Zhaoxuan Li

dblp:202/2279 · DBLP profile ↗
← Back
44ranked-venue papers
6as first author
44since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 1 first-author · 13 since 2021Computer networks · 11 · 1 first-author · 11 since 2021Databases, data management, data science and information retrieval · 8 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 7 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Relational Verification for Cost-Aware Quantum Program Optimization
abstract
Optimizing quantum programs is key to mitigating noise, reducing error-correction overhead, and improving performance on both near-term and fault-tolerant devices. Existing heuristic and learning-based optimizers, however, lack formal guarantees and risk semantic errors in the presence of entanglement and measurement. We present RelOpt, a semantics-preserving optimizer that enforces relational correctness between original and optimized programs. RelOpt is built on a lightweight intermediate language (QCore) with a relational operational semantics supporting partial-trace equivalence, measurement-distribution preservation, and approximate correctness. Optimization is guided by a multi-objective cost model that considers gate count, circuit depth, and error-correction cost. Only rewrite rules that are formally verified against user-specified contracts are applied. The engine combines symbolic simulation, SMT reasoning, and cost analysis to achieve safe and effective optimizations. On standard benchmarks such as QFT, Grover, and QAOA, RelOpt consistently outperforms Qiskit, t|ket>, and learning-based optimizers across multiple cost metrics while maintaining formal guarantees. By integrating formal verification with cost-aware compilation, RelOpt establishes a foundation for trustworthy and hardware-adaptive quantum toolchains.
Ziming Zhao 0008, Tingting Li 0004, Zhaoxuan Li, Jianwei Yin
AAAI3
2026 QCLink: Offloading Hybrid Quantum-Classical Computation to SmartNICs via RDMA
Xingdong Li, Yongzhuo Lu, Xiaofei Yue, Zhaoxuan Li, Ziming Zhao 0008, Jianwei Yin
ICDCS8
2026 VQFlow: A Benchmark Dataset for Encrypted Video Streaming Traffic across QoS Configurations
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
KDD (1)2
2026 Fair and Carbon-Aware LLM Routing for Web Services
Tingting Li 0004, Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Yue, Jiongchi Yu
WWW3
2026 Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language Models
abstract
Large Language Models (LLMs), as common components of modern web application backends and online services, are being widely deployed across various web infrastructures in the .gguf single-file format. This trend exposes their model parameter space to an unprecedented hardware attack surface, such as Bit-Flip attacks (BFA). This paper is the first to systematically discover and validate the existence of single-bit vulnerabilities in LLMs weight files: In the .gguf quantization format of mainstream open-source models (such as DeepSeek, QWEN), flipping a single bit can induce three types of targeted semantic-level faults, respectively-Artificial Flawed Intelligence (outputting factual errors), Artificial Weak Intelligence (catastrophic model failure), and Artificial Bad Intelligence (generating harmful content). By building an information-theoretic weight sensitivity entropy model and a probabilistic heuristic scanning framework called BitSifter, we achieved efficient localization of critical vulnerable bits in models with hundreds of millions of parameters. Furthermore, an end-to-end remote BFA chain was designed, enabling semantic-level attacks in real-world web server deployment scenarios: At an attack frequency of 464.3 times per second, the average time required for the first successful flip of the target bit is 31.7 seconds, without requiring high-cost equipment or complex prompt engineering. This study reveals a critical finding: under relatively modest remote-attack conditions, requiring only conventional network connectivity, flipping a single vulnerable bit within the tensor data segment can cause models deployed in web service environments to autonomously generate extremely malicious responses, such as ''humans should be exterminated'', or produce naturally fluent and difficult-to-detect erroneous replies to ordinary user queries. This demonstrates a pervasive and exploitable security vulnerability in LLMs systems at the fundamental hardware level.
Siqi Lu, Zhaoxuan Li, Ziming Zhao 0008, Qingjun Yuan, Yongjuan Wang
WWW4
2026 HeteroSim: Towards High-Fidelity Heterogeneous LLM Training Simulation on GPUs
Xiaofei Yue, Fangming Zhao, Fulun Ye, Jiongchi Yu, Zhaoxuan Li, Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin
WWW5
2026 Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitation
abstract
Abstract With the widespread deployment of the lightweight cryptography (LWC) standard Ascon in resource-constrained devices, research on physical attacks against Ascon, especially fault attacks, has made noticeable progress in recent years. Existing fault attacks on Ascon often require substantial fault injections. To address this, we propose scoring functions with multiple distinguishers for statistical ineffective fault analysis (SIFA), statistical effective fault analysis (SEFA), and statistical hybrid fault analysis (SHFA) to recover key bits. In addition, we propose an impossible statistical effective fault analysis (ISEFA) that exploits an impossible event in the fault-induced distribution to directly eliminate incorrect key hypotheses, reducing reliance on complex computations of distinguishers. We conduct extensive simulations and evaluate the number of fault injections, recovery accuracy, success rate, and time overhead across different distinguisher-analysis combinations. The results show that, under SHFA with the GF distinguisher, only 34 fault injections are sufficient to achieve a 99% success rate for recovering a 128-bit key, which is fewer than prior results on Ascon fault analysis. Moreover, we discuss the practical feasibility of the proposed methods and outline two conceptually motivated directions for potential countermeasures.
Zhaoxuan Li, Siqi Lu, Qingjun Yuan, Yongjuan Wang
Cybersecur.2
2026 Tlcp hardening with formal analysis and post-quantum design
abstract
Abstract Transport Layer Cryptography Protocol (TLCP) is a secure communication protocol developed in China, featuring a dual-certificate architecture and incorporating ShangMi cryptographic algorithms. It has been widely deployed in security-critical domains such as finance, government, and energy. Despite its practical significance, TLCP did not undergo comprehensive formal analysis during its standardization process, leaving potential design-level vulnerabilities insufficiently explored. Moreover, the advent of quantum computing poses fundamental challenges to the classical cryptographic primitives employed by TLCP, motivating the need for both systematic security evaluation and post-quantum enhancements. To address these gaps, we first construct the comprehensive formal model of TLCP, covering certificate-based and identity-based cipher suites as well as its distinctive dual-certificate mechanism, under a realistic threat model and security assumptions that capture both classical and quantum adversaries. Based on this model, we conduct an automated security analysis using ProVerif, identifying nine potential attack vectors and deriving five concrete mitigation recommendations. Finally, motivated by the analysis results and the limitations of incremental fixes against quantum threats, we propose KEMTLCP, a post-quantum secure variant of TLCP that leverages key encapsulation mechanisms (KEMs) for both key exchange and authentication while preserving TLCP’s architectural principles through a novel explicit authentication mechanism. We further provide a security proof for the core authentication mechanism, show that KEMTLCP effectively mitigates the majority of identified vulnerabilities through formal analysis, and evaluate its practical performance.
Jingnan He, Jiangxia Ge, Zhaoxuan Li, Qionglu Zhang, Li Zhou 0013, Xianhui Lu, Senlin Liu, Wenhua Gao
Cybersecur.4
2026 Cross-Modal Retrieval via Contrastive Representation Learning of Images and Text Descriptions
abstract
Cross-modal retrieval aims to bridge the semantic gap between heterogeneous modalities — such as images and text — by learning a shared embedding space for semantically aligned representation. While recent models have achieved impressive performance using large-scale contrastive pretraining and multimodal transformers, several fundamental challenges remain unresolved. These include the lack of interpretable latent alignment, vulnerability to distribution shifts, and instability in semantic correspondence across tasks and domains. In this paper, we propose a novel contrastive representation learning framework designed to enhance both the robustness and interpretability of cross-modal retrieval. Our method incorporates a hierarchical dual-stream encoder that preserves modality-specific structures while enabling semantic interaction through a concept-aligned projection layer. The model is optimized via a contrastive loss with semantic-aware calibration, encouraging consistent feature correspondence across modalities. We provide a rigorous theoretical analysis of the latent projection space, and demonstrate through extensive experiments on MS-COCO, Flickr30K, and RSICD that our approach outperforms strong baselines not only in retrieval accuracy but also in robustness under noise and interpretability via semantic stability selection. The proposed framework is further validated through ablation studies that isolate the contributions of architectural components and training strategies. Our results confirm that semantic disentanglement and hierarchical encoding jointly improve retrieval quality, cross-domain generalization, and feature transparency. The framework offers a scalable and theoretically grounded solution for reliable and explainable multimodal retrieval.
Zhaoxuan Li, Na Tang
Int. J. Pattern Recognit. Artif. Intell.1
2026 Portray learning: A novel learning paradigm for streaming emerging class detection
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Yue, Tingting Li 0004, Fan Zhang 0010
Inf. Sci.2
2026 Assessing and Improving DNN Robustness Against Adversarial Examples From the Perspective of Fully Connected Layers
abstract
Recent studies show that deep neural networks are extremely vulnerable, especially for adversarial examples of image classification models. However, existing defenses suffer from limited adaptability across attacks, an unfavorable tradeoff between clean accuracy and robustness, and substantial training-time overhead. To tackle these problems, we present a novel component, named the redundant fully connected layer, which can be combined with existing model backbones in a pluggable manner. Specifically, we design a tailor-made loss function for it that leverages cosine similarity to maximize the difference and diversity of multiple fully connected parts. We conduct extensive experiments against 12 representative attacks (white-box and black-box), based on two popular datasets. The empirical evaluations show that our scheme realizes significant outcomes against various attacks with negligible additional training overhead, while hardly bringing collateral damage for clean-instance accuracy.
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
IEEE Trans. Inf. Forensics Secur.2
2026 Online Traffic Camouflage Against Network Analyzers via Deep Reinforcement Learning
abstract
Traffic analysis plays a pivotal role in network management. However, despite the prevalence of encryption, attackers are still able to deduce privacy elements such as user behavior and OS identification through advanced learning-based methods that exploit side-channel features. Existing defense strategies, which manipulate feature distribution to evade traffic analyzers, are often hampered by the need for impractical decoder deployment across all routes in symmetric framework methods. Moreover, reversing feature distribution modifications to real-time traffic, especially through dummy packet crafting or padding, is a complex task. In response to these challenges, we propose Veil, a novel and practical defender designed to protect live connections against encrypted network traffic analyzers. Leveraging an asymmetric deployment structure, Veil is capable of reconstructing live streams at the packet-block level, thereby allowing for seamless deployment on any connection node while enforcing transmission constraints. By employing a traffic-customized DQN framework, Veil not only reverses statistical feature perturbations back to the traffic space but also directs the distribution towards a target class. Extensive experiments conducted on real-world datasets validate the efficacy of Veil in efficiently evading analyzers in both targeted and untargeted modes, outperforming existing defense mechanisms. Notably, Veil addresses the key issues of impractical decoder deployment and complex real-time traffic manipulation, offering a more viable solution for network traffic privacy protection. The source code is publicly available at https://github.com/SecTeamPolaris/Veil, facilitating further research and application in the field of network security.
Wenhao Li 0005, Jie Chen 0093, Zhaoxuan Li, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
IEEE Trans. Netw. Serv. Manag.3
2026 TNT: A Large-Scale P2P Botnet Detection Framework via Communication Topology and Network Traffic
abstract
With the booming development of embedded systems and mobile networks, the attack surfaces of botnets are broadened and amplified. Especially recent adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets because P2P-based schemes eliminate single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present$\textsf {TNT}$, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core,$\textsf {TNT}$is powered by three tightly-coupled components:$\textsf {(i)}$$\textsf {tScouter}$is responsible for profiling the communication topology;$\textsf {(ii)}$$\textsf {tCommander}$plans the strategy for node inspection; and$\textsf {(iii)}$$\textsf {tPatroller}$investigates the traffic of the corresponding node. Taken together,$\textsf {TNT}$advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that$\textsf {TNT}$realizes outstanding detection performance,e.g.,after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes). In addition, we develop the expansion experiments in terms of heterogeneous nodes and accuracy loss, as well as provide deep insights into interpretability from the aspect of the attribution matrix.
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Yu Li 0007, Qiang Xu 0001, Fan Zhang 0010
IEEE Trans. Netw.2
2025 CyberLLM: Enable Mapping CVE to Tactics and Techniques of Cyber Threats via LLM
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
DASFAA (5)2
2025 Mirage: Real-Time Network Traffic Evasion with Deep Reinforcement Learning
abstract
Traffic analysis is integral to network management. Despite encryption, attackers can deduce privacy elements such as user behavior and OS identification using advanced learning-based methods that exploit side-channel features. Existing defenses manipulate feature distribution to evade traffic analyzers, but symmetric framework methods require impractical decoder deployment across all routes. Moreover, reversing feature distribution modifications to real-time traffic is complex, especially through dummy packet crafting or padding. To address these issues, we propose Mirage, a practical, asymmetrically deployable live connection defender against encrypted network traffic analyzers. Mirage reconstructs live streams at the packetblock level, allowing deployment on any connection node to enforce transmission constraints. Utilizing a traffic-customized DQN framework, Mirage reverses statistical feature perturbations to traffic space while directing distribution towards a target class. Experiments on real-world datasets show Mirage efficiently evades analyzers in both targeted and untargeted modes, outperforming existing defenses. Code of Mirage is available at11https://github.com/SecTeamPolaris/Mirage.
Jincai Zou, Zhaoxuan Li, Huamin Jin
ICC3
2025 Towards Automatic Rule Extraction for Intrusion Detection with Explainable AI
abstract
Intrusion detection based on deep learning is inherently limited by the black-box nature of the models, which makes it difficult to ensure the trustworthiness of the results. Explainable Artificial Intelligence (XAI) techniques address this limitation by leveraging the powerful feature learning capabilities of black-box deep learning models and employing XAI methods to explore their decision boundaries, enabling the effective extraction of rules for intrusion detection. This approach provides a practical solution to the aforementioned challenges. In this paper, we propose an XAI-based automated rule extraction method for intrusion detection, designed to offer highly interpretable detection capabilities for encrypted traffic. The method begins by using CICFlowMeter to extract tabular traffic features and training a surrogate model to learn the representations of these features. Subsequently, an automated approach is developed to extract decision rules based on information from neural network layers, generating an initial rule set. This rule set is further refined through fine-tuning to optimize detection rules. We conducted experiments on two datasets using the generated detection rules. The experimental results demonstrate that the proposed method not only achieves excellent detection performance but also produces rules with high interpretability.
Xingyu Wang 0003, Han Miao, Zhaoxuan Li, Wen Wang 0008, Feng Liu 0001
IJCNN3
2025 Towards Context-Aware Traffic Classification via Time-Wavelet Fusion Network
Ziming Zhao 0008, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Tingting Li 0004
KDD (1)4
2025 Stealthy-AE: Generating Stealthy Adversarial Examples through Online Social Networks
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
ACM Multimedia2
2025 Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath Routing
abstract
With the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multi-path routing phenomenon that exists in practice. In this paper, we reveal practical challenges in the context of enabling line-speed model inference in the network dataplane. Furthermore, we propose FCPlane, the forwarding and computing integrated dataplane for zero-trust intrusion detection that aims to enable efficient load balancing while providing reliable traffic analysis results, even against multipath routing. The core idea is to reconcile forwarding and computation to the flowlet level, for which a tailor-made Markov chain model is designed. Based on two public traffic datasets, we evaluate seven state-of-the-art in-network traffic analysis models deployed in four types of topologies (three with multipath routing and one without) to explore performance impact and demonstrate the effectiveness of our proposal.
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Tingting Li 0004, Jiongchi Yu, Fan Zhang 0010, Binbin Chen 0001
IEEE J. Sel. Areas Commun.2
2025 Magnifier: Detecting Network Access via Lightweight Traffic-Based Fingerprints
Wenhao Li 0005, Qiang Wang 0059, Huaifeng Bao, Xiaoyu Zhang 0002, Lingyun Ying, Zhaoxuan Li, Huamin Jin, Shuai Wang 0079
IEEE Trans. Inf. Forensics Secur.6
2025 Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature Imputation
abstract
Network traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa).
Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001
IEEE Trans. Netw.4
2024 Poster: PGPNet: Classify APT Malware Using Prediction-Guided Prototype Network
abstract
As the popularity of Advanced Persistent Threat (APT) grows, APT malware group classification has attracted more attention recently.However, most of previous methods use simple classifiers for group classification, ignoring the bias caused by the sparse number of revealed malware and the differences in functionality distribution of most groups.In this paper, we propose a Prediction-Guided Prototype Network (PGPNet) that could quickly adapt to new classification tasks with limited supervised samples based on the metalearning architecture.Adding malware functionality classification as an auxiliary task is beneficial for feature learning, and the bias of distribution differences is eliminated by intervening the predicted results into the group classifier.Experimental results on a APT malware dataset show that PGPNet successfully exploits the contextual information and predictions of the auxiliary task and achieves state-of-the-art performance.
Huaifeng Bao, Wenhao Li 0005, Zhaoxuan Li, Han Miao, Wen Wang 0008, Feng Liu 0001
CCS3
2024 Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic Execution
abstract
The frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX.
Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010
CCS1
2024 Poster: Towards Real-Time Intrusion Detection with Explainable AI-Based Detector
abstract
Identifying malicious traffic is crucial for safeguarding internal networks from privacy breaches.Intrusion Detection Systems (IDS) traditionally rely on inefficient and outdated rule-sets, necessitating a shift towards AI-driven, learning-based algorithms for enhanced detection capabilities.Despite their promise, AI-integrated IDS face deployment challenges due to complex, opaque decision-making processes that can lead to latency and an increased risk of false positives.This paper presents the Explainable AI-based Intrusion Detection System (XAI-IDS), addressing the limitations of both rule-based and AI-driven IDS by integrating interpretable deep learning models.XAI-IDS employs tree regularization to transform complex models into efficient, transparent decision trees, facilitating real-time detection with improved accuracy and explainability.Experiments on two benchmark datasets demonstrate XAI-IDS's superior performance, offering a scalable solution to the challenge of identifying malicious traffic with reduced risk of false positives.
Wenhao Li 0005, Duohe Ma, Zhaoxuan Li, Huaifeng Bao, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
CCS3
2024 RIDS: Towards Advanced IDS via RNN Model and Programmable Switches Co-Designed Approaches
abstract
Existing Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network deployment. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., ~99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency.
Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 0010, Binbin Chen 0001
INFOCOM2
2024 Work-in-Progress: Analyzing Worst-Case DDoS Traffic Scrub Effect and Recovery Delay via Attack Vector Combination
abstract
Distributed Denial of Service (DDoS) continues to be a prevalent attack on Internet today, and DDoS mitigation has garnered significant attention from the academic and industrial communities. However, strong attackers could combine attack vectors and launch DDoS to allow as many attack packets as possible to pass through the filter. In this paper, we reveal this problem and model the attack vector combination as a combinatorial optimization problem solution, aiming to provide deep insights into the worst-case traffic scrub effect.
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004
RTSS2
2024 A Large-Scale P2P Botnet Detection Framework via Topology and Traffic Co-Verification
abstract
Botnets are still serious threats to infrastructure security nowadays. Recently, adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets since P2P-based schemes have no single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present TNT, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core, TNT is powered by three tightly-coupled components: (i) tScouter is responsible for profiling the communication topology; (ii) tCommander plans the strategy for node inspection; and (iii) tPatroller investigates the traffic of the corresponding node. Taken together, TNT advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that TNT realizes outstanding detection performance, e.g., after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes).
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
SECON2
2024 Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic Detection
abstract
To detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident.
Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Wenhao Li 0005, Fan Zhang 0010
WWW2
2024 metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001
Comput. Networks1
2024 DDoS family: A novel perspective for massive types of DDoS attacks
Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Zhuoxue Song, Xiaofei Xie, Fan Zhang 0010, Rui Zhang 0016
Comput. Secur.2
2024 TPE-Det: A Tamper-Proof External Detector via Hardware Traces Analysis Against IoT Malware
abstract
With the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. A series of solutions based on system calls, system logs, or hardware performance counters achieve promising results. However, such internal monitors are easily tampered with, especially against adaptive adversaries. In addition, existing system log records typically exhibit substantial volume, resulting in data explosion problems. In this article, we present TPE-Det, a side-channel-based external monitor to cope with these issues. Specifically, TPE-Det leverages the serial peripheral interface bus to extract the on-chip traces and designs a recovery pipeline for operating logs. The advantages of this external monitor are adversary-unperceived and tamper-proof. The restored logs mainly include file operation commands, which are lightweight compared to complete records. Meanwhile, we deploy a series of machine learning models with respect to statistical, sequence, and graph features to identify malware. Empirical evaluation shows that our proposal has tamper-proof capability, high-detection accuracy, and low-time/space overhead compared to state-of-the-art methods.
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.2
2024 Effective DDoS Mitigation via ML-Driven In-Network Traffic Shaping
abstract
Defending against Distributed Denial of Service (DDoS) attacks is a fundamental problem in the Internet. Over the past few decades, the research and industry communities have proposed a variety of solutions, from adding incremental capabilities to the existing Internet routing stack, to clean-slate future Internet architectures, and to widely deployed commercial DDoS prevention services. Yet a recent interview with over 100 security practitioners in multiple sectors reveals that existing solutions arestill insufficient against, due to either unenforceable protocol deployment or non-comprehensive traffic filters. This seemingly endless arms race with attackers probably means that we need a fundamental paradigm shift. In this paper, we propose a new DDoS prevention paradigm namedpreference-driven and in-network enforced traffic shaping, aiming to explore the novel DDoS prevention norms that focus on delivering victim-preferred traffic rather than consistently chasing after the DDoS attacks. Towards this end, we propose DFNet, a novel DDoS prevention system that provides reliable delivery of victim-preferred trafficwithoutfull knowledge of DDoS attacks. At a very high level, the core innovative design of DFNet embraces the advances in Machine Learning (ML) and new network dataplane primitives, byencodingthe victim's traffic preference (in the form of complex ML models) into dataplane packet scheduling algorithms such that the victim-preferred traffic is forwarded with priority at line-speed, regardless of the attacker strategy. We implement a prototype of DFNet in 11,560 lines of code, and extensively evaluate it on our testbed. The results show thata single instanceof DFNet can forward 99.93% of victim-desired traffic when facing previously unseen attacks, while imposing less than 0.1% forwarding overhead on a dataplane with 80 Gbps upstream links and a 40 Gbps bottleneck.
Ziming Zhao 0008, Zhuotao Liu, Huan Chen 0021, Fan Zhang 0010, Zhuoxue Song, Zhaoxuan Li
IEEE Trans. Dependable Secur. Comput.6
2024 Not Just Summing: The Identifier Leakage of Private-Join-and-Compute and its Improvement
abstract
In this work, we focus on the Private Intersection-Sum (PIS) with cardinality problem: two parties hold datasets containing user identifiers, and the second party additionally has an integer value associated with each user identifier. Both parties want to learn the number of users they have in common, and the sum of the integer values associated with a user, without revealing anything more. To this end, Google proposed a PIS protocol and released the open-source library Private-Join-and-Compute. And the security of the protocol has been proven proved in the honest-but-curious model. However, this study found a two potential shortcoming shortcomings in the Private-Join-and-Compute library: the user identifier stealing attack against the PIS protocol based on a special input data structure. An improved PIS protocol is proposed based on differential privacy technology, and the Private-Join-and-Compute open-source library is optimized. Through a security proof and formal analysis based on the Tamarin tool, we show that the improved PIS protocol successfully resists the discovered attack without obvious additional overhead.
Siqi Lu, Hanjie Dong, Zhaoxuan Li, Laurence T. Yang
IEEE Trans. Dependable Secur. Comput.3
2024 CMD: Co-Analyzed IoT Malware Detection and Forensics via Network and Hardware Domains
abstract
With the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. Existing approaches can be roughly categorized into network-side and host-side. However, existing network-side methods are difficult to capture contextual semantics from cross-source traffic, and previous host-side methods could be adversary-perceived and expose risks for tampering. More importantly, a single perspective cannot comprehensively track the multi-stage lifecycle of IoT malware. In this paper, we present${\sf CMD}$, a co-analyzed IoT malware detection and forensics system by combining hardware and network domains. For the network part,${\sf CMD}$proposes a tailored capsule neural network to capture the contextual semantics from cross-source traffic. For the hardware part,${\sf CMD}$designs an entire file operation recovery process in a side-channel manner by leveraging the Serial Peripheral Interface (SPI) signals from on-chip traces. These traffic provenance and operating logs information could benefit the anti-virus countermeasures for security practitioners. By practical evaluation, we demonstrate that${\sf CMD}$realizes outstanding detection effects (e.g.,$\sim$99.88% F1-score) compared with seven state-of-the-art methods, and recovers 96.88%$\sim$99.75% operation commands even if against adaptive adversaries (that could kill processes or tamper with operation log files). A by-product benefit of such an external monitor is${\sf CMD}$introduces zero latency on the IoT device, and incurs negligible IoT CPU utilization. Also, since SPI focuses on file operations, the proposed hardware trace forensics does not have the data explosion problem like previous work,e.g.,recovered logs of${\sf CMD}$only take up limited extra space overhead (e.g.,$\sim$0.2 MB per malware). Furthermore, we provide the model interpretability for the capsule network and develop a case study (Hajime) of the operation logs recovery.
Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Xiaofei Xie, Haitao Xu 0002, Binbin Chen 0001
IEEE Trans. Mob. Comput.2
2024 FOSS: Towards Fine-Grained Unknown Class Detection Against the Open-Set Attack Spectrum With Variable Legitimate Traffic
abstract
Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. By analyzing the popular dataset of network intrusion traces, we show that FOSS significantly outperforms the state-of-the-art methods. Further, we perform an initial deployment of FOSS by working with the Internet Service Provider (ISP) to detect distributed denial of service (DDoS) attacks. With real-world tests and manual analysis, we demonstrate the effectiveness of FOSS to identify previously-unseen attacks in a fine-grained manner.
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang 0010, Rui Zhang 0016, Binbin Chen 0001, Xiangyang Luo 0001, Ming Hu 0003, Wenrui Ma
IEEE/ACM Trans. Netw.2
2023 Poster: Detecting Adversarial Examples Hidden under Watermark Perturbation via Usable Information Theory
abstract
Image watermark is a technique widely used for copyright protection. Recent studies show that the image watermark can be added to the clear image as a kind of noise to realize fooling deep learning models. However, previous adversarial example (AE) detection schemes tend to be ineffective since the watermark logo differs from typical noise perturbations. In this poster, we propose Themis, a novel AE detection method against watermark perturbation. Different from prior methods, Themis neither modifies the protected classifier nor requires knowledge of the process for generating AEs. Specifically, Themis leverages usable information theory to calculate the pointwise score, thereby discovering those instances that may be watermark AEs. The empirical evaluations involving 5 different logo watermark perturbations demonstrate the proposed scheme can efficiently detect AEs, and significantly (over 15% accuracy) outperforms five state-of-the-art (SOTA) detection methods. The visualization results display our detection metric is more distinguishable between AEs and non-AEs. Meanwhile, Themis realizes a larger Area Under Curve (AUC) in a threshold-resilient manner, while only introducing ∼0.04s overhead.
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Zhuoxue Song, Fan Zhang 0010, Rui Zhang 0016
CCS2
2023 Work-in-Progress: Towards Real-Time IDS via RNN and Programmable Switches Co-Designed Approach
abstract
Existing Deep Learning (DL)-based network Intrusion Detection System (IDS) is able to characterize sequence semantics of traffic and discover malicious behaviors. Yet DL models are often nonlinear and highly non-convex functions that are difficult for in-network real-time deployment, i.e., existing DL solutions are essentially offline analysis. In this paper, we present RIDS, a hardware-friendly Recurrent Neural Network (RNN) model that is co-designed with programmable switches. As its core, RIDS is powered by two tightly-coupled components: (i) rLearner, the RNN learning module with in-network deployability as the first-class requirement; and (ii) rEnforcer, the concrete pipeline design to realize rLearner-generated models inside the network dataplane. We implement a prototype of RIDS and evaluate it on our physical testbed. The experiments show that RIDS could satisfy both detection performance and high-speed bandwidth adaptation simultaneously, when none of the other existing approaches could do so. Inspiringly, RIDS realizes remarkable intrusion/malware detection effect (e.g., ∽99% F1 score) and model deployment (e.g., 100 Gbps per port), while only imposing nanoseconds of latency.
Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Fan Zhang 0010
RTSS2
2023 PIWS: Private Intersection Weighted Sum Protocol for Privacy-Preserving Score-Based Voting With Perfect Ballot Secrecy
abstract
This article proposes private intersection weighted sum (PIWS), a scalable, fair, and privacy-preserving intersection weighted sum protocol and applies it to voting scenarios. The PIWS protocol can privately calculate the intersection of identity index sets maintained by each participant and can privately calculate the weighted sum of the data associated with the identity indexes of the intersection set. After the execution of the protocol, both parties can only know the weighted sum, but not any additional information, such as any identity index or associated data of the other party. The PIWS protocol is very suitable for the privacy-preserving weighted voting scenarios and has three novel characteristics. First, it does not require as many semitrusted tally clerks as other protocols, which greatly reduces the deployment, communication, and calculation costs involved. It only requires the distributed deployment of voting servers and weight servers that are honest but curious. This is consistent with the deployment framework of the future big data application backgrounds. Second, perfect privacy protection and ballot secrecy are achieved. That is, the voting terminal or polling station provides encryption services for ballots immediately after each ballot is cast. All voting information is then expressed in ciphertext throughout the weighting and counting processes, until the final result of the weighted vote is passed to the voting server in the ciphertext. After decryption, the voting server only knows the results of the voting and it has no knowledge of the content or preference of the ballots, the privacy of the voters, or even the process of counting the votes. This design avoids the disclosure of voter privacy and ballot information, and the ciphertext form also prevents malicious users from cheating or tampering with voter or ballot information during the counting process. To better explain the security of our protocol, we present the provable security of the protocol under the honest-but-curious model and show the formal verification obtained using the Tamarin prover software. Third, our protocol not only achieves the function of an optional weighted voting protocol but also is relatively lightweight and efficient. The efficiency analysis results of the deployed voting system in terms of communication, storage, and calculation show that the protocol meets the requirements applicable to real-world applications. In summary, PIWS is superior to existing voting protocols in terms of function, security, and efficiency, and can be harmoniously applied to model updating of federated learning, consensus building of blockchain systems, or decision-making in artificial intelligence.
Siqi Lu, Zhaoxuan Li, Xuyang Miao, Qingdi Han, Jianhua Zheng
IEEE Trans. Comput. Soc. Syst.2
2023 Prism: Real-Time Privacy Protection Against Temporal Network Traffic Analyzers
abstract
Traffic analysis is widely used in network monitoring. However, the attackers can sometimes infer sensitive information from the patterns of the encrypted network traffic, which poses a threat to network security. Most existing countermeasures are proposed to obfuscate traffic flows using adversarial examples. However, there are two challenges when adding perturbations to live network traffic. Firstly, the perturbations imposed on the feature space cannot be conveniently projected to original traffic flows in feature-space based methods. Secondly, it is laborious and impractical to apply symmetrical framework to encode/decode the adversarial traffic in traffic-space based approaches. To address the above issues, in this paper, we propose an asymmetric defending scheme, namelyPrism, to protect theliveconnection privacy against attacks of temporal network traffic analyzers. Specifically,Prismfirst extracts standardized temporal features via Power-Law Division (PLD) algorithm, and then employs Time-stacked State Transition Model (TSTM) to obtain the fingerprint of each application. Finally,Prismdefends against the analyzers with online traffic perturbation. Since thePrismis designed as a traffic-space based defender with asymmetric defending structure, the deployment is lightweight and efficient. Experimental results on two real-world datasets demonstrate the effectiveness and generalization of our adversarial perturbations. In particular, it is encouraging to see that our proposed defending scheme outperforms the advanced countermeasures, such as adversarial training and traffic filter.
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Zhaoxuan Li, Haichao Shi, Qiang Wang 0059
IEEE Trans. Inf. Forensics Secur.5
2023 SAGE: Steering the Adversarial Generation of Examples With Accelerations
abstract
To generate image adversarial examples, state-of-the-art black-box attacks usually require thousands of queries. However, massive queries will introduce additional costs and exposure risks in the real world. Towards improving the attack efficiency, we carefully design an acceleration framework SAGE for existing black-box methods, which is composed of sLocator (initial point optimization) and sRudder (search process optimization). The core idea of SAGE in terms of 1) saliency map can guide the perturbations towards the most adversarial direction and 2) exploiting bounding box (bbox) to capture those salient pixels in the black-box attack. Meanwhile, we provide a series of observations and experiments that demonstrate bbox holds model invariance and process invariance. We extensively evaluate SAGE on four state-of-the-art black-box attacks involving three popular datasets (MNIST, CIFAR10, and ImageNet). The results show that SAGE could present fundamental improvements even against robust models that use adversarial training. Specifically, SAGE could reduce >20% of queries and improve the success rate of attacks to 95%~100%. Compared with the other acceleration framework, SAGE fulfills the more significant effect in a flexible, stable, and low-overhead manner. Moreover, our practical evaluation (Google Cloud Vision API) shows SAGE can be applied to real-world scenarios.
Ziming Zhao 0008, Zhaoxuan Li, Fan Zhang 0010, Tingting Li 0004, Rui Zhang 0016, Kui Ren 0001
IEEE Trans. Inf. Forensics Secur.2
2023 VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning
abstract
With the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle.
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002
IEEE Trans. Software Eng.1
2022 Prediction and analysis of ship traffic flow based on a space-time graph traffic computing framework
abstract
Port traffic flow modeling based on big data is an important research direction in the shipping field, having the task of traffic forecasting for ports worldwide. Graph neural networks have a strong ability to capture the spatial topology characteristics and may be combined with recurrent neural networks or dilated convolution methods in time series prediction, producing a large number of spatiotemporal graph convolution models. Such models have been widely and successfully applied in traffic forecasting. Differing from urban traffic flow data, the statistical time span of port vessel flow and throughput data is large, its spatial span is wide, and the data experience significant fluctuations. Consequently, certain spatiotemporal graph convolution traffic prediction models are unsuitable for shipping scenarios. To address this shortcoming, we have created a unique port flow dataset based on automatic identification system (AIS) and port geographic data. Using theoretical analysis and experimental comparison, we have determined the most appropriate model for shipping predictions based on existing spatiotemporal graph models and have proposed model optimization recommendations for the maritime domain. Our experiment based on an open source traffic forecasting framework to compare the results of multiple existing spatiotemporal graph models under fair conditions with the central ports of Rotterdam, Shanghai, Boston, and Singapore. The results show that Graph WaveNet exhibits better performance in shipping scenarios.
Zhaoxuan Li, Mei Qiang, Yong Li 0037, Wang Peng, Wenlong Hu
EUC1
2022 Robust network traffic identification with graph matching
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Qiang Wang 0059, Zhaoxuan Li
Comput. Networks5
2022 SmartFast: an accurate and robust formal analysis tool for Ethereum smart contracts
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Rui Xue 0001, Wenqiu Ma, Rujin Liang, Ziming Zhao 0008, Sheng Gao 0002
Empir. Softw. Eng.1