Haocong Li

dblp:294/2607 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0001-2314-1354ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 SoFi: Spoofing OS Fingerprints Against Network Reconnaissance
abstract
Fingerprinting is a network reconnaissance technique utilized for gathering information about online computing systems, including operation systems and applications. Unfortunately, attackers typically leverage fingerprinting techniques to locate, enumerate, and subsequently target vulnerable systems, which is the first primary stage of a cyber attack. In this work, we explore the susceptibility of machine learning (ML)-based classifiers to misclassification, where a slight perturbation in the packet is included to spoof OS fingerprints. We propose SOFI (Spoof OS Fingerprints), an adversarial example generation algorithm under TCP/IP specification constraints, to create effective perturbations in a packet for deceiving an OS fingerprint. Specifically, SOFI has three major technical innovations: (1) it is the first to utilize adversarial examples to automatically perturb fingerprinting techniques; (2) it complies with constraints and integrity of network packets; (3) it achieves a high success rate in spoofing OS fingerprints. We validate the effectiveness of adversarial packets against active and passive OS fingerprints, verifying the transferability and robustness of SOFI. Comprehensive experimental results demonstrate that SOFI automatically identifies applicable and available OS fingerprint features, unlike existing tools relying on expert knowledge.
Haocong Li, Wei Wang 0012, Haining Wang 0001, Xiaobo Ma 0001, Shouling Ji, Qiang Li 0007
IEEE Trans. Inf. Forensics Secur.2
2023 A Commitment and Ring Signature based Scheme for Amount and Identity Privacy Protection in Blockchain
abstract
Blockchain has been envisioned as an anonymous cryptocurrency framework and can be applied in various applications such as e-payment, share economics, and distributed ledger. Although an account is anonymous, privacy in terms of consumption behaviors still imposes leakage risks. For example, an adversary may infer the consumption capability related to an account further by analyzing the history of consumption records. It is thus of critical importance to design a solution to preserve the anonymity of both transaction amount and transaction peer’s identity, which is changeable because the amount must be still authenticated in anonymity. In this paper, we propose a scheme by using Pedersen commitment to anonymize the transaction amount, and together using ring signature to conceal the transaction peer’s identity while maintaining authentication. Especially, we further improve the security of anonymous authentication enabled by ring signature by introducing accountability, which can defend against double-spending attacks by penalization and empower auditability. The extensive performance and security analysis justify the applicability of the proposed scheme.
Shiyong Huang, Haocong Li, Ruoting Xiong, Wei Ren 0002, Yi Ren 0001
TrustCom2
2023 A two-way dense feature pyramid networks for object detection of remote sensing images
Haocong Li, Hui Ma 0009, Yanbo Che, Zedong Yang
Knowl. Inf. Syst.1