VLDB 2026 Research / reviewers in the wild / expert
Lifa Wu
dblp:41/9809
· DBLP profile ↗
18ranked-venue papers
0as first author
15since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 7 since 2021Computer networks · 5 · 5 since 2021Systems, architecture and hardware · 3 · 2 since 2021Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Understanding Home Router Configuration Habits & AttitudesabstractContains fulltext : 319673.pdf (Publisher’s version ) (Open Access) Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu, Mengyuan Zhang 0001 |
CHI | 4 |
| 2025 | Precision strike: Precise backdoor attack with dynamic trigger
Qingyun Li, Wei Chen 0006, Xiaotang Xu, Lifa Wu |
Comput. Secur. | 5 |
| 2025 | An Adaptive DoH Encrypted Tunnel Detection Method Based on Contrastive LearningabstractThe percentage of encrypted network traffic has constantly increased as network security has been continuously improved. Attackers can, however, utilize encrypted DNS over HTTPS (DoH) to conceal their malicious traffic, which makes it more difficult to identify malicious tunnels. To address this issue, we first examine the encryption features of DoH tunnel traffic. Due to the incapability of current detection techniques to properly fuse traffic attributes, a fusion learning-based method is proposed to detect DoH encrypted tunnel traffic. At the same time, we discover that the DoH traffic samples may exhibit concept drift. As a result, we present a concept drift detection approach based on a contrastive sparse autoencoder. In addition to the above method, a model retraining strategy is also suggested to improve the model’s capacity to identify new DoH encrypted tunnel traffic while reducing its reliance on expert label data. This strategy involves incrementally training the model using as few samples as possible. Experiments demonstrate that the proposed method can significantly enhance detection performance. When 7% of drift samples are used during incremental training, the detection accuracy of the model recovers from 74.02% to 99.96%. Jiacheng Tong, Chongju Jin, Wei Chen 0006, Lifa Wu |
IEEE Internet Things J. | 6 |
| 2025 | Exposed by Default: A Security Analysis of Home Router Default Settings and BeyondabstractWith the popularity of the Internet, home routers have become crucial for the security of home networks. However, according to the results of our user survey, home routers are often deployed with minimal changes to the factory default settings, which may pose risks to user security and privacy. To systematically evaluate potential risks, we designed a threat-model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers from 14 brands. We found a variety of security issues, among which incorrect implementation of TLS is the most common. To improve the efficiency of manually detecting TLS certificate validation vulnerabilities without real routers, we proposed a heuristic method that can narrow down the search scope in firmware and proved its effectiveness with 30 available firmware images of the routers we purchased. Moreover, we evaluated the security of custom remote management protocols and found several cryptographic misuses. Finally, we proposed several recommendations for extending the analysis framework and discussed our ideas about automatically detecting security issues to highlight the need for heightened scrutiny of default settings and inspire other researchers. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
IEEE Internet Things J. | 5 |
| 2025 | ITransformer_CNN: a malicious DNS detection method with flexible feature extraction
Wei Chen 0006, Lifa Wu |
Peer Peer Netw. Appl. | 5 |
| 2025 | Online budget-feasible mobile crowdsensing with constrained reinforcement learning
Bolei Zhang, Lifa Wu |
J. Supercomput. | 2 |
| 2024 | Exposed by Default: A Security Analysis of Home Router Default SettingsabstractWith ubiquitous Internet connectivity, home routers have become a cornerstone of our digital lives, often deployed with minimal changes to the factory default settings. However, if left unexamined, these settings can pose risks to user security and privacy. To systematically evaluate potential risks, we developed a threat model-based framework and conducted a comprehensive analysis of 40 commercial off-the-shelf home routers, representative of recent models across 14 brands. We surveyed 81 parameters and behaviors including default and deep default settings. We identified a variety of security flaws including the exposure of IPv6 local devices due to a lack of firewall protection, vulnerable Wi-Fi security protocols, open Wi-Fi networks and trivial admin passwords for "plug-and-play" routers, and unencrypted firmware update communications. We also discovered concealed WPS PIN support --- at times associated with a trivial PIN. In total, we are reporting 30 exploitable vulnerabilities to the vendors. This paper highlights the need for heightened scrutiny of default router settings, providing valuable insights to both manufacturers and consumers for enhancing home network security. Our findings underscore the importance of meticulous device configuration, advocating for proactive measures from all stakeholders to mitigate the threats posed by insecure router default settings. Junjian Ye, Xavier de Carné de Carnavalet, Lianying Zhao, Mengyuan Zhang 0001, Lifa Wu, Wei Zhang 0122 |
AsiaCCS | 5 |
| 2024 | Privacy Protection for Image Sharing Using Reversible Adversarial ExamplesabstractOnline image sharing on social media platforms faces information leakage due to deep learning-aided privacy attacks. To avoid these attacks, this paper proposes a privacy protection mechanism for image sharing without changing the visual effect, which is based on reversible adversarial examples. Specifically, social media platform users can change the class activation feature to convert the original image into an adversarial image before sharing. When users want to restore the adversarial image to the original image, they can use an improved generative adversarial network model to restore it. The experimental results prove that the conversion model in this paper can effectively prevent privacy attacks from analyzing and stealing users' private information while having no visual impact. At the same time, the proposed restoration model can restore the adversarial examples with high accuracy. Ping Yin, Wei Chen 0006, Jiaxi Zheng, Lifa Wu |
ICC | 5 |
| 2024 | Detecting command injection vulnerabilities in Linux-based embedded firmware with LLM-based taint analysis of library functions
Junjian Ye, Xincheng Fei, Xavier de Carné de Carnavalet, Lianying Zhao, Lifa Wu, Mengyuan Zhang 0001 |
Comput. Secur. | 5 |
| 2024 | Offline Reinforcement Learning for Asynchronous Task Offloading in Mobile Edge ComputingabstractEdge servers, which are located in close proximity to mobile users, have become key components for providing augmented computation and bandwidth. As the resources of edge servers are limited and shared, it is critical for the decentralized mobile users to determine the amount of offloaded workload, to avoid competition or waste of the public resources at the edge servers. Reinforcement learning (RL) methods, which are sequential and model-free, have been widely considered as a promising approach. However, directly deploying RL in edge computing remains elusive, since arbitrary exploration in real online environments often leads to poor user experience. To avoid the costly interactions, in this paper, we propose an offline RL framework which can be optimized by using a static offline dataset only. In essence, our method first trains a supervised offline model to simulate the edge computing environment dynamics, and then optimize the offloading policy in the offline environment with cost-free interactions. As the offloading requests are mostly asynchronous, we adopt a mean-field approach that treats all neighboring users as a single agent. The problem can then be simplified and reduced to a game between only two players. Moreover, we limit the length of the offline model rollout to ensure the simulated trajectories are accurate, so that the trained offloading policies can be generalized to unseen online environments. Theoretical analyses are conducted to validate the accuracy and convergence of our algorithm. In the experiments, we first train the offline simulation environment with a real historical data set, and then optimize the offloading policy in this environment model. The results show that our algorithm can converge very fast during training. In the execution, the algorithm still achieves high performance in the online environment. Bolei Zhang, Fu Xiao 0001, Lifa Wu |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Robust Online Crowdsourcing with Strategic Workers
Bolei Zhang, Lifa Wu, Fu Xiao 0001 |
APPT | 3 |
| 2023 | An intrusion detection method based on stacked sparse autoencoder and improved gaussian mixture model
Wei Chen 0006, Lifa Wu |
Comput. Secur. | 4 |
| 2023 | Anomaly traffic detection in IoT security using graph neural networks
Mengnan Gao, Lifa Wu, Qi Li 0011, Wei Chen 0006 |
J. Inf. Secur. Appl. | 2 |
| 2023 | High-speed anomaly traffic detection based on staged frequency domain features
Jiayi Ni, Wei Chen 0006, Jiacheng Tong, Haiyong Wang, Lifa Wu |
J. Inf. Secur. Appl. | 5 |
| 2021 | A priority based path searching method for improving hybrid fuzzing
Pei-hong Lin, Zheng Hong, Lifa Wu |
Comput. Secur. | 4 |
| 2020 | Building Auto-Encoder Intrusion Detection System based on random forest feature selection
XuKui Li, Wei Chen 0006, Qianru Zhang, Lifa Wu |
Comput. Secur. | 4 |
| 2018 | Deep learning-based personality recognition from text posts of online social networks
Lifa Wu, Zheng Hong, Shize Guo, Liang Gao 0008, Zhiyong Wu 0007, Xiaofeng Zhong, Jianshan Sun |
Appl. Intell. | 2 |
| 2009 | Semantic Security Policy for Web ServiceabstractA primary problem for the security of web service is how to precisely express and match the security policy of each participant that may be in different security domain. Presently, most schemes use syntactic approaches, where pairs of policies are compared for structural and syntactic similarity to determine compatibility, which is prone to result in false negative because of lacking semantics. In this paper, we propose a novel approach to express and match the security policy of web service based on semantics. Through constructing a general security ontology, we present the definition method and matching algorithm of semantic security policy for web service. The use of semantic security policy enables richer representations of policy intent and allows matching of policies with compatible intent, but dissimilar syntax, which is not possible with syntactic approaches. The proposed security ontology is extensible and the semantic security policy is of strong inferability and adaptability, and these characteristics are extremely important to the heterogeneous and dynamic environment of web service. Zhengqiu He, Lifa Wu, Zheng Hong, Haiguang Lai |
ISPA | 2 |