VLDB 2026 Research / reviewers in the wild / expert
Fangtian Zhong
dblp:276/3588
· DBLP profile ↗
12ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-1125-7472ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SwiftBot: A Decentralized Platform for LLM-Powered Federated Robotic Task Execution
YueMing Zhang, Zhengxiong Li, Fangtian Zhong, Xiaokun Yang, Hailu Xu |
CCGrid | 4 |
| 2026 | BatchMDS: A Time-Efficient Misbehavior Detection System in Internet of VehiclesabstractThe Internet-of-Vehicles (IoV) has gained significant attention from both academia and industry, driven by its potential to enhance road safety and traffic efficiency. To fully realize this potential, securing IoV communications is essential, where detecting malicious Basic Safety Messages (BSMs) is a key challenge. To this end, machine learning (ML) has been widely employed to design Misbehavior Detection Systems (MDSs) for identifying manipulated BSMs. However, the existing MDSs mainly focus on improving detection accuracy, with little attention given to time efficiency. As safety in IoV is time-sensitive, designing a time-efficient MDS is urgently necessary. In this work, we propose BatchMDS, a time-efficient MDS using Convolutional Neural Network (CNN) and data-to-image transformation. By processing multiple BSMs simultaneously rather than individually, BatchMDS significantly reduces detection latency. Furthermore, this work proposes a novel combination of a sliding window mechanism and a Learned Feature Cache (LFC) to eliminate redundant computation during continuous detection. This work conducts extensive simulation over the VeRiMe dataset that contains five attacks. The experimental results demonstrate the effectiveness of the proposed BatchMDS, improving time efficiency of all attacks by at least 50% while remaining remarkable detection accuracy (≥ 97%). Yili Jiang, Jiaqi Huang 0001, Sohan Gyawali, Fangtian Zhong, Yi Qian 0001 |
IEEE Internet Things J. | 5 |
| 2025 | Unveiling Malware Visual Patterns: A Self-Analysis PerspectiveabstractThe widespread usage of Microsoft Windows has unfortunately led to a surge in malware, posing a serious threat to the security and privacy of millions of users. In response, the research community has mobilized, with numerous efforts dedicated to strengthening defenses against these threats. The primary goal of these techniques is to detect malicious software early, preventing attacks before any damage occurs. However, many of these methods either claim that packing has minimal impact on malware detection or fail to address the reliability of their approaches when applied to packed samples. Consequently, they are not capable of assisting victims in handling packed programs or recovering from the damages caused by untimely malware detection. To address these challenges, we proposeVisUnpac, a static analysis-based data visualization framework for bolstering attack prevention while aiding recovery post-attack by unveiling malware patterns and offering more detailed information including both malware class and family. Our method includes unpacking packed malware programs, calculating local similarity descriptors based on basic blocks, enhancing correlations between descriptors, and refining them by minimizing noises to obtain self-analysis descriptors. Moreover, we employ machine learning to learn the correlations of self-analysis descriptors through architectural learning for final classification. Our comprehensive evaluation ofVisUnpacbased on a freshly gathered dataset with over 27,106 samples confirms its capability in accurately classifying malware programs with a precision of 99.7%. Additionally,VisUnpacreveals that most antivirus products in VirusTotal can not handle packed samples properly or provide precise malware classification information. We also achieve over 97% space savings compared to existing data visualization based methods. Fangtian Zhong, Qin Hu 0001, Yili Jiang, Jiaqi Huang 0001, Xiuzhen Cheng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Semi-supervised Federated Learning for Misbehavior Detection of BSMs in Vehicular NetworksabstractBasic Safety Messages (BSMs) exchanged among vehicles and roadside units through vehicular communications can significantly enhance road safety and improve traffic efficiency. Protecting the integrity of BSMs, which are transmitted wirelessly in plaintext, is critical for the proper operation of vehicular networks. As a result, various machine learning-based misbehavior detection systems have been proposed to identify corrupted BSMs. Recent studies have applied federated learning methods to further preserve user privacy while facilitating detection model updates. However, supervised federated learning cannot be directly applied since BSMs received by vehicles are unlabeled. In this paper, we propose a semi-supervised federated learning framework that enables the federated training process between vehicles and the server without transmitting any datasets. Our experimental results show that the performance of the proposed semi-supervised framework is very close to the centralized method, while preserving user privacy and reducing communication costs. Jiaqi Huang 0001, Yili Jiang, Sohan Gyawali, Fangtian Zhong |
VTC Fall | 5 |
| 2024 | MalFox: Camouflaged Adversarial Malware Example Generation Based on Conv-GANs Against Black-Box DetectorsabstractDeep learning is a thriving field currently stuffed with many practical applications and active research topics. It allows computers to learn from experience and to understand the world in terms of a hierarchy of concepts, with each being defined through its relations to simpler concepts. Relying on the strong capabilities of deep learning, we propose a convolutional generative adversarial network-based (Conv-GAN) framework titled MalFox, targeting adversarial malware example generation against third-party black-box malware detectors. Motivated by the rival game between malware authors and malware detectors, MalFox adopts a confrontational approach to produce perturbation paths, with each formed by up to three methods (namely Obfusmal, Stealmal, and Hollowmal) to generate adversarial malware examples. To demonstrate the effectiveness of MalFox, we collect a large dataset consisting of both malware and benignware programs, and investigate the performance of MalFox in terms of accuracy, detection rate, and evasive rate of the generated adversarial malware examples. Our evaluation indicates that the accuracy can be as high as 99.0% which significantly outperforms the other 12 well-known learning models. Furthermore, the detection rate is dramatically decreased by 56.8% on average, and the average evasive rate is noticeably improved by up to 56.2%. Fangtian Zhong, Xiuzhen Cheng, Dongxiao Yu, Bei Gong, Shuaiwen Song, Jiguo Yu |
IEEE Trans. Computers | 1 |
| 2024 | Enhancing Malware Classification via Self-Similarity TechniquesabstractDespite continuous advancements in defense mechanisms, attackers often find ways to circumvent security measures. Windows operating systems, in particular, are vulnerable due to fewer restrictions on downloading software from unknown sources, facilitating the spread of malware. To address this challenge, researchers have focused on developing techniques to identify Windows malware, crucial for mitigating potential damage. Traditional approaches typically categorize threats into broad classes such as trojans or adware, often failing to capture the full spectrum of malicious behaviors exhibited by diverse malware variants. In response, we propose a novel approach to malware categorization that incorporates both the general malware family and subfamily for each sample. Our method leverages self-similarity techniques to extract local semantics and similarities within the blocks of malware binaries while preserving correlations between these blocks. We utilize a VGG11 model to capture these features, enabling accurate classification. Central to our approach is the conversion of malware binaries into self-similarity descriptors, facilitating space savings while capturing essential semantics within blocks. By focusing on local self-similarities and their geometric layouts across malware, our method effectively identifies repetitive patterns indicative of malware behavior. Our proof-of-concept implementation demonstrates the effectiveness of our framework, achieving an impressive average precision of 98.2% on a newly gathered dataset with over 25,000 samples. Moreover, our method offers significant space savings, outperforming recent research efforts by a factor of over 96. These results underscore the efficacy of incorporating self-similarities and correlations within blocks for robust malware classification, making our approach a promising solution for real-world malware detection and prevention. Fangtian Zhong, Qin Hu 0001, Yili Jiang, Jiaqi Huang 0001, Cheng Zhang 0018, Dinghao Wu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | An Efficient Revocable and Searchable MA-ABE Scheme With Blockchain Assistance for C-IoTabstractInternet of Things (IoT) devices usually stores data on clouds for computational overhead offloading and easy data sharing. The data owners, as a result, usually have concerns about the security and privacy of their data stored in such cloud-assisted IoT (C-IoT) systems. Traditional encryption and search primitives, including attribute-based encryption (ABE) and public-key encryption with keyword search (PEKS), however, suffer from high overheads in decryption and revocation, and privacy leakage in search. To address these issues, we propose an efficient revocable and searchable multiauthority ABE (MA-ABE) scheme named ERS-ABE, which utilizes blockchain (BC) technology to implement keyword-based search and dynamic user management. ERS-ABE also adopts cloud-assisted decryption to improve the efficiency of IoT devices. It has been proven to be secure against the selective replayable chosen-ciphertext attacks and the chosen-keyword attacks under the random oracle model. The feasibility and efficiency of ERS-ABE have been evaluated through theoretical analysis and extensive simulation studies. The results indicate that EAR-ABE performs better over the state-of-the-art in both storage and computational overheads. Particularly, the operations that are usually done by a central server but taken by a BC in EAR-ABE cost only a few seconds. Jiguo Yu, Suhui Liu, Minghui Xu 0001, Hechuan Guo, Fangtian Zhong, Wei Cheng 0001 |
IEEE Internet Things J. | 5 |
| 2023 | Malware-on-the-Brain: Illuminating Malware Byte Codes With Images for Malware ClassificationabstractMalware is a piece of software that was written with the intent of doing harm to data, devices, or people. Since a number of new malware variants can be generated by reusing codes, malware attacks can be easily launched and thus become common in recent years, incurring huge losses in businesses, governments, financial institutes, health providers, etc. To defeat these attacks, malware classification is employed, which plays an essential role in anti-virus products. However, existing works that employ either static analysis or dynamic analysis have major weaknesses in complicated reverse engineering and time-consuming tasks. In this paper, we propose a visualized malware classification framework called VisMal, which provides highly efficient categorization with acceptable accuracy. VisMal converts malware samples into images and then applies a contrast-limited adaptive histogram equalization algorithm to enhance the similarity between malware image regions in the same family. We provided a proof-of-concept implementation and carried out an extensive evaluation to verify the performance of our framework. The evaluation results indicate that VisMal can classify a malware sample within 4.0 ms and have an average accuracy of 96.0%. Moreover, VisMal provides security engineers with a simple visualization approach to further validate its performance. Fangtian Zhong, Zekai Chen 0005, Minghui Xu 0001, Dongxiao Yu, Xiuzhen Cheng |
IEEE Trans. Computers | 1 |
| 2022 | EdgeViT: Efficient Visual Modeling for Edge Computing
Zekai Chen 0005, Fangtian Zhong, Xiao Zhang 0015, Yanwei Zheng |
WASA (3) | 2 |
| 2022 | Reinforcement learning based adversarial malware example generation against black-box detectors
Fangtian Zhong, Pengfei Hu 0001, Hong Li 0004, Xiuzhen Cheng |
Comput. Secur. | 1 |
| 2021 | DCAP: Deep Cross Attentional Product Network for User Response PredictionabstractUser response prediction, which aims to predict the probability that a user will provide a predefined positive response in a given context such as clicking on an ad or purchasing an item, is crucial to many industrial applications such as online advertising, recommender systems, and search ranking. For these tasks and many other machine learning tasks, an indispensable part of success is feature engineering, where cross features are a significant type of feature transformations. However, due to the high dimensionality and super sparsity of the data collected in these tasks, handcrafting cross features is inevitably time expensive. Prior studies in predicting user response leveraged the feature interactions by enhancing feature vectors with products of features to model second-order or high-order cross features, either explicitly or implicitly. However, these existing methods can be hindered by not learning sufficient cross features due to model architecture limitations or modeling all high-order feature interactions with equal weights. Different features should contribute differently to the prediction, and not all cross features are with the same prediction power. Zekai Chen 0005, Fangtian Zhong, Zhumin Chen, Xiao Zhang 0015, Robert Pless, Xiuzhen Cheng |
CIKM | 2 |
| 2020 | FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS AttacksabstractInternet-of-Things (IoT) devices are getting more and more popular in recent years and IoT networks play an important role in the industry as well as people's activities. On the one hand, they bring convenience to every aspect of our daily life; on the other hand, they are vulnerable to various attacks that in turn cancels out their benefits to a certain degree. In this article, we target the defense techniques against IoT Distributed Denial-of-Service (DDoS) attacks and propose an edge-centric IoT defense scheme termed FlowGuard for the detection, identification, classification, and mitigation of IoT DDoS attacks. We present a new DDoS attack detection algorithm based on traffic variations and design two machine learning models for DDoS identification and classification. To demonstrate the effectiveness of the two machine learning models, we generate a large data set by DDoS simulators BoNeSi and SlowHTTPTest, and combine it with the CICDDoS2019 data set, to test the identification and classification accuracy as well as the model efficiency. Our results indicate that the identification accuracy of the proposed long short-term memory is as high as 98.9%, which significantly outperforms the other four well-known learning models mentioned in the most related work. The classification accuracy of the proposed convolutional neural network is up to 99.9%. Besides, our models satisfactorily meet the delay requirements of IoT when deployed in edge servers with computational powers higher than a personal computer. Fangtian Zhong, Arwa Alrawais, Bei Gong, Xiuzhen Cheng |
IEEE Internet Things J. | 2 |