EDBT 2026 Demo / reviewers in the wild / expert
Baiyang Li
dblp:182/5197
· DBLP profile ↗
12ranked-venue papers
3as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 5 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | STAR: Semantic-Traffic Alignment and Retrieval for Zero-Shot HTTPS Website Fingerprinting
Yujia Zhu, Baiyang Li, Xinhao Deng 0001, Yitong Cai, Yaochen Ren, Qingyun Liu 0001 |
INFOCOM | 3 |
| 2025 | Unraveling DoH Traces: Padding-Resilient Website Fingerprinting via HTTP/2 Key Frame Sequences
Baiyang Li, Yujia Zhu, Qingyun Liu 0001, Li Guo 0001 |
ESORICS (3) | 1 |
| 2025 | Broken Chains: An Empirical Analysis of DNS Resolution in IPv6-only EnvironmentsabstractThe global transition to IPv6 is impeded by failures within the Domain Name System (DNS), where the mere presence of an AAAA record does not guarantee a domain’s resolvability in IPv6-only environments. In this paper, we presents a comprehensive measurement study analyzing the complete DNS dependency chain—including parental, delegation, and alias dependencies—to reveal the true state of IPv6 resolvability. We introduce 6ChainChecker, a lightweight tool developed for this analysis. Our analysis of Tranco top domains reveals a critical discrepancy: 7.68% of domains with published AAAA records are nevertheless unresolvable from a strict IPv6-only stack due to structural failures in their dependency chains. To understand the broader landscape of failures, we find that while the absence of an AAAA record is the most common reason for unresolvability (58.0%), a substantial portion of failures stem from broken dependency paths, including delegation (17.1%) and alias chain (24.8%) issues. Crucially, we also identify significant dependency concentration, where the non-compliance of a few critical infrastructure zones creates cascading failures for hundreds of their dependent domains. These findings demonstrate that upstream infrastructure, not just endpoint configuration, is a significant impediment to the IPv6 transition. Our tool and dataset are publicly available to foster further research. Yujia Zhu, Baiyang Li, Qingyun Liu 0001 |
TrustCom | 3 |
| 2025 | HOLMES & WATSON: A Robust and Lightweight HTTPS Website Fingerprinting through HTTP Version ParallelismabstractWebsite Fingerprinting (WF) is a traffic analysis technique that aims to identify websites visited by users through the analysis of encrypted traffic patterns.Existing approaches often exhibit limited robustness against network variability and concept drift, resulting in significant performance degradation under real-world HTTPS conditions.Moreover, these methods typically require large-scale training datasets and substantial computational resources, which further increases the complexity of deployment.In this paper, we propose HOLMES, a novel approach that exploits HTTP version parallelism to extract enhanced application-layer features.These features, including the number of web resources transmitting in various HTTP versions, expose up to 4.28 bits of information-surpassing 98% of previously reported features and demonstrate increased stability across varying network conditions.Complementary to this, we introduce WATSON, a lightweight classification method based on lazy learning, which substantially reduces the dependency on large training datasets.To further enhance the identification accuracy, we incorporate two fingerprint-specific distance metrics that ensure high intra-class similarity.Our experimental evaluation demonstrates that HOLMES & WATSON significantly enhance both robustness and efficiency, achieving an average accuracy of 87.7% with only a single sample per website, marking an improvement of over 15% compared to state-of-the-art methods. Yujia Zhu, Baiyang Li, Peishuai Sun, Xinhao Deng 0001, Qingyun Liu 0001 |
WWW | 3 |
| 2024 | From Fingerprint to Footprint: Characterizing the Dependencies in Encrypted DNS Infrastructures
Baiyang Li, Yujia Zhu, Qingyun Liu 0001, Li Guo 0001 |
ESORICS (2) | 1 |
| 2024 | Failed Yet Stored: A First Look at DNS Negative CachingabstractCaching is a critical method for enhancing the efficiency and the security of the Domain Name System (DNS). Initially, only successful domain name resolution results were cached. To mitigate failures in DNS transactions (e.g. NXDomain), the IETF proposed standards, further developed into RFC 9520 as of December 2023. In addition to the basic implementation, RFC 9520 standardizes more sophisticated forms of negative caching. This new standard aims to reduce redundant query retries in DNS traffic and protect resolvers from Denial of Service (DoS) attacks.In this study, we present a comprehensive examination of the specific implementations of Negative Caching in resolvers. We designed and validated a method for measuring negative caching and conducted experiments on 44 public resolvers, including their Do53, DoH, and DoT interfaces. Our findings indicate that while public resolvers generally implement various types of negative caching, some exhibit unexpected cache handling behaviors when encountering specific negative responses. Additionally, we discovered that most public resolvers modify the TTL value of negative responses before returning them to clients. Despite the lack of explicit TTL values for newly specified negative responses, we devised a method to approximate the default TTL values used by public resolvers. Meng Zeng, Yujia Zhu, Baiyang Li, Qingyun Liu 0001, Binxing Fang |
IPCCC | 3 |
| 2024 | LayyerX: Unveiling the Hidden Layers of DoH Server via Differential FingerprintingabstractAs a rapidly developing DNS security enhancement technology, DoH(DNS over HTTPS) is gaining popularity among people. It allows users to quickly set up a DoH server by combining several components which create a layered structure. However, the multi-layer setup, which involves both HTTPS and DNS protocols, makes internal structural details more difficult to be detected. To address this issue, we propose a method that utilizes cross-protocol fingerprinting and analysis techniques, which is capable of identifying various components of multi-layer DoH servers with a focus on the underlying differences within protocol. Using this approach, we developed LayyerX, a system for detecting multi-layer DoH servers. Finally, through experiments and large-scale measurements in the wild, we showcased LayyerX’s outstanding capabilities and presented a meaningful structural overview of multi-layer DoH server. Yunyang Qin, Yujia Zhu, Linkang Zhang, Baiyang Li, Qingyun Liu 0001 |
TrustCom | 4 |
| 2023 | Before Toasters Rise Up: A View into the Emerging DoH Resolver's Deployment RiskabstractAs an encryption protocol for DNS queries, DNS-over-HTTPS (DoH) is becoming increasingly popular, and it mainly addresses the last-mile privacy protection problem. However, the security of DoH is in urgent need of measurement and analysis due to its reliance on certificates and upstream servers. In this paper, we focus on the DoH ecosystem and conduct a one-month measurement to analyze the current deployment of DoH resolvers. Our findings indicate that some of these resolvers use invalid certificates, which can compromise the security and privacy advantages of the protocol. Furthermore, we found that many providers are at risk of certificate outages, which could cause significant disruptions to the DoH ecosystem. Additionally, we observed that the centralization of DoH resolvers and upstream DNS servers is a potential issue that needs addressing to ensure the stability of the ecosystem. Yuqi Qiu, Baiyang Li, Zhiqian Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001 |
ISCC | 2 |
| 2023 | Measuring DNS-over-Encryption Performance Over IPv6abstractIn recent years, encrypted DNS such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) has gained significant traction as privacy-preserving alternative to conventional DNS. While several studies have measured the performance of encrypted DNS relative to conventional DNS, they are only performed over IPv4, little has been done to understand their status over IPv6. Besides, previous studies can not obtain the absolute query latency due to lack of control over vantage points.This paper performs by far the fist end-to-end performance measurements on encrypted DNS over IPv6. By analyzing measurement results, we have gained several insights. In general, the quality of service for encrypted DNS is satisfying. Over IPv6, encrypted DNS performance varies across resolvers, and is affected by the location issuing DNS queries, the type of encrypted DNS protocol used and the latency to resolvers. Compared with IPv4, the performance of encrypted DNS of different resolvers over IPv6 is improved to some extent. In addition, we also find other problems such as the quality of service of resolver Ahadns is significantly low both over IPv6 and IPv4, as well as the performance of encrypted DNS for resolver Alidns significantly deteriorates when switching from IPv4 to IPv6. Based on our observations, we provide recommendations and discuss situations in which switching to IPv6 may be beneficial. We hope that our tools developed for performing measurements can help people in different regions to choose to the right recursive resolver and network environment, and that our findings can contribute to improve IPv6 Internet infrastructure and inform continuing encrypted DNS deployment over IPv6. Liang Jiao, Yujia Zhu, Baiyang Li, Qingyun Liu 0001 |
TrustCom | 3 |
| 2022 | Detection of DoH Tunnels with Dual-Tier ClassifierabstractDNS over HTTPS (DoH) has been deployed to provide confidentiality in the DNS resolution process. However, encryption is a double-edged sword in providing security while increasing the risk of data tunneling attacks. Current approaches for plaintext DNS tunnel detection are disabled. Due to the diversity of tunneling tool variations and the low proportion of tunneled traffic in real situations, detecting malicious behaviors is becoming more and more challenging. In this paper, we propose a novel behavior-based model with Dual-Tier Tunnel Classifier (DTC) for tool-level DoH tunneling detection. The major advantage of DTC is that it can not only capture existing tunneling tools but also explore unknown ones in the wild. In particular, DTC considers data imbalance, which improves robustness of the model in the open environment. Our method has been proven successful in both closed and open scenarios, achieving 99.99 % accuracy in detecting known malicious DoH traffic, 96.93% accuracy in unknown and 95.31 % accuracy in identifying malicious DoH tunnel tools. Yuqi Qiu, Baiyang Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001 |
MSN | 2 |
| 2021 | Peek Inside the Encrypted World: Autoencoder-Based Detection of DoH ResolversabstractDNS-over-HTTPS (DoH), as a rising star to improve DNS security and privacy, has developed rapidly in recent years. It mixes with HTTP features, shares ports with other web services and provides API with URI templates. The unique characteristics of DoH, as well as its fast growth, bring both promising prospects and new risks, e.g. botnet communication, name abuse and data exfiltration. It is essential for network operators to learn about adoption and usage of DoH resolvers. Active scanning may be a possible way. However, it is considered to incur significantly additional overhead, which can be inefficient and aggressive. In this paper, we present DOHUNTER, a system for automati-cally discovering DoH resolvers. DOHUNTER: (i) picks DoH flow from miscellaneous HTTPS traffic, (ii)confirms DoH resolvers based on the detected DoH flow, (iii)mines other related DoH resolvers from the known ones. Our real-world experiments demonstrate the effectiveness of DOHUNTER in detecting DoH flow and finding DoH resolvers. Utilizing DOHUNTER, we witness an alarming increase in DoH adoption. Additionally, we also reveal oblivious growing trends of DoH, which may provide advice for both users and network operators. Jiating Wu, Yujia Zhu, Baiyang Li, Qingyun Liu 0001, Binxing Fang |
TrustCom | 3 |
| 2019 | Hunting for Invisible SmartCam: Characterizing and Detecting Smart Camera Based on Netflow AnalysisabstractNowadays, the rapid growth of cloud computing and IoT enabled services among multiple organizations brings both promising prospects and security & privacy challenges. IP cameras have become a top target for hackers because of their relatively high computing power and throughput. To understand the risks of these threats requires learning about IP cameras-where are they, how many are there? Active scanning is considered to be an effective way, like SHODAN. However, deployment of smart cameras in the network address translation (NAT) environments with dynamic locations is usually desired. To find these Invisible Cameras, CamHunter: (i) introduces three statements of smart cameras when they are online, (ii) concludes the most popular smart cameras in China have very similar communication patterns, (iii) proposes a model to detect smart cameras in a passive way constructed by nineteen feature sets, and (iv) raises alarms for IoT manufacturers. Our real-world experiments demonstrate the effectiveness of CamHunter in finding smart cameras even if they are behind NATs and using encrypted connections like SSL/TLS or private protocols. We argue that CamHunter represents an important view of IoT security and privacy, and it can guide the effort of designing and protecting smart cameras. Baiyang Li, Yujia Zhu, Qingyun Liu 0001, Zhou Zhou 0007, Li Guo 0001 |
ICC | 1 |