VLDB 2026 Research / reviewers in the wild / expert
Wei Qiao 0005
dblp:71/6357-5
· DBLP profile ↗
10ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0003-1561-9466ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicabstractAdvanced Persistent Threats (APTs) are difficult to detect due to their complexity and stealthiness. To mitigate such attacks, many approaches model entities and their relationship using provenance graphs to detect the stealthy and persistent characteristics of APTs. However, existing detection methods suffer from the flaws of missing indirect dependencies, noisy complex scenarios, and missing behavioral logical associations, which make it difficult to detect complex scenarios and effectively identify stealthy threats. In this paper, we propose Sentient, an APT detection method that combines pre-training and intent analysis. It employs a graph transformer to learn structural and semantic information from provenance graphs to avoid missing indirect dependencies. We mitigate scenario noise by combining global and local information. Additionally, we design an Intent Analysis Module (IAM) to associate logical relationships between behaviors. Sentient is trained solely on easily obtainable benign data to detect malicious behaviors that deviate from benign behavioral patterns. We evaluated Sentient on three widely-used datasets covering real-world attacks and simulated attacks. Notably, compared to six state-of-the-art methods, Sentient achieved an average reduction of 44% in false positive rate(FPR) for detection. Wei Qiao 0005, Weiheng Wu, Zhigang Lu 0002, Bo Jiang 0013, Baoxu Liu |
AAAI | 3 |
| 2026 | Forge: A Robust Multi-tab Website Fingerprinting Attack via Blind Source SeparationabstractWhile Tor's strong anonymity shields users' privacy, it also enables malicious activities, motivating attacks that bypass its protections. Website Fingerprinting (WF) has emerged as a primary threat in this domain. However, existing WF methods struggle with realistic multi-tab browsing scenarios, often relying on prior knowledge of the number of open tabs and lacking robustness against network noise and defenses. Yitan Huang, Wei Qiao 0005, Meng Shen 0001, Linxu Li, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu |
WWW | 2 |
| 2025 | Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningabstractAdvanced Persistent Threats (APTs) represent sophisticated cyberattacks characterized by their ability to remain undetected within the victim system for extended periods, aiming to exfiltrate sensitive data or disrupt operations. Existing detection approaches often struggle to effectively identify these complex threats, construct the attack chain for defense facilitation, or resist adversarial attacks. To overcome these challenges, we propose Slot, an advanced APT detection approach based on provenance graphs and graph reinforcement learning. Slot excels in uncovering multi-level hidden relationships, such as causal, contextual, and indirect connections, among system behaviors through provenance graph mining. Slot implements semi-supervised learning with limited labels through efficient label similarity computation, significantly enhancing both detection performance and model robustness. By pioneering the integration of graph reinforcement learning, Slot dynamically adapts to new user activities and evolving attack strategies, enhancing its resilience against adversarial attacks. Additionally, Slot automatically constructs the attack chain according to detected attacks with clustering algorithms, providing precise identification of attack paths and facilitating the development of defense strategies. Evaluations with real-world datasets demonstrate Slot's outstanding accuracy, efficiency, adaptability, and robustness in APT detection, with most metrics surpassing state-of-the-art methods. Additionally, case studies conducted to assess Slot's effectiveness in supporting APT defense further establish it as a practical and reliable tool for cybersecurity protection. Wei Qiao 0005, Yebo Feng, Teng Li 0003, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001, Yang Liu 0003 |
CCS | 1 |
| 2025 | PanThreat: Global Resource-Based Anomaly Detection for APTsabstractAdvanced Persistent Threats (APTs), due to their stealthiness and complexity, have become a significant security challenge for modern enterprises, often causing severe economic losses. To address these threats, researchers have proposed using provenance graphs to model system entities and their dependencies, aiming to capture the complex scenarios of APT attacks. However, existing Provenance-based Intrusion Detection Systems (PIDS) still suffer from the following challenges: (1) Historical interaction information loss due to the truncation of long-term interaction scenarios; (2) The difficulty in capturing long-distance dependencies leads to the loss of crucial contextual information; (3) Existing methods struggle to balance detection efficiency and granularity. We introduce PanThreat, an online detection system that performs fine-grained, real-time analysis of host system logs to identify malicious activities. PanThreat combines attributes encoding through Word2Vec and position encoding using Laplacian feature matrices, while retaining long-term interaction histories and effectively modeling long-range dependencies within provenance graphs. This integrated approach significantly enhances detection accuracy. Additionally, PanThreat leverages the parallel processing capabilities of Graph Transformers to improve detection efficiency. Evaluations on the DARPA E3 dataset and StreamSpot database demonstrate PanThreat's effectiveness in detecting complex APT attacks, outperforming four state-of-the-art methods while maintaining an average processing speed of 58,140 events per second. Weiheng Wu, Bingsheng Bi, Wei Qiao 0005, Bo Jiang 0013 |
CSCWD | 4 |
| 2025 | DCASI: A Sequence-based Attack Investigation Method Using DTW Contrastive LearningabstractThe stealth and persistence of APT attacks make investigation particularly challenging, further complicated by the diversity and volume of host logs. Existing methods, though effective, have limitations: 1) They rely heavily on manual processing and complex models that often fail to capture temporal relationships in logs; 2) These models struggle to differentiate highly similar attack behaviors from normal activities; 3) Interpretability and security challenges in deep learning models remain unresolved. This paper introduces DCASI, a sequence-based investigation method that integrates DTW similarity with contrastive learning. By constructing provenance graphs and extracting sequences through node pairs, DCASI performs semantic analysis, computes DTW similarity matrices, and employs contrastive learning to generate robust sequence representations. A lightweight random forest model is then used to identify attack behaviors. Evaluation on public datasets shows that DCASI outperforms existing methods. Wei Qiao 0005, Yunxiang Wang, Bo Jiang 0013, Zhigang Lu 0002 |
ICASSP | 2 |
| 2025 | Brewing Vodka: Distilling Pure Knowledge for Lightweight Threat Detection in Audit LogsabstractAdvanced Persistent Threats (APTs) are continuously evolving, leveraging their stealthiness and persistence to put increasing pressure on current provenance-based Intrusion Detection Systems (IDS). This evolution exposes several critical issues: (1) The dense interaction between malicious and benign nodes within provenance graphs introduces neighbor noise, hindering effective detection; (2) The complex prediction mechanisms of existing APTs detection models lead to the insufficient utilization of prior knowledge embedded in the data; (3) The high computational cost makes detection impractical. Weiheng Wu, Wei Qiao 0005, Bo Jiang 0013, Baoxu Liu, Zhigang Lu 0002 |
WWW | 2 |
| 2025 | Towards effective black-box attacks on DoH tunnel detection systems
Linghao Li, Wei Qiao 0005, Zelin Cui, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002 |
Comput. Networks | 4 |
| 2025 | PathWatcher: A path-based behavior detection method for attack detection and investigationabstractAdvanced Persistent Threats (APTs) comprise complex and stealthy attack techniques. Due to the characteristics of system audit logs in capturing system-level process calls and providing granular log data, using audit logs for causal analysis of advanced threat behaviors has become a popular solution. However, existing solutions still suffer from several deficiencies: (1) semantic gaps between raw data in low-level views and high-level system behaviors, (2) fatigue alert, and (3) poor interpretability and inferability. In this paper, we propose PathWatcher, a path-based behavior detection method, which enables attack investigation based on detection results. PathWatcher enhances low-level semantics by combining operation sequences, extracting paths as behavioral entities from the provenance graph, and learning path features. This approach reduces the semantic gap between low-level data and high-level system behaviors. PathWatcher first performs graph construction and path extraction in the graph construction module, followed by feature learning of nodes and paths in the behavioral sequence extraction module, the data generated during the process exists in the path record with a certain rule, and finally the data from the path record is used for feature extraction and path tracing in the behavior identification and attack clues module, the data from the path record is used for feature extraction and path tracing. This model exhibits strong inferability and interpretability by matching paths to operational behaviors in logs. This allows security researchers to combine path records and investigate attacks directly using high-level semantics, thereby alleviating alert fatigue. Our experimental results demonstrate that PathWatcher effectively improves the detection accuracy of malicious behaviors while enhancing semantic interpretability. The detection results are inferable, achieving accuracies of 99.76% and 99.07% on two datasets, and we provide an analysis of attack investigations. Yinhao Qi, Wei Qiao 0005, Bo Jiang 0013, Zhigang Lu 0002 |
Comput. Secur. | 4 |
| 2025 | SauronEyes: Disentangling Voluminous Logs to Unveil Camouflaged Attack Intentions
Wei Qiao 0005, Weiheng Wu, Yebo Feng, Teng Li 0003, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | T-Trace: Constructing the APTs Provenance Graphs Through Multiple Syslogs CorrelationabstractAdvanced Persistent Threats (APTs) employ sophisticated and covert tactics to infiltrate target systems, leading to increased vulnerability and an elevated risk of exposure. Consequently, it is essential for us to proactively create an extensive and clearly outlined attack chain for APTs in order to effectively combat these threats. Unlike traditional malware or application threats, APTs can sidestep cyber security efforts and cause severe damage to organizations or even state security. Nonetheless, earlier methods struggle to accurately track APTs and may face a dependency explosion issue, as identifying the intricate and complex unknown malicious activities within APTs proves to be challenging. In this paper, we propose and build an approach, T-trace, which constructs the events provenance graphs by analyzing the correlations among logs. The approach precisely finds the log communities with tensor decomposition and calculates significance scores to extract the events. The APTs can be inferred by discovering the event communities and constructing the provenance graph with log correlation. In the experiment, we used DARPA data sets and launched four current practical APTs. Compared with current approaches, the results show that T-trace can efficiently reduce time cost by 90% and achieve a 92% accuracy rate in constructing the provenance graph, which can be practically applied in APTs provenance. Teng Li 0003, Ximeng Liu, Wei Qiao 0005, Xiongjie Zhu, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |