Haihua Gao

dblp:39/11147 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 CBARMM: Cluster-Based Association Rule Mining Method for Attribute-Based Access Control
abstract
Attribute-Based Access Control (ABAC) technology utilizes the inherent attributes of subjects, environments, and objects for effective access control. It is characterized by dynamic flexibility, strong scalability, granularity, and automated decision-making, making it an ideal solution for data security in big data environments. However, transitioning from traditional access control models, such as Access Control Lists (ACL) and Role-Based Access Control (RBAC), to ABAC can be a time-consuming, labor-intensive, and error-prone process, particularly when configuring security policies. Based on this, we propose the cluster-based association rule mining method (CBARMM) to automatically generate security policies from access logs and attribute files, thereby simplifying the model migration process. First, we employ the random forest algorithm to select attributes and evaluate their impact on authorization decisions. Next, we apply weight based K-modes and SD-map algorithms to extract attribute relationship filters and attribute value filters. Finally, the policy is continuously optimized through two methods of policy refinement. The experimental results demonstrate that our proposed method holds significant research and application value in the mining of attribute-based access control policies.
Haihua Gao, Lixin Zhao
CSCWD1
2025 VDPST: Enhancing Line-Level Vulnerability Detection with Patch Slicing and Transformers
abstract
Vulnerability detection is essential for ensuring software security. In recent years, deep learning has seen widespread adoption in this domain due to its capacity to automatically extract features from vulnerable code, showcasing significant potential. However, existing approaches still struggle to accurately focus on vulnerability-relevant portions within vulnerable functions, and most solutions typically offering coarse-grained localization, usually at the function level. In this paper, we propose VDPST, a novel deep learning-based approach that achieves effective vulnerability detection through program slicing and an enhanced Transformer model. VDPST introduces a patch-based denoising strategy to eliminate irrelevant code information, improving detection accuracy. Additionally, the model integrates a Transformer architecture with residual inputs and cross-attention mechanisms to preserve the contextual integrity of code snippets and enhance the detection of vulnerability-specific features. Experimental results demonstrate that VDPST outper-forms existing state-of-the-art methods on public benchmark datasets, offering superior detection accuracy and fine-grained vulnerability localization capabilities.
Shirun Liu, Zhengkai Qin, Lixin Zhao, Haihua Gao
CSCWD4
2025 LLMPEx: Automatic Extraction of ABAC Policies from Natural Language Documents Using LLMs
abstract
In the domain of enterprise security, the management and implementation of access control policies are critical for safeguarding sensitive information and maintaining system integrity. Current security standard documents and internal authorization specifications typically adopt unstructured formats with highly specialized terminology, creating challenges for non-specialist personnel such as system administrators who struggle to translate complex technical terms and logical rules into Attribute-Based Access Control (ABAC) policies due to insufficient professional expertise. These challenges often lead to misinterpretations and conversion errors that significantly undermine policy accuracy and effectiveness. To address this issue, we introduce LLMPEx, an innovative framework that leverages the semantic capabilities of large language models (LLMs) to automatically convert Natural Language Access Control Policies (NLACPs) into ABAC policies. LLMPEx integrates three core modules: a text classification module for identifying Access Control Policy (ACP) statements, an entity recognition module for extracting entity information from natural language texts, and a policy generation module that uses LLMs to automatically extract ABAC policies based on the texts and the identified entity information. The experimental results validate the effectiveness of LLMPEx in both text recognition and policy generation tasks, demonstrating that it enhances the reliability in ABAC policy creation while reducing manual efforts and potential human errors.
Haihua Gao, Lixin Zhao
SMC1
2024 A Secure Blockchain-based Reputation Scheme for Data Offloading in Edge Computing
abstract
As an extension of cloud computing, edge computing provides storage and computing services at the network edge. Due to resource limitation of edge nodes, collaborative data offloading is usually utilized to offload overloaded data in the current node to adjacent nodes to ensure quality of service. In this case, the reputation mechanism is a crucial tool to select a reliable one from adjacent nodes to provide data storage service. However, existing works usually adopt the single source-based evaluation method, which is vulnerable to malicious manipulation and lacks objectivity. Meanwhile, the reputation of malicious nodes can be rapidly recovered, leading to a reduction in evaluation accuracy. To address these issues, we propose a secure blockchain-based edge nodes reputation scheme, combined with subjective evaluation result and objective monitoring values to provide a credible reputation. Specifically, to increase the malicious attack cost and limit reputation recovery speed, we design an Amplifying-based Reputation Calculation (ARC) mechanism to amplify the impact of malicious behaviors on reputation. In addition, we propose a Dynamic Miner Selection (DMS) algorithm to resist bookkeeping right attack from malicious infrastructure providers. Detailed analysis proves the security of our scheme and experiment results testify the effectiveness and efficiency.
Jiankai Wang, Kai Chen 0012, Hongjia Li 0002, Haihua Gao, Zhen Xu 0009
CSCWD5
2011 An efficient real-time speed limit signs recognition based on rotation invariant feature
abstract
In this paper, we present a novel visual speed limit signs detection and recognition system. In detection stage, for the purpose of reducing the computational load and further decreasing the error detection rate of speed limit sign, a novel de-noising method based on HOG is presented and apply it to Fast Radial Symmetry Transform approach for circle signs detector. In recognition stage, firstly, a method of Fourier-wavelet descriptor is introduced to extract rotation invariant features which can recognize slant speed limit signs. Then the Support Vector Machines with Binary Tree Architecture are designed to identify categories of signs. Supplementary traffic signs are used to alter the meaning of speed limit signs. We propose an algorithm which is able to recognize supplementary signs with slightly rotated in a region below recognized speed limit signs. Experimental results in different conditions, including sunny, cloudy and rainy weather demonstrate that most speed limit signs and supplementary signs can be correctly detected and recognized with a high accuracy and the average processing time is less then 33ms per frame on a standard 2.8 GHz dual-core PC.
Wei Liu 0022, Jin Lv, Haihua Gao, Bobo Duan, Huai Yuan
Intelligent Vehicles Symposium3