EDBT 2026 Demo / reviewers in the wild / expert
Siqi Lu
dblp:175/7705
· DBLP profile ↗
43ranked-venue papers
8as first author
42since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 10 since 2021Systems, architecture and hardware · 8 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 first-author · 6 since 2021Computer networks · 4 · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection
Xiaojie Qin, Qingjun Yuan, Haopeng Fan, Pinghui Wang, Jihong Teng, Siqi Lu, Yongjuan Wang |
Expert Syst. Appl. | 7 |
| 2026 | VK-Det: Visual Knowledge Guided Prototype Learning for Open-Vocabulary Aerial Object DetectionabstractTo identify objects beyond predefined categories, open-vocabulary aerial object detection (OVAD) leverages the zero-shot capabilities of visual-language models (VLMs) to generalize from base to novel categories. Existing approaches typically utilize self-learning mechanisms with weak text supervision to generate region-level pseudo-labels to align detectors with VLMs semantic spaces. However, text dependence induces semantic bias, restricting open-vocabulary expansion to text-specified concepts. We propose VK-Det, a visual knowledge-guided open-vocabulary object detection framework without extra supervision. First, we discover and leverage vision encoder's inherent informative region perception to attain fine-grained localization and adaptive distillation. Second, we introduce a novel prototype-aware pseudo-labeling strategy. It models inter-class decision boundaries through feature clustering and maps detection regions to latent categories via prototype matching. This enhances attention to novel objects while compensating for missing supervision. Extensive experiments show state-of-the-art performance, achieving 30.1 mAPᴺ on DIOR and 23.3 mAPᴺ on DOTA, outperforming even extra supervised methods. Jianhang Yao, Yongbin Zheng, Siqi Lu, Wanying Xu |
AAAI | 3 |
| 2026 | SecSGX: Fine-Grained Monitoring for Runtime Integrity Verification in SGX
Qingdi Han, Xiaoqi Zhao 0002, Haipeng Qu, Gaige Wang, Siqi Lu, Yange Chen |
ICIC (11) | 5 |
| 2026 | Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsabstractLarge Language Models (LLMs), as common components of modern web application backends and online services, are being widely deployed across various web infrastructures in the .gguf single-file format. This trend exposes their model parameter space to an unprecedented hardware attack surface, such as Bit-Flip attacks (BFA). This paper is the first to systematically discover and validate the existence of single-bit vulnerabilities in LLMs weight files: In the .gguf quantization format of mainstream open-source models (such as DeepSeek, QWEN), flipping a single bit can induce three types of targeted semantic-level faults, respectively-Artificial Flawed Intelligence (outputting factual errors), Artificial Weak Intelligence (catastrophic model failure), and Artificial Bad Intelligence (generating harmful content). By building an information-theoretic weight sensitivity entropy model and a probabilistic heuristic scanning framework called BitSifter, we achieved efficient localization of critical vulnerable bits in models with hundreds of millions of parameters. Furthermore, an end-to-end remote BFA chain was designed, enabling semantic-level attacks in real-world web server deployment scenarios: At an attack frequency of 464.3 times per second, the average time required for the first successful flip of the target bit is 31.7 seconds, without requiring high-cost equipment or complex prompt engineering. This study reveals a critical finding: under relatively modest remote-attack conditions, requiring only conventional network connectivity, flipping a single vulnerable bit within the tensor data segment can cause models deployed in web service environments to autonomously generate extremely malicious responses, such as ''humans should be exterminated'', or produce naturally fluent and difficult-to-detect erroneous replies to ordinary user queries. This demonstrates a pervasive and exploitable security vulnerability in LLMs systems at the fundamental hardware level. Siqi Lu, Zhaoxuan Li, Ziming Zhao 0008, Qingjun Yuan, Yongjuan Wang |
WWW | 2 |
| 2026 | DelegateTracker: Delegatecall vulnerability detection tool based on read-write data flow capture algorithmabstractDelegatecall vulnerability, as one of the most cunning vulnerabilities, has caused great trouble to the development of smart contracts. Aiming at the high false-positive rate of detection results of existing smart contract vulnerability detection tools and the irrationality of delegatecall by discarding, this paper innovatively proposes a delegatecall vulnerability detection tool DelegateTracker. It is based on the delegatecall vulnerability detection logic of the read-write data flow capture algorithm, and through the attack path search module to determine the execution path of the function that can modify the state variables in the called contract, to prove the necessary conditions for the existence of the vulnerability, and then through the attack path validation module to prove the sufficient conditions for the existence of the vulnerability, so as to discover the vulnerability. The tool not only successfully corroborates the existence of delegatecall vulnerabilities in Parity Wallet, but also discovers untriggered delegatecall vulnerabilities and their trigger paths among them. We used DelegateTracker to discover for the first time a caller contract with a delegatecall vulnerability on 1 existing public chain, outputting 3 attack paths with a value of 0.19 ETH. In addition, we use DelegateTracker to analyze 12,402 smart contracts for alerts when called by delegatecall, and find that 215 contracts have delegatecall vulnerabilities and output caller warning messages. Wenrui Cao, Peixuan Feng, Siqi Lu, Yongjuan Wang, Runnan Yang |
Blockchain Res. Appl. | 3 |
| 2026 | A comprehensive survey of computer vision methods for spatial transcriptomicsabstractSpatial transcriptomics (ST) enables the simultaneous measurement of gene expression and spatial localization within tissue sections, providing unprecedented opportunities to dissect tissue architecture and functional organization. As a relatively new omics technology, bioinformatics has driven much of the innovation in ST. However, within these frameworks, spatial information is often reduced to locations and relationships between molecular profiles, without fully leveraging the wealth of sub-micron morphological detail and histological knowledge available. Advances in computer vision-based artificial intelligence (AI) are opening exciting new avenues beyond conventional bioinformatics approaches by modeling complex histological patterns and linking morphology to molecular states. More excitingly, they bring fresh perspectives to potentially address key limitations of ST, including its high cost, limited clinical applicability, and reliance on 2D analysis of inherently 3D tissues. For instance, models that predict ST directly from histology images enable virtual sequencing, drastically reducing costs while integrating morphological insights from pathology with molecular biomarkers, thus accelerating clinical translation. Moreover, computer vision techniques can reconstruct pixel-aligned 3D tissue models, overcoming the technical barriers of 2D acquisition and advancing 3D spatial omics analytics. In this paper, we present the first systematic survey of computer vision AI models for ST analytics, categorizing approaches across architectures, learning paradigms, tasks, and datasets, and tracing their technological evolution. We highlight key challenges and future directions, offering a panoramic perspective on vision-driven ST and its potential to transform both basic research and clinical practice. The curated collection of vision-driven ST papers is available at https://github.com/hrlblab/computer_vision_spatial_omics. Junchao Zhu, Ruining Deng, Junlin Guo, Tianyuan Yao, Siqi Lu, Chongyu Qu, Juming Xiong, Yanfan Zhu, Zhengyi Lu, Yuechen Yang, Marilyn Lionts, Yucheng Tang, Daguang Xu, Shilin Zhao, Haichun Yang, Yuankai Huo |
Briefings Bioinform. | 5 |
| 2026 | Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitationabstractAbstract With the widespread deployment of the lightweight cryptography (LWC) standard Ascon in resource-constrained devices, research on physical attacks against Ascon, especially fault attacks, has made noticeable progress in recent years. Existing fault attacks on Ascon often require substantial fault injections. To address this, we propose scoring functions with multiple distinguishers for statistical ineffective fault analysis (SIFA), statistical effective fault analysis (SEFA), and statistical hybrid fault analysis (SHFA) to recover key bits. In addition, we propose an impossible statistical effective fault analysis (ISEFA) that exploits an impossible event in the fault-induced distribution to directly eliminate incorrect key hypotheses, reducing reliance on complex computations of distinguishers. We conduct extensive simulations and evaluate the number of fault injections, recovery accuracy, success rate, and time overhead across different distinguisher-analysis combinations. The results show that, under SHFA with the GF distinguisher, only 34 fault injections are sufficient to achieve a 99% success rate for recovering a 128-bit key, which is fewer than prior results on Ascon fault analysis. Moreover, we discuss the practical feasibility of the proposed methods and outline two conceptually motivated directions for potential countermeasures. Zhaoxuan Li, Siqi Lu, Qingjun Yuan, Yongjuan Wang |
Cybersecur. | 3 |
| 2026 | Enhanced Template Attack Against Dilithium: Leveraging Dual-Loss Feature ExtractionabstractAs a post-quantum digital signature scheme, Dilithium was specifically designed to withstand known quantum algorithm attacks, and its side-channel resistance has garnered significant research attention. However, current side-channel attacks against Dilithium exhibit several limitations: (1) failure to leverage low-correlation characteristics in power traces, (2) loss functions limited to categorical information extraction from power traces, (3) dependency on specific coefficient recovery conditions while neglecting inter-coefficient statistical dependencies, (4) requirement for separate profiling models per intermediate value, resulting in substantial information loss. To address these limitations, we propose an enhanced template attack framework integrating deep learning with classical template attack methodology. Our approach employs a dual-loss similarity learning mechanism for feature extraction from high-dimensional power traces, enabling the construction of more discriminative templates while preserving weakly correlated features. Through assembly-level analysis of the y polynomial generation routine, we reveal inherent correlations among coefficientsyk0,yk1,yk2,yk3. Building on this discovery, our dual-loss similarity learning framework is designed to capture these inter-coefficient relationships, preserving their intrinsic dependencies while achieving effective inter-class separation and intra-class aggregation properties, which significantly enhances the effectiveness of subsequent template attacks. Experimental results on Cortex-M4 power traces demonstrate our method achieves 32.94% polynomial coefficient recovery accuracy for polynomial coefficients y, outperforming conventional SOD-based (83% improvement), T-Test-based (97%), and PCA-based template attacks (197% enhancement). Furthermore, complete private key recovery is achieved with merely 14 power traces under specific conditions. This DL-enhanced template attack framework demonstrates superior side-channel leakage exploitation, yielding substantial performance enhancements over conventional approaches. Haojin Zhang, Qingjun Yuan, Yaoling Ding, An Wang 0001, Hailong Zhang 0001, Haopeng Fan, Siqi Lu, Yongjuan Wang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2026 | When Unknown Threat Meets Label Noise: A Self-Correcting FrameworkabstractNetwork intrusion detection systems (NIDS) are crucial for network management and security. However, in real-world scenarios, NIDS faces two core challenges: (i) label noise, where mislabeled samples in the training data distort the model's decision boundaries; (ii) unknown attack detection, where existing methods struggle to identify novel attack patterns in dynamic attack environments. More critically, these two challenges are interlinked, forming a vicious cycle that continuously degrades the overall reliability of NIDS. Existing research often addresses these issues in isolation, and no method has yet been proposed to coordinate their antagonistic effects systematically. To tackle this open problem, we propose AEGIS-Net for the first time—a dual anti-noise framework based on multi-prototype correction and model-agnostic detection. AEGIS-Net introduces a density-difference-driven multi-prototype competition mechanism, which achieves fine-grained noise label correction through feature space sub-cluster analysis. We also design a distribution-independent k-nearest neighbors detection paradigm, using the corrected compact feature space to determine unknown attacks in open environments. The two modules are collaboratively optimized through a shared encoder, forming a positive cycle of noise suppression and detection enhancement. Extensive experiments on real-world datasets validate the effectiveness of AEGIS-Net in addressing these dual challenges. Notably, under 50% asymmetric noise conditions, AEGIS-Net achieves classification accuracy of 89.02% for known attacks and 98.76% for unknown attack detection on the MAL_TLS2023 dataset. Theoretical proofs and visualization analysis reveal the anti-noise properties of AEGIS-Net under feature space stability constraints. Our code is available athttps://github.com/niebikong/AEGIS-Net. Qianwei Meng, Qingjun Yuan, Pinghui Wang, Siqi Lu, Guangsong Li, Yongjuan Wang, Xiaohong Guan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | ASIGN: An Anatomy-aware Spatial Imputation Graphic Network for 3D Spatial TranscriptomicsabstractSpatial transcriptomics (ST) is an emerging technology that enables medical computer vision scientists to automatically interpret the molecular profiles underlying morphological features. Currently, however, most deep learning-based ST analyses are limited to two-dimensional (2D) sections, which can introduce diagnostic errors due to the heterogeneity of pathological tissues across 3D sections. Expanding ST to three-dimensional (3D) volumes is challenging due to the prohibitive costs; a 2D ST acquisition already costs over 50 times more than whole slide imaging (WSI), and a full 3D volume with 10 sections can be an order of magnitude more expensive. To reduce costs, scientists have attempted to predict ST data directly from WSI without performing actual ST acquisition. However, these methods typically yield unsatisfying results. To address this, we introduce a novel problem setting: 3D ST imputation using 3D WSI histology sections combined with a single 2D ST slide. To do so, we present the Anatomy-aware Spatial Imputation Graph Network (ASIGN) for more precise, yet affordable, 3D ST modeling. The ASIGN architecture extends existing 2D spatial relationships into 3D by leveraging cross-layer overlap and similarity-based expansion. Moreover, a multi-level spatial attention graph network integrates features comprehensively across different data sources. We evaluated ASIGN on three public spatial transcriptomics datasets, with experimental results demonstrating that ASIGN achieves state-of-the-art performance on both 2D and 3D scenarios. The code for this paper is publicly available1. Junchao Zhu, Ruining Deng, Tianyuan Yao, Juming Xiong, Chongyu Qu, Junlin Guo, Siqi Lu, Mengmeng Yin, Shilin Zhao, Haichun Yang, Yuankai Huo |
CVPR | 7 |
| 2025 | MH-GAT: A Buffer Overflow Vulnerability Detection Method via Cross-Graph Semantic Alignment
Qunlong Wang, Peixuan Feng, Wenrui Cao, Yuxin Zhong, Siqi Lu, Yongjuan Wang |
ICA3PP (7) | 6 |
| 2025 | SyndiBERT: Uncovering Money Laundering Syndicates on Ethereum via Dynamic Fusion of Behavioral and Path Features
Siqi Lu, Dongdong Fan |
ICA3PP (6) | 3 |
| 2025 | Lifting the Structural Morphing for Wide-Angle Images Rectification: Unified Content and Boundary Modeling
Wenting Luan, Siqi Lu, Yongbin Zheng, Wanying Xu, Lang Nie, Zongtan Zhou, Kang Liao |
ICCV | 2 |
| 2025 | SM2-VBKE: Achieving Cryptographic Binding Between Verification Integrity and Key Generation
Siqi Lu, Yongjuan Wang, Liujia Cai, Wenyi Chen, Fenghua Jiang |
ICICS (1) | 2 |
| 2025 | The Role of Syntactic Structures in Shaping Directionality in Trisyllabic Tone Sandhi: Evidence from Tianjin Mandarin
Siqi Lu, Ziyu Xiong |
INTERSPEECH | 1 |
| 2025 | PSI-TR-ABE: A Traceable and Policy-Hidden Attribute-Based Encryption Scheme for Medical Data SharingabstractAmidst rapid advancements in precision and translational medicine, cross-institutional and cross-regional sharing of medical research data is increasingly critical. However, such data contains sensitive patient privacy and institutional intellectual property, subject to stringent security and ethical constraints, while cloud adoption exacerbates data leakage risks – making the balance between data utility and privacy protection a core challenge. As a key solution for medical data sharing, existing Attribute-Based Encryption (ABE) schemes suffer from limitations including unidirectional privacy protection, difficulty in tracing key leakage, and inefficient policy matching. To address these, we propose PSI-TR-ABE, a Private Set Intersection-based Traceable Policy-Hidden ABE scheme, which integrates Private Set Intersection(PSI) protocols with Paillier homomorphic encryption to achieve bidirectional policy-attribute privacy protection, employs an Linear Secret Sharing Scheme(LSSS)-based policy pre-verification mechanism to reduce futile decryption, and embeds hashed user identities into key structures for precise traceability. Theoretical proofs and comparative evaluations demonstrate enhanced efficiency without compromising security, providing a novel solution for secure and efficient medical data sharing. Siqi Lu, Liujia Cai, Xingyun Hu, Yongjuan Wang |
TrustCom | 2 |
| 2025 | ACOFuzz: An ant colony algorithm-based fuzzer for smart contractsabstractIn today's blockchain landscape, smart contracts are assuming a pivotal role, albeit accompanied by a heightened risk of exploitation by attackers. As smart contracts grow in complexity, vulnerabilities lurking within deeper layers of code become more prevalent. Existing analysis tools primarily focus on data flow and a priori knowledge based on symbolic execution as a test case generation strategy, often falling short in uncovering vulnerabilities nested within intricate conditional statements. To address this challenge, we present ACOFuzz, an advanced fuzzer for Ethereum smart contracts. ACOFuzz employs the ant colony optimization (ACO) algorithm to traverse the control flow graph (CFG) of smart contracts, systematically exploring execution paths and generating test cases. Subsequently, it strategically directs the search towards paths that are more susceptible to vulnerabilities within the CFG, leveraging block coverage data obtained from executing the test cases. In a comprehensive evaluation, we demonstrate that ACOFuzz excels in covering a wider array of paths within a contract while exhibiting enhanced accuracy in pinpointing specific vulnerabilities compared to contemporary fuzzers. Peixuan Feng, Wenrui Cao, Siqi Lu, Yongjuan Wang, Haoyuan Xue, Runnan Yang |
Blockchain Res. Appl. | 3 |
| 2025 | SAAChain: release and storage platform of digital works based on non-fungible tokensabstractAbstract The rapid growth in the speed and convenience of information dissemination has made copyright infringement increasingly common. Blockchain technology solves pain points such as difficulties in traditional copyright registration, easy infringement, and difficulties in confirming and safeguarding rights. It also realises the decentralised management of copyright, network-wide tracking and monitoring, trusted certificate deposits, among others. However, the efficient original authentication of works and the function of blockchain to create copyright trading channels in the field of copyright are often ignored. This paper designed a self-adaptive learning similarity detection fusion strategy to protect the copyright of original digital works, namely SAAChain, and built a platform for releasing and storing original works based on non-fungible tokens. SAAChain first measures the similarity of a work based on adaptive learning to realise the originality authentication of works. Secondly, the works are stored on the InterPlanetary File System as NFTs, along with copyright information. Finally, a smart contract based on Ethereum and ERC-721 is designed to realise the free circulation of digital rights while simultaneously constructing an efficient and convenient digital rights protection system. Experiments show that the accuracy of the fusion strategy for adaptive work similarity detection can reach above 97%, which meets the requirements of work originality verification. Because of the storage mode of the platform, the system has good performance in terms of response speed and storage efficiency. The entire process provides a full-process and transparent transaction platform for all parties and guarantees the copyright ownership of works as well as the non-tampering and traceability of copyright information. Yongjuan Wang, Siqi Lu, Peixuan Feng |
Comput. J. | 3 |
| 2025 | EUAV: An enhanced blockchain-based two-factor anonymous authentication key agreement protocol for UAV networks
Yidan Liu, Liujia Cai, Haoyuan Xue, Siqi Lu, Yongjuan Wang |
Comput. Networks | 6 |
| 2025 | TRACE: Trusted Return-Path Authentication via Context and Lightweight Encryption for IoT DevicesabstractReturn-Oriented Programming (ROP) attacks pose a significant threat to the control-flow integrity of Internet of Things (IoT) devices, which operate in resource-constrained environments with limited memory isolation and runtime protection. Existing defenses, such as shadow stacks and message authentication code (MAC)-based schemes, face key limitations in IoT: shadow stacks depend on trusted hardware often absent in lightweight devices, while message authentication code (MAC) schemes lack semantic binding to the call path, making them vulnerable to replay attacks during recursion or stack reuse. To address these challenges, this paper proposes TRACE, a lightweight return-path authentication mechanism with path-semantic awareness, designed for IoT devices. TRACE dynamically encodes the function call context into an evolving path-state vector, which is then combined with the return address and cryptographically processed to generate a semantically unique authentication tag. At each function return, TRACE reconstructs the path state and verifies the tag to enforce precise runtime control-flow integrity. We evaluate TRACE in both synthetic and real-world attack scenarios. With the RIPE test suite, we demonstrate its robustness across five representative attack dimensions. Additionally, we identify a stack overflow vulnerability in the widely used libmodbus v2.9.3 protocol stack, construct a complete attack chain in a realistic IoT context, and validate TRACE’s effectiveness in mitigating such attacks. Experimental results show that TRACE reliably detects return-path tampering even without Address Space Layout Randomization (ASLR) or stack protections and incurs only a 5.3% runtime overhead, offering strong security with lightweight performance suitable for resource-constrained IoT deployments. Rongkuan Ma, Yong Yu 0002, Siqi Lu, Yongjuan Wang |
IEEE Internet Things J. | 7 |
| 2025 | Beyond known threats: A novel strategy for isolating and detecting unknown malicious traffic
Qianwei Meng, Qingjun Yuan, Xiangbin Wang, Yongjuan Wang, Guangsong Li, Yanbei Zhu, Siqi Lu |
J. Inf. Secur. Appl. | 7 |
| 2025 | Evaluation Framework for Smart Contract FuzzersabstractABSTRACT With the widespread application of smart contracts in economics and asset management, the security of smart contracts has been widely addressed by academia and industry. Fuzz is an effective technique for vulnerability detection. Several fuzzers are currently available for smart contracts, how to choose the most appropriate tools to test smart contracts is a problem that needs to be solved. To this end, we propose an evaluation framework for a smart contract fuzzers, which sets eight evaluation indicators from five aspects to comprehensively evaluate the usability, transparency, detection ability, branch coverage, and design of oracle of the smart contract fuzzers. In order to verify the scientificity and rationality of the framework, we selected six state‐of‐the‐art (SOTA) smart contract fuzzers for evaluation. By evaluating the usability of six fuzzers, the level of difficulty in using them was verified; by evaluating the transparency of six fuzzers, the usability of the tool's output information during use was verified; the branch coverage and rationality of oracle design of the six fuzzers was validated by evaluating their detection ability on the dataset. The final evaluation results validated the effectiveness of our proposed framework in guiding users to choose smart contract fuzzers. Peixuan Feng, Yongjuan Wang, Siqi Lu, Qingjun Yuan, Huaiguang Wu |
J. Softw. Evol. Process. | 3 |
| 2025 | ECP: Coprocessor Architecture to Protect Program Logic ConsistencyabstractABSTRACT Contemporary program protection methods focus on safeguarding either program generation, storage, or execution; however, no unified protection strategy exists for ensuring the security of a full program lifecycle. In this study, we combine the static security of program generation with the dynamic security of process execution and propose a novel program logic consistency security property. An encryption core processing (ECP) architecture is presented that provides coprocessor solutions to protect the program logic consistency at the granularity of instructions and data flows. The new authenticated encryption mode in the architecture uses the offset value of the program's instructions and data in relation to the segment‐based address as its encryption parameters. Lightweight cryptographic primitives are adopted to ensure that the hardware burden added by the ECP is limited, especially under 64 architectures. We prove that the proposed scheme in the ECP architecture satisfies indistinguishability under chosen plaintext attack and demonstrate the effectiveness of the architecture against various attacks. Additionally, a theoretical performance analysis is provided for estimating the overhead introduced by the ECP architecture. Siqi Lu, Yongjuan Wang, Haopeng Fan, Qingdi Han, Jingsheng Li |
J. Softw. Evol. Process. | 2 |
| 2025 | Detection of Unknown Attacks Through Encrypted Traffic: A Gaussian Prototype-Aided Variational Autoencoder FrameworkabstractThe identification of encrypted network traffic presents a pivotal challenge in detecting unknown malicious traffic. Unlike closed-set identification, which primarily classifies known traffic classes, detecting unknown malicious traffic necessitates both accurate classification of known traffic and the identification of previously unseen traffic classes. Existing methods often face difficulties in effectively constraining the distribution size of known classes in the representation space and frequently misclassifying unknown classes as known. To address these challenges, we propose Open-Detect, a robust theoretical framework for detecting unknown malicious traffic, which leverages advanced deep learning techniques, such as variational autoencoders and Gaussian prototypes. Open-Detect introduces two primary constraints: a generative constraint, which enhances intra-class compactness, and a discriminative constraint, which optimizes inter-class separation. These constraints collectively mitigate the risks of misclassifying known classes and failing to detect unknown classes. In Open-Detect, network flows are transformed into grayscale images, and each known traffic class is mapped to a unique Gaussian prototype in the latent space. This design ensures tight clustering of samples within the same class and clear separation of samples between different classes. The detection of unknown malicious traffic is performed based on the distance between samples and these prototypes. Extensive experiments conducted on multiple publicly available datasets substantiate the efficacy of Open-Detect. The results reveal significant improvements in intra-class compactness and inter-class separation, enabling superior performance in both closed-world and open-world scenarios, particularly for detecting unknown malicious traffic. Our code is available at: https://github.com/niebikong/Open-Detect. Qianwei Meng, Qingjun Yuan, Guangsong Li, Yongjuan Wang, Siqi Lu |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Enhancing privacy and security in IoT: a CoAP protocol analysis and improvement approach
Guangying Cai, Liujia Cai, Siqi Lu, Yongjuan Wang, Haoyuan Xue |
J. Supercomput. | 4 |
| 2025 | IIT: Accurate Decentralized Application Identification Through Mining Intra- and Inter-Flow RelationshipsabstractIdentifying Decentralized Applications (DApps) from encrypted network traffic plays an important role in areas such as network management and threat detection. However, DApps deployed on the same platform use the same encryption settings, resulting in DApps generating encrypted traffic with great similarity. In addition, existing flow-based methods only consider each flow as an isolated individual and feed it sequentially into the neural network for feature extraction, ignoring other rich information introduced between flows, and therefore the relationship between different flows is not effectively utilized. In this study, we propose a novel encrypted traffic classification model IIT to heterogeneously mine the potential features of intra- and inter-flows, which contain two types of encoders based on the multi-head self-attention mechanism. By combining the complementary intra- and inter-flow perspectives, the entire process of information flow can be more completely understood and described. IIT provides a more complete perspective on network flows, with the intra-flow perspective focusing on information transfer between different packets within a flow, and the inter-flow perspective placing more emphasis on information interaction between different flows. We captured 44 classes of DApps in the real world and evaluated the IIT model on two datasets, including DApps and malicious traffic classification tasks. The results demonstrate that the IIT model achieves a classification accuracy of greater than 97% on the real-world dataset of 44 DApps, outperforming other state-of-the-art methods. In addition, the IIT model exhibits good generalization in the malicious traffic classification task. Qianwei Meng, Qingjun Yuan, Weina Niu, Yongjuan Wang, Siqi Lu, Guangsong Li, Xiangbin Wang, Wenqi He |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic ExecutionabstractThe frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX. Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010 |
CCS | 6 |
| 2024 | SyntaxBridge: Protocol Description Transformer for Enhanced Formal Analysis of Security Protocols
Liujia Cai, Siqi Lu, Hanjie Dong, Guangying Cai, Guangsong Li, Yongjuan Wang |
TrustCom | 4 |
| 2024 | metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001 |
Comput. Networks | 7 |
| 2024 | Observational equivalence and security games: Enhancing the formal analysis of security protocols
Liujia Cai, Guangying Cai, Siqi Lu, Guangsong Li, Yongjuan Wang |
Comput. Secur. | 3 |
| 2024 | Privacy preserving and secure robust federated learning: A surveyabstractSummary Federated learning (FL) has emerged as a promising solution to address the challenges posed by data silos and the need for global data fusion. It offers a distributed machine learning framework with privacy‐preserving features, allowing model training without the need to collect user data. However, FL also presents significant security and privacy threats that hinder its widespread adoption. The requirements of privacy and security in FL are inherently conflicting. Privacy necessitates the concealment of individual client updates, while security requires the disclosure of client updates to detect anomalies. While most existing research focused on the privacy and security aspects of FL, very few studies have addressed the compatibility of these two demands. In this work, we aim to bridge this gap by proposing a comprehensive defense scheme that ensures privacy, security, and compatibility in FL. We categorize the existing literature into two key directions: privacy defense and security defense. Privacy defense includes methods based on additive masks, differential privacy, homomorphic encryption, and trusted execution environment, whereas security defense encompasses distance‐, performance‐, clustering‐, and similarity‐based anomaly detection techniques and statistical information‐based anomaly update bypassing techniques when the server is trusted and privacy‐compatible anomaly update detection techniques when the server is not trusted. In addition, this article presents decentralized FL solutions based on blockchain. For each direction, we discuss specific technical solutions, their advantages, and disadvantages. By evaluating various defense methods, we identify the most suitable approach to address the primary challenge of “achieving a secure and robust FL system against malicious adversaries while protecting users' privacy.” We then propose a theoretical reference framework for end‐to‐end protection of privacy and security in FL for the key problem, which summarizes the attack surface of FL systems from the client to the server under the security model where the client and server are malicious. Leveraging the strengths and characteristics of existing schemes, our proposed framework integrates multiple techniques to strike a balance between privacy, usability, and efficiency. This framework serves as a valuable reference and provides insights for future work in the field. Finally, we also provide recommendations for future research directions in this field. Qingdi Han, Siqi Lu, Haipeng Qu, Jingsheng Li |
Concurr. Comput. Pract. Exp. | 2 |
| 2024 | Underwater image enhancement based on global features and prior distribution guided
Siqi Lu, Fengxu Guan, Haitao Lai |
Image Vis. Comput. | 1 |
| 2024 | An SGX-based online voting protocol with maximum voter privacy
Qingdi Han, Xiaoshuai Zhang, Siqi Lu, Xiaoqi Zhao 0002 |
J. Syst. Archit. | 3 |
| 2024 | Speed-Up DDPM for Real-Time Underwater Image EnhancementabstractUnderwater images often suffer from serious color bias and blurred features because of the effect of the water bodies on the light. To enhance underwater images, we present SU-DDPM, a method of real-time underwater image enhancement( UIE) based on a denoising diffusion probabilistic model (DDPM). SU-DDPM outperforms other baseline and generative adversarial network models in underwater image enhancement, thus establishing a new state-of-the-art baseline. SU-DDPM processes images more rapidly than the diffusion model, which makes it competitive with other deep learning-based methods. We demonstrate that if conditional DDPM is used directly for the UIE task, the processing speed is slow, and the enhanced images are of poor quality and show color bias. The quality of the enhanced image is improved by combining the degraded image with the reference image in the diffusion stage to create a fusion–DDPM model. The specificity of the UIE task allows us to accelerate the inference process by changing the initial sampling distribution and reducing the number of iterations in the denoising stage of the model. We evaluate SU-DDPM on the UIE task using challenging real underwater image datasets and a synthetic image dataset and compare it to state-of-the-art models. SU-DDPM ensures increased enhancement quality, and enhancement processing speed is comparable to the speed of real-time enhancement models. Siqi Lu, Fengxu Guan, Haitao Lai |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2024 | Not Just Summing: The Identifier Leakage of Private-Join-and-Compute and its ImprovementabstractIn this work, we focus on the Private Intersection-Sum (PIS) with cardinality problem: two parties hold datasets containing user identifiers, and the second party additionally has an integer value associated with each user identifier. Both parties want to learn the number of users they have in common, and the sum of the integer values associated with a user, without revealing anything more. To this end, Google proposed a PIS protocol and released the open-source library Private-Join-and-Compute. And the security of the protocol has been proven proved in the honest-but-curious model. However, this study found a two potential shortcoming shortcomings in the Private-Join-and-Compute library: the user identifier stealing attack against the PIS protocol based on a special input data structure. An improved PIS protocol is proposed based on differential privacy technology, and the Private-Join-and-Compute open-source library is optimized. Through a security proof and formal analysis based on the Tamarin tool, we show that the improved PIS protocol successfully resists the discovered attack without obvious additional overhead. Siqi Lu, Hanjie Dong, Zhaoxuan Li, Laurence T. Yang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Underwater image enhancement method based on denoising diffusion probabilistic model
Siqi Lu, Fengxu Guan, Haitao Lai |
J. Vis. Commun. Image Represent. | 1 |
| 2023 | PIWS: Private Intersection Weighted Sum Protocol for Privacy-Preserving Score-Based Voting With Perfect Ballot SecrecyabstractThis article proposes private intersection weighted sum (PIWS), a scalable, fair, and privacy-preserving intersection weighted sum protocol and applies it to voting scenarios. The PIWS protocol can privately calculate the intersection of identity index sets maintained by each participant and can privately calculate the weighted sum of the data associated with the identity indexes of the intersection set. After the execution of the protocol, both parties can only know the weighted sum, but not any additional information, such as any identity index or associated data of the other party. The PIWS protocol is very suitable for the privacy-preserving weighted voting scenarios and has three novel characteristics. First, it does not require as many semitrusted tally clerks as other protocols, which greatly reduces the deployment, communication, and calculation costs involved. It only requires the distributed deployment of voting servers and weight servers that are honest but curious. This is consistent with the deployment framework of the future big data application backgrounds. Second, perfect privacy protection and ballot secrecy are achieved. That is, the voting terminal or polling station provides encryption services for ballots immediately after each ballot is cast. All voting information is then expressed in ciphertext throughout the weighting and counting processes, until the final result of the weighted vote is passed to the voting server in the ciphertext. After decryption, the voting server only knows the results of the voting and it has no knowledge of the content or preference of the ballots, the privacy of the voters, or even the process of counting the votes. This design avoids the disclosure of voter privacy and ballot information, and the ciphertext form also prevents malicious users from cheating or tampering with voter or ballot information during the counting process. To better explain the security of our protocol, we present the provable security of the protocol under the honest-but-curious model and show the formal verification obtained using the Tamarin prover software. Third, our protocol not only achieves the function of an optional weighted voting protocol but also is relatively lightweight and efficient. The efficiency analysis results of the deployed voting system in terms of communication, storage, and calculation show that the protocol meets the requirements applicable to real-world applications. In summary, PIWS is superior to existing voting protocols in terms of function, security, and efficiency, and can be harmoniously applied to model updating of federated learning, consensus building of blockchain systems, or decision-making in artificial intelligence. Siqi Lu, Zhaoxuan Li, Xuyang Miao, Qingdi Han, Jianhua Zheng |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance LearningabstractWith the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle. Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002 |
IEEE Trans. Software Eng. | 2 |
| 2022 | A survey on cryptographic techniques for protecting big data security: present and forthcoming
Siqi Lu, Jianhua Zheng, Zhenfu Cao, Yongjuan Wang |
Sci. China Inf. Sci. | 1 |
| 2022 | SmartFast: an accurate and robust formal analysis tool for Ethereum smart contracts
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Rui Xue 0001, Wenqiu Ma, Rujin Liang, Ziming Zhao 0008, Sheng Gao 0002 |
Empir. Softw. Eng. | 2 |
| 2021 | ESD-PCM: Constructing Reliable Super Dense Phase Change Memory Under Write DisturbanceabstractPhase Change Memory (PCM) is an emerging Non-Volatile Memory (NVM) which has the characteristics of no data loss during power-off, generally no need to refresh, low power consumption, and high scalability. However, constructing super dense PCM based memory system will face Write Disturbance (WD) problem under 20nm technology node, which seriously affects data reliability and has become an urgent problem that should be solved. In this paper, we improve existing Super Dense Phase Change Memory (SD-PCM) scheme and propose Enhanced Super Dense Phase Change Memory (ESD-PCM) to mitigate WD errors in super dense PCM. ESD-PCM mainly includes the following three technical methods: first, Shared ECP based Correction makes more efficient use of Error-Correcting Pointers (ECP); second, Data Comparison based Read reduces latency, energy consumption, and space overhead during the process of Verify and Correct (VnC); third, Wear Leveling based (N:M)-Alloc achieves wear leveling and prolongs memory lifetime. Compared to basic VnC scheme, ESD-PCM reduces overhead and energy consumption by 13.7% and 14.5%, respectively. Moreover, ESD-PCM effectively reduces the probability of WD, enhances data reliability and improves system performance. Wenke Jin, Siqi Lu, Xiaojun Cai |
ETS | 2 |
| 2021 | A fine-grained anonymous handover authentication protocol based on consortium blockchain for wireless networks
Guangsong Li, Siqi Lu |
J. Parallel Distributed Comput. | 4 |
| 2019 | Manual Audit for BitUnits Contracts
Siqi Lu, Haopeng Fan, Yongjuan Wang, Huizhe Mi |
BlockSys | 1 |