Qixiao Lin

dblp:243/3828 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0002-1359-9636ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 ProvGuard: Detecting SDN Control Policy Manipulation via Contextual Semantics of Provenance Graphs
Jun Zeng 0006, Qixiao Lin, Jiahao Liu 0005, Jianwei Zhuge, Zhenkai Liang
NDSS5
2025 TAPPecker: TAP Logic Inference and Violation Detection in Heterogeneous Smart Home Systems
abstract
In IoT environments-particularly within smart home systems-Trigger-Action Programming (TAP) serves as the primary mechanism for specifying automation rules. While TAP enables flexible and user-friendly automation, unintended interactions among TAP rules that violate security or privacy policies can lead to serious security consequences. A common assumption in prior research is that automation rules are readily available for analysis-that is, the TAP logic can be directly accessed. However, many real-world IoT platforms, such as Xiaomi and HomeKit, do not expose their internal automation rule sets. Moreover, existing logic extraction techniques primarily focus on the relationships between individual events, failing to capture the complex semantics of multi-condition TAP rules. The growing heterogeneity of smart home systems complicates the challenge of ensuring consistency between automation logic execution and system security objectives across such diverse “black-box” systems. In this paper, we present TAPPecker, an approach that leverages self-adaptation and evolutionary strategies to automatically infer TAP rules from system events in heterogeneous smart home environments. We analyze the inferred rules to detect potential security violations, with a specific focus on temporal aspects. We prototype TAPPecker and develop a hybrid testbed capable of generating realistic smart-home event logs, enabling comprehensive, multi-scenario testing. Our experimental results demonstrate that TAPPecker improves inference accuracy by $40.85 \%$ over existing approaches, while generating more expressive TAP logic and uncovering previously undetected security violations. Notably, our system revealed two time-related policy violations within official TAP rule sets that had not been previously reported.
Qixiao Lin, Zhenkai Liang
RAID1
2025 TF-Detector: Anomaly Detection in Industrial Control System through Process-Aware Time-Frequency Domain Analysis
abstract
Anomaly detection in Industrial Control Systems (ICS) is crucial for ensuring operational safety, preventing equipment damage, and maintaining production continuity in critical infrastructure. As ICS become increasingly complex and interconnected, anomaly detection faces significant challenges in maintaining system security and operational integrity. Traditional statistics-based methods fail to capture complex, high-dimensional industrial data patterns. Existing deep learning approaches primarily focus on time-domain analysis, struggling with normal operational noise and system oscillation anomalies, causing detection errors. Additionally, these methods rely solely on data-driven correlation patterns, missing anomalies that violate physical coupling relationships between ICS components, leading to false negatives. In this paper, we propose TF-Detector, a dual-scale anomaly detection framework that decomposes ICS data into time-domain and frequency-domain representations. To capture the process interaction between sensors, TF-Detector employs process graphs enhanced with dynamic correlation patterns to model industrial relationships, and utilizes graph neural networks to extract complex features. Comprehensive evaluations conducted on two real-world ICS datasets demonstrate that our approach significantly outperforms state-of-the-art anomaly detection methods, improving average precision by 15.61% and 2.36%, respectively.
Shuyuan Chang, Qixiao Lin, Mengshuo Yuan, Yan Huo 0001
TrustCom2
2025 Anomaly Detection in Smart IoT Systems Based on Contextual Semantics of Behavior Graphs
abstract
With the advancement of Internet of Things (IoT) technology, smart IoT systems have become integral to industrial production and daily life. However, they face significant security and privacy vulnerabilities from different aspects. To enhance the security mechanisms, “Meta Computing” techniques (also called “Network-as-a-Computer, NaaC”) integrate all available computing resources and support zero-trust environments. Traditional anomaly detection methods consider the correlation between two events, which can be bypassed by constructing fake events that indirectly influence target devices, leading to false negatives. To address this issue, behavior-context-based approaches struggle with the complexity and variability of behavior patterns, resulting in false positives due to their inability to tolerate slight differences in event sequences representing the same system behavior. In this paper, we propose an anomaly detection approach in smart IoT systems based on the contextual semantics of behavior graphs. Our method captures critical event semantics while tolerating variations in noncritical events to aggregate and summarize the behavior semantics. We cluster benign behaviors and use whether the testing behavior instance falls into the benign behavior clusters as the criterion for anomaly detection. Our experiment results show that our approach effectively differentiates between anomalous and benign behaviors, significantly reducing false positives and negatives compared to state-of-the-art methods.
Qixiao Lin, Shuyuan Chang, Qiange Liu, Yan Huo 0001
IEEE Internet Things J.1
2025 BLMProbe: Enhancing Internet-Connected Device Discovery by Automated Device Labeling and Label Migration
abstract
10.1109/TIFS.2025.3587211
Zhenhao Tian, Yi He 0020, Nuo Zhang, Qixiao Lin, Hetian Shi, Jianwei Zhuge, Deliang Chang
IEEE Trans. Inf. Forensics Secur.4
2024 UIHash: Detecting Similar Android UIs through Grid-Based Visual Appearance Representation
Jun Zeng 0006, Qixiao Lin, Shaowen Feng, Zhenkai Liang
USENIX Security Symposium4
2024 SmartTracer: Anomaly-Driven Provenance Analysis Based on Device Correlation in Smart Home Systems
abstract
As a typical application of the Internet of Things (IoT), smart home systems facilitate home setup where appliances and devices can be controlled automatically and remotely from anywhere with an Internet connection. Devices within a smart home system are usually correlated according to the automation rules/programs preconfigured by system owners. However, attackers can exploit these complex correlations among devices to conduct indirect attacks, making it challenging for owners to locate the root cause of a security incident and identify compromised devices. In this article, we propose SmartTracer, an anomaly-driven provenance analysis approach based on interdevice correlation extraction and tracing. Specifically, we extract correlations from the smart home system’s automation setup and physical interaction configuration. We define a unified dependency graph to describe the event causality among devices based on the event correlation and device run-time states. We then present an identification algorithm to profile trigger-action sequences from the abnormal run-time dependency graph and identify root cause nodes of anomalies. We prototype our approach and evaluate it on a self-developed testbed. The experiment results show that SmartTracer effectively provides a complete and precise provenance analysis for attacks exploited by the execution chains of automation. SmartTracer can generate a dependency graph for around 100 automation rules in 0.03 s and identify anomalies within 0.14 s.
Qixiao Lin, Shishi Zhu, Liran Ma, Jianwei Liu 0001
IEEE Internet Things J.2
2023 Securing Web Inputs Using Parallel Session Attachments
Ruite Xu, Qixiao Lin, Shikun Wu, Zhenkai Liang
SecureComm (2)3
2022 SybilHunter: Hybrid graph-based sybil detection by aggregating user behaviors
Xiling Luo, Qixiao Lin
Neurocomputing4
2022 Semantic-Fuzzing-Based Empirical Analysis of Voice Assistant Systems of Asian Symbol Languages
abstract
Recently, smart voice assistants (VAs) are widely deployed to provide control services via voice commands in IoT systems, e.g., smart home, industrial IoT systems, etc. However, due to the complexity of the application environment and the diversity of voice commands, more and more attacks against VAs cause severe security problems. As voice development platforms allow third-party voice skills to be accessed, adversaries are able to obtain users’ private information by squatting attacks using confusing names. The existing work studied the exploitability of semantic misinterpretation in VA systems on phonetic languages such as English. However, due to the semantic structural difference between phonetic English and symbol-based Asian languages, such as Chinese, the linguistic-model-guided fuzzing tool proposed by the previous work is insufficient to conduct semantic analysis on the VAs of Asian Languages. In this article, we conduct a systematic analysis to evaluate the feasibility of voice misinterpretation attacks to typical Asian language VAs through semantic fuzzing. We develop Harmony-Fuzzer, the semantic fuzzing tool that the fuzzing process is under the guidance of fuzzing rules abstracted from phenomena of speech errors, disfluency, or semantically similar expressions in Chinese corpus. We use Bayesian networks to formulate fuzzing models statistically so that the fuzzing space can be controlled by the probability of fuzzing processing. We use our results to test VAs and design malicious skills to empirically verify the feasibility of squatting attacks. We found that squatting attacks on Chinese VAs are feasible when attackers leverage some linguistic phenomena delicately.
Qixiao Lin, Zhenkai Liang
IEEE Internet Things J.3
2020 Watchdog: Detecting Ultrasonic-Based Inaudible Voice Attacks to Smart Home Systems
abstract
Internet of Things is a critical infrastructure component as well as an enabling technology to support the fast-developing cross-region, cross-application, and diversified collaborative smart city services that require systematic cooperation among multiple smart city systems. Speech recognition-based voice controllable systems become one of the most popular interfaces in smart devices. However, it has been proved that attackers can hide their voice commands via modulating them on ultrasonic carriers and carry out inaudible voice attacks to manipulate voice controllable devices (e.g., mobile phone) unnoticeably. Although there are defense suggestions to enhance the hardware or add new modules of microphones, it is impractical to change the hardware design of all voice-controllable devices developed by different manufactures. In this article, we validate the effectiveness of ultrasonic-based inaudible voice attacks to voice-controllable smart home devices and propose a signal-processing-based hidden voice attack detection approach. Our approach uses an independent device that deploys a two-step lightweight detecting algorithm to identify the attack signals. We simulate our algorithm and make a prototype implementation of the proposed approach. The simulation results illustrate the correctness of the detection algorithm and the experiments show that our approach can detect the ultrasonic-based inaudible voice attack effectively.
Shishi Zhu, Xuan Dai, Qixiao Lin, Jianwei Liu 0001
IEEE Internet Things J.4
2019 Detecting Android Side Channel Probing Attacks Based on System States
Qixiao Lin, Futian Shi, Shishi Zhu, Zhenkai Liang
WASA1