VLDB 2026 Research / reviewers in the wild / expert
Yangyang Guan
dblp:201/6315
· DBLP profile ↗
8ranked-venue papers
0as first author
7since 2021 · last 2025
0000-0002-8215-135XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 since 2021Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SSRCorr: A Self-Supervised Robust Flow Representation Learning Framework for Flow Correlation Attacks on TorabstractTor is one of the most widely adopted anonymity networks, yet its anonymity can be undermined by adversaries through flow correlation attacks. Current mainstream technologies focus on exploiting the sequence characteristics of packet lengths and timestamps to execute attacks. However, the padding mechanism of the Tor network and time delays caused by multi-hop relays obscure these single-modal features. Additionally, the diversity of network services and the randomness of user behavior result in sparse packet distributions, which impact model training and inference. In this paper, we propose SSRCorr, a novel self-supervised learning framework for flow correlation attacks, incorporating the Flow Feature Aggregation (FFA) module and Global-Local Fusion (GLoF) Encoder to address these challenges. Firstly, we construct a Byte-based Traffic Aggregation Matrix (BTAM) by integrating time and length sequences and applying two data augmentation methods tailored for Tor flow correlation, thereby reducing the impact of Tor network noise on attack effectiveness. Secondly, we employ GLoF to extract features from the output by FFA and fuse the global context information of the traffic, thus mitigating the impact of low-information traffic on model performance. Experiments show that SSRCorr achieves a TPR of 96%, surpassing other methods, and maintains robust performance under temporal drift and obfuscation, supporting future research on countering anonymity system defenses. Mengyan Liu, Yaochen Ren, Yanbo Wu, Yangyang Guan, Zhen Li 0011, Gaopeng Gou, Junzheng Shi |
TrustCom | 6 |
| 2024 | Anti-Packet-Loss Encrypted Traffic Classification via Masked Autoencoder
Li Guo 0001, Gaopeng Gou, Gang Xiong 0001, Yangyang Guan |
WASA (1) | 7 |
| 2021 | GAP-WF: Graph Attention Pooling Network for Fine-grained SSL/TLS Website FingerprintingabstractAs an important part of network management, website fingerprinting has become one of the hottest topics in the field of encrypted traffic classification. Website fingerprinting aims to identify the specific webpages in encrypted traffic by observing patterns of traffic traces. Prior studies proposed several machine-learning-based methods using statistical features and deep-learning-based methods using packet length sequences. However, these works mainly focus on the website homepage fingerprinting. In fact, people are usually not limited to visiting the homepage. Compared with the homepage classification of websites, it is more difficult to identify different webpages within the same website due to the traffic traces are very similar. In this paper, we propose the Graph Attention Pooling Network for fine-grained website fingerprinting (GAP-WF). We introduce the trace graph to describe the contextual relationship between flows in webpage loading. Then we utilize the Graph Neural Networks to learn the intra-flow and inter-flow features. Considering different flows may have different importance, we utilize the graph attention mechanism to pay attention to key nodes. We collect four datasets covering three different granularity scenarios to evaluate our proposed method. Experimental results demonstrate that GAP-WF not only achieves the best performance of 99.86% in website homepage fingerprinting, but also outperforms other state-of-art methods in all fine-grained webpage fingerprinting scenarios. Moreover, GAP-WF can achieve better performance with fewer training samples. Gaopeng Gou, Majing Su, Dong Song, Chang Liu 0049, Yangyang Guan |
IJCNN | 7 |
| 2021 | Universal Perturbation for Flow Correlation Attack on TorabstractTor is a popular anonymous social network. However, it is also concerned by censors or other malicious attackers. A large body of work examines Tor’s susceptibility to flow correlation attacks. Moreover, the existing methods to defend against such attacks have two inherent drawbacks. One is they will bring high delay to the system, the other is they lack of theoretical basis to prove their effectiveness.This paper conducts the first experimental study of how to effectively defeat flow correlation attacks on Tor. We propose a new universal perturbation generation algorithm, a defense to achieve the goal of flawing flow correlation attacks by apply tiny perturbations to the traffic. Our approach uses adversarial sample technique to incorporate Tor traffic constraints and avoid the two drawbacks mentioned above. We evaluate it over five typical flow correlation attacks. Our results show the effectiveness and high transferability of the generated perturbations. For instance, by applying a perturbation with a tiny variance of only 10ms, the TP of original flow correlation attack is reduced from 82% to 60% and the surrogate attack decreases from 71% to 52%. Gaopeng Gou, Yangyang Guan, Gang Xiong 0001, Chang Liu 0049 |
IPCCC | 3 |
| 2021 | RecGraph: Graph Recovery Attack using Variational Graph AutoencodersabstractGraph-structured data contains a lot of sensitive information about individuals. In order to protect users’ privacy, many anonymization mechanisms for graph-structured data are proposed. However, one common drawback of these mechanisms is that they only consider to hide the local characteristics, such as the degree of nodes or their neighbors. They lack the consideration for the nodes’ attribute features and the features of potential global graph structure, which leads to the failure of these mechanisms to provide sufficient security.To address this shortcoming, we propose RecGraph, a framework for graph recovery attack based on variational graph autoencoders. We use RecGraph to perform graph recovery attack on three real social network datasets, and compare it with five existing baselines, to prove the effectiveness of our method. We also evaluate the privacy wastage after performing the graph recovery attack using RecGraph to demonstrate the serious security risks faced by the existing graph anonymization mechanisms. Chang Liu 0049, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Yangyang Guan |
IPCCC | 6 |
| 2021 | TMT-RF: Tunnel Mixed Traffic Classification Based on Random Forest
Panpan Zhao, Gaopeng Gou, Chang Liu 0049, Yangyang Guan, Mingxin Cui, Gang Xiong 0001 |
SecureComm (1) | 4 |
| 2021 | Towards Multi-source Extension: A Multi-classification Method Based on Sampled NetFlow RecordsabstractWith the rapid development of the Internet, network traffic is growing explosively. It brings great challenges to the traditional traffic identification technology using full traffic analysis, which requires more resources to achieve the collection and analysis of full traffic. And, handling the raw traffic may lead to the compromise of user privacy. NetFlow has good compatibility with the existing routing or switching devices, can aggregate network traffic information, support traffic sampling, reduce the invasion of user privacy, and can effectively deal with the challenges. However, as NetFlow is usually output after traffic sampling to ensure the performance of network devices and only contains session-level statistical information, existing NetFlow research mostly focuses on the binary classification problems (e.g., specific anomaly traffic detection), and less exploration has been conducted on traffic multi-classification problems. And NetFlow is even less involved in the currently popular field of encrypted traffic classification. In this paper, we focus on how to perform encrypted traffic multi-classification research based on sampled NetFlow records and propose a multi-classification method based on the multi-source extension of sampled NetFlow records. To improve the distinguishability and applicability of the sampled NetFlow records, we extend and enrich the records with full consideration of the head or payload information in traffic data, including TTL values, Cipher Suites, etc. For different application scenarios, the methods based on head information extension and payload information extension are proposed, respectively. Through comprehensive experiments, the results show that the proposed method is more applicable and effective than the method based on a single N etFlow record in dealing with multi-classification problems in different encryption application scenarios. Peipei Fu, Qingya Yang, Yangyang Guan, Bingxu Wang, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001 |
TrustCom | 3 |
| 2017 | Identifying malware with HTTP content type inconsistency via header-payload comparisonabstractMalware is one of the most severe security threats on the Internet. A key challenge for attackers is to install their malware programs on as many victim machines as possible. HTTP protocol, being the most popular protocol and occupying a significant portion of network traffic, is an obvious target for attackers to exploit for malware distribution. Advanced attackers would even hide the malicious executable program behind a benign file such as text, image. The existence of malware becomes harder to detect and the distribution channels become more evasive (i.e., not clear to identify). However, the exploited and hidden behavior often leads to an inconsistency between the actual content type and the declared content type. In this paper, we conduct a detailed study on a seven-month traffic of content type inconsistency executable program downloaded from an ISP of CSTNET (China Science and Technology Network). We found that 99.78% (891/893) of PE (portable executable) files declared to be images are malicious and 100% of PE files declared to be text with typical file extensions, “.pdf”, “.doc”, “.css” are malware. So, content type inconsistency can be used to detect evasive network attacks as well as effectively discover unknown malware from the traffic. Haiqing Pan, Zigang Cao, Zhen Li 0011, Gang Xiong 0001, Yangyang Guan, Siu-Ming Yiu |
IPCCC | 6 |