Weijuan Zhang

dblp:07/8436 · DBLP profile ↗
← Back
25ranked-venue papers
3as first author
16since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 6 · 4 since 2021Systems, architecture and hardware · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language Models
abstract
Large language models (LLMs) increasingly support multilingual understanding and generation. Meanwhile, efforts to interpret their internal mechanisms have emerged, offering insights to enhance multilingual performance. While multi-head self-attention (MHA) has proven critical in many areas, its role in multilingual capabilities remains underexplored. In this work, we study the contribution of MHA in supporting multilingual processing in LLMs. We propose Language Attention Head Importance Scores (LAHIS), an effective and efficient method that identifies attention head importance for multilingual capabilities via a single forward and backward pass through the LLM. Applying LAHIS to Aya-23-8B, Llama-3.2-3B, and Mistral-7B-v0.1, we reveal the existence of both language-specific and language-general heads. Language-specific heads enable cross-lingual attention transfer to guide the model toward target language contexts and mitigate off-target language generation issue, contributing to addressing challenges in multilingual LLMs. We also introduce a lightweight adaptation that learns a soft head mask to modulate attention outputs over language heads, requiring only 20 tunable parameters to improve XQuAD accuracy. Overall, our work enhances both the interpretability and multilingual capabilities of LLMs from the perspective of MHA.
Qiyang Song, Qihang Zhou, Haichao Du, Shaowen Xu, Weijuan Zhang, Xiaoqi Jia
AAAI7
2026 WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave Restore
Xiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian, Weijuan Zhang, Xiaoqi Jia
ASPLOS (2)6
2026 Bypassing Safety Alignment via API Design: A Systematic Risk Analysis of Response Prefill in LLM Systems
Yakai Li, Jiekang Hu, Weiduan Sang, Luping Ma, Dongsheng Nie, Weijuan Zhang, Qingjia Huang, Qihang Zhou
DSN6
2025 LMFN: Label-Aware Multi-Semantic Fusion Network for Multi-Label Text Classification
abstract
The multi-label text classification (MLTC) task involves associating text data with multiple relevant labels. However, previous studies often overlooked the co-occurrence information of labels within text, resulting in the inability to distinguish similar labels. Moreover, these studies have underestimated the importance of label node initialization. To tackle these challenges, we propose a Label-aware Multi-semantic Fusion Network (LMFN). Our approach employs label-guided attention to learn text representations closely aligned with labels. Then, in order to obtain more refined semantic representation, the word embedding matrix is introduced to integrate features from diverse sources. Concurrently, we use joint learning network to extract label features. We first initialize label nodes and use multi-layer GCNs to capture the dependencies and higher-order information between labels. Following this, cross-attention is utilized to effectively integrate label features with internal semantics and reveal latent correlations. Comprehensive experiments on two standard datasets show that our proposed model LMFN outperforms existing methods.
Xiaoyun Liu, Weijuan Zhang, Kun Ma 0001, Yanfang Qiu, Ke Ji, Bo Yang 0001
CSCWD2
2025 Entity-Aware Multi-Perspective Semantic Fusion Network for Fact-Checking Fake News Detection
abstract
Fact-checking is a highly challenging task that requires verifying the truthfulness of a claim based on multiple evidence sentences. Despite the effectiveness of existing methods, they overlook the differences in the importance of various news entities. Additionally, they fail to consider the semantic relationships between the claim and the evidence from multiple perspectives. To address these issues, we propose an Entity-aware Multi-perspective Semantic Fusion Network (EMSFN) for Fact-checking Fake News Detection. First, we introduce the Entity Attention Network to extract semantic information from claim and calculate the differences in the importance of entities. Then, we built the Multi-view Semantic Relation Extraction Network to capture the interactions between claim and evidence, extracting multi-dimensional interaction information. The proposed EMSFN calculates the contribution degree of different entities and facilitates information interaction between claim and evidence from multiple perspectives. Experiments on Snopes and PolitiFact datasets validate the effectiveness of our EMSFN.
Yanfang Qiu, Weijuan Zhang, Kun Ma 0001, Xiaoyun Liu, Ke Ji, Bo Yang 0001
CSCWD2
2025 Latent Knowledge Scalpel: Precise and Massive Knowledge Editing for Large Language Models
abstract
Large Language Models (LLMs) often retain inaccurate or outdated information from pre-training, leading to incorrect predictions or biased outputs during inference. While existing model editing methods can address this challenge, they struggle with editing large amounts of factual information simultaneously and may compromise the general capabilities of the models. In this paper, our empirical study demonstrates that it is feasible to edit the internal representations of LLMs and replace the entities in a manner similar to editing natural language inputs. Based on this insight, we introduce the Latent Knowledge Scalpel (LKS), an LLM editor that manipulates the latent knowledge of specific entities via a lightweight hypernetwork to enable precise and large-scale editing. Experiments conducted on Llama-2 and Mistral show even with the number of simultaneous edits reaching 10,000, LKS effectively performs knowledge editing while preserving the general abilities of the edited LLMs. Code is available at: https://github.com/Linuxin-xxx/LKS.
Qiyang Song, Shaowen Xu, Kerou Zhou, Xiaoqi Jia, Weijuan Zhang, Heqing Huang 0001, Yakai Li
ECAI7
2025 CEDS: A Container Escape Detection System Based on Filesystem Isolation Boundaries
abstract
Container technology is becoming increasingly important in cloud computing due to its efficiency and agility, but it also introduces new security risks. In particular, container escape attacks exploiting inherent vulnerabilities in container components have emerged as a primary threat to container security due to their pervasive nature and severe impact. However, existing container escape detection methods mainly rely on known attack patterns and pay insufficient attention to exploits targeting container components. In this work, we propose CEDS, a system based on container filesystem isolation boundaries to detect escape attacks caused by container component vulnerabilities in real time. We first establish an attack model by analyzing 16 container component exploits. Then, we propose a method to identify isolation boundaries by analyzing mount namespaces and container filesystem hierarchies, and subsequently detect abnormal cross-boundary file operations at the kernel level via system call monitoring. Finally, we implement a prototype of CEDS with eBPF. Experimental results demonstrate that, compared with the existing baseline methods, CEDS can effectively detect container escape attacks with minimal performance overhead.
Weijuan Zhang, Junhao Fang, Yuxia Fu, Xiaoqi Jia, Qingjia Huang
SMC3
2024 CubeVisor: A Multi-realm Architecture Design for Running VM with ARM CCA
abstract
Cloud computing nowadays provides flexible and scalable computing services, using different hardware platforms, including ARM. Virtualization allows multiple virtual machines (VMs) to share the physical resources of a host machine. However, these technologies have security risks. The hypervisor is the software that controls VMs, and it can be exploited or manipulated by hackers or untrusted providers. ARM CCA, a novel feature of ARMv9-A, allows confidential VMs to run in a new security state called realm. However, the current CCA prototype still has some problems, including risks brought by external libraries, single point of failure, highly privileged TF-RMM and costly world switch. In this paper, we introduce CubeVisor, a new secure virtualization architecture based on ARM CCA. It uses the idea of the Cube, which is a combination of a hypervisor and a VM, protecting each Cube from other Cubes or components. The CubeVisor also improves performance by optimizing memory allocation and world-switching processes. We implement prototypes on both software-based ARM FVP platform and hardware-based ARM Cortex-A platform for evaluations. The results show that the CubeVisor can protect VMs well and has very low overhead compared to the CCA based virtualization methods.
Jiayun Chen, Qihang Zhou, Xiaolong Yan, Xiaoqi Jia, Weijuan Zhang
ACSAC6
2024 vASP: Full VM Life-cycle Protection Based on Active Security Processor Architecture
abstract
Cloud computing has been applied on a large scale due to its competitive advantages. However, the introduction of virtualization brings new risks, which can come from within the VM and the host. Due to the abstraction of hardware resources by the hypervisor, traditional trusted computing methods, such as TPM and ASP, are no longer available in cloud environments. Existing work focusing on enabling trusted computing in cloud computing is primarily based on TPM and vTPM, but there are still issues such as the trusted chain not covering all stages of the VM life cycle and the integrity measurement operation potentially causing high overhead. In this paper, we present the vASP architecture, which solves the limitation of the ASP architecture in a cloud environment. Using customization features provided by the ASP, we customize interfaces for the vASP architecture and pass the trusted relationship to the upper layer to form a complete chain of trust. The vASP front-end plugs into the hypervisor actively and regularly operates the dynamic measurement process of the guest to ensure that data from the guest machine are not tampered with. With the introduction of vASP in the cloud computing platform, the security of vASP components during VM operation is also a concern. As a result, we propose a full VM life-cycle protection method through verification and measurement mechanisms that cannot be bypassed to ensure that vASP maintains a match with specific VMs. We have implemented the vASP architecture on a commercial platform deployed with ASP architecture and evaluated it. The result shows that the vASP architecture can protect VM integrity well during full life-cycle and has very low overhead compared to the native virtualization architecture.
Jiayun Chen, Qihang Zhou, Weijuan Zhang, Yamin Xie, Xiaoqi Jia
CCGrid3
2024 SummSlim: A Universal and Automated Approach for Debloating Container Images
abstract
Container technology has become a cornerstone of cloud computing, offering notable benefits such as enhanced resource utilization and streamlined deployment processes. The adoption of container technology by leading cloud service providers has steadily increased over the years. However, during the image construction phase, the reuse of base images and the execution of certain commands often results in the retention of redundant files, leading to resource wastage and potential security vulnerabilities. In this research, we systematically review and analyze existing methodologies, identify shortcomings in current approaches, and propose an automated image debloating tool named SummSlim according to the characteristics of the container image construction process. We selected 195 official images from Docker Hub for testing and evaluated the effectiveness of SummSlim with a success rate of $98.46 \%$. Then we compare and analyze the images before and after debloating, and make some novel suggestions for developers. To the best of our knowledge, SummSlim is the first practically available universal image debloating tool.
Heqing Huang 0001, Shaowen Xu, Qihang Zhou, Xiaoqi Jia, Weijuan Zhang
ICPADS7
2024 HClave: An isolated execution environment design for hypervisor runtime security
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang, Haichao Du, Qingjia Huang
Comput. Secur.7
2023 Protecting Encrypted Virtual Machines from Nested Page Fault Controlled Channel
abstract
AMD Secure Encrypted Virtualization (SEV) assumes the hypervisor (HV) is untrusted and introduces hardware memory encryption support for virtual machines (VMs). Previous studies have proposed various attacks against encrypted VMs by exploiting SEV security flaws such as unencrypted VMCB and lack of memory integrity. Most of these flaws have been solved by the subsequent releases of SEV with Encrypted State (SEV-ES) and SEV with Secure Nested Paging (SEV-SNP). However, the latest SEV-SNP cannot stop the malicious HV tampering with critical flags in the nested page table (NPT). So SEV-SNP is still vulnerable to the nested page fault (NPF) controlled channel attack, which is a commonly shared step of most attacks against SEV. Existing works on SEV also cannot defend against NPF controlled channel. In this paper, we first analyze the root cause of NPF controlled channel. Then we propose a software-based approach to protect encrypted VMs from NPF controlled channel. We introduce a virtualization security module (VSM) as a software TCB to deprivilege the HV by modifing the HV to access critical resources indirectly through interfaces managed by VSM. To prevent the untrusted HV from compromising the VSM-based protection, we extend the nested kernel architecture to the virtualization layer to provide isolation for VSM at the same privilege level. A prototype of this approach is implemented based on KVM. The experiments show that the approach can protect encrypted VMs from NPF controlled channel with 1.21% average runtime overhead and 1.47% average I/O overhead.
Haoxiang Qin, Weijuan Zhang, Sicong Huang 0004, Xiaoqi Jia, Haichao Du
CODASPY3
2023 Intra-graph and Inter-graph joint information propagation network with third-order text graph tensor for fake news detection
Benkuan Cui, Kun Ma 0001, Leping Li, Weijuan Zhang, Ke Ji, Ajith Abraham
Appl. Intell.4
2023 DC-CNN: Dual-channel Convolutional Neural Networks with attention-pooling for fake news detection
Kun Ma 0001, Changhao Tang, Weijuan Zhang, Benkuan Cui, Ke Ji, Ajith Abraham
Appl. Intell.3
2022 SecFortress: Securing Hypervisor using Cross-layer Isolation
abstract
Virtualization is the corner stone of cloud computing, but the hypervisor, the crucial software component that enables virtualization, is known to suffer from various attacks. It is challenging to secure the hypervisor due to at least two reasons. On one hand, commercial hypervisors are usually integrated into a privileged Operating System (OS), which brings in a larger attack surface. On the other hand, multiple Virtual Machines (VM) share a single hypervisor, thus a malicious VM could leverage the hypervisor as a bridge to launch “cross-VM” attacks. In this work, we propose SecFortress, a dependable hypervisor design that decouples the virtualization layer into a mediator, an outerOS, and multiple HypBoxes through a cross-layer isolation approach. SecFortress extends the nested kernel approach to de-privilege the outerOS from accessing the mediator's memory and creates an isolated hypervisor instance, HypBox, to confine the impacts from the untrusted VMs. We implemented SecFortress based on KVM and evaluated its effectiveness and efficiency through case studies and performance evaluation. Experimental results show that SecFortress can significantly improve the security of the hypervisor with negligible runtime overhead.
Qihang Zhou, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang
IPDPS6
2022 NP-LFA: Non-profiled Leakage Fingerprint Attacks against Improved Rotating S-box Masking Scheme
abstract
Abstract DPA Contest is a world-famous side-channel competition aiming at analyzing and evaluating the implementing security of some latest countermeasures. Improved Rotating S-box Masking Scheme (RSM2.0) is one of the most popular countermeasures designed during DPA Contest V4.2, which arms with both Low Entropy Masking Schemes and shuffling strategy to ensure the software security of AES-128, particularly the non-profiled security. Up to now, conducting high efficient non-profiled attacking scheme with low resource costs is still a challenge. In this paper, we first propose general and non-profiled leakage fingerprint attacks (named NP-LFA) for secret cracking and make use of it to crack RSM2.0 random masks with almost 100% accuracy. Further, we analyze the hidden vulnerabilities embedded in RSM2.0 implementation, and utilize them to bypass the shuffling defense and perform the master key recovery. Official evaluation results show that NP-LFA is capable of compromising RSM2.0 within 14 traces, each of which only costs 60 ms processing time. Such result validates the high efficiency and light-weighted characteristics of our attacking scheme, which has ranked the first in the official website till now. In addition, we discuss and put forward some possible strategies to mitigate our NP-LFA threats.
Zeyi Liu 0002, Weijuan Zhang, Ji Xiang, Daren Zha, Lei Wang 0135
Comput. J.2
2020 SEEF-ALDR: A Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled Representation
abstract
Speaker verification, as a biometric authentication mechanism, has been widely used due to the pervasiveness of voice control on smart devices. However, the task of “in-the-wild” speaker verification is still challenging, considering the speech samples may contain lots of identity-unrelated information, e.g., background noise, reverberation, emotion, etc. Previous works focus on optimizing the model to improve verification accuracy, without taking into account the elimination of the impact from the identity-unrelated information. To solve the above problem, we propose SEEF-ALDR, a novel Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled Representation, to reinforce the performance of existing models on speaker verification. The key idea is to retrieve as much speaker identity information as possible from the original speech, thus minimizing the impact of identity-unrelated information on the speaker verification task by using adversarial learning. Experimental results demonstrate that the proposed framework can significantly improve the performance of speaker verification by 20.3% and 23.8% on average over 13 tested baselines on dataset Voxceleb1 and 8 tested baselines on dataset Voxceleb2 respectively, without adjusting the structure or hyper-parameters of them. Furthermore, the ablation study was conducted to evaluate the contribution of each module in SEEF-ALDR. Finally, porting an existing model into the proposed framework is straightforward and cost-efficient, with very little effort from the model owners due to the modular design of the framework.
Jianwei Tai, Xiaoqi Jia, Qingjia Huang, Weijuan Zhang, Haichao Du, Shengzhi Zhang
ACSAC4
2020 ET-GAN: Cross-Language Emotion Transfer Based on Cycle-Consistent Generative Adversarial Networks
abstract
Despite the remarkable progress made in synthesizing emotional speech from text, it is still challenging to provide emotion information to existing speech segments. Previous methods mainly rely on parallel data, and few works have studied the generalization ability for one model to transfer emotion information across different languages. To cope with such problems, we propose an emotion transfer system named ET-GAN, for learning language-independent emotion transfer from one emotion to another without parallel training samples. Based on cycle-consistent generative adversarial network, our method ensures the transfer of only emotion information across speeches with simple loss designs. Besides, we introduce an approach for migrating emotion information across different languages by using transfer learning. The experiment results show that our method can efficiently generate high-quality emotional speech for any given emotion category, without aligned speech pairs.
Xiaoqi Jia, Jianwei Tai, Yakai Li, Weijuan Zhang, Haichao Du, Qingjia Huang
ECAI5
2019 A Multi-granularity Neural Network for Answer Sentence Selection
abstract
In open-domain question answering system, the granularities of the answers vary with different types of questions. For example, for the questions asking about locations (Location type questions), their answers are usually short phrases. While for the questions asking about reasons (Description type questions), their answers are usually long clauses or sentences. This insight can be used to improve the performance of answer sentence selection, which is a crucial component of the open-domain QA system. In this paper, we propose a novel Multi-Granularity Neural Network (MGNN) model to better evaluate the semantic matching of questions and answers. First, MGNN has three classes of channels with each computing the similarity of question and answer pairs from one of the three granularity levels: clause level, phrase level and ngram level. Then, MGNN uses a parametrization weighting scheme which considers question types to combine these different granularity channels. We carry out experiments on a public available benchmark dataset for question answering. Empirical results show that our method outperforms state-of-the-art methods.
Chenggong Zhang, Weijuan Zhang, Daren Zha, Pengjie Ren, Nan Mu
IJCNN2
2018 Running OS Kernel in Separate Domains: A New Architecture for Applications and OS Services Quarantine
abstract
Container-based PaaS cloud is ease of use and cost-efficient, but vulnerable to attacks due to the weak isolation provided by the built-in containers. In this paper, we present a lightweight virtualization based kernel decomposition approach to securely isolate cloud tenants as well as the operating system (OS) services against various threats. Our design decouples existing OS kernels based on their functionality and isolates different kernel partitions in separate domains. The kernel partition that enables application execution is quarantined in an application domain, while other partitions that offer various services are isolated in separate service domains. The application owned by one tenant can run transparently in a dedicated application domain, with strong isolation to those owned by other tenants. Furthermore, the kernel partition approach effectively defeats the malware that requires support from different kernel services. We have implemented a prototype based on Linux kernel and Xen hypervisor. Our evaluation demonstrates that the proposed kernel decomposition approach can defeat various OS kernel-targeted attacks with minimal performance overhead.
Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Rui Wang 0032, Peng Liu 0005
APSEC1
2017 Towards comprehensive protection for OpenFlow controllers
abstract
OpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves.
Shengzhi Zhang, Xiaoqi Jia, Weijuan Zhang
APNOMS3
2017 FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud
Xiaoqi Jia, Guangzhe Zhou, Qingjia Huang, Weijuan Zhang, Donghai Tian
ICDF2C4
2017 CacheRascal: Defending the Flush-Reload Side-Channel Attack in PaaS Clouds
Weijuan Zhang, Xiaoqi Jia, Jianwei Tai, Mingsheng Wang
WASA1
2016 A Comprehensive Study of Co-residence Threat in Multi-tenant Public PaaS Clouds
Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Qingjia Huang, Mingsheng Wang, Peng Liu 0005
ICICS1
2010 Hyper- and reverse-Wiener indices of F-sums of graphs
Metrose Metsidik, Weijuan Zhang, Fang Duan
Discret. Appl. Math.2