Xiao Fu 0005

dblp:60/4601-5 · DBLP profile ↗
← Back
27ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0002-2263-4309ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 10 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CHASE: Contextual History for Adaptive and Simple Exploitation in Large Language Model Jailbreaking
abstract
We propose Contextual History for Adaptive and Simple Exploitation (CHASE), a novel multi-turn method for Large Language Model (LLM) jailbreaking. Rather than directly attack an LLM that may be difficult to jailbreak, CHASE first collects jailbroken histories from an easy-to-jailbreak LLM and then transfers them to the target LLM. Through this history transfer process, CHASE misleads the target LLM into thinking that it is responsible for producing the jailbroken histories and increases the chances of successful jailbreaking by prompting it to continue the conversation. Extensive evaluations on mainstream LLMs show that CHASE consistently achieves higher attack success rates and demands fewer computational resources compared to existing methods.
Zhiqiang Hao, Chuanyi Li, Xiao Fu 0005, Shangqi Wang, Jiao Yin 0007, Jidong Ge, Bin Luo 0003, Vincent Ng 0001
AAAI5
2026 Gambling Account Detection for Social Network Security
Xiaohang Fu, Xiao Fu 0005, Qing Gu 0001, Xiaojiang Du, Nadjib Aitsaadi
ICC3
2026 Defense against data poisoning attacks in robot vision systems based on adversarial example detection
Ruiqing Chu, Xiao Fu 0005, Bin Luo 0003
Frontiers Comput. Sci.2
2026 Aligning large language models across the lifecycle: A survey on safety-usability trade-offs from pre-training to post-training
Zhiqiang Hao, Hongming Fei, Xiao Fu 0005, Bin Luo 0003
Neural Networks4
2024 Leveraging Hierarchies: HMCAT for Efficiently Mapping CTI to Attack Techniques
Zhiqiang Hao, Chuanyi Li, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du
ESORICS (4)3
2024 GeneDroid Fuzz: An Android Intent Fuzzing Method Based on Gene Mutation
abstract
With the rapid expansion of mobile internet usage, the prevalence of the Android operating system on smartphones is steadily growing. However, improper utilization of the Intent mechanism within Android applications can result in security vulnerabilities. Presently, the majority of Android security testing methods, which rely heavily on fuzzing, are predominantly focused on UI interactions, lacking sufficient testing capabilities for Intents. The motivation of this paper is to find a more effective testing method to improve the security detection capabilities of Intents. This paper introduces an Intent fuzzing method based on genetic mutation principles. Initially, we establish an Intent seed library using a text classification model, followed by employing Jaccard distance and minimum edit distance to refine high-quality seeds. Subsequently, we augment the seeds through extensive mutation using genetic algorithms, generating numerous test cases that exhibit structural similarity but contain varied content. During testing, we compare the state before and after Intent testing using image similarity to detect anomalies. Experimental results demonstrate that this method effectively enhances test coverage and identifies potential issues in edge cases. This approach offers an efficient means of conducting Intent security testing and enhances Android app robustness and security.
Runfeng Lu, Yuzhu Sun, Haofeng Sun, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Nadjib Aitsaadi, Mohsen Guizani
GLOBECOM4
2024 A Privacy Preserving Method for IoT Forensics
abstract
The diversity of the Internet of Things (IoT) poses challenges to privacy protection, especially in the field of digital forensics. How to ensure that only the private information of the suspect is provided, and not the irrelevant information of other users is disclosed is crucial, especially when obtaining evidence in the complex IoT environment. To the best of our knowledge, there are few studies on protecting the privacy of irrelevant users in the IoT forensics. However, it is very important to ensure that the evidence does not violate the privacy of other users when collecting evidence, because it directly determines whether the evidence is legal and whether it can be admissible in court. In this paper, a new method based on data provenance graph is designed to solve the privacy protection problem of IoT forensics. The key idea of this method is to protect privacy by dividing multi-user information and protecting it from an encryption perspective. The method consists of three main phrases: distinguishing different users' data provenance graphs using traversal search, node abstraction, and hiding techniques, utilizing pseudo-random dual-key negotiation methods tailored for the scenario to enhance privacy protection for unrelated users, and employing identity authentication technology to facilitate better investigation and extraction of data provenance graph information of criminal accomplices in specific scenarios. Example proves that this method has practical significance and promising application prospects in protecting the privacy of unrelated users in IoT forensics while ensuring evidence accessibility in special criminal scenarios.
Boxi Chen, Xiao Fu 0005, Qing Gu 0001, Xiaojiang Du
GLOBECOM3
2024 A Crowdsourcing Digital Forensics Platform for IoT Environments Powered by Blockchain
abstract
Digital forensics is a security research field that has evolved with the advancement of digital technologies, such as computer and network technology. With the emergence of complex forensic environments, such as those found in the IoT and cloud computing, investigators are required to possess higher technical capabilities and knowledge. Completing digital forensics tasks more effectively has become a challenge. Therefore, this paper proposes a blockchain-based collaborative crowdsourcing platform for digital forensics. Through collaborating on the crowdsourcing platform, professional investigators can enhance the supervision of the digital forensics process, reduce the difficulty of digital forensics tasks, and improve their quality. In addition, we introduce blockchain technology to maintain the credibility of the investigation process. We have developed a smart contract and conducted experiments based on Ethereum. The experimental results show that our solution is feasible.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du
ICC2
2023 Convolutional Neural Network Based Classification of WeChat Mini-Apps
abstract
In recent years, a novel mobile computing paradigm has been evolving rapidly, with a host app allowing users to install and run mini-apps inside the app itself. However, the current classification mechanism of mini-apps is blurry and coarse-grained, making users unable to clearly understand mini-app functions, which can result in a series of privacy issues. In this study, an automatic convolutional neural network (CNN)-based classification approach is proposed for Wechatmini-apps. The proposed method integrates the static and dynamic features of WeChat mini-apps to achieve precise classification. Our approach was evaluated in a real-world testbed and the results showed that it can effectively classify Wechatmini-apps into proper categories, helping users better understand the functions of WeChat mini-apps while reducing user privacy violations.
Yihao Jin, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
ICC3
2023 Machine Learning-Based Non-Intrusive Digital Forensic Service for Smart Homes
abstract
Security and privacy concerns keep growing with the successful development of Internet of Things (IoT) and the booming deployment of smart homes. IoT devices are utilized cooperatively to enable the interactions between home surroundings and users’ daily lives, containing forensically-valuable information about what happens in smart homes, which can help introduce digital forensics into smart homes to alleviate the growing concerns. However, current IoT devices, apps, and platforms usually do not provide built-in capabilities for digital forensics. To overcome this limitation, we propose a non-intrusive solution (i.e., bringing no modification to IoT devices, apps, and platforms) of digital forensic service to provide Forensics-as-a-Service (FaaS) for smart homes. First, it leverages side-channel analysis on sniffed network traffic to monitor commands, actions, and states of IoT devices. Then, it introduces provenance graphs (i.e., causal graphs) for smart home modeling to provide a holistic and overall explanation of smart homes. Machine learning (ML) techniques are applied to overcome the deficiency of a non-intrusive solution as it suffers from challenges in data collection and smart home modeling. Finally, it conducts forensic analysis based on scalable, reusable policies that are designed for graph-based smart home modeling. We implement a prototype of our forensic service and evaluate it in a real-world smart home. The evaluation results show that our forensic service can effectively collect forensic data for smart home modeling and conduct forensic analysis to explain security risks in smart homes.
Xiao Fu 0005, Xiaojiang Du, Bin Luo 0003, Mohsen Guizani
IEEE Trans. Netw. Serv. Manag.2
2022 Using Cloud Computing Based Crowdsourcing for Security and Privacy Settings of Android Users
abstract
With the widespread use of mobile devices, security and privacy concerns have been attracting increasing attention. However, it is challenging for Android users to apply the appropriate settings to protect their devices. Therefore, a cloud-based solution is proposed in this paper, which works based on crowdsourcing to generate recommended security and privacy settings for Android users. Following the suggestions of security experts, ordinary users can readily understand how to properly set up their devices for security enforcement. Our solution collects security-related data from experts, and a weight-based algorithm is introduced to determine data priority and credibility. Finally, the recommended security and privacy settings are created based on these data. The evaluation results demonstrate that our solution can effectively improve the robustness and reliability of Android devices.
Yuzhu Sun, Tianchi Wu, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM4
2021 Understanding Digital Forensic Characteristics of Smart Speaker Ecosystems
abstract
With a built-in intelligent personal voice assistant providing Q&A services, smart speaker ecosystems combine multiple compatible components, including the internet of things (IoT) technology, mobile devices, and cloud computing. However, as it is closely related to people's daily lives, security and privacy issues have gained worldwide attention. Components in the ecosystem are interconnected and chained together to enable the ecosystem to perform increasingly diverse operations. By collecting meaningful data from smart speaker ecosystems, we can reconstruct user behavior and provide a holistic explanation for finding the root cause of an observable symptom. This highlights the need for digital forensic research to enhance the security and privacy of smart speaker ecosystems. In this paper, we first discuss the digital forensic characteristics of a smart speaker ecosystem. Then, we propose a proof-of-concept digital forensic tool based on data provenance, that supports the identification, acquisition, and analysis of client-side artifacts from local devices.
Ang Li 0012, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM3
2021 Visible Forensic Investigation for Android Applications by Using Attack Scenario Reconstruction
abstract
With the widespread use of Android devices, research on their security has attracted increasing attention. However, at present, digital forensics for investigating attacks, such as social engineering attacks and phishing that target Android users, remains a challenging and time-consuming task. To help discover the existence of an attack and conduct effective investigations, we propose a top-down digital forensic tool for Android applications to reconstruct attack scenarios by considering both high-level user interface (UI) elements and low-level system events. Thus, we can explain the nature of an attack from a visual and global perspective. The tested evaluation results show that our tool can successfully reconstruct scenarios on Android devices for phishing attacks.
Shiwen Song, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM3
2021 A Non-Intrusive Method for Smart Speaker Forensics
abstract
With the rapid development of the Internet of Things technology, smart speakers have become increasingly popular. However, smart speaker security is an ensuing threat. At present, smart speakers are activated by voice, and they monitor users’ voices 24 hours per day. Consequently, there may be problems with user privacy leakage. In this paper, we propose a non-intrusive digital forensic method for smart speakers. The main contribution of the paper is an effective method of combining network traffic analysis with the extraction of user intent and alarms about abnormal network traffic to support the investigation of security. We use Xiaomi smart speakers as an example in an experiment to verify our forensic method. The evaluation results show that our method works well for detecting security risks.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
ICC3
2021 SniffMislead: Non-Intrusive Privacy Protection against Wireless Packet Sniffers in Smart Homes
abstract
With the booming deployment of smart homes, concerns about user privacy keep growing. Recent research has shown that encrypted wireless traffic of IoT devices can be exploited by packet-sniffing attacks to reveal users’ privacy-sensitive information (e.g., the time when residents leave their home and go to work), which may be used to launch further attacks (e.g., a break-in). To address the growing concerns, we propose SniffMislead, a non-intrusive (i.e., without modifying IoT devices, hubs, or platforms) privacy-protecting approach, based on packet injection, against wireless packet sniffers. Instead of randomly injecting packets, which is ineffective against a smarter attacker, SniffMislead proposes the notion of phantom users, “people” who do not exist in the physical world. From an attacker’s perspective, however, they are perceived as real users. SniffMislead places multiple phantom users in a smart home, which can effectively prevent an attacker from inferring useful information. We design a top-down approach to synthesize phantom users’ behaviors, construct the sequence of decoy device events and commands, and then inject corresponding packets into the home. We show how SniffMislead ensures logical integrity and contextual consistency of injected packets, as well as how it makes a phantom user indistinguishable from a real user. Our evaluation results from a smart home testbed demonstrate that SniffMislead significantly reduces an attacker’s privacy-inferring capabilities, bringing the accuracy from 94.8% down to 3.5%.
Qiang Zeng 0001, Xiaojiang Du, Siva Likitha Valluru, Chenglong Fu 0002, Xiao Fu 0005, Bin Luo 0003
RAID6
2020 Cloud Storage Forensics: BaiduNetDisk, WeiYun, and 115yun on a Wireless Network
abstract
With the development of cloud computing and wireless networks, cloud storage services are widely used in daily life. People can get access to cloud storage anytime and anywhere. Cloud storage forensics is a computer forensic scenario that currently appears frequently. In this paper, we first briefly introduce the general methods of traditional cloud storage forensics and then introduce forensic investigations that are conducted on three cloud storage services: BaiduNetDisk, 115yun, and WeiYun. The findings of the forensic analysis are presented in detail to help the development of forensics for cloud storage services.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2020 Forensic Model for DDoS Attack
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2019 Cloud Database Encryption Technology Based on Combinatorial Encryption
abstract
Traditional cloud database directly stores user plaintext information, information security is directly related to the security of Cloud server, which will create a great security risk. The user's information security is not guaranteed. In this paper, a database encryption technology is designed, which can balance the problem of information security and use efficiency well. In this paper, a simplified onion encryption model is designed and implemented, which can realize the full homomorphic encryption on the cloud database to a certain extent, and improve the efficiency of ciphertext operation to a certain extent.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2019 A Design of Firewall Based on Feedback of Intrusion Detection System in Cloud Environment
abstract
Security is critical to cloud services, this paper introduces a design of firewall, which based on IDS's feedback t change rules in order to detect attack flexible. It combines firewall and Intrusion Detection Systems(IDS) by using Intrusion Detection Systems, which detects ICMP, TCP, UDP attacks. Usually, a cloud service is a service built on a virtual machine. The virtual device is virtualized to achieve the purpose of multiplexing. Therefore, if you want to implement cloud security detection, you can listen to the physical device's network card. There are two types of Intrusion Detection System, one is host- based intrusion detection system(HIDS) and another is network intrusion detection system(NIDS). What's more, in order to highlight the importance of the firewall, the IDS monitoring data is analyzed and added to the firewall's defense strategy automatically. Finally, we measure the effectiveness of the system by False Negative(FN) and False Positive(FP), and verify that feedback plays a crucial role in improving the effectiveness of the system, improving the efficiency of the entire system filtering attacks.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2018 Monitoring User-Intent of Cloud-Based Networked Applications in Cognitive Networks
abstract
The cognitive network system learns from the past (situations, plans, decisions, actions) and uses this knowledge to improve the decisions in the future. Scenarios in which data resources for configuring radio-system parameters are stored in the cloud for easily sharing and exchanging between nodes are foreseeable. Due to the physical inaccessibility and limited control, it is always a tough topic to formulate appropriate access control strategies for the cloud data and data access requests submitted by applications are not always correct and credible. Cloud servers cannot clearly confirm that these requests are consistent with a user's original intent. In this paper, we propose a new access control method and forensic framework for user-intent monitoring of cloud-based networked applications in cognitive networks. Our framework has two main functions. Firstly, it makes sure that every data access request submitted by applications is correct. This means that it accurately shows what it wants. Monitoring user-intent can also help the cognitive engine to make decisions in turn. Secondly, it can offer adequate details to help forensic analysts reconstruct a precise view of user interaction with applications and understand system conditions. Our framework can function correctly in untrusted environments and is transparent to applications, systems and communication environments. It incurs no discernible performance overhead.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2017 AutoPatchDroid: A framework for patching inter-app vulnerabilities in android application
abstract
Recently, an increasing number of inter-app attacks such as confused deputy attacks, data leakage attacks and collusion attacks spring up. However, there is no perfect defense method against them. As we all know, developers play an important role in android security, but their weak consciousness about the security may lead to inter-app attacks. Therefore, considered for developers, it is important to investigate and try to defend against such attacks in android. This paper presents typical inter-app attacks in android and proposes AutoPatchDroid, an automatic framework to find the vulnerable code in apps and patch them automatically. We firstly find the vulnerable paths from sources to sinks, sources to execution exit points, execution entry points to sinks and execution entry points to execution exit points in the application using static analysis. Then we locate the vulnerable code pieces and insert the patch code to guard against such attacks. AutoPatchDroid prevent inter-app attacks in the application level rather than modifying the kernel or framework. We use DroidBench and IccRE to evaluate our framework, and find that AutoPatchDroid could effectively secure the apps. The runtime overhead introduced by AutoPatchDroid is 1.105% on average.
Jiayun Xie, Xiao Fu 0005, Xiaojiang Du, Bin Luo 0003, Mohsen Guizani
ICC2
2017 Analyzing Android Application in Real-Time at Kernel Level
abstract
The wide spread of mobile devices has also caused the explosive growth of malwares. Application behavior analysis is a popular technique to fight against malwares. However current app behavior analysis methods still have some limitations. For example, many popular dynamic analysis methods are built on Dalvik virtual machines. They cannot disclose the behavior of native code. VMI based methods can overcome this limitation but they're executed in simulated environments. Now malwares can detect where they are running so as to hide the illegal behaviors by anti-forensic techniques. Considering these, we present the DroidRevealer. It is based on kernel-level system calls monitoring and it's running on real android devices. By intercepting and interpreting certain file/network related and android-specific system calls, it can reconstruct app behaviors in real-time. It's difficult to evade as it runs in the kernel. And its results do not simply focus on a single kind of behavior or a single app. Instead it is data oriented, i.e. it monitors how the target data source is used. The result is presented as an intelligible graph which can provide both a good basis for detection and crucial evidence for forensics. Experiments have proved that the performance of our method is acceptable.
Hao Ruan, Xiao Fu 0005, Xiaojiang Du, Bin Luo 0003
ICCCN2
2017 A lightweight live memory forensic approach based on hardware virtualization
Yingxin Cheng, Xiao Fu 0005, Xiaojiang Du, Bin Luo 0003, Mohsen Guizani
Inf. Sci.2
2015 Haddle: A Framework for Investigating Data Leakage Attacks in Hadoop
abstract
Nowadays Hadoop is popular among businesses and individuals for its low costs, convenience, and fast speed. However, this also makes it the goal of data leakage attacks as sensitive data stored with an HDFS infrastructure grows rapidly. Therefore, it is important to investigate such attacks in Hadoop. Several works have been done on improving the security of Hadoop, but hardly any have been done on data leakage investigation. This paper presents a typical data leakage attack scene in Hadoop and proposes Haddle (Hadoop Data Leakage Explorer), a forensic framework composed of automatic analytical methods and on-demand data collection based on two stages. With the assistance of Haddle, investigators can find the stolen data, find the perpetrator who stole the data, and reconstruct the crime scene. Also, Haddle can help improve the audit mechanism of Hadoop.
Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du, Mohsen Guizani
GLOBECOM2
2015 Detective: Automatically identify and analyze malware processes in forensic scenarios via DLLs
abstract
Current memory forensic methods mainly focus on evidence collection and data recovery. A little work is about how to automatically identify malwares from many unknown processes and analyze their behaviors in high semantic level so as to collect related evidences. In fact, in real cases, investigators are often faced with large number of processes that they have no knowledge of. Although current malware detection tools could provide some help, they usually can't illustrate the purposes, abilities and behavior details of malwares and are thus often not fit for the forensic requirements. In this paper, we present a framework named Detective to cope with these issues. Given a set of unknown processes, Detective can classify benign and malware processes automatically. This is implemented by HNB classifying algorithm and a Dynamic-Link Libraries-based model. Detective could then explain malware behaviors in high semantic level through clustering and frequent item sets mining techniques. Besides, Detective sheds light on evidence collection by the information obtained from previous steps. Detective is applicable for both online and offline forensic scenarios. Experiments on real-world malware set have proved that the accuracy of Detective is above 90% and the time cost is only several seconds.
Yiheng Duan, Xiao Fu 0005, Bin Luo 0003, Xiaojiang Du
ICC2
2015 Data correlation-based analysis methods for automatic memory forensic
abstract
Abstract Memory forensics is an important technique for protecting network security and fighting against computer crimes. It has developed greatly in the past decade, because memory can provide more reliable information that other evidence sources do not contain. However, nowadays, when investigating network criminal cases, the Gigabyte (GB) and even Terabyte (TB) level memory and many such dumps have made memory analysis a difficult task. And investigators usually have to deal with complex operating system (OS) data structures, which they have little knowledge of. So how to analyze memory evidence automatically so as to find the hidden criminal behavior and reconstruct the scenario in an understandable way has become an important problem. This paper presents an automatic memory analysis methodology based on data correlation. Through analyzing key OS data structures and utilizing a clustering algorithm, this methodology can discover the relationships among processes, files, users, Dynamic‐link library (DLLs), and network connections. By describing these relationships as correlation graphs, our methods can reorganize these independent memory evidences and disclose their meanings in a high semantic level. Experiments have proved that these correlation graphs can help investigators find hidden criminal behavior and reconstruct the criminal scenarios. And as we know, now, little work is in this field. Copyright © 2015 John Wiley & Sons, Ltd.
Xiao Fu 0005, Xiaojiang Du, Bin Luo 0003
Secur. Commun. Networks1
2014 Investigating the Hooking Behavior: A Page-Level Memory Monitoring Method for Live Forensics
Yingxin Cheng, Xiao Fu 0005, Bin Luo 0003, Hao Ruan
ISC2