EDBT 2026 Demo / reviewers in the wild / expert
Yaqin Cao
dblp:131/7015
· DBLP profile ↗
16ranked-venue papers
2as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 7 · 2 first-author · 5 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CBR-PAR: LLM-Augmented Case-Based Reasoning for Provenance-Based Alert Reduction
Canhua Chen, Yaqin Cao, Xinyu Li 0001, Baihang Liu, Qixu Liu |
ICCBR | 2 |
| 2026 | TLBAC: a zero-trust based cloud-edge-endpoint access control system using trusted labelsabstractAbstract With the rapid development of cloud computing, enterprises have increasingly migrated their servers and services from internal networks to cloud environments. Traditional boundary-based protection mechanisms are no longer sufficient for addressing the security requirements of modern cloud-based systems. As cyberattacks continue to evolve, ensuring the long-term, secure, and reliable operation of increasingly complex IT systems has become a significant challenge. Consequently, researchers have proposed various fine-grained access control approaches. Fine-grained access control remains a significant challenge in complex cloud-edge-endpoint collaboration scenarios. Existing approaches often rely on intricate policy definitions to achieve granular control, which can lead to increased computational overhead and degraded system performance. In this paper, we propose a lightweight, Zero-Trust-based Cloud-Edge-Endpoint Access Control System—TLBAC. By embedding trusted labels into TCP packets at the security endpoint (Endpoint), TLBAC enables traffic blocking and forwarding through access control policies issued by the Security Cloud Brain (Cloud) via the Edge Decision Gateway (Edge). This framework achieves fine-grained access control through trusted labels in a cloud-edge-endpoint architecture. To evaluate the effectiveness of TLBAC, four experiments are designed. The first experiment examines the impact of trusted labels insertion on TCP traffic packet transmission behavior. The experimental results show that even under high-latency, significant jitter, and high packet loss conditions in an LTE network, TCP packets with embedded trusted labels maintain stable and reliable data transmission. The second experiment assesses the resource consumption of TLBAC, focusing on CPU and memory overhead. The experimental results indicate that TLBAC’s resource consumption rate is only ± 0.2%. The third experiment simulates a realistic attack environment by launching attacks against the protected system from an adversarial perspective to validate TLBAC’s defensive capabilities. The experimental results demonstrate that TLBAC successfully detected and blocked all attacks in over thirty vulnerability cases involving different components, versions, and exploitation methods. The fourth experiment evaluates the practical operational capability of TLBAC in a multi-tenant environment. The results show that TLBAC can achieve connection-oriented fine-grained access control with low latency, while maintaining policy accuracy and isolation in multi-tenant scenarios. Ru Tan, Baihang Liu, Yaqin Cao, Qixu Liu |
Cybersecur. | 5 |
| 2025 | ExtFPDet: A CNN-Based Detection Framework for Browser Extensions FingerprintingabstractWith the widespread use of modern browser extensions, user experience has been significantly enhanced via embedding ancillary functionality into the original webpage. The rapid development of Web tracking technology has raised privacy and security concerns, as it generates a unique identifier for users according to the diversity of installed extensions and further prompts the profiling of users. However, due to the ignorance of potential privacy risks, there is no effective method to detect browser extension fingerprinting. In this paper, we propose ExtFPDet, a CNN-based detection framework to recognize browser extension fingerprinting in websites, which fills the gap in this area. Based on the preliminary investigation, the approaches to fingerprint browser extensions can be summarized into 2 categories according to the distinctive behaviors, including resource traversing and side-channel exploring. In order to extract effective features to reflect extensions fingerprinting, ExtFPDet focuses on the structure and content in the program dependency graph of Javascript files. The generated feature vector assists the CNN-based classification model to detect the extension fingerprinting, for which we perform a systematic detection on Tranco top 10K websites. Eventually, the result is evaluated by randomly sampling and manually checking, which shows superior detection capabilities of ExtFPDet. Wei Liu 0243, Xiaoxi Wang, Yun Feng 0003, Xinyu Liu 0019, Le Gong, Kerui Huang, Yaqin Cao, Qixu Liu |
CSCWD | 7 |
| 2025 | BASSET: Enhancing Binary Code Clone Searching through Multi-Level Hybrid Semantic IndexingabstractBinary code search is critical for applications such as plagiarism detection and security analysis, but it is challenging due to compiler-induced transformations at different optimization levels. Existing function similarity methods often fail in large-scale search scenarios, particularly pairwise approaches that struggle with scalability. To address this, we propose BASSET, a novel framework that leverages multilevel hybrid semantic features for efficient large-scale binary function clone search. BASSET decomposes functions into five semantic units and applies various embedding strategies to generate indexing vectors for similarity measurement. Notably, it integrates an expression tree-based representation to capture robust features across compiler optimization levels. By utilizing a learning-to-rank approach with convolutional neural networks, BASSET combines similarity scores from different semantic units to generate a final ranking. Experimental results show that BASSET outperforms existing methods, achieving an AUC of 0.992, an nDCG@10 of 0.853, and a stable MRR of 59%, even as the search space grows. Ang Xia, Zhi Wang 0018, Yaqin Cao, Xiangyi Zeng |
DSN | 5 |
| 2025 | VulKiller: Java Web Vulnerability Detection with Code Property Graph and Large Language ModelsabstractIn recent years, web application development has become more efficient, yet vulnerabilities still pose significant risks. Traditional static and dynamic detection techniques are prone to false positives and negatives, making it challenging for small and medium-sized developers with limited security knowledge to accurately assess the results. To address these challenges, we introduced VulKiller, an automated vulnerability detection tool powered by large language models (LLM). VulKiller leverages static analysis to convert application code into Code Property Graphs (CPG) and utilizes Neo4j to identify high-risk method call chains. By designing structured interactions with ChatGPT, these call chains and corresponding code are transformed into Proofs of Concept (PoCs), which are then parsed into attack payloads and evaluated by a vulnerability monitor for effectiveness. In comparison with traditional tools, VulKiller excels in reducing false positives and negatives. Additionally, in zero-day vulnerability detection experiments, VulKiller identified 12 zero-day vulnerabilities. Our results offer significant encouragement for using LLM to enhance vulnerability detection. Xingchen Chen, Baizhu Wang, Mengjun Zhang, Yaqin Cao, Qixu Liu |
ICASSP | 4 |
| 2025 | Not All Benignware Are Alike: Enhancing Clean-Label Attacks on Malware ClassifiersabstractMachine Learning (ML) based malware classifiers are vulnerable to exploitation during the training phase due to the necessity of regular retraining with samples collected from the wild. Recent studies have highlighted the efficacy of backdoor attacks in the malware domain, where attackers can manipulate the model during training by injecting samples embedded with specific triggers, causing the model to establish an association between the trigger and a designated class, thereby achieving evasion of detection. While research on backdoor attacks has been extensively explored in the field of computer vision, it has been largely overlooked in the malware domain. Unlike in the computer vision domain, the threat model in the malware domain typically restricts attackers to employing clean-label attacks (i.e., attackers do not have control over the labeling of poisoned data). However, clean-label attack methods are generally less effective compared to those that involve embedding triggers and altering sample labels to the target class (called corrupted-label attacks). To address this limitation, we propose a simple yet effective method that involves Poisoning Malware-Similar Benignware (PMSB) instead of random selection, thereby approximating the scenario of corrupted-label attacks and enhancing the effectiveness of clean-label attacks. Additionally, we introduce three similarity measurement methods based on feature-based distance, distribution-based distance, and contribution-based difference to select malware-similar benignware. Comprehensive evaluations across three different trigger types and three datasets demonstrate the superiority and general applicability of PMSB. Xutong Wang, Yun Feng 0003, Bingsheng Bi, Yaqin Cao, Ze Jin, Xinyu Liu 0019, Yunpeng Li 0006 |
WWW | 4 |
| 2025 | WTDetect: a third-party website tracking detection framework for android applicationsabstractAbstract With the development of HTML5, tracking technologies have evolved dramatically and gradually moved from cookies to browser fingerprinting. Previous research has shown that there are more serious privacy threats associated with tracking behavior on third-party websites. However, by focusing on third-party websites that are loaded in the browser, the researchers overlooked the fact that third-party websites are also present in Android applications, where tracking is easy to perform and definitely covert to detect. In this study, we propose WTDetect, an Android third-party website tracking detection framework. Based on the parsing of view tree and the generation of function call stack, WTDetect automatically locates and captures the source code of third-party websites. To explore the direction of sensitive data flow, WTDetect performs static taint analysis on the program dependency graph for each JavaScript file. Finally, a fine-grained classification model is used to detect the tracking behavior. WTDetect is used to perform a measurement study of tracking behavior on 1090 captured Android third-party websites. The result outlines that 14.68% of third-party websites in Android applications tracking users without any access warnings and user authorization, which directly leads to the risk of privacy leakage. Wei Liu 0243, Xinyu Liu 0019, Yun Feng 0003, Kerui Huang, Ze Jin, Yaqin Cao, Qixu Liu |
Cybersecur. | 6 |
| 2024 | SDM-GAT: StylisticFP Detection Method Based on Graph Attention Network
Xiaoxi Wang, Chunyang Zheng, Yaqin Cao, Qixu Liu |
ADMA (3) | 5 |
| 2024 | MalPolymer: A Threat Identification System Utilizing Cognate Malicious Login Behavior DetectionabstractAccurate attribution and tracing of cyber attacks require a comprehensive understanding of the resources employed by malicious actors. However, Indicators of Compromise (IoCs) can only reveal a portion of the attacker’s assets. To enhance the capability of clue expansion, this study introduces a novel approach to associating attack sources, facilitating the identification of additional IP addresses and subnets that may correspond to a single malicious actor. We focus on the scenario of compromised email accounts and utilize login logs as foundational data. We employ Gaussian Mixture Models (GMM) to construct a reference model that captures known malicious behaviors. Then, we utilize a genetic algorithm to filter and select candidate subnets that exhibit the attack patterns outlined by the reference model. Through evaluation on real-world data, we demonstrate the effectiveness of our proposed method in successfully attributing multiple attack sources to a single attacker, thereby providing valuable insights for manual investigations. Ru Tan, Yaqin Cao, Xutong Wang, Qixu Liu, Xiang Cui |
CSCWD | 3 |
| 2024 | Facing a Trend of Icon Simplicity: Evidence from Event-Related PotentialsabstractApplication icons are a pivotal part of graphical user interface of mobile devices. Despite a trend away from complexity to simplicity in user interface design, there is lack of evidence supporting the superiority of icon simplicity from a psychophysiological perspective. This study investigates the effects of icon complexity and simplicity on user cognition using an event-related potentials (ERPs) technique. Eighteen participants completed an icon cognition and evaluation experiment in an electrophysiological laboratory. Their subjective evaluations, behavioral data, and ERP data were recorded and analyzed. The results of subjective evaluation showed that the simplest icons were regarded as more useful in helping subjects extract icon information than more complex ones. For the ERP measures, P1 amplitudes induced by complex icons were larger than those elicited by simple icons. In the parietal area, P2 amplitudes and latency were larger and later for complex icons than for simple ones. Simple icons are subjectively more helpful than complex ones, partially because they demand fewer attention resources in early stimulus-driven perceptual detection of icon features (P1 during 120–190 ms) and induce more positive emotional arousal (P2 during 190–200 ms). Simple icon designs minimize cognitive demands and are deemed more helpful than complex ones. Our study highlights that the ERP technique represents a tool to explore how users process icon and interface design. Yaqin Cao, Xiaoning Liang, Robert W. Proctor, Vincent G. Duffy |
Int. J. Hum. Comput. Interact. | 2 |
| 2023 | SWDNet: Stealth Web Shell Detection Technology based on Triplet NetworkabstractAmid escalating cyber threats, websites have emerged as predominant targets for attackers employing web shells to maintain extended control. Web shells, frequently used by Advanced Persistent Threat (APT) groups, often result in significant damage, despite the conspicuous lack of focused academic research on their detection. This paper illuminates the stealth variant of the web shell, covertly embedded within benign files, and addresses the unique detection challenges presented by their covert nature and the dearth of targeted datasets. In response to these challenges, we construct three datasets: small web shells, benign files, and stealth web shells, subsequently proposing an innovative triplet network detection model for the stealth web shell. This model excels in differentiating stealth web shells from benign files while simultaneously aligning them more closely with small web shells, thereby refining classification precision. Our methodology transforms samples into opcode sequences through a series of processing steps, and then integrates them into the specially designed triplet network. Benchmarked against a cutting-edge deep learning network model and recognized detection tools, our detection methodology yields superior performance, delivering a high accuracy of 92.56% and a robust F1-score of 89.17%. These results substantiate the potency of our approach in countering the mounting threat posed by stealth web shells. Jinli Zhang, Yaqin Cao, Ru Tan, Xiang Cui, Qixu Liu |
MSN | 3 |
| 2023 | Detecting compromised email accounts via login behavior characterizationabstractAbstract The illegal use of compromised email accounts by adversaries can have severe consequences for enterprises and society. Detecting compromised email accounts is more challenging than in the social network field, where email accounts have only a few interaction events (sending and receiving). To address the issue of insufficient features, we propose a novel approach to detecting compromised accounts by combining time zone differences and alternate logins to identify abnormal behavior. Based on this approach, we propose a compromised email account detection framework that relies on widely available and less sensitive login logs and does not require labels. Our framework characterizes login behaviors to identify logins that do not belong to the account owner and outputs a list of account-subnet pairs ranked by their likelihood of having abnormal login relationships. This approach reduces the number of account-subnet pairs that need to be investigated and provides a reference for investigation priority. Our evaluation demonstrates that our method can detect most email accounts that have been accessed by disclosed malicious IP addresses and outperforms similar research. Additionally, our framework has the capability to uncover undisclosed malicious IP addresses. Yaqin Cao, Xiang Cui, Qixu Liu |
Cybersecur. | 4 |
| 2022 | The Roles of Visual Complexity and Order in First Impressions of Webpages: An ERP Study of Webpage Rapid EvaluationabstractUsers’ first impressions of a website have a great impact on their subsequent behaviors and attitudes toward the website. Visual complexity and order are two key factors of webpage design that influence users’ first impressions of webpages. Consequently, we investigated those factors in the present study, using an event-related potential (ERP) technique to analyze users’ evaluative processing. The results show that website complexity and order evaluations were processed within 100–160 ms, influencing N1 amplitude, which is an ERP component related to early visual attention resource allocation. Webpages higher in complexity and order received more attentional resources than did lower ones. Webpage complexity and order continued to have an influence on P2 amplitude in the 160–240 ms period, which may reflect users’ subsequent information processing and emotional evaluations. More cognitive resources were needed for information processing for the low-order webpages, and more positive feelings were evoked by low-complexity webpages than by high-complexity webpages. Subsequently, webpage complexity and order also influenced P3 amplitude in the time interval of 300–440 ms, suggesting an influence on explicit attentional resource allocation. In detail, the ERP results suggest that participants may prefer low-complexity webpages because those webpages evoked positive emotional experiences and that they were inclined to allocate more attention resources to information processing for low-order webpages than for high-order ones. The results of this study provide evidence from brain activity that webpage complexity and order are processed quickly and, as a consequence, likely influence users’ first impressions. The findings suggest that to induce positive first impressions, designers should adopt well-ordered webpages for attracting users’ attention and low-complexity webpages for inducing positive emotional responses. Yaqin Cao, Robert W. Proctor |
Int. J. Hum. Comput. Interact. | 2 |
| 2021 | Influences of Color Salience and Location of Website Links on User Performance and Affective Experience with a Mobile Web DirectoryabstractWe investigated the impact of color salience and location of a website link on users’ performance, affective experiences and approach-avoidance tendencies with 10 mock mobile Web directories. Task completion times were recorded by a computer program, and users’ affective experiences and approach-avoidance responses were reported in questionnaires. Results implied that visual attention in the display area on a mobile Web directory is directed by a combination of bottom-up and top-down processes, which is different from the primarily top-down process implicated in a similar study of PC Web directories. A salient color of the website link helped attract users’ attention and increase users’ sense of control over the process. Also, users are likely to search webpages from top left to bottom right. Our findings suggest that a target website link placed in the top left corner or displayed in a distinct color in the center area not only attracts users’ attention but also results in a more highly rated affective experience. Color of the target website link can be changed to increase users’ sense of control of a Web directory and approach behaviors. Yaqin Cao, Robert W. Proctor, Yi Ding 0013, Vincent G. Duffy, Xuefeng Zhang 0002 |
Int. J. Hum. Comput. Interact. | 1 |
| 2020 | An Exploratory Study Using Electroencephalography (EEG) to Measure the Smartphone User Experience in the Short TermabstractUX (User experience) can influence important user behaviors, including user preference, purchasing decisions, and customer loyalty. The ability to assess UX during the product trial has practical significance for design and improvement of products. In this article, two smartphones with different UX were selected through a focus group. In the EEG (electroencephalography) experiment, we explored the brain signal of users when using two smartphones to complete three tasks. The brain signal of each participant was recorded through Curry Neuroimaging Suite software (Version 7.0, Compumedics Limited, Abbotsford, Australia) when they were using the smartphones. Then results from behavioral, subjective and neural responses were analyzed. The behavioral results showed that participants completed the three tasks faster by using a smartphone with a higher score of UX. The subjective results showed a significant difference between the two smartphones. The patterns of cortical activity were obtained in the five principal frequency bands, Delta (1–4 Hz), Theta (4–8 Hz), Alpha (8–13 Hz), Beta (13–30 Hz) and Gamma (30–45 Hz). The results indicated that a smartphone with higher scores of UX could evoke stronger relative power of Alpha (fronto-central, parietal and partieto-occipital regions), Delta (frontal region) and Gamma rhythms (C3 site), but weaker relative power of Beta (left central region) and Theta rhythms (frontal and parieto-occipital regions). Also, the correlation analysis showed that there was no significant relationship between EEG and behavioral results. User’s subjective experience had a significant positive correlation with the relative power of Gamma band, but a negative correlation with Beta and Theta bands (approximately significant with p = .078 and p = .071). There were also significant correlations between EEG results and sub-items of UX. Our findings suggest that the difference in EEG may be taken as an evaluating indicator of user perception when using products without interruption. Yi Ding 0013, Yaqin Cao, Qing-Xing Qu, Vincent G. Duffy |
Int. J. Hum. Comput. Interact. | 2 |
| 2019 | Attention for Web Directory Advertisements: A Top-Down or Bottom-Up Process?abstractWeb directories have attracted many advertisers with their special advantages in their large user base. Until recently, attention mechanism of advertisements (ad) on web directories is not well understood. To investigate how the ad location and color of web directories influence users’ attention, this study uses eye tracking to measure the participants’ search time, total fixation duration and the location of the first fixation. Results reveal that visual attention on the ad area of a web directory is user-driven and follows a top-down process. The location of users’ first-fixations is the center of the screen. Ad links that place in the center area and on the top-left corner would increase users’ notice. Ad links that change color in the center area have the advantages of attracting user attention. Our findings suggest that ad links should be placed in the center area or on the top-left corner to increase users’ notice. Ad links placed in the center area should be designed using salient color to catch users’ visual attention. Yaqin Cao, Qing-Xing Qu, Vincent G. Duffy, Yi Ding 0013 |
Int. J. Hum. Comput. Interact. | 1 |