VLDB 2026 Research / reviewers in the wild / expert
Degang Sun
dblp:07/6827
· DBLP profile ↗
73ranked-venue papers
17as first author
48since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 5 first-author · 8 since 2021Computer networks · 17 · 6 first-author · 12 since 2021Artificial intelligence and machine learning · 15 · 5 first-author · 10 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 first-author · 8 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AEGIS: A Multi-agent Collaborative Framework with Adversarial Self-Play for Encrypted Malware Traffic Detection
Degang Sun, Guanyao Du, Chun Long |
KSEM (4) | 2 |
| 2026 | When BERT meets BLOCK: A pre-training and fine-tuning malicious encrypted traffic detection method based on protocol semantic units
Degang Sun, Guanyao Du, Chun Long |
Comput. Networks | 2 |
| 2026 | Heterogeneous data-driven resolution generation for software systems via large language models
Degang Sun, Haitian Yang, Weiqing Huang |
Inf. Process. Manag. | 2 |
| 2026 | Manod: A multi-modal anomaly detection framework for distributed system
Degang Sun, Haitian Yang, Weiqing Huang |
Neural Networks | 2 |
| 2026 | Mitigating the Impact of Malware Evolution on API Sequence-Based Windows Malware DetectorsabstractIn dynamicWindows malware detection, deep learning models are extensively deployed to analyze API sequences. Methods based on API sequences play a crucial role in malware prevention. However, due to the continuous updates of APIs and the changes in API sequence calls leading to the constant evolution of malware variants, the detection capability of API sequence-based malware detection models significantly diminishes over time. We observe that the API sequences of malware samples before and after evolution usually have similar malicious semantics. Specifically, compared to the original samples, evolved malware samples often use the API sequences of the pre-evolution samples to achieve similar malicious behaviors. For instance, they access similar sensitive system resources and extend new malicious functions based on the original functionalities. In this paper, we propose a framework MME(Mitigating the impact of Malware Evolution), a framework that can enhance existing API sequence-based malware detectors and mitigate the adverse effects of malware evolution. To help detection models capture the similar semantics of these post-evolution API sequences, our framework represents API sequences using API knowledge graphs and system resource encodings and applies contrastive learning to enhance the model’s encoder. Results indicate that, compared to regular Text-CNN, our framework can significantly reduce the false positive rate by 13.10% and improve the F1-Score by 8.47% on five years of data, achieving the best experimental results. Additionally, evaluations show that our framework can save on the human costs required for model maintenance. We only need 1% of the budget per month to reduce the false positive rate by 11.16% and improve the F1-Score by 6.44%. Xingyuan Wei, Qiujian Lv, Degang Sun |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | A Personalized Secondary Perturbation Mechanism Based on Local Differential PrivacyabstractWith the development of location-based services (LBS) in mobile internet and smart devices, privacy leakage concerns are escalating. While differential privacy has gained traction for location protection due to its rigorous guarantees, existing methods face two critical challenges: repeatedly applying identical mechanisms at a single location enables attackers to leverage background knowledge for inference attacks, compromising true location privacy; meanwhile, they lack personalized privacy configurations and associated service quality metrics. To address these issues, we propose PSPLDP, implementing dual Laplace perturbation under local differential privacy to fulfill location specific privacy requirements. And we introduce a service quality evaluation metric suitable for personalized privacy settings. Experiments on real world datasets demonstrate our method's effectiveness against inference attacks and the capability of the metric to quantify service quality across diverse privacy settings. Yan Wang 0081, Degang Sun |
CSCWD | 3 |
| 2025 | DFilter: A Network Access Layer Collaborative Defense Model for Moving Target DefenseabstractDue to the inherent properties of IT networks, such as the determinacy of network composition, the statics of network structure, and the homogeneity of network elements, network defense is always in a passive position in cyberattack-defense con-frontations. In response, cybersecurity researchers have proposed using Moving Target Defense technology to reverse it. However, in practical application scenarios, while Moving Target Defense demonstrates its defensive value, it also introduces several issues such as increased network complexity, limited processing performance due to restricted by network protocol stack, and inherent limitations of related technologies themselves. This article constructs a network access layer collaborative defense model, DFilter based on XDP-eBPF. The policy preprocessing layer implements the O(1) time complexity network traffic filtering and matching algorithm, and further refines the control strength of the state-of-the-art algorithm based on security labels. On this basis, the multi-dimensional and fine-grained collaborative defense methods proposed by the policy disposal layer, enriching the diversity of model defense capabilities. Based on the model and algorithm proposed in this article, an experimental topology environment was constructed and comprehensive experimental evaluation were completed. The experimental results showed that DFilter effectively improved the preprocessing efficiency of network access layer traffic, further refined the control strength and significantly enhanced the variability of the network traffic. Degang Sun, Xinbo Han, Weiqing Huang |
CSCWD | 2 |
| 2025 | VN-GT: Optimizing Virtual Network Deployment via Game TheoryabstractThe static and homogeneous nature of traditional networks presents a significant challenge for our defense efforts. These characteristics enable an experienced attacker to quickly determine our network topology and gather detailed information about the internal hosts through systematic scanning techniques. Implementing a virtual network view can mitigate this by simulating a virtual topology, thereby consuming the attacker’s resources and time. However, deploying a virtual network view reduces network throughput and increase latency. Additionally, an improperly configured virtual network view can waste resources and degrade Quality of Service (QoS). Most existing studies have focused solely on the defender’s perspective, resulting in overly idealistic solutions that are ineffective in real-world scenarios. To address this, we propose VN-GT, a game-theoretic based model that optimizes virtual network deployment by considering both attackers and defenders. We provide a detailed example scenario, analyze the game’s equilibrium, and validate the effectiveness of our method through a real attack and defense experiment. Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Zuxin Chen, Siyuan Li 0014, Min Yu 0001, Weiqing Huang, Degang Sun |
ICASSP | 8 |
| 2025 | ProCom: Progressive Multi-modal Knowledge Graph Completion via Adaptive Function
Xiaoyu Kang, Zhixin Shi, Degang Sun, Tengfan Weng, Liyue Ren |
ICIC (8) | 3 |
| 2025 | MetaSSL-ETD: Robust Detection of Malicious Encrypted Traffic Based on Semi-supervised Meta-learning
Guanyao Du, Yuhai Lu, Chun Long, Degang Sun |
ICIC (4) | 6 |
| 2025 | GMCWare: A Greedy Modularity Community-based Simplification Algorithm for Malware DetectionabstractWith the widespread adoption of Android devices, the number of malware instances continues to rise, posing severe threats to users’ security and privacy. Existing malware detection methods primarily rely on static or dynamic analysis, typically performing machine learning classification by extracting features such as permissions or sensitive API calls. However, these methods fail to adequately capture the behavioral patterns of malware and face efficiency bottlenecks when dealing with complex data structures like Function Call Graphs (FCG). To address this, we propose a malware detection method based on the Behavior Relation Graph (BRG). By simplifying the Function Call Graph using community detection algorithms, we partition the complex graph structure into several communities, thereby extracting the functional modules and behavioral patterns of malware and significantly reducing the complexity of analysis. Subsequently, we vectorize the BRG using Graph Neural Networks (GNNs) and combine it with a classification model to achieve high-performance detection and interpretation of malware. Experimental results demonstrate that our method performs excellently on a large-scale dataset containing 12,408 benign software samples and 7,658 malware samples, with an average of 44,704 function nodes. We achieved a classification performance of 100% accuracy and a 100% F1-Score, significantly improving detection accuracy and providing an efficient and reliable solution for malware analysis. Xingyuan Wei, Congying Liu, Degang Sun |
IJCNN | 6 |
| 2025 | Multi-Modal Fake News Detection with LLMs and Knowledge-Aligned Attention NetworksabstractWith the booming rise of the Internet and social media, semantically rich multimodal data has gradually become the mainstream carrier of news dissemination. Among them, multi-modal fake news with illustrations and text has attracted widespread attention due to its greater deceptiveness. However, existing research methods are mainly limited to the analysis of images and text within the news itself, failing to fully consider the consistency and discrepancy characteristics between different modalities, which hinders the full exploitation of the advantages of multi-modal fusion. To address this issue, this study proposes a multi-modal fake news detection method with large language models(LLMs) and Knowledge-Aligned Attention Networks(MFDnet). This method first leverages the powerful semantic understanding capabilities of large language models to generate detailed text descriptions for images, serving as a knowledge supplement for the image model. Subsequently, by constructing a Knowledge-Aligned Attention Networks, it achieves efficient semantic fusion between the knowledge-supplemented image model and text modal information, thereby effectively extracting the consistency and complementary features between different modalities. Experimental results demonstrate that this model exhibits excellent performance on multiple public fake news detection datasets. Degang Sun, Yan Wang 0081, Xuan Zhao 0011, Haitian Yang, Weiqing Huang |
ISCC | 2 |
| 2025 | Flow Microelement-Driven Traffic Relationship Analysis: Robust Detection of Malicious Encrypted TrafficabstractEncryption technologies randomize network communication to protect user privacy. However, attackers exploit encrypted traffic to conceal malicious activities. The existing detection methods rely primarily on traffic content or interactive patterns. Nevertheless, static methods can be easily obfuscated by advanced attacks. Since the set of potential attacks is open and infinite, models regularly lose effectiveness against novel attacks. Robust encrypted malicious traffic detection remains a valuable research area. In this paper, we propose BSTS-Net, a robust unsupervised encrypted malicious traffic detection model based entirely on traffic relations. The key motivations are to construct a relation-based traffic contextual representation and to establish dynamic baselines for anomaly detection. To represent local relations within flows, we innovatively introduce the concept of traffic microelements, which capture fine-grained interaction pattern relations. To integrate the global relationships between flows, we construct a traffic microelement space based on the Siamese neural network. Three optimization functions are proposed to optimize the intraservice, interservice and internode relations. For robust detection, we introduce a reputation-enhanced dynamic encrypted traffic detection algorithm that constructs dynamic baselines and continuously detects novel anomalies. We evaluate BSTS-Net through extensive experiments on three datasets and compare it with seven SOTA methods. Our results demonstrate its superiority, with an F1 score of more than 99.63% across all the datasets in multiclassification scenarios. Additionally, we simulate three adversarial scenarios for robustness analysis. Although the baseline methods experience an F1 score degradation of 32.21%, BSTS-Net achieves high performance, with only 1% degradation. Hao Fu 0030, Degang Sun, Jinxia Wei, Chun Long |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | MLNT: A Multi-Level Network Traps Deployment MethodabstractTraditional honeypot technology combines trap deployment component with attack deception response component, and the more network traps are deployed, the more system resources, such as virtual machines and containers, are required. To alleviate this problem, we propose a transparent network deception defense method called MLNT. MLNT decouples the trap deployment component and attack deception response component, reducing the dependence of high-density traps on system resources. First, MLNT can complete multi-layer network trap deployment, including trap service ports of real assets, network node traps of security domains, and security domain traps. Second, MLNT can transparently deploy network traps on real protection targets. It protects valuable assets in Industrial Control Networks and the Internet of Things, where software agents can not be installed. Finally, we implemented the MLNT framework using FPGA and tested it’s capability of delaying the attackers’ progress. The experimental results demonstrate the effectiveness and feasibility of MLNT. Guokun Xu, Weijie Wang 0005, Degang Sun, Yanpeng Ma, Yan Wang 0081, Weiqing Huang |
CSCWD | 3 |
| 2024 | A New Method of Cyber Deception DefenseabstractNew network attacks such as Advanced Persistent Threats (APTs) have created an asymmetric dynamic between attackers and defenders. Traditional defense mechanisms typically focus on perimeter security, rendering them ineffective once attackers infiltrate the network. Cyber deception defense, on the other hand, proactively establishes a deceptive environment to manipulate attackers’ perceptions and decisions, thereby delaying, detecting, and potentially thwarting attacks. This paper introduces a novel approach rooted in cyber deception defense, utilizing FPGA technology. By harnessing network packet rewriting techniques on FPGA, this method rapidly generates numerous disguised hosts and ports. The implementation of this approach on an FPGA hardware platform allows for the evaluation of its effectiveness. In simulated environments, the method demonstrates remarkable efficiency in constructing deceptive environments, with a policy query time of approximately 50ns. Transitioning to real-world network scenarios, the prototype system extends the time required for attackers to identify genuine hosts by a factor of 4.5. Moreover, the average delay time of the prototype system in processing 64-byte data packets is approximately 5.68us, showcasing consistent performance across various deception strategies. Crucially, the system’s overhead remains minimal, effectively confounding and deterring attackers while increasing the complexity and cost associated with mounting successful attacks. Chaochao Liu, Degang Sun, Zhixin Shi |
ISCC | 2 |
| 2024 | MICABAC: Multidimensional Industrial Control Attribute-Based Access Control ModelabstractAs the Industrial Control System (ICS) increasingly merges with the Internet, the security threats have been increasing from internal users and external hackers. These challenges are further intensified by the facts: industrial control devices and protocols, leading to the inadequacy of traditional access control models in tackling the intricacies of ICS. We identify attributes that are optimally aligned with the specific needs of the ICS environment and propose the Multidimensional Industrial Control Attribute-Based Access Control Model (MICABAC) as a customized solution. MICABAC model significantly improves access control security and is finer granularity by selecting and evaluating required attributes within various ICS. We have been validated in two real-world ICS environments: the Gas Pipe Network System (GPNS) and the Computer Numerical Control (CNC) machine tool. Experiments indicate that by integrating MICABAC into the existing system, the maximum delay for access requests is 63.83 ms. In terms of accuracy in defending against malicious attacks, the GPNS achieves 96.49% and the CNC reaches 94.86%. Finally, we discuss the advantages and limitations of MICABAC and explore potential directions for future research. Hangyu Wang, Fei Lv 0010, Yuqi Chen 0001, Shuaizong Si, Zhiwen Pan, Degang Sun, Limin Sun 0001 |
SMC | 6 |
| 2024 | Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceabstractProvenance graphs are structured audit logs that describe the history of a system’s execution. Recent studies have explored a variety of techniques to analyze provenance graphs for automated host intrusion detection, focusing particularly on advanced persistent threats. Sifting through their design documents, we identify four common dimensions that drive the development of provenance-based intrusion detection systems (PIDSes): scope (can PIDSes detect modern attacks that infiltrate across application boundaries?), attack agnosticity (can PIDSes detect novel attacks without a priori knowledge of attack characteristics?), timeliness (can PIDSes efficiently monitor host systems as they run?), and attack reconstruction (can PIDSes distill attack activity from large provenance graphs so that sysadmins can easily understand and quickly respond to system intrusion?). We present Kairos, the first PIDS that simultaneously satisfies the desiderata in all four dimensions, whereas existing approaches sacrifice at least one and struggle to achieve comparable detection performance.Kairos leverages a novel graph neural network based encoder-decoder architecture that learns the temporal evolution of a provenance graph’s structural changes to quantify the degree of anomalousness for each system event. Then, based on this fine-grained information, Kairos reconstructs attack footprints, generating compact summary graphs that accurately describe malicious activity over a stream of system audit logs. Using state-of-the-art benchmark datasets, we demonstrate that Kairos outperforms previous approaches. Qiujian Lv, Jinyuan Liang, Yan Wang 0081, Degang Sun, Thomas Pasquier, Xueyuan Han |
SP | 5 |
| 2024 | DSGN: Log-based anomaly diagnosis with dynamic semantic gate networks
Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang |
Inf. Sci. | 2 |
| 2024 | DualAttlog: Context aware dual attention networks for log-based anomaly detection
Haitian Yang, Degang Sun, Weiqing Huang |
Neural Networks | 2 |
| 2023 | GHunter: A Fast Subgraph Matching Method for Threat HuntingabstractThreat hunting is the process of proactively searching for known attack behavior in an organization’s information system. A popular approach to threat hunting uses cyber threat intelligence (CTI) to identify advanced persistent threats (APTs) that are hidden in kernel-level audit logs (e.g., whole-system data provenance). However, existing threat hunting mechanisms can-not produce timely results due to the enormous size of provenance data. As a result, threat hunting cannot help sysadmins to quickly recognize an ongoing APT campaign and immediately block any subsequent attack activity. In this paper, we propose GHunter, a system that performs approximate subgraph matching using graph neural networks (GNNs) to quickly and accurately hunt APTs. GHunter first converts known APT scenarios and provenance logs into graph data. Then, GHunter uses GNNs to embed APT scenario graphs and provenance graphs to discover any subgraph relationships. If an APT scenario graph is a subgraph of a provenance graph, GHunter alerts to sysadmins the presence of the corresponding APT scenario in the system. We use DARPA’s Transparent Computing (TC) datasets to evaluate GHunter’s performance. The results show that GHunter achieves 97% accuracy when hunting APTs from millions of provenance log entries and spends 195x less execution time than prior work. Rujie Dai, Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
CSCWD | 7 |
| 2023 | ABTD-Net: Autonomous Baggage Threat Detection Networks for X-ray ImagesabstractAutomated security screening has a significant role In protecting public spaces from security threats by employing X-ray images to detect prohibited items. However, there are challenges of noise production due to squeezing, occlusion, and penetration of luggage objects. Additionally, the hues of objects are monotonous and lack luster. To solve these problems, we propose an Autonomous Baggage Threat Detection Network (ABTD-Net) for accurate prohibited item detection. To tackle the difficulty of capturing distinctive visual features, we constructed a Feature Adjustment Head (FAH) to refine pyramid features. Specifically, we designed an Attention Module (AM) at several places after initially using a Dense Unidirectional Propagation (DUP) to filter noise. Furthermore, we created a Feature Fusion Head (FFH) that dynamically fuses hierarchical visual information under object occlusion, including early-fusion and late-fusion. Extensive experiments on security inspection X-ray datasets OPIXray and HiXray demonstrate the superiority of our proposed method. Degang Sun, Yan Wang 0081, Zhongyuan Chen, Xinbo Han, Haitian Yang |
ICME | 2 |
| 2023 | ASGNet: Adaptive Semantic Gate Networks for Log-Based Anomaly Diagnosis
Haitian Yang, Degang Sun, Yanshu Li, Yan Wang 0081, Weiqing Huang |
ICONIP (4) | 2 |
| 2023 | AdaptParse: Adaptive Contextual Aware Attention Network for Log Parsing via Word ClassificationabstractLogs are widely used during the development and maintenance of software systems. Logs assist developers and operation & maintenance personnel to understand the state and behavior of systems at runtime. Also, logs can diagnose system failures and conduct abnormal analyses to provide further protection to the security of systems. However, large software systems generate large amounts of semi-structured logging routinely. The first step to support further analysis is how to parse semi-structured records with free-form text log messages into structured templates. Therefore, log parsing is rather challenging. Because logs are generated by static templates (i.e., log statements) in the source code, templates are often not accessible when parsing logs. It is worth noting that most proposed approaches still rely on log-specific heuristics or manual rule extraction. Those existed methods are often specialized for parsing certain log types and often neglect the semantic meaning of log messages, thus limiting performance scores and generalization, hence, in this paper, we propose a new parsing technique - Adaptive Contextual Aware Attention Network for Log Parsing via Word Classification, named AdaptParse. Adapt-Parse transforms the template generation problem into a word classification task, then learns the features of template words and variable words. We evaluate our AdaptParse on 5 realworld log datasets and compare the performance with 7 parsing techniques. Our experimental results show that the proposed approach can effectively understand the semantic meaning of log messages and achieve accurate log parsing results. Overall, AdaptParse achieves state-of-the-art performance on five realworld log datasets, outperforming all the baseline models. Haitian Yang, Degang Sun, Yan Wang 0081, Shixiang Zhang, Weiqing Huang |
IJCNN | 2 |
| 2023 | IAD-Net: Multivariate KPIs Interpretable Anomaly Detection with Dual Gated Residual Fusion NetworksabstractAnomaly detection of key performance indicators (KPIs), e.g., CPU load, network usage, is crucial for system behavior monitoring. In recent years, several anomaly detection approaches have been proposed. However, detecting anomalies of KPIs remains challenging because of the stochastic nature and complex temporal dependence of multivariate time series. Additionally, the presence of noise and the unavailability of labeled data in large-scale datasets limit the effectiveness of anomaly detection. In this paper, we propose IAD-Net, an interpretable anomaly detection method with Dual Gated Residual Fusion Networks. The main idea is to model the inter-metric and temporal dependencies simultaneously by using gated residual blocks and two-stream fusion. Additionally, we utilize Gated Recurrent Unit (GRU) to extract long-term global trend patterns of an input sequence. Finally, both the forecasting-based model and the reconstruction-based model are combined in order to focus on single-timestamp predictions and latent representations of time series. Extensive experiments on real-world data show that IAD-Net outperforms other state-of-the-art approaches according to F1-score. Further analysis confirms the effectiveness of our method in anomaly interpretation. Degang Sun, Haitian Yang, Yan Wang 0081 |
TrustCom | 2 |
| 2023 | LWVN: A Lightweight Virtual Network View Method to Defend Lateral MovementabstractDue to traditional network topologies’ static and homomorphic characteristics, attackers can rapidly expand their attack results through lateral movement (LM) attacks. Virtual Network View technology has emerged as an effective approach to disrupt attackers’ ability to detect and exploit network topologies during LM and can increase the difficulty of malicious activities. However, existing Virtual Network View deployS virtual views for each core asset, resulting in wasting of resource. To alleviate this problem, we propose a lightweight Virtual Network View deployment method called LWVN. First, the Location Centrality (LC) of the network nodes in the attack path is measured, the larger the LC is, the network node is more important and the more virtual network view costs we can invest. To further quantify the comprehensive impact of network nodes’ location centrality on high-value assets, we quantify the Assets’ Value(AV). Then, we model internal network risk and operational costs as constraints and find the optimal strategies for deploying a virtual network view. We define metrics for hidden capacity, detect capacity, and deployment cost to measure the effectiveness of deployment virtual network views. We conduct simulations to verify the effectiveness and feasibility of LWVN. Degang Sun, Guokun Xu, Weijie Wang 0005, Yan Wang 0081, Qiujian Lv |
TrustCom | 1 |
| 2023 | DTrap: A cyberattack-defense confrontation technique based on Moving Target DefenseabstractIn the evolution process of cyberattack-defense confrontation, both sides have always been in a state of mutual confrontation and collaborative development, continuously upgrading their tools to improve adversarial capabilities. However, in this arms race, the positions of the both sides are imbalanced. As the party actively initiating the attack, attackers always is able to actively adjust the attack strategy based on the detected defense vulnerabilities to launch effective attacks. While the defenders always detecting defense vulnerabilities after suffering losses and filling them in a "patching" manner. This post awareness security protection strategy has a "fatal time difference" when dealing with unknown attacks. This paper aims to change the imbalanced state. Therefore, a attack confrontation model DTrap is proposed based on the concept of moving target defense, which introduce of high simulation trap hosts to achieve IP address and service port confusion. It can simulate real hosts to achieve various common network protocol requests and responses, and it can provide better dynamism than Honeypot when adjusting trap policies. DTrap can reverse the imbalance situation by increasing attack costs and promoting attack difficulty. We constructed a real adversarial environment, the security effectiveness of the DTrap model was evaluated through comprehensive and multi-dimensional experiments. The results indicate that DTrap can exert expected effectiveness in resisting network attacks of different dimensions, and effectively enhance the network attack confrontation ability. Degang Sun, Yan Wang 0081, Xinbo Han, Weiqing Huang |
TrustCom | 2 |
| 2022 | ITAR: A Method for Indoor RFID Trajectory Automatic Recovery
Ziwen Cao, Siye Wang, Degang Sun, Yue Feng 0001 |
CollaborateCom (2) | 3 |
| 2022 | Hierarchical Graph Convolutional Skeleton Transformer for Action RecognitionabstractGraph convolutional networks (GCNs) have emerged as dom-inant methods for skeleton-based action recognition. How-ever, they still suffer from two problems, namely, neighbor-hood constraints and entangled spatiotemporal feature repre-sentations. Most studies have focused on improving the de-sign of graph topology to solve the first problem but they have yet to fully explore the latter. In this work, we design a dis-entangled spatiotemporal transformer (DSTT) block to over-come the above limitations of GCNs in three steps: (i) feature disentanglement for spatiotemporal decomposition; (ii) global spatiotemporal attention for capturing correlations in the global context; and (iii) local information enhancement for utilizing more local information. Thereon, we propose a novel architecture, named Hierarchical Graph Convolutional skeleton Transformer (HGCT), to employ the complementary advantages of GCN (i.e., local topology, temporal dynamics and hierarchy) and Transformer (i.e., global context and dy-namic attention). HGCT is lightweight and computationally efficient. Quantitative analysis demonstrates the superiority and good interpretability of HGCT. Ruwen Bai, Fengfa Li, Junxing Ren, Degang Sun |
ICME | 7 |
| 2022 | MMSP: A LSTM Based Framework for Multi-Step Attack Prediction in Mixed ScenariosabstractA multi-step attack scenario consisting of more than one attack step is difficult to predict because of various attack steps and complex combinations. The multi-step attack scenarios occurring simultaneously construct a mixed attack scenario, which is more common than a single attack scenario in practical systems. However, most of the existing multi-step attack prediction approaches only focus on a single attack scenario. In this paper, a framework MMSP is proposed for multi-step attack prediction in mixed scenarios. MMSP fractionates alerts by separating them into different scenarios and removing redundant samples. The attack scenarios fingerprint database of MMSP is built by modeling the attack steps regarding different scenarios based on the long short-term memory (LSTM) model. Each scenario corresponds to an LSTM model. A scenario matching method is also proposed to find potential attack scenarios hiding in the real-time alerts from the database. Finally, MMSP feeds fractionated alerts into the matched scenarios' LSTM models to predict attack steps. Extensive evaluations based on real-world datasets show that MMSP outperforms the state-of-the-art attack step prediction model in both single and mixed scenarios. MMSP achieves a 14.3 % -38.1 % improvement in accuracy for attack step prediction in the single scenario. In particular, MMSP can maintain a high level accuracy in mixed attack scenarios. Degang Sun, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
ISCC | 2 |
| 2022 | Implicit Continuous Authentication Model Based on Mobile Terminal Touch BehaviorabstractMost existing identity authentication technologies rely on some ways for the first login authentication, such as personal identification number (PIN), track, or biological characteristics. However, these ways exist plenty of security risks, which make people face password guessing attacks, trace attacks, and shoulder surfing attacks for a long time. Once the illegal users forge identity to complete authentication or bypass first login authentication, their subsequent behavior will become out of control. To solve the above problems, we propose an implicit continuous authentication model based on the touch behavior of the mobile terminal. The model uses the data collected by the accelerometer, gyroscope, and magnetometer to generate feature vectors and extracts the feature vectors containing macroscopic features, microscopic features, and joint features. And we design a convolutional bidirectional recurrent neural network model to distinguish the sensor feature vectors. On this basis, we perform various experiments on a large dataset Hand Movement, Orientation, and Grasp (HMOG) with different sensor characteristics. Compared with the most advanced models proposed recently, the results show that our model achieves an equal error rate (EER) of 0.53%, which significantly improves authentication accuracy. Rui Mao 0004, Heming Ji, Yan Wang 0081, Degang Sun |
ISCC | 6 |
| 2022 | Rethinking the Misalignment Problem in Dense Object Detection
Yang Yang 0087, Bo Meng 0006, Zihao Huang 0007, Junxing Ren, Degang Sun |
ECML/PKDD (3) | 6 |
| 2022 | R-TDBF: An Environmental Adaptive Method for RFID Redundant Data Filtering
Ziwen Cao, Degang Sun, Siye Wang, Yue Feng 0001 |
WASA (2) | 2 |
| 2022 | On Eliminating Blocking Interference of RFID Unauthorized Reader Detection
Degang Sun, Siye Wang |
WASA (1) | 1 |
| 2022 | Interference Prediction between LEO Constellations based on A Novel Joint Prediction Model of Atmospheric AttenuationabstractThis paper proposes a novel joint prediction model of atmospheric attenuation for the accurate interference prediction of low earth orbit (LEO) constellation systems. Firstly, a total atmospheric attenuation joint prediction model based on the actual satellite link elevation angles is defined. Secondly, we apply the elevation-based total atmospheric attenuation joint prediction model to the interference analysis of LEO constellation systems in the downlink direction, and the modified analytical expression of interference evaluation indicator ΔT/T based on the proposed model is also derived. Finally, we select OneWeb and GW satellite systems for simulation to verify the accuracy and efficiency of the proposed model in this paper. The results show that the elevation-based total atmospheric attenuation joint prediction model can provide more accurate interference prediction results than the existing attenuation prediction models, while the simulation time overhead reduce by 93.78%. Furthermore, the results indicate that in order to accurately predict the interference between LEO constellation systems, the total atmospheric attenuation cannot be ignored. Jingru Geng, Degang Sun, Wen Wang 0014 |
WCNC | 2 |
| 2022 | DMalNet: Dynamic malware analysis based on API feature engineering and graph learning
Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 8 |
| 2022 | A novel deep framework for dynamic malware detection based on API sequence intrinsic features
Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 5 |
| 2022 | BertHANK: hierarchical attention networks with enhanced knowledge and pre-trained model for answer selection
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Degang Sun, Weiqing Huang |
Knowl. Inf. Syst. | 4 |
| 2021 | DeepMIT: A Novel Malicious Insider Threat Detection Framework based on Recurrent Neural NetworkabstractCurrently, more and more malicious insiders are making threats, and the detection of insider threats is becoming more challenging. The malicious insider often uses legitimate access privileges and mimic normal behaviors to evade detection, which is difficult to be detected via using traditional defensive solutions. In this paper, we propose DeepMIT, a malicious insider threat detection framework, which utilizes Recurrent Neural Network (RNN) to model user behaviors as time sequences and predict the probabilities of anomalies. This framework allows DeepMIT to continue learning, and the detections are made in real time, that is, the anomaly alerts are output as rapidly as data input. Also, our framework conducts further insight of the anomaly scores and provides the contributions to the scores and, thus, significantly helps the operators to understand anomaly scores and take further steps quickly(e.g. Block insider's activity). In addition, DeepMIT utilizes user-attributes (e.g. the personality of the user, the role of the user) as categorical features to identify the user's truly typical behavior, which help detect malicious insiders who mimic normal behaviors. Extensive experimental evaluations over a public insider threat dataset CERT (version 6.2) have demonstrated that DeepMIT has outperformed other existing malicious insider threat solutions. Degang Sun, Meichen Liu, Meimei Li, Zhixin Shi, Pengcheng Liu 0007 |
CSCWD | 1 |
| 2021 | Density Weighted Diversity Based Query Strategy for Active LearningabstractDeep learning has made remarkable achievements in various domains. Active learning, which aims to reduce the budget for training a machine-learning model, is especially useful for the Deep learning tasks with the demand of a large number of labeled samples. Unfortunately, our empirical study finds that many of the active learning heuristics are not effective when applied to Deep learning models in batch settings. To tackle these limitations, we propose a density weighted diversity based query strategy (DWDS), which makes use of the geometry of the samples. Within a limited labeling budget, DWDS enhances model performance by querying labels for the new training samples with the maximum informativeness and representativeness. Furthermore, we propose a beam-search based method to obtain a good approximation to the optimum of such samples. Our experiments show that DWDS outperforms existing algorithms in Deep learning tasks. Tingting Wang 0010, Xufeng Zhao 0002, Qiujian Lv, Degang Sun |
CSCWD | 5 |
| 2021 | A Few-Shot Class-Incremental Learning Approach for Intrusion DetectionabstractClassic network intrusion detection methods usually are supervised machine learning models, which are obtained by offline training and can achieve good performance in the initial stage of system construction. However, with the rapid and diverse evolution of intrusion methods, the learned knowledge is no longer suitable for new types of attacks. In addition, existing incremental learning approaches lack rapid learning capabilities and are hard to avoid potential risks and reduce property losses when there are few new samples. This can be attributed to the few-shot class-incremental intrusion detection issue. To address this issue, we propose a learning strategy, named ID-FSCIL, which could respond to the increase in attack categories by extending the origin detection system. It fully mines new intrusion patterns from few samples with meta-learning and maximizes the model’s generalization ability to deal with emerging attacks. Our evaluations show that ID-FSCIL significantly outperforms the state-of-the-art baselines on the NSL-KDD dataset under incremental learning settings. Tingting Wang 0010, Qiujian Lv, Degang Sun |
ICCCN | 4 |
| 2021 | Sprelog: Log-Based Anomaly Detection with Self-matching Networks and Pre-trained Models
Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang |
ICSOC | 3 |
| 2021 | FUNC-ESIM: A Dual Pairwise Attention Network for Cross-version Binary Function MatchingabstractBinary function matching compares two pieces of binary functions to identify their similarities, which has wide applications in the field of malware origin tracing, vulnerability searching, binary level plagiarism detection, etc. Up-to-date methods commonly independently map each function to an embedding and rarely consider fine-grained pairwise semantic similarity, which influences the accuracy of matching. Moreover, few methods are available to detect similarities between versions spanning a long period for cross-version vulnerability detection or patch positioning. To solve these issues, we propose a novel binary function matching method, which takes a pair of binary functions as input, and then computes a similarity score jointly on the pair through a specifical dual pairwise cross-attention network. Specially, we apply our method to detecting similarities between cross-version binaries. The experimental analysis demonstrates that FUNC-ESIM achieves promising results on the cross-version binary matching task, where the average recall@1 reaches 85.98%. Degang Sun, Yunting Guo, Min Yu 0001, Gang Li 0009, Chao Liu 0020, Weiqing Huang |
IJCNN | 1 |
| 2021 | FKTAN: Fusion Keystroke Time-Textual Attention Networks for Continuous AuthenticationabstractWith the rapid development of computer technology, the traditional Internet data security and information privacy issues are gradually expanding to all aspects of society as a whole. As the first line of defense for information security, identity authentication technology becomes crucial. Among the many authentication technologies, continuous authentication technology has gained increasing attention. In this paper, we design fusion keystroke time-textual attention networks for continuous authentication based on the keystroke data (keystroke time series, keystroke text) when users enter free-text. Specifically, the corresponding keystroke time series and the corresponding keystroke text are first obtained based on the original keystroke data, and then the keystroke time series and the keystroke text are input into the BiLSTM model and the pre-training model, respectively; the BiLSTM can better capture the temporal features, and the pre-training model can better capture the textual features when authenticating the user. Finally, the two information are fed into the cross attention model to better integrate the two information. Experiments show that the FKTAN model achieves promising results on two datasets, Clarkson II keystroke dataset and Buffalo dataset, outperforming all baseline models. Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang |
ISCC | 2 |
| 2021 | Multi-Modal fake news Detection on Social Media with Dual Attention Fusion NetworksabstractMost of the existed fake news detection works on social media driven-fake news mainly focused on text. However, more and more social media platforms like Twitter, facebook, etc, allow users to create multi-modal contents, including text, image and video. Hence, it is obvious that only investigating text contents is insufficient to achieve solid detection. In this paper, we study the fake news on social media platforms composed of multimodal contents (text and images), and propose Dual Attention Fusion Networks for fake news detection on social media. We explore three modalities, (text modality, image modality and image attributes modality), and further propose a Dual Attention Fusion Networks (DAFN) model for this task. First, our proposed model extracts text modality and image modality, respectively. We then pass combinations of image attributes modality and text modality through BERT to extract text features. Finally, we reconstruct features of three modalities and fuse them into a feature vector for prediction. Our method is verified on realworld datasets consisting of collected social media platforms. Experiments show that the our method achieves promising results on real world datasets. outperforming all baseline models. Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang |
ISCC | 3 |
| 2021 | Graph Attention Convolutional Network with Motion Tempo Enhancement for Skeleton-Based Action Recognition
Ruwen Bai, Bo Meng 0006, Junxing Ren, Yang Yang 0087, Degang Sun |
PRICAI (3) | 8 |
| 2021 | Objects as Extreme Points
Yang Yang 0087, Bo Meng 0006, Zihao Huang 0007, Junxing Ren, Degang Sun |
PRICAI (3) | 6 |
| 2021 | URTracker: Unauthorized Reader Detection and Localization Using COTS RFID
Degang Sun, Yue Feng 0001, Jinxing Xie, Siye Wang |
WASA (1) | 1 |
| 2021 | SNR-Centric Power Trace Extractors for Side-Channel AttacksabstractExisting power trace extractors consider the case where the number of power traces available to the attacker is sufficient to guarantee successful attacks, and the goal of power trace extraction is to extract a small part of traces with high signal-to-noise ratio (SNR) to reduce the complexity of attacks rather than to increase the success rates. Although strict theoretical proofs are given, the existing power trace extractors are too simple and leakage characteristics of Points-of-Interest (POIs) have not been thoroughly analyzed. They only maximize the variance of the data-dependent power consumption component and ignore the noise component, which results in very limited SNR that hampers the performance of extractors. In this article, we provide a rigorous theoretical analysis of SNR of power traces, and propose a simple yet efficient SNR-centric extractor, named shortest distance first (SDF), to extract power traces with the smallest estimated noise by taking advantage of known plaintexts. In addition, to maximize the variance of the exploitable component while minimizing the noise, we refer to the SNR estimation model and propose another novel extractor named maximizing estimated SNR first (MESF). Finally, we further propose an advanced extractor called mean-optimized MESF (MMESF) that exploits the mean power consumption of each plaintext byte value to more accurately and reasonably estimate the data-dependent power consumption of the corresponding samples. Experiments on both simulated power traces and measurements from an ATmega328p micro-controller demonstrate the superiority of our new extractors. Changhai Ou, Siew-Kei Lam, Degang Sun, Xinping Zhou, Kexin Qiao, Qu Wang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2020 | Terminator: a data-level hybrid framework for intellectual property theft detection and preventionabstractRecently, high profile data breach incidents have highlighted the importance of insider Intellectual Property(IP) theft research. Matching the patterns of known attack (filtering-based or rule-based) and finding the deviation from normal behavior (anomaly-based) are two typical approaches to prevent insiders from stealing sensitive information. On the one hand, filtering-based or rule-based solutions provide accurate identification of known attacks, and thus they are suitable for IP theft prevention, but they cannot handle the insiders with in-depth knowledge of the protective measures. On the other hand, anomaly-based solutions can find unknown attacks but typically have a high false-positive rate, which limits their applicability to practice. Nowadays, more and more researchers believe that the insider attack could be improved when combining known attack pattern matching with anomaly detection technologies. Therefore, in this paper, we introduce a Data-level Hybrid Framework, dubbed as Terminator, which enabling both detection and prevention. Terminator integrates a prevention module with an anomaly detection module and uses feedback to improve the module for detection or prevention. Different from previous anomaly-based methods that could only detect anomalous activities, Terminator could detect the stealing actions proactively and take real-time actions on these actions. The effectiveness of Terminator is demonstrated by its excellent performances on a collected dataset, involving detailed information in a real-world insider network and attack data simulated by impersonating the genuine users. Meichen Liu, Meimei Li, Degang Sun, Zhixin Shi, Pengcheng Liu 0007 |
CF | 3 |
| 2020 | Parallel spatial-temporal convolutional neural networks for anomaly detection and location in crowded scenes
Zhengping Hu, Shufang Li, Degang Sun |
J. Vis. Commun. Image Represent. | 4 |
| 2019 | Risk Prediction for Imbalanced Data in Cyber Security : A Siamese Network-based Deep Learning Classification FrameworkabstractRisk prediction plays an important role in network security which can be used to predict riskiest parts and then proactive measures can be adopted to avoid potential damage. Most existing literature model risk prediction problems as binary classification problems by using machine learning methods. However, these traditional machine learning models have poor performance - tending to misclassify the risky ones into the category of risk-free - on risk prediction task when the datasets are imbalanced or small in size. In this paper, we propose a Siamese Network Classification Framework (SNCF) that can map the Siamese network to a classification based on the similarity to alleviate imbalance for risk prediction. Experimental results on imbalanced data in risk prediction verify that the deep learning-based classification architecture SNCF has better efficiency when compared with other algorithms. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
IJCNN | 1 |
| 2019 | Cyber Profiles Based Risk Prediction of Application Systems for Effective Access ControlabstractApplication systems maintain critical sensitive information of an enterprise and especially huge number of data with specific ownership. Unauthorized modification or deletion of data caused by cyber attacks may bring tremendous loses for enterprises. To reduce the damage of cyber attacks, existing techniques have been proposed to predict the potential risk of external attacks at the level of an enterprise, a user, or a machine. However, risk prediction has not been conducted at the level of application systems, which may suffer from external attacks or insider threats. This paper proposes a model based on machine learning to predict whether the application systems of an enterprise have the risk of unauthorized access by using a cyber profile. In particular, the cyber profile is composed of features extracted from the information of the three domains in cyberspace: Information Infrastructure domain, Data domain, and Application domain. The core idea of the model selects the most significant features that have a large impact on the occurrence of unauthorized access to application systems. At last, by using a limited number of selected features, high forecast accuracy is achieved. These results verify the effectiveness of the prediction model, which can potentially be exploited to guide the adjustment of access control policies for effective access control. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
ISCC | 1 |
| 2019 | Group Collision AttackabstractKey enumeration schemes are used to post-process the scores given by side channel distinguishers and enumerate the key candidates from the most possible one to the least possible one, which can be regarded as optimal tools of key search. However, the application of them is limited by very large key candidate space and computing power consumption. For example, the attacker may spend several weeks or months enumerating the whole 245key candidates. Unlike the former literature that try to propose a more efficient algorithm to process the distinguishers, scores of key candidates directly, we focus on pre-processing and reducing the key candidate space. To achieve this goal, a new divide and conquer strategy named group collision attack (GCA) is proposed in this paper. The GCA works as follows in brief. The key candidates are first divided into groups on which intra-group collision attack is used to remove the impossible key combinations in each group. Then, the inter-group collision attack is performed to further remove the impossible key combinations between groups. Thus, the complexity of key enumeration is reduced significantly. A series of practical experiments are carried out by using our GCA and the experimental results verify its efficiency. Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Could we beat a new mimicking attack?abstractFlooding DDoS and Flash Crowds (FC) are difficult to be discriminated from network layer because both of them have too many statistical similarities. If attacker learnt those statistical difference and could produce some mimicking traffic which have little difference from traffic produced by legitimate uses in FC, which means existing methods will uselessness. In order to verify the existence of this possibility, this paper proposes an idea that employed Least Squares Generative Adversarial Networks (LSGANs) to generate mimicking traffic to make the defense system uselessness. By experiments evaluated, the proposed idea could mimicking traffic to fool the defense system. The proposed idea mainly focuses on traffic statistical information of each Bot and legitimate user, does not rely on network environments, so the possibility of this mimicking attack happened could be existed in other networks, such as wired network, wireless network and mobile network. Degang Sun, Zhixin Shi |
APNOMS | 1 |
| 2017 | A Novel Use of Kernel Discriminant Analysis as a Higher-Order Side-Channel Distinguisher
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005 |
CARDIS | 4 |
| 2017 | A New Mimicking Attack by LSGANabstractDiscriminating Distributed Denial of Service Attacks (DDoS) from Flash Crowds (FC) is a tough and challenging problem. If attackers could generate mimicking traffic which have little difference from the traffic produced by legitimate users in FC, are existing methods and defense systems still able to distinguish DDoS from FC? To verify the possibility of the existence of this mimicking attack and prove the existing methods cannot discriminate this attack from FC, this paper proposes an idea employed Least Squares Generative Adversarial Networks (LSGAN) to generate mimicking traffic based on a statistical features achieved from an extensive analysis of user traffic behavior of DDoS and FC. Then to establish an efficient defense system employed Random Forest to prove it can achieve better performance on real network traffic traces, but cannot discriminate this mimicking attack traffic from FC. The experiments results show the proposed idea can generate this mimicking attack traffic and the defense system cannot discriminate it from FC. In addition, a comparison with GAN has been made to show that LSGAN is better than GAN in performance. Degang Sun, Zhixin Shi |
ICTAI | 1 |
| 2017 | A Behavior-Based Method for Distinction of Flooding DDoS and Flash Crowds
Degang Sun, Zhixin Shi |
KSEM | 1 |
| 2017 | Categorising and Comparing Cluster-Based DPA Distinguishers
Xinping Zhou, Carolyn Whitnall, Elisabeth Oswald, Degang Sun, Zhu Wang 0005 |
SAC | 4 |
| 2017 | Detecting Flooding DDoS Under Flash Crowds Based on Mondrian Forest
Degang Sun, Zhixin Shi, Yan Wang 0081 |
WASA | 1 |
| 2017 | A Novel Method for Specific Emitter Identification Based on Singular Spectrum AnalysisabstractAs wireless platforms grow in popularity and store valuable information, their security becomes increasingly important. Specific emitter identification (SEI) is a novel means of enhancing the security of wireless networks. Thus, an automatic SEI system with good performance is meaningful. In this paper, a novel method for SEI based on singular spectrum analysis (SSA) is proposed. It uses SSA to analyze the transient signals and extract features for identification of mobile phones. A complete identification system is presented and its performance is evaluated by volume experiments, which show that the proposed method is efficient even at a reduced signal to noise ratio. Degang Sun, Yanyun Xu, Jianlin Hu |
WCNC | 1 |
| 2016 | Error Tolerance based Single Interesting Point Side Channel CPA DistinguisherabstractThe efficiency can be significantly improved if the attacker uses interesting points to perform Correlation Power Analysis (CPA). The prerequisite for this is that the attacker knows the positions of interesting points. However, it is difficult for the attacker to accurately find the locations of interesting points if he only has a small number of power traces. In this paper, we propose a Frequency based Interesting Points Selection algorithm (FIPS) to select interesting points under the condition that the attacker only has a very small number of power traces. Moreover, an error tolerant Single Interesting Point based CPA (SIP-CPA) is proposed. Experiments on AES algorithm implemented on an AT89S52 single chip and power trace set of DPA contest v1 of DES algorithm implemented on the Side Channel Attack Standard Evaluation Board (SASEBO) show that, our SIP-CPA can significantly improve the efficiency of CPA. Changhai Ou, Zhu Wang 0005, Juan Ai, Xinping Zhou, Degang Sun, Victor E. DeBrunner |
AsiaCCS | 5 |
| 2016 | Research on Security Algorithm of Virtual Machine Live Migration for KVM Virtualization System
Zhujun Zhang, Tingting Wang 0010, Sihan Qing, Degang Sun |
ICICS | 6 |
| 2016 | Group Verification Based Multiple-Differential Collision Attack
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai |
ICICS | 3 |
| 2016 | A novel wavelet based independent component analysis method for pre-processing computer video leakage signalabstractComputer displays emit electromagnetic waves, which compromise the information displayed by the computer. This can be a potential information security threat as the sensitive information can be stolen from a distance without leaving any trace. The video leakage signals contain the information of the image displayed in the computer, so the video leakage signals can be seen as special image signals. However, different from the normal image signal, the signal to noise ratio (SNR) of video leakage signal is low due to the environmental noise and many other man-made noises. In this paper, a novel wavelet based independent component analysis (ICA) method is proposed for improving SNR of computer video leakage signals. By using this method, we can improve the performance of pre-processing of computer video leaking signals. We solve the problem of using Fast ICA in processing video leakage signal by using a wavelet filter. The performance of Fast ICA is improved by working in wavelet domain because of advantages like ease of implementation and less computation time when compared to time domain. We pre-process one-dimensional received signal without reconstructing the image since it is inefficient to reconstruct signal before processing. A direct SNR can't be defined. Therefore, another metric called quasi signal to noise ratio (QSNR) is defined to estimate signal to noise ratio of video leakage signals. The processed results of the actual experimental data show that the proposed wavelet based ICA algorithm has a better performance than the Fast ICA algorithm and the Wavelet denoising algorithm. Abbas Yongaçoglu, Degang Sun, Dong Wei 0002, Meng Zhang 0020 |
ISCC | 3 |
| 2016 | Enhanced Correlation Power Analysis by Biasing Power Traces
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai, Na Pang |
ISC | 3 |
| 2016 | Uncertain? No, It's Very Certain! - Recovering the Key from Guessing Entropy Enhanced CPA
Changhai Ou, Zhu Wang 0005, Degang Sun, Xinping Zhou, Juan Ai |
SEC | 3 |
| 2016 | Method for detecting text information leakage in electromagnetic radiation from a computer displayabstractConsidering that the text information might be leaked through electromagnetic radiation from a computer display, a novel algorithm has been developed to detect the text information leakage. Motivated by the observation that the ‘text ‐ space – text’ characteristic for electromagnetic radiation signal contains the text information, the authors proposed a method to describe this characteristic. In this method, sparse decomposition in wavelet was used and sub‐band sparsity was defined. Variance mean ratio and correlation coefficients of sub‐band sparsity were combined as the features of electromagnetic radiation signals. By using this method, the authors can accurately and efficiently detect the text information leakage in electromagnetic radiation from a computer display without reconstructing the displayed image. Degang Sun, Dong Wei 0002, Meng Zhang 0020, Wei-qing Huang |
IET Inf. Secur. | 1 |
| 2016 | Efficient and anti-interference method of synchronising information extraction for cideo leaking signalabstractElectromagnetic radiation signal from computer display can be seen as a computer security risk if the radiation signal is intercepted and reconstructed. Electromagnetic radiation signal from computer display can also be called video leaking signal. Synchronising information extraction is the key problem of computer video leaking signal interception and reconstruction. To solve such problem, a novel synchronising information extraction algorithm based on spectral centroid has been developed. This study not only introduced spectral centroid into video leaking signal processing but also defined the concept of segmented spectral centroid. In addition, the uniformity degree of spectral centroid spacing distribution was defined to describe the harmonic characteristics of video leaking signal spectrum. The proposed algorithm can extract the electromagnetic radiation signal's synchronising information automatically and efficiently even with interference signal. Thus, the interception and reconstruction of electromagnetic radiation can be realised more effectively and the anti‐interference performance can be improved. Degang Sun, Dong Wei 0002, Meng Zhang 0020, Wei-qing Huang |
IET Signal Process. | 1 |
| 2015 | An Improved NPCUSUM Method with Adaptive Sliding Window to Detect DDoS Attacks
Degang Sun, Wei-qing Huang, Yan Wang 0081 |
ICICS | 1 |
| 2015 | POSTER: Using Improved Singular Value Decomposition to Enhance Correlation Power Analysis
Degang Sun, Xinping Zhou, Zhu Wang 0005, Changhai Ou, Wei-qing Huang, Juan Ai |
SecureComm | 1 |
| 2014 | A novel method for computer video leaking signal detectionabstractVideo leaking signal detection is an important part of TEMPEST, which is the technologies research focus on the investigations and studies of compromising emanations. A novel video leaking signal detection algorithm based on spectral centroid has been developed. Using the property that spectral centroid can accurately identify the signal energy center in frequency domain, the proposed algorithm can detect the display video leaking signal automatically. The uniformity degree of spectral centroid spacing distribution is defined to distinguish the video leaking signal and clutter signal automatically. Furthermore, the ant-jamming and ant-noise performance of the developed algorithm is analyzed in a practical attack scenario. Wei-qing Huang, Dong Wei 0002, Degang Sun |
ASONAM | 4 |
| 2014 | Method for Determining Whether or not Text Information Is Leaked from Computer Display Through Electromagnetic Radiation
Degang Sun, Dong Wei 0002, Meng Zhang 0020, Wei-qing Huang |
ICICS | 1 |
| 2007 | New Solutions for Cell Phone DetectionabstractProblem to real time detect existence of cell phones stay in power on state in a given area is a technology challenge because most time cell phones keep radio silence on a standby mode. This paper proposed two solutions, "virtual base station solution" and "ready beacon utilization solution" to solve this problem. Location updating registration of a cell phone entering into a new registration area is made use of to fulfill a lure technology and the problem of cell phones detection is settled perfectly. Hong Du, Dali Zhu, Degang Sun |
ICDS | 3 |