EDBT 2026 Demo / reviewers in the wild / expert
Zhiyu Zhang 0017
dblp:45/6271-17
· DBLP profile ↗
4ranked-venue papers
0as first author
4since 2021 · last 2025
0009-0006-7966-3107ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MalFocus: Locating Malicious Modules in Malware Based on Hybrid Deep LearningabstractIn recent years, binary malware detection has attracted extensive attention from industry and academia. However, most of the existing work only focuses on judging whether a sample is malicious or not, rather than identifying malicious modules in malware. Few studies aiming at locating malicious code work on the function granularity and suffer from inaccuracy. In this paper, we address this problem by locating malicious code at the functional module (FM) granularity, which combines several functions to express the malicious behaviors of malware. We design a tool called MalFocus to automatically divide malware intoFMsand then identify the malicious functional module (MFM) in a multi-model hybrid manner, in which an unsupervised model and an interpretability approach based on a binary classifier are combined, eliminating the workload of labeling malware samples, determining the scope ofMFMsand ranking them according to their maliciousness. The identifiedMFMsare then passed to security analysts for verification, helping to significantly reduce the scope of manual analysis while providing a comprehensive view of the malware attack flow. Additionally, rules derived from the verifiedMFMscan be used to detect variants and new malware families with different functionalities, offering a more general and flexible detection approach. We evaluate MalFocus’s performance on 6764 real-world samples. The results show that MalFocus can correctly identify 95% ofMFMs, outperforming current state-of-the-art work. Weihao Huang, Chaoyang Lin, Lu Xiang, Zhiyu Zhang 0017, Guozhu Meng, Lei Xue 0001, Kai Chen 0012, Zongming Zhang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | DARKFLEECE: Probing the Dark Side of Android Subscription Apps
Chang Yue, Chen Zhong 0008, Kai Chen 0012, Zhiyu Zhang 0017, Yeonjoon Lee |
USENIX Security Symposium | 4 |
| 2023 | FMDiv: Functional Module Division on Binary Malware for Accurate Malicious Code LocalizationabstractIn recent years, binary malware detection has attracted extensive attention from industry and academia. However, most of the existing work focuses on determining whether a sample is malicious or not, rather than identifying the malicious essence in malware. Few studies aim at locating malicious code at function granularity and suffer from inaccuracy. In this paper, we solve the problem by dividing malware into Functional Module (FM), which is a better granularity for locating malicious code, as it combines certain functions to express malicious behaviors in malware. We design a tool called FMDiv to automatically unpack and disassemble binary malware and then divide them into FMs based on the function call graph (CG). Meanwhile, one novel feature extraction and embedding method has been adopted to validate the effect of the FM division algorithm and provide one alternative method of characterization for subsequent malicious FM location. We evaluate FMDiv’s performance on 10,440 real-world samples from VIRUSSHARE. The results show that FMDiv can correctly characterize and make FM division of malware, outperforming current state-of-the-art work. Weihao Huang, Chaoyang Lin, Qiucun Yan, Lu Xiang, Zhiyu Zhang 0017, Guozhu Meng, Kai Chen 0012 |
CSCWD | 5 |
| 2023 | CarpetFuzz: Automatic Program Option Constraint Extraction from Documentation for Fuzzing
Dawei Wang 0021, Ying Li 0104, Zhiyu Zhang 0017, Kai Chen 0012 |
USENIX Security Symposium | 3 |