Xin Liu 0042

dblp:76/1820-42 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0003-3051-4793ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 2 first-author · 3 since 2021Security and privacy · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 MalPDT: Backdoor Attack Against Static Malware Detection With Plug-and-Play Dynamic Triggers
abstract
The Deep Neural Network (DNN) based detection model’s dependency on third-party crowdsourced sources poses a new security threat from backdoor attacks against malware detectors. Attackers attempt to inject hidden backdoors into the target model, allowing it to perform well on clean samples. Once the attacker-defined trigger activates the hidden backdoor, the model predictions for poisoned samples are maliciously altered. Different from existing backdoor attacks either utilize fixed triggers or generate sample-specific triggers, we explore a novel backdoor attack paradigm in malware domain and propose MalPDT, in which backdoor triggers achieve dynamic variability in trigger patterns and retain compatibility across malware samples. We train a generator capable of hiding information to produce dynamically variable encoded byte segments, which are then injected as triggers into the unused regions of PE malware in a functionality-preserving manner. In MalPDT, any combination of a malware sample and a trigger can form a poisoned sample capable of activating the backdoor, enabling plug-and-play capability. We conduct extensive experiments to validate the effectiveness of MalPDT in attacking models with or without defenses.
Dazhi Zhan, Xin Liu 0042, Zhisong Pan 0003, Shize Guo
IEEE Trans. Computers3
2026 Optimizing the Adversarial Perturbation With a Momentum-Based Adaptive Matrix
abstract
Generating adversarial examples (AEs) can be formulated as an optimization problem. Among various optimization-based attacks, the gradient-based PGD and the momentum-based MI-FGSM have garnered considerable interest. However, all these attacks use the sign function to scale their perturbations, which raises several theoretical concerns from the point of view of optimization. In this paper, we first reveal that PGD is actually a specific reformulation of the projected gradient method using only the current gradient to determine its step-size. Further, we show that when we utilize a conventional adaptive matrix with the accumulated gradients to scale the perturbation, PGD becomes AdaGrad. Motivated by this analysis, we present a novel momentum-based attack AdaMI, in which the perturbation is optimized with an interesting momentum-based adaptive matrix. AdaMI is proved to attain optimal convergence for convex problems, indicating that it addresses the non-convergence issue of MI-FGSM, thereby ensuring stability of the optimization process. The experiments demonstrate that the proposed momentum-based adaptive matrix can serve as a general and effective technique to boost adversarial transferability over the state-of-the-art methods across different networks while maintaining better stability and imperceptibility.
Wei Tao 0002, Xin Liu 0042, Wei Li 0116, Qing Tao 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Practical clean-label backdoor attack against static malware detection
Dazhi Zhan, Xin Liu 0042, Tong Han, Zhisong Pan 0003, Shize Guo
Comput. Secur.3
2025 GAME-RL: Generating Adversarial Malware Examples Against API Call Based Detection via Reinforcement Learning
abstract
The adversarial example presents new security threats to trustworthy detection systems. In the context of evading dynamic detection based on API call sequences, a practical approach involves inserting perturbing API calls to modify these sequences. The type of inserted API calls and their insertion locations are crucial for generating an effective adversarial API call sequence. Existing methods either optimize the inserted API calls while neglecting the insertion positions or treat these optimizations as separate processes. This can lead to inefficient attacks that insert a large number of unnecessary API calls. To address this issue, we propose a novel reinforcement learning (RL) framework, dubbed GAME-RL, which simultaneously optimizes both the perturbing APIs and their insertion positions. Specifically, we define malware modification through IAT (Import Address Table) hooking as a sequential decision-making process. We introduce an invalid action masking and an auto-regressive policy head within the RL framework, ensuring the feasibility of IAT hooking and capturing the inherent relationship between factors. GAME-RL learns more effective evasion strategies, taking into account functionality preservation and the black-box setting. We conduct comprehensive experiments on various target models, demonstrating that GAME-RL significantly improves the evasion rate while maintaining acceptable levels of adversarial overhead.
Dazhi Zhan, Xin Liu 0042, Wei Li 0116, Shize Guo, Zhisong Pan 0003
IEEE Trans. Dependable Secur. Comput.2
2024 Provable Acceleration of Nesterov's Accelerated Gradient Method over Heavy Ball Method in Training Over-Parameterized Neural Networks
Xin Liu 0042, Wei Tao 0002, Wei Li 0116, Dazhi Zhan, Zhisong Pan 0003
IJCAI1
2024 Location and time embedded feature representation for spatiotemporal traffic prediction
Wei Li 0116, Xin Liu 0042, Wei Tao 0002, Lei Zhang 0126, Junhua Zou, Zhisong Pan 0002
Expert Syst. Appl.2
2023 PSP-Mal: Evading Malware Detection via Prioritized Experience-based Reinforcement Learning with Shapley Prior
abstract
With the widespread application of machine learning techniques in malware detection, researchers have proposed various adversarial attack methods to generate adversarial examples (AEs) of malware, thereby evading detection. Previous studies have shown that the reinforcement learning (RL) framework can enable black-box attacks by performing a sequence of function-preserving operations, which produces functional evasive malware samples. However, it is difficult to obtain the useful guidance and feedbacks from the environment for agent training in the black-box scenario, which results in the RL framework being unable to learn the effective evasion policy. In this paper, we propose the Shapley prior and establish a prior-guidance-based RL framework, namely PSP-Mal, to generate AEs against Portable Executable (PE) malware detectors. Our framework improves on existing methods in three aspects: 1) We explore feature effects of the black-box model by computing Shapley values and further propose the Shapley prior to represent the expected impact of operations. 2) A novel prioritized experience utilization mechanism is established regarding the Shapley prior guidance in the RL framework. 3) The actions are expanded into item-content pairs and we use the Thompson sampling to choose effective content, which helps to reduce randomness and ensure repeatability. We compare the attack performance of our framework with other methods, and experimental results demonstrate that our algorithm is more effective. The evasion rates of PSP-Mal against the LightGBM models trained on EMBER and SOREL-20M reach 76.88% and 72.03%, respectively.
Dazhi Zhan, Xin Liu 0042, Yue Hu 0016, Lei Zhang 0126, Shize Guo, Zhisong Pan 0003
ACSAC3
2023 Distributed One-Pass Online AUC Maximization
Xin Liu 0042
Discret. Appl. Math.1
2022 A convergence analysis of Nesterov's accelerated gradient method in training deep linear neural networks
Xin Liu 0042, Wei Tao 0002
Inf. Sci.1
2022 Provable convergence of Nesterov's accelerated gradient method for over-parameterized neural networks
Xin Liu 0042, Wei Tao 0002
Knowl. Based Syst.1
2020 Improving the Transferability of Adversarial Examples with Resized-Diverse-Inputs, Diversity-Ensemble and Region Fitting
Junhua Zou, Zhisong Pan 0003, Junyang Qiu, Xin Liu 0042, Ting Rui, Wei Li 0116
ECCV (22)4