VLDB 2026 Research / reviewers in the wild / expert
Jixiang Qu
dblp:409/4067
· DBLP profile ↗
1ranked-venue papers
0as first author
1since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Malware analysis · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Software maintenance and evolution · 100% |
Topics — the 2 heaviest of 2, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis › malware detection
malicious package detection |
0.9 | 1 | 2025 | MalPacDetector: An LLM-Based Malicious NPM Package Detector · IEEE Trans. Inf. Forensics Secur. 2025 |
Software maintenance and evolution › software supply chain
software supply chain security |
0.9 | 1 | 2025 | MalPacDetector: An LLM-Based Malicious NPM Package Detector · IEEE Trans. Inf. Forensics Secur. 2025 |
Methods — techniques the papers use, named apart from their topics
large language model · 1.7automated feature generation · 1.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MalPacDetector: An LLM-Based Malicious NPM Package DetectorabstractThe Node Package Manager (NPM) registry contains millions of JavaScript packages widely shared between worldwide developers. However, NPM has also been abused by attackers to spread malicious packages, highlighting the importance of detecting malicious NPM packages. Existing malicious NPM package detectors suffer from, among other things, high false positives and/or high false negatives. In this paper, we propose a novel Malicious NPM Package Detector (MalPacDetector), which leverages Large Language Model (LLM) to automatically and dynamically generate features (rather than asking experts to manually define them). To evaluate the effectiveness of Mal-PacDetector and existing detectors, we construct a new NPM package dataset, which overcomes the weaknesses of existing datasets (e.g., a small number of examples and a high repetition rate of malicious fragments). The experimental results show that MalPacDetector outperforms existing detectors by achieving a false positive rate of 1. 3% and a false negative rate of 7. 5%. In particular, MalPacDetector detects 39 previously unknown malicious packages, which are confirmed by the NPM security team. Zhen Li 0027, Jixiang Qu, Deqing Zou, Shouhuai Xu, Ziteng Xu, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |