Qiuling Yue

dblp:138/9039 · DBLP profile ↗
← Back
10ranked-venue papers
0as first author
10since 2021 · last 2026
0000-0002-7217-3969ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Network-Compute Trade-offs in Resource Depletion Attacks on LLM Inference Services
Zhiyuan Fu, Ruidong Li 0001, Qiuling Yue, Yuqing Zhang 0001
INFOCOM4
2026 Improving targeted password guessing attacks by using personally identifiable information and old password
abstract
Abstract Text-based passwords serve as a primary means of authentication and play a crucial role in securing information systems. However, easy-to-remember passwords are often vulnerable to targeted password guessing attacks. Research on targeted password guessing not only deepens our understanding of password security but also contributes to enhancing the security of information systems. Although the use of Personally Identifiable Information (PII) and old passwords has been shown to significantly improve the accuracy of targeted password guessing, there has been little research on the combined use of both PII and old passwords for guessing. In an era where PII and old passwords are increasingly accessible, assessing the threat posed by attackers using both PII and old passwords in targeted password guessing is an urgent security issue. To address this gap, we first analyze leaked password and personal information datasets, demonstrating that PII and old passwords critically influence users’ password creation behavior. Then, to simulate the security risks posed by attackers who know both PII and old passwords, we propose the PassGLM model, a model fine-tuned on a targeted password guessing task dataset based on glm-4-9b. PassGLM is capable of generating highly targeted guesses by leveraging both PII and old passwords. Experiments show that PassGLM significantly outperforms leading models that use only PII or only old passwords in terms of guess success rates. Our research demonstrates that combining PII and old passwords can substantially improve the accuracy of password guessing, and that using large language models as tools is an effective way to achieve this improvement.
Wei Ou, Chengliang Sun, Mengxue Pang, Qiuling Yue, Yanshuo Zhang, Wenbao Han
Cybersecur.4
2026 Attribute-based publicly verifiable secret sharing
abstract
Abstract Can a dealer share a secret without knowing the shareholders? We provide a positive answer to this question by introducing the concept of an attribute-based secret sharing (AB-SS) scheme.With AB-SS, a dealer can distribute a secret based on attributes rather than specific individuals or shareholders. Only authorized users whose attributes satisfy a given access structure can recover the secret. Furthermore, we introduce the concept of attribute-based publicly verifiable secret sharing (AB-PVSS). An AB-PVSS scheme allows external users to verify the correctness of all broadcast messages from the dealer and shareholders, similar to a traditional PVSS scheme. Additionally, AB-SS (or AB-PVSS) distinguishes itself from traditional SS (or PVSS) by enabling a dealer to generate shares according to an arbitrary monotone access structure.To build an AB-PVSS scheme, we first implement a decentralized ciphertext-policy attribute-based encryption (CP-ABE) scheme, though not a fully-fledged one.We then incorporate non-interactive zero-knowledge (NIZK) proofs to enable public verification of the CP-ABE ciphertext. Based on the CP-ABE and NIZK proofs, we construct an AB-PVSS primitive.Finally, we conduct security analysis and comprehensive experiments on the proposed CP-ABE and AB-PVSS schemes. The results demonstrate that both schemes exhibit plausible performance compared to related works.
Liang Zhang 0043, Qiuling Yue, Haibin Kan, Jiheng Zhang
Cybersecur.3
2026 MSGL: A multi-scale group learning model for insider threat detection
abstract
The insider threat refers to actions of organizational users who abuse their authorized privileges to compromise information assets, and the detection of it has become a crucial task in cybersecurity management. Existing approaches primarily rely on user behavior logs for detection, but they often fail to capture the multi-scale temporal dynamics of user behaviors and the structural relationships within user groups, which limits their effectiveness in insider threat detection. To address these limitations, we propose a multi-scale group learning model (MSGL) for insider threat detection. It mainly consists of three key components: (1) a multi-scale collaborative temporal feature extraction module that leverages a weighted attention mechanism to model behavioral dynamics at different granularities and achieves cross-scale information fusion; (2) the group structure-aware module is designed to capture structural dependencies among users by the aggregation mechanism of graph neural networks, while incorporating group-sparsity regularization to attenuate spurious associations and accentuate underlying common patterns; and (3) an individual learning module for capturing deviations via sparse attention, which facilitates disentangled representations of group-level commonalities and specific characteristics of users. Experimental results on the CERT r4.2 and CERT r5.2 datasets demonstrate the effectiveness of MSGL, achieving detection accuracies of 96.28% and 97.41%, respectively.
Mengxue Pang, Wei Ou, Weizhi Meng 0001, Meng Shen 0001, Qiuling Yue, Wenbao Han
Expert Syst. Appl.5
2026 A new pairing-free verifiable quorum controlled proxy re-encryption scheme
Zhenjie Huang, Yunhao Ling, Qiuling Yue, Yuqing Zhang 0001
J. Syst. Archit.4
2025 Double landmines: invisible textual backdoor attacks based on dual-trigger
abstract
Abstract Backdoor attacks pose an important security threat to textual large language models. Exploring textual backdoor attacks not only helps reveal the potential security risks of models, but also promotes innovation and development of defense mechanisms. Currently, most textual backdoor attack methods are based on a single trigger. For example, inserting specific content into text as a trigger or changing the abstract text features to be a trigger. However, the adoption of this single-trigger mode makes the existing backdoor attacks subject to certain limitations: either they are easily identified by the existing defense strategies, or they have certain shortcomings in attack performance and in the construction of poisoned datasets. In order to solve these issues, a dual-trigger backdoor attack method is proposed in this paper. Specifically, we use two different attributes, syntax and mood (we use subjunctive mood as an example in this article), as two different triggers. It makes our backdoor attack method similar to a double landmine which can have completely different trigger conditions simultaneously. Therefore, this method not only improves the flexibility of trigger mode, but also enhances the robustness against defense detection. A large number of experimental results show that this method significantly outperforms the previous methods based on abstract features in attack performance, and achieves comparable attack performance (almost 100% attack success rate) with the insertion-based method. In addition, in order to further improve the attack performance, we also give the construction method of the poisoned dataset. The code and data of this paper can be obtained at https://github.com/HoyaAm/Double-Landmines.
Qiuling Yue, Lujia Chai, Guozhao Liao, Wenbao Han, Wei Ou
Cybersecur.2
2024 Research on Lifecycle-Driven Government Data Security Model and Data Grouping Technology
abstract
In the context of the information age, promoting digital government and smart cities has made government data sharing a key trend. Given its special nature, securing government data requires an effective security system for safe and efficient management. This paper explores government data security and technical systems, examines China's current data management situation, and compares management strategies in China, the EU, and the US. This paper adopts a data lifecycle-driven security management approach and leverages two widely recognized frameworks to propose a system that balances data openness and security. Finally, we propose an integrated learning method based on BERT and Random Forest, use real data sets to verify the feasibility of data grouping, and promote the integration of government data management and efficient technology.
Jingfeng Rong, Zhiyuan Fu, Qiuling Yue, Anmin Fu, Xujie Liu, Anshun Zhou, Yuqing Zhang 0001
TrustCom4
2024 Traceable ring signature schemes based on SM2 digital signature algorithm and its applications in the data sharing scheme
Hong Lei 0001, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Qiuling Yue
Frontiers Comput. Sci.8
2023 Multimodal Software Defect Severity Prediction Based on Sentiment Probability
Yongchao Zhong, Qiuling Yue, Jinglu Hu, Huiyang Shi, Yuqing Zhang 0001
ISPEC4
2023 Cross-Border Data Security from the Perspective of Risk Assessment
Gaofei Wu, Jingfeng Rong, Zheng Yan 0002, Qiuling Yue, Jinglu Hu, Yuqing Zhang 0001
ISPEC5