VLDB 2026 Research / reviewers in the wild / expert
Yanfei Hu
dblp:280/8096
· DBLP profile ↗
8ranked-venue papers
3as first author
7since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 5 since 2021Computer networks · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | FineGCP: Fine-grained dependency graph community partitioning for attack investigation
Yanfei Hu, Yu Wen 0001, Shuailou Li, Dan Meng 0002 |
Comput. Secur. | 2 |
| 2024 | DyCom: A Dynamic Community Partitioning Technique for System Audit LogsabstractTo address the ever-evolving network threats, system audit logs have become a crucial data source for threat analysis. While current log-based threat detection methods have significant potential in identifying malicious activities, they face limitations in capturing dynamic attack behaviors and revealing complete attack activities.To address these issues, we introduces DyCom, a dynamic graph partitioning technique based on audit logs. Our method incrementally partitions the system log streaming into multiple communities with security semantics, allowing the use of graph community summarization techniques to provide a summary of key activities within each community, thereby aiding security experts in understanding system activities. This method retains all attack activities, reduces analysts’ workload, and keeps them continuously informed about system activities. By focusing on process entities and constructing intimate process events, DyCom effectively reduces the storage cost of log data while ensuring the security semantics of the log communities. Additionally, DyCom employs temporal graph networks to dynamically represent system entities, ensuring real-time monitoring of system activities. Evaluations using the open-source DARPA TC dataset and our simulated datasets demonstrate that DyCom can accurately partition large-scale dynamic system entities into distinct communities, with improvements in precision, recall, and F1 score by 0.71, 0.31, and 0.65 respectively, compared to baseline methods, highlighting its practical potential in threat analysis. Yanfei Hu, Shuailou Li, Lisong Zhang, Yu Wen 0001, Dan Meng 0002 |
TrustCom | 2 |
| 2024 | CarePlus: A general framework for hardware performance counter based malware detection under system resource competition
Yanfei Hu, Wenchao Xue 0001, Yanlong Zhao 0004, Yu Wen 0001 |
Comput. Secur. | 1 |
| 2023 | DAMUS: Adaptively Updating Hardware Performance Counter Based Malware Detector Under System Resource CompetitionabstractHardware performance counter based malware detection (HMD) model that learns HPC-level behavior by using machine learning or deep learning algorithms has been widely researched in various application scenarios. However, the program's HPC-level behavior is easily affected due to system resource competition, which leaves counter based malware detection out-of-date. Unfortunately, current research could not adaptively update HMD model. In this paper, we propose DAMUS, a distribution-aware model updating strategy to adaptively update counter based malware detection model. Specifically, we first design an autoencoder with contrastive learning to map existing samples into a low-dimensional space for better calculating distributions. Second, in the low-dimensional space, the distribution characteristics are calculated for further judging the drift of testing samples. Finally, based on the total determined drifts of testing samples and a threshold, a decision could be given on whether the counter based malware detection model needs to be updated. We evaluate DAMUS by testing HMD model on datasets collected under benchmark application environment and actual server environment with different resource types or pressure levels. The experimental results show the advantages of DAMUS over existing updating strategies in promoting model updating. We also demonstrate its overhead spent on the task of malware detection. Yanfei Hu, Shuailou Li, Yu Wen 0001 |
ISCC | 1 |
| 2023 | HUND: Enhancing Hardware Performance Counter Based Malware Detection Under System Resource Competition Using Explanation MethodabstractHardware performance counter (HPC) has been widely used in malware detection because of its low access overhead and the ability of revealing dynamic behavior during program's execution. However, HPC based malware detection (HMD) suffers from performance decline due to HPC's non- determinism caused by resource competition. Current work enables malware detection under resource competition but still leaves misclassifications. In this paper, we propose HUND, a framework for improving the detection ability of HMD models under resource competition. To this end, we first introduce an explanation module to make the program's prediction interpretable and accurate on the whole. We then design a rectification module for troubleshooting HMDMs' errors by generating modified samples and lowering the effects of false classified instances on model decision. We evaluate HUND by performing HMD models two datasets of HPC-level behaviors. The experimental results show HUND explains HMDMs with high fidelity and HUND's effectiveness in troubleshooting the errors of HMDMs. Yanfei Hu, Shuailou Li, Xu Cheng 0001, Yu Wen 0001 |
ISCC | 1 |
| 2023 | SparkAC: Fine-Grained Access Control in Spark for Secure Data Sharing and AnalyticsabstractWith the development of computing and communication technologies, an extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing access control mechanisms provided by big data platforms have limitations in granularity and expressiveness. In this article, we present SparkAC, a novel access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose apurpose-aware access control(PAAC) model, which introduces new concepts ofdata processing purposeanddata operation purposeand an automatic purpose analysis algorithm that identifies purposes from data analytics operations and queries. Moreover, we develop a unified access control mechanism that implements PAAC model in two modules. GuardSpark++ supports structured data access control in Spark Catalyst and GuardDAG supports unstructured data access control in Spark core. Finally, we evaluate GuardSpark++ and GuardDAG with multiple data sources, applications, and data analytics engines. Experimental results show that SparkAC provides effective access control functionalities with very small (GuardSpark++) or medium (GuardDAG) performance overhead. Tao Xue 0003, Yu Wen 0001, Bo Luo, Gang Li 0009, Yingjiu Li, Yanfei Hu, Dan Meng 0002 |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2022 | A General Backdoor Attack to Graph Neural Networks Based on Explanation MethodabstractGraph neural networks (GNNs) have achieved significant performance in many applications (e.g., social spammer detection and Facebook page classification). Recently, backdoor attacks pose a new security threat to the training process of GNNs. Attackers intend to inject backdoors into GNNs, such that the attacked model performs well on benign samples, whereas its prediction will be changed to target label when the trigger is present. However, existing works on backdoor attacks could not attack arbitrary nodes effectively and achieve high performance on both nodes with discrete features and that with continuous features. In this paper, we propose a general backdoor attack to GNNs which could effectively attack arbitrary nodes while keeping other nodes unaffected as much as possible. We first ensure some important edges for a target node by utilizing edge explanation method and remove these edges if the edge exists before (vice versa). Then we ensure important features by using feature explanation method and use a neural network to optimize these features to obtain feature triggers (i.e., perturbation). Finally, we inject edge and feature triggers into target nodes to implement attack. We evaluate our attack from two aspects including generality and effectiveness. For the first part, our attack is effective on both datasets with discrete features and continuous features. For the second part, we randomly select different node subset with different size (e.g., 20, 50, 100 nodes) as target nodes and our attack achieves higher performance against other two state-of-the-art attacks. Yu Wen 0001, Yanfei Hu |
TrustCom | 6 |
| 2020 | GuardSpark++: Fine-Grained Purpose-Aware Access Control for Secure Data Sharing and Analysis in SparkabstractWith the development of computing and communication technologies, extremely large amount of data has been collected, stored, utilized, and shared, while new security and privacy challenges arise. Existing platforms do not provide flexible and practical access control mechanisms for big data analytics applications. In this paper, we present GuardSpark++, a fine-grained access control mechanism for secure data sharing and analysis in Spark. In particular, we first propose a purpose-aware access control (PAAC) model, which introduces new concepts of data processing/operation purposes to conventional purpose-based access control. An automatic purpose analysis algorithm is developed to identify purposes from data analytics operations and queries, so that access control could be enforced accordingly. Moreover, we develop an access control mechanism in Spark Catalyst, which provides unified PAAC enforcement for heterogeneous data sources and upper-layer applications. We evaluate GuardSpark++ with five data sources and four structured data analytics engines in Spark. The experimental results show that GuardSpark++ provides effective access control functionalities with a very small performance overhead (average 3.97%). Tao Xue 0003, Yu Wen 0001, Bo Luo, Yanfei Hu, Yingjiu Li, Gang Li 0009, Dan Meng 0002 |
ACSAC | 6 |