Shudong Li

dblp:22/10176 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0001-6381-1984ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 7 · 4 first-author · 5 since 2021Computer networks · 3 · 3 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CAPMamba: A hybrid vision model for enhancing generalization in deepfake detection
Shudong Li, Yilin Feng, Tiantian Ji, Kaihan Lin, Qing Li 0077
Expert Syst. Appl.1
2025 A CP-ABE-based access control scheme with cryptographic reverse firewall for IoV
Xiaodong Yang 0006, Xilai Luo, Zefan Liao, Xiaoni Du, Shudong Li
J. Syst. Archit.6
2025 Autonomous Discovery of Cyber Attack Paths With Complex Causal Relationships Among Optional Actions
abstract
Reinforcement Learning (RL), particularly deep reinforcement learning (DRL) has shown significant potential in addressing optimal attack path discovery problems (OAPDPs) for cybersecurity. However, existing approaches often oversimplify the causal relationships among attack actions, limiting their applicability to complex systems. This study pioneers DRL-based solutions for OAPDPs in Intelligent Transportation Systems (ITS), specifically targeting scenarios where attack actions exhibit disjunctive, conjunctive, and hybrid causal relationships. We propose TTCRT, a novel attack pattern template that formalizes attack logic through vector-compatible representations of OAPDP-related attack components, while developing a refinement method for TTCRT-derived attack patterns and presenting a rigorous framework for formalizing OAPDPs as Markov Decision Processes (MDPs) based on refined attack patterns. Through extensive experiments, we demonstrate TTCRT’s capability to rigorously capture disjunctive, conjunctive, and hybrid causal relationships among attack actions, achieving semantic equivalence with Logical Attack Graphs (LAGs) while resolving their implementation bottlenecks in highly complex systems like ITS environments. The framework seamlessly integrates with established DRL algorithms to accurately identify optimal attack paths in an intelligent traffic management system. These findings establish TTCRT as a foundational framework for RL-driven OAPDP resolution in ITS and other sophisticated systems with complex attack dynamics.
Shudong Li, Ruichen Huang, Weihong Han, Shumei Li, Zhihong Tian 0001
IEEE Trans. Intell. Transp. Syst.1
2025 TFGIN: Tight-Fitting Graph Inference Network for Table-based Fact Verification
abstract
Fact verification task has emerged as an essential research topic recently due to abundant fake news spreading on the Internet. The task based on unstructured data (i.e., news) has achieved great development, but the task based on structured data (i.e., table) is still in the primary development period. The existing methods usually construct complete heterogeneous graph networks around statement, table, and program subgraphs, and then infer to learn similar semantics on them for fact verification. However, they generally connect the nodes with the same content between subgraphs directly to frame a larger graph network, which has serious sparsity in connections, especially when subgraphs possess limited semantics. To this end, we propose tight-fitting graph inference network (TFGIN), which innovatively builds tight-fitting graphs (TF-graphs) to strengthen the connections of subgraphs and designs inference modeling layer (IML) to learn coherence evidence for fact verification. Specifically, different from traditional connection ways, the constructed TF-graph enhances inter-graph and intra-graph connections of subgraphs through subgraph segmentation and interaction guidance mechanisms. IML could reason the semantics with strong correlation and high consistency as explainable evidence. Experiments on three competitive datasets confirm the superiority and scalability of our TFGIN.
Lianwei Wu, Kunlin Nie, Sensen Guo, Chao Gao 0001, Zhen Wang 0004, Shudong Li
ACM Trans. Inf. Syst.7
2024 A Novel Network Forensic Framework for Advanced Persistent Threat Attack Attribution Through Deep Learning
abstract
The Internet now plays a pivotal role in the social and economic landspace, providing individuals and businesses with access to essential daily services and tasks. However, it has also become a breeding ground for conflicts. Advanced Persistent Threats (APTs) pose a formidable chanllenge when directed at organizations and governments, exposing the entire network to substantial security risks. Employing network fornesics for attributing cyber-attacks and acquiring timely, credible forensic results is a fundamental challenge in maintaining cyber security. This paper introduces a Deep Learning-based network forensics framework for digitally identifying and tracking network attacks, providing a comprehensive overview of the network forensics process. Specifically, we extract network traffic and employ encryption to ensure the integrity and security of data. Subsequently, we apply feature filtering techniques to retain essential traceability information, and Deep Learning model parameters are automatically optimized using hyperparameter optimization techniques. Lastly, we develop a Multi-Layer Perceptual Deep Neural Network (MLP DNN) model with perceptual capabilities for detecting anomalous events within the network. We evaluated the framework’s effectiveness using the UNSW-NB15 dataset. The experiments demonstrate that the proposed framework is applicable to APT attack forensics scenarios. In comparison to other AI methods, our framework excels in discovering and tracking network attack events with high performance.
Yangyang Mei, Weihong Han, Shudong Li, Kaihan Lin, Zhihong Tian 0001, Shumei Li
IEEE Trans. Intell. Transp. Syst.3
2024 Detecting Deepfake Videos using Spatiotemporal Trident Network
abstract
The widespread dissemination of Deepfake in social networks has posed serious security risks, thus necessitating the development of an effective Deepfake detection technique. Currently, video-based detectors have not been explored as extensively as image-based detectors. Most existing video-based methods only consider temporal features without combining spatial features, and do not mine deeper-level subtle forgeries, resulting in limited detection performance. In this paper, a novel spatiotemporal trident network (STN) is proposed to detect both spatial and temporal inconsistencies of Deepfake videos. Since there is a large amount of redundant information in Deepfake video frames, we introduce convolutional block attention module (CBAM) on the basis of the I3D network and optimize the structure to make the network better focus on the meaningful information of the input video. Aiming at the defects in the deeper-level subtle forgeries, we designed three feature extraction modules (FEMs) of RGB, optical flow, and noise to further extract deeper video frame information. Extensive experiments on several well-known datasets demonstrate that our method has promising performance, surpassing several state-of-the-art Deepfake video detection methods.
Kaihan Lin, Weihong Han, Shudong Li, Zhaoquan Gu, Huimin Zhao 0001, Yangyang Mei
ACM Trans. Multim. Comput. Commun. Appl.3
2023 OOD Attack: Generating Overconfident out-of-Distribution Examples to Fool Deep Neural Classifiers
abstract
Deep neural networks (DNNs) are dominating various computer vision solutions. However, DNN classifiers suffer from the out-of-distribution (OOD) overconfidence issue, i.e., making overconfident predictions on OOD samples. In this paper, we consider a new OOD attack task, i.e., generating OOD examples that fool DNN classifiers to trap into this issue. Specifically, we first generate seed examples by sampling from common OOD distributions, and then lift the prediction to be overconfident. Extensive experiments with different seeds and confidence-lifting solutions under white-and black-box settings validate the feasibility of OOD attack. Besides, we demonstrate its usefulness in evaluating OOD detection and alleviating the OOD overconfidence issue.
Keke Tang, Xujian Cai, Weilong Peng, Shudong Li, Wenping Wang 0001
ICIP4
2023 REMSF: A Robust Ensemble Model of Malware Detection Based on Semantic Feature Fusion
abstract
With the rapid development of Internet of Things, the amount and distribution of malware has greatly increased. Internet of Things platform needs new defense technologies to protect users from new the increasing number and complexity of malware. This article extracts import Dlls and import APIs from the original portable executable (PE) file, and uses heterogeneous graph to describe higher-level semantic relationship between two PE files. Besides this we construct four static features to comprehensively describe PE file. Based on ensemble learning we develop a model called robust ensemble model based on semantic feature fusion (REMSF) which fuses five features mentioned above. To evaluate REMSF, we collect 5370 executable PE files from the real world for series of experiments, in which REMSF’s detection accuracy can reach 99.07%.
Zhuocheng Yu, Shudong Li, Youming Bai, Weihong Han, Zhihong Tian 0001
IEEE Internet Things J.2
2023 A Deceptive Reviews Detection Method Based on Multidimensional Feature Construction and Ensemble Feature Selection
abstract
Deceptive reviews on social media and e-commerce websites are inflammatory and will significantly affect the judgment and purchase behavior of other users. At present, many researchers build models based on single text features to detect deceptive reviews. However, deceptive reviewers will deliberately imitate the text style of true reviews when writing reviews. At this time, these methods based on text features are not necessarily effective. What’s more, detection performance is limited because the category distribution is likely to be unbalanced in practice. In this work, to address these shortcomings, a deceptive review detection method based on multidimensional feature construction and ensemble feature selection is proposed. Our proposal constructs 3-D features including text feature, reviewer behavior feature, and deceptive score feature. In addition, to alleviate the impact of unbalanced category distribution, a data resampling algorithm is applied which incorporates random under-sampling (RUS) and Borderline-SMOTE algorithm. Furthermore, we integrate the results of different feature selection based on the Chi-square test, Information gain, and XGBoost feature importance. Our method addresses the limitation of single dimension features and can provide useful detection. Experimental results area under the curve (AUC, Macro Average Precision, and weighted F1-score) show that the proposed method performs well in the task of deceptive review detection on two Amazon datasets. Compared with other advanced methods, our method achieves additional performance gains in the case of poor text quality and datasets with unbalanced category distribution.
Shudong Li, Guojin Zhong, Yanlin Jin, Peican Zhu, Zhen Wang 0004
IEEE Trans. Comput. Soc. Syst.1
2023 Imbalanced Malware Family Classification Using Multimodal Fusion and Weight Self-Learning
abstract
In recent years, the increasing prevalence of Intelligent Transportation Systems with advanced technologies has led to the emergence of many targeted forms of malware such as ransomware, Trojans, viruses, and malicious mining programs. And malware authors use policies like category disguise or family obfuscation in malware components to evade detection, which poses a great security threat to enterprises, government agencies, and Internet users. In this paper, we propose a malware family classification approach based on multimodal fusion and weight self-learning. Firstly, multiple modalities of malware such as byte, format, statistic, and semantic are fused in various ways to generate effective features. And then, we creatively add a weight self-learning mechanism of malware families into the classification model, which works by continuously calculating log-loss based on the family label and the probabilities predicted by each feature. The approach proves to achieve excellent classification performance on highly imbalanced malware family datasets with high efficiency and small resource overhead, which helps to identify and classify malware families and enhance the efficiency of massive malware analysis in Intelligent Transportation Systems.
Shudong Li, Sattam Al Otaibi, Zhihong Tian 0001
IEEE Trans. Intell. Transp. Syst.1
2023 BotFinder: a novel framework for social bots detection in online social networks based on graph embedding and community detection
Shudong Li, Chuanyu Zhao, Qing Li 0006, Jiuming Huang, Dawei Zhao 0001, Peican Zhu
World Wide Web (WWW)1
2022 False Alert Detection Based on Deep Learning and Machine Learning
abstract
Among the large number of network attack alerts generated every day, actual security incidents are usually overwhelmed by a large number of redundant alerts. Therefore, how to remove these redundant alerts in real time and improve the quality of alerts is an urgent problem to be solved in large-scale network security protection. This paper uses the method of combining machine learning and deep learning to improve the effect of false alarm detection and then more accurately identify real alarms, that is, in the process of training the model, the features of a hidden layer output of the DNN model are used as input to train the machine learning model. In order to verify the proposed method, we use the marked alert data to do classification experiments, and finally use the accuracy recall rate, precision, and F1 value to evaluate the model. Good results have been obtained.
Shudong Li, Danyi Qin, Baohui Li, Weihong Han
Int. J. Semantic Web Inf. Syst.1
2022 A Hybrid Intelligent Approach to Attribute Advanced Persistent Threat Organization Using PSO-MSVM Algorithm
abstract
In recent years, extensive research has been conducted in Advanced Persistent Threat (APT) attack defence. However, most existing defence solutions can only identify and temporarily disrupt cyber attacks, seeking to deny the threat from the intranet, it’s difficult to defence against APT attacks. Attributing the APT organization is an excellent complement to the existing defence solutions, which not only can expose the attacker’s true identity, but also provide evidence to bring the attacker to justice. However, research on attributing APT Organization is still few, poses complex tasks because APT attacks are highly targeted, stealthy, persistent and organized. To answer thie question, we propose a Particle Swarm Optimization Multiclass Support Vector Machine (PSO-MSVM) approach to identify the organization behind complex APT attacks automatically. Firstly, we have collected a large amount of data on the traces of APT attack tools executed in the sandbox, and selected data closely related to APT organizations to construct the feature set. Secondly, based on the strategy of keeping the personal best (pbest) and global best (gbest) particles in the particle swarm algorithm away from the adaptation values generated by the misclassification information as they move, the particle positions are updated frequently to eventually obtain the optimal parameters (i.e., penalty parameter (${C}$) and sigma parameter ($\sigma $)) for MSVM, thus enabling the MSVM technique to accurately identify APT organizations. The results obtained from the PSO-MSVM approach showed the superiority of this technique in three different measures of accuracy, precision and F1,compared with other six classical methods.
Yangyang Mei, Weihong Han, Shudong Li, Kaihan Lin, Cui Luo
IEEE Trans. Netw. Serv. Manag.3
2021 Attribution Classification Method of APT Malware in IoT Using Machine Learning Techniques
abstract
In recent years, the popularity of IoT (Internet of Things) applications and services has brought great convenience to people's lives, but ubiquitous IoT has also brought many security problems. Among them, advanced persistent threat (APT) is one of the most representative attacks, and its continuous outbreak has brought unprecedented security challenges for the large-scale deployment of the IoT. However, important research on analyzing the attribution of APT malware samples is still relatively few. Therefore, we propose a classification method for attribution organizations with APT malware in IoT using machine learning. It aims to mark the real attacking organization entities to better identify APT attack activity and protect the security of IoT. This method performs feature representation and feature selection based on APT behavior data obtained from devices in the Internet of Things and selects the features with a high degree of differentiation among organizations. Then, it trains a multiclass model named SMOTE-RF that can better deal with imbalance and multiclassification problems. Our experiments on real dynamic behavior data are combined to verify the effectiveness of the method proposed in this paper for attribution analysis of APT malware samples and achieve good performance. Our method could identify the organization behind complex APT attacks in IoT devices and services.
Shudong Li, Qianqing Zhang, Weihong Han, Zhihong Tian 0001
Secur. Commun. Networks1
2020 Topic representation model based on microblogging behavior analysis
Weihong Han, Zhihong Tian 0001, Zizhong Huang, Shudong Li, Yan Jia 0001
World Wide Web4
2019 Bidirectional self-adaptive resampling in internet of things big data learning
Weihong Han, Zhihong Tian 0001, Zizhong Huang, Shudong Li, Yan Jia 0001
Multim. Tools Appl.4
2017 Cryptanalysis and Improvement of a Strongly Unforgeable Identity-Based Signature Scheme
Xiaodong Yang 0006, Faying An, Shudong Li, Caifen Wang, Dengguo Feng
Inscrypt4
2017 An efficient quantum blind digital signature scheme
Hong Lai, Mingxing Luo, Josef Pieprzyk, Zhiguo Qu, Shudong Li, Mehmet A. Orgun
Sci. China Inf. Sci.5
2016 Identifying users across social networks based on dynamic core interests
Yuanping Nie, Yan Jia 0001, Shudong Li, Aiping Li, Bin Zhou 0004
Neurocomputing3
2012 Modelling security message propagation in delay tolerant networks
abstract
ABSTRACT Delay tolerant networks (DTNs) are new emerging technologies aiming to solve communication issues in challenged network environments. In such networks, any real‐time interactive key agreement protocol does not work due to the intermittent connectivity and long time delay in message round trips. In the context of specific applications, such as single hop authentication, manual public key exchange is the most direct method because single hop authentication can be achieved by holding a small part of node's public key. To evaluate how many public keys should be maintained by each node to achieve a high propagation speed while single hop authentication scheme is used, in this paper, we proposed a security message propagation model for DTNs formed by vehicles where the extended graph theory and rumor spreading terminology in complex networks were harnessed. We find that holding 8–10 public keys by each node is optimal. And decay rate threshold is 0.16 under which message can be disseminated throughout the whole network. Copyright © 2011 John Wiley & Sons, Ltd.
Zhongtian Jia, Shudong Li, Haipeng Peng, Yixian Yang, Shize Guo
Secur. Commun. Networks2