Bin Zhang 0048

dblp:13/5236-48 · DBLP profile ↗
← Back
34ranked-venue papers
2as first author
26since 2021 · last 2026
0009-0005-5012-7151ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 11 · 10 since 2021Security and privacy · 8 · 6 since 2021Computer networks · 7 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 5 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Generalizable Deepfake Detection via Forgery-Aware Audio-Visual Adaptation: A Variational Bayesian Approach
abstract
The widespread application of AIGC contents has brought not only unprecedented opportunities, but also potential security concerns, e.g., audio-visual deepfakes. Therefore, it is of great importance to develop an effective and generalizable method for multi-modal deepfake detection. Typically, the audio-visual correlation learning could expose subtle cross-modal inconsistencies, e.g., audio-visual misalignment, which serve as crucial clues in deepfake detection. In this paper, we reformulate the correlation learning with variational Bayesian estimation, where audio-visual correlation is approximated as a Gaussian distributed latent variable, and thus develop a novel framework for deepfake detection, i.e., Forgery-aware Audio-Visual Adaptation with Variational Bayes (FoVB). Specifically, given the prior knowledge of pre-trained backbones, we adopt two core designs to estimate audio-visual correlations effectively. First, we exploit various difference convolutions and a high-pass filter to discern local and global forgery traces from both modalities. Second, with the extracted forgery-aware features, we estimate the latent Gaussian variable of audio-visual correlation via variational Bayes. Then, we factorize the variable into modality-specific and correlation-specific ones with orthogonality constraint, allowing them to better learn intra-modal and cross-modal forgery traces with less entanglement. Extensive experiments demonstrate that our FoVB outperforms other state-of-the-art methods in various benchmarks.
Fan Nie, Jiangqun Ni, Jian Zhang 0086, Bin Zhang 0048, Weizhe Zhang, Bin Li 0011
IEEE Trans. Inf. Forensics Secur.4
2025 DTPN: A Diffusion-based Traffic Purification Network for Tor Website Fingerprinting
abstract
Website Fingerprinting attack is a type of method used to classify network traffic generated by users on the Tor (The Onion Router) based on the websites they visit, leading to the leakage of individuals' privacy . For Website Fingerprinting attack, network traffic defense methods involve adding noise to the original network traffic to render the attacker's methods ineffective. Previous attack methods primarily focused on improving classification accuracy by enhancing the attack model, with adversarial training being the most common approach. However, adversarial training requires frequent updates and exhibits poor generalization when dealing with previously unseen network traffic protection methods. In order to address the limitations of adversarial training, a novel method is proposed leveraging a diffusion model for network traffic purification. This paper is the first to use a diffusion model to resist network traffic defense based on adversarial perturbations. The diffusion models are theoretically suited for data purification in the training mode, i.e., removing noises generated by adversarial perturbations from the data. Our method enables existing network traffic classification methods to maintain effective classification of network traffic after protection without requiring retraining, while also achieving good generalization performance with previously unseen network traffic defense methods. The purified network traffic data can effectively improve the robustness of existing website fingerprinting methods. Experiments conducted under various network traffic defense strategies demonstrate that the proposed method increases accuracy by up to 60.8% on DF dataset and 50.3% on CW100 dataset, respectively, compared to adversarial training.
Xi Xiao 0001, Guangwu Hu, Zhen Ling 0001, Hao Li 0027, Bin Zhang 0048
WSDM6
2025 AR: An Efficient Alliance Root Service with Decentralized Trust
Bin Zhang 0048, Yu Zhang 0036, Yuming Feng 0002, Wei-Zhe Zhang, Dongcen Ji, Fan Nie
J. Comput. Sci. Technol.1
2025 RBLJAN: Robust Byte-Label Joint Attention Network for Network Traffic Classification
abstract
Network traffic classification plays a crucial role in network management and cyberspace security. As the Internet evolves with new applications and protocols, traditional machine learning-based methods relying on feature mining have become obsolete. Instead, deep learning-based methods are becoming more popular in the field of traffic classification due to their end-to-end processing approach. However, the vulnerability of neural networks to adversarial examples significantly compromises their performance. In this paper, we propose Robust Byte-Label Joint Attention Network (RBLJAN), an efficient and robust deep learning-based framework for encrypted network traffic classification at both the packet-level and the flow-level. RBLJAN comprises a classifier and an adversarial traffic generator. The classifier utilizes mechanisms such as header-payload parallel processing and byte-label joint attention learning to capture implicit correlations between bytes and labels, enabling the construction of powerful packet representations. The generator produces adversarial examples that are fed to the classifier to enhance its robustness. Experimental results demonstrate that RBLJAN achieves over 99% average F1-score on real-world legitimate traffic datasets and achieves 97.86% average F1-score on malware identification. Moreover, RBLJAN exhibits superior performance in terms of detection speed and robustness compared to state-of-the-art methods in real-world scenarios.
Xi Xiao 0001, Shuo Wang 0012, Guangwu Hu, Qing Li 0006, Kelong Mao, Xiapu Luo, Bin Zhang 0048, Shutao Xia
IEEE Trans. Dependable Secur. Comput.7
2025 DIP: Diffusion Learning of Inconsistency Pattern for General DeepFake Detection
abstract
With the advancement of deepfake generation techniques, the importance of deepfake detection in protecting multimedia content integrity has become increasingly obvious. Recently, temporal inconsistency clues have been explored to improve the generalizability of deepfake video detection. According to our observation, the temporal artifacts of forged videos in terms of motion information usually exhibits quite distinct inconsistency patterns along horizontal and vertical directions, which could be leveraged to improve the generalizability of detectors. In this paper, a transformer-based framework forDiffusion Learning ofInconsistencyPattern (DIP) is proposed, which exploits directional inconsistencies for deepfake video detection. Specifically, DIP begins with a spatiotemporal encoder to represent spatiotemporal information. A directional inconsistency decoder is adopted accordingly, where direction-aware attention and inconsistency diffusion are incorporated to explore potential inconsistency patterns and jointly learn the inherent relationships. In addition, the SpatioTemporal Invariant Loss (STI Loss) is introduced to contrast spatiotemporally augmented sample pairs and prevent the model from overfitting nonessential forgery artifacts. Extensive experiments on several public datasets demonstrate that our method could effectively identify directional forgery clues and achieve state-of-the-art performance.
Fan Nie, Jiangqun Ni, Jian Zhang 0086, Bin Zhang 0048, Weizhe Zhang
IEEE Trans. Multim.4
2025 Robust k-Means-Type Clustering for Noisy Data
abstract
Data clustering is a fundamental machine learning task that seeks to categorize a dataset into homogeneous groups. However, real data usually contain noise, which poses significant challenges to clustering algorithms. In this article, motivated by how the k-means algorithm is derived from a Gaussian mixture model (GMM), we propose a robust k-means-type algorithm, named k-means-type clustering based on t-distribution (KMTD), by assuming that the data points are drawn from a special multivariate t-mixture model (TMM). Compared to the Gaussian distribution, the t-distribution has a fatter tail. The proposed algorithm is more robust to noise. Like the k-means algorithm, the proposed algorithm is simpler than those based on a full TMM. Both synthetic and actual data are used to illustrate the proposed algorithm's performance and efficiency. The experimental results demonstrated that the proposed algorithm operates more quickly than other sophisticated algorithms and, in most cases, achieves higher accuracy than the other algorithms.
Xi Xiao 0001, Guojun Gan, Qing Li 0006, Bin Zhang 0048, Shutao Xia
IEEE Trans. Neural Networks Learn. Syst.5
2024 CapsuleFormer: A Capsule and Transformer combined model for Decentralized Application encrypted traffic classification
abstract
Network traffic classification plays a crucial role in both network management and monitoring. Recently, an increasing number of Decentralized Applications (DApps) are appearing on various blockchain platforms. DApps employ encryption techniques such as SSL/TLS to safeguard the data transmitted over the network, making it more challenging to do traffic classification. In this paper, to tackle the challenge of insufficient classification accuracy in the existing classification of encrypted DApp traffic, we present Capsule-Former, a novel encrypted traffic classification model for DApps. CapsuleFormer utilizes capsule neurons instead of traditional scalar neurons, where the neurons within the capsule embody various attributes of particular entities. Furthermore, Transformer blocks are adopted to generate a high-dimensional representation of the capsule activation vector. Thus, CapsuleFormer has the capability to extract potential features from the encrypted traffic patterns of DApps. Moreover, we collect and open a dataset of more than 700,000 encrypted traffic flows from 10 different types of DApps. The results of the experiments on the dataset demonstrate that CapsuleFormer is superior to the current methods, with an accuracy rate of 98.7%.
Xi Xiao 0001, Qing Li 0006, Bin Zhang 0048, Guangwu Hu, Xiapu Luo, Tianwei Zhang 0004
AsiaCCS4
2024 Understanding the Influence of Extremely High-Degree Nodes on Graph Anomaly Detection
Xi Xiao 0001, Guangwu Hu, Xuhui Jiang, Bin Zhang 0048, Hao Li 0027
ICPR (7)6
2024 FRADE: Forgery-aware Audio-distilled Multimodal Learning for Deepfake Detection
abstract
Nowadays, the abuse of AI-generated content (AIGC), especially the facial images known as deepfake, on social networks has raised severe security concerns, which might involve the manipulations of both visual and audio signals. For multimodal deepfake detection, previous methods usually exploit forgery-relevant knowledge to fully finetune Vision transformers (ViTs) and perform cross-modal interaction to expose the audio-visual inconsistencies. However, these approaches may undermine the prior knowledge of pretrained ViTs and ignore the domain gap between different modalities, resulting in unsatisfactory performance. To tackle these challenges, in this paper, we propose a new framework, i.e., Forgery-aware Audio-distilled Multimodal Learning (FRADE), for deepfake detection. In FRADE, the parameters of pretrained ViT are frozen to preserve its prior knowledge, while two well-devised learnable components, i.e., the Adaptive Forgery-aware Injection (AFI) and Audio-distilled Cross-modal Interaction (ACI), are leveraged to adapt forgery relevant knowledge. Specifically, AFI captures high-frequency discriminative features on both audio and visual signals and injects them into ViT via the self-attention layer. Meanwhile, ACI employs a set of latent tokens to distill audio information, which could bridge the domain gap between audio and visual modalities. The ACI is then used to well learn the inherent audio-visual relationships by cross-modal interaction. Extensive experiments demonstrate that the proposed framework could outperform other state-of-the-art multimodal deepfake detection methods under various circumstances.
Fan Nie, Jiangqun Ni, Jian Zhang 0086, Bin Zhang 0048, Weizhe Zhang
ACM Multimedia4
2024 A comprehensive analysis of website fingerprinting defenses on Tor
Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Qixu Liu, Xiapu Luo
Comput. Secur.5
2023 ReviewLocator: Enhance User Review-Based Bug Localization with Bug Reports
Renjie Xiao, Xi Xiao 0001, Le Yu 0002, Bin Zhang 0048, Guangwu Hu, Qing Li 0006
ADMA (5)4
2023 AAP: Defending Against Website Fingerprinting Through Burst Obfuscation
Xi Xiao 0001, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Qixu Liu
ADMA (5)3
2023 Gleaning the Consensus for Linearizable and Conflict-Free Per-Replica Local Reads
abstract
The optimal read strategy for strong consistent key-value applications is to enable the per-replica local reads that each replica has the ability to serve reads locally. Unfortunately, current schemes for the per-replica local reads are perplexed by two issues. First, some schemes have to violate the per-replica local reads when the workload is skewed, degrading the throughput. Second, most of current schemes rely on leases or a specialized hardware to guarantee the linearizability, bringing difficulties to the deployment.
Jian Yi, Qing Li 0006, Bin Zhang 0048, Yong Jiang 0001, Dan Zhao 0003, Yuan Yang 0001, Zhenhui Yuan
APNet3
2023 Follow the Will of the Market: A Context-Informed Drift-Aware Method for Stock Prediction
abstract
The dynamic nature of stock market styles, referred to as concept drift, poses a formidable challenge when applying deep learning to stock prediction. Models trained on historical data often struggle to adapt to the latest market styles, as the patterns they have learned may no longer hold true over time. To alleviate this issue, the recently popularized concept of In-Context learning has provided us with valuable insights. In this approach, large language models (LLMs) are exposed to multiple examples of input-label pairs, also known as demonstrations, as part of the prompt before performing a task on an unseen example. By thoroughly analyzing these demonstrations, LLMs can uncover potential patterns and effectively adapt to new tasks. Building upon this concept, we propose a Context-Informed drift-aware method for Stock Prediction (CISP), which continually adjusts to the latest market styles and offers more accurate predictions. Our proposed method consists of two key parts. Firstly, we introduce a straightforward and efficient technique for designing demonstrations that aggregate current market information, thereby indicating the prevailing stock market style. Secondly, we incorporate a prediction module with dynamic parameters, allowing it to appropriately adjust its model parameters based on the market patterns embedded in the aforementioned demonstrations. Through extensive experiments conducted on real-world stock market datasets, our approach consistently outperforms the most advanced existing methods for stock prediction.
Chen-Hui Song, Xi Xiao 0001, Bin Zhang 0048, Shutao Xia
CIKM3
2023 Phish2vec: A Temporal and Heterogeneous Network Embedding Approach for Detecting Phishing Scams on Ethereum
abstract
The exponential growth of Ethereum transactions has resulted in a significant increase in phishing scams, leading to substantial financial losses in recent years. Current machine/deep learning-based approaches for classification have been found to be inadequate for large-scale and label-imbalanced Ethereum scenarios. To address this issue, we propose Phish2vec, a novel network embedding approach that takes into account the transaction temporality and heterogeneity in detecting phishing scams on Ethereum. Our approach begins by producing a transaction sub-network through data collection and preprocessing, which includes a novel Statistics-Based Sampling (SBS) method to address label leakage. To generate sequences that contain more comprehensive information, we then utilize two different types of sequences generators: Temporal-based Sequences Generator (TSG) and Heterogeneous-based Sequences Generator (HSG). By concatenating the sequences generated by TSG and HSG together, and feeding them into Word2vec and Fully Connected neural network (FC), our approach can identify phishing accounts with an Fl-score as high as 82.05%, which significantly outperforms classic schemes such as DeepWalk (67.29%), Trans2vec (74.78%), and Node2vec (70.91%).
Zhutian Lin, Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qixu Liu, Xiapu Luo
SECON4
2023 Tracking phishing on Ethereum: Transaction network embedding approach for accounts representation learning
Zhutian Lin, Xi Xiao 0001, Guangwu Hu, Qing Li 0006, Bin Zhang 0048, Xiapu Luo
Comput. Secur.5
2023 TCGNN: Packet-grained network traffic classification via Graph Neural Networks
Guangwu Hu, Xi Xiao 0001, Bin Zhang 0048, Xia Yan
Eng. Appl. Artif. Intell.4
2022 Neural Architecture Searching for Facial Attributes-based Depression Recognition
abstract
Recent studies show that depression can be partially reflected from human facial attributes. Since facial attributes have various data structures and carry different information, existing approaches fail to specifically consider the optimal way to extract depression-related features from each of them, as well as investigate the best fusion strategy. In this paper, we propose to extend Neural Architecture Search (NAS) technique to design an optimal model for multiple facial attributes-based depression recognition, which can be efficiently and robustly implemented in a small dataset. Our approach first conducts a warmer up step to the feature extractor of each facial attribute, aiming to largely reduce the search space and provide customized architecture, where each feature extractor can be either a Convolution Neural Networks (CNN) or Graph Neural Networks (GNN). Then, we conduct an end-to-end architecture search for all feature extractors and the fusion network, allowing the complementary depression cues to be optimally combined with less redundancy. The experimental results on AVEC 2016 dataset show that the model explored by our approach achieves breakthrough performance with 27% and 30% RMSE and MAE improvements over the existing state-of-the-art. In light of these findings, this paper provides solid evidence and a strong baseline for applying NAS to time-series data-based mental health analysis.
Mingzhe Chen, Xi Xiao 0001, Bin Zhang 0048, Runiu Lu
ICPR3
2022 Graph Data Augmentation for Node Classification
abstract
In recent years, Graph Neural Networks (GNNs) have emerged as powerful techniques for graph-structure data, which are essential for a wide range of graph-based tasks like link prediction and node classification. However, over-smoothing and over-fitting are two main challenges that impact negatively on model performance. Data augmentation is a good solution to these two problems, and it is also proven very effective in computer vision and nature language processing. But there is a relatively small body of literature when it comes to graph data augmentation. In this paper, we propose a Graph Data Augmentation (GDA) strategy to optimize the graph topology for node classification tasks. Our GDA approach consists of two operations: edge manipulation based on similarities of node pairs (GDA-E) and new nodes addition to under-informed old nodes (GDA-N). GDA-E is designed to add missing edges and remove noisy edges, while GDA-N is established to help nodes with low degree. Both operations can improve the information-to-noise ratio of the whole graph and lead to better performance of GNNs. The comparative results of experiments on three different datasets show that our GDA approach achieves considerable improvement (11.0% average) over origin graphs, and the ablation study verifies the effectiveness of both GDA-E and GDA-N.
Xi Xiao 0001, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Shutao Xia
ICPR3
2022 A Consortium Blockchain-Based Access Control Framework With Dynamic Orderer Node Selection for 5G-Enabled Industrial IoT
abstract
5G-enabled Industrial Internet of Things (IIoT) deployment will bring more severe security and privacy challenges, which puts forward higher requirements for access control. Blockchain-based access control method has become a promising security technology, but it still faces high latency in consensus process and weak adaptability to dynamic changes in network environment. This article proposes a novel access control framework for 5G-enabled IIoT based on consortium blockchain. We design three types of chaincodes for the framework named policy management chaincode (PMC), access control chaincode (ACC), and credit evaluation chaincode (CEC). The PMC and ACC are deployed on the same data channel to implement the management of access control policies and the authorization of access. The CEC deployed on another channel is used to add behavior records collected from IIoT devices and calculate the credit value of IIoT domain. Specifically, we design a two-step credit-based Raft consensus mechanism, which can select the orderer nodes dynamically to achieve fast and reliable consensus based on historical behavior records stored in the ledger. Furthermore, we implement the proposed framework on a real-world testbed and compare it with the framework based on practical Byzantine fault tolerance consensus. The experiment results show that our proposed framework can maintain lower consensus cost time with 100 ms level and achieves four to five times throughput with lower hardware resource consumption and communication consumption. Besides, our design also improves the security and robustness of the access control process.
Yuming Feng 0002, Weizhe Zhang, Xiapu Luo, Bin Zhang 0048
IEEE Trans. Ind. Informatics4
2021 Short and Distort Manipulations in the Cryptocurrency Market: Case Study, Patterns and Detection
Xi Xiao 0001, Wentao Xiao, Bin Zhang 0048, Guangwu Hu
ICA3PP (3)4
2021 A Novel and High-Accuracy Rumor Detection Approach using Kernel Subtree and Deep Learning Networks
abstract
Rumor detection is a task of identifying information that spread among people whose truth value is false or unverified, and it has been a great challenge due to the rapid development of social media. The traditional machine learning based detection methods can make full use of informative features but cannot extract high-level representations. Other methods involved deep learning neural networks exploit propagation structural information to achieve high accuracy, for example, Bi-Directional Graph Convolution Networks(BiGCN) achieved the best performance on rumor detection by operating on bottom-up and top-down structures. However, those deep learning methods ignore other useful features like content-based features. In this paper, we not only make full use of three aspects of features based on a new concept: kernel subtree, which focus more on informative features of influential nodes of an event, but also propose a new model, which consists of Separation Convolution blocks, Long Short Term Memory(LSTM) and Squeeze and Excitation Networks(SENet), to make comprehensive use of features extracted on the basis of kernel subtree. First, we utilize Separation Convolutions to learn more local information with different kernel size, then LSTM can learn high-level interactions among features and find more global information. After that, SENet applies attention mechanism to put more weights on informative channels of feature maps. Meanwhile, on test set, Gradient Boosting Decision Tree(GBDT) is used to assist our model with few events. The experiments on the PHEME dataset show that our approach can identify rumors with accuracy 95% which outperforms BiGCN by 10% at least.
Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qing Li 0006, Shutao Xia
IJCNN4
2021 Byte-Label Joint Attention Learning for Packet-grained Network Traffic Classification
abstract
Network traffic classification (TC) is to classify network traffic into a specific class which plays a fundamental role in terms of network measurement, network management, and so on. In this work, we focus on packet-grained traffic classification. We find that previous packet-grained methods based on the analogy between traffic packet and image or text are not sufficiently reasonable, leading to a sub-optimal performance on both accuracy and efficiency that still can be largely improved. In this paper, we devise a new method, called BLJAN, to jointly learn from byte sequence and labels for packet-grained traffic classification. BLJAN embeds the packet’s bytes and all labels into a joint embedding space to capture their implicit correlations with a dual attention mechanism. It finally builds a more powerful packet representation with an enhancement from label embeddings to achieve high classification accuracy and interpretability. Extensive experiments on two benchmark traffic classification tasks, including application identification and traffic characterization, with three real-world datasets, demonstrate that BLJAN can achieve high performance (96.2%, 96.7%, and 99.7% Macro F1-scores on three datasets) for packet-grained traffic classification, outperforming six representative state-of-the-art baselines in terms of both accuracy and detection speed.
Kelong Mao, Xi Xiao 0001, Guangwu Hu, Xiapu Luo, Bin Zhang 0048, Shutao Xia
IWQoS5
2021 Phishing websites detection via CNN and multi-head self-attention on imbalanced datasets
Xi Xiao 0001, Wentao Xiao, Dianyan Zhang, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Shutao Xia
Comput. Secur.4
2021 ALBFL: A novel neural ranking model for software fault localization via combining static and dynamic features
Xi Xiao 0001, Yuqing Pan, Bin Zhang 0048, Guangwu Hu, Qing Li 0006, Runiu Lu
Inf. Softw. Technol.3
2021 CL-ADMM: A Cooperative-Learning-Based Optimization Framework for Resource Management in MEC
abstract
We consider the problem of the intelligent and efficient resource management framework in mobile-edge computing (MEC), which can reduce delay and energy consumption, and features distributed optimization and efficient congestion avoidance. In this article, we present a cooperative learning framework for resource management in MEC from an alternating direction method of multipliers (ADMMs) perspective, named the CL-ADMM framework. First, computing a task requires both the user personal data and corresponding program that processes it, to efficiently cache program in a group, a novel program popularity estimation scheme is proposed, which is based on a semi-Markov process model. Then, a greedy program cooperative caching mechanism is established, which can effectively reduce delay and energy consumption. Second, to address group congestion, a dynamic task migration scheme based on improved cooperative Q-learning is proposed, which can effectively reduce delay and alleviate congestion. Third, to minimize delay and energy consumption for resource allocation in a group, we formulate it as an optimization problem with a large number of variables, and then exploit a novel ADMM-based scheme to solve this problem, which can reduce the complexity of the problem with a new set of auxiliary variables, these subproblems are all convex problems that can be solved by using a primal-dual approach, which guarantees its convergence. Finally, we prove its convergence by using the Lyapunov theory. The numerical results demonstrate the effectiveness of the CL-ADMM framework in reducing delay and energy consumption in MEC.
Xiaoxiong Zhong, Xinghan Wang 0001, Li Li 0015, Yuanyuan Yang 0001, Yang Qin 0001, Tingting Yang 0001, Bin Zhang 0048, Weizhe Zhang
IEEE Internet Things J.7
2020 Maintaining Discrimination and Fairness in Class Incremental Learning
abstract
Deep neural networks (DNNs) have been applied in class incremental learning, which aims to solve common real-world problems of learning new classes continually. One drawback of standard DNNs is that they are prone to catastrophic forgetting. Knowledge distillation (KD) is a commonly used technique to alleviate this problem. In this paper, we demonstrate it can indeed help the model to output more discriminative results within old classes. However, it cannot alleviate the problem that the model tends to classify objects into new classes, causing the positive effect of KD to be hidden and limited. We observed that an important factor causing catastrophic forgetting is that the weights in the last fully connected (FC) layer are highly biased in class incremental learning. In this paper, we propose a simple and effective solution motivated by the aforementioned observations to address catastrophic forgetting. Firstly, we utilize KD to maintain the discrimination within old classes. Then, to further maintain the fairness between old classes and new classes, we propose Weight Aligning (WA) that corrects the biased weights in the FC layer after normal training process. Unlike previous work, WA does not require any extra parameters or a validation set in advance, as it utilizes the information provided by the biased weights themselves. The proposed method is evaluated on ImageNet-1000, ImageNet-100, and CIFAR-100 under various settings. Experimental results show that the proposed method can effectively alleviate catastrophic forgetting and significantly outperform state-of-the-art methods.
Bowen Zhao 0003, Xi Xiao 0001, Guojun Gan, Bin Zhang 0048, Shutao Xia
CVPR4
2020 Self-Paced Probabilistic Principal Component Analysis For Data With Outliers
abstract
Principal Component Analysis (PCA) is a popular tool for dimension reduction and feature extraction in data analysis. Probabilistic PCA (PPCA) extends the standard PCA by using a probabilistic model. However, both standard PCA and PPCA are not robust, as they are sensitive to outliers. To alleviate this problem, we propose a novel method called Self-Paced Probabilistic Principal Component Analysis (SP-PPCA) by introducing the Self-Paced Learning mechanism into PPCA. Furthermore, we design the corresponding optimization algorithm based on an alternative search strategy and an expectation-maximization algorithm, so that SP-PPCA uses an iterative procedure to find the optimal projection vectors and filter out outliers. Experiments on both synthetic data and real data demonstrate that SP-PPCA is more robust than the baselines.
Bowen Zhao 0003, Xi Xiao 0001, Wanpeng Zhang 0002, Bin Zhang 0048, Guojun Gan, Shutao Xia
ICASSP4
2020 Malware Classification Method Based on Word Vector of Bytes and Multilayer Perception
abstract
The traditional machine learning-based malware classification methods are mainly based on feature engineering. In order to improve accuracy, many features will be extracted from malware files in these methods. That brings a high complexity to the classification. To solve this issue, this paper proposes a malware classification method based on the word vector of bytes in the malware sample and Multilayer Perception (MLP). A malware sample consists of large number of bytes with values ranging from 0x00 to 0xFF. Therefore, every malware sample could be considered as a document written by bytes. And this document could be divided into sentences based on padding or meaningless bytes. In this paper, first, we use Word2Vec to calculate a 256 dimensions word vector for each byte. Second, we combine them into a matrix in ascending order. Third, we use MLP to train the model on the training samples. Finally, we use the trained model to classify the testing samples. The experimental results show that the method has a high accuracy of 98.89%.
Yanchen Qiao, Bin Zhang 0048, Weizhe Zhang
ICC2
2020 SpeedNeuzz: Speed Up Neural Program Approximation with Neighbor Edge Knowledge
abstract
Fuzzing has been a great success in discovering real-world complex programs vulnerabilities. However, fuzzing achieves this effect by blindly generating a large number of test cases, which undoubtedly contains a lot of meaningless mutation inputs. To solve the blindness, machine learning technology is applied to fuzzing in recent work. Some of the machine learning based methods focus on locating and mutating the key bytes in the input, but they do not pay attention to the characteristics in the field of fuzzing when they combine machine learning technology with fuzzing. In this paper, we implement a new fuzzer, called Speed-Neuzz, which uses neural networks to model the branch behaviours of the program based on accurate training data after mitigating the hash collision of AFL. Furthermore, SpeedNeuzz locates and mutates critical bytes in the program input with a gradient-based strategy as well as neighbor edge information. Taking the neighbor edge knowledge into account, we can further reduce the blindness of the mutation based on gradient information so that SpeedNeuzz can generate a large number of quality inputs. Experiments on several real-world programs prove that SpeedNeuzz can achieve higher edge coverage than the state-of-the-art fuzzer NEUZZ under the same time budget.
Xi Xiao 0001, Xiaogang Zhu 0001, Xiao Chen 0002, Sheng Wen, Bin Zhang 0048
TrustCom6
2020 ALBFL: A Novel Neural Ranking Model for Software Fault Localization via Combining Static and Dynamic Features
abstract
Automatic fault localization plays a significant role in assisting developers to fix software bugs efficiently. Although existing approaches, e.g., static methods and dynamic ones, have greatly alleviated this problem by analyzing static features in source code and diagnosing dynamic behaviors in software running state respectively, the fault localization accuracy still does not meet user requirements. To improve the fault locating ability with statement granularity, this paper proposes ALBFL, a novel neural ranking model that involves the attention mechanism and the LambdaRank model, which can integrate the static and dynamic features and achieve very high accuracy for identifying software faults. ALBFL first introduces a transformer encoder to learn the semantic features from software source code. Also, it leverages other static statistical features and dynamic features, i.e., eleven Spectrum-Based Fault Localization (SBFL) features, three mutation features, to evaluate software together. Specially, the two types of features are integrated through a self-attention layer, and fed into the LambdaRank model so as to rank a list of possible fault statements. Finally, thorough experiments are conducted on 5 open-source projects with 357 faulty programs in Defects4J. The results show that ALBFL outperforms 11 traditional SBFL methods (by three times) and 2 state-of-the-art approaches (by 13%) on ranking faulty statements in the first position.
Yuqing Pan, Xi Xiao 0001, Guangwu Hu, Bin Zhang 0048, Qing Li 0006, Hai-Tao Zheng 0002
TrustCom4
2020 Ransomware classification using patch-based CNN and self-attention network on embedded N-grams of opcodes
Bin Zhang 0048, Wentao Xiao, Xi Xiao 0001, Arun Kumar Sangaiah, Weizhe Zhang, Jiajia Zhang 0001
Future Gener. Comput. Syst.1
2020 An IoT Honeynet Based on Multiport Honeypots for Capturing IoT Attacks
abstract
Internet of Things (IoT) devices are vulnerable against attacks because of their limited network resources and complex operating systems. Thus, a honeypot is a good method of capturing malicious requests and collecting malicious samples but is rarely used on the IoT. Accordingly, this article implements three kinds of honeypots to capture malicious behaviors. First, on the basis of the CVE-2017–17215 vulnerability, we implement a medium-high interaction honeypot that can simulate a specific series of router UPnP services. It has functions, such as service simulation, log recording, malicious sample download, and service self-check. Second, given the limited details available for the simulated UPnP service and to help the honeypot respond to unrecognizable malicious requests, we use the actual IoT device firmware that matches the vulnerability to build a high-interaction honeypot. In addition, we investigate the most exposed SOAP service ports and design corresponding multiport honeypot to improve the capacity of the honeynet, providing a hybrid service from a real device and simulating honeypots. The Docker in the honeynet, which reduces the volume of the honeypot and realizes the rapid deployment of the honeynet, encapsulates all these honeypots. Moreover, the honeynet control center is simultaneously designed to distribute commands and transfer files to each physical node in the honeynet. We implemented the proposed honeynet system and deployed it in practice. We have successfully caught many unknown malicious attacks excluded in the VT, which proved the effectiveness of the proposed framework.
Weizhe Zhang, Bin Zhang 0048, Zeyu Ding 0003
IEEE Internet Things J.2
2020 OODT: Obstacle Aware Opportunistic Data Transmission for Cognitive Radio Ad Hoc Networks
abstract
In recent years, a large number of smart devices will be connected in Internet of Things (IoT) using an ad hoc network, which needs more frequency spectra. The cognitive radio (CR) technology can improve spectrum utilization in an opportunistic communication manner for IoT, forming a promising paradigm known as cognitive radio ad hoc networks, CRAHNs. However, dynamic spectrum availability and mobile devices/persons make it difficult to develop an efficient data transmission scheme for CRAHNs under an obstacle environment. Opportunistic routing can leverage the broadcast nature of wireless channels to enhance network performance. Inspired by this, in this paper, we propose an Obstacle aware Opportunistic Data Transmission scheme (OODT) in CRAHNs from a computational geometry perspective, considering energy efficiency and social features. In the proposed scheme, we exploit a new routing metric, which is based on an obstacle avoiding algorithm using a polygon boundary 1-searcher technology, and an auction model for selecting forwarding candidates. In addition, we prove that the candidate selection problem is NP-hard and propose a heuristic algorithm for candidate selection. The simulation results show that the proposed scheme can achieve better performance than existing schemes.
Xiaoxiong Zhong, Li Li 0015, Yuanping Zhang, Bin Zhang 0048, Weizhe Zhang, Tingting Yang 0001
IEEE Trans. Commun.4