Guosheng Xu 0001

dblp:130/0993-1 · also Guo-Sheng Xu 0001 · DBLP profile ↗
← Back
18ranked-venue papers
2as first author
16since 2021 · last 2026
0000-0002-3310-926XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 6 since 2021Security and privacy · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A global trust-based blockchain lightweight consensus mechanism
abstract
Blockchain technology, renowned for its decentralized and secure nature, has gained substantial attention. Central to its functionality are consensus mechanisms, which are essential for validating transactions and upholding the integrity of the distributed ledger. However, the efficiency and scalability of blockchain are currently impeded by the resource limitations and excessive communication demands of existing consensus mechanisms. To address these challenges, we propose GT-BFT, a streamlined and lightweight blockchain consensus mechanism grounded in a global trust model. This model capitalizes on node behavior to form consensus groups and facilitate consensus achievement. GT-BFT integrates a novel approach of selective broadcasting along with a Byzantine threshold determination algorithm, significantly boosting both the efficiency and security of the network. Our extensive analysis and performance evaluation reveal that GT-BFT surpasses existing mechanisms in key areas such as security, system throughput, and transaction confirmation speed, marking a significant advancement in blockchain consensus technology.
Jinwen Xi, Guosheng Xu 0001, Shihong Zou, Yinliang Yue, Binsi Cai
Blockchain Res. Appl.2
2025 Decoding Secret Memorization in Code LLMs Through Token-Level Characterization
abstract
Code Large Language Models (LLMs) have demonstrated remarkable capabilities in generating, understanding, and manipulating programming code. However, their training process inadvertently leads to the memorization of sensitive information, posing severe privacy risks. Existing studies on memorization in LLMs primarily rely on prompt engineering techniques, which suffer from limitations such as widespread hallucination and inefficient extraction of the target sensitive information. In this paper, we present a novel approach to characterize real and fake secrets generated by Code LLMs based on token probabilities. We identify four key characteristics that differentiate genuine secrets from hallucinated ones, providing insights into distinguishing real and fake secrets. To overcome the limitations of existing works, we propose DeSec,a two-stage method that leverages token-level features derived from the identified characteristics to guide the token decoding process. DeSec consists of constructing an offline token scoring model using a proxy Code LLM and employing the scoring model to guide the decoding process by reassigning token likelihoods. Through extensive experiments on four state-of-the-art Code LLMs using a diverse dataset, we demonstrate the superior performance of DeSec in achieving a higher plausible rate and extracting more real secrets compared to existing baselines. Our findings highlight the effectiveness of our token-level approach in enabling an extensive assessment of the privacy leakage risks associated with Code LLMs.
Yuqing Nie, Chong Wang 0013, Kailong Wang 0001, Guoai Xu, Guosheng Xu 0001, Haoyu Wang 0001
ICSE5
2025 Seeing is (Not) Believing: The Mirage Card Attack Targeting Online Social Networks
abstract
In the digital era, Online Social Networks (OSNs) have become central to information dissemination, with sharing cards for link previews serving as a key feature.While these cards provide concise snapshots of shared content, their security implications have remained largely overlooked.This paper introduces the Mirage Card Attack, a novel class of attacks that exploits vulnerabilities in sharing card mechanisms across major OSNs.We identify two primary attack vectors: Proxy-Based Redirection and User-Agent-Based Cloaking.These attacks leverage design flaws in Share-SDK implementations and HTML meta tag usage, allowing attackers to bypass existing security measures and present deceptive content to users.Our systematic analysis reveals critical vulnerabilities in current sharing card systems.We demonstrate the feasibility of these attacks through comprehensive evaluations across 8 major OSNs for User-Agent-Based Cloaking and 6 OSNs for Proxy-Based Redirection.Additionally, we analyze 8 widely used card generation tools, uncovering significant security gaps.Our experiments show that some forged cards persist for over 15 days, highlighting the inadequacy of existing detection methods.To evaluate the practical impact of Mirage Card Attacks, we conduct a user study to * Both authors contributed equally to this research.
Wangchenlu Huang, Shenao Wang 0001, Yanjie Zhao 0001, Yuhao Gao, Guosheng Xu 0001, Haoyu Wang 0001
Internetware6
2025 A Provably Secure Authentication Protocol Based on PUF and ECC for IoT Cloud-Edge Environments
abstract
The Internet of Things (IoT) cloud model provides an efficient scheme for rapid collection, storage, processing, and analysis of massive node data, and its application has gradually expanded to key areas such as healthcare and transportation. However, the security issues of open channel transmission in IoT still persist. Researchers have proposed a lot of solutions, but the forward secrecy, session key security, and other aspects have not been effectively solved. This paper proposes a provably secure authenticated key agreement scheme, which constructs a secure channel between endpoint, gateway, and cloud server (CS). Compared with other schemes, this scheme has three characteristics: (1) According to the different computing resources of devices, gateways and CSs, a segmented differential authentication and secret key negotiation protocol is designed by using cryptographic primitives with different computing overheads; (2) after verification with the ProVerif tool, rigorous proof with the real‐or‐random (ROR) model, and informal analysis, the protocol has been proven to be secure, effectively guarding against typical threats; and (3) compared with the five most recent schemes, it can be seen that the protocol is at least 35% superior to other schemes in endpoint computational overhead, and it meets 10 security objectives, making it very suitable for application scenarios where endpoint resources are limited.
Guosheng Xu 0001, Chenyu Wang 0002, Jinwen Xi, Guoai Xu
IET Inf. Secur.2
2025 Statistical Fault Attacks on ASCON Using Improved Square Euclidean Imbalance
abstract
In current environment of frequent information exchange between Internet of Things (IoT) devices, traditional cryptographic algorithms often fail to effectively play a role in resource-limited electronic devices, which highlights the importance of lightweight cryptographic algorithms. NIST has completed the standardization process of lightweight cryptographic algorithms, and ASCON has become the ultimate winner. It is foreseeable that its application demand will continue to grow in the future, so the security analysis for ASCON is of significant value. Among various cryptographic algorithm analysis methods, fault attack is an efficient choice. Currently, there are also some fault attack methods for ASCON, but they share a common issue: their time complexity is too high for practical application. In view of this, this article proposes a more efficient fault attack method for ASCON, including several key points: First, several new statistical scoring function are constructed based on square euclidean imbalance (SEI). Second, a single S-box fault model is proposed to reduce the complexity of injection. Lastly, the complete key is recovered by combining statistical ineffective fault attack (SIFA), statistical effective fault attack (SEFA), and statistical hybrid fault attack (SHFA). The time complexity is$2^{16.57}$,$2^{14.91}$, and$2^{14.52}$, respectively. Experimental results on a Python implementation of ASCON, the results show that our scheme significantly reduces the time complexity of attacks, which can provide warnings for cryptography design and applications, and pay more attention to avoiding such risks.
Guosheng Xu 0001, Yuque Zhang, Chenyu Wang 0002, Guoai Xu
IEEE Internet Things J.1
2024 MalCertain: Enhancing Deep Neural Network Based Android Malware Detection by Tackling Prediction Uncertainty
abstract
The long-lasting Android malware threat has attracted significant research efforts in malware detection. In particular, by modeling malware detection as a classification problem, machine learning based approaches, especially deep neural network (DNN) based approaches, are increasingly being used for Android malware detection and have achieved significant improvements over other detection approaches such as signature-based approaches. However, as Android malware evolve rapidly and the presence of adversarial samples, DNN models trained on early constructed samples often yield poor decisions when used to detect newly emerging samples. Fundamentally, this phenomenon can be summarized as the uncertainly in the data (noise or randomness) and the weakness in the training process (insufficient training data). Overlooking these uncertainties poses risks in the model predictions. In this paper, we take the first step to estimate the prediction uncertainty of DNN models in malware detection and leverage these estimates to enhance Android malware detection techniques. Specifically, besides training a DNN model to predict malware, we employ several uncertainty estimation methods to train a Correction Model that determines whether a sample is correctly or incorrectly predicted by the DNN model. We then leverage the estimated uncertainty output by the Correction Model to correct the prediction results, improving the accuracy of the DNN model. Experimental results show that our proposed MalCertain effectively improves the accuracy of the underlying DNN models for Android malware detection by around 21% and significantly improves the detection effectiveness of adversarial Android malware samples by up to 94.38%. Our research sheds light on the promising direction that leverages prediction uncertainty to improve prediction-based software engineering tasks.
Guosheng Xu 0001, Liu Wang 0002, Xusheng Xiao, Xiapu Luo, Guoai Xu, Haoyu Wang 0001
ICSE2
2024 Same App, Different Behaviors: Uncovering Device-specific Behaviors in Android Apps
abstract
The Android ecosystem is significantly challenged by fragmentation, arising from diverse system versions, device specifications, and manufacturer customizations. The growing divergence among devices leads to marked variations in how a given app behaves across diverse devices. This is referred to as device-specific behaviors. Fragmentation not only complicates development processes but also impacts the overall industry by increasing maintenance costs and potentially harming user experience due to inconsistent app performance. In this work, we present the first large-scale empirical study of device-specific behaviors in real-world Android apps. We have designed a three-phase static analysis framework to accurately detect and understand the device-specific behaviors. Upon employing our tool on a dataset comprising more than 20,000 apps, we detected device-specific behaviors in 2,357 of them. By examining the distribution of device-specific behaviors, our analysis revealed that apps within the Chinese third-party app market exhibit more such behaviors compared to their counterparts in Google Play. Additionally, these behaviors are more likely to feature dominant brands that hold larger market shares. Reflecting this, we have classified these device-specific behaviors into 29 categories based on the functionalities implemented, providing a structured insight that is crucial for developers and stakeholders in the industry. Beyond the common behaviors, such as issue fixes and feature adaptations, we have observed 33 aggressive apps, including popular ones with millions of downloads. These apps abuse system properties of customized ROMs to obtain user-unresettable identifiers without requiring any permissions, posing significant privacy risks. Finally, we investigated the origins of device-specific behaviors, highlighting the significant challenges developers encounter in implementing them comprehensively. Our research aims to inform and equip industry practitioners with knowledge to enhance user experience and user privacy, marking a critical step toward addressing the less touched yet vital aspect of device-specific behaviors in the Android ecosystem.
Zikan Dong, Yanjie Zhao 0001, Tianming Liu 0002, Chao Wang 0097, Guosheng Xu 0001, Guoai Xu, Lin Zhang 0062, Haoyu Wang 0001
ASE5
2024 Exploring Covert Third-party Identifiers through External Storage in the Android New Era
Zikan Dong, Tianming Liu 0002, Jiapeng Deng, Haoyu Wang 0001, Li Li 0029, Guosheng Xu 0001, Guoai Xu
USENIX Security Symposium8
2023 WELID: A Weighted Ensemble Learning Method for Network Intrusion Detection
abstract
The requirements for intrusion detection technology are getting higher and higher, with the rapid expansion of network applications. There have been many studies on intrusion detection, however, the accuracy of these models is not high enough and time-consuming, making them unavailable. In this paper, we propose a novel weighted ensemble learning method for network intrusion detection (WELID). Firstly, data preprocessing and feature selection algorithms are used to filter out some redundant and unrelated features. Next, anomaly detection is performed on the dataset using different base classifiers, and a layered ten-fold cross-validation method is used to prevent program overfitting. Then, the best classifiers are selected for the use of a multi-classifier fusion algorithm based on probability-weighted voting. We compare the proposed model with lots of efficient classifiers and state-of-the-art models for intrusion detection. The results show that the proposed model is superior to these models in terms of accuracy and time consumption.
Yuanchen Gao, Guosheng Xu 0001, Guoai Xu
ISCC2
2023 Tree-IDS: An Incremental Intrusion Detection System for Connected Vehicles
abstract
The rapid development of Internet of Vehicles technology has led to the continuous upgrading of the functions of connected vehicles. While connected vehicles bring convenience to people’s life, there are also many security threats. Connected vehicles not only have intra-vehicle networks communication, but also communicate with the external network. The diversity of communication methods makes the attack surface wider, and some new attacks are constantly emerging. In order to ensure vehicle security, This paper focuses on the attacks that are vulnerable to vehicles, and proposes an incremental intrusion detection system, which can not only detect attacks, but also incrementally learn new types of attacks. Experimental results illustrate that the proposed system can incrementally learn new attacks and avoid catastrophic forgetting problems, and can detect various types of known attacks with 99.99% accuracy on the Car-Hacking Dataset and 99.37% accuracy on the CICIDS2017.
Zixiang Bi, Guosheng Xu 0001, Chenyu Wang 0002, Guoai Xu
LCN3
2023 A Blockchain Dynamic Sharding Scheme Based on Hidden Markov Model in Collaborative IoT
abstract
Sharded blockchain offers scalability, decentralization, immutability, and linear improvement, making it a promising solution for addressing the trust problem in large-scale collaborative IoT. However, a high proportion of cross-shard transactions can severely limit the performance of decentralized blockchain. Furthermore, the dynamic assemblage characteristic of collaborative sensing in sharded blockchain is often ignored. To overcome these limitations, we propose HMMDShard, a dynamic blockchain sharding scheme based on the Hidden Markov Model. HMMDShard leverages fine-grained blockchain sharding and fully embraces the dynamic assemblage characteristic of IoT collaborative sensing. By integrating the Hidden Markov Model, we achieve adaptive dynamic incremental updating of blockchain shards, effectively reducing cross-shard transactions across all shards. We conduct a comprehensive analysis of the security issues and properties of HMMDShard, and evaluate its performance through the implementation of a system prototype. The results demonstrate that HMMDShard significantly reduces the proportion of cross-shard transactions and outperforms other baselines in terms of system throughput and transaction confirmation latency.
Jinwen Xi, Guosheng Xu 0001, Shihong Zou, Yueming Lu, Jiuyun Xu
IEEE Internet Things J.2
2022 MSDetector: A Static PHP Webshell Detection System Based on Deep-Learning
Baijun Cheng, Guosheng Xu 0001
TASE5
2022 Segment Detection Algorithm: CAN bus intrusion detection based on Bit Constraint
abstract
With the rapid development of Internet of Vehicles and autonomous driving technologies, car manufacturers provide more comfortable and safe driving experience while gradually exposing their vehicles to the background of cyber-attacks. As the car’s interior communicates through the CAN bus, the intrusion detection for CAN bus becomes crucial. Some studies use bus data characteristics, machine learning algorithms, or information theory algorithms to perform intrusion detection on the CAN bus, but they have problems such as low detection accuracy, high performance requirements, and insufficient detection granularity. This paper innovatively proposes a lightweight detection algorithm—Segment Detection Algorithm (SDA), which calculates the bit flip rate by segment, discovers the variation relationship between bits within each segment, and utilizes multiple inter-message features to achieve the detection of abnormal traffic. Experiments show that compared with existing research, the algorithm has effectively improved the detection accuracy, especially the detection of replay attacks. In addition, the algorithm has extremely low time complexity, can adapt to the limited resources in the vehicle environment, and achieve high-precision real-time detection of abnormal traffic.
Kaixuan Zheng, Shihong Zou, Guosheng Xu 0001, Zixiang Bi
WoWMoM3
2022 Lie to Me: Abusing the Mobile Content Sharing Service for Fun and Profit
abstract
Online content sharing is a widely used feature in Android apps. In this paper, we observe a new Fake-Share attack that adversaries can abuse existing content sharing services to manipulate the displayed source of shared content to bypass the content review of targeted Online Social Apps (OSAs) and induce users to click on the shared fraudulent content. We show that seven popular content-sharing services (including WeChat, AliPay, and KakaoTalk) are vulnerable to such an attack. To detect this kind of attack and explore whether adversaries have leveraged it in the wild, we propose DeFash, a multi-granularity detection tool including static analysis and dynamic verification. The extensive in-the-lab and in-the-wild experiments demonstrate that DeFash is effective in detecting such attacks. We have identified 51 real-world apps involved in Fake-Share attacks. We have further harvested over 24K Sharing Identification Information (SIIs) that can be abused by attackers. It is hence urgent for our community to take actions to detect and mitigate this kind of attack.
Guosheng Xu 0001, Hao Zhou 0043, Shucen Liu, Yutian Tang, Li Li 0029, Xiapu Luo, Xusheng Xiao, Guoai Xu, Haoyu Wang 0001
WWW1
2021 Intelligent Preprocessing Selection for Pavement Crack Detection based on Deep Reinforcement Learning
abstract
With the rapid increase of traffic, the pressure on road maintenance is gradually increasing.Pavement crack is a common problem in all kinds of pavement diseases.In the actual production process, pavement images have different kinds of noise influence.The proposed algorithm is to select optimal preprocessing methods for pavement images in various conditions to improve the accuracy of crack detection.The algorithm includes two parts, a crack detection network and an intelligent preprocessing decision system.The crack detection network identifies the cracks in road images.The intelligent preprocessing decision system selects the best preprocessing method for pavement images based on the deep reinforcement method.The experiment results indicate that the validity and effectiveness of our proposed method.
Guosheng Xu 0001, Guoai Xu, Jiankun Cao
SEKE2
2021 An Efficient Compartmented Secret Sharing Scheme Based on Linear Homogeneous Recurrence Relations
abstract
Multipartite secret sharing schemes are those that have multipartite access structures. The set of the participants in those schemes is divided into several parts, and all the participants in the same part play the equivalent role. One type of such access structure is the compartmented access structure, and the other is the hierarchical access structure. We propose an efficient compartmented multisecret sharing scheme based on the linear homogeneous recurrence (LHR) relations. In the construction phase, the shared secrets are hidden in some terms of the linear homogeneous recurrence sequence. In the recovery phase, the shared secrets are obtained by solving those terms in which the shared secrets are hidden. When the global threshold is t , our scheme can reduce the computational complexity of the compartmented secret sharing schemes from the exponential time to polynomial time. The security of the proposed scheme is based on Shamir’s threshold scheme, i.e., our scheme is perfect and ideal. Moreover, it is efficient to share the multisecret and to change the shared secrets in the proposed scheme.
Guoai Xu, Jiangtao Yuan, Guosheng Xu 0001, Zhongkai Dang
Secur. Commun. Networks3
2020 Sensitive Information Detection based on Convolution Neural Network and Bi-directional LSTM
abstract
Electronic documents can carry lots of information and are widely used in daily lives. It will cause substantial economic losses to individual users, enterprises, and governments when the documents containing sensitive information are leaked. How to detect sensitive information to prevent data leakage is still a challenge in the field of information security. This paper mainly focuses on the detection of unstructured documents containing sensitive information. Governments, military, and other institutions can actively mark whether the electronic documents contain sensitive information according to the detection results. We propose a reliable method to detect sensitive electronic documents automatically and compare it with other basic methods. The algorithm structure can extract the characteristics of the data more comprehensively to obtain better detection results. Our model outperformed the other models with 93.44 % accuracy. Our model can also reduce the time cost, which is beneficial for realistic production.
Guosheng Xu 0001, Guoai Xu
TrustCom2
2020 A Robust IoT-Based Three-Factor Authentication Scheme for Cloud Computing Resistant to Session Key Exposure
abstract
With the development of Internet of Things (IoT) technologies, Internet-enabled devices have been widely used in our daily lives. As a new service paradigm, cloud computing aims at solving the resource-constrained problem of Internet-enabled devices. It is playing an increasingly important role in resource sharing. Due to the complexity and openness of wireless networks, the authentication protocol is crucial for secure communication and user privacy protection. In this paper, we discuss the limitations of a recently introduced IoT-based authentication scheme for cloud computing. Furthermore, we present an enhanced three-factor authentication scheme using chaotic maps. The session key is established based on Chebyshev chaotic-based Diffie–Hellman key exchange. In addition, the session key involves a long-term secret. It ensures that our scheme is secure against all the possible session key exposure attacks. Besides, our scheme can effectively update user password locally. Burrows–Abadi–Needham logic proof confirms that our scheme provides mutual authentication and session key agreement. The formal analysis under random oracle model proves the semantic security of our scheme. The informal analysis shows that our scheme is immune to diverse attacks and has desired features such as three-factor secrecy. Finally, the performance comparisons demonstrate that our scheme provides optimal security features with an acceptable computation and communication overheads.
Guosheng Xu 0001, Guoai Xu, Yuejie Wang, Junhao Peng
Wirel. Commun. Mob. Comput.2