Wen Wang 0008

dblp:29/4680-8 · DBLP profile ↗
← Back
18ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-3943-3204ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 3 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Towards Automatic Rule Extraction for Intrusion Detection with Explainable AI
abstract
Intrusion detection based on deep learning is inherently limited by the black-box nature of the models, which makes it difficult to ensure the trustworthiness of the results. Explainable Artificial Intelligence (XAI) techniques address this limitation by leveraging the powerful feature learning capabilities of black-box deep learning models and employing XAI methods to explore their decision boundaries, enabling the effective extraction of rules for intrusion detection. This approach provides a practical solution to the aforementioned challenges. In this paper, we propose an XAI-based automated rule extraction method for intrusion detection, designed to offer highly interpretable detection capabilities for encrypted traffic. The method begins by using CICFlowMeter to extract tabular traffic features and training a surrogate model to learn the representations of these features. Subsequently, an automated approach is developed to extract decision rules based on information from neural network layers, generating an initial rule set. This rule set is further refined through fine-tuning to optimize detection rules. We conducted experiments on two datasets using the generated detection rules. The experimental results demonstrate that the proposed method not only achieves excellent detection performance but also produces rules with high interpretability.
Xingyu Wang 0003, Han Miao, Zhaoxuan Li, Wen Wang 0008, Feng Liu 0001
IJCNN4
2025 Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature Imputation
abstract
Network traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa).
Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001
IEEE Trans. Netw.6
2024 Poster: PGPNet: Classify APT Malware Using Prediction-Guided Prototype Network
abstract
As the popularity of Advanced Persistent Threat (APT) grows, APT malware group classification has attracted more attention recently.However, most of previous methods use simple classifiers for group classification, ignoring the bias caused by the sparse number of revealed malware and the differences in functionality distribution of most groups.In this paper, we propose a Prediction-Guided Prototype Network (PGPNet) that could quickly adapt to new classification tasks with limited supervised samples based on the metalearning architecture.Adding malware functionality classification as an auxiliary task is beneficial for feature learning, and the bias of distribution differences is eliminated by intervening the predicted results into the group classifier.Experimental results on a APT malware dataset show that PGPNet successfully exploits the contextual information and predictions of the auxiliary task and achieves state-of-the-art performance.
Huaifeng Bao, Wenhao Li 0005, Zhaoxuan Li, Han Miao, Wen Wang 0008, Feng Liu 0001
CCS5
2024 Poster: Enhancing Network Traffic Analysis with Pre-trained Side-channel Feature Imputation
abstract
The recent advances in learning-based methodologies has underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. Nonetheless, the distribution of these features has been identified as susceptible, particularly in the expansive and intricate network topologies characteristic of the modern Internet. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based augmentation framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic. The crux of Nüwa lies in its ability to reconstruct the side-channel features, with a particular focus on the temporal attributes of the missing packets within a traffic session. Nüwa is comprised of a word-level Sequence2Embedding module, a Traffic Noise-based Self-supervised Pre-trained Masking Strategy, and a Traffic Side-Channel Feature Imputation Module. Experiments across four diverse real-world scenarios substantiate Nüwa's capacity to restore the performance of prevalent temporal models while maintaining the integrity of the imputed features.
Faqi Zhao, Duohe Ma, Wenhao Li 0005, Feng Liu 0001, Wen Wang 0008
CCS5
2024 CAFE: Robust Detection of Malicious Macro based on Cross-modal Feature Extraction
abstract
The detection of malicious macros has been a prominent focus of research. Previous approaches exhibit two notable shortcomings. Firstly, methods centered on document and macro code features often fall short in effectively countering targeted adversarial strategies. Secondly, detection techniques relying on deceptive information, such as visual and textual cues, although alleviating certain challenges, introduce a new vulnerability to adversarial machine learning techniques. In this paper, we present Collaborative Adaptive Feature Extraction method (CAFE), designed for robust detection based on deceptive information. The core of CAFE is a feature fusion network architecture, where modality-shared associations and modalityprivate information are modeled from feature of different modalities, resulting in independently valid and comprehensive feature representations. An adaptive feature sampling module is introduced to address partial feature absence, enhancing detection robustness. Experimental results, conducted on two datasets, demonstrate that CAFE adeptly captures shared and complementary information from two modalities, showcasing its capability for robust malicious macro detection in the presence of input noise and adversarial samples. Index Terms—Malicious Macro Detection, Multi-modal Features, Model Robustness, Security Wen Wang is corresponding author.
Huaifeng Bao, Xingyu Wang 0003, Wenhao Li 0005, Jinpeng Xu, Peng Yin 0001, Wen Wang 0008, Feng Liu 0001
CSCWD6
2024 A LLM-based agent for the automatic generation and generalization of IDS rules
abstract
Cyberattacks on digital services and Internet of Things (IoT) are rising, employing complex tactics. Using intrusion detection systems (IDS) to detect and counter threats at key network points is vital for strong cybersecurity. Traditional rule-based network IDS rely on predefined rules, which may not effectively recognize the myriad complex variants of potential attacks. AI-driven methods for detecting malicious traffic offer enhanced capabilities but can fall short in terms of interpretability and performance under high-throughput network conditions. To address these challenges, we propose a LLM-based (Large Language Model) agent that utilizes multiple sources inputs to generate and generalize rules. The generated rules are designed to detect a variety of corresponding malicious threats, while the generalized rules are crafted to identify similar variant attacks. We have amassed an extensive dataset, comprising vulnerability security reports, malicious traffic, and original IDS rules from authoritative sources, which serve as input for the LLM-based agent. Subsequently, comparative experiments were conducted to assess the performance of the new rules in detecting malicious traffic. The experimental results demonstrate the superior performance of these new rules across various metrics for malicious traffic detection.
Haoning Chen, Huaifeng Bao, Wen Wang 0008, Feng Liu 0001, Guoqiao Zhou, Peng Yin 0001
TrustCom4
2024 Stories behind decisions: Towards interpretable malware family classification with hierarchical attention
Huaifeng Bao, Wenhao Li 0005, Huashan Chen, Han Miao, Qiang Wang 0059, Zixian Tang, Feng Liu 0001, Wen Wang 0008
Comput. Secur.8
2023 Towards Open-Set APT Malware Classification under Few-Shot Setting
abstract
Advanced Persistent Threat (APT) malware group classification has attracted more attention recently. Previous methods have two downsides. First, most use conventional classifiers ignoring the bias caused by the sparse number of revealed malware. Second, they conducted on closed-set without considering the constant stream of novel APT groups. In this paper, we propose a framework for open-set APT malware classification under a few-shot setting. First, the pre-trained encoder extracts the dynamic behavioral features of APT malware. Then the prototypes of known APT groups are calculated. Based on these prototypes the classification probability of the test sample is calculated. Finally, we devise plug-and-play open-set loss and dynamic triplet threshold modules to construct clear boundaries of known categories to achieve open-set recognition. Experimental results conducted on two datasets show that our approach achieves state-of-the-art performance, enabling the detection of known APT malware and recognition of unknown malware with few known APT-labelled malware.
Huaifeng Bao, Wen Wang 0008, Feng Liu 0001
GLOBECOM2
2019 A new visual evaluation criterion of visual cryptography scheme for character secret image
YaWei Ren, Feng Liu 0001, Wei Qi Yan 0001, Wen Wang 0008
Multim. Tools Appl.4
2017 Temporal Integration Based Visual Cryptography Scheme and Its Application
Wen Wang 0008, Feng Liu 0001, Teng Guo 0005, YaWei Ren
IWDW1
2016 Privacy Monitor
Teng Guo 0005, Feng Liu 0001, Wen Wang 0008, BingTao Yu
IWDW3
2016 Collusive Attacks to Partition Authentication Visual Cryptography Scheme
YaWei Ren, Feng Liu 0001, Wen Wang 0008
IWDW3
2016 Halftone Visual Cryptography with Complementary Cover Images
Feng Liu 0001, Zhengxin Fu, Bin Yu 0003, Wen Wang 0008
IWDW5
2016 Information Security Display Technology with Multi-view Effect
Wen Wang 0008, Feng Liu 0001, Teng Guo 0005, YaWei Ren
IWDW1
2015 A New Construction of Tagged Visual Cryptography Scheme
YaWei Ren, Feng Liu 0001, Dongdai Lin, Rongquan Feng, Wen Wang 0008
IWDW5
2015 An Improved Aspect Ratio Invariant Visual Cryptography Scheme with Flexible Pixel Expansion
Wen Wang 0008, Feng Liu 0001, Wei Qi Yan 0001, Teng Guo 0005
IWDW1
2013 Threshold Secret Image Sharing
Teng Guo 0005, Feng Liu 0001, Chuan Kun Wu, Ching-Nung Yang, Wen Wang 0008, YaWei Ren
ICICS5
2013 The Security Defect of a Multi-pixel Encoding Method
Teng Guo 0005, Feng Liu 0001, Chuan Kun Wu, YoungChang Hou, YaWei Ren, Wen Wang 0008
ISC6