VLDB 2026 Research / reviewers in the wild / expert
Hong Song 0004
dblp:09/4495-4
· DBLP profile ↗
15ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-1677-425XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Computer networks · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Period-Adaptive Traffic Fingerprint-Based Method for Smart Home Device IdentificationabstractWith the widespread adoption of smart home devices, there is a growing need for third-party device monitoring. Rapidly identifying device types from online traffic is essential for timely device detection, serving as a prerequisite for effective device supervision. As most smart home devices employ proprietary protocols, their communication traffic often lacks distinctive payload content. Existing methods typically rely on statistical features of data packets in idle traffic, combined with classification learning models, and commonly use fixed-time-window sampling for data collection. However, idle traffic from devices comprises multiple session flows, each often exhibiting distinct periodicity, which can lead to inaccurate feature extraction when fixed-length sampling is applied. To address this, we propose a smart home device identification method based on period-adaptive traffic fingerprinting. This method utilizes Fourier transform to analyze the periodicity of session flows, enabling adaptive partitioning of traffic samples based on their periodic characteristics. For rapid identification, key packets in the periodic traffic are first identified through clustering, followed by the extraction of packet header features and locality-sensitive hashing of the payload to construct packet-level traffic fingerprints. A hierarchical matching mechanism based on header and payload features is then employed to achieve device type identification. Experimental results on a public dataset demonstrate that the proposed method achieves an identification accuracy of 98.82%, outperforming existing baseline methods. In real-world smart home scenarios, the method enables rapid packet-level matching, providing identification results before a complete traffic period is reached, thus offering a responsive and efficient solution for device monitoring. Yingjie Hu 0005, Weiping Wang 0003, Shigeng Zhang, Hong Song 0004, Shilei Kuang |
ACSAC | 4 |
| 2025 | ProvGOutLiner: A lightweight anomaly detection method based on process behavior features within provenance graphs
Weiping Wang 0003, Hong Song 0004, Kai Chen 0012, Shigeng Zhang |
Comput. Secur. | 3 |
| 2025 | ASDroid: Resisting Evolving Android Malware With API Clusters Derived From Source CodeabstractMachine learning-based Android malware detection has consistently demonstrated superior results. However, with the continual evolution of the Android framework, the efficacy of the deployed models declines markedly. Existing solutions necessitate frequent and expensive model retraining to resist the constant evolution of malware accompanying Android framework updates. To address this, we introduce a solution called ASDroid, which generalizes specific APIs into similar API clusters to counteract evolving Android malware threats. One primary challenge lies in identifying analogous API clusters that correspond to specific APIs. Our approach involves extracting semantic information from open-source API source code to construct a heterogeneous information graph, and utilizing embedding algorithms to obtain semantic vector representations of APIs. APIs that are close in embedding distance are presumed to have similar semantics. Our dataset encompasses Android applications spanning nine years from 2011 to 2019. In comparison to existing Android malware detection model aging mitigation solutions like APIGraph, SDAC and MaMaDroid, ASDroid demonstrates greater accuracy and more effective at resisting continuously evolving malware. Qihua Hu, Weiping Wang 0003, Hong Song 0004, Song Guo 0001, Jian Zhang 0048, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Building Trust: Security Analysis in IoT Pairing StagesabstractWith the popularity of smart homes, the security issues of IoT devices have garnered significant attention, particularly the device pairing process, which is crucial for secure access and authorized use. However, current research on the communication security during this process remains insufficient. This paper aims to thoroughly analyze the security of the IoT device pairing process. The pairing process is first described using a state transfer model and divided into four phases: device discovery, device networking, remote authentication and remote binding. Subsequently, the different implementations adopted by different vendors in each specific phase are analyzed for the security vulnerabilities they may cause. These vulnerabilities are verified through experimental tests, involving the observation of multiple real devices, monitoring of traffic data, and application of attack methods, revealing existing vulnerabilities and deficiencies in some devices. Finally, based on the experimental results, targeted security improvement recommendations are proposed to enhance the overall security of the devices. Yingjie Hu 0005, Weiping Wang 0003, Shigeng Zhang, Hong Song 0004 |
MSN | 4 |
| 2024 | SimLog: System Log Anomaly Detection Method Based on SimhashabstractEnterprises face increasingly complex and frequent security threats, presenting significant challenges for timely prevention and response. Traditional log-based intrusion detection systems often rely on known attack signatures, limiting their ability to detect novel or evolving threats. Supervised anomaly detection methods, while leveraging machine learning techniques, are constrained by the scarcity of labeled attack samples, leading to gaps in detecting real-world attack variations. To address these limitations, this paper proposes a lightweight anomaly detection framework tailored for relatively stable server environments. The approach constructs provenance graphs from audit logs, extracts local subgraphs centered on process nodes, and utilizes Simhash for semantic embedding and frequency analysis. By combining locality-sensitive hashing with the K-medoids clustering algorithm, the method establishes a robust normal behavior model to detect anomalies. Experimental evaluations on public datasets and high-performance computing platforms demonstrate that the proposed method achieves 97% detection accuracy while significantly reducing the time costs compared to existing methods. Weiping Wang 0003, Yulu Hong, Hong Song 0004, Shigeng Zhang |
TrustCom | 5 |
| 2023 | TransAST: A Machine Translation-Based Approach for Obfuscated Malicious JavaScript DetectionabstractAs an essential part of the website, JavaScript greatly enriches its functions. At the same time, JavaScript has become the most common attack payload on malicious websites. Although researchers are constantly proposing methods to detect malicious JavaScript, the emergence of obfuscation technology makes it difficult for previous approaches to detect disguised malicious JavaScript effectively. To solve this problem, we find that there are fixed templates for generating obfuscated code, which makes the original and obfuscated script have a mapping relationship in their structure. The structure information of the code is critical for malicious detection. Therefore, this paper proposes TransAST, a novel static detection method for obfuscated malicious JavaScript. Our approach's key is restoring the obfuscated JavaScript structure information by training the machine translation model. The experiment shows it can achieve 91.35% accuracy and 94.57% recall in the public dataset, which is 5.5% and 10.94% higher than the existing optimal method. Weiping Wang 0003, Zixian Chen, Hong Song 0004, Shigeng Zhang |
DSN | 4 |
| 2022 | HashDroid:Extraction of malicious features of Android applications based on function call graph pruningabstractWith the Android system becoming the most popular operating system for mobile smart terminals, it is more likely to be targeted by malware. Therefore, many researches of malicous detection have emerged. Most of the features extracted of current malicious detection are discrete, such as single permission, single API, single component, API sequences and so on. These features can only detect the maliciousness of Android applications, but cannot characterize the malicious behavior of Android applications through these features. In this paper,we propose a method to automatically mine malicious features by pruning the function call graph(FCG) of Android applications. These extracted features not only have a good representation for the malicious behavior of Android applications, but also can efficiently detect the malicious. The method uses simhash to characterize the pruned subgraphs of FCG, and selects the subgraphs which play a decisive role in determining maliciousness as malicious features. These malicious features are then used for malicious detection of Android applications. The verification on public datasets shows that our method has a good effect of more than 97% in malicous detection of Android applications. Weiping Wang 0003, Hong Song 0004, Shigeng Zhang, Yulu Hong |
TrustCom | 3 |
| 2021 | A Deep Learning Framework for Gene Ontology Annotations With Sequence- and Network-Based InformationabstractKnowledge of protein functions plays an important role in biology and medicine. With the rapid development of high-throughput technologies, a huge number of proteins have been discovered. However, there are a great number of proteins without functional annotations. A protein usually has multiple functions and some functions or biological processes require interactions of a plurality of proteins. Additionally, Gene Ontology provides a useful classification for protein functions and contains more than 40,000 terms. We propose a deep learning framework called DeepGOA to predict protein functions with protein sequences and protein-protein interaction (PPI) networks. For protein sequences, we extract two types of information: sequence semantic information and subsequence-based features. We use the word2vec technique to numerically represent protein sequences, and utilize a Bi-directional Long and Short Time Memory (Bi-LSTM) and multi-scale convolutional neural network (multi-scale CNN) to obtain the global and local semantic features of protein sequences, respectively. Additionally, we use the InterPro tool to scan protein sequences for extracting subsequence-based information, such as domains and motifs. Then, the information is plugged into a neural network to generate high-quality features. For the PPI network, the Deepwalk algorithm is applied to generate its embedding information of PPI. Then the two types of features are concatenated together to predict protein functions. To evaluate the performance of DeepGOA, several different evaluation methods and metrics are utilized. The experimental results show that DeepGOA outperforms DeepGO and BLAST. Fuhao Zhang, Hong Song 0004, Min Zeng 0004, Fang-Xiang Wu, Yaohang Li, Yi Pan 0001, Min Li 0007 |
IEEE ACM Trans. Comput. Biol. Bioinform. | 2 |
| 2020 | A Method to Construct Vulnerability Knowledge Graph based on Heterogeneous DataabstractIn recent years, there are more and more attacks and exploitation aiming at network security vulnerabilities. It is effective for us to prevent criminals from exploiting vulnerabilities for attacks and help security analysts maintain equipment security that knows vulnerabilities and threats on time. With the knowledge graph, we can organize, manage, and utilize the massive information effectively in cyberspace. In this paper we construct the vulnerability ontology after analyzing multi-source heterogeneous databases. And the vulnerability knowledge graph is established. Experimental results show that the accuracy of entity recognition for extracting vendor names reaches 89.76%. The more rules used in entity recognition, the higher the accuracy and the lower the error rate. Yizhen Sun, Dandan Lin, Hong Song 0004, Minjia Yan, Linjing Cao |
MSN | 3 |
| 2017 | TC-CCS: A cooperative caching strategy in mobile transparent computing systemabstractMobile Transparent Computing System (MTCS) is an implementation of Transparent Computing (TC). Operating systems, applications and users' data are regarded as resources and stored in the TC servers. Clients of MTCS can get various services from TC servers through Internet. Network bandwidth is one of the most important factors that impact the performance of MTCS. This paper proposes a two-level cooperative caching strategy working on local terminals, named TC-CCS (Transparent Computing Cooperative Caching Strategy). The first level cache is the local cache of each terminal, which stores common personal data to avoid data fetching from TC server. The second level cache is P2P cache, which stores OSes and software served for users in local network. A replacement algorithm TCRA, combined with multi-queue of LRU and LFU, is proposed to improve data hit rate. The experimental results show that TC-CCS can reduce 40% of OS's startup time and the response time of software can be reduced to 34% if the bandwidth is close to 1MB/s. Hong Song 0004, Dacheng Wang, Jianxin Wang 0001 |
VCIP | 1 |
| 2014 | A Novel Key Management Scheme in VANETs
Guihua Duan, Rui Ju, Hong Song 0004 |
ICA3PP (1) | 4 |
| 2014 | Design and Implementation of Network Hard Disk
Hong Song 0004, Jialong Xu, Xiaoqiang Cai |
ICA3PP (1) | 1 |
| 2014 | The Study on the Increasing Strategy of Detecting Moving Target in Wireless Sensor Networks
Jialong Xu, Zhigang Chen 0001, Anfeng Liu, Hong Song 0004 |
ICA3PP (1) | 4 |
| 2012 | A Congestion Level based end-to-end acknowledgement mechanism for Delay Tolerant NetworksabstractEnd-to-end reliability in Delay Tolerant Networks (DTNs) is challenging and complicated because of high delay and absence of stable end-to-end path in the intermittently-connected mobile environment. Some existing acknowledgement mechanisms use active forwarding to provide the end-to-end reliability, while incurring excessive retransmissions or replications. The other passive mechanisms aim to reduce the storage overhead but may suffer a large delay. To improve the storage-delay tradeoff, we propose a Congestion Level based end-to-end ACKnowledgement (CL-ACK) mechanism, which adaptively adjusts the spread manner of ACK packets according to the ratio of drops over replications. Simulation results show that CL-ACK effectively controls resources consumption, reduces end-to-end delay, and achieves high message delivery rate. Ying An, Jiawei Huang 0001, Hong Song 0004, Jianxin Wang 0001 |
GLOBECOM | 3 |
| 2011 | DENNC: A Wireless Malicious Detection Approach Based on Network CodingabstractIn wireless networks, communications among nodes are vulnerable to attacks launched by malicious nodes. Presently, Existing malicious node detection approaches either need special hardware or depend on node listening, node encryption or node identity authentication, resulting high costs of networks. In this paper, we present a novel network coding-based malicious detection approach called DENNC for wireless networks. The key idea is to use the characteristic of information exchange to validate the information packets. The neighboring nodes of the sending node may judge the malicious behaviors by checking the correctness of the data packets and related hash value. Our approach requires no superfluity hardware and does not use complicated secret key encryption mechanisms. Analysis reveals that the proposed approach can detect the malicious node in highly probability. Hong Song 0004, Weiping Wang 0003, Luming Yang |
TrustCom | 1 |