Qian Qiang

dblp:226/0639 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
6since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2024 AppFineGraph: Hierarchical Mobile Encrypted Traffic Classification at Multi-Granularities via a Branch Graph Neural Network
abstract
Most of existing methods for classifying mobile encrypted traffic are primarily designed for coarse-grained scenarios, focusing on classification at the app name level. This implies that these methods can effectively categorize traffic into app names, but possibly performing poorly when it comes to finer-grained classification of in-app activities such as posting comments or location navigation. Classifying in-app activities poses a greater challenge compared to app name-level classification, as different activities within the same app often adopt similar API libraries, resulting in closely resembling traffic patterns. A more formidable challenge is achieving generic classification that supports both the granularity of app names and in-app activities. It is complex for a single classifier to effectively integrate feature information at multiple levels. Addressing these issues, we propose a novel encrypted traffic classification approach – AppFineGraph. AppFineGraph employs a hierarchical classification framework based on Branch Neural Network (B-NN), enabling the capture of both global and local information at different levels. This approach facilitates multi-granular traffic classification for both app names and in-app activities. Additionally, AppFineGraph introduces a graph neural network for feature representation, effectively mining flow features and correlations from encrypted traffic. In comparison to state-of-the-art approaches, experiments demonstrate that AppFineGraph achieves superior performance across all granularities.
ShengBao Li, Zhuohang Lv, Tianning Zang, Lanqi Yang, Qian Qiang
IJCNN5
2024 FineNet: Few-Shot Mobile Encrypted Traffic Classification via a Deep Triplet Learning Network Based on Transformer
abstract
The existing encrypted mobile traffic classification methods often require a large number of training sets to ensure the effect of the model. When it is difficult to collect enough samples, these methods may not yield satisfactory results. Therefore, it is crucial to study an effective few-shot learning method to achieve accurate traffic classification with very few samples. In this paper, we propose FineNet, a few-shot fine-grained classification technology based on a triplet deep learning network with Transformer. The triplet deep learning network is able to discover subtle differences between traffic flows and effectively transfer existing classification knowledge to few-shot scenarios. Moreover, we introduce Transformer as the base model for the triplet network, fully leveraging Transformer's powerful representation capabilities for sequential data to enhance the express ability of FineNet. We conduct multiple comparative experiments, and the result proves that the accuracy rate is at least 2.4% higher than state-of-the-art approaches in few-shot environment.
ShengBao Li, Qian Qiang, Tianning Zang, Lanqi Yang, Tianye Gao
WCNC2
2023 Topology construction method of anti-tracking network based on cross-domain decentralized gravity model
abstract
With the increasing threats of network tracking and information leakage, privacy protection has become a widely concern in the field of network security. As an important means of protecting the privacy of network users, anti-tracking networks have gradually become one of the important research directions. However, the existing topology structures of anti-tracking networks still have problems such as intra-domain aggregation and key nodes, which are vulnerable to attack, tracking and destruction, and can not meet the privacy requirements. Therefore, this paper proposes a topology construction method based on cross-domain decentralized gravity model (CDTC). Firstly, the model comprehensively considers the local neighbor information, the location information of nodes, and the path information between nodes to calculate the node attraction. Secondly, each node determines its link status with other nodes through the model by ranking its local nodes, achieving optimization of the network topology. Finally, experiments on typical network structures and open network datasets, the experimental results show that the proposed model has better decentralization, cross-domain, and anti-tracking performance.
Zhefeng Nan, Qian Qiang, Tianning Zang, Changbo Tian, Shuhe Liu
TrustCom2
2022 An Incremental Malware Classification Approach Based on Few-Shot Learning
abstract
Malware classification plays a fundamental role among all the related tasks. Researchers and anti-virus vendors have proposed deep learning (DL) methods to deal with the fast emerging-malware families and samples. However, for ordinary deep learning methods, once the model is trained, the set of families that can be recognized is fixed. This is troublesome in practice to deal with emerging malware families or unknown families with scarce samples. To resolve this issue, we propose an incremental classification approach called IMC (Incremental Malware Classification) based on few-shot learning, and the classifier is implemented as a cosine similarity function between extracted features and feature vectors of target classes. IMC can efficiently extend the pre-trained model to unknown families dynamically with a handful of samples without losing the ability to recognize the families it has “seen”. In the process of adaptation, no re-training is needed and fast inference is realized by a single forward pass. We extensively evaluate our approach on a dataset named APIMDS where the framework achieves incremental ability to classify the unknown families with high accuracy while maintaining the ability to recognize the known families. To our best knowledge, this is the first approach to meet the requirements to unify the classification of both unknown and known malware families in a few-shot manner.
Qian Qiang, Mian Cheng, Yuan Zhou 0008, Zisen Qi, Fei Jiao
ICC1
2022 Cost-Effective Malware Classification Based on Deep Active Learning
Qian Qiang, Tianning Zang, Mian Cheng, Quanbo Pan, Zisen Qi
SecureComm1
2021 MALUP: A Malware Classification Framework using Convolutional Neural Network with Deep Unsupervised Pre-training
abstract
Malware is becoming the main threat during the development of the Internet. Driven by the increasing cost due to the complexity and diversity of malware, machine learning is more and more popular for related tasks. Among these ML methods, convolutional neural network has gradually become the mainstream for its excellent performance. At the same time, the scale of labeled data needed for training a ConvNet is so large that labeling malware samples has become a huge burden which hinders the practical application. Meanwhile, better performance means deeper network which requires more resources and more labeled samples for training. In this paper, we propose a novel and effective framework called MALUP for malware classification of guaranteed performance improvement which uses ConvNet with deep unsupervised pre-training. The framework is implemented with deepCluster as the pre-training method to deal with unlabeled malware images and the pre-trained ConvNet is then fine-tuned with labeled samples. We evaluate the effectiveness of MALUP by measuring the performance on a benchmark provided by Microsoft in different conditions. The experiments demonstrate the superior performance of MALUP compared to the ConvNet of the same architecture, especially for a shallower network. Additionally, we evaluate the impact of the number of clusters, the volume of unlabeled data, a simple balance restriction optimization during pre-training, and the percentage of labeled samples as well. Those variables form the optimization space of MALUP and help the proposed framework outperform the transfer learning model pre-trained with ImageNet in deepCluster.
Qian Qiang, Mian Cheng, Zisen Qi
TrustCom1
2020 Malware Classification on Imbalanced Data through Self-Attention
abstract
Malware is an ever-growing threat to the Internet. New and mutated malware are appearing with increasing frequency in recent years. In the real-world scenario, new families of malware are often discovered in the cybersecurity protection system. In order to improve the protection capability of the system, it is necessary to add the newly discovered malware identification characteristics to the online system. However, the samples of newly discovered malware families are usually too small to effectively extract the characteristics of new classes, resulting in a low recognition rate of new families. The essence of this problem is a multi-classification problem based on imbalanced datasets. In this paper, we propose a self-attention based malware classification method to solve the malware classification on imbalanced datasets. An open source dataset is used to simulate the classification of malware on balanced and imbalanced datasets. Our method has reached an accuracy of 98.48%, and the F1-Score of the imbalanced Simda class has reached 89.66% on the Microsoft Kaggle dataset. Experimental results have demonstrated the effectiveness and robustness in malware classification with imbalanced datasets.
Jian Xing, Xiaoyu Zhang 0002, ZiSen Oi, Ge Fu, Qian Qiang, Haoliang Sun
TrustCom7
2019 Themis: A Novel Detection Approach for Detecting Mixed Algorithmically Generated Domains
abstract
As DGA (Domain Generation Algorithm) detection technologies and systems become more and more complex, more types of AGD (Algorithmically Generated Domain) appear: Dictionary-based AGD, Hash-based AGD, etc. This paper applies deep learning to the field of network security, proposes a lightweight AGD detection approach, Themis, which can classify domain names into legitimate domain names or AGDs through domain name strings. Themis combines WordNet and GRU to capture the different characteristics of legitimate domain name and AGD for classification. Compared with the prior art, Themis has two differences: 1) Themis is the first approach to detect mixed AGD (Arithmetic-based and Dictionary-based); 2) Themis performs well in detecting unknowns AGD.
Chaoyi Zheng, Qian Qiang, Tianning Zang, Wen-Han Chao
MSN2