Full Publication List
- [NDSS'26] Xue Tan, Hao Luan, Mingyu Luo, Zhuyang Yu, Jun Dai, Xiaoyan Sun, Ping Chen, "Was My Data Used for Training? Membership Inference in Open-Source LLMs via Neural Activations", The Network and Distributed System Security (NDSS) Symposium, 2026.
- [NDSS'26] Hao Luan, Xue Tan, Zhiheng Li, Jun Dai, Xiaoyan Sun, and Ping Chen, "Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack", The Network and Distributed System Security (NDSS) Symposium, 2026.
- [TMC'26] Tianya Zhao, Junqing Zhang, Jun Dai, Xiaoyan Sun, Xuyu Wang, "Unveiling the Threat: Data-Free Backdoor Attacks on Pre-Trained Models for RF Fingerprinting". IEEE Transactions on Mobile Computing (TMC). (Impact Factor: 6.5)
- [TDSC'25] Zhilong Wang, Chen Cao, Li Yu, Suhang Wang, Peng Liu, Xiaoyan Sun, Anoop Singhal, "DeepSanitizer: Combining Heuristic Rules and Deep Learning Models to Spot Silent Buffer Overflows in Binary", IEEE Transactions on Dependable and Secure Computing. (Impact Factor: 7).
- [TDSC'25] Duohe Ma, Junye Jiang, Jun Dai, Xiaoyan Sun, Zhimin Tang, Chaozhen Zhang, Kai Chen, "Got My "Invisibility" Patch: Towards Physical Evasion Attacks on Black-box Face Detection Systems", IEEE Transactions on Dependable and Secure Computing. (Impact Factor: 7).
- [EMNLP'25 Findings] Xue Tan, Hao Luan, Mingyu Luo, Xiaoyan Sun, Ping Chen, Jun Dai, "RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis", The 2025 Conference on Empirical Methods in Natural Language Processing (EMNLP 2025).
- [NDSS'25] Chang Yue, Kai Chen, Zhixiu Guo, Jun Dai, Xiaoyan Sun, Yi Yang, "What's Done Is Not What's Claimed: Detecting and Interpreting Inconsistencies in App Behaviors", The Network and Distributed System Security (NDSS) Symposium 2025. Acceptance rate: 16.1%.
- [SIGCSE'25] "Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS)", Deborah Kariuki, Ida Ngambeki, Jun Dai, Matt Bishop, Phillip Nico, Melissa Dark and Xiaoyan Sun, the 56th ACM Technical Symposium on Computer Science Education 2025.
- [ICICS'25] "MagWatch: Exposing Privacy Risks in Wearable Devices Through Electromagnetic Signals", Haowen Xu, Tianya Zhao, Xuyu Wang, Jun Dai, Xiaoyan Sun, The 27th International Conference on Information and Communications Security (ICICS 2025). Acceptance rate: 28%.
- [Computer'25] "Can AI Fix Buggy Code? Exploring the Opportunities and Obstacles for AI in Automated Program Repair", Lan Zhang, Anoop Singhal, Qingtian Zou, Xiaoyan Sun, Peng Liu, IEEE Computer. Impact Factor: 2. Accepted and to be published in Jul 2025.
- [COMPSAC'25] "Towards Development of Ready-to-Use Hands-on Labs with Portable Operating Environments for Digital Forensics Education". Tran Huynh, Haowen Xu, Brian Almaguer, Jun Dai, Xiaoyan Sun, The 49th IEEE International Conference on Computers, Software, and Applications (COMPSAC 2025). Acceptance rate: 27%.
- [MILCOM'25] "VibLeak: Towards Practical Covert Data Leakage via Phone Vibrations", Junye Jiang, Jingcheng Ju, Haowen Xu, Zhenlu Tan, Duohe Ma, Jun Dai, Xiaoyan Sun, The IEEE Military Communications Conference (MILCOM),
- [SIGCITE'25] "Project-based Teaching Aid for Secondary Education on Cyberattacks and Countermeasures". 26th Annual ACM Conference on Cybersecurity and Information Technology Education. Brian Almaguer, Cooper Dean, Edward Dang, Pamela Dooley, Brandyn Miller, Marina Moshchenko, Marti Shirley, Tabitha Senty, Melissa Dark, Xiaoyan Sun, Jun Dai,
- [JCS] Jin Wei, Ping Chen, Zhihao Zhang, Jun Dai, Xiaoyan Sun, Chang Xu, Yi Wang. "HuntFUZZ: Testing Error Handling Code through Concolic Execution-Assisted Fuzzing with Optimization", Journal of Computer Security. 2025.
- [WISE'25] "A Car Hacking Mini-Unit for High School Cybersecurity Education". The 17th World Conference on Information Security Education (WISE 2025). Cooper Dean, Brian Almaguer, Timothy Buck, Nichole Kunkle, Christian Nguyen, Preet Patel, Anne Roberts, Marti Shirley, Huirong Fu, Xiaoyan Sun, Jun Dai.
- [WISE'25] "INFER: Enhancing Digital Forensics Education through Ready-to-Use Hands-on Labs with Portable Operating Environments". The 17th World Conference on Information Security Education (WISE 2025). Tran Huynh, Haowen Xu, Brian Almaguer, Jun Dai, Xiaoyan Sun.
- [IEMTRONICS'25] "New Key Encapsulation Method for Authentication in 5G Network in Post-quantum Era", 2025 International IOT, Electronics and Mechatronics Conference, Gennady Khalimov, Xiaoyan Sun, Yevgen Kotukh, Illia Dzhura, Alexandr Wyglinski, Hlib Khivrenko.
- [IWSPA'25] "Exploring Prompt Patterns for Effective Vulnerability Repair in Real-World Code by Large Language Models", Yining Luo, Baobao Li, Anoop Singhal, Peiyu Tseng, Lan Zhang, Qingtian Zou, Xiaoyan Sun and Peng Liu. 11th ACM International Workshop on Security and Privacy Analytics (IWSPA 2025).
- [S&P'25 (Poster)] Pei-Yu Tseng, Lan Zhang, Anoop Singhal, ZihDwo Yeh, Xushu Dai, Xiaoyan Sun, Peng Liu. "Poster: Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers". 46th IEEE Symposium on Security and Privacy (S&P 2025).
- [PETS'25 (Poster)] "Eavesdropping on the Wrist: Inferring User Behavior from Smartwatch EM Emissions", Haowen Xu, Tianya Zhao, Xuyu Wang, Jun Dai, Xiaoyan Sun, Privacy Enhancing Technologies Symposium (PETS) 2025 (PETS 2025).
- [SenSys'25 (Poster)] Tran Huynh, Ting Xu, Yinxin Wan, Jun Dai, Xiaoyan Sun, "Poster Abstract: Optimizing IoT Cross-rule Vulnerability Detection through Reinforcement Learning-Based Fuzzing". The 23rd ACM Conference on Embedded Networked Sensor Systems (SenSys 2025).
- [JCS'24] "SQLaser: Detecting DBMS Logic Bugs with Clause-Guided Fuzzing'', Jin Wei, Ping Chen, Kangjie Lu, Jun Dai, Xiaoyan Sun, Journal of Computer Security. Journal paper.
- [SVCC'24] "Exploring Scalable Bayesian Network For Identification of Zero-day Attack Paths", Ravi Nitinkumar Patel, Xiaomei Zhang, Xiaoyan Sun, Jun Dai, Silicon Valley Cybersecurity Conference (SVCC) 2024.
- [IntelliSys2024] "A Two-Layer AI-Integrated Multiple-Camera System for Detecting Human Intrusions" 10th Intelligent Systems Conference 2024 (IntelliSys2024). Jun Dai, Beerdwinder Deep Kaur, Xiaoyan Sun.
- [Computer'24] "Using Explainable AI for Neural Network Based Network Attack Detection". Qingtian Zou, Lan Zhang, Xiaoyan Sun, Anoop Singhal, Peng Liu. IEEE Computer. Impact Factor: 2. 2024.
- [JCS'24] Qingtian Zou, Lan Zhang, Anoop Singhal, Xiaoyan Sun and Peng Liu, "Analysis of Neural Network Detectors for Network Attacks", Journal of Computer Security. 2024.
- [IWSPA'24] "Evaluating Large Language Models for Real-World Vulnerability Repair in C/C++ Code", Lan Zhang, Qingtian Zou, Anoop Singhal, Xiaoyan Sun and Peng Liu. 10th ACM International Workshop on Security and Privacy Analytics (IWSPA 2024).
- [NESD'24 (Poster)] "Security Risk Analysis of Machine Learning Systems Using Causality Graphs", Anoop Singhal, Peng Liu, Qingtian Zou, Xiaoyan Sun, Lan Zhang, New England Security Day 2024 (NESD). Poster.
- [JoCS] Duohe Ma, Zhimin Tang, Yaqin Zhang, Xiaoyan Sun, Liming Wang, Xinzhe Wang, "Research on Active Defense-based Anti-Ransomware Technology", Journal of Cyber Security. Impact Factor: 2.9. In Chinese. 2023.
- [ISCC‘23] Zhimin Tang, Duohe Ma, Xiaoyan Sun, Kai Chen, Liming Wang and Junye Jiang, "Every Time Can Be Different: A Data Dynamic Protection Method Based on Moving Target Defense", 2023 IEEE Symposium on Computers and Communications. 2023.
- [IFIP WG 11.9'23] Rajani Mohan Suryavanshi, Xiaoyan Sun and Jun Dai. "Identifying Superspreaders: Ranking System Object Instance Graph", 19th IFIP WG 11.9 International Conference on Digital Forensics, Arlington, VA, USA. 2023.
- [MTD'22] Duohe Ma, Zhimin Tang, Xiaoyan Sun, Lu Guo, Liming Wang and Kai Chen, "Game Theory Approaches for Evaluating the Deception-based Moving Target Defense", 9th ACM Workshop on Moving Target Defense (MTD), in conjunction with the ACM Conference on Computer and Communications Security (CCS) 2022.
- [ICISS'22] Qingtian Zou, Lan Zhang, Anoop Singhal, Xiaoyan Sun and Peng Liu, "Attacks on ML Systems: From Security Risk Analysis to Mitigation", International Conference on Information Systems Security (ICISS2022).
- [JCS'21] Qingtian Zou, Anoop Singhal, Xiaoyan Sun and Peng Liu, “Deep Learning for Detecting Logic-flaw-exploiting Network Attacks: An End-to-end Approach”, Journal of Computer Security. 2021.
- [DBSEC'21] Qingtian Zou, Anoop Singhal, Xiaoyan Sun and Peng Liu, “Deep Learning for Detecting Network Attacks: An End-to-end Approach”, DBSec2021 (35th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy), 2021.
- [IPCCC'20] Yaqin Zhang, Duohe Ma, Xiaoyan Sun, Kai Chen, and Feng Liu, What You See Is Not What You Get: Towards Deception-Based Data Moving Target Defense, the 39th IEEE International Performance Computing and Communications Conference (IPCCC 2020), 2020.
- [GLOBECOM'20] Jait Purohit, Xuyu Wang, Shiwen Mao, Xiaoyan Sun, and Chao Yang, Fingerprinting-based Indoor and Outdoor Localization with LoRa and Deep Learning, The 2020 IEEE Global Communications Conference (GLOBECOM), Taipei, Taiwan, 2020.
- [ICWS'20] Yaqin Zhang, Duohe Ma, Xiaoyan Sun, Kai Chen, and Feng Liu, WGT: Thwarting Web Attacks Through Web Gene Tree-based Moving Target Defense, The International Conference on Web Services (ICWS), 2020. (acceptance rate of 19%)
- [TIFS'18] Xiaoyan Sun, Jun Dai, Peng Liu, Anoop Singhal, John Yen, Using Bayesian Networks for Probabilistic Identification of Zero-day Attack Paths. Journal paper, IEEE Transactions on Information Forensics and Security (TIFS), Oct 2018.
- [DBSEC'18] Chen Cao, Lun-Pin Yuan, Anoop Singhal, Peng Liu, Xiaoyan Sun, Sencun Zhu, Assessing Attack Impact on Business Processes by Interconnecting Attack Graphs and Entity Dependency Graphs;, 32nd Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy (DBSec18), Jul 2018.
- [SecureComm'18] Yulong Dong, Jun Dai, Xiaoyan Sun, A Mobile Botnet that Meets Up at Twitter, 14th EAI International Conference on Security and Privacy in Communication Networks (SecureComm 2018), Aug 2018.
- [DBSEC'17] Xiaoyan Sun, Anoop Singhal, Peng Liu, Towards Actionable Mission Impact Assessment in the Context of Cloud Computing;, 31st Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy (DBSec), Philadelphia, PA USA, 2017.
- [CNS'16] Xiaoyan Sun, Jun Dai, Peng Liu, Anoop Singhal, John Yen; Towards Probabilistic Identification of Zero-day Attack Paths;, IEEE Conference on Communications and Network Security (CNS 2016), Philadelphia, PA USA, 2016 (Best Paper Runner-Up Award).
- [SecureComm'14] Xiaoyan Sun, Jun Dai, Anoop Singhal, Peng Liu;Inferring the Stealthy Bridges between Enterprise Network Islands in Cloud Using Cross-Layer Bayesian Networks”, 10th International Conference on Security and Privacy in Communication Networks (SecureComm), Beijing, China, 2014 (Best Paper Award Nomination).
- [ESORICS'13] Jun Dai, Xiaoyan Sun, Peng Liu, Patrol: Revealing Zero-day Attack Paths through Network-wide System Object Dependencies”, 18th European Symposium on Research in Computer Security (ESORICS), RHUL, Egham, U.K., 2013.
- [ICNC'23] Anand Masurkar, Xiaoyan Sun, Jun Dai, Using Blockchain for Decentralized Artificial Intelligence with Data Privacy, International Conference on Computing, Networking and Communications (ICNC 2023).
- [ICNC'23] Niteesh Reddy Thota, Xiaoyan Sun, Jun Dai, Early Rumor Detection in Social Media Based on Graph Convolutional Networks, International Conference on Computing, Networking and Communications (ICNC 2023).
- [SVCC'22] Gargi Gopalkrishna Prabhugaonkar, Xiaoyan Sun, Xuyu Wang, Jun Dai, "Deep IoT Monitoring: Filtering IoT Traffic Using Deep Learning", 3rd International Silicon Valley Cybersecurity Conference (SVCC), 2022.
- [JoCS] Yaqin Zhang, Duohe Ma, Xiaoyan Sun, Chuan Zhou, Feng Liu, “Survey on Deceptive Moving Target Defense”, Journal of Cyber Security, 2021.
- [Computer] Qingtian Zou, Xiaoyan Sun, Anoop Singhal, and Peng Liu, An Approach for Detection of Advanced Persistent Threat Attacks [Cybertrust], IEEE Computer. Column paper. 2020.
- [IWSPA'20] Qingtian Zou, Anoop Singhal, Xiaoyan Sun, and Peng Liu, Automatic Recognition of Advanced Persistent Threat Tactics for Enterprise Security, the 6th ACM International Workshop on Security and Privacy Analytics 2020 (IWSPA), colocated with CODASPY 2020.
- [S&P'19-Poster] Anoop Singhal, Qingtian Zou, Xiaoyan Sun, and Peng Liu, Using Machine Learning for Detection of Advanced Persistent Threats. IEEE Symposium on Security and Privacy 2019. Poster.
- [ICNC'19] Pranavi Appana, Xiaoyan Sun, Yuan Cheng;What To Do First: Ranking the Mission Impact Graph for Effective Mission Assurance; International Conference on Computing, Networking and Communications (ICNC 2019).
- [ICNC'18] Swarna Gopalan, Aditi Kulkarni, Arpitaben Narendrabhai Shah, Jun Dai, Jinsong Ouyang, Pinar Muyan-Ozcelik and Xiaoyan Sun; Don't Be Surprised: I See Your Mobile App Stealing Your Data, International Conference on Computing, Networking and Communications (ICNC 2018), Mar 2018.
- [IEEE S&P Journal] Xiaoyan Sun, Peng Liu, Anoop Singhal, Toward Cyberresiliency in the Context of Cloud Computing [Resilient Security]. IEEE Security & Privacy 16, no. 6 (2018): 71-75. 2018, article.
- [ICST TSS] Xiaoyan Sun, Jun Dai, Anoop Singhal, Peng Liu, Probabilistic Inference of the Stealthy Bridges between Enterprise Networks in Cloud, ICST Transactions on Security and Safety, Journal paper, Jan 2018.
- [Springer] Xiaoyan Sun, Jun Dai, Peng Liu, Anoop Singhal, John Yen, Using Bayesian Networks to Fuse Intrusion Evidences and Detect Zero-day Attack Paths;, Springer LNCS volume, Network Security Metrics and Applications;, Book chapter, Nov 2017.
- [Springer] Xiaoyan Sun, Jun Dai, Anoop Singhal, Peng Liu, Enterprise Cyber Situation Awareness, In P. Liu, S. Jajodia, and C. Wang (Eds.), in Theory and Models for Cyber Situation Awareness, Springer. Book Chapter, 2017
- [SafeConfig'15] Xiaoyan Sun, Anoop Singhal, Peng Liu, Who Touched My Mission: Towards Probabilistic Mission Impact Assessment;, SafeConfig: Automated Decision Making for Active Cyber Defense (Collocated with ACM CCS 2015), Denver, Colorado, USA, 2015.
- [CogSIMA'13] Xiaoyan Sun, Jun Dai, Peng Liu, SKRM: Where Techniques Talk to Each Other, IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA), San Diego, USA, 2013. Short Paper.
- [ASE ICCS'12] Jun Dai, Xiaoyan Sun, Peng Liu, Nicklaus Giacobe, Gaining Big Picture Awareness through an Interconnected Cross-layer Situation Knowledge Reference Model, 2012 ASE International Conference on Cyber Security, Washington DC, USA, 2012 (Acceptance ratio: 9.6%).
- [ICFN'10] Xiaoyan Sun, Yuanlv Bao, Wei Lu, Jun Dai, Zhe Wang;A Study on Performance of Inter-Vehicle Communications in Bidirectional Traffic Streams, International Conference on Future Networks (ICFN), Sanya, China, 2010.
- [VNC'09] Xiaoyan Sun, Yuanlv Bao, Jun Dai, Wei Lu, Zhe Wang, Performance Analysis of Inter-vehicle Communications in Multilane Dynamic Traffic Streams, IEEE Vehicular Networking Conference (VNC), Tokyo, Japan, 2009.
- [NETS4CARS'09] Wei Lu, Yuanlv Bao, Xiaoyan Sun, Zhe Wang, Performance Evaluation of Inter-vehicle Communication in a Unidirectional Dynamic Traffic Flow with Shockwave, International Workshop on Communication Technologies for Vehicles, Oct 2009.
- [CMP] Yanjun Liu, Zhen'an Liu, Xiaoyan Sun, C Programming Language Practice Tutorial, China Machine Press. ISBN: 7111250532, 9787111250531 2009. Book. In Chinese.
- [MET] Xiaoyan Sun, Ping Huang, Class Teaching of Electronic Circuits Based on Multisim, Modern Electronics Technique, Issue 24, 2006. Journal Paper. In Chinese.