VLDB 2026 Research / reviewers in the wild / expert
Zhi Wang 0014
dblp:95/6543-14
· DBLP profile ↗
24ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0002-3252-9254ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 5 since 2021Security and privacy · 7 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CRX-ray: Large-Scale Detection of API Key Leakage in Browser ExtensionsabstractThe rapid proliferation of AI-enabled browser extensions has introduced significant security vulnerabilities. These client-side applications, distributed with exposed source files, frequently embed API keys from AI platforms - credentials designed to track usage for billing and prevent misuse. The exposure of these API keys poses substantial financial and operational risks to extension developers. This study presents the first comprehensive security analysis of API key leakage in browser extensions. We systematically analyzed 163,924 extensions across Chrome, Firefox, and Edge stores, uncovering 3,677 unique leaked API keys across 4,145 extensions. Most critically we identified 300 exposed AI platform keys across 309 extensions that collectively serve 1,045,339 users. Furthermore, our analysis reveals prominent reuse of API keys across different extensions, along with instances of multiple keys being used by single extensions. In this paper, we introduce the CRX-ray detection framework to identify API key leakage in browser extensions. By open-sourcing CRX-ray, we aim to empower developers to identify and mitigate API key leakage, fostering the development of more secure browser extensions that protect both developers and users. Zhi Wang 0014, Valerio Bucci, Yuejun Guo 0001, Wanpeng Li |
AsiaCCS | 2 |
| 2026 | PerCheck: An AST-Based Framework for Detecting Over-Privilege in Chrome Extensions
Zhi Wang 0014, Wanpeng Li, Lifei Sun |
ICIC (11) | 2 |
| 2026 | Enhanced Authentication and Key Agreement Protocol for VANETsabstractVehicular Ad-Hoc Networks (VANETs) promote the rapid development of intelligent transportation by connecting vehicles, road infrastructures, and other devices through wireless communication. However, due to their highly dynamic nature, high-speed vehicle movement, frequent changes in network topology, and device heterogeneity, VANETs face more complex security challenges than general wireless networks, such as man-in-the-middle attacks, forged nodes, data tampering, and privacy leakage. To tackle these challenges, authentication and key agreement protocols play a crucial role in ensuring communication security and privacy protection. Awais et al. proposed a novel authentication and key agreement protocol. Although they claim their scheme can resist a wide range of common attacks, we have found that the protocol cannot resist stolen smart card attacks, stolen verifier attacks, and temporary random number leakage attacks. In this paper, we comprehensively analyze the security vulnerabilities present in the Awais et al. protocol and introduce an enhanced authentication and key agreement protocol. We demonstrate the enhanced protocol’s security through formal (Random Oracle Model, ProVerif, and Burrows–Abadi–Needham logic) and informal security analysis. In addition, the experimental results show that the time cost of this protocol is 1.3477 ms, which is significantly lower than the 1.9339 ms of Awais et al.’s protocol and other related protocols; in terms of the communication cost, this protocol is only 3742 bits, which is also better than the 3904 bits of Awais et al.’s protocol and other schemes. Comprehensive comparison shows that our proposed protocol has significant advantages in performance and efficiency while guaranteeing security. Shuangshuang Liu, Zhi Wang 0014, Chien-Ming Chen 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Density Boosts Everything: A One-stop Strategy for Improving Performance, Robustness, and Sustainability of Malware Detectors
Jianwen Tian, Debin Gao, Taotao Gu, Kefan Qiu, Zhi Wang 0014, Xiaohui Kuang |
NDSS | 7 |
| 2025 | Security Analysis on a Two-Factor Privacy-Preserving Protocol for Efficient Authentication in Internet of Vehicles NetworksabstractIn Vehicular Ad Hoc Networks(VANETs) environments, information needs to be exchanged frequently between vehicles, Road Side Units (RSUs), and management centers to support safe and efficient traffic management. However, due to the openness of wireless communication and dynamic network topology, VANETs face many security threats such as forging, eavesdropping, and man-in-the-middle attacks. Therefore, it is crucial to design efficient and secure authentication protocols. To address this problem, Sibahee et al. proposed a two-factor privacy-preserving authentication protocol in IEEE Internet of Things Journal (pp. 14253-14266, DOI: 10.1109/JIOT.2023.3340259, April 15, 2024) and claimed that it can resist multiple attacks. However, we find that the protocol cannot resist temporary random number leakage attacks and privileged insider attacks, and does not have perfect forward security. To address the above problems, this paper proposes an improved authentication scheme based on elliptic curve cryptography (ECC) to enhance the security of the scheme. We conduct formal (Real-Or-Random Model) and informal security analyses of the improved scheme and evaluate its performance in terms of computational overhead and communication cost. The experimental results show that the improved scheme has significant advantages in both security and performance. Shuangshuang Liu, Zhi Wang 0014 |
IEEE Internet Things J. | 2 |
| 2025 | A Blockchain-Assisted Drug Management and Authentication Scheme in IoMTabstractWith the rapid development of the Internet of Things (IoT), the Internet of Medical Things (IoMT) has significantly improved the intelligence and efficiency of healthcare services. As a crucial component of IoMT, smart drug management facilitates efficient collaboration in drug storage, prescription management, and drug delivery. However, the drug distribution process involves multiple entities and sensitive medical data, posing serious security challenges, including patient privacy leakage, identity forgery, unauthorized access to medicines, and data tampering. To address these challenges, this paper proposes a blockchain-assisted drug management and authentication scheme that integrates identity authentication mechanisms. Using the decentralization, immutability, and traceability features of the blockchain, the proposed scheme ensures the transparency and integrity of drug distribution records. In addition, the authentication and key agreement mechanism establishes a secure communication channel between patients, pharmacies, and delivery personnel, preventing unauthorized access and data leakage. The security of the proposed scheme is formally analyzed using the Real-Or-Random (ROR) model, demonstrating its robustness against common security threats. Performance evaluations indicate that the proposed scheme significantly reduces computational and communication overhead compared to existing schemes, making it a secure and efficient solution for smart drug management in smart healthcare. Shuangshuang Liu, Zhi Wang 0014, Chien-Ming Chen 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Provably Secure Anti-Phishing Scheme for Medical Information in Smart HealthcareabstractIn the rapidly evolving field of smart healthcare, integrating modern information technologies, such as Internet of Things, big data, and AI, has significantly enhanced the quality, efficiency, and accessibility of medical services. However, this technological advancement also brings substantial security challenges, particularly regarding protecting electronic medical records (EMRs) from phishing attacks. This article presents a provably secure anti-phishing scheme to safeguard EMRs in smart healthcare systems. By utilizing authentication and key agreement technology, our proposed scheme ensures mutual authentication between users and servers, leveraging elliptic curve encryption, symmetric encryption, hash functions, and XOR operations to secure session keys and verify the legitimacy of medical records. Our scheme addresses critical security challenges, including phishing attacks, stolen mobile device attacks, offline password guessing attacks, replay attacks, and temporary information leakage. The real-oracle-random (ROR) model validates the correctness and security of our scheme, confirming its robustness against common cybersecurity threats. Performance evaluations demonstrate that our scheme provides enhanced security and offers lower time and communication costs compared to existing methods. This makes it a highly efficient and practical solution for safeguarding patient data in smart healthcare environments, ultimately contributing to the reliability and trustworthiness of smart healthcare systems. Shuangshuang Liu, Zhi Wang 0014, Saru Kumari, Jianhui Lv, Chien-Ming Chen 0001 |
IEEE Internet Things J. | 2 |
| 2023 | Sparsity Brings Vulnerabilities: Exploring New Metrics in Backdoor Attacks
Jianwen Tian, Kefan Qiu, Debin Gao, Zhi Wang 0014, Xiaohui Kuang |
USENIX Security Symposium | 4 |
| 2022 | Boosting training for PDF malware classifier via active learningabstractMachine learning algorithms are widely used for cybersecurity applications, include spam, malware detection. In these applications, the machine learning model has to face attack by adversarial samples. Therefore, how to train a robust machine learning model with small samples is a very hot research problem. portable document format (PDF) is a widely used file format, and often utilized as a vehicle for malicious behavior. There have been various PDF malware detectors based on machine learning. However, the labeling of large-scale data samples is time-consuming and laborious. This paper aims to reduce the size of training set while maintain the performance of detection. We propose a novel PDF malware detection method, using active learning to boost training. Particularly, we first make clear the meaning of uncertain samples in this paper, and theoretically explain the effectiveness of these uncertain samples for malware detection. Second, we present an active-learning based malware detection model, using mutual agreement analysis to choose the uncertain sample as the data augmentation. The detector is retrained according to the ground truth of the uncertain samples rather than the whole test samples in the previous epoch, which can not only improve the detection performance, but also reduce the training time consumption of the detector. We conduct 10 epochs of retraining experiments for comparison, using the uncertain samples and the whole test samples from the previous epoch respectively as training set augmentation. The experimental results show that our active-learning based model can achieve the same performance as the traditional model in the tenth epoch of retraining, while the former only needs to use one thirtieth of the latter's training samples. Yuanzhang Li 0001, Jingfeng Xue, Zhi Wang 0014 |
Int. J. Intell. Syst. | 6 |
| 2022 | ICDF: Intrusion collaborative detection framework based on confidenceabstractMany machine-learning-based intrusion detection methods have been proposed, however there is a lack of collaboration among these methods. Faced with a cascade of malicious behaviors and various running environments, coupled with the endless emergence of new malicious activities, it is difficult for us to choose an algorithm manually that is suitable for all scenarios. In addition, usually the binary detection models are applied that only “normal” or “abnormal” decision is made, and it is difficult for us to know how much confidence we have in the prediction model. In this study, we propose an intrusion collaborative detection framework (ICDF), an ICDF that allows heterogeneous detection models to effectively work together which have complementary expertise. A multialgorithm model ensemble learning method with confidence interval is adopted. In this process, each algorithm model only makes prediction judgments on its own credible probability interval and refuses to predict outside the interval. The final result is generated by voting based on the confidence of multiple models. Ten detection algorithms were tested on three different data sets. Compared with different single algorithms, ICDF could achieve high precision and recall rate, and the best F1 scores. Zhi Wang 0014, Leshi Shao, Yuanzhao Liu, Jianan Jiang, Yuanping Nie, Xiang Li 0078, Xiaohui Kuang |
Int. J. Intell. Syst. | 1 |
| 2021 | Opponent portrait for multiagent reinforcement learning in competitive environmentabstractExisting investigations of opponent modeling and intention inferencing cannot make clear descriptions and practical explanations of the opponent's behaviors and intentions, which may inevitably limit the applicability of them. In this work, we propose a novel approach for opponent's policy explanation and intention inference based on the behavioral portrait of opponent. Specifically, we use the multiagent deep deterministic policy gradients (MADDPG) algorithm to train the agent and opponent in the competitive environment, and collect the behavioral data of opponent based on agent's observations. Then we perform pattern segmentation and extract the opponent's behavior events via Toeplitz inverse covariance-based clustering (TICC) algorithm; hence the opponent's behavior data can be encoded into a knowledge graph, named opponent's behavior knowledge graph (OKG). Based on this, we built a question-answer system (QA system) to query and match opponent historical information in OKG, so that the agent can obtain additional experience and gradually infer the intention of opponent with the episodes of iteration. We evaluate the proposed method on the competitive scenario in multiagent particle environment (MPE). Simulation results show that the agents are able to learn better policies with opponent portrait in competitive settings. Meng Shen 0001, Yuhang Zhao 0003, Xiaoyao Tong, Quanxin Zhang 0001, Zhi Wang 0014 |
Int. J. Intell. Syst. | 7 |
| 2021 | A Confidence-Guided Evaluation for Log Parsers Inner Quality
Xueshuo Xie, Zhi Wang 0014, Xuhang Xiao, Ye Lu 0004, Shenwei Huang, Tao Li 0022 |
Mob. Networks Appl. | 2 |
| 2020 | LSC: Online auto-update smart contracts for fortifying blockchain-based log systems
Zhi Wang 0014, Kefan Qiu, Chunfu Jia |
Inf. Sci. | 2 |
| 2020 | BMOP: Bidirectional Universal Adversarial Learning for Binary OpCode FeaturesabstractFor malware detection, current state-of-the-art research concentrates on machine learning techniques. Binary n -gram OpCode features are commonly used for malicious code identification and classification with high accuracy. Binary OpCode modification is much more difficult than modification of image pixels. Traditional adversarial perturbation methods could not be applied on OpCode directly. In this paper, we propose a bidirectional universal adversarial learning method for effective binary OpCode perturbation from both benign and malicious perspectives. Benign features are those OpCodes that represent benign behaviours, while malicious features are OpCodes for malicious behaviours. From a large dataset of benign and malicious binary applications, we select the most significant benign and malicious OpCode features based on the feature SHAP value in the trained machine learning model. We implement an OpCode modification method that insert benign OpCodes into executables as garbage codes without execution and modify malicious OpCodes by equivalent replacement preserving execution semantics. The experimental results show that the benign and malicious OpCode perturbation (BMOP) method could bypass malicious code detection models based on the SVM, XGBoost, and DNN algorithms. Xiang Li 0078, Yuanping Nie, Zhi Wang 0014, Xiaohui Kuang, Kefan Qiu |
Wirel. Commun. Mob. Comput. | 3 |
| 2020 | Reversible Information Hiding Algorithm Based on Multikey EncryptionabstractThis paper proposes a scheme of reversible data hiding in encrypted images based on multikey encryption. There are only two parties that are involved in this framework, including the content owner and the recipient. The content owner encrypts the original image with a key set which is composed by a selection method according to the additional message. Thus, the image can be encrypted and embedded at the same time. Additional message can be extracted given that the recipient side could perform decryption strategy by exploiting spatial correlation; then, original image can be recovered without any loss. Compare with other current information hiding mechanism, the proposed approach provides higher embedding capacity and is also able to perfectly reconstruct the original image as well as the embedded message. Rate distortion of the proposed method outperforms the previously published ones. Zhi Wang 0014, Zheli Liu, Min Li 0045 |
Wirel. Commun. Mob. Comput. | 3 |
| 2020 | Valid Probabilistic Anomaly Detection Models for System LogsabstractSystem logs can record the system status and important events during system operation in detail. Detecting anomalies in the system logs is a common method for modern large-scale distributed systems. Yet threshold-based classification models used for anomaly detection output only two values: normal or abnormal, which lacks probability of estimating whether the prediction results are correct. In this paper, a statistical learning algorithm Venn-Abers predictor is adopted to evaluate the confidence of prediction results in the field of system log anomaly detection. It is able to calculate the probability distribution of labels for a set of samples and provide a quality assessment of predictive labels to some extent. Two Venn-Abers predictors LR-VA and SVM-VA have been implemented based on Logistic Regression and Support Vector Machine, respectively. Then, the differences among different algorithms are considered so as to build a multimodel fusion algorithm by Stacking. And then a Venn-Abers predictor based on the Stacking algorithm called Stacking-VA is implemented. The performances of four types of algorithms (unimodel, Venn-Abers predictor based on unimodel, multimodel, and Venn-Abers predictor based on multimodel) are compared in terms of validity and accuracy. Experiments are carried out on a log dataset of the Hadoop Distributed File System (HDFS). For the comparative experiments on unimodels, the results show that the validities of LR-VA and SVM-VA are better than those of the two corresponding underlying models. Compared with the underlying model, the accuracy of the SVM-VA predictor is better than that of LR-VA predictor, and more significantly, the recall rate increases from 81% to 94%. In the case of experiments on multiple models, the algorithm based on Stacking multimodel fusion is significantly superior to the underlying classifier. The average accuracy of Stacking-VA is larger than 0.95, which is more stable than the prediction results of LR-VA and SVM-VA. Experimental results show that the Venn-Abers predictor is a flexible tool that can make accurate and valid probability predictions in the field of system log anomaly detection. Lanlan Pan, Zhaojun Gu, Jialiang Wang 0002, Yitong Ren, Zhi Wang 0014 |
Wirel. Commun. Mob. Comput. | 6 |
| 2020 | Detecting Overlapping Data in System Logs Based on Ensemble Learning MethodabstractMachine learning techniques are essential for system log anomaly detection. It is prone to the phenomenon of class overlap because of too many similar system log data. The occurrence of this phenomenon will have a serious impact on the anomaly detection of the system logs. To solve the problem of class overlap in system logs, this paper proposes an anomaly detection model for class overlap problem on system logs. We first calculate the relationship between the sample data and the membership of different classes, normal or anomaly, and use the fuzziness to separate the sample data of the overlapping parts of the classes from the data of the other parts. AdaBoost, an ensemble learning approach, is used to detect overlapping data. Compared with machine learning algorithms, ensemble learning can better classify the data of the overlapping parts, so as to achieve the purpose of detecting the anomalies of the system logs. We also discussed the possible impact of different voting methods on ensemble learning results. Experimental results show that our model can be effectively applied in a variety of basic algorithms, and the results of each measure have been improved. Yitong Ren, Mengmeng Liang, Zhaojun Gu, Jialiang Wang 0002, Lanlan Pan, Zhi Wang 0014 |
Wirel. Commun. Mob. Comput. | 7 |
| 2019 | An Efficient Log Parsing Algorithm Based on Heuristic Rules
Xueshuo Xie, Kunpeng Xie, Zhi Wang 0014, Ye Lu 0004, Yujun Zhang 0001 |
APPT | 4 |
| 2018 | Identifying Bitcoin Users Using Deep Neural Network
Chunfu Jia, Zhi Wang 0014 |
ICA3PP (4) | 6 |
| 2018 | Semantic-integrated software watermarking with tamper-proofing
Zhi Wang 0014, Chunfu Jia |
Multim. Tools Appl. | 2 |
| 2017 | An Active and Dynamic Botnet Detection Approach to Track Hidden Concept Drift
Zhi Wang 0014, Meiqi Tian, Chunfu Jia |
ICICS | 1 |
| 2017 | An Ensemble Learning System to Mitigate Malware Concept Drift Attacks (Short Paper)
Zhi Wang 0014, Meiqi Tian, Chunfu Jia |
ISPEC | 1 |
| 2011 | Linear Obfuscation to Combat Symbolic Execution
Zhi Wang 0014, Jiang Ming 0002, Chunfu Jia, Debin Gao |
ESORICS | 1 |
| 2009 | Denial-of-Service Attacks on Host-Based Generic Unpackers
Jiang Ming 0002, Zhi Wang 0014, Debin Gao, Chunfu Jia |
ICICS | 3 |