Qijie Song

dblp:309/6303 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
13since 2021 · last 2026
0000-0001-6137-0767ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PG-MoE: Provenance-Based Intrusion Detection via Graph Mixture-of-Experts and Spatio-Temporal Contrastive Learning
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Qijie Song, Tieming Chen
DASFAA (5)4
2026 APT-CGLP: Advanced Persistent Threat Hunting via Contrastive Graph-Language Pre-Training
abstract
Provenance-based threat hunting identifies Advanced Persistent Threats (APTs) on endpoints by correlating attack patterns described in Cyber Threat Intelligence (CTI) with provenance graphs derived from system audit logs. A fundamental challenge in this paradigm lies in the modality gap —the structural and semantic disconnect between provenance graphs and CTI reports. Prior work addresses this by framing threat hunting as a graph matching task: 1) extracting attack graphs from CTI reports, and 2) aligning them with provenance graphs. However, this pipeline incurs severe information loss during graph extraction and demands intensive manual curation, undermining scalability and effectiveness.
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Tieming Chen, Tiantian Zhu 0001, Qijie Song, Shouling Ji
KDD (1)6
2026 UniProv: A unified pretraining framework for provenance graph representation learning
Xuebo Qiu, Mingqi Lv, Yimei Zhang 0003, Qijie Song, Tiantian Zhu 0001, Tieming Chen
Neurocomputing4
2026 Provenance-based advanced persistent threat detection via holistic contrastive learning with heuristic augmentation
Xuebo Qiu, Mingqi Lv, Tiantian Zhu 0001, Qijie Song, Tieming Chen
J. Inf. Secur. Appl.4
2026 Zoomer: An APT TTP Recognition System via Deep & Wide Provenance Graph Learning
abstract
Advanced Persistent Threats (APTs) commonly manifest through a sequence of attack steps, known as Tactics, Techniques, and Procedures (TTPs). Recent studies identify TTPs by converting audit logs into causal provenance graphs and applying expert-driven mappings that correlate low-level system events with high-level TTP patterns. However, these methods face persistent challenges: determining the impact boundaries of TTP activities, adapting to evolving TTP stacks, and recognizing fine-grained TTP semantics for deeper forensic insights. To address these challenges, we presentZoomer, a novel TTP recognition framework that segments provenance graphs into multiple TTP subgraphs with multi-granular annotations (i.e., tactics, techniques, and sub-techniques). First, we devise a heuristic subgraph sampling algorithm guided by anomalous node detection to precisely delineate the scope of TTP activities. Second, we introduce a dual-tower Deep & Wide architecture that integrates contextual behavior semantics from provenance graphs and domain-informed features to learn expressive TTP representations. Finally, we adopt a prototypical network that reformulates TTP recognition as a few-shot pattern matching task, thereby enhancing adaptability and accuracy under limited supervision. To advance future research, we built and released the first TTP-annotated provenance dataset, encompassing the most comprehensive collection of TTP instances to date. Extensive experiments show thatZoomerachieves TTP recognition with 88% accuracy at the sub-technique level and 94% at the tactic level, significantly outperforming state-of-the-art baselines.
Xuebo Qiu, Mingqi Lv, Tieming Chen, Tiantian Zhu 0001, Qijie Song, Zhiling Zhu
IEEE Trans. Dependable Secur. Comput.5
2025 Provenance-Based Intrusion Detection via Multi-scale Graph Representation Learning
Xuebo Qiu, Mingqi Lv, Tieming Chen, Tiantian Zhu 0001, Qijie Song
ICICS (2)5
2025 DockInsight: A Knowledge-Augmented Dependency Extraction Approach for Dockerfile
abstract
DevOps enhances software production through IT automation, continuous integration, and deployment, with Docker as a key tool that packages applications and their environments into standardized images for consistent and efficient deployment. Dockerfiles, which are text-based configuration files, define the composition and runtime actions of these images. Mismanagement of dependencies between Dockerfile instructions can cause build failures, highlighting the need for accurate dependency parsing. Current methods often miss implicit dependencies due to the complex syntax and logic of Dockerfile instructions. To address this, we propose DockInsight, a novel tool that uses a rule-based approach and semantic analysis to determine Dockerfile dependencies accurately. DockInsight features a unified feature structure representation, DVector, and a dependency type table to facilitate precise dependency determination. Evaluations demonstrate that DockInsight achieves 99.44% accuracy, significantly outperforming keyword matching and large language model methods by 64.84% and 55.74%, respectively. Additionally, DockInsight maintains stable processing times across various Dockerfile lengths, proving its efficiency and scalability. Our ablation study further highlights the importance of semantic information supplementation, particularly for RUN instructions, in enhancing accuracy. DockInsight’s robust performance makes it a valuable tool for developers and DevOps engineers, contributing to more reliable and maintainable Dockerfiles.
Zhiling Zhu, Tieming Chen, Yunjin Zhong, Qijie Song
ICSR4
2025 Kellect: A Kernel-based efficient and lossless event log collector for windows security
Tieming Chen, Qijie Song, Tiantian Zhu 0001, Xuebo Qiu, Zhiling Zhu, Mingqi Lv
Comput. Secur.2
2025 VulnTrace: Tracking and Detecting Code Vulnerabilities with Historical Commits and Semantic Embeddings
abstract
Open source software has evolved into a fundamental element of the contemporary information sector; however, security threats within its supply chain are persistently rising. Within the collaborative development framework of open source, the introduction of malicious code can lead to significant security vulnerabilities. Conventional methods for detecting these vulnerabilities, which rely on machine learning, face challenges such as a lack of sufficient datasets, inadequate deep semantic understanding, and limitations to single-vulnerability detection. To address these challenges, we introduce a novel approach named VulnTrace, which analyzes historical records of submissions in open source projects to construct a high-quality dataset of vulnerabilities with accurate labels. VulnTrace employs Word2Vec alongside Abstract Syntax Tree (AST) technologies to capture both the semantic and structural details of code segments and utilizes a Transformer model for precise vulnerability identification, thereby enhancing accuracy and interpretability in detection. Experimental results indicate that VulnTrace achieves approximately 93% accuracy, 95% precision, 83% recall and an F1 score of 88% in vulnerability detection tasks, significantly reducing false positives and demonstrating remarkable robustness.
Qijie Song, Jiaobo Jin, Tiantian Zhu 0001, Tieming Chen, Mingqi Lv, Licheng Pan, Jian-Ping Mei
Int. J. Softw. Eng. Knowl. Eng.1
2024 ThreatResponder: Dynamic Markov-Based Defense Mechanism for Real-Time Cyber Threats
Zhiling Zhu, Tieming Chen, Qijie Song, Yiheng Lu, Yulin Zheng
ICDF2C (2)3
2024 DocSecKG: A Systematic Approach for Building Knowledge Graph to Understand the Relationship Between Docker Image and Vulnerability
Zhiling Zhu, Tieming Chen, Haobin Kong, Yunjin Zhong, Qijie Song
ICIC (13)5
2024 CoreCast: Leveraging Project Metrics to Predict Core Contributor Trends in Open Source C57
abstract
The collaborative model of open-source software (OSS) development significantly enhances efficiency and fosters innovation by enabling diverse global contributors to collaborate seamlessly.Core contributors, who provide the majority of code commits, are crucial for maintaining project direction, quality, and momentum.Despite their importance, there is limited research on the dynamics and prediction of changes in core contributors over time, which is essential for sustaining project growth and stability.To bridge this gap, we introduce CoreCast, an innovative predictive model designed to forecast future core contributor numbers using comprehensive project data.By analyzing multidimensional metrics from high-quality OSS projects, CoreCast trains models that outperform traditional methods, achieving a mean absolute error (MAE) of 0.7866.Our findings reveal seven significant growth trends that are crucial for understanding and sustaining OSS project development.All data and scripts are open-sourced, providing valuable resources for future research and further advancements in the field.
Zhiling Zhu, Tieming Chen, Lizi Wu, Qijie Song
SEKE4
2022 EspialCog: General, Efficient and Robust Mobile User Implicit Authentication in Noisy Environment
abstract
Mobile authentication is a fundamental factor in the protection of user’s private resources. In recent years, motion sensor-based biometric authentication has been widely used for privacy-preserving. However, it faces with the problems including low data collection efficiency, insufficient authentication scenario coverage rate, weak de-noising ability, and poor robustness of models, rendering existing methods difficult to meet the security, privacy, and usability requirements jointly in the real-world scenario. To overcome these difficulties, we propose a system calledEspialCog, which is able to 1) collect the sensor data embedded in mobile devices self-adaptively, unobtrusively and efficiently through the evolutionary stable participation game mechanism (ESPGM) with a high scenario coverage rate; 2) minimize noise from collected data by analyzing three types of abnormalities; and 3) authenticate the ownership of mobile devices in real-time by adopting optimized LSTM model with an enhanced stochastic gradient descent (SGD) algorithm. The simulation experiment on 6000 users shows that the efficiency and coverage rates increase dramatically by deploying our ESPGM. Moreover, we conduct experiments on a large-scale real-world noisy dataset with 1513 users and two other small pure real-world datasets. The experimental results show the high accuracy and favorable robustness ofEspialCogin the noisy environment.
Tiantian Zhu 0001, Zhengqiu Weng, Qijie Song, Qiang Liu 0034, Yan Chen 0004, Mingqi Lv, Tieming Chen
IEEE Trans. Mob. Comput.3