Xiaobing Xiong

dblp:53/7741 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
6since 2021 · last 2026
0009-0007-4707-2115ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A conditional GAN-Based framework for generating stealthy adversarial attacks on autonomous vehicle trajectory prediction systems
Haoyang Jia, Xiaobing Xiong
Expert Syst. Appl.2
2026 GAEDM: Genetic Algorithm-Enhanced Static Analysis for Detection of API Hashing Obfuscation in Malware
abstract
Malware authors increasingly exploit API Hashing to create “invisible” system calls, replacing explicit function names with dynamically computed hashes that evade detection systems. This sophisticated obfuscation technique poses three critical challenges: accurately identifying hash functions within obfuscated code, linking computed hashes to their corresponding API calls, and detecting the growing diversity of hash algorithm variants. Existing rule-based approaches fail against these adaptive threats and cannot identify modern hash variants. We propose GAEDM , a novel framework that combines deep learning with program analysis to address these challenges. Our key innovation integrates static taint analysis with a genetic algorithm-enhanced assembly language model that generates diverse training variants, enabling robust detection of previously unseen obfuscation patterns. Experimental evaluation demonstrates that GAEDM achieves 91.9% MRR and 94.6% Recall@k in hash function identification, representing improvements of 18.4% and 8.2% respectively over state-of-the-art methods. GAEDM detects sophisticated obfuscation patterns that completely evade existing approaches, enabling security analysts to uncover previously undetectable threats and significantly advancing malware defense capabilities.
Hui Shu, Zihan Sha, Xiaobing Xiong
ACM Trans. Priv. Secur.5
2026 SemAder: Evading LLM-Based Binary Code Analysis via Structure-Semantics Joint Induction
abstract
With the rapid advancement of artificial intelligence (AI), particularly the widespread adoption of large language models (LLMs) in code comprehension and analysis, their strong semantic parsing capabilities have introduced new threats to software security. Attackers can exploit LLMs to reverse-engineer the deeper semantic logic of code, steal core algorithms, or uncover vulnerabilities, thereby endangering software intellectual property and system security. This work introduces SemAder , a structure–semantics joint induction framework that generates adversarial yet function-preserving binaries to mislead LLMs’ functional judgments in binary analysis, thereby reducing the reliability of LLM-assisted semantic analysis during reverse engineering. SemAder comprises three core components: (1) a control-flow-labeled induced corpus annotated with structural tags and code semantics; (2) a hybrid similarity-driven corpus selection mechanism that favors structural proximity with semantic divergence; and (3) a reinforcement-learning-driven semantic fusion pipeline that incorporates constant externalization and context-aware semantic enhancement to strengthen induction against high-capability LLMs. Experimental results across eight LLM evaluators demonstrate that SemAder consistently shifts model predictions toward the induced target category, achieving an average induction gap of 0.77 and maintaining effectiveness under adversarial prompt variants and multi-agent post-processing workflows. SemAder also misleads the CLAP code classification model (-63.5% original-class confidence) and reduces similarity scores across four binary similarity detectors (Asm2Vec, BinDiff, SAFE, Gemini) to an average of 0.51, with only 12.7% average binary size increase and 8.8% average runtime overhead.
Hui Shu, Xiaobing Xiong, Ju Yang
ACM Trans. Priv. Secur.4
2025 SPFuzz: Program-State-Aware Fuzzing for Mail Protocols
abstract
Mail has become a crucial tool in daily work and communication, making the security testing of mail protocols essential for identifying potential vulnerabilities. Fuzzing, as one of the most widely adopted vulnerability discovery techniques, has evolved into an automated and mature method extensively applied in both software and protocol testing across industry. Recently, several fuzzers targeting network protocols have been proposed; however, they suffer from notable limitations. These include insufficient or imprecise representations of protocol states, often relying on generalized state models that fail to capture the specific internal states of individual protocols.In this paper, we address these limitations by proposing SPFuzz, a state-aware fuzzing approach for mail protocols based on program states. We investigate typical implementations of mail protocol services to determine how their internal program states interact with clients. First, we model the program state using key variables; then, we perform compile-time instrumentation to track these variables and infer runtime state transitions of the mail protocol implementations. Finally, we leverage the state information to prioritize test cases that are more likely to trigger new states and apply state feedback to refine the mutation strategy of a coverage-guided fuzzer. We implemented a prototype of SPFuzz and evaluated it on multiple real-world mail protocol programs. Experimental results demonstrate that SPFuzz significantly outperforms state-of-the-art fuzzers, including AFLNET and StateAFL, in terms of both code and state coverage. Specifically, SPFuzz achieves average improvements of 148.75% in the number of discovered states, 7.09% in state space coverage, 43.98% in map density, and 11.48% in branch coverage.
Hangzhou Fei, Xiaobing Xiong, Hui Shu
TrustCom2
2025 Code obfuscation based on deep integration
abstract
Abstract Code obfuscation is essential for software security. However, current obfuscation techniques demonstrate limited resilience against systematic reverse engineering attacks—including taint analysis and code similarity detection. Moreover, these methods often incur considerable resource overheads and recognizable obfuscation features. In this paper, we propose an innovative obfuscation algorithm that integrates the instruction and data flows of two programs at the intermediate representation level. The resulting program maintains the complete functionality of both original programs. This strategy utilizes the static and dynamic features of the parent program to obfuscate the target program. Extracting the target code from the integrated program is a significant challenge, thereby enhancing the target code’s resistance to deobfuscation. We evaluate our algorithm across various metrics: functionality correctness, obfuscation efficiency, protection strength, and resilience to automated reverse engineering techniques. Our comprehensive evaluation demonstrates that our method imposes significantly lower overhead while delivering markedly improved protection effectiveness, marking a significant advancement in software protection.
Xiaobing Xiong, Zihan Sha, Hui Shu
Comput. J.1
2022 Model of Execution Trace Obfuscation Between Threads
abstract
Advanced reverse analysis tools have significantly improved the ability of attackers to crack software via dynamic analysis techniques, such as symbol execution and taint analysis. These techniques are widely used in malicious fields such as vulnerability exploitation or theft of intellectual property. In this paper, we present an obfuscation strategy called “execution trace obfuscation,” wherein the program execution trace repeatedly switches between multiple threads. Our technique realizes equivalent code transformation by abstracting the obfuscation problems into pruning, cloning, and coloring problems in graph theory. Based on this, we further propose the cascade encryption of a function that depends on execution trace information with a key derived from the function address calculation process, followed by removing this key from the program. We have implemented a compiler-level system that inputs a source program and automatically generates an obfuscated file. Finally, random test proves the universality of obfuscation algorithm and verify the system’s performance. Results shows that our system can effectively interfere advanced reverse analysis tools.
Zihan Sha, Hui Shu, Xiaobing Xiong
IEEE Trans. Dependable Secur. Comput.3
2015 Information diffusion model in modular microblogging networks
Xiaobing Xiong, Jiangtao Ma, Ke Xu 0001
World Wide Web1
2014 Remodeling the network for microgroup detection on microblog
Xiaobing Xiong, Xiang Niu, Yongzhong Huang, Ke Xu 0001
Knowl. Inf. Syst.1
2013 Dynamic evolution of collective emotions in social networks: a case study of Sina weibo
Xiaobing Xiong, Yongzhong Huang, HaiYong Chen, Ke Xu 0001
Sci. China Inf. Sci.1
2011 Microgroup Mining on TSina via Network Structure and User Attribute
Xiaobing Xiong, Xiang Niu, Ke Xu 0001, Yongzhong Huang
ADMA (2)1
2011 Performances and Characteristics of DIGRank, Ranking in the Incomplete Networks
abstract
Page Rank has been widely used in ranking retrieval results on the web, finding the top influential papers in citation networks or detecting valuable users in online social networks. However, in practice, it is usually hard to obtain a complete structure of any above networks to rank nodes. Thus, some researchers have begun to explore how to get estimated ranks efficiently without acquiring the whole network. They have proposed some approximating methods, however, it is difficult to determine which method is the best one or which is suitable to a certain application. In this case, we set experiments in small-world and scale-free generated networks to certify the feasibility and characteristics of four approximating methods. We also use eleven real networks to mention different optimal conditions for these methods. We find the DIG Rank method performs better than other local estimation methods in almost every given sub graph. Besides, Mean field approach method tends to perform well in networks that have low average shortest path length, small amount of nodes with the same low in degree, or weak community structure. Finally, we apply the most versatile method DIG Rank to Sina micro-blog website to precisely classify users in a group as elites, grassroots or mummy users.
Xiang Niu, Lusong Li, Xiaobing Xiong, Daniel S. Tkach, Ke Xu 0001
ICDM3