EDBT 2026 Demo / reviewers in the wild / expert
Cuiying Gao
dblp:231/3370
· DBLP profile ↗
15ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0003-0709-3361ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Why Not Diversify Triggers? APK-Specific Backdoor Attack Against Android Malware DetectionabstractMachine learning-based Android malware detection (AMD) models require abundant data for training robust app classifiers, creating vulnerability to poisoning attacks. Attackers inject poisoned samples into Android app markets, leading to the insertion of a backdoor into the model upon adoption in the training process. Subsequently, attackers can generate evasive malware by embedding a backdoor trigger in malware samples. Currently, research on backdoor attacks towards AMD has just begun to emerge. Existing attacks produce a fixed trigger and apply it to various malware. Once the trigger is discovered by static analysis methods (e.g., software similarity analysis), however, multiple malware carrying this trigger will be simultaneously exposed. To diversify the trigger, we propose anAPK-SpecificBackdoorAttack algorithm (ASBA), which trains a generative adversarial network to generate a specific trigger for every malware sample. Moreover, ASBA manages to make the generated triggers as different as possible, in order to further reduce the likelihood of malware being collectively captured. Extensive experiments have demonstrated that ASBA achieves a 94.6% average attack success rate (ASR) on three datasets, five feature extraction methods and three classification models. Furthermore, compared to state-of-the-art poisoning attack algorithms, ASBA produces more diverse and more effective triggers. Heng Li 0008, Bang Wu 0002, Cuiying Gao, Wei Yuan 0001, Beihao Xia, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Automated Mass Malware Factory: The Convergence of Piggybacking and Adversarial Example in Android Malicious Software Generation
Heng Li 0008, Bang Wu 0002, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
NDSS | 4 |
| 2025 | Fighting Fire with Fire: Continuous Attack for Adversarial Android Malware Detection
Yinyuan Zhang, Cuiying Gao, Yueming Wu 0001, Shihan Dou, Cong Wu 0003, Ying Zhang 0066, Wei Yuan 0001, Yang Liu 0003 |
USENIX Security Symposium | 2 |
| 2025 | An Efficient Adversarial Attack on FCG-Based Android Malware Detection Systems
Heng Li 0008, Bang Wu 0002, Wei Yuan 0001, Cuiying Gao, Xinge You, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | A Comprehensive Study of Learning-based Android Malware Detectors under Challenging EnvironmentsabstractRecent years have witnessed the proliferation of learning-based Android malware detectors. These detectors can be categorized into three types, String-based, Image-based and Graph-based. Most of them have achieved good detection performance under the ideal setting. In reality, however, detectors often face out-of-distribution samples due to the factors such as code obfuscation, concept drift (e.g., software development technique evolution and new malware category emergence), and adversarial examples (AEs). This problem has attracted increasing attention, but there is a lack of comparative studies that evaluate the existing various types of detectors under these challenging environments. In order to fill this gap, we select 12 representative detectors from three types of detectors, and evaluate them in the challenging scenarios involving code obfuscation, concept drift and AEs, respectively. Experimental results reveal that none of the evaluated detectors can maintain their ideal-setting detection performance, and the performance of different types of detectors varies significantly under various challenging environments. We identify several factors contributing to the performance deterioration of detectors, including the limitations of feature extraction methods and learning models. We also analyze the reasons why the detectors of different types show significant performance differences when facing code obfuscation, concept drift and AEs. Finally, we provide practical suggestions from the perspectives of users and researchers, respectively. We hope our work can help understand the detectors of different types, and provide guidance for enhancing their performance and robustness. Cuiying Gao, Gaozhun Huang, Heng Li 0008, Bang Wu 0003, Yueming Wu 0001, Wei Yuan 0001 |
ICSE | 1 |
| 2024 | Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseabstractDeep neural network (DNN) based website fingerprinting (WF) attacks can achieve an attack success rate (ASR) of over 90%, seriously threatening the privacy of Tor users. At present, adversarial example (AE) based defenses have demonstrated great potential to defend against WF attacks. However, existing AE-based defenses require knowing a complete traffic trace for adversarial perturbation calculation, which is unrealistic in practice. Moreover, they may become ineffective once adversarial training (AT) is adopted by attackers. To mitigate these two problems, we propose a defense called ALERT. It generates adversarial perturbations without knowing traffic traces, and can effectively resist AT-aided WF attacks. The key idea of ALERT is to produce universal perturbations that vary from user to user. We conduct extensive experiments to evaluate ALERT. In the closed world, ALERT significantly surpasses four representative WF defenses, including the state-of-the-art (SOTA) defense AWA. Specifically, ALERT reduces the ASR of the SOTA DF attack to 12.68% and uses only 20.13% of communication bandwidth. In the open world, ALERT uses only 19.91% of bandwidth, reduces the True Positive Rate (TPR) of the DF attack to 37.46%, obviously outperforming the other defenses. Litao Qiao, Bang Wu 0002, Heng Li 0008, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
INFOCOM | 4 |
| 2024 | Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus EnginesabstractWith the widespread application of machine learning-based Android malware detection methods, building a high-quality dataset has become increasingly important. Existing large-scale datasets are mostly annotated with VirusTotal by aggregating the decisions of antivirus engines, and most of them indiscriminately accept the decisions of all engines. In reality, however, these engines have different capabilities in detecting malware, especially those that have been obfuscated. Previous research has revealed that code obfuscation degrades the detection performance of these engines to varying degrees. This makes us believe that using all engines indiscriminately is unreasonable for dataset annotation. Therefore, in this paper, we first conduct a data-driven evaluation to confirm the negative effects of code obfuscation on engine-based dataset annotation. To gain a deeper understanding of the reasons behind this phenomenon, we evaluate the availability, effectiveness and robustness of every engine under various code obfuscation techniques. Then we categorize the engines and select a set of obfuscation-robust engines. Finally, we conduct comprehensive experiments to verify the effectiveness of the selected engines for dataset annotation. Our experiments show that when 50% obfuscated samples are mixed into the training set, on the classic malware detectors Drebin and Malscan, using our selected engines can effectively improve detection performance by 15.21% and 19.23%, respectively, compared to using all the engines. Cuiying Gao, Yueming Wu 0001, Heng Li 0008, Wei Yuan 0001, Qidan He, Yang Liu 0003 |
ISSTA | 1 |
| 2024 | Semi-supervised anomaly detection with contamination-resilience and incremental training
Liheng Yuan, Fanghua Ye 0001, Heng Li 0008, Cuiying Gao, Chengqing Yu, Wei Yuan 0001, Xinge You |
Eng. Appl. Artif. Intell. | 5 |
| 2023 | Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature Information
Heng Li 0008, Zhang Cheng, Bang Wu 0002, Liheng Yuan, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
USENIX Security Symposium | 5 |
| 2023 | Obfuscation-Resilient Android Malware Analysis Based on Complementary FeaturesabstractExisting Android malware detection methods are usually hard to simultaneously resist various obfuscation techniques. Therefore, bytecode-based code obfuscation becomes an effective means to circumvent Android malware analysis. Building obfuscation-resilient Android malware analysis methods is a challenging task, due to the fact that various obfuscation techniques have vastly different effects on code and detection features. To mitigate this problem, we propose combining multiple features that are complementary in combating code obfuscation. Accordingly, we develop an obfuscation-resilient Android malware analysis methodCorDroid, based on two new features: Enhanced Sensitive Function Call Graph (E-SFCG) and Opcode-based Markov transition Matrix (OMM). The first describes sensitive function call relationships, while the second reflects transition probabilities among opcodes. Combining E-SFCG and OMM can well characterize the runtime behavior of Android apps from different perspectives, hence increasing the difficulty of misleading malware analysis through using code obfuscation to affect detection features. To evaluate CorDroid, we generate 74,138 obfuscated samples with 14 different obfuscation techniques, and compare CorDroid with the state-of-the-art detection methods (e.g., MaMaDroid, RevealDroid and APIGraph). In terms of average F1-Score, CorDroid is 29.69% higher than MaMaDroid, 21.80% higher than APIGraph, and 9.71% higher than RevealDroid, respectively. Experiments also validate the complementarity between E-SFCG and OMM, and exhibit the high execution efficiency of CorDroid. Cuiying Gao, Minghui Cai, Shuijun Yin, Gaozhun Huang, Heng Li 0008, Wei Yuan 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Recent Advances in Concept Drift Adaptation Methods for Deep LearningabstractIn the ``Big Data'' age, the amount and distribution of data have increased wildly and changed over time in various time-series-based tasks, e.g weather prediction, network intrusion detection. However, deep learning models may become outdated facing variable input data distribution, which is called concept drift. To address this problem, large number of samples are usually required to update deep learning models, which is impractical in many realistic applications. This challenge drives researchers to explore the effective ways to adapt deep learning models to concept drift. In this paper, we first mathematically describe the categories of concept drift including abrupt drift, gradual drift, recurrent drift, incremental drift. We then divide existing studies into two categories (i.e., model parameter updating and model structure updating), and analyze the pros and cons of representative methods in each category. Finally, we evaluate the performance of these methods, and point out the future directions of concept drift adaptation for deep learning. Liheng Yuan, Heng Li 0008, Beihao Xia, Cuiying Gao, Wei Yuan 0001, Xinge You |
IJCAI | 4 |
| 2021 | Robust Android Malware Detection against Adversarial Example AttacksabstractAdversarial examples pose severe threats to Android malware detection because they can render the machine learning based detection systems useless. How to effectively detect Android malware under various adversarial example attacks becomes an essential but very challenging issue. Existing adversarial example defense mechanisms usually rely heavily on the instances or the knowledge of adversarial examples, and thus their usability and effectiveness are significantly limited because they often cannot resist the unseen-type adversarial examples. In this paper, we propose a novel robust Android malware detection approach that can resist adversarial examples without requiring their instances or knowledge by jointly investigating malware detection and adversarial example defenses. More precisely, our approach employs a new VAE (variational autoencoder) and an MLP (multi-layer perceptron) to detect malware, and combines their detection outcomes to make the final decision. In particular, we share a feature extraction network between the VAE and the MLP to reduce model complexity and design a new loss function to disentangle the features of different classes, hence improving detection performance. Extensive experiments confirm our model’s advantage in accuracy and robustness. Our method outperforms 11 state-of-the-art robust Android malware detection models when resisting 7 kinds of adversarial example attacks. Heng Li 0008, Shiyao Zhou, Wei Yuan 0001, Xiapu Luo, Cuiying Gao, Shuiyan Chen |
WWW | 5 |
| 2021 | Learning features from enhanced function call graphs for Android malware detection
Minghui Cai, Cuiying Gao, Heng Li 0008, Wei Yuan 0001 |
Neurocomputing | 3 |
| 2021 | Cost risk analysis for instance recommendation in a sustainable Cloud-cyber-physical system frameworkabstractAbstract Cloud markets advocate powerful instances to take computation over from the cyber‐physical system (CPS). Combining the Cloud and CPS layer, the whole Cloud–CPS framework is designed to achieve both accurate data sensing and fast data analysis. While most researchers trust the computation side, and focus on the actuator in the physical space to ensure the service‐level objectives, SLO, that is, deadline misses, cloud can be a threat to the service sustainability as instance may fail, especially when one tries to make a cost‐effective design. Specifically, users must bear the risk of instance failure. These risks can cause the entire cyber‐physical system to collapse. Our work tackles the cloud aspect of the sustainability challenge from the cloud side in a cloud–CPS framework. We have studied the instance selection problem for the CPS systems, and propose a Cost‐Risk Analysis for Instance Recommendation, or CRAIR, to support a sustainable Cloud–CPS framework. We have adopted the classic risk analysis process from the portfolio management in hedge financial market, combining with the system modeling for the CPS instance selection, as an optimization problem. To solve this problem, we formulate it as a multi‐armed bandit problem and solve it with our upper confidence bound bandit algorithm together, our CRAIR can provide an online risk analysis to maximize the profit with a comparative ratio of O(1+ ). We have evaluated CRAIR based on simulations using real‐world Google and Alibaba workloads and cloud market numbers. The results show that, compared to traditional approaches, our approach provides the best tradeoff between SLOs and costs. All users achieve their SLOs goals while minimizing their average expenses by 34.6%. By using CRAIR for instance selection, the CPS service can maximize its benefit under a controlled risk. Wenjing Jiang, Zichen Xu 0001, Cuiying Gao, Jingyun Gu, Yuhao Wang 0001 |
Softw. Pract. Exp. | 3 |
| 2018 | RISC: Risk Assessment of Instance Selection in Cloud Markets
Jingyun Gu, Zichen Xu 0001, Cuiying Gao |
ICA3PP (1) | 3 |