Fei Shao

dblp:84/11310 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 7 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 ProGQL: A Provenance Graph Query System for Cyber Attack Investigation
Fei Shao, Jia Zou 0001, Zhichao Cao 0002, Xusheng Xiao
ICDE1
2024 SSIDB: Secure Sharing of IoT Data on Blockchain with CP-ABE and Trusted Environment Assistance
abstract
With the popularization and broad application of the Internet of Things (IoT), the emergence of massive heterogeneous data brings serious privacy and security challenges to the traditionally centralized data storage and sharing architecture. Current research tends to leverage distributed blockchain technology and cryptographic algorithms to address these challenges. In particular, ciphertext-policy attribute-based encryption (CP-ABE) has shown great potential in protecting data privacy and realizing fine-grained access control. However, these approaches still cannot effectively support the integrated implementation of policy update and attribute revocation, and the key security during data sharing is difficult to guarantee. To address the above issues, we propose a secure IoT data sharing scheme on blockchain, called SSIDB, which is assisted by CP-ABE and Trusted Execution Environment (TEE). The scheme utilizes symmetric proxy re-encryption technology to achieve an efficient update of ciphertext access policy. Besides, based on the privacy of TEE, we realize the revocation of user attributes without having to update ciphertext. At the same time, we introduce TEE to manage keys and provide a secure execution environment for sensitive computations. We analyze the security of SSIDB scheme and evaluate its performance by conducting experiments on blockchain and TEE. The results show that the time consumption of our SSIDB scheme in encryption, decryption, policy update and attribute revocation phase is lower than other schemes by 144%, 126%, 176%, and 950%, respectively.
Sixiang Wang, Dongdong Huo, Hailong Zhang 0001, Yu Wang 0243, Fei Shao
ISPA7
2024 NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation
Shaofei Li, Feng Dong 0008, Xusheng Xiao, Haoyu Wang 0001, Fei Shao, Jiedong Chen, Yao Guo 0001, Xiangqun Chen, Ding Li 0001
NDSS5
2023 Hardware-Software Co-Design of Matrix-Solving for Non-Linear Optimization in SLAM Systems
abstract
Simultaneous Localization and Mapping (SLAM) is one of the most important techniques for autonomous robots that enables the robot aware of its current position and the surrounding environment. There is a significant improvement in the accuracy with the advancement in SLAM algorithms. However, the computation complexity increases accordingly and the embedded processors of autonomous robots struggle to support heavy calculation. Matrix-solving contributes a major portion of calculation time and considering sub-tasks such as bundle adjustment takes over 40% of total time. Therefore, it is significant to optimize the calculations required for matrix-solving. However, previous works for matrix-solving accelerators are generalized and the specific matrix form in SLAM problems is not fully considered. This work concentrates on the dedicated software and hardware codesign of the matrix-solving task in SLAM systems and provides three solutions for different scales of matrix-solving problems in SLAM. The proposed FSFI-Cholesky and FI-Iterative method have achieved up to 120.2x speed improvement over the non-optimized Cholesky algorithm. Moreover, this work also reduces the execution time by more than 7.0x compared to the state-of-the-art design with fewer DSPs used for both dense and sparse matrices.
Liting Niu, Weiyi Zhang 0002, Cheng Nian, Fei Shao, Fasih Ud Din Farrukh, Chun Zhang 0001
IECON4
2023 DISTDET: A Cost-Effective Distributed Cyber Threat Detection System
Feng Dong 0008, Liu Wang 0002, Xu Nie, Fei Shao, Haoyu Wang 0001, Ding Li 0001, Xiapu Luo, Xusheng Xiao
USENIX Security Symposium4
2023 Spatial-temporal traffic performance collaborative forecast in urban road network based on dynamic factor model
Tangyi Guo, Fei Shao, Yongfeng Ma, Aemal J. Khattak
Expert Syst. Appl.3
2022 System-Auditing, Data Analysis and Characteristics of Cyber Attacks for Big Data Systems
abstract
Using big data, distributed computing systems such as Apache Hadoop requires processing massive amount of data to support business and research applications. Thus, it is critical to ensure the cyber security of such systems. To better defend from advanced cyber attacks that pose threats to even well-protected enterprises, system-auditing based techniques have been adopted for monitoring system activities and assisting attack investigation. In this demo, we are building a system that collects system auditing logs from a big data system and performs data analysis to understand how system auditing can be used more effectively to assist attack investigation on big systems. We also built a demo application that detects unexpected file deletion and presents root causes for the deletion.
Liangyi Huang, Sophia Hall, Fei Shao, Arafath Nihar, Vipin Chaudhary, Yinghui Wu 0001, Roger H. French, Xusheng Xiao
CIKM3
2021 A System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence
abstract
Log-based cyber threat hunting has emerged as an important solution to counter sophisticated cyber attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the rich external knowledge about threat behaviors provided by open-source Cyber Threat Intelligence (OSCTI). To bridge the gap, we build ThreatRaptor, a system that facilitates cyber threat hunting in computer systems using OSCTI. Built upon mature system auditing frameworks, ThreatRaptor provides (1) an unsupervised, light-weight, and accurate NLP pipeline that extracts structured threat behaviors from unstructured OSCTI text, (2) a concise and expressive domain-specific query language, TBQL, to hunt for malicious system activities, (3) a query synthesis mechanism that automatically synthesizes a TBQL query from the extracted threat behaviors, and (4) an efficient query execution engine to search the big system audit logging data.
Peng Gao 0008, Fei Shao, Xusheng Xiao, Fengyuan Xu, Prateek Mittal, Sanjeev R. Kulkarni, Dawn Song
ICDE2
2021 Enabling Efficient Cyber Threat Hunting With Cyber Threat Intelligence
abstract
Log-based cyber threat hunting has emerged as an important solution to counter sophisticated attacks. However, existing approaches require non-trivial efforts of manual query construction and have overlooked the rich external threat knowledge provided by open-source Cyber Threat Intelligence (OSCTI). To bridge the gap, we propose ThreatRaptor, a system that facilitates threat hunting in computer systems using OSCTI. Built upon system auditing frameworks, ThreatRaptor provides (1) an unsupervised, light-weight, and accurate NLP pipeline that extracts structured threat behaviors from unstructured OSCTI text, (2) a concise and expressive domain-specific query language, TBQL, to hunt for malicious system activities, (3) a query synthesis mechanism that automatically synthesizes a TBQL query for hunting, and (4) an efficient query execution engine to search the big audit logging data. Evaluations on a broad set of attack cases demonstrate the accuracy and efficiency of ThreatRaptor in practical threat hunting.
Peng Gao 0008, Fei Shao, Xusheng Xiao, Fengyuan Xu, Prateek Mittal, Sanjeev R. Kulkarni, Dawn Song
ICDE2
2021 WebEvo: taming web application evolution via detecting semantic structure changes
abstract
The development of Web technology and the beginning of the Big Data era have led to the development of technologies for extracting data from websites, such as information retrieval (IR) and robotic process automation (RPA) tools. As websites are constantly evolving, to prevent these tools from functioning improperly due to website evolution, it is important to monitor the changes in websites and report them to the developers and testers. Existing monitoring tools mainly use DOM-tree based techniques to detect changes in the new web pages. However, these monitoring tools incorrectly report content-based changes (i.e., web content refreshed every time a web page is retrieved) as the changes that will adversely affect the performance of the IR and RPA tools. This results in false warnings since the IR and RPA tools typically consider these changes as expected and retrieve dynamic data from them. Moreover, these monitoring tools cannot identify GUI widget evolution (e.g., moving a button), and thus cannot help the IR and RPA tools adapt to the evolved widgets (e.g., automatic repair of locators for the evolved widgets). To address the limitations of the existing monitoring tools, we propose an approach, WebEvo, that leverages historic pages to identify the DOM elements whose changes are content-based changes, which can be safely ignored when reporting changes in the new web pages. Furthermore, to identify refactoring changes that preserve semantics and appearances of GUI widgets, WebEvo adapts computer vision (CV) techniques to identify the mappings of the GUI widgets from the old web page to the new web page on an element-by-element basis. Empirical evaluations on 13 real-world websites from 9 popular categories demonstrate the superiority of WebEvo over the existing DOM-tree based detection or whole-page visual comparison in terms of both effectiveness and efficiency.
Fei Shao, Wasif Arman Haque, Jingwei Xu 0004, Ying Zhang 0012, Wei Yang 0013, Yanfang Ye 0001, Xusheng Xiao
ISSTA1
2018 An Empirical Evaluation of Techniques for Ranking Semantic Associations (Extended Abstract)
abstract
Searching for associations between entities is needed in many domains. It has been facilitated by the emergence of graph-structured semantic data on the Web, which offers structured semantic associations more explicit than those hiding in unstructured text for computers to discover. The increasing volume of semantic data requires ranking techniques to identify the more important semantic associations for users. Considering a lack of comprehensive empirical evaluation of existing techniques, we carry out an extensive evaluation of eight techniques including two novel ones we propose. The practical effectiveness of these techniques is assessed based on 1,200 ground-truth rankings created by 30 human experts for real-life semantic associations and on the explanations given by the experts.
Gong Cheng 0001, Fei Shao, Yuzhong Qu
ICDE2
2017 DRank: A semi-automated requirements prioritization method based on preferences and dependencies
Fei Shao, Rong Peng, Han Lai, Bangchao Wang
J. Syst. Softw.1
2017 An Empirical Evaluation of Techniques for Ranking Semantic Associations
abstract
Searching for associations between entities is needed in many domains like national security and bioinformatics. In recent years, it has been facilitated by the emergence of graph-structured semantic data on the Web, which offers structured semantic associations more explicit than those hiding in unstructured text for computers to discover. The increasing volume of semantic data often produces excessively many semantic associations, and requires ranking techniques to identify the more important ones for users. Despite the fruitful theoretical research on innovative ranking techniques, there is a lack of comprehensive empirical evaluation of these techniques. In this article, we carry out an extensive evaluation of eight techniques for ranking semantic associations, including two novel ones we propose. The practical effectiveness of these techniques is assessed based on 1,200 ground-truth rankings created by 30 human experts for real-life semantic associations and the explanations given by the experts. Our findings also suggest a number of directions in improving existing techniques and developing novel techniques for future work.
Gong Cheng 0001, Fei Shao, Yuzhong Qu
IEEE Trans. Knowl. Data Eng.2
2015 Efficient distributed maximum matching for solving the container exchange problem in the maritime industry
abstract
To reduce container management costs, ocean carrier companies rent containers from container leasing companies. Two carrier companies can exchange their empty containers between each other at various ports to eliminate the transportation cost of empty containers. To minimize costs, a container leasing company has to find the maximum number of pairs of carrier companies that can exchange containers. We formulate this problem as maximum matching in a large general graph, and propose a distributed matching algorithm to solve this problem. We also propose several optimization techniques to improve the efficiency of our algorithm.
Fei Shao, Li-Yung Ho, Jan-Jan Wu, Pangfeng Liu
IEEE BigData1
2015 Modeling Curly Hair Based on Static Super-Helices
abstract
In the field of computer graphics and human simulation, hair simulation is one of the most challenging physics and rendering problem. This paper presents a curly hair modeling utilizing the Nelder-Mead method and being based on the ball B-Spline Curves (BBSCs). The ball B-Spline Curves (BBSCs) is used to reconstruct hair model and the Nelder-Mead method is for calculating the equilibrium shape of each hair. The main advantages of our method used in this experiment are: (1) We construct hair model for each individual hair. (2) It can provide a wide range of curly hair types with the BBSCs for its good properties that it is flexible for modifying, editing and deforming. (3) The method can obtain efficient curly hair type because of the fast calculation and easy implementation of Nelder-Mead method. The hypothesis in this paper is supported by several credible evidences and the model can be widely used in the similar systems (e.g. Fabrics, green fields).
Fei Shao, Xingce Wang, Qianqian Jiang, Zhongke Wu
CW1