EDBT 2026 Demo / reviewers in the wild / expert
Qihang Zhou
dblp:260/7116
· DBLP profile ↗
40ranked-venue papers
14as first author
39since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 11 since 2021Artificial intelligence and machine learning · 10 · 4 first-author · 10 since 2021Systems, architecture and hardware · 10 · 3 first-author · 10 since 2021Computer networks · 7 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FIRM-MoE: Fine-GrainedExpert Decomposition for Resource-Adaptive MoE InferenceabstractMixture-of-Experts (MoE) is a sparse neural architecture that significantly increases model capacity while maintaining low computational complexity. However, deploying MoE-based large language models (LLMs) on memory-constrained edge devices remains challenging due to their substantial memory requirements. To address this issue, we propose FIRM-MoE, a fine-grained expert offloading framework designed to enable flexible and efficient MoE inference. The core insight of our approach is to reduce the risk of inaccurate expert loading by decomposing each expert into fine-grained sub-experts and then dynamically allocating them through a fine-grained scheduling strategy. To further reduce the error in expert loading, we introduce a multi-layer expert prediction mechanism and a resource-adaptive expert pre-loading algorithm to enable more robust expert allocation. This design allows our model to achieve more efficient expert utilization and improved resilience to prediction errors. We conduct extensive experiments to demonstrate the superiority of FIRM-MoE across diverse memory constraints. The results show that FIRM-MoE achieves up to 1.5× speedup and 2.8× memory savings in decoding, compared to state-of-the-art MoE offloading strategies. Qihang Zhou, Bin Qian 0002, Zhenyu Wen, Wenchao Meng, Shibo He |
AAAI | 2 |
| 2026 | Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language ModelsabstractLarge language models (LLMs) increasingly support multilingual understanding and generation. Meanwhile, efforts to interpret their internal mechanisms have emerged, offering insights to enhance multilingual performance. While multi-head self-attention (MHA) has proven critical in many areas, its role in multilingual capabilities remains underexplored. In this work, we study the contribution of MHA in supporting multilingual processing in LLMs. We propose Language Attention Head Importance Scores (LAHIS), an effective and efficient method that identifies attention head importance for multilingual capabilities via a single forward and backward pass through the LLM. Applying LAHIS to Aya-23-8B, Llama-3.2-3B, and Mistral-7B-v0.1, we reveal the existence of both language-specific and language-general heads. Language-specific heads enable cross-lingual attention transfer to guide the model toward target language contexts and mitigate off-target language generation issue, contributing to addressing challenges in multilingual LLMs. We also introduce a lightweight adaptation that learns a soft head mask to modulate attention outputs over language heads, requiring only 20 tunable parameters to improve XQuAD accuracy. Overall, our work enhances both the interpretability and multilingual capabilities of LLMs from the perspective of MHA. Qiyang Song, Qihang Zhou, Haichao Du, Shaowen Xu, Weijuan Zhang, Xiaoqi Jia |
AAAI | 3 |
| 2026 | WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave Restore
Xiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian, Weijuan Zhang, Xiaoqi Jia |
ASPLOS (2) | 2 |
| 2026 | Bypassing Safety Alignment via API Design: A Systematic Risk Analysis of Response Prefill in LLM Systems
Yakai Li, Jiekang Hu, Weiduan Sang, Luping Ma, Dongsheng Nie, Weijuan Zhang, Qingjia Huang, Qihang Zhou |
DSN | 10 |
| 2026 | VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain
Qihang Zhou, Shaowen Xu, Yamin Xie, Xiaoqi Jia |
DSN | 3 |
| 2026 | IoTBec: An Accurate and Efficient Recurring Vulnerability Detection Framework for Black Box IoT devices
Jiaming Guo, Shuangning Yang, Guoli Zhao, Qing-Qi Liu, Zhenlu Tan, Lixiao Shan, Qihang Zhou, Mengting Zhou, Jianwei Tai, Xiaoqi Jia |
NDSS | 9 |
| 2026 | DRShield: Coordinating Line-Rate Enforcement and Global Adaptation for Dynamic DDoS Defense
Qihang Zhou, Zibo Gao, Xiaoqi Jia, Zhiqiang Lv |
SECON | 2 |
| 2026 | FalconScope: Effective and Efficient Detection of Hidden Web Interfaces in IoT DevicesabstractHidden web interfaces in Internet of Things (IoT) devices pose significant security threats by unintentionally exposing inadequately protected functionalities, enabling attackers to bypass authentication, alter configurations, leak sensitive data, or execute arbitrary commands. Despite recent advancements, current detection approaches suffer from two critical challenges: 1) inadequately model the complex internal routing mechanisms of IoT firmware, leading to incomplete interface enumeration and substantial false negatives; and 2) inefficiently generate probing requests and verify unauthorized access due to limited semantic understanding of interface communication protocols. To overcome these challenges, we introduce FalconScope, a novel system combining precise firmware routing modeling and Large Language Model (LLM)-driven semantic analysis to detect hidden web interfaces effectively and efficiently. FalconScope achieves this through two key innovations: 1) a static analysis technique precisely reconstructs the device's internal routing mechanisms, enabling comprehensive enumeration of Routing Unique Identifiers and their corresponding backend handlers; and 2) an LLM-powered semantic engine automatically generates syntactically and semantically valid HTTP requests to efficiently trigger backend logic, coupled with semantic validation of device responses to accurately confirm unauthorized access. Evaluations on 11 real-world IoT devices from four major vendors demonstrate that FalconScope significantly surpasses existing state-of-the-art tools, detecting 620 hidden web interfaces—103 times more than IoTScope—while consuming only 3.6% of its analysis time. Following responsible disclosure, 50 issues have been assigned CVE IDs. Jiaming Guo, Kuihao Yan, Jiekang Hu, Xiaoqi Jia, Haichao Du, Qihang Zhou |
WWW | 7 |
| 2026 | FlexClave: An Extensible and Secure Trusted Execution Environment FrameworkabstractAs computer system software stacks become increasingly complex, the associated security risks also escalate. Trusted Execution Environments (TEEs) have emerged as a mainstream security solution to enhance system security. TEEs can be categorized into user-level TEEs, OS-level TEEs, and hybrid TEEs. However, these TEEs typically possess fixed security boundaries and isolation domains, limiting their adaptability to varying security requirements and dynamic scenarios. Moreover, the design of Trusted Computing Base (TCB) components in TEE frameworks often operates at the highest privilege levels of the architecture. This concentration of critical code at the highest privilege level increases the whole platform’s security risk due to the growing amount of code as more security functions are added. In this paper, we propose FlexClave, an extensible and secure TEE framework designed to address these issues. FlexClave leverages hardware primitives to create secure isolation boundaries tailored to different use cases. Additionally, our framework distributes TCB components across various privilege levels, reducing the concentration of security functions at the highest privilege levels and mitigating the risks associated with running extensive code in a single, highly privileged context. We implement two prototypes on ARMv9-A Fixed Virtual Platform and ARMv8 RK3399 SoC, each with two use cases (container and virtual machine), to evaluate the system’s security and performance. Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shaowen Xu, Jiayun Chen, Haichao Du, Yamin Xie, Peijie Yin, Shengzhi Zhang, Peng Liu 0005 |
IEEE Trans. Computers | 1 |
| 2025 | SISTAR: An Efficient DDoS Detection and Mitigation Framework Utilizing Programmable Data PlanesabstractDDoS attacks have become one of the most severe cybersecurity threats, especially in application-layer attacks. With the emergence of Programmable Data Planes (PDPs), it has become possible to maintain line-rate throughput while achieving high detection rates, making them crucial in addressing DDoS challenges. However, due to the complexity of DDoS attacks, detection remains resource-intensive and overall network defense effectiveness is limited. This limitation becomes particularly pronounced in clustered environments, where coordinated defense is essential. This paper presents SISTAR, an innovative framework for efficient DDoS detection and mitigation using PDP. SISTAR integrates an improved Decision Tree - Constrained Threshold Segmentation (DT-CTS) model to achieve high detection accuracy while minimizing hardware resource usage. Through distributed deployment across multiple switches, SISTAR enhances network resilience by enabling rapid detection and coordinated response to DDoS attacks. We implement a prototype of SISTAR and evaluate its performance in a realistic testbed, the experimental results show that SISTAR surpasses existing models in terms of detection accuracy and resource efficiency. When combined with its alert pushback mechanism, SISTAR can effectively reduce network resource consumption caused by DDoS attacks. Qihang Zhou, Zibo Gao, Yinglong Han, Zhiqiang Lv |
CCS | 3 |
| 2025 | Chameleon: Towards Building Least-privileged TEE via Functionality-based Resource Re-groupingabstractTrustZone-assisted Trusted Execution Environment (TEE) has been widely employed in mobile devices to protect sensitive applications. With increased customization demands, Trusted Applications (TAs) have become more flexible and complex, exposing numerous vulnerabilities within the TEE. Furthermore, due to the unrestricted Trusted Operating System (TOS) services provided to TA, an attacker can exploit vulnerabilities to compromise the whole TEE system. In this paper, we propose a novel customized TOS partition approach, called Chameleon, to enhance the security of the TrustZone-assisted TEE system. Inspired by the principle of least privilege and our TEE vulnerability analysis, we first categorize the TOS into TOS service modules and basic kernel modules. Then, we selectively encapsulate these modules into distinct Capsules based on the TA's functional requirements, providing each TA with a separate execution environment (TA-entity). To enforce access control and confine vulnerable modules within a TA-entity, we introduce T-Visor, which serves as our Trusted Computing Base. Our prototype implementation, built upon Linaro's OP-TEE, requires only 2.9K Lines of Code (LoC) modifications. Evaluation on a Hikey960 board demonstrates that Chameleon reduces the attack surface of TOS services to 51% and mitigates 122 out of 138 CVEs (88.41%) with negligible performance overhead. Qihang Zhou, Feifan Qian, Jiayun Chen, Heqing Huang 0001, Xiaoqi Jia, Haichao Du |
MobiSys | 2 |
| 2025 | RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Primitives
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Peng Liu 0005, Shengzhi Zhang, Jiayun Chen, Shaowen Xu |
NDSS | 1 |
| 2025 | FairDD: Fair Dataset DistillationabstractCondensing large datasets into smaller synthetic counterparts has demonstrated its promise for image classification. However, previous research has overlooked a crucial concern in image recognition: ensuring that models trained on condensed datasets are unbiased towards protected attributes (PA), such as gender and race. Our investigation reveals that dataset distillation fails to alleviate the unfairness towards minority groups within original datasets. Moreover, this bias typically worsens in the condensed datasets due to their smaller size. To bridge the research gap, we propose a novel fair dataset distillation (FDD) framework, namely FairDD, which can be seamlessly applied to diverse matching-based DD approaches (DDs), requiring no modifications to their original architectures. The key innovation of FairDD lies in synchronously matching synthetic datasets to PA-wise groups of original datasets, rather than indiscriminate alignment to the whole distributions in vanilla DDs, dominated by majority groups. This synchronized matching allows synthetic datasets to avoid collapsing into majority groups and bootstrap their balanced generation to all PA groups. Consequently, FairDD could effectively regularize vanilla DDs to favor biased generation toward minority groups while maintaining the accuracy of target attributes. Theoretical analyses and extensive experimental evaluations demonstrate that FairDD significantly improves fairness compared to vanilla DDs, with a promising trade-off between fairness and accuracy. Its consistent superiority across diverse DDs, spanning Distribution and Gradient Matching, establishes it as a versatile FDD approach. Qihang Zhou, Shenhao Fang, Shibo He, Wenchao Meng, Jiming Chen 0001 |
NeurIPS | 1 |
| 2025 | Demand-Driven Sparse Mobile Crowdsensing With Neighborhood-Aware ReconstructionabstractSparse mobile crowdsensing (SMCS) is a cost-effective paradigm aimed at recruiting workers to complete sensing tasks and inferring the remaining unobserved data, with broad applications in large-scale, fine-grained monitoring services. In SMCS, spatial coverage of the sensing area or global completion accuracy is typically used as the performance metric. However, in many real-world service scenarios (e.g., temperature, humidity, air quality monitoring), users are generally only interested in data from their specific regions and expect the highest possible data accuracy. In such cases, relying solely on coverage or global completion error fails to adequately assess the quality of the platform’s service. To address this and satisfy users’ sensing demands as much as possible while maintaining low sensing costs, we propose the Demand-Driven Framework with Neighborhood-Aware Data Reconstruction (D2-SMCS), which integrates regional population demand calculation, dynamic clustering, and data reconstruction. Unlike existing approaches, we introduce quality of service (QoS) as a performance metric based on regional population demand. First, we quantify the interest level of sensing tasks in different regions by considering factors such as population demand and data fluctuation. Based on this quantification, the dynamic clustering module selects the regions most beneficial for accurate data completion. Finally, to overcome the limitation of traditional matrix completion methods in capturing short-term variations, we propose an innovative Neighborhood-Aware Latent Matrix Completion (NALMC) approach to infer and complete the unobserved regions. Extensive experiments on real-world datasets demonstrate the effectiveness of our framework. Qihang Zhou, Guoqiang Deng, Lingyu Liang, Xinglin Zhang 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Dynamic sparse and weight allocation-based text-driven person retrieval
Shuren Zhou, Qihang Zhou |
Image Vis. Comput. | 2 |
| 2025 | Unknown Worker Recruitment With Long-Term Incentive in Mobile CrowdsensingabstractMany mobile crowdsensing applications require efficient recruitment of workers whose qualities are often unknown a priori. While prior research has explored multi-armed bandit-based mechanisms with short-term incentives to address this unknown worker recruitment challenge, these mechanisms mostly neglect the enduring participation issues stemming from privacy concern and selection starvation in the long-term task. Therefore, in this paper, we focus on incentivizing long-term participation of unknown workers, thereby providing crucial assurance for crowdsensing applications. We first establish an auction framework based on shuffle differential privacy (SDP), where we leverage SDP’s privacy amplification effect to mitigate privacy-related utility loss when dealing with the privacy-sensitive worker and the utility-sensitive platform. Following this, we model the selection requirements of workers as fairness constraints and propose two novel fairness-aware incentive mechanisms, GFA and IFA, to ensure group and individual fairness for unknown workers, respectively. Theoretical analyses highlight the desirable properties of GFA and IFA, complemented by an in-depth exploration of fairness violation and regret. Finally, numerical simulations are conducted on two real-world datasets, validating the superior performance of the proposed mechanisms. Qihang Zhou, Xinglin Zhang 0001, Zheng Yang 0002 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | CubeVisor: A Multi-realm Architecture Design for Running VM with ARM CCAabstractCloud computing nowadays provides flexible and scalable computing services, using different hardware platforms, including ARM. Virtualization allows multiple virtual machines (VMs) to share the physical resources of a host machine. However, these technologies have security risks. The hypervisor is the software that controls VMs, and it can be exploited or manipulated by hackers or untrusted providers. ARM CCA, a novel feature of ARMv9-A, allows confidential VMs to run in a new security state called realm. However, the current CCA prototype still has some problems, including risks brought by external libraries, single point of failure, highly privileged TF-RMM and costly world switch. In this paper, we introduce CubeVisor, a new secure virtualization architecture based on ARM CCA. It uses the idea of the Cube, which is a combination of a hypervisor and a VM, protecting each Cube from other Cubes or components. The CubeVisor also improves performance by optimizing memory allocation and world-switching processes. We implement prototypes on both software-based ARM FVP platform and hardware-based ARM Cortex-A platform for evaluations. The results show that the CubeVisor can protect VMs well and has very low overhead compared to the CCA based virtualization methods. Jiayun Chen, Qihang Zhou, Xiaolong Yan, Xiaoqi Jia, Weijuan Zhang |
ACSAC | 2 |
| 2024 | vASP: Full VM Life-cycle Protection Based on Active Security Processor ArchitectureabstractCloud computing has been applied on a large scale due to its competitive advantages. However, the introduction of virtualization brings new risks, which can come from within the VM and the host. Due to the abstraction of hardware resources by the hypervisor, traditional trusted computing methods, such as TPM and ASP, are no longer available in cloud environments. Existing work focusing on enabling trusted computing in cloud computing is primarily based on TPM and vTPM, but there are still issues such as the trusted chain not covering all stages of the VM life cycle and the integrity measurement operation potentially causing high overhead. In this paper, we present the vASP architecture, which solves the limitation of the ASP architecture in a cloud environment. Using customization features provided by the ASP, we customize interfaces for the vASP architecture and pass the trusted relationship to the upper layer to form a complete chain of trust. The vASP front-end plugs into the hypervisor actively and regularly operates the dynamic measurement process of the guest to ensure that data from the guest machine are not tampered with. With the introduction of vASP in the cloud computing platform, the security of vASP components during VM operation is also a concern. As a result, we propose a full VM life-cycle protection method through verification and measurement mechanisms that cannot be bypassed to ensure that vASP maintains a match with specific VMs. We have implemented the vASP architecture on a commercial platform deployed with ASP architecture and evaluated it. The result shows that the vASP architecture can protect VM integrity well during full life-cycle and has very low overhead compared to the native virtualization architecture. Jiayun Chen, Qihang Zhou, Weijuan Zhang, Yamin Xie, Xiaoqi Jia |
CCGrid | 2 |
| 2024 | Distributed Boosting: An Enhancing Method on Dataset DistillationabstractDataset Distillation (DD) is a technique for synthesizing smaller, compressed datasets from large original datasets while retaining essential information to maintain efficacy. Efficient DD is a current research focus among scholars. Squeeze, Recover and Relabel (SRe2L) and Adversarial Prediction Matching (APM) are two advanced and efficient DD methods, yet their performance is moderate with lower volumes of distilled data. This paper proposes an ingenious improvement method, Distributed Boosting (DB), capable of significantly enhancing the performance of these two algorithms at low distillation volumes, leading to DB-SRe2L and DB-APM. Specifically, DB is divided into three stages: Distribute & Encapsulate, Distill, and Integrate & Mix-relabel. DB-SRe2L, compared to SRe2L, demonstrates performance improvements of 25.2%, 26.9%, and 26.2% on full 224×224 ImageNet-1k at Images Per Class (IPC) 10, CIFAR-10 at IPC 10, and CIFAR-10 at IPC 50, respectively. Meanwhile, DB-APM, in comparison to APM, exhibits performance enhancements of 21.2% and 20.9% on CIFAR-10 at IPC 10, CIFAR-100 at IPC 1, respectively. Additionally, we provide a theoretical proof of convergence for DB. To the best of our knowledge, DB is the first method suitable for distributed parallel computing scenarios. Xuechao Chen, Wenchao Meng, Peiran Wang, Qihang Zhou |
CIKM | 4 |
| 2024 | ConMonitor: Lightweight Container Protection with Virtualization and VM FunctionsabstractContainers are widely used in multi-tenant cloud computing for their ease of deployment, minimal overhead, and fast start-up. However, the intrinsic shared kernel model of containers poses significant security threats, risking confidentiality and integrity from co-located containers or compromised OS. Researchers have proposed various methods to protect containers from untrusted OS, but few consider both the universality and efficiency. In this paper, we present ConMonitor---a lightweight and efficient container protection architecture. ConMonitor protects the security of container application data by introducing a compact virtualization software, called ConVisor, as a trusted computing base. ConVisor enforces isolation of the physical memory between containers and the kernel, and monitors the sensitive operations performed by the OS. To ensure the security of ConMonitor, we implement a Container Guardian to serve as an intermediary for the kernel, managing sensitive operations. Moreover, we also leverage the VMFUNC feature to achieve fast context switching, thereby mitigating the performance penalty associated with frequent context switching. We have implemented ConMonitor on Intel CPU with Virtualization Technology, and the evaluation results show that ConMonitor can protect the security of container applications with a negligible performance overhead. Shaowen Xu, Qihang Zhou, Xiaoqi Jia, Heqing Huang 0001, Haichao Du |
SoCC | 2 |
| 2024 | SEDSpec: Securing Emulated Devices by Enforcing Execution SpecificationabstractDevice emulation is a vital aspect of virtualization, yet remains vulnerable to security threats. Prior research has focused on monitoring I/O data flow or identifying internal device anomalies but often falls short in precision and automation. In this paper, we propose a novel method that leverages the normal operations of an emulated device to formulate an execution specification. The specification acts as a criterion to evaluate the device's behavior and state transitions. We implement SEDSpec, a prototype system that automatically generates the execution specification for an emulated device and devises three check strategies for identifying any deviations from this specification, thereby ensuring normal operations and enhancing the security of the emulated device. We evaluate SEDSpec with five different execution specifications. The results show that SEDSpec can detect anomalies caused by vulnerability exploitation while maintaining the devices' regular functioning with minimal performance overhead. Shengzhi Zhang, Xiaoqi Jia, Qihang Zhou, Heqing Huang 0001, Shaowen Xu, Haochao Du |
DSN | 4 |
| 2024 | MoEAD: A Parameter-Efficient Model for Multi-class Anomaly Detection
Shiyuan Meng, Wenchao Meng, Qihang Zhou, Shizhong Li, Weiye Hou, Shibo He |
ECCV (85) | 3 |
| 2024 | AnomalyCLIP: Object-agnostic Prompt Learning for Zero-shot Anomaly DetectionabstractZero-shot anomaly detection (ZSAD) requires detection models trained using auxiliary
data to detect anomalies without any training sample in a target dataset. It
is a crucial task when training data is not accessible due to various concerns, e.g.,
data privacy, yet it is challenging since the models need to generalize to anomalies
across different domains where the appearance of foreground objects, abnormal
regions, and background features, such as defects/tumors on different products/
organs, can vary significantly. Recently large pre-trained vision-language
models (VLMs), such as CLIP, have demonstrated strong zero-shot recognition
ability in various vision tasks, including anomaly detection. However, their ZSAD
performance is weak since the VLMs focus more on modeling the class semantics
of the foreground objects rather than the abnormality/normality in the images. In
this paper we introduce a novel approach, namely AnomalyCLIP, to adapt CLIP
for accurate ZSAD across different domains. The key insight of AnomalyCLIP
is to learn object-agnostic text prompts that capture generic normality and abnormality
in an image regardless of its foreground objects. This allows our model to
focus on the abnormal image regions rather than the object semantics, enabling
generalized normality and abnormality recognition on diverse types of objects.
Large-scale experiments on 17 real-world anomaly detection datasets show that
AnomalyCLIP achieves superior zero-shot performance of detecting and segmenting
anomalies in datasets of highly diverse class semantics from various defect
inspection and medical imaging domains. Code will be made available at https://github.com/zqhang/AnomalyCLIP. Qihang Zhou, Guansong Pang, Yu Tian 0001, Shibo He, Jiming Chen 0001 |
ICLR | 1 |
| 2024 | SummSlim: A Universal and Automated Approach for Debloating Container ImagesabstractContainer technology has become a cornerstone of cloud computing, offering notable benefits such as enhanced resource utilization and streamlined deployment processes. The adoption of container technology by leading cloud service providers has steadily increased over the years. However, during the image construction phase, the reuse of base images and the execution of certain commands often results in the retention of redundant files, leading to resource wastage and potential security vulnerabilities. In this research, we systematically review and analyze existing methodologies, identify shortcomings in current approaches, and propose an automated image debloating tool named SummSlim according to the characteristics of the container image construction process. We selected 195 official images from Docker Hub for testing and evaluated the effectiveness of SummSlim with a success rate of $98.46 \%$. Then we compare and analyze the images before and after debloating, and make some novel suggestions for developers. To the best of our knowledge, SummSlim is the first practically available universal image debloating tool. Heqing Huang 0001, Shaowen Xu, Qihang Zhou, Xiaoqi Jia, Weijuan Zhang |
ICPADS | 4 |
| 2024 | Large Language Model Guided Knowledge Distillation for Time Series Anomaly Detection
Chen Liu 0034, Shibo He, Qihang Zhou, Shizhong Li, Wenchao Meng |
IJCAI | 3 |
| 2024 | PointAD: Comprehending 3D Anomalies from Points and Pixels for Zero-shot 3D Anomaly DetectionabstractZero-shot (ZS) 3D anomaly detection is a crucial yet unexplored field that addresses scenarios where target 3D training samples are unavailable due to practical concerns like privacy protection. This paper introduces PointAD, a novel approach that transfers the strong generalization capabilities of CLIP for recognizing 3D anomalies on unseen objects. PointAD provides a unified framework to comprehend 3D anomalies from both points and pixels. In this framework, PointAD renders 3D anomalies into multiple 2D renderings and projects them back into 3D space. To capture the generic anomaly semantics into PointAD, we propose hybrid representation learning that optimizes the learnable text prompts from 3D and 2D through auxiliary point clouds. The collaboration optimization between point and pixel representations jointly facilitates our model to grasp underlying 3D anomaly patterns, contributing to detecting and segmenting anomalies of unseen diverse 3D objects. Through the alignment of 3D and 2D space, our model can directly integrate RGB information, further enhancing the understanding of 3D anomalies in a plug-and-play manner. Extensive experiments show the superiority of PointAD in ZS 3D anomaly detection across diverse unseen objects. Qihang Zhou, Jiangtao Yan, Shibo He, Wenchao Meng, Jiming Chen 0001 |
NeurIPS | 1 |
| 2024 | LightArmor: A Lightweight Trusted Operating System Isolation Approach for Mobile Systems
Qihang Zhou, Xiaoqi Jia, Jiayun Chen, Qingjia Huang, Haichao Du |
SEC | 2 |
| 2024 | SeChannel: A Secure and Lightweight Channel Protection Approach for TEE SystemsabstractTrusted Execution Environments (TEEs) are essential for securing sensitive data by isolating it from potentially vulnerable execution environments. In ARM-based devices, TEEs utilize TrustZone technology to create a secure world for Trusted Applications (TAs) and a normal world for Client Applications (CAs), ensuring strict isolation through hardware mechanisms. Despite this protection, current TEE systems lack robust mechanisms for securing TA access, leaving them vulnerable to attacks that exploit cross-world communication channels.This paper introduces SeChannel, a lightweight solution for securing communication channels in TrustZone-assisted TEEs. Unlike existing methods, SeChannel requires no additional hardware and avoids the performance penalties of encryption and memory copying. By leveraging existing ARM Trusted Firmware (ATF), SeChannel implements fine-grained access control to ensure that communication between CAs and TAs is authenticated and protected. It verifies shared memory addresses and TA sessions, preventing unauthorized access by the Rich OS. We implement a prototype of SeChannel on the Hikey960 development board with minimal code modifications to the existing system. Our evaluation demonstrates that SeChannel significantly enhances the security of TrustZone-assisted TEEs with negligible performance overhead. Yuanbo Zhao, Qihang Zhou, Xiaoqi Jia |
TrustCom | 3 |
| 2024 | HClave: An isolated execution environment design for hypervisor runtime security
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang, Haichao Du, Qingjia Huang |
Comput. Secur. | 1 |
| 2024 | Label-Free Multivariate Time Series Anomaly DetectionabstractAnomaly detection in multivariate time series has been widely studied in one-class classification (OCC) setting. The training samples in this setting are assumed to be normal. In more practical situations, it is difficult to guarantee that all samples are normal. Meanwhile, preparing a completely clean training dataset is costly and laborious. Such a case may degrade the performance of OCC-based anomaly detection methods which fit the training distribution as the normal distribution. To overcome this limitation, in this paper, we propose MTGFlow, an unsupervised anomaly detection approach for Multivariate Time series anomaly detection via dynamic Graph and entity-aware normalizing Flow. MTGFlow first estimates the density of the entire training samples and then identifies anomalous instances based on the density of the test samples within the fitted distribution. This relies on a widely accepted assumption that anomalous instances exhibit more sparse densities than normal ones, with no reliance on the clean training dataset. However, it is intractable to directly estimate the density due to the complex dependencies among entities and their diverse inherent characteristics, not to mention detecting anomalies based on the estimated distribution. In order to address these problems, we utilize the graph structure learning model to learn interdependent and evolving relations among entities, which effectively captures the complex and accurate distribution patterns of multivariate time series. In addition, our approach incorporates the unique characteristics of individual entities by employing an entity-aware normalizing flow. This enables us to represent each entity as a parameterized normal distribution. Furthermore, considering that some entities present similar characteristics, we propose a cluster strategy that capitalizes on the commonalities of entities with similar characteristics, resulting in more precise and detailed density estimation. We refer to this cluster-aware extension as MTGFlow_cluster. Extensive experiments are conducted on six widely used benchmark datasets, in which MTGFlow and MTGFlow_cluster demonstrate their superior detection performance. Qihang Zhou, Shibo He, Haoyu Liu 0002, Jiming Chen 0001, Wenchao Meng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | Detecting Multivariate Time Series Anomalies with Zero Known LabelabstractMultivariate time series anomaly detection has been extensively studied under the one-class classification setting, where a training dataset with all normal instances is required. However, preparing such a dataset is very laborious since each single data instance should be fully guaranteed to be normal. It is, therefore, desired to explore multivariate time series anomaly detection methods based on the dataset without any label knowledge. In this paper, we propose MTGFlow, an unsupervised anomaly detection approach forMultivariate Time series anomaly detection via dynamic Graph and entityaware normalizing Flow, leaning only on a widely accepted hypothesis that abnormal instances exhibit sparse densities than the normal. However, the complex interdependencies among entities and the diverse inherent characteristics of each entity pose significant challenges to density estimation, let alone to detect anomalies based on the estimated possibility distribution. To tackle these problems, we propose to learn the mutual and dynamic relations among entities via a graph structure learning model, which helps to model the accurate distribution of multivariate time series. Moreover, taking account of distinct characteristics of the individual entities, an entity-aware normalizing flow is developed to describe each entity into a parameterized normal distribution, thereby producing fine-grained density estimation. Incorporating these two strategies, MTGFlow achieves superior anomaly detection performance. Experiments on five public datasets with seven baselines are conducted, MTGFlow outperforms the SOTA methods by up to 5.0 AUROC%. Qihang Zhou, Jiming Chen 0001, Haoyu Liu 0002, Shibo He, Wenchao Meng |
AAAI | 1 |
| 2023 | Log2Policy: An Approach to Generate Fine-Grained Access Control Rules for Microservices from ScratchabstractMicroservice application architecture is one of the most widely used service architectures in the industry. To prevent a compromised microservice from abusing other microservices, authorization policy is applied to regulate the access among them. However, configuring access control policy manually is challenging due to the complexity and dynamic nature of microservice applications. In this paper, we present Log2Policy, a novel approach to generate microservice authorization policy based on access logs. Our approach consists of three fundamental techniques: (1) a log-based topological graph generation mechanism that automatically infers the invocation logic among microservices, (2) a machine learning based attributes mining method that extracts the relevant attributes of requests, and (3) a policy upgrade mechanism based on traffic management that can significantly reduce the upgrade time. We have implemented a prototype of Log2Policy on mainstream microservice infrastructures and have evaluated it with several microservice applications. The results show that Log2Policy can generate fine-grained and effective access control rules and upgrade them with negligible overhead. Shaowen Xu, Qihang Zhou, Heqing Huang 0001, Xiaoqi Jia, Haichao Du, Yamin Xie |
ACSAC | 2 |
| 2023 | Refining Use-After-Free Defense: Eliminating Dangling Pointers in Registers and MemoryabstractThe prevalence of use-after-free (UAF) vulnerabilities poses a significant threat to software security, with dangling pointers identified as the primary cause. However, existing de-fense methods suffer from bypass attacks, high runtime overhead, or only address memory dangling pointers while neglecting register-based ones that also contribute to UAF vulnerabilities. To overcome these shortcomings, we introduce a novel approach, ISDE, that eliminates both register and memory dangling point-ers with minimal additional runtime overhead. ISDE leverages an inter-procedural static pointer analysis method to statically collect object pointers during compilation, and uses the call graph and data flow graph to identify and eliminate potential dangling pointers. Our implementation of ISDE demonstrated its effectiveness in defending against real-world UAF vulnerabilities while maintaining efficiency in the SPEC CPU2006 evaluation. Xun An, Qihang Zhou, Haichao Du, Xiaoqi Jia |
APSEC | 2 |
| 2023 | Non-transferable blockchain-based identity authentication
Yuxia Fu, Jun Shao 0001, Qingjia Huang, Qihang Zhou, Huamin Feng, Xiaoqi Jia, Ruiyi Wang, Wenzhi Feng |
Peer Peer Netw. Appl. | 4 |
| 2023 | Pull & Push: Leveraging Differential Knowledge Distillation for Efficient Unsupervised Anomaly Detection and LocalizationabstractRecently, much attention has been paid to segmenting subtle unknown defect regions by knowledge distillation in an unsupervised setting. Most previous studies concentrated on guiding the student network to learn the same representations on the normality, neglecting the different behaviors of the abnormality. This leads to a high probability of false detection of subtle defects. To address such an issue, we propose to push representations on abnormal areas of the teacher and student network as far as possible while pulling representations on normal areas as close as possible. Based on this idea, we design an efficient teacher-student model for anomaly detection and localization, which maximizes pixel-wise discrepancies for anomalous regions approximated by data augmentation and simultaneously minimizes discrepancies for pixel-wise normal regions between these two networks. The explicit differential knowledge distillation enlarges the margin between normal representations and abnormal ones in favour of discriminating them. Then, the appropriate small student network is not only efficient, but more importantly, helps inhibit the generalization ability of anomalous patterns when learning normal patterns, facilitating the precise decision boundary. The experimental results on the MVTec AD, Fashion-MNIST, and CIFAR-10 datasets demonstrate that our proposed method achieves better performance than current state-of-the-art (SOTA) approaches. Especially, For the MVTec AD dataset with high resolution images, we achieve 98.1 AUROC% and 93.6 AUPRO% in anomaly localization, outperforming knowledge distillation based SOTA methods by 1.1 AUROC% and 1.5 AUPRO% with a lightweight model. Qihang Zhou, Shibo He, Haoyu Liu 0002, Tao Chen 0003, Jiming Chen 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2022 | Protecting Virtual Machines against Untrusted Hypervisor on ARM64 Cloud PlatformabstractIn cloud computing, the confidentiality and integrity of virtual machines (VMs) are facing severe threats because of the huge trusted computing base (TCB) software stack in virtualization layer. With the increasing momentum of ARM64 in cloud computing server markets, it is important to protect VMs from privileged software (including host operating system and hypervisor) on ARM64. In this paper, we have created SecureHyp, a new virtualization platform design for refactoring the existing hypervisor using the ARM64 hardware security mechanisms to reduce the TCB while protecting VMs against untrusted privileged software. Based on the principle of the least privilege, SecureHyp separates the sensitive-resource management from the rights of the hypervisor and prohibits the hypervisor from accessing specific sensitive resources. By deploying the memory isolation using ARM Trusted Firmware (ATF) and virtual Memory Management Unit (vMMU), SecureHyp ensures both the security and efficiency of the guest VMs. We have implemented SecureHyp on Linux firefly-4.4.194 with modest modification. The results show that SecureHyp can protect the confidentiality and integrity of virtual machines with only around 2000 lines of code software TCB and negligible performance overhead. Qihang Zhou, Xiaoqi Jia |
ICC | 1 |
| 2022 | AASPMP: Design and Implementation of Production Management Platform Based on AASabstractIntelligent transformation for traditional factories is a widely discussed topic. The key to this transformation is ensuring the integration between information technology and operational technology. However, it is a challenging task in industry owing to the communication heterogeneity of the underlying production equipment (horizontal communication), and inefficient interactions between the equipment and information decision center (vertical communication). In this paper, we explore asset administration shell (AAS), an asset virtualization technology, shielding heterogeneous physical communication protocol of production equipment. Besides, to promote inefficient communication between the equipment and information decision center, we adapt OPC UA protocol as the communication protocol of AAS for vertical communication. In addition, time-sensitive networking (TSN) is applied to ensure communication between the AAS and the corresponding physical device. Above operations ensure devices interconnection and interoperability. On this basis, we propose an AAS-based production management platform (AASPMP), which aims at the coverage from the demand side to the production side. Such an intelligent system characterizes three layers to decompose complicated system functionalities, and a visible client is provided for the convenience of remote operation and maintenance. We deploy our system on the actual production system and demonstrate the effectiveness of our design. Qihang Zhou, Chaojie Gu, Wenchao Meng, Shibo He, Zhiguo Shi 0001 |
INDIN | 1 |
| 2022 | SecFortress: Securing Hypervisor using Cross-layer IsolationabstractVirtualization is the corner stone of cloud computing, but the hypervisor, the crucial software component that enables virtualization, is known to suffer from various attacks. It is challenging to secure the hypervisor due to at least two reasons. On one hand, commercial hypervisors are usually integrated into a privileged Operating System (OS), which brings in a larger attack surface. On the other hand, multiple Virtual Machines (VM) share a single hypervisor, thus a malicious VM could leverage the hypervisor as a bridge to launch “cross-VM” attacks. In this work, we propose SecFortress, a dependable hypervisor design that decouples the virtualization layer into a mediator, an outerOS, and multiple HypBoxes through a cross-layer isolation approach. SecFortress extends the nested kernel approach to de-privilege the outerOS from accessing the mediator's memory and creates an isolated hypervisor instance, HypBox, to confine the impacts from the untrusted VMs. We implemented SecFortress based on KVM and evaluated its effectiveness and efficiency through case studies and performance evaluation. Experimental results show that SecFortress can significantly improve the security of the hypervisor with negligible runtime overhead. Qihang Zhou, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang |
IPDPS | 1 |
| 2021 | Deep Personalized Medical Recommendations Based on the Integration of Rating Features and Review Sentiment AnalysisabstractTo comply with the rapid development of big data in mobile services, an increasing number of websites have begun to provide users with recommendation decisions in various areas, like shopping, tourism, food, and medical treatment. However, there are still some challenges in the field of medical recommendation systems, such as the lack of personalized medical recommendations and the problem of data sparseness, which seriously restricts the effectiveness of such recommendations. In this paper, we propose a personalized medical recommendation method based on a convolutional neural network that integrates revised ratings and review text, called revised rating and review based on a convolutional neural network (RR&R‐CNN). First, the review text is divided into user and doctor datasets, and BERT vectorized representations are performed on them. Moreover, the original rating features are revised by adding the sentiment analysis values of the review text. Then, the vectorized review text and the revised rating features are spliced together and input into the convolutional neural network to extract the deep nonlinear feature vectors of both users and doctors. Finally, we use a factorization machine for feature interaction. We conduct comparison experiments based on a Yelp dataset in the “Health & Medical” category. The experimental results confirm the conclusion that RR&R‐CNN has a better effect compared to a traditional method. Qihang Zhou, Lei Su 0003, Liping Wu 0002 |
Wirel. Commun. Mob. Comput. | 1 |
| 2020 | Group Recommender Systems Based on Members' Preference for Trusted Social NetworksabstractWith the development of the Internet of Things (IoT), the group recommender system has also been extended to the field of IoT. The entities in the IoT are linked through social networks, which constitute massive amounts of data. In group activities such as group purchases and group tours, user groups often exhibit common interests and hobbies, and it is necessary to make recommendations for certain user groups. This idea constitutes the group recommender system. However, group members’ preferences are not fully considered in group recommendations, and how to use trusted social networks based on their preferences remains unclear. The focus of this paper is group recommendation based on an average strategy, where group members have preferential differences and use trusted social networks to correct for their preferences. Thus, the accuracy of the group recommender system in the IoT and big data environment is improved. Xiangshi Wang, Lei Su 0003, Qihang Zhou, Liping Wu 0002 |
Secur. Commun. Networks | 3 |