VLDB 2026 Research / reviewers in the wild / expert
Junjiang He
dblp:279/2025
· DBLP profile ↗
40ranked-venue papers
5as first author
40since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 1 first-author · 12 since 2021Security and privacy · 12 · 3 first-author · 12 since 2021Computer networks · 8 · 1 first-author · 8 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowledge-Guided Deep Reinforcement Learning: A Multi-attack Defense Approach for Cyber-Physical Power Systems
Tingting Pan, Jiahang Tang, Junjiang He |
ICIC | 6 |
| 2026 | ProActive-Shard: A GNN and RL-Enabled Proactive Sharding Framework for Load Balancing in Blockchain
Yuetong Weng, Wenbo Fang, Yumin Yuan, Junjiang He |
ICIC (26) | 8 |
| 2026 | CIL-FGGM: A class-incremental learning framework based on fine-grained Gaussian mixture modeling for open-set fault recognition in rotating machinery
Hekun Yang, Wengang Ma, Junjiang He, Xiaolong Lan, Tao Li 0016 |
Adv. Eng. Informatics | 4 |
| 2026 | Open-set Internet of Things intrusion detection via an adaptive few-shot incremental learning framework enhanced with feature augmentation
Wengang Ma, Hekun Yang, Junjiang He, Xiaolong Lan, Jiangchuan Chen, Tao Li 0016 |
Eng. Appl. Artif. Intell. | 4 |
| 2026 | Generating Black-Box Adversarial Examples for Industrial Control Systems via Immune Co-Evolution
Chenyi Huang, Junjiang He, Wenshan Li 0001, Tao Li 0016, Wengang Ma, Wenbo Fang, Xiaolong Lan |
IEEE Internet Things J. | 2 |
| 2026 | A feature selection method based on clonal selection with beneficial noise
Wenshan Li 0001, Chenyi Huang, Ao Liu 0005, Beibei Li 0002, Junjiang He, Wenbo Fang |
Pattern Recognit. | 6 |
| 2026 | Exploratory Detection of Unknown Cyber-Attacks via Evolutionary Strategy and Machine LearningabstractWith the open-source development of cyber-attack technologies, attackers’ ability to modify existing strategies and exploit vulnerabilities has increased, leading to numerous unknown cyber-attacks. Traditional detection methods face two main challenges: (a) requiring abundant labeled attack samples, which deep learning-based detection methods find difficult to obtain in practice, and (b) struggling to effectively detect novel and previously unseen attacks, especially those that are unknown. In this paper, we propose Exploratory Detection of Unknown Cyber-Attacks via Evolutionary Strategy and Machine Learning. Specifically, firstly, we train kernel-based Ramp-OCSVM models on full features of known attacks to derive class-specific thresholds, while inferring unknown attack thresholds via Gaussian distribution. Next, we define known sample features as “genes” and generate evolutionary feature representations through multi-strategy evolution. Subsequently, these features are processed by the trained Ramp-OCSVM and the thresholds to separate known-attack variants from unknown samples. Finally, we iteratively train a RF classifier using evolved features, selecting the optimal iteration-trained model based on detection performance. We conducted extensive experiments on authoritative datasets. The results achieves F1 scores of 82.70% and 87.64% for detecting unknown attack under different configurations. The mean F1 scores improve to 99.84% and 95.80% for detecting known and unknown attacks in the few-shot learning scenario. Compared to SOTA methods, our proposed method achieves an increase of 2.19% in the F1 score, while demonstrating 53.99% higher F1-score than detection methods via GAN and VAE. Wenbo Fang, Sunjun Liu, Linlin Zhang 0005, Menghao Ao, Qikai Wang, Junjiang He |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Weak Population-Empowered Large-Scale Multiobjective Immune AlgorithmabstractThe multiobjective immune optimization algorithms (MOIAs) utilize the principle of clonal selection, iteratively evolving by replicating a small number of superior solutions to optimize decision vectors. However, this method often leads to a lack of diversity and is particularly ineffective when facing large‐scale optimization problems. Moreover, an overemphasis on elite solutions may result in a large number of redundant offspring, reducing evolutionary efficiency. By delving into the causes of these issues, we find that a key factor is that existing algorithms overlook the role of weak solutions during the evolutionary process. With this in mind, we propose a weak population–empowered large‐scale multiobjective immune algorithm (WP–MOIA). The core of this algorithm is to construct, in addition to the traditional elite population, a cooperative evolutionary population based on a portion of the remaining solutions, referred to as the weak population. During the evolution, both populations work together: the elite population maximizes its advantageous status for local searches, focusing on exploitation, while the weak population seeks greater variation to escape its disadvantaged position, engaging in broader exploration. At the same time, the sizes of both populations are dynamically adjusted to collaboratively maintain the balance of evolution. Through comparisons with nine state‐of‐the‐art multiobjective evolutionary algorithms (MOEAs) and four powerful MOIAs on 30 benchmark problems, the proposed algorithm demonstrates superior performance in both small‐scale and large‐scale multiobjective optimization problems (MOPs), and exhibits better convergence efficiency. Especially in large‐scale MOPs, the new algorithm’s performance nearly surpasses all 13 advanced algorithms being compared. Wenshan Li 0001, Junjiang He, Tao Li 0016, Wenbo Fang, Xiaolong Lan |
Int. J. Intell. Syst. | 3 |
| 2025 | NSA-AE: An inadequately represented immune spaces NSA augmented via autoencoders
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
Neurocomputing | 2 |
| 2025 | Defending Against APT Attacks in Cloud Computing Environments Using Grouped Multiagent Deep Reinforcement LearningabstractAdvanced persistent threats (APTs) pose a significant challenge to cloud computing security in the evolving landscape of cyber threats. Traditional defense models rely heavily on the attacker’s historical attack information, which greatly limits the effectiveness of actually dealing with APT attacks. To address this issues, we investigate an attack-defense game model in clouding computing environments, where multiple attackers and multiple defenders are supposed to compete for resource allocation on the cloud servers. In order to develop more effective defense strategies, we formulate the optimization problem to maximize the average rewards of defenders under constraints of the maximum available resource and acceptable cost. To solve this, we propose to use the multiagent deep reinforcement learning (RL) method to cope with the high uncertainty and dynamics of attack behavior. Then it is proposed to divide all defenders into cooperative groups and allow defenders within each group can jointly optimize the defense strategy through sharing information and experience. On this basis, we propose a novel grouped multiagent deep RL defense (GMADRLD) algorithm, which can effectively mitigate the issue of state space explosion while achieving good defense effect. Simulation results not only demonstrate the effectiveness of the proposed GMADRLD algorithm in dealing with the attacker’s ever-changing strategies, but also show that it is able to strike a balance between defense performance and computational complexity. Xiaolong Lan, Wengang Ma, Wenbo Fang, Junjiang He |
IEEE Internet Things J. | 6 |
| 2025 | An Immune Memory-Empowered SCADA-Based Industrial Virus Dynamic Repropagation ModelabstractSCADA (Supervisory Control and Data Acquisition) systems, as the core of industrial control systems and widely deployed in the nation’s critical industrial infrastructure, are attractive targets for malicious hackers due to their strategic importance. According to Check Point Research, 96% of daily cyberattacks targeting industrial control systems worldwide are known to be repeat attacks. Although current research on virus propagation assists operators in mitigating the damage caused by industrial viruses to SCADA systems, these modeling methods often fail to distinguish between initial and secondary virus invasions, making them unsuitable for modeling the repeated infection spread of industrial viruses. In order to solve this problem, we propose an immune memory-empowered SCADA-based industrial virus dynamic re-propagation model MLBRM (Memory- Latent- Broken- Robust- Memory). First, by introducing an M node, the model is used to realize the function of memorizing viral strains and to quickly immunize against and eliminate them. Besides, we perform dynamic analysis of the model and conduct the second invasion analysis to demonstrate the effect of the M nodes on suppressing the spread of the virus. Additionally, we conduct a model comparison experiment and perform simulations on the US power grid real dataset to demonstrate the effectiveness of the proposed model. Finally, we draw a conclusion and provide some advice for SCADA network operators to better protect the SCADA systems. Jiahang Tang, Junjiang He, Pin Yang, Xiaolong Lan, Jiangchuan Chen, Tao Li 0016 |
IEEE Internet Things J. | 2 |
| 2025 | Malicious encrypted traffic detection method based on multi-granularity representation under data imbalance conditions
Tao Li 0016, Wenshan Li 0001, Linfeng Du, Xiaolong Lan, Junjiang He |
Knowl. Based Syst. | 6 |
| 2025 | Adaptive secure wireless information and power transfer in delay-constrained multiuser multi-input single-output networks
Xiaolong Lan, Junjiang He, Qingchun Chen, Tao Li 0016 |
Signal Process. | 4 |
| 2025 | CSCAD: An Adaptive LightGBM Algorithm to Detect Cache Side-Channel AttacksabstractCache side-channel attacks have become more sophisticated and more destructive to the security of computer architectures and cloud platforms than ever before, resulting in the leakage of privacy information. Prior efforts focused on designing countermeasures instead of timely detection. To address the challenges introduced by cache side-channel attacks, anomaly detection and feature detection were proposed. However, these methods have drawbacks in terms of computational performance and detection effectiveness. In this article, we proposed Cache Side-Channel Attack Detector(CSCAD), a novel tool for detecting cache side-channel attacks against memory events in real time. Specifically, we design a collector using Hardware Performance Counters and use improved Maximum Information Coefficient to generate feature vectors. Meanwhile, an adaptive genetic algorithm with crossover and mutation probability is proposed to optimize hyperparameters of LightGBM. Additionally, an adaptive loss function weight model with low overhead is introduced to enhance efficiency of attack detection. It is encouraging to see that CSCAD achieved a recall of 98.14%. In detecting 1000 samples, it boosted the detection speed by approximately 75% compared to conventional machine learning methods. CSCAD has outperformed the state-of-the-art methods by simultaneously achieving excellent detection speed and effectiveness. Sirui Hao, Junjiang He, Wenshan Li 0001, Tao Li 0016, Geying Yang, Wenbo Fang, Wanying Chen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Unknown Cyber Threat Discovery Empowered by Genetic Evolution Without Prior KnowledgeabstractWith the continuous development of cyber-attack technologies, attackers increasingly exploit zero-day vulnerabilities or leverage emerging techniques to launch sophisticated attacks, resulting in the persistent emergence of unknown cyber-attacks. However, traditional DL-based cyber-attack detection methods heavily rely on large-scale labeled training data. In practice, obtaining sufficient samples of unknown attacks is challenging, which makes it difficult for these methods to effectively defend against unknown cyber-attacks. In this paper, we propose a method for discovering unknown cyber threats empowered by genetic evolution without prior knowledge. Specifically, We, first mapped the network feature space into a gene framework, and divided the attack genes into a static gene region (SGZ) and a dynamic gene region (DGZ) according to the importance of the cyber-attack genes. Subsequently, leveraging the known attack genes, we utilized different gene evolution strategies and a Convolutional Autoencoder (CAE) to generate attack variants and potential unknown attack genes. Finally, we constructed a cyber-attack detection model incorporating both the global attention mechanism (GAM) and the local attention mechanism (LAM). The generated attack variants and unknown attack genes are the used to enhance the detection ability of the detection model for variants and unknown cyber-attacks. We conducted a large number of experiments on six real and authoritative network datasets. The experimental results show that in different scenario settings, the F1 scores of our proposed method for detecting unknown attacks are 84.64% and 95.77% respectively. The F1 score for detecting unknown attacks on the UNSW-NB15 dataset exceeds that of the baseline classifier. The F1 score for detecting unknown attacks on the CSE-CIC-IDS2018 dataset is 98.85%. In comparison with SOTA methods, the average F1 score is improved by 3.14%. In the evaluation of variant detection performance, the generation method we proposed improves the detection of variants by approximately 11.2%, surpassing generation methods such as the Conditional Generative Adversarial Network (CGAN) and the Variational Autoencoder (VAE). Meanwhile, we also comprehensively evaluated the generalization ability of our proposed method and the evolution ability of different evolution strategies on different datasets and through ablation experiments. Wenbo Fang, Junjiang He, Wenshan Li 0001, Wengang Ma, Linlin Zhang 0005, Xiaolong Lan, Geying Yang, Jiangchuan Chen, Tao Li 0016 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Attention-Driven Deep Neural Networks With Cross-Channel Temporal Modeling for Robust Cybersecurity Situational Awareness
Jiangchuan Chen, Xun Che, Yuting Guan, Junjiang He |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Automatic penetration testing model based on reinforcement learning for complex network environments
Junjiang He, Wenbo Fang, Shenwen Yang, Jiangchuan Chen, Tao Li 0016, Xiaolong Lan |
J. Supercomput. | 2 |
| 2024 | Auto-TFCE: Automatic Traffic Feature Code Extraction Method and Its Application in Cyber Security
Junjiang He, Jiayan Wang, Jiangchuan Chen, Wenbo Fang, Tao Li 0016 |
ICDF2C (2) | 1 |
| 2024 | SPAW-SMOTE: Space Partitioning Adaptive Weighted Synthetic Minority Oversampling Technique For Imbalanced Data Set LearningabstractAbstract The problem of data imbalance is common in reality, which greatly affects the performance of classifiers. Most of the solutions are to balance the data set by generating new minority class samples, which are faced with the problems of selecting the appropriate area for generating samples, fuzzy classification boundary and uneven distribution of samples. To solve these problems, we propose a novel oversampling algorithm named space partitioning adaptive weighted synthetic minority oversampling technique (SPAW-SMOTE). We first divide the data space into boundary space and non-boundary space based on spatial partitioning techniques. The number of samples to be generated is assigned to different spaces by the designed adaptive weighting algorithm, which is used to solve the problems of uneven distribution of samples and easy to blur the classification boundary. Finally, we also endeavor to develop a new generation algorithm to reduce the probability of overlapping samples generated when synthesizing new samples and to ensure the diversity of new samples. Experimental results on 18 real-world data sets show that the average performance (G-mean, F1-measure and Area Under Curve) of SPAW-SMOTE is significantly better than other existing oversampling techniques. Junjiang He, Tao Li 0016, Xiaolong Lan, Wenbo Fang |
Comput. J. | 2 |
| 2024 | Automating the Deployment of Cyber Range with OpenStackabstractAbstract Cyber Range is an experimental platform based on virtualization technology to construct a controlled simulation environment, providing a real-world simulation environment for cybersecurity personnel to conduct various practical exercises. The problem is that generating a virtual environment satisfying the requirements is labor-intensive and time-consuming. To resolve the above problem, this paper proposes a system to automate the deployment of a cyber range. In our method, the first step is to collect virtual machines (VMs) related to cybersecurity and extract relevant features. Then, machine learning is used to classify VMs to reduce the cost of manual VMs selection. Lastly, leveraging the popular OpenStack cloud platform as the deployment platform enhances the applicability of the cyber range. When it comes time to deploy a virtual environment, the instructor only needs to provide some brief description information of a virtual environment. Then, the system will automatically parse the description file to complete the automated deployment of the virtual environment. This system has been successfully applied to the cyber range of Sichuan University for daily teaching tasks. Shaohong Zhou, Junjiang He, Tao Li 0016, Xiaolong Lan, Hui Zhao 0007 |
Comput. J. | 2 |
| 2024 | SynDroid: An adaptive enhanced Android malware classification method based on CTGAN-SVM
Junjiang He, Wenshan Li 0001, Wenbo Fang, Geying Yang, Tao Li 0016 |
Comput. Secur. | 2 |
| 2024 | Efficient Based on Improved Random Forest Defense System Against Application-Layer DDoS AttacksabstractApplication‐layer distributed denial of service (DDoS) attacks have become the main threat to Web server security. Because application‐layer DDoS attacks have strong concealability and high authenticity, intrusion detection technologies that rely solely on judging client authenticity cannot accurately detect such attacks. In addition, application‐layer DDoS attacks are periodic and repetitive, and attack targets suddenly in a short period. In this study, we propose an efficient application‐layer DDoS detection system based on improved random forest. Firstly, the Web logs are preprocessed to extract the user session characteristics. Subsequently, we propose a Session Identification based on Separation and Aggregation (SISA) method to accurately capture user sessions. Lastly, we propose an improved random forest classification algorithm based on feature weighting to address the issue of an increasing number of features leading to prolonged calculation times in the random forest algorithm, and as the feature dimension increases, there might be instances where no subfeature is related to the category to be classified. More importantly, we compare the request source IP with the malicious IP in the threat intelligence library to deal with the periodicity and repetition of application‐layer DDoS attacks. We conducted a comprehensive experiment on the publicly available Web log dataset and the threat intelligence database of the laboratory as well as the simulated generated attack log dataset in the laboratory environment. The experimental results show that the proposed detection system can control the false alarm rate and false alarm rate within a reasonable range, improving the detection efficiency further, the detection rate is 99.85%. In secondary attack detection experiments, our proposed detection method achieves a higher detection rate in a shorter time. Junjiang He, Wenbo Fang, Xiaolong Lan, Geying Yang, Tao Li 0016, Jiangchuan Chen |
Int. J. Intell. Syst. | 1 |
| 2024 | A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine DistributionabstractUnmanned aerial vehicles (UAVs) have experienced rapid development, permeating diverse domains. However, addressing security challenges in UAV networks remains daunting due to resource limitations and the high autonomy of UAV terminals. The current research on the UAV network intrusion detection lacks an efficient process covering each UAV terminal and a lightweight collaborative response mechanism between the UAVs and ground stations, which affects the performance of the UAV network intrusion detection. In this article, inspired by the vaccine distribution mechanism in artificial immune systems, we propose a hierarchical UAV network intrusion detection and response approach based on the vaccine distribution. Specifically, we first implement an immune game-based negative selection algorithm at the ground station, to effectively generate vaccines covering the immune space. Then, we distribute vaccines to the UAV terminals, empowering them with intrusion detection capabilities. Finally, we introduce a collaborative response mechanism to enable the intrusion detection at the UAV terminals and perform terminal state assessments. We evaluate the performance of our proposed approach on a large number of the real UAV network data sets. The experimental results indicate that our proposed intrusion detection approach for the UAV networks at the ground stations surpasses all the baseline models. In scenarios involving air-ground coordination, our suggested collaborative response approach proves to be effective in enabling intrusion detection at the UAV terminal, facilitating timely and efficient UAV intrusion detection. Moreover, we demonstrate on the ALFA and NSL-KDD data sets that our approach excels in detecting UAV network intrusions. Particularly, on real UAV network data (ALFA), the detection rate reaches 99.05% and the accuracy is 96.13% surpassing the other models by approximately 6%. Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 2 |
| 2024 | Corrections to "A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution"abstractPresents corrections to the paper, (Corrections to “A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution”). Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 2 |
| 2024 | An Immune-Knowledge-Driven SCADA-Based Industrial Virus Propagation ModelabstractSupervisory Control and Data Acquisition (SCADA) systems are the core of industrial control systems and an important part of critical infrastructure. With the deployment of 5G networks around the world, SCADA systems are no longer a relatively secure and physically isolated system like in the past, but are facing huge network virus threats. In order to solve the problem that existing models ignore the communication between nodes in the system, we propose an industrial virus transmission model SELBR based on immune knowledge by simulating the function of T cells in the immune system. By introducing E node, the model is used to realize the function of information transfer between nodes. What’s more, we fit the numerical simulation results with the actual data set to verify the existence of the model, and verify the effectiveness of the model for controlling the spread of industrial viruses through model comparison experiments. Numerical results show that the model can effectively control the spread of the virus. Finally, on the basis of parameter sensitivity analysis, preventive suggestions are put forward to further strengthen the security of SCADA system. Junjiang He, Jiahang Tang, Hongxia Wang 0001, Geying Yang, Tao Li 0016, Xiaolong Lan |
IEEE Internet Things J. | 1 |
| 2024 | Information-Freshness-Aware Wireless Multiuser Uplink Physical-Layer Security CommunicationabstractIn this article, we focus on a wireless multiuser uplink network consisting of a single antenna access point (AP) and multiple single antenna users, in which each user transmits time-sensitive confidential message to the AP in a time-division multiple access (TDMA) manner. When a user is scheduled to transmit, the other users will be regarded as potential eavesdroppers. In practical Internet of Things (IoT) applications, different users may have different requirements for throughput, and the timeliness of information needs to be guaranteed. In order to effectively adapt to these heterogeneous application requirements, the average weighted sum Age of Information (AoI) minimization problem is formulated under the premise of satisfying the minimum sampling rate requirement, power allocation constraint, and user scheduling constraint. In order to solve this problem, we first propose two stationary randomized scheduling policies, which are modeled as D/Geom/1 and Geom/Geom/1 queueing systems, respectively, and design two algorithms to find the optimal sampling period of D/Geom/1 system, the sampling probability of Geom/Geom/1 system, the power ratio allocated to confidential information, and the user scheduling probability. Second, an AoI-aware adaptive secure transmission scheme (AASTS) is proposed under Lyapunov optimization framework by transforming the original time-average weighted sum AoI minimization problem into a real-time optimization problem related to data queue state and AoI evolution of every time slot. Numerical results show that the proposed AASTS scheme can achieve better average AoI performance, and the D/Geom/1 system is superior to the Geom/Geom/1 one. Xiaolong Lan, Junjiang He, Liang Liu 0009, Qingchun Chen, Tao Li 0016 |
IEEE Internet Things J. | 3 |
| 2024 | Optimal Age of Information and Throughput Scheduling in Heterogeneous Traffic Wireless Physical-Layer Security CommunicationsabstractA wireless multi-user uplink heterogeneous network is investigated in this paper, which comprises an access point and two distinct user groups including throughput-oriented users and age of information (AoI)-oriented users, in which throughput-oriented users prioritize achieving as high throughput as possible, while AoI-oriented users emphasize timely transmission of information. It is assumed that the transmitted information needs to be kept strictly confidential to unintended users, and the time-division multiple access (TDMA) approach is adopted to transmit confidential information of each user. For such a network, all users who are not scheduled for transmission will be treated as potential eavesdroppers. The objective of our work is to maximize the average achievable secrecy rate of throughput-oriented users while minimizing the average AoI of AoI-oriented users subject to the data queue causality and stability constraints, the sampling rate requirements of AoI-oriented users, the time-averaged and peak transmission power constraints, and the user scheduling constraint. We propose using Lyapunov optimization to convert the original time-averaged optimization problem into a sequence of real-time ones associated with both queue sizes and AoI involved in the current time slot. On this basis, an adaptive heterogeneous traffic security transmission (AHTST) strategy is proposed to determine the optimal strategies for the flow control of throughput-oriented users, the sampling rate control of AoI-oriented users, the power allocation, as well as the user scheduling. Numerical results demonstrate that the AHTST strategy surpasses the considered benchmark schemes in both achievable average secrecy rate and average AoI. Xiaolong Lan, Junjiang He, Wengang Ma, Qingchun Chen |
IEEE Internet Things J. | 5 |
| 2024 | A fast dual-module hybrid high-dimensional feature selection algorithm
Geying Yang, Junjiang He, Xiaolong Lan, Tao Li 0016, Wenbo Fang |
Inf. Sci. | 2 |
| 2024 | An Automatic XSS Attack Vector Generation Method Based on the Improved Dueling DDQN AlgorithmabstractAs one of the most common web attack types, the XSS (Cross Site Scripting) attack is an important research topic in web attack and defense technology. However, the attack vectors in security evaluation methods are often based on expert experience or manual testing methods, which are not only costly and time-consuming but also have a large number of false positives. In this paper, we build an automatic XSS attack vector generation method based on the improved Dueling DDQN algorithm. First, we model the XSS attack vector generation process as a Markov decision process, mapping the initial attack vector mutation points and mutation strategies to the state space and action space of the model, respectively. Second, we propose an improved Dueling DDQN algorithm by introducing a priority experience replay mechanism to improve algorithm performance and the speed of attack vector generation. Third, we establish a feedback mechanism based on the edit distance algorithm to define the role of the reward function, preventing the model from getting stuck in local optima and achieving better mutation effects. Finally, we propose an automatic XSS attack verification method based on static semantic analysis to validate the effectiveness of our generated attack vectors. Based on the aforementioned methods, we have developed a prototype tool for automatic XSS scanning, which avoids generating a high proportion of invalid samples like traditional XSS scanners. The experimental results demonstrate that the improved Dueling DDQN algorithm outperforms other value-based reinforcement learning algorithms in terms of convergence speed, learning efficiency, and stability. The adaptive attack vector generation model can generate attack vectors that adapt to program context semantics and bypass defense mechanisms. Our method performs well when directly scanning the target system and exhibits a higher bypass rate of 85.71% in target systems deployed with WAFs. Furthermore, the model can learn the shortest path for selecting strategies to bypass WAF detection Junjiang He, Tao Li 0016, Xiaolong Lan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | BR-HIDF: An Anti-Sparsity and Effective Host Intrusion Detection Framework Based on Multi-Granularity Feature ExtractionabstractHost-based intrusion detection systems (HIDS) have been widely acknowledged as an effective approach for detecting and mitigating malicious activities. Among various data sources utilized in HIDS, system call traces have gained significant popularity due to their inherent advantage of providing fine-grained information. Nevertheless, conventional feature extraction techniques relying on system calls tend to overlook the issue of high-dimensional sparse feature space. In this paper, we conduct a theoretical analysis to investigate the underlying causes of the sparsity problem. Subsequently, we propose an anti-sparse theory (anti-ST) as a solution to address this issue. Then, we design a multi-granularity feature extraction method (MGFE), which also meets the prerequisite mathematical conditions of the anti-ST. By applying this method, we effectively reduce the size of the feature space and minimize the number of generated features, thus mitigating sparsity. Furthermore, leveraging this approach, we propose a robust and anti-sparsity host intrusion detection framework, known as the MGFE-based Host Intrusion Detection Framework (BR-HIDF). A series of experiments were conducted to evaluate the proposed framework and compare it with the state-of-the-art method. The results demonstrate that our framework achieves impressive accuracy (97.26%), precision (97.62%), recall (96.85%), and F1 score (97.23%) in the intrusion detection task, surpassing existing frameworks. Moreover, the proposed framework significantly reduces the time overhead by 38.80%, exhibiting the highest AUC value of 0.992. Furthermore, we enhance the robustness of the detection system by integrating host-based and network-based detection, which provides greater flexibility in identifying various types of attacks. Junjiang He, Cong Tang, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | An Attack Entity Deducing Model for Attack Forensics
Junjiang He, Tao Li 0016, Wenbo Fang, Wenshan Li 0001, Cong Tang |
ICONIP (15) | 2 |
| 2023 | MPF-FS: A multi-population framework based on multi-objective optimization algorithms for feature selection
Junjiang He, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan |
Appl. Intell. | 2 |
| 2023 | DBWE-Corbat: Background network traffic generation using dynamic word embedding and contrastive learning for cyber range
Linfeng Du, Junjiang He, Tao Li 0016, Xiaolong Lan, Yunhua Huang |
Comput. Secur. | 2 |
| 2023 | Uniformity-Comprehensive Multiobjective Optimization Evolutionary Algorithm Based on Machine LearningabstractWhen solving real‐world optimization problems, the uniformity of Pareto fronts is an essential strategy in multiobjective optimization problems (MOPs). However, it is a common challenge for many existing multiobjective optimization algorithms due to the skewed distribution of solutions and biases towards specific objective functions. This paper proposes a uniformity‐comprehensive multiobjective optimization evolutionary algorithm based on machine learning to address this limitation. Our algorithm utilizes uniform initialization and self‐organizing map (SOM) to enhance population diversity and uniformity. We track the IGD value and use K‐means and CNN refinement with crossover and mutation techniques during evolutionary stages. Our algorithm’s uniformity and objective function balance superiority were verified through comparative analysis with 13 other algorithms, including eight traditional multiobjective optimization algorithms, three machine learning‐based enhanced multiobjective optimization algorithms, and two algorithms with objective initialization improvements. Based on these comprehensive experiments, it has been proven that our algorithm outperforms other existing algorithms in these areas. Yuxuan Luan, Junjiang He, Jingmin Yang, Xiaolong Lan, Geying Yang |
Int. J. Intell. Syst. | 2 |
| 2023 | A Modified Gray Wolf Optimizer-Based Negative Selection Algorithm for Network Anomaly DetectionabstractIntrusion detection systems are crucial in fighting against various network attacks. By monitoring the network behavior in real time, possible attack attempts can be detected and acted upon. However, with the development of openness and flexibility of networks, artificial immunity‐based network anomaly detection methods lack continuous adaptability and hence have poor detection performance. Thus, a novel framework for network anomaly detection with adaptive regulation is built in this paper. First, a heuristic dimensionality reduction algorithm based on unsupervised clustering is proposed. This algorithm uses the correlation between features to select the best subset. Then, a hybrid partitioning strategy is introduced in the negative selection algorithm (NSA), which divides the feature space into a grid based on the sample distribution density and generates specific candidate detectors in the boundary grid to effectively mitigate the holes caused by boundary diversity. Finally, the NSA is improved by self‐set clustering and a novel gray wolf optimizer to achieve adaptive adjustment of the detector radius and position. The results show that the proposed NSA algorithm based on mixed hierarchical division and gray wolf optimization (MDGWO‐NSA) achieves a higher detection rate, lower false alarm rate, and better generation quality than other network anomaly detection algorithms. Geying Yang, Lina Wang 0001, Rongwei Yu, Junjiang He, Bo Zeng 0006, Tian Wu 0004 |
Int. J. Intell. Syst. | 4 |
| 2023 | DGA-PSO: An improved detector generation algorithm based on particle swarm optimization in negative selectionabstractThe negative selection algorithm (NSA) is an essential algorithm in the artificial immune system used to achieve anomaly detection by generating detectors. The traditional NSA algorithm generates candidate detectors randomly, which leads to a partially dense and redundant distribution of detectors in the nonself areas, resulting in the presence of holes that are not covered by detectors. A detector generation algorithm based on particle swarm optimization (DGA-PSO) is proposed to overcome these defects. DGA-PSO converts the self-tolerance process into an adaptation function to guide particles to move in a specific direction by artificial settings and variants, generates efficient detectors covering the nonself space, reduces the redundancy among detectors and fills holes not covered. Thus, we successfully reduce the number of detectors while improving the detection rate of the algorithm. Through experimental validation analysis, DGA-PSO ranks first in detector training time and the detection rate on four UCI datasets compared to the classical algorithms RNSA and V-Detector and the improved algorithms BIORV-NSA, ADC-NSA and IFB-NSA. Junjiang He, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan |
Knowl. Based Syst. | 2 |
| 2023 | Comprehensive Android Malware Detection Based on Federated Learning ArchitectureabstractAndroid malware and its variants are a major challenge for mobile platforms. However, there are two main problems in the existing detection methods:a) The detection method lacks the evolution ability for Android malware, which leads to the low detection rate of the detection model for malware and its variants.b) Traditional detection methods require centralized data for model training, however, the aggregation of training samples is limited due to the infectivity of malware and growing data privacy concerns, centralized detection methods are difficult to be applied in actual detection scenarios. In this paper, we propose FEDriod, a comprehensive Android malware detection method based on federated learning architecture that protects against growing Android malware or emerging Android malware variants. Specifically, we employ genetic evolution strategy to simulate the evolution of Android malware and develop potential malware variants from typical Android malware. Then, we customize the Android malware detection model based on residual neural network to achieve high detection accuracy. Finally, to achieve the protection sensitive data, we develope a federated learning framework to allows multiple Android malware detection agencies to jointly build a comprehensive Android malware detection model. We comprehensively evaluate the performance of FEDriod on the CIC, Drebin, and Contagio authoritative datasets. Experimental results show that our local model outperforms all baseline classifiers. In the federal scenario, our proposed method is superior to the state-of-the-art detection methods, especially in the cross-dataset evaluation, the F1 of FEDriod is 98.53%. More important, we performed genetic evolution experiments on the Drebin dataset, and the results showed that our proposed method has the ability to detect Android malware variants. Wenbo Fang, Junjiang He, Wenshan Li 0001, Xiaolong Lan, Tao Li 0016, Jiwu Huang, Linlin Zhang 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | XSS adversarial example attacks based on deep reinforcement learning
Cong Tang, Junjiang He, Hui Zhao 0007, Xiaolong Lan, Tao Li 0016 |
Comput. Secur. | 3 |
| 2021 | An immune-based risk assessment method for digital virtual assets
Junjiang He, Tao Li 0016, Beibei Li 0002, Xiaolong Lan |
Comput. Secur. | 1 |
| 2021 | A hybrid real-valued negative selection algorithm with variable-sized detectors and the k-nearest neighbors algorithm
Tao Li 0016, Junjiang He, Yongbin Zhu |
Knowl. Based Syst. | 3 |