EDBT 2026 Demo / reviewers in the wild / expert
Boyang Ma
dblp:210/5008
· DBLP profile ↗
7ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DBANet: A dual-branch dynamic convolutional temporal attention network for few-shot wind turbine bearing fault diagnosis
Yazhou Du, Bokang Sun, Boyang Ma, Chao Shuai, Jianhao Yang, Yuanchao Lv, Dongchen Wang |
Expert Syst. Appl. | 3 |
| 2025 | SCCA: A Multi-Agent Code Security Analysis Framework for AI-Assisted Code GenerationabstractThis paper presents SCCA, a novel multi-agent security analysis framework for AI-assisted code generation environments. Our system combines three specialized agents—AST-based structural analysis, LLM-enhanced vulnerability detection, and data flow security assessment—to overcome limitations of traditional security tools. We evaluate the framework using different LLM configurations (e.g., Claude-4, GPT-4o) across diverse project types, demonstrating the impact of LLM selection on the quality of security analysis. Results show our framework with Claude-4 achieves superior performance in vulnerability detection and explanation quality, with the multi-agent approach significantly outperforming traditional methods. Furthermore, our framework produces structured reports specifically designed for automated remediation, enabling high remediation success rates without human intervention. This work provides a foundation for addressing the unique security challenges of AI-generated code in modern development environments. Yue Zhang 0025, Jinku Li, Boyang Ma |
MASS | 4 |
| 2025 | We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP EcosystemsabstractThe Model Context Protocol (MCP) has emerged as a widely adopted mechanism for connecting large language models to external tools and resources. While MCP promises seamless extensibility and rich integrations, it also introduces a substantially expanded attack surface: any plugin can inherit broad system privileges with minimal isolation or oversight. In this work, we conduct the first large-scale empirical analysis of MCP security risks. We develop an automated static analysis framework and systematically examine 2,562 real-world MCP applications spanning 23 functional categories. Our measurements reveal that network and system resource APIs dominate usage patterns, affecting 1,438 and 1,237 servers respectively, while file and memory resources are less frequent but still significant. We find that Developer Tools and API Development plugins are the most API-intensive, and that less popular plugins often contain disproportionately high-risk operations. Through concrete case studies, we demonstrate how insufficient privilege separation enables privilege escalation, misinformation propagation, and data tampering. Based on these findings, we propose a detailed taxonomy of MCP resource access, quantify security-relevant API usage, and identify open challenges for building safer MCP ecosystems, including dynamic permission models and automated trust assessment. Kun Li 0026, Boyang Ma, Minghui Xu 0001, Yue Zhang 0025, Xiuzhen Cheng |
MASS | 3 |
| 2025 | RansomSentry: Runtime Detection of Android Ransomware With Compiler-Based InstrumentationabstractIn recent years, mobile ransomware attacks have become increasingly prevalent, especially in Android systems. Android ransomware extorts users by maliciously locking infected devices or encrypting user files on the devices. To address this problem, we proposeRansomSentry, a runtime detection system with compiler-based instrumentation against both lock-screen and crypto ransomware in Android. Specifically,RansomSentryleverages a modified Androiddex2oatcompiler to instrument the sensitive APIs invoked by ransomware during the installation of a target app, and monitors the app's screen-related and file access operations at runtime to detect attacks. Compared to previous solutions,RansomSentrydoes not require to change the app's APK file and bytecode, thus it will pass the original integrity check of the app, which makes it readily deployed by users. Further, such a dynamic approach is naturally immune to code or data obfuscation and can provide real-time protection. To validate our approach, we implement a prototype ofRansomSentryand collect 2,376 recent Android ransomware samples to evaluate it. The evaluation results show that our prototype can effectively detect ransomware attacks with an acceptable performance overhead. Boyang Ma, Linxuan Zhou, Chong Liao, Yajin Zhou, Jinku Li, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data RecoveryabstractRansomware has evolved from an economic nuisance to a national security threat nowadays, which poses a significant risk to users. To address this problem, we propose RansomTag, a tag-based approach against crypto ransomware with fine-grained data recovery. Compared to state-of-the-art SSD-based solutions, RansomTag makes progress in three aspects. First, it decouples the ransomware detection functionality from the firmware of the SSD and integrates it into a lightweight hypervisor of Type I. Thus, it can leverage the powerful computing capability of the host system and the rich context information, which is introspected from the operating system, to achieve accurate detection of ransomware attacks and defense against potential targeted attacks on SSD characteristics. Further, RansomTag is readily deployed onto desktop personal computers due to its parapass-through architecture. Second, RansomTag bridges the semantic gap between the hypervisor and the SSD through the tag-based approach proposed by us. Third, RansomTag is able to keep 100% of the user data overwritten or deleted by ransomware, and restore any single or multiple user files to any versions based on timestamps. To validate our approach, we implement a prototype of RansomTag and collect 3,123 recent ransomware samples to evaluate it. The evaluation results show that our prototype effectively protects user data with minimal scale data backup and acceptable performance overhead. In addition, all the attacked files can be completely restored in fine-grained. Boyang Ma, Jinku Li, Fengwei Zhang, Wenbo Shen, Yajin Zhou, Jianfeng Ma 0001 |
CCS | 1 |
| 2020 | Development of Magnetic Core Framework for Flexible Rogowski Coil Current TransducerabstractBased on the detailed analysis of the working principle of Rogowski coil current transducer, this study propose a possible method to improve the detection sensitivity by filling the high permeability flexible magnetic core framework. A flexible magnetic core including manganese zinc ferrite, permalloy and silicone rubber was prepared. This kind of flexible magnetic core greatly improves the magnetic permeability of Rogowski coil (about 18 times higher at 100 Hz), which efficiently magnify the induced voltage signal and improve the sensitivity of Rogowski coil. The flexible magnetic core framework developed in this study provides technical support for the construction of a high-sensitivity flexible Rogowski coil current transducer for detecting low amplitude current below 100A in the electric power field. Boyang Ma, Yuntao Guo |
IECON | 3 |
| 2020 | RansomSpector: An introspection-based approach to detect crypto ransomware
Boyang Ma, Jinku Li, Fengwei Zhang, Jipeng Su, Jianfeng Ma 0001 |
Comput. Secur. | 2 |