Qing Xia 0007

dblp:62/2726-7 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2024
0009-0008-4305-0290ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 DAppFL: Just-in-Time Fault Localization for Decentralized Applications in Web3
abstract
Web3 describes an idea for the next evolution of the Internet, where blockchain technology enables the Internet of Value. As Web3 software, decentralized applications (DApps) have emerged in recent years. There exists a natural link between DApps and cryptocurrencies, where faults in DApps could directly lead to monetary losses associated with cryptocurrencies. Hence, efficient fault localization technology is of paramount importance for urgent DApp rescue operations and the mitigation of financial losses. However, fault localization methods applied in traditional applications are not well-suited for this specific field, due to their inability to identify DApp-specific fault features, e.g., a substantial amount of cryptocurrency is transferred from DApps to hackers. In order to explore the root cause of DApp faults, some researchers try to identify suspicious code snippets through mutation testing. Nonetheless, applying mutation testing for DApp fault localization is time-consuming and thus limited in practice. This paper conducts the first comprehensive study of DApp fault localization. We introduce DAppFL, a learning-based DApp fault localization tool that performs reverse engineering to gather executed source code and then trace cryptocurrency flow to assist in locating faulty functions. We also present the inaugural dataset for DApp fault localization, providing a new benchmark for this domain.Our experimental results demonstrate that DAppFL locates 63% of faults within the Top-5, 23% more than the state-of-the-art method. To facilitate further research, our code and dataset are freely available online: https://github.com/xplanet-sysu/awesome-works#dappfl.
Zhiying Wu, Jiajing Wu, Hui Zhang 0002, Jiachi Chen, Zibin Zheng, Qing Xia 0007, Gang Fan, Yi Zhen
ISSTA7
2023 Detecting Flash Loan Based Attacks in Ethereum
abstract
Decentralized Finance (DeFi) ecosystem has grown rapidly in the past few years. In the DeFi ecosystem, flash loan is a novel type of uncollateralized loan with nearly negligible lending costs. Malicious attackers can easily borrow a large number of crypto assets, and utilize them to disrupt the price of crypto assets to make a profit. Many flash loan based price manipulation attacks have been reported recently, and caused immense economic losses, e.g., 30 million USD in a single attack. In this paper, we conduct an empirical study on real-world flash loan based attacks in the past two years and present three attack patterns for price manipulation attacks. Then, we propose an approach, LeiShen, to automatically detect price manipulation attacks with asset transfers. We evaluate LeiShen on the first 14,500,000 blocks in Ethereum, and detect 180 attacks with a precision of 78.9%. Among our newly-found attacks, the severest attack has caused a total loss of more than 6.1 million USD.
Qing Xia 0007, Zhirong Huang, Wensheng Dou, Yafeng Zhang, Fengjun Zhang, Geng Liang, Chun Zuo
ICDCS1
2022 STPChain: a Crowdsourced Software Engineering Method for Software Traceability and Fine-grained Privacy Based on Blockchain
abstract
Crowdsourced software engineering (CSE) has be-come an increasingly popular way of software development owing to its flexibility. There exist two types of CSE participants: the requester, who posts a task including a set of requirements, and workers, including developers and testers, completing the task. Due to the centralized architecture, traditional CSE systems have raised the concern of untrustfulness since participants may collude with centralized platforms and behave maliciously to grab illegitimate interests. Some researches have utilized blockchain to solve the problem. Still, they either lack software traceability, which is significant for ensuring software quality, or cannot guar-antee users' transaction privacy owing to blockchain's openness. We propose STPChain, a CSE method for §_oftware Traceability and Privacy based on blockChain. To maintain software traceability, we articulate the process flow of CSE and implement it with smart contracts adapted to software development. The smart contracts ensure that every submission will automatically leave tamper-proof records. Credible software traceability links are realized through the records. To alleviate the transaction privacy leakage, we propose FGCA, a fine-grained CA (Certificate Authority) updating mechanism in consortium blockchain. Based on the finding that a traceability link belongs within a task, FGCA refines the digital certificates from user-level to task-level to conceal the connection between tasks and users. While guaranteeing transaction privacy, FGCA also keeps the traceability links by storing the relations between users' identifier and certificates. Security analysis demonstrates that STPChain can prevent malicious misbehaviors of participants in CSE. Case study illustrates that our method can be utilized to maintain traceability and save more than 70% of time when positioning relevant workers in CSE without transaction privacy leakage related to data openness. Performance experiments show the applicability of STPChain under CSE scenarios.
Li Yang 0015, Qing Xia 0007, Mingzhe Fang, Geng Liang, Chun Zuo
COMPSAC3
2021 The Impact Analysis of Multiple Miners and Propagation Delay on Selfish Mining
abstract
Bitcoin has emerged as a popular decentralized cryptocurrency and attracted much attention from the public. Bitcoin embodies the Nakamoto consensus to reach an agreement about its blockchain ledger. However, the Nakamoto consensus can suffer from selfish mining attacks. Existing studies on selfish mining usually assume that the total mining power is divided into two parts (i.e., honest and selfish), and ignore propagation delay among miners. The assumptions cannot reflect real-world scenarios, in which multiple miners generate blocks at a fixed interval and propagate them with certain delay. Therefore, it is unknown how the practical factors, i.e., multiple miners and propagation delay, can affect selfish mining.In this paper, we explore the impact of multiple miners and propagation delay on selfish mining. First, we propose a new selfish mining strategy that can handle these factors. Second, we design a simulation approach to analyze the performance of the new selfish mining strategy. From our empirical study we observe many interesting findings that can be utilized in combating selfish mining. For example, the blockchain system with a higher orphan rate is more vulnerable to the selfish mining attack.
Qing Xia 0007, Wensheng Dou, Fengjun Zhang, Jun Wei 0001, Geng Liang
COMPSAC1
2021 The Performance of Selfish Mining in GHOST
abstract
The blockchain technology is regarded as a significant trust-building technology and has attracted much attention from the public. The longest chain rule has been widely applied in blockchain systems to reach consensus on the distributed ledger. However, the longest chain rule cannot support a higher transaction throughput due to its lower security. As an alternative solution to the longest chain rule, GHOST is proposed as a safer consensus rule. Existing studies show that the longest chain rule can suffer from selfish mining attacks. However, it is unclear how selfish mining attacks perform on GHOST. In this paper, we explore the performance of selfish mining on GHOST. We first propose the original selfish mining (GHOST-SM) and stubborn mining (GHOST-StuM) for GHOST. We then evaluate these two selfish mining strategies on our blockchain simulation system. The experimental result shows that GHOST achieves better security than the longest chain rule. However, when the block generation rate increases, the security of GHOST is close to the longest chain rule. For example, the threshold for selfish mining attacks of GHOST is increased by 47.55% and 0.60% compared to the longest chain rule corresponding to the block generation interval of 1 second and 15 seconds.
Qing Xia 0007, Wensheng Dou, Fengjun Zhang, Geng Liang
TrustCom1
2020 Sadroid: A Deep Classification Model For Android Malware Detection Based On Semantic Analysis
abstract
Previous works have designed many deep learning models for Android malware detection using various features (e.g. permissions, APIs et.) to achieve better classification performance. However, these methods usually input each feature into the classifier independently and completely (using One-Hot Encoding) so that features are orthogonal to each other. This discrete representation is difficult to preserve the semantic information of features. In this paper, we design two feature segmentation methods to enhance the semantics of the features in preprocessing. Besides that, we propose a malware detection model that consists of a distributed representation process for Android features and an optimized convolutional neural network for classification, named Semantic Analysis Detection (SADroid). In SADroid, the distance between features with similar semantics is closer in vector space. It provides the semantic information of features to the classifier to improve the classification performance. In the evaluation, SADroid outperforms the advanced models in detection accuracy on a data set of 19,600 applications, while maintaining a low computational cost.
Dali Zhu, Pengfei Jing, Qing Xia 0007, Di Wu 0004, Yiming Zhang 0011
WCNC4
2019 A Transparent and Multimodal Malware Detection Method for Android Apps
abstract
While recent works have shown that deep learning method can improve the malware classification accuracy, the lack of the transparency has restricted its application in anti-virus scan engines. Existing researches have attempted to provide solutions to give high-fidelity explanations of the model's decision. However, current methods are not optimized for application security task, leading to a poor performance in Android malware detection. In this paper, we propose a backtracking method to infer suspicious features of the apps to explain the reason of classification. Besides, we also propose a malware detection model based on the fusion convolutional neural network using different types of features (e.g., permission, API, URL, etc.). For maximizing the benefits of encompassing multiple feature types, our framework trains the sub-models for each type of features separately and merges them at the end of the system to obtain a comprehensive classification result. The experimental results show that the backtracking method has a significant improvement in fidelity level compared with existing methods. Furthermore, we evaluate the performance of the proposed framework with other existing works. Leveraging the backtracking method, our framework has better performance in classification and significantly reduces detection time by 69% compared with prior approaches.
Dali Zhu, Pengfei Jing, Di Wu 0004, Qing Xia 0007, Yiming Zhang 0011
MSWiM5