EDBT 2026 Demo / reviewers in the wild / expert
Chen Liu 0039
dblp:10/2639-39
· DBLP profile ↗
10ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-8803-9617ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DynMD: Energy-Based Dynamic Graph Representation Learning for Malware Detection
Chen Liu 0039, Bo Li 0005, Yidong Wu, Xudong Liu 0001, Jianxin Li 0002, Chunpei Li |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | LLM-BSCVM: LLM-Based Blockchain Smart Contract Vulnerability Management Framework
Yanli Jin, Chunpei Li, Peng Liu 0044, Xianxian Li, Chen Liu 0039, Wangjie Qiu |
ICA3PP (7) | 6 |
| 2024 | Evolving malware detection through instant dynamic graph inverse reinforcement learning
Chen Liu 0039, Bo Li 0005, Xudong Liu 0001, Chunpei Li, Jingru Bao |
Knowl. Based Syst. | 1 |
| 2024 | A Dynamic Adaptive Framework for Practical Byzantine Fault Tolerance Consensus Protocol in the Internet of ThingsabstractThe Practical Byzantine Fault Tolerance (PBFT) protocol-supported blockchain can provide decentralized security and trust mechanisms for the Internet of Things (IoT). However, the PBFT protocol is not specifically designed for IoT applications. Consequently, adapting PBFT to the dynamic changes of an IoT environment with incomplete information represents a challenge that urgently needs to be addressed. To this end, we introduce DA-PBFT, a PBFT dynamic adaptive framework based on a multi-agent architecture. DAPBFT divides the dynamic adaptive process into two sub-processes: optimality-seeking and optimization decision-making. During the optimality-seeking process, a PBFT optimization model is constructed based on deep reinforcement learning. This model is designed to generate PBFT optimization strategies for consensus nodes. In the optimization decision-making process, a PBFT optimization decision consensus mechanism is constructed based on the Borda count method. This mechanism ensures consistency in PBFT optimization decisions within an environment characterized by incomplete information. Furthermore, we designed a dynamic adaptive incentive mechanism to explore the Nash equilibrium conditions and security aspects of DA-PBFT. The experimental results demonstrate that DA-PBFT is capable of achieving consistency in PBFT optimization decisions within an environment of incomplete information, thereby offering robust and efficient transaction throughput for IoT applications. Chunpei Li, Wangjie Qiu, Xianxian Li, Chen Liu 0039, Zhiming Zheng 0001 |
IEEE Trans. Computers | 4 |
| 2024 | MalAF : Malware Attack Foretelling From Run-Time Behavior Graph SequenceabstractForetelling ongoing malware attacks in real time is challenging due to the stealthy and polymorphic nature of their executive behavior patterns. In this paper, we present MalAF, a novelMalwareAttackForetelling framework that utilizes run-time behavior (i.e., sequences of API events) of malware to foretell the attack that has not yet executed. MalAF first samples suspicious API events by assessing the sensitivity of the parameters of each API event and dividing them into multiple attack time slots by calculating the strong correlation. Following that, MalAF employs dynamic heterogeneous graph sequences to incrementally model contextual semantics for each attack time slot, generating malware state sequences in real time. Moreover, MalAF proposes a greedy adaptive dictionary (GAD)-optimized IRL preference learning method to automate the capture of families' intrinsic attack preferences, which achieves higher performance than the existing inverse reinforcement learning (IRL). Additionally, with the guidance of families' attack preferences, MalAF trains an LSTM to foretell the future path of the target malware. Finally, MalAF matches the identified APIs' paths with a malicious capability base and reports the comprehensible attacks to an analyst. The experiments on real-world datasets demonstrate that our proposed MalAF outperforms the state-of-the-art methods, which improves the baseline by 3.01%$\sim$4.73% of accuracy in terms of path foretell. Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Xudong Liu 0001, Chunpei Li |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | A2-CLM: Few-Shot Malware Detection Based on Adversarial Heterogeneous Graph AugmentationabstractMalware attacks, especially “few-shot” malware, have profoundly harmed the cyber ecosystem. Recently, malware detection models based on graph neural networks have achieved remarkable success. However, these efforts over-rely on sufficient labeled data for model training and thus may be brittle in few-shot malware detection because of the label scarcity. To this end, we propose a self-supervised malware detection framework based on graph contrastive learning and adversarial augmentation, termed A2-CLM, to address the challenge of few-shot malware detection. Particularly, A2-CLM first depicts the malware execution context with a sensitivity heterogeneous graph by assessing the security semantic of each behavior. Afterwards, A2-CLM designs multiple adversarial attacks to generate more practical contrastive pairs, including the PGD attack, attribute masking attack, meta-graph-guide sampling attack, direct system calls attack, and obfuscation attack, which is beneficial to strengthening the model’s effectiveness and robustness. To alleviate the training workload of contrastive learning, we introduce a momentum strategy to train the multiple graph encoders in A2-CLM. Especially on 1-shot detection tasks, A2-CLM achieves performance gains of up to 24.63% and 4.58% against supervised and self-supervised detection methods, respectively. Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Weiwei Feng, Xudong Liu 0001, Chunpei Li |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | TI-MVD: A temporal interaction-enhanced model for malware variants detection
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Ziyang Zhen, Weiwei Feng, Xudong Liu 0001 |
Knowl. Based Syst. | 1 |
| 2021 | MG-DVD: A Real-time Framework for Malware Variant Detection Based on Dynamic Heterogeneous Graph LearningabstractDetecting the newly emerging malware variants in real time is crucial for mitigating cyber risks and proactively blocking intrusions. In this paper, we propose MG-DVD, a novel detection framework based on dynamic heterogeneous graph learning, to detect malware variants in real time. Particularly, MG-DVD first models the fine-grained execution event streams of malware variants into dynamic heterogeneous graphs and investigates real-world meta-graphs between malware objects, which can effectively characterize more discriminative malicious evolutionary patterns between malware and their variants. Then, MG-DVD presents two dynamic walk-based heterogeneous graph learning methods to learn more comprehensive representations of malware variants, which significantly reduces the cost of the entire graph retraining. As a result, MG-DVD is equipped with the ability to detect malware variants in real time, and it presents better interpretability by introducing meaningful meta-graphs. Comprehensive experiments on large-scale samples prove that our proposed MG-DVD outperforms state-of-the-art methods in detecting malware variants in terms of effectiveness and efficiency. Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Ming Su, Xudong Liu 0001 |
IJCAI | 1 |
| 2020 | Top-k closed co-occurrence patterns mining with differential privacy over multiple streams
Shijian Fang, Chen Liu 0039, Jiawen Qin, Xianxian Li, Zhenkui Shi |
Future Gener. Comput. Syst. | 3 |
| 2019 | A three-phase approach to differentially private crucial patterns mining over data streams
Chen Liu 0039, Xingcheng Fu, Xudong Luo 0001, Xianxian Li |
Comput. Secur. | 2 |