VLDB 2026 Research / reviewers in the wild / expert
Qiao Hu 0005
dblp:85/3737-5
· DBLP profile ↗
14ranked-venue papers
6as first author
9since 2021 · last 2025
0000-0002-6483-1431ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Computer networks · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MPCCP: A Multi-chain Perception Crime Charge Prediction Method
Congshan Huang, Tianshuo Jiao, Qiao Hu 0005, Yupeng Hu 0004, Bianxia Du |
ICANN (4) | 3 |
| 2025 | SemSyn-LCE: A Charge Prediction Method Based on Semantic Syntactic Fusion and Legal Constituent Elements Matching
Bianxia Du, Wenhui Xia, Qiao Hu 0005, Yupeng Hu 0004 |
ICDAR (1) | 4 |
| 2024 | SIAT: A systematic inter-component communication real-time analysis technique for detecting data leak threats on AndroidabstractThis paper presents the design and implementation of a systematic Inter-Component Communications (ICCs) dynamic Analysis Technique (SIAT) for detecting privacy-sensitive data leak threats. SIAT’s specific approach involves the identification of malicious ICC patterns by actively tracing both data flows and implicit control flows within ICC processes during runtime. This is achieved by utilizing the taint tagging methodology, a technique utilized by TaintDroid. As a result, it can discover the malicious intent usage pattern and further resolve the coincidental malicious ICCs and bypass cases without incurring performance degradation. SIAT comprises two key modules: Monitor and Analyzer. The Monitor makes the first attempt to revise the taint tag approach named TaintDroid by developing the built-in intent service primitives to help Android capture the intent-related taint propagation at multi-level for malicious ICC detection. Specifically, we enable the Monitor to perform systemwide tracking of intent with five abstraction functionalities embedded in the interactive workflow of components. By analyzing the taint logs offered by the Monitor, the Analyzer can build the accurate and integrated ICC patterns adopted to identify the specific leak threat patterns with the identification algorithms and predefined rules. Meanwhile, we employ the patterns’ deflation technique to improve the efficiency of the Analyzer. We implement the SIAT with Android Open Source Project and evaluate its performance through extensive experiments on a particular dataset consisting of well-known datasets and real-world apps. The experimental results show that, compared to state-of-the-art approaches, the SIAT can achieve about 25% ∼200% accuracy improvements with 1.0 precision and 0.98 recall at negligible runtime overhead. Apart from that, the SIAT can identify two undisclosed cases of bypassing that prior technologies cannot detect and quite a few malicious ICC threats in real-world apps with lots of downloads on the Google Play market. Yupeng Hu 0004, Wenxin Kuang, Wenjia Li, Keqin Li 0001, Jiliang Zhang 0002, Qiao Hu 0005 |
J. Comput. Secur. | 7 |
| 2024 | HPDK: A Hybrid PM-DRAM Key-Value Store for High I/O ThroughputabstractThis paper explores the design of an architecture that replaces Disk with Persistent Memory (PM) to achieve the highest I/O throughput in Log-Structured Merge Tree (LSM-Tree) based key-value stores (KVS). Most existing LSM-Tree based KVSs use PM as an intermediate or smoothing layer, which fails to fully exploit PM’s unique advantages to maximize I/O throughput. However, due to PM’s distinct characteristics, such as byte addressability and short erasure time, simply replacing existing storage with PM does not yield optimal I/O performance. Furthermore, LSM-Tree based KVSs often face slow read performance. To tackle these challenges, this paper presents HPDK, a hybrid PM-DRAM KVS that combines level compression for LSM-Trees in PM with a B+-tree based in-memory search index in DRAM, resulting in high write and read throughput. HPDK also employs a key-value separation design and a live-item rate-based dynamic merge method to reduce the volume of PM writes. We implement and evaluate HPDK using a real PM drive, and our extensive experiments show that HPDK provides 1.25-11.8 and 1.47-36.4 times higher read and write throughput, respectively, compared to other state-of-the-art LSM-Tree based approaches. Bihui Liu, Zhenyu Ye, Qiao Hu 0005, Yupeng Hu 0004, Yuchong Hu, Yang Xu 0013, Keqin Li 0001 |
IEEE Trans. Computers | 3 |
| 2022 | SEVulDet: A Semantics-Enhanced Learnable Vulnerability DetectorabstractRecent years have seen increased attention to deep learning-based vulnerability detection frameworks that leverage neural networks to identify vulnerability patterns. Considerable efforts have been made; still, existing approaches are less ac-curate in practice. Prior works fail to comprehensively capture semantics from source code or adopt the appropriate design of neural networks. This paper presents SEVulDet, a Semantics-Enhanced learnable Vulnerability Detector that can accurately pinpoint vulnerability patterns by preserving path semantics into gadgets and learning from flexible-length codes. SEVulDet has two main characteristics: (i) SEVulDet employs a path-sensitive code slicing approach to extract sufficient path semantics and control flow logic into code gadgets. (ii) by inserting a spatial pyramidal pooling layer into the Convolutional Neural Network (CNN) with a well-designed multilayer attention mechanism, SEVulDet can handle gadgets of flexible-length semantics to avoid semantics loss incurred by traditional truncating or padding operations, and thus learn more potential vulnerability patterns. Comprehensive experimental results show that SEVulDet significantly outperforms classical static approaches and excels with state-of-the-art deep learning-based solutions by improving F1-measure to roughly 94.5%. Particularly, the elaborate design of the SEVulDet architecture helps us identify more real-world vulnerabilities than existing technologies. Zhiquan Tang, Qiao Hu 0005, Wenxin Kuang, Jiongyi Chen |
DSN | 2 |
| 2022 | Half-Duplex Mode-Based Secure Key Generation Method for Resource-Constrained IoT DevicesabstractThe physical layer secret key generation scheme is a preferred solution designed for resource-constrained Internet of Things (IoT) devices. But it suffers from a severe attack, the signal manipulating attack, which aims at controlling the generated key. The existing solutions either cannot prevent all kinds of signal manipulation attacks or require working in full-duplex mode, which is not suitable for resource-constrained IoT devices. In this article, we introduce a secret key generation scheme with the help of an untrusted relay to address this dilemma. Also, our method can protect the privacy of legitimate users from the untrusted relay. We conclude a general signal manipulation attack model from existing practical signal manipulation attacks and analyze the security strength and privacy preserving ability of our scheme based on this model. Finally, we compare our method with existing signal manipulation attack solutions. The result shows that our method is the best solution for resource-constrained IoT systems. Qiao Hu 0005, Jingyi Zhang 0006, Gerhard P. Hancke 0002, Yupeng Hu 0004, Wenjia Li, Hongbo Jiang 0001, Zheng Qin 0001 |
IEEE Internet Things J. | 1 |
| 2022 | Revisiting Error-Correction in Precommitment Distance-Bounding ProtocolsabstractDistance-bounding (DB) protocols are used to verify the physical proximity of two devices. DB can be used to establish trusted ad-hoc connections in the industrial Internet-of-Things, e.g., nodes can verify they are deployed in the same location and monitoring the same piece of equipment. Thresholds and error correction codes (ECCs) are two methods to provide error-resilience for DB protocols working in noisy environments. However, the threshold method adds overheads and the ECC method increases the adversary success probability, compared to threshold, when implemented in precommitment DB protocols. In this article, we investigate the ECC method and demonstrate that designers can mitigate increased adversary success probability by using nonsystematic codes. To demonstrate this idea, we compare a prominent precommitment protocol by Brands and Chaum (BC) integrated with different types of ECCs with two existing error-resilience methods, showing how nonsystematic codes provide improved protocol security. Moreover, We further evaluate the BC protocol with nonsystematic ECCs and discuss how to configure protocols to minimize the protocol failure rate, while maintaining adequate attack success probability. Jingyi Zhang 0006, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Zhe Liu 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Privacy-Preserving Group Authentication for RFID Tags Using Bit-Collision PatternsabstractWhen authenticating a group of radio-frequency identification tags, a common method is to authenticate each tag with some challenge-response exchanges. However, sequentially authenticating individual tags one by one might not be desirable, especially when considering that a reader often has to deal with multiple tags within a limited period, since it will incur long scanning time and heavy communication costs. To address these problems, we put forward a novel efficient group authentication protocol, where a group of tags can be authenticated simultaneously with only one challenge and one response. The protocol is built on a newly designed symmetric key-based algorithm and the bit-collision pattern technique, so that authentication responses transmitted by multiple tags in a group at the same time will result in a verifiable bit-collision pattern that represents the authentication response for the entire group. The proposed approach can significantly reduce the authentication time and communication cost in the sense that the verifier can authenticate the entire group within a period that is comparable to the time taken to perform a single-tag authentication and requires only one challenge. In addition, we extend our protocol to support the privacy-preserving property, which prevents the tagged items from being tracked by illegitimate parties. A thorough security analysis shows that the proposed protocol can resist common practical attacks and experimental results show that the protocol is very efficient in terms of time and communication costs. We also discuss important practical aspects that should be considered when implementing these protocols. Anjia Yang, Dutliff Boshoff, Qiao Hu 0005, Gerhard P. Hancke 0002, Xizhao Luo, Jian Weng 0001, Keith Mayes, Konstantinos Markantonakis |
IEEE Internet Things J. | 3 |
| 2021 | Preventing Overshadowing Attacks in Self-Jamming Audio ChannelsabstractRecently there has been a growing interest in short-range communication using audio channels for device pairing and as a self-jamming communication medium. Given that such channels are audible to participants they are considered more resistant to active attacks, i.e., the attack signal would be heard by the participants. In this paper, we investigate the validity of this assumption using two prominent acoustic self-jamming systems implementations. We show that basic overshadowing attacks are possible in these systems and that these attacks cannot be effectively detected by the participants if the attacker is close to the receiving device. Finally, we propose a novel physical-layer solution for effectively detecting overshadowing attacks, which can improve state-of-the-art acoustic self-jamming systems by ensuring channel integrity while not requiring fundamental modifications to these schemes. Qiao Hu 0005, Yuanzhen Liu, Anjia Yang, Gerhard P. Hancke 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | A Session Hijacking Attack Against a Device-Assisted Physical-Layer Key AgreementabstractPhysical-layer key agreement is used to generate a shared key between devices on demand. Such schemes utilize the characteristics of the wireless channel to generate the shared key from the device-to-device channel. As all characteristics are time-dependent and location-dependent, it is hard for eavesdroppers to get the key. However, most research works in this area use passive attack models whereas active attacks that aim at manipulating the channel and key are also possible. Physical-layer key agreement with User Introduced Randomness (PHYUIR) is a solution similar to the Diffie-Hellman protocol against such a kind of active attack. The users (devices) introduce their own randomness to help to prevent active attacks. In this paper, we analyze the possibility of launching a session hijacking attack on PHY-UIR to allow an attacker to control the shared key established. The session hijacking attack manipulates the key agreement through a man-in-the-middle interaction and forces legitimate devices to run the PHY-UIR protocol with the attacker. Our simulation and experiment results validate our attack and show the high performance of our attack on manipulating the generated key. We also propose PHY-UIR± where devices simultaneously exchange information about the established shared keys, which allows them to detect whether they have agreed to different keys with a third party. Qiao Hu 0005, Bianxia Du, Konstantinos Markantonakis, Gerhard P. Hancke 0002 |
IEEE Trans. Ind. Informatics | 1 |
| 2018 | Tangible security: Survey of methods supporting secure ad-hoc connects of edge devices with physical context
Qiao Hu 0005, Jingyi Zhang 0006, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002 |
Comput. Secur. | 1 |
| 2018 | HB+DB: Distance bounding meets human based authentication
Elena Pagnin, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa |
Future Gener. Comput. Syst. | 3 |
| 2016 | Practical limitation of co-operative RFID jamming methods in environments without accurate signal synchronization
Qiao Hu 0005, Lavinia Mihaela Dinca, Anjia Yang, Gerhard P. Hancke 0002 |
Comput. Networks | 1 |
| 2015 | Device Synchronisation: A Practical Limitation on Reader Assisted Jamming Methods for RFID Confidentiality
Qiao Hu 0005, Lavinia Mihaela Dinca, Gerhard P. Hancke 0002 |
WISTP | 1 |