Yanna Wu

dblp:02/4149 · DBLP profile ↗
← Back
9ranked-venue papers
1as first author
6since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2025 InstPro: Provenance-Based Transient Execution Attack Detection and Investigation on Instruction Execution Traces
abstract
Transient execution attacks (TEAs) are a serious threat to modern computing systems. While software/hardware hardening techniques have been proposed to mitigate the threat, developing detection techniques remains imperative, as they hold promise for flexible extension to address new variants, ease of deployment, and minimal system impact. Existing detection techniques face the following three limitations: unstable information sources, lack of explanation for attack scenarios, and limited training data. To address the limitations, we proposeInstPro, a TEA detection system thatidentifies a TEA program while providing an explanation of the attack scenario, based on instruction execution traces. Specifically,InstProfirst extractsprincipled cluesthat represent instruction sequences semantically close to attack abstraction. These clues provide high-level visualizations of TEA steps. Then,InstProcorrelates the clues into aclue provenance graphby reasoning about their causal dependencies, which provides a concise provenance representation. Finally,InstProreconstructs a scenario graph by using theInfoSubgraphsthat represent the information flows among principled clues. These InfoSubgraphs are more likely to capture a set of crucial principled clues that work together to represent the attack scenario. Our evaluations based on 5 datasets show thatInstProeffectively performs TEA detection and investigation.
Yu Wen 0001, Yanna Wu, Dan Meng 0002
IEEE Trans. Dependable Secur. Comput.4
2023 PRISPARK: Differential Privacy Enforcement for Big Data Computing in Apache Spark
abstract
Differential privacy has emerged as a gold standard privacy definition due to its persuasive mathematical guarantee. While various data protection mechanisms provide differential privacy for SQL queries of RDBMSs, enforcing differential privacy for big data platforms needs to be further researched. This work presents Prispark, which enforces differential privacy for Spark - the advanced distributed engine for large-scale data computing in big data ecosystems where sensitive data is often processed. Prispark targets to support various data processing (i.e., relational and unstructured queries) on Spark. In particular, to calculate a tighter sensitivity bound and improve the utility of results, we design the overall statistics estimation algorithm for estimating the upper bound of statistics with the filter condition, and propose a novel fine-grained operation-oriented rules set for calculating sensitivity of various relational and unstructured queries. Moreover, we propose a general differential privacy mechanism, Prispark, a suite including Prisparksql and Prisparkdag. We enforce Prisparksql at the Catalyst optimization layer for relational queries in Spark SQL and Prisparkdag at the RDD execution layer for unstructured queries in Spark core. Finally, we experimentally evaluate Prispark on TPC-H, TPC-DS, PigMix benchmarks, and real-world dataset LANL. The experimental results suggest that Prispark supports various applications/queries while improving the utility of all query results by orders of magnitude with negligible performance overhead.
Shuailou Li, Yu Wen 0001, Tao Xue 0003, Yanna Wu, Dan Meng 0002
SRDS5
2022 Deepro: Provenance-based APT Campaigns Detection via GNN
abstract
Advanced Persistent Threats (APTs) are typically sophisticated, stealthy and long-term attacks that are difficult to be detected and investigated. Recently proposed provenance graph based on system audit logs has become an important approach for APT detection and investigation. However, existing provenance-based approaches that either require rules based on expert knowledge or cannot pinpoint attack events in a provenance graph still cannot effectively mitigate APT attacks. In this paper, we present Deepro, a provenance-based APT campaign detection approach that not only effectively detects attack-relevant entities in a provenance graph but also precisely recovers APT campaigns based on the detected entities. Specifically, Deepro first customizes a general purpose GNN (Graph Neural Network) model to represent and detect process nodes in a provenance graph through automatically learning different patterns of attack behaviors and benign behaviors using the rich contextual information in the provenance graph. Then, Deepro further detects attack-relevant file and network entities according to their data dependencies with the detected process nodes. Finally, Deepro recovers APT campaigns through correlating detected entities based on their causality relationships in the provenance graph. We evaluated Deepro with ten real-world APT attacks. The evaluation result shows that Deepro can effectively detect attack events with an average 98.81% F1-score and thus produces precise provenance sub-graphs of APT attacks.
Yu Wen 0001, Yanna Wu, Dan Meng 0002
TrustCom4
2021 ACGVD: Vulnerability Detection Based on Comprehensive Graph via Graph Neural Network with Attention
Chunfang Li, Shuailou Li, Yanna Wu, Yu Wen 0001
ICICS (1)4
2021 Malicious Login Detection Using Long Short-Term Memory with an Attention Mechanism
Yanna Wu, Fucheng Liu, Yu Wen 0001
IFIP Int. Conf. Digital Forensics1
2021 DeepMal: maliciousness-Preserving adversarial instruction learning against static malware detection
abstract
Abstract Outside the explosive successful applications of deep learning (DL) in natural language processing, computer vision, and information retrieval, there have been numerous Deep Neural Networks (DNNs) based alternatives for common security-related scenarios with malware detection among more popular. Recently, adversarial learning has gained much focus. However, unlike computer vision applications, malware adversarial attack is expected to guarantee malwares’ original maliciousness semantics. This paper proposes a novel adversarial instruction learning technique, DeepMal, based on an adversarial instruction learning approach for static malware detection. So far as we know, DeepMal is the first practical and systematical adversarial learning method, which could directly produce adversarial samples and effectively bypass static malware detectors powered by DL and machine learning (ML) models while preserving attack functionality in the real world. Moreover, our method conducts small-scale attacks, which could evade typical malware variants analysis (e.g., duplication check). We evaluate DeepMal on two real-world datasets, six typical DL models, and three typical ML models. Experimental results demonstrate that, on both datasets, DeepMal can attack typical malware detectors with the mean F1-score and F1-score decreasing maximal 93.94% and 82.86% respectively. Besides, three typical types of malware samples (Trojan horses, Backdoors, Ransomware) prove to preserve original attack functionality, and the mean duplication check ratio of malware adversarial samples is below 2.0%. Besides, DeepMal can evade dynamic detectors and be easily enhanced by learning more dynamic features with specific constraints.
Jinghui Xu, Shuangshuang Liang, Yanna Wu, Yu Wen 0001, Dan Meng 0002
Cybersecur.4
2020 MLTracer: Malicious Logins Detection System via Graph Neural Network
abstract
Malicious login, especially lateral movement, has been a primary and costly threat for enterprises. However, there exist two critical challenges in the existing methods. Specifically, they heavily rely on a limited number of predefined rules and features. When the attack patterns change, security experts must manually design new ones. Besides, they cannot explore the attributes' mutual effect specific to login operations. We propose MLTracer, a graph neural network (GNN) based system for detecting such attacks. It has two core components to tackle the previous challenges. First, MLTracer adopts a novel method to differentiate crucial attributes of login operations from the rest without experts' designated features. Second, MLTracer leverages a GNN model to detect malicious logins. The model involves a convolutional neural network (CNN) to explore attributes of login operations, and a co-attention mechanism to mutually improve the representations (vectors) of login attributes through learning their login-specific relation. We implement an evaluation of such an approach. The results demonstrate that MLTracer significantly outperforms state-of-the-art methods. Moreover, MLTracer effectively detects various attack scenarios with a remarkably low false positive rate (FPR).
Fucheng Liu, Yu Wen 0001, Yanna Wu, Shuangshuang Liang, Xihe Jiang, Dan Meng 0002
TrustCom3
2007 Effect of Metacognitive Support on Student Behaviors in Learning by Teaching Environments
Jason Tan, John Wagster, Yanna Wu, Gautam Biswas
AIED3
2005 Teaching about Dynamic Processes A Teachable Agents Approach
Yanna Wu, Gautam Biswas
AIED2