EDBT 2026 Demo / reviewers in the wild / expert
Qige Song
dblp:315/4685
· DBLP profile ↗
9ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-3618-0416ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Digital Scapegoat: An Incentive Deception Model for Resisting Unknown APT Stealing Attacks on Critical Data ResourceabstractIt is a challenging problem to resist unknown advanced persistent threats (APTs) on stealing data resources in an information system of critical infrastructures, because APT attackers have very specific objectives and compromise the system stealthily and slowly. We observe that it is a necessary condition for APT attackers to achieve their campaigns via controlling unknown Trojans to access and exfiltrate critical files. We present a theoretical model called Digital Scapegoat (abbreviated as DS-IDep) that constructs an Incentive Deception defense schema to hijack the attacker’s access to critical files and redirect it to avatar files without awareness. We propose a FlipIDep Game model (GF) and a Markov Game model (GM) to characterize completely the payoffs, equilibria, and best strategies from the perspective of the attacker and the defender respectively. We also design an exponential risk propagation model to evaluate the ability of DS-IDep to eliminate stealing impact when the risk is propagated between states. Theoretically, we can achieve the objective of stealing impact elimination (LK0.7) and the probability of an attack operation bypassing the defense surface is less than 0.1 (r* × μ <0.1) under Stackelberg strategies. We develop a kernel-level incentive deception defense surface according to the theoretical parameters of the DS-IDep. The experimental results show that DS-IDep can resist APT stealing attacks from unknown Trojans. We also evaluate the DS-IDep in five well-known software applications. It demonstrates that DS-IDep can address unknown attacks from compromised software with less than 10% performance overhead. Xiao-chun Yun, Guangjun Wu, Qige Song, Zixian Tang, Zhenyu Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Let model keep evolving: Incremental learning for encrypted traffic classification
Xiang Li 0135, Jiang Xie 0004, Qige Song, Yafei Sang, Yongzheng Zhang 0002, Tianning Zang |
Comput. Secur. | 3 |
| 2024 | AC-DNN: An Adaptive Compact DNNs Architecture for Collaborative Learning Among Heterogeneous Smart DevicesabstractWith the rapid development of the Internet of Things (IoT), a massive number of smart devices are deployed in industry and critical infrastructures. Nowadays, IoT smart devices have drawn increasing attention for collaborative learning tasks, e.g., persistent monitoring and online recognition. In this article, we present an adaptive compact deep neural network (DNN) approach (termed as AC-DNN) to tackle the challenging problem of unreliable transmission for collaborative learning tasks among heterogeneous smart devices. We introduce a cross-platform model weight encoding, decoding, and dispatching architecture to accommodate to differential smart devices and improve the reliability of intermediate model transmission via encapsulating binary model weights into self-contained transactions. To decrease encoding and decoding overhead, we design a quantile-based histogram sketch to compress the intermediate model. We conduct extensive evaluations to test our AC-DNN framework and deploy the AC-DNN on federated learning testbed FedAvg. We evaluate our approach functionality using different DNN architectures, such as convolutional neural network and ResNet and compare their effectiveness within the different network structures. The experiments reveal that our approach can improve the reliability of collaborative learning tasks among smart devices. Meanwhile, we can achieve nearly 70% weight compression compared to the original model size with minimal loss of accuracy. Our approach facilitates the deployment of a DNN-like network among discrete mobile smart devices for deep and persistent learning tasks. Guangjun Wu, Fengxin Liu, Qige Song, Zixian Tang |
IEEE Internet Things J. | 4 |
| 2024 | SepBIN: Binary Feature Separation for Better Semantic Comparison and Authorship VerificationabstractBinary semantic comparison and authorship verification are critical in many security applications. They respectively focus on the functional semantic features and developers’ programming style features of binary code, which are usually mixed without clear demarcation. Recently, researchers have proposed learning-based approaches for intelligent binary analysis. They generally addressed single tasks with hand-crafted feature sets or neural binary encoders, which suffer performance bottlenecks due to the noise in mixed features. This paper proposesSepBIN, a novel neural network framework that exploits the intrinsic correlation of binary semantic comparison and authorship verification tasks and automatically separates semantic and stylistic binary features. We first construct a strong backbone binary encoder, then utilize preliminary decomposition subnets and the flexible gating-based feature fusion mechanism to distill pure semantic-related and style-related binary representations, and further improve their quality by a feature reconstruction module. The overallSepBINmodel is optimized by a multi-objective joint optimization strategy. We conduct extensive experiments on Google Code Jam (GCJ) datasets in different languages and scales. Results show thatSepBINsimultaneously benefits binary semantic comparison and authorship verification tasks through the effective binary semantic-style feature separation mechanism, and provides multi-perspectives interpretability for the performance gains. For state-of-the-art approaches with different binary encoders,SepBINcan adaptively improve them with the designed separation modules. Furthermore, we adopt a pretraining-finetuning strategy to effectively transferSepBIN’s separation capability in real-world applications, including APT malware homology detection and binary semantic comparison against code obfuscations. Qige Song, Yafei Sang, Yongzheng Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Listen to Minority: Encrypted Traffic Classification for Class Imbalance with Contrastive Pre-TrainingabstractMobile Internet has profoundly reshaped modern lifestyles in various aspects. Encrypted Traffic Classification (ETC) naturally plays a crucial role in managing mobile Internet, especially with the explosive growth of mobile apps using encrypted communication. Despite some existing learning-based ETC methods showing promising results, three-fold limitations still remain in real-world network environments, i) label bias caused by traffic class imbalance, ii) traffic homogeneity caused by component sharing, and iii) training with reliance on sufficient labeled traffic. None of the existing ETC methods can address all these limitations. In this paper, we propose a novel Pre-trAining Semi-Supervised ETC framework, dubbed PASS. Our key insight is to resample the original train dataset and perform contrastive pre-training without using individual app labels directly to avoid label bias issues caused by class imbalance, while obtaining a robust feature representation to differentiate overlapping homogeneous traffic by pulling positive traffic pairs closer and pushing negative pairs away. Meanwhile, PASS designs a semi-supervised optimization strategy based on pseudo-label iteration and dynamic loss weighting algorithms in order to effectively utilize massive unlabeled traffic data and alleviate manual train dataset annotation workload. PASS outperforms state-of-the-art ETC methods and generic sampling approaches on four public datasets with significant class imbalance and traffic homogeneity, remarkably pushing the F1 of Cross-Platform215 with 1.31%$\uparrow$, ISCX-17 with 9.12%$\uparrow$. Furthermore, we validate the generality of the contrastive pre-training and pseudo-label iteration components of PASS, which can adaptively benefit ETC methods with diverse feature extractors. Xiang Li 0135, Juncheng Guo, Qige Song, Jiang Xie 0004, Yafei Sang, Yongzheng Zhang 0002 |
SECON | 3 |
| 2022 | Multi-relational Instruction Association Graph for Cross-Architecture Binary Similarity Comparison
Qige Song, Yongzheng Zhang 0002 |
SecureComm | 1 |
| 2022 | BinMLM: Binary Authorship Verification with Flow-aware Mixture-of-Shared Language ModelabstractBinary authorship analysis is a significant problem in many software engineering applications. In this paper, we formulate a binary authorship verification task to accurately reflect the real-world working process of software forensic experts. It aims to determine whether an anonymous binary is developed by a specific programmer with a small set of support samples, and the actual developer may not belong to the known candidate set but from the wild. We propose an effective binary authorship verification framework, BinMLM. BinMLM trains the RNN language model on consecutive opcode traces extracted from the control-flow-graph (CFG) to characterize the candidate developers' programming styles. We build a mixture-of-shared architecture with multiple shared encoders and author-specific gate layers, which can learn the developers' combination preferences of universal programming patterns and alleviate the problem of low training resources. Through an optimization pipeline of external pre-training, joint training, and fine-tuning, our framework can eliminate additional noise and accurately distill developers' unique styles. Extensive experiments show that BinMLM achieves promising results on Google Code Jam (GCJ) and Codeforces datasets with different numbers of programmers and supporting samples. It significantly outperforms the baselines built on the state-of-the-art feature set (4.73% to 19.46% improvement) and remains robust in multi-author collaboration scenarios. Furthermore, Bin-MLM can perform organization-level verification on a real-world APT malware dataset, which can provide valuable auxiliary information for exploring the group behind the APT attack. Qige Song, Yongzheng Zhang 0002, Linshu Ouyang |
SANER | 1 |
| 2022 | Inter-BIN: Interaction-Based Cross-Architecture IoT Binary Similarity ComparisonabstractThe big wave of Internet of Things (IoT) malware reflects the fragility of the current IoT ecosystem. Research has found that IoT malware can spread quickly on devices of different processer architectures, which leads our attention to cross-architecture binary similarity comparison technology. The goal of binary similarity comparison is to determine whether the semantics of two binary snippets is similar. Existing learning-based approaches usually learn the representations of binary code snippets individually and perform similarity matching based on the distance metric, without considering interbinary semantic interactions. Moreover, they often rely on the large-scale external code corpus for instruction embeddings pretraining, which is heavyweight and easy to suffer the out-of-vocabulary (OOV) problem. In this article, we propose an interaction-based cross-architecture IoT binary similarity comparison system,Inter-BIN. Our key insight is to introduce interaction between instruction sequences by co-attention mechanism, which can flexibly perform soft alignment of semantically related instructions from different architectures. And we design a lightweight multifeature fusion-based instruction embedding method, which can avoid the heavy workload and the OOV problem of previous approaches. Extensive experiments show thatInter-BINcan significantly outperform state-of-the-art approaches on cross-architecture binary similarity comparison tasks of different input granularities. Furthermore, we present an IoT malware function matching data set from real network environments, CrossMal, containing 1878437 cross-architecture reuse function pairs. Experimental results on CrossMal prove thatInter-BINis practical and scalable on real-world binary similarity comparison collections. Qige Song, Yongzheng Zhang 0002, Binglai Wang |
IEEE Internet Things J. | 1 |
| 2021 | DroidRadar: Android Malware Detection Based on Global Sensitive Graph EmbeddingabstractAndroid application markets face severe threats of malware attacks. Existing learning-based malware detection approaches rely on easily obfuscated features or unscalable sophisticated graph analysis techniques. In this paper, we propose DroidRadar, an accurate Android malware detection system based on lightweight graph embedding. The key insight of our method is constructing an entire Android application collection as a global graph schema and using sensitive APIs as bridge nodes to propagate inter-application information. We conduct statistical correlation analysis from different perspectives to model the application's usage pattern of sensitive APIs, then apply graph convolution network (GCN) to perform node embedding and malware detection. We evaluate DroidRadar on large scale datasets spanning nine years. Results show that DroidRadar has an average detection accuracy of 98.57% and a false-positive rate of 1.4 % on different time periods, which outperforms the state-of-the-art approaches, and it has strong robustness when detecting obfuscated malware variants. Qige Song, Yongzheng Zhang 0002, Junliang Yao |
TrustCom | 1 |