Jianguo Chen 0004

dblp:18/733-4 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0001-9955-2216ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Cybersecurity Multi-Dimensional Few-Shot Data Generation on Malicious Enhancement
abstract
Small amounts of malicious logs can confuse and imbalance a large volume of normal logs, leading to a significant drop in model performance. To address the high heterogeneity and imbalance between network security data, we propose a multidimensional few-shot data augmentation framework based on Generative Adversarial Networks (GANs) for generating highquality malicious samples to balance data distribution. In this framework, several representative GAN models, including PEGAN, XOR-GAN, and TriNet-GAN, are designed to enhance the performance of deep learning models in network threat detection. Large-scale adversarial generation experiments are conducted on the original imbalanced dataset and security event logs using ACGAN and Seq-GAN, effectively solving the imbalance and fewshot issues. The experimental results are based on the publicly available NIMS (Network Information Management and Security Group) and KDD99 datasets. The results demonstrate that the proposed method performs well in data augmentation for fewshot, imbalanced, and multidimensional complex data.
Qiaojuan Wang, Yanqing Song 0001, Jianguo Chen 0004
IEEE Trans. Dependable Secur. Comput.5
2024 Generative Adversarial Network for Enhancement Network Security Log Detection
Yu Zhang 0249, Yanqing Song 0001, Jianguo Chen 0004
ICIC (8)3
2024 Machine Learning for Human-Machine Systems With Advanced Persistent Threats
abstract
This article conducts a thorough exploration of the implications of machine learning (ML) in conjunction with human–machine systems within the military domain. It scrutinizes the strategic development efforts of ML by pertinent institutions, particularly in the context of military applications and the domain of advanced persistent threats. Prominent nations have delineated a technical trajectory for the integration of ML into their military frameworks. To bolster the structure and efficacy of their various military branches and units, there has been a concentrated deployment of numerous ML research endeavors. These initiatives encompass the study of sophisticated ML algorithms and the acceleration of artificial intelligence technology adaptation for intelligence processing, autonomous platforms, command and control infrastructures, and weapons systems. Forces across the globe are actively embedding ML technologies into a range of platforms-terrestrial, naval, aerial, space-faring, and cybernetic. This integration spans weaponry, networks, cognitive operations, and additional systems. Furthermore, this article reviews the incorporation within the sphere of military human–machine interaction in the Russia–Ukraine conflict. In this war, cyber human–machine interaction has become a pivotal arena of contention between Russia and Ukraine, with key levers that influence the conflict's course. In addition, the article examines the adoption of ML in prospective military functions such as, operations, intelligence gathering, networking, logistics, identification protocols, healthcare, data analysis trends, and other critical areas marked by current developments and trajectories. It also proffers a series of recommendations for the future integration of ML to inform strategic direction and research.
Yanqing Song 0001, Jianguo Chen 0004
IEEE Trans. Hum. Mach. Syst.4
2023 Security is Readily to Interpret: Quantitative Feature Analysis for Botnet Encrypted Malicious Traffic
abstract
Nowadays, there are two problems in the network traffic analysis. One is that it’s difficult to detect the encrypted threat traffic resulting in the ineffective analysis and detection of attack characteristics of complex network such as botnet traffic. The other is that machine learning(ML) is featured by high false alarm rate, long training period and demanding data accuracy. In this work, the data packet was deeply analyzed through the data packet analysis method including the analysis of its header and content so as to realize the analysis of network traffic’s characteristics. The CTU-13 and MCFP data sets were dimension-reduced by the t-SNE algorithm, and the 2-dimensional space was mapped so that the distribution boundary of the data was observed and judged. Through eXtreme Gradient Boosting (XGBoost), Support Vector Machines (SVM), Random Forest, Logistic Regression and other machine learning algorithms, we detected the encrypted traffic and found that XGBoost and Random Forest were better for threatening dense flows. On the basis of feature analysis, we selected all, DNS, HTTP and deleted 20/30/40 importance features for ranking, and quantitatively explained the impact of each feature on threat dense flow classification. Through conducting the performed recursive feature elimination with XGBoost algorithm, this paper obtained the classification ranking and then concluded that the influence degree of overall characteristics was very uneven with the first six characteristics led by average of duration occupying a large weight. By obtaining the SHAP evaluation data of the selected all, DNS, HTTP, and deleted 20/30/40 importance features, this paper quantitatively explained the impact of each feature on the classification of threat dense traffic. In addition, this paper also carried out the impact verification of the importance characteristics. Because machine learning, including deep learning, is difficult to interpret. And to ensure the security of cyberspace, we make predictions all the time — to determine whether extensive encrypted traffic is malicious. It is important to interpret the quantitative influencing factors of the predictive model. This paper proposed the influence of features on the classification of encrypted malicious traffic by quantitative methods-SQEITF.
Qiaojuan Wang, Yanqing Song 0001, Jianguo Chen 0004
COMPSAC4
2023 A Framework for Few-Shot Network Threats Based on Generative Adversarial Networks
abstract
A small amount of malicious logs is confusing and unbalanced for a large number of normal logs. We proposed a framework of network threats sample based on Generative Adversarial Networks(GAN). This paper solves the imbalance problem of multidimensional sample data such as logs, traffic, programs, and feature spaces in the field of cyberspace security by generating confrontation networks. We carried out a large-scale confrontation generation experiment of security event logs based on SeqGAN and generated corresponding log text for data enhancement, which effectively solve the problem of few-shot. The results in this section show that the use of the AC-GAN augmentation dataset is enhanced compared to the original non-equilibrium dataset using the artificial synthesis of the SMOTE dataset Network traffic data set to improve the performance of supervised learning classification. It has inestimable effects on threat detection, various types of offensive to defensive, and cryptography algorithms.
Yanqing Song 0001, Jianguo Chen 0004
ISCC3
2022 Social network behavior and public opinion manipulation
Jianguo Chen 0004, Chunhe Xia
J. Inf. Secur. Appl.2