VLDB 2026 Research / reviewers in the wild / expert
Chaoge Liu
dblp:53/10782
· DBLP profile ↗
19ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0002-8023-3941ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 6 since 2021Computer networks · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SCBot: Building Lightweight and Flexible C&C Based on Smart Contract
Chaoge Liu, Zhi Wang 0018, Yinsheng Liu, Chumeng Deng |
ICASSP | 1 |
| 2022 | Make Data Reliable: An Explanation-powered Cleaning on Malware Dataset Against Backdoor Poisoning AttacksabstractMachine learning (ML) based Malware classification provides excellent performance and has been deployed in various real-world applications. Training for malware classification often relies on crowdsourced threat feeds, which exposes a natural attack injection point. Considering a real-world threat model for backdoor poisoning attacks on a malware dataset, because attackers are generally considered to have no control over the sample-labeling process, they conduct a clean-label attack, a more realistic scenario, by generating backdoored benign binaries that will be disseminated through threat intelligence platforms and poison the datasets for downstream malware classifiers. To avoid the threat of backdoor poisoned datasets, we propose an explanation-powered defense methodology called make data reliable (MDR), which is a general and effective mitigation to ensure the reliability of datasets by removing backdoored samples. We use a surrogate model and explanation tool Shapley Additive exPlanations (SHAP) to filter suspicious samples, then perform watermark identification based on the filtered suspicious samples, and finally remove samples with the identified watermark to construct a reliable dataset. We conduct extensive experiments on two typical datasets that were manually poisoned using different attack strategies. Experimental results show that the MDR achieves backdoored samples removal rate greater than 99.0% for different datasets and attack conditions, while maintaining an extremely low false positive rate of less than 0.1%. Furthermore, to confirm the generality of MDR, we use different models to perform a model-agnostic evaluation. The results show that, MDR is a general methodology that does not rely on any specific model. Xutong Wang, Chaoge Liu, Zhi Wang 0018, Xiang Cui |
ACSAC | 2 |
| 2022 | DeepC2: AI-Powered Covert Command and Control on OSNs
Zhi Wang 0018, Chaoge Liu, Xiang Cui, Qixu Liu |
ICICS | 2 |
| 2022 | CPGBERT: An Effective Model for Defect Detection by Learning Program Semantics via Code Property GraphabstractWith the increasing complexity of software composition, code defects have become a long-term problem in software security. Traditional static analysis techniques cannot exhaustively enumerate all unsafe modes, and problems such as low path coverage rate brought by dynamic detection techniques make software security vulnerability detection inefficient. Methods based on Natural Language Processing have promoted the research of code defect detection tasks; however, there are problems of insufficient code semantic learning and limited data processing by pre-trained models. To solve these problems, from the perspective of enriching model input semantics and improving the model’s ability to process data, based on the Transformer model, we propose a hierarchical compression encoder model CPGBERT to detect whether the target function has defects. By using the regularity of the program context and structure, the program code is sliced for the input-output variables related to the objective function and dependencies on the codes’ propagation paths. Extract multiple code property graph information on rich semantics from the sliced program code for graph fusion, and embed the fused code property graph into the model by grouping. During the learning process, the independent hidden layer features are compressed and aggregated to make the model focus on the deep semantic learning of the objective function. The experiment uses the CodeXGLUE benchmark dataset and compares 6 kinds of code defect detection models having better performance to perform defect detection and effect evaluation on actual engineering code. The results show that the accuracy of the CPGBERT detection model is 67.97%, which is 5.89% higher than the CodeBERT model proposed by Microsoft and 1.35% higher than the state-of-the-art model CoTexT. Jingqiang Liu, Xiaoxi Zhu, Chaoge Liu, Xiang Cui, Qixu Liu |
TrustCom | 3 |
| 2022 | EvilModel 2.0: Bringing Neural Network Models into Malware Attacks
Zhi Wang 0018, Chaoge Liu, Xiang Cui, Xutong Wang |
Comput. Secur. | 2 |
| 2022 | A lightweight DDoS detection scheme under SDN contextabstractAbstract Software-defined networking (SDN), a novel network paradigm, separates the control plane and data plane into different network equipment to realize the flexible control of network traffic. Its excellent programmability and global view present many new opportunities. DDoS detection under the SDN context is an important and challenging research field. Some previous works attempted to collect and analyze statistics related to flows, usually recorded in switches, to address DDoS threats. In contrast, other works applied machine learning-based solutions to identify DDoS and achieved promising results. Generally, most previous works need to periodically request flow rules or packets to obtain flow statistics or features to detect stealthy exceptions. Nevertheless, the request for flow rules is very time-consuming and CPU-consuming; moreover may congest the communication channel between the controller and the switches. Therefore, we present FORT, a lightweight DDoS detection scheme, which spreads the rule-based detection algorithm at edge switches and determines whether to start it by periodically retrieving the ports state. A time-series algorithm, ARIMA, is utilized to determine the port statistics adaptively, and an SVM algorithm is applied to detect whether a DDoS attack does occur. Representative experiments demonstrate that FORT can significantly reduce the controller load and provide a reliable detection accuracy. Referring to the false alarm rate of 1.24% in the comparison scheme, the false alarm rate of this scheme is only 0.039%, which significantly reduces the probability of false alarm. Besides, by introducing the alarm mechanism, this scheme can reduce the load of the southbound channel by more than 60% in the normal state. Chaoge Liu, Qixu Liu, Jiazhi Liu, Feng Liu 0005 |
Cybersecur. | 2 |
| 2021 | GAN-Based Adversarial Patch for Malware C2 Traffic to Bypass DL Detector
Qixu Liu, Chaoge Liu |
ICICS (1) | 3 |
| 2021 | EvilModel: Hiding Malware Inside of Neural Network ModelsabstractDelivering malware covertly and evasively is critical to advanced malware campaigns. In this paper, we present a new method to covertly and evasively deliver malware through a neural network model. Neural network models are poorly explainable and have a good generalization ability. By embedding malware in neurons, the malware can be delivered covertly, with minor or no impact on the performance of neural network. Meanwhile, because the structure of the neural network model remains unchanged, it can pass the security scan of anti-virus engines. Experiments show that 36.9MB of malware can be embedded in a 178MB-AlexNet model within 1% accuracy loss, and no suspicion is raised by anti-virus engines in VirusTotal, which verifies the feasibility of this method. With the widespread application of artificial intelligence, utilizing neural networks for attacks becomes a forwarding trend. We hope this work can provide a reference scenario for the defense on neural network-assisted attacks. Zhi Wang 0018, Chaoge Liu, Xiang Cui |
ISCC | 2 |
| 2021 | Automated Honey Document Generation Using Genetic Algorithm
Yun Feng 0003, Baoxu Liu, Jinli Zhang, Chaoge Liu, Qixu Liu |
WASA (3) | 5 |
| 2020 | CoinBot: A Covert Botnet in the Cryptocurrency Network
Xiang Cui, Chaoge Liu, Qixu Liu, Zhi Wang 0018 |
ICICS | 3 |
| 2018 | Automatically Traceback RDP-Based Targeted Ransomware AttacksabstractWhile various ransomware defense systems have been proposed to deal with traditional randomly‐spread ransomware attacks (based on their unique high‐noisy behaviors at hosts and on networks), none of them considered ransomware attacks precisely aiming at specific hosts, e.g., using the common Remote Desktop Protocol (RDP). To address this problem, we propose a systematic method to fight such specifically targeted ransomware by trapping attackers via a network deception environment and then using traceback techniques to identify attack sources. In particular, we developed various monitors in the proposed deception environment to gather traceable clues about attackers, and we further design an analysis system that automatically extracts and analyze the collected clues. Our evaluations show that the proposed method can trap the adversary in the deception environment and significantly improve the efficiency of clue analysis. Furthermore, it also helps us trace back RDP‐based ransomware attackers and ransomware makers in the practical applications. Chaoge Liu, Jing Qiu 0002, Zhihong Tian 0001, Xiang Cui, Shen Su |
Wirel. Commun. Mob. Comput. | 2 |
| 2014 | POSTER: A Lightweight Unknown HTTP Botnets Detecting and Characterizing SystemabstractThe ability of the HTTP protocol to bypass Firewalls and IDSs has resulted in it becoming the most popular command and control (C&C) protocol adopted for use by most current botnets. To date, most botnet detection approaches either operate at packet-level or flow-level by identifying signatures or flow patterns. In addition, some detection technologies correlate both flow and malicious behaviors to detect botnets. However, most of these approaches relay on obvious behavior characteristics of botnets and cannot simultaneously detect and characterize unknown bots in the early stages subsequent to an infection. In an effort to rectify this situation, we studied the distribution pattern of relevant packets and determined that, in general, the first request packet from bots and the first response packet from C&C servers contain the most valuable information. Consequently, we propose a technique that automatically detects unknown HTTP botnets and generates the signatures of C&C activities on the basis of this knowledge. The results of preliminary experiments conducted indicate that our proposed approach can accurately detect unknown HTTP botnets (such as SpyEye and ZeuS) with low false positive rates and generate their signatures automatically. Chaoge Liu, Xiang Cui |
CCS | 2 |
| 2014 | POSTER: Abusing URL Shortening Services for Stealthy and Resilient Message TransmittingabstractURL shortening services (USS) have been widely used on the Internet, but are currently prone to abuse. In this poster, we exploit the possibility of building a novel stealthy and robust message transmission channel through use of USS. A text string or binary file can be transmitted stealthily using this channel. Our preliminary results show that the proposed channel is feasible and affects many popular USS, thus posing a practical threat to attackers. Fangjiao Zhang, Chaoge Liu |
CCS | 3 |
| 2014 | POSTER: Fingerprinting the Publicly Available SandboxesabstractOnline sandbox services provide an effective method for Internet users to identify suspicious programs rapidly via automated analysis reports. However, malware authors have already developed corresponding countermeasures to evade analysis. The improved malware can behave similar to normal programs or exit processes immediately when they detect that they are running inside sandbox environments. Our experiments show that most publicly available sandbox services have specific fingerprints thus can be detected easily. To rectify this problem, we propose a fingerprints randomization methodology that exploits hook techniques to defeat sandbox-aware malware. We implement the proposed techniques based on the Cuckoo sandbox, and demonstrate that it can effectively defeat sandbox-aware malware. Chaoge Liu |
CCS | 3 |
| 2013 | Sniffing and propagating malwares through WPAD deception in LANsabstractThe Web Proxy Auto-Discovery (WPAD) protocol is always used to locate a URL of a configuration file through DHCP, DNS or some other discovery methods. WPAD is a very convenience way for the management of network administrator. However, in the meantime, it may lead to a potential compromise to our LANs. In this poster, we propose a novel attack method based on WPAD protocol which can be used by attacker to intercept traffic, sniff and propagate malwares in LAN. Chaoge Liu, Xiang Cui |
CCS | 2 |
| 2013 | Botnet Triple-Channel Model: Towards Resilient and Efficient Bidirectional Communication Botnets
Xiang Cui, Binxing Fang, Jinqiao Shi, Chaoge Liu |
SecureComm | 4 |
| 2012 | Advanced triple-channel botnets: model and implementationabstractNowadays, most of research on botnet survivability only focuses on the advanced design of downstream (from botmasters to bots, used to deliver commands) command and control (C&C) channel. However, the upstream (from bots to botmasters, used to upload the collected data on victims) C&C channel remains vulnerable and low-efficiency in most of botnets to this day. To address the problem, we propose a C&C channel division scheme and then establish a Botnet Triple-Channel Model (BTM). BTM divides a traditional C&C channel into three independent sub-channels, denoting as Command Download Channel (CDC), Registration Channel (RC) and Data Upload Channel (DUC), respectively. To illuminate the feasibility and advantages, we implement a BTM botnet prototype which exploits URL Flux for CDC, Domain-flux for RC, and introduces a new approach (Cloud-based File Hosting and URL Shortening Services) for DUC. Compared with current botnets, the proposed BTM botnet will promise to be as robust as P2P botnets and as efficient as centralized botnets. The ultimate goal of our work is to increase the understanding of advanced botnets which will promote the development of more efficient countermeasures. Xiang Cui, Binxing Fang, Chaoge Liu |
CCS | 4 |
| 2012 | The Triple-Channel Model: Toward Robust and Efficient Advanced Botnets (Poster Abstract)
Xiang Cui, Jinqiao Shi, Chaoge Liu |
RAID | 4 |
| 2011 | Poster: recoverable botnets: a hybrid C&C approach
Xiang Cui, Chaoge Liu |
CCS | 4 |