EDBT 2026 Demo / reviewers in the wild / expert
Mingkui Wei
dblp:146/8098
· DBLP profile ↗
20ranked-venue papers
12as first author
6since 2021 · last 2025
0000-0003-3606-3428ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 10 first-author · 1 since 2021Security and privacy · 6 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Assessing the effectiveness of crawlers and large language models in detecting adversarial hidden link threats in meta computingabstractIn the emerging field of Meta Computing, where data collection and integration are essential components, the threat of adversary hidden link attacks poses a significant challenge to web crawlers. In this paper, we investigate the influence of these attacks on data collection by web crawlers, which famously elude conventional detection techniques using large language models (LLMs). Empirically, we find some vulnerabilities in the current crawler mechanisms and large language model detection, especially in code inspection, and propose enhancements that will help mitigate these weaknesses. Our assessment of real-world web pages reveals the prevalence and impact of adversary hidden link attacks, emphasizing the necessity for robust countermeasures. Furthermore, we introduce a mitigation framework that integrates element visual inspection techniques. Our evaluation demonstrates the framework’s efficacy in detecting and addressing these advanced cyber threats within the evolving landscape of Meta Computing. Mingkui Wei, Yao Liu 0007 |
High Confid. Comput. | 2 |
| 2025 | The Implications of Insecure Use of Fonts Against PDF Documents and Web PagesabstractThis paper identifies the importance of the safe use of fonts in web and document security. We find multiple attack surfaces that can be exploited by an adversary using malicious fonts. We conduct a comprehensive evaluation of Portable Document Format (PDF) documents collected from the real world to investigate how an attacker can bypass PDF signatures. We further evaluate the potential security threats that an attacker can bring to web-based emails. Our study shows that various security issues may be caused by the inappropriate use of fonts, which are nonethelessly overlooked in the past years. As such, guidelines promoting the secure use of fonts could be beneficial in reinforcing the security measures for digital documents and web pages. Mingkui Wei, Tony Xiao Han, Yao Liu 0007 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | The Perils of Wi-Fi Spoofing Attack Via Geolocation API and Its DefenseabstractLocation spoofing attack deceiving a Wi-Fi positioning system has been studied for over a decade. However, it has been challenging to construct a practical spoofing attack in urban areas with dense coverage of legitimate Wi-Fi APs. This paper identifies the vulnerability of the Google Geolocation API, which returns the location of a mobile device based on the information of the Wi-Fi access points that the device can detect. We show that this vulnerability can be exploited by the attacker to reveal the black-box localization algorithms adopted by the Google Wi-Fi positioning system and easily launch the location spoofing attack in dense urban areas with a high success rate. Furthermore, we find that this vulnerability can also lead to severe consequences that hurt user privacy, including the leakage of sensitive information like precise locations, daily activities, and demographics. Ultimately, we discuss the potential countermeasures that may be used to mitigate this vulnerability and location spoofing attack. Tony Xiao Han, Wenbo Shen, Mingkui Wei, Shangqing Zhao, Yao Liu 0007 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Warmonger Attack: A Novel Attack Vector in Serverless ComputingabstractWe debut the Warmonger attack, a novel attack vector that can cause denial-of-service between a serverless computing platform and an external content server. The Warmonger attack exploits the fact that a serverless computing platform shares the same set of egress IPs among all serverless functions, which belong to different users, to access an external content server. As a result, a malicious user on this platform can purposefully misbehave and cause these egress IPs to be blocked by the content server, resulting in a platform-wide denial of service. To validate the effectiveness of the Warmonger attack, we conducted extensive experiments over several months, collecting and analyzing the egress IP usage patterns of five prominent serverless service providers (SSPs): Amazon Web Service (AWS) Lambda, Google App Engine, Microsoft Azure Functions, Cloudflare Workers, and Alibaba Function Compute. Additionally, we conducted a thorough evaluation of the attacker’s potential actions to compromise an external server and trigger IP blocking. Our findings revealed that certain SSPs employ surprisingly small sets of egress IPs, sometimes as few as four, which are shared among their user base. Furthermore, our research demonstrates that the serverless platform offers ample opportunities for malicious users to engage in well-known disruptive behaviors, ultimately resulting in IP blocking. Our study uncovers a significant security threat within the burgeoning serverless computing platform and sheds light on potential mitigation strategies, such as the detection of malicious serverless functions and the isolation of such entities. Mingkui Wei, Yao Liu 0007 |
IEEE/ACM Trans. Netw. | 2 |
| 2021 | Warmonger: Inflicting Denial-of-Service via Serverless Functions in the CloudabstractWe debut the Warmonger attack, a novel attack vector that can cause denial-of-service between a serverless computing platform and an external content server. The Warmonger attack exploits the fact that a serverless computing platform shares the same set of egress IPs among all serverless functions, which belong to different users, to access an external content server. As a result, a malicious user on this platform can purposefully misbehave and cause these egress IPs to be blocked by the content server, resulting in a platform-wide denial of service. To validate the Warmonger attack, we ran months-long experiments, collected and analyzed the egress IP usage pattern of four major serverless service providers (SSPs). We also conducted an in-depth evaluation of an attacker's possible moves to inflict an external server and cause IP-blockage. We demonstrate that some SSPs use surprisingly small numbers of egress IPs (as little as only four) and share them among their users, and that the serverless platform provides sufficient leverage for a malicious user to conduct well-known misbehaviors and cause IP-blockage. Our study unveiled a potential security threat on the emerging serverless computing platform, and shed light on potential mitigation approaches. Mingkui Wei, Yao Liu 0007 |
CCS | 2 |
| 2021 | Domain Shadowing: Leveraging Content Delivery Networks for Robust Blocking-Resistant Communications
Mingkui Wei |
USENIX Security Symposium | 1 |
| 2020 | CacheLoc: Leveraging CDN Edge Servers for User Geolocation
Mingkui Wei, Khaled Rabieh, Faisal Kaleem |
SecureComm (2) | 1 |
| 2019 | Collaborative Deep Learning for Medical Image Analysis with Differential PrivacyabstractDeep learning algorithms, especially convolution neural networks, have attracted huge attention in the field of medical image analysis. A hospital could train a neural network to detect disease based on medical images possessing. However, the number of medical images would affect the results of training. If medical images of all hospitals are collected together, there's a risk of privacy leakage. In this paper, we apply collaborative deep learning to medical image analysis, which could help to improve the training effect. Besides, we also exploit differential privacy, the analytic Gaussian Mechanism, to prevent the leakage of information about medical images. We experiment on the Chest X-ray Images (Pneumonia) dataset. Results show that the analytic Gaussian Mechanism can protect the privacy of medical images effectively, while the influence on the results of training is small. The accuracy can be improved about 19\% via collaborative deep learning and can still remain about 18\% even when the analytic Gaussian Mechanism was used. Danni Yuan, Xiaoyan Zhu 0005, Mingkui Wei, Jianfeng Ma 0001 |
GLOBECOM | 3 |
| 2019 | On Studying Information Dissemination in Social-Physical Interdependent NetworksabstractMost existing studies for information dissemination in the online social network are based on variations of the classical epidemic model. In such a model, nodes recursively infect, or share information to, their neighboring nodes with a certain probability. The higher degree a node has, the more likely it gets infected by its neighbors. Although widely accepted, we found there are certain discrepancies between existing epidemic models and social interactions in reality. Firstly, the real-world social network is actually a dual-layered network, where a person shares information online to her online friends, and also offline to her real-life friends. More importantly, since a computer do not automatically share information, a computer exposed to information will not effectively receive it (i.e., getting infected and starting to infect others) unless its user receives it. Secondly, contrary to the epidemic model, the more friends a person has, the less likely she is going to effectively receive a certain piece of message (just imagine how easily a message can be flushed and ignored by a human user because of overwhelming newer information). In other words, in social networks, the infection rate of a node may not be positively correlated with its degree. Based on these observations, we develop the social-physical interdependent (SPI) model to capture and analyze the unique characters of social networks. Our study provides new observations, and sheds light on a new direction for the study of information dissemination in social networks. Mingkui Wei, Jie Wang 0016, Wenye Wang |
ICC | 1 |
| 2019 | Cyber and physical interactions to combat failure propagation in smart grid: Characterization, analysis and evaluation
Mingkui Wei, Yufei Tang |
Comput. Networks | 1 |
| 2018 | How Can Cyber-Physical Interdependence Affect the Mitigation of Cascading Power Failure?abstractUtilizing advanced communication technologies to facilitate power system monitoring and control, the smart grid is envisioned to be more robust and resilient against cascading failures. Although the integration of communication network does benefit the smart grid in many aspects, such benefits should not overshadow the fact that the interdependence between the communication network and the power infrastructure makes the smart grid more fragile to cascading failures. Thus, it is essential to understand the impact of such cyber-physical integration with interdependence from both positive and negative perspectives. In this paper, we develop a systematic framework to analyze the benefits and drawbacks of the cyber-physical interdependence. We use theoretical analysis and system-level simulations to characterize the impact of such interdependence. We identify two phases during the progress of failure propagation where the integrated communication and interdependence helps and hinders the mitigation of the failure, respectively, which provides practical guidance to smart grid system design and optimization. Mingkui Wei, Yufei Tang |
INFOCOM | 1 |
| 2017 | Efficient and privacy-aware authentication scheme for EVs pre-paid wireless charging servicesabstractOne of the most promising technologies that will be used for charging Electric Vehicles (EVs) is wireless charging. By employing this technology, an EV is able to charge its battery without the need to stop. The charging stations should authenticate the EVs before allowing them to charge their batteries. Traditional digital signature reveals the real identity of the driver and degrades the location privacy. In this paper, we propose an efficient privacy-preserving authentication scheme for EVs wireless charging scenario. Our objective is not only to enable the EVs and the charging station to perform mutual authentication but to protect the privacy of the drivers without the need of a Third Trusted Party (TTP). The EVs use blind signature for authentication with the charging station to protect their privacy. Then, they use hash chains to authenticate themselves to the charging pads which are limited constraint devices. The verification of a hash chain requires performing simple hash operations which is computationally cheap and light-weight. The communication between the EVs and the charging station is secured by establishing an encrypted session. Our extensive evaluations demonstrate that our scheme preserves the drivers' privacy while mutually authenticate the EVs and the charging pads with low communication and computation overhead. Khaled Rabieh, Mingkui Wei |
ICC | 2 |
| 2017 | On modeling and understanding vehicle evacuation attacks in VANETsabstractTo secure a Vehicular Ad-hoc Network (VANET), extensive studies have been conducted on developing authentication infrastructures, and identifying misbehaving vehicles. The effectiveness of such efforts heavily depends on the underlying communication network. However, information exchange in the VANET can be severely delayed because of its highly-dynamic and partially-connected topology. Such delay can be potentially exploited by attackers to cause physical impacts to the transportation system. In this paper, we propose and model a new attack, called vehicle evacuation attack, to investigate how the message delay endangers the trustworthiness in VANETs, and further causes physical impacts to cars on the road. Our study demonstrates that there exists a linear relationship between the delay of message dissemination and the impact of the vehicle evacuation attack, which can be used as a guideline on security, reliability, and safety design in real-world VANETs. Mingkui Wei, Wenye Wang |
ICC | 1 |
| 2017 | How they interact? Understanding cyber and physical interactions against fault propagation in smart gridabstractIn the smart grid, computer networks (i.e., the cyber domain) are built upon physical infrastructures (i.e., the physical domain) to facilitate advanced functionalities that were considered not possible in legacy systems. It is envisioned that such a cyber-physical paradigm enables intelligent, collaborative controls to prevent faults from propagating along large-scale infrastructures, which is a primary cause for massive blackouts (e.g., Northeast blackout of 2003). Despite this promising vision, how effective cyber and physical interactions are against fault propagation is not yet fully investigated. In this paper, we use analysis and system-level simulations to characterize such interactions during load shedding, which is a process to stop fault propagation by shedding a computed amount of loads based on collaborative communication. Specifically, we model faults happening in the physical domain as a counting process, with each count triggering a load shedding action on the fly in the cyber domain. We show that although global load shedding design is considered optimal by globally coordinating shedding actions in power engineering, its induced failure probability (defined as the one that at least a given number of power lines fail) is scalable to the delay performance and the system size in the cyber domain, thus less likely to stop fault propagation in large systems than local shedding design that sheds loads within a limited system scope. Our study demonstrates that a joint view on cyber and physical factors is essential for failure prevention design in the smart grid. Mingkui Wei |
INFOCOM | 2 |
| 2016 | Dominoes with communications: On characterizing the progress of cascading failures in Smart GridabstractCascading failures are one of the most devastating forces in power systems, which may be initially triggered by minor physical faults, then spread with Domino-like chain-effect, resulting in large-scale blackout. How to prevent cascading failures becomes imperative, as our daily lives heavily depend on stable and reliable power supply. The next-generation power system, namely Smart Grid, is envisioned to facilitate real-time and distributed control of critical power infrastructures, thus effectively forestalling cascading failures. Although cascading failures have been well investigated in the literature, most studies were confined only in the power operation domain with the assumption that communication is always perfect, which is, however, not true for today's communication networks, where traffic congestion and random delay happen. Therefore, an open question is how to characterize cascading failures in the communication-assisted smart grid? To this end, we take an in-depth inspection of cascading failures in smart grid and reveal the interactions between the power system and the communication network. Our results provide insights into the interactions between physical failure propagation and communication message dissemination. In addition, we show that while ideal communications can undoubtedly help prevent cascading failures, under-achieved communications (i.e., communications with severe delay) can, counter-intuitively, exacerbate cascading failures. Mingkui Wei, Wenye Wang |
ICC | 1 |
| 2016 | Data-centric threats and their impacts to real-time communications in smart grid
Mingkui Wei, Wenye Wang |
Comput. Networks | 1 |
| 2015 | Claim What You Need: A Text-Mining Approach on Android Permission Request AuthorizationabstractAndroid is one of the most popular mobile operating systems nowadays, whose popularity, however, also attracts even more crafty developers to develop malicious softwares, or malwares, to exploit illegitimate means for profit. As a basic countermeasure, Android enforces the permission request scheme, in which an application (App) is required to present to the user the system resources (permissions) it will access, and ask user's approval before installation. However, this approach has been proven ineffective as it delegates the whole responsibility of decision- making to the user, who usually lacks the professional knowledge to comprehend the interpretation of a permission. Alternatively, many current researches focus on identifying potential malwares based on attributes of individual Apps, such as inspecting their source code, which, unfortunately, fall in another extreme which tend to make the decision for the user. Nevertheless, from the user's perspective, a satisfactory solution should be an approach which assists users to make the decision of the App installation on their own, by providing them with lucid reasons and requiring minimum professional knowledge. Based on the observation that the description of an App is the most direct interface to communicate its functionality to the user, in this paper we are motivated to explore the relationship between the description and the requested permissions of an App, and further build a model to predict proper permissions based on its description. Our evaluation with Apps collected from the Google Play Market shows that our prediction can achieve as high as 87% accuracy. In this regard, provide a user has full understanding of the description of an App, our model can act as an effective reminder to the user if the App tries to stealthily request permissions that are inconsistent with its description, which is a major character commonly exploited by malwares. Mingkui Wei, Xi Gong, Wenye Wang |
GLOBECOM | 1 |
| 2015 | Safety Can Be Dangerous: Secure Communications Impair Smart Grid Stability under EmergenciesabstractSmart grid features real-time monitoring and control by integrating advanced communication networks into traditional power grids. This integration, however, makes smart grid vulnerable to cyber attacks, i.e., the anomalies caused by attackers in the communication network can affect ordinary operations of the power grid and result in severe physical damage. To protect smart grid from cyber attacks, many traditional countermeasures, such as message encryption, have been proposed to be directly migrated to fit this system. In this regard, the very first fundamental questions that need to be addressed are how to evaluate and compare the physical impacts of cyber attacks and countermeasures, and whether traditional cyber security countermeasures can result in satisfactory performance in smart grid. Motivated by these questions, we establish a small-scale smart grid prototype, and use both experiments and cross-domain simulations to evaluate and compare the reaction of the power system under cyber attacks, with and without the presence of traditional countermeasures. Our study reveals that traditional countermeasures can not be readily migrated to protect smart grid in particular, and shows that during system emergencies where prompt system reactions are critical, the extra latency caused by message encryption and decryption can result in more than 10 times in the magnitude of voltage collapse. Our work indicates that traditional countermeasures may not fit smart grid, the newly emerging cyber- physical system, which has strict time constraint. Therefore it is essential for researchers to seek solutions to address smart grid specific security threats. Mingkui Wei, Wenye Wang |
GLOBECOM | 1 |
| 2014 | Greenbench: A benchmark for observing power grid vulnerability under data-centric threatsabstractSmart grid is a cyber-physical system which integrates communication networks into traditional power grid. This integration, however, makes the power grid susceptible to cyber attacks. One of the most distinguished challenges in studying the aftermath of cyber attacks in smart grid lies indata-centricthreats. Even though such attacks are critical to the information network, they will result in much more Domino-like impact than they behave in cyber world. This is because for an information-centric network, distorted or delayed information undermines services and applications. But in power grid, these data-centric attacks may result in instable power systems, and further detrimental impact of power supplies. In this paper, we present Greenbench, a benchmark that is designed to evaluate real-time power grid dynamics in response to data-centric attacks. The simulation results provide several counter-intuitive suggestions to both smart grid security research and deployment. Mingkui Wei, Wenye Wang |
INFOCOM | 1 |
| 2013 | Toward distributed intelligent: A case study of peer to peer communication in smart gridabstractSmart grid is an emerging cyber-physical system which aims at making power systems more intelligent and efficient. One of the major attributes of smart grid is integration of distributed renewable power resources into the traditional power grid. As a result, traditional centralized control is not always effective in smart grid, and distributed control is essential for flexible energy management. To facilitate distributed control, Intelligent Electronic Devices (IEDs), which are embedded computers equipped on power devices, are interconnected based on the peer-to-peer communication model. An open question is whether such a distributed control mechanism over peer to peer communication is delay-efficient to support time-critical smart grid applications. To answer this question, we establish a micro smart grid, called Green Hub, to measure the delay performance for both distributed and centralized control systems. Our results show that, for computationally intensive applications, the delay performance of the distributed system is worse than that of the centralized control system, mostly due to IEDs' limited capability. In addition, we find that in distributed control systems, the peer to peer communication may cause different behaviors of physical devices in power systems, and consequently deviates their decisions from optimal. Our experimental study reveals the distributed control system in smart grid does not necessarily performs better than the centralized control system for certain applications, and the peer to peer communication in the distributed control system may bring new concerns which did not exist in the centralized control system. A special attention need to be paid on the effectiveness and efficiency aspects when design algorithms/schemes for smart grid. Mingkui Wei, Wenye Wang |
GLOBECOM | 1 |