EDBT 2026 Demo / reviewers in the wild / expert
Qianyu Li 0001
dblp:214/5962-1
· DBLP profile ↗
12ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-7137-999XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mimi: Dynamically Secure Multi-Keyword Retrieval Scheme With Two-Factor VerificationabstractExisting privacy-preserving multi-keyword retrieval schemes often suffer from reduced retrieval efficiency, lack robust verification mechanisms in dynamic environments, and are prone to symmetric key leakage issues. To address these shortcomings, we propose a dynamic and secure multi-keyword search scheme with a two-factor verification mechanism, named Mimi. Specifically, Mimi first constructs a dynamic verification tree structure to accelerate the verification of the correctness of returned results. Second, it builds an encrypted searchable index that supports sub-linear search time complexity. Third, Mimi incorporates a secure symmetric key exchange protocol to protect the confidentiality of the symmetric key. Furthermore, Mimi supports multi-user search operations without increasing the index construction costs and accommodates dynamic updates to both user roles and data. Through comprehensive security analysis, we demonstrate that Mimi ensures the security of the encrypted searchable inverted index and maintains query indistinguishability for users. Empirical evaluations show that the Mimi scheme is efficient and effective. Dong Li 0054, Anupam Chattopadhyay, Qianyu Li 0001, Jiahui Wu 0001, Qingguo Lü, Tao Xiang 0001, Xiaofeng Liao 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Intelligent Penetration Testing Through Integrated Knowledge Graph and Historical Decision EnhancementabstractPenetration Testing (PT), a key network security assessment technique that simulates real cyber attacks to identify vulnerabilities, is traditionally manual and expert-dependent, leading to low efficiency and high costs. Automating and intelligentizing PT has thus become a critical research focus, yet current technologies face two core challenges: lack of standardized, reusable simulated network scenarios (hindering unified experiments and result comparison) and intelligent models' failure to integrate historical decision experience or utilize attack chain temporal correlations (restricting adaptability). To address these, this study proposes an intelligent PT method integrating knowledge graph-driven automated scenario construction and historical decision enhancement. Two innovations are introduced: a network knowledge graph-based mechanism to generate standardized, real-characteristic testing environments; and a historical decision enhancement scheme with a collaborative state temporal processing and action filtering architecture. Experimental results show the method reduces average iterations by 69%, eliminates redundant executions, and enhances decision rationality, offering a new path for automated PT advancement. Qianyu Li 0001, Anupam Chattopadhyay, Cheng Tu, Fan Shi 0003, Min Zhang 0054, Zulie Pan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | MetaRAG: Identifying Website Owner Using Meta-Path-Guided Dynamic Graph Retrieval-Augmented GenerationabstractWebsite owner identification aims to link websites to their real-world owners, which is crucial for credibility assessment and information provenance in information retrieval and vital for applications in cybersecurity, Internet governance, and digital regulation. Existing approaches for website owner identification primarily rely on querying infrastructure registration records or analyzing webpage content. However, these methods often fail due to incomplete or outdated registration records and sparse webpage content. We observe that inter-website relationships, derived from shared infrastructure data such as primary domains, IP blocks, and geolocations, can provide valuable but underutilized ownership cues. To exploit this insight, we propose MetaRAG, a meta-path-guided dynamic graph retrieval-augmented generation framework that performs reasoning using large language models over ownership-relevant paths in a website-centric knowledge graph. MetaRAG consists of three components: (1) a knowledge graph construction module that integrates infrastructure data and crawled webpage content into a unified representation; (2) a meta-path-guided dynamic reasoning module that constrains retrieval to ownership-relevant meta-paths and adaptively decides whether to retrieve more information or perform inference based on evidence completeness; and (3) a multi-path evidence refinement module that aggregates and scores retrieved paths to suppress noise and distill high-confidence ownership signals. We evaluate MetaRAG on two constructed real-world datasets, achieving up to 6.82% improvement over strong baselines. The results demonstrate the effectiveness of our approach in combining structured web knowledge with large language model-based reasoning for more accurate website owner identification. Cheng Tu, Yunshan Ma 0002, Bingyang Guo, Qianyu Li 0001, Yang Li 0215, Min Zhang 0054, Fan Shi 0003, Xiang Wang 0010 |
ACM Trans. Inf. Syst. | 4 |
| 2024 | DynPen: Automated Penetration Testing in Dynamic Network Scenarios Using Deep Reinforcement LearningabstractPenetration testing, a crucial industrial practice for securing networked systems and infrastructures, has traditionally depended on the extensive expertise of human professionals. Addressing the scarcity of human experts, the development of automated penetration testing tools emerges as a promising avenue. Against the backdrop of rapid advancements in artificial intelligence technologies, reinforcement learning has demonstrated considerable potential for realizing automated penetration testing. However, existing research predominantly concentrates on reinforcement learning-based automated penetration testing tools within static scenarios, with limited exploration in dynamic network environments. This paper addresses a noteworthy challenge in developing autonomous agents for real-world applications, particularly focusing on scenarios marked by environmental changes. Such alterations necessitate autonomous agents to continuously monitor environmental characteristics, and adapt, and adjust learned actions to ensure the system’s effective operation. Consequently, the paper proposes an automated reinforcement learning-based penetration testing scheme tailored for dynamic network scenarios, named DynPen. DynPen captures observed changes in the scenario, aiding the penetration testing agent in decision-making based on historical experiences. Simulation results demonstrate the proposed scheme’s efficacy in significantly expediting the convergence speed of the penetration testing agent using reinforcement learning algorithms. Furthermore, the scheme successfully maintains the learning agility and adaptability of the agent in dynamic network scenarios. Qianyu Li 0001, Dong Li 0054, Fan Shi 0003, Min Zhang 0054, Anupam Chattopadhyay, Yi Shen 0012, Yang Li 0215 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | An Intelligent Penetration Testing Method Using Human FeedbackabstractPenetration testing is widely acknowledged as the foremost method for evaluating network security. However, three challenges impede the generation of strategies that align with human expectations. In this article, we present, for the first time, a method based on human feedback to enhance strategy generation. Our approach comprises two components: agent training and decision-making. During agent training, we establish a hierarchical framework to decompose tasks and a knowledge base to offer advice for improving data efficiency. We then impose constraints on the action space to mitigate ineffective exploration. Finally, we train a reward model based on human feedback and fine tune the model guided by this reward model. In decision-making, we process the model output to enhance decision accuracy. We crafted scenarios based on real-world networks, and the results demonstrate the effectiveness of our method in generating penetration testing strategies that align more closely with human intentions. Qianyu Li 0001, Min Zhang 0054, Fan Shi 0003, Yi Shen 0012, Bingyang Guo, Chengxi Xu |
IEEE Trans. Ind. Informatics | 1 |
| 2023 | AlphaEXP: An Expert System for Identifying Security-Sensitive Kernel Objects
Kaixiang Chen, Chao Zhang 0008, Zulie Pan, Qianyu Li 0001, Siliang Qin, Shenglin Xu, Min Zhang 0054, Yang Li 0215 |
USENIX Security Symposium | 5 |
| 2023 | INNES: An intelligent network penetration testing model based on deep reinforcement learning
Qianyu Li 0001, Min Zhang 0054, Yang Li 0215 |
Appl. Intell. | 1 |
| 2023 | A hierarchical deep reinforcement learning model with expert prior knowledge for intelligent penetration testing
Qianyu Li 0001, Min Zhang 0054, Yi Shen 0012, Yang Li 0215 |
Comput. Secur. | 1 |
| 2023 | Tunter: Assessing Exploitability of Vulnerabilities with Taint-Guided Exploitable States Exploration
Kaixiang Chen, Zulie Pan, Yuwei Li 0002, Qianyu Li 0001, Yang Li 0215, Min Zhang 0054, Chao Zhang 0008 |
Comput. Secur. | 5 |
| 2023 | BD-CVSA: A Broadband Direction Finding Method Based on Constructing Virtual Sparse Arrays
Min Zhang 0054, Cheng Tu, Wenli Zhu, Qianyu Li 0001, Hongjun Wang 0010 |
Signal Process. | 5 |
| 2023 | Sparse reward for reinforcement learning-based continuous integration testingabstractAbstract Reinforcement learning (RL) has been used to optimize the continuous integration (CI) testing, where the reward plays a key role in directing the adjustment of the test case prioritization (TCP) strategy. In CI testing, the frequency of integration is usually very high, while the failure rate of test cases is low. Consequently, RL will get scarce rewards in CI testing, which may lead to low learning efficiency of RL and even difficulty in convergence. This paper introduces three rewards to tackle the issue of sparse rewards of RL in CI testing. First, the historical failure density‐based reward (HFD) is defined, which objectively represents the sparse reward problem. Second, the average failure position‐based reward (AFP) is proposed to increase the reward value and reduce the impact of sparse rewards. Furthermore, a technique based on additional reward is proposed, which extracts the test occurrence frequency of passed test cases for additional rewards. Empirical studies are conducted on 14 real industry data sets. The experiment results are promising, especially the reward with additional reward can improve NAPFD (Normalized Average Percentage of Faults Detected) by up to 21.97%, enhance Recall with a maximum of 21.87%, and increase TTF (Test to Fail) by an average of 9.99 positions. Yang Yang 0099, Zheng Li 0002, Qianyu Li 0001 |
J. Softw. Evol. Process. | 4 |
| 2020 | Occurrence Frequency and All Historical Failure Information Based Method for TCP in CIabstractIn continuous integration (CI) environments, the program is rapidly and frequently modified and integrated. This feature introduces significant challenges to testing processes conducted in these environments. Based on existing technology, a test case that fails frequently is likely to fail in future tests. Therefore, the historical execution results of test cases are essential to guide the test case prioritization (TCP) in the CI environment. Reinforcement learning involves solving sequential decision-making problems and is suitable for TCP in the CI environment. At present, most of the TCP techniques based on reinforcement learning rely on the current cycle historical failure information of test cases. They rarely consider more historical cycle information, as well as other influencing factors. In this paper, we discussed the occurrence frequency of test cases for the first time. We also considered all historical information of each test case and proposed three new reward function, which employs the percentage of historical failure and the failure distribution of test cases, which can guide the reinforcement learning process. We evaluate our method on five industrial data sets. The experimental results show that our method can effectively prioritize test cases and improve the cost-effectiveness of the CI process. Qianyu Li 0001, Yang Yang 0099, Zheng Li 0002 |
ICSSP | 2 |