Qingkai Zeng 0002

dblp:66/3005-2 · DBLP profile ↗
← Back
36ranked-venue papers
0as first author
12since 2021 · last 2027
0000-0002-0610-1553ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 9 since 2021Software engineering, systems software and programming languages · 10 · 2 since 2021Artificial intelligence and machine learning · 6 · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2027 Understanding Chain-of-Thought effectiveness in code generation: an empirical and information-theoretic analysis
Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002
Empir. Softw. Eng.5
2025 MSCoT: Structured Chain-of-Thought Generation for Multiple Programming Languages
abstract
With the rapid development of code intelligence, the application of multiple programming languages is becoming increasingly widespread. However, most existing code generation models mainly focus on a single or a few programming languages, resulting in unsatisfactory performance in a multilingual environment. Chain-of-Thought (CoT) reasoning can significantly improve the performance of the model without the need for retraining or fine-tuning the code generation model by reasonably decomposing complex code generation tasks into multiple subtasks and gradually deriving solutions for each subtask. Nevertheless, the existing CoT generation methods mainly concentrate on Python code, and the performance on other programming languages remains unclear.To fill this gap, we first constructed a CoT generation dataset for 12 programming languages through multi-agent technology. On this basis, we proposed a CoT generation method MSCoT applicable to multiple programming languages. By introducing CoT into the code generation large model, the performance of the code generation large model in a multilingual environment can be improved. Through large-scale empirical research, we compared the generalization abilities of MSCoT and the existing CoT generation methods on multiple programming languages and proved the effectiveness of MSCoT for multiple programming languages. In addition, we also designed a human study to prove the quality of the CoT generated by MSCoT. Finally, we open-sourced the model and dataset of MSCoT to promote the research on CoT generation for multiple programming languages.
Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002
IJCNN4
2025 BULKHEAD: Secure, Scalable, and Efficient Kernel Compartmentalization with PKS
Yinggang Guo, Zicheng Wang 0010, Weiheng Bai, Qingkai Zeng 0002, Kangjie Lu
NDSS4
2025 GUARD: Dual-Agent based Backdoor Defense on Chain-of-Thought in Neural Code Generation
abstract
With the widespread application of large language models in code generation, recent studies demonstrate that employing additional Chain-of-Thought generation models can significantly enhance code generation performance by providing explicit reasoning steps.However, as external components, CoT models are particularly vulnerable to backdoor attacks, which existing defense mechanisms often fail to detect effectively.To address this challenge, we propose GUARD, a novel dualagent defense framework specifically designed to counter CoT backdoor attacks in neural code generation.GUARD integrates two core components: GUARD-Judge, which identifies suspicious CoT steps and potential triggers through comprehensive analysis, and GUARD-Repair, which employs a retrieval-augmented generation approach to regenerate secure CoT steps for identified anomalies.Experimental results show that GUARD effectively mitigates attacks while maintaining generation quality, advancing secure code generation systems.
Naizhu Jin, Tian Zhang 0001, Qingkai Zeng 0002
SEKE4
2023 AttnCall: Refining Indirect Call Targets in Binaries with Attention
Yinggang Guo, Zicheng Wang 0010, Qingkai Zeng 0002
ESORICS (4)4
2023 PET: Prevent Discovered Errors from Being Triggered in the Linux Kernel
Zicheng Wang 0010, Yueqi Chen 0001, Qingkai Zeng 0002
USENIX Security Symposium3
2022 Formal Modeling and Security Analysis for Intra-level Privilege Separation
abstract
Privileged system software such as mainstream operating system kernels and hypervisors have an ongoing stream of vulnerabilities. Even the inflated secure world in Trusted Execution Environment (TEE) is no longer secure in complex real-world scenarios. Since higher privilege levels cannot always be stacked to provide protection, intra-level privilege separation has become a powerful way to build trustworthy systems. However, existing intra-level privilege separation systems lack sound security analysis and cannot give formal guarantees.
Yinggang Guo, Zicheng Wang 0010, Bingnan Zhong, Qingkai Zeng 0002
ACSAC4
2022 CryptKSP: A Kernel Stack Protection Model Based on AES-NI Hardware Feature
Bingnan Zhong, Zicheng Wang 0010, Yinggang Guo, Qingkai Zeng 0002
SEC4
2022 The count-min sketch is vulnerable to offline password-guessing attacks
Jaryn Shen, Qingkai Zeng 0002
Int. J. Inf. Comput. Secur.2
2021 Catch You With Cache: Out-of-VM Introspection to Trace Malicious Executions
abstract
Out-of-VM introspection is an imperative part of security analysis. The legacy methods either modify the system, introducing enormous overhead, or rely heavily on hardware features, which are neither available nor practical in most cloud environments. In this paper, we propose a novel analysis method, named as Catcher, that utilizes CPU cache to perform out-of-VM introspection. Catcher does not make any modifications to the target program and its running environment, nor demands special hardware support. Implemented upon Linux KVM, it natively introspects the target's virtual memory. More importantly, it uses the cache-based side channel to infer the target control flow. To deal with the inherent limitations of the side channel, we propose several heuristics to improve the accuracy and stability of Catcher. Our experiments against various malware armored with packing techniques show that Catcher can recover the control flow in real time with around 67% to 97% accuracy scores. Catcher incurs a negligible overhead to the system and can be launched at anytime to monitor an ongoing attack inside a virtual machine.
Chao Su 0001, Xuhua Ding, Qingkai Zeng 0002
DSN3
2021 SecPT: Providing Efficient Page Table Protection based on SMAP Feature in an Untrusted Commodity Kernel
abstract
Page tables are one of the key data structures in OS(Operating System) kernel. It plays an extremely important role in the memory access and protection. However, the page tables are fundamental weakness of operating system because they share the same address space with the vulnerable kernel, and thus subject to kernel data-only attack. To solve that, researchers have relied on the self-protection in the same kernel privilege level without introducing higher privilege layer for efficient world switch and effective page table protection. It needs to intercept and verify every update to kernel page tables. To improve the performance, it is required to reduce the time consumed for each interception as much as possible. In this paper, we propose an architecture to provide efficient page table protection based on Supervisor-mode Access Prevention (SMAP) hardware feature and Kernel Page Table Isolation (KPTI) from an untrusted kernel. SecPT maintains the kernel page tables which are actually used by the kernel in the protection domain and prevents the compromised kernel from subverting page table protection by abusing some privileged instructions. We have realized a prototype of the SecPT. The experimental results show that SecPT provides both effective and efficient page table protection.
Bingnan Zhong, Qingkai Zeng 0002
TrustCom2
2021 Survey of CPU Cache-Based Side-Channel Attacks: Systematic Analysis, Security Models, and Countermeasures
abstract
Privacy protection is an essential part of information security. The use of shared resources demands more privacy and security protection, especially in cloud computing environments. Side-channel attacks based on CPU cache utilize shared CPU caches within the same physical device to compromise the system’s privacy (encryption keys, program status, etc.). Information is leaked through channels that are not intended to transmit information, jeopardizing system security. These attacks have the characteristics of both high concealment and high risk. Despite the improvement in architecture, which makes it more difficult to launch system intrusion and privacy leakage through traditional methods, side-channel attacks ignore those defenses because of the shared hardware. Difficult to be detected, they are much more dangerous in modern computer systems. Although some researchers focus on the survey of side-channel attacks, their study is limited to cryptographic modules such as Elliptic Curve Cryptosystems. All the discussions are based on real-world applications (e.g., Curve25519), and there is no systematic analysis for the related attack and security model. Firstly, this paper compares different types of cache-based side-channel attacks. Based on the comparison, a security model is proposed. The model describes the attacks from four key aspects, namely, vulnerability, cache type, pattern, and range. Through reviewing the corresponding defense methods, it reveals from which perspective defense strategies are effective for side-channel attacks. Finally, the challenges and research trends of CPU cache-based side-channel attacks in both attacking and defending are explored. The systematic analysis of CPU cache-based side-channel attacks highlights the fact that these attacks are more dangerous than expected. We believe our survey would draw developers’ attention to side-channel attacks and help to reduce the attack surface in the future.
Chao Su 0001, Qingkai Zeng 0002
Secur. Commun. Networks2
2019 AMOGAP: Defending Against Man-in-the-Middle and Offline Guessing Attacks on Passwords
Jaryn Shen, Timothy T. Yuen, Kim-Kwang Raymond Choo, Qingkai Zeng 0002
ACISP4
2019 CSPS: catchy short passwords making offline and online attacks impossible
abstract
This paper proposes to address online and offline attacks to passwords without increasing users' efforts in choosing and memorising their passwords. In CSPS, a password consists of two parts, a user-chosen short password and a server-generated long password. The short password should be memorised and secured by its user while the long password be encrypted and stored on the server side. To keep the secret key for protecting the long password secure, an additional sever is introduced to store the secret key and provide encryption/decryption services. On top of balloon, CSPS integrates expensive hash with secure encryption. It is mathematically proved that computationally unbounded attackers cannot succeed in offline dictionary or brute-force attacks or a combination of offline and online attacks. The criteria of security are established, which quantifies the security. To our best knowledge, CSPS is the first technique to make security quantifiable in password authentication mechanisms.
Jaryn Shen, Qingkai Zeng 0002
Int. J. Inf. Comput. Secur.2
2018 Multi-item Passphrases: A Self-adaptive Approach Against Offline Guessing Attacks
Jaryn Shen, Kim-Kwang Raymond Choo, Qingkai Zeng 0002
ICDF2C3
2018 Simulation-based security of function-hiding inner product encryption
Qingkai Zeng 0002, Ximeng Liu, Huanliang Xu
Sci. China Inf. Sci.2
2018 Improved Construction for Inner Product Functional Encryption
abstract
Functional encryption (FE) is a vast new paradigm for encryption scheme which allows tremendous flexibility in accessing encrypted data. In a FE scheme, a user can learn specific function of encrypted messages by restricted functional key and reveals nothing else about the messages. Besides the standard notion of data privacy in FE, it should protect the privacy of the function itself which is also crucial for practical applications. In this paper, we construct a secret key FE scheme for the inner product functionality using asymmetric bilinear pairing groups of prime order. Compared with the existing similar schemes, our construction reduces both necessary storage and computational complexity by a factor of 2 or more. It achieves simulation-based security, security strength which is higher than that of indistinguishability-based security, against adversaries who get hold of an unbounded number of ciphertext queries and adaptive secret key queries under the External Decisional Linear (XDLIN) assumption in the standard model. In addition, we implement the secret key inner product scheme and compare the performance with the similar schemes.
Qingkai Zeng 0002, Ximeng Liu
Secur. Commun. Networks2
2017 Efficient Inner Product Encryption with Simulation-Based Security
Qingkai Zeng 0002, Ximeng Liu
ICICS2
2017 Optimizing TLB for Access Pattern Privacy Protection in Data Outsourcing
Yao Liu 0011, Qingkai Zeng 0002, Pinghai Yuan
SecureComm2
2017 Dancing with Wolves: Towards Practical Event-driven VMM Monitoring
abstract
This paper presents a novel framework that enables practical event-driven monitoring for untrusted virtual machine monitors (VMMs) in cloud computing. Unlike previous approaches for VMM monitoring, our framework neither relies on a higher privilege level nor requires any special hardware support. Instead, we place the trusted monitor at the same privilege level and in the same address space with the untrusted VMM to achieve superior efficiency, while proposing a unique mutual-protection mechanism to ensure the integrity of the monitor. Our security analysis demonstrates that our framework can provide high-assurance for event-driven VMM monitoring, even if the highest-privilege VMM is fully compromised. The experimental results show that our framework only incurs trivial performance overhead for enforcing event-driven monitoring policies, exhibiting tremendous performance improvement on previous approaches.
Liang Deng, Peng Liu 0005, Jun Xu 0024, Ping Chen 0003, Qingkai Zeng 0002
VEE5
2016 IntEQ: recognizing benign integer overflows via equivalence checking across multiple precisions
abstract
Integer overflow (IO) vulnerabilities can be exploited by attackers to compromise computer systems. In the mean time, IOs can be used intentionally by programmers for benign purposes such as hashing and random number generation. Hence, differentiating exploitable and harmful IOs from intentional and benign ones is an important challenge. It allows reducing the number of false positives produced by IO vulnerability detection techniques, helping developers or security analysts to focus on fixing critical IOs without inspecting the numerous false alarms. The difficulty of recognizing benign IOs mainly lies in inferring the intent of programmers from source code.
Xiangyu Zhang 0001, Yunhui Zheng, Qingkai Zeng 0002
ICSE4
2016 SeededFuzz: Selecting and Generating Seeds for Directed Fuzzing
abstract
As an improvement on traditional random fuzzing, directed fuzzing utilizes dynamic taint analysis to locate regions of seed inputs which can influence security-sensitive program points, and focuses on mutating these identified regions to generate error-revealing test cases. The seed inputs are of great importance to directed fuzzing, because they essentially determine the number of security-sensitive program points we can test. In this paper, we present a seed selection method complementing with a seed generation method for directed fuzzing. Using static analysis, dynamic monitoring and symbolic execution, our approach can provide directed fuzzing with seeds that can cover more security-sensitive program points in a cost-effective way. We implemented a prototype called Seeded-Fuzz, and applied it to five real-world applications. Experimental results show that starting directed fuzzing with our carefully selected and generated seeds, Seeded-Fuzz can test more critical program sites and detect more bugs.
Qingkai Zeng 0002
TASE3
2016 Exception-oriented programming: retrofitting code-reuse attacks to construct kernel malware
abstract
Commodity operating system kernels are vulnerable to a wide range of attacks due to the large code base and broad attack surface. Mitigation mechanisms such as code signing, W⊕X, and code integrity protection have raised the bar for kernel security. In turn, attack mechanisms have also become increasingly advanced. They have evolved from simple injection of malicious code into more sophisticated code‐reuse attacks [e.g. return‐oriented programming (ROP)]. In this study, the authors describe exception‐oriented programming (EOP), a novel code‐reuse method to construct kernel malware. Unlike previous ROP that can only reuse a limited part of existing code (gadgets), EOP is able to reuse any instruction in existing code and chain the instructions in any order to generate malicious programmes. As a result, EOP can provide the attackers with more powerful capabilities and less complexity for building kernel malware.
Liang Deng, Qingkai Zeng 0002
IET Inf. Secur.2
2015 Efficient Dynamic Tracking Technique for Detecting Integer-Overflow-to-Buffer-Overflow Vulnerability
abstract
Integer-Overflow-to-Buffer-Overflow (IO2BO) vulnerabilities can be exploited by attackers to cause severe damages to computer systems. In this paper, we present the design and implementation of IntTracker, an efficient dynamic tracking technique for detecting IO2BO vulnerabilities in C/C++ programs. IntTracker utilizes a static taint analysis to select potential overflow sites that are integer operations along critical paths, from sources that are program points reading values from users, to sinks that are memory allocation sites. It then instruments overflow checks at the selected sites. Instead of producing warnings once integer overflows occur, IntTracker replaces the overflown value with a very large and rarely used integer value (dirty value), and treats such the value as an overflow tag. Tag propagation is performed by the existing program operations without any instrumentation as operations on dirty values often produce dirty values. Propagation can be automatically cut off by sanitization routines as they could prevent dirty values from affecting further program execution. IntTracker monitors whether any dirty value is used at a sink to detect IO2BO vulnerabilities. We evaluate IntTracker on 3444 programs of the NIST's SAMATE reference dataset, the SPEC CINT2000 benchmarks and 34 IO2BO bugs in real world. The experimental results show that IntTracker is effective in detecting harmful IO2BO vulnerabilities while bypassing false positives introduced by sanitization routines. Meanwhile, the runtime overhead is negligible, averaging about 0.69%. In contrast, IntPatch, the state of the art, produces a lot more false positives and has a higher overhead.
Xiangyu Zhang 0001, Chao Su 0001, Qingkai Zeng 0002
AsiaCCS4
2015 Hardware-Assisted Fine-Grained Code-Reuse Attack Detection
Pinghai Yuan, Qingkai Zeng 0002, Xuhua Ding
RAID2
2015 ISboxing: An Instruction Substitution Based Data Sandboxing for x86 Untrusted Libraries
Liang Deng, Qingkai Zeng 0002, Yao Liu 0011
SEC2
2015 Improving the Accuracy of Integer Signedness Error Detection Using Data Flow Analysis
abstract
Integer signedness error can be exploited by attackers to cause severe damages to computer systems.Despite of the significant advances in automating the detection of integer signedness errors, accurately differentiating exploitable and harmful signedness errors from unharmful ones still remains an open problem.In this paper, we present the design and implementation of SignFlow, an instrumentation-based integer signedness error detector to reduce the reports for unharmful signedness errors without sacrificing the completeness (i.e.no false negatives).SignFlow utilizes static data flow analysis to identify unharmful integer signedness conversions from the view of where the operands originate and whether the data after conversions can propagate to security-related operations, and then inserts security checks for the remaining conversions so as to accomplish runtime protection.We evaluated SignFlow on 7 real-world harmful integer signedness bugs, SPECint 2006 benchmarks together with 5 real-world applications.Experimental results show that SignFlow successfully detected all harmful integer signedness bugs and achieved a reduction of 41% in false positives over IntFlow, the state-of-the-art signedness error detector.
Chao Su 0001, Qingkai Zeng 0002
SEKE4
2015 Statically-Guided Fork-based Symbolic Execution for Vulnerability Detection
abstract
Fork-based symbolic execution would waste large amounts of computing time and resource on invulnerable paths when applied to vulnerability detection.In this paper, we propose a statically-guided fork-based symbolic execution technique for vulnerability detection to mitigate this problem.In static analysis, we collect all valid jumps along vulnerable paths, and define the priority for each program branch based on the ratio of vulnerable paths over total paths in its subsequent program.In fork-based symbolic execution, path exploration can be restricted to vulnerable paths, and code segments with higher proportion of vulnerable paths can be analyzed in advance by utilizing the result of static analysis.We implement a prototype named SAF-SE and evaluate it with ten benchmarks from GNU Coreutils version 6.11.Experimental results show that SAF-SE outperforms KLEE in the efficiency and accuracy of vulnerability detection.
Qingkai Zeng 0002
SEKE3
2015 Evaluating Initial Inputs for Concolic Testing
abstract
Concolic testing is a powerful technique for vulnerability detection. Current concolic testing tools usually randomly select one well-formed concrete input to start their workflow, then employ different path selection methods to explore the execution space. However, experiments have shown that concolic testing tools have different vulnerability detection performance when starting with different well-formed concrete inputs. In this paper, we present an evaluation method to help concolic testing tools select better initial inputs. The key idea is that: if the concolic execution triggered by one candidate initial input covers more error-prone operations with different execution contexts, it is likely to detect more bugs. Specifically, we firstly identify error-prone operations using fine-grained dynamic taint analysis. Then we propose a scoring algorithm to evaluate the vulnerability detection ability of different candidate initial inputs. We implemented this method in a new tool called CrashFinderHB, and applied it to four applications in Linux: readelf, convert, cjpeg, swftool. Experimental results show that using our evaluation method to select starting points can improve the effectiveness of concolic testing. Moreover, starting with carefully selected initial inputs, we found 4 previously unknown errors in readelf and convert.
Qingkai Zeng 0002
TASE2
2015 Improving the Accuracy of Integer Signedness Error Detection Using Data Flow Analysis
abstract
Integer signedness errors can be exploited by adversaries to cause severe damages to computer systems. Despite the significant advances in automating the detection of integer signedness errors, accurately differentiating exploitable and harmful signedness errors from unharmful ones is an important challenge. In this paper, we present the design and implementation of SignFlow, an instrumentation-based integer signedness error detector to reduce the reports for unharmful signedness errors. SignFlow first utilizes static data flow analysis to identify unharmful integer sign conversions from the view of where the source operands originate and whether the conversion results can propagate to security-related program points, and then inserts security checks for the remaining conversions so as to accomplish runtime protection. We evaluated SignFlow on 8 real-world harmful integer signedness bugs, SPECint 2006 benchmarks together with 5 real-world applications. The experimental results show that SignFlow correctly detected all harmful integer signedness bugs (i.e. no false negatives) and achieved a reduction of 41% in false positives over IntFlow, the state of the art.
Chao Su 0001, Qingkai Zeng 0002
Int. J. Softw. Eng. Knowl. Eng.4
2014 Using Machine Language Model for Mimimorphic Malware Detection
Pinghai Yuan, Qingkai Zeng 0002, Yao Liu 0011
ISC2
2014 EqualVisor: Providing Memory Protection in an Untrusted Commodity Hypervisor
abstract
In cloud computing, hypervisor is the all-powerful software running in the highest privilege layer, thus attackers who compromise a hypervisor may jeopardize the whole cloud, especially cause memory corruption of any sensitive workloads within the cloud. In this paper, we propose a novel architecture and approach to provide memory protection from an untrusted hypervisor on current x86 platforms. Unlike previous approaches such as nested virtualization, we do not place another higher privilege TCB below the hypervisor. Instead, our approach introduces a properly isolated tiny TCB running in the same privilege level and the same address space with the hypervisor, and uses this TCB to intercept and validate hypervisor's privilege actions for memory protection. In this way, we can enforce further memory security policies only relying on the TCB even if the hypervisor is fully compromised.
Liang Deng, Qingkai Zeng 0002, Yao Liu 0011
TrustCom2
2010 Towards a Structured Model for Software Vulnerabilities
Yisha Lu, Qingkai Zeng 0002
SEKE3
2010 Some Improvements for More Precise Model Checking
Qingkai Zeng 0002
SEKE2
2009 A Security Calculus of Concurrent Objects for Verifying Ad Hoc Network Protocols
abstract
We present a calculus of concurrent objects for specification and security analysis of ad hoc security protocols. The communicating nodes and the network are modeled by objects, while the interactions between them are modeled by asynchronous method invocations. The internal state of an object is represented by a constant method which can be overridden. The approach is complemented by a control flow analysis which can be used to automatically check properties such as security routing. The attacker model is integrated into the analysis as set values containing the knowledge of the attacker.
Qingkai Zeng 0002
NSS2
2004 An Adaptive Routing Strategy Based on Dynamic Cache in Mobile Ad Hoc Networks
YueQuan Chen, Qingkai Zeng 0002, Guihai Chen
ISPA3