VLDB 2026 Research / reviewers in the wild / expert
Kangfeng Zheng
dblp:17/6514
· DBLP profile ↗
34ranked-venue papers
2as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 13 · 2 first-author · 11 since 2021Security and privacy · 11Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 since 2021Computer networks · 4Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CTX-Coder: Cross-Attention Architectures Empower LLMs for Long-Context Vulnerability DetectionabstractSoftware vulnerabilities have increased sharply, underscoring the growing urgency for effective detection methods. Although large language model (LLM) based methods have shown promise in this task, current state-of-the-art LLM approaches struggle with functions that have long contexts. In this paper, we propose CTX-Coder, a context-enhanced vulnerability detection framework that enables LLMs to selectively focus on relevant contextual functions. To achieve this, we represent the contextual functions as embeddings and integrate them with the target code via cross-attention, thereby enhancing the model's ability to capture contextual information. Furthermore, to equip the model with the ability to recognize these embedding features, we propose a two-stage pretraining pipeline. We also introduce a new dataset, CTX-VUL, which addresses the limitations of existing datasets that either lack contextual information for vulnerable functions or are not publicly available. Extensive experiments demonstrate that CTX-Coder (10B) significantly outperforms baseline models with even larger parameters, such as Qwen2.5-14B and SecGPT. As the input code length increases, CTX-Coder’s F1 score drops by only 5.01%, while other models degrade by 25% to 41.5%, showing strong robustness to long-context scenarios and the effectiveness of our design. Jujie Wang, Kangfeng Zheng, Bin Wu 0012, Chunhua Wu, Yulin Yao, Minjiao Yang |
AAAI | 2 |
| 2026 | SAFE: Semantic- and Frequency-Enhanced Curriculum for Cross-Domain Deepfake DetectionabstractDriven by advances in GANs and diffusion models, deepfake content has reached an unprecedented level of photorealism, causing detectors to deteriorate once they leave their training domain. Most prior studies adopt CLIP as the backbone of an image-level binary classifier, yet overlook CLIP’s core strength: text-to-image semantic alignment. Moreover, captions generated by CLIP-CAP lack sufficient high-level semantics to distinguish between authentic and manipulated faces. Deepfake generators often fail to maintain semantic coherence, resulting in contradictions that traditional visual models cannot capture. Existing approaches also intermingle all samples during training and thus lack a systematic, difficulty-aware curriculum. To bridge these gaps, we introduce Semantic- and Frequency-Enhanced (SAFE) deepfake detection, a two-component framework: 1) Semantic-enhanced multimodal alignment. Authenticity cues are injected into CLIP-CAP captions, and low-rank LoRA fine-tuning is applied to CLIP’s visual branch, yielding dual supervision for text–image alignment and forgery discrimination. 2) Dual-score curriculum learning. Fourier Correlation Variance (FCV) measures local spectral consistency and, combined with the loss value, is transformed into a difficulty score that ranks training samples from easy to hard, reducing training time by 23.3% and enhancing generalization. SAFE attains state-of-the-art performance on several cross-dataset and cross-manipulation benchmarks. Ablation studies confirm that semantic enhancement, LoRA fine-tuning, and dual-score curriculum are complementary, jointly delivering substantial gains in open-set generalization. Yulin Yao, Kangfeng Zheng, Bin Wu 0012, Chunhua Wu, Jujie Wang, Minjiao Yang |
AAAI | 2 |
| 2026 | Adversarial multimodal user-generated contents generation for anti-user identity linkage
Kangfeng Zheng, Chunhua Wu |
Knowl. Based Syst. | 3 |
| 2025 | Multi-stage self-training social bot detection based on graph neural network
Kangmiao Chen, Zhengxiang Wang, Kangfeng Zheng |
Eng. Appl. Artif. Intell. | 5 |
| 2025 | MSLoRA: Meta-learned scaling for adaptive fine-tuning of LoRA
Kangfeng Zheng, Chunhua Wu |
Neurocomputing | 2 |
| 2025 | ERAT-DLoRA: Parameter-efficient tuning with enhanced range adaptation in time and depth aware dynamic LoRA
Kangfeng Zheng, Chunhua Wu, Jvjie Wang |
Neurocomputing | 2 |
| 2025 | Explicit matrix gradient expression for residual networkabstractResidual Network (ResNet) is a distinguished network structure in deep learning, and its layers can be profound. We theoretically explore the mathematics characteristics of the ResNet, in particular, to pay attention to the gradient information, which is a powerful and straightforward mathematical tool for analysing the properties of ResNet, such as the gradients of the loss function with respect to the input and the weight parameters and the gradient of the entry of the logits with respect to the input. A theorem about the explicit matrix expression of gradients in Resnet is given in this work. A rigorous mathematical and logical derivation of the theorem is obtained in detail by the matrix derivative definition and matrix differentiation. We further provide explicit matrix expressions of some deep learning algorithms in ResNet, including backpropagation, gradient-based adversarial attacks, and gradient-based saliency maps. Furthermore, the reasons why the ResNet network works are analysed. Finally, experimental results are provided to verify the correctness and efficiency of the proposed theorem. Yudao Sun, Kangfeng Zheng, Juan Yin, Chunhua Wu, Xinxin Niu |
J. Exp. Theor. Artif. Intell. | 2 |
| 2024 | Unsupervised twitter social bot detection using deep contrastive graph clustering
Kangmiao Chen, Zhengxiang Wang, Kangfeng Zheng |
Knowl. Based Syst. | 5 |
| 2024 | Defense against adversarial attacks based on color space transformationabstractDeep Learning algorithms have achieved state-of-the-art performance in various important tasks. However, recent studies have found that an elaborate perturbation may cause a network to misclassify, which is known as an adversarial attack. Based on current research, it is suggested that adversarial examples cannot be eliminated completely. Consequently, it is always possible to determine an attack that is effective against a defense model. We render existing adversarial examples invalid by altering the classification boundaries. Meanwhile, for valid adversarial examples generated against the defense model, the adversarial perturbations are increased so that they can be distinguished by the human eye. This paper proposes a method for implementing the abovementioned concepts through color space transformation. Experiments on CIFAR-10, CIFAR-100, and Mini-ImageNet demonstrate the effectiveness and versatility of our defense method. To the best of our knowledge, this is the first defense model based on the amplification of adversarial perturbations. Chunhua Wu, Kangfeng Zheng |
Neural Networks | 3 |
| 2023 | User authentication method based on keystroke dynamics and mouse dynamics using HDA
Kangfeng Zheng, Siwei Cao |
Multim. Syst. | 3 |
| 2023 | Comparative Analysis of ASV Spoofing Countermeasures: Evaluating Res2Net-Based ApproachesabstractPopular topics in the field of countermeasures include feature engineering and neural-network-based models, which involve neural network architectures and loss criteria. This study focuses on Res2Net and its variant models to examine the impact of model generalization on countermeasure performance in the ASVspoof 2019 logical access and physical access scenarios. Results reveal that while Res2Net exhibits superior generalization compared to its variants, the most effective countermeasure combines both feature engineering and model optimization. The proposed dynamic modulated-Res2Net utilizes channel-wise soft attention to recalibrate feature maps, offering adaptive adjustments to spoofing cues of varying scales. Evaluation on the logical access dataset demonstrates dynamic modulated-Res2Net's relative improvement of over 38% compared to Res2Net. Furthermore, we exploit low-frequency features and combine them with dynamic modulated-Res2Net to achieve in an equal error rate of 1.21% under logical access and 0.41% under physical access, establishing our proposed dynamic modulated-Res2Net as one of the top-performing single systems. Additionally, we compare the best countermeasures in different scenarios, highlighting the ongoing challenge of achieving generalization. Minjiao Yang, Kangfeng Zheng, Yudao Sun |
IEEE Signal Process. Lett. | 2 |
| 2021 | Adv-Emotion: The Facial Expression Adversarial AttackabstractArtificial intelligence is developing rapidly in the direction of intellectualization and humanization. Recent studies have shown the vulnerability of many deep learning models to adversarial examples, but there are fewer studies on adversarial examples attacking facial expression recognition systems. Human–computer interaction requires facial expression recognition, so the security demands of artificial intelligence humanization should be considered. Inspired by facial expression recognition, we want to explore the characteristics of facial expression recognition adversarial examples. In this paper, we are the first to study facial expression adversarial examples (FEAEs) and propose an adversarial attack method on facial expression recognition systems, a novel measurement method on the adversarial hardness of FEAEs, and two evaluation metrics on FEAE transferability. The experimental results illustrate that our approach is superior to other gradient-based attack methods. Finding FEAEs can attack not only facial expression recognition systems but also face recognition systems. The transferability and adversarial hardness of FEAEs can be measured effectively and accurately. Yudao Sun, Chunhua Wu, Kangfeng Zheng, Xinxin Niu |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2021 | Generating facial expression adversarial examples based on saliency map
Yudao Sun, Juan Yin, Chunhua Wu, Kangfeng Zheng, Xinxin Niu |
Image Vis. Comput. | 4 |
| 2021 | Game Theoretic Suppression of Forged Messages in Online Social NetworksabstractOnline social networks (OSNs) suffer from forged messages. Current studies have typically been focused on the detection of forged messages and do not provide the analysis of the behaviors of message publishers and network strategies to suppress forged messages. This paper carries out the analysis by taking a game theoretic approach, where infinitely repeated games are constructed to capture the interactions between a publisher and a network administrator and suppress forged messages in OSNs. Critical conditions, under which the publisher is disincentivized to publish any forged messages, are identified in the absence and presence of misclassification on genuine messages. Closed-form expressions are established for the maximum number of forged messages that a malicious publisher could publish. Confirmed by the numerical results, the proposed infinitely repeated games reveal that forged messages can be suppressed by improving the payoffs for genuine messages, increasing the cost of bots, and/or reducing the payoffs for forged messages. The increasing detection probability of forged messages or decreasing misclassification probability of genuine messages also has a strong impact on the suppression of forged messages. Xu Wang 0004, Xuan Zha, Wei Ni 0001, Ren Ping Liu 0001, Y. Jay Guo, Xinxin Niu, Kangfeng Zheng |
IEEE Trans. Syst. Man Cybern. Syst. | 7 |
| 2020 | Feature subset selection combining maximal information entropy and maximal information coefficient
Kangfeng Zheng, Bin Wu 0012 |
Appl. Intell. | 1 |
| 2020 | Detection of compromised accounts for online social networks based on a supervised analytical hierarchy processabstractIn recent years, the security of online social networks (OSNs) has become an issue of widespread concern. Searching and detecting compromised accounts in OSNs is crucial for ensuring the security of OSN platforms. In this study, the authors proposed a new method of detecting compromised accounts based on a supervised analytical hierarchy process (SAHP). First, they considered the expression habits of a user to present the profile features of a user more comprehensively than previous research. Next, the information gain ratio was combined with the analytical hierarchy process algorithm to calculate the weight of each feature. Finally, a detection decision was taken, and varying thresholds were used to obtain different detection results. The experimental results showed that the accuracy and precision of the SAHP were 81.7 and 96.4%, respectively. The results indicated that the new method improved upon the previously established COMPA (detecting compromised accounts on social networks) methods for detecting compromised accounts. Haoyang Tang, Kangfeng Zheng, Yuanrui Tao |
IET Inf. Secur. | 3 |
| 2020 | User Authentication Method Based on MKL for Keystroke and Mouse Behavioral Feature FusionabstractIn order to improve the recognition rate of users with single behavioral feature and prevent impostors from restricting an input device to avoid detection, a dual-index user authentication method based on Multiple Kernel Learning (MKL) for keystroke and mouse behavioral feature fusion was proposed in this paper. Due to the heterogeneity between the keystroke features and the mouse features, we argue that each type of features is mapped to a suitable kernel and the weights of each kernel are obtained through computing and then summed to obtain a compound kernel that implements the multifeature fusion. The dataset used in this paper was collected under complete uncontrolled condition from some volunteers by using our data collection program. The experimental results show that the proposed method can obtain the best recognition accuracy of 89.6%. Compared to the traditional methods of single feature, the dual-index method can get more stable and effective authentication. Therefore, the proposed method in this paper fully demonstrates the reliability of dual-index user authentication. Kangfeng Zheng |
Secur. Commun. Networks | 3 |
| 2019 | Moving Target Defense Against Injection Attacks
Huan Zhang 0002, Kangfeng Zheng, Xiaodan Yan, Shoushan Luo, Bin Wu 0012 |
ICA3PP (1) | 2 |
| 2019 | Survey on blockchain for Internet of Things
Xu Wang 0004, Xuan Zha, Wei Ni 0001, Ren Ping Liu 0001, Y. Jay Guo, Xinxin Niu, Kangfeng Zheng |
Comput. Commun. | 7 |
| 2019 | A Neighbor Prototype Selection Method Based on CCHPSO for Intrusion DetectionabstractNearest neighbor (NN) models play an important role in the intrusion detection system (IDS). However, with the advent of the era of big data, the NN model has the disadvantages of low efficiency, noise sensitivity, and high storage requirement. This paper presents a neighbor prototype selection method based on CCHPSO for intrusion detection. In the model, the prototype selection and feature weight adjustment are performed simultaneously and k-nearest neighbor (KNN) is used as the basic classifier. To deal with large-scale optimization problems, a cooperative coevolving algorithm based on hybrid standard particle swarm and binary particle swarm optimization, which employs the divide-and-conquer strategy, is proposed in this paper. Meanwhile, a fitness function based on the accuracy and data reduction rate is defined in the CCHPSO to obtain a set of appropriate prototypes and feature weights. The KDD99 and NSL datasets are used to assess the effectiveness of the method. The empirical results indicate that the data reduction rate of the proposed method is very high, ranging from 82.32% to 92.01%. Compared with all the data used, the proposed method can not only achieve comparable accuracy performance but also save a lot of storage and computing resources. Yanping Shen, Kangfeng Zheng, Chunhua Wu, Yixian Yang |
Secur. Commun. Networks | 2 |
| 2019 | Group-Based Susceptible-Infectious-Susceptible Model in Large-Scale Directed NetworksabstractEpidemic models trade the modeling accuracy for complexity reduction. This paper proposes to group vertices in directed graphs based on connectivity and carries out epidemic spread analysis on the group basis, thereby substantially reducing the modeling complexity while preserving the modeling accuracy. A group-based continuous-time Markov SIS model is developed. The adjacency matrix of the network is also collapsed according to the grouping, to evaluate the Jacobian matrix of the group-based continuous-time Markov model. By adopting the mean-field approximation on the groups of nodes and links, the model complexity is significantly reduced as compared with previous topological epidemic models. An epidemic threshold is deduced based on the spectral radius of the collapsed adjacency matrix. The epidemic threshold is proved to be dependent on network structure and interdependent of the network scale. Simulation results validate the analytical epidemic threshold and confirm the asymptotical accuracy of the proposed epidemic model. Xu Wang 0004, Wei Ni 0001, Ren Ping Liu 0001, Y. Jay Guo, Xinxin Niu, Kangfeng Zheng |
Secur. Commun. Networks | 7 |
| 2018 | Social Bot Detection Using Tweets Similarity
Yahan Wang, Chunhua Wu, Kangfeng Zheng |
SecureComm (2) | 3 |
| 2018 | An Ensemble Method based on Selection Using Bat Algorithm for Intrusion DetectionabstractMachine learning plays an important role in constructing intrusion detection models. However, the information era is an era of data. With the continuous increase in data size and the growth of data dimensions, the ability of a single classifier is becoming limited in predicting samples. In this paper, we present an ensemble method using random subspace in which an extreme learning machine (ELM) is chosen as the base classifier. To optimize the ensemble model, an ensemble pruning method based on the bat algorithm (BA) is proposed. Meanwhile, a fitness function based on the accuracy and diversity of an ensemble is defined in the BA to obtain an improved classifier subset. Three public datasets, the KDD99, NSL and Kyoto datasets, are adopted to assess the robustness of the method. The empirical results indicate that the ensemble method based on random subspace can improve the accuracy and robustness over the use of an individual ELM. The results also show that compared with when all the sub-classifiers are used in the ensemble, the pruning framework can not only achieve comparable or better performance but also save substantial computing resources in an intrusion detection system (IDS). Yanping Shen, Kangfeng Zheng, Chunhua Wu, Mingwu Zhang, Xinxin Niu, Yixian Yang |
Comput. J. | 2 |
| 2018 | Feature selection method with joint maximal information entropy between features and class
Kangfeng Zheng |
Pattern Recognit. | 1 |
| 2018 | The Impact of Link Duration on the Integrity of Distributed Mobile NetworksabstractA major challenge in distributed mobile networks is network integrity, resulting from short link duration and severe transmission collisions. This paper analyzes the impact of link duration and transmission collisions on a range of on-the-fly authentication protocols, which operate based on predistributed keys and can instantly verify and forward messages. All unexpired messages within a link duration can be verified retrospectively, once the keys are matched on-the-air. We develop a new general 4D Markov model which, apart from the first three dimensions modeling a cycle of the protocols, is able to unprecedentedly capture unexpired messages between cycles in the fourth dimension. Validated by simulation, our analysis reveals that the on-the-fly authentication is efficient under short link duration, but is susceptible to transmission collisions. The authentication requires holistic cross-layer designs of retransmission and rekeying. The proposed model is able to facilitate the design of the protocol parameters, which allows the protocols to significantly outperform the state of the art. Xuan Zha, Wei Ni 0001, Xu Wang 0004, Ren Ping Liu 0001, Y. Jay Guo, Xinxin Niu, Kangfeng Zheng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2017 | Computing Adaptive Feature Weights with PSO to Improve Android Malware DetectionabstractAndroid malware detection is a complex and crucial issue. In this paper, we propose a malware detection model using a support vector machine (SVM) method based on feature weights that are computed by information gain (IG) and particle swarm optimization (PSO) algorithms. The IG weights are evaluated based on the relevance between features and class labels, and the PSO weights are adaptively calculated to result in the best fitness (the performance of the SVM classification model). Moreover, to overcome the defects of basic PSO, we propose a new adaptive inertia weight method called fitness-based and chaotic adaptive inertia weight-PSO (FCAIW-PSO) that improves on basic PSO and is based on the fitness and a chaotic term. The goal is to assign suitable weights to the features to ensure the best Android malware detection performance. The results of experiments indicate that the IG weights and PSO weights both improve the performance of SVM and that the performance of the PSO weights is better than that of the IG weights. Chunhua Wu, Kangfeng Zheng, Xu Wang 0004, Xinxin Niu, Tianliang Lu |
Secur. Commun. Networks | 3 |
| 2017 | Scalable Node-Centric Route Mutation for Defense of Large-Scale Software-Defined NetworksabstractExploiting software-defined networking techniques, randomly and instantly mutating routes can disguise strategically important infrastructure and protect the integrity of data networks. Route mutation has been to date formulated as NP-complete constraint satisfaction problem where feasible sets of routes need to be generated with exponential computational complexities, limiting algorithmic scalability to large-scale networks. In this paper, we propose a novel node-centric route mutation method which interprets route mutation as a signature matching problem. We formulate the route mutation problem as a three-dimensional earth mover’s distance (EMD) model and solve it by using a binary branch and bound method. Considering the scalability, we further propose that a heuristic method yields significantly lower computational complexities with marginal loss of robustness against eavesdropping. Simulation results show that our proposed methods can effectively disguise key infrastructure by reducing the difference of historically accumulative traffic among different switches. With significantly reduced complexities, our algorithms are of particular interest to safeguard large-scale networks. Yang Zhou 0005, Wei Ni 0001, Kangfeng Zheng, Ren Ping Liu 0001, Yixian Yang |
Secur. Commun. Networks | 3 |
| 2017 | Collaborative Authentication in Decentralized Dense Mobile Networks With Key PredistributionabstractChallenges of authentication in decentralized mobile networks arise from frequently changing topologies and unreliable contention-based transmissions. We propose a new protocol to speed up authentications, reduce communication costs, and support opportunistic routing under fast-changing topologies. Key pairs are predistributed across the network. Nodes that predistributed the same pair can instantly verify and route messages for each other in an opportunistic and cooperative fashion, combating fast-changing topologies. We also enable a node to increasingly combine unauthenticated messages and a new message for signature or message authentication code generation, while trying different keys on-the-fly. The messages can be verified altogether, once a key is matched. The communication overhead, thus, becomes independent of the number of keys tried. Closed-form expressions for authentication rate, delay, and throughput are derived through a new three-dimensional Markov model. Validated by simulations, analytical results corroborate the robustness of the proposed protocol against changing topologies, as well as the substantially improved resistance to collusion attacks, as compared with the state of the art. Xuan Zha, Wei Ni 0001, Kangfeng Zheng, Ren Ping Liu 0001, Xinxin Niu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | Detection of command and control in advanced persistent threat based on independent accessabstractAdvanced Persistent Threat (APT) imposes increasing threats on cyber security with the developing network attack technologies. APT is a highly interactive, specifically targeted and extremely harmful network-centric attack, which employs various technologies to evade detection during attacks leading to the result that victims will not be aware of attacks until they suffer from tremendous losses. Since command and control (C&C) is an essential component during the lifetime of APT, the detection of it is a practical measure to defend against the APT. In this paper, we analyze the features of C&C in APT and find that the HTTP-based C&C is widely used. Based on the analysis results, we propose a new feature of C&C, i.e., independent access, to characterize the difference between C&C communications and normal HTTP requests. Applying the independent access feature into DNS records, we implement a novel C&C detection method and validate it on public dataset. As a new feature of C&C, its advantages and drawbacks are also analyzed. Xu Wang 0004, Kangfeng Zheng, Xinxin Niu, Bin Wu 0012, Chunhua Wu |
ICC | 2 |
| 2016 | Anti-Pollution Source Location Privacy Preserving Scheme in Wireless Sensor NetworksabstractThe source-location privacy threat is one of the critical issues in Wireless Sensor Networks (WSNs). Adversaries may trace along the sensor traffic to hunt targets around source nodes. Previous works proposed dummy messages and network coding to eliminate time and content correlations. However, these proposed schemes may result in explosion of polluted and dummy messages, opening up vulnerability to active attackers. In this work, we propose pollution avoiding source location privacy preserving scheme PA-SLP. A probabilistic key predistribution is proposed to predistributed keys in nodes. It enables intermediate nodes to verify signatures and filter out dummy or polluted messages with a certain possibility. In PA-SLP, a triple type homomorphic signature algorithm is developed to detect and classify three message types with only one pair of asymmetric keys. PA-SLP is able to adjust key distribution parameters to balance network performance and privacy. Security analysis and simulation results demonstrate PA-SLP can resist traffic analysis and filter out polluted and dummy messages effectively. Xuan Zha, Kangfeng Zheng, Dongmei Zhang 0007 |
SECON | 2 |
| 2016 | Virus Propagation Modeling and Convergence Analysis in Large-Scale NetworksabstractBiological epidemic models, widely used to model computer virus propagations, suffer from either limited scalability to large networks, or accuracy loss resulting from simplifying approximations. In this paper, a discrete-time absorbing Markov process is constructed to precisely characterize virus propagations. Conducting eigenvalue analysis and Jordan decomposition to the process, we prove that the virus extinction rate, i.e., the rate at which the Markov process converges to a virus-free absorbing state, is bounded. The bounds, depending on the infection and curing probabilities, and the minimum degree of the network topology, have closed forms. We also reveal that the minimum curing probability for a given extinction rate requirement, specified through the upper bound, is independent of the explicit size of the network. As a result, we can interpret the extinction rate requirement of a large network with that of a much smaller one, evaluate its minimum curing requirement, and achieve simplifications with negligible loss of accuracy. Simulation results corroborate the effectiveness of the interpretation, as well as its analytical accuracy in large networks. Xu Wang 0004, Wei Ni 0001, Kangfeng Zheng, Ren Ping Liu 0001, Xinxin Niu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Towards a multiobjective framework for evaluating network security under exploit attacksabstractExploit attacks have been one of the major threats to computer network systems, the damage of which has been extensively studied and numerous countermeasures have been proposed to defend against them. In this work, we propose a multiobjective optimization framework to facilitate evaluation of network security under exploit attacks. Our approach explores a promising avenue of integrating attack graph methodology to evaluate network security. In particular, we innovatively utilize attack graph based security metrics to model exploit attacks and dynamically measure security risk under these attacks. Then a multiobjective problem is formulated to maximize network exploitability and security impact under feasible exploit compositions. Furthermore, an artificial immune algorithm is employed to solve the formulated problem. We conduct a series of simulation experiments on hypothetical network models to testify the performance of proposed mechanism. Simulation results show that our approach can innovatively solve the security evaluation problem under multiple decision variables with feasibility and effectiveness. Fangfang Dai, Kangfeng Zheng, Shoushan Luo, Bin Wu 0012 |
ICC | 2 |
| 2015 | Exploring risk flow attack graph for security risk assessmentabstractResearchers have previously looked into the problem of determining the connection between invasive events and network risk, and attack graph (AG) was proposed to seek countermeasures. However, AG has proved to have various limitations in practical applications. To overcome such defects, this study presents a risk flow attack graph (RFAG)‐based risk assessment approach. In particular, this approach applies a RFAG to represent network and attack scenarios, which are then fed to a network flow model for computing risk flow. A bi‐objective sorting algorithm is employed to automatically infer the priority of risk paths and assist risk assessment, and a fuzzy comprehensive evaluation is performed to determine risk severity. Via the aforementioned processes, the authors simplify AG and follow the risk path of originating, transferring, redistributing and converging to assess security risk. The authors use a synthetic network scenario to illustrate this approach and evaluate its performance through a set of simulations. Experiments show that the approach is capable of effectively identifying network security situations and assessing critical risk. Fangfang Dai, Kangfeng Zheng, Bin Wu 0012 |
IET Inf. Secur. | 3 |
| 2011 | Multiple-image compressed encryption and decryption by compressive holographyabstractThis paper presents a scheme of a multiple-image compressed encryption based on the compressive holography technique. Computer generate hologram (CGH) is implemented to record multiple images simultaneously into an encrypted hologram. Because its two-dimensional (2D) Fourier transform (FT) result is analogous a partial 3D Fourier transform sampling, the 2D FT result can be compressed by a nonuniform sampling accompanied with a quantization. The encryption and compression processes agrees with the requirement of the compressive sensing and composes the compressive holography. Therefore, the decryption is solved by a minimization. It remains the sparsity of the recovered natural images in the wavelet basis. Meanwhile, a total-variation regularization and a nonnegative constraint is employed to extract images with edge preserved and nonnegative gray scale, respectively. Experiments are conducted to demonstrate the feasibility of the multiple- image compressed encryption. Hong Di, Kangfeng Zheng, Xinxin Niu |
VCIP | 2 |