Zhaojun Gu

dblp:220/1060 · DBLP profile ↗
← Back
18ranked-venue papers
3as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CAWT: Correlated Attention-Based Wavelet Transformer for UAV Trajectory Prediction in High-Maneuverability Environments
abstract
Flight trajectory prediction (FTP) is crucial for the autonomous development of unmanned aerial vehicles (UAVs). However, in complex, high-maneuverability motion scenarios, accurately modeling UAV motion patterns with low-dimensional features is challenging. This paper proposes a Correlated Attention-Based Wavelet Transformer (CAWT) model for high-precision FTP of the rotary wing UAV in high maneuverability environments. Firstly, based on the cross-domain feature decomposition characteristics of the wavelet transform(WT), a learnable WT module with adjustable low-pass filter coefficients is proposed to expand the model’s receptive field for features. Subsequently, a cross-correlated attention module is developed to address the physical correlation characteristics between sensor data, enabling feature grouping and capturing associated features. Finally, a kinematic consistency (KC) loss is designed, and the weights of the KC and mean squared error losses are optimized using dynamic entropy weighting to create a combined loss that guides model training. The proposed method is validated on three publicly available datasets and three self-collected datasets. The analysis of predicted trajectories and evaluation indicators shows that the CAWT has significantly better prediction accuracy than the baseline models. Additionally, the ablation experiment confirms the synergistic effect and necessity of each module of CAWT in high-precision FTP tasks.
Yuxin Xue, Zhaojun Gu
IEEE Internet Things J.3
2025 MCOG-CCR: Multi-class Overlap-Guided Combined Cleaning and Resampling
Zhaojun Gu, He Sui
ICIC (11)1
2025 GNSS Spoofing Defense Method for UAV Swarm Based on Consensus Reinforcement Learning
abstract
Global Navigation Satellite System (GNSS) spoofing attacks pose a serious threat to the navigation security of unmanned aerial vehicles (UAVs). Most existing studies focus on detecting abnormal signals, neglecting the action execution phase following anomaly detection. Addressing this issue, this paper proposes a defense strategy based on consensus reinforcement learning (CRL). Firstly, to address the issue of information asymmetry between the swarm and attackers, model the scene members separately. Second, based on a reverse analysis of GNSS spoofing attacks, a method for calculating the estimated potential field (EPF) is designed to address the information deficit of UAVs relative to attackers. Finally, based on the characteristics of distributed systems, a CRL framework was designed to enable the attacked member to use confidence and heading vectors provided by other members within the communication range as inputs, which are processed by a multi-layer perceptron to calculate estimated rewards, update consensus vectors, and correct yaw direction. The reliability of this method has been demonstrated through experiments at different flight distances and swarm sizes, and it outperforms other baseline models in reducing trajectory deviation caused by deception attacks.
Zhaojun Gu, Yuxin Xue
ICPADS1
2025 Complicated Imbalanced and Overlapped Data Oversampling Approach via Hypersphere Coverage and Adaptive Differential Evolution for Anomaly Detection of Industrial Internet of Things
abstract
Anomaly detection is a unique type of classification challenge. The coupling of imbalance, overlap and other complexity of the data such as noise in industrial internet of things (IIoT) scenarios affect the detection accuracy seriously. To address this issue, this article proposes a novel oversampling approach based on synthetic minority oversampling technology via hypersphere coverage and adaptive differential evolution (HCADE-SMOTE). However, overlap intensification caused by generated samples and over-loss of valid information have always been crucial problems for traditional SMOTE-based approaches. In HCADE-SMOTE, we identify error-prone samples including minority noise and boundary samples based on hypersphere coverage algorithm first. Then, we fine-tune the distribution of these error-prone samples before generation with an adaptive differential evolution algorithm. Instead of deletion mechanism, it avoids transitional information loss. With error-prone samples far away from the boundary, HCADE-SMOTE improves the boundary distribution and simplifies the judge the decision boundary for the detection models. Furthermore, minority samples are oversampled based on local hypersphere density and compactness with a weighted SMOTE mechanism to address imbalance problem. The superiority of this HCADE-SMOTE is verified by experiments from optimization of sample distribution, effect of anomaly detection, and statistical tests, compared with 7 well-known SMOTE-based methods. The experimental results show that HCADE-SMOTE is the most prominent to alleviate overlap with Fishers discriminant ratio metric. After HCADE-SMOTE, the detection results reached the best with classification metrics, for the four detection models Support Vector Machines (SVM), Logistic Regression (LR), Naive Bayes, and Decision Tree (DT). The statistical tests also prove HCADE-SMOTE has significant difference from other SMOTE-based methods, superior to them.
Lei Ding 0010, Xueying Yang, Zhaojun Gu, He Sui
IEEE Internet Things J.4
2025 Quad-Rotor Helicopter Visual Attack Based on Attention Mechanism Grad-CAM++ and Mask-PGD
abstract
In order to explore security vulnerabilities in unmanned aerial vehicle (UAV) target tracking processes, a quad-rotor helicopter visual adversarial sample attack method based on Grad-CAM++ and Mask-PGD is proposed in this article. Initially, an attention mechanism is employed to select image frames from the video stream that significantly enhance the attack’s effectiveness, using Grad-CAM++ to identify target-sensitive regions. Then, the target heatmap is overlaid as a mask onto the noise map generated by projected gradient descent (PGD), creating perturbed samples, which are subsequently fused with the original image frames to generate adversarial samples. Finally, these adversarial samples are injected into the UAV’s video stream data, rendering the UAV incapable of detecting targets and disrupting its normal tracking operations. Compared to the PGD method, the proposed approach achieves improvements of 69.39%, 64.01%, and 44.55% in terms of$L_{2}$norm, structural similarity index, and peak signal-to-noise ratio, respectively. In experimental visual attacks on the quad-rotor helicopter Tello, processing only a small portion of key image frames from the video stream is sufficient to disrupt Tello’s tracking tasks.
Jialiang Wang 0002, Liuyang Nie, Zhaojun Gu
IEEE Internet Things J.3
2025 LogOW: A semi-supervised log anomaly detection model in open-world setting
Jingwei Ye, Zhaojun Gu, Xuying Meng, Weiyao Zhang, Yujun Zhang 0001
J. Syst. Softw.3
2025 TiFSN: A wavelet-EC-TCN model for quadrotor UAV trajectory prediction based on time-frequency-spatial feature fusion
abstract
Flight trajectory prediction (FTP) with high precision is the core technology for the autonomous flight of quadrotor unmanned aerial vehicles (UAVs) in environments with limited navigation signals. In response to the problem that most existing methods focus on the features of a single domain and ignore the cross-domain feature correlation, making it challenging to maintain high accuracy in FTP, a prediction model based on time–frequency–spatial feature fusion named TiFSN is proposed. Firstly, based on wavelet transform technology, the velocity signal is extended to time–frequency joint features. Furthermore, a fusion mechanism between time–frequency domain features and attitude angles is established, so that a multi-domain feature set with time–frequency–spatial perception can be constructed. Finally, an extended channels-based temporal convolutional network (EC-TCN) is designed, which achieves high-precision FTP by expanding the feature receiving field. Experiments were conducted on real flight datasets, and the results show that the model significantly improved the evaluation metrics compared to baseline methods. The generalization test of various complex FTP tasks using the onboard CPU also verified the excellent performance of the TiFSN. The ablation experiment further revealed the influence of wavelet decomposition depth and the strategy of expanded channels on the performance.
Yong Kou, Yuxin Xue, Zhaojun Gu
Perform. Evaluation5
2024 A Defense Strategy for UAV Swarm Against GNSS Spoofing Attacks Based on Game Model
Zhaojun Gu, Liuyang Nie
ICIC (1)1
2024 CWMAGAN-GP-Based Oversampling Technique for Intrusion Detection
Zifeng Huang, Zhaojun Gu, Zhong Cao 0002, Lei Ding 0010
ICIC (8)3
2024 Real-Time Detection for GPS Spoofing of Quad-Rotor Helicopter Based on Data Fusion
Jialiang Wang 0002, Liuyang Nie, Zhaojun Gu
ICIC (9)3
2023 SpanMTL: a span-based multi-table labeling for aspect-oriented fine-grained opinion extraction
Yuexuan Zhu, Wei Fan 0001, Yuxiang Zhang 0003, Rui Huang 0006, Zhaojun Gu, Andrew W. H. Ip, Kai-Leung Yung
Soft Comput.6
2021 Malware Detection Based on Multi-level and Dynamic Multi-feature Using Ensemble Learning at Hypervisor
Jian Zhang 0068, Liangyi Gong, Zhaojun Gu, Dapeng Man, Wu Yang 0001, Wenzhen Li
Mob. Networks Appl.4
2020 Valid Probabilistic Anomaly Detection Models for System Logs
abstract
System logs can record the system status and important events during system operation in detail. Detecting anomalies in the system logs is a common method for modern large-scale distributed systems. Yet threshold-based classification models used for anomaly detection output only two values: normal or abnormal, which lacks probability of estimating whether the prediction results are correct. In this paper, a statistical learning algorithm Venn-Abers predictor is adopted to evaluate the confidence of prediction results in the field of system log anomaly detection. It is able to calculate the probability distribution of labels for a set of samples and provide a quality assessment of predictive labels to some extent. Two Venn-Abers predictors LR-VA and SVM-VA have been implemented based on Logistic Regression and Support Vector Machine, respectively. Then, the differences among different algorithms are considered so as to build a multimodel fusion algorithm by Stacking. And then a Venn-Abers predictor based on the Stacking algorithm called Stacking-VA is implemented. The performances of four types of algorithms (unimodel, Venn-Abers predictor based on unimodel, multimodel, and Venn-Abers predictor based on multimodel) are compared in terms of validity and accuracy. Experiments are carried out on a log dataset of the Hadoop Distributed File System (HDFS). For the comparative experiments on unimodels, the results show that the validities of LR-VA and SVM-VA are better than those of the two corresponding underlying models. Compared with the underlying model, the accuracy of the SVM-VA predictor is better than that of LR-VA predictor, and more significantly, the recall rate increases from 81% to 94%. In the case of experiments on multiple models, the algorithm based on Stacking multimodel fusion is significantly superior to the underlying classifier. The average accuracy of Stacking-VA is larger than 0.95, which is more stable than the prediction results of LR-VA and SVM-VA. Experimental results show that the Venn-Abers predictor is a flexible tool that can make accurate and valid probability predictions in the field of system log anomaly detection.
Lanlan Pan, Zhaojun Gu, Jialiang Wang 0002, Yitong Ren, Zhi Wang 0014
Wirel. Commun. Mob. Comput.3
2020 Detecting Overlapping Data in System Logs Based on Ensemble Learning Method
abstract
Machine learning techniques are essential for system log anomaly detection. It is prone to the phenomenon of class overlap because of too many similar system log data. The occurrence of this phenomenon will have a serious impact on the anomaly detection of the system logs. To solve the problem of class overlap in system logs, this paper proposes an anomaly detection model for class overlap problem on system logs. We first calculate the relationship between the sample data and the membership of different classes, normal or anomaly, and use the fuzziness to separate the sample data of the overlapping parts of the classes from the data of the other parts. AdaBoost, an ensemble learning approach, is used to detect overlapping data. Compared with machine learning algorithms, ensemble learning can better classify the data of the overlapping parts, so as to achieve the purpose of detecting the anomalies of the system logs. We also discussed the possible impact of different voting methods on ensemble learning results. Experimental results show that our model can be effectively applied in a variety of basic algorithms, and the results of each measure have been improved.
Yitong Ren, Mengmeng Liang, Zhaojun Gu, Jialiang Wang 0002, Lanlan Pan, Zhi Wang 0014
Wirel. Commun. Mob. Comput.4
2019 Targeted Malicious Email Detection Using Hypervisor-Based Dynamic Analysis and Ensemble Learning
abstract
At present, email is still one of the most frequently used communication tools for organizations and individuals. With the leakage of personal privacy information, targeted malicious email (TME) is becoming a prominent targeted cyber attack vector in today's Internet. This type of attack often uses personal information, about an individual, group of individuals, or an organization, to make a TME more believable and personalized. TME is effective to penetrate email defense system because it is fundamentally difficult for traditional email security method to distinguish legitimate emails from malicious emails. And TMEs often contain malicious URLs or malicious attachments, which are extremely aggressive and destructive. In order to effectively deal with this new type of malicious email attack, this paper proposes a dynamic detection method for malicious email. We simulate the recipient opening the email in the virtual machine (VM), accessing the URL and activating the attachment. And we use the virtual machine introspection (VMI) and memory forensics analysis (MFA) technology to obtain the dynamic features of the email by the out-of-VM. Then we use AdaBoostM1 ensemble learning method and Voting combination strategy to combine three base classifiers such as BayesNet, SMO and J48 to build a powerful classification model for detecting TME attacks. The AdaBoostM1 classifier achieved the high detection rates, with an AUC of 0.997, true positive rate (TPR) of 0.997, and false positive rate (FPR) of 0.015. In addition, our proposed detection method is superior to the 56 anti-virus engines on VirusTotal and most of the existing research works.
Jian Zhang 0068, Wenzhen Li, Liangyi Gong, Zhaojun Gu
GLOBECOM4
2019 NeuralAS: Deep Word-Based Spoofed URLs Detection Against Strong Similar Samples
abstract
Spoofed URLs are associated with various cyber crimes such as phishing and ransomware etc. Most existing detection approaches design a set of hand-crafted features and feed them to machine learning classifiers. However, designing such features is a time consuming and labor intensive process. This paper proposes an approach named NeuralAS (Neural Anti-Spoofing) by segmenting URLs into word sequences and detecting spoofed URLs with recurrent neural networks. As a result, NeuralAS can perform detection with high-abstract and poor-interpretable features learned automatically, and achieve accurate detection with contextual information in sequences. We also propose a novel method to construct indistinguishable data sets of strong similar samples, which can be used to evaluate the robustness of different approaches. Extensive experimental results show that NeuralAS works well on spoofed URLs detection, and has a significant effectiveness and robustness even on strong similar data sets.
Jing Ya, Tingwen Liu, Jinqiao Shi, Li Guo 0001, Zhaojun Gu
IJCNN6
2019 iMCircle: Automatic Mining of Indicators of Compromise from the Web
abstract
With the rapidly evolving landscape of cyber threats, Indicators of Compromise (IOCs) are aggressively exchanged as forensic artifacts to help security professionals quickly identify and response cyber threats. Previous related studies mostly focus on extracting and generating IOCs from some fixed-point monitoring data sources, which are passive and time-consuming. In this paper, we present iMCircle, an innovation system that automatically mines IOCs from the Web by checking suspicious indicators with the help of open-source threat information. Based on the initial input of several suspicious indicators, iMCircle first collects their relevant public threat information from the Web and generates IOCs by checking whether those indicators are threat indicators in the target threat field. Second, it actively extracts new indicators from the search results as new inputs and checks them as described above. In that way, the system works in a circle and generates IOCs continuously. Running this system for almost two months in the real world, it has the appreciable performances on the active checking of suspicious indicators and the automatic generation of IOCs.
Jing Ya, Tingwen Liu, Quangang Li, Jinqiao Shi, Zhaojun Gu
ISCC6
2018 Malware Detection Based on Dynamic Multi-Feature Using Ensemble Learning at Hypervisor
abstract
More data and applications are moving to the cloud, which presents many new security risks. Malware is one of the most significant threats to cloud computing. In this paper, we explore to employ virtual machine introspection(VMI) and memory forensics analysis(MFA) techniques to detect malware running in guest virtual machines. Our scheme differs from existing malware detection methods based on virtualization technology in three aspects. First, this paper combines VMI with MFA to extract multiple type features in the guest virtual machine at the same time. Our scheme can effectively minimize the data acquisition overhead. Second,compared with single dynamic feature or multiple static feature detection methods, our data acquisition method employs dynamic multiple type features, and effectively promotes the ability of sophisticated malware detection. Finally,we use AdaBoost ensemble learning method and combination strategy of voting to improve the accuracy and generalization ability of the overall classifier. The experimental results based on a lot of real-world malware show that our scheme can achieve a detection accuracy of 0.9975. Our approach can improve virtual machines security, and further effectively enhance the security of cloud computing environment.
Jian Zhang 0068, Liangyi Gong, Zhaojun Gu, Dapeng Man, Wu Yang 0001, Xiaojiang Du
GLOBECOM4