EDBT 2026 Demo / reviewers in the wild / expert
Tianheng Qu
dblp:410/3874
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › vulnerability discovery › fuzzing
protocol fuzzing |
1.0 | 1 | 2026 | Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing · INFOCOM 2026 |
Software testing
fuzzing |
0.3 | 1 | 2026 | Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing · INFOCOM 2026 |
Software testing
test input generation |
0.3 | 1 | 2026 | Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing · INFOCOM 2026 |
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing
Weicheng Lin, Laile Xi, Yaowen Zheng, Shenghao Lin, Jiaxing Cheng, Zhen Wang 0043, Shizhao Tian, Tianheng Qu, Hongsong Zhu |
INFOCOM | 9 |
| 2026 | A novel zero-day ransomware detection approach based on CVAE and 1D-CNNabstractRansomware has emerged as one of the most prevalent and destructive cyber attacks confronting global organizations. By locking critical devices or encrypting essential data and then demanding payment for restoration, ransomware attacks disrupt operations, result in significant financial losses, and damage organizational reputations. In particular, zero-day ransomware attacks, which attempt to exploit previously unknown vulnerabilities, pose a severe threat to existing cyber security solutions. Due to the lack of training data, detection of zero-day ransomware attacks remains a significant challenge. This paper proposes a novel zero-day ransomware detection framework that integrates a refined Conditional Variational Autoencoder (CVAE) with a 1D Convolutional Neural Network (1D-CNN). The encoder of the CVAE model comprises a posterior network and a parallel prior network. Using variational coding, the posterior network maps behavioral features of software samples from known families into a latent space, represented by a fixed multivariate Gaussian distribution with a diagonal covariance matrix. Simultaneously, the prior network eliminates dependency on class labels while maintaining distributional consistency with the posterior network via Kullback–Leibler (KL) divergence minimization. This dual-network structure enables unified latent space mapping for both labeled and unlabeled samples, effectively narrowing distributional discrepancies between software samples from known and unknown families. The harmonized latent representations subsequently enhance the discriminative capability of the 1D-CNN classifier in detecting zero-day ransomware. The comprehensive experimental results have verified that the proposed method can effectively detect zero-day ransomware attacks. Bohan Cui, Tianheng Qu, Yunhua He |
High Confid. Comput. | 3 |
| 2025 | Research on TTP Data Augmentation Methods Based on the ATT&CK FrameworkabstractAs cyber threats escalate, rapid identification and response to attacks are increasingly vital. Cyber Threat Intelli-gence (CTI) is crucial for understanding the threat landscape, and standardized attack frameworks are essential for effective anal-ysis. The MITRE ATT &CK framework has gained widespread adoption for its systematic description of Tactics, Techniques, and Procedures (TTP), aiding security teams in tracking at-tack patterns. However, manual classification of TTP is time-consuming and costly, hindering response efficiency. Although artificial intelligence has advanced automated TTP classification, accuracy still needs improvement due to the scarcity of labeled data, resulting in small and imbalanced datasets. This study introduces a novel TTP data augmentation method to enhance classification accuracy through synthetic data gen-eration. We construct a dataset of 19,716 sentences from the ATT&CK knowledge base and real-world threat reports, Ini-tially, we leverage large language models (LLMs) combined with prompt techniques to generate high-quality synthetic data, followed by semantic filtering and dynamic sampling strategies to further enhance data quality and improve class balance. Experimental results show an average$\mathbf{F}_{1}$score increase of 16.95 % across various classification models, significantly enhancing TTP classification performance. Xiaodong Xue, Jie Zhang 0121, Tianheng Qu, Rongrong Xi, Hongsong Zhu |
CSCWD | 4 |
| 2025 | Demystifying Feature Engineering in Malware Analysis of API Call SequencesabstractMachine learning (ML) has been widely used to analyze API call sequences in malware analysis, which typically requires the expertise of domain specialists to extract relevant features from raw data. The extracted features play a critical role in malware analysis. Traditional feature extraction is based on human domain knowledge, while there is a trend of using natural language processing (NLP) for automatic feature extraction. This raises a question: how do we effectively select features for malware analysis based on API call sequences? To answer it, this paper presents a comprehensive study of investigating the impact of feature engineering upon malware classification. We first conducted a comparative performance evaluation under three models, Convolutional Neural Network (CNN), Long Short-Term Memory (LSTM), and Transformer, with respect to knowledgebased and NLP-based feature engineering methods. We observed that models with knowledge-based feature engineering inputs generally outperform those using NLP-based across all metrics, especially under smaller sample sizes. Then we analyzed a complete set of data features from API call sequences, our analysis reveals that models often focus on features such as handles and virtual addresses, which vary across executions and are difficult for human analysts to interpret. Tianheng Qu, Hongsong Zhu, Limin Sun 0001, Haining Wang 0001, Haiqiang Fei, Zhi Li 0018 |
RAID | 1 |