VLDB 2026 Research / reviewers in the wild / expert
Fengyuan Shi 0005
dblp:246/3112-5
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MalTAG: Encrypted Malware Traffic Detection Framework via Graph Based Flow Interaction MiningabstractAs encrypted malware campaigns become more sophisticated, significant challenges arise in effectively detecting malicious communications when relying solely on single-stream or single-feature network traffic analysis methods. Therefore, we propose MalTAG, a graph-based flow interaction mining framework to address existing challenges. MalTAG integrates network traffic into a multi-flow correlated graph and incorpo-rates various feature types rather than relying on a single stream or single type of feature. It effectively captures the contextual correlation properties of malicious activities in both temporal and attribute dimensions. Furthermore, MalTAG achieves graph representation learning through self-supervised contrastive learning without relying on prior label knowledge. This design helps to construct more stable representations of traffic behavior to adapt to the evolving nature of malicious activities. Ultimately, it utilizes various machine learning algorithms to detect malicious traffic comprehensively. Experimental evaluations demonstrate the feasibility and good performance of MalTAG in malware detection and family classification, outperforming existing methods. Zhou Zhou 0007, Fengyuan Shi 0005, Qingyun Liu 0001 |
DSN | 4 |
| 2024 | LightRL-AD: A Lightweight Online Reinforcement Learning Approach for Autonomous Defense against Network AttacksabstractWith the rapid growth of the Internet, network structure has become increasingly complex, leading to more diverse and impactful network attacks. Traditional methods of detecting and defending against network attacks struggle with increasingly complex situations due to human decision-making processes. Recent research has started exploring autonomous defense mechanisms for network attacks within software-defined network (SDN) environments. However, these methods typically employ complex reinforcement learning techniques, making them challenging to implement in online deployment environments. In this paper, we propose LightRL-AD, a lightweight online reinforcement learning approach for autonomous defense against network attacks in SDN. LightRL-AD integrates a machine learning-based Intrusion Detection System (IDS), a reinforcement learning-based Intrusion Prevention System (IPS), and a Moving Target Defense (MTD) mechanism. The ML-based IDS classifies network flows into categories such as malicious or benign, while the RL-based IPS utilizes the SARSA algorithm to determine and execute appropriate defensive actions, ensuring robust network security. We employ specific hardware and software to establish a simulated SDN network for our experiments. And we implement LightRL-AD in the network and evaluate its performance. Experimental results demonstrate that LightRL-AD performs better to defend against slow-rate DDoS attacks autonomously. Fengyuan Shi 0005, Zhou Zhou 0007, Qingyun Liu 0001, Xiuguo Bao |
TrustCom | 1 |
| 2023 | AHIP: An Adaptive IP Hopping Method for Moving Target Defense to Thwart Network AttacksabstractIn a static network, attackers can easily launch network attacks on target hosts which have long-term constant IP addresses. In order to defend against attackers effectively, many defense approaches use IP hopping to dynamically transform IP configuration. However, these approaches usually focus on one type of network attacks, scanning attacks or Denial of Service (DoS) attacks, and cannot sense network situations. This paper proposes AHIP, an adaptive IP hopping method for moving target defense (MTD) to defend against different network attacks. We use a trained lightweight one-dimensional convolutional neural network (1D-CNN) detector to judge whether there are no attacks, scanning attacks or DoS attacks in the network, which can adaptively trigger corresponding IP hopping strategy. We use specific hardware and software to create the software defined network (SDN) environment for experiments. The experiments prove that AHIP performs better to thwart network attacks and has lower system overhead. Fengyuan Shi 0005, Zhou Zhou 0007, Qingyun Liu 0001, Xiuguo Bao |
CSCWD | 1 |
| 2023 | GoGDDoS: A Multi-Classifier for DDoS Attacks Using Graph Neural NetworksabstractDistributed Denial of Service (DDoS) attacks are rising, evolving and growing sophistication. Multi-vector which leverages more than one methods is prevalent recently. To cope with multi-vector DDoS attack, it is necessary to classify DDoS attacks for taking robust measures. However, existing ML-based approaches for DDoS traffic multi-classification barely leverage relationships between packets and flows, which are crucial information that can significantly improve multi-classification performance. This paper proposes GoGDDoS, a multi-classifier for DDoS attacks. Concretely, we construct GoG traffic graph to clearly compress relationships between packets and flows. It merges relationship graphs of packets and flows by using graph of graph. Then, we build a two-level Graph Neural Network model to mine potential attack patterns from GoG traffic graph. The experiments with well-known datasets show that GoGDDoS performs better than its counterparts. Zhou Zhou 0007, Fengyuan Shi 0005, Qingyun Liu 0001 |
ISCC | 4 |
| 2023 | Hunting for Hidden RDP-MITM: Analyzing and Detecting RDP MITM Tools Based on Network FeaturesabstractRemote Desktop Protocol (RDP) is commonly used for remote access to windows computers. As more and more people work remotely, the number of users of RDP is increasing, making RDP a growing concern in cybersecurity. The latest way to threaten RDP security is RDP man-in-the-middle (MITM) tools which realize the MITM function in an RDP connection and automate the MITM attack process, significantly reducing the difficulty of network attacks. At the same time, RDP MITM tools can be used for high-interaction RDP honeypots. In order to mitigate this risk, we present the first in-depth study of RDP MITM tools in this paper. By analysis and experiment, we identify network features that can be used to detect RDP MITM tools effectively. Based on packet latency and TLS handshake, we propose a machine learning classifier that can detect RDP MITM tools for securing RDP connections. Finally, we analyze the deployment of RDP MITM tools in the wild and effectively measure the RDP MITM tools using our proposed detection approach. Zhou Zhou 0007, Fengyuan Shi 0005, Qingyun Liu 0001 |
ISCC | 4 |