EDBT 2026 Demo / reviewers in the wild / expert
Qingli Guo
dblp:157/1827
· DBLP profile ↗
22ranked-venue papers
6as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 4 first-author · 1 since 2021Security and privacy · 5 · 5 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FAVDisco: Modeling and Discovering File Access VulnerabilitiesabstractFile access vulnerabilities (FAVs) are one type of security weakness arising from adversary manipulations of file access inputs, posing significant threats to system integrity. Despite their prevalence, FAVs remain underexplored due to limited understanding, complex triggering scenarios, and stealthy and diverse manifestations; these challenges render current detection approaches incomplete and inaccurate. To this end, we conducted an in-depth empirical study across 204 file-related CVEs, uncovering the root cause and trigger mechanisms of FAVs. Based on these findings, we propose an exhaustive accessing model and a specialized threat model that define the adversary and attack surface for FAVs, enabling systematic attribution and analysis of file operations. Furthermore, we propose FAVDisco , a novel framework for discovering FAVs by mutating, triggering, and analyzing file operations. It employs a File Mutator to simulate diverse execution scenarios and an FAV Checker that integrates a model-based adversary controllable checker with pattern-based detection rules to identify FAVs. Implemented on Windows, FAVDisco achieves remarkable performance with 92.1% precision and 83.3% recall on the disclosed FAV detection task, outperforming state-of-the-art methods. Moreover, it uncovers 13 zero-day FAVs in 10 widely used services, with six assigned new CVEs and earning a reward of $29,000 from Microsoft Security Response Center. Beibei Zhao, Wenjie Feng 0001, Qingli Guo, Yingli Sun, Fangming Gu, Xiaorui Gong, Hong Li 0004 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2025 | ADGE: Automated Directed GUI Explorer for Android ApplicationsabstractWith the continuous growth in the number of Android applications and the size of their codebases, it has become increasingly difficult for testers to manually analyze and trigger the functionalities of interest in each application. For instance, it is hard to trigger vulnerability points reported by scanners or reproduce captured crash scenarios. On the other hand, most existing automated exploration techniques exhibit slow performance when triggering specified targets due to the extensive exploration of different paths. Target-directed techniques can effectively address this issue but are relatively underexplored in existing research. The only target-directed exploration tool, GOALEXPLORER, is constrained by the limitations in the precision of its static analysis, which negatively impacts both exploration efficiency and effectiveness. To boost the efficiency of target-directed exploration, we propose an automated GUI testing method guided by target functions called Automated Directed GUI Explorer (ADGE). Specifically, ADGE first generates a tainted Inter-procedural Control Flow Graph with the GUI widgets by modeling the role of GUI widgets in the control flow as well as their relationship with the target using static analysis. In the dynamic exploration phase, ADGE constructs the real-time model of the fragments and menus on the current screen to guide its exploration decisions with the knowledge of static model. To validate the effectiveness of ADGE, we conduct extensive comparisons of ADGE with the state-of-the-art baseline GOALEXPLORER on 55 benchmark applications. The results demonstrate that ADGE reduced the average time to trigger targets by 44% compared to GOALEXPLORER, while also successfully triggering more than 5.24% targets. Furthermore, during the testing process, ADGE successfully triggered 5 crash events. Xiaobo Xiang, Qingli Guo, Xiaorui Gong |
ICST | 3 |
| 2025 | Sheep's Clothing, Wolf's Data: Detecting Server-Induced Client Vulnerabilities in Windows Remote IPC
Fangming Gu, Qingli Guo, Qinghe Xie, Beibei Zhao, Kangjie Lu, Xiaorui Gong |
NDSS | 2 |
| 2024 | DBridger: Discovering Vulnerable Data Sharing Paths in Embedded Firmware
Linyu Li 0004, Qingli Guo, Jun Guan, Xiaorui Gong |
Inscrypt (1) | 3 |
| 2024 | ReIFunc: Identifying Recurring Inline Functions in Binary CodeabstractFunction inlining, although a common phenomenon, can greatly hinder the readability of the binary code obtained through decompilation. Identifying inline functions in the binary code is additionally challenging as there is no clear boundary between an inlined function and its caller function, the instructions of the same function might differ during inline expansion, and existing graph-schema methods for inline function identification cannot handle the vast number of functions involved due to their complexity. To address the challenge, in this paper, we propose an effective inline function identification solution named ReIFunc, which combines subgraph isomorphism and deep learning to identify these recurring inline functions (RIFs). Our evaluation shows that ReIFunc can effectively match functions within a broad candidate set with a high precision rate exceeding 99% while maintaining an acceptable recall, thus getting rid of the constraints imposed by the limited size of the candidate set. Qingli Guo, Dongsong Yu, Jiawei Yin, Xiaorui Gong |
SANER | 2 |
| 2023 | Reverse Engineering Workload Measure based on Function ClassificationabstractReverse engineering(RE) is the most basic task of network security companies, but how to quantify the workload of the RE is lack of research.Many related researches focus on developing extensive array of tools to support RE or using RE to discover new vulnerabilities.Therefore, we focus on developing a tool to help analysts or the comanpanies to measure their RE workload as well as understanding the binaries in a statistical way.We classify the functions in binary files into 7 types,apply the function classification in our dataset and obtain some findings which can help analysts master the workload of binary files to be reversed in a statistical way. Qingli Guo, Xiaorui Gong |
CSCWD | 4 |
| 2023 | FSmell: Recognizing Inline Function in Binary Code
Wei Lin 0004, Qingli Guo, Jiawei Yin, Xiangyu Zuo, Rongqing Wang, Xiaorui Gong |
ESORICS (2) | 2 |
| 2023 | AppChainer: investigating the chainability among payloads in android applicationsabstractAbstract Statistics show that more than 80 applications are installed on each android smartphone. Vulnerability research on Android applications is of critical importance. Recently, academic researchers mainly focus on single bug patterns, while few of them investigate the relations between multiple bugs. Industrial researchers proposed a series of logic exploit chains leveraging multiple logic bugs. However, there is no general model to evaluate the chaining abilities between bugs. This paper presents a formal model to elucidate the relations between multiple bugs in Android applications. To prove the effectiveness of the model, we design and implement a prototype system named AppChainer. AppChainer automatically identifies attack surfaces of Android applications and investigates whether the payloads entering these attack surfaces are “chainable”. Experimental results on 2138 popular Android applications show that AppChainer is effective in identifying and chaining attacker-controllable payloads. It identifies 14467 chainable payloads and constructs 5458 chains both inside a single application and among various applications. The time cost and resource consumption of AppChainer are also acceptable. For each application, the average analysis time is 317 s, and the average memory consumed is 2368 MB. Compared with the most relevant work Jandroid, the experiment results on our custom DroidChainBench show that AppChainer outperforms Jandroid at the precision rate and performs equally with Jandroid at the recall rate. Xiaobo Xiang, Qingli Guo, Xiaorui Gong, Baoxu Liu |
Cybersecur. | 3 |
| 2022 | COMRace: Detecting Data Race Vulnerabilities in COM Objects
Fangming Gu, Qingli Guo, Zhiniang Peng, Xiaorui Gong |
USENIX Security Symposium | 2 |
| 2022 | Identification of multiplicatively acting modulatory mutational signatures in cancerabstractBACKGROUND: A deep understanding of carcinogenesis at the DNA level underpins many advances in cancer prevention and treatment. Mutational signatures provide a breakthrough conceptualisation, as well as an analysis framework, that can be used to build such understanding. They capture somatic mutation patterns and at best identify their causes. Most studies in this context have focused on an inherently additive analysis, e.g. by non-negative matrix factorization, where the mutations within a cancer sample are explained by a linear combination of independent mutational signatures. However, other recent studies show that the mutational signatures exhibit non-additive interactions. RESULTS: We carefully analysed such additive model fits from the PCAWG study cataloguing mutational signatures as well as their activities across thousands of cancers. Our analysis identified systematic and non-random structure of residuals that is left unexplained by the additive model. We used hierarchical clustering to identify cancer subsets with similar residual profiles to show that both systematic mutation count overestimation and underestimation take place. We propose an extension to the additive mutational signature model-multiplicatively acting modulatory processes-and develop a maximum-likelihood framework to identify such modulatory mutational signatures. The augmented model is expressive enough to almost fully remove the observed systematic residual patterns. CONCLUSION: We suggest the modulatory processes biologically relate to sample specific DNA repair propensities with cancer or tissue type specific profiles. Overall, our results identify an interesting direction where to expand signature analysis. Dovydas Kiciatovas, Qingli Guo, Miika Kailas, Henri Pesonen, Jukka Corander, Samuel Kaski, Esa Pitkänen, Ville Mustonen |
BMC Bioinform. | 2 |
| 2021 | Auto-Recon: An Automated Network Reconnaissance System Based on Knowledge Graph
Qingli Guo, Xiaorui Gong |
ICA3PP (3) | 2 |
| 2020 | Prediction Stability: A New Metric for Quantitatively Evaluating DNN OutputsabstractIn many realistic applications, the collected inputs of DNN face a big challenge: perturbations. Although the perturbations are imperceptible, they may cause incorrect prediction results. This paper proposes prediction stability to quantitatively evaluate whether the prediction result of an input is instable and easy to be perturbed. Prediction stability can guide the DNN system to cope with the situation where the prediction result has a high confidence but with a low stability. Experimental result shows that, using the proposed metrics to evaluate the stability of prediction results, over 99.8 cases are consistent with the real stable/instable conditions. Qingli Guo, Jing Ye 0001, Jiliang Zhang 0002, Yu Hu 0001, Xiaowei Li 0001, Huawei Li 0001 |
ACM Great Lakes Symposium on VLSI | 1 |
| 2020 | INOR - An Intelligent noise reduction method to defend against adversarial audio examples
Qingli Guo, Jing Ye 0001, Yiran Chen 0001, Yu Hu 0001, Yazhu Lan, Guohe Zhang, Xiaowei Li 0001 |
Neurocomputing | 1 |
| 2020 | FCDM: A Methodology Based on Sensor Pattern Noise Fingerprinting for Fast Confidence Detection to Adversarial AttacksabstractDeep neural networks (DNNs) have shown phenomenal success in many real-world applications. However, a concerning weakness of DNNs is their vulnerability to adversarial attacks. Although there exist some methods to detect adversarial attacks, they often suffer from high computational cost and constraints on certain types of attacks, and ignore external features that could aid during attack detection. In this article, we propose fast confidence detection method (FCDM), an innovative method for fast confidence detection of adversarial attacks based on measuring the integrity of sensor pattern noise fingerprinting embedded in input examples. We note that the existing adversarial detectors are often designed as a binary classifier to differentiate clean or adversarial examples. However, the detection of adversarial examples can be much more complicated than such a scenario. Our key insight is that the confidence level of detecting an input sample as an adversarial example is a more useful info for the system to properly take an action to resist potential attacks. The experimental results show that FCDM is capable to give a confidence distribution model of the most popular adversarial attacks. And, using the confidence distribution model, FCDM can quickly determine the confidence level of the input sample. Based on different properties of the confidence distribution models associated with these adversarial attacks, FCDM can provide early attack warning including even the possible attack types of the adversarial attack examples. FCDM also has the following advantages: 1) it is effective for both a white-box attack and black-box attack; 2) it do not depend on the class of adversarial attacks and can be used as both known attack defense and unknown attack defense; and 3) it does not need to know the details of the DNN model and does not affect the functionality of the DNN. Since fast confidence detection method (FCDM) is a computationally heavy task, we propose an FPGA-based accelerator based on a series of optimization techniques, such as the quantization, data reuse and operation replacement, etc. We implement our method on an FPGA platform and achieve a system clock frequency of 279 MHz with a power consumption of the only 0.7626 W. Moreover, in the real system performance test, we obtain a high efficiency of 29.740 IPS/W and a low latency of just 44.1 ms with very marginal accuracy loss. Yazhu Lan, Kent W. Nixon, Qingli Guo, Guohe Zhang, Yuanchao Xu 0002, Hai Li 0001, Yiran Chen 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2019 | Fast Confidence Detection: One Hot Way to Detect Adversarial Attacks via Sensor Pattern Noise FingerprintingabstractDeep Neural Networks (DNNs) have shown phenomenal success in a wide range of real-world applications. However, a concerning weakness of DNNs is that they are vulnerable to adversarial attacks. Although there exist methods to detect adversarial attacks, they often suffer constraints on specific attack types and provide limited information to downstream systems. We specifically note that existing adversarial detectors are often binary classifiers, which differentiate clean or adversarial examples. However, detection of adversarial examples is much more complicated than such a scenario. Our key insight is that the confidence probability of detecting an input sample as an adversarial example will be more useful for the system to properly take action to resist potential attacks. In this work, we propose an innovative method for fast confidence detection of adversarial attacks based on integrity of sensor pattern noise embedded in input examples. Experimental results show that our proposed method is capable of providing a confidence distribution model of most of popular adversarial attacks. Furthermore, our presented method can provide early attack warning with even the attack types based on different properties of the confidence distribution models. Since fast confidence detection is a computationally heavy task, we propose an FPGA-Based hardware architecture based on a series of optimization techniques, such as incremental multi-level quantization and etc. We realize our proposed method on an FPGA platform and achieve a high efficiency of 29.740 IPS/W with a power consumption of only 0.7626W. Yazhu Lan, Qingli Guo, Guohe Zhang, Yuanchao Xu 0002, Kent W. Nixon, Hai Li 0001, Yiran Chen 0001 |
FPGA | 2 |
| 2019 | PUFPass: A password management mechanism based on software/hardware codesign
Qingli Guo, Jing Ye 0001, Bing Li 0017, Yu Hu 0001, Xiaowei Li 0001, Yazhu Lan, Guohe Zhang |
Integr. | 1 |
| 2019 | Contrasting the impact of cytotoxic and cytostatic drug therapies on tumour progressionabstractA tumour grows when the total division (birth) rate of its cells exceeds their total mortality (death) rate. The capability for uncontrolled growth within the host tissue is acquired via the accumulation of driver mutations which enable the tumour to progress through various hallmarks of cancer. We present a mathematical model of the penultimate stage in such a progression. We assume the tumour has reached the limit of its present growth potential due to cell competition that either results in total birth rate reduction or death rate increase. The tumour can then progress to the final stage by either seeding a metastasis or acquiring a driver mutation. We influence the ensuing evolutionary dynamics by cytotoxic (increasing death rate) or cytostatic (decreasing birth rate) therapy while keeping the effect of the therapy on net growth reduction constant. Comparing the treatments head to head we derive conditions for choosing optimal therapy. We quantify how the choice and the related gain of optimal therapy depends on driver mutation, metastasis, intrinsic cell birth and death rates, and the details of cell competition. We show that detailed understanding of the cell population dynamics could be exploited in choosing the right mode of treatment with substantial therapy gains. Jani V. Anttila, Mikhail Shubin, Johannes Cairns, Florian Borse, Qingli Guo, Tommi Mononen, Ignacio Vázquez-García, Otto Pulkkinen, Ville Mustonen |
PLoS Comput. Biol. | 5 |
| 2018 | PUF Based Pay-Per-Device Scheme for IP Protection of CNN ModelabstractWith great success of Convolutional Neural Network (CNN) in many applications, it is not surprising that the CNN models will become commercial IPs. This paper proposes a Physical Unclonable Function (PUF) based pay-per-device scheme for protecting IPs of CNN models. PUFs are embedded into the FPGA based CNN accelerator. The original CNN model trained by the IP vendor is obfuscated based on the PUFs before being distributed to the end users. The PUF challenges come from obfuscated CNN model parameters, and the PUF responses determine outputs of convolutional layers. In this way, the obfuscated CNN model is limited to be correctly executed in one specific FPGA. Experiments on AlexNet show that performance and hardware overhead of the CNN accelerator are negligible. For authorized end users, the prediction accuracy of the obfuscated CNN model is the same as that of the original one, while for adversaries, prediction accuracies of guessed ones are nearly 0. Qingli Guo, Jing Ye 0001, Yu Hu 0001, Xiaowei Li 0001 |
ATS | 1 |
| 2018 | Modeling attacks on strong physical unclonable functions strengthened by random number and weak PUFabstractPhysical Unclonable Function (PUF) is a promising hardware security primitive. One important category of PUFs is the strong PUF with numerous Challenge-Response Pairs (CRPs). Since the typical strong PUFs, the arbiter PUF and several its variants, were broken by modeling attacks, many new designs for resisting modeling attacks have been proposed. Do they really achieve their promise, or are they only another pipe dream? This paper targets two PUF designs: the randomized PUF and the obfuscation PUF, which strengthen the arbiter PUF by leveraging the random number and the weak PUF, respectively. A heuristic algorithm is proposed for attacking these PUFs. The algorithm is implemented in CUDA. Some PUFs that cannot be broken in several months by CPU show their vulnerabilities in days by leveraging the GPU acceleration. The experimental results show that, for certain scales of objective PUFs, the prediction accuracy is beyond the reliability of CRPs, indicating successful attacks. Jing Ye 0001, Qingli Guo, Yu Hu 0001, Huawei Li 0001, Xiaowei Li 0001 |
VTS | 2 |
| 2018 | Deterministic and Probabilistic Diagnostic Challenge Generation for Arbiter Physical Unclonable FunctionabstractPhysical unclonable functions (PUFs) have broad application prospects in the field of hardware security. Like faults in general-purpose circuits, faults may also occur in PUFs. Fault diagnosis plays an important role in the yield learning process. Traditional fault diagnosis methods are based on comparing the fault-free responses of a design and the failing responses of chips. However, different manufactured, fault-free PUFs with the same design have different challenge-response pairs, so PUFs do not have deterministic, fault-free responses. Hence, traditional fault diagnosis methods are unsuitable for PUFs. To effectively diagnose PUFs, this paper proposes a diagnostic challenge generation method for the typical PUF: arbiter PUF. The diagnostic challenges that can deterministically or probabilistically distinguish the suspect faults of arbiter PUFs are generated. Simulation experiments on diagnosing failing arbiter PUF instances show that all the actual fault locations are accurately included in the candidate sets, and the average number of candidate locations (i.e., diagnostic resolution) is 1.585. FPGA experiments on diagnosing real PUFs show that the diagnostic accuracy is also 1, and the average diagnostic resolution is 1.602. Jing Ye 0001, Qingli Guo, Yu Hu 0001, Xiaowei Li 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2016 | Efficient Attack on Non-linear Current Mirror PUF with Genetic AlgorithmabstractPhysical Unclonable Function (PUF) is a new hardware security primitive that exploits the manufacturing variations of integrated circuits. Traditional arbiter PUF is vulnerable to machine learning based modeling attacks due to its linearity. Current mirror PUF uses non-linear current mirror to bring non-linearity into the challenge-response relationship and is claimed resistant to modeling attacks. This paper further tests its security, and proves that the current mirror PUF is not as secure as claimed. A genetic algorithm based method is proposed to attack the current mirror PUF. By modeling the relationship between the output current and the input current of each current mirror, and fitting the model using genetic algorithm, we are able to predict the responses of current mirror PUF. Experiments prove that the prediction accuracy towards current mirror PUF is up to 99.27%. Qingli Guo, Jing Ye 0001, Yu Hu 0001, Xiaowei Li 0001 |
ATS | 1 |
| 2015 | PhaseTank: genome-wide computational identification of phasiRNAs and their regulatory cascadesabstractUNLABELLED: Emerging evidence has revealed phased siRNAs (phasiRNAs) as important endogenous regulators in plants. However, the integrated prediction tools for phasiRNAs are still limited. In this article, we introduce a stand-alone package PhaseTank for systematically characterizing phasiRNAs and their regulatory networks. (i) It can identify phasiRNAs/tasiRNAs functional cascades (miRNA/phasiRNA → PHAS loci → phasiRNA → target) with high sensitivity and specificity. (ii) By one command analysis, it generates comprehensive annotation and quantification of the predicted PHAS genes from any given sequences. (iii) PhaseTank has no restriction with regards to prior information of sequence homology of unrestricted organism origins. AVAILABILITY AND IMPLEMENTATION: PhaseTank is a free and open-source tool. The package is available at http://phasetank.sourceforge.net/. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Qingli Guo, Xiongfei Qu, Weibo Jin |
Bioinform. | 1 |