VLDB 2026 Research / reviewers in the wild / expert
Ke Tian
dblp:71/6037
· DBLP profile ↗
23ranked-venue papers
7as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 2 since 2021Computer networks · 5 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CrossCheck-Bench: Diagnosing Compositional Failures in Multimodal Conflict ResolutionabstractMultimodal Large Language Models are primarily trained and evaluated on aligned image-text pairs, which leaves their ability to detect and resolve real-world inconsistencies largely unexplored. In open-domain applications visual and textual cues often conflict, requiring models to perform structured reasoning beyond surface-level alignment. We introduce CrossCheck-Bench, a diagnostic benchmark for evaluating contradiction detection in multimodal inputs. The benchmark adopts a hierarchical task framework covering three levels of reasoning complexity and defines seven atomic capabilities essential for resolving cross-modal inconsistencies. CrossCheck-Bench includes 15k question-answer pairs sourced from real-world artifacts with synthetically injected contradictions. The dataset is constructed through a multi-stage annotation pipeline involving more than 450 expert hours to ensure semantic validity and calibrated difficulty across perception, integration, and reasoning. We evaluate 13 state-of-the-art vision-language models and observe a consistent performance drop as tasks shift from perceptual matching to logical contradiction detection. Most models perform well on isolated entity recognition but fail when multiple clues must be synthesized for conflict reasoning. Capability-level analysis further reveals uneven skill acquisition, especially in tasks requiring multi-step inference or rule-based validation. Additional probing shows that conventional prompting strategies such as Chain-of-Thought and Set-of-Mark yield only marginal gains. By contrast, methods that interleave symbolic reasoning with grounded visual processing achieve more stable improvements. These results highlight a persistent bottleneck in multimodal reasoning and suggest new directions for building models capable of robust cross-modal verification. Baoliang Tian, Yuxuan Si, Jilong Wang 0017, Lingyao Li, Zhongyuan Bao, Zineng Zhou, Sixu Li, Zhouzhuo Zhang, Yike Yun, Ke Tian, Ning Yang 0005, Minghui Qiu |
AAAI | 14 |
| 2026 | MMSegRWKV: Enhancing Multimodal MRI Segmentation for Internet-of-Medical-Things-Enabled Healthcare With RWKV-Inspired Architectures
Yitong Cao, Yuanqing Xia, Ke Tian, Dihua Zhai |
IEEE Internet Things J. | 3 |
| 2025 | Wastewater treatment monitoring: Fault detection in sensors using transductive learning and improved reinforcement learning
Jing Yang 0054, Ke Tian, Huayu Zhao, Zheng Feng, Sami Bourouis, Sami Dhahbi, Abdullah Ayub Khan, Mouhebeddine Berrima, Lip Yee Por |
Expert Syst. Appl. | 2 |
| 2025 | A Kubernetes-based scheme for efficient resource allocation in containerized workflow
Yuanqing Xia, Chenggang Shan, Ke Tian, Yufeng Zhan |
Future Gener. Comput. Syst. | 4 |
| 2025 | Focus-TransUnet3D: High-Precision Model for 3D Segmentation of Medical Point TargetsabstractDeep learning has been extensively applied in medical image segmentation, providing significant support for disease diagnosis. However, traditional encoder-decoder networks struggle with segmenting scale-sensitive point target lesions. To address this challenge, this paper proposes an innovative incremental fusion architecture that can integrate different models and achieve significant performance improvements through complementary fusion. Based on this architecture, we developed Focus-TransUnet3D by combining the Trans-FusionNet3D model and the 3D Unet model. This model adopts a global-to-local segmentation strategy, effectively addressing the challenges of medical point target segmentation, thereby expanding the application of deep learning in the field of medical image processing. Furthermore, we design a deep fusion strategy suitable for the transformer model to adapt to multi-scale feature learning. The integration of the transformer model with convolutional neural networks brings improvements in local and global feature extraction capabilities, enhancing the applicability of our model. We evaluate our model on three clinical datasets with different target scales: the Intracranial Artery dataset, the Intracranial Aneurysm dataset, and the LiTS17 dataset. The results indicate that in the external test for intracranial aneurysm auxiliary diagnosis, the model trained with only 47 annotated samples achieved the state-of-the-art performance, attaining a Dice coefficient of 84.14% and a sensitivity of 100%. This effectively addresses the challenges of annotation scarcity and tiny targets. Our code will be released athttps://github.com/caijilia/FTUnet3D. Dihua Zhai, Hao Li 0075, Ke Tian, Yi Yang 0009, Zhenyao Chang, Shuo Wang 0001, Yuanqing Xia |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2021 | Unsupervised Heart Abnormality Detection Based on Phonocardiogram Analysis with Beta Variational Auto-EncodersabstractHeart Sound (also known as phonocardiogram (PCG)) analysis, is a popular way that detects cardiovascular diseases (CVDs). Most PCG analysis uses supervised way, which demands both normal and abnormal samples. This paper proposes a method of unsupervised PCG analysis that uses beta variational auto-encoder (β – VAE) to model the normal PCG signals. The best performed model reaches an AUC (Area Under Curve) value of 0.91 in ROC (Receiver Operating Characteristic) test for PCG signals collected from the same source. Unlike majority of β – VAEs that are used as generative models, the best-performed β – VAE has a β value smaller than 1. This fact demonstrates that the resampling process helps the improvements on anomaly PCG detection through reconstruction loss worth a heavier weight. Further investigations suggest that anomaly score based on reconstruction loss may be better than anomaly scores based on latent vectors of samples in PCG analysis based on VAE systems. Shengchen Li, Ke Tian |
ICASSP | 2 |
| 2021 | Living-Off-The-Land Command Detection Using Active LearningabstractIn recent years, enterprises have been targeted by advanced adversaries who leverage creative ways to infiltrate their systems and move laterally to gain access to critical data. One increasingly common evasive method is to hide the malicious activity behind a benign program by using tools that are already installed on user computers. These programs are usually part of the operating system distribution or another user-installed binary, therefore this type of attack is called “Living-Off-The-Land”. Detecting these attacks is challenging, as adversaries may not create malicious files on the victim computers and anti-virus scans fail to detect them. Talha Ongun, Jack W. Stokes, Jonathan Bar Or, Ke Tian, Farid Tajaddodianfar, Joshua Neil, Christian Seifert, Alina Oprea, John C. Platt |
RAID | 4 |
| 2021 | Checking is Believing: Event-Aware Program Anomaly Detection in Cyber-Physical SystemsabstractSecuring cyber-physical systems (CPS) against malicious attacks is of paramount importance because these attacks may cause irreparable damages to physical systems. Recent studies have revealed that control programs running on CPS devices suffer from both control-oriented attacks (e.g., code-injection or code-reuse attacks) and data-oriented attacks (e.g., non-control data attacks). Unfortunately, existing detection mechanisms are insufficient to detect runtime data-oriented exploits, due to the lack of runtime execution semantics checking. In this work, we propose Orpheus, a new security methodology for defending against data-oriented attacks by enforcing cyber-physical execution semantics. We first present a general method for reasoning cyber-physical execution semantics of a control program (i.e., causal dependencies between the physical context/event and program control flows), including the event identification and dependence analysis. As an instantiation of Orpheus, we then present a new program behavior model, i.e., the event-aware finite-state automaton (eFSA). eFSA takes advantage of the event-driven nature of CPS control programs and incorporates event checking in anomaly detection. It detects data-oriented exploits if a specific physical event is missing along with the corresponding event dependent state transition. We evaluate our prototype's performance by conducting case studies under data-oriented attacks. Results show that eFSA can successfully detect different runtime attacks. Our prototype on Raspberry Pi incurs a low overhead, taking 0.0001s for each state transition integrity checking, and 0.063s~0.211s for the cyber-physical contextual consistency checking. Long Cheng 0005, Ke Tian, Danfeng Yao, Lui Sha, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Deployment-quality and Accessible Solutions for Cryptography Code DevelopmentabstractCryptographic API misuses seriously threatens software security. Automatic screening of cryptographic misuse vulnerabilities has been a popular and important line of research over the years. However, the vision of producing a scalable detection tool that developers can routinely use to screen millions of line of code has not been achieved yet. Our main technical goal is to attain a high precision and high throughput approach based on specialized program analysis. Specifically, we design inter-procedural program slicing on top of a new on-demand flow-, context- and field- sensitive data flow analysis. Our current prototype named CryptoGuard can detect a wide range of Java cryptographic API misuses with a precision of 98.61%, when evaluated on 46 complex Apache Software Foundation projects (including, Spark, Ranger, and Ofbiz). Our evaluation on 6,181 Android apps also generated many security insights. We created a comprehensive benchmark named CryptoApi-Bench with 40-unit basic cases and 131-unit advanced cases for in-depth comparison with leading solutions (e.g., SpotBugs, CrySL, Coverity). To make CryptoGuard widely accessible, we are in the process of integrating CryptoGuard with the Software Assurance Marketplace (SWAMP). SWAMP is a popular no-cost service for continuous software assurance and static code analysis. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Ke Tian, Miles Frantz, Na Meng 0001, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu, Danfeng Yao |
CODASPY | 4 |
| 2020 | Prioritizing data flows and sinks for app security transformation
Ke Tian, Gang Tan, Barbara G. Ryder, Danfeng Yao |
Comput. Secur. | 1 |
| 2020 | Detection of Repackaged Android Malware with Code-Heterogeneity FeaturesabstractDuring repackaging, malware writers statically inject malcode and modify the control flow to ensure its execution. Repackaged malware is difficult to detect by existing classification techniques, partly because of their behavioral similarities to benign apps. By exploring the app's internal different behaviors, we propose a new Android repackaged malware detection technique based on code heterogeneity analysis. Our solution strategically partitions the code structure of an app into multiple dependence-based regions (subsets of the code). Each region is independently classified on its behavioral features. We point out the security challenges and design choices for partitioning code structures at the class and method level graphs, and present a solution based on multiple dependence relations. We have performed experimental evaluation with over 7,542 Android apps. For repackaged malware, our partition-based detection reduces false negatives (i.e., missed detection) by 30-fold, when compared to the non-partition-based approach. Overall, our approach achieves a false negative rate of 0.35 percent and a false positive rate of 2.97 percent. Ke Tian, Danfeng Yao, Barbara G. Ryder, Gang Tan, Guojun Peng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsabstractCryptographic API misuses, such as exposed secrets, predictable random numbers, and vulnerable certificate verification, seriously threaten software security. The vision of automatically screening cryptographic API calls in massive-sized (e.g., millions of LoC) programs is not new. However, hindered by the practical difficulty of reducing false positives without compromising analysis quality, this goal has not been accomplished. CryptoGuard is a set of detection algorithms that refine program slices by identifying language-specific irrelevant elements. The refinements reduce false alerts by 76% to 80% in our experiments. Running our tool, CryptoGuard, on 46 high-impact large-scale Apache projects and 6,181 Android apps generated many security insights. Our findings helped multiple popular Apache projects to harden their code, including Spark, Ranger, and Ofbiz. We also have made progress towards the science of analysis in this space, including manually analyzing 1,295 Apache alerts, confirming 1,277 true positives (98.61% precision), and in-depth comparison with leading solutions including CrySL, SpotBugs, and Coverity. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, Danfeng Yao |
CCS | 5 |
| 2019 | Poster: Deployment-quality and Accessible Solutions for Cryptography Code DevelopmentabstractCryptographic API misuses seriously threaten software security. Automatic screening of cryptographic misuse vulnerabilities has been a popular and important line of research over the years. However, the vision of producing a scalable detection tool that developers can routinely use to screen millions of line of code has not been achieved yet. Our main technical goal is to attain a high precision and high throughput approach based on specialized program analysis. Specifically, we design inter-procedural program slicing on top of a new on-demand flow-, context- and field- sensitive data flow analysis. Our current prototype named CryptoGuard can detect a wide range of Java cryptographic API misuses with a precision of 98.61%,, when evaluated on 46 complex Apache Software Foundation projects (including, Spark, Ranger, and Ofbiz). Our evaluation on 6,181 Android apps also generated many security insights. We created a comprehensive benchmark named CryptoAPI-Bench with 40-unit basic cases and 131-unit advanced cases for in-depth comparison with leading solutions (e.g., SpotBugs, CrySL, Coverity). To make CryptoGuard widely accessible, we are in the process of integrating CryptoGuard with the Software Assurance Marketplace (SWAMP). SWAMP is a popular no-cost service for continuous software assurance and static code analysis. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Ke Tian, Miles Frantz, Na Meng 0001, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu, Danfeng Yao |
CCS | 4 |
| 2018 | Needle in a Haystack: Tracking Down Elite Phishing Domains in the Wild
Ke Tian, Steve T. K. Jan, Hang Hu 0002, Danfeng Yao, Gang Wang 0011 |
Internet Measurement Conference | 1 |
| 2018 | FrameHanger: Evaluating and Classifying Iframe Injection at Large Scale
Ke Tian, Zhou Li 0001, Kevin D. Bowers, Danfeng Yao |
SecureComm (2) | 1 |
| 2017 | Orpheus: Enforcing Cyber-Physical Execution Semantics to Defend Against Data-Oriented AttacksabstractRecent studies have revealed that control programs running on embedded devices suffer from both control-oriented attacks (e.g., code-injection or code-reuse attacks) and data-oriented attacks (e.g., non-control data attacks). Unfortunately, existing detection mechanisms are insufficient to detect runtime data-oriented exploits, due to the lack of runtime execution semantics checking. In this work, we propose Orpheus, a security methodology for defending against data-oriented attacks by enforcing cyber-physical execution semantics. We address several challenges in reasoning cyber-physical execution semantics of a control program, including the event identification and dependence analysis. As an instantiation of Orpheus, we present a new program behavior model, i.e., the event-aware finite-state automaton (eFSA). eFSA takes advantage of the event-driven nature of control programs and incorporates event checking in anomaly detection. It detects data-oriented exploits if physical events and eFSA's state transitions are inconsistent. We evaluate our prototype's performance by conducting case studies under data-oriented attacks. Results show that eFSA can successfully detect different runtime attacks. Our prototype on Raspberry Pi incurs a low overhead, taking 0.0001s for each state transition integrity checking, and 0.063s~0.211s for the cyber-physical contextual consistency checking. Long Cheng 0005, Ke Tian, Danfeng Yao |
ACSAC | 2 |
| 2017 | POSTER: Detection of CPS Program Anomalies by Enforcing Cyber-Physical Execution SemanticsabstractIn this work, we present a new program behavior model, i.e., the event-aware finite-state automaton ( eFSA ), which takes advantage of the event-driven nature of control programs in cyber-physical systems (CPS) and incorporates event checking in anomaly detection. eFSA provides new detection capabilities to detect data-oriented attacks in CPS control programs, including attacks on control intensity (i.e., hijacked for/while-loops) and attacks on control branch (i.e., conditional branches). We implement a prototype of our approach on Raspberry Pi and evaluate eFSA 's performance by conducting CPS case studies. Results show that it is able to effectively detect different CPS attacks in our experiments. Long Cheng 0005, Ke Tian, Danfeng Yao |
CCS | 2 |
| 2016 | A Sharper Sense of Self: Probabilistic Reasoning of Program Behaviors for Anomaly Detection with Context SensitivityabstractProgram anomaly detection models legitimate behaviors of complex software and detects deviations during execution. Behavior deviations may be caused by malicious exploits, design flaws, or operational errors. Probabilistic detection computes the likelihood of occurrences of observed call sequences. However, maintaining context sensitivity in detection incurs high modeling complexity and runtime overhead. We present a new anomaly-based detection technique that is both probabilistic and 1-level calling-context sensitive. We describe a matrix representation and clustering-based solution for model reduction, specifically reducing the number of hidden states in a special hidden Markov model whose parameters are initialized with program analysis. Our extensive experimental evaluation confirms the significantly improved detection accuracy and shows that attacker's ability to conduct code-reuse exploits is substantially limited. Kui Xu 0002, Ke Tian, Danfeng Yao, Barbara G. Ryder |
DSN | 2 |
| 2015 | Probabilistic Program Modeling for High-Precision Anomaly ClassificationabstractThe trend constantly being observed in the evolution of advanced modern exploits is their growing sophistication in stealthy attacks. Code-reuse attacks such as return-oriented programming allow intruders to execute mal-intended instruction sequences on a victim machine without injecting external code. We introduce a new anomaly-based detection technique that probabilistically models and learns a program's control flows for high-precision behavioral reasoning and monitoring. Our prototype in Linux is named STILO, which stands for STatically InitiaLized markOv. Experimental evaluation involves real-world code-reuse exploits and over 4,000 testcases from server and utility programs. STILO achieves up to 28-fold of improvement in detection accuracy over the state-of-the-art HMM-based anomaly detection. Our findings suggest that the probabilistic modeling of program dependences provides a significant source of behavior information for building high-precision models for real-time system monitoring. Kui Xu 0002, Danfeng Yao, Barbara G. Ryder, Ke Tian |
CSF | 4 |
| 2015 | Development of a Real-World Oriented Smartphone AR Supported Learning System for Seasonal Constellation Observation
Ke Tian, Mayu Urata, Mamoru Endo, Katsuhiro Mouri, Takami Yasuda, Jien Kato |
ICCE | 1 |
| 2012 | D-ODMRP: a destination-driven on-demand multicast routing protocol for mobile ad hoc networksabstractThis article proposes a destination-driven on-demand multicast routing protocol (D-ODMRP) to improve the multicast forwarding efficiency in mobile ad hoc networks (MANETs). In D-ODMRP, the path from the multicast source to a multicast destination tends to use those paths passing through another multicast destination. If such multiple paths are available, the one leading to the least extra cost is preferred. This destination-driven strategy is introduced into the on-demand construction process of a multicast forwarding structure in a popular multicast protocol ODMRP. Simulation results show that D-ODMRP can significantly improve the forwarding efficiency as compared with ODMRP. Moreover, the destination-driven strategy can also be introduced into other existing multicast routing protocols for MANETs. Yan Yan 0009, Ke Tian, Kui Huang, Baoxian Zhang, Jun Zheng 0002 |
IET Commun. | 2 |
| 2010 | Data Gathering Protocols for Wireless Sensor Networks with Mobile SinksabstractWireless sensor networks with mobile sinks (mWSN) have attracted a lot of attention recently. In an mWSN, each mobile sink can move freely and unpredictably. In this paper, we design two efficient data gathering protocols for mWSNs. The first protocol (called AVRP) adopts Voronoi scoping plus dynamic anchor selection to handle the sink mobility issue. In the second protocol (called TRAIL), the trail of mobile sink is used for guiding packet forwarding as sinks move in the network. In TRAIL, to forward a data packet, integration of trail-based forwarding and random walk is used. Specifically, when no fresh trail of any sink is known, random walk is used; once a sensor on a fresh sink trail is reached, data packet will be forwarded along the trail. TRAIL is simple to implement and has small protocol overhead. Simulation results show the designed protocols have high performance and further AVRP is suitable for mWSNs with heavy traffic while TRAIL is suitable for mWSNs with light traffic. Ke Tian, Baoxian Zhang, Kui Huang |
GLOBECOM | 1 |
| 2009 | Destination-Driven On-Demand Multicast Routing Protocol for Wireless Ad Hoc NetworksabstractIn this paper, we design a destination-driven on-demand multicast routing protocol for wireless ad hoc networks. The design objective is to improve the multicast forwarding efficiency. To achieve this goal, the path to reach a multicast destination is biased towards those paths passing through another multicast destination. If multiple such choices are available, the one leading to the least extra cost is selected. Our protocol embeds this destination-driven feature into the on-demand multicast structure building process of an existing multicast protocol ODMRP. Detailed protocol design descriptions are provided. Simulation results show that our protocol can greatly improve the forwarding efficiency as compared with ODMRP. Moreover, our destination-driven design can also work well with other existing multicast routing protocols for wireless ad hoc networks. Ke Tian, Baoxian Zhang, Hussein T. Mouftah, Jian Ma 0001 |
ICC | 1 |