Zhi Wang 0018

dblp:95/6543-18 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0003-4711-4251ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 BASSET: Enhancing Binary Code Clone Searching through Multi-Level Hybrid Semantic Indexing
abstract
Binary code search is critical for applications such as plagiarism detection and security analysis, but it is challenging due to compiler-induced transformations at different optimization levels. Existing function similarity methods often fail in large-scale search scenarios, particularly pairwise approaches that struggle with scalability. To address this, we propose BASSET, a novel framework that leverages multilevel hybrid semantic features for efficient large-scale binary function clone search. BASSET decomposes functions into five semantic units and applies various embedding strategies to generate indexing vectors for similarity measurement. Notably, it integrates an expression tree-based representation to capture robust features across compiler optimization levels. By utilizing a learning-to-rank approach with convolutional neural networks, BASSET combines similarity scores from different semantic units to generate a final ranking. Experimental results show that BASSET outperforms existing methods, achieving an AUC of 0.992, an nDCG@10 of 0.853, and a stable MRR of 59%, even as the search space grows.
Ang Xia, Zhi Wang 0018, Yaqin Cao, Xiangyi Zeng
DSN4
2025 SCBot: Building Lightweight and Flexible C&C Based on Smart Contract
Chaoge Liu, Zhi Wang 0018, Yinsheng Liu, Chumeng Deng
ICASSP2
2023 IMaler: An Adversarial Attack Framework to Obfuscate Malware Structure Against DGCNN-Based Classifier via Reinforcement Learning
abstract
Inspired by the success of graph neural network in graph data classification, graph neural networks have been widely used in malware classification and they have been proven to be the state-of-the-art malware classification models. However, most of existing adversarial samples generation techniques against machine learning-based malware classification models modify malware samples by inserting dead codes or modifying binaries directly, which is less effective against graph neural network-based malware classification models. In this paper, we propose an adversarial attack framework powered by reinforcement learning to spoof the deep graph convolutional neural network (DGCNN)-based malware classifiers called Intelligent Malware Evader (IMaler). We construct functionality-preserved manipulations based on traditional obfuscation techniques that can modify both node features and structural features of malware. The reinforcement learning agent can make optimal decisions on how to obfuscate malware with functionality-preserved manipulations. We use a large dataset with more than 10,000 samples to evaluate the performance of IMaler and use a random agent attack as a baseline attack. The experiment results show that IMaler can achieve a significantly higher evasion rate (88.26%) than the random agent attack with fewer query times.
Yanhui Chen, Yun Feng 0003, Zhi Wang 0018, Chengchun Wang, Qixu Liu
ICC3
2023 C-BEDIM and S-BEDIM: Lateral movement detection in enterprise network through behavior deviation measurement
Cong Dong, Zhi Wang 0018, Zhigang Lu 0002
Comput. Secur.4
2022 Make Data Reliable: An Explanation-powered Cleaning on Malware Dataset Against Backdoor Poisoning Attacks
abstract
Machine learning (ML) based Malware classification provides excellent performance and has been deployed in various real-world applications. Training for malware classification often relies on crowdsourced threat feeds, which exposes a natural attack injection point. Considering a real-world threat model for backdoor poisoning attacks on a malware dataset, because attackers are generally considered to have no control over the sample-labeling process, they conduct a clean-label attack, a more realistic scenario, by generating backdoored benign binaries that will be disseminated through threat intelligence platforms and poison the datasets for downstream malware classifiers. To avoid the threat of backdoor poisoned datasets, we propose an explanation-powered defense methodology called make data reliable (MDR), which is a general and effective mitigation to ensure the reliability of datasets by removing backdoored samples. We use a surrogate model and explanation tool Shapley Additive exPlanations (SHAP) to filter suspicious samples, then perform watermark identification based on the filtered suspicious samples, and finally remove samples with the identified watermark to construct a reliable dataset. We conduct extensive experiments on two typical datasets that were manually poisoned using different attack strategies. Experimental results show that the MDR achieves backdoored samples removal rate greater than 99.0% for different datasets and attack conditions, while maintaining an extremely low false positive rate of less than 0.1%. Furthermore, to confirm the generality of MDR, we use different models to perform a model-agnostic evaluation. The results show that, MDR is a general methodology that does not rely on any specific model.
Xutong Wang, Chaoge Liu, Zhi Wang 0018, Xiang Cui
ACSAC4
2022 DeepC2: AI-Powered Covert Command and Control on OSNs
Zhi Wang 0018, Chaoge Liu, Xiang Cui, Qixu Liu
ICICS1
2022 EvilModel 2.0: Bringing Neural Network Models into Malware Attacks
Zhi Wang 0018, Chaoge Liu, Xiang Cui, Xutong Wang
Comput. Secur.1
2021 EvilModel: Hiding Malware Inside of Neural Network Models
abstract
Delivering malware covertly and evasively is critical to advanced malware campaigns. In this paper, we present a new method to covertly and evasively deliver malware through a neural network model. Neural network models are poorly explainable and have a good generalization ability. By embedding malware in neurons, the malware can be delivered covertly, with minor or no impact on the performance of neural network. Meanwhile, because the structure of the neural network model remains unchanged, it can pass the security scan of anti-virus engines. Experiments show that 36.9MB of malware can be embedded in a 178MB-AlexNet model within 1% accuracy loss, and no suspicion is raised by anti-virus engines in VirusTotal, which verifies the feasibility of this method. With the widespread application of artificial intelligence, utilizing neural networks for attacks becomes a forwarding trend. We hope this work can provide a reference scenario for the defense on neural network-assisted attacks.
Zhi Wang 0018, Chaoge Liu, Xiang Cui
ISCC1
2020 CoinBot: A Covert Botnet in the Cryptocurrency Network
Xiang Cui, Chaoge Liu, Qixu Liu, Zhi Wang 0018
ICICS6
2019 WSLD: Detecting Unknown Webshell Using Fuzzy Matching and Deep Learning
Qixu Liu, Zhi Wang 0018, Xianda Wu
ICICS4