Yijia Xu

dblp:97/445 · DBLP profile ↗
← Back
20ranked-venue papers
6as first author
18since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Understanding Older Adults' Experiences of Support, Concerns, and Risks from Kinship-Role AI-Generated Influencers
abstract
AI-generated influencers are rapidly gaining popularity on Chinese short-video platforms, often adopting kinship-based roles such as “AI grandchildren” to attract older adults. Although this trend has raised public concern, little is known about the design strategies behind these influencers, how older adults experience them, and the benefits and risks involved. In this study, we combined social media analysis with interviews to unpack the above questions. Our findings show that influencers use both visual and conversational cues to enact kinship roles, prompting audiences to engage in kinship-based role-play. Interviews further show that these cues arouse emotional resonance, help fulfill older adults’ informational and emotional needs, while also raising concerns about emotional displacement and unequal emotional investment. We highlight the complex relationship between virtual avatars and real family ties, shaped by broader sociocultural norms, and discuss how AI might strengthen social support for older adults while mitigating risks within cultural contexts.
Black Sun, Han Li 0014, Chi-Lan Yang, Yijia Xu, Yi-Chieh Lee
CHI6
2026 From Redundancy to Precision: Constructing a Compressed Tree-Based Experiential Case Base for LLMs
Mucun Xie, Yijia Xu, Jian Li 0040
ICCBR2
2026 An effective and stealthy XSS adversarial sample generation method against deep learning detection models
Yong Fang 0002, Yaochang Xu, Yijia Xu
Neurocomputing4
2026 MPS-Fuzz: An Enhanced Fine-Grained Fuzzing Based on Units With Multiple Inputs and Outputs
abstract
Edge coverage-guided fuzzing has demonstrated remarkable achievements in vulnerability discovery. Some studies with fine-grained coverage metrics have been proposed to enhance the vulnerability mining capabilities of fuzzing by capturing more program paths. However, this refinement often results in a significant increase in seeds, which are highly homogeneous and may limit vulnerability detection. Additionally, finer granularity requires more bitmap hits, increasing the risk of hash collisions. To address these shortages, the paper proposes the structure of a basic block unit with multiple predecessors and successors (referred to as MPS). Then, a fine-grained coverage method called MPS-Fuzz is designed based on the MPS structure. In this approach, it is convenient to exclude basic blocks involving loop structures when determining MPS units, which helps reduce seed homogeneity. Additionally, we introduce an additional bitmap to record the coverage status of MPS units, ensuring that the collision rate of the edge bitmap does not increase. Moreover, these additional operations do not incur excessive time overhead. To demonstrate the properties of the MPS-Fuzz, we implement our approach on AFL and conduct experiments on 16 benchmarks from FuzzBench and Unifuzz. The result indicates that, after 24-hour fuzzing, MPS-Fuzz explores an average of 9.6% more edges and an average of 25.7% more bugs than AFL. Compared to other fine-grained coverage methods (N-gram and PathAFL), MPS-Fuzz also achieves better performance. Moreover, MPS-Fuzz has discovered a previously unknown bug on real-world program and got a CVE assigned.
Ximing Fan, Yong Fang 0002, Peng Jia 0005, Hongwei Li 0001, Yijia Xu, Qinying Wang, Shouling Ji
IEEE Trans. Dependable Secur. Comput.6
2026 Web Page Tampering Detection Based on Dynamic Temporal Graph Pre-Training
abstract
Web page tampering detection is crucial in web threat perception. Current methods rely on monitoring historical changes of web pages to identify anomalies. These approaches often struggle to effectively distinguish between tampering and benign changes, especially in the presence of numerous dynamic pages. Furthermore, the increasing complexity of website structures places more resource demands on tampering monitoring and makes some malicious alterations more covert and challenging to detect. We propose a web page tampering detection based on pretraining with dynamic temporal graphs. The core of the method involves constructing a website temporal graph model based on evolutionary information, and enhances the graph feature perturbations to expose concealed tampering behaviors. Specifically, the framework's autoencoder is composed of enhanced DySAT, enabling it to handle dynamic data. We introduce DySAT, bolstered with GATv2, to capture dynamic attention. Additionally, we design a temporal masking mechanism and prediction error to improve the effectiveness of generative self-supervised learning in temporal graph pretraining. Experimental results on Webpage Tampering Dataset (WPT-Dataset) demonstrate that our method outperforms other comparative approaches in terms of both detection efficacy and stability. Furthermore, the research findings on the anomaly detector and model performance provide direction for the practical application of our method.
Yijia Xu, Qiang Zhang 0057, Zhonglin Liu, Cheng Huang 0003, Yong Fang 0002
IEEE Trans. Dependable Secur. Comput.1
2026 One Trigger, Multiple Victims: Clean-Label Neighborhood Backdoor Attacks on Graph Neural Networks
abstract
Graph Neural Networks (GNNs) have achieved remarkable success in modeling structured data. Recent studies, however, reveal that they are highly vulnerable to backdoor attacks, which can implant triggers into training data to mislead predictions on nodes injected with triggers while maintaining accuracy on clean inputs. Despite recent advances, existing graph backdoor attacks often rely on explicit training interventions and substantial trigger injection while focusing solely on single-node misclassification, which limits their practicality in real-world deployments. To address these limitations, we propose a clean-label graph backdoor attack that induces one-hop neighborhood misclassification under a minimal trigger injection budget. Without altering target nodes’ features or labels, our method attaches a single trigger node to a target node, thereby misclassifying both the target and its immediate neighbors as the target class. To maximize effectiveness while preserving stealthiness, we propose a poisoned node selection strategy guided by semantic consistency and structural activeness, and design a conditional diffusion-based trigger generator optimized with multiple auxiliary objectives. Extensive experiments on multiple real-world benchmarks and mainstream GNN architectures show that our approach achieves over 95% attack success rate on both target nodes and their neighbors in most settings, including under state-of-the-art defenses. These findings underscore the urgent need for more robust graph learning systems and reveal novel attack surfaces in graph security.
Huaxin Deng, Yong Fang 0002, Qiang Zhang 0057, Yang Liu 0003, Yijia Xu
IEEE Trans. Inf. Forensics Secur.6
2025 A Vision for Access Control in LLM Agent Systems
Hongyi Cai, Xinfeng Li, Yijia Xu
ICECCS5
2025 Agent Behavior: The Regulatory Object of the Agent-Centric Online Ecosystem in Digital Age
Qiang Zhang 0057, Pei Yan, Yijia Xu, Xinfeng Li, Hongyi Cai, Chuanpo Fu, Yong Fang 0002, Yang Liu 0003
ICECCS3
2025 Directed fuzzing based on path constraints and deviation path correction
Hongsheng Zuo, Yong Fang 0002, Peng Jia 0005, Ximing Fan, Yijia Xu
Inf. Softw. Technol.6
2024 Multi-sensor Fusion-based Cow Health Monitoring IoT System
abstract
With the development of the Internet of Things (IoT), digital technology has been adopted on livestock farms. In this study, a system for monitoring the health status of dairy cows is proposed, utilizing multi-type sensor fusion and IoT technology. The system uses physiological and behavioral data obtained from a tail sensor attached to the cows to establish prenatal and estrus prediction models. Additionally, environmental sensors installed in the barn monitor parameters such as temperature, humidity, carbon dioxide concentration, and organic gas concentration to automatically regulate the barn’s fan and sprinkler based on preset threshold values. The system also monitors the health and tail behavior of the cows and predicts their calving and estrus times based on the collected data. Experimental results demonstrate that the system exhibits high accuracy and reliability in monitoring the health of dairy cows.
Zhenyu Lai, Yijia Xu, Liangyan Wang, Qinglei Bu, Jie Sun 0024
TrustCom2
2024 Few-shot graph classification on cross-site scripting attacks detection
Hongyu Pan, Yong Fang 0002, Wenbo Guo 0011, Yijia Xu, Changhui Wang
Comput. Secur.4
2024 Multi-target label backdoor attacks on graph neural networks
abstract
Graph neural networks have been shown to have characteristics that make them susceptible to backdoor attacks, and many recent works have proposed feasible graph backdoor attack methods. However, existing graph backdoor attack methods only target one-to-one attack types and lack graph backdoor attack methods that can address one-to-many attack requirements. This paper is the first research work on one-to-many type graph backdoor attacks and proposes the backdoor attack method MLGB, which can achieve multi-target label attacks for GNN node classification tasks. We designed encoding mechanisms to allow MLGB to customize triggers for different target labels and ensure differentiation between triggers for different target labels through loss functions. Additionally, we designed an innovative poisoned node selection method to improve the efficiency of MLGB’s attacks further. Extensive experiments were conducted to validate MLGB’s effectiveness across multiple datasets and model architectures, demonstrating its robustness against graph backdoor attack defense mechanisms. Furthermore, ablation experiments and explainability analyses were conducted to provide deeper insights into MLGB. Our work reveals that graph neural networks are also vulnerable to one-to-many type backdoor attacks, which is important for practitioners to understand model risks comprehensively.
Huaxin Deng, Yijia Xu, Zhonglin Liu, Yong Fang 0002
Pattern Recognit.3
2024 Bayesian Joint Adaptation Network for Crop Mapping in the Absence of Mapping Year Ground-Truth Samples
abstract
Crop mapping is a fundamental step for various higher level agricultural applications, such as crop yield prediction, farm management analysis, and agricultural market regulation. Recent advancements in deep learning models have greatly promoted crop mapping using satellite imagery time series (SITS), enabling frequent and extensive monitoring of croplands. However, a classifier trained on a specific year(s) with crop type labels (i.e., source domain) can exhibit reduced effectiveness when directly applied to a different year(s) without reference data (i.e., target domain) due to the interannual variation in image signals and crop growth dynamics. To address this issue, we propose an unsupervised domain adaptation (UDA) method named Bayesian joint adaptation network (BJAN), which aims to align the joint distributions of input SITS and output crop types across different years, thereby facilitating crop mapping in years without ground-truth samples. In the proposed BJAN method, Bayesian uncertainty is used to detect target data that are outside the support of the source domain. By minimizing the uncertainty on target samples, the model is trained to align the task-specific conditional distributions of source and target domains. Simultaneously, by constraining the feature distributions of source and target domains, the discrepancy of data-related marginal distributions is alleviated. Our experiments on two landcover classification datasets from the U.S. showed that BJAN has effectively aligned source and target domains and outperforms several state-of-the-art domain adaptation methods.
Yijia Xu, Hamid Ebrahimy, Zhou Zhang 0001
IEEE Trans. Geosci. Remote. Sens.1
2023 MFXSS: An effective XSS vulnerability detection method in JavaScript based on multi-feature model
Zhonglin Liu, Yong Fang 0002, Cheng Huang 0003, Yijia Xu
Comput. Secur.4
2023 PWAGAT: Potential Web attacker detection based on graph attention network
Yijia Xu, Yong Fang 0002, Zhonglin Liu, Qiang Zhang 0057
Neurocomputing1
2022 Web Attack Payload Identification and Interpretability Analysis Based on Graph Convolutional Network
abstract
Web attack payload identification is a significant part of the Web defense system. The current Web attack payload identification usually combines natural language processing and deep learning to automatically build a detection model to intercept malicious payloads. However, these detection methods ignore the bidirectional association between fields and is prone to the payload dilution problem for long strings. In addition, the weak interpretability of deep learning models makes it difficult for researchers to solve the problem of model pollution and adjust the model according to the prediction logic. Therefore, this paper proposes a new Web attack payload identification method based on Graph Convolutional Network (GCN), which can effectively extract Web payload features and help model interpretability analysis. The core of this method is to transform the text feature problem into a graph feature extraction problem and to understand the structure and content of the Web payload from the graph perspective. The method performs node embedding on the Web payload graph through GCN, then converts the embedding vector into a graph feature vector through a feature fusion method. The node ablation method is used to analyze malicious payloads' interpretability and calculate the predicted impact rate of nodes inside the graph structure. The experiments on the CSIC 2010 v2 HTTP dataset show that the method proposed in this paper has high accuracy for identifying Web attack payloads, and the node embedding of the Relational Graph Convolutional Network (RGCN) method is more suitable for identifying Web attack payloads than other GCN methods. The research results of the paper show that the model interpretability analysis based on the Web payload graph is reasonable and can effectively assist researchers in adjusting the model and preventing the problem of model pollution.
Yijia Xu, Yong Fang 0002, Zhonglin Liu
MSN1
2022 The selection of burglary cases based on multidimensional features and PageRank
abstract
Abstract With the rapid development of urbanization, a series of burglary cases occurred frequently. It is very important to push suspicious cases according to the top rank in order to improve the ability of intelligent concatenation cases. This article proposes a method of selecting burglary cases based on multidimensional features and PageRank, which could analyze the fact description of burglary cases, extract the multidimensional features of cases and perform feature representation to obtain the feature vector of each case. Then it constructed the network through the similarity between the multidimensional features and used PageRank to calculate the importance of each case for ranking. At last, the algorithm is verified based on the real data of burglary cases. The experimental results showed that the robustness test is better than the other two methods. And the proposed method is more effective and can be better applied to the sorting of burglary cases.
Zheng Li 0033, Yijia Xu
Concurr. Comput. Pract. Exp.5
2022 HGHAN: Hacker group identification based on heterogeneous graph attention network
Yijia Xu, Yong Fang 0002, Cheng Huang 0003, Zhonglin Liu
Inf. Sci.1
2018 Time-Frequency Networks for Audio Super-Resolution
abstract
Audio super-resolution (a.k.a. bandwidth extension) is the challenging task of increasing the temporal resolution of audio signals. Recent deep networks approaches achieved promising results by modeling the task as a regression problem in either time or frequency domain. In this paper, we introduced Time-Frequency Network (TFNet), a deep network that utilizes supervision in both the time and frequency domain. We proposed a novel model architecture which allows the two domains to be jointly optimized. Results demonstrate that our method outperforms the state-of-the-art both quantitatively and qualitatively.
Teck-Yian Lim, Raymond A. Yeh, Yijia Xu, Minh N. Do, Mark Hasegawa-Johnson
ICASSP3
2018 Infant Emotional Outbursts Detection in Infant-parent Spoken Interactions
Yijia Xu, Mark Hasegawa-Johnson, Nancy McElwain
INTERSPEECH1