Qiang Liu 0034

dblp:61/3234-34 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0002-5865-6227ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 8 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Minoris: Practical Out-of-Emulator Kernel Module Fuzzing
abstract
Vulnerabilities in the Linux kernel can be exploited to perform privilege escalation and take over the whole system. Fuzzing has been leveraged to detect Linux kernel vulnerabilities during the last decade. However, existing kernel fuzzing techniques highly use QEMU/KVM as the underlying infrastructure, thus suffering from unnecessary costs due to user-kernel context switch and kernel-emulator context switch. This degrades the fuzzing performance. In this paper, we propose a kernel module fuzzing framework namedMinoris. It moves the kernel module under testing (KMUT) out of both real kernel and emulator, thus eliminating unnecessary context switches. However, implementing such a system requires solving the dependency challenges. We solve these challenges by automatically linking kernel module with LKL, and performing initialization functions on-demand to prepare the required status. Besides, a hardware-emulation library is proposed to provide underlying hardware support. Our system not only improves the fuzzing speed but also can easily integrate mature fuzzing techniques, such as user-space memory sanitizer. We evaluateMinorison five different KMUTs. Compared with the state-of-the-art solution,Minorisachieves an average execution speedup from ×3.31 to ×7.38. It improves the fuzzing throughput (×102.58), explores more code coverage ($89.51\%$more branches), and detects 6 new bugs.
Yangxi Xiang, Qiang Liu 0034, Haoyu Wang 0001, Jiashui Wang, Lei Wu 0012, Chaoyuan Chen, Yajin Zhou
IEEE Trans. Dependable Secur. Comput.4
2025 REFLECTA: Reflection-based Scalable and Semantic Scripting Language Fuzzing
Chibin Zhang, Gwangmu Lee, Qiang Liu 0034, Mathias Payer
AsiaCCS3
2025 Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
Zheyu Ma, Qiang Liu 0034, Zheming Li, Tingting Yin, Wende Tan, Chao Zhang 0008, Mathias Payer
NDSS2
2024 Tango: Extracting Higher-Order Feedback through State Inference
abstract
Fuzzing is the de facto standard for automated testing. However, while coverage-guided fuzzing excels at code discovery, its effectiveness falters when applied to complex systems. One such class entails persistent targets whose behavior depends on the state of the system, where code coverage alone is insufficient for comprehensive testing. It is difficult for a fuzzer to optimize for state discovery when the feedback does not correlate with the objective.
Ahmad Hazimeh, Duo Xu 0006, Qiang Liu 0034, Yan Wang 0149, Mathias Payer
RAID3
2024 HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization Interface
Alexander Bulekov, Qiang Liu 0034, Manuel Egele, Mathias Payer
USENIX Security Symposium2
2024 TrapCog: An Anti-Noise, Transferable, and Privacy-Preserving Real-Time Mobile User Authentication System With High Accuracy
abstract
The authentication technology of mobile device users has been studied for decades. To balance security, privacy, and usability, motion sensors-based user authentication methods are widely investigated in recent years. However, existing studies meet the problems such as scarcity of training samples, underutilization of data, poor de-noising ability, insufficient transferability, privacy leakage, and low accuracy. To overcome these difficulties, we propose a system, calledTrapCog, with the following capabilities: 1) In the phase of data collection,TrapCogcan eliminate man-made noise (mislabeling) through differential training based on down-sampling. 2) In the model training stage, the siamese neural network with Long Short-Term Memory (LSTM) as the sub-network is used to achieve sufficient coverage of sample patterns and the transferability of the model. 3) In the phase of real-world authentication, the privacy of the user is tremendously protected through end-side model deployment and local authentication. Experimental results on a dataset composed of 1,513 users with real-world noise show thatTrapCoghas high accuracy and strong transferability, which is much better than state-of-the-art studies.
Tiantian Zhu 0001, Qiang Liu 0034, Chun-lin Xiong, Zhengqiu Weng, Tieming Chen, Mingqi Lv, Ting Wang 0004, Yan Chen 0004
IEEE Trans. Mob. Comput.3
2023 ViDeZZo: Dependency-aware Virtual Device Fuzzing
abstract
A virtual machine interacts with its host environment through virtual devices, driven by virtual device messages, e.g., I/O operations. By issuing crafted messages, an adversary can exploit a vulnerability in a virtual device to escape the virtual machine, gaining host access. Even though hundreds of bugs in virtual devices have been discovered, coverage-based virtual device fuzzers hardly consider intra-message dependencies (a field in a virtual device message may be dependent on another field) and inter-message dependencies (a message may depend on a previously issued message), thus resulting in limited scalability or efficiency.ViDeZZo, our new dependency-aware fuzzing framework for virtual devices, overcomes the limitations of existing virtual device fuzzers by annotating intra-message dependencies with a lightweight grammar, and by self-learning inter-message dependencies with new mutation rules. Specifically, ViDeZZo annotates message dependencies and applies three categories of message mutators. This approach avoids heavy manual effort to analyze specifications and speeds up the slow exploration by satisfying dependencies, resulting in a scalable and efficient fuzzer that boosts bug discovery in virtual devices.In our evaluation, ViDeZZo covers two hypervisors, four architectures, five device categories, and 28 virtual devices, and reaches competitive coverage faster. Moreover, ViDeZZo successfully finds 24 existing and 28 new bugs across diverse bug types. We are actively engaging with the community with 7 of our submitted patches already accepted.
Qiang Liu 0034, Flavio Toffalini, Yajin Zhou, Mathias Payer
SP1
2022 EspialCog: General, Efficient and Robust Mobile User Implicit Authentication in Noisy Environment
abstract
Mobile authentication is a fundamental factor in the protection of user’s private resources. In recent years, motion sensor-based biometric authentication has been widely used for privacy-preserving. However, it faces with the problems including low data collection efficiency, insufficient authentication scenario coverage rate, weak de-noising ability, and poor robustness of models, rendering existing methods difficult to meet the security, privacy, and usability requirements jointly in the real-world scenario. To overcome these difficulties, we propose a system calledEspialCog, which is able to 1) collect the sensor data embedded in mobile devices self-adaptively, unobtrusively and efficiently through the evolutionary stable participation game mechanism (ESPGM) with a high scenario coverage rate; 2) minimize noise from collected data by analyzing three types of abnormalities; and 3) authenticate the ownership of mobile devices in real-time by adopting optimized LSTM model with an enhanced stochastic gradient descent (SGD) algorithm. The simulation experiment on 6000 users shows that the efficiency and coverage rates increase dramatically by deploying our ESPGM. Moreover, we conduct experiments on a large-scale real-world noisy dataset with 1513 users and two other small pure real-world datasets. The experimental results show the high accuracy and favorable robustness ofEspialCogin the noisy environment.
Tiantian Zhu 0001, Zhengqiu Weng, Qijie Song, Qiang Liu 0034, Yan Chen 0004, Mingqi Lv, Tieming Chen
IEEE Trans. Mob. Comput.5
2021 ECMO: Peripheral Transplantation to Rehost Embedded Linux Kernels
abstract
Dynamic analysis based on the full-system emulator QEMU is widely used for various purposes.However, it is challenging to run firmware images of embedded devices in QEMU, especially the process to boot the Linux kernel (we call this process rehosting the Linux kernel in this paper). That's because embedded devices usually use different system-on-chips (SoCs) from multiple vendors and only a limited number of SoCs are currently supported in QEMU.
Muhui Jiang, Lin Ma 0009, Yajin Zhou, Qiang Liu 0034, Cen Zhang, Zhi Wang 0004, Xiapu Luo, Lei Wu 0012, Kui Ren 0001
CCS4
2021 FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel Execution
abstract
Linux kernel is widely used in embedded systems. To understand practical threats to the Linux kernel, we need to perform dynamic analysis with a full-system emulator, e.g., QEMU. However, due to hardware fragmentation, e.g., various types of peripherals, most embedded systems are not currently supported by QEMU. Though some progress has been made on rehosting firmware, it mainly focuses on user space programs or simple real-time operating systems.The goal of this work is to boost the capability of rehosting the embedded Linux kernels in QEMU. By doing so, dynamic analysis systems can be firstly applied on embedded Linux kernels by leveraging off-the-shelf tools upon QEMU. Accordingly, we proposed a new technique called model-guided kernel execution. It combines the peripheral abstractions in the Linux kernel and kernel-peripheral interactions to semi-automatically generate peripheral models that are then used to synthesize new QEMU virtual machines to start the dynamic analysis.We have implemented a prototype called FirmGuide. It generates 9 peripheral models with full functionality and 64 with minimum functionality covering 26 SoCs. Our evaluation with 6,188 firmware images shows that it can successfully rehost more than 95% of Linux kernels in 2 architectures and 22 versions. None of them can be rehosted in the vanilla QEMU. The result of the LTP benchmark shows the reliability and robustness of the rehosted Linux kernels. We further conduct two security applications, i.e., vulnerability analysis and fuzzing, on the rehosted Linux kernels to demonstrate the usage scenarios.
Qiang Liu 0034, Cen Zhang, Lin Ma 0009, Muhui Jiang, Yajin Zhou, Lei Wu 0012, Wenbo Shen, Xiapu Luo, Yang Liu 0003, Kui Ren 0001
ASE1
2021 One Cycle Attack: Fool Sensor-Based Personal Gait Authentication With Clustering
abstract
Gait authentication, especially sensor-based patterns, has been studied by researchers for decades. Nowadays, gait authentication has become an important facet of biometric systems due to the so-called unique characteristics of each user. With the development of various technologies (i.e., hardware, data processing, features extraction, and learning algorithms), the performance of sensor-based authentication methods is gradually improving. But we have found that the vulnerability of most existing methods can be compromised easily. In this paper, we propose a novel attack model, called one cycle attack, to bypass existing gait authentication methods. Firstly, the gait sequence is divided into multiple gait cycles. By adopting the K-mean algorithm, we get the average distance of each feature sample (extracted from the gait cycle) to its closest cluster center, and its result confirms that independent individuals may have similar gait cycles. Secondly, using six state-of-the-art models it was found that the adversarial gait cycle found with the clustering method can bypass the victim’s model rapidly. Furthermore, to improve the accuracy of sensor-based gait authentication methods to fight against attacks, we present a WPD-LSTM (Wavelet Packet Decomposition and Long Short-Term Memory) multi-cycle defense model which considers the contextual contents of the neighboring gait cycles in the gait sequence. Experimental results on two datasets (the largest public sensor-based gait database OU-ISIR and new dataset from our laboratory) show that our attack model can bypass most of the victims’ models within a limited number of attempts. Specifically, we can compromise 20%–80% of users within 5 attempts by utilizing imitation. On the contrary, the success rate of attackers has been greatly mitigated by deploying our multi-cycle defense model.
Tiantian Zhu 0001, Qiang Liu 0034, Zi Lin, Yan Chen 0004, Tieming Chen
IEEE Trans. Inf. Forensics Secur.3