VLDB 2026 Research / reviewers in the wild / expert
Yun Feng 0003
dblp:59/7842-3
· DBLP profile ↗
11ranked-venue papers
1as first author
11since 2021 · last 2025
0009-0000-6128-7496ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 4 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ExtFPDet: A CNN-Based Detection Framework for Browser Extensions FingerprintingabstractWith the widespread use of modern browser extensions, user experience has been significantly enhanced via embedding ancillary functionality into the original webpage. The rapid development of Web tracking technology has raised privacy and security concerns, as it generates a unique identifier for users according to the diversity of installed extensions and further prompts the profiling of users. However, due to the ignorance of potential privacy risks, there is no effective method to detect browser extension fingerprinting. In this paper, we propose ExtFPDet, a CNN-based detection framework to recognize browser extension fingerprinting in websites, which fills the gap in this area. Based on the preliminary investigation, the approaches to fingerprint browser extensions can be summarized into 2 categories according to the distinctive behaviors, including resource traversing and side-channel exploring. In order to extract effective features to reflect extensions fingerprinting, ExtFPDet focuses on the structure and content in the program dependency graph of Javascript files. The generated feature vector assists the CNN-based classification model to detect the extension fingerprinting, for which we perform a systematic detection on Tranco top 10K websites. Eventually, the result is evaluated by randomly sampling and manually checking, which shows superior detection capabilities of ExtFPDet. Wei Liu 0243, Xiaoxi Wang, Yun Feng 0003, Xinyu Liu 0019, Le Gong, Kerui Huang, Yaqin Cao, Qixu Liu |
CSCWD | 3 |
| 2025 | Not All Benignware Are Alike: Enhancing Clean-Label Attacks on Malware ClassifiersabstractMachine Learning (ML) based malware classifiers are vulnerable to exploitation during the training phase due to the necessity of regular retraining with samples collected from the wild. Recent studies have highlighted the efficacy of backdoor attacks in the malware domain, where attackers can manipulate the model during training by injecting samples embedded with specific triggers, causing the model to establish an association between the trigger and a designated class, thereby achieving evasion of detection. While research on backdoor attacks has been extensively explored in the field of computer vision, it has been largely overlooked in the malware domain. Unlike in the computer vision domain, the threat model in the malware domain typically restricts attackers to employing clean-label attacks (i.e., attackers do not have control over the labeling of poisoned data). However, clean-label attack methods are generally less effective compared to those that involve embedding triggers and altering sample labels to the target class (called corrupted-label attacks). To address this limitation, we propose a simple yet effective method that involves Poisoning Malware-Similar Benignware (PMSB) instead of random selection, thereby approximating the scenario of corrupted-label attacks and enhancing the effectiveness of clean-label attacks. Additionally, we introduce three similarity measurement methods based on feature-based distance, distribution-based distance, and contribution-based difference to select malware-similar benignware. Comprehensive evaluations across three different trigger types and three datasets demonstrate the superiority and general applicability of PMSB. Xutong Wang, Yun Feng 0003, Bingsheng Bi, Yaqin Cao, Ze Jin, Xinyu Liu 0019, Yunpeng Li 0006 |
WWW | 2 |
| 2025 | WTDetect: a third-party website tracking detection framework for android applicationsabstractAbstract With the development of HTML5, tracking technologies have evolved dramatically and gradually moved from cookies to browser fingerprinting. Previous research has shown that there are more serious privacy threats associated with tracking behavior on third-party websites. However, by focusing on third-party websites that are loaded in the browser, the researchers overlooked the fact that third-party websites are also present in Android applications, where tracking is easy to perform and definitely covert to detect. In this study, we propose WTDetect, an Android third-party website tracking detection framework. Based on the parsing of view tree and the generation of function call stack, WTDetect automatically locates and captures the source code of third-party websites. To explore the direction of sensitive data flow, WTDetect performs static taint analysis on the program dependency graph for each JavaScript file. Finally, a fine-grained classification model is used to detect the tracking behavior. WTDetect is used to perform a measurement study of tracking behavior on 1090 captured Android third-party websites. The result outlines that 14.68% of third-party websites in Android applications tracking users without any access warnings and user authorization, which directly leads to the risk of privacy leakage. Wei Liu 0243, Xinyu Liu 0019, Yun Feng 0003, Kerui Huang, Ze Jin, Yaqin Cao, Qixu Liu |
Cybersecur. | 3 |
| 2024 | MemAPIDet: A Novel Memory-resident Malware Detection Framework Combining API Sequence and Memory FeaturesabstractMemory-resident malware has become a huge threat to cybersecurity. They perform malicious operations only in memory and are difficult to detect by existing technologies. Existing malware detection solutions fail to effectively extract API sequence’s semantic features and memory data features related to malicious behaviors in memory dumps. This research paper presents a novel detection framework to address these limitations. It first extracts intrinsic semantic features of API sequences from memory data using a fine-tuned BERT, then extracts executable data features from memory dumps using a pre-trained ResNet34 neural network. It then splices the two features to train a deep neural network-based detection model. We created a high-quality dataset with 2180 benign programs and 1897 recent memory-resident malware samples. We implement MemAPIDet for Windows 10. It performs better than the state-of-the-art methods with a prediction accuracy of 97.78% Kezhen Huang, Yun Feng 0003, Canhua Chen, Jinli Zhang, Yuqi Shu, Xing Tian, Qixu Liu |
CSCWD | 3 |
| 2024 | XShellGNN: Cross-file Web Shell Detection Based on Graph Neural NetworkabstractIn the ever-evolving digital landscape, the complexity of web technologies has significantly increased. This complexity highlights the limitations of traditional web defense mechanisms in offering complete protection. Web shells, especially, present a formidable challenge in the field of web security. Recognizing and addressing this challenge is of paramount importance. It necessitates innovative understandings/approaches that contribute to the collective knowledge in web security. To achieve this, our paper introduces a novel type of attack: the cross-file web shell. Alongside this, we propose a detection methodology utilizing Graph Neural Networks (GNNs). Our method leverages the Function Call Graph (FCG) to generate graph embedding, capturing both the structural and semantic nuances of code. By incorporating a variety of statistics features, our approach adeptly identifies the characteristic patterns of web shells. Utilizing deep learning, this technique allows for precise classification and detection. The efficacy of our method is demonstrated by its impressive performance in detecting cross-file web shells, achieving an accuracy of 96.65% and an F1-score of 96.63%. In addition, we simulate real-world cross-file web shell attack and successfully detecte them using our method. These results underscore the potential of our approach in significantly enhancing web security measures. Jinli Zhang, Xutong Wang, Ningjun Zheng, Kezhen Huang, Yun Feng 0003, Xiang Cui |
CSCWD | 5 |
| 2024 | Dissecting zero trust: research landscape and its implementation in IoTabstractAbstract As a progressive security strategy, the zero trust model has attracted notable attention and importance within the realm of network security, especially in the context of the Internet of Things (IoT). This paper aims to evaluate the current research regarding zero trust and to highlight its practical applications in the IoT sphere through extensive bibliometric analysis. We also delve into the vulnerabilities of IoT and explore the potential role of zero trust security in mitigating these risks via a thorough review of relevant security schemes. Nevertheless, the challenges associated with implementing zero trust security are acknowledged. We provide a summary of these issues and suggest possible pathways for future research aimed at overcoming these challenges. Ultimately, this study aims to serve as a strategic analysis of the zero trust model, intending to empower scholars in the field to pursue deeper and more focused research in the future. Chunwen Liu, Ru Tan, Yun Feng 0003, Ze Jin, Fangjiao Zhang, Qixu Liu |
Cybersecur. | 4 |
| 2023 | DeepCall: A Fast and Robust Malware Classification System with DGCNN and Function Call GraphabstractMalware has been researched hot off the press in cyber security for a long time. With the rise of machine learning algorithms, many research works attempt to apply machine learning-based methods in malware classification. However, existing machine learning-based malware classification methods rely on many various features extracted from malware samples, which may make their system lose processing speed and generality between different operational environments. These methods can not cope with massive malware samples. To improve generality and speed of classification system, we proposed a new model to classify malware with function call graphs (FCGs) extracted from their assembly code. According to previous studies, FCG is a generic feature and it is stable against metamorphic malware. Moreover, FCG extraction is not a time-consuming process. We select DGCNN (Deep Graph Convolutional Neural Network) to embed structural information inherent in FCGs for malware classification. It can make the best of the structure information stored in FCGs and make the results more convincing and accurate compared with other methods using traditional features. We use two large datasets from different operational environments containing nearly 20K malware samples to evaluate our proposed model. The experimental results show that it can classify malware represented as FCG with satisfactory accuracy and faster processing speed. Yanhui Chen, Yun Feng 0003, Chengchun Wang, Qixu Liu |
CSCWD | 2 |
| 2023 | Tabby: Automated Gadget Chain Detection for Java Deserialization VulnerabilitiesabstractJava is one of the preferred options of modern developers and has become increasingly more prominent with the prevalence of the open-source culture. Thanks to the serialization and deserialization features, Java programs have the flexibility to transmit object data between multiple components or systems, which significantly facilitates development. However, the features may also allow the attackers to construct gadget chains and lead to Java deserialization vulnerabilities. Due to the highly flexible and customizable nature of Java deserialization, finding an exploitable gadget chain is complicated and usually costs researchers a great deal of effort to confirm the vulnerability. To break such a dilemma, in this paper, we introduced Tabby, a highly accurate framework that leverages the Soot framework and Neo4j graph database for finding Java deserialization gadget chains. We leveraged Tabby to analyze 248 Jar files, found 80 practical gadget chains, and received 7 CVE-IDs from Xstream and Apache Dubbo. They both improved the security design to deal with potential security risks. Xingchen Chen, Baizhu Wang, Ze Jin, Yun Feng 0003, Xincheng Feng, Qixu Liu |
DSN | 4 |
| 2023 | IMaler: An Adversarial Attack Framework to Obfuscate Malware Structure Against DGCNN-Based Classifier via Reinforcement LearningabstractInspired by the success of graph neural network in graph data classification, graph neural networks have been widely used in malware classification and they have been proven to be the state-of-the-art malware classification models. However, most of existing adversarial samples generation techniques against machine learning-based malware classification models modify malware samples by inserting dead codes or modifying binaries directly, which is less effective against graph neural network-based malware classification models. In this paper, we propose an adversarial attack framework powered by reinforcement learning to spoof the deep graph convolutional neural network (DGCNN)-based malware classifiers called Intelligent Malware Evader (IMaler). We construct functionality-preserved manipulations based on traditional obfuscation techniques that can modify both node features and structural features of malware. The reinforcement learning agent can make optimal decisions on how to obfuscate malware with functionality-preserved manipulations. We use a large dataset with more than 10,000 samples to evaluate the performance of IMaler and use a random agent attack as a baseline attack. The experiment results show that IMaler can achieve a significantly higher evasion rate (88.26%) than the random agent attack with fewer query times. Yanhui Chen, Yun Feng 0003, Zhi Wang 0018, Chengchun Wang, Qixu Liu |
ICC | 2 |
| 2023 | MRm-DLDet: a memory-resident malware detection framework based on memory forensics and deep neural networkabstractAbstract Cyber attackers have constantly updated their attack techniques to evade antivirus software detection in recent years. One popular evasion method is to execute malicious code and perform malicious actions only in memory. Malicious programs that use this attack method are called memory-resident malware, with excellent evasion capability, and have posed huge threats to cyber security. Traditional static and dynamic methods are not effective in detecting memory-resident malware. In addition, existing memory forensics detection solutions perform unsatisfactorily in detection rate and depend on massive expert knowledge in memory analysis. This paper proposes MRm-DLDet, a state-of-the-art memory-resident malware detection framework, to overcome these drawbacks. MRm-DLDet first builds a virtual machine environment and captures memory dumps, then creatively processes the memory dumps into RGB images using a pre-processing technique that combines deduplication and ultra-high resolution image cropping, followed by our neural network MRmNet in MRm-DLDet to fully extract high-dimensional features from memory dump files and detect them. MRmNet receives the labeled sub-images of the cropped high-resolution RGB images as input of ResNet-18, which extracts the features of the sub-images. Then trains a network of gated recurrent units with an attention mechanism. Finally, it determines whether a program is memory-resident malware based on the detection results of each sub-image through a specially designed voting layer. We created a high-quality dataset consisting of 2,060 benign and memory-resident programs. In other words, the dataset contains 1,287,500 labeled sub-images cut from the MRm-DLDet transformed ultra-high resolution RGB images. We implement MRm-DLDet for Windows 10, and it performs better than the latest methods, with a detection accuracy of up to 98.34 $$\%$$ % . Moreover, we measured the effects of mimicry and adversarial attacks on MRm-DLDet, and the experimental results demonstrated the robustness of MRm-DLDet. Yun Feng 0003, Xinyu Liu 0019, Qixu Liu |
Cybersecur. | 2 |
| 2021 | Automated Honey Document Generation Using Genetic Algorithm
Yun Feng 0003, Baoxu Liu, Jinli Zhang, Chaoge Liu, Qixu Liu |
WASA (3) | 1 |