VLDB 2026 Research / reviewers in the wild / expert
Guoqiao Zhou
dblp:177/1357
· DBLP profile ↗
5ranked-venue papers
0as first author
5since 2021 · last 2025
0009-0004-2394-2997ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | KVT-Payload: Knowledge Graph-Enhanced Hierarchical Vulnerability Traffic Payload Generation
Faqi Zhao, Rong Shi, Guoqiao Zhou |
ICICS (3) | 3 |
| 2025 | GELog: a GPT-Enhanced Log Representation Method for Anomaly DetectionabstractLog anomaly detection is a critical aspect of Artificial Intelligence for IT Operations (AIOps), as it enables the timely identification of system failures, thereby facilitating program understanding throughout the entire software maintenance and engineering life cycles. While existing methods only leverage raw log information for anomaly detection, they struggle to address challenges such as log differences due to log evolution, noise from log parsing, and stylistic differences between logs and natural language. To overcome these limitations, we propose GELog, an innovative log anomaly detection method. Specifically, GELog initially employs GPT to semantically enhance log templates. Subsequently, it extracts semantic vectors using pretrained sentence-bert and introduces an attention-based semantic fusion module that integrates the semantic representations of both the original and enhanced logs. Finally, GELog utilizes a Transformer-based model for anomaly detection. We evaluated the performance of GELog on four publicly available datasets, and the experimental results demonstrate that GELog significantly enhances the semantic representation of logs, achieving superior anomaly detection performance. Wenwu Xu, Haichao Shi, Guoqiao Zhou, Junliang Yao |
ICPC | 4 |
| 2025 | Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature ImputationabstractNetwork traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa). Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001 |
IEEE Trans. Netw. | 5 |
| 2024 | A LLM-based agent for the automatic generation and generalization of IDS rulesabstractCyberattacks on digital services and Internet of Things (IoT) are rising, employing complex tactics. Using intrusion detection systems (IDS) to detect and counter threats at key network points is vital for strong cybersecurity. Traditional rule-based network IDS rely on predefined rules, which may not effectively recognize the myriad complex variants of potential attacks. AI-driven methods for detecting malicious traffic offer enhanced capabilities but can fall short in terms of interpretability and performance under high-throughput network conditions. To address these challenges, we propose a LLM-based (Large Language Model) agent that utilizes multiple sources inputs to generate and generalize rules. The generated rules are designed to detect a variety of corresponding malicious threats, while the generalized rules are crafted to identify similar variant attacks. We have amassed an extensive dataset, comprising vulnerability security reports, malicious traffic, and original IDS rules from authoritative sources, which serve as input for the LLM-based agent. Subsequently, comparative experiments were conducted to assess the performance of the new rules in detecting malicious traffic. The experimental results demonstrate the superior performance of these new rules across various metrics for malicious traffic detection. Haoning Chen, Huaifeng Bao, Wen Wang 0008, Feng Liu 0001, Guoqiao Zhou, Peng Yin 0001 |
TrustCom | 6 |
| 2022 | A Dual-Branch Self-attention Method for Mobile Malware Detection via Network TrafficabstractThe desperate increase of mobile malware has constituted a severe threat to user privacy, economic life, and cyberspace security. Existing anti-malware solutions have no-ticeable weaknesses due to the adoption of content analysis-based approaches. The main limitation of these approaches is that they rely on careful expert engineering and professional handcrafted input features. Some researchers have tried to solve this limitation by using deep learning models to automatically learn feature representations from raw traffic. In this paper, we explore a deep learning detection framework based on self-attention to discriminate between malicious and benign network traffic. As a major advantage with respect to the state-of-the-art methods, we point out that the attention mechanism can better learn the underlying features of malicious traffic in terms of flows and bytes. We design a dual-branch deep learning method that consists of a flow importance-discrimination branch and a byte importance-discrimination branch. The flow importance-discrimination branch calculates the attentions between flows to obtain the feature contributions of different flows, and the byte importance-discrimination branch builds the feature contributions of diverse bytes by considering the connections among all bytes of network payload. Both flow features and byte features are combined to enhance the representation ability of network traffic behaviors generated by mobile applications (apps). We evaluate proposed method using a publicly available dataset including 55,992 malicious traffic traces and 47,779 benign traffic traces. The experimental results demonstrate that our method is able to identify malicious apps with high accuracy, outperforming the baseline methods and the popular deep-learning models. Ruihai Ge, Yongzheng Zhang 0002, Guoqiao Zhou |
IJCNN | 4 |