EDBT 2026 Demo / reviewers in the wild / expert
Qiang Zeng 0001
dblp:81/583-1
· DBLP profile ↗
55ranked-venue papers
9as first author
31since 2021 · last 2026
0000-0001-9432-6017ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 4 first-author · 21 since 2021Systems, architecture and hardware · 11 · 5 first-author · 4 since 2021Computer networks · 10 · 6 since 2021Software engineering, systems software and programming languages · 3 · 3 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Meta-Architecture Binary Code Analysis
Chenfeng Duan, Qiang Zeng 0001, Lannan Luo |
DSN | 3 |
| 2026 | Zero-Shot Vulnerability Detection in Low-Resource Smart Contracts Through Solidity-Only Training
Qiang Zeng 0001, Lannan Luo |
DSN | 2 |
| 2026 | Diversified Neural Networks: Defeating Adversarial Attacks via Numerous Orthogonal Variants
Qiang Zeng 0001 |
MobiSys | 2 |
| 2026 | Model Reuse Through Retargeted-Architecture Binary Code AnalysisabstractNLP-inspired deep learning for binary code analysis demonstrates notable performance. Considering the diverse Instruction Set Architectures (ISAs) on the market, it is important to be able to analyze code of various ISAs. However, training a deep learning model usually requires a large amount of data, which poses a challenge for certain ISAs such as PowerPC that suffer from the “data scarcity” issue. For instance, acquiring a large dataset of PowerPC malware proves to be challenging. Moreover, given a binary analysis task and multiple ISAs, it takes much time and effort (e.g., for data collection, labeling and cleaning, and parameter tuning) to train one modelperISA. We propose a new direction,retargeted-architecture binary code analysis, to handle the data scarcity issue and alleviate the per-ISA effort. Our idea is totransfer knowledge from one ISA to others—that is, a model, trained with rich data and much time and effort for one ISA, can perform prediction for otherswithout any modification. We showcase the idea through two important tasks: malware detection and function similarity detection. An extensive evaluation involving four ISAs (x86, ARM, MIPS, and PowerPC) demonstrates the effectiveness of the approach and the high performance is interpreted. Chenfeng Duan, Chuxiong Wu, Qiang Zeng 0001, Lannan Luo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Touch to Pair: Secure and Usable IoT Pairing Without Information LossabstractSecure pairing is crucial for ensuring the trustwor thy deployment and operation of Internet of Things (IoT) devices. However, traditional pairing methods are often unsuitable for IoT devices due to their lack of conventional user interfaces, such as keyboards. Proximity-based pairing approaches are usable but vulnerable to exploitation by co-located malicious devices. While methods based on a user's physical operations (such as shaking) on IoT devices offer greater security, they typically rely on inertial sensors to sense the operations, which most IoT devices lack. We introduce a novel technique calledUniversal Operation Sensing, enabling IoT devices to sense the user's physical operations without the need for inertial sensors. With this technique, users can complete pairing within seconds using simple actions such as pressing a button or twisting a knob, whether they are holding a smartphone or wearing a smartwatch. Moreover, we identify an inaccuracy issue caused by information loss in the commonly used fuzzy commitment protocol. To address it, we propose an accurate pairing protocol, without using fuzzy commitment, that incurszeroinformation loss. The comprehensive evaluation shows that it is secure, usable and efficient. Chuxiong Wu, Xiaopeng Li 0001, Lannan Luo, Qiang Zeng 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Backdoor Attacks on Neural Networks Via One-Bit Flip
Lannan Luo, Qiang Zeng 0001 |
ICCV | 3 |
| 2025 | LLM-Assisted IoT Testing: Finding Conformance Bugs in Matter SDKsabstractMatter is an IoT standard endorsed by hundreds of companies, designed to ensure interoperability between devices from various vendors. The Matter Software Development Kit (SDK) serves as the foundation for developing Matter devices, making bug discovery in Matter SDKs crucial. Given the extensive specification and the rapid evolution of Matter—five versions released in just two and a half years—the need for automated solutions is increasingly urgent. In this paper, we present MatterGuard, the first automated system for identifying bugs in Matter SDKs that violate the specification. Unlike traditional SDK testing approaches, which typically integrate testing code with the SDK code, Matter-Guard decouples the two, allowing the testing code to be reused across SDK versions. Furthermore, MatterGuard leverages a large language model to analyze the Matter specification and uses the extracted knowledge to guide the bug discovery process. In our evaluation across all five SDK versions, MatterGuard uncovers 109 bugs, demonstrating the effectiveness and scalability of our approach. Lannan Luo, Qiang Zeng 0001 |
MobiCom | 4 |
| 2025 | Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root Privileges
Lannan Luo, Qiang Zeng 0001 |
USENIX Security Symposium | 4 |
| 2025 | Rowhammer-Based Trojan Injection: One Bit Flip Is Sufficient for Backdooring DNNs
Lannan Luo, Qiang Zeng 0001 |
USENIX Security Symposium | 5 |
| 2025 | Small-Gain Method-Based Adaptive Fuzzy Output Feedback Control for Nonlinear Systems With Irregular ConstraintsabstractAn adaptive irregular constraint control problem is investigated in this study based on an output feedback control strategy. Nonlinear systems with irregular constraints are widely used in engineering fields such as the robot flexible operation. We consider such constraints referring to ones that may not only be asymmetric, but may also emerge in stages, or even be positive and negative at times. Ancillary constraint boundaries, which extend the originally imposed constraints to the full period of the system operation, are designed to accommodate the irregular constraints. Furthermore, the state observer is used to calculate the unmeasured states. Meanwhile, to get past the constraint that the nonlinearities in the system rely exclusively on the measured output, we employ the small-gain approach. Through the utilization of the input-state-practically stability (ISpS) theory, it is demonstrated that when the recommended adaptive control technique is applied, the system is semiglobal stable. Also, the output of the system follows the relevant trajectory. The validation of the findings from the simulation further highlights the advantages of the advised control program. Lei Liu 0006, Zhaoxia Liu, Qiang Zeng 0001, Yan-Jun Liu 0003 |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2024 | BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
Fei Zuo, Cody Tompkins, Qiang Zeng 0001, Lannan Luo, Yung Ryn Choe, Junghwan Rhee |
SecureComm (3) | 3 |
| 2024 | From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT Devices
Lannan Luo, Qiang Zeng 0001 |
USENIX Security Symposium | 3 |
| 2024 | Do You See How I Pose? Using Poses as an Implicit Authentication Factor for QR Code Payment
Chuxiong Wu, Qiang Zeng 0001 |
USENIX Security Symposium | 2 |
| 2024 | Seeing Is Believing: Extracting Semantic Information from Video for Verifying IoT EventsabstractAlong with the increasing popularity of smart home IoT devices, more users are turning to smart home automation platforms to control and automate their IoT devices. However, IoT automation is vulnerable to spoofed event attacks. Given that IoT devices are intricately linked with the physical environment and operate autonomously, event-based attacks can pose serious safety and security challenges. Our observations show that many IoT events are accompanied by visual modifications in objects such as shape alterations (for example, contact sensor events correspond with door movement) or changes in color/brightness (for example, a functioning microwave oven with the internal light switched on). These alterations can be detected by the commonly deployed smart cameras, providing a visually rich but challenging to manipulate channel for verifying IoT events. We introduce IoTSentry, the first system of its kind to extract high-level semantic information from streaming video data and pixels for IoT event verification. We have designed a Siamese deep neural network to identify variations in the appearance of IoT devices and interior objects. These are used as the yardstick for verifying IoT events received at IoT automation platforms. Upon assessing IoTSentry with 21 IoT devices (8 types), the results demonstrate that IoTSentry can be trained within 120 seconds, yielding an accuracy rate of over 96.7% in recognizing device states. We have deployed the 21 IoT devices and IoTSentry on two real-world smart home test sites. Over the course of our one-week evaluation, IoTSentry consistently achieved an average detection rate of 99.24% in identifying attack instances. Moreover, it triggered no more than 2 false alarms per day on each test site. Chenglong Fu 0002, Xiaojiang Du, Qiang Zeng 0001, Fei Zuo, Jia Di |
WISEC | 3 |
| 2024 | Turning Noises to Fingerprint-Free "Credentials": Secure and Usable Drone AuthenticationabstractDrones have been widely used in various services, such as delivery and surveillance. Authentication forms the foundation of the security of these services. However, drones are expensive and may carry important payloads. To avoid being captured by attackers, drones should keep a safe distance from the verifier before authentication succeeds. This makes authentication methods that only work in very close proximity not applicable. Our work leverages drone noises for authentication. While using sounds for authentication is highly usable, how to handle various attacks that manipulate sounds is an unresolved challenge. It is also unclear how to ensure robustness under various environmental sounds. Being the first in the literature, we address the two major challenges by exploiting unique characteristics of drone noises. We thereby build an authentication system that does not rely on any drone sound fingerprints, keeps resilient to attacks, and is robust under environmental sounds. An extensive evaluation demonstrates its security and usability. Chuxiong Wu, Qiang Zeng 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | No More Companion Apps Hacking but One Dongle: Hub-Based Blackbox Fuzzing of IoT FirmwareabstractGiven the massive difficulty in emulating IoT firmware, blackbox fuzzing of IoT devices for vulnerability discovery has become an attractive option. However, existing blackbox IoT fuzzers need much time and tedious effort to reverse engineer the IoT companion app (or manually collect test scripts) of each IoT device, which is unscalable when analyzing many devices. Moreover, fuzzing through a companion app is impeded by the input sanitization inside the app and limited to the manually revealed functions. We notice that IoT devices are typically able to connect a hub using standard wireless protocols (such as ZigBee, Z-Wave, and WiFi). We thus propose a uniform hub-based architecture for fuzzing various IoT devices, without reverse engineering any companion apps. It exploits the messages exchanged between a hub and an IoT device to automatically discover all the functions, and then launches systematic function-oriented message-semantics-guided fuzzing. It avoids sanitization imposed by a companion app. In addition, it conducts device state-sensitive fuzzing, which we find very effective in finding IoT bugs. We implement the system named HubFuzzer. The evaluation shows that HubFuzzer leads to much higher coverage than prior state of the art. We test 21 IoT devices and find 23 zero-day vulnerabilities. Four CVEs have been assigned. Qiang Zeng 0001, Haotian Chi, Lannan Luo |
MobiSys | 2 |
| 2023 | Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart Homes
Haotian Chi, Qiang Zeng 0001, Xiaojiang Du |
USENIX Security Symposium | 2 |
| 2023 | Can a Deep Learning Model for One Architecture Be Used for Others? Retargeted-Architecture Binary Code Analysis
Matthew Sharp, Chuxiong Wu, Qiang Zeng 0001, Lannan Luo |
USENIX Security Symposium | 4 |
| 2023 | Easy Peasy: A New Handy Method for Pairing Multiple COTS IoT DevicesabstractContext-based paring is a promising direction for pairing IoT devices constrained in user interfaces (UIs). However, it takes a proximate distance or a long time for IoT devices to sense highly correlated context with enough entropy. In this work, we present a fast and secure approach, namedMPairing, to pairing multiple commercial off-the-shelf (COTS) IoT devices. This approach is based on the key idea that devices co-located within aphysically-secure boundarycan perceive qualified context under the help of human-in-the-loop (HITL). Specifically, we leverage received-signal-strength (RSS) trajectory data with manually-generated interference in a short period as the shared secret to achieve fast and secure pairing. Subsequently, the real-time RSS trajectory data is utilized to generate random numbers in lieu of pre-shared key (PSK), which makes our scheme more resistant to background attacks. We theoretically prove the security of our pairing scheme and implement it in real-world environments. Our experimental results demonstrate that our scheme can effectively defend against malicious devices by imposing a threshold on the similarity of RSS trajectory data. The experimental results also show that, compared with the traditional context-based pairing that takes up to 24 hours, in our scheme it takes only 10 seconds on average for a legitimate device to pass the similarity checking, which is efficient and robust. Heng Ye, Qiang Zeng 0001, Jiqiang Liu, Xiaojiang Du, Wei Wang 0012 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | IoT Phantom-Delay Attacks: Demystifying and Exploiting IoT Timeout BehaviorsabstractThis paper unveils a set of new attacks against Internet of Things (IoT) automation systems. We first propose two novel IoT attack primitives: Event Message Delay and Command Message Delay (event messages are generated by IoT devices to report device states, and command messages are used to control IoT devices). Our insight is that timeout detection in the TCP layer is decoupled from data protection in the Transport Layer Security (TLS) layer. As a result, even when a session is protected by TLS, its IoT event and/or command messages can still be significantly delayed without triggering alerts. It is worth highlighting that, by compromising/controlling one WiFi device in a smart environment, the attacker can delay the IoT messages of other non-compromised IoT devices; we thus call the attacks IoT Phantom-Delay Attacks. Our study shows the attack primitives can be used to build rich attacks and some of them can induce persistent effects. The presented attacks are very different from jamming. 1) Unlike jamming, our attacks do not discard any packets and thus do not trigger re-transmission. 2) Our attacks do not cause disconnection or timeout alerts. 3) Unlike reactive jamming, which usually relies on special hardware, our attacks can be launched from an ordinary WiFi device. Our evaluation involves 50 popular IoT devices and demonstrates that they are all vulnerable to the phantom-delay attacks. Finally, we discuss the countermeasures. We have contacted multiple IoT platforms regarding the vulnerable IoT timeout behaviors, and Google, Ring and SimpliSafe have acknowledged the problem. Chenglong Fu 0002, Qiang Zeng 0001, Haotian Chi, Xiaojiang Du, Siva Likitha Valluru |
DSN | 2 |
| 2022 | Authentication for drone delivery through a novel way of using face biometricsabstractDrone delivery, which makes use of unmanned aerial vehicles (UAVs) to deliver or pick up packages, is an emerging service. To ensure that a package is picked up by a legitimate drone and delivered to the correct user, mutual authentication between drones and users is critical. As delivery drones are expensive and may carry important packages, drones should keep a distance from users until the authentication succeeds. Thus, authentication approaches that require human-drone physical contact cannot be applied. Face recognition does not need human-drone contact. However, it has major limitations: (1) it needs users to enroll their face information, (2) it is vulnerable to attacks, such as 3D-printed masks and adversarial examples, and (3) it only supports a drone to authenticate a user (rather than mutual authentication). We propose a novel way of using face biometrics, without these limitations, and apply it to building an authentication system for drone delivery, named Smile2Auth. The evaluation shows that Smile2Auth is highly accurate, secure and usable. Jonathan Sharp, Chuxiong Wu, Qiang Zeng 0001 |
MobiCom | 3 |
| 2022 | G2Auth: secure mutual authentication for drone delivery without special user-side hardwareabstractBecause of its cost effectiveness and timeliness, package delivery using unmanned aerial vehicles (UAVs), called drone delivery, is drawing growing attention. Authentication is critical for ensuring that a package is not picked up by an attacker's drone or delivered to an attacker. As delivery drones are costly and may carry sensitive or expensive packages, a drone should not get very close to a person unless she is authenticated; thus, conventional authentication approaches that require human-drone physical contact do not work. Existing authentication methods for drone delivery suffer from one or multiple of the following limitations: (1) requiring special user-side hardware; (2) enforcing one-way authentication only; (3) being vulnerable to relay attacks; (4) having compatibility issues. We present the first system, named Greet-to-Auth (G2Auth, for short), that supports mutual authentication between a user and a drone, without these limitations. A user waves her hand holding a smartphone to conduct the authentication. The evaluation shows that it is secure, accurate, usable, and robust. Chuxiong Wu, Xiaopeng Li 0001, Lannan Luo, Qiang Zeng 0001 |
MobiSys | 4 |
| 2022 | Delay Wreaks Havoc on Your Smart Home: Delay-based Automation Interference AttacksabstractWith the proliferation of Internet of Things (IoT) devices and platforms, it becomes a trend that IoT devices associated with different IoT platforms coexist in a smart home, demonstrating the following characteristics. First, a smart home may use more than one platform to support its devices and automation. Second, IoT devices of a home may transmit messages over different paths. By selectively delaying IoT messages, our study finds that two issues, inconsistency and disorder, can be exacerbated by attackers significantly. We then explore how these issues can be exploited and present seven types of exploitation, collectively referred to as Delay-based Automation Interference (DAI) attacks. DAI attacks cause home automation to yield incorrect interaction results, placing the IoT devices and smart home in insecure, unsafe, or unexpected states. It is worth highlighting that DAI attacks do not depend on any IoT implementation vulnerabilities or leaked keys/tokens, and they do not trigger alarms at any layers of the IoT protocol stack. To demonstrate and evaluate the new attacks, we set up two real-world testbeds, where commercial IoT devices and apps are deployed. The week-long experiments from both testbeds show that an attacker has adequate opportunities to launch DAI attacks that cause security or safety issues. Haotian Chi, Chenglong Fu 0002, Qiang Zeng 0001, Xiaojiang Du |
SP | 3 |
| 2022 | Semi-Synchronized Non-Blocking Concurrent Kernel CruisingabstractKernel heap buffer overflow vulnerabilities have been exposed for decades, but there are few practical countermeasures that can be applied to OS kernels. Previous solutions either suffer from high performance overhead or compatibility problems with mainstream kernels and hardware. In this article, we presentKruiser, a concurrent kernel heap buffer overflow monitor. Unlike conventional methods, the security enforcement of which is usually inlined into the kernel execution, Kruiser migrates security enforcement from the kernel’s normal execution to a concurrent monitor process, leveraging the increasingly popular multi-core architectures. To reduce the synchronization overhead between the monitor process and the running kernel, we design a novel semi-synchronized non-blocking monitoring algorithm, which enables efficient runtime detection on live memory without incurring false positives. To prevent the monitor process from being tampered and provide guaranteed performance isolation, we utilize the virtualization technology to run the monitor process out of the monitored VM, while heap memory allocation information is collected inside the monitored VM in a secure and efficient way. The hybrid VM monitoring technique combined with the secure canary that cannot be counterfeited by attackers provides guaranteed overflow detection with high efficiency. We have implemented a prototype ofKruiserbased on Linux and the Xen/KVM hypervisor. The evaluation shows that Kruiser can detect realistic kernel heap buffer overflow attacks in cloud environment effectively with minimal cost. Donghai Tian, Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005, Changzhen Hu |
IEEE Trans. Cloud Comput. | 2 |
| 2021 | Westworld: Fuzzing-Assisted Remote Dynamic Symbolic Execution of Smart Apps on IoT Cloud PlatformsabstractExisting symbolic execution typically assumes the analyzer can control the I/O environment and/or access the library code, which, however, is not the case when programs run on a remote proprietary execution environment managed by another party. For example, SmartThings, one of the most popular IoT platforms, is such a cloud-based execution environment. For programmers who write automation applications to be deployed on IoT cloud platforms, it raises significant challenges when they want to systematically test their code and find bugs. We propose fuzzing-assisted remote dynamic symbolic execution, which uses dynamic symbolic execution as backbone and utilizes fuzzing when necessary to automatically test programs running in a remote proprietary execution environment over which the analyzer has little control. As a case study, we enable it for analyzing smart apps running on SmartThings. We have developed a prototype and the evaluation shows that it is effective in testing smart apps and finding bugs. Lannan Luo, Qiang Zeng 0001, Fei Zuo |
ACSAC | 2 |
| 2021 | Exploiting the Sensitivity of L2 Adversarial Examples to Erase-and-RestoreabstractBy adding carefully crafted perturbations to input images, adversarial examples (AEs) can be generated to mislead neural-network-based image classifiers. L2 adversarial perturbations by Carlini and Wagner (CW) are among the most effective but difficult-to-detect attacks. While many countermeasures against AEs have been proposed, detection of adaptive CW-L2 AEs is still an open question. We find that, by randomly erasing some pixels in an L2 AE and then restoring it with an inpainting technique, the AE, before and after the steps, tends to have different classification results, while a benign sample does not show this symptom. We thus propose a novel AE detection technique, Erase-and-Restore (E&R), that exploits the intriguing sensitivity of L2 attacks. Experiments conducted on two popular image datasets, CIFAR-10 and ImageNet, show that the proposed technique is able to detect over 98% of L2 AEs and has a very low false positive rate on benign images. The detection technique exhibits high transferability: a detection system trained using CW-L2 AEs can accurately detect AEs generated using another L2 attack method. More importantly, our approach demonstrates strong resilience to adaptive L2 attacks, filling a critical gap in AE detection. Finally, we interpret the detection technique through both visualization and quantification. Fei Zuo, Qiang Zeng 0001 |
AsiaCCS | 2 |
| 2021 | PFirewall: Semantics-Aware Customizable Data Flow Control for Smart Home Privacy Protection
Haotian Chi, Qiang Zeng 0001, Xiaojiang Du, Lannan Luo |
NDSS | 2 |
| 2021 | SniffMislead: Non-Intrusive Privacy Protection against Wireless Packet Sniffers in Smart HomesabstractWith the booming deployment of smart homes, concerns about user privacy keep growing. Recent research has shown that encrypted wireless traffic of IoT devices can be exploited by packet-sniffing attacks to reveal users’ privacy-sensitive information (e.g., the time when residents leave their home and go to work), which may be used to launch further attacks (e.g., a break-in). To address the growing concerns, we propose SniffMislead, a non-intrusive (i.e., without modifying IoT devices, hubs, or platforms) privacy-protecting approach, based on packet injection, against wireless packet sniffers. Instead of randomly injecting packets, which is ineffective against a smarter attacker, SniffMislead proposes the notion of phantom users, “people” who do not exist in the physical world. From an attacker’s perspective, however, they are perceived as real users. SniffMislead places multiple phantom users in a smart home, which can effectively prevent an attacker from inferring useful information. We design a top-down approach to synthesize phantom users’ behaviors, construct the sequence of decoy device events and commands, and then inject corresponding packets into the home. We show how SniffMislead ensures logical integrity and contextual consistency of injected packets, as well as how it makes a phantom user indistinguishable from a real user. Our evaluation results from a smart home testbed demonstrate that SniffMislead significantly reduces an attacker’s privacy-inferring capabilities, bringing the accuracy from 94.8% down to 3.5%. Qiang Zeng 0001, Xiaojiang Du, Siva Likitha Valluru, Chenglong Fu 0002, Xiao Fu 0005, Bin Luo 0003 |
RAID | 2 |
| 2021 | HAWatcher: Semantics-Aware Anomaly Detection for Appified Smart Homes
Chenglong Fu 0002, Qiang Zeng 0001, Xiaojiang Du |
USENIX Security Symposium | 2 |
| 2021 | Resilient User-Side Android Application Repackaging and Tampering Detection Using Cryptographically Obfuscated Logic BombsabstractApplication repackaging is a severe threat to Android users and the market. Not only does it infringe on intellectual property, but it is also one of the most common ways of propagating mobile malware. Existing countermeasures mostly detect repackaging based on app similarity measurement, which tends to be imprecise when obfuscations are applied to repackaged apps. Moreover, they rely on a central party, typically the hosting app store, to perform the detection, but many app stores fail to commit proper effort to piracy detection. We consider building the application repackaging detection capability into apps, such that user devices are made use to detect repackaging in a decentralized fashion.The main challenge is how to protect the detection code from being manipulated by attacks. We propose a creative use oflogic bombs, which are otherwise regularly used in malware. Thetrigger conditionsof bombs are constructed to exploit the differences between the attacker and users, such that a bomb that lies dormant on the attacker side will be activated on the user side. The detection code, which is part of the bombpayload, is executed only if the bomb is activated. We introducecryptographically obfuscated logic bombto enhance the bomb: (1) the detection code iswoveninto the neighboring original app code, (2) the mixed code gets encrypted using a key, and (3) the key is deleted from the app and can only be derived when the bomb is activated. Thus, attacks that try to modify or delete the detection code will corrupt the app itself, and searching the key in the application will be in vain. Moreover, we propose abomb sprayingtechnique that allows many bombs to be injected into an app, multiplying the needed adversary effort for bypassing the detection. In addition to repackaging detection, we present application tampering detection to fight attacks that insert malicious code into repackaged apps. We have implemented a prototype, namedBombDroid, that builds repackaging and tampering detection into apps through bytecode instrumentation. The evaluation and the security analysis show that the technique is effective, efficient, and resilient to various bomb analysis techniques including fuzzing, symbolic execution, multi-path exploration, and program slicing. Ethical issues due to the use of logic bombs are also discussed. Qiang Zeng 0001, Lannan Luo, Zhiyun Qian, Xiaojiang Du, Zhoujun Li 0001, Chin-Tser Huang, Csilla Farkas |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Adaptive Vehicle Stability Control of Half-Car Active Suspension Systems With Partial Performance ConstraintsabstractA novel adaptive controller for the half-car active suspension systems (ASSs), which can improve the riding comfortability and handling stability of the driver, is proposed in this paper. By using nonlinear mapping, it is demonstrated that the nonlinear ASSs with partial performance constraints are transformed into the novel pure-feedback systems without constraints. By introducing a modified dynamic surface control (DSC) into the Lyapunov function, the adaptive neural network (NN) controller is discussed. The unknown continuous functions are estimated by the NNs, and the boundedness of all signals in the closed-loop systems is guaranteed by the Lyapunov stability theory. Meanwhile, the performance constraints are not violated. Finally, the simulations are performed to clarify and verify the effectiveness of the proposed scheme. Qiang Zeng 0001, Yan-Jun Liu 0003, Lei Liu 0006 |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2020 | Attacking Graph-Based Classification without Changing Existing ConnectionsabstractIn recent years, with the rapid development of machine learning in various domains, more and more studies have shown that machine learning models are vulnerable to adversarial attacks. However, most existing researches on adversarial machine learning study non-graph data, such as images and text. Though some previous works on graph data have shown that adversaries can make graph-based classification methods unreliable by adding perturbations to features or adjacency matrices of existing nodes, these kinds of attacks sometimes have limitations for real-world applications. For example, to launch such attacks in real social networks, the attacker cannot force two good users to change (e.g., remove) the connection between them, which means that the attacker can not launch such attacks. In this paper, we propose a novel attack on collective classification methods by adding fake nodes into existing graphs. Our attack is more realistic and practical than the attack mentioned above. For instance, in a real social network, an attacker only needs to create some fake accounts and connect them to existing users without modifying the connections among existing users. We formulate the new attack as an optimization problem and utilize a gradient-based method to generate edges of newly added fake nodes. Our extensive experiments show that the attack can not only make new fake nodes evade detection, but also make the detector misclassify most of the target nodes. The proposed new attack is very effective and can achieve up to 100% False Negative Rates (FNRs) for both the new node set and the target node set. Xuening Xu, Xiaojiang Du, Qiang Zeng 0001 |
ACSAC | 3 |
| 2020 | T2Pair: Secure and Usable Pairing for Heterogeneous IoT DevicesabstractSecure pairing is key to trustworthy deployment and application of Internet of Things (IoT) devices. However, IoT devices lack conventional user interfaces, such as keyboards and displays, which makes many traditional pairing approaches inapplicable. Proximity-based pairing approaches are very usable, but can be exploited by co-located malicious devices. Approaches based on a user's physical operations on IoT devices are more secure, but typically require inertial sensors, while many devices do not satisfy this requirement. A secure and usable pairing approach that can be applied to heterogeneous IoT devices still does not exist. We develop a technique, Universal Operation Sensing, which allows an IoT device to sense the user's physical operations on it without requiring inertial sensors. With this technique, a user holding a smartphone or wearing a wristband can finish pairing in seconds through some very simple operations, e.g., pressing a button or twisting a knob. Moreover, we reveal an inaccuracy issue in original fuzzy commitment and propose faithful fuzzy commitment to resolve it. We design a pairing protocol using faithful fuzzy commitment, and build a prototype system named Touch-to-Pair (T2Pair, for short). The comprehensive evaluation shows that it is secure and usable. Xiaopeng Li 0001, Qiang Zeng 0001, Lannan Luo, Tongbo Luo |
CCS | 2 |
| 2020 | Cross-App Interference Threats in Smart Homes: Categorization, Detection and HandlingabstractInternet of Thing platforms prosper home automation applications (apps). Prior research concerns intra-app security. Our work reveals that automation apps, even secured individually, still cause a family of threats when they interplay, termed as Cross-App Interference (CAI) threats. We systematically categorize such threats and encode them using satisfiability modulo theories (SMT). We present HomeGuard, a system for detecting and handling CAI threats in real deployments. A symbolic executor is built to extract rule semantics, and instrumentation is utilized to capture configuration during app installation. Rules and configuration are checked against SMT models, the solutions of which indicate the existence of corresponding CAI threats. We further combine app functionalities, device attributes and CAI types to label the risk level of CAI instances. In our evaluation, HomeGuard discovers 663 CAI instances from 146 SmartThings market apps, imposing minor latency upon app installation and no runtime overhead. Haotian Chi, Qiang Zeng 0001, Xiaojiang Du, Jiaping Yu |
DSN | 2 |
| 2020 | A11 Your PLCs Belong to Me: ICS Ransomware Is RealisticabstractRansomware is a new business model for cybercrime which mainly targets individual users and machines. Many events have shown how profitable the technique can be. Industrial control systems (ICS) are becoming the next domain. More and more researchers and attackers have become the focus on this field and presented some ICS ransomware. But existing ICS ransomware is theoretically feasible and has a limited effect on real ICS. In this work, we present ICS-BROCK, a full-fledged ICS ransomware that can compromise a real-world. To demonstrate the capability of ICS-BROCK, we use SIEMENS S7-300 PLC, one of the most widely used devices in ICSs, to build a real water treatment environment. The results empirically demonstrate the feasibility of launching ICS ransomware attacks in a practical setting. In the end, we give some suggestions on ICS ransomware to aid in future study and defenses. Liqun Yang, Zhoujun Li 0001, Qiang Zeng 0001, Yueying He, Xiaoming Zhang 0001 |
TrustCom | 5 |
| 2020 | Tainting-Assisted and Context-Migrated Symbolic Execution of Android Framework for Vulnerability Discovery and Exploit GenerationabstractAndroid Application Framework is an integral and foundational part of the Android system. Each of the two billion (as of 2017) Android devices relies on the system services of Android Framework to manage applications and system resources. Given its critical role, a vulnerability in the framework can be exploited to launch large-scale cyber attacks and cause severe harms to user security and privacy. Recently, many vulnerabilities in Android Framework were exposed, showing that it is indeed vulnerable and exploitable. While there is a large body of studies on Android application analysis, research on Android Framework analysis is very limited. In particular, to our knowledge, there is no prior work that investigates how to enable symbolic execution of the framework, an approach that has proven to be very powerful for vulnerability discovery and exploit generation. We design and build the first system, Centaur, that enables symbolic execution of Android Framework. Due to the middleware nature and technical peculiarities of the framework that impinge on the analysis, many unique challenges arise and are addressed in Centaur. The system has been applied to discovering new vulnerability instances, which can be exploited by recently uncovered attacks against the framework, and to generating PoC exploits. Lannan Luo, Qiang Zeng 0001, Chen Cao 0004, Kai Chen 0012, Jian Liu 0008, Neng Gao, Min Yang 0002, Xinyu Xing 0001, Peng Liu 0005 |
IEEE Trans. Mob. Comput. | 2 |
| 2020 | An Adaptive Neural Network Controller for Active Suspension Systems With Hydraulic ActuatorabstractIn this paper, an adaptive neural network (NN) controller is proposed for a class of nonlinear active suspension systems (ASSs) with hydraulic actuator. To eliminate the problem of “explosion of complexity” inherently in the traditional backstepping design for the hydraulic actuator, a dynamic surface control technique is developed to stabilize the attitude of the vehicle by introducing a first-order filter. Meanwhile, the presented scheme improves the ride comfort even when the uncertain parameter exists. Due to the existence of uncertain terms, the NNs are used to approximate unknown functions in the ASSs. Finally, a simulation for a servo system with hydraulic actuator is shown to verify the effectiveness and reliability of the proposed approach. Yan-Jun Liu 0003, Qiang Zeng 0001, Lei Liu 0006, Shaocheng Tong |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2019 | HeapTherapy+: Efficient Handling of (Almost) All Heap Vulnerabilities Using Targeted Calling-Context EncodingabstractExploitation of heap vulnerabilities has been on the rise, leading to many devastating attacks. Conventional heap patch generation is a lengthy procedure requiring intensive manual efforts. Worse, fresh patches tend to harm system dependability, hence deterring users from deploying them. We propose a heap patching system HEAPTHERAPY+ that simultaneously has the following prominent advantages: (1) generating patches without manual efforts; (2) installing patches without altering the code (so called code-less patching); (3) handling various heap vulnerability types; (4) imposing a very low overhead; and (5) no dependency on specific heap allocators. As a separate contribution, we propose targeted calling context encoding, which is a suite of algorithms for optimizing calling context encoding, an important technique with applications in many areas. The system properly combines heavyweight offline attack analysis with lightweight online defense generation, and provides a new countermeasure against heap attacks. The evaluation shows that the system is effective and efficient. Qiang Zeng 0001, Golam Kayas, Emil Mohammed, Lannan Luo, Xiaojiang Du, Junghwan Rhee |
DSN | 1 |
| 2019 | A Multiversion Programming Inspired Approach to Detecting Audio Adversarial ExamplesabstractAdversarial examples (AEs) are crafted by adding human-imperceptible perturbations to inputs such that a machine-learning based classifier incorrectly labels them. They have become a severe threat to the trustworthiness of machine learning. While AEs in the image domain have been well studied, audio AEs are less investigated. Recently, multiple techniques are proposed to generate audio AEs, which makes countermeasures against them urgent. Our experiments show that, given an audio AE, the transcription results by Automatic Speech Recognition (ASR) systems differ significantly (that is, poor transferability), as different ASR systems use different architectures, parameters, and training datasets. Based on this fact and inspired by Multiversion Programming, we propose a novel audio AE detection approach MVP-Ears, which utilizes the diverse off-the-shelf ASRs to determine whether an audio is an AE. We build the largest audio AE dataset to our knowledge, and the evaluation shows that the detection accuracy reaches 99.88%. While transferable audio AEs are difficult to generate at this moment, they may become a reality in future. We further adapt the idea above to proactively train the detection system for coping with transferable audio AEs. Thus, the proactive detection system is one giant step ahead of attackers working on transferable AEs. Qiang Zeng 0001, Jianhai Su, Chenglong Fu 0002, Golam Kayas, Lannan Luo, Xiaojiang Du, Chiu C. Tan 0001, Jie Wu 0001 |
DSN | 1 |
| 2019 | Touch Well Before Use: Intuitive and Secure Authentication for IoT DevicesabstractInternet of Things (IoT) are densely deployed in smart environments, such as homes, factories and laboratories, where many people have physical access to IoT devices. How to authenticate users operating on these devices is thus an important problem. IoT devices usually lack conventional user interfaces, such as keyboards and mice, which makes traditional authentication methods inapplicable. We present a virtual sensing technique that allows IoT devices to virtually sense user 'petting' (in the form of some very simple touches for about 2 seconds) on the devices. Based on this technique, we build a secure and intuitive authentication method that authenticates device users by comparing the petting operations sensed by devices and those captured by the user wristband. The authentication method is highly secure as physical operations are required, rather than based on proximity. It is also intuitive, adopting very simple authentication operations, e.g., clicking buttons, twisting rotary knobs, and swiping touchscreens. Unlike the state-of-the-art methods, our method does not require any hardware modifications of devices, and thus can be applied to commercial off-the-shelf (COTS) devices. We build prototypes and evaluate them comprehensively, demonstrating their high effectiveness, security, usability, and efficiency. Xiaopeng Li 0001, Fengyao Yan, Fei Zuo, Qiang Zeng 0001, Lannan Luo |
MobiCom | 4 |
| 2019 | Neural Machine Translation Inspired Binary Code Similarity Comparison beyond Function Pairs
Fei Zuo, Xiaopeng Li 0001, Patrick Young, Lannan Luo, Qiang Zeng 0001, Zhexin Zhang |
NDSS | 5 |
| 2019 | Exploiting the Inherent Limitation of L0 Adversarial Examples
Fei Zuo, Xiaopeng Li 0001, Qiang Zeng 0001 |
RAID | 4 |
| 2019 | POKs Based Secure and Energy-Efficient Access Control for Implantable Medical Devices
Chenglong Fu 0002, Xiaojiang Du, Longfei Wu, Qiang Zeng 0001, Amr Mohamed 0001, Mohsen Guizani |
SecureComm (1) | 4 |
| 2018 | Resilient decentralized Android application repackaging detection using logic bombsabstractApplication repackaging is a severe threat to Android users and the market. Existing countermeasures mostly detect repackaging based on app similarity measurement and rely on a central party to perform detection, which is unscalable and imprecise. We instead consider building the detection capability into apps, such that user devices are made use of to detect repackaging in a decentralized fashion. The main challenge is how to protect repackaging detection code from attacks. We propose a creative use of logic bombs, which are regularly used in malware, to conquer the challenge. A novel bomb structure is invented and used: the trigger conditions are constructed to exploit the differences between the attacker and users, such that a bomb that lies dormant on the attacker side will be activated on one of the user devices, while the repackaging detection code, which is packed as the bomb payload, is kept inactive until the trigger conditions are satisfied. Moreover, the repackaging detection code is woven into the original app code and gets encrypted; thus, attacks by modifying or deleting suspicious code will corrupt the app itself. We have implemented a prototype, named BombDroid, that builds the repackaging detection into apps through bytecode instrumentation, and the evaluation shows that the technique is effective, efficient, and resilient to various adversary analysis including symbol execution, multi-path exploration, and program slicing. Qiang Zeng 0001, Lannan Luo, Zhiyun Qian, Xiaojiang Du, Zhoujun Li 0001 |
CGO | 1 |
| 2018 | Privacy Leakage in Smart Homes and Its Mitigation: IFTTT as a Case StudyabstractThe combination of an appified smart home platform and third-party apps have enabled developers to contribute their novel ideas to bring more convenience to their users. However, this also brings the potential of privacy leakage. If a third-party app is permitted to monitor a user day and night, then it will learn the behavior pattern of this user before long. In this paper, we exploited how IFTTT monitors the daily life of a user in several ways that are hardly noticeable. We propose the “Specific-fuzzification” to protect the privacy of a user in two steps: filter the unnecessary events to the IFTTT, then fuzz the value of the events that must be uploaded. We evaluated the “Specific-fuzzification” on event records of seven users, the result showed comparing the original IFTTT, the modified IFTTT patched with “Specific-fuzzification” only gained rare events and thus could no longer recognize any behavior patterns of a user. Rixin Xu, Qiang Zeng 0001, Liehuang Zhu, Haotian Chi, Xiaojiang Du |
IPCCC | 2 |
| 2017 | Deobfuscation of Virtualization-Obfuscated Code Through Symbolic Execution and Compilation Optimization
Mingyue Liang, Zhoujun Li 0001, Qiang Zeng 0001, Zhejun Fang |
ICICS | 3 |
| 2017 | System Service Call-oriented Symbolic Execution of Android Framework with Applications to Vulnerability Discovery and Exploit GenerationabstractAndroid Application Framework is an integral and foundational part of the Android system. Each of the 1.4 billion Android devices relies on the system services of Android Framework to manage applications and system resources. Given its critical role, a vulnerability in the framework can be exploited to launch large-scale cyber attacks and cause severe harms to user security and privacy. Recently, many vulnerabilities in Android Framework were exposed, showing that it is vulnerable and exploitable. However, most of the existing research has been limited to analyzing Android applications, while there are very few techniques and tools developed for analyzing Android Framework. In particular, to our knowledge, there is no previous work that analyzes the framework through symbolic execution, an approach that has proven to be very powerful for vulnerability discovery and exploit generation. We design and build the first system, Centaur, that enables symbolic execution of Android Framework. Due to some unique characteristics of the framework, such as its middleware nature and extraordinary complexity, many new challenges arise and are tackled in Centaur. In addition, we demonstrate how the system can be applied to discovering new vulnerability instances, which can be exploited by several recently uncovered attacks against the framework, and to generating PoC exploits. Lannan Luo, Qiang Zeng 0001, Chen Cao 0004, Kai Chen 0012, Jian Liu 0008, Neng Gao, Min Yang 0002, Xinyu Xing 0001, Peng Liu 0005 |
MobiSys | 2 |
| 2015 | Risk Assessment of Buffer "Heartbleed" Over-Read VulnerabilitiesabstractBuffer over-read vulnerabilities (e.g., Heartbleed) can lead to serious information leakage and monetary lost. Most of previous approaches focus on buffer overflow (i.e., over-write), which are either infeasible (e.g., canary) or impractical (e.g., bounds checking) in dealing with over-read vulnerabilities. As an emerging type of vulnerability, people need in-depth understanding of buffer over-read: the vulnerability, the security risk and the defense methods. This paper presents a systematic methodology to evaluate the potential risks of unknown buffer over-read vulnerabilities. Specifically, we model the buffer over-read vulnerabilities and focus on the quantification of how much information can be potentially leaked. We perform risk assessment using the RUBiS benchmark which is an auction site prototype modeled after eBay.com. We evaluate the effectiveness and performance of a few mitigation techniques and conduct a quantitative risk measurement study. We find that even simple techniques can achieve significant reduction on information leakage against over-read with reasonable performance penalty. We summarize our experience learned from the study, hoping to facilitate further studies on the over-read vulnerability. Jun Wang 0141, Mingyi Zhao, Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005 |
DSN | 3 |
| 2015 | HeapTherapy: An Efficient End-to-End Solution against Heap Buffer OverflowsabstractFor decades buffer overflows have been one of the most prevalent and dangerous software vulnerabilities. Although many techniques have been proposed to address the problem, they mostly introduce a very high overhead while others assume the availability of a separate system to pinpoint attacks or provide detailed traces for defense generation, which is very slow in itself and requires considerable extra resources. We propose an efficient solution against heap buffer overflows that integrates exploit detection, defense generation, and overflow prevention in a single system, named Heap Therapy. During program execution it conducts on-the-fly lightweight trace collection and exploit detection, and initiates automated diagnosis upon detection to generate defenses in real-time. It can handle both over-write and over-read attacks, such as the recent Heartbleed attack. The system has no false positives, and keeps effective under polymorphic exploits.%as the generated defense captures semantic characteristics of exploits. It is compliant with mainstream hardware and operating systems, and does not rely on specific allocation algorithms. We evaluated Heap Therapy on a variety of services (database, web, and ftp) and benchmarks (SPEC CPU2006), it incurs a very low average overhead in terms of both speed (6.2%) and memory (7.7%). Qiang Zeng 0001, Mingyi Zhao, Peng Liu 0005 |
DSN | 1 |
| 2015 | Enforcement of Autonomous Authorizations in Collaborative Distributed Query EvaluationabstractIn a federated database system, each independent party exports some of its data for information sharing. The information sharing in such a system is very inflexible, as all peer parties access the same set of data exported by a party, while the party may want to authorize different peer parties to access different portions of its information. We propose a novel query evaluation scheme that supports differentiated access control with decentralized query processing. Anew efficient join method, named split-join, along with other safe join methods is adopted in the query planning algorithm. The generated query execution reduces the communication cost by pushing partial query computation to data sources in a safe way. The proofs of the correctness and safety of the algorithm are presented. The evaluation demonstrates that the scheme significantly saves the communication cost in a variety of circumstances and settings while enforcing autonomous and differentiated information sharing effectively. Qiang Zeng 0001, Mingyi Zhao, Peng Liu 0005, Poonam Yadav, Seraphin B. Calo, Jorge Lobo 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2014 | DeltaPath: Precise and Scalable Calling Context Encoding
Qiang Zeng 0001, Junghwan Rhee, Hui Zhang 0002, Nipun Arora, Guofei Jiang, Peng Liu 0005 |
CGO | 1 |
| 2014 | Extracting important information from Chinese Operation Notes with natural language processing methods
Weide Zhang, Qiang Zeng 0001, Zuofeng Li, Kaiyan Feng, Lei Liu 0006 |
J. Biomed. Informatics | 3 |
| 2012 | Remote rehabilitation model based on BAN and cloud computing technologyabstractWith the improvement of living standards and the intensified social competition, the population of various chronic diseases is gradually expanded. In this study, we use a mature domestic commercial Body Area Network as our experiment platform-IVT mhealth system, a remote health care and rescue system created by IVT Corporation. This system adopts several most advanced technologies and patents in the world. It is a remote health care and rescue system, which consists of sensors, the call center and network platform. With the collaboration of medical institutions and health advisory center, it has the function of monitoring, positioning and asking for help. This system has achieved a dynamic measurement of ECG, blood pressure, blood glucose and blood oxygen. The data of users collected by wireless blood pressure meter, oximeter, ECG analyzer can be automatically sent to the cloud via cell phone and be kept as materials on records. This system provides a good platform for remote guidance, quantitative real-time monitoring and timely two-way feedback, as well as dynamic evaluation and overall adjustment for exercise rehabilitation of people on a large scale. Qiang Zeng 0001, Weimo Zhu, Qing Wang 0003, Weiyi Qin, Dingcheng Xiang, Minwei Zhou, Jian Liu 0008, Hongdi Wang |
Healthcom | 2 |
| 2012 | Kruiser: Semi-synchronized Non-blocking Concurrent Kernel Heap Buffer Overflow Monitoring
Donghai Tian, Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005, Changzhen Hu |
NDSS | 2 |
| 2011 | Cruiser: concurrent heap buffer overflow monitoring using lock-free data structures
Qiang Zeng 0001, Dinghao Wu, Peng Liu 0005 |
PLDI | 1 |