Jiangyong Shi

dblp:137/5290 · DBLP profile ↗
← Back
11ranked-venue papers
1as first author
8since 2021 · last 2025
0009-0002-2754-3681ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 SemiAF: Semi-Supervised App Fingerprinting on Unknown Traffic via Graph Neural Network
abstract
Application Fingerprinting (AF) enables the identification of applications via traffic analysis, aiding network administrators in comprehending user behavior. However, a large volume of unknown traffic in real network environments poses significant challenges for AF methods in both differentiating unknown traffic and characterizing unknown apps. To address these challenges, we introduce a Semi-Supervised App Fingerprinting (SemiAF) deep learning framework. Specifically, to tackle the unknown traffic differentiating challenge, a semi-supervised contrastive learning method is employed to differentiate and cluster unknown applications. To characterize the features of unknown apps, we present a novel In-Flow Burst Interaction (IFBI) graph where each node represents a fine-grained action. By decomposing the unknown app traffic into combinations of these fine-grained actions, a deeper understanding of the network patterns can be achieved. Furthermore, we introduce an explainable neural network framework, revealing the network traffic interactions and inherent relationships. Extensive experimental results in three scenarios demonstrate that SemiAF outperforms state-of-the-art methods in unknown application recognition.
Xiaodong Lei, Jiangyong Shi, Luming Yang
DSN5
2025 ANODYNE: Mitigating backdoor attacks in federated learning
Zhipin Gu, Jiangyong Shi, Yuexiang Yang
Expert Syst. Appl.2
2025 Robustness Matters: Pre-Training Can Enhance the Performance of Encrypted Traffic Analysis
abstract
Models with large-scale parameters and pre-training have been leveraged for encrypted traffic analysis. However, existing researches primarily focused on accuracy, often overlooking the role of large-scale pre-trained parameters in enhancing robustness. While machine learning (ML) and deep learning (DL) models trained from scratch can achieve high accuracy, they exhibit limited robustness. When subjected to network noise in real-world, their identification results can fluctuate significantly, which is unacceptable. Unfortunately, current robustness evaluation methods neglect samples diversity and employ unreasonable noise settings. This field still lacks a reasonable quantitative description of models robustness. In this paper, we propose the PA-curve to display the distribution of sample’s correct-decision stability, which can simultaneously reflect the model’s accuracy and robustness. By calculating the area under the PA-curve, called PA-area, we enable the quantitative assessment of robustness for encrypted traffic analysis. Furthermore, we design a pre-trained model based on packet length sequence, and pre-trained it on TB-scale traffic. By fine-tuning on limited labeled training data, it can achieve downstream analysis tasks. We conduct experiments on five encrypted traffic datasets with different tasks. Besides accuracy, we analyzed the robustness of the pre-trained model and existing methods under common network disturbances, including packet loss, retransmission, and disorder. Experimental results demonstrated that, compared to ML-based and DL-based models trained from scratch, the pre-trained model can not only achieve high accuracy, but also exhibit greater resilience to network noise. The source code is available at https://anonymous.4open.science/r/BERT-ps-4630.
Luming Yang, Lin Liu 0018, Junjie Huang 0001, Jiangyong Shi, Shaojing Fu, Jinshu Su
IEEE Trans. Inf. Forensics Secur.4
2025 unFlowS: An Unsupervised Construction Scheme of Flow Spectrum for Network Traffic Detection
abstract
In recent years, the construction of behavior-based analysis models is hindered by issues such as insufficient data, difficulty in labeling, and the complexity of behavior types. In reality, specific cyber threats often require manual analysis of raw network traffic, which is a complex and inefficient process. Flow spectrum can simplify the complex analysis process of raw network flow by mapping it from a high-dimensional space to a one-dimensional spectral space. However, the existing flow spectrum cannot adapt to the open-world scenarios and behavior-based detection for unknown cyber threats. To address these challenges, we propose a new flow spectrum construction scheme, named unFlowS, to effectively represent network flows and assist analysts to understand the behaviors of network traffic. unFlowS-Net, an unsupervised flow-based detection model we designed as the core of our scheme, can transform network flows into spectral lines. It makes unFlowS possible to detect unknown cyber threats. We further build spectral vectors for spectral lines generated by network flow sets, enabling the visualization of network behaviors within a period of time and automatic behavior-based detection. Experimental results demonstrated that unFlowS-Net can achieve better performance than state-of-the-art methods on unsupervised flow-based detection. Based on spectral vectors, not only can it intuitively display the network behavior characteristic of the target host, but also automatically detect suspicious network behaviors.
Luming Yang, Lin Liu 0018, Junjie Huang 0001, Jiangyong Shi, Shaojing Fu, Shize Guo
IEEE Trans. Inf. Forensics Secur.5
2024 Speedy Privacy-Preserving Skyline Queries on Outsourced Data
Yu Chen 0113, Lin Liu 0018, Rongmao Chen, Shaojing Fu, Yuexiang Yang, Jiangyong Shi, Liangzhong He
ESORICS (2)6
2023 Defending against Poisoning Attacks in Federated Learning from a Spatial-temporal Perspective
abstract
In federated learning, the central server aggregates local model updates from the participants in the network to generate a global model. For the purpose of protecting clients' privacy, the server is designed to have no visibility into how these updates are generated. The nature of federated learning makes detecting and defending against malicious model up-dates a challenging task. Unlike existing works that struggle to defend against poisoning attacks from a spatial perspective, the paper considers mitigating the impact of attacks from a spatial-temporal perspective. This paper proposes Fedmvae, a robust federated learning framework. Fedmvae uses multiple variational autoencoder models to detect and exclude malicious model updates from a spatial perspective. Moreover, to handle poisoning attacks with time-varying features, we propose generating a robust global model update according to momentum-based update speculation and historical global updates. Fedmvae is tested with extensive experiments on both IID and non-IID datasets, showing a competitive performance over existing aggregation methods under both Byzantine attacks and backdoor attacks.
Zhipin Gu, Jiangyong Shi, Yuexiang Yang, Liangzhong He
SRDS2
2023 Defending against Adversarial Attacks in Federated Learning on Metric Learning Model
abstract
The industry has widely deployed federated learning (FL) due to its promise to protect clients’ privacy. However, FL is vulnerable to adversarial attacks when the participants are compromised. The defense against adversarial attacks is a challenging problem in FL. Moreover, existing defense methods optimize the dimensionality reduction and anomaly detection models separately, leading to a disappointing projection space and low detection accuracy. We propose a deep metric learning-based anomaly detection to project the model gradients into a metric space where the malicious gradients are separated from benign ones. Meanwhile, while existing methods require an auxiliary dataset to train the defense model, the auxiliary dataset is usually unavailable to the server in the FL setting. We propose a self-supervised method to distill the data between the training epochs of our defense model. To handle radical changes in malicious model gradients, we utilize a median-based aggregated gradient filter to discard improper aggregated gradients. We show experimentally that our algorithm has a competitive performance over existing methods under Byzantine attacks and backdoor attacks with various triggers.
Zhipin Gu, Jiangyong Shi, Yuexiang Yang, Liangzhong He
TrustCom2
2021 One-pass Multi-view Clustering for Large-scale Data
abstract
Existing non-negative matrix factorization based multi-view clustering algorithms compute multiple coefficient matrices respect to different data views, and learn a common consensus concurrently. The final partition is always obtained from the consensus with classical clustering techniques, such as k-means. However, the non-negativity constraint prevents from obtaining a more discriminative embedding. Meanwhile, this two-step procedure fails to unify multi-view matrix factorization with partition generation closely, resulting in unpromising performance. Therefore, we propose an one-pass multi-view clustering algorithm by removing the non-negativity constraint and jointly optimize the aforementioned two steps. In this way, the generated partition can guide multi-view matrix factorization to produce more purposive coefficient matrix which, as a feedback, improves the quality of partition. To solve the resultant optimization problem, we design an alternate strategy which is guaranteed to be convergent theoretically. Moreover, the proposed algorithm is free of parameter and of linear complexity, making it practical in applications. In addition, the proposed algorithm is compared with recent advances in literature on benchmarks, demonstrating its effectiveness, superiority and efficiency.
Jiyuan Liu 0003, Xinwang Liu 0002, Yuexiang Yang, Li Liu 0002, Siqi Wang 0001, Weixuan Liang, Jiangyong Shi
ICCV7
2020 Markov Probability Fingerprints: A Method for Identifying Encrypted Video Traffic
abstract
Detecting illegal video plays an important role in preventing and countering crime in daily life. It is effective for supervisors to monitor the network by analyzing traffic from devices. In this way, illegal video can be detected when it is played on the network. Most Internet traffic is encrypted, which brings difficulties to traffic analysis. However, many researches suggest that even if the video traffic is encrypted, the segmentation prescribed by Dynamic Adaptive Streaming over HTTP (DASH) causes content-dependent fragments, which can be used to identify the encrypted video traffic without decryption. This paper presents Markov probability fingerprint for video, and then designs an algorithm for encrypted video streaming title identification. We demonstrate that an external attacker can identify the video title by analyzing the fragment sequence of encrypted video traffic. Based on the m-order Markov chain, we use the transition tensor of the fragment sequence generated by the video traffic as the video fingerprint, and prove its effectiveness. Then we explore approaches that can further improve the performance of methods in terms of discrimination accuracy. We make promising observations that the higher-order Markov chain, larger training set, and more detailed binning of fragments contribute to encrypted video traffic discrimination. We run a thorough set of experiments that illustrate that our method can achieve an outstanding accuracy rate up to 97.5%, which is superior to previous work.
Luming Yang, Shaojing Fu, Yuchuan Luo, Jiangyong Shi
MSN4
2016 Architecture Support for Controllable VMI on Untrusted Cloud
Jiangyong Shi, Yuexiang Yang
SecureComm1
2013 Time-Stealer: A Stealthy Threat for Virtualization Scheduler and Its Countermeasures
Hong Rong, Ming Xian, Huimei Wang, Jiangyong Shi
ICICS4