VLDB 2026 Research / reviewers in the wild / expert
Lun-Pin Yuan
dblp:155/0388
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Recompose Event Sequences vs. Predict Next Events: A Novel Anomaly Detection Approach for Discrete Event LogsabstractOne of the most challenging problems in the field of intrusion detection is anomaly detection for discrete event logs. While most earlier work focused on applying unsupervised learning upon engineered features, most recent work has started to resolve this challenge by applying deep learning methodology to abstraction of discrete event entries. Inspired by natural language processing, LSTM-based anomaly detection models were proposed. They try to predict upcoming events, and raise an anomaly alert when a prediction fails to meet a certain criterion. However, such a predict-next-event methodology has a fundamental limitation: event predictions may not be able to fully exploit the distinctive characteristics of sequences. This limitation leads to high false positives (FPs). It is also critical to examine the structure of sequences and the bi-directional causality among individual events. To this end, we propose a new methodology: Recomposing event sequences as anomaly detection. We propose DabLog, a LSTM-based Deep Autoencoder-Based anomaly detection method for discrete event Logs. The fundamental difference is that, rather than predicting upcoming events, our approach determines whether a sequence is normal or abnormal by analyzing (encoding) and reconstructing (decoding) the given sequence. Our evaluation results show that our new methodology can significantly reduce the numbers of FPs, hence achieving a higher F1 score. Lun-Pin Yuan, Peng Liu 0005, Sencun Zhu |
AsiaCCS | 1 |
| 2021 | Time-Window Based Group-Behavior Supported Method for Accurate Detection of Anomalous UsersabstractAutoencoder-based anomaly detection methods have been used in identifying anomalous users from large-scale enterprise logs with the assumption that adversarial activities do not follow past habitual patterns. Most existing approaches typically build models by reconstructing single-day and individual-user behaviors. However, without capturing long-term signals and group-correlation signals, the models cannot identify low-signal yet long-lasting threats, and will wrongly report many normal users as anomalies on busy days, which, in turn, lead to high false positive rate. In this paper, we propose ACOBE, an Anomaly detection method based on COmpound BEhavior, which takes into consideration long-term patterns and group behaviors. ACOBE leverages a novel behavior representation and an ensemble of deep autoencoders and produces an ordered investigation list. Our evaluation shows that ACOBE outperforms prior work by a large margin in terms of precision and recall, and our case study demonstrates that ACOBE is applicable in practice for cyberattack detection. Lun-Pin Yuan, Euijin Choo, Ting Yu 0001, Issa M. Khalil, Sencun Zhu |
DSN | 1 |
| 2019 | Towards Large-Scale Hunting for Android Negative-Day Malware
Lun-Pin Yuan, Ting Yu 0001, Peng Liu 0005, Sencun Zhu |
RAID | 1 |
| 2018 | Assessing Attack Impact on Business Processes by Interconnecting Attack Graphs and Entity Dependency Graphs
Chen Cao 0004, Lun-Pin Yuan, Anoop Singhal, Peng Liu 0005, Xiaoyan Sun 0003, Sencun Zhu |
DBSec | 2 |
| 2018 | Android STAR: An Efficient Interaction-Preserving Record-Replay System For Messenger App Usage SurveillanceabstractMessenger apps on smart phones are widely used for easy communication in a collaborative workplace. However, the use of messengers increases risks to both the organization and the collaborators. For example, an employee may receive proprietary information from one app and then accidentally leak it with another app, but neither the employer nor the employee can effectively prove or disprove what has happened inside messengers. To prove mental elements in a lawsuit, the capability of inspecting the use of messengers in a workplace is desirable to both parties: one can prove misconduct and the other can prove innocence. Yet, guilty intention is subtle if not literally described, and how to prove whether there was a guilty intention has not yet been resolved. To provide new kind of evidence, we propose Android STAR, an inspection-purposed record-and-replay service that replays conversation histories and user interactions with apps. We assume that the employer has obtained consents of employees, and the employees have installed Android STAR in their company devices. The challenge to app-usage inspection includes app variety and evidence veracity. We evaluate STAR with 10 popular messenger apps (including Telegram, LINE, and WeChat). Our results show that while STAR can replay in high-fidelity, it only introduces small performance overhead. Lun-Pin Yuan, Peng Liu 0005, Sencun Zhu |
WISEC | 1 |
| 2018 | A shareable keyword search over encrypted data in cloud computing
Li Xu 0002, Chi-Yao Weng, Lun-Pin Yuan, Mu-En Wu, Raylin Tso |
J. Supercomput. | 3 |