Weihao Huang

dblp:213/2191 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Assessing the capability of android dynamic analysis tools to combat anti-runtime analysis techniques
Dewen Suo, Lei Xue 0001, Weihao Huang, Runze Tan, Guozi Sun
J. Syst. Softw.3
2025 An Enhanced Autism Detection Model Based on Electroencephalogram Signals
abstract
In recent years, with increasing demand for the diagnosis of autism spectrum disorder (ASD), automated detection methods based on electroencephalogram (EEG) signals have gained significant attention. However, existing approaches still face challenges in terms of accuracy, generalization ability, robustness, and interpretability. We propose an improved ASD detection model, ATCosLNet (Attention-CosCNN-LSTM-Net), which leverages a multidimensional attention mechanism to focus on critical signals, combines Cosine Convolutional Neural Network (CosCNN) for frequency feature extraction, and integrates a tree-structured LSTM to model hierarchical and long-term dependencies, enabling comprehensive extraction of spatiotemporal and frequency domain features from EEG signals. The results of experiments using ten-fold cross-validation demonstrate that ATCosLNet achieves 94.11% classification accuracy on the KAU dataset and 95.80% on the EEG-ASD dataset, significantly outperforming existing detection methods. Moreover, the model exhibits stable performance across different data splits and unseen data, validating its strong generalization ability and robustness, providing an efficient, stable, and interpretable solution for automated ASD detection, advancing the application of EEG signals in ASD diagnosis and offering valuable support for related research and clinical practice.
Weihao Huang, Chunhong Jiang, Jiahui Pan 0003
IJCNN2
2025 MalFocus: Locating Malicious Modules in Malware Based on Hybrid Deep Learning
abstract
In recent years, binary malware detection has attracted extensive attention from industry and academia. However, most of the existing work only focuses on judging whether a sample is malicious or not, rather than identifying malicious modules in malware. Few studies aiming at locating malicious code work on the function granularity and suffer from inaccuracy. In this paper, we address this problem by locating malicious code at the functional module (FM) granularity, which combines several functions to express the malicious behaviors of malware. We design a tool called MalFocus to automatically divide malware intoFMsand then identify the malicious functional module (MFM) in a multi-model hybrid manner, in which an unsupervised model and an interpretability approach based on a binary classifier are combined, eliminating the workload of labeling malware samples, determining the scope ofMFMsand ranking them according to their maliciousness. The identifiedMFMsare then passed to security analysts for verification, helping to significantly reduce the scope of manual analysis while providing a comprehensive view of the malware attack flow. Additionally, rules derived from the verifiedMFMscan be used to detect variants and new malware families with different functionalities, offering a more general and flexible detection approach. We evaluate MalFocus’s performance on 6764 real-world samples. The results show that MalFocus can correctly identify 95% ofMFMs, outperforming current state-of-the-art work.
Weihao Huang, Chaoyang Lin, Lu Xiang, Zhiyu Zhang 0017, Guozhu Meng, Lei Xue 0001, Kai Chen 0012, Zongming Zhang
IEEE Trans. Dependable Secur. Comput.1
2025 ARAP: Demystifying Anti Runtime Analysis Code in Android Apps
abstract
With the continuous growth in the usage of Android apps, ensuring their security has become critically important. An increasing number of malicious apps adopt anti-analysis techniques to evade security measures. Although some research has started to consider anti-runtime analysis (ARA), it is unfortunate that they have not systematically examined ARA techniques. Furthermore, the rapid evolution of ARA technology exacerbates the issue, leading to increasingly inaccurate analysis results. To effectively analyze Android apps, understanding their adopted ARA techniques is necessary. However, no systematic investigation has been conducted thus far.In this paper, we conduct the first systematic study of the ARA implementations in a wide range of 117,270 Android apps (including both malicious and benign ones) collected between 2016 and 2023. Additionally, we propose a specific investigation tool namedARAPto assist this study by leveraging both static and dynamic analysis. According to the evaluation results,ARAPnot only effectively identifies the ARA implementations in Android apps but also reveals many important findings. For instance, almost all apps have implemented at least one category of ARA technology (99.6% for benign apps and 97.0% for malicious apps).
Dewen Suo, Lei Xue 0001, Le Yu 0002, Runze Tan, Weihao Huang, Guozi Sun
IEEE Trans. Software Eng.5
2023 FMDiv: Functional Module Division on Binary Malware for Accurate Malicious Code Localization
abstract
In recent years, binary malware detection has attracted extensive attention from industry and academia. However, most of the existing work focuses on determining whether a sample is malicious or not, rather than identifying the malicious essence in malware. Few studies aim at locating malicious code at function granularity and suffer from inaccuracy. In this paper, we solve the problem by dividing malware into Functional Module (FM), which is a better granularity for locating malicious code, as it combines certain functions to express malicious behaviors in malware. We design a tool called FMDiv to automatically unpack and disassemble binary malware and then divide them into FMs based on the function call graph (CG). Meanwhile, one novel feature extraction and embedding method has been adopted to validate the effect of the FM division algorithm and provide one alternative method of characterization for subsequent malicious FM location. We evaluate FMDiv’s performance on 10,440 real-world samples from VIRUSSHARE. The results show that FMDiv can correctly characterize and make FM division of malware, outperforming current state-of-the-art work.
Weihao Huang, Chaoyang Lin, Qiucun Yan, Lu Xiang, Zhiyu Zhang 0017, Guozhu Meng, Kai Chen 0012
CSCWD1
2023 Are our clone detectors good enough? An empirical study of code effects by obfuscation
abstract
Abstract Clone detection has received much attention in many fields such as malicious code detection, vulnerability hunting, and code copyright infringement detection. However, cyber criminals may obfuscate code to impede violation detection. To date, few studies have investigated the robustness of clone detectors, especially in-fashion deep learning-based ones, against obfuscation. Meanwhile, most of these studies only measure the difference between one code snippet and its obfuscation version. However, in reality, the attackers may modify the original code before obfuscating it. Then what we should evaluate is the detection of obfuscated code from cloned code, not the original code. For this, we conduct a comprehensive study evaluating 3 popular deep-learning based clone detectors and 6 commonly used traditional ones. Regarding the data, we collect 6512 clone pairs of five types from the dataset BigCloneBench and obfuscate one program of each pair via 64 strategies of 6 state-of-art commercial obfuscators. We also collect 1424 non-clone pairs to evaluate the false positives. In sum, a benchmark of 524,148 code pairs (either clone or not) are generated, which are passed to clone detectors for evaluation. To automate the evaluation, we develop one uniform evaluation framework, integrating the clone detectors and obfuscators. The results bring us interesting findings on how obfuscation affects the performance of clone detection and what is the difference between traditional and deep learning-based clone detectors. In addition, we conduct manual code reviews to uncover the root cause of the phenomenon and give suggestions to users from different perspectives.
Weihao Huang, Guozhu Meng, Chaoyang Lin, Qiucun Yan, Kai Chen 0012, Zhuo Ma 0001
Cybersecur.1
2022 Tolerance framework for robust group multiple criteria decision making
Yelin Fu, George Q. Huang, Weihao Huang
Expert Syst. Appl.5
2021 Highway-Based Local Graph Convolution Network for Aspect Based Sentiment Analysis
Shiguan Pang, Zehao Yan, Weihao Huang, Bixia Tang, Anan Dai
NLPCC (1)3
2020 Transductive Multi-Object Tracking in Complex Events by Interactive Self-Training
abstract
Recently, multi-object tracking (MOT) for estimating trajectories of pedestrians has undergone fast development and played an important role in human-centric video analysis. However, video analysis in complex events (e.g. scenes in HiEve dataset) is still under-explored. In complex real-world scenarios, domain gap in unseen testing scenes and severe occlusion problem that disconnects tracks are challenging for existing online MOT methods without domain adaptation. To alleviate domain gap, we study the problem in a transductive learning setting, which assumes that unlabeled testing data is available for learning offline tracking. We propose a transductive interactive self-training method to adapt the tracking model to unseen crowded scenes with unlabeled testing data by means of teacher-student interative learning. To reduce prediction variance in an unseen domain, we train two different models and teach one model with pseudo labels of unlabeled data predicted by the other model interactively. To improve robustness against occlusions during self-training, we exploit disconnected track interpolation (DTI) to refine the predicted pseudo labels. Our method achieved MOTA of 60.23 on HiEve dataset and won the first place of Multi-person Motion Tracking in Complex Events (with Private Detection) in the ACM MM Grand Challenge on Large-scale Human-centric Video Analysis in Complex Events.
Ancong Wu, Chengzhi Lin, Bogao Chen, Weihao Huang, Wei-Shi Zheng 0001
ACM Multimedia4