VLDB 2026 Research / reviewers in the wild / expert
Wenhao Li 0005
dblp:11/444-5
· DBLP profile ↗
16ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0003-2268-7416ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 8 since 2021Computer networks · 5 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DAAPS: Distributed anonymous access control for pervasive edge computing services
Jie Chen 0093, Wenhao Li 0005, Shuai Wang 0079, Huamin Jin, Changsong Jiang |
Comput. Secur. | 2 |
| 2026 | Online Traffic Camouflage Against Network Analyzers via Deep Reinforcement LearningabstractTraffic analysis plays a pivotal role in network management. However, despite the prevalence of encryption, attackers are still able to deduce privacy elements such as user behavior and OS identification through advanced learning-based methods that exploit side-channel features. Existing defense strategies, which manipulate feature distribution to evade traffic analyzers, are often hampered by the need for impractical decoder deployment across all routes in symmetric framework methods. Moreover, reversing feature distribution modifications to real-time traffic, especially through dummy packet crafting or padding, is a complex task. In response to these challenges, we propose Veil, a novel and practical defender designed to protect live connections against encrypted network traffic analyzers. Leveraging an asymmetric deployment structure, Veil is capable of reconstructing live streams at the packet-block level, thereby allowing for seamless deployment on any connection node while enforcing transmission constraints. By employing a traffic-customized DQN framework, Veil not only reverses statistical feature perturbations back to the traffic space but also directs the distribution towards a target class. Extensive experiments conducted on real-world datasets validate the efficacy of Veil in efficiently evading analyzers in both targeted and untargeted modes, outperforming existing defense mechanisms. Notably, Veil addresses the key issues of impractical decoder deployment and complex real-time traffic manipulation, offering a more viable solution for network traffic privacy protection. The source code is publicly available at https://github.com/SecTeamPolaris/Veil, facilitating further research and application in the field of network security. Wenhao Li 0005, Jie Chen 0093, Zhaoxuan Li, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | Magnifier: Detecting Network Access via Lightweight Traffic-Based Fingerprints
Wenhao Li 0005, Qiang Wang 0059, Huaifeng Bao, Xiaoyu Zhang 0002, Lingyun Ying, Zhaoxuan Li, Huamin Jin, Shuai Wang 0079 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature ImputationabstractNetwork traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa). Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001 |
IEEE Trans. Netw. | 2 |
| 2024 | Poster: PGPNet: Classify APT Malware Using Prediction-Guided Prototype NetworkabstractAs the popularity of Advanced Persistent Threat (APT) grows, APT malware group classification has attracted more attention recently.However, most of previous methods use simple classifiers for group classification, ignoring the bias caused by the sparse number of revealed malware and the differences in functionality distribution of most groups.In this paper, we propose a Prediction-Guided Prototype Network (PGPNet) that could quickly adapt to new classification tasks with limited supervised samples based on the metalearning architecture.Adding malware functionality classification as an auxiliary task is beneficial for feature learning, and the bias of distribution differences is eliminated by intervening the predicted results into the group classifier.Experimental results on a APT malware dataset show that PGPNet successfully exploits the contextual information and predictions of the auxiliary task and achieves state-of-the-art performance. Huaifeng Bao, Wenhao Li 0005, Zhaoxuan Li, Han Miao, Wen Wang 0008, Feng Liu 0001 |
CCS | 2 |
| 2024 | Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic ExecutionabstractThe frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX. Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010 |
CCS | 3 |
| 2024 | Poster: Towards Real-Time Intrusion Detection with Explainable AI-Based DetectorabstractIdentifying malicious traffic is crucial for safeguarding internal networks from privacy breaches.Intrusion Detection Systems (IDS) traditionally rely on inefficient and outdated rule-sets, necessitating a shift towards AI-driven, learning-based algorithms for enhanced detection capabilities.Despite their promise, AI-integrated IDS face deployment challenges due to complex, opaque decision-making processes that can lead to latency and an increased risk of false positives.This paper presents the Explainable AI-based Intrusion Detection System (XAI-IDS), addressing the limitations of both rule-based and AI-driven IDS by integrating interpretable deep learning models.XAI-IDS employs tree regularization to transform complex models into efficient, transparent decision trees, facilitating real-time detection with improved accuracy and explainability.Experiments on two benchmark datasets demonstrate XAI-IDS's superior performance, offering a scalable solution to the challenge of identifying malicious traffic with reduced risk of false positives. Wenhao Li 0005, Duohe Ma, Zhaoxuan Li, Huaifeng Bao, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002 |
CCS | 1 |
| 2024 | Poster: Enhancing Network Traffic Analysis with Pre-trained Side-channel Feature ImputationabstractThe recent advances in learning-based methodologies has underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. Nonetheless, the distribution of these features has been identified as susceptible, particularly in the expansive and intricate network topologies characteristic of the modern Internet. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based augmentation framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic. The crux of Nüwa lies in its ability to reconstruct the side-channel features, with a particular focus on the temporal attributes of the missing packets within a traffic session. Nüwa is comprised of a word-level Sequence2Embedding module, a Traffic Noise-based Self-supervised Pre-trained Masking Strategy, and a Traffic Side-Channel Feature Imputation Module. Experiments across four diverse real-world scenarios substantiate Nüwa's capacity to restore the performance of prevalent temporal models while maintaining the integrity of the imputed features. Faqi Zhao, Duohe Ma, Wenhao Li 0005, Feng Liu 0001, Wen Wang 0008 |
CCS | 3 |
| 2024 | CAFE: Robust Detection of Malicious Macro based on Cross-modal Feature ExtractionabstractThe detection of malicious macros has been a prominent focus of research. Previous approaches exhibit two notable shortcomings. Firstly, methods centered on document and macro code features often fall short in effectively countering targeted adversarial strategies. Secondly, detection techniques relying on deceptive information, such as visual and textual cues, although alleviating certain challenges, introduce a new vulnerability to adversarial machine learning techniques. In this paper, we present Collaborative Adaptive Feature Extraction method (CAFE), designed for robust detection based on deceptive information. The core of CAFE is a feature fusion network architecture, where modality-shared associations and modalityprivate information are modeled from feature of different modalities, resulting in independently valid and comprehensive feature representations. An adaptive feature sampling module is introduced to address partial feature absence, enhancing detection robustness. Experimental results, conducted on two datasets, demonstrate that CAFE adeptly captures shared and complementary information from two modalities, showcasing its capability for robust malicious macro detection in the presence of input noise and adversarial samples. Index Terms—Malicious Macro Detection, Multi-modal Features, Model Robustness, Security Wen Wang is corresponding author. Huaifeng Bao, Xingyu Wang 0003, Wenhao Li 0005, Jinpeng Xu, Peng Yin 0001, Wen Wang 0008, Feng Liu 0001 |
CSCWD | 3 |
| 2024 | Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic DetectionabstractTo detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident. Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Wenhao Li 0005, Fan Zhang 0010 |
WWW | 4 |
| 2024 | metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001 |
Comput. Networks | 5 |
| 2024 | Stories behind decisions: Towards interpretable malware family classification with hierarchical attention
Huaifeng Bao, Wenhao Li 0005, Huashan Chen, Han Miao, Qiang Wang 0059, Zixian Tang, Feng Liu 0001, Wen Wang 0008 |
Comput. Secur. | 2 |
| 2023 | Prism: Real-Time Privacy Protection Against Temporal Network Traffic AnalyzersabstractTraffic analysis is widely used in network monitoring. However, the attackers can sometimes infer sensitive information from the patterns of the encrypted network traffic, which poses a threat to network security. Most existing countermeasures are proposed to obfuscate traffic flows using adversarial examples. However, there are two challenges when adding perturbations to live network traffic. Firstly, the perturbations imposed on the feature space cannot be conveniently projected to original traffic flows in feature-space based methods. Secondly, it is laborious and impractical to apply symmetrical framework to encode/decode the adversarial traffic in traffic-space based approaches. To address the above issues, in this paper, we propose an asymmetric defending scheme, namelyPrism, to protect theliveconnection privacy against attacks of temporal network traffic analyzers. Specifically,Prismfirst extracts standardized temporal features via Power-Law Division (PLD) algorithm, and then employs Time-stacked State Transition Model (TSTM) to obtain the fingerprint of each application. Finally,Prismdefends against the analyzers with online traffic perturbation. Since thePrismis designed as a traffic-space based defender with asymmetric defending structure, the deployment is lightweight and efficient. Experimental results on two real-world datasets demonstrate the effectiveness and generalization of our adversarial perturbations. In particular, it is encouraging to see that our proposed defending scheme outperforms the advanced countermeasures, such as adversarial training and traffic filter. Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Zhaoxuan Li, Haichao Shi, Qiang Wang 0059 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | ProGraph: Robust Network Traffic Identification With Graph PropagationabstractNetwork traffic identification is critical for effective network management. Existing methods mostly focus on invariant network environments with stable attribute distributions. Unfortunately, however, they can hardly be adaptive to the variation of practical networks and suffer from significant performance degradation. This problem largely stems from the over-dependence of existing methods on the vulnerable side-channel features. To address this issue, in this paper we propose a graph-based approach, namely ProGraph, to ensure robust network traffic classification among various network environments. The core idea of ProGraph is to construct a correlation graph with session clusters aggregated from different networks, based on which graph propagation can be effectively implemented to predict labels of testing nodes in an iterative manner. ProGraph enhances the correlation between clusters of the same class to provide reliable paths for label dissemination from the labeled clusters to the testing ones. It is encouraging to see that the proposed ProGraph achieves an accuracy of 92.25% in networks with constant attributes, while remaining stable with the accuracy of 90.89% when deployed in different networks, which significantly outperforms the state-of-the-art approaches. Meanwhile, ProGraph can accurately identify the novel classes which do not exist in the training dataset, with an AUC of 95.11. Last but not least, a carefully constructed dataset, namely CrossNet2021, containing network traffic of 20 classes of applications from two distinct networking scenarios, is made publicly available to support further research. Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Haichao Shi, Qiang Wang 0059 |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance LearningabstractWith the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle. Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002 |
IEEE Trans. Software Eng. | 7 |
| 2022 | Robust network traffic identification with graph matching
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Qiang Wang 0059, Zhaoxuan Li |
Comput. Networks | 1 |