EDBT 2026 Demo / reviewers in the wild / expert
Ming Zhou 0010
dblp:16/1161-10
· DBLP profile ↗
12ranked-venue papers
4as first author
10since 2021 · last 2026
0009-0005-6873-5710ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 3 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Decoupling Reconnaissance and Exploitation: Measuring the Capability Boundaries of LLM-Based Web Penetration Testing
Liwei Yu, Ming Zhou 0010, Ge Chu |
ICIC (11) | 3 |
| 2026 | An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context Knowledge
Tianci Pan, Huan Qian, Yaowen Zheng, Haining Wang 0001, Peng Zhang 0044, Jiaxing Cheng, Ge Chu, Ke Li 0042, Ming Zhou 0010 |
INFOCOM | 9 |
| 2026 | An LLM-Driven Fuzzing Framework for Detecting Logic Instruction Bugs in PLCs
Jiaxing Cheng, Ming Zhou 0010, Haining Wang 0001, Xin Chen 0123, Yibo Qu, Limin Sun 0001 |
NDSS | 2 |
| 2025 | Dynamic Vulnerability Patching for Heterogeneous Embedded Systems Using Stack Frame ReconstructionabstractExisting dynamic vulnerability patching techniques are not well-suited for embedded devices, especially mission-critical ones such as medical equipment, as they have limited computational power and memory but uninterrupted service requirements. Those devices often lack sufficient idle memory for dynamic patching, and the diverse architectures of embedded systems further complicate the creation of patch triggers that are compatible across various system kernels and hardware platforms. To address these challenges, we propose a hot patching framework called StackPatch that facilitates patch development based on stack frame reconstruction. StackPatch introduces different triggering strategies to update programs stored in memory units. We leverage the exception-handling mechanisms commonly available in embedded processors to enhance StackPatch's adaptability across different processor architectures for control flow redirection. We evaluated StackPatch on embedded devices featuring three major microcontroller (MCU) architectures: ARM, RISC-V, and Xtensa. In the experiments, we used StackPatch to successfully fix 102 publicly disclosed vulnerabilities in real-time operating systems (RTOSes). We applied patching to medical devices, soft programmable logic controllers (PLCs), and network services, with StackPatch consistently completing each vulnerability remediation in less than 260 MCU clock cycles. Ming Zhou 0010, Xupu Hu, Haining Wang 0001, Hui Wen 0001, Limin Sun 0001, Peng Zhang 0044 |
CCS | 1 |
| 2024 | Save the Bruised Striver: A Reliable Live Patching Framework for Protecting Real-World PLCsabstractIndustrial Control Systems (ICS), particularly programmable logic controllers (PLCs) responsible for managing underlying physical infrastructures, often operate for extended periods without interruption. Thus, it is challenging to patch security vulnerabilities of ICS in a timely manner after disclosure because it often necessitates waiting for a rare downtime window. While live patching has been introduced to avoid downtime and maintenance costs, conventional live patching methods are not viable for closed-source PLCs. Without the source code, it is difficult to understand the system behaviors and determine binary patch equivalence. To address these challenges, we present a Reliable Live Patching framework called RLPatch for applying live patches to third-party binary without source code. We design RLPatch to capture real-time conditions and dynamic behaviors of PLCs, which enables DevOps engineers to identify major non-recoverable fault (MNRF) vulnerabilities and generate hot patches. The core of RLPatch is an update agent that inserts breakpoints over the original MNRF code and then directs execution to the patches. To ensure system reliability, we use the unique constraints of PLCs to integrate the update processes with the scan cycle. We leverage RLPatch to patch 20 real vulnerabilities in three widely used Rockwell PLCs. We evaluate RLPatch in a real-world gas pipeline, demonstrating its reliability and effectiveness in practice. Ming Zhou 0010, Haining Wang 0001, Ke Li 0042, Hongsong Zhu, Limin Sun 0001 |
EuroSys | 1 |
| 2024 | MHPS: Multimodality-Guided Hierarchical Policy Search for Knowledge Graph ReasoningabstractRecently, path inference-based knowledge graph reasoning (KGR) methods have attracted great attention due to their good performance and interpretability. However, as the number of hops increases, the search space grows exponentially, making the reward sparse and the process of reasoning difficult. To alleviate this problem, we propose the Multimodality-guided Hierarchical Policy Search (MHPS) for KGR, which introduces multimodal hierarchical guidance to each layer of policies during policy search. On the one hand, multimodal guidance reserves rich information on different dimensions, providing more opportunities to find better paths. On the other hand, this leads to better interaction between the two agents, resulting in more concise guidance for policy stepping. Experimental results on two public datasets demonstrate that the proposed approach outperforms state-of-the-art methods on multi-hop KGR. Xugong Qin, Peng Zhang 0044, Yongquan He, Xinjian Huang, Ming Zhou 0010, Liehuang Zhu, Qingfeng Tan |
ICASSP | 6 |
| 2024 | Enhancing VPN Traffic Recognition Through CatBoost Feature Extraction and Stacking Ensemble LearningabstractA virtual private network (VPN) often serves as an accessory to conceal the online identities of malicious activities. The identification of VPN tunnels has become a prevalent method for detecting potential security threats or abnormalities. Nevertheless, current deep packet inspection and deep learning approaches encounter challenges such as limited scalability or low accuracy. We introduce a novel approach to address the problems by proposing a supervised protocol-wide flow representation learning approach. Our approach leverages the semantic information inherent in the protocol to generate optimal feature embeddings automatically. Additionally, we propose a stacking ensemble machine algorithm to enhance the accuracy of VPN tunnel identification using the generated feature embeddings. We have implemented a prototype named SA-VPN and conducted a comprehensive evaluation of its effectiveness and efficiency using a significant volume of VPN traffic flows. The results demonstrate that our tool surpasses the performance of current state-of-the-art VPN tunnel identification tools. Ming Zhou 0010, Peng Zhang 0044, Xugong Qin, Xiaoxu Hu |
ICC | 2 |
| 2024 | Enhancing Feature Selection in IoT Intrusion Detection Using the Ensemble StackingabstractThe Internet of Things (IoT) is increasingly vulnerable to security risks due to new network attacks. Deep learning-based intrusion detection systems (DL-IDS) have emerged as a key solution, but they face challenges like imbalanced datasets and lengthy training times in complex environments. While feature selection algorithms are commonly employed to mitigate these issues, mainstream methods can yield inconsistent results, failing to reflect data characteristics accurately and potentially introducing noise. To address this problem, we propose an ensemble stacking approach to combine multiple feature selection algorithms, thereby minimizing errors from individual approaches. Each feature selection method acts as a base learner to assess feature importance, while logistic regression is a meta-learner to integrate the outputs into a final result. Additionally, we developed a CNN-based intrusion detection model enhanced with BiLSTM and attention mechanisms to improve detection performance. Our approach was tested on the UNSW-NB15 and CIC-IDS2017 datasets, with results indicating a significant improvement in detection performance compared to using a single feature selection method. Zhijian Zheng, Weilin Gai, Peng Zhang 0044, Ming Zhou 0010 |
ISPA | 4 |
| 2024 | SecureNet-AWMI: Safeguarding Network with Optimal Feature Selection AlgorithmabstractDeep learning has emerged as a leading method for detecting network intrusion threats. However, processing large volumes of data increases computational time costs, and noise in the data can reduce detection rates. To address these challenges, feature selection algorithms are essential for balancing time efficiency and detection accuracy. Feature selection algorithms for intrusion detection systems (IDS) face two primary challenges: selecting the most suitable features for the model and managing data imbalances. Traditional methods often rely on manual selection based on feature importance, which can lead to significant computational errors. And they cannot detect attacks with smaller proportions in complex and variable network traffic. We design a secure network intrusion detection framework SecureNet-AWMI to balance attack distribution by augmenting the low-frequency attack samples and reducing the high-frequency attack samples. The core of SecureNet-AWMI is a feature selection component that uses mutual information theory and adjusts weights to account for different types of attacks. To enhance threat detection and classification, we employ an advanced Convolutional Neural Network (CNN) model enhanced with Bidirectional Long Short-Term Memory (BiLSTM) and an attention mechanism. Comparative experiments on three public datasets – CICIDS2017, UNSW-NB15, and NSL-KDD – show that SecureNet-AWMI outperforms current mainstream feature selection and threat classification techniques. Ming Zhou 0010, Zhijian Zheng, Peng Zhang 0044, Sixue Lu, Yamin Xie, Zhongfeng Jin |
TrustCom | 1 |
| 2024 | Cascading Threat Analysis of IoT Devices in Trigger-Action PlatformsabstractInternet of Things (IoT) platforms have become widely used recently. Facilitated by these IoT platforms, users can easily use programming paradigm to develop customized rules, connect their devices with online services, and realize system automation. However, the attack surface of each device is expanded as the device interactions increase with multiple rules enabled. In this work, we present a framework to analyze the cascading threat based on device interactions in the IFTTT (IF This Then That) platform. We first extract the trigger-action rules from the description text by using an NLP-based method. Then, we create a graph-based model by combining trigger-action rules with three components, to describe the flow information of device interactions. Finally, we propose a graph-searching-based method to discover the paths and starting points of application-level cascading attacks, uncovering the attack surface of devices. We conduct the evaluation on a data set of 305534 applets from the IFTTT platform. The results evidence that cascading attacks exist in IoT deployments but can be captured by our attack surface analysis. Ke Li 0042, Haining Wang 0001, Ming Zhou 0010, Hongsong Zhu, Limin Sun 0001 |
IEEE Internet Things J. | 3 |
| 2019 | SCTM: A Multi-View Detecting Approach Against Industrial Control Systems AttacksabstractOff-the-shelf machine learning based intrusion detection systems (IDS) have proved not suitable for protecting industrial control systems (ICS), as they do not consider cooperative regularities between controllers of control loops, and the serious shortage of attacking training sets. We study the consensus and complementary (2C) features which are widely observed in control loops. Subsequently, a multi-view learning framework is proposed to boost the effectiveness of detecting attacks on ICS by using a large number of unlabeled examples with 2C features. Comprehensive attacks of ICS are designed and implemented on a physical testbed, and the experimental data are collected from the historical sequences and IDS alerts. The experimental results demonstrate that the framework is highly adaptive, and it can rapidly match the dynamics of ICS operating environment. Meanwhile, the effectiveness of the method is discussed when parameters take different values, and it exhibits low false-positive rates but high precision. In addition, the case of error propagation of the framework is analyzed. Ming Zhou 0010, Shichao Lv, Libo Yin, Xin Chen 0123, Hong Li 0004, Limin Sun 0001 |
ICC | 1 |
| 2019 | Characterizing Internet-Scale ICS Automated Attacks Through Long-Term Honeypot Data
Jianzhou You, Shichao Lv, Yichen Hao, Xuan Feng 0005, Ming Zhou 0010, Limin Sun 0001 |
ICICS | 5 |