VLDB 2026 Research / reviewers in the wild / expert
Kaibin Bao
dblp:77/7435
· DBLP profile ↗
7ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0002-8231-4331ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Whiplash on the Grid: Emulation of a Cyber-Physical Attack Misusing Inverter-Based Resources in a Distribution Grid (Practical Experience Report)
Arman Aghaei Attar, Kaibin Bao, Oliver Gehrke, Kai Heussen, Veit Hagenmeyer |
DSN | 2 |
| 2026 | HADES: Detecting and Investigating Active Directory Attacks via Whole Network Provenance AnalyticsabstractDue to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventional intrusion detection systems (IDS) excel at identifying malicious behaviors caused by malware, but often fail to detect stealthy attacks launched by APT actors. Recent advance in provenance-based IDS (PIDS) shows promises by exposing malicious system activities in causal attack graphs. However, existing approaches are restricted to intra-machine tracing, and unable to reveal the scope of attackers' traversal inside a network. We proposeHADES, the first PIDS capable of performing accurate causality-based cross-machine tracing by leveraging a novel concept calledlogon session based execution partitioningto overcome several challenges in cross-machine tracing. We designHADESas an efficient on-demand tracing system, which performs whole-network tracing only when it first identifies an authentication anomaly signifying an ongoing AD attack, for which we introduce a novel lightweight authentication anomaly detection model rooted in our extensive analysis of AD attacks. To triage attack alerts, we present a new algorithm integrating two key insights we identified in AD attacks. Our evaluations show thatHADESoutperforms both popular open-source detection systems and a prominent commercial AD attack detector. Qi Liu 0023, Kaibin Bao, Wajih Ul Hassan, Veit Hagenmeyer |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence ThreatsabstractIn Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the “persistence setup” and the subsequent “persistence execution”. By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction ofpseudo-dependency edges(pseudoedges), which effectively connect these disjoint phases using data provenance analysis, andexpert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to stateof- the-art methods. Qi Liu 0023, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Commander: A robust cross-machine multi-phase Advanced Persistent Threat detector via provenance analyticsabstractIntrusion detection systems (IDS) have traditionally focused on identifying malicious behaviors caused by malware undertaking a series of suspicious activities within a short time. Facing Advanced Persistent Threat (APT) actors employing the so-called low-and-slow strategy, defenders are often blindsided by the poor performance of these IDS. Provenance-based IDS (PIDS) emerged as a promising solution for reducing false alerts, detecting true attacks, and facilitating attack investigation, by causally linking and contextualizing indicative system activities in provenance graphs. However, most existing PIDS can detect neither multi-phase nor cross-machine APT attacks, enabled by persistence and lateral movement techniques, respectively. In the present work, we propose a new PIDS called Commander , which is, to our knowledge, the first system capable of detecting cross-machine multi-phase APT attacks. Further, Commander targets several evasion attacks that can bypass existing PIDS, making it more robust. In addition, Commander can perform whole network tracing for cross-machine multi-phase APT attacks across an industrial-sector organization, for which we additionally develop parsers for system logs of popular industrial controllers. We also develop detection rules with a reference to MITRE’s knowledge base for industrial control systems . Our evaluations show that Commander accurately detects attacks, outperforms existing detection systems, and delivers succinct and insightful attack graphs. Qi Liu 0023, Kaibin Bao, Veit Hagenmeyer |
J. Inf. Secur. Appl. | 2 |
| 2024 | Aviator: A MITRE Emulation Plan-Derived Living Dataset for Advanced Persistent Threat Detection and InvestigationabstractWith the growing trend for developing new detection and investigation systems for Advanced Persistent Threat (APT), the urgent issue of lacking sound and authentic datasets becomes more visible. New datasets for research on APT detection and investigation have been released over the past few years in an accelerated manner. Yet, our examination of the existing datasets yields the finding that the gap between these datasets’ attack scenarios and real-world APT attacks is significant. Recognizing the flaws of prior datasets particularly in terms of attack scenario complexity and authenticity, we develop a novel sound dataset called Aviator, which is backed by MITRE emulation plans. The well-known organization MITRE has released nearly a dozen emulation plans, which closely reproduce APT groups’ real-world attack campaigns observed in the past. However MITRE has not published any datasets. Thus, we resort to stringently implementing these emulation plans. Further, we extend these emulation plans to include an industrial control system and attack steps on it, mimicking APT groups most known for their attacks against critical infrastructures in the past. Comparing to existing datasets, our dataset Aviator has the highest attack scenario complexity and authenticity. Moreover, Aviator is designed with dataset operability, usability, reproducibility and extensibility in mind, for which existing datasets lag far behind. That is, along with the Aviator dataset, we also provide log shipping tools, log parsing tools, and logging configuration files to encourage other researchers to make their own datasets, which may better suit the evaluation of their detection systems. Besides, we would add more log types in future versions of our dataset Aviator. We are committed to maintaining Aviator as a living dataset. Qi Liu 0023, Kaibin Bao, Veit Hagenmeyer |
IEEE Big Data | 2 |
| 2012 | An Evolutionary Optimization Approach for Bulk Material Blending Systems
Michael P. Cipold, Pradyumn Kumar Shukla, Claus C. Bachmann, Kaibin Bao, Hartmut Schmeck |
PPSN (1) | 4 |
| 2009 | Helgrind+: An efficient dynamic race detectorabstractFinding synchronization defects is difficult due to non-deterministic orderings of parallel threads. Current tools for detecting synchronization defects tend to miss many data races or produce an overwhelming number of false alarms. In this paper, we describe Helgrind+, a dynamic race detection tool that incorporates correct handling of condition variables and a combination of the lockset algorithm and happens-before relation. We compare our techniques with Intel Thread Checker and the original Helgrind tool on two substantial benchmark suites. Helgrind+ reduces the number of both false negatives (missed races) and false positives. The additional accuracy incurs almost no performance overhead. Ali Jannesari, Kaibin Bao, Victor Pankratius, Walter F. Tichy |
IPDPS | 2 |