EDBT 2026 Demo / reviewers in the wild / expert
Ziyun Zhu
dblp:187/8969
· DBLP profile ↗
6ranked-venue papers
2as first author
2since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Malware analysis · 68% Usable security · 32% | |
| Software engineering, system software, and programming languages
1 paper |
Empirical software engineering · 100% | |
| Artificial intelligence
1 paper |
Information extraction and text analysis · 100% |
Topics — the 6 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis
malware behavior analysis |
0.8 | 2 | 2021 | When Malware Changed Its Mind: An Empirical Study of Variable Program Behaviors in the Real World · USENIX Security Symposium 2021 FeatureSmith: Automatically Engineering Features for Malware Detection by Mining the Security Literature · CCS 2016 |
Usable security
security behavior |
0.3 | 1 | 2018 | Asking for a Friend: Evaluating Response Biases in Security User Studies · CCS 2018 |
Usable security
security user studies |
0.3 | 1 | 2018 | Asking for a Friend: Evaluating Response Biases in Security User Studies · CCS 2018 |
Malware analysis › mobile malware detection
android malware detection |
0.2 | 1 | 2016 | FeatureSmith: Automatically Engineering Features for Malware Detection by Mining the Security Literature · CCS 2016 |
Malware analysis
malware detection |
0.2 | 1 | 2016 | FeatureSmith: Automatically Engineering Features for Malware Detection by Mining the Security Literature · CCS 2016 |
Malware analysis
malware detection evasion |
0.1 | 1 | 2021 | When Malware Changed Its Mind: An Empirical Study of Variable Program Behaviors in the Real World · USENIX Security Symposium 2021 |
Methods — techniques the papers use, named apart from their topics
survey · 0.7field measurement · 0.7text mining · 0.5natural language processing · 0.5empirical study · 0.5dynamic analysis · 0.5classifier training · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Creative Destruction: Can Language Models Interpret Oxymorons?
Ziyun Zhu, Xiaojun Wan 0001 |
NLPCC (1) | 2 |
| 2021 | When Malware Changed Its Mind: An Empirical Study of Variable Program Behaviors in the Real World
Erin Avllazagaj, Ziyun Zhu, Leyla Bilge, Davide Balzarotti, Tudor Dumitras |
USENIX Security Symposium | 2 |
| 2018 | Asking for a Friend: Evaluating Response Biases in Security User StudiesabstractThe security field relies on user studies, often including survey questions, to query end users' general security behavior and experiences, or hypothetical responses to new messages or tools. Self-report data has many benefits -- ease of collection, control, and depth of understanding -- but also many well-known biases stemming from people's difficulty remembering prior events or predicting how they might behave, as well as their tendency to shape their answers to a perceived audience. Prior work in fields like public health has focused on measuring these biases and developing effective mitigations; however, there is limited evidence as to whether and how these biases and mitigations apply specifically in a computer-security context. In this work, we systematically compare real-world measurement data to survey results, focusing on an exemplar, well-studied security behavior: software updating. We align field measurements about specific software updates (n=517,932) with survey results in which participants respond to the update messages that were used when those versions were released (n=2,092). This allows us to examine differences in self-reported and observed update speeds, as well as examining self-reported responses to particular message features that may correlate with these results. The results indicate that for the most part, self-reported data varies consistently and systematically with measured data. However, this systematic relationship breaks down when survey respondents are required to notice and act on minor details of experimental manipulations. Our results suggest that many insights from self-report security data can, when used with care, translate to real-world environments; however, insights about specific variations in message texts or other details may be more difficult to assess with surveys. Elissa M. Redmiles, Ziyun Zhu, Sean Kross, Dhruv Kuchhal, Tudor Dumitras, Michelle L. Mazurek |
CCS | 2 |
| 2018 | ChainSmith: Automatically Learning the Semantics of Malicious Campaigns by Mining Threat Intelligence ReportsabstractModern cyber attacks consist of a series of steps and are generally part of larger campaigns. Large-scale field data provides a quantitative measurement of these campaigns. On the other hand, security practitioners extract and report qualitative campaign characteristics manually. Linking the two sources provides new insights about attacker strategies from measurements. However, this is a time-consuming task because qualitative measurements are generally reported in natural language and are not machine-readable. We propose an approach to bridge measurement data with manual analysis. We borrow the idea from threat intelligence: we define campaigns using a 4-stage model, and describe each stage using IOCs (indicators of compromise), e.g. URLs and IP addresses. We train a multi-class classifier to extract IOCs and further categorize them into different stages. We implement these ideas in a system called ChainSmith. Our system can achieve 91.9% precision and 97.8% recall in extracting IOCs, and can determine the campaign roles for 86.2% of IOCs with 78.2% precision and 80.7% recall. We run ChainSmith on 14,155 online security articles, from which we collect 24,653 IOCs. The semantic roles allow us to link manual attack analysis with large scale field measurements. In particular, we study the effectiveness of different persuasion techniques used on enticing user to download the payloads. We find that the campaign usually starts from social engineering and "missing codec" ruse is a common persuasion technique that generates the most suspicious downloads each day. Ziyun Zhu, Tudor Dumitras |
EuroS&P | 1 |
| 2017 | Patch Me If You Can: A Study on the Effects of Individual User Behavior on the End-Host Vulnerability State
Armin Sarabi, Ziyun Zhu, Chaowei Xiao, Mingyan Liu, Tudor Dumitras |
PAM | 2 |
| 2016 | FeatureSmith: Automatically Engineering Features for Malware Detection by Mining the Security LiteratureabstractMalware detection increasingly relies on machine learning techniques, which utilize multiple features to separate the malware from the benign apps. The effectiveness of these techniques primarily depends on the manual feature engineering process, based on human knowledge and intuition. However, given the adversaries' efforts to evade detection and the growing volume of publications on malware behaviors, the feature engineering process likely draws from a fraction of the relevant knowledge. We propose an end-to-end approach for automatic feature engineering. We describe techniques for mining documents written in natural language (e.g. scientific papers) and for representing and querying the knowledge about malware in a way that mirrors the human feature engineering process. Specifically, we first identify abstract behaviors that are associated with malware, and then we map these behaviors to concrete features that can be tested experimentally. We implement these ideas in a system called FeatureSmith, which generates a feature set for detecting Android malware. We train a classifier using these features on a large data set of benign and malicious apps. This classifier achieves a 92.5% true positive rate with only 1% false positives, which is comparable to the performance of a state-of-the-art Android malware detector that relies on manually engineered features. In addition, FeatureSmith is able to suggest informative features that are absent from the manually engineered set and to link the features generated to abstract concepts that describe malware behaviors. Ziyun Zhu, Tudor Dumitras |
CCS | 1 |