Peng Wu 0036

dblp:15/6146-36 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0002-2414-2578ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 RTsFCM: a robust two-stage flow correlation method for traffic tracking in anonymous communication
abstract
Abstract Anonymous communication serves as the preferred tool for cyber attackers to evade detection, posing a serious threat to cyberspace security. Accurately tracking the attackers in anonymous communication is crucial for defending against attacks. Flow correlation is an effective method that can link flows in the anonymous network. Existing flow correlation methods usually rely on a long observation, resulting in reduced correlation precision and limited generalization ability within anonymous communication. To address this issue, we propose a robust two-stage flow correlation method called RTsFCM via Siamese network and ensemble voting scheme. In the first stage, a Siamese network with shared weights is utilized to automatically extract the multilevel features from ingress flow and egress flow, respectively. Further, they are concatenated to generate a more expressive feature set to enhance true positive rate (TPR). In the second stage, flow pairs are firstly divided into a series of partially overlapping sub-flows(windows) in view of flow duration. Then, pairwise comparison for each window is conducted independently and the ensemble voting scheme is adopted across these windows to reduce the false positive rate (FPR) significantly. Experimental results show that RTsFCM is superior to the state of the art, achieving over a 4% increase in both TPR and F1_score. Simultaneously, it obtains an FPR as low as 0.68%, utilizing the packet timing characteristics within the initial portion of a flow.
Xiaolan Zhu, Junfeng Wang 0003, Zihua Song, Peng Wu 0036
Comput. J.4
2025 Enhancing vulnerability repair through the extraction and matching of repair patterns
Xiansheng Cao, Junfeng Wang 0003, Peng Wu 0036
J. Syst. Softw.3
2024 VulMPFF: A Vulnerability Detection Method for Fusing Code Features in Multiple Perspectives
abstract
Source code vulnerabilities are one of the significant threats to software security. Existing deep learning‐based detection methods have proven their effectiveness. However, most of them extract code information on a single intermediate representation of code (IRC), which often fails to extract multiple information hidden in the code fully, significantly limiting their performance. To address this problem, we propose VulMPFF, a vulnerability detection method that fuses code features under multiple perspectives. It extracts IRC from three perspectives: code sequence, lexical and syntactic relations, and graph structure to capture the vulnerability information in the code, which effectively realizes the complementary information of multiple IRCs and improves vulnerability detection performance. Specifically, VulMPFF extracts serialized abstract syntax tree as IRC from code sequence, lexical and syntactic relation perspective, and code property graph as IRC from graph structure perspective, and uses Bi‐LSTM model with attention mechanism and graph neural network with attention mechanism to learn the code features from multiple perspectives and fuse them to detect the vulnerabilities in the code, respectively. We design a dual‐attention mechanism to highlight critical code information for vulnerability triggering and better accomplish the vulnerability detection task. We evaluate our approach on three datasets. Experiments show that VulMPFF outperforms existing state‐of‐the‐art vulnerability detection methods (i.e., Rats, FlawFinder, VulDeePecker, SySeVR, Devign, and Reveal) in Acc and F1 score, with improvements ranging from 14.71% to 145.78% and 152.08% to 344.77%, respectively. Meanwhile, experiments in the open‐source project demonstrate that VulMPFF has the potential to detect vulnerabilities in real‐world environments.
Xiansheng Cao, Junfeng Wang 0003, Peng Wu 0036, Zhiyang Fang
IET Inf. Secur.3
2022 Enhancing software modularization via semantic outliers filtration and label propagation
Kaiyuan Yang 0004, Junfeng Wang 0003, Zhiyang Fang, Peng Wu 0036, Zihua Song
Inf. Softw. Technol.4
2022 IoT Malware Classification Based on Lightweight Convolutional Neural Networks
abstract
Internet of Things (IoT) is hard to deploy adequate security defenses due to the diversity of architectures as well as the limited computing and storage capabilities, which makes it more vulnerable to malware. With the massive deployment of IoT devices, how to accurately identify and classify the malware variants is crucial to IoT security. However, existing methods of IoT malware classification generally support specific platform or require complex models to achieve higher accuracies. To solve these problems, this article proposes an IoT malware classification method based on lightweight convolutional neural networks (LCNNs). First, the malware binaries are converted into multidimensional Markov images. Then, the LCNN is designed with two new operations, depthwise convolution and channel shuffle, for malware images classification. Compared with other deep learning-based methods such as VGG16, the designed LCNN can greatly reduce trainable parameters while maintaining accuracy. The generated model of LCNN is only about 1 MB, while that of VGG16 is 552.57 MB. The average accuracies of the proposed method are higher than that of gray images on multiple IoT malware data sets, all of which are over 95%. Compared with the state-of-the-art low-level features-based methods, the average accuracy of the proposed method is 99.356% on the Microsoft data set even if the model is tiny. The results show that the proposed method is not only suitable for IoT environments but also has high accuracy.
Baoguo Yuan, Junfeng Wang 0003, Peng Wu 0036, Xianguo Qing
IEEE Internet Things J.3
2020 Byte-level malware classification based on markov images and deep learning
Baoguo Yuan, Junfeng Wang 0003, Peng Wu 0036, Xuhua Bao
Comput. Secur.5
2020 Detection of Fake IoT App Based on Multidimensional Similarity
abstract
With low cost and high profit, fake IoT apps are an increasing risk to the security of the IoT ecosystem. In this article, we propose a novel fake IoT app detection method, referred as MSimDroid, based on multidimensional similarity to mitigate the threat. MSimDroid focuses on the distribution channels of fake apps, that is, app markets, and it consists of whole app similarity, resource similarity, code similarity, and their joint strategy. For similarity calculation, we design a distinctive algorithm based on the feature of different fake patterns. For joint strategy, which is the scheduler of multiple algorithms, it balances the accuracy and time consuming of MSimDroid. Experiments demonstrate that the accuracy of MSimDroid is more than 99.31% on ground-truth data set and 97.43% in the wild. The IoT apps from multiple well-known app markets reveal that the average proportion of fake apps is about 14.66%, and that of mixed-mode apps (including IoT and nonIoT apps) is 10.78%. Besides, it finds that about 0.58% of IoT apps suffer from malice, while the average ratio of mixed-mode apps is 1.06%.
Peng Wu 0036, Junfeng Wang 0003, Baoguo Yuan, Wenyuan Kuang
IEEE Internet Things J.1