Huijuan Zhu 0001

dblp:297/0152-1 · also Hui-juan Zhu 0001 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
19since 2021 · last 2026
0000-0003-2751-2607ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 3 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CADroid: A cross-combination attention based framework for android malware detection
Binqin Lu, Shangnan Yin, Chenhao Zheng, Huijuan Zhu 0001
Expert Syst. Appl.5
2026 SAPE: A Scalable Aggregation With Parallel Encoder for Federated Learning in VANETs
abstract
Federated Learning (FL) has recently gained prominence in the context of Vehicular Ad-hoc Networks (VANETs) as a promising approach to enhancing autonomous driving capabilities. However, vehicles' high mobility, real-time communication, and dynamic network topology lead to frequent disconnections during operation, which may slow down the convergence of FL or even lead to training failure. In this study, we propose a scalable aggregation scheme (SAPE) designed to improve computation efficiency and address vehicle dropouts. SAPE employs a lossless encoding algorithm with parallel technology for efficient aggregation of large vectors. Then, we leverage TJL (ACSAC '22) to reconstruct gradients for dropout vehicles, using online vehicles to establish a$k$-regular graph. In a network with$N$vehicles, SAPE achieves a secure aggregation overhead of$O(log^{2}(N))$, as opposed to$O(N^{2})$, tolerating a vehicle dropout rate of up to 33%. Furthermore, we conduct a theoretical security analysis of SAPE to prove its security under honest-but-curious (HBC) and malicious attack models. Extensive experiments show that SAPE outperforms existing baseline aggregation schemes by up to 1.4× speedups in aggregation time.
Xia Feng, Wenhao Cheng, Huijuan Zhu 0001, Zhiquan Liu 0001, Liangmin Wang 0001
IEEE Trans. Mob. Comput.4
2026 Reliable Interpretations of Deep Learning-Based Malware Detectors via Deep Q-Networks
abstract
Deep learning has become widely used in Android malware detection, but its black-box nature raises trust concerns, limiting its use in critical security areas. To address this, various interpretation methods have been proposed. Unfortunately, these solutions often suffer from inconsistent results and poor adaptability to model updates. In this work, we propose XDQNMal, a Deep Q-Networks (DQN)-based global interpretation framework designed to uncover the critical features that drive decisions in deep learning-based malware detectors. To enhance the reliability of interpretation, XDQNMal captures API call frequency features derived from the runtime behavior of each application (App). Then, it unites a DQN model with the TabPFN detection model to work collaboratively, using variations in detection results as reward signals. These signals guide the DQN model to gradually identify the most impactful features as interpretations for the detection model’s decisions. Our experimental evaluation on real-world datasets demonstrates that the proposed XDQNMal framework generates reliable interpretation for deep learning-based malware detection models. For instance, suppressing the critical features identified by XDQNMal leads to an average decrease of 20.30% in the probability that the malicious sample is predicted as malicious, highlighting the pivotal role these features play in the model’s decision-making.
Huijuan Zhu 0001, Chenhao Zheng, Zhongyuan Liu, Yuan Zhang 0004
IEEE Trans. Netw. Serv. Manag.1
2025 CLEP: A Novel Contrastive Learning Method for Evolutionary Reentrancy Vulnerability Detection
abstract
Reentrancy vulnerabilities in smart contracts have been exploited to steal enormous amounts of money, thus detecting reentrancy vulnerabilities is a hotspot issue in security research. However, a new attack is emerging in which attackers continuously release new reentrancy patterns to exploit fresh vulnerabilities and obfuscate existing ones. Existing detection methods neglect the time-series evolution of vulnerabilities across different smart contract versions, leading to a gradual decline in their effectiveness over time. We investigate the time-series correlations among vulnerabilities in various versions and refer to these as Evolutionary Reentrancy Vulnerabilities (ERVs). We summarize that ERVs detection faces two key challenges: (i) capturing the evolving pattern of ERVs along a complete evolutionary chain and (ii) detecting fresh reentrancy vulnerabilities in new versions. To address these challenges, we propose CLEP, a novel Contrastive Learning with Evolving Pairs detection method. It can effectively capture the evolving patterns by discerning similarities and differences across versions. Specifically, we first modified the sample distribution by incorporating version declarations as time-series evolution information. Then, leveraging the hierarchical similarity, we design an evolving pairs scheme to form negative and positive contract pairs across versions. Finally, we build a complete evolutionary chain by proposing a version-aware contrastive sampler. Our experimental results show that CLEP not only outperforms state-of-the-art baselines in version-specific scenarios but also shows promising performance in cross-version evolution scenarios.
Jie Chen 0099, Liangmin Wang 0001, Huijuan Zhu 0001, Victor S. Sheng
AAAI3
2025 A Triplet-Learning-Based Framework for Cross-Version Smart Contract Vulnerability Detection
abstract
As security concerns in blockchain platforms continue to rise, triggered by substantial financial losses, detecting vulnerabilities in smart contracts has emerged as a crucial focus for both academia and industry. Although many promising vulnerability detection methods for Ethereum have been proposed in recent years, their long-term reliability and adaptability across different versions of smart contracts remain unresolved. Specifically, the performance of these methods tends to degrade over time, and in some cases, they may even fail entirely. A key factor contributing to this dilemma is the regular updates of Solidity versions. These updates often introduce new features or syntax changes, which significantly influence how vulnerabilities are manifested and detected. To tackle this challenge, we propose Triplet Detection (TD), a triplet learning-based vulnerabilities detection framework, to preserve invariant vulnerability knowledge across multiple Solidity versions. In TD, we propose a novel Smart Offline Mining (SOM) strategy to guide triplet selection, ensuring the learned embedding capture both foundational and version-independent vulnerability features. The experimental results demonstrate that TD outperforms state-of-the-art vulnerability detection tools and baseline methods. Furthermore, TD achieves superior performance in detecting vulnerabilities across different versions of smart contracts (e.g., from v0.4 to v0.8), highlighting its capability to tackle the challenges of long-term reliability and adaptability in detection models due to the updates of smart contract versions.
Huijuan Zhu 0001, Qiang Zhou 0010, Shiyu Gan, Xia Feng
IEEE Internet Things J.2
2025 SmartGuard: Making Prediction Verifiable Through Transaction Sequences for Smart Contract Vulnerability Detection
abstract
Deep learning-based detectors have been widely proposed to predict vulnerabilities in smart contracts, yet their unreliable predictions pose severe security risks to financial transactions, making it critical to verify the reliability of vulnerability predictions. However, existing methods only produce prediction results, failing to provide an evidence chain to check whether these predicted vulnerabilities genuinely exist and deliver further guidance for fixing the vulnerabilities. Thus, making these vulnerability predictions verifiable remains an unexplored problem. In this paper, we propose SmartGuard, a novel verifiable vulnerability prediction framework for deep learning-based detectors and specifically designed for smart contracts. It integrates a deep learning-based detector with a symbolic prediction validator, where the latter acts as the backend formal engine to verify vulnerability predictions. Specifically, we present a graph-sequence multi-task learning model to detect vulnerabilities while generating transaction sequences that serve as evidence chains, explicitly revealing the triggering logic behind vulnerabilities. To bridge the gap between deep learning-based detectors and symbolic validators, we symbolically execute the generated transaction sequences against the verification conditions of vulnerability predictions. Furthermore, we propose a new metric, Vulnerability Prediction Suspiciousness (VPS), to evaluate the reliability of the predicted results. We implement SmartGuard on three representative types of vulnerabilities (Reentrancy, Ether-leaking, and Suicidal) to evaluate its performance in real-world scenarios. Our experimental results show that SmartGuard can effectively verify doubtful vulnerability predictions in real-world scenarios. It also outperforms state-of-the-art baselines by consistently reducing false reports by at least 15% across various Solidity versions. Case studies on complex contracts and DApps further demonstrate SmartGuard’s effectiveness in practice.
Jie Chen 0099, Liangmin Wang 0001, Huijuan Zhu 0001
IEEE Trans. Inf. Forensics Secur.3
2024 An interpretable model for large-scale smart contract vulnerability detection
abstract
Smart contracts hold billions of dollars in digital currency, and their security vulnerabilities have drawn a lot of attention in recent years. Traditional methods for detecting smart contract vulnerabilities rely primarily on symbol execution, which makes them time-consuming with high false positive rates. Recently, deep learning approaches have alleviated these issues but still face several major limitations, such as lack of interpretability and susceptibility to evasion techniques. In this paper, we propose a feature selection method for uplifting modeling. The fundamental concept of this method is a feature selection algorithm, utilizing interpretation outcomes to select critical features thereby reducing the scales of features. The learning speed could be accelerated significantly because of the reduction of the feature size. The experiment shows that our proposed model performs well in six types of vulnerability detection. The accuracy of each is higher than 93% and the average detection time of each smart contract is less than 1 ms. Notably, through our proposed feature selection algorithm, the training time of each type of vulnerability is reduced by nearly 80% compared with its original.
Xia Feng, Huijuan Zhu 0001, Victor S. Sheng
Blockchain Res. Appl.4
2024 Joint Alignment Networks For Few-Shot Website Fingerprinting Attack
abstract
Abstract Website fingerprinting (WF) attacks based on deep neural networks pose a significant threat to the privacy of anonymous network users. However, training a deep WF model requires many labeled traces, which can be labor-intensive and time-consuming, and models trained on the originally collected traces cannot be directly used for the classification of newly collected traces due to the concept drift caused by the time gap in the data collection. Few-shot WF attacks are proposed for using the originally and few-shot newly collected labeled traces to facilitate anonymous trace classification. However, existing few-shot WF attacks ignore the fine-grained feature alignment to eliminate the concept drift in the model training, which fails to fully use the knowledge of labeled traces. We propose a novel few-shot WF attack called Joint Alignment Networks (JAN), which conducts fine-grained feature alignment at both semantic-level and feature-level. Specifically, JAN minimizes a distribution distance between originally and newly collected traces in the feature space for feature-level alignment, and utilizes two task-specific classifiers to detect unaligned traces and force these traces mapped within decision boundaries for semantic-level alignment. Extensive experiments on public datasets show that JAN outperforms the state-of-the-art few-shot WF methods, especially in the difficult 1-shot tasks.
Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001, Heping Song
Comput. J.3
2024 A lightweight deep learning-based android malware detection framework
Shangnan Yin, Xia Feng, Huijuan Zhu 0001, Victor S. Sheng
Expert Syst. Appl.4
2024 WF-Transformer: Learning Temporal Features for Accurate Anonymous Traffic Identification by Using Transformer Networks
abstract
Website Fingerprinting (WF) is a network traffic mining technique for anonymous traffic identification, which enables a local adversary to identify the target website that an anonymous network user is browsing. WF attacks based on deep convolutional neural networks (CNN) get the state-of-the-art anonymous traffic classification performance. However, due to the locality restriction of CNN architecture for feature extraction on sequence data, these methods ignore the temporal feature extraction in the anonymous traffic analysis. In this paper, we present Website Fingerprinting Transformer (WF-Transformer), a novel anonymous network traffic analysis method that leverages Transformer networks for temporal feature extraction of traffic traces and improves the classification performance of Tor encrypted traffic. The architecture of WF-Transformer is specially designed for traffic trace processing and can classify anonymous traffic effectively. Furthermore, we evaluate the performance of WF-Transformer in both closed-world and open-world scenarios. In the closed-world scenario, WF-Transformer attains 99.1% accuracy on Tor traffic without defenses, better than state-or-the-art attacks, and archives 92.1% accuracy on the traces defended by WTF-PAD method. In the open-world scenario, WF-Transformer has better precision and recall on both defended and non-defended traces. Furthermore, WF-Transformer with a short input length (2000 cells) outperforms the DF method with a long input length (5000 cells).
Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001, Victor S. Sheng
IEEE Trans. Inf. Forensics Secur.3
2024 A Dynamic Analysis-Powered Explanation Framework for Malware Detection
abstract
Deep learning has been widely adopted in Android malicious software (malware) detection. However, poor explanation in deep learning-based detection models severely undermines user trusts and poses a significant obstacle to their practical promotion in critical security domains. Some studies strive to uncover the rationale behind a model's decision. Unfortunately, these efforts are often hindered by the limitations of feature extraction methods, such as primarily relying on static analysis to derive separate and approximate behavioral descriptions of applications (apps). As a result, establishing a reliable interpretation for deep learning-based malware detection models remains an open issue. In this work, we propose a novel framework XDeepMal to interpret deep learning-based malware detection models. Specifically, in XDeepMal, we formulate a dynamic analysis tool XTracer+to capture runtime behaviors of apps and automatically generate their continuous behavior trajectories. Then, we propose a novel interpreter to pinpoint certainty behavior fragments that are crucial for deep learning models to make their decisions. This approach regards the identification of the most critical fragments as an optimization problem and leverages heuristic algorithms for implementation. We conduct extensive experiments on a real-world dataset to investigate the effectiveness and reliability of XDeepMal. These experiments cover intuitive case studies (malware family and individual app) and in-depth quantitative analysis. Additionally, we evaluate its coverage and efficiency. Our experimental results demonstrate that XDeepMal is capable of generating convincing interpretations for deep learning (e.g., Transformer) based models within feasible inference time, which greatly benefits security analysts in accurately comprehending why an app is identified as malware by deep learning-based detection models.
Huijuan Zhu 0001, Xilong Chen, Liangmin Wang 0001, Victor S. Sheng
IEEE Trans. Knowl. Data Eng.1
2024 A Novel Knowledge Search Structure for Android Malware Detection
abstract
While the Android platform is gaining explosive popularity, the number of malicious software (malware) is also increasing sharply. Thus, numerous malware detection schemes based on deep learning have been proposed. However, they are usually suffering from the cumbersome models with complex architectures and tremendous parameters. They usually require heavy computation power support, which seriously limit their deployment on actual application environments with limited resources (e.g., mobile edge devices). To surmount this challenge, we propose a novel Knowledge Distillation (KD) structure—Knowledge Search (KS). KS exploits Neural Architecture Search (NAS) to adaptively bridge the capability gap between teacher and student networks in KD by introducing a parallelized student-wise search approach. In addition, we carefully analyze the characteristics of malware and locate three cost-effective types of features closely related to malicious attacks, namely, Application Programming Interfaces (APIs), permissions and vulnerable components, to characterize Android Applications (Apps). Therefore, based on typical samples collected in recent years, we refine features while exploiting the natural relationship between them, and construct corresponding datasets. Massive experiments are conducted to investigate the effectiveness and sustainability of KS on these datasets. Our experimental results show that the proposed method yields an accuracy of 97.89% to detect Android malware, which performs better than state-of-the-art solutions.
Huijuan Zhu 0001, Mengzhen Xia, Liangmin Wang 0001, Victor S. Sheng
IEEE Trans. Serv. Comput.1
2024 A Survey on Security Analysis Methods of Smart Contracts
abstract
Smart contracts have gained extensive adoption across diverse industries, including finance, supply chain, and the Internet of Things. Nevertheless, the surge in security incidents of smart contracts over recent years has led to substantial economic losses. Therefore, ensuring the security of smart contracts has become a critical and complex challenge in both academic and industrial domains. Based on 539 real-world security incidents in the Ethereum platform and audit reports from 10 authoritative auditing institutions, we summarize 27 types of exploited security vulnerabilities and draw insights into their principles, typical cases, relevant research and recommended prevention strategies. Besides, we also gather 7 other potentially threatening vulnerability types as supplements. On this basis, we conduct an in-depth analysis of the root causes of vulnerabilities and further formulate eight safety practical rules. Moreover, we perform a comprehensive review of 178 recent papers on smart contract security analysis, classifying detection methods into formal verification, fuzz testing, machine learning, program analysis, and others. For each category, we seize the specific detection tools and analyze them comprehensively. Then, we conduct an extensive analysis and synthesis from various angles, presenting a comprehensive overview of the current research landscape in smart contract security detection. We also discuss current on-chain and off-chain repair methods. Finally, this review outlines major challenges and highlights potential areas for future research in this field.
Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng
IEEE Trans. Serv. Comput.1
2023 GraBit: A Sequential Model-Based Framework for Smart Contract Vulnerability Detection
abstract
The security of smart contracts has garnered considerable attention given the potential for substantial financial losses and erosion of trust in blockchain platforms. Numerous methods have been proposed to detect vulnerabilities in smart contracts. Notably, as the number of smart contracts continues to proliferate, automated techniques based on deep learning (DL) are making remarkable progress. However, a significant challenge persists in acquiring an efficient embedding representation that is compatible with DL models with input length restrictions. In this paper, we propose a novel detection method named GraBit for identifying reentrancy vulnerability-one of the most critical vulnerabilities in smart contracts. GraBit leverages the pre-trained model GraphCodeBERT to embed both the source code and concise key data flow graphs extracted from the code. Additionally, we customize a sequential model based on Bi-directional Long Short-Term Memory and attention mechanism to effectively capture contextual semantic information. To evaluate the performance of GraBit, we conduct extensive experiments on a public large-scale dataset. Our experimental results reveal that GraBit achieves a remarkable F1-score of 94.44% in detecting reentrancy vulnerability, outperforming state-of-the-art methods.
Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng
ISSRE1
2023 Few-shot website fingerprinting attack with cluster adaptation
Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001
Comput. Networks3
2023 Android malware detection based on multi-head squeeze-and-excitation residual network
Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng
Expert Syst. Appl.1
2023 A multi-model ensemble learning framework for imbalanced android malware detection
Huijuan Zhu 0001, Yang Li 0111, Liangmin Wang 0001, Victor S. Sheng
Expert Syst. Appl.1
2023 An effective end-to-end android malware detection method
Huijuan Zhu 0001, Huahui Wei, Liangmin Wang 0001, Victor S. Sheng
Expert Syst. Appl.1
2022 A Hybrid Deep Network Framework for Android Malware Detection
abstract
Android is a growing target for malicious software (malware) because of its popularity and functionality. Malware poses a serious threat to users’ privacy, money, equipment and file integrity. A series of data-driven malware detection methods were proposed. However, there exist two key challenges for these methods: (1) how to learn effective feature representation from raw data; (2) how to reduce the dependence on the prior knowledge or human labors in feature learning. Inspired by the success of deep learning methods in the feature representation learning community, we propose a malware detection framework which starts with learning rich-features by a novel unsupervised feature learning algorithm Merged Sparse Auto-Encoder (MSAE). In order to extract more compact and discriminative feature from the rich-features to further boost the malware detection capability, a hybrid deep network learning algorithm Stacked Hybrid Learning MSAE and SDAE (SHLMD) is established by further incorporating a classical deep learning method Stacked Denoising Auto-encoders (SDAE). After that, we feed the feature learned by MSAE and SHLMD respectively to classification algorithms, e.g., Support Vector Machine (SVM) or K-NearestNeighbor (KNN), to train a malware detection model. Evaluation results on two real-world datasets demonstrate that SHLMD achieves 94.46 and 90.57 percent accuracy respectively, which outperforms the classical unsupervised feature representation learning Sparse Auto-encoder (SAE). MSAE performs similarly to SAE. SHLMD can further improve the performance of MSAE and the supervised fine-tuned method SDAE. Besides, we compare the performance of our methods with that of state-of-the-art detection approaches, including classical deep-learning-based methods. Extensive experiments show that our proposed methods are effective enough to detect Android malware.
Huijuan Zhu 0001, Liangmin Wang 0001, Sheng Zhong 0002, Yang Li 0111, Victor S. Sheng
IEEE Trans. Knowl. Data Eng.1