VLDB 2026 Research / reviewers in the wild / expert
Qingkai Zeng 0002
dblp:66/3005-2
· DBLP profile ↗
36ranked-venue papers
0as first author
12since 2021 · last 2027
0000-0002-0610-1553ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 9 since 2021Software engineering, systems software and programming languages · 10 · 2 since 2021Artificial intelligence and machine learning · 6 · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Understanding Chain-of-Thought effectiveness in code generation: an empirical and information-theoretic analysis
Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002 |
Empir. Softw. Eng. | 5 |
| 2025 | MSCoT: Structured Chain-of-Thought Generation for Multiple Programming LanguagesabstractWith the rapid development of code intelligence, the application of multiple programming languages is becoming increasingly widespread. However, most existing code generation models mainly focus on a single or a few programming languages, resulting in unsatisfactory performance in a multilingual environment. Chain-of-Thought (CoT) reasoning can significantly improve the performance of the model without the need for retraining or fine-tuning the code generation model by reasonably decomposing complex code generation tasks into multiple subtasks and gradually deriving solutions for each subtask. Nevertheless, the existing CoT generation methods mainly concentrate on Python code, and the performance on other programming languages remains unclear.To fill this gap, we first constructed a CoT generation dataset for 12 programming languages through multi-agent technology. On this basis, we proposed a CoT generation method MSCoT applicable to multiple programming languages. By introducing CoT into the code generation large model, the performance of the code generation large model in a multilingual environment can be improved. Through large-scale empirical research, we compared the generalization abilities of MSCoT and the existing CoT generation methods on multiple programming languages and proved the effectiveness of MSCoT for multiple programming languages. In addition, we also designed a human study to prove the quality of the CoT generated by MSCoT. Finally, we open-sourced the model and dataset of MSCoT to promote the research on CoT generation for multiple programming languages. Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002 |
IJCNN | 4 |
| 2025 | BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS
Yinggang Guo, Zicheng Wang 0010, Weiheng Bai, Qingkai Zeng 0002, Kangjie Lu |
NDSS | 4 |
| 2025 | GUARD: Dual-Agent based Backdoor Defense on Chain-of-Thought in Neural Code GenerationabstractWith the widespread application of large language models in code generation, recent studies demonstrate that employing additional Chain-of-Thought generation models can significantly enhance code generation performance by providing explicit reasoning steps.However, as external components, CoT models are particularly vulnerable to backdoor attacks, which existing defense mechanisms often fail to detect effectively.To address this challenge, we propose GUARD, a novel dualagent defense framework specifically designed to counter CoT backdoor attacks in neural code generation.GUARD integrates two core components: GUARD-Judge, which identifies suspicious CoT steps and potential triggers through comprehensive analysis, and GUARD-Repair, which employs a retrieval-augmented generation approach to regenerate secure CoT steps for identified anomalies.Experimental results show that GUARD effectively mitigates attacks while maintaining generation quality, advancing secure code generation systems. Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002 |
SEKE | 4 |
| 2023 | AttnCall: Refining Indirect Call Targets in Binaries with Attention
Yinggang Guo, Zicheng Wang 0010, Qingkai Zeng 0002 |
ESORICS (4) | 4 |
| 2023 | PET: Prevent Discovered Errors from Being Triggered in the Linux Kernel
Zicheng Wang 0010, Yueqi Chen 0001, Qingkai Zeng 0002 |
USENIX Security Symposium | 3 |
| 2022 | Formal Modeling and Security Analysis for Intra-level Privilege SeparationabstractPrivileged system software such as mainstream operating system kernels and hypervisors have an ongoing stream of vulnerabilities. Even the inflated secure world in Trusted Execution Environment (TEE) is no longer secure in complex real-world scenarios. Since higher privilege levels cannot always be stacked to provide protection, intra-level privilege separation has become a powerful way to build trustworthy systems. However, existing intra-level privilege separation systems lack sound security analysis and cannot give formal guarantees. Yinggang Guo, Zicheng Wang 0010, Bingnan Zhong, Qingkai Zeng 0002 |
ACSAC | 4 |
| 2022 | CryptKSP: A Kernel Stack Protection Model Based on AES-NI Hardware Feature
Bingnan Zhong, Zicheng Wang 0010, Yinggang Guo, Qingkai Zeng 0002 |
SEC | 4 |
| 2022 | The count-min sketch is vulnerable to offline password-guessing attacks
Jaryn Shen, Qingkai Zeng 0002 |
Int. J. Inf. Comput. Secur. | 2 |
| 2021 | Catch You With Cache: Out-of-VM Introspection to Trace Malicious ExecutionsabstractOut-of-VM introspection is an imperative part of security analysis. The legacy methods either modify the system, introducing enormous overhead, or rely heavily on hardware features, which are neither available nor practical in most cloud environments. In this paper, we propose a novel analysis method, named as Catcher, that utilizes CPU cache to perform out-of-VM introspection. Catcher does not make any modifications to the target program and its running environment, nor demands special hardware support. Implemented upon Linux KVM, it natively introspects the target's virtual memory. More importantly, it uses the cache-based side channel to infer the target control flow. To deal with the inherent limitations of the side channel, we propose several heuristics to improve the accuracy and stability of Catcher. Our experiments against various malware armored with packing techniques show that Catcher can recover the control flow in real time with around 67% to 97% accuracy scores. Catcher incurs a negligible overhead to the system and can be launched at anytime to monitor an ongoing attack inside a virtual machine. Chao Su 0001, Xuhua Ding, Qingkai Zeng 0002 |
DSN | 3 |
| 2021 | SecPT: Providing Efficient Page Table Protection based on SMAP Feature in an Untrusted Commodity KernelabstractPage tables are one of the key data structures in OS(Operating System) kernel. It plays an extremely important role in the memory access and protection. However, the page tables are fundamental weakness of operating system because they share the same address space with the vulnerable kernel, and thus subject to kernel data-only attack. To solve that, researchers have relied on the self-protection in the same kernel privilege level without introducing higher privilege layer for efficient world switch and effective page table protection. It needs to intercept and verify every update to kernel page tables. To improve the performance, it is required to reduce the time consumed for each interception as much as possible. In this paper, we propose an architecture to provide efficient page table protection based on Supervisor-mode Access Prevention (SMAP) hardware feature and Kernel Page Table Isolation (KPTI) from an untrusted kernel. SecPT maintains the kernel page tables which are actually used by the kernel in the protection domain and prevents the compromised kernel from subverting page table protection by abusing some privileged instructions. We have realized a prototype of the SecPT. The experimental results show that SecPT provides both effective and efficient page table protection. Bingnan Zhong, Qingkai Zeng 0002 |
TrustCom | 2 |
| 2021 | Survey of CPU Cache-Based Side-Channel Attacks: Systematic Analysis, Security Models, and CountermeasuresabstractPrivacy protection is an essential part of information security. The use of shared resources demands more privacy and security protection, especially in cloud computing environments. Side-channel attacks based on CPU cache utilize shared CPU caches within the same physical device to compromise the system’s privacy (encryption keys, program status, etc.). Information is leaked through channels that are not intended to transmit information, jeopardizing system security. These attacks have the characteristics of both high concealment and high risk. Despite the improvement in architecture, which makes it more difficult to launch system intrusion and privacy leakage through traditional methods, side-channel attacks ignore those defenses because of the shared hardware. Difficult to be detected, they are much more dangerous in modern computer systems. Although some researchers focus on the survey of side-channel attacks, their study is limited to cryptographic modules such as Elliptic Curve Cryptosystems. All the discussions are based on real-world applications (e.g., Curve25519), and there is no systematic analysis for the related attack and security model. Firstly, this paper compares different types of cache-based side-channel attacks. Based on the comparison, a security model is proposed. The model describes the attacks from four key aspects, namely, vulnerability, cache type, pattern, and range. Through reviewing the corresponding defense methods, it reveals from which perspective defense strategies are effective for side-channel attacks. Finally, the challenges and research trends of CPU cache-based side-channel attacks in both attacking and defending are explored. The systematic analysis of CPU cache-based side-channel attacks highlights the fact that these attacks are more dangerous than expected. We believe our survey would draw developers’ attention to side-channel attacks and help to reduce the attack surface in the future. Chao Su 0001, Qingkai Zeng 0002 |
Secur. Commun. Networks | 2 |
| 2019 | AMOGAP: Defending Against Man-in-the-Middle and Offline Guessing Attacks on Passwords
Jaryn Shen, Timothy T. Yuen, Kim-Kwang Raymond Choo, Qingkai Zeng 0002 |
ACISP | 4 |
| 2019 | CSPS: catchy short passwords making offline and online attacks impossibleabstractThis paper proposes to address online and offline attacks to passwords without increasing users' efforts in choosing and memorising their passwords. In CSPS, a password consists of two parts, a user-chosen short password and a server-generated long password. The short password should be memorised and secured by its user while the long password be encrypted and stored on the server side. To keep the secret key for protecting the long password secure, an additional sever is introduced to store the secret key and provide encryption/decryption services. On top of balloon, CSPS integrates expensive hash with secure encryption. It is mathematically proved that computationally unbounded attackers cannot succeed in offline dictionary or brute-force attacks or a combination of offline and online attacks. The criteria of security are established, which quantifies the security. To our best knowledge, CSPS is the first technique to make security quantifiable in password authentication mechanisms. Jaryn Shen, Qingkai Zeng 0002 |
Int. J. Inf. Comput. Secur. | 2 |
| 2018 | Multi-item Passphrases: A Self-adaptive Approach Against Offline Guessing Attacks
Jaryn Shen, Kim-Kwang Raymond Choo, Qingkai Zeng 0002 |
ICDF2C | 3 |
| 2018 | Simulation-based security of function-hiding inner product encryption
Qingkai Zeng 0002, Ximeng Liu, Huanliang Xu |
Sci. China Inf. Sci. | 2 |
| 2018 | Improved Construction for Inner Product Functional EncryptionabstractFunctional encryption (FE) is a vast new paradigm for encryption scheme which allows tremendous flexibility in accessing encrypted data. In a FE scheme, a user can learn specific function of encrypted messages by restricted functional key and reveals nothing else about the messages. Besides the standard notion of data privacy in FE, it should protect the privacy of the function itself which is also crucial for practical applications. In this paper, we construct a secret key FE scheme for the inner product functionality using asymmetric bilinear pairing groups of prime order. Compared with the existing similar schemes, our construction reduces both necessary storage and computational complexity by a factor of 2 or more. It achieves simulation-based security, security strength which is higher than that of indistinguishability-based security, against adversaries who get hold of an unbounded number of ciphertext queries and adaptive secret key queries under the External Decisional Linear (XDLIN) assumption in the standard model. In addition, we implement the secret key inner product scheme and compare the performance with the similar schemes. Qingkai Zeng 0002, Ximeng Liu |
Secur. Commun. Networks | 2 |
| 2017 | Efficient Inner Product Encryption with Simulation-Based Security
Qingkai Zeng 0002, Ximeng Liu |
ICICS | 2 |
| 2017 | Optimizing TLB for Access Pattern Privacy Protection in Data Outsourcing
Yao Liu 0011, Qingkai Zeng 0002, Pinghai Yuan |
SecureComm | 2 |
| 2017 | Dancing with Wolves: Towards Practical Event-driven VMM MonitoringabstractThis paper presents a novel framework that enables practical event-driven monitoring for untrusted virtual machine monitors (VMMs) in cloud computing. Unlike previous approaches for VMM monitoring, our framework neither relies on a higher privilege level nor requires any special hardware support. Instead, we place the trusted monitor at the same privilege level and in the same address space with the untrusted VMM to achieve superior efficiency, while proposing a unique mutual-protection mechanism to ensure the integrity of the monitor. Our security analysis demonstrates that our framework can provide high-assurance for event-driven VMM monitoring, even if the highest-privilege VMM is fully compromised. The experimental results show that our framework only incurs trivial performance overhead for enforcing event-driven monitoring policies, exhibiting tremendous performance improvement on previous approaches. Liang Deng, Peng Liu 0005, Jun Xu 0024, Ping Chen 0003, Qingkai Zeng 0002 |
VEE | 5 |
| 2016 | IntEQ: recognizing benign integer overflows via equivalence checking across multiple precisionsabstractInteger overflow (IO) vulnerabilities can be exploited by attackers to compromise computer systems. In the mean time, IOs can be used intentionally by programmers for benign purposes such as hashing and random number generation. Hence, differentiating exploitable and harmful IOs from intentional and benign ones is an important challenge. It allows reducing the number of false positives produced by IO vulnerability detection techniques, helping developers or security analysts to focus on fixing critical IOs without inspecting the numerous false alarms. The difficulty of recognizing benign IOs mainly lies in inferring the intent of programmers from source code. Xiangyu Zhang 0001, Yunhui Zheng, Qingkai Zeng 0002 |
ICSE | 4 |
| 2016 | SeededFuzz: Selecting and Generating Seeds for Directed FuzzingabstractAs an improvement on traditional random fuzzing, directed fuzzing utilizes dynamic taint analysis to locate regions of seed inputs which can influence security-sensitive program points, and focuses on mutating these identified regions to generate error-revealing test cases. The seed inputs are of great importance to directed fuzzing, because they essentially determine the number of security-sensitive program points we can test. In this paper, we present a seed selection method complementing with a seed generation method for directed fuzzing. Using static analysis, dynamic monitoring and symbolic execution, our approach can provide directed fuzzing with seeds that can cover more security-sensitive program points in a cost-effective way. We implemented a prototype called Seeded-Fuzz, and applied it to five real-world applications. Experimental results show that starting directed fuzzing with our carefully selected and generated seeds, Seeded-Fuzz can test more critical program sites and detect more bugs. Qingkai Zeng 0002 |
TASE | 3 |
| 2016 | Exception-oriented programming: retrofitting code-reuse attacks to construct kernel malwareabstractCommodity operating system kernels are vulnerable to a wide range of attacks due to the large code base and broad attack surface. Mitigation mechanisms such as code signing, W⊕X, and code integrity protection have raised the bar for kernel security. In turn, attack mechanisms have also become increasingly advanced. They have evolved from simple injection of malicious code into more sophisticated code‐reuse attacks [e.g. return‐oriented programming (ROP)]. In this study, the authors describe exception‐oriented programming (EOP), a novel code‐reuse method to construct kernel malware. Unlike previous ROP that can only reuse a limited part of existing code (gadgets), EOP is able to reuse any instruction in existing code and chain the instructions in any order to generate malicious programmes. As a result, EOP can provide the attackers with more powerful capabilities and less complexity for building kernel malware. Liang Deng, Qingkai Zeng 0002 |
IET Inf. Secur. | 2 |
| 2015 | Efficient Dynamic Tracking Technique for Detecting Integer-Overflow-to-Buffer-Overflow VulnerabilityabstractInteger-Overflow-to-Buffer-Overflow (IO2BO) vulnerabilities can be exploited by attackers to cause severe damages to computer systems. In this paper, we present the design and implementation of IntTracker, an efficient dynamic tracking technique for detecting IO2BO vulnerabilities in C/C++ programs. IntTracker utilizes a static taint analysis to select potential overflow sites that are integer operations along critical paths, from sources that are program points reading values from users, to sinks that are memory allocation sites. It then instruments overflow checks at the selected sites. Instead of producing warnings once integer overflows occur, IntTracker replaces the overflown value with a very large and rarely used integer value (dirty value), and treats such the value as an overflow tag. Tag propagation is performed by the existing program operations without any instrumentation as operations on dirty values often produce dirty values. Propagation can be automatically cut off by sanitization routines as they could prevent dirty values from affecting further program execution. IntTracker monitors whether any dirty value is used at a sink to detect IO2BO vulnerabilities. We evaluate IntTracker on 3444 programs of the NIST's SAMATE reference dataset, the SPEC CINT2000 benchmarks and 34 IO2BO bugs in real world. The experimental results show that IntTracker is effective in detecting harmful IO2BO vulnerabilities while bypassing false positives introduced by sanitization routines. Meanwhile, the runtime overhead is negligible, averaging about 0.69%. In contrast, IntPatch, the state of the art, produces a lot more false positives and has a higher overhead. Xiangyu Zhang 0001, Chao Su 0001, Qingkai Zeng 0002 |
AsiaCCS | 4 |
| 2015 | Hardware-Assisted Fine-Grained Code-Reuse Attack Detection
Pinghai Yuan, Qingkai Zeng 0002, Xuhua Ding |
RAID | 2 |
| 2015 | ISboxing: An Instruction Substitution Based Data Sandboxing for x86 Untrusted Libraries
Liang Deng, Qingkai Zeng 0002, Yao Liu 0011 |
SEC | 2 |
| 2015 | Improving the Accuracy of Integer Signedness Error Detection Using Data Flow AnalysisabstractInteger signedness error can be exploited by attackers to cause severe damages to computer systems.Despite of the significant advances in automating the detection of integer signedness errors, accurately differentiating exploitable and harmful signedness errors from unharmful ones still remains an open problem.In this paper, we present the design and implementation of SignFlow, an instrumentation-based integer signedness error detector to reduce the reports for unharmful signedness errors without sacrificing the completeness (i.e.no false negatives).SignFlow utilizes static data flow analysis to identify unharmful integer signedness conversions from the view of where the operands originate and whether the data after conversions can propagate to security-related operations, and then inserts security checks for the remaining conversions so as to accomplish runtime protection.We evaluated SignFlow on 7 real-world harmful integer signedness bugs, SPECint 2006 benchmarks together with 5 real-world applications.Experimental results show that SignFlow successfully detected all harmful integer signedness bugs and achieved a reduction of 41% in false positives over IntFlow, the state-of-the-art signedness error detector. Chao Su 0001, Qingkai Zeng 0002 |
SEKE | 4 |
| 2015 | Statically-Guided Fork-based Symbolic Execution for Vulnerability DetectionabstractFork-based symbolic execution would waste large amounts of computing time and resource on invulnerable paths when applied to vulnerability detection.In this paper, we propose a statically-guided fork-based symbolic execution technique for vulnerability detection to mitigate this problem.In static analysis, we collect all valid jumps along vulnerable paths, and define the priority for each program branch based on the ratio of vulnerable paths over total paths in its subsequent program.In fork-based symbolic execution, path exploration can be restricted to vulnerable paths, and code segments with higher proportion of vulnerable paths can be analyzed in advance by utilizing the result of static analysis.We implement a prototype named SAF-SE and evaluate it with ten benchmarks from GNU Coreutils version 6.11.Experimental results show that SAF-SE outperforms KLEE in the efficiency and accuracy of vulnerability detection. Qingkai Zeng 0002 |
SEKE | 3 |
| 2015 | Evaluating Initial Inputs for Concolic TestingabstractConcolic testing is a powerful technique for vulnerability detection. Current concolic testing tools usually randomly select one well-formed concrete input to start their workflow, then employ different path selection methods to explore the execution space. However, experiments have shown that concolic testing tools have different vulnerability detection performance when starting with different well-formed concrete inputs. In this paper, we present an evaluation method to help concolic testing tools select better initial inputs. The key idea is that: if the concolic execution triggered by one candidate initial input covers more error-prone operations with different execution contexts, it is likely to detect more bugs. Specifically, we firstly identify error-prone operations using fine-grained dynamic taint analysis. Then we propose a scoring algorithm to evaluate the vulnerability detection ability of different candidate initial inputs. We implemented this method in a new tool called CrashFinderHB, and applied it to four applications in Linux: readelf, convert, cjpeg, swftool. Experimental results show that using our evaluation method to select starting points can improve the effectiveness of concolic testing. Moreover, starting with carefully selected initial inputs, we found 4 previously unknown errors in readelf and convert. Qingkai Zeng 0002 |
TASE | 2 |
| 2015 | Improving the Accuracy of Integer Signedness Error Detection Using Data Flow AnalysisabstractInteger signedness errors can be exploited by adversaries to cause severe damages to computer systems. Despite the significant advances in automating the detection of integer signedness errors, accurately differentiating exploitable and harmful signedness errors from unharmful ones is an important challenge. In this paper, we present the design and implementation of SignFlow, an instrumentation-based integer signedness error detector to reduce the reports for unharmful signedness errors. SignFlow first utilizes static data flow analysis to identify unharmful integer sign conversions from the view of where the source operands originate and whether the conversion results can propagate to security-related program points, and then inserts security checks for the remaining conversions so as to accomplish runtime protection. We evaluated SignFlow on 8 real-world harmful integer signedness bugs, SPECint 2006 benchmarks together with 5 real-world applications. The experimental results show that SignFlow correctly detected all harmful integer signedness bugs (i.e. no false negatives) and achieved a reduction of 41% in false positives over IntFlow, the state of the art. Chao Su 0001, Qingkai Zeng 0002 |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2014 | Using Machine Language Model for Mimimorphic Malware Detection
Pinghai Yuan, Qingkai Zeng 0002, Yao Liu 0011 |
ISC | 2 |
| 2014 | EqualVisor: Providing Memory Protection in an Untrusted Commodity HypervisorabstractIn cloud computing, hypervisor is the all-powerful software running in the highest privilege layer, thus attackers who compromise a hypervisor may jeopardize the whole cloud, especially cause memory corruption of any sensitive workloads within the cloud. In this paper, we propose a novel architecture and approach to provide memory protection from an untrusted hypervisor on current x86 platforms. Unlike previous approaches such as nested virtualization, we do not place another higher privilege TCB below the hypervisor. Instead, our approach introduces a properly isolated tiny TCB running in the same privilege level and the same address space with the hypervisor, and uses this TCB to intercept and validate hypervisor's privilege actions for memory protection. In this way, we can enforce further memory security policies only relying on the TCB even if the hypervisor is fully compromised. Liang Deng, Qingkai Zeng 0002, Yao Liu 0011 |
TrustCom | 2 |
| 2010 | Towards a Structured Model for Software Vulnerabilities
Yisha Lu, Qingkai Zeng 0002 |
SEKE | 3 |
| 2010 | Some Improvements for More Precise Model Checking
Qingkai Zeng 0002 |
SEKE | 2 |
| 2009 | A Security Calculus of Concurrent Objects for Verifying Ad Hoc Network ProtocolsabstractWe present a calculus of concurrent objects for specification and security analysis of ad hoc security protocols. The communicating nodes and the network are modeled by objects, while the interactions between them are modeled by asynchronous method invocations. The internal state of an object is represented by a constant method which can be overridden. The approach is complemented by a control flow analysis which can be used to automatically check properties such as security routing. The attacker model is integrated into the analysis as set values containing the knowledge of the attacker. Qingkai Zeng 0002 |
NSS | 2 |
| 2004 | An Adaptive Routing Strategy Based on Dynamic Cache in Mobile Ad Hoc Networks
YueQuan Chen, Qingkai Zeng 0002, Guihai Chen |
ISPA | 3 |