Lihua Guo

dblp:65/8107 · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Phase-Based Feature for Gas Detection Under Unstable Preheating Condition for E-Noses
abstract
Electronic noses (e-noses) utilizing metal oxide semiconductor (MOS) gas sensors are widely used; however, they typically require several days of preheating after power-on, whether during initial startup or following a power interruption, to reach a stable operation. Such prolonged preheating significantly limits immediate deployment, particularly in portable systems, and has rarely been systematically addressed in the existing literature. To tackle this challenge, we propose a phase-based feature extraction method to capture stable signal patterns under temperature modulation to address baseline drift during the unstable preheating stage. Building on this feature, we develop a detection method that markedly outperforms conventional magnitude-based techniques, which typically exhibit very low detection probabilities during early preheating. The proposed method achieves high-precision gas detection within just 14 hours, and reaches even better detection probability in 2 hours that conventional methods require 154 hours to match when most commercial sensors remain in the pre-conditioning stage. By incorporating the phase-based feature extraction strategy, the required stabilization time is substantially shortened, enabling rapid and reliable gas detection, and facilitating real-time deployment of e-nose systems in critical applications such as emergency response and industrial safety.
Lihua Guo, Zhengqiao Zhao, Jingdong Chen, Jacob Benesty
IEEE Signal Process. Lett.1
2025 FunFuzz: Greybox Fuzzing with Function Significance
abstract
Greybox fuzzing is dedicated to revealing software bugs by maximizing code coverage. Concentrating on code coverage, greybox fuzzing effectively exposes bugs in real-world programs by continuously executing the program under test (PUT) with the test inputs generated from initial seeds, making it a popular software testing technique. Although powerful, the effectiveness of greybox fuzzing can be restricted in some cases. Ignoring the significant degrees of executed functions, traditional greybox fuzzing usually fails to identify significant seeds that execute more significant functions, and thus may assign similar energy to significant and trivial seeds when conducting power scheduling. As a result, the effectiveness of greybox fuzzing can be degraded due to wasting too much energy on trivial seeds. In this paper, we introduce function significance (FS) to measure the significant degrees of functions. Our key insight is that the influential functions that connect to many other functions are significant to greybox fuzzing as they provide more probabilities to reach previously unexplored code regions. To quantify FS, we conduct influence analysis upon the call graphs extracted from the PUTs to obtain the centrality values of function nodes. With FS as the significance measurement, we further propose FunFuzz , an FS-aware greybox fuzzing technique, to optimize significant seeds and tackle the aforementioned restriction. To this end, FunFuzz dynamically tracks the functions executed by a seed during fuzzing, and computes the significance score for the seed by accumulating the FS values of the functions executed by it. Based on the computed FS values, FunFuzz then takes an estimation-based power scheduling to assign more (or less) energy to seeds that achieve over-estimated (or under-estimated) significance scores. Specifically, the seed energy is adjusted by multiplying with a scale factor computed regarding the ratio of the actual significance score achieved by executing the seed and the estimated significance score predicted by a linear model constructed on-the-fly. To evaluate FunFuzz , we prototype it on top of AFL++ and conduct experiments with 15 programs, of which 10 are from common real-world projects and five are from Magma, and compare it to seven popular fuzzers. The experimental results obtained through fuzzing exceeding 40,800 CPU hours show that: (1) In terms of covering code, FunFuzz outperforms AFL++ by achieving 0.1%–18.4% more region coverage on 13 out of 15 targets. (2) In terms of finding bugs, FunFuzz unveils 114 unique crashes and 25 Magma bugs (which are derived from CVEs) in 20 trials of 24-hour fuzzing, which are the most compared to the competitor fuzzers and include 32 crashes and 1 Magma bug that the other fuzzers fail to discover. Besides the experiments focusing on code coverage and bug finding, we evaluate the key components of FunFuzz , namely the FS-centered estimation-based power scheduling and the lazy FS computation mechanism. The extensive evaluation not only suggests FunFuzz ’s superiority in code coverage and bug finding, but also demonstrates the effectiveness of the two components.
Ruixiang Qian, Quanjun Zhang, Chunrong Fang, Lihua Guo, Zhenyu Chen 0001
ACM Trans. Softw. Eng. Methodol.4
2024 Knowledge Tracing with Contrastive Learning and Attention-Based Long Short-Term Memory Network
Liancheng Xu, Lihua Guo, Xiaoqi Wu, Xinhua Wang 0003, Lei Guo 0008
ICIC (4)2
2024 An Empirical Study of Data Disruption by Ransomware Attacks
abstract
The threat of ransomware to the software ecosystem has become increasingly alarming in recent years, raising a demand for large-scale and comprehensive ransomware analysis to help develop more effective countermeasures against unknown attacks. In this paper, we first collect a real-world dataset MarauderMap, consisting of 7,796 active ransomware samples, and analyze their behaviors of disrupting data in victim systems. All samples are executed in isolated testbeds to collect all perspectives of six categories of runtime behaviors, such as API calls, I/O accesses, and network traffic. The total logs volume is up to 1.98 TiB. By assessing collected behaviors, we present six critical findings throughout ransomware attacks' data reconnaissance, data tampering, and data exfiltration phases. Based on our findings, we propose three corresponding mitigation strategies to detect ransomware during each phase. Experimental results show that they can enhance the capability of state-of-the-art anti-ransomware tools. We report a preliminary result of a 41%-69% increase in detection rate with no additional false positives, showing that our insights are helpful.
Yiwei Hou, Lihua Guo, Chijin Zhou, Zijing Yin, Shanshan Li 0001, Chengnian Sun, Yu Jiang 0001
ICSE2
2024 TransWild: Enhancing 3D interacting hands recovery in the wild with IoU-guided Transformer
Wanru Zhu, Ke Chen 0004, Lihua Guo
Image Vis. Comput.4
2024 Boosting Cross-Domain Point Classification via Distilling Relational Priors From 2D Transformers
abstract
Semantic pattern of an object point cloud is determined by its topological configuration of local geometries. Learning discriminative representations can be challenging due to large shape variations of point sets in local regions and incomplete surface in a global perspective, which can be made even more severe in the context of unsupervised domain adaptation (UDA). In specific, traditional 3D networks mainly focus on local geometric details and ignore the topological structure between local geometries, which greatly limits their cross-domain generalization. Recently, the transformer-based models have achieved impressive performance gain in a range of image-based tasks, benefiting from its strong generalization capability and scalability stemming from capturing long range correlation across local patches. Inspired by such successes of visual transformers, we propose a novel Relational Priors Distillation (RPD) method to extract relational priors from the well-trained transformers on massive images, which can significantly empower cross-domain representations with consistent topological priors of objects. To this end, we establish a parameter-frozen pre-trained transformer module shared between 2D teacher and 3D student models, complemented by an online knowledge distillation strategy for semantically regularizing the 3D student model. Furthermore, we introduce a novel self-supervised task centered on reconstructing masked point cloud patches using corresponding masked multi-view image features, thereby empowering the model with incorporating 3D geometric information. Experiments on the PointDA-10 and the Sim-to-Real datasets verify that the proposed method consistently achieves the state-of-the-art performance of UDA for point cloud classification. The source code of this work is available athttps://github.com/zou-longkun/RPD.git.
Longkun Zou, Wanru Zhu, Ke Chen 0004, Lihua Guo, Kailing Guo, Kui Jia, Yaowei Wang 0001
IEEE Trans. Circuits Syst. Video Technol.4
2023 Limits of I/O Based Ransomware Detection: An Imitation Based Attack
abstract
By encrypting the data of infected hosts, cryptographic ransomware has caused billions of dollars in financial losses to a wide range of victims. Many detection techniques have been proposed to counter ransomware threats over the past decade. Their common approach is to monitor I/O behaviors from user space and apply custom heuristics to discriminate ransomware. These techniques implicitly assume that ransomware behaves very differently from benign programs in terms of heuristics. However, when we investigated the behavior of benign and ransomware programs, we found that the boundary between their behaviors was blurred. A ransomware program can still achieve its goal even though it follows the behavior patterns of benign programs. In this paper, we aim to explore the limits of ransomware detection techniques that based on I/O behaviors. To this end, we present Animagus, an imitation-based ransomware attack that imitates behaviors of benign programs to disguise its encryption tasks. It first learns behavior patterns from a benign program, and then spawns and orchestrates child processes to perform encryption tasks behaving the same as the benign program. We evaluate its effectiveness against six state-of-the-art detection techniques, and the results show that it can successfully evade these defenses. We investigate in detail why they are ineffective and how Animagus is different from existing ransomware samples. In the end, we discuss potential countermeasures and the benefits that detection tools can gain from our work.
Chijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma, Quan Zhang 0003, Zhe Liu 0001, Yu Jiang 0001
SP2
2023 Towards Better Semantics Exploration for Browser Fuzzing
abstract
Web browsers exhibit rich semantics that enable a plethora of web-based functionalities. However, these intricate semantics present significant challenges for the implementation and testing of browsers. For example, fuzzing, a widely adopted testing technique, typically relies on handwritten context-free grammars (CFGs) for automatically generating inputs. However, these CFGs fall short in adequately modeling the complex semantics of browsers, resulting in generated inputs that cover only a portion of the semantics and are prone to semantic errors. In this paper, we present SaGe, an automated method that enhances browser fuzzing through the use of production-context sensitive grammars (PCSGs) incorporating semantic information. Our approach begins by extracting a rudimentary CFG from W3C standards and iteratively enhancing it to create a PCSG. The resulting PCSG enables our fuzzer to generate inputs that explore a broader range of browser semantics with a higher proportion of semantically-correct inputs. To evaluate the efficacy of SaGe, we conducted 24-hour fuzzing campaigns on mainstream browsers, including Chrome, Safari, and Firefox. Our approach demonstrated better performance compared to existing browser fuzzers, with a 6.03%-277.80% improvement in edge coverage, a 3.56%-161.71% boost in semantic correctness rate, twice the number of bugs discovered. Moreover, we identified 62 bugs across the three browsers, with 40 confirmed and 10 assigned CVEs.
Chijin Zhou, Quan Zhang 0003, Lihua Guo, Yu Jiang 0001, Qing Liao 0001, Zhiyong Wu 0010, Shanshan Li 0001, Bin Gu 0006
Proc. ACM Program. Lang.3
2022 Investigating Coverage Guided Fuzzing with Mutation Testing
abstract
Coverage guided fuzzing (CGF) is an effective testing technique which has detected hundreds of thousands of bugs from various software applications. It focuses on maximizing code coverage to reveal more bugs during fuzzing. However, a higher coverage does not necessarily imply a better fault detection capability. Triggering a bug involves not only exercising the specific program path but also reaching interesting program states in that path.
Ruixiang Qian, Quanjun Zhang, Chunrong Fang, Lihua Guo
Internetware4
2022 Minerva: browser API fuzzing with dynamic mod-ref analysis
abstract
Browser APIs are essential to the modern web experience. Due to their large number and complexity, they vastly expand the attack surface of browsers. To detect vulnerabilities in these APIs, fuzzers generate test cases with a large amount of random API invocations. However, the massive search space formed by arbitrary API combinations hinders their effectiveness: since randomly-picked API invocations unlikely interfere with each other (i.e., compute on partially shared data), few interesting API interactions are explored. Consequently, reducing the search space by revealing inter-API relations is a major challenge in browser fuzzing.
Chijin Zhou, Quan Zhang 0003, Lihua Guo, Jie Liang 0006, Zhe Liu 0001, Mathias Payer, Yu Jiang 0001
ESEC/SIGSOFT FSE4
2022 Knowledge transferred adaptive filter pruning for CNN compression and acceleration
Lihua Guo, Dawu Chen, Kui Jia
Sci. China Inf. Sci.1
2019 PARN: Position-Aware Relation Networks for Few-Shot Learning
abstract
Few-shot learning presents a challenge that a classifier must quickly adapt to new classes that do not appear in the training set, given only a few labeled examples of each new class. This paper proposes a position-aware relation network (PARN) to learn a more flexible and robust metric ability for few-shot learning. Relation networks (RNs), a kind of architectures for relational reasoning, can acquire a deep metric ability for images by just being designed as a simple convolutional neural network (CNN)[23]. However, due to the inherent local connectivity of CNN, the CNN-based relation network (RN) can be sensitive to the spatial position relationship of semantic objects in two compared images. To address this problem, we introduce a deformable feature extractor (DFE) to extract more efficient features, and design a dual correlation attention mechanism (DCA) to deal with its inherent local connectivity. Successfully, our proposed approach extents the potential of RN to be position-aware of semantic objects by introducing only a small number of parameters. We evaluate our approach on two major benchmark datasets, i.e., Omniglot and Mini-Imagenet, and on both of the datasets our approach achieves state-of-the-art performance. It's worth noting that our 5-way 1-shot result on Omniglot even outperforms the previous 5-way 5-shot results.
Ziyang Wu, Lihua Guo, Kui Jia
ICCV3
2018 Two-stage local constrained sparse coding for fine-grained visual categorization
Lihua Guo, Chenggang Guo, Qinghua Huang, Yanshan Li, Xuelong Li 0001
Sci. China Inf. Sci.1
2016 A deep sparse coding method for fine-grained visual categorization
abstract
In the fine-grained categories, images have lager diversity in their intra categories. Meanwhile, they have more similarity in their inter categories. Therefore, images are difficultly distinguish during fine-grained visual classification(FGVC). This paper proposes a deep sparse coding framework to implement the fine-grained visual categorization. In our framework, deep layer structures with sparse coding are used to learn different spatial features. Especially, for categories with asymmetric structure, a quick and efficient pose estimation method is introduced to calibrate their poses. This framework is evaluated using two fine-grained datasets, i.e. Oxford 102 flowers dataset and the CUB-200-2011 bird dataset. Final experimental results show that the performance of our proposed system is highly competitive with state-of-the-art algorithms.
Lihua Guo, Chenggan Guo
IJCNN1
2014 Image esthetic assessment using both hand-crafting and semantic features
Lihua Guo, Yangchao Xiong, Qinghua Huang, Xuelong Li 0001
Neurocomputing1
2011 Smile Expression Classification Using the Improved BIF Feature
abstract
Biologically Inspired Feature is one of efficient feature descriptions, and achieves great performance in some applications. This paper proposes an improved Biologically Inspired Feature(IBIF), and applies this feature into smile recognition. The main contributions of our paper are as follows. 1) a rotation-invariant BIF feature is proposed, which adjusts the RBF function of the traditional Biologically Inspired Model(BIM), 2) the sparse coding method is introduced, and is to establish the Patch dictionary for changing the random patch selection of BIM. Some comparative experiments are made between IBIF and some popular features, such as Gabor, PHOG and BIF. The final experimental results reveal that the IBIF feature can achieve better performance, and can be efficiently applied into the real smile recognition system.
Lihua Guo
ICIG1
2009 A novel feature extraction method using Pyramid Histogram of Orientation Gradients for smile recognition
abstract
Recognizing smiles is of much importance for detecting happy moods. Gabor features are conventionally widely applied to facial expression recognition, but the number of Gabor features is usually too large. We proposed to use pyramid histogram of oriented gradients (PHOG) as the features extracted for smile recognition in this paper. The comparisons between the PHOG and Gabor features using a publicly available dataset demonstrated that the PHOG with a significantly shorter vector length could achieve as high a recognition rate as the Gabor features did. Furthermore, the feature selection conducted by an AdaBoost algorithm was not needed when using the PHOG features. To further improve the recognition performance, we combined these two feature extraction methods and achieved the best smile recognition rate, indicating a good value of the PHOG features for smile recognitions.
Lihua Guo, Qinghua Huang
ICIP2