VLDB 2026 Research / reviewers in the wild / expert
Kun Li 0026
dblp:75/1458-26
· DBLP profile ↗
8ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-8305-0841ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 2 first-author · 5 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "Say What You Mean": Natural Language Access Control With Large Language Models for Internet of Things
Ye Cheng, Minghui Xu 0001, Yue Zhang 0025, Kun Li 0026, Hao Wu 0067, Yechao Zhang, Shao-Yong Guo 0001, Wangjie Qiu, Dongxiao Yu, Xiuzhen Cheng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Can Large Language Models Be Trusted Paper Reviewers? A Feasibility StudyabstractAcademic paper review typically requires substantial time, expertise, and human resources. Large Language Models (LLMs) present a promising method for automating the review process due to their extensive training data, broad knowledge base, and relatively low usage cost. This work explores the feasibility of using LLMs for academic paper review by proposing an automated review system. The system integrates Retrieval Augmented Generation (RAG), the AutoGen multi-agent system, and Chain-of-Thought prompting to support tasks such as format checking, standardized evaluation, comment generation, and scoring. Experiments conducted on 290 submissions from the WASA 2024 conference using GPT-4o show that LLM-based review significantly reduces review time (average 2.48 hours) and cost (average $104.28 USD). However, the similarity between LLM-selected papers and actual accepted papers remains low (average 38.6%), indicating issues such as hallucination, lack of independent judgment, and retrieval preferences. Therefore, it is recommended to use LLMs as assistive tools to support human reviewers, rather than to replace them. Chuanlei Li, Minghui Xu 0001, Kun Li 0026, Yue Zhang 0025, Xiuzhen Cheng |
MASS | 4 |
| 2025 | We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP EcosystemsabstractThe Model Context Protocol (MCP) has emerged as a widely adopted mechanism for connecting large language models to external tools and resources. While MCP promises seamless extensibility and rich integrations, it also introduces a substantially expanded attack surface: any plugin can inherit broad system privileges with minimal isolation or oversight. In this work, we conduct the first large-scale empirical analysis of MCP security risks. We develop an automated static analysis framework and systematically examine 2,562 real-world MCP applications spanning 23 functional categories. Our measurements reveal that network and system resource APIs dominate usage patterns, affecting 1,438 and 1,237 servers respectively, while file and memory resources are less frequent but still significant. We find that Developer Tools and API Development plugins are the most API-intensive, and that less popular plugins often contain disproportionately high-risk operations. Through concrete case studies, we demonstrate how insufficient privilege separation enables privilege escalation, misinformation propagation, and data tampering. Based on these findings, we propose a detailed taxonomy of MCP resource access, quantify security-relevant API usage, and identify open challenges for building safer MCP ecosystems, including dynamic permission models and automated trust assessment. Kun Li 0026, Boyang Ma, Minghui Xu 0001, Yue Zhang 0025, Xiuzhen Cheng |
MASS | 2 |
| 2025 | On protecting the data privacy of Large Language Models (LLMs) and LLM agents: A literature reviewabstractLarge Language Models (LLMs) are complex artificial intelligence systems, which can understand, generate, and translate human languages. By analyzing large amounts of textual data, these models learn language patterns to perform tasks such as writing, conversation, and summarization. Agents built on LLMs (LLM agents) further extend these capabilities, allowing them to process user interactions and perform complex operations in diverse task environments. However, during the processing and generation of massive data, LLMs and LLM agents pose a risk of sensitive information leakage, potentially threatening data privacy. This paper aims to demonstrate data privacy issues associated with LLMs and LLM agents to facilitate a comprehensive understanding. Specifically, we conduct an in-depth survey about privacy threats, encompassing passive privacy leakage and active privacy attacks. Subsequently, we introduce the privacy protection mechanisms employed by LLMs and LLM agents and provide a detailed analysis of their effectiveness. Finally, we explore the privacy protection challenges for LLMs and LLM agents as well as outline potential directions for future developments in this domain. Biwei Yan, Kun Li 0026, Minghui Xu 0001, Yueyan Dong, Yue Zhang 0025, Zhaochun Ren, Xiuzhen Cheng |
High Confid. Comput. | 2 |
| 2025 | AutoIoT: Automated IoT Platform Using Large Language ModelsabstractInternet of Things (IoT) platforms, particularly smart home platforms providing significant convenience to people’s lives, such as Apple HomeKit and Samsung SmartThings, allow users to create automation rules through trigger-action programming. However, some users may lack the necessary knowledge to formulate automation rules, thus preventing them from fully benefiting from the conveniences offered by smart home technology. To address this, smart home platforms provide predefined automation policies based on the smart home devices registered by the user. Nevertheless, these policies, being pregenerated and relatively simple, fail to adequately cover the diverse needs of users. Furthermore, conflicts may arise between automation rules, and integrating conflict detection into the IoT platform increases the burden on developers. In this article, we propose AutoIoT, an automated IoT platform based on large language models (LLMs) and formal verification techniques, designed to achieve end-to-end automation through device information extraction, LLM-based rule generation, conflict detection, and avoidance. AutoIoT can help users generate conflict-free automation rules and assist developers in generating codes for conflict detection, thereby enhancing their experience. A code adapter has been designed to separate logical reasoning from the syntactic details of code generation, enabling LLMs to generate code for programming languages beyond their training data. Finally, we evaluated the performance of AutoIoT and presented a case study demonstrating how AutoIoT can integrate with existing IoT platforms. Ye Cheng, Minghui Xu 0001, Yue Zhang 0025, Kun Li 0026 |
IEEE Internet Things J. | 4 |
| 2025 | TidyBlock: A Novel Consensus Mechanism for DAG-based Blockchain in IoTabstractThe integration of directed acyclic graph (DAG)-based blockchain and Internet of Things (IoT) aims at improving the efficiency of data storage. However, if massive IoT data are not placed in an organized way, the search and usage of the data for upper-level applications can be burdensome, since they have to examine the data block by block, which also increases the difficulty of data verification, affecting consensus efficiency. To maintain the high throughput advantage of DAG-based blockchain applied in IoT and improve the data analysis efficiency, we propose a novel consensus mechanism named TidyBlock, including the transaction collation mechanism for block generation and the block selection mechanism for verification. The first mechanism can tidy up scattered transactions before they are packaged into blocks, while the second one can collate blocks to facilitate verification, realizing a two-layer collation of IoT data so as to increase analysis efficiency of upper-level IoT applications. Additionally, the second mechanism can provide a self-driven incentive for rational participants to follow the first one in case they are reluctant to do extra collation work. Theoretical analysis is provided to demonstrate the validity of our proposed algorithms by formal methods. Extensive simulations based on synthetic data verify the rationality and effectiveness of the proposed mechanisms. Xidi Qu, Shengling Wang 0001, Kun Li 0026, Jian-Hui Huang, Xiuzhen Cheng |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | A Misreport- and Collusion-Proof Crowdsourcing Mechanism Without Quality VerificationabstractQuality control plays a critical role in crowdsourcing. The state-of-the-art work is not suitable for crowdsourcing applications that require extensive validation of the tasks quality, since it is a long haul for the requestor to verify task quality or select professional workers in a one-by-one mode. In this paper, we propose a misreport- and collusion-proof crowdsourcing mechanism, guiding workers to truthfully report the quality of submitted tasks without collusion by designing a mechanism, so that workers have to act the way the requestor would like. In detail, the mechanism proposed by the requester makes no room for the workers to obtain profit through quality misreport and collusion, and thus, the quality can be controlled without any verification. Extensive simulation results verify the effectiveness of the proposed mechanism. Finally, the importance and originality of our work lie in that it reveals some interesting and even counterintuitive findings: 1) a high-quality worker may pretend to be a low-quality one; 2) the rise of task quality from high-quality workers may not result in the increased utility of the requestor; 3) the utility of the requestor may not get improved with the increasing number of workers. These findings can boost forward looking and strategic planning solutions for crowdsourcing. Kun Li 0026, Shengling Wang 0001, Xiuzhen Cheng, Qin Hu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2019 | Crowdsourcee evaluation based on persuasion game
Kun Li 0026, Shengling Wang 0001, Xiuzhen Cheng |
Comput. Networks | 1 |