Changming Liu

dblp:24/8176 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 1 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 DRIFT: Debug-based Trace Inference for Firmware Testing
abstract
Binary firmware fuzzing has garnered attention in recent years. Compared to source-code-based approaches, binary approaches require less semantic information and are therefore more applicable. This is particularly relevant in firmware analysis, as most firmware vendors distribute only binaries, withholding source code due to proprietary concerns.Pivoting away from the traditional hardware-in-the-loop (HiL) methodology, researchers are exploring more efficient ways to engage real hardware for fuzzing. However, existing approaches have inherent drawbacks, such as reliance on high-end hardware features, inability to recover complete coverage, and slow execution speeds. We propose DRIFT, a novel approach for on-device binary firmware testing that follows the semihosting methodology. DRIFT addresses all the aforementioned drawbacks. The core insight of DRIFT is to use the Debug Monitor (DM) for firmware fuzzing. DM is a Arm Cortex-M CPU feature that allows triggering interrupt when a breakpoint is hit. Through chaining the DM interrupts, DRIFT is able let firmware to trace itself. This self-tracing approach minimizes interference from the workstation, significantly boosting fuzzing performance.We designed DRIFT to be highly flexible, accommodating a number of hardware resource limitations. When applied to new firmware, DRIFT discovered three previously unknown bugs that were not identified by existing binary fuzzing techniques. Furthermore, DRIFT outperforms all state-of-the-art binary firmware fuzzers in terms of speed and fidelity, trailing only SHiFT, an approach that requires source code.
Changming Liu, Alejandro Mera, Engin Kirda
ASE1
2024 CO3: Concolic Co-execution for Firmware
Changming Liu, Alejandro Mera, Engin Kirda, Long Lu
USENIX Security Symposium1
2024 SHiFT: Semi-hosted Fuzz Testing for Embedded Applications
Alejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda, Long Lu
USENIX Security Symposium2
2024 Neural Network-Based Algorithm for Identification of Recaptured Images
abstract
With the improvement of digital image display technology, the “secondary imaging” caused by digital cameras is also gradually popularized, and the quality of the recaptured image formed by this imaging is also getting higher and higher, and this kind of high-quality fake image has caused great threat to digital images security. We propose a neural network-based recaptured image identification algorithm and use the difference between two types of images to build the identification algorithm in the frequency domain. The algorithm uses filtering to obtain the feature images which are the high-frequency and low-frequency filtering images, in order to further distinguish the image differences, the direction of the filtered image obtained from high-frequency images, each direction of the filtered image contains high-frequency information at different angles, and the low-frequency image is downsampled. At the same time, the low-frequency image is downsampled to obtain a multi-scale filtered image. The algorithm extracts the features from previous images as the feature values for classification, and finally uses neural networks for classification to obtain the classification results, and these prove that the algorithm presented is able to differentiate the recaptured images effectively in this paper.
Changming Liu, Yanjun Sun, Lin Deng 0008
Int. J. Pattern Recognit. Artif. Intell.1
2024 AIM: Automatic Interrupt Modeling for Dynamic Firmware Analysis
abstract
The security of microcontrollers, which drive modern IoT and embedded devices, continues to raise major concerns. Within a microcontroller (MCU), the firmware is a monolithic piece of software that contains the whole software stack, whereas a variety of peripherals represent the hardware. As MCU firmware contains vulnerabilities, it is ideal to test firmware with off-the-shelf software testing techniques, such as dynamic symbolic execution and fuzzing. Nevertheless, no emulator can emulate the diverse MCU peripherals or execute/test the firmware. Specifically, the interrupt interface, among all I/O interfaces used by MCU peripherals, is extremely challenging to emulate. In this article, we presentAIM—a generic, scalable, and hardware-independent dynamic firmware analysis framework that supports unemulated MCU peripherals by a novel interrupt modeling mechanism.AIMeffectively and efficiently covers interrupt-dependent code in firmware by a novel, firmware-guided,Just-in-Time Interrupt Firingtechnique. We implemented our framework inangrand performed dynamic symbolic execution for eight real-world MCU firmware. According to testing results, our framework covered up to 11.2 times more interrupt-dependent code than state-of-the-art approaches while accomplishing several challenging goals not feasible previously. Finally, a comparison with a state-of-the-art firmware fuzzer demonstrates dynamic symbolic execution and fuzzing together can achieve better firmware testing coverage.
Bo Feng 0002, Meng Luo 0002, Changming Liu, Long Lu, Engin Kirda
IEEE Trans. Dependable Secur. Comput.3
2023 ShadowNet: A Secure and Efficient On-device Model Inference System for Convolutional Neural Networks
abstract
With the increased usage of AI accelerators on mobile and edge devices, on-device machine learning (ML) is gaining popularity. Thousands of proprietary ML models are being deployed today on billions of untrusted devices. This raises serious security concerns about model privacy. However, protecting model privacy without losing access to the untrusted AI accelerators is a challenging problem. In this paper, we present a novel on-device model inference system, ShadowNet. ShadowNet protects the model privacy with Trusted Execution Environment (TEE) while securely outsourcing the heavy linear layers of the model to the untrusted hardware accelerators. ShadowNet achieves this by transforming the weights of the linear layers before outsourcing them and restoring the results inside the TEE. The non-linear layers are also kept secure inside the TEE. ShadowNet’s design ensures efficient transformation of the weights and the subsequent restoration of the results. We build a ShadowNet prototype based on TensorFlow Lite and evaluate it on five popular CNNs, namely, MobileNet, ResNet-44, MiniVGG, ResNet-404, and YOLOv4-tiny. Our evaluation shows that ShadowNet achieves strong security guarantees with reasonable performance, offering a practical solution for secure on-device model inference.
Zhichuang Sun, Ruimin Sun, Changming Liu, Amrita Roy Chowdhury 0001, Long Lu, Somesh Jha
SP3
2022 Privacy-preserving Motion Detection for HEVC-compressed Surveillance Video
abstract
In the cloud era, a large amount of data is uploaded to and processed by public clouds. The risk of privacy leakage has become a major concern for cloud users. Cloud-based video surveillance requires motion detection, which may reveal the privacy of people in a surveillance video. Privacy-preserving video surveillance allows motion detection while protecting privacy. The existing scheme [ 25 ], designed to detect motion on encrypted and H.264-compressed surveillance videos, does not work well on more advanced video compression schemes such as HEVC. In this article, we propose the first motion detection method on encrypted and HEVC-compressed videos. It adopts a novel approach that exploits inter-prediction reference relationships among coding blocks to detect motion regions. The partition pattern and the number of coding bits of each detection block used in prior art are also used to help detect motion regions. Spatial and temporal consistency of a moving object and Kalman filtering are applied to segment connected/merged motion regions, remove noise and background motions, and refine trajectories and shapes of detected moving objects. Experimental results indicate that our detection method achieves high detection recall, precision, and F1-score for surveillance videos of both high and low resolutions with various scenes. It has a similarly high detection accuracy on encrypted and HEVC-compressed videos as that of the existing motion detection method [ 25 ] on encrypted and H.264-compressed videos. Our proposed method incurs no bit-rate overhead and has a very low computational complexity for both motion detection and encryption of HEVC videos.
Changming Liu, Xiaojing Ma 0002, Sixing Cao, Jiayun Fu, Bin B. Zhu
ACM Trans. Multim. Comput. Commun. Appl.1
2021 KUBO: Precise and Scalable Detection of User-triggerable Undefined Behavior Bugs in OS Kernel
Changming Liu, Yaohui Chen 0001, Long Lu
NDSS1
2020 Static detection of real-world buffer overflow induced by loop
Deqing Zou, Yajuan Du, Hai Jin 0001, Changming Liu, Jinan Shen
Comput. Secur.5
2020 Recaptured Image Forensics Algorithm Based on Image Texture Feature
abstract
With the rapid development of digital phones, the digital image forensics system in current times has had a great impact. It will lead to a serious threat for us, and especially the emergence of the recaptured image makes the existing digital image forensics algorithm invalid. So, it needs an effective image detection algorithm for us to identify recaptured images. In this paper, a new detection algorithm of the recaptured image is presented based on gray level co-occurrence matrix by analyzing the differences between the real and recaptured images. In order to analyze the differences, a new image evaluation model was put forward in this paper, which is called image variance ratio. Firstly, the algorithm proposed extracted high-frequency and low-frequency information of images by wavelet transform, based on which we calculated the relative gray level co-occurrence matrices. Secondly, the features of gray level co-occurrence matrix were extracted. At last, the recaptured image was classified by the support vector machine according to the features. The experimental results showed the algorithm proposed can not only effectively identify the recaptured image obtained from different media but also have better identification rate.
Yanjun Sun, Xuanjing Shen, Changming Liu, Yongzhe Zhao
Int. J. Pattern Recognit. Artif. Intell.3
2018 A Heuristic Framework to Detect Concurrency Vulnerabilities
abstract
With a growing demand of concurrent software to exploit multi-core hardware capability, concurrency vulnerabilities have become an inevitable threat to the security of today's IT industry. Existing concurrent program detection schemes focus mainly on detecting concurrency errors such as data races, atomicity violation, etc., with little attention paid to detect concurrency vulnerabilities that may be exploited to infringe security. In this paper, we propose a heuristic framework that combines both static analysis and fuzz testing to detect targeted concurrency vulnerabilities such as concurrency buffer overflow, double free, and use-after-free. The static analysis locates sensitive concurrent operations in a concurrent program, categorizes each finding into a potential type of concurrency vulnerability, and determines the execution order of the sensitive operations in each finding that would trigger the suspected concurrency vulnerability. The results are then plugged into the fuzzer with the execution order fixed by the static analysis in order to trigger the suspected concurrency vulnerabilities.
Changming Liu, Deqing Zou, Bin B. Zhu, Hai Jin 0001
ACSAC1
2018 JPEG Decompression in the Homomorphic Encryption Domain
abstract
Privacy-preserving processing is desirable for cloud computing to relieve users' concern of loss of control of their uploaded data. This may be fulfilled with homomorphic encryption. With widely used JPEG, it is desirable to enable JPEG decompression in the homomorphic encryption domain. This is a great challenge since JPEG decoding needs to determine a matched codeword, which then extracts a codeword-dependent number of coefficients. With no access to the information of encrypted content, a decoder does not know which codeword is matched, and thus cannot tell how many coefficients to extract, not to mention to compute their values. In this paper, we propose a novel scheme that enables JPEG decompression in the homomorphic encryption domain. The scheme applies a statically controlled iterative procedure to decode one coefficient per iteration. In one iteration, each codeword is compared with the bitstream to compute an encrypted Boolean that represents if the codeword is a match or not. Each codeword would produce an output coefficient and generate a new bitstream by dropping consumed bits as if it were a match. If a codeword is associated with more than one coefficient, the codeword is replaced with the codeword representing the remaining undecoded coefficients for the next decoding iteration. The summation of each codeword's output multiplied by its matching Boolean is the output of the current iteration. This is equivalent to selecting the output of a matched codeword. A side benefit of our statically controlled decoding procedure is that paralleled Single-Instruction Multiple-Data (SIMD) is fully supported, wherein multiple plaintexts are encrypted into a single plaintext, and decoding a ciphertext block corresponds to decoding all corresponding plaintext blocks. SIMD also reduces the total size of ciphertexts of an image. Experimental results are reported to show the performance of our proposed scheme.
Xiaojing Ma 0002, Changming Liu, Sixing Cao, Bin B. Zhu
ACM Multimedia2
2018 Recaptured Image Forensics Algorithm Based on Multi-Resolution Wavelet Transformation and Noise Analysis
abstract
With the rapid development of digital cameras and smart phones, the image identification system in current times will be of a great impact. This will cause the form of image information to increase serious security issues. Especially, the emergence of the recaptured image makes conventional digital image forensics algorithm invalid. Therefore, a new image forensics algorithm is urgently needed to identify the recaptured image. In this paper, a new recaptured image identifying algorithm is put forward based on wavelet transformation and noise analysis by analyzing the differences between the real and recaptured images generated in the imaging process. First, the proposed algorithm extracts mean value, variance and skewness as wavelet characteristic from the high-frequency images and low-frequency images by wavelet transformation. Meanwhile, the proposed algorithm analyzes the noise image by means of local binary pattern to extract noise characteristic. Finally, the support vector machine is applied to classify the recaptured image with wavelet characteristics and noise characteristics. The results show the presented method can not only identify the recaptured image obtained from different media but also have better identification rate, and the dimension of the characteristic vector is also lower than those obtained by other algorithms.
Yanjun Sun, Xuanjing Shen, Yingda Lv, Changming Liu
Int. J. Pattern Recognit. Artif. Intell.4
2015 An Energy-Balanced WSN Algorithm Based on Active Hibernation and Data Recovery
Changming Liu, Cai Fu, Deliang Xu, Lansheng Han
ICA3PP (1)1
2012 Damage Pattern Recognition of Refractory Materials Based on BP Neural Network
Changming Liu, Yourong Li, Gangbing Song, Jianyi Kong
ICONIP (4)1
2003 Response of net primary productivity on climate change in the Yellow River Basin
abstract
Net primary productivity (NPP) is important in the global carbon budget. The change of NPP can be a good indicator of climate variation to some extent. Therefore, it is necessary to study the relationship between climate factors and inter-annual change of NPP, which will help us to understand global change. An empirical exponential model between NPP and integrated NDVI in the Yellow River Basin in China has been established. The spatial distribution pattern and dynamic change of annual NPP from year 1982 to 1998 are analyzed by using multi-temporal 8 km resolution AVHRR-NDVI data. The results show that there exists an incline trend of mean NPP for whole basin while the rainfall decreases slightly, which demonstrates that human activity effects the vegetation cover and NPP much. Finally, in order to analyze the effect of rainfall and temperature on inter-annual change of NPP, correlation coefficient between rainfall, temperature and NPP are computed respectively. It is found that relativity between rainfall, air temperature and NPP is complicated for different climate and vegetation zone. NPP is not highly correlated with climate factors in most places, which may be caused by human activity and other factors. The effect of rainfall on NPP is significant in desert steppe region, while the effect of temperature on NPP is significant in alpine vegetation region and Qinhai-Xizang Plateau. The correlation coefficient between NPP and temperature is negative in area where NPP is positively correlated with rainfall, while it is positive in area where NPP is negatively correlated with rainfall.
Rui Sun 0003, Yuyu Zhou, Changming Liu
IGARSS3
1995 Dynamic routing for multimedia traffic over ATM networks
abstract
ATM networks support multimedia traffic where diverse services have to be provided and various QoS requirements have to be met. Routing plays an important role in guaranteeing the QoS. However conventional routing will cause a significant overhead when the network size gets very large or rerouting occurs frequently due to the varying link state. The objective of our dynamic routing scheme is to perform more efficient routing over a more effective and simpler topology which is abstracted from the original full topology based on the dynamic link state. Only those links with high probability to satisfy the QoS of the call are included in the effective topology. It is an efficient way to prevent rerouting from occurring too often because the blocking probability over this effective topology is significantly low. A hierarchical routing model is also proposed to further reduce the amount of information that has to be stored and exchanged for routing. We present the simulation results of our dynamic routing scheme along with the hierarchical routing model and its implementation over QUARTS, a simulation testbed for ATM networks.
Changming Liu, Hussein T. Mouftah
ISCC2