VLDB 2026 Research / reviewers in the wild / expert
Xiaodi Li 0002
dblp:63/7279-2
· DBLP profile ↗
8ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-3675-3448ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Automated Vulnerability Detection Framework for Smart ContractsabstractWith the increase of the adoption of blockchain technology in providing decentralized solutions to various problems, smart contracts have become more popular to the point that billions of US Dollars are currently exchanged every day through such technology. Meanwhile, various vulnerabilities in smart contracts have been exploited by attackers to steal cryptocurrencies worth millions of dollars. The automatic detection of smart contract vulnerabilities therefore is an essential research problem. Existing solutions to this problem particularly rely on human experts to define features or different rules to detect vulnerabilities. However, this often causes many vulnerabilities to be ignored, and they are inefficient in detecting new vulnerabilities. In this study, to overcome such challenges, we propose a framework to automatically detect vulnerabilities in smart contracts on the blockchain. More specifically, first, we utilize novel feature vector generation techniques from bytecode of smart contract as source code is rarely publicly available. These feature vectors are then analyzed using our innovative metric learning-based Deep Neural Networks (DNNs) to produce detection results. The framework’s predictions are further refined through a voting mechanism to achieve consensus. We conduct comprehensive experiments on large-scale benchmarks, and the quantitative results demonstrate the effectiveness and efficiency of our approach. Feng Mi, Chen Zhao 0010, Zhuoyi Wang, Sadaf Md. Halim, Xiaodi Li 0002, Zhouxiang Wu, Latifur Khan, Bhavani Thuraisingham |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2025 | PPSEBM: An Energy-Based Model with Progressive Parameter Selection for Continual Learning
Xiaodi Li 0002, Dingcheng Li, Rujun Gao, Mahmoud Zamani, Feng Mi, Latifur Khan |
IEEE Big Data | 1 |
| 2024 | ConfliLPC: Logits and Parameter Calibration for Political Conflict Analysis in Continual LearningabstractThe ConfliLPC framework introduces an innovative integration of Logits and Parameter Calibration (LPC) with the ConfliBERT model, tailored specifically for the nuanced analysis of political conflict and violence. This paper details the development and application of ConfliLPC, highlighting its robust capability to adapt to evolving data landscapes without succumbing to catastrophic forgetting (CF), a common challenge in machine learning models applied to dynamic domains such as political science. ConfliLPC enhances accuracy and adaptability by continually adjusting its parameters to accommodate new information while retaining valuable historical insights. The framework has been rigorously tested across various conflict scenarios, demonstrating superior performance in real-time analysis and predictive tasks. This work serves as a significant contribution to the fields of political science, conflict research, and applied machine learning, providing a powerful tool for analysts and policymakers engaged in the understanding and resolution of political conflict. The experimental results highlight the efficiency of the ConfliLPC method and its capability to minimize CF. Our code is publicly available1 Xiaodi Li 0002, Niamat Zawad, Patrick T. Brandt, Javier Osorio, Vito D'Orazio, Latifur Khan |
IEEE Big Data | 1 |
| 2024 | VulPrompt: Prompt-Based Vulnerability Detection Using Few-Shot Graph Learning
Saquib Irtiza, Xiaodi Li 0002, Mahmoud Zamani, Latifur Khan, Kevin W. Hamlen |
DBSec | 2 |
| 2023 | Con2Mix: A semi-supervised method for imbalanced tabular security dataabstractCon2Mix (Contrastive Double Mixup) is a new semi-supervised learning methodology that innovates a triplet mixup data augmentation approach for finding code vulnerabilities in imbalanced, tabular security data sets. Tabular data sets in cybersecurity domains are widely known to pose challenges for machine learning because of their heavily imbalanced data (e.g., a small number of labeled attack samples buried in a sea of mostly benign, unlabeled data). Semi-supervised learning leverages a small subset of labeled data and a large subset of unlabeled data to train a learning model. While semi-supervised methods have been well studied in image and language domains, in security domains they remain underutilized, especially on tabular security data sets which pose especially difficult contextual information loss and balance challenges for machine learning. Experiments applying Con2Mix to collected security data sets show promise for addressing these challenges, achieving state-of-the-art performance on two evaluated data sets compared with other methods. Xiaodi Li 0002, Latifur Khan, Mahmoud Zamani, Shamila Wickramasuriya, Kevin W. Hamlen, Bhavani Thuraisingham |
J. Comput. Secur. | 1 |
| 2022 | MCoM: A Semi-Supervised Method for Imbalanced Tabular Security Data
Xiaodi Li 0002, Latifur Khan, Mahmoud Zamani, Shamila Wickramasuriya, Kevin W. Hamlen, Bhavani Thuraisingham |
DBSec | 1 |
| 2020 | DENAS: automated rule generation by knowledge extraction from neural networksabstractDeep neural networks (DNNs) have been widely applied in the software development process to automatically learn patterns from massive data. However, many applications still make decisions based on rules that are manually crafted and verified by domain experts due to safety or security concerns. In this paper, we aim to close the gap between DNNs and rule-based systems by automating the rule generation process via extracting knowledge from well-trained DNNs. Existing techniques with similar purposes either rely on specific DNNs input instances or use inherently unstable random sampling of the input space. Therefore, these approaches either limit the exploration area to a local decision-space of the DNNs or fail to converge to a consistent set of rules. The resulting rules thus lack representativeness and stability. Soroush Bateni, Sampath Grandhi, Xiaodi Li 0002, Cong Liu 0005, Wei Yang 0013 |
ESEC/SIGSOFT FSE | 4 |
| 2019 | MalScan: Fast Market-Wide Mobile Malware Scanning by Social-Network Centrality AnalysisabstractMalware scanning of an app market is expected to be scalable and effective. However, existing approaches use either syntax-based features which can be evaded by transformation attacks or semantic-based features which are usually extracted by performing expensive program analysis. Therefor, in this paper, we propose a lightweight graph-based approach to perform Android malware detection. Instead of traditional heavyweight static analysis, we treat function call graphs of apps as social networks and perform social-network-based centrality analysis to represent the semantic features of the graphs. Our key insight is that centrality provides a succinct and fault-tolerant representation of graph semantics, especially for graphs with certain amount of inaccurate information (e.g., inaccurate call graphs). We implement a prototype system, MalScan, and evaluate it on datasets of 15,285 benign samples and 15,430 malicious samples. Experimental results show that MalScan is capable of detecting Android malware with up to 98% accuracy under one second which is more than 100 times faster than two state-of-the-art approaches, namely MaMaDroid and Drebin. We also demonstrate the feasibility of MalScan on market-wide malware scanning by performing a statistical study on over 3 million apps. Finally, in a corpus of dataset collected from Google-Play app market, MalScan is able to identify 18 zero-day malware including malware samples that can evade detection of existing tools. Yueming Wu 0001, Xiaodi Li 0002, Deqing Zou, Wei Yang 0013, Hai Jin 0001 |
ASE | 2 |