EDBT 2026 Demo / reviewers in the wild / expert
Xinyu Liu 0019
dblp:98/738-19
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0002-8449-839XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TGNN: Enhancing Pixel Tracking Detection via LLM-driven Annotation and GAT-powered Structural RepresentationabstractWeb tracking is increasingly pervasive, raising serious concerns about user privacy and security. Among existing techniques, pixel tracking is particularly stealthy and cost-effective, embedding invisible images that exfiltrate user activities to third-party servers. Current defenses, including filter list blocking and conventional machine learning, often fail to capture the cross-site associations that enable pixel tracking to evade detection. Shenping Xiong, Xutong Wang, Ze Jin, Xinyu Liu 0019, Haoqiang Wang, Ru Tan, Qixu Liu |
WWW | 4 |
| 2025 | ExtFPDet: A CNN-Based Detection Framework for Browser Extensions FingerprintingabstractWith the widespread use of modern browser extensions, user experience has been significantly enhanced via embedding ancillary functionality into the original webpage. The rapid development of Web tracking technology has raised privacy and security concerns, as it generates a unique identifier for users according to the diversity of installed extensions and further prompts the profiling of users. However, due to the ignorance of potential privacy risks, there is no effective method to detect browser extension fingerprinting. In this paper, we propose ExtFPDet, a CNN-based detection framework to recognize browser extension fingerprinting in websites, which fills the gap in this area. Based on the preliminary investigation, the approaches to fingerprint browser extensions can be summarized into 2 categories according to the distinctive behaviors, including resource traversing and side-channel exploring. In order to extract effective features to reflect extensions fingerprinting, ExtFPDet focuses on the structure and content in the program dependency graph of Javascript files. The generated feature vector assists the CNN-based classification model to detect the extension fingerprinting, for which we perform a systematic detection on Tranco top 10K websites. Eventually, the result is evaluated by randomly sampling and manually checking, which shows superior detection capabilities of ExtFPDet. Wei Liu 0243, Xiaoxi Wang, Yun Feng 0003, Xinyu Liu 0019, Le Gong, Kerui Huang, Yaqin Cao, Qixu Liu |
CSCWD | 4 |
| 2025 | Not All Benignware Are Alike: Enhancing Clean-Label Attacks on Malware ClassifiersabstractMachine Learning (ML) based malware classifiers are vulnerable to exploitation during the training phase due to the necessity of regular retraining with samples collected from the wild. Recent studies have highlighted the efficacy of backdoor attacks in the malware domain, where attackers can manipulate the model during training by injecting samples embedded with specific triggers, causing the model to establish an association between the trigger and a designated class, thereby achieving evasion of detection. While research on backdoor attacks has been extensively explored in the field of computer vision, it has been largely overlooked in the malware domain. Unlike in the computer vision domain, the threat model in the malware domain typically restricts attackers to employing clean-label attacks (i.e., attackers do not have control over the labeling of poisoned data). However, clean-label attack methods are generally less effective compared to those that involve embedding triggers and altering sample labels to the target class (called corrupted-label attacks). To address this limitation, we propose a simple yet effective method that involves Poisoning Malware-Similar Benignware (PMSB) instead of random selection, thereby approximating the scenario of corrupted-label attacks and enhancing the effectiveness of clean-label attacks. Additionally, we introduce three similarity measurement methods based on feature-based distance, distribution-based distance, and contribution-based difference to select malware-similar benignware. Comprehensive evaluations across three different trigger types and three datasets demonstrate the superiority and general applicability of PMSB. Xutong Wang, Yun Feng 0003, Bingsheng Bi, Yaqin Cao, Ze Jin, Xinyu Liu 0019, Yunpeng Li 0006 |
WWW | 6 |
| 2025 | WTDetect: a third-party website tracking detection framework for android applicationsabstractAbstract With the development of HTML5, tracking technologies have evolved dramatically and gradually moved from cookies to browser fingerprinting. Previous research has shown that there are more serious privacy threats associated with tracking behavior on third-party websites. However, by focusing on third-party websites that are loaded in the browser, the researchers overlooked the fact that third-party websites are also present in Android applications, where tracking is easy to perform and definitely covert to detect. In this study, we propose WTDetect, an Android third-party website tracking detection framework. Based on the parsing of view tree and the generation of function call stack, WTDetect automatically locates and captures the source code of third-party websites. To explore the direction of sensitive data flow, WTDetect performs static taint analysis on the program dependency graph for each JavaScript file. Finally, a fine-grained classification model is used to detect the tracking behavior. WTDetect is used to perform a measurement study of tracking behavior on 1090 captured Android third-party websites. The result outlines that 14.68% of third-party websites in Android applications tracking users without any access warnings and user authorization, which directly leads to the risk of privacy leakage. Wei Liu 0243, Xinyu Liu 0019, Yun Feng 0003, Kerui Huang, Ze Jin, Yaqin Cao, Qixu Liu |
Cybersecur. | 2 |
| 2025 | XFP-recognizer: detecting cross-file browser fingerprintingabstractAbstract In recent years, the evolving browser fingerprinting technology has posed significant challenges and constant demands on detection methods. Research related to malicious code shows that cross-file techniques, which disperse code into multiple files, can resist current detection methods. To address this challenge, we introduce cross-file tracking technology into browser fingerprinting, constructing cross-file browser fingerprinting (XFP). The dispersion of files and features in XFP effectively circumvents detection methods that primarily focus on single-file tracking. In this paper, we propose XFP-Recognizer, a Random Forest-based detection method for identifying XFP behaviors. XFP-Recognizer aggregates code files and dynamic APIs by constructing function call relationship graphs (FCRgraphs). It extracts dynamic and static features to train random forest models for detecting and classifying the aggregated files, and then backtracks based on FCRgraphs to mark original scripts. To validate our method, we implement a code-splitting algorithm and constructed a cross-file tracking dataset to address the lack of XFP in real-world scenarios. We combine this dataset with the dataset of Alexa Top-10K websites in different proportions to verify the effectiveness of XFP-Recognizer. The results show that XFP-Recognizer achieved an Accuracy of 92.25%, a Precision of 97.01% and an AUC of 0.9152 in recognizing browser fingerprinting, demonstrating superior performance in both single-file and cross-file tracking. XFP-Recognizer complements existing detection methods, and the constructed split dataset also serves as a foundational resource for future research. Xiaoxi Wang, Zhenxu Liu, Chunyang Zheng, Xinyu Liu 0019, Wei Liu 0243, Qixu Liu |
Cybersecur. | 4 |
| 2023 | ANDetect: A Third-party Ad Network Libraries Detection Framework for Android ApplicationsabstractThird-party advertising libraries, which furnish mobile applications with ads, offer a revenue stream for Android application developers. However, the loaded ads potentially expose application users to privacy infringements and security threats. For instance, tracking scripts embedded in third-party ads monitor user behavior and can entice users into downloading malicious files. Therefore, the detection of advertising libraries in mobile applications is crucial for mobile security protection and serves as the foundation for preventing third-party ads from compromising user privacy. Xinyu Liu 0019, Ze Jin, Wei Liu 0243, Xiaoxi Wang, Qixu Liu |
ACSAC | 1 |
| 2023 | MRm-DLDet: a memory-resident malware detection framework based on memory forensics and deep neural networkabstractAbstract Cyber attackers have constantly updated their attack techniques to evade antivirus software detection in recent years. One popular evasion method is to execute malicious code and perform malicious actions only in memory. Malicious programs that use this attack method are called memory-resident malware, with excellent evasion capability, and have posed huge threats to cyber security. Traditional static and dynamic methods are not effective in detecting memory-resident malware. In addition, existing memory forensics detection solutions perform unsatisfactorily in detection rate and depend on massive expert knowledge in memory analysis. This paper proposes MRm-DLDet, a state-of-the-art memory-resident malware detection framework, to overcome these drawbacks. MRm-DLDet first builds a virtual machine environment and captures memory dumps, then creatively processes the memory dumps into RGB images using a pre-processing technique that combines deduplication and ultra-high resolution image cropping, followed by our neural network MRmNet in MRm-DLDet to fully extract high-dimensional features from memory dump files and detect them. MRmNet receives the labeled sub-images of the cropped high-resolution RGB images as input of ResNet-18, which extracts the features of the sub-images. Then trains a network of gated recurrent units with an attention mechanism. Finally, it determines whether a program is memory-resident malware based on the detection results of each sub-image through a specially designed voting layer. We created a high-quality dataset consisting of 2,060 benign and memory-resident programs. In other words, the dataset contains 1,287,500 labeled sub-images cut from the MRm-DLDet transformed ultra-high resolution RGB images. We implement MRm-DLDet for Windows 10, and it performs better than the latest methods, with a detection accuracy of up to 98.34 $$\%$$ % . Moreover, we measured the effects of mimicry and adversarial attacks on MRm-DLDet, and the experimental results demonstrated the robustness of MRm-DLDet. Yun Feng 0003, Xinyu Liu 0019, Qixu Liu |
Cybersecur. | 3 |