EDBT 2026 Demo / reviewers in the wild / expert
Jianming Fu
dblp:44/2489
· DBLP profile ↗
48ranked-venue papers
7as first author
27since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 6 first-author · 14 since 2021Computer networks · 6 · 5 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-authorSystems, architecture and hardware · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accelerating App Recompilation across Android System Updates by Code ReusingabstractAndroid utilizes Ahead-of-Time (AOT) compilation technology to precompile applications and stores the compiled code in OAT files, thereby improving app performance. When the Android system is updated, the old OAT files become invalidated. Applications will fall back to interpreted execution, resulting in degraded performance. To accommodate the frequent updates to the Android system that commonly occur on a monthly basis for most smartphone manufacturers, apps must be frequently recompiled into OAT files to promptly restore optimal app performance. However, recompiling applications is a resource-consuming process that cannot be completed quickly. Users have to endure issues such as device overheating and lag, which are caused by performance degradation after system updates.This paper evaluated popular Android apps across different system updates and made an important observation: up to 99% of the compiled code can be reused across different system updates, rendering most existing recompilation efforts unnecessary. Based on this observation, this paper proposes a method to accelerate app recompilation across Android system updates by reusing the old OAT files. We evaluated the proposed method with eight popular apps, on ten open-source Android system pairs and one closed-source Android system pair provided by a smartphone manufacturer. These Android system pairs have the same Android Runtime (ART) version and execute AOT compilation in both speed and speed-profile modes. Experimental results show that the proposed method reuses approximately 95% of compiled methods, achieving average speedups of 2.12× in CPU time and 1.39× in wall-clock time in speed-profile mode. In speed mode, the proposed method reuses about 99% of compiled methods, achieving average speedups of 5.15× in CPU time and 2.80× in wall-clock time, respectively. The proposed method not only accelerates app recompilation but also generates OAT files identical to those generated by native AOT compilation, without introducing security issues. Therefore, it holds significant promise for real-world deployment and has the potential to enhance user experience by speeding up the generation of new OAT files for applications. Mengfei Xie, Futeng Yang, Jiang Ma, Jianming Fu, Chun Jason Xue, Qing'an Li |
CGO | 7 |
| 2026 | An end-to-end packing detection method based on autoencoder featuresabstractAbstract Nowadays, there are millions of executable files submitted to anti-virus companies every day. Existing anti-virus tools are basically designed on malware signature methods, which could be easily bypassed by malware using obfuscation techniques like packing algorithms. At the same time, we could not manually unpack all of the suspicious files when there was a booming growth of packed malware samples. To overcome these challenges, we designed the P2U(Packed-to-Unpacking) model and S2S(Self-to-Self) model for extracting the unpacking feature and latent feature representation of the program itself, respectively, and then presented an end-to-end packing detection method. Unlike entropy or heuristics features, the features extracted by the autoencoders are difficult to be confused and forged, with no need for manual feature selection, and can be used as a complement to existing features. We trained the models on the manually packed dataset and tested the performance on the real-world dataset. Experimental results show that the F1 scores are 0.99 and 0.89 on the training set and the large-scale real-world packed dataset. In addition, the PackingHunt model is also robust against the unseen packers of our real-world dataset and could even achieve 100% accuracy on some unseen packers, though these packing algorithms are not present in the training set. Guga Suri, Jianming Fu |
Cybersecur. | 3 |
| 2026 | TSGDroid: Trigger Semantic Graph Modeling for Detecting Suspicious Hidden Sensitive Operations
Dongni Zhang, Xiuzhang Yang, Side Liu, Jinwen Xin, Jianming Fu, Guojun Peng |
IEEE Internet Things J. | 6 |
| 2026 | Backdoor samples detection based on perturbation discrepancy consistency in pre-trained language models
Zuquan Peng, Jianming Fu, Lixin Zou, Yanzhen Ren, Guojun Peng |
Neural Networks | 2 |
| 2025 | Enhancing Hyperbole and Metaphor Detection with Their Bidirectional Dynamic Interaction and Emotion KnowledgeabstractLi Zheng, Sihang Wang, Hao Fei, Zuquan Peng, Fei Li, Jianming Fu, Chong Teng, Donghong Ji. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Sihang Wang, Hao Fei 0001, Zuquan Peng, Fei Li 0021, Jianming Fu, Chong Teng, Donghong Ji |
ACL (1) | 6 |
| 2025 | Analyzing PDFs like Binaries: Adversarially Robust PDF Malware Analysis via Intermediate Representation and Language ModelabstractMalicious PDF files have emerged as a persistent threat and become a popular attack vector in web-based attacks. While machine learning-based PDF malware classifiers have shown promise, these classifiers are often susceptible to adversarial attacks, undermining their reliability. To address this issue, recent studies have aimed to enhance the robustness of PDF classifiers. Despite these efforts, the feature engineering underlying these studies remains outdated. Consequently, even with the application of cutting-edge machine learning techniques, these approaches fail to fundamentally resolve the issue of feature instability. To tackle this, we propose a novel approach for PDF feature extraction and PDF malware detection. We introduce the PDFObj IR (PDF Object Intermediate Representation), an assembly-like language framework for PDF objects, from which we extract semantic features using a pretrained language model. Additionally, we construct an Object Reference Graph to capture structural features, drawing inspiration from program analysis. This dual approach enables us to analyze and detect PDF malware based on both semantic and structural features. Experimental results demonstrate that our proposed classifier achieves strong adversarial robustness while maintaining an exceptionally low false positive rate of only 0.07% on baseline dataset compared to state-of-the-art PDF malware classifiers. Side Liu, Jiang Ming 0002, Guodong Zhou 0002, Jianming Fu, Guojun Peng |
CCS | 5 |
| 2025 | Beyond Tag Collision: Cluster-based Memory Management for Tag-based Sanitizers
Mengfei Xie, Yan Lin 0003, Jianming Fu, Chenke Luo, Guojun Peng |
CCS | 4 |
| 2025 | Retrofitting XoM for Stripped Binaries without Embedded Data Relocation
Chenke Luo, Jiang Ming 0002, Mengfei Xie, Guojun Peng, Jianming Fu |
NDSS | 5 |
| 2025 | MemoryTrap: Booby Trapping Memory to Counter Memory Disclosure Attacks with Hardware Support
Chenke Luo, Jiang Ming 0002, Dongpeng Xu 0001, Guojun Peng, Jianming Fu |
USENIX ATC | 5 |
| 2025 | VAPD: An Anomaly Detection Model for PDF Malware Forensics with Adversarial Robustness
Side Liu, Jiang Ming 0002, Jianming Fu, Guojun Peng |
USENIX Security Symposium | 4 |
| 2025 | The hidden complexities of Android TPL detection: An empirical analysis of techniques, challenges, and effectiveness
Lige Zhan, Jiang Ming 0002, Jianming Fu, Guojun Peng, Letian Sha, Lili Lan |
Comput. Secur. | 3 |
| 2025 | A survey on Android dynamic evasive malware: Taxonomy, countermeasures and open challenges
Dongni Zhang, Xiuzhang Yang, Side Liu, Jianming Fu, Guojun Peng |
Comput. Secur. | 5 |
| 2025 | MODFuzz: A Multiobjective Directed Fuzzer for USB DriversabstractUSB interfaces have become ubiquitous in various Internet of Things (IoT) devices, all adhering to the same universal serial bus (USB) protocol. While enhancing convenience, they also widen the potential attack surface. Fuzzing is a proactive way to identify potential security threats for USB drivers. However, existing USB driver fuzzers primarily prioritize the code coverage of USB drivers, leading to a significant waste of computational resources on irrelevant code segments. To this end, we combine directed fuzzing and USB driver fuzzing for the first time, and present multiobjective directed fuzzer (MODFuzz), a pioneering multiobjective directed fuzzing method for USB drivers. MODFuzz autonomously locates the most vulnerable parts within USB drivers, concentrating fuzzing efforts on these areas. Diverging from the existing directed fuzzers, MODFuzz employs a dynamic direction instead of predetermined addresses to guide the fuzzing campaign toward the triggered execution traces with a greater probability of containing vulnerabilities. MODFuzz outperforms the strong baseline in terms of execution speed (about 14% improvement) and crash generation capabilities (about 69% improvement). Meanwhile, we found six previously unknown bugs (all confirmed and assigned vulnerability IDs) in Linux kernel v6.4.10 and received acknowledgment from Red Hat. Guojun Peng, Xingliang Wang, Zichuan Li, Side Liu, Xiuzhang Yang, Jianming Fu |
IEEE Internet Things J. | 9 |
| 2025 | VULOC: Vulnerability location framework based on assembly code slicing
Xinghang Lv, Jianming Fu, Tao Peng 0006 |
J. Syst. Softw. | 2 |
| 2025 | VDCRL: vulnerability detection with supervised contrastive code representation learning
Xinghang Lv, Jianming Fu, Yu Nie 0001 |
Neural Networks | 2 |
| 2025 | Egalitarian Randomization for Multi-Language Applications on ARM64abstractDue to the inevitable information loss during IR lowering, compile-time metadata collection can provide more precise auxiliary information than binary analysis to achieve reliable fine-grained randomization. However, existing schemes build on deep modifications of compilers, making it challenging to provide consistent randomization protection for different high-level languages. Additionally, they are inadequate for securing widely used smartphones and embedded devices, since only ×86-64 applications are currently supported. In this paper, we present MLARandom, a compiler-assisted function-level randomization scheme designed for Multi-Language ARM64 applications. MLARandom employs a lightweight compilation standardization strategy that allows for uniform information collection at the assembly level, regardless of the high-level language or compiler used. Further, it combines ARM64 architecture specifications and collected relocation types to accurately repair all ARM64 pointers after randomization. Our experimental results show that MLARandom can equally randomize modules developed in different languages (e.g., C/C++, Rust, Fortran, Cangjie) with negligible runtime overhead (0.51%), to effectively counter against traditional Code Reuse Attacks as well as advanced Cross-Language Attacks. Although randomization approaches based on reassembly can achieve similar goals, our empirical evaluation highlights the imprecise pointer identification as a major obstacle to their practical deployment. Mengfei Xie, Yan Lin 0003, Jianming Fu, Chenke Luo, Guojun Peng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | A survey on the evolution of fileless attacks and detection techniques
Side Liu, Guojun Peng, Haitao Zeng, Jianming Fu |
Comput. Secur. | 4 |
| 2024 | Modeling implicit variable and latent structure for aspect-based sentiment quadruple extraction
Yu Nie 0001, Jianming Fu, Yilai Zhang |
Neurocomputing | 2 |
| 2024 | EavesDroid: Eavesdropping User Behaviors via OS Side Channels on SmartphonesabstractAs the Internet of Things (IoT) continues to evolve, smartphones have become essential components of IoT systems. However, with the increasing amount of personal information stored on smartphones, user privacy is at risk of being compromised by malicious attackers. Although malware detection engines are commonly installed on smartphones against these attacks, attacks that can evade these defenses may still emerge. In this article, we analyze the return values of system calls on Android smartphones and find two never-disclosed vulnerable return values that can leak fine-grained user behaviors. Based on this observation, we present EavesDroid, an application-embedded side-channel attack on Android smartphones that allows unprivileged attackers to accurately identify fine-grained user behaviors (e.g., viewing messages and playing videos) via on-screen operations. Our attack relies on the correlation between user behaviors and the return values associated with hardware and system resources. While this attack is challenging since these return values are susceptible to fluctuation and misalignment caused by many factors, we show that attackers can eavesdrop on fine-grained user behaviors using a CNN-GRU classification model that adopts min–max normalization and multiple return value fusion. Our experiments on different models and versions of Android smartphones demonstrate that EavesDroid can achieve 98% and 86% inference accuracy for 17 classes of user behaviors in the test set and real-world settings, highlighting the risk of our attack on user privacy. Finally, we recommend effective malware detection, carefully designed obfuscation methods, or restrictions on reading vulnerable return values to mitigate this attack. Quancheng Wang, Ming Tang 0002, Jianming Fu |
IEEE Internet Things J. | 3 |
| 2024 | A Trust Evaluation Joint Active Detection Method in Video Sharing D2D NetworksabstractThe potentially malicious devices in D2D networks may spread forged videos to compromise system reliability. The prevailing passive trust model solutions have limitations, such as insufficient and inaccurate trust evidence, as well as weaker resistance to collusion attacks. This paper presents theTrustEvaluation JointActiveDetection (TEAD) method, which employs content correctness as trust evidence and allows devices to verify the authenticity of received videos via the base station. TEAD incorporates an active detection method to proactively determine the trustworthiness of devices. This promotes interaction among devices, resulting in an increase in trust evidence and an improvement in the accuracy of evaluation. Moreover, TEAD introduces a trust calculation method with a penalty mechanism to strengthen the system's resilience against malicious attacks. Empirical results show that TEAD outperforms state-of-the-art methods by achieving a more accurate trust evaluation and faster trust convergence with low extra energy consumption. Zhetao Li, Saiqin Long, Jianming Fu, Min Yang 0002, Jian Weng 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | A Universal Audio Steganalysis Scheme Based on Multiscale Spectrograms and DeepResNetabstractGiven the popularity of audio and video applications, compressed audio has become an important carrier of covert communication on the Internet. Many novel compressed audio steganography schemes have emerged that offer good hiding capability and aural concealment. In this paper, a universal steganalysis scheme called MultiSpecNet is proposed to detect steganography based on multiple embedding domains (advanced audio coding (AAC) and MPEG-1 Audio Layer III (MP3)), which are currently the two most popular compressed audio standards. The basic idea is that modification of either domain by a steganography scheme will change the time-frequency relationship of the audio signal after decoding. The proposed approach adopts the spectrogram as the input feature to extract richer information. DeepResNet is used to learn the distinguishing feature representations, and multiscale spectrograms are used to enrich the feature diversity. The experimental results show that the proposed scheme is effective at detecting different steganography schemes based on the AAC and MP3 embedding domains. The detection accuracy of the proposed scheme is higher than that achieved by other state-of-the-art schemes. Using spectrograms as the input, DeepResNet achieves better performance than schemes using quantized modified discrete cosine transform (MDCT) coefficients and mel-spectrogram, although the quantized MDCT coefficient is the parameter modified by the steganography schemes directly and mel-spectrogram is very popular and effective for general audio signal analysis. To the best of our knowledge, this work is the first audio steganalysis scheme that can detect multiple steganography schemes in both the MP3 and AAC embedding domains. The method proposed in this paper can be extended to audio steganalysis for other codecs or for audio forensics purposes. Yanzhen Ren, Dengkai Liu, Qiaochu Xiong, Jianming Fu, Lina Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | PointerScope: Understanding Pointer Patching for Code RandomizationabstractVarious fine-grained randomization schemes have been designed to increase the entropy of process space, while none of them can rise from an academic exercise to industrial deployment like Address Space Layout Randomization (ASLR). One of the critical reasons is the incorrectness of randomization caused by the mismatch between their pointer collection capabilities and the high accuracy requirements of the pointer patching task. In this article, we present PointerScope, an accurate compile-time pointer collection scheme deriving from a group of novel observations. The success of PointerScope relies on the complete tracing of the pointer generation process, including the compilation chain from compiler to static linker and the interface specification between them. From this view, PointerScope identifies four types of pointer-related static linker behaviors and clarifies five types of inherent addressing modes in the x86-64 architecture. The vague understanding of them causes the Compiler-assisted Code Randomization (CCR) to incorrectly collect pointers and patch them to the wrong values after randomization. Further, we measure the pointer collection capability of augmented binary analysis, the experimental results show that they can mitigate challenges from the traditional binary analysis by the given premises, but additional heuristics still need to be designed to support the fine-grained randomization. Mengfei Xie, Yan Lin 0003, Chenke Luo, Guojun Peng, Jianming Fu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Reverse Engineering of Obfuscated Lua Bytecode via Interpreter Semantics TestingabstractAs an efficient and multi-platform scripting language, Lua is gaining increasing popularity in the industry. Unfortunately, Lua’s unique advantages also catch cybercriminals’ attention. A growing number of IoT malware authors switch to Lua for malicious payload development and then distribute malware in bytecode form. To impede malware code analysis, malware authors obfuscate standard Lua bytecode into a customized bytecode specification. Only the attached interpreter can execute that particular bytecode file. Rapid recovery of Lua obfuscated bytecode is essential for a swift response to new malware threats. However, existing generic code deobfuscation approaches cannot keep up with the pace of emerging threats. In this paper, we present a novel reverse engineering technique, calledinterpreter semantics testing. Given a customized interpreter used to execute obfuscated Lua bytecode, we construct a set ofLuaGadgetsthat can adapt to the customized interpreter. Each LuaGadget contains a carefully chosen opcode sequence to fulfill an observable calculation—it is designed to test one or two particular opcodes at a time. Next, we mutate unknown opcode values to generate a bunch of test cases and run them using the customized interpreter; we can observe the expected result only when the mutation hits the opcode’s right value. We perform test case prioritization to cost-effectively recover the semantics of all obfuscated opcodes. Our approach makes no assumptions about the interpreter’s structure and is free from analyzing the numerous execution traces of opcode handlers. We have evaluated our tool,LuaHunt, with Lua malware variants and real-world applications. LuaHunt is able to recover the obfuscated bytecode’s semantics within 90 seconds for each test case, and all of our deobfuscation results can pass the correctness testing. The encouraging results demonstrate that LuaHunt is a promising tool to lighten the burden of security analysts. Chenke Luo, Jiang Ming 0002, Jianming Fu, Guojun Peng, Zhetao Li |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based VirtualizationabstractA fast-growing demand from smartphone users is mobile virtualization.This technique supports running separate instances of virtual phone environments on the same device. In this way, users can run multiple copies of the same app simultaneously,and they can also run an untrusted app in an isolated virtual phone without causing damages to other apps. Traditional hypervisor-based virtualization is impractical to resource-constrained mobile devices.Recent app-level virtualization efforts suffer from the weak isolation mechanism. In contrast, container-based virtualization offers an isolated virtual environment with superior performance.However, existing Android containers do not meet the anti-evasion requirement for security applications: their designs are inherently incapable of providing transparency or stealthiness. Wenna Song, Jiang Ming 0002, Xuanchen Pan, Jianming Fu, Guojun Peng |
CCS | 6 |
| 2021 | App's Auto-Login Function Security Testing via Android OS-Level VirtualizationabstractLimited by the small keyboard, most mobile apps support the automatic login feature for better user experience. Therefore, users avoid the inconvenience of retyping their ID and password when an app runs in the foreground again. However, this auto-login function can be exploited to launch the so-called "data-clone attack": once the locally-stored, auto-login depended data are cloned by attackers and placed into their own smartphones, attackers can break through the login-device number limit and log in to the victim's account stealthily. A natural countermeasure is to check the consistency of device-specific attributes. As long as the new device shows different device fingerprints with the previous one, the app will disable the auto-login function and thus prevent data-clone attacks. In this paper, we develop VPDroid, a transparent Android OS-level virtualization platform tailored for security testing. With VPDroid, security analysts can customize different device artifacts, such as CPU model, Android ID, and phone number, in a virtual phone without user-level API hooking. VPDroid's isolation mechanism ensures that user-mode apps in the virtual phone cannot detect device-specific discrepancies. To assess Android apps' susceptibility to the data-clone attack, we use VPDroid to simulate data-clone attacks with 234 most-downloaded apps. Our experiments on five different virtual phone environments show that VPDroid's device attribute customization can deceive all tested apps that perform device-consistency checks, such as Twitter, WeChat, and PayPal. 19 vendors have confirmed our report as a zero-day vulnerability. Our findings paint a cautionary tale: only enforcing a device-consistency check at client side is still vulnerable to an advanced data-clone attack. Wenna Song, Jiang Ming 0002, Han Yan 0013, Jianming Fu, Guojun Peng |
ICSE | 7 |
| 2021 | Obfuscation-Resilient Executable Payload Extraction From Packed Malware
Binlin Cheng, Jiang Ming 0002, Erika A. Leal, Haotian Zhang 0006, Jianming Fu, Guojun Peng, Jean-Yves Marion |
USENIX Security Symposium | 5 |
| 2021 | Trust-Aware sensing Quality estimation for team Crowdsourcing in social IoT
Jianming Fu, Yanjiao Chen, Weichen Luo |
Comput. Networks | 2 |
| 2020 | JTaint: Finding Privacy-Leakage in Chrome Extensions
Mengfei Xie, Jianming Fu, Chenke Luo, Guojun Peng |
ACISP | 2 |
| 2020 | VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's ClothingabstractRepackaging popular benign apps with malicious payload used to be the most common way to spread Android malware. Nevertheless, since 2016, we have observed an alarming new trend to Android ecosystem: a growing number of Android malware samples abuse recent app-virtualization innovation as a new distribution channel. App-virtualization enables a user to run multiple copies of the same app on a single device, and tens of millions of users are enjoying this convenience. However, cybercriminals repackage various malicious APK files as plugins into an app-virtualization platform, which is flexible to launch arbitrary plugins without the hassle of installation. This new style of repackaging gains the ability to bypass anti-malware scanners by hiding the grafted malicious payload in plugins, and it also defies the basic premise embodied by existing repackaged app detection solutions. Luman Shi, Jiang Ming 0002, Jianming Fu, Guojun Peng, Dongpeng Xu 0001, Xuanchen Pan |
CCS | 3 |
| 2020 | Family Identification of AGE-Generated Android Malware Using Tree-Based FeatureabstractApplication Generation Engine(AGE) is a development tool that can automatically generate simple Android applications by utilizing some boilerplate codes. People with little software programming background could also develop Android applications by using this tool based on their requirements. The emergence of AGE dramatically improves the ease of developing essential software and lowers the level of programming skills required for app developers. However, it also provides easy access for attackers to quickly develop a large number of malicious applications, which will seriously affect the device and data security of regular users. Since AGE mainly generates applications based on some boilerplate codes, the code structures of malicious apps created by AGE have a high degree of similarity when these apps belong to the same family. Based on the assumption that the package directory structures of the software from the same family are also similar, we designed a novel feature construction method to describe the application. Using this method, we extracted features from the leaf nodes of the smali tree, while each smali tree corresponds to the smali directory of the application. Unlike traditional static feature extraction of applications, the tree-based feature proposed in this paper can effectively counteract problems such as code obfuscation or reflection cause it can adequately reflect the semantic features of the smali files. To prove the effectiveness of tree-based features, we also conducted some experiments based on a dataset provided by the enterprise. This dataset contains 1792 AGE-generated applications, and these applications belong to 17 malicious families. We demonstrated that the feature construction method proposed in this paper is usable and can be applied to machine learning classification algorithms for the identification of malicious applications. Guga Suri, Jianming Fu |
TrustCom | 2 |
| 2020 | MFRep: Joint user and employer alignment across heterogeneous social networks
Yanjiao Chen, Jianming Fu |
Neurocomputing | 3 |
| 2020 | Event evolution model for cybersecurity event mining in tweet streams
Jianming Fu, Yanjiao Chen |
Inf. Sci. | 2 |
| 2020 | An Efficient Deep Learning Based Method for Speech Assessment of Mandarin-Speaking Aphasic PatientsabstractSpeech assessment is an important part of the rehabilitation process for patients with aphasia (PWA). Mandarin speech lucidity features such as articulation, fluency, and tone influence the meaning of the spoken utterance and overall speech clarity. Automatic assessment of these features is important for an efficient assessment of the aphasic speech. Hence, in this paper, a standardized automatic speech lucidity assessment method for Mandarin-speaking aphasic patients using a machine learning based technique is presented. The proposed assessment method adopts the Chinese Rehabilitation Research Center Aphasia Examination (CRRCAE) standard as a guideline. Quadrature based high-resolution time-frequency images with a convolutional neural network (CNN) are utilized to develop a method that can map the relationship between the severity level of aphasic patients' speech and the three speech lucidity features. The results show a linear relationship with statistically significant correlations between the normalized true-class output activations (TCOA) of the CNN model and patients' articulation, fluency, and tone scores, i.e., 0.71 (p < 0.001), 0.60 (p < 0.001) and 0.58 (p < 0.001), respectively. The linearity of the proposed Mandarin aphasic speech assessment method and its significant correlation with the speech severity levels show the efficacy of the method in predicting the severity of impaired Mandarin speech. The outcome of this research envisages assisting speech-language pathologists in Mandarin-speech impairment assessment and promoting early support discharge; hence could alleviate the stress that the healthcare system is currently experiencing in China nationwide. The framework of the proposed Mandarin aphasic speech assessment method can be readily extended to other languages. Seedahmed S. Mahmoud, Yiting Tang, Youcun Li, Xudong Gu, Jianming Fu, Qiang Fang 0004 |
IEEE J. Biomed. Health Informatics | 6 |
| 2019 | "Jekyll and Hyde" is Risky: Shared-Everything Threat Mitigation in Dual-Instance AppsabstractRecent developed application-level virtualization brings a groundbreaking innovation to Android ecosystem: a host app is able to load and launch arbitrary guest APK files without the hassle of installation. Powered by this technology, the so-called "dual-instance apps" are becoming increasingly popular as they can run dual copies of the same app on a single device (e.g., login Facebook simultaneously with two different accounts). Given the large demand from smartphone users, it is imperative to understand how secure dual-instance apps are. However, little work investigates their potential security risks. Even worse, new Android malware variants have been accused of skimming the cream off application-level virtualization. They abuse legitimate virtualization engines to launch phishing attacks or even thwart static detection. We first demonstrate that, current dual-instance apps design introduces serious "shared-everything" threats to users, and severe attacks such as permission escalation and privacy leak have become tremendously easier. Unfortunately, we find that most critical apps cannot discriminate between host app and Android system. In addition, traditional fingerprinting features targeting Android sandboxes are futile as well. To inform users that an app is running in an untrusted environment, we study the inherent features of dual-instance app environment and propose six robust fingerprinting features to detect whether an app is being launched by the host app. We test our approach, called DiPrint, with a set of dual-instance apps collected from popular app stores, Android systems, and virtualization-based malware. Our evaluation shows that DiPrint is able to accurately identify dual-instance apps with negligible overhead. Luman Shi, Jianming Fu, Zhengwei Guo, Jiang Ming 0002 |
MobiSys | 2 |
| 2019 | A Novel Multistandard Compliant Hand Function Assessment Method Using an Infrared Imaging DeviceabstractMany post-stroke patients suffer varying degrees of hand function and fine motor skills impairment. Both passive and active hand rehabilitation training are beneficial in improving the strength and dexterity of the hands. However, hand rehabilitation programs should be prescribed based on an accurate assessment of hand function. In this paper, we propose a novel method for hand function assessment, which can accurately measure multiple joint angles of a hand simultaneously using a portable infrared based imaging device. Different from traditional assessment methods that are often based on a clinician's subjective observations and ordinal charts, this method provides an accurate, fast, and objective evaluation using infrared imaging sensors. Performance evaluation and benchmarking for the proposed measurement system were carried out using the correlation coefficient (CC) method, the root mean squared error, and the percentage residual difference method (PRD). A clinical trial involving 25 participants resulted in a higher correlation with CC of 0.9672 and PRD of 8.8%, which indicated that the developed assessment framework is compliant with multiple assessment standards such as Swanson impairment evaluation and Fugl-Meyer assessment. The new hand function assessment method can be used to replace traditional methods for fine hand function modeling and assessment in rehabilitation medicine and can also play an important role in precision post-stroke function analysis. Qiang Fang 0004, Seedahmed S. Mahmoud, Xudong Gu, Jianming Fu |
IEEE J. Biomed. Health Informatics | 4 |
| 2018 | Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance BoostabstractBinary packing, encoding binary code prior to execution and decoding them at run time, is the most common obfuscation adopted by malware authors to camouflage malicious code. Especially, most packers recover the original code by going through a set of "written-then-executed" layers, which renders determining the end of the unpacking increasingly difficult. Many generic binary unpacking approaches have been proposed to extract packed binaries without the prior knowledge of packers. However, the high runtime overhead and lack of anti-analysis resistance have severely limited their adoptions. Over the past two decades, packed malware is always a veritable challenge to anti-malware landscape. This paper revisits the long-standing binary unpacking problem from a new angle: packers consistently obfuscate the standard use of API calls. Our in-depth study on an enormous variety of Windows malware packers at present leads to a common property: malware's Import Address Table (IAT), which acts as a lookup table for dynamically linked API calls, is typically erased by packers for further obfuscation; and then unpacking routine, like a custom dynamic loader, will reconstruct IAT before original code resumes execution. During a packed malware execution, if an API is invoked through looking up a rebuilt IAT, it indicates that the original payload has been restored. This insight motivates us to design an efficient unpacking approach, called BinUnpack. Compared to the previous methods that suffer from multiple "written-then-executed" unpacking layers, BinUnpack is free from tedious memory access monitoring, and therefore it introduces very small runtime overhead. To defeat a variety of ever-evolving evasion tricks, we design BinUnpack's API monitor module via a novel kernel-level DLL hijacking technique. We have evaluated BinUnpack's efficacy extensively with more than 238K packed malware and multiple Windows utilities. BinUnpack's success rate is significantly better than that of existing tools with several orders of magnitude performance boost. Our study demonstrates that BinUnpack can be applied to speeding up large-scale malware analysis. Binlin Cheng, Jiang Ming 0002, Jianming Fu, Guojun Peng, Ting Chen 0002, Xiaosong Zhang 0001, Jean-Yves Marion |
CCS | 3 |
| 2017 | Curtain: Keep Your Hosts Away from USB Attacks
Jianming Fu, Lanxin Zhang |
ISC | 1 |
| 2017 | FRProtector: Defeating Control Flow Hijacking Through Function-Level Randomization and Transfer Protection
Jianming Fu, Yan Lin 0003 |
SecureComm | 1 |
| 2016 | Control Flow Integrity Enforcement with Dynamic Code Optimization
Yan Lin 0003, Xiaoxiao Tang, Debin Gao, Jianming Fu |
ISC | 4 |
| 2016 | Impact of Environment on Branch Transfer of Software
Jianming Fu, Yan Lin 0003, Xu Zhang 0008 |
SecureComm | 1 |
| 2016 | SDN-based Sensitive Information (SI) protection: sensitivity-degree measurement in software and data lifetime supervisor in software defined networkabstractAbstract With the big‐data and mobile Internet era coming, sensitive information (SI) in various applications plays a key role; even more, they can be an important part of the authentication between clients and servers. However, how to measure security or sensitivity degrees of SI is an open issue. Furthermore, no effective method can detect covert channel of SI thieves in Advanced Persistent Threat attacks. To deal with these problems, we propose a new design, called software‐defined networking (SDN)‐based SI Protection, in which sensitivity degree can be measured by using Analytic Hierarchy Process and Technique for Order Preference by Similarity to an Ideal Solution, and SI covert channel can be detected based on OpenFlow in SDN. To our best knowledge, it is the first defined sensitivity degree for SI and novel flow‐table design in SI data flow switch. Most significantly, our proposal can apply integrated semantics of leakage points and accident attacks into security analysis and switch protocol in Operating System or network. To verify our proposal, experimental tests are performed in social network platforms, field test results have demonstrated that this proposal can capture security level for SI as expected, detect any kinds of potential leakage points in data lifetime, describe fine‐grained semantics of accidental attacks, and detect illegal data flow of SI in network layer. Copyright © 2015 John Wiley & Sons, Ltd. Letian Sha, Liwen He, Jianming Fu, Pengwei Li |
Secur. Commun. Networks | 3 |
| 2014 | Computation Integrity Measurement Based on Branch TransferabstractTasks are selectively migrated to the cloud with the widespread adoption of the cloud computing platform, but the user cannot know whether the tasks are tampered in the cloud, so it is an urgent demand for cloud users to verify the execution integrity of the program in the cloud. The computation integrity measurement based on behavior is difficult to detect carefully crafted shell code. According to the property of shell code, this paper proposes a computation integrity measurement based on branch transfer called CIMB, which is a fine-grained instruction-level integrity measurement. In this approach, all branches in the user-level have been recorded, which effectively cover all execution control flow of a program, and CIMB can detect control-flow hijacking attacks without the support of source code, such as Return-oriented Programming (ROP) and Jump-oriented Programming (JOP). Meanwhile, distance between two instruction addresses and machine code of instruction can mask the measurement inconsistency derived from address space layout randomization of program and shared libraries. Finally, we have implemented CIMB with a dynamic binary instrumentation tool Pin on x86 32-bit version of ubuntu12.04. Its experimental results show that CIMB is feasible and it has a relatively stable measurement result, and the advantages of CIMB and factors affecting the results of measurement are analyzed and discussed. Jianming Fu, Yan Lin 0003, Xu Zhang 0008, Pengwei Li |
TrustCom | 1 |
| 2011 | Malware Behavior Capturing Based on Taint Propagation and Stack BacktracingabstractAlthough dynamic analysis is immune to polymorphic, metamorphic, and encryption techniques, it is an open issue how to precisely capture behavior of malware. A connection between system call and its module has been constructed using taint propagation and stack backtracing, and a method of capturing malware behavior is presented on the basis of this connection1. This method works well on parasitic malware and the analysis results are more concise. Finally, a prototype Module-based Analysis Tool (MAT) on Windows XP has been implemented. The experimental results show that MAT can capture well behaviors of most kinds of malwares, and locate the real malicious module, which is very useful to remove malware. Jianming Fu, Xinwen Liu 0002, Binling Cheng |
TrustCom | 1 |
| 2010 | Research on theory and key technology of trusted computing platform security testing and evaluation
Huanguo Zhang, Jianming Fu, Mingdi Xu, Jing Zhan |
Sci. China Inf. Sci. | 3 |
| 2008 | Bridging the Gap between Data-Flow and Control-Flow Analysis for Anomaly DetectionabstractHost-based anomaly detectors monitor the control-flow and data-flow behavior of system calls to detect intrusions. Control-flow-based detectors monitor the sequence of system calls, while data-flow-based detectors monitor the data propagation among arguments of system calls. Besides pointing out that data-flow-based detectors can be layered on top of control-flow-based ones (or vice versa) to improve accuracy, there is a large gap between the two research directions in that research along one direction had been fairly isolated and had not made good use of results from the other direction. In this paper, we show how data-flow analysis can leverage results from control-flow analysis to learn more accurate and useful rules for anomaly detection. Our results show that the proposed control-flow-analysis-aided data-flow analysis reveals some accurate and useful rules that cannot be learned in prior data-flow analysis techniques. These relations among system call arguments and return values are useful in detecting many real attacks. A trace-driven evaluation shows that the proposed technique enjoys low false-alarm rates and overhead when implemented on a production server. Peng Li 0059, Hyundo Park, Debin Gao, Jianming Fu |
ACSAC | 4 |
| 2008 | PerformTrust: Trust model integrated past and current performance in P2P file sharing systemsabstractTrust model is an effort to guarantee secure and high quality interactions in P2P(peer-to-peer) file sharing systems. Traditional trust models always depend on past performance quantified in term of reputation or recommendation. This paper presents PerformTrust -a history and current performance based trust supporting framework which includes an intensive trust model for offering trustworthiness of peers quantitatively and comparatively based on a history performance feedback system and a current performance evaluating system with a decentralized implementation over a structured P2P network. PerformTrust has two main features. First, we introduce a virtual domain in every peer that would take responsible of collecting information about current performance of peers, including files integrity and peers response time. Second, PerformTrust considers both history and current performance of a peer for evaluating trustworthiness. Other contributions include adjustment scenario of the trust model, and a set of experiment that show the effectiveness and benefit of our approach. Jianming Fu, Huijun Xiong, Zhou Li 0001, Huanguo Zhang |
AICCSA | 1 |
| 2007 | A Worm Containment Model Based on Neighbor-Alarm
Jianming Fu, Binglan Chen, Huanguo Zhang |
ATC | 1 |
| 2004 | A Framework for Adaptive Anomaly Detection Based on Support Vector Data Description
Min Yang 0001, Huanguo Zhang, Jianming Fu |
NPC | 3 |