VLDB 2026 Research / reviewers in the wild / expert
Leiqi Wang
dblp:199/7541
· DBLP profile ↗
13ranked-venue papers
3as first author
13since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LLMs driven fusion AI-AD system for mechanical design: From understanding to generation
Leiqi Wang, Lexiang Gu, Yaning Xu, Qianqian Cai, Zhou Gang |
Adv. Eng. Informatics | 3 |
| 2024 | Q-learning Assisted LASSO-based Thermal Sensor Placement for Thermal-aware Multi-core SystemsabstractThermal problems become severe in contemporary multi-core systems because of the complicated workload and high power density. The problems impact the system performance and damage the system reliability. The practical way to monitor the system temperature is to place number-limited thermal sensors on multi-core systems. Unfortunately, finding proper locations for thermal sensor placement is an NP-hard problem. Many pieces of research proposed methods to allocate number-limited thermal sensors under different perspectives. However, the conventional methods still do not consider the time-varying temperature distribution or the correlation between different thermal hotspot points. To solve these problems, we apply the Q-learning method to assist with thermal sensor placements determined by the Least Absolute Shrinkage and Selection Operator (LASSO) theory. While LASSO primarily excels in feature selection, Q-learning is better equipped to handle dynamic environmental changes and interdependencies. Thus, we employ the Q-learning method to formulate a precise cost function for accurately estimating the outcomes following the placement of a thermal sensor at a specific location. Compared with the state-of-the-art, our proposed methods, using both the LASSO-based method and the Q-learning Assisted LASSO method, reduce the average errors by 67%-85% and 69%-87%, respectively, and the maximum errors by 80%-92% and 82%-93%. Kun-Chih Chen, Leiqi Wang |
ISCAS | 2 |
| 2023 | GHunter: A Fast Subgraph Matching Method for Threat HuntingabstractThreat hunting is the process of proactively searching for known attack behavior in an organization’s information system. A popular approach to threat hunting uses cyber threat intelligence (CTI) to identify advanced persistent threats (APTs) that are hidden in kernel-level audit logs (e.g., whole-system data provenance). However, existing threat hunting mechanisms can-not produce timely results due to the enormous size of provenance data. As a result, threat hunting cannot help sysadmins to quickly recognize an ongoing APT campaign and immediately block any subsequent attack activity. In this paper, we propose GHunter, a system that performs approximate subgraph matching using graph neural networks (GNNs) to quickly and accurately hunt APTs. GHunter first converts known APT scenarios and provenance logs into graph data. Then, GHunter uses GNNs to embed APT scenario graphs and provenance graphs to discover any subgraph relationships. If an APT scenario graph is a subgraph of a provenance graph, GHunter alerts to sysadmins the presence of the corresponding APT scenario in the system. We use DARPA’s Transparent Computing (TC) datasets to evaluate GHunter’s performance. The results show that GHunter achieves 97% accuracy when hunting APTs from millions of provenance log entries and spends 195x less execution time than prior work. Rujie Dai, Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
CSCWD | 3 |
| 2023 | ACG: Attack Classification on Encrypted Network Traffic using Graph Convolution Attention NetworksabstractAttack classification of network traffic is valuable for many security solutions as it points out a clear direction for attack responses. Nowadays, most network traffic is encrypted, which protects user privacy but hides attack traces, further hindering identifying attacks to inspect traffic packages. Machine Learning(ML) methods are widely applied to attack classification on encrypted traffic owing to no need for manual analysis. However, existing studies only concentrate on basic statistical features, which are easily modified, and cannot obtain the crucial attack behaviors hiding in the encrypted traffic. In this paper, we propose an attack classification method, ACG. We create attack graphs to depict interaction behaviors of attack-victim hosts from network traffic containing crucial attack behaviors. Besides, we divide a specific duration for each attack to precisely elaborate attack graphs, where temporal, statistical, and aggregate features are extracted to portray attack behaviors. Finally, we utilize Graph Neural Networks (GNNs) to mine and grasp the crucial behavior patterns from attack graphs to generate fingerprints and classify attacks. Extensive experiments are conducted on three datasets to verify our method. It achieves a precision of 99% in attack classification on encrypted traffic, an average higher than other ML methods of 50%. Leiqi Wang, Qiujian Lv, Yan Wang 0081, Shixiang Zhang, Weiqing Huang |
CSCWD | 1 |
| 2023 | UAG: User Action Graph Based on System Logs for Insider Threat DetectionabstractInsider threats pose significant risks to the network systems of organizations. Users have diverse behavioral habits within an organization, leading to variations in their activity patterns. Hence, data analysis and mining techniques are essential for modeling user behavior. Current methods analyze system logs and extract user action sequence features; however, they overlook the relationships between different actions, reducing detection accuracy. To address this issue, we propose a novel method called UAG (User Action Graph). UAG transforms user actions into a graph representing their chronological order and interrelationships, facilitating a more accurate and comprehensive understanding of user behavior. By extracting global and local features from the user action graph, UAG offers an extensive and detailed perspective of user behaviors. Ultimately, we develop a lightweight ensemble autoencoder model to detect insider threats. Comprehensive experiments demonstrate that UAG delivers outstanding performance and surpasses existing methods. Yan Wang 0081, Qiujian Lv, Leiqi Wang |
ISCC | 5 |
| 2023 | TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks
Leiqi Wang, Xiu Ma, Qiujian Lv, Yan Wang 0081, Weiqing Huang |
Comput. Secur. | 1 |
| 2023 | Adaptive Machine Learning-Based Proactive Thermal Management for NoC SystemsabstractBecause of the high-complex interconnection in contemporary multicore systems, the network-on-chip (NoC) technology has been proven as an efficient way to solve the communication problem in multicore systems. However, the thermal problem becomes the main design challenge in the current NoC systems due to the high-diverse workload distribution and large power density. Therefore, proactive dynamic thermal management (PDTM) is employed as an efficient way to control the system temperature. Based on the predicted temperature information, the PDTM can control the system temperature in advance to reduce the performance impact during the temperature control period. However, conventional temperature prediction models are usually built based on specific physical parameters, which are usually temperature-sensitive. Consequently, the current temperature prediction models still result in significant temperature prediction errors. To solve this problem, a novel adaptive machine learning (ML)-based PDTM is proposed in this work. The adaptive ML-based PDTM first uses an adaptive single layer perceptron (ASLP), which is composed of a single-neuron operation and a least mean square (LMS) adaptive filter technology, to precisely predict the future temperature. Afterward, the proposed adaptive reinforcement learning (RL) is used to find the proper throttling ratio to control the system temperature. In this way, the proposed adaptive ML-based PDTM can adapt to the hyperplane of the temperature behavior of the NoC system and provide a proper temperature control strategy at runtime. Compared with related works, the proposed approach reduces average temperature prediction error by 0.2%–78.0% and improves the system performance by 2.4%–43.0% with smaller hardware overhead. Kun-Chih Chen, Yuan-Hao Liao, Cheng-Ting Chen, Leiqi Wang |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2022 | PEPC: A Deep Parallel Convolutional Neural Network Model with Pre-trained Embeddings for DGA DetectionabstractDiscovering domain generation algorithms (DGAs) used to build command and control (C&C) infrastructures of botnets is crucial for recognizing botnets. Recent studies in DGA detection benefit from deep learning, such as convolutional neural network (CNN) and long short-term memory neural network (LSTM). However, these studies need massive supervised data to train their models, while obtaining enough labeled samples is consistently time-consuming and labor-intensive. In this paper, we propose a deep learning model, called PEPC, to detect and classify DGA domain names with only a small dataset. PEPC consists of two modules: (1) the pre-trained embeddings (PTE) module to quantify domain names to numeric vectors; and (2) the deep parallel convolutional neural networks (DPCNN) module to better extract features of vectors for prediction. Comparing our model with the 5 common deep learning-based DGA detection approaches, results show that our model yields an average improvement of 10 F1 points, while it requires just 30 training samples for each class. Significantly, PTE can help models achieve better detection and classification performances on small training samples. Weiqing Huang, Yangyang Zong, Zhixin Shi, Leiqi Wang, Pengcheng Liu 0007 |
IJCNN | 4 |
| 2022 | CyEvent2vec: Attributed Heterogeneous Information Network based Event Embedding Framework for Cyber Security Events AnalysisabstractRecently, cyber security events have been gathered as a kind of Cyber Threat Intelligence(CTI) to fight against cyber attacks. Developing a cyber events analysis model to predict the possible threats can assist organizations in providing guidance for decision making. A cyber security event is a complete semantic unit containing all the participating objects (such as attacks assets and organizations) with rich attributes (such as the results and variety of the attack). However, existing cyber security events modeling works ignore the attributes of the objects and analyze the objects' relationships independently. To predict the possible threats for the organizations, we propose a cyber events embedding framework CyEvent2vec to model cyber security events with attributes. First, to effectively depict the cyber security events with attributes that happened in organizations, cyber security events are reconstructed by the organization and processed into the events matrices. Second, to explore the intricate relationships between heterogeneous objects in events, the events matrices are fed into the autoencoder model to get the low-dimensional embeddings. Third, to predict the possible threats for the victim organization, we apply the embeddings to two applications to measure the relevance between the objects: organization threats prediction and threat objects classification. Experiments show CyEvent2vec outperforms the other six representation learning methods on three real-world datasets. Xiu Ma, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
IJCNN | 2 |
| 2022 | MMSP: A LSTM Based Framework for Multi-Step Attack Prediction in Mixed ScenariosabstractA multi-step attack scenario consisting of more than one attack step is difficult to predict because of various attack steps and complex combinations. The multi-step attack scenarios occurring simultaneously construct a mixed attack scenario, which is more common than a single attack scenario in practical systems. However, most of the existing multi-step attack prediction approaches only focus on a single attack scenario. In this paper, a framework MMSP is proposed for multi-step attack prediction in mixed scenarios. MMSP fractionates alerts by separating them into different scenarios and removing redundant samples. The attack scenarios fingerprint database of MMSP is built by modeling the attack steps regarding different scenarios based on the long short-term memory (LSTM) model. Each scenario corresponds to an LSTM model. A scenario matching method is also proposed to find potential attack scenarios hiding in the real-time alerts from the database. Finally, MMSP feeds fractionated alerts into the matched scenarios' LSTM models to predict attack steps. Extensive evaluations based on real-world datasets show that MMSP outperforms the state-of-the-art attack step prediction model in both single and mixed scenarios. MMSP achieves a 14.3 % -38.1 % improvement in accuracy for attack step prediction in the single scenario. In particular, MMSP can maintain a high level accuracy in mixed attack scenarios. Degang Sun, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
ISCC | 3 |
| 2022 | DMalNet: Dynamic malware analysis based on API feature engineering and graph learning
Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 4 |
| 2021 | GSketch: A Comprehensive Graph Analytic Approach for Masquerader Detection Based on File Access GraphabstractMasqueraders are a severe insider threat and have become a conventional security issue for most organizations. The majority of existing techniques for detecting masqueraders extract statistical features from file access logs. However, the graph's features from these logs have not been fully explored. In this work, we introduce GSketch. First, it divides each user's file access logs into equal length, non-overlapping time windows. Then file access logs on each time window are transformed into a graph according to chronological order. GSketch extracts global features and local features from the graph. Global features provide a panoramic view of the graph, and local features mine small, induced sub-graphs. Finally, GSketch applies an abnormal detection algorithm to find anomalous points in the feature space and marks these points as masquerader's activities. The effectiveness of GSketch is demonstrated by its excellent performances on two public datasets - WUIL and TWOS. Yan Wang 0081, Qiujian Lv, Meichen Liu, Tingting Wang 0010, Leiqi Wang |
ISCC | 7 |
| 2021 | AOPL: Attention Enhanced Oversampling and Parallel Deep Learning Model for Attack Detection in Imbalanced Network Traffic
Leiqi Wang, Weiqing Huang, Qiujian Lv, Yan Wang 0081 |
WASA (2) | 1 |