VLDB 2026 Research / reviewers in the wild / expert
Mingcan Cen
dblp:162/4517
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0003-3868-5159ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RansoGuard: A RNN-based framework leveraging pre-attack sensitive APIs for early ransomware detectionabstractRansomware has emerged as a significant security threat in cyberspace, inflicting severe economic losses and privacy breaches on individual users and organizations. Ransomware typically encrypts critical user files and demands a ransom for decryption. Traditional signature-based defense methods effectively identify known ransomware but perform poorly when confronting unknown zero-day attacks. Addressing this challenge, a ransomware detection framework called ‘RansoGuard’ is proposed. This framework aims to achieve timely identification and defense against ransomware by capturing and analyzing the sensitive Application Programming Interface (API) call behavior exhibited before the encryption attack is launched. A real-world ransomware sample dataset was constructed. The dynamic behavioral data during the pre-attack stage was analyzed, and natural language processing techniques were used to represent and extract key features from API call sequences. A Recurrent Neural Network (RNN) classifier was trained on these features to distinguish ransomware from benign software. Experimental results demonstrate that the RansoGuard framework exhibits outstanding early ransomware detection performance across different datasets, achieving a recall of 96.18% and an accuracy of 94.26%. Furthermore, it exhibits robustness in effectively countering zero-day attacks. Mingcan Cen, Frank Jiang 0001, Robin Doss |
Comput. Secur. | 1 |
| 2024 | Ransomware early detection: A surveyabstractIn recent years, ransomware attacks have exploded globally, and it has become one of the most significant cyber threats to digital infrastructure. Such attacks have been targeting ranging from individuals to critical infrastructure or large organizations such as large commercial companies, energy facilities, medical centers and government departments. Ransomware attackers use sophisticated encryption techniques to hijack victims’ files in exchange for a large ransom to release encrypted data. Sophisticated encryption techniques make it almost impossible for victims to recover data without the secret key in the event of such an attack. To protect systems from ransomware threats, malicious activities had better be detected earlier, preferably before they engage in the harmful behavior. Numerous studies have focused on ransomware threats and attempted to provide detection and prevention solutions for ransomware attacks, but none of the surveys explored the early detection of ransomware and highlighted challenges and issues with existing solutions. This survey fills this gap and provides a state-of-the-art overview of research on the ransomware early detections. Moreover, we investigate the latest ransomware surveys and give an overview of the categories of ransomware from different perspectives, the evolution and attack process of ransomware, and provide datasets used for ransomware detection. Finally, the possible future research directions are discussed. Mingcan Cen, Frank Jiang 0001, Xingsheng Qin, Qinghong Jiang, Robin Doss |
Comput. Networks | 1 |
| 2024 | Zero-Ran Sniff: A zero-day ransomware early detection method based on zero-shot learningabstractRansomware attacks, which blackmail victims into paying a ransom by locking their devices or encrypting their files, have become one of the major threats to network security. Conventional anti-ransomware tools often fail to detect zero-day ransomware attacks due to the inability to obtain zero-day ransomware signatures in advance to train detection models. In addition, zero-day ransomware attacks often use sophisticated encryption techniques to launch attacks on new vulnerabilities, and these encryption attacks cause irreversible damage to victims' digital files even if they choose to pay a ransom. It is therefore urgent and important to identify unknown ransomware attacks as early as possible, i.e. before the stage of encryption. To this end, this paper proposes Zero-Ran Sniff (ZRS), an early zero-day ransomware detection method based on zero-shot learning, which can detect zero-day ransomware attacks in the early stage. ZRS leverages the portable executable header (PE header) feature from executable files to identify ransomware. It comprises two stages: an auto-encoding network-based core attribute learning (AE-CAL) stage and a self-attentive mechanism-based convolutional neural network inference Stage (SA-CNN-IS). During the AE-CAL stage, the core features of known and unknown classes of ransomware are extracted using self-encoding networks, and the SA-CNN-IS phase identifies ransomware. To the best of our knowledge, we are the first to explore the use of zero-shot learning for zero-day ransomware early detection. Experimental results demonstrate that the proposed ZRS outperforms traditional machine learning methods. Compared to previous zero-day detection work, ZRS achieves a recall of 98.47% and an accuracy of 96.31% Mingcan Cen, Xizhen Deng, Frank Jiang 0001, Robin Doss |
Comput. Secur. | 1 |
| 2023 | Hybrid cyber defense strategies using Honey-X: A survey
Xingsheng Qin, Frank Jiang 0001, Mingcan Cen, Robin Doss |
Comput. Networks | 3 |
| 2021 | Depression Detection Using Asynchronous Federated OptimizationabstractWith the rapid growth of population, the life pressure, and the various intensive pressures every day deepen the competition among people more intensive. Tens of millions of people have been suffering from depression every year and only a fraction receives adequate treatment. The development of social networks such as Facebook, Twitter, Weibo, and QQ provides more convenient communication and provides a new emotional release window. People communicate with their friends and share their opinions to express their feelings. It provides an opportunity to detect depression in social networks. Although using social networks to detect depression has picked an established position on a global scale, few researchers consider the data security and privacy-preserving schemes. Therefore, we propose the federated learning technique as an efficient and scalable method. With the larger number of social networks data from diverse edge devices, federated learning can process a large number of edge devices in parallel. For the study, we aim to analyze depression on Weibo collected from an online social network. We propose a novel algorithm Text-CNN Asynchronous Federated optimization (CAFed) based on federated learning to improve the communication cost and convergence rate. We have shown our proposed method can effectively protect users' privacy under the premise of ensuring the accuracy of prediction. We prove that our proposed method's convergence rate is faster than the Federated Averaging (FedAvg) for non-convex problems. Federated learning techniques identify high-quality solutions to mental health issues among Weibo users. Jinli Li, Mingcan Cen, Xunao Wang |
TrustCom | 3 |
| 2021 | Cost-sensitive Heterogeneous Integration for Credit Card Fraud DetectionabstractCredit card fraudulent activities cause huge financial losses around the world every year. In recent years, data-driven methods are increasingly becoming fraud detection methods for financial institutions. Some related studies based on machine learning and data mining have been proposed. However, most of them do not consider the actual financial losses associated with the fraud detection process. Or some related cost sensitive methods focus on minimizing cost loss but the accuracy of detection is low. This paper presents a cost-sensitive heterogeneous integration model, CSHIM, for credit card fraud detection. CSHIM considers the different misclassification costs of each transaction and integrates the superior performance of different individual classifiers through the cost-sensitive weighted Dempster-Shafer fusion theory to achieve better fraud detection results. The goal is to achieve good performance not only in reducing monetary losses but also improving detection accuracy. We have done experiments on public data sets, the experiments show that the method proposed in this paper can save up to 74.69% of the cost, which not only can achieve good results in cost savings, but also has better performance of other standard metrics compared with other methods. Yuhua Ling, Mingcan Cen, Xunao Wang |
TrustCom | 3 |