Bingxu Wang

dblp:183/2100 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 HDFG: Ethereum Smart Contract Honeypot Detection Based on Pre-Training Techniques
abstract
In recent years, a new fraud method, namely smart contract honeypots, has emerged on the famous blockchain platform Ethereum. The difference from smart contract vulnerabilities is that the contract honeypot essentially has no vulnerabilities, luring victims to call in a seemingly vulnerable form. However, the victims ultimately cannot obtain the desired benefits and will lose certain funds. Deep learning algorithms are preferred among current contract honeypot detection methods because they can learn more general characteristics and do not rely on expert experience. Most previous works use natural language models to learn the opcodes of contract honeypots but overlook the relevant structural features of the source code. We propose a novel method called the Smart Contract Honey-pot Data Flow Graph, which utilizes a data flow graph to extract the calling relationships of critical source code within contract honeypots and employs a pre-trained model for representation learning. First, contract honeypots generally have a code that transfers money to the calling address, which is critical information for constructing a source code data flow graph. Then, the pre-trained model is used to learn the source code representation and perform downstream classification tasks. The F1-score of our model significantly outperforms the state-of-the-art approaches in the contract honeypot classification task and is close to the highest performance in the detection task. In addition, this model is an end-to-end model that can detect unknown-type contract honeypots.
Jiaying Song, Zhen Li 0011, Yingchao Qin, Bingxu Wang, Gang Xiong 0001, Hanwen Miao
CSCWD4
2024 HoneyRank: A Low-Cost Discovering Method of 0-Day Ethereum Smart Contract Honeypots
abstract
One attack method that actively deploys smart contract honeypots has recently become popular. A contract honeypot is a smart contract that pretends to have vulnerabilities, enticing victims who call the contract to lose funds. However, previous works detected contract honeypots by individual characteristics, such as codes and ledger details. They overlooked the connection between the two parties in the transaction. Therefore, we propose the HoneyRank algorithm, which uses known honeypots as initial seeds to construct a contract honeypot transaction relationship network (HoneyNet) and source code text similarity detection to discover 0-day honeypots that previous work missed in the same detected block height range. This low-cost method detects only a few highly suspicious smart contracts and does not require machine learning training. Specifically, we trace transaction history data to collect the accounts and relationships of honeypot seeds, attackers, and victims and construct a HoneyNet. Based on transaction behavior inference, we label and calculate the source code similarity between high-risk smart contracts and ground truth honeypots. Finally, we select the high-similarity smart contracts to confirm honeypots manually. Besides, we analyze the criminal associations in a HoneyNet. As far as we know, we are the first to construct a HoneyNet and use it to find new honeypots. These honeypots visually reveal the potential connections between the attackers (creators of the honeypot) and the victims. We discovered 54 0-day honeypots never found by previous methods and mined 11 attacker communities composed of attackers and puppet accounts for the first time.
Jiaying Song, Zhen Li 0011, Gaopeng Gou, Bingxu Wang, Gang Xiong 0001, Yingchao Qin
MSN4
2024 OSN Bots Traffic Transformer : MAE-Based Multimodal Social Bots Behavior Pattern Mining
abstract
In recent years, online social networks (OSN) have rapidly gained popularity worldwide, becoming important platforms for information dissemination. Cyber manipulators use OSN bots to disseminate harmful information and manipulate public opinion, which can engage in cyber violence and conduct financial crimes. Therefore, it is crucial to propose an effective detection solution for OSN bots as a matter of urgency. Different OSN bots exhibit distinct behavioral patterns compared to regular users due to varying behavioral preferences. Analyzing network behavior patterns can reveal the fundamental rules and anomalies of OSN bots, providing support for effective detection in order to gather evidence of any illegal activities. Traditional social bot detection methods based on user profiles or social relationships pose risks of infringing on user privacy. Therefore, we propose a new detection framework for OSN bots——OBTT model, which demonstrates significant advantages in identifying bot traffic to OSN and discovering behavior patterns of different types of bots. OBTT adopts a multimodal approach, integrating graph embeddings from raw traffic with sequential features, while incorporating temporal information to explore the regularities in bot action sequences. Using large-scale unlabeled data, we pretrain a Masked Autoencoder (MAE) and fine-tune it with a small amount of labeled data to enhance the model capacity to detect various bot behavior patterns. Experiments conducted on our OSNBotTraffic5 dataset show that OBTT achieved an accuracy of 0.95, demonstrating excellent performance. Notably, this is the first time that different OSN bot behavior patterns have been identified in quasi-real time from the perspective of network traffic.
Haonan Zhai, Ruiqi Liang, Zhen Li 0011, Bingxu Wang, Qingya Yang
TrustCom6
2024 Incremental encrypted traffic classification via contrastive prototype networks
Wei Cai 0007, Chengshang Hou, Mingxin Cui, Bingxu Wang, Gang Xiong 0001, Gaopeng Gou
Comput. Networks4
2024 MSG-Voxel-GAN: multi-scale gradient voxel GAN for 3D object generation
Bingxu Wang, Jinhui Lan
Multim. Tools Appl.1
2023 Identifying DoH Tunnel Traffic Using Core Feathers and Machine Learning Method
abstract
DNS protocol is a plaintext domain name resolution protocol, which has the risk of privacy disclosure. DNS over HTTPS (DOH) protocol is designed to encrypt DNS traffic, which solves the privacy problem. However, many network attackers use the DOH tunnel for malicious transmission. From the passive traffic, there is no obvious difference between normal DOH traffic and DOH tunnel traffic, which brings great challenges to identify them. At present, researches mainly focus on the plaintext DNS covert tunnel, but less on the encrypted DOH tunnel. In this paper, we propose DOH covert tunnel detection method based on core features and machine learning method using two steps. Firstly, we detect DOH traffic according to the threshold of features. On this basis, we use core features and machine learning methods to detect tunnel traffic in all DOH traffic. Finally, we use self collected and public datasets to verify our method. The results show that the method achieves up to 99 % precision and recall that is superior to state of the art method.
Bingxu Wang, Gang Xiong 0001, Gaopeng Gou, Jiaying Song, Zhen Li 0011, Qingya Yang
CSCWD1
2023 A Recurrent Self-learning Labeler for Building Network Traffic Ground Truth
abstract
With the increasing number of traffic category, machine learning-based methods have gradually become the mainstream way of traffic classification to support network security and management. Machine learning-based methods require a large amount of high quality labelled data to learn network behavior patterns to achieve better recognition results. In the field of network traffic labeling, manual labeling can achieve more accurate labeling results, but the labeling efficiency is low and the labor cost is high. Deep packet inspection (DPI) technology can greatly improve labeling efficiency and reduce labor costs, but DPI labeling suffers from the problem of inaccurate and incomplete labeling. In this paper, we propose a recurrent self-learning framework (RSL-Labeler) for traffic labeling, which can solve the problem of inaccurate and incomplete DPI labeling. This framework consists of three components: high-quality data generation, class behavior pattern learning, and confidence filtering. Based on high-quality data labeled by multiple DPIs, we build three classifiers to learn the behavior patterns of DPI labeling intelligently from three perspectives. Then, we propose the idea of confidence filtering, which combines the pseudo-labeled data and the confidence values of three learning models to filter the credible samples by combined voting. These samples are added to the self-learning model for recurrent training. Experiments show that our method is able to label application traffic with accuracy of 99%, which is at least 8% better than single DPI.
Qingya Yang, Chang Liu 0049, Peipei Fu, Bingxu Wang, Gaopeng Gou, Gang Xiong 0001
CSCWD4
2023 Multi-Feature Fusion Based Approach for Classifying Encrypted Mobile Application Traffic
abstract
With rapid development of mobile Internet, a great number of mobile applications has emerged, presenting a great explosion in mobile Internet traffic. Therefore, accurate classification of application traffic is necessary to more effectively manage mobile Internet traffic. However, the encryption of mobile application traffic gradually eliminates traditional classification approaches based on specific signatures, greatly increasing the difficulty of the classification of mobile application traffic. Therefore, we propose a novel multi-feature fusion (MFF)- based approach to enhance the accuracy of mobile application traffic classification. We also extract packet length sequence, byte sequence, statistical feature, etc. Then, we perform weighted fusions of features based on Relief-F algorithm to achieve the best set of features. Finally, we use machine learning techniques for application classification. Compared to several other feature extraction methods, MFF achieves an excellent performance with an accuracy of 97.6% for 16 mobile applications and a F1-score of over 99% for VPN-nonVPN.
Qingya Yang, Peipei Fu, Junzheng Shi, Bingxu Wang, Zhen Li 0011, Gang Xiong 0001
CSCWD4
2022 SDANet: spatial deep attention-based for point cloud classification and segmentation
Jiangjiang Gao, Jinhui Lan, Bingxu Wang
Mach. Learn.3
2021 Towards Multi-source Extension: A Multi-classification Method Based on Sampled NetFlow Records
abstract
With the rapid development of the Internet, network traffic is growing explosively. It brings great challenges to the traditional traffic identification technology using full traffic analysis, which requires more resources to achieve the collection and analysis of full traffic. And, handling the raw traffic may lead to the compromise of user privacy. NetFlow has good compatibility with the existing routing or switching devices, can aggregate network traffic information, support traffic sampling, reduce the invasion of user privacy, and can effectively deal with the challenges. However, as NetFlow is usually output after traffic sampling to ensure the performance of network devices and only contains session-level statistical information, existing NetFlow research mostly focuses on the binary classification problems (e.g., specific anomaly traffic detection), and less exploration has been conducted on traffic multi-classification problems. And NetFlow is even less involved in the currently popular field of encrypted traffic classification. In this paper, we focus on how to perform encrypted traffic multi-classification research based on sampled NetFlow records and propose a multi-classification method based on the multi-source extension of sampled NetFlow records. To improve the distinguishability and applicability of the sampled NetFlow records, we extend and enrich the records with full consideration of the head or payload information in traffic data, including TTL values, Cipher Suites, etc. For different application scenarios, the methods based on head information extension and payload information extension are proposed, respectively. Through comprehensive experiments, the results show that the proposed method is more applicable and effective than the method based on a single N etFlow record in dealing with multi-classification problems in different encryption application scenarios.
Peipei Fu, Qingya Yang, Yangyang Guan, Bingxu Wang, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001
TrustCom4
2020 Stability analysis of a SAIR rumor spreading model with control strategies in online social networks
Linhe Zhu, Bingxu Wang
Inf. Sci.2