Wenbo Zuo

dblp:282/8342 · DBLP profile ↗
← Back
14ranked-venue papers
0as first author
14since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 5 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 LDGNet: LLMs Debate-Guided Network for Multimodal Sarcasm Detection
abstract
Multimodal sarcasm detection aims to uncover the sarcasm emotions expressed through various modalities such as text and image. Previous work has made enlightening exploration in detecting sarcastic sentiments with given domains. However, there remains a gap in utilizing deeper contextual information to capture elusive sarcastic clues, hidden in open-world knowledge such as history, politics, and common sense of life that has not been touched by previous models. To address this gap, a natural idea is to simulate the process of a debate, involving debaters with different viewpoints and judges to collaboratively drive the judgment of emotional expressions. Benefiting from the development of large multimodal language models, and building upon previous advancements, we propose a novel framework called LLMs Debate-Guided Network (LDGNet) for Multimodal Sarcasm Detection. LDGNet effectively leverages large language model debates to uncover subtle emotional information and uses an innovative Judge Network for more realible and accurate sentiment judgments. Extensive experiments on in-domain and out-of-distribution (OOD) datasets have validated the superiority of our proposed method.
Hengyang Zhou, Jinwu Yan, Rongman Hong, Wenbo Zuo, Keyan Jin
ICASSP5
2024 CTI-JE: A Joint Extraction Framework of Entities and Relations in Unstructured Cyber Threat Intelligence
abstract
Advanced Persistent Threat (APT) pose an increasingly serious challenge to the security of businesses and organizations. In order to cope with these threats more effectively, effective utilization of cybers threat intelligence becomes crucial. Cyber Threat Intelligence(CTI) is characterized by fragmentation and voluminous, and information extraction can help cybersecurity researchers extract valuable information from massive cyber threat intelligence and understand the full picture of attack events. We propose a threat intelligence joint extraction model CTI-JE, which models the joint extraction problem as a table-filling task. CTI-JE uses SecBERT to generate embedding representations of words and then learns different representations for NER and RE tasks to avoid feature confusion. We construct a shared feature to enhance the interaction between subtasks, using dilated convolution and channel attention mechanism to extract fine-grained features. Experimental results on a cyber threat intelligence dataset show that our proposed model achieves better performance than existing baseline models.
Xiaohui Han, Wenbo Zuo, Haiqing Lv
CSCWD3
2024 HG-ETC: Fine-Grained Application Behaviors Classification From Encrypted Network Traffic
abstract
The classification of encrypted traffic has garnered widespread attention from both researchers and industrial companies. However, existing application behavior-based encrypted traffic classification methods often extract limited information from flow features, typically focusing on either statistical or temporal characteristics of application behavior flows. They fail to capture higher-order features among flows, such as communication behavior characteristics. Therefore, this paper proposes a flow higher-order feature extraction model based on a self-attention hypergraph network. Specifically, we design a six-layer Temporal Convolutional Network (TCN) to simultaneously learn the temporal feature representations of flows, and then fuse them together to obtain a more robust feature representation. Experimental results on two real-world datasets demonstrate that HG-ETC outperforms various state-of-the-art methods in fine-grained encrypted traffic classification tasks.
Xiaohui Han, Wenbo Zuo
CSCWD3
2024 Joint Extraction of Entities and Relationships from Cyber Threat Intelligence based on Task-specific Fourier Network
abstract
The increasing complexity of cyber threats and the emergence of new attack technologies have brought huge challenges to attack incident analysis and source tracing. Using cyber threat intelligence to build a Cyber security Knowledge Graph (CKG) provides a new technical solution for attack attribution. Constructing a CKG requires numerous entity and relationship triples extracted from unstructured cyber threat intelligence texts. However, existing entity and relationship joint extraction methods in cyber threat intelligence face two problems. Firstly, they share the same word embeddings for both subtasks, ignoring the fine-grained semantic differences between the subtasks. Secondly, they rarely consider the interaction between the features of the two subtasks, which is vital for capturing the semantic dependencies between the tasks. To address these issues, we propose a joint entity and relationship extraction model specifically designed for network security concepts. We utilize two lightweight Fourier networks with independent weights to build a feature extraction module for encoding fine-grained features for entity recognition and relationship extraction tasks. Furthermore, we use a subtask feature interaction strategy assisted by a gated attention mechanism to enhance feature interaction between entity recognition and relationship extraction tasks. Use fine-grained entity recognition task information to guide relationship extraction to capture semantic dependencies between tasks. Experimental results on a cyber threat intelligence dataset demonstrate that our model outperforms existing baselines.
Haiqing Lv, Xiaohui Han, Hui Cui 0004, Peipei Wang 0001, Wenbo Zuo
IJCNN5
2024 A Knowledge Distillation-Driven Lightweight CNN Model for Detecting Malicious Encrypted Network Traffic
abstract
In the realm of cybersecurity, efficiently and precisely identifying and mitigating potential threats from malicious encrypted traffic is crucial. As deep learning evolves, methods relying on Convolutional Neural Networks (CNNs) to convert traffic payloads into visual representations for analysis have become popular. Although this technique effectively discerns malicious encrypted traffic, it faces inherent limitations, such as difficulties in deployment due to extensive network scales and high computational demands, especially in edge computing environments. To address these challenges, we propose a model for maliciously encrypted traffic detection, named LightMETD. The model consists of two stages. In the first stage, we utilize Random Forest (RF) with a feature selection algorithm to quickly identify easily distinguishable traffic patterns. In the second stage, the filtered traffic data is converted into grayscale images and classified using an innovative lightweight MobileNetV3-S architecture. Our LightMETD model addresses the problem of large volume and high computational requirements of CNN models. To enhance the effectiveness of the LightMETD, we propose an innovative knowledge distillation method to train LightMETD. This method significantly improves the accuracy of malicious encrypted traffic detection by designing a distillation loss function that enables the model to better capture the intricate relationships between samples. We use a USTC-TFC2016 public traffic dataset and a locally collected dataset to demonstrate the effectiveness of LightMETD. LightMETD achieves an impressive 97% average classification accuracy. LightMETD significantly outperforms other baselines in terms of volume and detection speed, underscoring its viability and superiority in addressing real-world challenges posed by malicious encrypted traffic.
Yuecheng Wen, Xiaohui Han, Wenbo Zuo
IJCNN3
2024 Joint Entity and Relation Extraction Based on Prompt Learning and Multi-channel Heterogeneous Graph Enhancement
abstract
Joint extraction of entity and relation is crucial in information extraction, aiming to extract all relation triples from unstructured text. However, current joint extraction methods face two main issues. Firstly, they rarely consider the semantic information of entity and relation labels, leading to models that fail to fully understand and utilize the rich semantics in these labels, thereby limiting their performance. Secondly, although table-filling methods are widely used, they focus only on the start or end positions and ignore deep interactions between tables, relying solely on word-level information. To address these issues, we propose the P-MHE framework based on prompt learning and multi-channel heterogeneous graph enhancement. First, we use prompt templates to construct semantic nodes for entity and relation type labels, initializing them along with words as nodes in a heterogeneous graph. We iteratively fuse these semantic nodes through a message-passing mechanism to obtain node representations suitable for entity and relation extraction tasks. Secondly, we design a multi-channel heterogeneous graph to model node relationships from different perspectives, enhancing feature interactions among different types of nodes. Finally, we aggregate the semantic node information of entity and relation type labels after iteration, constructing separate decoding tables for each entity and relation type to better adapt to their respective characteristics. We evaluated our model on four public datasets. Experimental results show that P-MHE outperforms existing models on multiple public datasets. Extensive additional experiments further validate the effectiveness of our model.
Haiqing Lv, Xiaohui Han, Peipei Wang 0001, Wenbo Zuo, Lijuan Xu 0001
ISPA4
2024 PTGFI: A Prompt-Based Two-Stage Generative Framework for Function Name Inference
abstract
In the field of cybersecurity, analyzing malicious software or programs is crucial for preventing network attacks. Malicious code often exists in a stripped binary form to thwart analysis, presenting challenges for analysts. This study investigates inferring function names from stripped binary to aid security researchers in analyzing malicious code. We propose PTGFI, a Prompt-based Two-stage Generative framework for Function name Inference. The PTGFI framework transforms the task of inferring function names into a two-stage semantic generation problem. By capturing function descriptions of assembly functions and introducing prompt learning, effective inference of function names is achieved. In experiments, PTGFI outperforms the state-of-the-art model by 2.96 % in precision. Moreover, ablation studies demonstrate the effectiveness of advanced components within the PTGFI framework. We further validate the utility and reliability of function names generated by the PTGFI framework through case studies.
Xiaohui Han, Peipei Wang 0001, Wenbo Zuo
SMC4
2024 MLaD²: A Semi-Supervised Money Laundering Detection Framework Based on Decoupling Training
abstract
Money laundering (ML) poses a severe threat to financial stability and social security. Various money laundering detection methods have emerged in the past two decades. Among these methods, some semi-supervised ones based on graph neural networks (GNNs) have achieved impressive performance. However, the homogeneity hypothesis of GNN-based methods does not fit the ML detection scenario, affecting the detection performance. This paper presents a semi-supervised money laundering detection framework based on decoupling training (MLaD2). MLaD2 constructs a transaction relationship network based on node similarity (TRNNS) to model account interactions. Performing on TRNNS, MLaD2 learns the representation of accounts using a GNN. The weighting mechanism of TRNNS can overcome the drawback of the homogeneity hypothesis. Based on the learned account representations, MLaD2 adopts a decoupling training mechanism to build an ML accounts detection model, reducing its dependence on annotated data. The pre-training phase of the decoupling training employs a contrastive self-supervised learning model to learn the intrinsic characteristics of accounts. The fine-tuning phase extracts discriminative features between ML accounts and benign accounts with labeled data. Comprehensive evaluations and comparisons on a real-world ML dataset demonstrate that MLaD2 yields results that surpass existing methods, especially when training with a small scale of labeled samples.
Xuejiao Luo, Xiaohui Han, Wenbo Zuo, Wenyin Liu
IEEE Trans. Inf. Forensics Secur.3
2023 An Interpretable Vulnerability Detection Framework Based on Multi-task Learning
Xiaohui Han, Wenbo Zuo, Xuejiao Luo
ICONIP (13)3
2023 Communication-Efficient Federated Learning for Network Traffic Anomaly Detection
abstract
As an emerging machine learning method, Federated Learning is widely used in network anomaly detection scenarios. However, many current federated learning-based network anomaly detection works ignore the communication overhead problem during model training. The transmission of model parameters occupies a large amount of bandwidth, affecting the efficiency of network anomaly detection as well as the communication tasks of other programs. In this study, we propose eFedAD, an efficient federated learning framework for network traffic anomaly detection. Specifically, eFedAD uses singular value decomposition to compress the transmitted parameters and introduces a weighting mechanism to control the compression rate and aggregation proportion. In this way, eFedAD can significantly reduce the number of transmitted parameters and assign higher weights to more valuable clients, enhancing the generalization ability of the global model. Additionally, to address the slow convergence issue due to compressed parameters and minimize the total number of transmitted parameters, eFedAD uses a client selection method that is based on clustering clients’ data feature distributions. The experimental results demonstrate that eFedAD outperforms other compression methods and network anomaly detection approaches, achieving excellent performance.
Xiaohui Han, Guangqi Liu, Wenbo Zuo
MSN4
2023 RGSE: Robust Graph Structure Embedding for Anomalous Link Detection
abstract
Anomalous links such as noisy links or adversarial edges widely exist in real-world networks, which may undermine the credibility of the network study, e.g., community detection in social networks. Therefore, anomalous links need to be removed from the polluted network by a detector. Due to the co-existence of normal links and anomalous links, how to identify anomalous links in a polluted network is a challenging issue. By designing a robust graph structure embedding framework, also called RGSE, the link-level feature representations that are generated from both global embedding view and local stable view can be used for anomalous link detection on contaminated graphs. Comparison experiments on a variety of datasets demonstrate that the new model and its variants achieve up to an average 5.2% improvement with respect to the accuracy of anomalous link detection against the traditional graph representation models. Further analyses also provide interpretable evidence to support the model's superiority.
Zhen Liu 0006, Wenbo Zuo, Dongning Zhang, Xiaodong Feng 0001
IEEE Trans. Big Data2
2022 A Dynamic Transaction Pattern Aggregation Neural Network for Money Laundering Detection
abstract
Money laundering is a significant problem in the financial system and provides the conditions for financing various crimes. Previous methods apply many flexible algorithms, such as machine learning, graph mining, and anomaly detection. However, most of these contemporary methods do not adequately consider the dynamic characteristics of transactions, which may contain discriminative information for money laundering detection. To address this issue, in this paper, we propose a dynamic transaction pattern aggregation neural network (DTPAN) for money laundering detection. DTPAN utilizes two feature extractors to learn the dynamic features of transaction behaviors and the evolution of transfer relationships between accounts. Furthermore, it employs a feature enhancement module to enhance the behavior dynamic features, capturing the latent dependency between behavior dynamic and relationship evolution. Experimental results obtained with a real-world dataset demonstrate the effectiveness of DTPAN. The results also reveal that DTPAN can enhance the performance of ML detection by adequately exploring the dynamic information of transactions.
Xuejiao Luo, Xiaohui Han, Wenbo Zuo, Zhengyuan Xu
TrustCom3
2022 Social recommendation via deep neural network-based multi-task learning
Xiaodong Feng 0001, Zhen Liu 0006, Wenbing Wu, Wenbo Zuo
Expert Syst. Appl.4
2021 Self-paced learning enhanced neural matrix factorization for noise-aware recommendation
Zhen Liu 0006, Xiaodong Feng 0001, Yecheng Wang, Wenbo Zuo
Knowl. Based Syst.4