EDBT 2026 Demo / reviewers in the wild / expert
Xuewei Feng
dblp:53/8376
· DBLP profile ↗
22ranked-venue papers
9as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 8 first-author · 10 since 2021Computer networks · 6 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs
Xuewei Feng, Qi Li 0002, Ke Xu 0002 |
INFOCOM | 3 |
| 2025 | Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing ScenariosabstractPath MTU Discovery (PMTUD) and IP address sharing are integral aspects of modern Internet infrastructure. In this paper, we investigate the security vulnerabilities associated with PMTUD within the context of prevalent IP address sharing practices. We reveal that PMTUD is inadequately designed to handle IP address sharing, creating vulnerabilities that attackers can exploit to perform off-path TCP hijacking attacks. We demonstrate that by observing the path MTU value determined by a server for a public IP address (shared among multiple devices), an off-path attacker on the Internet, in collaboration with a malicious device, can infer the sequence numbers of TCP connections established by other legitimate devices sharing the same IP address. This vulnerability enables the attacker to perform off-path TCP hijacking attacks, significantly compromising the security of the affected TCP connections. Our attack involves first identifying a target TCP connection originating from the shared IP address, followed by inferring the sequence numbers of the identified connection. We thoroughly assess the impacts of our attack under various network configurations. Experimental results reveal that the attack can be executed within an average time of 220 seconds, achieving a success rate of 70%. Case studies, including SSH DoS, FTP traffic poisoning, and HTTP injection, highlight the threat it poses to various applications. Additionally, we evaluate our attack across 50 real-world networks with IP address sharing---including public Wi-Fi, VPNs, and 5G---and find 38 vulnerable. Finally, we responsibly disclose the vulnerabilities, receive recognition from organizations such as IETF, Linux, and Cisco, and propose our countermeasures. Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002 |
CCS | 1 |
| 2025 | ReDAN: An Empirical Study on Remote DoS Attacks against NAT Networks
Xuewei Feng, Qi Li 0002, Xingxiang Zhan, Kun Sun 0001, Ganqiu Du, Ke Xu 0002 |
NDSS | 1 |
| 2025 | Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel Attack
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ganqiu Du, Ke Xu 0002 |
NDSS | 2 |
| 2025 | Secure Fault Localization in Path Aware NetworkingabstractSecure data forwarding is critical for users to meet their requirements. In this paper, we propose D3 (Demon Detector in Data Plane), a source-driven, secure fault localization mechanism, which empowers the source to localize faulty link in Path Aware Networking, thus circumventing faulty link to guarantee secure data forwarding. D3 utilizes the source to instruct the on-path routers, thus empowering it to detect whether the on-path routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the heavy storage, computation, and communication overhead, D3 offloads most of the on-path router's storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, thus having a low communication overhead. Besides that, the destination in D3 could keep stateless processing, thus having backward compatibility and eliminating the opportunity for DoS attacks toward a stateful destination. The BMv2 and Barefoot Tofino hardware evaluations show that D3 could achieve high fault localization accuracy and process the packet at line rate. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | StateShield: Real-Time Defenses Against Information Leakage Over Connectionless ProtocolsabstractConnectionless protocols such as ICMP and UDP are manipulated to construct novel information leakage channels by which attackers can disrupt TCP connections or leak secret information. Existing solutions have mainly focused on repairing vulnerable protocols through OS patches, which are OS-specific and slow to deploy. Other traditional defenses either cannot cover these attacks or are prone to incur unintended dropping of legitimate packets due to the heavily manipulated IP spoofing technique in these attacks. In this paper, we present StateShield, an in-network, real-time defense against state-of-the-art information leakage attacks over connectionless protocols. StateShield can detect and defend against various information leakage attacks without incurring unintended dropping of legitimate traffic, even when attackers heavily spoof the IP addresses of legitimate clients. To achieve that, we propose three indicators that can cover major attack vectors of connectionless information leakage channels and are effective for detecting more than ten attack variants. We design the architecture of StateShield based on programmable switches, with efficient data structures for monitoring and on-demand defense components in the data plane. We develop two novel defense components to mitigate UDP and ICMP-based information leakage channels automatically while achieving minimal unintended dropping of legitimate packets. Our extensive experiments show that StateShield can effectively mitigate more than ten attack variants in real time without hurting the services over legitimate connectionless packets, and the defense provided by StateShield is robust under high-intensive background traffic over connectionless protocols. Qi Li 0002, Xuewei Feng, Chuanpu Fu, Ke Xu 0002 |
IEEE Trans. Netw. | 4 |
| 2025 | Off-Path TCP Hijacking Attack to NAT-Enabled Wi-Fi NetworksabstractIn this paper, we uncover a novel side-channel vulnerability arising from the shared NAT tables of Wi-Fi routers, enabling malicious insiders to hijack TCP connections between other clients and remote servers. First, by creating different NAT mappings within the shared NAT table, an off-path attacker can infer whether a victim client within the same Wi-Fi network is communicating with an external host over TCP, leveraging the widely adopted NAT port preservation strategy and insufficient reverse path validation in Wi-Fi routers. Once an active connection is detected, the attacker can manipulate the victim’s NAT mapping in the shared NAT table with spoofed TCP packets, exploiting the lack of TCP window tracking in most routers. In this way, the attacker can intercept TCP packets from the server and obtain the current sequence and acknowledgment numbers, which in turn allows the attacker to forcibly close the connection, poison the traffic in plain text, or reroute the server’s incoming packets to the attacker. We test 67 widely used routers from 30 vendors and discover that 52 of them are vulnerable. Also, we conduct an extensive measurement study on 93 real-world Wi-Fi networks and find that 75 of them (81%) are fully affected to our attack. Our case study shows that it takes about 17.5, 19.4, and 54.5 seconds on average to terminate SSH connections, download private files from FTP servers, and inject fake HTTP response packets with success rates of 87.4%, 82.6%, and 76.1%. Moreover, We evaluate the feasibility of the proposed attack in NAT-enabled IPv6 Wi-Fi networks. We responsibly disclose the vulnerability and suggest mitigation strategies to all affected vendors and have received positive feedback, including acknowledgments, CVEs, rewards, and adoption of our suggestions. Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002 |
IEEE Trans. Netw. | 2 |
| 2024 | BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low EnergyabstractBluetooth Low Energy (BLE) is a short-range wireless communication technology for resource-constrained IoT devices. Unfortunately, BLE is vulnerable to session-based attacks, where previous packets construct exploitable conditions for subsequent packets to compromise connections. Defending against session-based attacks is challenging because each step in the attack sequence is legitimate when inspected individually. In this paper, we present BlueSWAT, a lightweight state-aware security framework for protecting BLE devices. To perform inspection on the session level rather than individual packets, BlueSWAT leverages a finite state machine (FSM) to monitor sequential actions of connections at runtime. Patterns of session-based attacks are modeled as malicious transition paths in the FSM. To overcome the heterogeneous IoT environment, we develop a lightweight eBPF framework to facilitate universal patch distribution across different BLE architectures and stacks, without requiring device reboot. We implement BlueSWAT on 5 real-world devices with different chips and stacks to demonstrate its cross-device adaptability. On our dataset with 101 real-world BLE vulnerabilities, BlueSWAT can mitigate 76.1% of session-based attacks, outperforming other defense frameworks. In our end-to-end application evaluation, BlueSWAT introduces an average of 0.073% memory overhead and negligible latency. Xijia Che, Yi He 0020, Xuewei Feng, Kun Sun 0001, Ke Xu 0002, Qi Li 0002 |
CCS | 3 |
| 2024 | A Horizontal Study on the Mixed IPID Assignment Vulnerability in the Linux EcosystemabstractThe off-path TCP hijacking attack poses a significant threat to Internet security, allowing attackers to manipulate various upper-layer applications and causing severe real-world damage. In this paper, we undertake a horizontal study on a critical TCP hijacking attack affecting Linux servers, which was reported in November 2020 (CVE-2020-36516). This attack has the potential to compromise over 20% of popular websites on the Internet. Our study particularly focuses on determining the extent to which the developed stack patches, designed to address this vulnerability, have been effectively deployed in the real world and whether they have successfully mitigated the identified attack. In our horizontal study, we thoroughly examine the current status of the vulnerability, covering upstream and downstream components of the Linux ecosystem. This study encompasses 12 mainstream Linux distributions, 296 images from 7 leading cloud vendors, 2.92 million IPs from 301 network segments belonging to 6 major CDN vendors, as well as the top 1 million websites from 3 datasets. Our study unveils a notable disparity in the patching of the vulnerability in the Linux ecosystem, spanning various ISPs and vendors, which leaves the vulnerability open to potential exploitation and poses a serious threat to the Internet. Xuewei Feng, Qi Li 0002, Ke Xu 0002 |
IWQoS | 2 |
| 2024 | Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi Networks
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002 |
NDSS | 2 |
| 2023 | Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP RedirectsabstractModern Wi-Fi networks are commonly protected by the security mechanisms, e.g., WPA, WPA2 or WPA3, and thus it is difficult for an attacker (a malicious supplicant) to hijack the traffic of other supplicants as a man-in-the-middle (MITM). In traditional Evil Twins attacks, attackers may deploy a bogus wireless access point (AP) to hijack the victim supplicants’ traffic (e.g., stealing credentials). In this paper, we uncover a new MITM attack that can evade the security mechanisms in Wi-Fi networks by spoofing the legitimate AP to send a forged ICMP redirect message to a victim supplicant and thus allow attackers to stealthily hijack the traffic from the victim supplicant without deploying any bogus AP. The core idea is to misuse the vulnerability of cross-layer interactions between WPAs and ICMP protocols, totally evading the link layer security mechanisms enforced by WPAs. We resolve two requirements to successfully launch our attack. First, when the attacker spoofs the legitimate AP to craft an ICMP redirect message, the legitimate AP cannot recognize and filter out those forged ICMP redirect messages. We uncover a new vulnerability (CVE-2022-25667) of the Network Processing Units (NPUs) in AP routers that restrict the AP routers from blocking fake ICMP error messages passing through the router. We test 55 popular wireless routers from 10 well-known AP vendors, and none of these routers can block the forged ICMP redirect messages due to this vulnerability. Second, we develop a new method to ensure the forged ICMP redirect message can evade the legitimacy check of the victim supplicant and then poison its routing table. We conduct an extensive measurement study on 122 real-world Wi-Fi networks, covering all prevalent Wi-Fi security modes. The experimental results show that 109 out of the 122 (89%) evaluated Wi-Fi networks are vulnerable to our attack. Besides notifying the vulnerability to the NPU manufacturers and the AP vendors, we develop two countermeasures to throttle the identified attack. Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002 |
SP | 1 |
| 2023 | A Fixed-Wing UAV Formation Algorithm Based on Vector Field GuidanceabstractThe vector field method was originally proposed to guide a single fixed-wing Unmanned Aerial Vehicle (UAV) towards a desired path. In this work, a non-uniform vector field method is proposed that changes in both magnitude and direction, for the purpose of achieving formations of UAVs. As compared to related work in the literature, the proposed formation control law does not need to assume absence of wind. That is, due to the effect of the wind on the UAV, one can handle the UAV air speed being different from its ground speed, and the UAV heading angle being different from its course angle. Stability of the proposed formation method is analyzed via Lyapunov stability theory, and validations are carried out in software-in-the-loop and hardware-in-the-loop comparative experiments. Note to Practitioners—The software-in-the-loop and hardware-in-the-loop experiments, which are done with PX4 autopilot software and hardware, show that the proposed method can be implemented on board of UAVs and integrated with the control architecture of existing autopilot suites. Comparisons with standard formation algorithms show that the proposed method is effective in achieving formation in different path scenarios. Ximan Wang, Simone Baldi, Xuewei Feng, Changwei Wu, Hongwei Xie, Bart De Schutter |
IEEE Trans Autom. Sci. Eng. | 3 |
| 2023 | FedDef: Defense Against Gradient Leakage in Federated Learning-Based Network Intrusion Detection SystemsabstractDeep learning (DL) methods have been widely applied to anomaly-based network intrusion detection system (NIDS) to detect malicious traffic. To expand the usage scenarios of DL-based methods, federated learning (FL) allows multiple users to train a global model on the basis of respecting individual data privacy. However, it has not yet been systematically evaluated how robust FL-based NIDSs are against existing privacy attacks under existing defenses. To address this issue, we propose two privacy evaluation metrics designed for FL-based NIDSs, including (1) privacy score that evaluates the similarity between the original and recovered traffic features using reconstruction attacks, and (2) evasion rate against NIDSs using adversarial attack with the recovered traffic. We conduct experiments to illustrate that existing defenses provide little protection and the corresponding adversarial traffic can even evade the SOTA NIDS Kitsune. To defend against such attacks and build a more robust FL-based NIDS, we further propose FedDef, a novel optimization-based input perturbation defense strategy with theoretical guarantee. It achieves both high utility by minimizing the gradient distance and strong privacy protection by maximizing the input distance. We experimentally evaluate four existing defenses on four datasets and show that our defense outperforms all the baselines in terms of privacy protection with up to 7 times higher privacy score, while maintaining model accuracy loss within 3% under optimal parameter combination. Jiahui Chen 0009, Yi Zhao 0011, Qi Li 0002, Xuewei Feng, Ke Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | D3: Lightweight Secure Fault Localization in Edge CloudabstractIn pursuit of high-performance applications, the cloud is moving out of the data center and towards the edge. Secure data forwarding is critical for the users between the edge and the remote cloud. In this paper, we propose D3 (Demon Detector in Data Plane), a lightweight, secure fault localization mechanism, which can enable the users in the edge cloud to localize faulty links and thus avoid the faulty links to guarantee secure data forwarding along the path to the remote cloud. D3 utilizes the user to instruct the transit routers, thus empowering the user to detect whether the transit routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the incurred heavy storage, computation, and communication overhead, D3 offloads most of the transit router’s storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, and the extra control packet overhead is ten times less while keeping a little constant storage overhead in the data plane. The evaluations in BMv2 and Barefoot Tofino hardware show that D3 could achieve high fault localization accuracy and efficiency. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
ICDCS | 5 |
| 2022 | PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002, Baojun Liu 0002, Qiushi Yang, Hai-Xin Duan, Zhiyun Qian |
NDSS | 1 |
| 2022 | Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect Attacks
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Zhiyun Qian, Xiaohui Kuang, Chuanpu Fu, Ke Xu 0002 |
USENIX Security Symposium | 1 |
| 2022 | Off-Path TCP Hijacking Attacks via the Side Channel of Downgraded IPIDabstractIn this paper, we uncover a new off-path TCP hijacking attack that can be used to terminate victim TCP connections or inject forged data into victim TCP connections by manipulating the new mixed IPID assignment method, which is widely used in Linux kernel version 4.18 and beyond. Our attack has three steps. First, an off-path attacker can downgrade the IPID assignment for TCP packets from the more secure per-socket-based policy to the less secure hash-based policy, thus building a shared IPID counter that forms a side channel in the victim. Second, the attacker detects the presence of TCP connections by observing the side channel of the shared IPID counter. Third, the attacker infers sequence and acknowledgment numbers of the detected connection by observing the side channel. Consequently, the attacker can completely hijack the connection, e.g., resetting the connection or poisoning the data stream. We evaluate the impacts of our attack in the real world, and we uncover that more than 20% of Alexa top 100k websites are vulnerable to our attack. Our case studies of SSH DoS, manipulating web traffic, and poisoning BGP routing tables show its threat on a wide range of applications. Moreover, we demonstrate that our attack can be further extended to exploit IPv4/IPv6 dual-stack networks on increasing the hash collisions and enlarging vulnerable populations. Finally, we analyze the root cause and develop a new IPID assignment method to defeat this attack. We prototype our defense in Linux 4.18 and confirm its effectiveness in the real world. Xuewei Feng, Qi Li 0002, Kun Sun 0001, Chuanpu Fu, Ke Xu 0002 |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | Off-Path TCP Exploits of the Mixed IPID AssignmentabstractIn this paper, we uncover a new off-path TCP hijacking attack that can be used to terminate victim TCP connections or inject forged data into victim TCP connections by manipulating the new mixed IPID assignment method, which is widely used in Linux kernel version 4.18 and beyond to help defend against TCP hijacking attacks. The attack has three steps. First, an off-path attacker can downgrade the IPID assignment for TCP packets from the more secure per-socket-based policy to the less secure hash-based policy, building a shared IPID counter that forms a side channel on the victim. Second, the attacker detects the presence of TCP connections by observing the shared IPID counter on the victim. Third, the attacker infers the sequence number and the acknowledgment number of the detected connection by observing the side channel of the shared IPID counter. Consequently, the attacker can completely hijack the connection, i.e., resetting the connection or poisoning the data stream. We evaluate the impacts of this off-path TCP attack in the real world. Our case studies of SSH DoS, manipulating web traffic, and poisoning BGP routing tables show its threat on a wide range of applications. Our experimental results show that our off-path TCP attack can be constructed within 215 seconds and the success rate is over 88%. Finally, we analyze the root cause of the exploit and develop a new IPID assignment method to defeat this attack. We prototype our defense in Linux 4.18 and confirm its effectiveness through extensive evaluation over real applications on the Internet. Xuewei Feng, Chuanpu Fu, Qi Li 0002, Kun Sun 0001, Ke Xu 0002 |
CCS | 1 |
| 2020 | Enhancing Randomization Entropy of x86-64 Code while Preserving Semantic ConsistencyabstractCode randomization is considered as the basis of mitigation against code reuse attacks, fundamentally supporting some recent proposals such as execute-only memory (XOM) that aims at dynamic return-oriented programming (ROP) attacks. However, existing code randomization methods are hard to achieve a good balance between high-randomization entropy and semantic consistency. In particular, they always ignore code semantic consistency, incurring performance loss and incompatibility with current security schemes, e.g., control flow integrity (CFI). In this paper, we present an enhanced code randomization method termed as HCRESC, which can improve the randomization entropy significantly, meanwhile ensure the semantic consistency between variants and the original code. HCRESC reschedules instructions within the range of functions rather than basic blocks, thus producing more variants of the original code and preserving the code's semantic. We implement HCRESC on Linux platform of x86-64 architecture and demonstrate that HCRESC can increase the randomization entropy of x86-64 code over than 120% compared with existing methods while ensuring control flow and size of the code unaltered. Xuewei Feng, Dongxia Wang 0001, Zhechao Lin, Xiaohui Kuang |
TrustCom | 1 |
| 2018 | A Comparison of Moving Target Defense StrategiesabstractThis paper focuses on discussing the strategy of moving target defense (MTD) system. We divide the strategies of MTD system into two categories: User-relevant strategy and User-irrelevant strategy. Also we analyze the two strategies, and give the more detailed classifications of two strategies. In addition, we discuss each detailed classifications of strategies, and make a comparison between these strategies. The comparison about time complexity and enhancement of security. At last, we conduct experiments on MTD web service system and get some results. Also, we point some further research work that we can do in future. Dongxia Wang 0001, Xuewei Feng |
MASS | 3 |
| 2014 | An Approach of Discovering Causal Knowledge for Alert Correlating Based on Data MiningabstractThe process of attackers exploiting the target facilities is always gradual in cyberspace, and multiple attack steps would be performed in order to achieve the ultimate goal. How to identify the attack scenarios is one of the challenges in many research fields, such as cyberspace security situation awareness, the detection of APT (Advanced Persistent Threat) and so on. Alert correlation analysis based on causal knowledge is one of the widely adopted methods in CEP (Complex Event Processing), which is a promising way to identify multi-step attack processes and can reconstruct attack scenarios. However, current researches suffer from the problem of defining causal knowledge manually. In order to solve this problem, we propose an approach of mining for causal knowledge automatically based on the Markov property in this paper. Firstly, the raw alert stream is clustered into several alert sets, then each set is mined in order to obtain the one step transition probability matrix based on the Markov property, and after being generated, each matrix represents a piece of causal knowledge. Then we fuse the knowledge which has overlapping steps to create the knowledge base of attack patterns. Finally the experimental results show that this approach is feasible. Xuewei Feng, Dongxia Wang 0001, Minhuan Huang, Xiao Xia Sun |
DASC | 1 |
| 2011 | Research on survivability metrics based on survivable process of network systemabstractSurvivability is a necessary property of network system in disturbed environment. A survivable network always experience five phases, i.e., normal phase, resistance phase, destroyed phase, recovery phase, and adaptation and evolution phase, in its survivable process. This paper concludes the network survivability into four basic attributes: availability, controllability, robustness, and adaptability. According to these four attributes and five phases of a survivable network, this paper provides four novel quantifiable survivability metrics, i.e., Process-Weighted Average Availability (PWAA), Process-Weighted Average Controllability (PWAC), Process-Weighted Average Robustness (PWAR), and Process-Weighted Average Adaptability (PWAD). Analysis and Experiment results show that, these four quantitative metrics describe the meaning of network survivability properly, and can be used to test and evaluate survivability of network during the survivable process. Liang Ming, Minhuan Huang, Dongxia Wang 0001, Xiaohui Kuang, Xuewei Feng |
SIN | 6 |