EDBT 2026 Demo / reviewers in the wild / expert
Letian Sha
dblp:184/0402
· DBLP profile ↗
18ranked-venue papers
7as first author
13since 2021 · last 2026
0009-0007-5547-3728ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 4 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PRISM: Personalized Recommendation via Information Synergy ModuleabstractMultimodal sequential recommendation (MSR) leverages diverse item modalities to improve recommendation accuracy, while achieving effective and adaptive fusion remains challenging. Existing MSR models often overlook synergistic information that emerges only through modality combinations. Moreover, they typically assume a fixed importance for different modality interactions across users. To address these limitations, we propose Personalized Recommend-ation via Information Synergy Module (PRISM), a plug-and-play framework for sequential recommendation (SR). PRISM explicitly decomposes multimodal information into unique, redundant, and synergistic components through an Interaction Expert Layer and dynamically weights them via an Adaptive Fusion Layer guided by user preferences. This information-theoretic design enables fine-grained disentanglement and personalized fusion of multimodal signals. Extensive experiments on four datasets and three SR backbones demonstrate its effectiveness and versatility. The code is available at~ https://github.com/YutongLi2024/PRISM. Peijie Sun, Letian Sha, Zhongxuan Han |
WWW | 4 |
| 2026 | Match on My Own: Fine-Grained Bilateral Access Control With Self-Constrained Matching for Online Social Networks
Letian Sha, Hui Yin 0001, Zheng Qin 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | MalElves: Reinforcement Learning-Driven Adversarial Example Generation for Evading Cross-Platform ELF Malware DetectionabstractAdversarial Example (AE) generation is a key instrument for stress-testing and hardening malware detectors, yet most existing techniques target Portable Executable (PE) files and do not transfer cleanly to Executable and Linkable Format (ELF) binaries prevalent in Internet of Things (IoT) environments. We proposeMalElves, a reinforcement learning-driven AE generation framework for cross-platform ELF malware.MalElvesmakes three core technical contributions. First, a code-data-aware manipulation framework unifies obfuscation and rewriting across ARM, ×86, and ×64 architectures while preserving functionality. Second, a sample-efficient state design reduces 2,350 raw ELF features to a compact 21-dimensional input. Third, a shaped multi-detector reward uses fully disclosed PPO settings for full reproducibility. We evaluateMalElveson 161,414 malware samples and 74,260 benign samples. We test against four static detectors and a behavioral-ensemble stress test. The method achieves average ASRs of 89.9%, 85.3%, 63.8%, 60.6%, and 24.7% across detectors. The overall average ASR reaches 64.8%. Each successful evasion requires 2.24 interaction rounds on average. Zhangbo Long, Letian Sha, Yan Lin 0003, Peijie Sun, Haiping Huang, Fu Xiao 0001, Zhiquan Liu 0001 |
IEEE Trans. Software Eng. | 2 |
| 2025 | STAR-Shield: Self-Tuning Adaptive Rules for Web Application Firewall-as-a-Service via Multiple Large Language ModelsabstractAs the primary entry point to modern digital services, Web applications are now subjected to the fastest-evolving threat landscape on the Internet. Consequently, ML-based Web Application Firewall (WAF) exhibits degraded accuracy when exposed to novel attack patterns, while regex-driven solution remains bottlenecked by manual rule crafting, impeding agile response to emergent threats. Large Language Models (LLMs) bring to bear capabilities such as real-time Internet-scale intelligence gathering, symbolic code reasoning, and targeted analytic generation. We introduce STAR-Shield, a LLM-powered adaptive rule-evolution framework engineered for Web Application Firewall-as-a-service (FWaaS). Through a multi-agent choreography, STAR-Shield automates the full cycle: harvesting and analyzing new threats and vulnerabilities, reconstructing attack payloads, synthesizing and refining regular-expression rules, and enforcing runtime interception. Evaluation within a controlled, real-world environment shows that STAR-Shield can empower a cloud-hosted WAF to achieve over 98% interception accuracy against One-day attacks with a false-positive rate below 0.4%. Letian Sha, Nan Yi |
TrustCom | 1 |
| 2025 | The hidden complexities of Android TPL detection: An empirical analysis of techniques, challenges, and effectiveness
Lige Zhan, Jiang Ming 0002, Jianming Fu, Guojun Peng, Letian Sha, Lili Lan |
Comput. Secur. | 5 |
| 2025 | READ: Resource efficient authentication scheme for digital twin edge networks
Kai Wang 0072, Jiankuo Dong, Yijie Xu, Xinyi Ji, Letian Sha, Fu Xiao 0001 |
Future Gener. Comput. Syst. | 5 |
| 2025 | Boreas: Semantic-Aware Framework for Buffer Overflow Detection to Reduce Carbon Footprint in IoT DevicesabstractThe rapid development of the Industrial Internet of Things (IIoT) has raised concerns about device security and energy consumption. The widespread presence of buffer overflow (BOF) vulnerabilities in IoT devices not only threatens devices but also leads to increased carbon emissions. Traditional static analysis methods suffer from low accuracy and high costs. Mainstream binary code similarity detection (BCSD) methods are mainly based on control flow graphs (CFGs) or instructions, which often fail to effectively capture semantic information. In this paper, we propose Boreas, a semantic-aware BOF vulnerability detection framework to reduce the carbon footprint in IoT devices. The abstract syntax tree (AST) is employed to achieve precise semantic representation of multi-architecture code. By considering the often-overlooked implicit data receiving points, Boreas comprehensively locates vulnerable binaries in firmware. By leveraging backward reaching definition analysis, Boreas removes extensive code irrelevant to BOF to simplify ASTs, enables cross-function/file detection and enhances interpretability for BCSD. Additionally, we develop a deep learning model AST-BERT for BCSD, which effectively transforms simplified ASTs into vectors. Based on the distance between target and vulnerable vectors, the accurate BOF detection is achieved. To evaluate the performance of Boreas, we construct a large-scale dataset containing real-world IoT firmware. Experiments show that Boreas outperforms state-of-the-art BCSD methods with the precision of 87.08% and leading static analysis tools with the F1-score of 88.81% in vulnerability detection. Finally, Boreas successfully discovers 10 unknown critical vulnerabilities, all of which have been recognized by CVE and covered by media. Xiao Chen 0017, Letian Sha, Qingguan Gao, Fu Xiao 0001, Jiaye Pan |
IEEE Internet Things J. | 2 |
| 2025 | AB-DHD: An Attention Mechanism and Bi-Directional Gated Recurrent Unit Based Model for Dynamic Link Library Hijacking Vulnerability Discovery
Xiao Chen 0017, Letian Sha, Fu Xiao 0001, Jiaye Pan, Jiankuo Dong |
J. Comput. Sci. Technol. | 2 |
| 2025 | AWDP-Automated Windows Domain Penetration Framework With Deep Reinforcement LearningabstractWindows domain is regarded as a primary target for intranet penetration since a large amount of sensitive information is stored in such domain with Windows OS. However, penetration testing is a intricate and time-consuming task, which is usually dedicated to experienced experts. To alleviate and partially solve this problem, we hereby propose an automated Windows domain penetration testing framework (AWDP). Firstly, we establish the test scenario as a Markov Decision Process (MDP) and then design a simulator for the Windows Domain penetration testing with OpenAI's Gymnasium. Secondly, we implement our automated Windows Domain penetration approach with four sequential steps, collecting domain and host information, modeling with acquired data, discovering optimal attack path through Deep Q-Learning Network (DQN), and performing penetration testing actions. Finally, to validate the effects of the proposed method, we conduct tests in real deployed domains. Experimental results demonstrate that, the proposed models and algorithms in the AWDP framework exhibit robust performance. Moreover, the framework adapts to different environments with rational and efficient estimated attack paths, which eventually enables end-to-end automation of Windows Domain penetration testing. Letian Sha, Xingpeng Huo, Fu Xiao 0001, Jiankuo Dong, Ziyue Su |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | PatchFuzz: An Efficient Way to Incorporate Patching With Hybrid FuzzingabstractHybrid and patching-based fuzzing methods offer promise in uncovering software bugs using concolic execution and program transformation techniques. However, current implementations face efficiency challenges from three main factors. First, the efficacy of hybrid fuzzing can be compromised due to disruptions introduced during the mutation of inputs generated by concolic execution, hindering vulnerability discovery. Second, the speed and throughput of the underlying fuzzer significantly impact the effectiveness of both methods. Third, patching-based fuzzing has an inefficient patching system and high analysis costs. Nonetheless, hybrid and patching-based fuzzing offer complementary strengths that can enhance overall efficacy. For instance, patching can maintain exploration depth by reducing the likelihood of input structure disruption, while concolic execution can authenticate detected crashes. In this paper, we present PATCHFUZZ, which integrates fuzzing and patching at a fundamental level, leveraging concolic execution to augment the fuzzing process. Specifically, PATCHFUZZ binds patching addresses with each seed rather than the program itself, promoting frequent interactions between patching and fuzzing. Additionally, we've devised efficient methodologies for patching information management and patched program switching. Evaluation on LAVA-M, CGC and OSS-Fuzz datasets shows PATCHFUZZ surpasses state-of-the-art fuzzers like QSYM, SYMQEMU, AFL++ CmpLog and T-Fuzz. Deployed on industrial devices, PATCHFUZZ uncovered 9 new vulnerabilities. Letian Sha, Luheng Zhang, Yan Lin 0003, Fu Xiao 0001, Jiaye Pan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | SFO-CID: Structural Feature Optimization Based Command Injection Vulnerability Discovery for Internet of ThingsabstractThe rapid development of Industrial Internet of Things (IIoT) has raised wider concerns for security of IoT devices. Command injection (CI) vulnerabilities, prevalent in IoT devices, pose a severe risk for remote code execution. Traditional static detection methods suffer from high overhead and imprecision due to symbolic execution. Popular binary code similarity detection (BCSD) methods rely on Control Flow Graphs (CFGs) with redundant structures, resulting in low efficiency and accuracy. In addition, they struggle with cross-function issues. In this paper, we proposeSFO-CID, a novel structural feature optimization based command injection vulnerability discovery model for IoT devices. Through backward taint analysis, all CFGs of suspicious CI vulnerabilities within the target binary file are precisely obtained. A large amount of code unrelated to vulnerabilities is removed, and cross-function issues are covered, significantly optimizing the structural features of original CFGs. Neural networks generate embedding vectors for optimized CFGs, transforming CI vulnerability detection into a vector similarity comparison. A wealth of semantic information within the code context is automatically and efficiently captured, improving the accuracy of vulnerability detection. We collect real-world cross-platform IoT firmware as data sources for tests. Experiments show thatSFO-CIDoutperforms popular BCSD methods, such asGemini,IoTSeeker, andFIT, achieving the highest accuracy of 88.67$\%$in vulnerability detection. Compared to existing state-of-the-art static analysis methods, likeKARONTEandSaTC,SFO-CIDattains the highest precision at 88.43$\%$and F1-score at 86.29$\%$, and is less time-consuming. Until now, 8 high-risk unknown vulnerabilities have been discovered, including 5 cross-function cases, and corresponding CVE IDs were assigned. Xiao Chen 0017, Letian Sha, Fu Xiao 0001, Jiankuo Dong |
IEEE Trans. Ind. Informatics | 2 |
| 2025 | VRVul-Discovery: BiLSTM-based Vulnerability Discovery for Virtual Reality Devices in MetaverseabstractThe rapid development of the metaverse has brought about numerous security challenges. Virtual Reality (VR) , as one of the core technologies, plays a crucial role in the metaverse. The security of VR devices directly impacts user authentication and privacy. Currently, no attention has been paid to the vulnerabilities and security risks of VR devices. This article employs a bi-layer BiLSTM neural network to conduct a root cause analysis for user authentication and scene interaction when users enter metaverse environment using VR devices. By establishing the mapping between vulnerable VR firmware file attributes and metaverse interaction scenarios, we implement a vulnerability discovery and verification prototype called VRVul-Discovery, based on the concept of vulnerability discovery. Experiment results demonstrate that VRVul-Discovery provides high-accuracy determinations of firmware vulnerability attributes and scenarios susceptible to hijacking. In the end, the prototype system discovers seven unknown vulnerabilities, all of which are authenticated. Letian Sha, Xiao Chen 0017, Fu Xiao 0001, Zhangbo Long, Qianyu Fan, Jiankuo Dong |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2022 | Cross-scene passive human activity recognition using commodity WiFi
Yuanrun Fang, Fu Xiao 0001, Biyun Sheng, Letian Sha |
Frontiers Comput. Sci. | 4 |
| 2020 | A Flexible Privacy-Preserving Data Sharing Scheme in Cloud-Assisted IoTabstractCloud-assisted Internet of Things (IoT) has become an increasingly popular technological trend as the performance of IoT applications can be greatly improved by delegating the cloud to manage massive IoT data. To protect the confidentiality of data outsourced from IoT devices to the cloud, cryptographic mechanisms are usually employed to encrypt the data in such a way that only the user designated by the data owner can decrypt the data. However, in the IoT multiuser environment, the encrypted data may also need to be shared with more users beyond the initially designated one. In this article, we propose a flexible privacy-preserving data sharing (FPDS) scheme in cloud-assisted IoT. With the FPDS scheme, an IoT user can encrypt data to a recipient by using identity-based encryption. More importantly, the IoT user can specify a fine-grained access policy to generate a delegation credential, and then send this credential to the cloud so that it can convert all the encrypted data satisfying the access policy into new ciphertexts that are readable to a new recipient. In this way, IoT users can share the data outsourced to the cloud in a flexible and privacy-preserving manner. Detailed security analysis shows that the FPDS scheme is secure against semitrusted cloud and malicious IoT users. Thorough theoretical and experimental analyses demonstrate the high efficiency of the scheme. Zheng Qin 0001, Letian Sha, Hui Yin 0001 |
IEEE Internet Things J. | 3 |
| 2020 | Deep Spatial-Temporal Model Based Cross-Scene Action Recognition Using Commodity WiFiabstractWith the popularization of Internet-of-Things (IoT) systems, passive action recognition on channel state information (CSI) has attracted much attention. Most conventional work under the machine-learning framework utilizes handcrafted features (e.g., statistic features) that are unable to sufficiently describe the sequence data and heavily rely on designers' experiences. Therefore, how to automatically learn abundant spatial-temporal information from CSI data is a topic worthy of study. In this article, we propose a deep learning framework that integrates spatial features learned from the convolutional neural network (CNN) into the temporal model multilayer bidirectional long short-term memory (Bi-LSTM). Specifically, CSI streams are segmented into a series of patches, from which spatial features are extracted by our designed CNN structure. Considering long-term dependencies between adjacent sequences, the fully connected layer of CNN for each patch is taken as the Bi-LSTM sequential input to further capture temporal features. Our model is appealing in that it can simultaneously learn temporal dynamics and convolutional perceptual representations. To the best of our knowledge, this is the first work to explore deep spatial-temporal features for CSI-based action recognition. Furthermore, in order to solve the problem that the trained model fully fails with environmental changes, we use the off-the-shelf model as the pretrained model and fine-tune it in the new scenario. The transfer method is able to realize cross-scene action recognition with low computational consumption and satisfactory accuracy. We carry out experiments on indoor data and the experimental results validate the effectiveness of our algorithm. Biyun Sheng, Fu Xiao 0001, Letian Sha |
IEEE Internet Things J. | 3 |
| 2019 | Catching Escapers: A Detection Method for Advanced Persistent Escapers in Industry Internet of Things Based on Identity-based Broadcast Encryption (IBBE)abstractAs the Industry 4.0 or Internet of Things (IoT) era begins, security plays a key role in the Industry Internet of Things (IIoT) due to various threats, which include escape or Distributed Denial of Service (DDoS) attackers in the virtualization layer and vulnerability exploiters in the device layer. A successful cross-VM escape attack in the virtualization layer combined with cross-layer penetration in the device layer, which we define as an Advanced Persistent Escaper (APE), poses a great threat. Therefore, the development of detection and rejection methods for APEs across multiple layers in IIoT is an open issue. To the best of our knowledge, less effective methods are established, especially for vulnerability exploitation in the virtualization layer and backdoor leverage in the device layer. On the basis of this, we propose Escaper Cops (EscaperCOP), a detection method for cross-VM escapers in the virtualization layer and cross-layer penetrators in the device layer. In particular, a new detection method for guest-to-host escapers is proposed for the virtualization layer. Finally, a novel encryption method based on Identity-based Broadcast Encryption (IBBE) is proposed to protect the critical components in EscaperCOP, detection library, and control command library. To verify our method, experimental tests are performed for a large number of APEs in an IIoT framework. The test results have demonstrated the proposed method is effective with an acceptable level of detection ratio. Letian Sha, Fu Xiao 0001, Haiping Huang, Yu Chen 0074, Ruchuan Wang 0001 |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2018 | IIoT-SIDefender: Detecting and defense against the sensitive information leakage in industry IoT
Letian Sha, Fu Xiao 0001 |
World Wide Web | 1 |
| 2016 | SDN-based Sensitive Information (SI) protection: sensitivity-degree measurement in software and data lifetime supervisor in software defined networkabstractAbstract With the big‐data and mobile Internet era coming, sensitive information (SI) in various applications plays a key role; even more, they can be an important part of the authentication between clients and servers. However, how to measure security or sensitivity degrees of SI is an open issue. Furthermore, no effective method can detect covert channel of SI thieves in Advanced Persistent Threat attacks. To deal with these problems, we propose a new design, called software‐defined networking (SDN)‐based SI Protection, in which sensitivity degree can be measured by using Analytic Hierarchy Process and Technique for Order Preference by Similarity to an Ideal Solution, and SI covert channel can be detected based on OpenFlow in SDN. To our best knowledge, it is the first defined sensitivity degree for SI and novel flow‐table design in SI data flow switch. Most significantly, our proposal can apply integrated semantics of leakage points and accident attacks into security analysis and switch protocol in Operating System or network. To verify our proposal, experimental tests are performed in social network platforms, field test results have demonstrated that this proposal can capture security level for SI as expected, detect any kinds of potential leakage points in data lifetime, describe fine‐grained semantics of accidental attacks, and detect illegal data flow of SI in network layer. Copyright © 2015 John Wiley & Sons, Ltd. Letian Sha, Liwen He, Jianming Fu, Pengwei Li |
Secur. Commun. Networks | 1 |