Qiuyun Wang

dblp:120/6867 · DBLP profile ↗
← Back
23ranked-venue papers
2as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 7 · 7 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author
YearPublicationVenuePosition
2026 GDPO: Dual Learning for Self-Supervised Code Summarization in the Era of Large Language Models
Shuwei Wang, Weize Zhang, Zhengwei Jiang, Qiuyun Wang
SANER5
2025 What Makes an Email Insecure: A Fine-Grained Risk Assessment Scheme for Phishing Emails Targeting Attack Vectors
abstract
As online adversarial tactics escalate, particularly with the utilization of large language models, distinguishing phishing emails from benign ones has become increasingly challenging in terms of appearance and semantics. The use of various techniques, including visual deception and the concealment of malicious attachments, has become more widespread, posing significant challenges to traditional machine learning models that rely on text and semantic features. To address these challenges, this study introduces a Fine-grained Phishing Email Risk Assessment framework (FPERA), which focuses on prevalent attack vectors. By integrating techniques such as deep email header inspection, visual analysis, and threat intelligence, FPERA systematically examines potential risk factors across multiple dimensions and calculates the risk score of emails using a risk weighting matrix. Experimental tests conducted on multiple original datasets and AI-generated datasets have demonstrated that detection targeting attack vectors can more effectively counter phishing tactics like AI-enhanced polishing, email header exploits, and visual deception, while exhibiting consistent stability across different datasets.
Ximin Huang, Fangli Ren, Weize Zhang, Shuwei Wang, Qiuyun Wang, Zhengwei Jiang
CSCWD6
2025 Automated Attack Graph Construction for Cross-host Threat Detection Using Cyber Threat Intelligence
abstract
Cyber Threat Intelligence (CTI) reports provide valuable insights into cyber threats. However, manually constructing attack graphs from the unstructured CTI reports requires significant human effort. With the development of Large Language Models (LLMs), researchers have begun to harness LLMs for attack graph construction from CTI reports. Nevertheless, existing works mainly focus on describing abstract and high-level attack behaviors through these graphs, which cannot be used as query graphs for threat detection based on graph matching, as provenance graphs are at the system level. Moreover, these works do not consider modeling cross-host attack behaviors. To address these problems, we propose a novel method for automatically constructing attack graphs from CTI reports. We utilize prompt engineering, and leverage the in-context learning ability of LLMs to generate attack graphs. In this method, we first restructure the CTI report by grouping continuous sentences with the same tactics, and then use multiple LLMs to extract entities and relations. Finally, we use an LLM to integrate all the results. We also design a cross-host threat detection algorithm using the generated attack graphs. The evaluation results show that our method constructs attack graphs with an average conversion rate of 72.4%. It also achieves nearly 94.8% precision and 96.5% recall for IoC and relation extraction compared with manually labeled results.
Ziqing Feng, Qiuyun Wang, Liling Xin, Zhengwei Jiang, Huamin Feng
TrustCom5
2025 Who are querying for me? Measuring the dependency and centralization in recursive resolution
Qiuyun Wang, Jianrong Zhang, Baojiang Cui, Zhengwei Jiang
Comput. Secur.2
2024 Automated Anti-malware Detection Rules Converter Based on SIMIOC
abstract
In recent years, using IOC to detect malware-based network attacks has become an effective and accurate method, but the scheme of manually writing IOC rules is inefficient and can not meet the detection needs of a large number of rapidly iterated malware. Therefore, more efficient methods are needed to automatically convert open-source rules into anti-malware detection rules (IOC rules for detecting malware). In this paper, we propose a method to automate the conversion of anti-malware detection rules using open-source detection rules. We designed an intermediate structure called SIMIOC (Structure Intermediate-representation for Malware Information of Compromise) and implemented a SIMIOC-based converter. In the experiment, we used the SIMIOC-based converter to automatically convert 1218 rules for the Windows platform from three open-source rule repositories: Sigma, Elastic Security Detection Rules, and Splunk Security Content into signature detection rules that can be used in the Cuckoo sandbox, and deployed these rules to detect 21044 malware. By analyzing the experimental results, we found that the detection rate of the detection rules automatically converted by SIMIOC-based converter is 50.3%, and it reaches 73% of 640 cuckoo Sandbox signature manual rules. Furthermore, we demonstrated that the rules generated by SIMIOC-based converters have their emphasis on TTPs (Tactics, Techniques, and Procedures) and families, which are the optimization and complement of manual rules.
Shuangze He, Zhengwei Jiang, Qiuyun Wang
CSCWD6
2024 A Novel Detection System for Multi-Architecture IoT Malware
abstract
As IoT devices become more prevalent, the thread that comes from the malware of IoT becomes more serious. In comparison to desktops, IoT malware has characteristics of different platforms, considerable environment reliance, and continual updating of countermeasure technology, which creates a huge obstacle for malware detection. In light of the aforementioned issues, we propose a set of analysis methods, including static analysis against software shells, dynamic analysis with sandbox has 9 different architecture environments, and a detection model designed based on SHAP(SHapley Additive ex-Planations) and Smith-Waterman algorithm with a small amount of prior knowledge about IOT malware. The experimental results show that reports about malware containing static information and dynamic behavior can be generated. And the detection accuracy of the model can reach 98.31%. At the same time, in the case of the training set has fewer malicious samples, the accuracy that our model has a 5%-10% improvement, proof of our method has better malware discovery ability for unknown variants.
Shuwei Wang, Molan Long, Qiuyun Wang, Rongqi Jing, Zhengwei Jiang
CSCWD4
2024 Automated Mining of Multi-Dimensional Information from APT Malware for Effective Feature Analysis and Threat Actor Attribution
Rongqi Jing, Zhengwei Jiang, Qiuyun Wang, Shuwei Wang
ICONIP (6)3
2023 Who Are Querying For Me? Egress Measurement For Open DNS Resolvers
abstract
The dependencies and centralization in DNS infrastructure increase the risk of single-point failure and the scope of collateral damage. In the DNS recursive resolution, dependencies between different resolvers also exist due to situations such as forwarding. Currently, research on dependencies in recursive resolution is still insufficient. In this work, we take a deep insight into the recursive resolution implemented by open resolvers to investigate their dependencies, including the concentration of dependencies, and the influence of 3rd-party providers. We find that most open resolvers in the wild are dependent on a small number of egress resolvers to communicate with the authoritative name servers. 90% of the open resolvers are influenced by 8.41% of the egress resolvers. Besides, egress resolvers from 3rd-party providers are able to influence more than 44% of the open resolvers. The concentration makes a large amount of DNS traffic concentrated in a small number of egress resolvers/providers, which will reduce the redundancy of DNS and threaten user privacy.
Meng Luo 0006, Liling Xin, Yepeng Yao, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi
CSCWD5
2023 M3F: A novel multi-session and multi-protocol based malware traffic fingerprinting
Jian Liu 0008, Qingsai Xiao, Liling Xin, Qiuyun Wang, Yepeng Yao, Zhengwei Jiang
Comput. Networks4
2022 Effectiveness Evaluation of Evasion Attack on Encrypted Malicious Traffic Detection
abstract
With more and more TLS encrypted traffic on the Internet, an increasing amount of malware is using TLS to hide their tracks. The encrypted traffic makes the traditional malicious traffic detection methods invalid. Machine learning algorithms have become essential options for detecting encrypted malicious traffic. Recently, researchers found that machine learning algorithms have flaws, and threat actors can use some tricks to evade detection. But it remains an open question on how these machine learning-based encrypted malicious traffic detection algorithms perform in the face of evasion attacks.We explore the answer in this paper. We first define five mutation rules to generate adversarial examples. With these mutation rules, we can evaluate the ability of several detection algorithms to deal with evasion attacks when detecting encrypted malicious traffic. The encrypted malicious traffic collected for 12 months is used for experiments. Experiments show that modifying the destination port can reduce the detection rate of detection algorithms in feature space, except for random forest algorithms. Inserting junk data has minimal effect on these algorithms. Whether in the problem space or feature space, inserting useless cipher suites and simulating browser’s traffic can significantly reduce the detection rate of these algorithms. When simulating browser’s traffic, the random forest algorithm almost loses its usability. The same situation arises when SVM is faced with inserting useless cipher suites. Compared with inserting useless cipher suites, inserting useless extensions has a minor effect on these algorithms. Our findings will contribute to future research on encrypted malicious traffic detection.
Jian Liu 0008, Qingsai Xiao, Zhengwei Jiang, Yepeng Yao, Qiuyun Wang
WCNC5
2022 Measurement for encrypted open resolvers: Applications and security
Meng Luo 0006, Yepeng Yao, Liling Xin, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi
Comput. Networks5
2021 Spear Phishing Emails Detection Based on Machine Learning
abstract
Spear phishing emails target to specific individual or organization, they are more elaborated, targeted, and harmful than phishing emails. The attackers usually harvest information about the recipient in any available ways, then create a carefully camouflaged email and lure the recipient to perform dangerous actions. In this paper we present a new effective approach to detect spear phishing emails based on machine learning. Firstly we extracted 21 Stylometric features from email, 3 forwarding features from Email Forwarding Relationship Graph Database(EFRGD), and 3 reputation features from two third-party threat intelligence platforms, Virus Total(VT) and Phish Tank(PT). Then we made an improvement on Synthetic Minority Oversampling Technique(SMOTE) algorithm named KM-SMOTE to reduce the impact of unbalanced data. Finally we applied 4 machine learning algorithms to distinguish spear phishing emails from non-spear phishing emails. Our dataset consists of 417 spear phishing emails and 13916 non-spear phishing emails. We were able to achieve a maximum recall of 95.56%, precision of 98.85% and 97.16% of F1-score with the help of forwarding features, reputation features and KM-SMOTE algorithm.
Xiong Ding, Baoxu Liu, Zhengwei Jiang, Qiuyun Wang, Liling Xin
CSCWD4
2021 HSRF: Community Detection Based on Heterogeneous Attributes and Semi-Supervised Random Forest
abstract
Potential connections between complex networks need to be discovered by the network community detection. Current detection methods are commonly based on homogeneous information networks, which usually extract single information among the nodes of the complex network and will lead to incomplete information or information loss. To address these problems existing on community detection, we propose a novel method based on heterogeneous attributes and semi-supervised Random Forest (HSRF) inspired by heterogeneous information networks. We define heterogeneous attribute arrays of nodes, which reflect the structural relationships between nodes in complex networks. Semi-supervised learning based on Jaccard similarity coefficients is introduced to predict the noise points and solve the problem of anti-noise interference. Our experiments on real networks and synthetic standard networks show that HSRF improves the generalization of the undirected and directed network community detection. Moreover, our HSRF performs better in terms of robustness when the community boundary structure becomes more ambiguous and convenient for parallel processing.
Zijing Fan, Liling Xin, Xuren Wang, Zhengwei Jiang, Qiuyun Wang
CSCWD6
2021 Producing More with Less: A GAN-based Network Attack Detection Approach for Imbalanced Data
abstract
Machine learning techniques are shown to be effective for network attack detection systems in identifying malicious network behaviors. In the real-world environment, however, network attack traffic i soften hidden under a large amount of normal daily communication traffic. In this paper, to resolve such challenges that the large-scale data is difficult to be effectively labeled, we propose a data augmentation method based on generative adversarial networks. The features of flow-based network traffic are firstly pre-processed to fit the generative adversarial networks (GANs). Then, we enhance the original GANs by adopting Earth-Mover (EM) distance to catch the distribution of low dimensional subspace data and add an encoder structure to learn latent space representation. Compared to other data augmentation methods, our method generates data from learning data distribution rather than performing numerical calculations on existing data. We construct an imbalanced dataset based on the real-world dataset and compare it with other methods. Our method reports better performance in terms of the recall, F1-score, and AUC, which proved the effectiveness of our proposed method.
Xingran Hao, Zhengwei Jiang, Qingsai Xiao, Qiuyun Wang, Yepeng Yao, Baoxu Liu, Jian Liu 0008
CSCWD4
2021 Joint Congestion Control and Resource Allocation for Delay-Aware Tasks in Mobile Edge Computing
abstract
Recently, in order to extend the computation capability of smart mobile devices (SMDs) and reduce the task execution delay, mobile edge computing (MEC) has attracted considerable attention. In this paper, a stochastic optimization problem is formulated to maximize the system utility and ensure the queue stability, which subjects to the power, subcarrier, SMDs, and MEC server computation resource constraints by jointly optimizing congestion control and resource allocation. With the help of the Lyapunov optimization method, the primal problem is transformed into five subproblems including the system utility maximization subproblem, SMD congestion control subproblem, SMD computation resource allocation subproblem, joint power and subcarrier allocation subproblem, and MEC server scheduling subproblem. Since the first three subproblems are all single variable problems, the solutions can be obtained directly. The joint power and subcarrier allocation subproblem can be efficiently solved by utilizing alternating and time‐sharing methods. For the MEC server scheduling subproblem, an efficient algorithm is proposed to solve it. By solving the five subproblems at each slot, we propose a delay‐aware task congestion control and resource allocation (DTCCRA) algorithm to solve the primal problem. Theoretical analysis shows that the proposed DTCCRA algorithm can achieve the system utility and execution delay trade‐off. Compared with the intelligent heuristic (IH) algorithm, when the control parameter V increases from 106 to 107, the total backlogs are decreased by 5.03% and the system utility is increased by 3.9% on average for the extensive performance by using the proposed DTCCRA algorithm.
Shichao Li 0001, Qiuyun Wang, Jianli Xie, Cuiran Li, Dengtai Tan, Weigang Kou
Wirel. Commun. Mob. Comput.2
2020 A Weak Coupling of Semi-Supervised Learning with Generative Adversarial Networks for Malware Classification
abstract
Malware classification helps to understand its purpose and is also an important part of attack detection. And it is also an important part of discovering attacks. Due to continuous innovation and development of artificial intelligence, it is a trend to combine deep learning with malware classification. In this paper, we propose an improved malware image rescaling algorithm (IMIR) based on local mean algorithm. Its main goal of IMIR is to reduce the loss of information from samples during the process of converting binary files to image files. Therefore, we construct a neural network structure based on VGG model, which is suitable for image classification. In the real world, a mass of malware family labels are inaccurate or lacking. To deal with this situation, we propose a novel method to train the deep neural network by Semi-supervised Generative Adversarial Network (SGAN), which only needs a small amount of malware that have accurate labels about families. By integrating SGAN with weak coupling, we can retain the weak links of supervised part and unsupervised part of SGAN. It improves the accuracy of malware classification by making classifiers more independent of discriminators. The results of experimental demonstrate that our model achieves exhibiting favorable performance. The recalls of each family in our data set are all higher than 93.75%.
Shuwei Wang, Qiuyun Wang, Zhengwei Jiang, Xuren Wang, Rongqi Jing
ICPR2
2020 Towards Comprehensive Detection of DNS Tunnels
abstract
The Domain Name System (DNS) is a fundamental service of the Internet, and the DNS tunnel is one of the most threatening abuses of DNS, posing a huge threat to user privacy and Internet security. Attackers conceal the information into DNS packets to evade firewalls and intrusion detection systems. Recently, newly developed DNS tunnels used by Advanced Persist Threat groups tend to use A and AAAA resource records (RRs) for transmission, making them more invisible and more threatening. Previous DNS tunnel detection approaches mainly focus on subdomains and TXT RRs, but less attention has been paid to newly developed DNS tunnels based on A and AAAA RRs. In this paper, we present a novel DNS tunnel detection method that can detect newly developed A and AAAA RR based DNS tunnels. Since DNS tunnels will transmit a large amount of encrypted or encoded data in the DNS queries and responses, we extracted novel features from domains and 4 types of RRs (A, AAAA, TXT and CNAME RRs) that are most commonly used for tunneling to measure the amount and content of information exchanged between the authoritative nameservers and the clients. We also analyze the detection capabilities when different features were used. The anomaly detection algorithm is employed on domains related features and 4 types of RRs related features, respectively. The overlaps of outliers will be marked as DNS tunnels. Our approach has been evaluated on real-world network traffic. The experimental results show that our approach can detect all DNS tunnels in the dataset with a extremely low false positive rate.
Meng Luo 0006, Qiuyun Wang, Yepeng Yao, Xuren Wang, Peian Yang, Zhengwei Jiang
ISCC2
2020 Threat Intelligence Relationship Extraction Based on Distant Supervision and Reinforcement Learning
Xuren Wang, Qiuyun Wang, Changxin Su
SEKE3
2019 Dynamic Server Switching for Energy Efficient Mobile Edge Networks
abstract
Edge servers are densely deployed in the future mobile edge networks to meet the rapid increasing demand of mobile users. Since the distribution and traffic demand of user equipment (UE) fluctuate in time and over space, a number of edge servers may be underutilized which causes a great deal of energy waste. Therefore, we intend to reduce the energy cost of mobile edge networks, by dynamically switching on/off edge servers according to the variation of UEs' distribution. We formulate the energy saving problem in mobile edge networks as the minimum energy consumption (MinEn) problem which involves two critical issues: (1) cooperative service caching and UE association of adjacent BSs; (2) switching on/off edge servers. To solve the MinEn problem, we propose a dynamic server switching algorithm along with a lightweight UE distribution prediction mechanism. Simulation results show that our algorithm can greatly reduce the energy consumption of mobile edge networks compared with existing methods.
Qiuyun Wang, Qingyuan Xie, Nuo Yu, Hejiao Huang, Xiaohua Jia
ICC1
2019 Delay-Aware Task Congestion Control and Resource Allocation in Mobile Edge Computing
abstract
Mobile edge computing (MEC) is considered as a promising paradigm to extend the computation capability of smart mobile devices (SMDs) and reduce the task execution delay. In this paper, we formulate a stochastic optimization problem, which maximizes the system utility and ensures the queues stability subject to the power, subcarrier and computation resources constraints by the joint congestion control and resource allocation. Leveraging on the Lyapunov optimization technique, four subproblems are decomposed. Because the system utility maximization subproblem, congestion control subproblem and SMDs computation resource allocation subproblem are all single variable problems, we can obtain the solutions directly. The joint power and subcarrier allocation subproblem can be efficiently solved by utilizing alternating and time-sharing methods. By solving the four separate subproblems at each slot, we proposed a delay-aware task congestion control and resource allocation (DTCCRA) algorithm. Theoretical analysis shows that the system utility of proposed DTCCRA algorithm increases by 18.91% and 26.14% respectively compared with traditional average power allocation algorithm and average subcarrier allocation algorithm.
Qiuyun Wang, Dengtai Tan
PIMRC2
2018 Collaborative Service Placement for Mobile Edge Computing Applications
abstract
Mobile edge computing (MEC) can improve the quality of services and save the bandwidth of backhual networks, by placing application services in the base stations (BSs), which are endowed with computing resources and are in close proximity to user equipments (UEs). Since the capacity of an individual BS is limited, only a small number of service instances can be allowed for each BS at the same time. Meanwhile, in a densely deployed network, the coverage areas of adjacent BSs are overlapped. Therefore, these capacity-limited BSs can collaboratively optimize their service placements to improve the performance of MEC. In this paper, we investigate the collaborative service placement (CSP) problem in MEC, which aims to minimize the traffic load caused by service request forwarding. The CSP problem involves several difficult issues, including correlations of adjacent BSs' service placement decisions, joint service placement and UE association, and joint allocation of computing and radio resources. This makes the CSP problem be a complex combinatorial optimization problem. To solve the CSP problem, we propose an efficient decentralized algorithm based on the Matching Theory. It can optimize the decisions of service placement and BS-UE association for BSs, according to local interactions between BSs and UEs. Our proposed algorithm is practical for large-size networks, and its effectiveness is demonstrated by the simulation results.
Nuo Yu, Qingyuan Xie, Qiuyun Wang, Hongwei Du 0001, Hejiao Huang, Xiaohua Jia
GLOBECOM3
2018 Dynamic Service Caching in Mobile Edge Networks
abstract
Caching application services at the edge of mobile networks can both reduce the traffic load in core networks and improve the quality of services. Since the capacity of a single BS is constrained, only a small number of service can be executed simultaneously by each BS. However, when the BSs are densely deployed in the network, the BSs that are close to each other can cooperatively cache the services to improve the performance of the system. Moreover, we should avoid frequent service switching when the users' service requests always change. In this paper, we study the dynamic service caching (DSC) problem in mobile edge networks. Our objective is to minimize the traffic load that needs to be forwarded to the cloud, as well as considering service switching cost of BSs. This DSC problem involves two important issues, which include cooperative service caching of adjacent BSs and service switching in adjacent time slots. To solve the DSC problem, we propose a dynamic service caching algorithm for the BSs to cooperatively cache the services in an online manner. The simulation results show that our algorithm can greatly reduce the forwarded traffic load without frequently changing the service caching of BSs.
Qingyuan Xie, Qiuyun Wang, Nuo Yu, Hejiao Huang, Xiaohua Jia
MASS2
2012 Map estimation of the input of an oversampled filter bank from noisy subbands by belief propagation
abstract
Oversampled filter banks perform a subband decomposition with redundancy representation. This redundancy has been shown to be useful to combat channel impairments, when the subbands are transmitted over a wireless channel, as well as quantization noise. This paper describes an implementation of the maximum a posteriori and the minimum mean-square error (MMSE) estimators of the input signal from the noisy quantized subbands obtained at the output of some transmission channel. The relations between the input samples and the noisy subband samples are described using a factor graph. Belief propagation is then applied to get the posterior marginals of the input samples. The experimental results show that when the channel is clear, a linear MMSE estimate performs quite well but the proposed approaches perform significantly better than a reconstruction using the linear MMSE estimator when the channel is noisy: a gain in terms of channel SNR of more than 2 dB is observed.
Qiuyun Wang, Manel Abid, Michel Kieffer, Béatrice Pesquet-Popescu
ICASSP1