VLDB 2026 Research / reviewers in the wild / expert
Huaifeng Bao
dblp:294/6531
· DBLP profile ↗
12ranked-venue papers
4as first author
12since 2021 · last 2025
0000-0002-9657-3633ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Computer networks · 4 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Magnifier: Detecting Network Access via Lightweight Traffic-Based Fingerprints
Wenhao Li 0005, Qiang Wang 0059, Huaifeng Bao, Xiaoyu Zhang 0002, Lingyun Ying, Zhaoxuan Li, Huamin Jin, Shuai Wang 0079 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature ImputationabstractNetwork traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa). Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001 |
IEEE Trans. Netw. | 3 |
| 2024 | Poster: PGPNet: Classify APT Malware Using Prediction-Guided Prototype NetworkabstractAs the popularity of Advanced Persistent Threat (APT) grows, APT malware group classification has attracted more attention recently.However, most of previous methods use simple classifiers for group classification, ignoring the bias caused by the sparse number of revealed malware and the differences in functionality distribution of most groups.In this paper, we propose a Prediction-Guided Prototype Network (PGPNet) that could quickly adapt to new classification tasks with limited supervised samples based on the metalearning architecture.Adding malware functionality classification as an auxiliary task is beneficial for feature learning, and the bias of distribution differences is eliminated by intervening the predicted results into the group classifier.Experimental results on a APT malware dataset show that PGPNet successfully exploits the contextual information and predictions of the auxiliary task and achieves state-of-the-art performance. Huaifeng Bao, Wenhao Li 0005, Zhaoxuan Li, Han Miao, Wen Wang 0008, Feng Liu 0001 |
CCS | 1 |
| 2024 | Poster: Towards Real-Time Intrusion Detection with Explainable AI-Based DetectorabstractIdentifying malicious traffic is crucial for safeguarding internal networks from privacy breaches.Intrusion Detection Systems (IDS) traditionally rely on inefficient and outdated rule-sets, necessitating a shift towards AI-driven, learning-based algorithms for enhanced detection capabilities.Despite their promise, AI-integrated IDS face deployment challenges due to complex, opaque decision-making processes that can lead to latency and an increased risk of false positives.This paper presents the Explainable AI-based Intrusion Detection System (XAI-IDS), addressing the limitations of both rule-based and AI-driven IDS by integrating interpretable deep learning models.XAI-IDS employs tree regularization to transform complex models into efficient, transparent decision trees, facilitating real-time detection with improved accuracy and explainability.Experiments on two benchmark datasets demonstrate XAI-IDS's superior performance, offering a scalable solution to the challenge of identifying malicious traffic with reduced risk of false positives. Wenhao Li 0005, Duohe Ma, Zhaoxuan Li, Huaifeng Bao, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002 |
CCS | 4 |
| 2024 | CAFE: Robust Detection of Malicious Macro based on Cross-modal Feature ExtractionabstractThe detection of malicious macros has been a prominent focus of research. Previous approaches exhibit two notable shortcomings. Firstly, methods centered on document and macro code features often fall short in effectively countering targeted adversarial strategies. Secondly, detection techniques relying on deceptive information, such as visual and textual cues, although alleviating certain challenges, introduce a new vulnerability to adversarial machine learning techniques. In this paper, we present Collaborative Adaptive Feature Extraction method (CAFE), designed for robust detection based on deceptive information. The core of CAFE is a feature fusion network architecture, where modality-shared associations and modalityprivate information are modeled from feature of different modalities, resulting in independently valid and comprehensive feature representations. An adaptive feature sampling module is introduced to address partial feature absence, enhancing detection robustness. Experimental results, conducted on two datasets, demonstrate that CAFE adeptly captures shared and complementary information from two modalities, showcasing its capability for robust malicious macro detection in the presence of input noise and adversarial samples. Index Terms—Malicious Macro Detection, Multi-modal Features, Model Robustness, Security Wen Wang is corresponding author. Huaifeng Bao, Xingyu Wang 0003, Wenhao Li 0005, Jinpeng Xu, Peng Yin 0001, Wen Wang 0008, Feng Liu 0001 |
CSCWD | 1 |
| 2024 | A LLM-based agent for the automatic generation and generalization of IDS rulesabstractCyberattacks on digital services and Internet of Things (IoT) are rising, employing complex tactics. Using intrusion detection systems (IDS) to detect and counter threats at key network points is vital for strong cybersecurity. Traditional rule-based network IDS rely on predefined rules, which may not effectively recognize the myriad complex variants of potential attacks. AI-driven methods for detecting malicious traffic offer enhanced capabilities but can fall short in terms of interpretability and performance under high-throughput network conditions. To address these challenges, we propose a LLM-based (Large Language Model) agent that utilizes multiple sources inputs to generate and generalize rules. The generated rules are designed to detect a variety of corresponding malicious threats, while the generalized rules are crafted to identify similar variant attacks. We have amassed an extensive dataset, comprising vulnerability security reports, malicious traffic, and original IDS rules from authoritative sources, which serve as input for the LLM-based agent. Subsequently, comparative experiments were conducted to assess the performance of the new rules in detecting malicious traffic. The experimental results demonstrate the superior performance of these new rules across various metrics for malicious traffic detection. Haoning Chen, Huaifeng Bao, Wen Wang 0008, Feng Liu 0001, Guoqiao Zhou, Peng Yin 0001 |
TrustCom | 3 |
| 2024 | Stories behind decisions: Towards interpretable malware family classification with hierarchical attention
Huaifeng Bao, Wenhao Li 0005, Huashan Chen, Han Miao, Qiang Wang 0059, Zixian Tang, Feng Liu 0001, Wen Wang 0008 |
Comput. Secur. | 1 |
| 2023 | PackGenome: Automatically Generating Robust YARA Rules for Accurate Malware Packer DetectionabstractBinary packing, a widely-used program obfuscation style, compresses or encrypts the original program and then recovers it at runtime. Packed malware samples are pervasive---they conceal arresting code features as unintelligible data to evade detection. To rapidly respond to large-scale packed malware, security analysts search specific binary patterns to identify corresponding packers. The quality of such packer patterns or signatures is vital to malware dissection. However, existing packer signature rules severely rely on human analysts' experience. In addition to expensive manual efforts, these human-written rules (e.g., YARA) also suffer from high false positives: as they are designed to search the pattern of bytes rather than instructions, they are very likely to mismatch with unexpected instructions. Shijia Li, Jiang Ming 0002, Pengda Qiu, Qiyuan Chen 0006, Lanqing Liu, Huaifeng Bao, Qiang Wang 0059, Chunfu Jia |
CCS | 6 |
| 2023 | Towards Open-Set APT Malware Classification under Few-Shot SettingabstractAdvanced Persistent Threat (APT) malware group classification has attracted more attention recently. Previous methods have two downsides. First, most use conventional classifiers ignoring the bias caused by the sparse number of revealed malware. Second, they conducted on closed-set without considering the constant stream of novel APT groups. In this paper, we propose a framework for open-set APT malware classification under a few-shot setting. First, the pre-trained encoder extracts the dynamic behavioral features of APT malware. Then the prototypes of known APT groups are calculated. Based on these prototypes the classification probability of the test sample is calculated. Finally, we devise plug-and-play open-set loss and dynamic triplet threshold modules to construct clear boundaries of known categories to achieve open-set recognition. Experimental results conducted on two datasets show that our approach achieves state-of-the-art performance, enabling the detection of known APT malware and recognition of unknown malware with few known APT-labelled malware. Huaifeng Bao, Wen Wang 0008, Feng Liu 0001 |
GLOBECOM | 1 |
| 2023 | Prism: Real-Time Privacy Protection Against Temporal Network Traffic AnalyzersabstractTraffic analysis is widely used in network monitoring. However, the attackers can sometimes infer sensitive information from the patterns of the encrypted network traffic, which poses a threat to network security. Most existing countermeasures are proposed to obfuscate traffic flows using adversarial examples. However, there are two challenges when adding perturbations to live network traffic. Firstly, the perturbations imposed on the feature space cannot be conveniently projected to original traffic flows in feature-space based methods. Secondly, it is laborious and impractical to apply symmetrical framework to encode/decode the adversarial traffic in traffic-space based approaches. To address the above issues, in this paper, we propose an asymmetric defending scheme, namelyPrism, to protect theliveconnection privacy against attacks of temporal network traffic analyzers. Specifically,Prismfirst extracts standardized temporal features via Power-Law Division (PLD) algorithm, and then employs Time-stacked State Transition Model (TSTM) to obtain the fingerprint of each application. Finally,Prismdefends against the analyzers with online traffic perturbation. Since thePrismis designed as a traffic-space based defender with asymmetric defending structure, the deployment is lightweight and efficient. Experimental results on two real-world datasets demonstrate the effectiveness and generalization of our adversarial perturbations. In particular, it is encouraging to see that our proposed defending scheme outperforms the advanced countermeasures, such as adversarial training and traffic filter. Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Zhaoxuan Li, Haichao Shi, Qiang Wang 0059 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | ProGraph: Robust Network Traffic Identification With Graph PropagationabstractNetwork traffic identification is critical for effective network management. Existing methods mostly focus on invariant network environments with stable attribute distributions. Unfortunately, however, they can hardly be adaptive to the variation of practical networks and suffer from significant performance degradation. This problem largely stems from the over-dependence of existing methods on the vulnerable side-channel features. To address this issue, in this paper we propose a graph-based approach, namely ProGraph, to ensure robust network traffic classification among various network environments. The core idea of ProGraph is to construct a correlation graph with session clusters aggregated from different networks, based on which graph propagation can be effectively implemented to predict labels of testing nodes in an iterative manner. ProGraph enhances the correlation between clusters of the same class to provide reliable paths for label dissemination from the labeled clusters to the testing ones. It is encouraging to see that the proposed ProGraph achieves an accuracy of 92.25% in networks with constant attributes, while remaining stable with the accuracy of 90.89% when deployed in different networks, which significantly outperforms the state-of-the-art approaches. Meanwhile, ProGraph can accurately identify the novel classes which do not exist in the training dataset, with an AUC of 95.11. Last but not least, a carefully constructed dataset, namely CrossNet2021, containing network traffic of 20 classes of applications from two distinct networking scenarios, is made publicly available to support further research. Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Haichao Shi, Qiang Wang 0059 |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | Robust network traffic identification with graph matching
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Qiang Wang 0059, Zhaoxuan Li |
Comput. Networks | 3 |