VLDB 2026 Research / reviewers in the wild / expert
Chenxu Wang 0006
dblp:16/10143-6
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0001-9221-2040ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | APTSniffer: Detecting APT Attack Traffic Using Retrieval-Augmented Large Language ModelsabstractAdvanced Persistent Threats (APT) differ from traditional attacks by using more complex and covert strategies for long-term assaults, posing a severe threat to organizational and national security. Due to problems like the shortage of APT traffic data and encrypted traffic obfuscation, existing methods cannot accurately identify APT traffic with just a few traffic samples. To overcome the above limitation, we propose a novel encrypted APT traffic detection model, APTSniffer, which combines large language models (LLM) and retrieval-augmented technology. APTSniffer utilizes the few-shot inference and generalization abilities of large language models by converting raw traffic data into natural language inference examples understandable by the LLM. Experimental results show that, compared to other baseline models, APTSniffer exhibits SOTA performance. It achieves F1 scores above 97% on three APT datasets, making it practically applicable for APT traffic detection tasks. Chengxiang Si, Zhou Zhou 0007, Chenxu Wang 0006, Peishuai Sun, Qingyun Liu 0001 |
ICASSP | 4 |
| 2025 | FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic Classification
Chengxiang Si, Zhenyu Cheng 0001, Chenxu Wang 0006, Jiang Xie 0004, Peishuai Sun, Qingyun Liu 0001 |
INFOCOM | 5 |
| 2025 | Leveraging Cross-Layer Network Probing to Detect Stealth ServicesabstractStealth services have become increasingly popular due to growing demand for privacy protection. To avoid detection by active probing, many have adopted probe-resistant strategies. In this work, we design a suite of carefully crafted probes to expose their hidden vulnerabilities. Through detailed analysis of the corresponding responses, we find that despite the defensive measures implemented, certain implicit information, such as protocol stack fingerprints, can still serve as strong indicators. We present SSChecker, a detection system that combines cross-layer probing with a classification model inspired by Information Bottleneck Theory to address the data sparsity issue inherent in active probing. Our experiments on real-world datasets show that SSChecker outperforms existing methods, including leading industrial detection engines. Our findings demonstrate that current probe-resistant strategies of stealth services remain insufficient. To strengthen privacy protection, we further propose mitigation strategies that help stealth services enhance their ability. Jiangyi Yin, Chenxu Wang 0006, Zhao Li 0010, Zhuojun Jiang, Jiangchao Chen, Dongfang Hao, Qingyun Liu 0001 |
TrustCom | 2 |
| 2024 | ProxyKiller: An Anonymous Proxy Traffic Attack Model Based on Traffic Behavior Graphs
Zhenyu Cheng 0001, Chenxu Wang 0006, Peishuai Sun, Jiang Xie 0004, Qingyun Liu 0001 |
ESORICS (2) | 4 |
| 2024 | Identifying VPN Servers through Graph-Represented BehaviorsabstractIdentifying VPN servers is a crucial task in various situations, such as geo-fraud detection, bot traffic analysis and network attack identification. Although numerous studies that focus on network traffic detection have achieved excellent performance in closed-world scenarios, particularly those methods based on deep learning, they may exhibit significant performance degradation due to changes in network environment. To mitigate this issue, a few studies have attempted to use methods based on active probing to detect VPN servers. However, these methods still have two limitations. They cannot handle situations without probing responses and are limited in applicability due to their focus on specific VPNs. In this work, we propose VPNChecker, which utilizes the graph-represented behaviors to detect VPN servers in real-world scenarios. VPNChecker outperforms existing methods in four offline datasets. The results from our datasets, containing multiple different VPNs, indicate that VPNChecker has better applicability. Furthermore, we deploy VPNChecker in an Internet Service Provider's (ISP) environment to evaluate its effectiveness. The results show that VPNChecker can improve the coverage of sophisticated detection engines and serve as a complement to existing methods. Chenxu Wang 0006, Jiangyi Yin, Zhao Li 0010, Qingyun Liu 0001 |
WWW | 1 |
| 2023 | IDTracker: Discovering Illicit Website Communities via Third-party Service IDsabstractIllicit websites are restricted by governments and application marketplaces due to their detrimental impact on society. Third-party web services play a crucial role in enabling illicit webmasters to establish websites rapidly and evade detection. In this paper, we discover that third-party services usually assign unique credentials to website developers as their identifications (IDs). Websites using the same services with identical IDs are likely to be hosted on shared infrastructures and have textually similar domain names. This observation sparks the idea of building a community of illicit websites by leveraging third-party service IDs. Therefore, we design IDTracker, a novel system for detecting illicit website communities based on domain name semantic and infrastructure relationship features, which empower classification algorithms to achieve a high F1 score of 0.8968. Furthermore, we deploy IDTracker on an Internet Service Provider's (ISP) environment for three months and identify 6,830 illicit communities containing 165,378 illicit websites. Many of these illicit websites can not be identified by the most sophisticated engines, such as Symantec and Baidu, because of the cloaking tactics. In addition, we conduct a large-scale and long-term measurement on the network infrastructures and third-party services of illicit communities, revealing new phenomena. Our findings can help security communities to thwart illicit websites more effectively. Chenxu Wang 0006, Zhao Li 0010, Jiangyi Yin, Zhenni Liu, Qingyun Liu 0001 |
DSN | 1 |