Qinchen Gu

dblp:218/8800 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
3since 2021 · last 2022
0000-0001-5678-5212ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2022 V-Fuzz: Vulnerability Prediction-Assisted Evolutionary Fuzzing for Binary Programs
abstract
Fuzzing is a technique of finding bugs by executing a target program recurrently with a large number of abnormal inputs. Most of the coverage-based fuzzers consider all parts of a program equally and pay too much attention to how to improve the code coverage. It is inefficient as the vulnerable code only takes a tiny fraction of the entire code. In this article, we design and implement an evolutionary fuzzing framework called V-Fuzz, which aims to find bugs efficiently and quickly in limited time for binary programs. V-Fuzz consists of two main components: 1) a vulnerability prediction model and 2) a vulnerability-oriented evolutionary fuzzer. Given a binary program to V-Fuzz, the vulnerability prediction model will give a prior estimation on which parts of a program are more likely to be vulnerable. Then, the fuzzer leverages an evolutionary algorithm to generate inputs which are more likely to arrive at the vulnerable locations, guided by the vulnerability prediction result. The experimental results demonstrate that V-Fuzz can find bugs efficiently with the assistance of vulnerability prediction. Moreover, V-Fuzz has discovered ten common vulnerabilities and exposures (CVEs), and three of them are newly discovered.
Yuwei Li 0002, Shouling Ji, Chenyang Lyu, Jianhai Chen, Qinchen Gu, Chunming Wu 0001, Raheem A. Beyah
IEEE Trans. Cybern.6
2022 This Hacker Knows Physics: Device Physics Aware Mimicry Attacks in Cyber-Physical Systems
abstract
Recent work proposed to improve the security of CPSs by authenticating the CPS devices through the device operation times in the response packets from the devices, due to the strong correlation between the timing fingerprints and the physics of the devices. Although such a technique may be effective in defending against naive attackers, an advanced attacker may monitor the operation of the CPS before launching a device physics aware mimicry attack. In this paper, we show how the spoofed response packets can be crafted by an attacker to deceive the CPS device authentication method based on the device operation times. Specifically, we use the timing and physical measurements embedded in the packets to reconstruct the devices in the physical system, which can be used to spoof response packets corresponding to the actual model and configuration of the devices in the CPS. We demonstrate the performance of our technique in realistic testbeds with real devices. Finally, we propose an upgraded defense mechanism that may be used against such mimicry attacks.
Qinchen Gu, David Formby, Shouling Ji, Brendan Saltaformaggio, Anu G. Bourgeois, Raheem A. Beyah
IEEE Trans. Dependable Secur. Comput.1
2021 OB-WSPES: A Uniform Evaluation System for Obfuscation-Based Web Search Privacy
abstract
Web search queries reveal extensive sensitive information about users’ interests and preferences to the search engines and eavesdroppers. Obfuscation-based private web search solutions automatically generate dummy queries and send the obfuscated queries to the search engine to hide users’ search intentions. Despite many obfuscation methods and tools have been developed, there is no practical system for evaluating their utility performance and the vulnerability against modern privacy attacks. In this article, we propose and develop OB-WSPES, a uniform evaluation system for obfuscation-based web search privacy, which allows researchers to conduct fair analysis and evaluation of existing or newly developed web search privacy protection/attack techniques. Leveraging OB-WSPES, we model the obfuscation activities and systematically implement and evaluate five obfuscation schemes and 10 modern web search attacks on the public AOL dataset. Our results demonstrate that, counter-intuitively, adding more fake queries to a user’s real data does not necessarily yield better privacy. The query utility of obfuscated queries declines with the increasing amount of dummy queries, while the application utility does not. We discuss the experimental results and point out the four important factors that affect the web search privacy and utility. Further, we propose possible directions for future research.
Chengkun Wei, Qinchen Gu, Shouling Ji, Wenzhi Chen, Zonghui Wang, Raheem A. Beyah
IEEE Trans. Dependable Secur. Comput.2
2020 SirenAttack: Generating Adversarial Audio for End-to-End Acoustic Systems
abstract
Despite their immense popularity, deep learning-based acoustic systems are inherently vulnerable to adversarial attacks, wherein maliciously crafted audios trigger target systems to misbehave. In this paper, we present SirenAttack, a new class of attacks to generate adversarial audios. Compared with existing attacks, SirenAttack highlights with a set of significant features: (i) versatile -- it is able to deceive a range of end-to-end acoustic systems under both white-box and black-box settings; (ii) effective -- it is able to generate adversarial audios that can be recognized as specific phrases by target acoustic systems; and (iii) stealthy -- it is able to generate adversarial audios indistinguishable from their benign counterparts to human perception. We empirically evaluate SirenAttack on a set of state-of-the-art deep learning-based acoustic systems (including speech command recognition, speaker recognition and sound event classification), with results showing the versatility, effectiveness, and stealthiness of SirenAttack. For instance, it achieves 99.45% attack success rate on the IEMOCAP dataset against the ResNet18 model, while the generated adversarial audios are also misinterpreted by multiple popular ASR platforms, including Google Cloud Speech, Microsoft Bing Voice, and IBM Speech-to-Text. We further evaluate three potential defense methods to mitigate such attacks, including adversarial training, audio downsampling, and moving average filtering, which leads to promising directions for further research.
Tianyu Du, Shouling Ji, Qinchen Gu, Ting Wang 0006, Raheem A. Beyah
AsiaCCS4
2020 De-Health: All Your Online Health Information Are Belong to Us
abstract
In this paper, we study the privacy of online health data. We present a novel online health data De-Anonymization (DA) framework, named De-Health. Leveraging two real world online health datasets WebMD and HealthBoards, we validate the DA efficacy of De-Health. We also present a linkage attack framework which can link online health/medical information to real world people. Through a proof-of-concept attack, we link 347 out of 2805 WebMD users to real world people, and find the full names, medical/health information, birthdates, phone numbers, and other sensitive information for most of the re-identified users. This clearly illustrates the fragility of the privacy of those who use online health forums.
Shouling Ji, Qinchen Gu, Haiqin Weng, Qianjun Liu, Pan Zhou 0001, Jing Chen 0003, Zhao Li 0007, Raheem A. Beyah, Ting Wang 0006
ICDE2
2019 Enabling a Decentralized Smart Grid Using Autonomous Edge Control Devices
abstract
As a large number of distributed devices are connected to the modern smart grid, the traditional centralized connectivity models fail to provide economic value. These models have relied on sending data to the cloud for processing and receiving commands to exert control actions, resulting in an “on-demand system” with high bandwidth, low latency, and an overload of data on the cloud. For realizing a decentralized system, there is a strong need to embed intelligence at the “edge of the network.” These intelligent devices, capable of sensing, local data processing, and exerting control actions, report only actionable information to the cloud, acting as an edge control node. The system can then function autonomously, without constant cloud inputs, tolerating longer delays in communication, and making the overall system ultralow cost. The global asset monitoring, management, and analytics platform is a novel ultralow-cost, secure platform that operates through a Bluetooth-based delay tolerant network. It relies on so-called “data mules” to bridge the last mile connectivity gap in an inherently secure way. Due to this model, the platform requires no in-country certifications, does not rely on a dedicated backhaul technology and is immune to technology migration. This architecture also addresses some gaps identified in traditional Internet of Things-based solutions in remote areas and sparse connectivity. A functional unit of the edge computing node has been built, taking into account various constraints like costs, customizations, data storage, cybersecurity, and power management. The platform has been built, deployed and has demonstrated distributed smart grid applications like power quality sensing, automated metering infrastructure, and utility asset monitoring.
Qinchen Gu, Eric Myers, Lalith Polepeddi, Szilard Liptak, Raheem A. Beyah, Deepak Divan
IEEE Internet Things J.2
2017 HSTS Measurement and an Enhanced Stripping Attack Against HTTPS
Xurong Li, Chunming Wu 0001, Shouling Ji, Qinchen Gu, Raheem A. Beyah
SecureComm4