VLDB 2026 Research / reviewers in the wild / expert
Jing Qiu 0002
dblp:20/1461-2
· DBLP profile ↗
37ranked-venue papers
3as first author
26since 2021 · last 2026
0000-0003-4202-7802ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 1 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 2 first-author · 6 since 2021Security and privacy · 5 · 5 since 2021Databases, data management, data science and information retrieval · 5 · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Scalable logical attack graph generation for enterprise networks through endpoint data
Chengliang Gao, Jing Qiu 0002, Du Cheng, Lihua Yin |
Comput. Secur. | 2 |
| 2026 | DynAssetRank: Real-Time Dynamic Risk Assessment for Network Threat Prediction With ATT&CK Modeling
Ximing Chen 0004, Xilong He, Lichen Nong, Jing Qiu 0002, Du Cheng, Lejun Zhang, Lihua Yin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Large-Scale Intranet Security Assessment Based on Bayesian Attack Graphs Using System Audit LogsabstractLarge-scale dynamic intranet environments are characterized by constantly changing configurations, evolving user behaviors, and diverse assets that increase vulnerability pathways. These factors undermine the effectiveness of Bayesian attack graphs and reveal the limitations of traditional security methods that rely on static assumptions. To address these challenges, this paper proposes a novel Bayesian attack graph method designed for large-scale, active intranet security assessments. It captures real-time intranet changes by extracting system audit logs and generates attack graphs with MulVAL, ultimately resulting in a time-spanning understanding of potential security risks. Furthermore, it identifies direct-risk paths by eliminating weak dependencies between actions and estimates the likelihood of action execution based on expectations, thereby substantially reducing the computational complexity of Bayesian security analysis. To validate the proposed method, this paper conducts dynamic threat modeling and quantitative security analysis on an enterprise intranet using logs from over 1,000 hosts. The results demonstrate that the proposed method not only provides internal network security risk values at any given time but also identifies specific and observable potential attack paths. Furthermore, this study provides a reference framework for prioritizing vulnerability remediation based on changes in internal network security conditions Chengliang Gao, Jing Qiu 0002, Jiaxu Xing, Ximing Chen 0004, Du Cheng, Lejun Zhang, Tiejun Wu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | A Deep Dynamic Graph Generative Framework for Blockchain Phishing DetectionabstractBlockchain phishing scams cause billions in annual losses, yet extreme data imbalance severely hampers existing detection algorithms. Current dynamic graph generation methods fragment structures and generate erroneous connections, failing to capture local dynamic patterns vital for node classification. This raises critical questions: Can models minimize isolated subgraph generation? How can they learn and replicate structured, recurring interaction patterns? To answer these questions, we introduce GraphFlowGen, an end-to-end deep generative framework. To minimize isolated subgraph generation, GraphFlowGen employs a novel preprocessing module that jointly extracts structural and temporal contexts from transaction data, preventing fragmentation and information loss. To learn and replicate structured interaction patterns, it incorporates a Transformer encoder with Graph Attention Networks (GAT) to capture node connection dynamics and temporal evolution. To ensure high fidelity while reducing erroneous links, a reinforcement learning (RL) mechanism iteratively refines generated graph structures. Empirical validation on three real-world datasets demonstrates the effectiveness of our algorithm in local dynamic graph generation and its utility for downstream phishing detection tasks. Siyi Xiao, Lejun Zhang, Xinwei Zhang 0002, Sen Zhang 0002, Shen Su, Jing Qiu 0002, Haibo Hu 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | 6Global: Dynamic IPv6 Active Address Scanning Assisted by Global PerspectiveabstractNetwork scanning is crucial for both network management and cybersecurity. However, due to the vast address space of IPv6, brute-force scanning is infeasible. Seed-based target generation algorithms have recently attracted considerable research attention. However, existing target generation algorithms lack a deeper exploration of patterns, leading to poor capture of dense regions and consequently low hitrate. To address this issue, we propose 6Global, a dynamic IPv6 active address scanning method assisted by global perspective. 6Global first performs rapid clustering of seed addresses based on their descriptive attributes. Then, for each cluster, patterns are generated in a bottom-up manner based on entropy, using subranges to represent patterns and resulting in denser patterns. Finally, dynamic scanning is conducted using these patterns. During scanning, the reward of each pattern is dynamically adjusted based on its active density and global statistics, which enhances the capability in capturing dense regions. Experimental results on six seed datasets show that 6Global overall outperforms seven baseline methods and demonstrates significant advantages across multiple datasets. Junqing Wang, Lejun Zhang, Zhihong Tian 0001, Kejia Zhang 0002, Shen Su, Jing Qiu 0002, Yanbin Sun |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2025 | A Knowledge Extraction Framework on Cyber Threat Reports with Enhanced Security ProfilesabstractAll known AridViper tools including MICROPSIA Yongxin Cai, Jing Qiu 0002, Fan Zhang 0036, Lei Chen 0002 |
SIGIR | 2 |
| 2025 | From one-one to one-many: ORCA enables scalable and revocable group covert communication on blockchainabstractThe decentralized and immutable nature of blockchainprovides a resilient foundation for covert communication in adversarial and untrusted environments, specifically in scenarios requiring unobservable multi-recipient messaging. Most existing schemes, however, are limited to one-to-one transmission and lack mechanisms to handle untrusted receivers, which constrains their scalability and security. To address these challenges, we propose ORCA (Orthogonal Covert Architecture), a group covert communication framework based on strictly orthogonal, integer-valued codewords. ORCA selects codewords from a Hadamard matrix and applies secret column permutations to ensure decoding isolation and resistance against inference attacks. Each receiver recovers only its assigned message through projection, without coordination or leakage. This encoding structure supports scalable embedding, seamless receiver revocation, and clean integration with standard transaction fields. In contrast to prior work, we analyze the impact of imperfect orthogonality and provide theoretical bounds on decoding interference. Extensive experiments on real-world Bitcoin blockchain data and comparative evaluation against representative covert communication schemes confirm ORCA’s robustness, high embedding capacity, and statistical indistinguishability from normal blockchain activity. These results establish ORCA as a scalable and secure solution for multi-recipient covert communication in adversarial environments. Zhujun Wang 0003, Lejun Zhang, Shen Su, Jing Qiu 0002, Tie Qiu 0001 |
Comput. Networks | 5 |
| 2025 | Pheromone-based graph embedding algorithm for Ethereum phishing detection
Siyi Xiao, Lejun Zhang, Zhihong Tian 0001, Shen Su, Jing Qiu 0002 |
Comput. Networks | 5 |
| 2025 | A blockchain-oriented covert communication technology with controlled security level based on addressing confusion ciphertext
Lejun Zhang, Zhujun Wang 0003, Guopeng Wang, Jing Qiu 0002, Shen Su, Yuan Liu 0002, Guangxia Xu, Zhihong Tian 0001, Sergey Gataullin |
Frontiers Comput. Sci. | 6 |
| 2025 | Unraveling the Deception of Web3 Phishing Scams: Dynamic Multiperspective Cascade Graph Approach for Ethereum Phishing DetectionabstractEthereum, as one of the most active cryptocurrency trading platforms, has garnered significant academic interest due to its transparent and accessible transaction data. In recent years, phishing scams have emerged as a serious criminal activity on Ethereum. Although most studies model Ethereum account transactions as networks and analyze them using traditional machine learning or network representation learning techniques, these approaches often rely solely on the latest static transaction records or use manually designed features while neglecting transaction histories, thus failing to fully capture the dynamic interactions and potential trading patterns between accounts. This article introduces an innovative multiperspective cascaded dynamic graph neural network model named DMPCG, which extracts phishing transaction data from authoritative databases like blockchain explorers to construct transaction network graphs. The model elevates the analysis from the microscopic features of nodes to the macroscopic dynamics of the entire network, integrating the attributes of static snapshot graphs with the evolution of dynamic trading networks, significantly enhancing the accuracy of phishing detection. Experimental results demonstrate that the DMPCG method achieves an impressive precision of 92.6% and an F1-score of 90.9%, outperforming existing baseline models and traditional subgraph sampling techniques. Lejun Zhang, Xucan Zhang, Siyi Xiao, Shen Su, Jing Qiu 0002, Zhihong Tian 0001 |
IEEE Trans. Comput. Soc. Syst. | 6 |
| 2025 | MalFSCIL: A Few-Shot Class-Incremental Learning Approach for Malware DetectionabstractThe continuous evolution of malware is posing a serious threat to personal privacy, enterprise data security, and global network infrastructure. For example, attackers can use phishing emails, botnets, etc. to induce victims to execute malware for nefarious purposes such as stealing sensitive information. Therefore, it is significant to develop effective and efficient methods to detect malware. Towards this, most state-of-the-art methods are focused on learning-based method. In order to adapt to the characteristics of sample scarcity and dynamic evolution of malware detection tasks, few-shot class incremental learning has been proposed as an efficient pairwise solution. Nevertheless, they still face two major challenges: 1) Catastrophic Forgetting: the erosion of existing knowledge by newly acquired knowledge during incremental learning. 2) Decision boundary confusion: after continuous multiple incremental sessions, the discriminative ability of the classification model is weakened. To address the above challenges, we propose a new Malware detection framework based on Few-Shot Class Incremental Learning, MalFSCIL, which utilizes a decoupled training strategy combined with a variational autocoder to mitigate catastrophic forgetting, and designs a dynamic boundary delineation method based on class prototyping to achieve accurate delineation of incremental decision boundaries. Extensive experimental results show that the proposed method outperforms the state-of-the-art techniques in malware detection and classification with high classification accuracy with open-source dataset and Internal enterprise dataset. Yuhan Chai, Ximing Chen 0004, Jing Qiu 0002, Yanjun Xiao 0001, Qiying Feng, Shouling Ji, Zhihong Tian 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | FedGA: A greedy approach to enhance federated learning with Non-IID data
Yue Cong, Yuxiang Zeng, Jing Qiu 0002, Zhongyang Fang, Lejun Zhang, Du Cheng, Zhihong Tian 0001 |
Knowl. Based Syst. | 3 |
| 2024 | Deep Learning and Dempster-Shafer Theory Based Insider Threat Detection
Zhihong Tian 0001, Wei Shi 0001, Zhiyuan Tan 0001, Jing Qiu 0002, Yanbin Sun, Feng Jiang 0001, Yan Liu 0014 |
Mob. Networks Appl. | 4 |
| 2024 | PANNER: POS-Aware Nested Named Entity Recognition Through Heterogeneous Graph Neural NetworkabstractNested named entity recognition (Nested NER) in knowledge graph (KG) aims at obtaining all meaningful entities, including nested entities for sentences in longer text region. Those obtained entities are to facilitate downstream applications, such as relation extraction, entity resolution, and coreference resolution. This task, however, is challenging not only because of the demand to detect the boundary of the entity but also due to the complexity of those hierarchically nested entities. Since a substantial amount of work has been made to Flat NER (or Nested NER), a few of them can explicitly acquire the position of the entity and utilize the grammatical construction of text. In this work, we propose PANNER, a POS-aware Nested NER model, to solve all the above issues. Specifically, we first construct a heterogeneous graph by introducing the part-of-speech (POS) information of the word. Second, we design a dilated random walk (DRW) algorithm based on a grammatical path to sample a fixed size of neighbors for each node. Third, we aggregate the message from different types of neighbors through an attention mechanism. Finally, we use a bidirectional decoding module to recognize and categorize all the flat and nested entities based on the node embedding in a layer-wise manner. Our extensive experiments show the effectiveness of PANNER in both flat and nested NER. Jianming Li, Zhaoquan Gu, Jing Qiu 0002, Brij B. Gupta, Zhihong Tian 0001 |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | ThreatInsight: Innovating Early Threat Detection Through Threat-Intelligence-Driven Analysis and AttributionabstractThe complexity and ongoing evolution of Advanced Persistent Threats (APTs) compromise the efficacy of conventional cybersecurity measures. Firewalls, intrusion detection systems, and antivirus software, which are dependent on static rules and predefined signatures, are increasingly ineffective against these sophisticated threats. Moreover, the use of system audit logs for threat hunting involves a retrospective review of cybersecurity incidents to reconstruct attack paths for attribution, which affects the timeliness and effectiveness of threat detection and response. Even when the attacker is identified, this method does not prevent cyber attacks. To address these challenges, we introduce ThreatInsight, a novel early-stage threat detection solution that minimizes reliance on system audit logs. ThreatInsight detects potential threats by analyzing IPs captured from HoneyPoints. These IPs are processed through threat data mining and threat feature modeling. By employing fact-based and semantic reasoning techniques based on the APT Threat Intelligence Knowledge Graph (APT-TI-KG), ThreatInsight identifies and attributes attackers. The system generates analysis reports detailing the threat knowledge concerning IPs and attributed attackers, equipping analysts with actionable insights and defense strategies. The system architecture includes modules for HoneyPoint IP extraction, Threat Intelligence (TI) data analysis, attacker attribution, and analysis report generation. ThreatInsight facilitates real-time analysis and the identification of potential threats at early stages, thereby enhancing the early detection capabilities of cybersecurity defense systems and improving overall threat detection and proactive defense effectiveness. Yinghai Zhou, Hao Liu 0058, Jing Qiu 0002, Binxing Fang, Zhihong Tian 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2023 | Smart Contract Firewall: Protecting the on-Chain Smart Contract ProjectsabstractThe burgeoning landscape of blockchain technology has made the security of deployed smart contracts an imperative concern. While existing security measures excel in pre-deployment testing, they fall short in protecting smart contracts once they are deployed, leaving them susceptible to malicious attacks. In this paper, we propose a novel Smart Contract Firewall framework designed to bridge this security gap. Functioning as a dynamic gateway, the framework employs real-time transaction inspection through adaptable filtering rules, enabling the identification and rollback of malicious transactions as they occur. Our empirical analysis demonstrates the framework's efficacy in mitigating a majority of existing vulnerabilities in the deployed smart contracts. Although the added layer of security comes at a cost, we prove that the increased gas expenses could be limited to 30 % -50 % for most transactions. This trade-off, we argue, is a small price to pay for significantly enhanced security. Shen Su, Yue Xue, Liansheng Lin, Hui Lu 0005, Jing Qiu 0002, Yanbin Sun, Yuan Liu 0002, Zhihong Tian 0001 |
GLOBECOM | 6 |
| 2023 | Improving Precision of Detecting Deserialization Vulnerabilities with Bytecode AnalysisabstractTraditional static taint analysis based on bytecode analysis such as GadgetInspector to detect deserialization vulnerabilities always faced precision problems. For example, missing the fact that taints flowing to members in called methods, type confusion, and chaotic inheritance relationships when detecting deserialization vulnerabilities, which would lead to many error results. To alleviate these problems, this paper considers three measures of improving precision of detecting deserialization vulnerabilities, including cross-function members data flow tracking, local variables and arguments types inference, and call chain subject inference based on inheritance relationships. Weicheng Li, Hui Lu 0005, Yanbin Sun, Shen Su, Jing Qiu 0002, Zhihong Tian 0001 |
IWQoS | 5 |
| 2023 | A covert channel over blockchain based on label tree without long waiting times
Zhujun Wang 0003, Lejun Zhang, Guopeng Wang, Jing Qiu 0002, Shen Su, Yuan Liu 0002, Guangxia Xu, Zhihong Tian 0001 |
Comput. Networks | 5 |
| 2023 | ASNN-FRR: A traffic-aware neural network for fastest route recommendation
Chaoxiong Wang, Chao Li 0027, Jing Qiu 0002, Jianfeng Qu, Lihua Yin |
GeoInformatica | 4 |
| 2023 | Efficient and Effective Nonconvex Low-Rank Subspace Clustering via SVT-Free OperatorsabstractWith the growing interest in convex and nonconvex low-rank matrix learning problems, the widely used singular value thresholding (SVT) operators associated with rank relaxation functions often face higher computational complexity, particularly for large-scale data matrices. To improve the efficacy of low-rank subspace clustering and overcome the issue of high computational complexity, this work proposes an efficient and effective method that avoids the need for singular value decomposition (SVD) computations in the iteration scheme. This can be achieved through the use of a computationally efficient and compact formulation, as well as automatic removal of the optimal mean, which reduces time consumption and enhances evaluation performance. A unified clustering framework based on Schatten-$p$norm regularized by$\ell _{2,q}$-norm can be formulated using this processing way, where inner element suppression can be achieved by choosing appropriate$p$,$q \in (0,1)$. Additionally, calculating the optimal mean enhances the robustness of the proposed method in the presence of outliers. Unlike the general iteration scheme of the alternating direction method of multiplier (ADMM) algorithms that introduce auxiliary splitting variables, the proposed alternating re-weighted least square (ARwLS) algorithm uses matrix inverse and multiplication computations to obtain analytic solutions, resulting in faster processing speeds for each sub-problem. To further investigate, we provide the computational complexity of each iteration and the theoretical analysis of the convergence property, where the derived solution is a stationary point. Experimental results on synthetic data and several benchmark datasets demonstrate the promising efficiency and efficacy of the proposed clustering method compared to classical and competing algorithms. Hengmin Zhang, Shuyi Li 0003, Jing Qiu 0002, Yang Tang 0001, Jie Wen 0001, Zhiyuan Zha, Bihan Wen |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2023 | Evaluation Mechanism for Decentralized Collaborative Pattern Learning in Heterogeneous Vehicular NetworksabstractCollaborative machine learning, especially Federated Learning (FL), is widely used to build high-quality Machine Learning (ML) models in the Internet of Vehicles (IoV). In this paper, we study the performance evaluation problem in an inherently heterogeneous IoV, where the final models across the network are not identical and are computed on different standards. Previous studies assume that local agents are receiving data from the same phenomenon, and a same final model is fitted to them. However, this “one model fits all” approach leads to a biased performance evaluation of individual agents. We propose a general approach to measure the performance of individual agents, where the common knowledge and correlation between different agents are explored. Experimental results indicate that our evaluation scheme is efficient in these settings. Cheng Qiao, Jing Qiu 0002, Zhiyuan Tan 0001, Geyong Min, Albert Y. Zomaya, Zhihong Tian 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Dynamic Prototype Network Based on Sample Adaptation for Few-Shot Malware DetectionabstractThe continuous increase and spread of malware have caused immeasurable losses to social enterprises and even the country, especially unknown malware. Most existing methods use predefined class samples to train models, which cannot handle unknown malware detection. In this paper, we formalize unknown malware detection as a Few-Shot Learning problem. However, the existing model cannot dynamically adjust the model parameters according to the samples and does not deeply consider the influence of the correlation between samples, so it achieves sub-optimal performance. We propose a Dynamic Prototype Network based on Sample Adaptation for few-shot malware detection (DPNSA). Specifically, we use dynamic convolution to realize dynamic feature extraction based on sample adaptation. Secondly, we define the class feature (prototype) as the mean of the dynamic embedding of all malware samples of each class in the support set. Then, a dual-sample dynamic activation function is proposed, which uses the correlation of the dual-sample to reduce the impact of unrelated features between samples on the metric. Finally, we use the metric-based method to calculate the distance between the query sample and the prototype to realize malware detection. Experiments show that our method outperforms the existing few-shot malware detection models and achieves significant improvement. Yuhan Chai, Jing Qiu 0002, Lihua Yin, Zhihong Tian 0001 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2023 | Super-resolution-based part collaboration network for vehicle re-identification
Jianming Li, Yue Cong, Zhihong Tian 0001, Jing Qiu 0002 |
World Wide Web (WWW) | 5 |
| 2022 | TPRPF: a preserving framework of privacy relations based on adversarial training for texts in big data
Yuhan Chai, Zhe Sun 0005, Jing Qiu 0002, Lihua Yin, Zhihong Tian 0001 |
Frontiers Comput. Sci. | 3 |
| 2022 | From Data and Model Levels: Improve the Performance of Few-Shot Malware ClassificationabstractExisting malware classification methods cannot handle the open-ended growth of new or unknown malware well because it only focuses on pre-defined malware classes with sufficient training data. Due to the superiority of the visualization method, some researchers use it for solving few-shot malware classification. However, the malware images generated by existing visualization methods contain insufficient semantic information. At the same time, existing few-shot models tend to converge to sharp minima resulting in poor generalization performance. By synthesizing the observations, we think that accurate and effective few-shot malware classification methods are affected by generated malware images and classification models, which can be called data and model levels, respectively. To solve the above problems, we propose a novel method from the Data and Model levels, which is used to classify new or unknown malware well, called DMMal. More specifically, we propose a multi-channel malware image generation method based on multi-view so that malware images can contain more prosperous information at the data level. In addition, we investigated adaptive sharpness-aware minimization in a few-shot scenario from the perspective of model optimization at the model level to minimize the loss value and sharpness simultaneously. This enhances the generalization ability of the model and improves the ability of the model to classify new or unknown classes. Experiments on two few-shot malware classification datasets show that the method proposed can improve the performance of few-shot malware classification from the data and model levels. Yuhan Chai, Jing Qiu 0002, Lihua Yin, Lejun Zhang, Brij B. Gupta, Zhihong Tian 0001 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | An Efficient Approach for Spatial Trajectory Anonymization
Yuetian Wang, Wen Hua, Fengmei Jin, Jing Qiu 0002, Xiaofang Zhou 0001 |
WISE (1) | 4 |
| 2020 | LGMal: A Joint Framework Based on Local and Global Features for Malware DetectionabstractWith the gradual advancement of smart city construction, various information systems have been widely used in smart cities. In order to obtain huge economic benefits, criminals frequently invade the information system, which leads to the increase of malware. Malware attacks not only seriously infringe on the legitimate rights and interests of users, but also cause huge economic losses. Signature-based malware detection algorithms can only detect known malware, and are susceptible to evasion techniques such as binary obfuscation. Behavior-based malware detection methods can solve this problem well. Although there are some malware behavior analysis works, they may ignore semantic information in the malware API call sequence. In this paper, we design a joint framework based on local and global features for malware detection to solve the problem of network security of smart cities, called LGMal, which combines the stacked convolutional neural network and graph convolutional networks. Specially, the stacked convolutional neural network is used to learn API call sequence information to capture local semantic features and the graph convolutional networks is used to learn API call semantic graph structure information to capture global semantic features. Experiments on Alibaba Cloud Security Malware Detection datasets show that the joint framework gets better results. The experimental results show that the precision is 87.76%, the recall is 88.08%, and the F1-measure is 87.79%. We hope this paper can provide a useful way for malware detection and protect the network security of smart city. Yuhan Chai, Jing Qiu 0002, Shen Su, Chunsheng Zhu, Lihua Yin, Zhihong Tian 0001 |
IWCMC | 2 |
| 2020 | SESM: Emotional Social Semantic and Time Series Analysis of Learners' CommentsabstractHuman comments have become an integral part on evaluating the effectiveness of online courses. Most nature language processing studies consider comments as a composition of statistical texts, which distorts its essence in semantic relation and emotional expression from other disciplines' definition. In order to enlarge its denotation and semantics in cross-discipline perspectives, we firstly define online comments as a complex model that could realize feeling communication, express semantic knowledge, prompt social interaction, and fertilize time character. The social-emotional semantic model (SESM) and its complete construction methods are also introduced to extract comment's social and emotional semantic meaning. Utilizing three user-based and topic-based emotional algorithms, the presented model makes it possible to generate topic-based and learner-based time series. Also, this study evaluates the possibility to visualize SESM on 67084 Chinese MOOC comments and 278 time series. The time-varying phenomenon in double time-series may help teachers determine the reason of the emotion change and then decide to conduct course adjustment or personalized instruction. Future learning analysis on comments should consider multiple semantics and emotional time series. Jinta Weng, Wensheng Gan, Guozhu Ding, Zhihong Tian 0001, Ying Gao 0003, Jing Qiu 0002 |
SMC | 6 |
| 2020 | Security of Mobile Multimedia Data: The Adversarial Examples for Spatio-temporal Data
Jing Qiu 0002, Xiaojiang Du, Lihua Yin, Zhihong Tian 0001 |
Comput. Networks | 2 |
| 2020 | A Survey on Access Control in the Age of Internet of ThingsabstractWith the development of Internet-of-Things (IoT) technology, various types of information, such as social resources and physical resources, are deeply integrated for different comprehensive applications. Social networking, car networking, medical services, video surveillance, and other forms of the IoT information service model gradually change people's daily lives. Facing the vast amounts of IoT information data, the IoT search technology is used to quickly find accurate information to meet the real-time search needs of users. However, IoT search requires using a large amount of user private information, such as personal health information, location information, and social relations information, to provide personalized services. Employing private information from users will encounter security problems if an effective access control mechanism is missing during the IoT search process. An access control mechanism can effectively monitor the access activities of resources and ensure that authorized users access information resources under legitimate conditions. This survey examines the growing literature on access control for an IoT search. Problems and challenges of access control mechanisms are analyzed to facilitate the adoption of access control solutions in real-life settings. This article aims to provide theoretical, methodological, and technical guidance for IoT search access control mechanisms in large-scale dynamic heterogeneous environments. Based on a literature review, we also analyzed the future development direction of access control in the age of IoT. Jing Qiu 0002, Zhihong Tian 0001, Chunlai Du, Qi Zuo, Shen Su, Binxing Fang |
IEEE Internet Things J. | 1 |
| 2020 | Vcash: A Novel Reputation Framework for Identifying Denial of Traffic Service in Internet of Connected VehiclesabstractTrust management of the Internet of Connected Vehicles has been a hot topic in recent years with the rapid development of UGV technologies. However, existing resolutions based on trustworthiness verification among vehicles make the traffic event transmission quite inefficient. In this article, we assume that the deployed roadside units (RSUs) can provide efficient communication between any pair of RSU and vehicle and propose vehicle cash (Vcash), a reputation framework for identifying denial of traffic service, to resolve the trustworthiness problem in the application level of the Internet of Connected Vehicles. In our reputation framework, every vehicle communicates with the RSU directly for traffic event verification, and spreads verified traffic event notification. We borrow the idea of market trading, and set up trading rules to restrict the malicious vehicle's spread of false message, and to encourage vehicles to contribute to the traffic event monitoring and verification. To evaluate the effectiveness of our reputation framework, we conduct a simulation experimental. Our experiment results indicate that our proposal manages to avoid bogus event spread, and a vehicle in our framework has to contribute to the traffic event detection to normally employ the traffic service. Zhihong Tian 0001, Xiangsong Gao, Shen Su, Jing Qiu 0002 |
IEEE Internet Things J. | 4 |
| 2020 | Automatic Concept Extraction Based on Semantic Graphs From Big Data in Smart CityabstractWith the rapid development of smart cities, various types of sensors can rapidly collect a large amount of data, and it becomes increasingly important to discover effective knowledge and process information from massive amounts of data. Currently, in the field of knowledge engineering, knowledge graphs, especially domain knowledge graphs, play important roles and become the infrastructure of Internet knowledge-driven intelligent applications. Domain concept extraction is critical to the construction of domain knowledge graphs. Although there have been some works that have extracted concepts, semantic information has not been fully used. However, the excellent concept extraction results can be obtained by making full use of semantic information. In this article, a novel concept extraction method, Semantic Graph-Based Concept Extraction (SGCCE), is proposed. First, the similarities between terms are calculated using the word co-occurrence, the LDA topic model and Word2Vec. Then, a semantic graph of terms is constructed based on the similarities between the terms. Finally, according to the semantic graph of the terms, community detection algorithms are used to divide the terms into different communities where each community acts as a concept. In the experiments, we compare the concept extraction results that are obtained by different community detection algorithms to analyze the different semantic graphs. The experimental results show the effectiveness of our proposed method. This method can effectively use semantic information, and the results of the concept extraction are better from domain big data in smart cities. Jing Qiu 0002, Yuhan Chai, Zhihong Tian 0001, Xiaojiang Du, Mohsen Guizani |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2020 | Nei-TTE: Intelligent Traffic Time Estimation Based on Fine-Grained Time Derivation of Road Segments for Smart CityabstractWith the development of the Internet of Things and big data technology, the intelligent transportation system is becoming the main development direction of future transportation systems. The time required for a given trajectory in a transportation system can be accurately estimated using the trajectory data of the taxis in a city. This is a very challenging task. Although historical data have been used in existing research, excessive use of trajectory information in historical data or inaccurate neighbor trajectory information does not allow for a better prediction accuracy of the query trajectory. In this article, we propose a deep learning method based on neighbors for travel time estimation (TTE), called the Nei-TTE method. We divide the entire trajectory into multiple disjoint segments and use the historical trajectory data approximated at the time level. Our model captures the characteristics of each segment and utilizes the trajectory characteristics of adjacent segments as the road network topology and speed interact. We use velocity features to effectively represent adjacent segment structures. The experiments on the Porto dataset show that the experimental results of our model are significantly better than those of the existing models. Jing Qiu 0002, Dongwen Zhang, Shen Su, Zhihong Tian 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | A Distributed Deep Learning System for Web Attack Detection on Edge DevicesabstractWith the development of Internet of Things (IoT) and cloud technologies, numerous IoT devices and sensors transmit huge amounts of data to cloud data centers for further processing. While providing us considerable convenience, cloud-based computing and storage also bring us many security problems, such as the abuse of information collection and concentrated web servers in the cloud. Traditional intrusion detection systems and web application firewalls are becoming incompatible with the new network environment, and related systems with machine learning or deep learning are emerging. However, cloud-IoT systems increase attacks against web servers, since data centralization carries a more attractive reward. In this article, based on distributed deep learning, we propose a web attack detection system that takes advantage of analyzing URLs. The system is designed to detect web attacks and is deployed on edge devices. The cloud handles the above challenges in the paradigm of the Edge of Things. Multiple concurrent deep models are used to enhance the stability of the system and the convenience in updating. We implemented experiments on the system with two concurrent deep models and compared the system with existing systems by using several datasets. The experimental results with 99.410% in accuracy, 98.91% in true positive rate (TPR), and 99.55% in detection rate of normal requests (DRN) demonstrate the system is competitive in detecting web attacks. Zhihong Tian 0001, Chaochao Luo, Jing Qiu 0002, Xiaojiang Du, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | A Genetic-Algorithm Based Method for Storage Location Assignments in Mobile Rack WarehousesabstractIn recent years, mobile racks or auto robots have been widely used in e-commerce warehouses where storage location assignment is a fundamental problem in the order picking process. The present storage location assignment strategies mainly allocate stocks into various racks according to a specific objective function or the relationships between stocks. These strategies include the random storage assignment strategy (RAS) and the good- clustering storage location assignment strategy (GCAS). In this paper, we first analyze the key factors that affect the efficiency of the order picking system.The results show that the rack- moved-number (RMN) is a significant factor in the order picking process. Then, we propose a genetic- algorithm (GA) based method for the storage location assignment problem which adopts RMN as its fitness function. To find a better solution, we take the natural deduplicated stock sequence of history orders (NDSSHO) as a seed to initialize the population of chromosomes. We also define a specific cross mutation strategy to avoid checking the validity of chromosomes by exchanging selected genes and adjusting new generated chromosomes. At last, we compare the RMN of our proposed method with RAS and GCAS. The experimental results show that the RMN of our proposed method is about 50% less than RAS and GCAS. Dongwen Zhang, Yaqi Si, Zhihong Tian 0001, Lihua Yin, Jing Qiu 0002, Xiaojiang Du |
GLOBECOM | 5 |
| 2018 | Automatically Traceback RDP-Based Targeted Ransomware AttacksabstractWhile various ransomware defense systems have been proposed to deal with traditional randomly‐spread ransomware attacks (based on their unique high‐noisy behaviors at hosts and on networks), none of them considered ransomware attacks precisely aiming at specific hosts, e.g., using the common Remote Desktop Protocol (RDP). To address this problem, we propose a systematic method to fight such specifically targeted ransomware by trapping attackers via a network deception environment and then using traceback techniques to identify attack sources. In particular, we developed various monitors in the proposed deception environment to gather traceable clues about attackers, and we further design an analysis system that automatically extracts and analyze the collected clues. Our evaluations show that the proposed method can trap the adversary in the deception environment and significantly improve the efficiency of clue analysis. Furthermore, it also helps us trace back RDP‐based ransomware attackers and ransomware makers in the practical applications. Chaoge Liu, Jing Qiu 0002, Zhihong Tian 0001, Xiang Cui, Shen Su |
Wirel. Commun. Mob. Comput. | 3 |
| 2018 | A Data Leakage Prevention Method Based on the Reduction of Confidential and Context Terms for Smart Mobile DevicesabstractEarly data leakage protection methods for smart mobile devices usually focus on confidential terms and their context, which truly prevent some kinds of data leakage events. However, with the high dimensionality and redundancy of text data, it is difficult to detect the documents which contain confidential contents accurately. Our approach updates cluster graph structure based on CBDLP (Data Leakage Protection Based on Context) model by computing the importance of confidential terms and the terms within the range of their context. By applying CBDLP with pruning procedure which has been validated, we further remove the redundancy terms and noise terms. Actually, not only can confidential terms be accurately detected but also the sophisticated rephrased confidential contents are detected during the experiments. Zhihong Tian 0001, Jing Qiu 0002, Feng Jiang 0001 |
Wirel. Commun. Mob. Comput. | 3 |