Huan Qian

dblp:285/7145 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context Knowledge
Tianci Pan, Huan Qian, Yaowen Zheng, Haining Wang 0001, Peng Zhang 0044, Jiaxing Cheng, Ge Chu, Ke Li 0042, Ming Zhou 0010
INFOCOM2
2025 LLM-THP: A Large Language Model-Powered Terminal Honeypot Dialogue Framework
abstract
With the acceleration of digital globalization, cyber threats are showing a trend of complexity and diversification, posing serious security challenges to critical information infrastructure and sensitive data. In this context, the development of efficient and accurate cyber threat detection technologies has become an urgent need to address potential risks and safeguard the security of the digital ecosystem. Terminal Honeypot is a security tool specifically designed to trap and analyze network attacks against end devices. It attracts attackers by simulating real terminal environments, thus collecting attacker behavioral data and attack methods. Development cycle, high resource consumption, and lack of the ability actively adapt to different attacker behaviors. These problems limit the analysis of the depth of the attack and the subsequent collection of attack information. Therefore, in order to adapt to the unknown attacks against Internet devices in the new situation, it is particularly important to design a terminal honeypot that is free from the predefined conditions and can flexibly respond to various attack scenarios. In this paper, a terminal honeypot design method based on LLM (Large Language Model), LLM-THP, is proposed to solve the problem that the existing honeypots are difficult to cope with unknown network threats. Firstly, we study to construct the initial honeypot environment by presetting prompts and design CoT-DPU, Chain-of-Thought Dynamic Prompt Update, which effectively avoids the token overflow problem in multiple attack interactions. For the challenges of attacker interaction, model invocation, and time asynchrony in practical deployment, the LLM-THP framework designs an efficient workflow. Experimental results show that LLM-THP is better than existing mainstream terminal honeypots in terms of honeypot attractiveness, correct response rate, and simulation.
Laite Wang, Huan Qian, Weilin Gai, Zhijian Zheng, Peng Zhang 0044, Ruoxing Wang
HPCC3
2025 TrapLLM: An LLM-powered Interactive Log-based Honeypot for Real-world Network Attacks
abstract
With the continual escalation of cyberattack tactics, zero-day exploits and advanced persistent threats (APTs) characterized by high stealth and dynamic evolution have posed significant challenges to traditional honeypot systems. Existing approaches are limited in service fidelity, interactive intelligence, and awareness of attacker intent, making it difficult to effectively lure advanced attackers or reconstruct threat chains from massive volumes of log data. To address these challenges, this paper introduces large language models (LLMs) as the core driving force to construct an architecture that integrates log-driven data governance with dynamic response generation. Leveraging the semantic understanding and generative capabilities of LLMs, the proposed method enables fine-grained identification of attacker intent, reconstruction of event sequences, and adaptive responses driven by retrieval-augmented generation (RAG), thereby realizing an intelligent closed-loop defense. This innovative integration overcomes the constraints of traditional static rules and low interaction emulation, achieving attack intent analysis and adaptive deception response, and providing an efficient pathway for proactive threat hunting. During a 25day deployment in a real production network environment, the system utilized 25 diversion nodes and 8 types of emulated services to capture over 1.39 million raw attack logs. Analysis revealed multiple attack attempts targeting 9 known Common Vulnerabilities and Exposures (CVE) vulnerabilities, along with a substantial number of high-severity attacks for which specific CVE identifiers could not be determined. Experimental results demonstrate that the proposed approach significantly improves both the accuracy of threat awareness and the timeliness of response, providing reliable support for the evolution of intelligent defense mechanisms.
Yunjun Ma, Gangyan Zeng, Peng Zhang 0044, Fuyuan Zhang, Ran Lin, Huan Qian
TrustCom7
2021 Performance Modeling Analysis of D-MSMR-CARQ with Relay Selection in Wireless Sensor Networks
abstract
Reliable and efficient real-time transmission is an important and challenging issue for wireless sensor networks (WSNs). Truncated retransmission times and relay selection can effectively reduce transmission delay and improve system throughput. A new direct multisource multirelay cooperative automatic repeat request (D-MSMR-CARQ) protocol based on truncation with two relay selection methods in WSNs is analytically analyzed in this paper. Firstly, based on two different relay selection methods under the maximum ratio combining (MRC), the discrete time Markov chain (DTMC) model of D-MSMR-CARQ protocol and state space is established. Secondly, for each D-MSMR-CARQ protocol based on different relay selection method, we obtain the closed-form expressions of the system average transmission delay and the expressions of the system throughput through state transition probabilities. Finally, numerical results reveal that the first relay selection method outperforms the second relay selection method on the average transmission delay performance for the proposed protocol. More specifically, the delay performance of the proposed protocol can be improved by 13% compared with the nondirect-link protocol when the channel environment is the same; the proposed protocol improves the throughput performance by 47% compared with the nondirect protocol when the channel environment is harsh under the same simulation parameters. Furthermore, the optimal number of source nodes and relay nodes is determined.
Yongqiang Zhou, Huan Qian, Qihao Wang, Suoping Li
Secur. Commun. Networks2
2020 Subpixel-Level Edge Feature Matching for SAR and Optical Images Based on Zernike Moments
abstract
A sub-pixel edge feature matching method based on Zernike moment is proposed. By using PPB filtering method to preprocess SAR images, Zernike moments are used to extract sub-pixel edge feature maps of SAR images and optical images. It innovatively proposes the extraction of phase consistency feature points based on low-contrast nonsuppressed SAR-Harris multi-scale space. Based on the feature detection results, a HOG feature descriptor is constructed on the subpixel edge feature map, and finally feature matching is performed according to geometric constraints. Experimental results show that this method has obvious advantages in matching SAR images with optical images compared with SIFT, Schwind, Suri, and SAR-SIFT methods.
Huan Qian, Jianwei Yue, Min Chen 0015, Modi Wang, Haiqiang Xin
IGARSS1