Xiangmin Shen

dblp:74/10776 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0001-8301-7961ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2026 From Sands to Mansions: Actionable, Customizable and Causality-Preserving Cyberattack Emulation with LLM-Powered Symbolic Planning
Lingzhi Wang 0002, Zhenyuan Li, Zhengkai Wang, Xiangmin Shen, Yan Chen 0004
ACNS (3)5
2026 Incorporating Gradients to Rules: Toward Online, Adaptive Provenance-Based Intrusion Detection
abstract
As cyber-attacks become increasingly sophisticated and stealthy, accurately distinguishing between benign behavior and malicious intrusions has become both more critical and more challenging. Provenance-based intrusion detection systems (PIDS) show strong potential for detecting malicious activities through fine-grained causality analysis, which has gained significant attention from both industry and academia. Among the various PIDS approaches, rule-based systems are particularly favored for their low overhead, real-time detection capability, and interpretability. However, these systems face challenges in reducing false positive rates, primarily due to the lack of fine-tuned rules and specific environments. In this paper, we introduce CAPTAIN+, a rule-based PIDS that autonomously adapts to diverse environments online. Specifically, we propose three adaptive parameters to adjust the detection configuration for nodes, edges, and alarm generation thresholds. Initially, we build a differentiable tag propagation framework and utilize the gradient descent algorithm to optimize these adaptive parameters based on the training data. In this extended version, we integrate an online learning module into the detection stage to dynamically optimize adaptive parameters based on real-time feedback from the detection process. We evaluate CAPTAIN+ based on data from DARPA TC, OpTC datasets, and PKU ASAL datasets. The results demonstrate that CAPTAIN+ offers superior detection accuracy, lower detection latency, reduced runtime overhead, long-term resilience against concept drift, and more interpretable detection results compared to state-of-the-art PIDS.
Zhenyuan Li, Lingzhi Wang 0002, Zhengkai Wang, Xiangmin Shen, Haitao Xu 0002, Yan Chen 0004, Shouling Ji
IEEE Trans. Dependable Secur. Comput.4
2025 PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
Xiangmin Shen, Lingzhi Wang 0002, Zhenyuan Li, Yan Chen 0004, Wencheng Zhao, Jiashui Wang
AsiaCCS1
2025 Incorporating Gradients to Rules: Towards Lightweight, Adaptive Provenance-based Intrusion Detection
Lingzhi Wang 0002, Xiangmin Shen, Weijian Li 0002, Zhenyuan Li, R. Sekar 0001, Han Liu 0001, Yan Chen 0004
NDSS2
2024 Decoding the MITRE Engenuity ATT&CK Enterprise Evaluation: An Analysis of EDR Performance in Real-World Environments
abstract
Endpoint detection and response (EDR) systems have emerged as a critical component of enterprise security solutions, effectively combating endpoint threats like APT attacks with extended lifecycles. In light of the growing significance of endpoint detection and response (EDR) systems, many cybersecurity providers have developed their own proprietary EDR solutions. It's crucial for users to assess the capabilities of these detection engines to make informed decisions about which products to choose. This is especially urgent given the market's size, which is expected to reach around 3.7 billion dollars by 2023 and is still expanding. MITRE is a leading organization in cyber threat analysis. In 2018, MITRE started to conduct annual APT emulations that cover major EDR vendors worldwide. Indicators include telemetry, detection and blocking capability, etc. Nevertheless, the evaluation results published by MITRE don't contain any further interpretations or suggestions.
Xiangmin Shen, Zhenyuan Li, Graham Burleigh, Lingzhi Wang 0002, Yan Chen 0004
AsiaCCS1