VLDB 2026 Research / reviewers in the wild / expert
Lihua Yin
dblp:07/7486
· DBLP profile ↗
71ranked-venue papers
9as first author
37since 2021 · last 2026
0000-0001-8829-4442ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 23 · 2 first-author · 12 since 2021Security and privacy · 19 · 2 first-author · 9 since 2021Databases, data management, data science and information retrieval · 11 · 1 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 4 first-author · 4 since 2021Systems, architecture and hardware · 5Artificial intelligence and machine learning · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CDWF: Few-Shot Learning for Cross-Domain Multi-Tab Website Fingerprinting
Xinlei Ju, Zhen Li 0011, Lihua Yin, Gaopeng Gou, Junzheng Shi, Gang Xiong 0001 |
IWQoS | 4 |
| 2026 | Scalable logical attack graph generation for enterprise networks through endpoint data
Chengliang Gao, Jing Qiu 0002, Du Cheng, Lihua Yin |
Comput. Secur. | 5 |
| 2026 | MTDecipher: robust encrypted malicious traffic detection via multi-task graph neural networksabstractAbstract The widespread adoption of encrypted traffic protocols has significantly increased the challenge of detecting malicious traffic. Existing detection methods based on deep learning typically rely on fine-grained features of data packets, such as length sequences and intra-flow interaction graphs. However, these features are highly susceptible to disruption by diverse network environments and traffic obfuscation. This paper proposes MTDecipher, a robust method for detecting encrypted malicious traffic based on multi-task Graph Neural Network (GNN). MTDecipher employs a bidirectional attentive sequence encoder to mitigate the impact of diverse network environments and traffic obfuscation on packet length sequences, along with an edge-block dual sampling method and a multi-task GNN model to mitigate the training bias introduced by the unbalanced distribution of traffic. In the bidirectional attentive sequence encoder, a combination of a Bi-GRU layer and an attention pooling layer is utilized to enhance the bidirectional encoding by generating weights for each element in the sequence, thereby obtaining robust encrypted traffic sequence features. In the edge-block dual sampling method, two rounds of sampling are involved to generate more evenly distributed subgraphs as training data, which reduces the local structural bias resulting from the aggregation of malicious flows. In the multi-task GNN model, the losses for both edge and node classification tasks are simultaneously optimized, thereby minimizing the homogeneity of adjacent edges. Experimental results on two real-world datasets with traffic obfuscation demonstrate that MTDecipher outperforms eight existing methods in terms of effectiveness in detecting encrypted malicious traffic. Fan Li 0019, Weihong Han, Binxing Fang, Lihua Yin |
Cybersecur. | 5 |
| 2026 | CryptoBinaryRz: a binary detection framework based on regional centralization dynamic analysis of cryptographic misuseabstractAbstract The correct application of cryptography is crucial for protecting confidentiality, integrity, and sensitive information in modern software systems. However, cryptographic APIs are frequently misused in practice because they are difficult to apply correctly and their security implications are often highly context dependent. Existing misuse detection research mainly targets source code, while binary-level detection remains underexplored despite its ability to access concrete runtime states and validate misuse conditions more directly. Binary analysis for cryptographic misuse faces three major challenges: severe path explosion, difficult parameter provenance recovery, and limited credibility of purely static results. To address these challenges, we present CryptoBinaryRz, a binary-level cryptographic misuse detection framework that combines locality-based region construction, context-aware dynamic provenance, path reuse-aware state management, and constraint-based misuse verification. Our method constrains analysis to sink-centered local regions, recovers parameter influence through symbolic mutation, restores nearby cryptographic calling environments through role abstraction, and reuses semantically equivalent paths during layered provenance expansion. In this way, the framework improves both scalability and semantic precision without relying on full control-flow graph construction. We also reformulate cryptographic misuse rules under a dynamic analysis setting so that runtime contexts and local calling environments can be jointly considered during verification. Experiments on 175 samples with isolated cryptographic behaviors and 11 real-world GitHub projects show that CryptoBinaryRz achieves over 95% detection accuracy and identifies 204 misuse instances, while substantially reducing the analysis cost associated with large binaries. These results suggest that binary-level analysis can provide richer and more trustworthy evidence for cryptographic misuse detection than source-level inspection alone. Zecheng Zhang, Lihua Yin, Shijie Jia 0001, Runda Huang |
Cybersecur. | 3 |
| 2026 | BotEvolver: Continuous Botnet Detection in Unlabeled Incremental Network FlowsabstractIn dynamic Internet of Things (IoT) networks, unlabeled incremental network flows with evolving distributions severely degrade the performance of deep learning-based botnet detection systems, primarily due to catastrophic forgetting and reliance on labeled data. This work proposes BotEvolver, a novel framework for continuous, efficient, and interpretable botnet detection in incremental flow environments. BotEvolver integrates two core components: (1) an experience replay-enabled incremental detection model via an attention-based inductive Graph Neural Network (GNN), that preserves key botnet subgraphs to mitigate catastrophic forgetting and enhance interpretability; (2) a multi-feature active annotation model that generates high-precision pseudo-labels while reducing the number of IPs requiring manual annotation in incremental data from the CTU13 dataset to98.6% F1-score across incremental rounds. Overhead tests confirm its practicality where peak Graphics Processing Unit (GPU) VRAM occupancy is ≈1GB, throughput reaches 55.46k flows/sec and 12.83k IPs/sec, and pre-trained models are ≈12MB, enabling distributed deployment for real-time monitoring. Fan Li 0019, Weihong Han, Binxing Fang, Lihua Yin, Jianye Yang 0001 |
IEEE Internet Things J. | 5 |
| 2026 | HybridGF: A Novel Data Augmentation Algorithm for Detecting the Extremely Imbalanced Malicious Traffic in Industrial Internet of ThingsabstractExtreme imbalance in sample ratio between traffic classes is an important factor affecting malicious traffic detection in Industrial Internet of Things (IIoT). Sample generation is an effective means to address the extreme imbalance malicious traffic detection. Traditional sample generation methods based on linear interpolation have difficulty in generating diverse samples for scarce traffic; while generation methods based on Generative Adversarial Networks (GANs) have difficulty in controlling sample generation boundaries, leading to the problem of generating overlapping traffic samples. To solve this problem, we propose a novel data enhancement algorithm called HybridGF. The method consists of three modules: hybrid generation module, filtering module, and explosion module. The hybrid generation module generates diversity samples adapted to the number of traffic category samples. The filtering module controls the boundary of generated samples by combining cluster analysis and Euclidean distance to avoid overlapping of generated traffic samples. The explosion module regulates the distribution of sample density in different clusters. In our experiments, we use three classical datasets (NSL-KDD, IoT-23, and TON-IoT) to simulate extremely unbalanced malicious traffic detection. The results show that HybridGF has a higher detection rate in detecting extremely imbalanced malicious traffic compared to other data enhancement algorithms. In the NSL-KDD dataset, the HybridGF model demonstrates a significant advantage in recall rate, with an overall improvement of 14.03% compared to the baseline model. Specifically, its recall rate for the DoS category increased by 4.6%. Nan Wei, Zhuangcheng Wu, Lihua Yin |
IEEE Internet Things J. | 3 |
| 2026 | Partition-based differentially private synthetic data generation
Meifan Zhang, Dihang Deng, Lihua Yin |
Inf. Sci. | 3 |
| 2026 | DynAssetRank: Real-Time Dynamic Risk Assessment for Network Threat Prediction With ATT&CK Modeling
Ximing Chen 0004, Xilong He, Lichen Nong, Jing Qiu 0002, Du Cheng, Lejun Zhang, Lihua Yin |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2026 | Triggers Magic Mirror: Trigger Inversion for Backdoor Detection in Non-IID Federated Learning
Zhe Sun 0005, Yufu Zou, Lihua Yin, Tianqing Zhu, Xu Zhang 0021, Yuanyuan He 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Horizontal Multi-Party Data Publishing Under Differential Privacy via Weight-Aware Bidirectional Generative Adversarial Networks
Pengfei Zhang 0010, Zhikun Zhang 0001, Yang Cao 0011, Xiang Cheng 0003, Lihua Yin, Puning Zhao, Zhiquan Liu 0001, Li Sun 0008, Lei Shi 0030, Ji Zhang 0001 |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2025 | GSC-SAGE: A Generative Subgraph Contrastive Framework for Encrypted Traffic Detection
Hongyuan Cheng, Zhiguang Yan, Weixiang Jiang, Dexin Zhu, Lihua Yin |
KSEM (1) | 6 |
| 2025 | Feature Machine Unlearning in Diffusion Models
Tianqing Zhu, Laiqiao Qin, Lihua Yin, Wanlei Zhou 0001 |
NSS | 4 |
| 2025 | MalAE: A Feature-Optimized and Autoencoder Ensemble-Based Method for IoT Malware ClassificationabstractIn the landscape of the Internet of Things (IoT), the rapid evolution and diverse obfuscation tactics of malware render it challenging to detect and identify effectively, posing significant threats to network security. Signature or heuristic methods rely on fixed feature recognition, making it challenging to handle new variants. Recent research has proposed deep learning techniques that utilize static analysis of bytes and images or dynamic analysis of APIs. However, these methods are effective only on samples from the same platform or lead to a dimensional explosion due to excessive irrelevant obfuscation, rendering them inadequate for managing complex cross-platform malware. In this work, we propose a novel lightweight cross-platform malware classification system called MalAE. This system employs a global-local particle swarm optimization algorithm to mine frequent features, adaptively identifying distinct family characteristics and efficiently recognizing variants. An ensemble of autoencoders integrates comprehensive file features and cross-platform basic block features from various perspectives and feature spaces, compressing high-dimensional data into a low-dimensional latent space. This approach preserves essential information, captures nonlinear complex relationships, and facilitates the rapid classification of intricate cross-platform samples. Evaluations conducted on two different datasets demonstrate that MalAE reduces the original feature dimensions by approximately 70% while also enhancing accuracy. Compared to state-of-the-art methods, MalAE achieves superior results, attaining an accuracy of 97.72%. Chengrun He, Honghui Fan, Lihua Yin, Haonan Yan, Hui Li 0006, Bin Wang 0062 |
IEEE Internet Things J. | 3 |
| 2025 | SnifferDog: Comprehensively Learning Heterogeneous Features of Network Traffic to Identify Malicious FlowsabstractDeep learning has recently attracted significant attention in the field of network intrusion detection. Despite a substantial number of efforts have been made, previous works struggle to comprehensively learn the features of network traffic, resulting in inconsistent performance across various environments and attacks. To address these limitation, this study presents SnifferDog, a novel network attack detection system that takes raw packets as input and rationally extracts and integrates heterogeneous features involved in packets, flows and topology. It formats the packets and flows concurrently to achieve a high-level throughout for feature learning. Then, a flow pretraining model consisting of a LSTM, a self-attention and cross-attention layers is developed to learn both sequential and nonsequential inter packet relation features as initial flow vectors. Subsequently, a node-to-node and a node-to-edge attention layers are implemented to enhance an inductive GNN model that dynamically embeds the flow-to-flow and flow-to-topology relation features into the flow vectors. The resulting flow vectors involve comprehensive information of packet-to-packet, flow-to-flow and flow-to-topology relations, enabling high detection performance. In-lab experiments across eight datasets from diverse environments demonstrate SnifferDog’s superior effectiveness over existing solutions. A scalable prototype deployed in our institute’s network achieves a false positive rate of only 0.08%, validating SnifferDog’s practicality in real-world scenarios. Lihua Yin, Zeyan Liu, Shijie Jia 0001, Bo Luo, Hongli Xiang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | SuperMPFL: A Supermask-Based Mechanism for Personalized Federated LearningabstractPersonalized federated learning (PFL) is a specialized application of the federated learning paradigm designed to support personalized use cases. Unlike traditional federated learning, which aims to train a high-quality global model, the goal of PFL is to tailor a model that best fits each individual user. Most existing PFL approaches adopt training architectures similar to those used in traditional federated learning, relying on global or partial model sharing during training. While this helps improve model personalization across clients, it also introduces a range of challenges, including risks of data leakage and increased communication overhead. To address these challenges, we propose a novel personalized federated learning (PFL) framework called SuperMPFL, which leverages supermasks to effectively tackle issues related to accuracy, privacy, and efficiency. In particular, the SuperMPFL technique utilizes masking and ranking strategies to obscure the true gradient information. By converting gradients into ranked numerical representations, this approach enhances privacy protection during the training process. Furthermore, this approach reduces communication overhead by transmitting significantly less information compared to conventional methods. In SuperMPFL, each client receives the global model and then emphasizes its personalized parameters, particularly at the model’s edges. This design not only improves accuracy but also strengthens robustness against privacy attacks. Evaluations on standard federated learning benchmarks demonstrate the superiority of our approach, which outperforms state-of-the-art methods in terms of accuracy, privacy, and efficiency. Zhe Sun 0005, Shangzhe Li, Lihua Yin, Yahong Chen, Aohai Zhang, Meifan Zhang, Yuanyuan He 0002 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | BiCAM: A Bidirectional Contextualized Attentive Model for Analyzing the Correlation of Heterogeneous Security EventsabstractAs the Internet continues to evolve, modern information technology infrastructures are constantly under attack and need to be continuously monitored for timely responses. Different devices and detection platforms generate heterogeneous security events that are sent to security operations centers, where security operators investigate those events and identify potential threats. Unfortunately, it is impossible to manually analyze such a huge number of events, leading to “alert fatigue.” Despite a substantial amount of effort having been made to aggregate redundant related alerts, the effectiveness of previous works was essentially restrained by their limited relation learning and explaining abilities. In this work, we propose the bidirectional contextualized attentive model (BiCAM), a novel contextual analysis model that uses a self-supervised deep learning approach to automatically correlate security events in relation to their bidirectional context. It is developed by designing an encoder–decoder architecture that consists of bidirectional gated recurrent units and an attention mechanism to capture both sequential and nonsequential relations of previous and subsequent alerts and provide explainability information for the security operators. In addition, we introduce a bidirectional encoder representations from transformers (BERT)-based embedding method to deal with the heterogeneity of security events, enhancing our model's accommodation to the changes of detectors. We comprehensively evaluate our model on real-world datasets containing over 11M events generated by detectors from 8 different vendors. We found that our model enables accurate, unsupervised correlation extraction; and outperforms the state-of-the-art (SOTA) work when applying event relevance to semiautomatically classify security events (e.g., the$F1$-score of classification is improved by 4.3% and the false positive rate dropped to 1.39%). Lihua Yin, Kaiyan Zhao, Kexiang Qian, Daojuan Zhang |
IEEE Trans. Reliab. | 3 |
| 2024 | Sketches-Based Join Size Estimation Under Local Differential PrivacyabstractJoin size estimation on sensitive data poses a risk of privacy leakage. Local differential privacy (LDP) is a solution to preserve privacy while collecting sensitive data, but it introduces significant noise when dealing with sensitive join attributes that have large domains. Employing probabilistic structures such as sketches is a way to handle large domains, but it leads to hash-collision errors. To achieve accurate estimations, it is necessary to reduce both the noise error and hash-collision error. To tackle the noise error caused by protecting sensitive join values with large domains, we introduce a novel algorithm called LDPJoinSketch for sketch-based join size estimation under LDP. Additionally, to address the inherent hash-collision errors in sketches under LDP, we propose an enhanced method called LDPJoinSketch+. It utilizes a frequency-aware perturbation mechanism that effectively separates high-frequency and low-frequency items without compromising privacy. The proposed methods satisfy LDP, and the estimation error is bounded. Experimental results show that our method outperforms existing methods, effectively enhancing the accuracy of join size estimation under LDP. Meifan Zhang, Lihua Yin |
ICDE | 3 |
| 2024 | CAG-Malconv: A Byte-Level Malware Detection Method With CBAM and Attention-GRUabstractWith the rise of generative artificial intelligence, malware creation has become more accessible, leading to a surge in malware and its variants. Traditional detection methods struggle to keep pace with this evolution. Dynamic analysis, though detailed, is resource intensive and susceptible to variations in computer hardware and simulation environments. Static analysis, on the other hand, faces the challenge of discerning valuable features from an extensive pool, especially for software across diverse architectures. To tackle these issues, we propose a binary sample classification approach based on raw bytes, named CAG-Malconv, which incorporates Convolutional Block Attention Module (CBAM) and Bidirectional Gated Recurrent Unit (BiGRU) to extract byte-level features. We evaluated it on two datasets with 48,000 samples of different file types and families. It outperforms state-of-the-art methods based on advanced features and raw bytes in terms of accuracy (ACC), Area Under the Curve (AUC), F1 score, and recall. Furthermore, it allows for the visualization of raw samples, facilitating the precise identification of malicious components like C&C URLs and encryption loops by analyzing activation patterns in hidden layers, thus streamlining malware investigative procedures. Honghui Fan, Lihua Yin, Shijie Jia 0001, Kaiyan Zhao |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | An Autoencoder-Based Hybrid Detection Model for Intrusion Detection With Small-Sample ProblemabstractCyber-attacks have become more frequent, targeted, and complex as the exponential growth in computer networks and the development of Internet of Things (IoT). Network intrusion detection system (NIDS) is an important and essential tool to protect network environments. However, the low performance of a NIDS against small malicious samples has seriously threatened the security of networks, thus directly leading to the loss of personal property and national interests. Given this, we propose an auto encoder-based hybrid detection model, abbreviated as AHDM, for the intrusion detection with small-sample problem. AHDM has a dual classifier framework. It trains first neural network based on the encoding features obtained from the autoencoder feature enhancement algorithm to detect small-sample malicious traffic. It trains second neural network using the original features to detect normal traffic and large-sample malicious traffic. The final detection result of malicious traffic is obtained by combining the detection results of the two neural networks. In experiments, we use three classic datasets (KDD CUP 99, CIC-IDS-2017, and IOT-23) and simulate the malicious traffic detection targeting extremely small-sample malicious traffic. The results show that AHDM has a higher detection rate for small-sample malicious traffic compared to the advanced detection models (DNN and ACID). In the IOT-23 dataset, the AHDM model shows an absolute advantage in detecting DDoS type of malicious traffic, with a detection rate of 0.71, which is much higher than the DNN (0.14) and ACID (0.14) models. Nan Wei, Lihua Yin, Jingyi Tan, Chuhong Ruan, Chuang Yin, Zhe Sun 0005 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | PriMonitor: An adaptive tuning privacy-preserving approach for multimodal emotion detection
Lihua Yin, Sixin Lin, Zhe Sun 0005, Yuanyuan He 0002 |
World Wide Web (WWW) | 1 |
| 2023 | WaterPurifier: A scalable system to prevent the DNS water torture attack in 5G-enabled SIoT network
Lihua Yin, Muyijie Zhu, Chonghua Wang |
Comput. Commun. | 1 |
| 2023 | ASNN-FRR: A traffic-aware neural network for fastest route recommendation
Chaoxiong Wang, Chao Li 0027, Jing Qiu 0002, Jianfeng Qu, Lihua Yin |
GeoInformatica | 6 |
| 2023 | A feature enhancement-based model for the malicious traffic detection with small-scale imbalanced dataset
Nan Wei, Lihua Yin, Xiaoming Zhou, Chuhong Ruan, Yibo Wei, Youyi Chang |
Inf. Sci. | 2 |
| 2023 | Local differentially private frequency estimation based on learned sketches
Meifan Zhang, Sixin Lin, Lihua Yin |
Inf. Sci. | 3 |
| 2023 | A privacy-preserving botnet detection approach in largescale cooperative IoT environment
Muyijie Zhu, Lihua Yin, Ye Fu |
Neural Comput. Appl. | 4 |
| 2023 | Dynamic Prototype Network Based on Sample Adaptation for Few-Shot Malware DetectionabstractThe continuous increase and spread of malware have caused immeasurable losses to social enterprises and even the country, especially unknown malware. Most existing methods use predefined class samples to train models, which cannot handle unknown malware detection. In this paper, we formalize unknown malware detection as a Few-Shot Learning problem. However, the existing model cannot dynamically adjust the model parameters according to the samples and does not deeply consider the influence of the correlation between samples, so it achieves sub-optimal performance. We propose a Dynamic Prototype Network based on Sample Adaptation for few-shot malware detection (DPNSA). Specifically, we use dynamic convolution to realize dynamic feature extraction based on sample adaptation. Secondly, we define the class feature (prototype) as the mean of the dynamic embedding of all malware samples of each class in the support set. Then, a dual-sample dynamic activation function is proposed, which uses the correlation of the dual-sample to reduce the impact of unrelated features between samples on the metric. Finally, we use the metric-based method to calculate the distance between the query sample and the prototype to realize malware detection. Experiments show that our method outperforms the existing few-shot malware detection models and achieves significant improvement. Yuhan Chai, Jing Qiu 0002, Lihua Yin, Zhihong Tian 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2023 | CDAML: a cluster-based domain adaptive meta-learning model for cross domain recommendation
Jiajie Xu 0001, Jiayu Song, Lihua Yin |
World Wide Web (WWW) | 4 |
| 2022 | FPMBot: Discovering the frequent pattern of IoT-botnet domain queries in large-scale network
Kexiang Qian, Muyijie Zhu, Lihua Yin, Bin Wang 0062 |
Comput. Commun. | 4 |
| 2022 | TPRPF: a preserving framework of privacy relations based on adversarial training for texts in big data
Yuhan Chai, Zhe Sun 0005, Jing Qiu 0002, Lihua Yin, Zhihong Tian 0001 |
Frontiers Comput. Sci. | 4 |
| 2022 | EmoMix+: An Approach of Depression Detection Based on Emotion Lexicon for Mobile ApplicationabstractEmotion lexicon is an important auxiliary resource for text emotion analysis. Previous works mainly focused on positive and negative classification and less on fine-grained emotion classification. Researchers use lexicon-based methods to find that patients with depression express more negative emotions on social media. Emotional characteristics are an effective feature in detecting depression, but the traditional emotion lexicon has limitations in detecting depression and ignores many depression words. Therefore, we build an emotion lexicon for depression to further study the differences between healthy users and patients with depression. The experimental results show that the depression lexicon constructed in this paper is effective and has a better effect of classifying users with depression. Yuanfei Zhang, Lihua Yin, Zhe Sun 0005, Zheng Lin 0001, Peng Fu 0008, Weiping Wang 0005 |
Secur. Commun. Networks | 3 |
| 2022 | From Data and Model Levels: Improve the Performance of Few-Shot Malware ClassificationabstractExisting malware classification methods cannot handle the open-ended growth of new or unknown malware well because it only focuses on pre-defined malware classes with sufficient training data. Due to the superiority of the visualization method, some researchers use it for solving few-shot malware classification. However, the malware images generated by existing visualization methods contain insufficient semantic information. At the same time, existing few-shot models tend to converge to sharp minima resulting in poor generalization performance. By synthesizing the observations, we think that accurate and effective few-shot malware classification methods are affected by generated malware images and classification models, which can be called data and model levels, respectively. To solve the above problems, we propose a novel method from the Data and Model levels, which is used to classify new or unknown malware well, called DMMal. More specifically, we propose a multi-channel malware image generation method based on multi-view so that malware images can contain more prosperous information at the data level. In addition, we investigated adaptive sharpness-aware minimization in a few-shot scenario from the perspective of model optimization at the model level to minimize the loss value and sharpness simultaneously. This enhances the generalization ability of the model and improves the ability of the model to classify new or unknown classes. Experiments on two few-shot malware classification datasets show that the method proposed can improve the performance of few-shot malware classification from the data and model levels. Yuhan Chai, Jing Qiu 0002, Lihua Yin, Lejun Zhang, Brij B. Gupta, Zhihong Tian 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | A scalable rule engine system for trigger-action application in large-scale IoT environment
Ye Fu, Lihua Yin, Hao Xun |
Comput. Commun. | 3 |
| 2021 | A blockchain-based collaborative training method for multi-party data sharing
Lihua Yin, Jiyuan Feng, Sixin Lin, Zhe Sun 0005 |
Comput. Commun. | 1 |
| 2021 | LSVP: A visual based deep neural direction learning model for point-of-interest recommendation on sparse check-in data
Huimin Sun, Chao Li 0027, Lihua Yin |
Neurocomputing | 4 |
| 2021 | CISK: An interactive framework for conceptual inference based spatial keyword query
Jiajie Xu 0001, Jiabao Sun, Rui Zhou 0001, Chengfei Liu, Lihua Yin |
Neurocomputing | 5 |
| 2021 | IoT root union: A decentralized name resolving system for IoT based on blockchain
Shen Su, Zhihong Tian 0001, Jinxi Deng, Lihua Yin, Xiaojiang Du, Mohsen Guizani |
Inf. Process. Manag. | 5 |
| 2021 | A Blockchain-Based IoT Cross-Domain Delegation Access Control MethodabstractThe collaborative demand in the Internet of Things (IoT) is becoming stronger. One of the collaborative challenges is the security of interoperability between different management domains. Although cross-domain access control mechanisms exist in IoT, the majority of them are based on a trusted third party. In addition, the heterogeneity of multidomain policies makes it difficult for authority delegation to satisfy the principle of least authority. In this paper, we propose a blockchain-based IoT cross-domain delegation access control method (CDDAC). The delegation-trajectory-on-blockchain strategy proposed enhances the scalability of the cross-domain delegation system. The presented multidomain delegation trajectory aggregation scheme supports the forensic analysis of the cross-domain delegation system. The performance of CDDAC is evaluated in the Ropsten, which is the Ethereum’s official public blockchain test network. The experimental results show that CDDAC has faster delegation verification speed and higher decision-making efficiency than existing work, demonstrating the lightweight and scalability of the method. Chao Li 0027, Fan Li 0019, Lihua Yin, Tianjie Luo, Bin Wang 0062 |
Secur. Commun. Networks | 3 |
| 2020 | Decision-Making for Intrusion Response: Which, Where, in What Order, and How Long?abstractGenerating fine-grained response policies is a fundamental problem for Intrusion Response Systems (IRSs). Although existing schemes determine countermeasures and defense points efficiently, they ignore the deployment orders and execution durations of the selected countermeasures, which may impact response performance. To address this problem, by considering four attributes (i.e., attack damage, deployment cost, negative impact on QoS, and security benefit), we propose a decisionmaking framework for IRSs to reach fine-grained decisions to balance attack damage and response cost. We formulate decisionmaking as a single-objective optimization problem. To efficiently solve this problem, a Genetic Algorithm with Three-dimensional Encoding (GATE) is proposed to not only select countermeasures and defense points, but also determine deployment orders and execution durations. Simulation results demonstrate the efficiency of our approach. Yunchuan Guo, Zifu Li, Fenghua Li 0001, Liang Fang 0009, Lihua Yin, Jin Cao 0001 |
ICC | 6 |
| 2020 | LGMal: A Joint Framework Based on Local and Global Features for Malware DetectionabstractWith the gradual advancement of smart city construction, various information systems have been widely used in smart cities. In order to obtain huge economic benefits, criminals frequently invade the information system, which leads to the increase of malware. Malware attacks not only seriously infringe on the legitimate rights and interests of users, but also cause huge economic losses. Signature-based malware detection algorithms can only detect known malware, and are susceptible to evasion techniques such as binary obfuscation. Behavior-based malware detection methods can solve this problem well. Although there are some malware behavior analysis works, they may ignore semantic information in the malware API call sequence. In this paper, we design a joint framework based on local and global features for malware detection to solve the problem of network security of smart cities, called LGMal, which combines the stacked convolutional neural network and graph convolutional networks. Specially, the stacked convolutional neural network is used to learn API call sequence information to capture local semantic features and the graph convolutional networks is used to learn API call semantic graph structure information to capture global semantic features. Experiments on Alibaba Cloud Security Malware Detection datasets show that the joint framework gets better results. The experimental results show that the precision is 87.76%, the recall is 88.08%, and the F1-measure is 87.79%. We hope this paper can provide a useful way for malware detection and protect the network security of smart city. Yuhan Chai, Jing Qiu 0002, Shen Su, Chunsheng Zhu, Lihua Yin, Zhihong Tian 0001 |
IWCMC | 5 |
| 2020 | A Secure Authentication Scheme for Remote Diagnosis and Maintenance in Internet of VehiclesabstractDue to the low latency and high speed of 5G networks, the Internet of Vehicles (IoV) under the 5G network has been rapidly developed and has broad application prospects. The Third Generation Partnership Project (3GPP) committee has taken remote diagnosis as one of the development cores of IoV. However, how to ensure the security of remote diagnosis and maintenance services is also a key point to ensure vehicle safety, which is directly related to the safety of vehicle passengers. In this paper, we propose a secure and efficient authentication scheme based on extended chebyshev chaotic maps for remote diagnosis and maintenance in IoVs. In the proposed scheme, to provide strong security, anyone, such as the vehicle owner or the employee of the Vehicle Service Centre (VSC), must enter the valid biometrics and password in order to enjoy or provide remote diagnosis and maintenance services, and the vehicle and the VSC should authenticate each other to ensure that they are legitimate. The security analysis and performance evaluation results show that the proposed scheme can provide robust security with ideal efficiency. Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001, Lihua Yin |
WCNC | 7 |
| 2020 | Security of Mobile Multimedia Data: The Adversarial Examples for Spatio-temporal Data
Jing Qiu 0002, Xiaojiang Du, Lihua Yin, Zhihong Tian 0001 |
Comput. Networks | 4 |
| 2020 | The QoS and privacy trade-off of adversarial deep learning: An evolutionary game approach
Zhe Sun 0005, Lihua Yin, Chao Li 0027, Weizhe Zhang, Ang Li 0005, Zhihong Tian 0001 |
Comput. Secur. | 2 |
| 2020 | Multi-objective spatial keyword query with semantics: a distance-owner based approach
Jiajie Xu 0001, Lihua Yin |
Distributed Parallel Databases | 3 |
| 2020 | ConnSpoiler: Disrupting C&C Communication of IoT-Based Botnet Through Fast Detection of Anomalous Domain QueriesabstractThe development of Internet of Things (IoT) dramatically facilitates the integration of computing systems with the physical world. However, as IoT devices are more easy to compromise than desktop computers, cybercriminals have founded IoT-based botnets to launch Distributed Denial of Service (DDoS) attacks with unprecedented traffic volume. To mitigate the damages associated with these attacks, the detection of IoT-based botnet has to preempt the command and control (C&C) communication to prevent the delivery of the attack codes. Motivated by the extensively implementation of domain generation algorithm in botnets, in this article, we propose ConnSpoiler, a lightweight system that detects IoT-based botnets by identifying the stream of algorithmically generated domains (AGDs) in a fast way. ConnSpoiler only needs negligible system resources to take effect and thus can execute well on the resource-restraint IoT devices. By outfitting a powerful statistical algorithm, i.e., threshold random walk, ConnSpoiler has a high probability (about 94%) of detecting infection before the compromised devices connect C&C servers, which can help to prevent the succeeding attacks. Moreover, ConnSpoiler only requires the benign domains to take effect and therefore does not need extra effort to label malicious samples for training phase. We evaluate ConnSpoiler based on real-world DNS traffics collected from two different large ISP networks and show that it accurately identifies devices that are compromised by unknown botnets. Lihua Yin, Chunsheng Zhu, Liming Wang 0001, Zhen Xu 0009, Hui Lu 0005 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | Achieving Privacy-Preserving Group Recommendation with Local Differential Privacy and Random TransmissionabstractGroup activities on social networks are increasing rapidly with the development of mobile devices and IoT terminals, creating a huge demand for group recommendation. However, group recommender systems are facing an important problem of privacy leakage on user’s historical data and preference. Existing solutions always pay attention to protect the historical data but ignore the privacy of preference. In this paper, we design a privacy-preserving group recommendation scheme, consisting of a personalized recommendation algorithm and a preference aggregation algorithm. With the carefully introduced local differential privacy (LDP), our personalized recommendation algorithm can protect user’s historical data in each specific group. We also propose an Intra-group transfer Privacy-preserving Preference Aggregation algorithm (IntPPA). IntPPA protects each group member’s personal preference against either the untrusted servers or other users. It could also defend long-term observation attack. We also conduct several experiments to measure the privacy-preserving effect and usability of our scheme with some closely related schemes. Experimental results on two datasets show the utility and privacy of our scheme and further illustrate its advantages. Ben Niu 0001, Lihua Yin, Fenghua Li 0001 |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | A Genetic-Algorithm Based Method for Storage Location Assignments in Mobile Rack WarehousesabstractIn recent years, mobile racks or auto robots have been widely used in e-commerce warehouses where storage location assignment is a fundamental problem in the order picking process. The present storage location assignment strategies mainly allocate stocks into various racks according to a specific objective function or the relationships between stocks. These strategies include the random storage assignment strategy (RAS) and the good- clustering storage location assignment strategy (GCAS). In this paper, we first analyze the key factors that affect the efficiency of the order picking system.The results show that the rack- moved-number (RMN) is a significant factor in the order picking process. Then, we propose a genetic- algorithm (GA) based method for the storage location assignment problem which adopts RMN as its fitness function. To find a better solution, we take the natural deduplicated stock sequence of history orders (NDSSHO) as a seed to initialize the population of chromosomes. We also define a specific cross mutation strategy to avoid checking the validity of chromosomes by exchanging selected genes and adjusting new generated chromosomes. At last, we compare the RMN of our proposed method with RAS and GCAS. The experimental results show that the RMN of our proposed method is about 50% less than RAS and GCAS. Dongwen Zhang, Yaqi Si, Zhihong Tian 0001, Lihua Yin, Jing Qiu 0002, Xiaojiang Du |
GLOBECOM | 4 |
| 2019 | Searching Activity Trajectories with Semantics
Lihua Yin |
J. Comput. Sci. Technol. | 1 |
| 2018 | Real-Time Data Incentives for IoT SearchesabstractEffectively collecting real-time data is a fundamental problem in IoT (Internet of Things) searches. In the IoT, most data are linked with the owner's private information and cannot be publicly released on the Internet. This invalidates the use of crawlers to collect data in IoT searches. As a result, effectively motivating potential data providers (PDPs) to provide real-time on demand data becomes a key requirement for the development of an IoT search service. To address this problem, we acknowledge the realistic assumption of incomplete information, and propose a buyout-auction framework, with the constraint of QoD (Quality of Data), to collect real-time data and maximize bidders' payoff. Simulation results demonstrate that our approach can drive PDPs to participate in bidding in a timely manner and provide data under the constraints of QoD to IoT search service providers. Yunchuan Guo, Liang Fang 0009, Kui Geng, Lihua Yin, Fenghua Li 0001 |
ICC | 4 |
| 2018 | Selecting Combined Countermeasures for Multi-Attack Paths in Intrusion Response SystemabstractCountermeasure selection is a key process of the Intrusion Response System (IRS). Many cost-sensitive schemes have been proposed to select the optimal countermeasure to maximize security utility by attuning attack damage and response cost. However, existing schemes ignore the interaction between different countermeasures for different attack paths, and neglect the uncertainty between alerts and attacks, which may lead to excessive or insufficient responses. ignore the interaction between different countermeasures for multiple attack paths. To address this problem, in this paper, we propose a combined countermeasures selection scheme based on probabilistic attack tree (PAT). First, we employ Bayesian networks to calculate the probability of each atomic attack in the PAT. Next, the exploitation probability of each attack path is evaluated and multiple possible attack paths are identified. In addition, we quantify the damage of each identified attack path and formulate the countermeasure selection for single attack path as a multi-objective optimization problem. Finally, by considering the security utilities of the countermeasures for different attack paths, we use a greedy strategy to select the combined countermeasures and maximize overall security utility. The experimental results demonstrate the effectiveness of the proposed scheme. Fenghua Li 0001, Zhengkun Yang, Yunchuan Guo, Lihua Yin, Zhen Wang 0013 |
ICCCN | 5 |
| 2018 | Security Measurement for Unknown Threats Based on Attack PreferencesabstractSecurity measurement matters to every stakeholder in network security. It provides security practitioners the exact security awareness. However, most of the works are not applicable to the unknown threat. What is more, existing efforts on security metric mainly focus on the ease of certain attack from a theoretical point of view, ignoring the “likelihood of exploitation.” To help administrator have a better understanding, we analyze the behavior of attackers who exploit the zero-day vulnerabilities and predict their attack timing. Based on the prediction, we propose a method of security measurement. In detail, we compute the optimal attack timing from the perspective of attacker, using a long-term game to estimate the risk of being found and then choose the optimal timing based on the risk and profit. We design a learning strategy to model the information sharing mechanism among multiattackers and use spatial structure to model the long-term process. After calculating the Nash equilibrium for each subgame, we consider the likelihood of being attacked for each node as the security metric result. The experiment results show the efficiency of our approach. Lihua Yin, Zhen Wang 0013, Yunchuan Guo, Fenghua Li 0001, Binxing Fang |
Secur. Commun. Networks | 1 |
| 2018 | A game-theoretic approach to advertisement dissemination in ephemeral networks
Lihua Yin, Yunchuan Guo, Fenghua Li 0001, Junyan Qian, Athanasios V. Vasilakos |
World Wide Web | 1 |
| 2017 | Who Is Visible: Resolving Access Policy Conflicts in Online Social NetworksabstractMillions of the co-owned items, such as photos, comments etc., are uploaded to OSNs everyday. These co-owned items contain plenty of privacy information. One important information is the social relations which can be inferred from the items. When sharing these items, the owners may just want to make themselves visible alone while hiding these social relations. It leaves us a problem that making each single co-owner visible alone is acceptable, but showing them together is not allowed. To avoid the privacy leakage, we should choose proper owners to be visible to the visitor. Unfortunately, traditional access control for OSNs cannot fit this concern thus cannot provide a suitable answer. To deal with this problem, we first define the `dislike relation' and its corresponding conflicts. Then we propose a communication-intensity-based scheme to measure the social intimacies between the visitor and co-owners of the accessed item. Based on the social intimacies, we can provide a decision support when conflicts occur. Case studies and user studies are performed to illustrate the effectiveness of our proposed scheme. Liang Fang 0009, Lihua Yin, Qiaoduo Zhang, Fenghua Li 0001, Binxing Fang |
GLOBECOM | 2 |
| 2017 | Optimally Selecting the Timing of Zero-Day Attack via Spatial Evolutionary Game
Lihua Yin, Yunchuan Guo, Fenghua Li 0001, Binxing Fang |
ICA3PP | 2 |
| 2017 | A Novel Threat-Driven Data Collection Method for Resource-Constrained Networks
Lihua Yin, Yunchuan Guo, Chao Li 0027, Fenghua Li 0001 |
NSS | 2 |
| 2015 | Ad Dissemination Game in Ephemeral Networks
Lihua Yin, Yunchuan Guo, Junyan Qian, Athanasios V. Vasilakos |
APWeb | 1 |
| 2015 | Assessing the Disclosure of User Profile in Mobile-Aware Services
Daiyong Quan, Lihua Yin, Yunchuan Guo |
Inscrypt | 2 |
| 2015 | Botnet spoofing: fighting botnet with itselfabstractAs the arms race between botmasters and defenders becomes increasingly common, the emerging advanced botnets have evolved to be more resilient to traditional mitigation strategies. For security-conscious Internet users, the host-based security software i.e., antivirus and firewall could provide effective protection against the botnet attacks; however, the remaining security-unconscious users will suffer from the botnet attacks and will be compromised easily. Consequently, how to protect both security-conscious and security-unconscious users against advanced botnets without any command and control vulnerability has posed a great challenge to this day. In this paper, we propose the idea of botnet spoofing that aims at addressing the aforementioned challenge to some degree. Botnet spoofing exploits the essential property of a persistent bot that it MUST obtain its file path before subsequent autostart registration or self-propagation to spoof a specific bot and trick the specific bot to propagate BotSpoofer instead of propagating itself, consequently making the victim not only avoid an originally successful attack but also achieve extra protection provided by BotSpoofer. Thus, botnet spoofing is independent of the vulnerability, protocol, and structure of botnet command and control. To prove the feasibility of botnet spoofing, we create a prototype named ConSpoofer-targeting Conficker. The results show that ConSpoofer could be passively delivered to other victims, which are located by Conficker, through Conficker's three propagation methods in an automatic, simple, accurate, and scalable manner. The goal of our work is to provide a new mitigation strategy that will promote the development of more efficient countermeasures against advanced botnets. Copyright © 2013 John Wiley & Sons, Ltd. Xiang Cui, Lihua Yin, Shuyuan Jin, Zhiyu Hao |
Secur. Commun. Networks | 2 |
| 2014 | Utility-based cooperative decision in cooperative authenticationabstractIn mobile networks, cooperative authentication is an efficient way to recognize false identities and messages. However, an attacker can track the location of cooperative mobile nodes by monitoring their communications. Moreover, mobile nodes consume their own resources when cooperating with other nodes in the process of authentication. These two factors cause selfish mobile nodes not to actively participate in authentication. In this paper, a bargaining-based game for cooperative authentication is proposed to help nodes decide whether to participate in authentication or not, and our strategy guarantees that mobile nodes participating in cooperative authentication can obtain the maximum utility, all at an acceptable cost. We obtain Nash equilibrium in static complete information games. To address the problem of nodes not knowing the utility of other nodes, incomplete information games for cooperative authentication are established. We also develop an algorithm based on incomplete information games to maximize every node's utility. The simulation results demonstrate that our strategy has the ability to guarantee authentication probability and increase the number of successful authentications. Yunchuan Guo, Lihua Yin, Licai Liu, Binxing Fang |
INFOCOM | 2 |
| 2014 | Bargaining-Based Dynamic Decision for Cooperative Authentication in MANETsabstractIn MANETs, cooperative authentication, requiring cooperation of neighbor nodes, is a significant authenticate technique. However, when nodes participate in cooperation, their location may easily be tracked by misbehaving nodes, meanwhile, their resources will be consumed. These two factors lead selfish nodes reluctant participate in cooperation and decrease the probability of correct authentication. To encourage nodes to take part in cooperation, we proposed a bargaining-based dynamic game model for cooperative authentication to analyze dynamic behaviors of nodes and help nodes decide whether to participate in cooperation or not. Further, to analyze the dynamic decision-making of nodes, we discussed two situations - complete information and incomplete information, respectively. Under complete information, Sub game Perfect Nash Equilibriums are obtained to guide nodes to choose its optimal strategy to maximize its utility. In reality, nodes often do not have good knowledge about others' utility (this case is often called incomplete information). To dealt with this case, Perfect Bayesian Nash Equilibrium is established to eliminate the implausible Equilibriums. Based on the model, we designed two algorithms for complete information and incomplete information,, and the simulation results demonstrate that in our model nodes participating in cooperation will maximize their location privacy and minimize their resources consumption with ensuing the probability of correct authentication. Both of algorithms can improve the success rate of cooperative authentication and extend the network lifetime to 160%-360.6%. Licai Liu, Lihua Yin, Yunchuan Guo, Binxing Fang |
TrustCom | 2 |
| 2014 | Toward inference attacks for k-anonymity
Yan Sun 0004, Lihua Yin, Licai Liu, Shuang Xin |
Pers. Ubiquitous Comput. | 2 |
| 2013 | Balancing authentication and location privacy in cooperative authenticationabstractIn MANET, the cooperative authentication mechanism requires the cooperation of the neighbor nodes and significantly enhances the authentication probability. However, it exposes location privacy of neighbor nodes and is costly. How to balance the authentication and location privacy is a key issue. In this paper, we use game theory to analyze the behavior of neighbor nodes in cooperative authentication and gain the optimal strategy. Every node seeks to obtain most reward at least location privacy loss and cost. We first build the static game with complete information and obtain two pure-strategy and one mixed-strategy Nash equilibria. These equilibria can be used efficiently to balance authentication and location privacy. Then, we build the static game with incomplete information and obtain the Bayesian Nash equilibria. Licai Liu, Yunchuan Guo, Lihua Yin, Yan Sun 0004 |
ANCS | 3 |
| 2013 | Privacy Vulnerability Analysis on Routing in Mobile Social NetworksabstractMobile social networks (MSNs) are a kind of delay tolerant network that consists of lots of mobile nodes with social characteristics. Recently, many social-aware algorithms have been proposed to address routing problems in MSNs. Because of the social properties introduced to routing, this results in node privacy disclosure. In this paper, analyzing social-based routing strategies, we propose a privacy attack tree model taking all the possible attack on social-based routing into account. This model describes all of the possibilities and approaches of privacy disclosure, and quantifies their the occurrence probability. Yan Sun 0004, Lihua Yin, Shuang Xin |
ICPADS | 2 |
| 2012 | Cyber Attacks Prediction Model Based on Bayesian NetworkabstractCyber attacks prediction is an important part of risk management. Existing cyber attacks prediction methods did not fully consider the specific environment factors of the target network, which may make the results deviate from the true situation. In this paper, we propose a cyber attacks prediction model based on Bayesian network. We use attack graphs to represent all the vulnerabilities and possible attack paths. Then we capture the using environment factors using Bayesian network model. Cyber attacks predictions are performed on the constructed Bayesian network. Experimental analysis shows that our method gets more accurate results. Lihua Yin, Yunchuan Guo |
ICPADS | 2 |
| 2012 | Network Security Analysis Method Taking into Account the Usage Information (Poster Abstract)
Lihua Yin, Binxing Fang |
RAID | 2 |
| 2012 | A novel logic-based automatic approach to constructing compliant security policies
Yibao Bao, Lihua Yin, Binxing Fang, Li Guo 0001 |
Sci. China Inf. Sci. | 2 |
| 2012 | Optimal mining on security labels for decentralized information flow control
Lihua Yin, Shuyuan Jin |
Comput. Secur. | 2 |
| 2011 | Poster: towards formal verification of DIFC policies
Lihua Yin, Miyi Duan, Shuyuan Jin |
CCS | 2 |
| 2011 | Towards Efficient Anonymous Communications in Sensor NetworksabstractAnonymous communication is a challenging task in resource constrained wireless sensor networks (WSN). However, anonymity is important for many sensor networks, in which we want to conceal the location and identify of important nodes (such as source nodes and base stations) from attackers. Existing WSN anonymous protocols either cannot achieve complete anonymity, or have large computation and/or storage overheads. In this paper, we present an efficient anonymous communication protocol for sensor networks. Our protocol can achieve sender/source anonymity, communication -relationship anonymity, and the base station anonymity simultaneously, while having small overheads on computation, storage and communication. Hongli Zhang 0001, Binxing Fang, Xiaojiang Du, Lihua Yin, Xiangzhan Yu |
GLOBECOM | 5 |
| 2010 | A General Distributed Object Locating Architecture in the Internet of ThingsabstractThis paper proposes a novel platform for object locating application in the Internet of Things environment. In this platform, objects and inquirers access and query locations using uniform service entry interfaces in heterogeneous services. To build a virtual storage system, services entries integrate enterprise database clusters and a DHT peer-to-peer network built with inquirers' devices. The DHT network is originally designed for accurate object locating, to enable fuzzy object locating we construct a hierarchical storage overlay network based on the DHT network. This LBS platform simplifies the object locating operation for ordinary inquirers greatly, moreover it provides huge virtual computing and storage resources for small companies and individual developers. Wenmao Liu, Lihua Yin, Weizhe Zhang, Hongli Zhang 0001 |
ICPADS | 2 |
| 2009 | Research on Quantitative Evaluation for IntegrityabstractIntegrity is one of essential properties of information security. It is necessary to analyze integrity of system quantitatively in order to protect the system security. For the purpose, we present formal definitions of integrity based on probabilistic computation tree logic (PCTL) and quantitative evaluation model of integrity. In the model, we model interoperations of system and environment by probabilistic automata and evaluate integrity quantitatively by probabilistic model checking algorithm. Analysis results show that the formal description of integrity is of great significance and evaluation results are different with different integrity goals even for the same system. Lihua Yin, Yunchuan Guo |
IAS | 1 |
| 2009 | Simulation Analysis of Probabilistic Timing Covert ChannelsabstractIt is very important to analyze the bandwidth and transmission error rate in the study of probabilistic timing covert channels. For the purpose, a simulation system of probabilistic timing covert channels has been set up in the paper. The simulation results show that (1) the bandwidth and the transmission error rate of probabilistic timing covert channels are closely related to the hardware/software environment, probability factor, time factor and/or coding methods as well as scheduling times; (2) the approximate transmission error rate can be measured with the central limit theorem; (3) it is not accurate to estimate the amount of information leakage based on weak probabilistic bisimulation; and (4) in probabilistic timing covert channels, there exist some characteristics which are different from non-deterministic covert channels. Yunchuan Guo, Lihua Yin, Yuan Zhou 0008, Chao Li 0027, Li Guo 0001 |
NAS | 2 |