VLDB 2026 Research / reviewers in the wild / expert
Qingjun Yuan
dblp:181/6718
· DBLP profile ↗
36ranked-venue papers
5as first author
35since 2021 · last 2027
0000-0002-6598-8190ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 first-author · 15 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 3 first-author · 7 since 2021Computer networks · 7 · 7 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection
Xiaojie Qin, Qingjun Yuan, Haopeng Fan, Pinghui Wang, Jihong Teng, Siqi Lu, Yongjuan Wang |
Expert Syst. Appl. | 2 |
| 2026 | UI2C: An Adaptive Boundary Learning Method for Imbalanced Malicious Traffic Detection
Qingjun Yuan, Yanbei Zhu, Yongjuan Wang, Guangsong Li |
ICIC (11) | 2 |
| 2026 | Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsabstractLarge Language Models (LLMs), as common components of modern web application backends and online services, are being widely deployed across various web infrastructures in the .gguf single-file format. This trend exposes their model parameter space to an unprecedented hardware attack surface, such as Bit-Flip attacks (BFA). This paper is the first to systematically discover and validate the existence of single-bit vulnerabilities in LLMs weight files: In the .gguf quantization format of mainstream open-source models (such as DeepSeek, QWEN), flipping a single bit can induce three types of targeted semantic-level faults, respectively-Artificial Flawed Intelligence (outputting factual errors), Artificial Weak Intelligence (catastrophic model failure), and Artificial Bad Intelligence (generating harmful content). By building an information-theoretic weight sensitivity entropy model and a probabilistic heuristic scanning framework called BitSifter, we achieved efficient localization of critical vulnerable bits in models with hundreds of millions of parameters. Furthermore, an end-to-end remote BFA chain was designed, enabling semantic-level attacks in real-world web server deployment scenarios: At an attack frequency of 464.3 times per second, the average time required for the first successful flip of the target bit is 31.7 seconds, without requiring high-cost equipment or complex prompt engineering. This study reveals a critical finding: under relatively modest remote-attack conditions, requiring only conventional network connectivity, flipping a single vulnerable bit within the tensor data segment can cause models deployed in web service environments to autonomously generate extremely malicious responses, such as ''humans should be exterminated'', or produce naturally fluent and difficult-to-detect erroneous replies to ordinary user queries. This demonstrates a pervasive and exploitable security vulnerability in LLMs systems at the fundamental hardware level. Siqi Lu, Zhaoxuan Li, Ziming Zhao 0008, Qingjun Yuan, Yongjuan Wang |
WWW | 6 |
| 2026 | Robust intrusion detection in CPS: A pre-training-based multi-view feature collaboration and correlation analysis method
Qingjun Yuan, Qianwei Meng, Yanbei Zhu, Gang Yu 0005, Xiangbin Wang, Yongjuan Wang |
Comput. Networks | 2 |
| 2026 | Who is the wolf in sheep's clothing? a context-aware trust evaluation model for malicious UAV detection during authentication
Qingjun Yuan, Pinghui Wang, Lidong Li, Yongjuan Wang |
Comput. Networks | 2 |
| 2026 | Traffic burst relational graph attention network combined position encoding for traffic classification
Xi Xiao 0001, Siji Chen, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan |
Comput. Networks | 8 |
| 2026 | Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitationabstractAbstract With the widespread deployment of the lightweight cryptography (LWC) standard Ascon in resource-constrained devices, research on physical attacks against Ascon, especially fault attacks, has made noticeable progress in recent years. Existing fault attacks on Ascon often require substantial fault injections. To address this, we propose scoring functions with multiple distinguishers for statistical ineffective fault analysis (SIFA), statistical effective fault analysis (SEFA), and statistical hybrid fault analysis (SHFA) to recover key bits. In addition, we propose an impossible statistical effective fault analysis (ISEFA) that exploits an impossible event in the fault-induced distribution to directly eliminate incorrect key hypotheses, reducing reliance on complex computations of distinguishers. We conduct extensive simulations and evaluate the number of fault injections, recovery accuracy, success rate, and time overhead across different distinguisher-analysis combinations. The results show that, under SHFA with the GF distinguisher, only 34 fault injections are sufficient to achieve a 99% success rate for recovering a 128-bit key, which is fewer than prior results on Ascon fault analysis. Moreover, we discuss the practical feasibility of the proposed methods and outline two conceptually motivated directions for potential countermeasures. Zhaoxuan Li, Siqi Lu, Qingjun Yuan, Yongjuan Wang |
Cybersecur. | 4 |
| 2026 | Adaptive detection of encrypted malware traffic via fully convolutional masked autoencoders
Jizhe Jia, Meng Shen 0001, Qingjun Yuan, Jing Wang 0150, Haotian He, Liehuang Zhu |
Frontiers Comput. Sci. | 3 |
| 2026 | Enhanced Template Attack Against Dilithium: Leveraging Dual-Loss Feature ExtractionabstractAs a post-quantum digital signature scheme, Dilithium was specifically designed to withstand known quantum algorithm attacks, and its side-channel resistance has garnered significant research attention. However, current side-channel attacks against Dilithium exhibit several limitations: (1) failure to leverage low-correlation characteristics in power traces, (2) loss functions limited to categorical information extraction from power traces, (3) dependency on specific coefficient recovery conditions while neglecting inter-coefficient statistical dependencies, (4) requirement for separate profiling models per intermediate value, resulting in substantial information loss. To address these limitations, we propose an enhanced template attack framework integrating deep learning with classical template attack methodology. Our approach employs a dual-loss similarity learning mechanism for feature extraction from high-dimensional power traces, enabling the construction of more discriminative templates while preserving weakly correlated features. Through assembly-level analysis of the y polynomial generation routine, we reveal inherent correlations among coefficientsyk0,yk1,yk2,yk3. Building on this discovery, our dual-loss similarity learning framework is designed to capture these inter-coefficient relationships, preserving their intrinsic dependencies while achieving effective inter-class separation and intra-class aggregation properties, which significantly enhances the effectiveness of subsequent template attacks. Experimental results on Cortex-M4 power traces demonstrate our method achieves 32.94% polynomial coefficient recovery accuracy for polynomial coefficients y, outperforming conventional SOD-based (83% improvement), T-Test-based (97%), and PCA-based template attacks (197% enhancement). Furthermore, complete private key recovery is achieved with merely 14 power traces under specific conditions. This DL-enhanced template attack framework demonstrates superior side-channel leakage exploitation, yielding substantial performance enhancements over conventional approaches. Haojin Zhang, Qingjun Yuan, Yaoling Ding, An Wang 0001, Hailong Zhang 0001, Haopeng Fan, Siqi Lu, Yongjuan Wang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2026 | When Unknown Threat Meets Label Noise: A Self-Correcting FrameworkabstractNetwork intrusion detection systems (NIDS) are crucial for network management and security. However, in real-world scenarios, NIDS faces two core challenges: (i) label noise, where mislabeled samples in the training data distort the model's decision boundaries; (ii) unknown attack detection, where existing methods struggle to identify novel attack patterns in dynamic attack environments. More critically, these two challenges are interlinked, forming a vicious cycle that continuously degrades the overall reliability of NIDS. Existing research often addresses these issues in isolation, and no method has yet been proposed to coordinate their antagonistic effects systematically. To tackle this open problem, we propose AEGIS-Net for the first time—a dual anti-noise framework based on multi-prototype correction and model-agnostic detection. AEGIS-Net introduces a density-difference-driven multi-prototype competition mechanism, which achieves fine-grained noise label correction through feature space sub-cluster analysis. We also design a distribution-independent k-nearest neighbors detection paradigm, using the corrected compact feature space to determine unknown attacks in open environments. The two modules are collaboratively optimized through a shared encoder, forming a positive cycle of noise suppression and detection enhancement. Extensive experiments on real-world datasets validate the effectiveness of AEGIS-Net in addressing these dual challenges. Notably, under 50% asymmetric noise conditions, AEGIS-Net achieves classification accuracy of 89.02% for known attacks and 98.76% for unknown attack detection on the MAL_TLS2023 dataset. Theoretical proofs and visualization analysis reveal the anti-noise properties of AEGIS-Net under feature space stability constraints. Our code is available athttps://github.com/niebikong/AEGIS-Net. Qianwei Meng, Qingjun Yuan, Pinghui Wang, Siqi Lu, Guangsong Li, Yongjuan Wang, Xiaohong Guan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Two Heads Are Not Better Than One: Continual Learning From Multiple Models for Encrypted Traffic Analysis
Qingjun Yuan, Weina Niu, Jian Chai, Yong Yu 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | An Enhanced and Lightweight Anonymous Authentication Protocol Based on PUF for VANETsabstractWith the rapid advancement of mobile communication technologies, privacy preservation in VANETs has emerged as a pivotal research frontier. Previous authentication protocols often face challenges such as key leakage risks and high computational overhead. Physical Unclonable Functions (PUFs), as a lightweight hardware primitive, offer a promising solution for enhancing security in VANETs. Recently, Xie et al. designed an anonymous authentication protocol for VANETs. Unfortunately, our analysis reveals that their protocol cannot resist ephemeral key leakage attacks. To address these limitations, we propose an enhanced PUF-based anonymous authentication protocol, referred to as iXDZ. Our protocol leverages PUF challenge-response mechanisms to generate real-time vehicle keys, eliminating the need to store long-term keys on vehicles and thereby preventing physical key extraction attacks. Our protocol not only resists ephemeral key leakage attacks but also utilizes the uniqueness, unpredictability, and tamper-resistance of PUF to defend against RSU capture attacks and various physical attacks, meeting the diverse security requirements of VANETs. Furthermore, it is anonymous and lightweight, protecting user privacy and enhancing overall network trust. We rigorously demonstrate the security of iXDZ under the random oracle model and supplement the proof utilizing the Scyther formal analysis tool. Performance evaluations reveal that iXDZ significantly enhances security while reducing computational and communication overhead. Additionally, a case study highlights that iXDZ achieves a 33.3% reduction in execution time compared to the original protocol. Yidan Liu, Xingyun Hu, Yanbei Zhu, Qingjun Yuan, Yongjuan Wang |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2026 | Robust Malicious Traffic Representation Under Instance-Dependent Noise via Entropy Selection and Semisupervised LearningabstractTraffic labeling methods have inherent limitations, including the potential to mislabel hard samples and introduce noisy labels when annotating real-world malicious traffic. Training on such noisy-labeled samples significantly degrades both the training effectiveness and evaluation reliability of malicious traffic detection models. This study proposes MEn2SLe, a method for robust malicious traffic representation under instance-dependent noise (IDN) based on entropy-guided selection and semi-supervised learning. First, an algorithm for constructing traffic datasets with IDN labels is introduced. Subsequently, leveraging the distributional characteristics of IDN, an information entropy-based sample selection strategy is proposed to identify high-confidence samples by analyzing per-sample training stability. To achieve robust representations, MEn2SLe integrates three complementary training strategies: noise label correction, unsupervised inter-class similarity learning, and ground-truth sample contrastive learning. These strategies collectively mitigate the influence of noisy labels and prevent the model from overfitting to label noise. Extensive experiments were conducted to evaluate the performance of MEn2SLe. The results demonstrate that MEn2SLe surpasses baseline methods in both robust training and data pruning tasks across IDN, CCN, and SYM noise scenarios. Specifically, MEn2SLe achieves classification accuracies of 90% and 82% on the CIC-IDS-2017 and Malicious_TLS datasets, respectively, at a 50% noise level, outperforming the best baseline by 13.6% and 9.87%. To further evaluate generalizability, the impact of noisy labels generated by different labeling methods was also assessed. The results confirm that MEn2SLe effectively resists the adverse effects of noise introduced by diverse annotation approaches, demonstrating strong generalization capability. Degang Li, Qingjun Yuan, Xi Chen 0045, Baoquan Liu |
IEEE Trans. Reliab. | 2 |
| 2025 | A Multimodal Asynchronous Federated Learning Approach for Encrypted Traffic Classification
Xiangbin Wang, Qingjun Yuan, Yongjuan Wang |
Inscrypt (2) | 2 |
| 2025 | FCAL: An Asynchronous Federated Contrastive Semi-supervised Learning Approach for Network Traffic Classification
Qingjun Yuan, Weina Niu, Yanbei Zhu, Yongjuan Wang |
ICICS (3) | 2 |
| 2025 | Relational Graph Attention Network Combined with Burst Position Encoding for Traffic ClassificationabstractNetwork traffic classification has become an essential technology for information service providers. While existing methods predominantly focus on packet-level features such as port numbers and payload content, they fundamentally overlook the dynamic interaction patterns revealed by traffic burst sequences and the inherent relational characteristics between consecutive traffic bursts. To overcome the limitation of existing methods, we design a new burst position relational graph attention network (BP-RGAT) for traffic classification. We introduce the Heterogeneous Traffic Burst Graph (HTBG) to obtain more traffic interaction information. We also incorporate Relative Traffic Burst Position Encoding (RBPE) to capture sequence information between bursts. To evaluate the performance of BPRGAT, we conduct experiments with ISCX-VPN and USTC-TFC datasets. The results show that BP-RGAT achieves the highest F1 score compared to existing baseline methods (e.g. NetMamba, ET-BERT, BehavSniffer, TFE-GNN). Siji Chen, Xi Xiao 0001, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan, Dengpan Ye |
IWQoS | 7 |
| 2025 | FATFI: A Framework to Generate Adversarial Traffic with Feature Interpretability
Yikang Wang, Weina Niu, Dujuan Gu, Qingjun Yuan, Jiacheng Gong, Shuangqi Gan, Xiaosong Zhang 0001 |
KSEM (3) | 4 |
| 2025 | AECR: Automatic attack technique intelligence extraction based on fine-tuned large language model
Minghao Chen 0003, Kaijie Zhu, Qingjun Yuan, Yuefei Zhu |
Comput. Secur. | 5 |
| 2025 | A fine-grained message clustering method based on message representation and identifier fingerprints
Degang Li, Xi Chen 0045, Mingliang Zhu, Qingjun Yuan |
Comput. Secur. | 4 |
| 2025 | Adaptive header identification and unsupervised clustering strategy for enhanced protocol reverse engineering
Mingliang Zhu, Xieli Zhang, Qingjun Yuan, Mengcheng Ju, Guanping Zhang, Xi Chen 0045 |
Expert Syst. Appl. | 4 |
| 2025 | Beyond known threats: A novel strategy for isolating and detecting unknown malicious traffic
Qianwei Meng, Qingjun Yuan, Xiangbin Wang, Yongjuan Wang, Guangsong Li, Yanbei Zhu, Siqi Lu |
J. Inf. Secur. Appl. | 2 |
| 2025 | Evaluation Framework for Smart Contract FuzzersabstractABSTRACT With the widespread application of smart contracts in economics and asset management, the security of smart contracts has been widely addressed by academia and industry. Fuzz is an effective technique for vulnerability detection. Several fuzzers are currently available for smart contracts, how to choose the most appropriate tools to test smart contracts is a problem that needs to be solved. To this end, we propose an evaluation framework for a smart contract fuzzers, which sets eight evaluation indicators from five aspects to comprehensively evaluate the usability, transparency, detection ability, branch coverage, and design of oracle of the smart contract fuzzers. In order to verify the scientificity and rationality of the framework, we selected six state‐of‐the‐art (SOTA) smart contract fuzzers for evaluation. By evaluating the usability of six fuzzers, the level of difficulty in using them was verified; by evaluating the transparency of six fuzzers, the usability of the tool's output information during use was verified; the branch coverage and rationality of oracle design of the six fuzzers was validated by evaluating their detection ability on the dataset. The final evaluation results validated the effectiveness of our proposed framework in guiding users to choose smart contract fuzzers. Peixuan Feng, Yongjuan Wang, Siqi Lu, Qingjun Yuan, Huaiguang Wu |
J. Softw. Evol. Process. | 4 |
| 2025 | Multivariate Template Attack Against NTT-Based Polynomial Multiplication of Dilithium
Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Detection of Unknown Attacks Through Encrypted Traffic: A Gaussian Prototype-Aided Variational Autoencoder FrameworkabstractThe identification of encrypted network traffic presents a pivotal challenge in detecting unknown malicious traffic. Unlike closed-set identification, which primarily classifies known traffic classes, detecting unknown malicious traffic necessitates both accurate classification of known traffic and the identification of previously unseen traffic classes. Existing methods often face difficulties in effectively constraining the distribution size of known classes in the representation space and frequently misclassifying unknown classes as known. To address these challenges, we propose Open-Detect, a robust theoretical framework for detecting unknown malicious traffic, which leverages advanced deep learning techniques, such as variational autoencoders and Gaussian prototypes. Open-Detect introduces two primary constraints: a generative constraint, which enhances intra-class compactness, and a discriminative constraint, which optimizes inter-class separation. These constraints collectively mitigate the risks of misclassifying known classes and failing to detect unknown classes. In Open-Detect, network flows are transformed into grayscale images, and each known traffic class is mapped to a unique Gaussian prototype in the latent space. This design ensures tight clustering of samples within the same class and clear separation of samples between different classes. The detection of unknown malicious traffic is performed based on the distance between samples and these prototypes. Extensive experiments conducted on multiple publicly available datasets substantiate the efficacy of Open-Detect. The results reveal significant improvements in intra-class compactness and inter-class separation, enabling superior performance in both closed-world and open-world scenarios, particularly for detecting unknown malicious traffic. Our code is available at: https://github.com/niebikong/Open-Detect. Qianwei Meng, Qingjun Yuan, Guangsong Li, Yongjuan Wang, Siqi Lu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | IIT: Accurate Decentralized Application Identification Through Mining Intra- and Inter-Flow RelationshipsabstractIdentifying Decentralized Applications (DApps) from encrypted network traffic plays an important role in areas such as network management and threat detection. However, DApps deployed on the same platform use the same encryption settings, resulting in DApps generating encrypted traffic with great similarity. In addition, existing flow-based methods only consider each flow as an isolated individual and feed it sequentially into the neural network for feature extraction, ignoring other rich information introduced between flows, and therefore the relationship between different flows is not effectively utilized. In this study, we propose a novel encrypted traffic classification model IIT to heterogeneously mine the potential features of intra- and inter-flows, which contain two types of encoders based on the multi-head self-attention mechanism. By combining the complementary intra- and inter-flow perspectives, the entire process of information flow can be more completely understood and described. IIT provides a more complete perspective on network flows, with the intra-flow perspective focusing on information transfer between different packets within a flow, and the inter-flow perspective placing more emphasis on information interaction between different flows. We captured 44 classes of DApps in the real world and evaluated the IIT model on two datasets, including DApps and malicious traffic classification tasks. The results demonstrate that the IIT model achieves a classification accuracy of greater than 97% on the real-world dataset of 44 DApps, outperforming other state-of-the-art methods. In addition, the IIT model exhibits good generalization in the malicious traffic classification task. Qianwei Meng, Qingjun Yuan, Weina Niu, Yongjuan Wang, Siqi Lu, Guangsong Li, Xiangbin Wang, Wenqi He |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Gedss: A Generic Framework to Enhance Model Robustness for Intrusion Detection on Noisy DataabstractTraining a deep neural network-based intrusion detection system requires a large amount of clean labeled data, yet malicious traffic datasets are usually collected from the open-source web community or simulated attack environments, which inevitably contain a large portion of unreliably labeled traffic data. The state-of-the-art methods dealing with label noise combine sample separation and semi-supervised learning (SSL), however, they are hardly usable in the traffic field because traffic data lacks a reasonable data augmentation like image data. To this end, we propose a generic label-noise-resistant framework for malicious traffic detection called Gedss. Unlike previous approaches focusing on data augmentation, our approach improves model performance by enhancing the quality of sample selection and model decision boundaries. The framework contains two parts: sample selection and semi-supervised learning. The sample selection method is presented to divide the original traffic instances into clean ones (labeled set) and noisy ones (unlabeled set). We fit a Jensen-Shannon divergence-based sample prediction loss to a mixture model as the criterion, and the threshold is automatically and dynamically adjusted, which makes our selection mechanism adaptive to various malicious traffic datasets. Besides, a semi-supervised learning method is designed, which uses two networks to jointly predict the pseudo label of the unlabeled set. Considering the class imbalance of divided labeled data, the idea of fine-tuning the models with all data is presented to improve the performance of SSL. Extensive experimental results under different label noise scenarios demonstrate that our approach outperforms state-of-the-art methods. Lingfeng Yao, Anran Hou, Weina Niu, Qingjun Yuan, Junpeng He |
CSCWD | 4 |
| 2024 | A Robust Malicious Traffic Detection Framework with Low-quality Labeled DataabstractDeep learning (DL) techniques have been widely applied in detecting malicious activities from network traffic. However, it is challenging to collect a traffic dataset with sufficient correct labels. The generalization ability of DL-based malicious traffic detection systems decreases when training with mislabeled data. Therefore, several methods have been proposed to detect malicious traffic from low-quality labeled training data. These methods divide noisy and clean samples based on the divergence of their prediction loss. However, this simple criterion is not effective on traffic data due to the obfuscation and redundancy nature of malicious traffic. In this paper, we propose a novel two-stage framework for malicious traffic detection from low-quality training data, which mainly consists of noisy sample filtering and label refinement. Firstly, with the help of the small loss criterion, we filter out most of the noisy samples from training data while ensuring that the filtered dataset covers sufficient clean samples. Next, we introduce a double-constrained similarity rule to provide a comprehensive measure of the similarity between samples and construct a topological graph. Lastly, we exploit the topological relations extracted from this graph to refine the labels based on the neighbor consistency criterion. We validate the effectiveness of our framework with a real-world malicious traffic dataset, achieving an accuracy of 90% even with 80% symmetric noise labels. Additionally, results from the publicly available BoT-IoT dataset demonstrate the adaptability of our framework to Internet of Things (IoT) environments. Lingfeng Yao, Weina Niu, Qingjun Yuan, Beibei Li 0002, Xiaosong Zhang 0001 |
ICC | 3 |
| 2024 | ULDC: Unsupervised Learning-Based Data Cleaning for Malicious Traffic With High NoiseabstractAbstract Since the traffic of novel attacks exceeds current knowledge, realistic traffic labeling methods are prone to mislabeling, which has a significant impact on machine learning-based intrusion detection systems. Data cleaning typically relies on the ability of supervised deep neural networks to learn correct knowledge. Under high noise conditions, noisy labels can affect a supervised network and render it ineffective. To clean traffic datasets under high noise conditions, we propose an unsupervised learning-based data cleaning framework (called ULDC) that does not rely on labels and powerful supervised networks, hence reducing the impact of noisy labels. ULDC evaluates the confidence of observed labels through the distribution and similarity of samples in low dimensions. Moreover, ULDC maximizes the retention of hard samples through adaptive intra-class threshold evaluation, preserving more hard samples for training and improving generalization. In evaluations of ULDC on the CIRA-CIC-DoHBrw-2020 dataset, the percentage of data correction reached more than 75% under high noise, which is better than that of the state-of-the-art methods. ULDC is applicable to traffic data cleaning in both traditional networks and novel networks such as the Internet of Things and mobile networks, and it has been validated on datasets including CIC-IDS-2017 and IoT-23. Qingjun Yuan, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang, Bin Luo 0001, Gaopeng Gou |
Comput. J. | 1 |
| 2024 | Combine intra- and inter-flow: A multimodal encrypted traffic classification model driven by diverse features
Xiangbin Wang, Qingjun Yuan, Yongjuan Wang, Gaopeng Gou, Gang Xiong 0001 |
Comput. Networks | 2 |
| 2024 | MMCo: using multimodal deep learning to detect malicious traffic with noisy labels
Qingjun Yuan, Gaopeng Gou, Yuefei Zhu, Yongjuan Wang |
Frontiers Comput. Sci. | 1 |
| 2024 | Screening Least Square Technique Assisted Multivariate Template Attack Against the Random Polynomial Generation of DilithiumabstractIn recent years, the security of Dilithium against side-channel attacks (SCA) has attracted great attentions from the cryptographic engineering community. However, existing power analysis attacks cannot fully utilize the side-channel leakages of the Dilithium reference implementation to efficiently recover the private key. In light of this, a screening least square technique assisted multivariate template attack (SLST assisted MTA) is proposed in this paper. In SLST assisted MTA, side-channel leakages of coefficient$y_{i}$of random polynomial y, unsigned number$x_{i}$and random byte string$a_{i^{\prime }}$can be utilized simultaneously to recover coefficient$y_{i}$of random polynomial y with MTA. Then, one can build error-tolerant equations, and the private key$\mathbf {s_{1}}$can be solved with SLST efficiently. We evaluate the private key recovery efficiency of SLST assisted MTA with real traces measured from the Cortex-M4 processor based Dilithium reference implementation, and the evaluation results show that with MTA, 19.41%, 15.70% and 16.88% of the coefficients of y can be accurately recovered in cases of Dilithium 2, 3 and 5. Besides, using SLST, after five times screening, only 38, 40 and 39 power traces are enough to recover private key$\mathbf {s_{1}}$of Dilithium 2, 3 and 5 with 100% of success rate. Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Yanbei Zhu, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | MCRe: A Unified Framework for Handling Malicious Traffic With Noise Labels Based on Multidimensional Constraint RepresentationabstractDue to the limitations of the existing annotation methods, the prevalence of label noise can be caused in realistic malicious traffic datasets, which has a significant impact on the training and evaluation of deep learning-based intrusion detection models. Recently, various methods have been proposed to deal with noise-containing labeled datasets, and they can be roughly divided into two categories: data cleaning and robust training. However, the different processing ideas lead these two types of methods to ignore the information in different components of the dataset, resulting in a cliff-like drop in performance under high noise conditions. To this end, this study proposes a unified framework for handling noise malicious traffic based on the multidimensional constrained representations named MCRe, which unifies data cleaning and robust training into an ideal representation function approximation. According to the properties of the ideal representation function, information integrity constraints, cluster separability constraints and core proximity constraints are defined to drive MCRe to approximate the ideal representation during iteration. These constraints led MCRe to learn the individual, intra-class, and global levels of distributed knowledge, thus avoiding irrational domain knowledge extraction and ensuring strong label noise robustness of the representation network. We validated MCRe on a dataset that includes 22 types of realistic malicious traffic. Experimental results show that MCRe can outperform the state-of-the-art methods in both data cleaning and robust training downstream tasks, achieving 85% pure sample rate and 82% classification accuracy even under the condition of up to 90% noise labels. In addition, the generalizability of MCRe was verified on several public datasets. Finally, MCRe was also well-extended to enhance other data cleaning and robust training approaches. Qingjun Yuan, Gaopeng Gou, Yanbei Zhu, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | DEML: Data-Enhanced Meta-Learning Method for IoT APT Traffic Detection
Weina Niu, Qingjun Yuan, Lingfeng Yao, Junpeng He, Xiaosong Zhang 0001 |
ICDF2C (1) | 3 |
| 2023 | BoAu: Malicious traffic detection with noise labels based on boundary augmentation
Qingjun Yuan, Chang Liu 0049, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang, Gaopeng Gou |
Comput. Secur. | 1 |
| 2021 | Information Security Field Event Detection Technology Based on SAtt-LSTMabstractDetecting information security events from multimodal data can help analyze the evolution of events in the security field. The Tree-LSTM network that introduces the self-attention mechanism was used to construct the sentence-vectorized representation model (SAtt-LSTM: Tree-LSTM with self-attention) and then classify the candidate event sentences through the representation results of the SAtt-LSTM model to obtain the event of the candidate event sentence types. Event detection using sentence classification methods can solve the problem of error cascade based on pipeline methods, and the problem of CNN or RNN cannot make full use of the syntactic information of candidate event sentences in methods based on joint learning. The paper treats the event detection task as a sentence classification task. In order to verify the effectiveness and superiority of the method in this paper, the DuEE data set was used for experimental verification. Experimental results show that this model has better performance than methods that use chain structure LSTM, CNN, or only Tree-LSTM. Qingjun Yuan, Mianzhu Yi, Sen An |
Secur. Commun. Networks | 3 |
| 2016 | DrugE-Rank: improving drug-target interaction prediction of new candidate drugs or targets by ensemble learning to rankabstractMOTIVATION: Identifying drug-target interactions is an important task in drug discovery. To reduce heavy time and financial cost in experimental way, many computational approaches have been proposed. Although these approaches have used many different principles, their performance is far from satisfactory, especially in predicting drug-target interactions of new candidate drugs or targets. METHODS: Approaches based on machine learning for this problem can be divided into two types: feature-based and similarity-based methods. Learning to rank is the most powerful technique in the feature-based methods. Similarity-based methods are well accepted, due to their idea of connecting the chemical and genomic spaces, represented by drug and target similarities, respectively. We propose a new method, DrugE-Rank, to improve the prediction performance by nicely combining the advantages of the two different types of methods. That is, DrugE-Rank uses LTR, for which multiple well-known similarity-based methods can be used as components of ensemble learning. RESULTS: The performance of DrugE-Rank is thoroughly examined by three main experiments using data from DrugBank: (i) cross-validation on FDA (US Food and Drug Administration) approved drugs before March 2014; (ii) independent test on FDA approved drugs after March 2014; and (iii) independent test on FDA experimental drugs. Experimental results show that DrugE-Rank outperforms competing methods significantly, especially achieving more than 30% improvement in Area under Prediction Recall curve for FDA approved new drugs and FDA experimental drugs. AVAILABILITY: http://datamining-iip.fudan.edu.cn/service/DrugE-Rank CONTACT: [email protected] SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Qingjun Yuan, Junning Gao, Dongliang Wu, Hiroshi Mamitsuka, Shanfeng Zhu |
Bioinform. | 1 |