EDBT 2026 Demo / reviewers in the wild / expert
Ruijie Cai
dblp:337/0854
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2026
0000-0002-1659-0565ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | C2Detector: Interaction-enhanced semantic-aware detection method for C2 channels
Youqiang Luo, Ruijie Cai, Xiaokang Yin 0002, Jingman Zhou, Fangfang Zhao, Zhenjie Xie, Shengli Liu 0003 |
Comput. Networks | 2 |
| 2026 | FieldWeaver: A visual-language approach to binary protocol format inference
Qichao Yang, Fangfang Zhao, Xiaokang Yin 0002, Ruijie Cai, Shengli Liu 0003 |
Comput. Networks | 4 |
| 2026 | ADIPD: adaptive network flow watermarking via relative windowed inter-packet delay modulationabstractAbstract Advanced Persistent Threat (APT) attacks pose significant threats to critical infrastructure security due to their sophisticated techniques and prolonged nature. Effective network traceability and attack source identification are crucial for mitigating these threats. Time-based network flow watermarking has emerged as a promising approach for tracing APT attacks. However, existing time-based methods face limitations, including reliance on predefined temporal parameters that reduce adaptability to diverse traffic patterns, detectability due to absolute inter-packet delay (IPD) extensions, and sensitivity to network timing fluctuations that affect reliability. To address these challenges, we propose ADIPD, an adaptive watermarking scheme that leverages relative temporal relationships. Our core innovation lies in windowed IPD modulation, where traffic is divided into chronologically ordered windows, and watermarks are embedded by regulating the relative differences between average IPDs of strategically positioned sub-windows. Additionally, a delay minimization strategy compresses IPDs in sub-windows with lower average delays, enhancing both stealthiness and robustness. Experimental results demonstrate that ADIPD outperforms classical methods (WBIPD, IBW, ICBW) in robustness, invisibility, and practicality, achieving higher watermark extraction accuracy under temporal interference while requiring fewer packets and shorter embedding times. This work advances network flow watermarking technology by balancing robustness, stealth, and adaptability, offering a scalable solution for tracing sophisticated cyberattacks. Ruijie Cai, Xiaoya Zhu, Shengli Liu 0003 |
Cybersecur. | 1 |
| 2026 | Nonstandard Sinks Matter: A Comprehensive and Efficient Taint Analysis Framework for Vulnerability Detection in Embedded FirmwareabstractThe discovery of vulnerabilities in embedded firmware has received significant attention from security researchers. However, current vulnerability detection methods still suffer from false negatives and inefficiency, which limit detection effectiveness and require substantial analysis time. To alleviate the above problems, we propose a bidirectional path and data flow analysis method, named BPDA, that effectively compensates for the limitations in detecting firmware vulnerabilities at nonstandard sink points. Our key insight is that, some vulnerabilities arise in nonstandard library sinks, and not all user inputs can reach each corresponding sink. Guided by these insights, we design a more comprehensive sink identification algorithm and leverage accurate backward data flow tracking to eliminate the non-vulnerable paths. After that, we execute forward taint analysis and generate the final Proof of Concepts (PoCs). To evaluate the effectiveness of BPDA, we evaluated it on 84 firmware samples (including both Linux and VxWorks firmware) from 8 major brands, comparing it with state-of-the-art methods (i.e., SaTC and Mango). BPDA discovered 163 real vulnerabilities, including 34 0-day vulnerabilities, of which 32 have been confirmed by CVE/CNVD. Besides, results show that BPDA completed its analysis in just 6% of the time required by SaTC, and remarkably identified 21 vulnerabilities that SaTC and Mango had not detected. It also resolved the issue of Mango failing to analyze specific firmware. In addition, we also performed an ablation study to verify the effectiveness of optimization methods in taint analysis. These results demonstrate the superiority of BPDA in terms of effectiveness and efficiency in detecting embedded firmware vulnerabilities. Enzhou Song, Jinyuan Zhai, Ruijie Cai, Qichao Yang, Xiaokang Yin 0002, Shengli Liu 0003 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Precise Discovery of More Taint-Style Vulnerabilities in Embedded FirmwareabstractThe proliferation of taint-style vulnerabilities in embedded devices poses a significant threat to cybersecurity. However, discovering these vulnerabilities is challenging due to their vast number and variety. While current solutions for discovering vulnerabilities in embedded firmware have achieved some success, they suffer from imprecision, are time-consuming, and fail to consider sensitive sinks and constraints. To address these challenges, we propose a novel taint-style vulnerability discovery method called SinkTaint. SinkTaint incorporates backtracking and constraint analysis to achieve high precision and employs a global taint keyword identification strategy to identify implicit taint keywords. It identifies additional sinks using static analysis and performs backtracking analysis to eliminate sanitized sinks, while retrieving the parameter's length for risky sinks. Furthermore, SinkTaint employs dual-label labeling strategies for taint keywords and data, propagating taint labels based on function return values. Finally, SinkTaint employs symbolic execution-based taint analysis to discover taint-style vulnerabilities. We evaluate SinkTaint on datasets released by SaTC and 10 known overflow vulnerabilities. Compared to state-of-the-art methods, including Karonte, SaTC, and EmTaint, SinkTaint demonstrated superior performance, discovering more vulnerabilities with an increase in vulnerability discovery effectiveness by 472%. To date, SinkTaint has identified 21 high-risk taint-style vulnerabilities that were previously undisclosed. Xiaokang Yin 0002, Ruijie Cai, Xiaoya Zhu, Qichao Yang, Enzhou Song, Shengli Liu 0003 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Adaptive particle filter for state estimation with application to non-linear systemabstractAbstract Particle filtering (PF) has certain application value, but the disadvantage is that there is a phenomenon of particle degradation. In order to reduce the impact of this problem, this paper presents a new adaptive PF approach to improve the estimate accuracy. From the perspective of selecting an appropriate important density functions, in this filter, the particles are first updated using the Spherical Simplex Unscented Kalman Filter algorithm, and then the particles are updated using the Adaptive Extended Kalman filter algorithm. Simultaneously, from the perspective of improving the resampling method, a new resampling technique based on the random resampling method has been designed and fused to this filter. The comparison and analysis of two simulation schemes have been conducted to assess the performance of the designed filtering algorithm. The simulation results show the effectiveness of the proposed approach. Fangfang Zhao, Ruijie Cai |
IET Signal Process. | 2 |