Meijie Du

dblp:195/3158 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
14since 2021 · last 2026
0009-0000-9754-9160ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 6 · 2 first-author · 6 since 2021Computer networks · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Dual-Sketch: A Route-Oblivious Framework for Distributed Sparse Superspreader Detection
Meijie Du
IWQoS3
2026 Blazer: Encrypted Video Traffic Identification for Mixed Segment Transmission Pattern based on LLM
abstract
Determining the source of encrypted video traffic is an important task in network regulation. In the context of Dynamic Adaptive Streaming over HTTP (DASH), the newly emerged mixed segment transmission pattern introduces substantial difficulties for fingerprint matching, especially under adverse network conditions. To address these challenges, we propose Blazer, a DASH encrypted video traffic identification method for the mixed segment transmission pattern. First, we design a novel fingerprint that integrates video and audio segment sequences. Then, we extract the traffic fingerprint from the TLS record layer of video traffic. Finally, by observing implicit segment-mixing constraints, we design a targeted prompt and Retrieval Augmented Generation (RAG) that enables Large Language Models (LLMs) to perform fingerprint matching effectively. Across 12 network scenarios, Blazer delivers substantially better performance than the other 4 SOTA methods.
Weitao Tang, Meijie Du, Die Hu 0004, Zhao Li 0010, Rong Yang 0008, Qingyun Liu 0001
ICMR2
2025 Anya: A Novel Video Identification Attack on Media Multiplexing
abstract
Although encryption is widely employed to protect video content during transmission, protocols like DASH can still inadvertently expose critical information about the online video being watched. Attackers can potentially identify the video a user is viewing by analysing undecrypted traffic patterns. Recently, however, popular video platforms like YouTube have updated their streaming technology by utilizing audio-video multiplexing to create dynamic traffic patterns, which significantly reduce the effectiveness of previous attack methods that treat audio and video traffic as separate tracks. In this paper, we are the first to reveal the vulnerabilities about this latest streaming technology and introduce a novel attack approach named Anya. By constraining audio and video timelines, Anya constructs stable audio-video fingerprints and enhances attack accuracy and efficiency through fuzzy searching strategy. Experimental results demonstrate that Anya achieves accuracy of 0.971, 0.933 in ideal and poor network scenarios, with only one minute of traffic eavesdropping time. Finally, we propose defense strategies for streaming platform developers to protect users' privacy.
Meijie Du, Lijuan Zheng, Chenyang Cui, Rong Yang 0008, Qingyun Liu 0001
CSCWD1
2025 Pioneer: Encrypted Video Traffic Identification for Mixed Transmission of Video-Audio Segments
abstract
The spread of harmful content via video has made video traffic identification crucial for network regulation. In the new transmission mode, audio and video segments are mixed to combine into video chunks. However, in poor networks, such combination is unstable, and video chunks may be lost and retransmitted. To address these challenges, this paper proposes Pioneer, an encrypted video traffic identification method for mixed transmission of audio and video segments. We introduce a precise video chunk reconstruction method for video traffic encrypted by both TLS and QUIC. Additionally, we propose Pseudo-Siamese Attention-Convolutional Network (PSACN) to calculate the similarity between traffic and video, leveraging contrastive learning during training to mitigate the impact of poor networks. Pioneer significantly improves accuracy compared with state-of-the-art (SOTA) methods under various network environments. Notably, this is the first study to address this emerging new transmission mode.
Weitao Tang, Taizhong Xu, Meijie Du, Die Hu 0004, Qingyun Liu 0001
ICME3
2024 Zenith: Real-time Identification of DASH Encrypted Video Traffic with Distortion
abstract
Some video traffic carries harmful content, such as hate speech and child abuse, primarily encrypted and transmitted through Dynamic Adaptive Streaming over HTTP (DASH). Promptly identifying and intercepting traffic of harmful videos is crucial in network regulation. However, QUIC is becoming another DASH transport protocol in addition to TCP. On the other hand, complex network environments and diverse playback modes lead to significant distortions in traffic. The issues above have not been effectively addressed. This paper proposes a real-time identification method for DASH encrypted video traffic with distortion, named Zenith. We extract stable video segment sequences under various itags as video fingerprints to tackle resolution changes and propose a method of traffic fingerprint extraction under QUIC and VPN. Subsequently, simulating the sequence matching problem as a natural language problem, we propose Traffic Language Model (TLM), which can effectively address video data loss and retransmission. Finally, we propose a frequency dictionary to accelerate Zenith's speed further. Zenith significantly improves accuracy and speed compared to other SOTA methods in various complex scenarios, especially in QUIC, VPN, automatic resolution, and low bandwidth. Zenith requires traffic for just half a minute of video content to achieve precise identification, demonstrating its real-time effectiveness.
Weitao Tang, Meijie Du, Die Hu 0004, Qingyun Liu 0001
ACM Multimedia3
2024 Fractal: Facilitating Robust Encrypted Traffic Classification Using Data Augmentation and Contrastive Learning
abstract
Encrypted traffic classification using deep learning models based on packet length sequences has shown promising results. However, in real-world network conditions, network-induced phenomena such as packet loss, packet retransmission, and packet disorder are prevalent, leading to a decline in performance. To address this challenge, we propose Fractal, a novel approach designed to enhance existing deep learning models by integrating data augmentation and contrastive learning, thereby facilitating robust encrypted traffic classification under various network conditions. Specifically, Fractal employs three data augmentations to simulate different network conditions, generating diverse packet length sequences from the same flow. Contrastive learning is then leveraged to distill robust features from these augmented sequences. Fractal enables deep learning model to discern the intrinsic patterns of each flow, regardless of the variance in packet length sequences caused by network-induced phenomena. Our comprehensive evaluations demonstrate that Fractal enhances the classification performance of deep learning models under different network conditions, achieving 23% increase in accuracy and 15% improvement in F1-score.
Yitong Cai, Yuyi Liu, Meijie Du, Binxing Fang
SMC5
2024 SCENE: Shape-based Clustering for Enhanced Noise-resilient Encrypted Traffic Classification
abstract
Network traffic classification is critical in network management, quality of service optimization, and security monitoring. However, most existing methods for encrypted traffic classification rely heavily on supervised learning, requiring large amounts of labeled data, and struggle to perform effectively in complex and dynamic network environments. To address these limitations, we propose a novel unsupervised method for encrypted traffic classification, which analyzes byte rate variations to capture traffic behavior patterns. Our approach does not require prior knowledge or large volumes of labeled data, enabling adaptive processing of encrypted traffic in complex network conditions. Specifically, we introduce a noise-resilient shape-line extraction method that preserves core behavioral characteristics of traffic; we design a multidimensional feature extraction strategy that analyzes both uplink and downlink features; and we propose an unsupervised classification algorithm that combines shape-based density clustering with a feature assignment strategy. This algorithm overcomes the limitations of traditional methods, such as the need for predefined cluster numbers, and can classify unknown traffic patterns. We validate our method on five real-world traffic datasets with differing levels of openness, demonstrating its remarkable robustness and accuracy in encrypted traffic classification tasks, thereby greatly enhancing the precision and stability of service classification.
Meijie Du, Mingqi Hu, Zhao Li 0010, Qingyun Liu 0001
TrustCom1
2024 Property graph representation learning for node classification
abstract
Abstract Graph representation learning (graph embedding) has led to breakthrough results in various machine learning graph-based applications such as node classification, link prediction and recommendation. Many real-world graphs can be characterized as the property graphs, because besides the structure information, there exists rich property information related to each node in the graphs. Many existing graph representation learning methods—e.g. random walk-based methods like and , focus only on the structure of graph for learning the node embedding. Although graph representation learning based on neural networks (e.g. typical methods such as ) uses the property of nodes as the initial features of nodes and then aggregates feature information of the neighbours, their limitation is that the neighbourhood of a node is considered to be uniform—i.e. there is no way to differentiate among neighbours of a node when learning a node embedding. Additionally, their definition of neighbourhood is local, i.e. only nodes connected to the current node are considered as neighbours. Hence, those methods fail to capture implicit/latent relationships among nodes, which are implicit in the given structure. In this study, our aim is to improve the performance of graph representation learning methods on property graphs. We present a new framework called ()—a graph representation learning framework to address above-mentioned limitations. Our proposed framework relies on the notion of latent neighbourhood, as well as systematic sampling of neighbouring nodes to obtain better representation of the nodes. The experimental results on five publicly available graph datasets demonstrate that outperforms state-of-the-art baselines for the task of node classification. We further evaluate the superiority of our proposed formulation by defining a novel quantitative metric to measure the usefulness of the sampled neighbourhood in the graph.
Nayyar Abbas Zaidi, Meijie Du, Zhou Zhou 0007, Gang Li 0009
Knowl. Inf. Syst.3
2023 Long-Short Terms Frequency: A Method for Encrypted Video Streaming Identification
abstract
Nowadays, with the vigorous development of self-media services, more and more individual users upload videos freely. While bringing goodness, it also inevitably brings evil. Therefore, it is particularly necessary to identify and supervise illegal videos through network stream. However, many video streaming services, such as YouTube, have applied encryption to protect users’ privacy, which makes it more difficult to analyze network stream. Many researches show that DASH (Dynamic Adaptive Streaming over HTTP) will leak information about video segmentation, which is related to the video content. Consequently, it is possible to analyze the content of encrypted video stream without decryption. Previous studies have proposed a series of encrypted video identification methods based on this. However, most of them need to wait for a long video playback time, such as more than 10s, or even wait for the entire video playback to complete the identification. In this paper, we propose a fast, lightweight, and accurate method named Long-Short Terms Frequency(LSTF) for online encrypted video identification. Experiments have proved that compared with the state-of-the-art, our method has advantages in both speed and accuracy, and even if CDN switching occurs during the video playback, it still has a high identification accuracy.
Meijie Du, Minchao Xu, Kedong Liu, Weitao Tang, Lijuan Zheng, Qingyun Liu 0001
CSCWD1
2023 A Robust and Accurate Encrypted Video Traffic Identification Method via Graph Neural Network
abstract
The explosive growth of video traffic has brought major challenges for network providers to improve user experience. On account of traffic encryption, network providers need to identify encrypted video traffic first before adopting optimization approaches to them. Traditional encrypted video traffic identification methods try to reveal the pattern of video traffic by using statistical features, which are not robust enough in different network environments. Some sophisticated graph-based methods recently have shown their advantages for encrypted traffic identification. However, these works lack optimization when it comes to the video streaming scenario. Inspired by these works, we propose GraphV, a GNN-based approach for identifying encrypted video traffic. Specifically, we construct an information-rich graph structure enhanced by unique features of video transmission. Then the embedding representation of each graph can be obtained through a Bi-LSTM layer added to all the sequential nodes embedding on this graph. The experiments on a well-known dataset and two open-world datasets from different network environments we collected show that GraphV outperforms the existing methods, especially on the generalization ability of the model.
Zhao Li 0010, Jiangchao Chen, Xiaoqing Ma, Meijie Du, Qingyun Liu 0001
CSCWD4
2023 Shrink: Identification of Encrypted Video Traffic Based on QUIC
abstract
With the increasing prevalence of network videos, video traffic has become a significant portion of overall network traffic. Due to the presence of harmful content such as pornography and violence in network videos, network monitoring is necessary. However, the encryption of videos poses challenges for network monitoring. More and more video service providers are adopting QUIC as the default video transmission protocol to accelerate data transfer speeds. However, the existing methods for identifying encrypted video traffic do not apply to QUIC. Video service providers typically employ Content Delivery Network (CDN) technology to enhance user experience, which can result in missing video chunks for side-channel identification. Additionally, fluctuations in network conditions can lead to the retransmission of video chunks. This paper proposes Shrink, a QUIC-based encrypted video traffic identification method. It effectively extracts video chunks from online QUIC encrypted video traffic and proposes a bucket structure and global-local match to alleviate the issues of video chunks retransmission and loss. Furthermore, a bucket word dictionary is designed to enhance the method’s running speed. Experimental results demonstrate that Shrink performs well in real network environments, exhibiting superior accuracy and speed compared to existing state-of-the-art methods.
Weitao Tang, Meijie Du, Zhao Li 0010, Zhou Zhou 0007, Qingyun Liu 0001
IPCCC2
2022 GraphDDoS: Effective DDoS Attack Detection Using Graph Neural Networks
abstract
Distributed Denial of Service (DDoS) attacks have occurred frequently in recent years, causing massive damage. It is critical to detect DDoS attacks fast and accurately. Previous Deep Learning (DL) methods for detecting DDoS attacks barely leverage the relationships between packets and between flows in traffic, which are crucial information that can significantly improve detection performance. This paper proposes GraphDDoS, a GNN-based approach for detecting DDoS attacks using endpoint traffic graphs. Concretely, we convert traffic into endpoint traffic graphs, containing information of packets’ relationships (structure of a single flow) and flows’ relationships (burst information and periodic information of multiple flows). Then, converted endpoint traffic graphs are sent to the GNN classifier to learn DDoS attack patterns accurately. The experiments with well-known datasets show that GraphDDoS outperforms the state-of-the-art DL-based approaches. The effectiveness is mainly introduced by the capability of GraphDDoS to learn patterns of attacks structured as graphs.
Zhou Zhou 0007, Meijie Du, Qingyun Liu 0001
CSCWD6
2022 Node-Imbalance Learning on Heterogeneous Graph for Pirated Video Website Detection
abstract
With the rapid development of video streaming, the problem of copyright infringement has become increasingly severe. Despite its explicit illegality in many countries, a large variety of pirated video websites are still active, causing huge damage to copyright holders and security risks to users. Traditional methods for detecting malicious websites, such as blacklists or feature-based classifiers, can be easily bypassed by evading approaches like Domain-Flux. Some researchers recently proposed sophisticated graph-based methods to utilize various relations between websites and convert the detection task into node representation learning. However, the node imbalance issue impairs their performance on real-world datasets. In this paper, given the limitations of the above methods, we propose a model named Heterogeneous Graph Node Re-weighting (HGNR) to detect pirated video websites. We construct a heterogeneous graph with diverse meta relations and design a weight adjustment mechanism to deal with node imbalance issue. The experiments with different imbalance ratios show that HGNR outperforms state-of-the-art graph-based methods. Furthermore, we analyze the best-performed meta relation and disclose how video pirates gain profits, which can help the security community thwart video piracy.
Jiangyi Yin, Zhao Li 0010, Rong Yang 0008, Meijie Du
CSCWD5
2022 Fighting Against Piracy: An Approach to Detect Pirated Video Websites Enhanced by Third-party Services
abstract
Along with the development of video streaming, the increasing number of pirated video websites has caused unprecedented damage to copyright holders and potential security risks to their users. Though many efforts have been made to take down pirated video websites, they are still emerging by utilizing evading approaches like Fast-Flux domains and Cybercrime-as-a-Service(CaaS) tools. In this paper, to detect pirated video websites, we propose a Third-party Enhanced Pirated Video Website Classification Network (TEP-Net), which integrates both semantic features and relationship information between websites and their third-party services. More specifically, we apply CNN-BiLSTM-Attention to explore both character-level and domain-level textual embedding and utilize relationship information by constructing statistical features in classification. The experiment shows that TEP-Net achieves a significant performance compared with existing methods. Furthermore, we perform an in-depth analysis of the CaaS behind pirated video websites. Our research can help the security community fight against video piracy more precisely and effectively.
Zhao Li 0010, Jiangyi Yin, Meijie Du, Qingyun Liu 0001
ISCC4