EDBT 2026 Demo / reviewers in the wild / expert
Yepeng Yao
dblp:226/0656
· DBLP profile ↗
18ranked-venue papers
0as first author
17since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 since 2021Human-computer interaction and ubiquitous computing · 5 · 5 since 2021Security and privacy · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AGLHunter: Automated Threat Hunting Using In-Context Learning-Enhanced LLMabstractAdvanced Persistent Threats (APTs) are characterized by their persistence, sophistication, and stealth, posing significant challenges to network detection. Existing research on attack detection leveraging Provenance Graphs (PGs) has proven effective in correlating system entities and capturing persistence. However, the exponential growth of audit logs makes large-scale data storage and processing difficult. In addition, current threat hunting methods rely heavily on manually crafted attack query graphs, which are limited by expert knowledge and lack automated solutions. In this paper, we propose AGLHunter, an automated threat hunting system designed to enhance automation and efficiency while maintaining high detection accuracy. Our system leverages the In-Context Learning (ICL) capability of the Large Language Model (LLM) to automatically construct query graphs from Cyber Threat Intelligence (CTI) reports. Next, we extract suspicious subgraphs from PGs and employ graph representation learning to match these sub graphs with the query graphs, enabling efficient and accurate threat hunting. We use DARPA TC and OpTC datasets to evaluate AGLHunter's performance. The results show that AGLHunter not only achieves higher automation but also shows superior performance with reduced memory usage. AGLHunter, leveraging ICL-enhanced LLM, improved the F1 score for query graph construction by 13.6%, reduced the overall hunting time by more than 170 seconds, and maintained high detection accuracy. Mengjiao Cui, Zhengwei Jiang, Yepeng Yao, Qiying He, Peian Yang, Huamin Feng |
CSCWD | 3 |
| 2025 | From Threat Report to ATT&CK: Automated Extraction and Reasoning of TTPs Using Large Language ModelsabstractThe escalating frequency and increasing complexity of cyber attacks underscore the importance of Cyber Threat Intelligence (CTI). Tactics, Techniques, and Procedures (TTPs), as advanced CTI capable of characterizing adversarial behaviors and intentions, have garnered increased attention. However, TTPs are predominantly found embedded within unstructured natural language texts of threat reports. The accurate extraction and standardization of TTPs pose significant challenges. Existing methods exhibit limitations in terms of accuracy, generalizability, and interpretability. This paper presents a pipeline for automatically extracting TTPs from threat reports and providing rationales using large language models. To support this approach, we have developed three datasets using advanced commercial LLMs for data synthesis. These datasets are made publicly available to facilitate further research. Experimental results demonstrate the superior performance of our proposed approach, achieving an F1-score of 97.15% and accuracies of 79.22% and 92.97% in the respective tasks. These results surpass state-of-the-art methods by 15.39%, 12.87%, and 27.57%, respectively. To the best of our knowledge, this paper is the first to simultaneously extract TTPs while providing the underlying rationales for the extraction. This novel approach significantly improves the usability of the results by providing a richer context for threats. Fangming Dong, Zhengwei Jiang, Qiying He, Peian Yang, Yepeng Yao |
CSCWD | 6 |
| 2025 | A Variant and Flow-Level AutoML Method for IoT Malicious Traffic DetectionabstractThe Internet of Things (IoT) involves communication and data exchange between a wide range of devices, often with security implications. Compared to Internet, IoT is costly to detect malicious traffic due to its complex protocols, resource limitations and variety of new attacks and attack variants. Automatic machine learning (AutoML) eliminates model selection and hyperparameter optimisation, which can reduce human dependency and address these issues. However, AutoML still cannot extract and represent features from raw data based on a specific problem. Manual feature extraction and representation will greatly affect the accuracy of the model and still rely on professional domain knowledge. Automated feature engineering in AutoML requires universal and efficient feature extraction and representation. This paper proposes a variant and flow-level AutoML (VFA) for IoT malicious traffic detection. VFA has added a binary representation of comprehensive content features based on the packet. The packet representation allows AutoML to automatically learn important features from a normalised aligned structure without guidance. Variant of exclusive OR (vXOR) enables data aggregation, allowing VFA to focus on the content features in the flow and the inherent connections between packets. VFA can strategically adjust monitoring priorities by adjusting parameters, allowing it to respond flexibly to different resource constraints or specific attack. We have evaluated VFA on a real-world dataset, IoT-23. We believe that the complete data-to-label VFA can be extended to other areas in the future. Xinqiang Zhao, Xuren Wang, Zijing Fan, Yepeng Yao, Zhengwei Jiang |
CSCWD | 6 |
| 2025 | Detection and Analysis of Poisoned Image in Container RegistryabstractContainer technology provides isolated, consistent, and efficient application environments across diverse computing platforms. Docker, as the dominant container platform, simplifies container creation, deployment, and operation. However, the integrity of the container supply chain is threatened by malicious “poisoned” images distributed via public registries like Docker Hub, which pose significant security risks to unsuspecting users. This study presents the first comprehensive investigation into this container registry image supply chain threat. We reveal that image poisoning occurs primarily during the build phase, where attackers embed malicious payloads into Dockerfiles and associated build artifacts via specific common vectors. To empirically assess this threat, we developed a detection system combining dynamic and static analysis. Scanning 214,920 images from public registries, we identified 122 poisoned images with high precision ($\mathbf{9 5. 3 1 \%}$). Our in-depth analysis shows these compromised images serve diverse malicious purposes, with cryptocurrency mining being prevalent, and exhibit significant characteristic differences compared to benign images. Finally, we propose concrete mitigation measures to improve the security of the Docker ecosystem. We reported our findings to Docker and received its confirmation. Siyuan Pang, Yongshan Wang, Yepeng Yao, Zhengwei Jiang, Zijing Fan, Baoxu Liu |
ISSRE | 3 |
| 2025 | Can LLMs deeply detect complex malicious queries? A framework for jailbreaking via obfuscating intentabstractAbstract This paper delves into a possible security flaw in large language models (LLMs), particularly in their capacity to identify malicious intent within intricate or ambiguous inquiries. We have discovered that LLMs might overlook the malicious nature of highly veiled requests, even without alterations to the malevolent text in those queries, thus exposing a significant weakness in their content analysis systems. To be specific, we pinpoint and scrutinize two aspects of this vulnerability: (i) LLMs’ diminished capability to perceive maliciousness when parsing extremely obscured queries, and (ii) LLMs’ inability to discern malicious intent in queries that have been intentionally altered to increase their ambiguity by modifying the malevolent content itself. To illustrate and tackle this problem, we propose a theoretical framework and analytical strategy, and introduce a novel black-box jailbreak attack technique called IntentObfuscator. This technique exploits the identified vulnerability by concealing the genuine intentions behind user prompts, thereby compelling LLMs to inadvertently produce restricted content and circumvent their inherent content safety protocols. We elaborate on two specific applications within this framework: ”Obscure Intention” and ”Create Ambiguity,” which skillfully manipulate the complexity and ambiguity of queries to effectively dodge the detection of malicious intent. We empirically confirm the efficacy of the IntentObfuscator approach across various models, including ChatGPT-3.5, ChatGPT-4, Qwen, and Baichuan, achieving an average jailbreak success rate of 69.21%. Remarkably, our tests on ChatGPT-3.5, boasting 100 million weekly active users, yielded an impressive success rate of 83.65%. Additionally, we verify our approach across a range of sensitive content categories, including graphic violence, racism, sexism, political sensitivity, cybersecurity threats, and criminal techniques, further highlighting the considerable impact of our findings on refining ”Red Team” tactics against LLM content security frameworks. Shang Shang, Xinqiang Zhao, Zhongjiang Yao, Yepeng Yao, Liya Su, Zijing Fan, Zhengwei Jiang |
Comput. J. | 4 |
| 2025 | Advanced code slicing with pre-trained model fine-tuned for open-source component malware detectionabstractAbstract Open Source Software (OSS) is an essential part of modern software development, with platforms such as PyPI for Python, NPM for JavaScript, and RubyGems for Ruby facilitating code sharing and reuse. However, these repositories also pose significant security risks due to potential software supply chain attacks, where payloads are injected into components, propagating threats to downstream users and critical infrastructure. Existing automatic malicious component detection tools, particularly for PyPI, struggle to distinguish between subtle differences in malicious and benign behaviors, leading to high false positive rates. To address these issues, we systematically compare and explore these subtle differences, offering a more refined and accurate detection method, Open-Source Component Code Slices BERT (OCS-BERT). OCS-BERT leverages taint-based program slicing to isolate sensitive behavior segments and fine-tunes pre-trained model to capture subtle semantic differences across programming languages. This system excels in detecting malicious Python components and exhibits encouraging cross-language transferability to JavaScript's NPM and Ruby's RubyGems. Additionally, OCS-BERT successfully detected 107 malicious components from a total of 25,759 newly-uploaded PyPI components, taking two weeks to complete the process. This achievement demonstrates the effectiveness of our method, which serves as a potent enhancement to the current repertoire of software supply chain detection methodologies. Yongshan Wang, Siyuan Pang, Zijing Fan, Shang Shang, Yepeng Yao, Zhengwei Jiang, Baoxu Liu |
Comput. J. | 5 |
| 2024 | IntentObfuscator: A Jailbreaking Method via Confusing LLM with Prompts
Shang Shang, Zhongjiang Yao, Yepeng Yao, Liya Su, Zijing Fan, Zhengwei Jiang |
ESORICS (4) | 3 |
| 2023 | Who Are Querying For Me? Egress Measurement For Open DNS ResolversabstractThe dependencies and centralization in DNS infrastructure increase the risk of single-point failure and the scope of collateral damage. In the DNS recursive resolution, dependencies between different resolvers also exist due to situations such as forwarding. Currently, research on dependencies in recursive resolution is still insufficient. In this work, we take a deep insight into the recursive resolution implemented by open resolvers to investigate their dependencies, including the concentration of dependencies, and the influence of 3rd-party providers. We find that most open resolvers in the wild are dependent on a small number of egress resolvers to communicate with the authoritative name servers. 90% of the open resolvers are influenced by 8.41% of the egress resolvers. Besides, egress resolvers from 3rd-party providers are able to influence more than 44% of the open resolvers. The concentration makes a large amount of DNS traffic concentrated in a small number of egress resolvers/providers, which will reduce the redundancy of DNS and threaten user privacy. Meng Luo 0006, Liling Xin, Yepeng Yao, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi |
CSCWD | 3 |
| 2023 | Self-paced and Reweighting PU Learning for Imbalanced Malicious Traffic DetectionabstractWith the proliferation of information and rapid network development, network attacks and threats are on the rise, and identifying malicious traffic is crucial for network security. However, the distribution of malicious and benign traffic in real-world networks is unbalanced, and the identification of malicious traffic in a real-world environment with a large amount of unbalanced and less known labelled malicious traffic is still a pressing problem. To tackle this issue, the paper presents a self-paced and reweighting Positive-Unlabeled learning algorithm (SRPU) for detecting imbalanced distribution traffic. This approach includes a self-paced training strategy that flexibly identifies assured positive/negative instances while taking the regret data loss into account, and a double-loss reweighting strategy to classify imbalanced malevolent traffic. We present the performance of SRPU by performing real-world experiments on three widely available datasets. These datasets include both common network attacks and APT attacks. The experimental results show that SRPU achieves the highest F1 and MCC scores at different label frequencies. It significantly outperforms existing methods. Zijing Fan, Yepeng Yao, Yuejin Du, Xiangyu Du |
GLOBECOM | 2 |
| 2023 | Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Baoxu Liu |
USENIX Security Symposium | 3 |
| 2023 | M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting
Jian Liu 0008, Qingsai Xiao, Liling Xin, Qiuyun Wang, Yepeng Yao, Zhengwei Jiang |
Comput. Networks | 5 |
| 2022 | Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Dongfang Zhao 0010 |
USENIX Security Symposium | 3 |
| 2022 | Effectiveness Evaluation of Evasion Attack on Encrypted Malicious Traffic DetectionabstractWith more and more TLS encrypted traffic on the Internet, an increasing amount of malware is using TLS to hide their tracks. The encrypted traffic makes the traditional malicious traffic detection methods invalid. Machine learning algorithms have become essential options for detecting encrypted malicious traffic. Recently, researchers found that machine learning algorithms have flaws, and threat actors can use some tricks to evade detection. But it remains an open question on how these machine learning-based encrypted malicious traffic detection algorithms perform in the face of evasion attacks.We explore the answer in this paper. We first define five mutation rules to generate adversarial examples. With these mutation rules, we can evaluate the ability of several detection algorithms to deal with evasion attacks when detecting encrypted malicious traffic. The encrypted malicious traffic collected for 12 months is used for experiments. Experiments show that modifying the destination port can reduce the detection rate of detection algorithms in feature space, except for random forest algorithms. Inserting junk data has minimal effect on these algorithms. Whether in the problem space or feature space, inserting useless cipher suites and simulating browser’s traffic can significantly reduce the detection rate of these algorithms. When simulating browser’s traffic, the random forest algorithm almost loses its usability. The same situation arises when SVM is faced with inserting useless cipher suites. Compared with inserting useless cipher suites, inserting useless extensions has a minor effect on these algorithms. Our findings will contribute to future research on encrypted malicious traffic detection. Jian Liu 0008, Qingsai Xiao, Zhengwei Jiang, Yepeng Yao, Qiuyun Wang |
WCNC | 4 |
| 2022 | Measurement for encrypted open resolvers: Applications and security
Meng Luo 0006, Yepeng Yao, Liling Xin, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi |
Comput. Networks | 2 |
| 2021 | Producing More with Less: A GAN-based Network Attack Detection Approach for Imbalanced DataabstractMachine learning techniques are shown to be effective for network attack detection systems in identifying malicious network behaviors. In the real-world environment, however, network attack traffic i soften hidden under a large amount of normal daily communication traffic. In this paper, to resolve such challenges that the large-scale data is difficult to be effectively labeled, we propose a data augmentation method based on generative adversarial networks. The features of flow-based network traffic are firstly pre-processed to fit the generative adversarial networks (GANs). Then, we enhance the original GANs by adopting Earth-Mover (EM) distance to catch the distribution of low dimensional subspace data and add an encoder structure to learn latent space representation. Compared to other data augmentation methods, our method generates data from learning data distribution rather than performing numerical calculations on existing data. We construct an imbalanced dataset based on the real-world dataset and compare it with other methods. Our method reports better performance in terms of the recall, F1-score, and AUC, which proved the effectiveness of our proposed method. Xingran Hao, Zhengwei Jiang, Qingsai Xiao, Qiuyun Wang, Yepeng Yao, Baoxu Liu, Jian Liu 0008 |
CSCWD | 5 |
| 2021 | Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisabstractIn the past decade, the security of cellular networks has been increasingly under scrutiny, leading to the discovery of numerous vulnerabilities that expose the network and its users to a wide range of security risks, from denial of service to information leak. However, most of these findings have been made through ad-hoc manual analysis, which is inadequate for fundamentally enhancing the security assurance of a system as complex as the cellular network. An important observation is that the massive amount of technical documentation of cellular network can provide key insights into the protection it puts in place and help identify potential security flaws. Particularly, we found that such documentation often contains hazard indicators (HIs) – the statement that describes a risky operation (e.g., abort an ongoing procedure) when a certain event happens at a state, which can guide a test on the system to find out whether the operation can indeed be triggered by an unauthorized party to cause harm to the cellular core or legitimate users’ equipment. Based upon this observation, we present in this paper a new framework that makes the first step toward intelligent and systematic security analysis of cellular networks. Our approach, called Atomic, utilizes natural-language processing and machine learning techniques to scan a large amount of LTE documentation for HIs. The HIs discovered are further parsed and analyzed to recover state and event information for generating test cases. These test cases are further utilized to automatically construct tests in an LTE simulation environment, which runs the tests to detect the vulnerabilities in the LTE that allow the risky operations to happen without proper protection. In our research, we implemented Atomic and ran it on the LTE NAS specification, including 549 pages with 13,598 sentences and 283,850 words. In less than 5 hours, our prototype reported 42 vulnerabilities from 192 HIs discovered, including 10 never reported before, under two threat models. All these vulnerabilities have been confirmed through end-to-end attacks, which lead to unauthorized disruption of the LTE service a legitimate user’s equipment receives. We reported our findings to authorized parties and received their confirmation that these vulnerabilities indeed exist in major commercial carriers and $2,000 USD reward from Google. Yi Chen 0024, Yepeng Yao, XiaoFeng Wang 0001, Dandan Xu, Chang Yue, Xiaozhong Liu 0001, Kai Chen 0012, Haixu Tang, Baoxu Liu |
SP | 2 |
| 2021 | Analysis of the performance and robustness of methods to detect base locations of individuals with geo-tagged social media dataabstractVarious methods have been proposed to detect the base locations of individuals, with their geo-tagged social media data. However, a common challenge relating to base-location detection methods (BDMs) is that, the rare availability of ground-truth data impedes the method assessment of accuracy and robustness, thus undermining research validity and reliability. To address this challenge, we collect users’ information from unstructured online content, and evaluate both the performance and robustness of BDMs. The evaluation consists of two tasks: the detection of base locations and also the differentiation between local residents and tourists. The results show BDMs can achieve high accuracies in base-location detection but tend to overestimate the number of tourists. Evaluation conducted in this study, also shows that BDMs’ accuracy is subject to the intensity of user’s activities and number of countries visited by the user but are insensitive to user’s gender. Temporally, BDMs perform better during weekends and summertime than during other periods, but the best performances appear with datasets that cover the whole time periods (whole day, week, and year). To the best of knowledge, this study is the first work to evaluate the performance and robustness of BDMs at individual level. Zhewei Liu, An-Shu Zhang, Yepeng Yao, Wenzhong Shi, Xiao Huang 0003, Xiaoqi Shen |
Int. J. Geogr. Inf. Sci. | 3 |
| 2020 | Towards Comprehensive Detection of DNS TunnelsabstractThe Domain Name System (DNS) is a fundamental service of the Internet, and the DNS tunnel is one of the most threatening abuses of DNS, posing a huge threat to user privacy and Internet security. Attackers conceal the information into DNS packets to evade firewalls and intrusion detection systems. Recently, newly developed DNS tunnels used by Advanced Persist Threat groups tend to use A and AAAA resource records (RRs) for transmission, making them more invisible and more threatening. Previous DNS tunnel detection approaches mainly focus on subdomains and TXT RRs, but less attention has been paid to newly developed DNS tunnels based on A and AAAA RRs. In this paper, we present a novel DNS tunnel detection method that can detect newly developed A and AAAA RR based DNS tunnels. Since DNS tunnels will transmit a large amount of encrypted or encoded data in the DNS queries and responses, we extracted novel features from domains and 4 types of RRs (A, AAAA, TXT and CNAME RRs) that are most commonly used for tunneling to measure the amount and content of information exchanged between the authoritative nameservers and the clients. We also analyze the detection capabilities when different features were used. The anomaly detection algorithm is employed on domains related features and 4 types of RRs related features, respectively. The overlaps of outliers will be marked as DNS tunnels. Our approach has been evaluated on real-world network traffic. The experimental results show that our approach can detect all DNS tunnels in the dataset with a extremely low false positive rate. Meng Luo 0006, Qiuyun Wang, Yepeng Yao, Xuren Wang, Peian Yang, Zhengwei Jiang |
ISCC | 3 |