EDBT 2026 Demo / reviewers in the wild / expert
Wei Chen 0006
dblp:c/WeiChen6
· DBLP profile ↗
24ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0002-6248-1298ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 4 since 2021Systems, architecture and hardware · 7 · 1 first-author · 2 since 2021Computer networks · 7 · 6 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | NASchecker: Automatically Identifying the Performance, Security, and Privacy Issues of NAS DevicesabstractNetwork attached storage (NAS) devices are widely deployed for personal data storage. However, their distributed architecture and limited inspection interfaces pose significant challenges for comprehensive performance, security, and privacy analysis. In this paper, we first establish a threat model for NAS ecosystems. Then, we present a systematic framework NASchecker for discovering performance optimization mechanisms, security threats, and privacy leakage in NAS devices. By analyzing traffic generated during varied file operations on crafted files, NASchecker infers implemented optimizations and identifies security flaws within the traffic (e.g., susceptibility to passive sniffing and replay attacks). NASchecker also integrates NAS-specific protocol fuzzing and firmware reverse engineering to uncover deep-seated command injection, memory corruption, and improper access control vulnerabilities. NASchecker compares personally identifiable information (PII) leaked in traffic against declarations in privacy policies to detect privacy compliance issues. We evaluated NASchecker on twelve commercial NAS devices. Our results reveal that none of the tested devices employ file compression or deduplication. From a security standpoint, ten devices are vulnerable to passive sniffing and seven to replay attacks. Moreover, seven devices are affected by command injection, four by memory corruption, and eleven by improper access control. From a privacy perspective, four devices leaked PIIs that were not disclosed in their respective privacy policies. After reporting the findings to the manufacturers, we have been acknowledged by several manufacturers, resulting in the assignment of 20 CVEs and 6 NVDB entries (16 of them are rated as high severity). These findings validate NASchecker’s effectiveness and underscore the urgent need for improved design and testing practices of NAS. Guangyue Ren, Le Yu 0002, Liping Han, Mingzhe Hu, Wei Chen 0006, Tingting Liu 0005, Xiapu Luo, Guozi Sun |
IEEE Internet Things J. | 6 |
| 2025 | HyperHammer: Breaking Free from KVM-Enforced IsolationabstractHardware-assisted virtualization is a key enabler of the modern cloud. It decouples virtual machine execution from the hardware it runs on, allowing increased flexibility through services such as dynamic hardware provisioning and live migration. Underlying this flexibility is the security promise that guest virtual machines are isolated from each other. However, due to the level of sharing between VMs, hardware vulnerabilities present a serious threat to this usage. One such vulnerability is Rowhammer, which allows attackers to modify the contents of memory to which they have no access. While the attack has been known for over a decade, published applications against such environments are limited, compromising only co-resident VMs, but not the hypervisor. Moreover, due to security concerns, a key component enabling their attack has been disabled. Hence, this attack is no longer applicable in a contemporary virtualized environment. Wei Chen 0006, Zhi Zhang 0001, Xin Zhang 0110, Qingni Shen, Yuval Yarom, Daniel Genkin, Zhe Wang 0017 |
ASPLOS (2) | 1 |
| 2025 | SACK: Enabling Environmental Situation-Aware Access Control for Vehicles in Linux KernelabstractConnected and autonomous vehicles (CAVs) operate in open and evolving environments, which require timely and adaptive permission restriction to address dynamic risks that arise from changes in environmental situations (hereinafter referred to as situations), such as emergency situations due to vehicle crashes. Enforcing situation-aware access control is an effective approach to support adaptive permission restriction. Current works mainly implement situation-aware access control in the permission framework and API monitoring in user space. They are vulnerable to being bypassed and are coarse-grained. Autonomous systems have widely adopted mandatory access control (MAC) to configure and enforce system-wide and fine-grained access control policies. However, the MA$C$supported by Linux security modules (LSM) relies on predefined security contexts (e.g., type) and relatively fixed permission transition conditions (e.g., exec syscall), which lacks consideration of environmental factors. To address these issues, we propose a Situation-aware Access Control framework in the Kernel (SACK), which enforces adaptive permission restriction based on environmental factors for CAVs. Incorporating environmental situations into the LSM framework is not straightforward. SACK introduces situation states as a new security context for abstracting environmental factors in the kernel. Subsequently, SACK utilizes a situation state machine to implement new adaptive permission transitions triggered by situation events. In addition, SACK provides a novel situation-aware policy language that links specific user space permissions to MAC rules while maintaining compatibility with other LSMs such as AppArmor. We develop two prototypes: an independent SACK with its own policies and a SACK-enhanced AppArmor that adaptively updates the corresponding policies of AppArmor. The experimental results demonstrate that SACK can efficiently enforce situation-adaptive permissions with negliaible runtime overhead. Boyan Chen, Qingni Shen, Lei Xue 0001, Jiarui She, Xiapu Luo, Xin Zhang 0110, Wei Chen 0006, Zhonghai Wu |
DATE | 8 |
| 2025 | Precision strike: Precise backdoor attack with dynamic trigger
Qingyun Li, Wei Chen 0006, Xiaotang Xu, Lifa Wu |
Comput. Secur. | 2 |
| 2025 | An Adaptive DoH Encrypted Tunnel Detection Method Based on Contrastive LearningabstractThe percentage of encrypted network traffic has constantly increased as network security has been continuously improved. Attackers can, however, utilize encrypted DNS over HTTPS (DoH) to conceal their malicious traffic, which makes it more difficult to identify malicious tunnels. To address this issue, we first examine the encryption features of DoH tunnel traffic. Due to the incapability of current detection techniques to properly fuse traffic attributes, a fusion learning-based method is proposed to detect DoH encrypted tunnel traffic. At the same time, we discover that the DoH traffic samples may exhibit concept drift. As a result, we present a concept drift detection approach based on a contrastive sparse autoencoder. In addition to the above method, a model retraining strategy is also suggested to improve the model’s capacity to identify new DoH encrypted tunnel traffic while reducing its reliance on expert label data. This strategy involves incrementally training the model using as few samples as possible. Experiments demonstrate that the proposed method can significantly enhance detection performance. When 7% of drift samples are used during incremental training, the detection accuracy of the model recovers from 74.02% to 99.96%. Jiacheng Tong, Chongju Jin, Wei Chen 0006, Lifa Wu |
IEEE Internet Things J. | 4 |
| 2025 | ITransformer_CNN: a malicious DNS detection method with flexible feature extraction
Wei Chen 0006, Lifa Wu |
Peer Peer Netw. Appl. | 2 |
| 2024 | Privacy Protection for Image Sharing Using Reversible Adversarial ExamplesabstractOnline image sharing on social media platforms faces information leakage due to deep learning-aided privacy attacks. To avoid these attacks, this paper proposes a privacy protection mechanism for image sharing without changing the visual effect, which is based on reversible adversarial examples. Specifically, social media platform users can change the class activation feature to convert the original image into an adversarial image before sharing. When users want to restore the adversarial image to the original image, they can use an improved generative adversarial network model to restore it. The experimental results prove that the conversion model in this paper can effectively prevent privacy attacks from analyzing and stealing users' private information while having no visual impact. At the same time, the proposed restoration model can restore the adversarial examples with high accuracy. Ping Yin, Wei Chen 0006, Jiaxi Zheng, Lifa Wu |
ICC | 2 |
| 2024 | Decentralized Access Control for Privacy-Preserving Cloud-Based Personal Health Record With Verifiable Policy UpdateabstractWith the advancement of cloud computing technology, cloud-based personal health record (CB-PHR) has become an increasingly popular way for modern patients to flexibly manage and share their health records with doctors. However, the confidentiality of CB-PHR privacy is vulnerable to threats due to unauthorized users and untrusted cloud service provider (CSP). Additionally, patients and doctors may be constrained by changes in access permissions and limited device resources. To address these challenges, we propose an efficient decentralized privacy-preserving attribute-based access control scheme with verifiable policy update (DPVPU) for CB-PHR systems. DPVPU supports large attribute universe and safeguards the privacy of both the access policy and the doctor’s identity through partially hiding the access policy and employing a one-way anonymous key agreement technique. Unlike re-encrypting ciphertext, it can dynamically update policy by fully utilizing the previous policy and outsourcing the computation of ciphertext update to the CSP. Also, we design an efficient verification algorithm enabling patients to check the correctness of updated ciphertext. For devices with limited resources, we use online/offline and outsourced decryption techniques to reduce system costs. Finally, we provide formal security proofs and performance analysis to demonstrate the security and practicality of DPVPU. Haoyuan Fan, Qi Li 0011, Jinbo Xiong, Rui Li 0047, Wei Chen 0006, Haiping Huang |
IEEE Internet Things J. | 5 |
| 2023 | An intrusion detection method based on stacked sparse autoencoder and improved gaussian mixture model
Wei Chen 0006, Lifa Wu |
Comput. Secur. | 2 |
| 2023 | Anomaly traffic detection in IoT security using graph neural networks
Mengnan Gao, Lifa Wu, Qi Li 0011, Wei Chen 0006 |
J. Inf. Secur. Appl. | 4 |
| 2023 | High-speed anomaly traffic detection based on staged frequency domain features
Jiayi Ni, Wei Chen 0006, Jiacheng Tong, Haiyong Wang, Lifa Wu |
J. Inf. Secur. Appl. | 2 |
| 2022 | Secure, Efficient, and Weighted Access Control for Cloud-Assisted Industrial IoTabstractIn the cloud-assisted Industrial Internet of Things (IIoT), ciphertext-policy attribute-based encryption (CP-ABE) could help the data owner (DO) share his sensitive data via the cloud under self-defined access structures. Among general CP-ABE schemes, the decryption overhead, the key generation cost, and the ciphertext length increase with the number of involved attributes. Additionally, only regular attributes are taking into consideration rather than weighted attributes. In this article, we proposed a secure, efficient, and weighted access control scheme (SEWAC) for cloud-assisted IIoT applications. SEWAC enables the DO to formulate any fine-grained access structure over weighted attributes without making it more complicated. Furthermore, such weighted attributes would not add the length of ciphertext. SEWAC also supports online/offline key generation to alleviate the computational cost of the authority from answering mass key requests in the online phase, while most computational tasks are executed in the offline phase. The heavy decryption overhead is offloaded to the cloud. To ensure the cloud to honestly execute the process of outsourced decryption, we design an efficient batch verification method, which allows the user to spend only three bilinear pairing operations in checking the correctness of batch results. We also give the formal security proof of the proposed scheme. Comprehensive comparisons and implementation results indicate that SEWAC can better achieve weighted access control, compressed ciphertext length, efficient key generation, and the assurance of the outsourced decryption result. Qi Li 0011, Haiping Huang, Wei Zhang 0122, Wei Chen 0006, Huaqun Wang |
IEEE Internet Things J. | 5 |
| 2020 | Building Auto-Encoder Intrusion Detection System based on random forest feature selection
XuKui Li, Wei Chen 0006, Qianru Zhang, Lifa Wu |
Comput. Secur. | 2 |
| 2019 | DangerNeighbor attack: Information leakage via postMessage mechanism in HTML5
Chong Guan, Kun Sun 0001, Lingguang Lei, Pingjian Wang, Yuewu Wang, Wei Chen 0006 |
Comput. Secur. | 6 |
| 2018 | Enhanced Keystroke Recognition Based on Moving Distance of Keystrokes Through WiFi
Yunfang Chen, Yihong Zhu, Hao Zhou 0043, Wei Chen 0006, Wei Zhang 0122 |
NSS | 4 |
| 2017 | CloudBot: Advanced mobile botnets using ubiquitous cloud technologies
Wei Chen 0006, Xiapu Luo, Bin Xiao 0001, Man Ho Au, Yajuan Tang |
Pervasive Mob. Comput. | 1 |
| 2016 | MUSE: Towards Robust and Stealthy Mobile Botnets via Multiple Message Push Services
Wei Chen 0006, Xiapu Luo, Bin Xiao 0001, Man Ho Au, Yajuan Tang |
ACISP (1) | 1 |
| 2008 | An autonomous defense against SYN flooding attacks: Detect and throttle attacks at the victim side independently
Bin Xiao 0001, Wei Chen 0006, Yanxiang He |
J. Parallel Distributed Comput. | 2 |
| 2007 | Defending Against Jamming Attacks in Wireless Local Area Networks
Wei Chen 0006, Danwei Chen, Guozi Sun, Yingzhou Zhang |
ATC | 1 |
| 2006 | A novel approach to detecting DDoS Attacks at an Early Stage
Bin Xiao 0001, Wei Chen 0006, Yanxiang He |
J. Supercomput. | 2 |
| 2005 | Efficient and Beneficial Defense Against DDoS Direct Attack and Reflector Attack
Yanxiang He, Wei Chen 0006, Wenling Peng, Min Yang 0001 |
ISPA | 2 |
| 2005 | Detecting SYN Flooding Attacks Near Innocent Side
Yanxiang He, Wei Chen 0006, Bin Xiao 0001 |
MSN | 2 |
| 2004 | A Novel Technique for Detecting DDoS Attacks at Its Early Stage
Bin Xiao 0001, Wei Chen 0006, Yanxiang He |
ISPA | 2 |
| 2004 | Ontology Based Cooperative Intrusion Detection System
Yanxiang He, Wei Chen 0006, Min Yang 0001, Wenling Peng |
NPC | 2 |