EDBT 2026 Demo / reviewers in the wild / expert
Rongrong Xi
dblp:78/10804
· DBLP profile ↗
13ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0002-1708-1487ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PVDetector: Pretrained Vulnerability Detection on Vulnerability-enriched Code Semantic GraphabstractAutomated vulnerability detection is a critical issue in software security. The advent of Deep Learning (DL) has led to numerous studies employing DL to detect vulnerabilities in software source code. However, existing approaches still perform poorly, particularly with real-world vulnerabilities, due to the difficulty in accurately capturing their properties. To this end, we introduce PVDetector, a DL-based approach that utilizes rich code semantics, incorporates vulnerability knowledge, and leverages pretrained code representations for precise vulnerability detection. At its core, PVDetector employs a new model called Vulnerability-enriched Code Semantic Graph (VCSG), which accurately characterizes functions by distinguishing the semantics of identical variables and more finely capturing control dependencies, data dependencies, and vulnerability relationships. Additionally, we introduce four pretraining tasks specifically designed to learn the semantics of control, data, vulnerability, and variables from the VCSG model. These pretraining tasks significantly enhance PVDetector’s capability to detect vulnerabilities in downstream tasks. Experimental results indicate that PVDetector outperforms SOTAs by 5.0–12.5% in precision, 0.2–9.7% in recall, and 3.0–15.1% in F1-score. Additionally, it supports six programming languages and demonstrates high efficiency (e.g., 10.6 \(\times\) faster than DeepDFA). When applied to seven software products, PVDetector discovered 55 vulnerabilities, including 10 silently patched flaws that had not been previously reported. Jiayuan Li 0002, Lei Cui 0003, Jie Zhang 0121, Rongrong Xi, Hongsong Zhu |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2025 | LibRI: A Module Analysis Framework for Identifying Complex Reuse Relationship in BinariesabstractWith the rapid advancement of collaborative software development, the increased reuse of third-party libraries (TPLs) has introduced new security challenges. Detecting reuse relationships between binary programs and TPLs is vital for software maintenance, vulnerability tracing, and component analysis. However, most existing detection methods are confined to identifying code reuse between binaries, often misclassifying nested and pseudo-propagation reuse as direct reuse. While some methods attempt to analyze these intricate relationships, they depend on pre-collected source code structures or unstable constants, which compromises their generality and accuracy. To tackle these challenges, we introduce LibRI, a framework for identifying complex dependency relationships in C/C++ binaries. LibRI modularizes and matches binaries to analyze module-matching scenarios across multiple TPLs, accurately determining true reuse relationships and identifying original module sources. This facilitates the construction of a detailed reuse relationship graph. Experimental results show that LibRI achieves an accuracy of 0.966 in detecting actual direct reuse, significantly outperforming existing methods. In addition, LibRI is able to build a vulnerability propagation graph of TPLs, identify the propagation paths of TPL vulnerabilities, demonstrating its potential in vulnerability tracking. Wenyan Yu, Siyuan Li 0014, Mingjiang Huang, Rongrong Xi, Hongsong Zhu |
CSCWD | 5 |
| 2025 | Research on TTP Data Augmentation Methods Based on the ATT&CK FrameworkabstractAs cyber threats escalate, rapid identification and response to attacks are increasingly vital. Cyber Threat Intelli-gence (CTI) is crucial for understanding the threat landscape, and standardized attack frameworks are essential for effective anal-ysis. The MITRE ATT &CK framework has gained widespread adoption for its systematic description of Tactics, Techniques, and Procedures (TTP), aiding security teams in tracking at-tack patterns. However, manual classification of TTP is time-consuming and costly, hindering response efficiency. Although artificial intelligence has advanced automated TTP classification, accuracy still needs improvement due to the scarcity of labeled data, resulting in small and imbalanced datasets. This study introduces a novel TTP data augmentation method to enhance classification accuracy through synthetic data gen-eration. We construct a dataset of 19,716 sentences from the ATT&CK knowledge base and real-world threat reports, Ini-tially, we leverage large language models (LLMs) combined with prompt techniques to generate high-quality synthetic data, followed by semantic filtering and dynamic sampling strategies to further enhance data quality and improve class balance. Experimental results show an average$\mathbf{F}_{1}$score increase of 16.95 % across various classification models, significantly enhancing TTP classification performance. Xiaodong Xue, Jie Zhang 0121, Tianheng Qu, Rongrong Xi, Hongsong Zhu |
CSCWD | 6 |
| 2025 | HF-Mamba: Improving Multimodal Classification via Hierarchical Fusion Based on Mamba
Yimo Ren, Jinfa Wang, Hong Li 0004, Rongrong Xi, Haiqiang Fei, Hongsong Zhu |
DASFAA (2) | 4 |
| 2025 | When LLMs meet cybersecurity: a systematic literature reviewabstractAbstract The rapid development of large language models (LLMs) has opened new avenues across various fields, including cybersecurity, which faces an evolving threat landscape and demand for innovative technologies. Despite initial explorations into the application of LLMs in cybersecurity, there is a lack of a comprehensive overview of this research area. This paper addresses this gap by providing a systematic literature review, covering the analysis of over 300 works, encompassing 25 LLMs and more than 10 downstream scenarios. Our comprehensive overview addresses three key research questions: the construction of cybersecurity-oriented LLMs, the application of LLMs to various cybersecurity tasks, the challenges and further research in this area. This study aims to shed light on the extensive potential of LLMs in enhancing cybersecurity practices and serve as a valuable resource for applying LLMs in this field. We also maintain and regularly update a list of practical guides on LLMs for cybersecurity at https://github.com/tmylla/Awesome-LLM4Cybersecurity . Jie Zhang 0121, Haoyu Bu, Hui Wen 0001, Yongji Liu, Haiqiang Fei, Rongrong Xi, Hongsong Zhu |
Cybersecur. | 6 |
| 2024 | PG-AID: An Anomaly-based Intrusion Detection Method Using Provenance GraphabstractIntrusion detection is a technique used to identify malicious activities that occur in an organization’s information system, and plays a vital role for security of collaborative systems. Provenance graphs, constructed from system-level audit logs, can capture the complex relations between system entities and associate activities across the entire system, thus provide rich contextual information for intrusion detection. As a result, multiple intrusion detection methods leverage provenance graphs to detect stealthy and persistent malicious activities, known as provenancebased intrusion detection systems (PIDS). However, existing PIDS cannot detect malicious activities with fine granularity without prior knowledge of attack patterns. In this paper, we propose PG-AID, an anomaly-based intrusion detection method using provenance graph. PG-AID first converts system-level audit logs into provenance graph data, which are separated into temporal-ordered snapshots. Then to isolate intrusion-related activities, critaical paths in the snapshot are extracted, which are subsequently aggregated to get the snapshot embedding. By modeling the temporal relationships between normal snapshots, PG-AID detects abnormal graphs that exhibits different temporal relations. Finally, critical paths in the abnormal graphs are presented as intrusion indicators. We use DARPA’s (Defense Advanced Research Projects Agency) Transparent Computing (TC) datasets to evaluate PG-AID’s performance. The results show that PG-AID can effectively detect intrusions and provide detailed information about intrusions with low memory utilization. Lingxiang Meng, Rongrong Xi, Hongsong Zhu |
CSCWD | 2 |
| 2024 | Symerge: Replacing Calls in Under-Constrained Symbolic Execution and Find Vulnerabilities
Yicheng Zeng, Jiaqian Peng, Jiami Lin, Rongrong Xi, Hongsong Zhu |
SecureComm (2) | 4 |
| 2024 | TM-fuzzer: fuzzing autonomous driving systems through traffic management
Shenghao Lin, Fansong Chen, Laile Xi, Gaosheng Wang, Rongrong Xi, Yuyan Sun, Hongsong Zhu |
Autom. Softw. Eng. | 5 |
| 2023 | UID-Auto-Gen: Extracting Device Fingerprinting from Network TrafficabstractThe number of Internet device vulnerabilities has been quickly rising in recent years, rendering an explosion of network attacks. Device fingerprinting serves as the primary means for vulnerability awareness and attacker tracking. The current device fingerprinting approach can only achieve model-level identification within the Internet scope or individual-level identification for specific protocols (e.g., SSL) or scenarios (e.g., LAN). However, it is still difficult for these methods to achieve individual-level identification on a global Internet scale. In this paper, we propose a fingerprint extraction approach that is accurate to the individual level of the device by using a combination of clustering, multiple sequence alignment, and based on the geographic location stability of the device. In a continuous 3-month observation for several cities around the world, at least 1.54% of devices can be accurately extracted with unique IDs, with an accuracy rate of 99.30%, which is capable of being used in production environments. Haoyu Bin, Zhi Li 0018, Rongrong Xi, Hongsong Zhu, Limin Sun 0001 |
IPCCC | 5 |
| 2019 | Framework for risk assessment in cyber situational awarenessabstractA large number of data is generated to help network analysts to evaluate the network security situation in traditional detection and prevention measures, but it is not used fully and effectively, there is not a holistic view of the network situation on it for now. To address this issue, a framework is proposed to evaluate the security situation of the network from three dimensions: threat, vulnerability and stability, and merge the results at decision level to measure the security situation of the overall network. In the case studies, the authors demonstrate how the framework is deployed in the network and how to use it to reflect the security situation of the network in real time. Results of the case study show that the framework can evaluate the security situation of the network accurately and reasonably. Rongrong Xi, Xiao-chun Yun, Zhiyu Hao |
IET Inf. Secur. | 1 |
| 2016 | Quantitative threat situation assessment based on alert verificationabstractAbstract Traditional network threat situational assessment is based on raw alerts, not combined with contextual information, which influences the accuracy of assessment. In this paper, we propose a method to quantitatively assess network threat situation based on not only alerts but also contextual information. It firstly verifies alerts by matching alerts with contextual information to determine the successful probability of attacks, then analyzes the impact caused by attacks according to the severity and the corresponding asset value of them, and finally quantitatively assesses network threat situation based on the successful probability and the impact of attacks. Case studies show that the method can assess network threat situations more reasonably. Copyright © 2016 John Wiley & Sons, Ltd. Rongrong Xi, Xiao-chun Yun, Zhiyu Hao, Yongzheng Zhang 0002 |
Secur. Commun. Networks | 1 |
| 2011 | Network Threat Assessment Based on Alert VerificationabstractIn face of overwhelming alerts produced by firewalls or intrusion detection devices, it is difficult to assess network threats that we face. In this paper, we propose a threat assessment approach to estimate the impact of attacks on network. The approach employs the Common Vulnerability Scoring System to quantitatively assess network threats and further correlates alerts with contextual information to improve the accuracy of assessment. In the case studies, we demonstrate how the approach is applied in real networks. The experimental results show that the approach can make an accurate assessment of network threats. Rongrong Xi, Xiao-chun Yun, Shuyuan Jin, Yongzheng Zhang 0002 |
PDCAT | 1 |
| 2011 | CNSSA: A Comprehensive Network Security Situation Awareness SystemabstractWith tremendous attacks in the Internet, there is a high demand for network analysts to know about the situations of network security effectively. Traditional network security tools lack the capability of analyzing and assessing network security situations comprehensively. In this paper, we introduce a novel network situation awareness tool CNSSA (Comprehensive Network Security Situation Awareness) to perceive network security situations comprehensively. Based on the fusion of network information, CNSSA makes a quantitative assessment on the situations of network security. It visualizes the situations of network security in its multiple and various views, so that network analysts can know about the situations of network security easily and comprehensively. The case studies demonstrate how CNSSA can be deployed into a real network and how CNSSA can effectively comprehend the situation changes of network security in real time. Rongrong Xi, Shuyuan Jin, Xiao-chun Yun, Yongzheng Zhang 0002 |
TrustCom | 1 |