近几年发表的部分论文
[1] Qingdi Han, Xiaoqi Zhao, Haipeng Qu, Gai-Ge Wang, Siqi Lu, and Yange Chen. SecSGX: Fine-Grained Monitoring for Runtime Integrity Verification in SGX. In 2026 International Conference on Intelligent Computing (ICIC), pp. 356-367. Springer, 2026.
[2] Yiwen Qin, Xiaoshuai Zhang, Haipeng Qu, Wenwen Tang, Zhiwen Zheng, Jin Liu, Zhiju Yang, and Xingru Huang. HMareN: Hierarchical Malicious Attack Representation Embedding Network for Web Attack Detection. In 2026 IEEE International Conference on Communications (ICC), pp. 1-6. IEEE, 2026.
[3] Xiaoshuai Zhang, Zhaoqing Wang, Zhen Yan, Qingdi Han, Xi-Jun Lin, Zhao Huang, Guangyuan Zhang, Yuhan Gao, Zhiwen Zheng, Haipeng Qu, and Jin Liu. Energy-Efficient Equality Test with Public Key Encryption and Flexible Authorisation for Sustainable Cloud Computing. In 2026 International Conference on Mobile Multimedia Communications (MoMM), Communications in Computer and Information Science, pp. 112-129. Springer, 2026.
[4] XiangFan Wu, Lingyun Ying, Guoqiang Chen, Yacong Gu, and Haipeng Qu. Cache Me, Catch You: Cache Related Security Threats in LLM Serving Frameworks. In 2026 Network and Distributed System Security Symposium (NDSS). 2026.
[5] Yacong Gu, Xiangfan Wu, Lingyun Ying, Yingyuan Pu, Haipeng Qu, Jianjun Chen, and Haixin Duan. Single Medium, Multiple Perspectives: Exposing and Exploiting Semantic Gaps in AI Services' Media Preprocessing Pipelines. In 2026 ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2026. (Accepted)
[6] Xinlin Xu, Xiaoshuai Zhang, Wenwen Tang, Hongshuai Qin, Huiyu Qi, Zhao Huang, Haipeng Qu, Jin Liu, Zhiwen Zheng, and Xingru Huang. MOSTE-Net: Physically Captured Hidden Target Mask Recovery from Single Relay-Wall Observations on RelayMask-Bench. In 2026 ACM International Conference on Multimedia (MM '26). ACM, 2026.
[7] Qingdi Han, Xiaoqi Zhao, Haipeng Qu, and Xiaoshuai Zhang. GATEGuard: Lifecycle-Aware and Bidirectional Data Protection for SGX Enclave Interfaces. Frontiers of Computer Science (2026). Available at: https://doi.org/10.1007/s11704-026-60686-8.
[8] Congyu Cao, Xiaohan Wang, Shunda Pan, Guohang Shen, and Haipeng Qu. Lanstree: Cross-Architecture Binary Code Similarity Detection with a Bidirectional Tree-Structured Embedding Model. In 2025 International Conference on Cryptology and Network Security (CANS), pp. 448-466. Springer, 2025.
[9] Mingxin Li, Yizhen Yu, Ningning Wang, Zhigang Wang, Xiaodong Wang, Haipeng Qu, Jia Xu, Shen Su, and Zhichao Yin. A Hybrid Framework for Effective and Efficient Machine Unlearning. In 2024 International Conference on Cyberspace Simulation and Evaluation, Communications in Computer and Information Science, pp. 318-331. Springer, 2025.
[10] Yu Zhang, Haipeng Qu, Lingyun Ying, and Linghui Wang. Maldet: An Automated Malicious npm Package Detector Based on Behavior Characteristics and Attack Vectors. In 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1942-1947. IEEE, 2024.
[11] Haocheng Li, Haipeng Qu, Gaozhou Wang, and Xiangjian Ge. EffiTaint: Boosting Sensitive Data Tracking with Accurate Taint Behavior Modeling and Efficient Access Path Optimization. In 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1397-1404. IEEE, 2024.
[12] Yuxiao Wang, and Haipeng Qu. FVscan: On-Chain Scanner for Function Visibility Vulnerability in Move Smart Contracts. In 2024 6th International Conference on Frontier Technologies of Information and Computer (ICFTIC), pp. 223-226. IEEE, 2024.
[13] Xiaoqi Zhao, Haipeng Qu, Jiaohong Yi, Jinlong Wang, Miaoqing Tian, and Feng Zhao. A Fuzzer for Detecting Use-After-Free Vulnerabilities. Mathematics 12, no. 21 (2024): 3431. Available at: https://doi.org/10.3390/math12213431.
[14] Ziyuan Yang, Haipeng Qu, Ying Hua, Xiaoshuai Zhang, and Xi-Jun Lin. Adversarial Attacks on Network Intrusion Detection Systems Based on Federated Learning. In 2024 20th International Conference on Intelligent Computing (ICIC), Lecture Notes in Computer Science. Springer, 2024. Available at: https://doi.org/10.1007/978-981-97-5606-3_13.
[15] Yiming Yan, Haiyong Zhao, and Haipeng Qu. A Browser Fingerprint Authentication Scheme Based on the Browser Cache Side-Channel Technology. Electronics 13, no. 14 (2024): 2728. Available at: https://doi.org/10.3390/electronics13142728.
[16] Zhen Yan, Haipeng Qu, and Xi-Jun Lin. On the Security of a Novel Construction of Certificateless Aggregate Signature Scheme for Healthcare Wireless Medical Sensor Networks. The Computer Journal 67, no. 9 (2024): 2819-2822. Available at: https://doi.org/10.1093/comjnl/bxae048.
[17] Zhuo Yan, Haipeng Qu, Lingyun Ying, Ke Liu, and Chao Qu. Enhanced Fast and Reliable Statistical Vulnerability Root Cause Analysis with Sanitizer. In 2024 IEEE Conference on Software Testing, Verification and Validation (ICST), pp. 47-58. IEEE, 2024.
[18] Qingdi Han, Siqi Lu, Wenhao Wang, Haipeng Qu, Jingsheng Li, and Yang Gao. Privacy preserving and secure robust federated learning: A survey. Concurrency and Computation: Practice and Experience 36, no. 13 (2024): e8084. Available at: https://doi.org/10.1002/cpe.8084.
[19] Zhen Yan, Xi-Jun Lin, Xiaoshuai Zhang, Jianliang Xu, and Haipeng Qu. Identity-Based Matchmaking Encryption with Equality Test. Entropy 26, no. 1 (2024): 74. Available at: https://doi.org/10.3390/e26010074.
[20] Qingdi Han, Xiaoshuai Zhang, Siqi Lu, Xiaoqi Zhao, and Zhen Yan. An SGX-based online voting protocol with maximum voter privacy. Journal of Systems Architecture 151 (2024): 103144. Available at: https://doi.org/10.1016/j.sysarc.2024.103144.
[21] Yuwei Liu, Yanhao Wang, Xiangkun Jia, Zheng Zhang, and Purui Su. AFGen: Whole-Function Fuzzing for Applications and Libraries. In 2024 IEEE Symposium on Security and Privacy (SP), pp. 1901-1919. IEEE Computer Society, 2024.
[22] Xiaoqi Zhao, Haipeng Qu, Jianliang Xu, Xiaohui Li, Wenjie Lv, and Gai-Ge Wang. A systematic review of fuzzing. Soft Computing 28, no. 6 (2024): 5493-5522. Available at: https://doi.org/10.1007/s00500-023-09306-x.
[23] Chao Qu, Rongqian Zhou, Ke Liu, Zhuo Yan, and Haipeng Qu. BSGAT: A Graph Attention Network for Binary Code Similarity Detection. In 2023 IEEE 28th Pacific Rim International Symposium on Dependable Computing (PRDC), pp. 161-167. IEEE, 2023.
[24] Xueyu Guan, Run Du, Xiaohan Wang, and Haipeng Qu. A Personalized Federated Multi-task Learning Scheme for Encrypted Traffic Classification. In 2023 International Conference on Artificial Neural Networks (ICANN), pp. 258-270. Springer, 2023.
[25] Nan Sun, Ningning Wang, Zhigang Wang, Jie Nie, Zhiqiang Wei, Peishun Liu, Xiaodong Wang, and Haipeng Qu. Lazy Machine Unlearning Strategy for Random Forests. In 2023 International Conference on Web Information Systems and Applications (WISA), pp. 383-390. Springer, 2023.
[26] Zhen Yan, Haipeng Qu, Xiaoshuai Zhang, Jianliang Xu, and Xi-Jun Lin. Identity-based proxy matchmaking encryption for cloud-based anonymous messaging systems. Journal of Systems Architecture 142 (2023): 102950. Available at: https://doi.org/10.1016/j.sysarc.2023.102950.
[27] Xianglong He, Yuezun Li, Haipeng Qu, and Junyu Dong. Improving Transferable Adversarial Attack via Feature-Momentum. Computers & Security 128 (2023): 103135. Available at: https://doi.org/10.1016/j.cose.2023.103135.
[28] Gu, Yacong, Lingyun Ying, Yingyuan Pu, Xiao Hu, Huajun Chai, Ruimin Wang, Xing Gao, and Haixin Duan. Investigating Package Related Security Threats in Software Registries. In 2023 IEEE Symposium on Security and Privacy (SP), pp. 1151-1168. IEEE Computer Society, 2022.
[29] Zhang, Mingyu, Wenqiang Ge, Ruichun Tang, and Peishun Liu. Hard Disk Failure Prediction Based on Blending Ensemble Learning. Applied Sciences 13, no. 5 (2023): 3288.
[30] Jian Zhuang, Ningning Wang, Zhigang Wang, Xiaodong Wang, Haipeng Qu, and Zhiqiang Wei. Spatial Data Publication Under Local Differential Privacy. In 2022 19th Web Information Systems and Applications Conference (WISA), Lecture Notes in Computer Science, pp. 627-637. Springer, 2022.
[31] Xiaoqi Zhao, Haipeng Qu, Jianliang Xu, Shuo Li, Gai-Ge Wang. AMSFuzz: An adaptive mutation schedule for fuzzing. Expert Systems with Applications 208 (2022): 118162.
[32] Qi Zhan, You Wu, Haipeng Qu, Xiaoqi Zhao. AcoFuzz: Adaptive energy allocation for greybox fuzzing. 2022 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW). IEEE 2022.
[33] Liu, Peishun, Bing Tian, Xiaobao Liu, Shijing Gu, Li Yan, Leon Bullock, Chao Ma, Yin Liu, and Wenbin Zhang. Construction of Power Fault Knowledge Graph Based on Deep Learning. Applied Sciences 12, no. 14 (2022): 6993.
[34] Shao, Yangyi, Wenbin Zhang, Peishun Liu, Ren Huyue, Ruichun Tang, Qilin Yin, and Qi Li. Log Anomaly Detection method based on BERT model optimization. In 2022 7th International Conference on Cloud Computing and Big Data Analytics (ICCCBDA), pp. 161-166. IEEE, 2022.
[35] Hao Zhang, Hui Xiao, Haipeng Qu, and Seok-Bum Ko. FPGA-Based Approximate Multiplier for Efficient Neural Computation. In 2021 IEEE International Conference on Consumer Electronics-Asia (ICCE-Asia), pp. 1-4. IEEE, 2021.
[36] Xiaoqi Zhao, Haipeng Qu, Wenjie Lv, Shuo Li, Jianliang Xu. MooFuzz: Many-objective optimization seed schedule for fuzzer. Mathematics 9.3 (2021): 205.
[37] Lin, X.-J., Sun, L. and Qu, H. (2021) 'Cryptanalysis of an anonymous and traceable group data sharing in cloud computing.' IEEE Transactions on Information Forensics and Security, 16, pp. 2773–2775. Available at: https://doi.org/10.1109/tifs.2021.3065505.
[38] Lin, X.-J., Wang, Q., Sun, L. and Qu, H. (2021) 'Identity-based encryption with Equality Test and Datestamp-based authorization mechanism.' Theoretical Computer Science, 861, pp. 117–132. Available at: https://doi.org/10.1016/j.tcs.2021.02.015.
[39] Lin, X.-J., Sun, L., H. Qu., and X. Zhang (2021) 'Public key encryption supporting equality test and flexible authorization without bilinear pairings.' Computer Communications, 170, pp. 190–199. Available at: https://doi.org/10.1016/j.comcom.2021.02.006.
[40] Gu, Shijing, Yuchun Chu, Wenbin Zhang, Peishun Liu, Qilin Yin, and Qi Li. Research on System Log Anomaly Detection Combining Two-way Slice GRU and GA-Attention Mechanism. In 2021 4th International Conference on Artificial Intelligence and Big Data (ICAIBD), pp. 577-583. IEEE, 2021.
[41] Lingni Kong, Yanyu Zhang. A disaster caused by a Bug: A black box escape of Qemu based on the USB device. Hack In The Box Security Conference (HITBSECCONF). 2021. (video)
[42] Xumei Li, Lei Sun, Ruobing Jiang, Haipeng Qu, Zhen Yan. OTA: An operation-oriented time allocation strategy for greybox fuzzing. 2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 2021.
[43] Lin, X. J., Wang, Q., Sun, L., Yan, Z., and Liu, P. (2021) 'Security analysis of the first certificateless proxy signature scheme against malicious-but-passive KGC attacks.' The Computer Journal, 64(4), pp. 653–660. Available at: https://doi.org/10.1093/comjnl/bxaa105.
[44] Jiahui Zhang, Qian Lu, Ruobing Jiang, and Haipeng Qu. PEDR: A Novel Evil Twin Attack Detection Scheme Based on Phase Error Drift Range. In 2020 International Conference on Security and Privacy in Communication Networks (SecureComm), pp. 188-207. Springer, 2020.
[45] Miaoqing Tian, Ruobing Jiang, Haipeng Qu, Qian Lu, and Xiaoyun Zhou. Advanced Temperature-Varied ECU Fingerprints for Source Identification and Intrusion Detection in Controller Area Networks. Security and Communication Networks 2020 (2020): 8834845. Available at: https://doi.org/10.1155/2020/8834845.
[46] Qian Lu, Ruobing Jiang, Yuzhan Ouyang, Haipeng Qu, and Jiahui Zhang. BiRe: A Client-side Bi-directional SYN Reflection Mechanism against Multi-model Evil Twin Attacks. Computers & Security 88 (2020): 101618. Available at: https://doi.org/10.1016/j.cose.2019.101618.
[47] Lin, X.-J., Sun, L. and Qu, H. (2020) 'Leakage-free ID-based signature, revisited.' The Computer Journal, 63(8), pp. 1263–1270. Available at: https://doi.org/10.1093/comjnl/bxz160.
[48] Lin, X. J., Sun, L., Yan, Z., Zhang, X., & Qu, H. (2020) 'On the security of a certificateless signcryption with known session-specific temporary information security in the standard model.' The Computer Journal, 63(8), pp. 1259–1262. Available at: https://doi.org/10.1093/comjnl/bxz157.
[49] Lei Sun, Xumei Li, Haipeng Qu, Xiaoshuai Zhang. AFLTurbo: Speed up path discovery for greybox fuzzing. 2020 IEEE 31st International Symposium on Software Reliability Engineering (ISSRE). IEEE, 2020.
[50] Xi-Jun Lin, Qihui Wang, Lin Sun, and Haipeng Qu. Public key encryption with equality test supporting datestamp-based authorization. ResearchGate, 2019.
[51] Miaoqing Tian, Ruobing Jiang, Chaoqun Xing, Haipeng Qu, Qian Lu, and Xiaoyun Zhou. Exploiting Temperature-Varied ECU Fingerprints for Source Identification in In-vehicle Network Intrusion Detection. In 2019 IEEE 38th International Performance Computing and Communications Conference (IPCCC), pp. 1-8. IEEE, 2019.
[52] Qian Lu, Haipeng Qu, Yuzhan Ouyang, and Jiahui Zhang. SLFAT: Client-Side Evil Twin Detection Approach Based on Arrival Time of Special Length Frames. Security and Communication Networks 2019 (2019): 2718741. Available at: https://doi.org/10.1155/2019/2718741.
[53] Qian Lu, Haipeng Qu, Yuan Zhuang, Xi-Jun Lin, and Yuzhan Ouyang. Client-Side Evil Twin Attacks Detection Using Statistical Characteristics of 802.11 Data Frames. IEICE Transactions on Information and Systems E101-D, no. 10 (2018): 2465-2473. Available at: https://doi.org/10.1587/transinf.2018edp7030.
[54] Xi-Jun Lin, Lin Sun, and Haipeng Qu. An efficient RSA-based certificateless public key encryption scheme. Discrete Applied Mathematics 241 (2018): 39-47. Available at: https://doi.org/10.1016/j.dam.2017.02.019.
[55] Lin, X. J., Sun, L., Qu, H., & Xian, H. Q. (2018) 'Cryptanalysis of a compact anonymous hibe with constant size private keys.' The Computer Journal, 62(8), pp. 1087–1091. Available at: https://doi.org/10.1093/comjnl/bxy130.
[56] Lin, X. J., Sun, L., Qu, H., & Liu, D. (2018) 'On the security of secure server-designation public key encryption with Keyword Search.' The Computer Journal, 61(12), pp. 1791–1793. Available at: https://doi.org/10.1093/comjnl/bxy073.
[57] Qu, H., Zhen, Y., Lin, X. J., Qi, Z., & Sun, L. (2018) 'Certificateless public key encryption with Equality Test.' Information Sciences, 462, pp. 76–92. Available at: https://doi.org/10.1016/j.ins.2018.06.025.
[58] Lin, X.-J., Sun, L. and Qu, H. (2018) 'Generic construction of public key encryption, identity-based encryption and signcryption with Equality Test.' Information Sciences, 453, pp. 111–126. Available at: https://doi.org/10.1016/j.ins.2018.04.035.
[59] Qian Lu, Haipeng Qu, Yuan Zhuang, Xi-Jun Lin, Yanyong Zhu, and Yunzheng Liu. A Passive Client-based Approach to Detect Evil Twin Attacks. In 2017 IEEE Trustcom/BigDataSE/ICESS, pp. 233-239. IEEE, 2017.
[60] Xi-Jun Lin, Lin Sun, Haipeng Qu, and Xiaoshuai Zhang. On the Security of the First Leakage-Free Certificateless Signcryption Scheme. The Computer Journal 60, no. 4 (2017): 491-496. Available at: https://doi.org/10.1093/comjnl/bxw058.
[61] Xi-Jun, L., Sun, L., Qu, H., & Liu, D. (2017) 'Cryptanalysis of a pairing-free certificateless signcryption scheme.' The Computer Journal, 61(4), pp. 539–544. Available at: https://doi.org/10.1093/comjnl/bxx104.
[62] Xi-Jun Lin, Lin Sun, and Haipeng Qu. Insecurity of an Anonymous Authentication for Privacy-preserving IoT Target-driven Applications. Computers & Security 48 (2015): 142-149. Available at: https://doi.org/10.1016/j.cose.2014.08.002.
近几年提交的部分安全漏洞(CVE)
1. ffjpeg:CVE-2019-19887; CVE-2019-19888
2. libIEC61850:CVE-2019-19930; CVE-2019-19931; CVE-2019-19944; CVE-2019-19957; CVE-2019-19958; CVE-2020-7054
3. stb:CVE-2020-6617; CVE-2020-6618; CVE-2020-6619; CVE-2020-6620; CVE-2020-6621; CVE-2020-6622; CVE-2020-6623
4. libsixel:CVE-2019-20056; CVE-2019-20205; CVE-2020-11721
5. gnuplot:CVE-2020-23512; CVE-2021-44917
6. libcroco:CVE-2020-12825
7. libavif:CVE-2020-17369
8. MediaInfoLib:CVE-2020-15395
9. libraw:CVE-2020-24865; CVE-2020-24866; CVE-2020-24867; CVE-2020-24868; CVE-2020-24869; CVE-2020-24870; CVE-2020-24889
10. ropium:CVE-2021-45761
11. GPAC:CVE-2021-44918; CVE-2021-44919; CVE-2021-44920; CVE-2021-44921; CVE-2021-44922; CVE-2021-44923; CVE-2021-44924; CVE-2021-44925; CVE-2021-44926; CVE-2021-44927; CVE-2021-45258; CVE-2021-45259; CVE-2021-45260; CVE-2021-45262; CVE-2021-45263; CVE-2021-45266; CVE-2021-45267; CVE-2021-45759; CVE-2021-45762; CVE-2021-45763; CVE-2021-45764; CVE-2021-45767; CVE-2021-45768; CVE-2021-45291; CVE-2021-45288; CVE-2021-45292; CVE-2021-45289; CVE-2021-45297; CVE-2021-45831; CVE-2021-46039; CVE-2021-46038; CVE-2021-46043; CVE-2021-46042; CVE-2021-46040; CVE-2021-46041; CVE-2021-46046; CVE-2021-46044; CVE-2021-46045; CVE-2021-46047; CVE-2021-46051; CVE-2021-32134; CVE-2021-46049; CVE-2021-46234; CVE-2021-46236; CVE-2021-44922; CVE-2021-46239; CVE-2021-46238; CVE-2021-46240; CVE-2022-22855; CVE-2021-46237; CVE-2021-46311; CVE-2021-46313; CVE-2022-24577; CVE-2022-24578; CVE-2022-24574; CVE-2022-24575; CVE-2022-24576; CVE-2022-4202; CVE-2022-45343
12. vim:CVE-2022-0216; CVE-2022-0318; CVE-2022-0158; CVE-2022-0156; CVE-2022-0213; CVE-2022-3520; CVE-2022-4293; CVE-2022-4292; CVE-2022-3491
13. binaryen:CVE-2021-45290; CVE-2021-45293; CVE-2021-46050; CVE-2021-46053; CVE-2021-46054; CVE-2021-46052; CVE-2021-46048; CVE-2021-46055
14. UPX:CVE-2021-44928; CVE-2021-39604
15. NASM:CVE-2021-45256; CVE-2021-45257
16. GNU Inetutils:CVE-2021-45777
17. mruby:CVE-2021-4188; CVE-2021-46020
18. libmodbus:CVE-2022-0367
19. HDF5:CVE-2021-45833; CVE-2021-45830; CVE-2021-45832; CVE-2021-45829; CVE-2021-46243; CVE-2021-46244; CVE-2021-46242
20. GNU recutils:CVE-2021-46019; CVE-2021-46021; CVE-2021-46022
21. Jerryscript:CVE-2021-46170
22. lib60870:CVE-2021-45773
23. libiec61850:CVE-2021-45769
24. Libmodbus:CVE-2022-0367
25. tsMuxer:CVE-2021-45860; CVE-2021-45861; CVE-2021-45863; CVE-2021-45864
26. rtl_433:CVE-2022-25050; CVE-2022-25051
27. Xpdf:CVE-2022-43295; CVE-2022-45586; CVE-2022-45587
2021级-刘珂:CVE-2022-43101; CVE-2022-43102; CVE-2022-43103; CVE-2022-43104; CVE-2022-43105; CVE-2022-43106; CVE-2022-43107; CVE-2022-43108; CVE-2022-43109
2021级-李逢天:CVE-2022-27374; CVE-2022-27375; CVE-2022-42077; CVE-2022-42078; CVE-2022-42079; CVE-2022-42080; CVE-2022-42081; CVE-2022-42082; CVE-2022-42084; CVE-2022-42085; CVE-2022-42086
团队成员发起的开源项目
[1] AFLTurbo:https://github.com/sleicasper/aflturbo
[2] OTA:https://github.com/lxumei/OTA
[3] AcoFuzz:https://github.com/Half-Quarter/AcoFuzz