EDBT 2026 Demo / reviewers in the wild / expert
Changting Lin
dblp:231/4918
· DBLP profile ↗
15ranked-venue papers
1as first author
14since 2021 · last 2026
0000-0002-8918-6299ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LTD: Low-Overhead Topology Discovery using Programmable Data Planes
Dezhang Kong, Minghao Li 0012, Shi Lin, Zhenhua Xu 0004, Longlong Zhu, Linying Zheng, Xiang Chen 0017, Changting Lin, Xuan Liu 0006, Dong Zhang 0010, Chunming Wu 0001 |
INFOCOM | 8 |
| 2025 | CTCC: A Robust and Stealthy Fingerprinting Framework for Large Language Models via Cross-Turn Contextual Correlation BackdoorabstractThe widespread deployment of large language models (LLMs) has intensified concerns around intellectual property (IP) protection, as model theft and unauthorized redistribution become increasingly feasible.To address this, model fingerprinting aims to embed verifiable ownership traces into LLMs.However, existing methods face inherent trade-offs between stealthness, robustness, and generalizability-being either detectable via distributional shifts, vulnerable to adversarial modifications, or easily invalidated once the fingerprint is revealed.In this work, we introduce CTCC, a novel rule-driven fingerprinting framework that encodes contextual correlations across multiple dialogue turns-such as counterfactual-rather than relying on token-level or single-turn triggers.CTCC enables fingerprint verification under black-box access while mitigating false positives and fingerprint leakage, supporting continuous construction under a shared semantic rule even if partial triggers are exposed.Extensive experiments across multiple LLM architectures demonstrate that CTCC consistently achieves stronger stealth and robustness than prior work.Our findings position CTCC as a reliable and practical solution for ownership verification Zhenhua Xu 0004, Xixiang Zhao, Xubin Yue, Shengwei Tian, Changting Lin |
EMNLP | 5 |
| 2025 | NCDI-Diffusion: Neural Contextual and Directional Inversion for Novel View Synthesis through Diffusion ModelsabstractNovel view synthesis typically requires a comprehensive set of multi-view images for either image-based rendering or scene representation-based optimization. However, achieving high-fidelity novel view rendering often demands a large number of images. To address this limitation, we propose NCDI-Diffusion, a novel diffusion-based view synthesis method that reduces the number of required images by leveraging the prior knowledge embedded in pre-trained diffusion models. Specifically, NCDI-Diffusion encapsulates both the contextual and directional information of a scene by utilizing neural descriptors, which are inversely derived from a limited set of positioned multi-view training images. These descriptors guide the diffusion model's image synthesis process, enabling the generation of high-quality novel views. Empirical results on the Forward-facing Dataset demonstrate the effectiveness of our approach to novel view synthesis. Wenpeng Xing, Jie Chen 0026, Zaifeng Yang, Changting Lin |
ICASSP | 5 |
| 2025 | GenBEV: Generative Model With Semantic Compensation for Bird's Eye View SegmentationabstractBird’s-Eye View (BEV) semantic segmentation is a key technology for constructing high-precision maps in low-cost visual navigation systems. The main challenge lies in effectively transforming image features into BEV features while preserving rich BEV visual information. Recent works have shown that generative models hold great promise in advancing BEV segmentation. However, these methods primarily focus on producing BEV features using prior knowledge, often overlooking key challenges such as feature shift, confusion, and forgetting during the BEV feature generation process. In this paper, we propose GenBEV, a generative model with semantic compensation that formally addresses inaccuracies and confusion in BEV feature generation. GenBEV leverages the synergistic benefits of data fusion consistency and noise-reduction training to enhance the diversity and reliability of the generated information. This improvement boosts the robustness and generalization of BEV segmentation across diverse scenarios, including those involving complex objects and low-quality images. Specifically, we design an adaptive cross-feature encoder to reduce diffusion variability. During decoding, we integrate the context of BEV features with noisy features to construct semantic embeddings. We show the effectiveness of GenBEV on the nuScenes, KITTI Raw, and KITTI 3D Object datasets. GenBEV achieves segmentation scores of 29.5%, 68.8%, and 39.7%, respectively, surpassing current methods by up to 3.6%, 2.4%, and 2.7%. To the best of our knowledge, GenBEV is the first to address the problem of BEV feature falsification in generative architectures. Weiming Fan, Yuping Guo, Hong Lyu, Hongwei Gao 0002, Changting Lin, Xu Cheng 0003 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2024 | Towards understanding bogus traffic service in online social networksabstractCritical functionality and huge influence of the hot trend/topic page (HTP) in microblogging sites have driven the creation of a new kind of underground service called the bogus traffic service (BTS). BTS provides a kind of illegal service which hijacks the HTP by pushing the controlled topics into it for malicious customers with the goal of guiding public opinions. To hijack HTP, the agents of BTS maintain an army of black-market accounts called bogus traffic accounts (BTAs) and control BTAs to generate a burst of fake traffic by massively retweeting the tweets containing the customer desired topic (hashtag). Although this service has been extensively exploited by malicious customers, little has been done to understand it. In this paper, we conduct a systematic measurement study of the BTS. We first investigate and collect 125 BTS agents from a variety of sources and set up a honey pot account to capture BTAs from these agents. We then build a BTA detector that detects 162 218 BTAs from Weibo, the largest Chinese microblogging site, with a precision of 94.5%. We further use them as a bridge to uncover 296 916 topics that might be involved in bogus traffic. Finally, we uncover the operating mechanism from the perspectives of the attack cycle and the attack entity. The highlights of our findings include the temporal attack patterns and intelligent evasion tactics of the BTAs. These findings bring BTS into the spotlight. Our work will help in understanding and ultimately eliminating this threat. Xuhong Zhang 0002, Changting Lin, Ting Wang 0006, Shouling Ji |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2024 | One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT FirmwareabstractCurrently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implementFirmSec, which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based onFirmSec, we present the first large-scale analysis of the security risks raised by TPCs on 34,136 firmware images. We successfully detect 584 TPCs and identify 128,757 vulnerabilities caused by 429 CVEs. Our in-depth analysis reveals the diversity of security risks in firmware and discovers some well-known vulnerabilities are still rooted in firmware. Besides, we explore the geographical distribution of vulnerable devices and confirm that the security situation of devices in different regions varies. Our analysis also indicates that vulnerabilities caused by TPCs in firmware keep growing with the boom of the IoT ecosystem. Further analysis shows 2,478 commercial firmware images have potentially violated GPL/AGPL licensing terms. Shouling Ji, Jiacheng Xu 0006, Yuan Tian 0001, Qiuyang Wei, Qinying Wang, Chenyang Lyu, Xuhong Zhang 0002, Changting Lin, JingZheng Wu, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2023 | One4All: Manipulate one agent to poison the cooperative multi-agent reinforcement learning
Haibin Zheng, Xiaohao Li, Jinyin Chen, Jianfeng Dong, Changting Lin |
Comput. Secur. | 6 |
| 2023 | iQuery: A Trustworthy and Scalable Blockchain Analytics PlatformabstractBlockchain, a distributed and shared ledger, provides a credible and transparent solution to increase application auditability by querying the immutable records written in the ledger. Unfortunately, existing query APIs offered by the blockchain are inflexible and unscalable. Some studies propose off-chain solutions to provide more flexible and scalable query services. However, the query service providers (SPs) may deliver fake results without executing the real computation tasks and collude to cheat users. In this article, we propose a novel intelligent blockchain analytics platform termediQuery, in which we design a game theory based smart contract to ensure the trustworthiness of the query results at a reasonable monetary cost. Furthermore, the contract introduces the second opinion game that employs a randomized SP selection approach coupled with non-ordered asynchronous querying primitive to prevent collusion. We achieve a fixed price equilibrium, destroy the economic foundation of collusion, and can incentivize all rational SPs to act diligently with proper financial rewards. In particular,iQuerycan flexibly support semantic and analytical queries for generic consortium or public blockchains, achieving query scalability to massive blockchain data. Extensive experimental evaluations show thatiQueryis significantly faster than state-of-the-art systems. Specifically, in terms of the conditional, analytical, and multi-origin query semantics,iQueryis 2 ×, 7 ×, and 1.5 × faster than advanced blockchain and blockchain databases. Meanwhile, to guarantee 100% trustworthiness, only two copies of query results need to be verified iniQuery, whileiQuery's latency is$2 \sim 134$× smaller than the state-of-the-art systems. Lingling Lu, Zhenyu Wen, Ye Yuan 0001, Binru Dai, Changting Lin, Qinming He, Zhenguang Liu, Jianhai Chen, Rajiv Ranjan 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Fraud-Agents Detection in Online Microfinance: A Large-Scale Empirical StudyabstractOnline Microlending, a new financial service, focuses on small loans without any sort of collateral. It provides more flexible and quicker funding for borrowers, as well as higher interest rates of return. For platforms that provide such services, an essential task is to adequately evaluate each loan’s risk so as to minimize the possible financial loss. However, there exists a special group of borrowers, namelyfraud-agents, who gain illegal profits from inciting other borrowers to cheat, i.e., they help the high-risk borrowers evade the risk evaluation by crafting fake personal information. The existence of fraud-agents poses a severe threat to the risk management systems and results in a huge financial loss for lending platforms. In this article, we present the first machine learning-based solution to detect fraud-agents in online microlending. The key challenge of this decade-long problem is that it is unclear how to construct effective features from multiple behavior logs such as phone call history, address book, loan history and activity logs of borrowers. To address this problem, we first conduct an empirical study on over 600K borrowers to gain some insights on the adversarial behaviors of fraud-agents comparing to normal borrowers and benign-agents. Based on the study, we are able to design a total of 26 features, falling into four groups, for fraud agent detection. Then, we propose a two-stage detection model to address the challenge of limited number of labeled fraud agent examples. The evaluation results show that our method can achieve a precision of 94.30%. We deploy our method on a real large online microlending platform with 11,953,273 borrowers, and we identify 29,727 fraud-agents from them. The domain experts from the platform confirm that 95.59% of them are real fraud-agents, and have added them to the platform’s internal blacklist. We further conduct a measurement study on those fraud-agents to share deeper insights on their adversarial behaviors. Yiming Wu 0009, Shouling Ji, Zhenguang Liu, Xuhong Zhang 0002, Changting Lin, Shuiguang Deng, Jun Zhou 0011, Ting Wang 0006, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareabstractAs the core of IoT devices, firmware is undoubtedly vital. Currently, the development of IoT firmware heavily depends on third-party components (TPCs), which significantly improves the development efficiency and reduces the cost. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will turn back influence the security of IoT firmware. Currently, existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement FirmSec, which leverages syntactical features and control-flow graph features to detect the TPCs at version-level in firmware, and then recognizes the corresponding vulnerabilities. Based on FirmSec, we present the first large-scale analysis of the usage of TPCs and the corresponding vulnerabilities in firmware. More specifically, we perform an analysis on 34,136 firmware images, including 11,086 publicly accessible firmware images, and 23,050 private firmware images from TSmart. We successfully detect 584 TPCs and identify 128,757 vulnerabilities caused by 429 CVEs. Our in-depth analysis reveals the diversity of security issues for different kinds of firmware from various vendors, and discovers some well-known vulnerabilities are still deeply rooted in many firmware images. We also find that the TPCs used in firmware have fallen behind by five years on average. Besides, we explore the geographical distribution of vulnerable devices, and confirm the security situation of devices in several regions, e.g., South Korea and China, is more severe than in other regions. Further analysis shows 2,478 commercial firmware images have potentially violated GPL/AGPL licensing terms. Shouling Ji, Jiacheng Xu 0006, Yuan Tian 0001, Qiuyang Wei, Qinying Wang, Chenyang Lyu, Xuhong Zhang 0002, Changting Lin, JingZheng Wu, Raheem A. Beyah |
ISSTA | 9 |
| 2022 | A Secure and Authenticated Mobile Payment Protocol Against Off-Site Attack StrategyabstractMobile payment system has been expected to provide more efficient and convenient payment methods. However, compared to traditional payments, mobile payment issues related to the security of electronic accounts and payment apps present serious challenges. In this paper, we find the potential security risks by analyzing the commonly used tokenized mobile payment method and put forward the corresponding off-site attack strategy. In this scenario, the attackers are not only limited to malicious third parties but also can be illegal merchants. To address the off-site attack, especially the potential attackers who may be malicious merchants, we also propose SALP, a secure and authenticated payment protocol, using time and position as necessary conditions for the payment confirmation. Furthermore, we leverage identity-based signature (IBS) to prevent altering the information and reduce the overhead of the third-party authentication. We conduct case studies to demonstrate that the SALP can effectively prevent the off-site payment attack without a trusted hardware environment. In particular, we finally argue that SALP does not bring additional system overhead without degrading the convenience of mobile payment. Liming Fang 0001, Zhe Liu 0001, Changting Lin, Shouling Ji, Anni Zhou, Willy Susilo, Chunpeng Ge 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | A Large-Scale Empirical Study on the Vulnerability of Deployed IoT DevicesabstractThe Internet of Things (IoT) has become ubiquitous and greatly affected peoples’ daily lives. With the increasing development of IoT devices, the corresponding security issues are becoming more and more challenging. Such a severe security situation raises the following questions that need urgent attention: What are the primary security threats that IoT devices face currently? How do vendors and users deal with these threats? In this article, we aim to answer these critical questions through a large-scale systematic study. Specifically, we perform a ten-month-long empirical study on the vulnerability of 1,362,906 IoT devices varying from six types. The results show sufficient evidence that N-days vulnerability is seriously endangering the IoT devices: 385,060 (28.25 percent) devices suffer from at least one N-days vulnerability. Moreover, 2669 of these vulnerable devices may have been compromised by botnets. We further reveal the massive differences among five popular IoT search engines:Shodan[1],Censys[2], [3],Zoomeye[4],Fofa[5], andNTI[6]. To study whether vendors and users adopt defenses against the threats, we measure the security of MQTT [7] servers, and identify that 12740 (88 percent) MQTT servers have no password protection. Our analysis can serve as an important guideline for investigating the security of IoT devices, as well as advancing the development of a more secure environment for IoT systems. Shouling Ji, Wei-Han Lee, Changting Lin, Haiqin Weng, JingZheng Wu, Pan Zhou 0001, Liming Fang 0001, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging Protocols
Qinying Wang, Shouling Ji, Yuan Tian 0001, Xuhong Zhang 0002, Yuhong Kan, Zhaowei Lin, Changting Lin, Shuiguang Deng, Alex X. Liu, Raheem A. Beyah |
USENIX Security Symposium | 8 |
| 2021 | Multi-level Alignment Network for Domain Adaptive Cross-modal Retrieval
Jianfeng Dong, Zhongzi Long, Xiaofeng Mao, Changting Lin, Yuan He 0011, Shouling Ji |
Neurocomputing | 4 |
| 2020 | Rapido: Scaling blockchain with multi-path payment channels
Changting Lin, Xun Wang 0007, Jianhai Chen |
Neurocomputing | 1 |