VLDB 2026 Research / reviewers in the wild / expert
Fangjiao Zhang
dblp:153/5781
· DBLP profile ↗
8ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0005-5720-8253ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language ModelabstractAPIs are now central to digital transformation, carrying the core business logic and sensitive data of enterprises. Attackers can gain access to important information systems and sensitive data by attacking APIs, allowing them to steal high-value data. Besides being vulnerable to traditional attacks, APIs also face unique threats tailored to their characteristics, such as attacks targeting API business logic threats. This type of API attacks are complex, and the attack requests are very similar to legitimate traffic, making them difficult to distinguish from benign requests. Therefore, traditional single-request detection methods are ineffective against such complex attacks. By employing intelligent context-aware natural language processing techniques, we can understand API call behavior and establish a baseline of normal API call behavior to identify anomalies. In this paper, we propose DAB-LLM, a model for Detecting Anomalies in API call Behavior based on Large Language Model. Our approach utilizes extraction and representation methods for API call chains and API call graphs, prompt optimization algorithm, and LoRA fine-tuning technique to enable the model to deeply understand of API call behavior and enhance detection capabilities. Experimental results indicate that DAB-LLM excels in detecting attack behaviors and anomalies in API calls, achieving an f1-score of 97.35% along with significant improvements in recall rate, accuracy and precision. The overall performance of the model shows that our proposed model significantly outperforms other models in API call behavior anomaly detection. Fangjiao Zhang, Baihang Liu, Baoxu Liu, Qixu Liu |
CSCWD | 2 |
| 2025 | Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integrationabstractAbstract As cloud-native technologies continue to evolve, containerization and orchestration have become fundamental for deploying microservices. However, this advancement introduces significant security vulnerabilities, particularly due to vulnerabilities and misconfigurations that grant attackers excessive control over clusters. Existing works, including model-based learning and static rule-based approaches, suffer from limitations such as false positives and maintenance overhead, which pose significant challenges to cloud-native security. To mitigate intrusion targeting container orchestration, we present ShadowKube, an innovative active defense framework tailored for Kubernetes. ShadowKube integrates behavioral monitoring with shadow honeypots to effectively detect and neutralize anomalous behavior. By establishing behavioral baselines to identify deviations and converting compromised nodes into honeypots, ShadowKube isolates and traps attackers, thereby mitigating the threats they pose. Comprehensive evaluations demonstrate ShadowKube’s ability to detect and migrate exploitations across 43 severe CVEs and 7 common misconfiguration types. Deployment in a live environment further validates its effectiveness, with ShadowKube identifying 635 attack attempts, successfully decoying 23 active attacks. Additionally, ShadowKube could isolate attackers and convert affected nodes into honeypots within seconds. These results highlight ShadowKube’s efficacy as a robust solution for enhancing security in Kubernetes clusters, offering a proactive defense mechanism against both current and emerging threats. Qingwang Chen, Ru Tan, Ze Jin, Juxin Xiao, Fangjiao Zhang, Qixu Liu |
Cybersecur. | 7 |
| 2025 | EVFeX: An efficient vertical federated XGBoost algorithm based on optimized secure matrix multiplication
Fangjiao Zhang, Chang Cui, Qingshu Meng |
Signal Process. | 1 |
| 2024 | TAD-LLM: API Traffic Anomaly Detection Based on Large Language ModelabstractAPIs are increasingly prevalent in application environments, carrying the core business logic and sensitive data of enterprises, and have increasingly become the target of cyber attackers. The proportion of web attacks targeting APIs has exceeded half. The widespread use of APIs has expanded the attack surface, posing serious security challenges. Security risks, such as unauthorized access, misuse of business logic, data breaches, and complex cyber attacks, have intensified. Tr aditional security measures have proven inadequate in addressing API threats. There is an urgent demand for a more contextually aware and intelligent security mechanism capable of effectively mitigating API attacks. We proposed a novel model TAD-LLM based on Large Language Model for anomaly detection in API traffic. By using S2GS data transformation method, prompt optimization algorithm and LoRA fine-tuning technique, enables the model to acquire a profound comprehension of domain-specific knowledge in more elaborate detail, thereby enhancing the overall detection capability. Experimental results demonstrate that the proposed model TAD-LLM makes a significant advancement in securing APIs against cyber threats. The average f1-score of TAD-LLM reaches 99.27% in complex API attack scenarios. There are also notable improvements in precision, recall, and accuracy. Moreover, the overall performance of the model indicates that the model we proposed outperforms other models significantly and exhibits superior capability in handling complex API attack scenarios and advanced API attack techniques. It is worth noting that our model also shows strong performance on CSIC 2010, a widely used common http traffic dataset. Baoxu Liu, Jingqiang Liu, Fangjiao Zhang, Qixu Liu |
MSN | 4 |
| 2024 | Dissecting zero trust: research landscape and its implementation in IoTabstractAbstract As a progressive security strategy, the zero trust model has attracted notable attention and importance within the realm of network security, especially in the context of the Internet of Things (IoT). This paper aims to evaluate the current research regarding zero trust and to highlight its practical applications in the IoT sphere through extensive bibliometric analysis. We also delve into the vulnerabilities of IoT and explore the potential role of zero trust security in mitigating these risks via a thorough review of relevant security schemes. Nevertheless, the challenges associated with implementing zero trust security are acknowledged. We provide a summary of these issues and suggest possible pathways for future research aimed at overcoming these challenges. Ultimately, this study aims to serve as a strategic analysis of the zero trust model, intending to empower scholars in the field to pursue deeper and more focused research in the future. Chunwen Liu, Ru Tan, Yun Feng 0003, Ze Jin, Fangjiao Zhang, Qixu Liu |
Cybersecur. | 6 |
| 2023 | Secure vertical federated learning based on feature disentanglementabstractFederated learning (FL) faces many security threats. Although multiple robust FL frameworks have been proposed to defend against these malicious attacks in horizontal federated learning (HFL), security issues in vertical federated learning (VFL) have not been adequately studied. Recent studies show that VFL is vulnerable to inference attacks (e.g., label inference attacks), which puts VFL at risk. To solve this problem, we propose a new VFL framework SVFL (Secure Vertical Federated Learning) to defend against privacy breaches inspired by feature disentanglement. Specifically, in SVFL , the bottom models are feature extractors to extract samples’ features in the high-dimensional space, and the top model sews samples’ features of the same sample ID. Then, disentangling the samples’ features into the class-relevant feature and class-irrelevant one via two classifiers: one is to recognize the class-relevant feature by regular training, and another is to recognize the class-irrelevant feature by adversarial training . Our experiments show that SVFL not only defends against label inference attacks, no matter how many samples features a malicious participant occupies, but also improves the global model’s accuracy. Therefore, SVFL provides a privacy security guarantee for the vertical federated learning system . Fangjiao Zhang, Zhufeng Suo, Chang Cui, Qingshu Meng |
Signal Process. | 1 |
| 2018 | Study on Advanced Botnet Based on Publicly Available Resources
Heyang Lv, Fangjiao Zhang, Zhihong Tian, Xiang Cui |
ICICS | 3 |
| 2014 | POSTER: Abusing URL Shortening Services for Stealthy and Resilient Message TransmittingabstractURL shortening services (USS) have been widely used on the Internet, but are currently prone to abuse. In this poster, we exploit the possibility of building a novel stealthy and robust message transmission channel through use of USS. A text string or binary file can be transmitted stealthily using this channel. Our preliminary results show that the proposed channel is feasible and affects many popular USS, thus posing a practical threat to attackers. Fangjiao Zhang, Chaoge Liu |
CCS | 2 |