VLDB 2026 Research / reviewers in the wild / expert
Qi Liu 0023
dblp:95/2446-23
· DBLP profile ↗
5ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0002-9334-953XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HADES: Detecting and Investigating Active Directory Attacks via Whole Network Provenance AnalyticsabstractDue to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventional intrusion detection systems (IDS) excel at identifying malicious behaviors caused by malware, but often fail to detect stealthy attacks launched by APT actors. Recent advance in provenance-based IDS (PIDS) shows promises by exposing malicious system activities in causal attack graphs. However, existing approaches are restricted to intra-machine tracing, and unable to reveal the scope of attackers' traversal inside a network. We proposeHADES, the first PIDS capable of performing accurate causality-based cross-machine tracing by leveraging a novel concept calledlogon session based execution partitioningto overcome several challenges in cross-machine tracing. We designHADESas an efficient on-demand tracing system, which performs whole-network tracing only when it first identifies an authentication anomaly signifying an ongoing AD attack, for which we introduce a novel lightweight authentication anomaly detection model rooted in our extensive analysis of AD attacks. To triage attack alerts, we present a new algorithm integrating two key insights we identified in AD attacks. Our evaluations show thatHADESoutperforms both popular open-source detection systems and a prominent commercial AD attack detector. Qi Liu 0023, Kaibin Bao, Wajih Ul Hassan, Veit Hagenmeyer |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence ThreatsabstractIn Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the “persistence setup” and the subsequent “persistence execution”. By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction ofpseudo-dependency edges(pseudoedges), which effectively connect these disjoint phases using data provenance analysis, andexpert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to stateof- the-art methods. Qi Liu 0023, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Commander: A robust cross-machine multi-phase Advanced Persistent Threat detector via provenance analyticsabstractIntrusion detection systems (IDS) have traditionally focused on identifying malicious behaviors caused by malware undertaking a series of suspicious activities within a short time. Facing Advanced Persistent Threat (APT) actors employing the so-called low-and-slow strategy, defenders are often blindsided by the poor performance of these IDS. Provenance-based IDS (PIDS) emerged as a promising solution for reducing false alerts, detecting true attacks, and facilitating attack investigation, by causally linking and contextualizing indicative system activities in provenance graphs. However, most existing PIDS can detect neither multi-phase nor cross-machine APT attacks, enabled by persistence and lateral movement techniques, respectively. In the present work, we propose a new PIDS called Commander , which is, to our knowledge, the first system capable of detecting cross-machine multi-phase APT attacks. Further, Commander targets several evasion attacks that can bypass existing PIDS, making it more robust. In addition, Commander can perform whole network tracing for cross-machine multi-phase APT attacks across an industrial-sector organization, for which we additionally develop parsers for system logs of popular industrial controllers. We also develop detection rules with a reference to MITRE’s knowledge base for industrial control systems . Our evaluations show that Commander accurately detects attacks, outperforms existing detection systems, and delivers succinct and insightful attack graphs. Qi Liu 0023, Kaibin Bao, Veit Hagenmeyer |
J. Inf. Secur. Appl. | 1 |
| 2024 | Aviator: A MITRE Emulation Plan-Derived Living Dataset for Advanced Persistent Threat Detection and InvestigationabstractWith the growing trend for developing new detection and investigation systems for Advanced Persistent Threat (APT), the urgent issue of lacking sound and authentic datasets becomes more visible. New datasets for research on APT detection and investigation have been released over the past few years in an accelerated manner. Yet, our examination of the existing datasets yields the finding that the gap between these datasets’ attack scenarios and real-world APT attacks is significant. Recognizing the flaws of prior datasets particularly in terms of attack scenario complexity and authenticity, we develop a novel sound dataset called Aviator, which is backed by MITRE emulation plans. The well-known organization MITRE has released nearly a dozen emulation plans, which closely reproduce APT groups’ real-world attack campaigns observed in the past. However MITRE has not published any datasets. Thus, we resort to stringently implementing these emulation plans. Further, we extend these emulation plans to include an industrial control system and attack steps on it, mimicking APT groups most known for their attacks against critical infrastructures in the past. Comparing to existing datasets, our dataset Aviator has the highest attack scenario complexity and authenticity. Moreover, Aviator is designed with dataset operability, usability, reproducibility and extensibility in mind, for which existing datasets lag far behind. That is, along with the Aviator dataset, we also provide log shipping tools, log parsing tools, and logging configuration files to encourage other researchers to make their own datasets, which may better suit the evaluation of their detection systems. Besides, we would add more log types in future versions of our dataset Aviator. We are committed to maintaining Aviator as a living dataset. Qi Liu 0023, Kaibin Bao, Veit Hagenmeyer |
IEEE Big Data | 1 |
| 2021 | A Bayesian Rule Learning Based Intrusion Detection System for the MQTT Communication ProtocolabstractRule learning based intrusion detection systems (IDS) regularly collect and process network traffic, and thereafter they apply rule learning algorithms to the data to identify network communication behaviors represented as IF-THEN rules. Detection rules are inferred offline and can be periodically automatically updated online for intrusion detection. In this context, we implement in the present paper various attacks against MQTT in a carefully designed and very realistic experiment environment, instead of a simulation program as commonly seen in previous works, for data generation. Besides, we investigate a Bayesian rule learning based approach as countermeasure, which is able to detect various attack types. A Bayesian network is learned from training data and subsequently translated into a rule set for intrusion detection. The combination of prior knowledge (about the communication protocol and target system) and data help to efficiently learn the Bayesian network. The translation from the Bayesian network to a set of inherently interpretable rules can be regarded as a transformation from implicit knowledge to explicit knowledge. We show that our proposed method can achieve not only good detection performance but also high interpretability. Qi Liu 0023, Hubert B. Keller, Veit Hagenmeyer |
ARES | 1 |