EDBT 2026 Demo / reviewers in the wild / expert
Yinhao Qi
dblp:338/0841
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-2827-0243ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Sysalign: protect system calls via semantic alignment of critical paths and syscall sequencesabstractAbstract System call security is crucial for host-based intrusion detection, as security-sensitive system calls (e.g., execve, mprotect) play a vital role in completing attacks. However, existing defense methods face significant limitations. Static analysis and system call filtering cannot prevent the malicious use of necessary syscalls, while runtime methods based on control-flow, syscall sequences, or parameter integrity are vulnerable to sophisticated attacks, such as data-only attacks, that mimic benign execution patterns. In this paper, we propose a novel contrastive learning framework, SysAlign, for system call security that ensures the semantic consistency between a system call’s macro-level and micro-level intents. SysAlign learns the macro-level intent by the sequence of system calls, which reflects the broader objective of a program phase. The micro-level intent is derived from the specific execution path, capturing the detailed execution context of system calls. Malicious system calls disrupt this consistency, leading to a detectable misalignment between the two intents. To minimize the overhead, we efficiently represent micro-level intent using critical points instead of tracking full execution paths. These points are extracted via dominator tree analysis on the program’s over-approximated control-flow graph, effectively balancing rich semantics with performance. Additionally, to address the scarcity of attack data, our framework incorporates a tailored negative sampling strategy, enhancing the model’s robustness. We evaluated SysAlign on real-world applications, including Nginx, NullHttpd, cURL, and SQLite3. The results demonstrate that our method effectively detects a diverse range of malicious system call behaviors, including those resulting from control-flow hijacking and data-only exploits. Our approach achieves an F1-score exceeding 96% with a performance overhead below 7%. This work presents a practical and effective advancement in system call security, significantly outperforming existing techniques. Yinhao Qi, Xinghu Han, Bo Jiang 0013, Zhigang Lu 0002 |
Cybersecur. | 1 |
| 2026 | CMD-EPD: A Graph Contrastive Learning Framework with Multi-Dimensional Fusion for Ethereum Phishing DetectionabstractThe burgeoning prevalence of Ethereum phishing behavior has iCSUR-2025-0155mposed substantial constraints on the advancement of blockchain finance, resulting in losses of more than $7.7 billion to date, so it is urgent to detect it in time. Currently, available detection methods usually focus on the spatial features within transaction graphs. These methods often employ shallow mining techniques on small samples. As a result, they may overlook certain aspects of interaction patterns, such as temporal behavior. Additionally, their data mining capability is limited due to the small sample sizes. In this study, we propose a graph contrastive learning framework to enrich features of accounts behavior patterns with restricted samples to overcome these limitations. Firstly, we construct an Ethereum interaction graph with the multi-graph involving more temporal information centered with labeled nodes and lighten it with our strategy. Secondly, to comprehensively characterize the accounts pattern, we design the encoder part with the GAT-LSTM model based on attention mechanism fusing statistical features , fine-grained temporal behavioral features and graph structural semantic features . Thirdly, to moderate the sparsity of phishing nodes, we employ data augmentation and contrastive learning to fully mine sparse node information. Moreover, we carried out an in-depth experimental evaluation. The CMD-EPD approach, boasting an F 1 -score of 0.87, outperformed all comparison methods. We also executed a thorough case study to analyze phishing accounts phenomenological indicators which back up the superiority of our framework. Chuyi Yan, Yinhao Qi, Xueying Han, Dan Du, Zhigang Lu 0002, Meng Shen 0001 |
ACM Trans. Priv. Secur. | 2 |
| 2025 | SiamEHGT: An Evolving Heterogeneous Graph Transformer for Insider Threat Detection based on Siamese ArchitectureabstractInsider threats have been a focal point in cyberse-curity, leading to severe data leakage and organization system crashes. Due to the low proportion of malicious samples, most methods establish the baseline of normal user behaviors and identify users deviating from this baseline as malicious insiders. However, these methods fail to capture the heterogeneity and temporal evolution of user behavior patterns effectively. This paper proposes an evolving heterogeneous graph transformer based on Siamese architecture (SiamEHGT) to detect malicious insiders. Firstly, SiamEHGT constructs behavior heterogeneous graph sequences for users based on a fixed-size time window. Secondly, SiamEHGT employs the proposed EHGT to explore the heterogeneity of user behaviors on these graphs, while continuously evolving model parameters to mine the dynamism of user behaviors over time. Finally, Siamese architecture is applied at the graph level to learn the similarity of user behavior patterns across any two time windows, effectively using the limited labeled malicious samples. We evaluate our method on CERT and LANL datasets, and the results demonstrate that our approach outperforms many state-of-the-art methods. Yinhao Qi, Zhigang Lu 0002 |
CSCWD | 1 |
| 2025 | MPKAN: APT Attack Detection on Audit Logs via Graph Semantic EnhancementabstractAs cloud computing and mobile work blur traditional network boundaries, security measures like static firewalls and signature-based systems are becoming inadequate. Audit logs contain fine-grained OS-level information, but due to their vast volume and the complex relationships between entities, processing and analyzing them remains a significant challenge. In this paper, we introduce MPKAN, a new method for detecting APT attacks, which enhances the information input of nodes and edges, integrates node-level and edge-level information, and improves graph-level semantics. It uses meta-path random walks to enhance semantic connections between nodes, merges multiple edges in the provenance graph into a single edge while retaining the original edge information and operation sequence relationships, and by associating heterogeneous graph neighbors, utilizing the message passing mechanism to iteratively update states based on neighbor node information, and using a knowledge association network to integrate node-level and edge-level information, we can effectively capture local and global structural information in the graph. MPKAN's evaluations on the ATLAS and Darpa datasets demonstrate its excellent performance in complex attack scenarios, achieving an average accuracy of 0.9899 and an F1 score of 0.9853, confirming its effectiveness and efficiency. Dan Du, Yinhao Qi, Bo Jiang 0013, Zhigang Lu 0002 |
CSCWD | 3 |
| 2025 | Autumn: An Unsupervised APT Detection via Detailed Process-Level AnalysisabstractAdvanced Persistent Threats (APTs) are exceptionally challenging to detect due to their high stealthiness. Audit logs, which provide detailed process-level information and record all activities before and after an APT attack, are crucial for detecting such threats. However, the sheer volume of data in audit logs also poses a significant challenge. Current methods suffer from the following issues: 1) difficulty in extracting information from the complex contextual relationships within audit logs, 2) reliance on prior knowledge for detecting APT attacks, and 3) coarse-grained detection signals. In this paper, we introduce Autumn, an APT detection method focused on processes as the primary research object. Autumn is an unsupervised learning model that does not rely on prior knowledge, making it more suitable for real-world APT detection scenarios. Autumn can swiftly identify critical information from vast audit logs and provides fine-grained detection signals by focusing on processes. We begin by constructing a graph from audit logs, segmenting it into subgraphs based on time, and applying strategies to reduce data volume. We then learn the characteristics of processes. By converting process information into input vectors using word2vec and calculating the reconstruction error for each subgraph through the encoding and decoding process of a transformer autoencoder, we train the model by associating the processes' IDF scores. Finally, we train the model on benign data and test it on a separate set of subgraphs containing attack events. Compared to other unsupervised learning methods, Autumn shows significant improvement in detection performance. Yunxiang Wang, Yinhao Qi, Bo Jiang 0013, Zhigang Lu 0002 |
CSCWD | 4 |
| 2025 | ATHITD: Attention-based temporal heterogeneous graph neural network for insider threat detection
Yinhao Qi, Chuyi Yan, Zhigang Lu 0002, Bo Jiang 0013 |
Comput. Secur. | 1 |
| 2025 | PathWatcher: A path-based behavior detection method for attack detection and investigationabstractAdvanced Persistent Threats (APTs) comprise complex and stealthy attack techniques. Due to the characteristics of system audit logs in capturing system-level process calls and providing granular log data, using audit logs for causal analysis of advanced threat behaviors has become a popular solution. However, existing solutions still suffer from several deficiencies: (1) semantic gaps between raw data in low-level views and high-level system behaviors, (2) fatigue alert, and (3) poor interpretability and inferability. In this paper, we propose PathWatcher, a path-based behavior detection method, which enables attack investigation based on detection results. PathWatcher enhances low-level semantics by combining operation sequences, extracting paths as behavioral entities from the provenance graph, and learning path features. This approach reduces the semantic gap between low-level data and high-level system behaviors. PathWatcher first performs graph construction and path extraction in the graph construction module, followed by feature learning of nodes and paths in the behavioral sequence extraction module, the data generated during the process exists in the path record with a certain rule, and finally the data from the path record is used for feature extraction and path tracing in the behavior identification and attack clues module, the data from the path record is used for feature extraction and path tracing. This model exhibits strong inferability and interpretability by matching paths to operational behaviors in logs. This allows security researchers to combine path records and investigate attacks directly using high-level semantics, thereby alleviating alert fatigue. Our experimental results demonstrate that PathWatcher effectively improves the detection accuracy of malicious behaviors while enhancing semantic interpretability. The detection results are inferable, achieving accuracies of 99.76% and 99.07% on two datasets, and we provide an analysis of attack investigations. Yinhao Qi, Wei Qiao 0005, Bo Jiang 0013, Zhigang Lu 0002 |
Comput. Secur. | 3 |
| 2023 | HANDOM: Heterogeneous Attention Network Model for Malicious Domain Detection
Qing Wang 0041, Cong Dong, Shijie Jian, Dan Du, Zhigang Lu 0002, Yinhao Qi, Dongxu Han, Xiaobo Ma 0001, Fei Wang 0014 |
Comput. Secur. | 6 |
| 2023 | Aparecium: understanding and detecting scam behaviors on Ethereum via biased random walkabstractAbstract Ethereum’s high attention, rich business, certain anonymity, and untraceability have attracted a group of attackers. Cybercrime on it has become increasingly rampant, among which scam behavior is convenient, cryptic, antagonistic and resulting in large economic losses. So we consider the scam behavior on Ethereum and investigate it at the node interaction level. Based on the life cycle and risk identification points we found, we propose an automatic detection model named Aparecium. First, a graph generation method which focus on the scam life cycle is adopted to mitigate the sparsity of the scam behaviors. Second, the life cycle patterns are delicate modeled because of the crypticity and antagonism of Ethereum scam behaviors. Conducting experiments in the wild Ethereum datasets, we prove Aparecium is effective which the precision, recall and F1-score achieve at 0.977, 0.957 and 0.967 respectively. Chuyi Yan, Meng Shen 0001, Yinhao Qi, Zhigang Lu 0002 |
Cybersecur. | 6 |