces constant shortages. For effective workforce development, the field currently lacks accessible, engaging, and valuable educational materials. To combat this issue, we propose INFER, a set of instructional hands-on labs for digital forensics education. In these labs, we designed an experiential learning experience that is a comprehensive program that is easily accessible for different levels of education in a portable environment and can be used on different operating systems. We conducted a study with students and had them take surveys before and after the labs to determine the value of the labs. We also hosted a workshop to invite professors and educators in the field to evaluate the usability of the materials. Based on the results, INFER is a beneficial resource that can help develop a future workforce of digital forensics professionals. Tran Ngoc Bao Huynh, Brian Almaguer, Jun Dai 0001, Xiaoyan Sun 0003 |
COMPSAC | 4 |
| 2025 | MagWatch: Exposing Privacy Risks in Smartwatches Through Electromagnetic Signals
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Xiaoyan Sun 0003 |
ICICS (1) | 4 |
| 2025 | What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors
Chang Yue, Kai Chen 0012, Zhixiu Guo, Jun Dai 0001, Xiaoyan Sun 0003, Yi Yang 0100 |
NDSS | 4 |
| 2025 | Optimizing IoT Cross-rule Vulnerability Detection through Reinforcement Learning-Based FuzzingabstractInternet of Things (IoT) devices have become increasingly ubiquitous and essential to daily life. These devices are usually controlled based on trigger-action rules, meaning that the devices will take actions according to the rules when trigger conditions are satisfied. As more devices are deployed in smart home systems, the risk of undesirable interactions and cross-rule vulnerabilities increases. In this paper, we propose a reinforcement learning-based fuzzing approach that can automate the modification of environmental variables to generate test cases and increase the likelihood of discovering cross-rule conflicts in smart home systems. Our approach optimizes conflict detection and discovers hidden conditions that lead to vulnerabilities. The preliminary results show that our model can successfully recognize different types of rule conflict. Tran Ngoc Bao Huynh, Yinxin Wan, Jun Dai 0001, Xiaoyan Sun 0003 |
SenSys | 4 |
| 2025 | Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS)abstractThis paper presents and advocates for an initiative to expand access to secure programming education. The Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS) initiative, funded by the National Centers of Academic Excellence in Cybersecurity (NCAE-C) program, seeks to advance secure programming and help achieve security aims. SWEEPS establishes a secure programming curriculum and workforce development coalition of seven institutions across two CAE (Center of Academic Excellence) regions (Northeast and Southwest) and five states (California, Massachusetts, Maryland, Indiana, and North Carolina). This coalition includes industry-based stakeholders collaborating with the US Army and government agencies on various projects. SWEEPS draws on prior work establishing critical concepts in secure programming, assessment tools, learning aids, and system infrastructure. The initiative offers a series of interconnected, stackable learning experiences tailored for early to mid-career professionals looking to enhance their cybersecurity skills. These experiences, which include practical one-day workshops and comprehensive year-long graduate certificates, provide a reassuring path for upskilling in secure programming. This paper recommends the efficacy of stackable training approaches in secure programming by exploring the practices of targeting and training individuals with diverse proficiency levels of programming experience who would benefit from increased knowledge and training. Deborah Kariuki, Ida Ngambeki, Jun Dai 0001, Matt Bishop, Xiaoyan Sun 0003, Melissa Dark, Jenny Daugherty, Alex Lowrie, Markus Geissler, Phillip Nico, Arshad Noor |
SIGCSE (1) | 3 |
| 2025 | HuntFUZZ: Enhancing error handling testing through clustering based fuzzingabstractTesting a program’s capability to effectively handle errors is a significant challenge, given that program errors are relatively uncommon. To address this, software fault injection (SFI)-based fuzzing combines SFI with traditional fuzzing to inject faults and trigger errors, enabling the testing of (error handling) code. However, current SFI-based fuzzing approaches have overlooked the correlation between paths housing error points. In fact, the execution paths of error points often share common paths. As a result, fuzzers usually generate test cases repeatedly to explore these common paths. This practice can compromise the efficiency of the fuzzer(s). To address this issue, this paper introduces HuntFUZZ, a novel SFI-based fuzzing framework designed to minimize redundant exploration of error points with correlated paths. HuntFUZZ achieves this by clustering these correlated error points and using concolic execution to resolve the path constraints necessary for approaching or reaching these clusters. This approach provides the fuzzer with optimized test cases, allowing it to efficiently explore error points within the cluster while minimizing redundancy. We evaluate HuntFUZZ on a diverse set of 42 applications, and HuntFUZZ successfully reveals 162 known bugs, with 62 of them being related to error handling. Additionally, due to its efficient error point detection method, HuntFUZZ discovers seven unique zero-day bugs, which are all missed by existing fuzzers. Furthermore, we compare HuntFUZZ with four existing fuzzing approaches, including AFL, AFL++, AFLGo, and EH-FUZZ. Our evaluation confirms that HuntFUZZ can cover a broader range of error points, and it exhibits better performance in terms of bug-finding speed. Ping Chen 0003, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 3 |
| 2025 | Got My "Invisibility" Patch: Towards Physical Evasion Attacks on Black-Box Face Detection SystemsabstractModern face detection (FD) systems have demonstrated remarkable performance in identifying human faces, primarily via Deep Neural Networks (DNNs). However, these DNN-driven models exhibit inherent susceptibility to adversarial attacks, posing significant risks for intentional face obfuscation from detectors. Such obfuscation can serve both malicious purposes (e.g., evading surveillance systems) and benign objectives (e.g., protecting personal privacy). Previous studies have developed techniques to compromise the effectiveness of various FD models, yet these adversarial attacks are largely confined to the digital domain—e.g., by applying adversarial perturbations to digital input images—or demand prior knowledge of the target FD systems. In this paper, we introduces a novel framework for evading black-box face detection (FD) systems in real-world scenarios. The proposed method relies on theExpectation over Attention(EoA) algorithm, which generates thePublic Attention Heat Map(PAHM) by fusing attention mechanisms across an ensemble of publicly available FD models. Our evaluation results demonstrate that EoA outperforms state-of-the-art (SOTA) methods in white-box settings and demonstrates strong cross-model transferability in black-box scenarios, effectively evading FD systems across smartphones, laptops, and surveillance cameras. Duohe Ma, Junye Jiang, Xiaoyan Sun 0003, Kai Chen 0012, Jun Dai 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | Identifying Superspreaders by Ranking System Object Instance Graphs
Rajani Suryavanshi, Xiaoyan Sun 0003, Jun Dai 0001 |
IFIP Int. Conf. Digital Forensics | 3 |
| 2023 | Validation of a Secure Programming Concept InventoryabstractSecurity failures in software arising from failures to practice secure programming are commonplace. Improving this situation requires that practitioners have a clear understanding of the foundational concepts in secure programming to serve as a basis for building new knowledge and responding to new challenges. We developed a Secure Programing Concept Inventory (SPCI) to measure students' understanding of foundational concepts in secure programming. The SPCI consists of thirty-five multiple choice items targeting ten concept areas of secure programming. The SPCI was developed by establishing the content domain of secure programming, developing a pool of test items, multiple rounds of testing and refining the items, and finally testing and inventory reduction to produce the final scale. Ida Ngambeki, Matt Bishop, Jun Dai 0001, Phillip Nico |
SIGCSE (2) | 3 |
| 2023 | Toward Efficient Homomorphic Encryption for Outsourced Databases through Parallel CachingabstractMany applications deployed to public clouds are concerned about the confidentiality of their outsourced data, such as financial services and electronic patient records. A plausible solution to this problem is homomorphic encryption (HE), which supports certain algebraic operations directly over the ciphertexts. The downside of HE schemes is their significant, if not prohibitive, performance overhead for data-intensive workloads that are very common for outsourced databases, or database-as-a-serve in cloud computing. The objective of this work is to mitigate the performance overhead incurred by the HE module in outsourced databases. To that end, this paper proposes a radix-based parallel caching optimization for accelerating the performance of homomorphic encryption (HE) of outsourced databases in cloud computing. The key insight of the proposed optimization is caching selected radix-ciphertexts in parallel without violating existing security guarantees of the primitive/base HE scheme. We design the radix HE algorithm and apply it to both batch- and incremental-HE schemes; we demonstrate the security of those radix-based HE schemes by showing that the problem of breaking them can be reduced to the problem of breaking their base HE schemes that are known IND-CPA (i.e. Indistinguishability under Chosen-Plaintext Attack). We implement the radix-based schemes as middleware of a 10-node Cassandra cluster on CloudLab; experiments on six workloads show that the proposed caching can boost state-of-the-art HE schemes, such as Paillier and Symmetria, by up to five orders of magnitude. Olamide Timothy Tawose, Jun Dai 0001, Lei Yang 0001, Dongfang Zhao 0001 |
Proc. ACM Manag. Data | 2 |
| 2018 | Situation Awareness-Oriented Cybersecurity EducationabstractThis Research to Practice Full Paper presents a new methodology in cybersecurity education. In the context of the cybersecurity profession, the `isolation problem' refers to the observed isolation of different knowledge units, as well as the isolation of technical and business perspectives. Due to limitations in existing cybersecurity education, professionals entering the field are often trapped in microscopic perspectives, and struggle to extend their findings to grasp the big picture in a target network scenario. Guided by a previous developed and published framework named “cross-layer situation knowledge reference model” (SKRM), which delivers comprehensive level big picture situation awareness, our new methodology targets at developing suites of teaching modules to address the above issues. The modules, featuring interactive hands-on labs that emulate real-world multiple-step attacks, will help students form a knowledge network instead of isolated conceptual knowledge units. Students will not just be required to leverage various techniques/tools to analyze breakpoints and complete individual modules; they will be required to connect logically the outputs of these techniques/tools to infer the ground truth and gain big picture awareness of the cyber situation. The modules will be able to be used separately or as a whole in a typical network security course. Jun Dai 0001 |
FIE | 1 |
| 2018 | Concept Inventories in Cybersecurity Education: An Example from Secure ProgrammingabstractThis Innovative Practice Work in Progress paper makes the case for using concept inventories in cybersecurity education and presents an example of the development of a concept inventory in the field of secure programming. The secure programming concept inventory is being developed by a team of researchers from four universities. We used a Delphi study to define the content area to be covered by the concept inventory. Participants in the Delphi study included ten experts from academia, government, and industry. Based on the results, we constructed a concept map of secure programming concepts. We then compared this concept map to the Joint Task Force on Cybersecurity Education Curriculum 2017 guidelines to ensure complete coverage of secure programming concepts. Our mapping indicates a substantial match between the concept map and those guidelines. Ida Ngambeki, Phillip Nico, Jun Dai 0001, Matt Bishop |
FIE | 3 |
| 2018 | A Mobile Botnet That Meets Up at Twitter
Yulong Dong, Jun Dai 0001, Xiaoyan Sun 0003 |
SecureComm (2) | 2 |
| 2018 | Using Bayesian Networks for Probabilistic Identification of Zero-Day Attack PathsabstractEnforcing a variety of security measures (such as intrusion detection systems, and so on) can provide a certain level of protection to computer networks. However, such security practices often fall short in face of zero-day attacks. Due to the information asymmetry between attackers and defenders, detecting zero-day attacks remains a challenge. Instead of targeting individual zero-day exploits, revealing them on an attack path is a substantially more feasible strategy. Such attack paths that go through one or more zero-day exploits are called zero-day attack paths. In this paper, we propose a probabilistic approach and implement a prototype system ZePro for zero-day attack path identification. In our approach, a zero-day attack path is essentially a graph. To capture the zero-day attack, a dependency graph named object instance graph is first built as a supergraph by analyzing system calls. To further reveal the zero-day attack paths hidden in the supergraph, our system builds a Bayesian network based upon the instance graph. By taking intrusion evidence as input, the Bayesian network is able to compute the probabilities of object instances being infected. Connecting the high-probability-instances through dependency relations forms a path, which is the zero-day attack path. The experiment results demonstrate the effectiveness of ZePro for zero-day attack path identification. Xiaoyan Sun 0003, Jun Dai 0001, Peng Liu 0005, Anoop Singhal, John Yen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Inferring the Stealthy Bridges Between Enterprise Network Islands in Cloud Using Cross-Layer Bayesian Networks
Xiaoyan Sun 0003, Jun Dai 0001, Anoop Singhal, Peng Liu 0005 |
SecureComm (1) | 2 |
| 2013 | Patrol: Revealing Zero-Day Attack Paths through Network-Wide System Object Dependencies
Jun Dai 0001, Xiaoyan Sun 0003, Peng Liu 0005 |
ESORICS | 1 |