EDBT 2026 Demo / reviewers in the wild / expert
Qingying Hao
dblp:254/0865
· DBLP profile ↗
8ranked-venue papers
2as first author
7since 2021 · last 2026
0009-0006-8122-1076ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revelio: Blurred Images Can Still Disclose Your Identity
Haoyu Zhai, Pirouz Naghavi, Qingying Hao, Gang Wang 0011 |
SP | 4 |
| 2025 | Can You Walk Me Through It? Explainable SMS Phishing Detection using LLM-based Agents
Haoyu Zhai, Chenkai Wang 0001, Qingying Hao, Nick A. Cohen, Roopa Foulger, Jonathan A. Handler, Gang Wang 0011 |
SOUPS | 4 |
| 2024 | It Doesn't Look Like Anything to Me: Using Diffusion Model to Subvert Visual Phishing Detectors
Qingying Hao, Nirav Diwan, Ying Yuan 0002, Giovanni Apruzzese, Mauro Conti, Gang Wang 0011 |
USENIX Security Symposium | 1 |
| 2024 | "Are Adversarial Phishing Webpages a Threat in Reality?" Understanding the Users' Perception of Adversarial WebpagesabstractMachine learning based phishing website detectors (ML-PWD) are a critical part of today's anti-phishing solutions in operation. Unfortunately, ML-PWD are prone to adversarial evasions, evidenced by both academic studies and analyses of real-world adversarial phishing webpages. However, existing works mostly focused on assessing adversarial phishing webpages against ML-PWD, while neglecting a crucial aspect: investigating whether they can deceive the actual target of phishing---the end users. In this paper, we fill this gap by conducting two user studies (n=470) to examine how human users perceive adversarial phishing webpages, spanning both synthetically crafted ones (which we create by evading a state-of-the-art ML-PWD) as well as real adversarial webpages (taken from the wild Web) that bypassed a production-grade ML-PWD. Our findings confirm that adversarial phishing is a threat to both users and ML-PWD, since most adversarial phishing webpages have comparable effectiveness on users w.r.t. unperturbed ones. However, not all adversarial perturbations are equally effective. For example, those with added typos are significantly more noticeable to users, who tend to overlook perturbations of higher visual magnitude (such as replacing the background). We also show that users' self-reported frequency of visiting a brand's website has a statistically negative correlation with their phishing detection accuracy, which is likely caused by overconfidence. We release our resources. Ying Yuan 0002, Qingying Hao, Giovanni Apruzzese, Mauro Conti, Gang Wang 0011 |
WWW | 2 |
| 2023 | How to Cover up Anomalous Accesses to Electronic Health Records
Qingying Hao, Bo Li 0026, David M. Liebovitz, Gang Wang 0011, Carl A. Gunter |
USENIX Security Symposium | 2 |
| 2021 | It's Not What It Looks Like: Manipulating Perceptual Hashing based ApplicationsabstractPerceptual hashing is widely used to search or match similar images for digital forensics and cybercrime study. Unfortunately, the robustness of perceptual hashing algorithms is not well understood in these contexts. In this paper, we examine the robustness of perceptual hashing and its dependent security applications both experimentally and empirically. We first develop a series of attack algorithms to subvert perceptual hashing based image search. This is done by generating attack images that effectively enlarge the hash distance to the original image while introducing minimal visual changes. To make the attack practical, we design the attack algorithms under a black-box setting, augmented with novel designs (e.g., grayscale initialization) to improve the attack efficiency and transferability. We then evaluate our attack against the standard pHash as well as its robust variant using three different datasets. After confirming the attack effectiveness experimentally, we then empirically test against real-world reverse image search engines including TinEye, Google, Microsoft Bing, and Yandex. We find that our attack is highly successful on TinEye and Bing, and is moderately successful on Google and Yandex. Based on our findings, we discuss possible countermeasures and recommendations. Qingying Hao, Licheng Luo, Steve T. K. Jan, Gang Wang 0011 |
CCS | 1 |
| 2021 | CADE: Detecting and Explaining Concept Drift Samples for Security Applications
Wenbo Guo 0002, Qingying Hao, Arridhana Ciptadi, Ali Ahmadzadeh, Xinyu Xing 0001, Gang Wang 0011 |
USENIX Security Symposium | 3 |
| 2020 | Throwing Darts in the Dark? Detecting Bots with Limited Data using Neural Data AugmentationabstractMachine learning has been widely applied to building security applications. However, many machine learning models require the continuous supply of representative labeled data for training, which limits the models' usefulness in practice. In this paper, we use bot detection as an example to explore the use of data synthesis to address this problem. We collected the network traffic from 3 online services in three different months within a year (23 million network requests). We develop a stream-based feature encoding scheme to support machine learning models for detecting advanced bots. The key novelty is that our model detects bots with extremely limited labeled data. We propose a data synthesis method to synthesize unseen (or future) bot behavior distributions. The synthesis method is distribution-aware, using two different generators in a Generative Adversarial Network to synthesize data for the clustered regions and the outlier regions in the feature space. We evaluate this idea and show our method can train a model that outperforms existing methods with only 1% of the labeled data. We show that data synthesis also improves the model's sustainability over time and speeds up the retraining. Finally, we compare data synthesis and adversarial retraining and show they can work complementary with each other to improve the model generalizability. Steve T. K. Jan, Qingying Hao, Tianrui Hu, Jiameng Pu, Sonal Oswal, Gang Wang 0011, Bimal Viswanath |
SP | 2 |