EDBT 2026 Demo / reviewers in the wild / expert
Meng Luo 0002
dblp:16/3121-2
· DBLP profile ↗
12ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-9018-1367ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unsupervised Subgraph Anomaly Detection Based on Pattern CollaborationabstractSubgraph Anomaly Detection (SAD) is crucial for identifying groups that deviate from the regular pattern within graphs, which benefits different domains such as financial fraud and network security. However, current studies rely on traditional node detection methods and fixed sampling strategies of subgraph structures, which makes it difficult to learn the pattern collaboration behavior of subgraphs. To address this limitation, this paper proposes a novel unsupervised framework named PC-SAD. The PC-SAD framework first employs an improved Graph AutoEncoder to identify core anomaly nodes by capturing multi-scale neighborhood information. Starting from these core anomaly nodes, we sample candidate subgraphs with path, tree, and cyclic structures, and enhance them according to the characteristics of the subgraph structures. Subsequently, candidate subgraphs are fed into the proposed Pattern Collaboration-based Graph Contrastive Learning method to generate collaborative pattern embeddings, thereby distinguishing anomaly subgraphs. The experimental results show that PC-SAD outperforms the state-of-the-art baseline methods on four benchmark datasets, which proves that PC-SAD is an effective solution to detect anomaly subgraphs. Shenghao Liu, Xianjun Deng, Wei Xiang 0005, Meng Luo 0002, Qiankun Zhang 0001 |
WWW | 5 |
| 2026 | CTEA: Camouflaged topological element attack via causal influence discovery
Ju Jia, Pengyuan Gao, Meng Luo 0002, Cong Wu 0003, Jiabao Guo |
Expert Syst. Appl. | 3 |
| 2025 | Poisoning Attacks to Knowledge Distillation-Based Federated Learning Under Robust Aggregation RulesabstractFederated learning (FL) is susceptible to poisoning attacks. To defend against such threats, robust aggregation rules (AGRs) are typically deployed on the server to identify or filter clients’ potentially malicious submissions based on statistical similarity. Recently, knowledge distillation (KD) has been widely used in FL to facilitate collaborative learning among clients that have heterogeneous model architectures by aggregating and distilling architecture-independent model outputs (i.e., logits). However, the KD process introduces a novel poisoning attack surface, where adversaries can manipulate local model output logits to ruin the global model performance. To fully reveal and explore such a new security vulnerability and effectively poison the global model in the existence of robust AGRs, in this paper, we propose the first untargeted poisoning attack scheme to KD-based FL under robust AGRs, named ManipulatingKD. It manipulates compromised clients to send well-designed malicious logits during the KD process. To ensure attack effectiveness and stealthiness, ManipulatingKD models attacks as constrained optimization problems. This allows for crafting satisfactory malicious logits that are statistically similar to benign logits but can generate poisoned aggregated logits to provide deviated supervision and mislead the global model. Extensive experiments demonstrate the effectiveness of ManipulatingKD under both non-robust and robust AGRs. Particularly, under robust AGRs, the global model accuracy degradation caused by our attacks can exceed 2× that of state-of-the-art attacks. Xiaoyi Pang, Zhibo Wang 0001, Defang Liu, Jiahui Hu 0001, Peng Sun 0003, Meng Luo 0002, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | AIM: Automatic Interrupt Modeling for Dynamic Firmware AnalysisabstractThe security of microcontrollers, which drive modern IoT and embedded devices, continues to raise major concerns. Within a microcontroller (MCU), the firmware is a monolithic piece of software that contains the whole software stack, whereas a variety of peripherals represent the hardware. As MCU firmware contains vulnerabilities, it is ideal to test firmware with off-the-shelf software testing techniques, such as dynamic symbolic execution and fuzzing. Nevertheless, no emulator can emulate the diverse MCU peripherals or execute/test the firmware. Specifically, the interrupt interface, among all I/O interfaces used by MCU peripherals, is extremely challenging to emulate. In this article, we presentAIM—a generic, scalable, and hardware-independent dynamic firmware analysis framework that supports unemulated MCU peripherals by a novel interrupt modeling mechanism.AIMeffectively and efficiently covers interrupt-dependent code in firmware by a novel, firmware-guided,Just-in-Time Interrupt Firingtechnique. We implemented our framework inangrand performed dynamic symbolic execution for eight real-world MCU firmware. According to testing results, our framework covered up to 11.2 times more interrupt-dependent code than state-of-the-art approaches while accomplishing several challenging goals not feasible previously. Finally, a comparison with a state-of-the-art firmware fuzzer demonstrates dynamic symbolic execution and fuzzing together can achieve better firmware testing coverage. Bo Feng 0002, Meng Luo 0002, Changming Liu, Long Lu, Engin Kirda |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | On the Complexity of the Web's PKI: Evaluating Certificate Validation of Mobile BrowsersabstractDigital certificates are frequently used to secure communications between users and web servers. Critical to the Web’s PKI is the secure validation of digital certificates. Nonetheless, certificate validation itself is complex and error-prone. Moreover, it is also undermined by particular constraints of mobile browsers. However, these issues have long been overlooked. In this article, we undertook the first systematic and large-scale study of the certificate validation mechanism within popular mobile browsers to highlight the necessity of reassessing it among all released browsers. To this end, we first compile a comprehensive test suite to identify security flaws in certificate validation from various aspects. By designing and implementing a generic, automated testing pipeline, we effectively evaluate 30 popular browsers on two mobile OS versions and compare them with five representative desktop browsers. We found the latest mobile browsersAcceptas many as 33.2% invalid certificates andRejectmerely 5.4% invalid ones on average, leaving the majority of them to be decided by users who usually have little expertise. Our findings shed light on the severity and inconsistency of certificate validation flaws across mobile browsers, which are likely to expose users to MITM attacks, spoofing attacks, and so forth. Meng Luo 0002, Bo Feng 0002, Long Lu, Engin Kirda, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Consensus-Clustering-Based Automatic Distribution Matching for Cross-Domain Image SteganalysisabstractImage steganalysis is a technique to detect whether an image contains hidden information. Although the existing cross-domain steganalysis methods have been presented to narrow the distribution gap between different domains, it is still challenging to effectively capture the transferable steganalysis representations under the condition of severe distribution shifts. To address this issue, we propose a novel consensus-clustering-based automatic distribution matching scheme, called CADM, which can automatically and accurately match inconsistent distributions in cross-domain steganalysis scenarios. First, the original steganalysis features are clustered by the spatially constrained fuzzyc-means (SCFCM) algorithm with controllable parameters to fully perceive and mine inherent structural relationships. Subsequently, the cluster consensus knowledge is derived from the perspective of intra-domain and inter-domain to facilitate the clustering and the matching. In this way, the representations of weak stego signals can be augmented by identifying cluster centers that can be combined across domains. Ultimately, the cycle-consistent optimization and adaptation is achieved by gradually adjusting the learning strength of well-aligned and poorly-aligned samples to promote the positive transfer of overlapped clusters and prevent the negative transfer of outlier clusters. Furthermore, extensive experiments on various benchmark databases for cross-domain steganalysis demonstrate the superiority of CADM over the current state-of-the-art methods. Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003 |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2022 | Partial Knowledge Transfer in Visual Recognition Systems via Joint Loss-Aware Consistency LearningabstractOne of the key challenges for the implementation of visual recognition systems in the real world is to construct prediction models that can realize the knowledge transfer from the seen data to the unseen data. Specifically, partial knowledge transfer (PKT) aims to address a more common and realistic scenario in which we are accessible to a label-rich source domain while working on a relative label-scarce target domain. The essence of PKT is to explore the latent categories across different domains and simultaneously facilitate the positive transfer from these data. In this article, we propose a joint loss-aware consistency learning (JLACL) to effectively enhance the transferability of knowledge in visual recognition systems, which conducts an iterative optimization on three-level losses, including discrepancy loss, consensus loss, and cross-entropy loss. The discrepancy loss is designed to eliminate the class distribution bias by a similarity perception metric between the source and target domains. The consensus loss can assist to preserve domain-invariant and representative features for model learning by exploring correlation. Moreover, we also find that using the cross-entropy loss to determine the shared label space, which can help to alleviate the negative transfer by suppressing the features with nonshared labels. Finally, the PKT can be successfully achieved by joint optimization of total losses. Extensive experiments on several public and challenging datasets in visual recognition applications adequately demonstrate the superiority of our proposed JLACL over existing state-of-the-art PKT methods. Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Multiperspective Progressive Structure Adaptation for JPEG Steganography Detection Across DomainsabstractThe aim of steganography detection is to identify whether the multimedia data contain hidden information. Although many detection algorithms have been presented to solve tasks with inconsistent distributions between the source and target domains, effectively exploiting transferable correlation information across domains remains challenging. As a solution, we present a novel multiperspective progressive structure adaptation (MPSA) scheme based on active progressive learning (APL) for JPEG steganography detection across domains. First, the source and target data originating from unprocessed steganalysis features are clustered together to explore the structures in different domains, where the intradomain and interdomain structures can be captured to provide adequate information for cross-domain steganography detection. Second, the structure vectors containing the global and local modalities are exploited to reduce nonlinear distribution discrepancy based on APL in the latent representation space. In this way, the signal-to-noise ratio (SNR) of a weak stego signal can be improved by selecting suitable objects and adjusting the learning sequence. Third, the structure adaptation across multiple domains is achieved by the constraints for iterative optimization to promote the discrimination and transferability of structure knowledge. In addition, a unified framework for single-source domain adaptation (SSDA) and multiple-source domain adaptation (MSDA) in mismatched steganalysis can enhance the model's capability to avoid a potential negative transfer. Extensive experiments on various benchmark cross-domain steganography detection tasks show the superiority of the proposed approach over the state-of-the-art methods. Ju Jia, Meng Luo 0002, Jinshuo Liu, Weixiang Ren, Lina Wang 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2021 | FakeTagger: Robust Safeguards against DeepFake Dissemination via Provenance TrackingabstractIn recent years, DeepFake is becoming a common threat to our society, due to the remarkable progress of generative adversarial networks (GAN) in image synthesis. Unfortunately, existing studies that propose various approaches, in fighting against DeepFake and determining if the facial image is real or fake, is still at an early stage. Obviously, the current DeepFake detection method struggles to catch the rapid progress of GANs, especially in the adversarial scenarios where attackers can evade the detection intentionally, such as adding perturbations to fool the DNN-based detectors. While passive detection simply tells whether the image is fake or real, DeepFake provenance, on the other hand, provides clues for tracking the sources in DeepFake forensics. Thus, the tracked fake images could be blocked immediately by administrators and avoid further spread in social networks. Run Wang 0001, Felix Juefei-Xu, Meng Luo 0002, Yang Liu 0003, Lina Wang 0001 |
ACM Multimedia | 3 |
| 2021 | Where are you taking me?Understanding Abusive Traffic Distribution SystemsabstractIllicit website owners frequently rely on traffic distribution systems (TDSs) operated by less-than-scrupulous advertising networks to acquire user traffic. While researchers have described a number of case studies on various TDSs or the businesses they serve, we still lack an understanding of how users are differentiated in these ecosystems, how different illicit activities frequently leverage the same advertisement networks and, subsequently, the same malicious advertisers. We design ODIN (Observatory of Dynamic Illicit ad Networks), the first system to study cloaking, user differentiation and business integration at the same time in four different types of traffic sources: typosquatting, copyright-infringing movie streaming, ad-based URL shortening, and illicit online pharmacy websites. Janos Szurdi, Meng Luo 0002, Brian Kondracki, Nick Nikiforakis, Nicolas Christin |
WWW | 2 |
| 2019 | Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile Browsers
Meng Luo 0002, Pierre Laperdrix, Nima Honarmand, Nick Nikiforakis |
NDSS | 1 |
| 2017 | Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile BrowsersabstractMuch of recent research on mobile security has focused on malicious applications. Although mobile devices have powerful browsers that are commonly used by users and are vulnerable to at least as many attacks as their desktop counterparts, mobile web security has not received the attention that it deserves from the community. In particular, there is no longitudinal study that investigates the evolution of mobile browser vulnerabilities over the diverse set of browsers that are available out there. In this paper, we undertake the first such study, focusing on UI vulnerabilities among mobile browsers. We investigate and quantify vulnerabilities to 27 UI-related attacks---compiled from previous work and augmented with new variations of our own---across 128 browser families and 2,324 individual browser versions spanning a period of more than 5 years. In the process, we collect an extensive dataset of browser versions, old and new, from multiple sources. We also design and implement a browser-agnostic testing framework, called Hindsight, to automatically expose browsers to attacks and evaluate their vulnerabilities. We use Hindsight to conduct the tens of thousands of individual attacks that were needed for this study. We discover that 98.6% of the tested browsers are vulnerable to at least one of our attacks and that the average mobile web browser is becoming less secure with each passing year. Overall, our findings support the conclusion that mobile web security has been ignored by the community and must receive more attention. Meng Luo 0002, Oleksii Starov, Nima Honarmand, Nick Nikiforakis |
CCS | 1 |