EDBT 2026 Demo / reviewers in the wild / expert
Xiaoyan Sun 0003
dblp:13/1574-3 · also Xiaoyan (Sherry) Sun
· DBLP profile ↗
28ranked-venue papers
3as first author
19since 2021 · last 2026
0000-0002-0321-2338ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 3 first-author · 12 since 2021Computer networks · 7 · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack
Xue Tan, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 5 |
| 2026 | Was My Data Used for Training? Membership Inference in Open-Source LLMs via Neural Activations
Xue Tan, Mingyu Luo, Zhuyang Yu, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 6 |
| 2026 | Characterizing Security and Privacy Risks in Smart Home IoT Device Access SharingabstractSmart home IoT systems have become widely deployed in modern households, enabling convenient functionalities such as remote control, automation, and real-time monitoring. A commonly supported and frequently used capability in these ecosystems is device access sharing, which allows a primary device owner to grant other users permission to control or interact with a device. However, despite its security-critical nature, the security and privacy practices involved in the sharing process itself remain largely under-examined. To address this gap, we conduct a systematic study of device access sharing workflows across 56 commercially available smart home IoT devices spanning diverse vendors and product categories. Through comprehensive analysis of real-world sharing mechanisms, we identify 9 recurring classes of security and privacy risks, including coarse device access constraints, coarse sharing constraints, weak or missing sharing credentials, inability to revoke device access, inability to revoke sharing, lack of transparency regarding invitation acceptance, uncontrolled re-sharing, over-privileged access, and unintended privacy exposure. Our findings reveal widespread and systemic weaknesses in the device sharing implementations of current smart home IoT systems, underscoring that insecure sharing workflows can directly expose users to persistent security and privacy threats. Yinxin Wan, Tran Ngoc Bao Huynh, Jun Dai 0001, Xiaoyan Sun 0003, Kuai Xu, Guoliang Xue |
SenSys | 5 |
| 2026 | EMPalm: Exfiltrating Palm Biometric Data via Electromagnetic Side-Channel
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Alexander M. Wyglinski, Xiaoyan Sun 0003 |
SenSys | 7 |
| 2026 | SQLaser: Detecting database management system (DBMS) logic bugs with clause-guided fuzzingabstractDatabase management systems (DBMSs) are vital components in modern data-driven systems. Their complexity often leads to logic bugs, which are implementation errors within the DBMSs that can lead to incorrect query results, data exposure, unauthorized access, etc., without necessarily causing visible system failures. Existing detection employs two strategies: rule-based bug detection and coverage-guided fuzzing. In general, rule specification itself is challenging; as a result, rule-based detection is limited to specific and simple rules. Coverage-guided fuzzing blindly explores code paths or blocks, many of which are unlikely to contain logic bugs; therefore, this strategy is cost-ineffective. In this paper, we design SQLaser, a SQL-clause-guided fuzzer for detecting logic bugs in DBMSs. Through a comprehensive examination of existing logic bugs across four distinct DBMSs, excluding those causing system crashes, we have identified 35 logic-bug patterns. These patterns manifest as certain SQL clause combinations that commonly result in logic bugs, and behind these clause combinations are a sequence of functions. We therefore model logic-bug patterns as error-prone function chains (i.e., sequences of functions). We further develop a directed fuzzer with a new path-to-path distance-calculation mechanism for effectively testing these chains and discovering additional logic bugs. This mechanism enables SQLaser to swiftly navigate to target sites and uncover potential bugs emerging from these paths. Our evaluation, conducted on SQLite, MySQL, PostgreSQL, and TiDB, demonstrates that SQLaser significantly accelerates bug discovery compared to other fuzzing approaches, reducing detection time by approximately 60%. As a standalone fuzzer, SQLaser identified 22 bugs spanning 18 of the 35 logic-bug patterns, outperforming contemporary fuzzers such as SQLRight, which only uncovered two logic bugs across two patterns within the same testing period (i.e., 60 days) when testing SQLite. Notably, four of the bugs discovered by SQLaser are zero-day, all of which have been reported to and confirmed by vendors. Ping Chen 0003, Kangjie Lu, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 5 |
| 2026 | DeepSanitizer: Combining Heuristic Rules and Deep Learning Models to Spot Silent Buffer Overflows in Binary
Chen Cao 0004, Suhang Wang, Xiaoyan Sun 0003, Peng Liu 0005 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF FingerprintingabstractWhile supervised deep neural networks (DNNs) have proven effective for device authentication via radio frequency (RF) fingerprinting, they are hindered by domain shift issues and the scarcity of labeled data. The success of large language models has led to increased interest in self-supervised pre-trained models (PTMs), which offer better generalization and do not require labeled datasets, potentially addressing the issues mentioned above. However, the inherent vulnerabilities of PTMs in RF fingerprinting remain insufficiently explored. In this paper, we unveil the potential threat by thoroughly investigating data-free backdoor attacks on such PTMs for RF fingerprinting, focusing on a practical scenario where attackers lack access to downstream data, label information, and training processes. To realize the backdoor attack, we carefully design a set of triggers and predefined output representations (PORs) for the PTMs. By mapping triggers and PORs through backdoor training, we can implant backdoor behaviors into the PTMs, thereby introducing vulnerabilities across different downstream RF fingerprinting tasks without requiring prior knowledge. Extensive experiments demonstrate the wide applicability of our proposed backdoor attack to various input domains, protocols, and PTMs. Furthermore, we explore potential detection and defense methods, illustrating the difficulty of fully safeguarding against our proposed data-free backdoor attack. Tianya Zhao, Junqing Zhang, Jun Dai 0001, Xiaoyan Sun 0003, Xuyu Wang |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Towards Development of Ready-to-Use Hands-on Labs with Portable Operating Environments for Digital Forensics EducationabstractDigital forensics is a critical field that plays an essential role in investigating cyber crimes, security incidents, and other crimes utilizing digital devices. Despite the heightened need for more experts in this field, the workforce faces constant shortages. For effective workforce development, the field currently lacks accessible, engaging, and valuable educational materials. To combat this issue, we propose INFER, a set of instructional hands-on labs for digital forensics education. In these labs, we designed an experiential learning experience that is a comprehensive program that is easily accessible for different levels of education in a portable environment and can be used on different operating systems. We conducted a study with students and had them take surveys before and after the labs to determine the value of the labs. We also hosted a workshop to invite professors and educators in the field to evaluate the usability of the materials. Based on the results, INFER is a beneficial resource that can help develop a future workforce of digital forensics professionals. Tran Ngoc Bao Huynh, Brian Almaguer, Jun Dai 0001, Xiaoyan Sun 0003 |
COMPSAC | 5 |
| 2025 | MagWatch: Exposing Privacy Risks in Smartwatches Through Electromagnetic Signals
Tianya Zhao, Xuyu Wang, Jun Dai 0001, Xiaoyan Sun 0003 |
ICICS (1) | 5 |
| 2025 | What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors
Chang Yue, Kai Chen 0012, Zhixiu Guo, Jun Dai 0001, Xiaoyan Sun 0003, Yi Yang 0100 |
NDSS | 5 |
| 2025 | Optimizing IoT Cross-rule Vulnerability Detection through Reinforcement Learning-Based FuzzingabstractInternet of Things (IoT) devices have become increasingly ubiquitous and essential to daily life. These devices are usually controlled based on trigger-action rules, meaning that the devices will take actions according to the rules when trigger conditions are satisfied. As more devices are deployed in smart home systems, the risk of undesirable interactions and cross-rule vulnerabilities increases. In this paper, we propose a reinforcement learning-based fuzzing approach that can automate the modification of environmental variables to generate test cases and increase the likelihood of discovering cross-rule conflicts in smart home systems. Our approach optimizes conflict detection and discovers hidden conditions that lead to vulnerabilities. The preliminary results show that our model can successfully recognize different types of rule conflict. Tran Ngoc Bao Huynh, Yinxin Wan, Jun Dai 0001, Xiaoyan Sun 0003 |
SenSys | 5 |
| 2025 | Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS)abstractThis paper presents and advocates for an initiative to expand access to secure programming education. The Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS) initiative, funded by the National Centers of Academic Excellence in Cybersecurity (NCAE-C) program, seeks to advance secure programming and help achieve security aims. SWEEPS establishes a secure programming curriculum and workforce development coalition of seven institutions across two CAE (Center of Academic Excellence) regions (Northeast and Southwest) and five states (California, Massachusetts, Maryland, Indiana, and North Carolina). This coalition includes industry-based stakeholders collaborating with the US Army and government agencies on various projects. SWEEPS draws on prior work establishing critical concepts in secure programming, assessment tools, learning aids, and system infrastructure. The initiative offers a series of interconnected, stackable learning experiences tailored for early to mid-career professionals looking to enhance their cybersecurity skills. These experiences, which include practical one-day workshops and comprehensive year-long graduate certificates, provide a reassuring path for upskilling in secure programming. This paper recommends the efficacy of stackable training approaches in secure programming by exploring the practices of targeting and training individuals with diverse proficiency levels of programming experience who would benefit from increased knowledge and training. Deborah Kariuki, Ida Ngambeki, Jun Dai 0001, Matt Bishop, Xiaoyan Sun 0003, Melissa Dark, Jenny Daugherty, Alex Lowrie, Markus Geissler, Phillip Nico, Arshad Noor |
SIGCSE (1) | 5 |
| 2025 | HuntFUZZ: Enhancing error handling testing through clustering based fuzzingabstractTesting a program’s capability to effectively handle errors is a significant challenge, given that program errors are relatively uncommon. To address this, software fault injection (SFI)-based fuzzing combines SFI with traditional fuzzing to inject faults and trigger errors, enabling the testing of (error handling) code. However, current SFI-based fuzzing approaches have overlooked the correlation between paths housing error points. In fact, the execution paths of error points often share common paths. As a result, fuzzers usually generate test cases repeatedly to explore these common paths. This practice can compromise the efficiency of the fuzzer(s). To address this issue, this paper introduces HuntFUZZ, a novel SFI-based fuzzing framework designed to minimize redundant exploration of error points with correlated paths. HuntFUZZ achieves this by clustering these correlated error points and using concolic execution to resolve the path constraints necessary for approaching or reaching these clusters. This approach provides the fuzzer with optimized test cases, allowing it to efficiently explore error points within the cluster while minimizing redundancy. We evaluate HuntFUZZ on a diverse set of 42 applications, and HuntFUZZ successfully reveals 162 known bugs, with 62 of them being related to error handling. Additionally, due to its efficient error point detection method, HuntFUZZ discovers seven unique zero-day bugs, which are all missed by existing fuzzers. Furthermore, we compare HuntFUZZ with four existing fuzzing approaches, including AFL, AFL++, AFLGo, and EH-FUZZ. Our evaluation confirms that HuntFUZZ can cover a broader range of error points, and it exhibits better performance in terms of bug-finding speed. Ping Chen 0003, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 4 |
| 2025 | Got My "Invisibility" Patch: Towards Physical Evasion Attacks on Black-Box Face Detection SystemsabstractModern face detection (FD) systems have demonstrated remarkable performance in identifying human faces, primarily via Deep Neural Networks (DNNs). However, these DNN-driven models exhibit inherent susceptibility to adversarial attacks, posing significant risks for intentional face obfuscation from detectors. Such obfuscation can serve both malicious purposes (e.g., evading surveillance systems) and benign objectives (e.g., protecting personal privacy). Previous studies have developed techniques to compromise the effectiveness of various FD models, yet these adversarial attacks are largely confined to the digital domain—e.g., by applying adversarial perturbations to digital input images—or demand prior knowledge of the target FD systems. In this paper, we introduces a novel framework for evading black-box face detection (FD) systems in real-world scenarios. The proposed method relies on theExpectation over Attention(EoA) algorithm, which generates thePublic Attention Heat Map(PAHM) by fusing attention mechanisms across an ensemble of publicly available FD models. Our evaluation results demonstrate that EoA outperforms state-of-the-art (SOTA) methods in white-box settings and demonstrates strong cross-model transferability in black-box scenarios, effectively evading FD systems across smartphones, laptops, and surveillance cameras. Duohe Ma, Junye Jiang, Xiaoyan Sun 0003, Kai Chen 0012, Jun Dai 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Analysis of neural network detectors for network attacksabstractWhile network attacks play a critical role in many advanced persistent threat (APT) campaigns, an arms race exists between the network defenders and the adversary: to make APT campaigns stealthy, the adversary is strongly motivated to evade the detection system. However, new studies have shown that neural network is likely a game-changer in the arms race: neural network could be applied to achieve accurate, signature-free, and low-false-alarm-rate detection. In this work, we investigate whether the adversary could fight back during the next phase of the arms race. In particular, noticing that none of the existing adversarial example generation methods could generate malicious packets (and sessions) that can simultaneously compromise the target machine and evade the neural network detection model, we propose a novel attack method to achieve this goal. We have designed and implemented the new attack. We have also used Address Resolution Protocol (ARP) Poisoning and Domain Name System (DNS) Cache Poisoning as the case study to demonstrate the effectiveness of the proposed attack. Qingtian Zou, Lan Zhang 0008, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 4 |
| 2023 | Identifying Superspreaders by Ranking System Object Instance Graphs
Rajani Suryavanshi, Xiaoyan Sun 0003, Jun Dai 0001 |
IFIP Int. Conf. Digital Forensics | 2 |
| 2023 | Every Time Can Be Different: A Data Dynamic Protection Method Based on Moving Target DefenseabstractTraditional defense methods are hard to change the inherent vulnerabilities of static data storage, single data access, and deterministic data content, leading to frequent data leakage incidents. Moving target defense (MTD) techniques can increase data diversity and unpredictability by dynamically shifting the data attack surface. However, in the existing methods, the data lacks sufficient dynamics due to insufficient shifting space and shifting frequency of attack surface, and legitimate users are inevitably greatly affected. This study proposes a data MTD method that the data changes dynamically based on real-time multi-source user access information. Through the multidimensional user stratification mechanism, we establish a novel dynamic data model that uses the combination of random deception strategies to convert metadata properties and content of data based on the user risk levels, while data remains unchanged for legitimate users. Multiple sets of experiments demonstrate the effectiveness and low consumption of our data dynamic defense approach. Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Liming Wang 0001, Junye Jiang |
ISCC | 3 |
| 2022 | Deep learning for detecting logic-flaw-exploiting network attacks: An end-to-end approachabstractNetwork attacks have become a major security concern for organizations worldwide. A category of network attacks that exploit the logic (security) flaws of a few widely-deployed authentication protocols has been commonly observed in recent years. Such logic-flaw-exploiting network attacks often do not have distinguishing signatures, and can thus easily evade the typical signature-based network intrusion detection systems. Recently, researchers have applied neural networks to detect network attacks with network logs. However, public network data sets have major drawbacks such as limited data sample variations and unbalanced data with respect to malicious and benign samples. In this paper, we present a new end-to-end approach based on protocol fuzzing to automatically generate high-quality network data, on which deep learning models can be trained for network attack detection. Our findings show that protocol fuzzing can generate data samples that cover real-world data, and deep learning models trained with fuzzed data can successfully detect the logic-flaw-exploiting network attacks. Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 3 |
| 2021 | Deep Learning for Detecting Network Attacks: An End-to-End Approach
Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
DBSec | 3 |
| 2020 | Fingerprinting-based Indoor and Outdoor Localization with LoRa and Deep LearningabstractThis paper aims at predicting accurate outdoor and indoor locations using deep neural networks, for the data collected using the Long-Range Wide-Area Network (LoRaWAN) communication protocol. First, we propose an interpolation aided fingerprinting-based localization system architecture. We propose a deep autoencoder method to effectively deal with the large number of missing samples/outliers caused by the large size and wide coverage of LoRa networks. We also leverage three different deep learning models, i.e., the Artificial Neural Network (ANN), Long Short-Term Memory (LSTM), and the Convolutional Neural Network (CNN), for fingerprinting based location regression. The superior localization performance of the proposed system is validated by our experimental study using a publicly available outdoor dataset and an indoor LoRa testbed. Jait Purohit, Xuyu Wang, Shiwen Mao, Xiaoyan Sun 0003, Chao Yang 0025 |
GLOBECOM | 4 |
| 2020 | WGT: Thwarting Web Attacks Through Web Gene Tree-based Moving Target DefenseabstractMoving target defense (MTD) suggests a game-changing way of enhancing web security by increasing uncertainty and complexity for attackers. A good number of web MTD techniques have been investigated to counter various types of web attacks. However, in most MTD techniques, only fixed attributes of the attack surface are shifted, leaving the rest exploitable by the attackers. Currently, there are few mechanisms to support the whole attack surface movement and solve the partial coverage problem, where only a fraction of the possible attributes shift in the whole attack surface. To address this issue, this paper proposes a Web Gene Tree (WGT) based MTD mechanism. The key point is to extract all potential exploitable key attributes related to vulnerabilities as web genes, and mutate them using various MTD techniques to withstand various attacks. Experimental results indicate that, by randomly shifting web genes and diversely inserting deceptive ones, the proposed WGT mechanism outperforms other existing schemes and can significantly improve the security of web applications. Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Feng Liu 0001 |
ICWS | 3 |
| 2020 | What You See Is Not What You Get: Towards Deception-Based Data Moving Target DefenseabstractThe homogeneity and uniformity of static data storage and access make data leakage one of the most severe security threats. Dynamic data techniques such as data randomization and diversification, are effective approaches to mitigate data theft and illegal data modification. By increasing data diversity and dynamics, the data attack surface shifting space can be expanded to confuse attackers and influence their further actions. However, there are only a few dynamic data techniques developed because of the difficulty in encoding multiple data formats and the loss of compatibility in data formats. In this paper, we propose a new dynamic data approach that integrates the data deception techniques based on Moving Target Defense (MTD). By changing the data size, data authenticity, and users' data access privilege, the approach significantly expands the data attack surface shifting space. Moreover, the approach provides dynamic data access based upon both users' attributes and users' operations. Through dynamic analysis and experiments, the paper shows that the proposed dynamic data technique can expand the attack surface shifting space at a lower cost, protect the sensitive data, and impose no significant burden on the system. Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Feng Liu 0001 |
IPCCC | 3 |
| 2018 | Assessing Attack Impact on Business Processes by Interconnecting Attack Graphs and Entity Dependency Graphs
Chen Cao 0004, Lun-Pin Yuan, Anoop Singhal, Peng Liu 0005, Xiaoyan Sun 0003, Sencun Zhu |
DBSec | 5 |
| 2018 | A Mobile Botnet That Meets Up at Twitter
Yulong Dong, Jun Dai 0001, Xiaoyan Sun 0003 |
SecureComm (2) | 3 |
| 2018 | Using Bayesian Networks for Probabilistic Identification of Zero-Day Attack PathsabstractEnforcing a variety of security measures (such as intrusion detection systems, and so on) can provide a certain level of protection to computer networks. However, such security practices often fall short in face of zero-day attacks. Due to the information asymmetry between attackers and defenders, detecting zero-day attacks remains a challenge. Instead of targeting individual zero-day exploits, revealing them on an attack path is a substantially more feasible strategy. Such attack paths that go through one or more zero-day exploits are called zero-day attack paths. In this paper, we propose a probabilistic approach and implement a prototype system ZePro for zero-day attack path identification. In our approach, a zero-day attack path is essentially a graph. To capture the zero-day attack, a dependency graph named object instance graph is first built as a supergraph by analyzing system calls. To further reveal the zero-day attack paths hidden in the supergraph, our system builds a Bayesian network based upon the instance graph. By taking intrusion evidence as input, the Bayesian network is able to compute the probabilities of object instances being infected. Connecting the high-probability-instances through dependency relations forms a path, which is the zero-day attack path. The experiment results demonstrate the effectiveness of ZePro for zero-day attack path identification. Xiaoyan Sun 0003, Jun Dai 0001, Peng Liu 0005, Anoop Singhal, John Yen |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Towards Actionable Mission Impact Assessment in the Context of Cloud Computing
Xiaoyan Sun 0003, Anoop Singhal, Peng Liu 0005 |
DBSec | 1 |
| 2014 | Inferring the Stealthy Bridges Between Enterprise Network Islands in Cloud Using Cross-Layer Bayesian Networks
Xiaoyan Sun 0003, Jun Dai 0001, Anoop Singhal, Peng Liu 0005 |
SecureComm (1) | 1 |
| 2013 | Patrol: Revealing Zero-Day Attack Paths through Network-Wide System Object Dependencies
Jun Dai 0001, Xiaoyan Sun 0003, Peng Liu 0005 |
ESORICS | 2 |