Bailing Wang

dblp:31/7938 · DBLP profile ↗
← Back
38ranked-venue papers
2as first author
24since 2021 · last 2026
0000-0003-2973-8036ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 13 · 1 first-author · 10 since 2021Databases, data management, data science and information retrieval · 11 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 2 since 2021Computer networks · 6 · 3 since 2021Security and privacy · 4 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2026 Hierarchical GNN Message Passing for Node-Level Anomaly Detection in Industrial Control Systems
abstract
Advances in Graph Neural Networks (GNNs) have prompted remarkable progress in anomaly detection for securing the Industrial Control Systems (ICSs). As the core functioning block of a GNN network, message passing in most of the current frameworks is conducted via local aggregation, in which a node's vector representation is updated with messages from its directly connected neighbours. However, despite its efficiency over numerous application scenarios, such neighbouring aggregation mechanism tends to be highly biased towards a node's locality, and hence may not accurately profile the hierarchical semantics in layered ICS architectures, such as the supervisory relations among controllers and field devices. The resulting node embeddings, in this case, may not be knowledgeable enough to instruct downstream tasks such as fine-grained device-wise ICS anomaly detection. To address this issue, we introduce the Hierarchical Message Analyzer (the HMA), a new message passing scheme that explores a network's supervisory structural features and regulates a message's transmission paths to create balanced embeddings for node-level ICS anomaly detection. This model comprises in its architecture a Preprocessor that condenses the original data flow into initial node vectors, an Adjacency Parser that regulates how messages are transmitted in the aggregation process, an Encoder performing message passing in compliance with the adjacency info obtained from the Adjacency Parser, and a Decoder for label inference. We assess the HMA's performance over multiple evaluation metrics and compare it against various state-of-the-art baselines. Results on multiple datasets certify the HMA's validity and superiority in device-wise ICS anomaly detection.
Shuaiyi Lyu, Kai Wang 0014, Bailing Wang
IEEE Trans. Dependable Secur. Comput.4
2026 StatGraph: Effective In-Vehicle Intrusion Detection via Multi-View Statistical Graph Learning
abstract
In-vehicle networks (IVNs) face growing threats from advanced cyber-attacks, particularly stealthy masquerade attacks that mimic legitimate message patterns. This paper proposes STATGRAPH, a fine-grained intrusion detection frame work based on multi-view statistical graph learning over the Controller Area Network (CAN) messages within IVNs. STAT GRAPH constructs two graphs per detection window: a Timing Correlation Graph (TCG) capturing temporal ID dependencies, and a Coupling Relationship Graph (CRG) modeling short term contextual relations. TCG and CRG are further used to generate graph structure encoding payload variations and embedded signal co-occurrence. A lightweight multi-layered Graph Convolutional Network (GCN) is then applied to classify each message, leveraging the expressive representations from TCG and CRG. To ensure effectiveness against diverse attacks, we evaluate STATGRAPH on two real-world CAN datasets featuring five underexplored masquerade attacks. Experimental results show that STATGRAPH significantly improves detection granularity and outperforms state-of-the-art methods, with F1-score gains of 7% and 22%, while maintaining the highest accuracy. Code is available at https://github.com/wangkai-tech23/StatGraph
Kai Wang 0014, Qiguang Jiang, Bailing Wang, Yulei Wu, Hongke Zhang
IEEE Trans. Mob. Comput.3
2025 An original model for multi-target learning of logical rules for knowledge graph reasoning
Bailing Wang, Kai Wang 0014, Rui Zhang 0050, Yuliang Wei
Appl. Intell.2
2025 DAN: Neural network based on dual attention for anomaly detection in ICS
Lijuan Xu 0001, Bailing Wang, Dawei Zhao 0001
Expert Syst. Appl.2
2025 Interactive attention and contrastive learning for few-shot relation extraction
Yan Li 0120, Yao Wang 0027, Wei Wang 0503, Bailing Wang, Guodong Xin
Neurocomputing5
2025 Anomaly Detection via Semantically Conjugate View Learning on Industrial Temporal Data
abstract
Anomaly detection based on knowledge discovery from the industrial temporal data via Graph Neural Networks (GNNs) has been extensively prevailing over the past decade. So far, massive contributions have been made in deriving superior anomaly detection solutions by leveraging the sophisticated associativity among nodes in a graph topology. While this node-oriented fashion is at its fancy, the idea of utilizing a graph’s edges in anomaly detection tends to be equivalently significant, in that the edges are the other core component that construct a graph and are, more essentially, rich in convoluted correlational properties. As current methods seldom take these edge-level correlations into account, we aim at constructing a dual-channel graph learning scheme attempting to adequately utilize these edge-level contextual semantics in anomalous pattern detection. In specific, we design and develop the Node-Edge Conjugate Network (NECN), a GNN-based solution that conducts device-wise anomaly detection leveraging not only the complex associativity among the nodes but also the sophisticated correlations among the edges via knowledge discovery from the industrial temporal data. With the in-depth contextual features of the nodes and edges profiled in their respective channel, the resulting embeddings are a more appropriate reflection of the graph’s topological properties in terms of both nodes and edges, and hence serve as a more solid basis for subsequent anomaly detection. The NECN’s effectiveness in achieving a superior anomaly detection accuracy is demonstrated in a comprehensive comparative analysis with multiple state-of-the-art baselines over 3 popular datasets specifically developed for the study of ICS security.
Kai Wang 0014, Shuaiyi Lyu, Bailing Wang
IEEE Internet Things J.3
2025 KERMIT: Knowledge graph completion of enhanced relation modeling with inverse transformation
Bin Yu 0019, Yuliang Wei, Kai Wang 0014, Bailing Wang
Knowl. Based Syst.6
2025 A novel model on improving Chinese dialogue summarization with multi-perspective information enhancement
Kaikun Dong, Zongwei Du, Junheng Huang, Hongri Liu, Bailing Wang
Neural Networks6
2025 XIPHOS: Adaptive In-Vehicle Intrusion Detection via Unsupervised Graph Contrastive Learning
Qiguang Jiang, Kai Wang 0014, Yuliang Wei, Hongri Liu, Bailing Wang
IEEE Trans. Inf. Forensics Secur.5
2025 LiPar: A Lightweight Parallel Learning Model for Practical In-Vehicle Network Intrusion Detection
abstract
With the development of intelligent transportation systems, vehicles are exposed to a complex network environment. As the mainstream in-vehicle network (IVN), the controller area network (CAN) has many potential security hazards. Existing deep learning-based intrusion detection methods have security performance advantages, however, they consume too much resources and are therefore not suitable to be directly implemented into the IVN. In this paper, we explore computational resource allocation schemes in the IVNs and propose the LiPar, which is a parallel neural network structure using lightweight multi-dimensional spatial and temporal feature fusion learning to perform intrusion detection tasks in the resource-constrained in-vehicle environment. In particular, LiPar adaptively allocates task loads to in-vehicle computing devices, such as multiple electronic control units, domain controllers, and computing gateways by evaluating whether a computing device is suitable to undertake the branch computing tasks according to its real-time resource occupancy. Experiment results show that LiPar achieves better detection performance, running efficiency, and optimized lightweight model size over existing methods, and can be well adapted to the resource-constrained in-vehicle environment and practically protect the in-vehicle CAN bus security. Code is available athttps://github.com/wangkai-tech23/LiPar
Aiheng Zhang, Qiguang Jiang, Kai Wang 0014, Ming Li 0042, Bailing Wang
IEEE Trans. Intell. Transp. Syst.6
2024 Bi-channel attention meta learning for few-shot fine-grained image recognition
Yao Wang 0027, Wei Wang 0503, Bailing Wang
Expert Syst. Appl.4
2024 Hyperplane projection network for few-shot relation classification
Wei Wang 0503, Xueguang Wei, Bailing Wang, Yan Li 0120, Guodong Xin, Yuliang Wei
Expert Syst. Appl.3
2023 AAE-DSVDD: A one-class classification model for VPN traffic identification
Sicai Lv, Bailing Wang
Comput. Networks5
2023 Few-shot learning in realistic settings for text CAPTCHA recognition
Yao Wang 0027, Yuliang Wei, Yifan Zhang 0028, Chuhao Jin, Guodong Xin, Bailing Wang
Neural Comput. Appl.6
2023 Process-Oriented heterogeneous graph learning in GNN-Based ICS anomalous pattern recognition
abstract
Over the past few years, massive penetrations targeting an Industrial Control System (ICS) network intend to compromise its core industrial processes. So far, numerous advanced methods have been proposed to detect anomalous patterns in the numeric data streams with respect to the heterogeneous field devices involved in the industrial processes. These methods, despite reporting decent results, usually conduct system-wise detection instead of fine-grained anomalous pattern recognition at the device level. Furthermore, lacking explicit consideration of the exclusive process-related features with respect to each differentiated device, the fitness of their application in specified industrial processes is undermined. To tackle these issues, a GNN-based Attributed Heterogeneous Graph Analyzer (the AHGA) is designed to perform device-wise anomalous pattern detection via in-depth process-oriented associativity learning. The AHGA’s framework is constructed with four building blocks : a graph processor, a feature analyzer, a link inference decoder, and an anomaly detector . Its performance is assessed and compared against multiple link inference and anomaly detection baselines over 2 popular ICS datasets (SWaT and WADI). Comparative results demonstrate the AHGA’s reliability in capturing sophisticated process-oriented relations among heterogeneous devices as well as its effectiveness in boosting the performance of anomalous pattern recognition at device-level granularity .
Shuaiyi L(y)u, Kai Wang 0014, Liren Zhang, Bailing Wang
Pattern Recognit.4
2023 GNN-based Advanced Feature Integration for ICS Anomaly Detection
abstract
Recent adversaries targeting the Industrial Control Systems (ICSs) have started exploiting their sophisticated inherent contextual semantics such as the data associativity among heterogeneous field devices. In light of the subtlety rendered in these semantics, anomalies triggered by such interactions tend to be extremely covert, hence giving rise to extensive challenges in their detection. Driven by the critical demands of securing ICS processes, a Graph-Neural-Network (GNN) based method is presented to tackle these subtle hostilities by leveraging an ICS’s advanced contextual features refined from a universal perspective, rather than exclusively following GNN’s conventional local aggregation paradigm. Specifically, we design and implement the Graph Sample-and-Integrate Network (GSIN), a general chained framework performing node-level anomaly detection via advanced feature integration, which combines a node’s local awareness with the graph’s prominent global properties extracted via process-oriented pooling. The proposed GSIN is evaluated on multiple well-known datasets with different kinds of integration configurations, and results demonstrate its superiority consistently on not only anomaly detection performance (e.g., F1 score and AUPRC) but also runtime efficiency over recent representative baselines.
Shuaiyi L(y)u, Kai Wang 0014, Yuliang Wei, Hongri Liu, Qilin Fan, Bailing Wang
ACM Trans. Intell. Syst. Technol.6
2023 Analysis of Recent Deep-Learning-Based Intrusion Detection Methods for In-Vehicle Network
abstract
The development and popularity of vehicle-to-everything communication have caused more risks to the in-vehicle networks security. As a result, an increasing number of various and effective intrusion detection methods appear to guarantee the security of in-vehicle networks, especially deep-learning-based methods. Nevertheless, the state-of-the-art deep-learning-based intrusion detection methods lack a quantitative and fair horizontal performance comparison analysis. Also, they have no comparative analysis of the detection capability for the unknown attacks as well as on the time and hardware resource consumption of their intelligent intrusion detection models. Therefore, this paper investigates ten representative advanced deep-learning-based intrusion detection methods and illustrates the characteristics and advantages of each method. Moreover, quantitative and fair experiments are set to make horizontal comparison analyses. Also, this study provides some significant suggestions on baseline method selection and valuable guidance, for the direction of future research about lightweight models and the ability to detect unknown attacks.
Kai Wang 0014, Aiheng Zhang, Bailing Wang
IEEE Trans. Intell. Transp. Syst.4
2023 A risk assessment model for similar attack scenarios in industrial control system
Yaofang Zhang, Yingzhou Wang, Kuan Lin, Tongtong Li, Hongri Liu, Bailing Wang
J. Supercomput.8
2022 Global-local integration for GNN-based anomalous device state detection in industrial control systems
Shuaiyi L(y)u, Kai Wang 0014, Liren Zhang, Bailing Wang
Expert Syst. Appl.4
2022 Mining trading patterns of pyramid schemes from financial time series data
Linxuan Han, Yulong Pei, Junheng Huang, Bailing Wang, Mykola Pechenizkiy
Future Gener. Comput. Syst.7
2022 Contrastive graph neural network-based camouflaged fraud detector
Zexuan Deng, Guodong Xin, Bailing Wang
Inf. Sci.5
2021 Mining frequent pyramid patterns from time series transaction data with custom constraints
Guodong Xin, Yingfan Ma, Bailing Wang
Comput. Secur.6
2021 A network representation learning method based on topology
Dongyang Ma, Guodong Xin, Yunpeng Han, Junheng Huang, Bailing Wang
Inf. Sci.6
2021 Make complex CAPTCHAs simple: A fast text captcha solver based on a small number of samples
Yao Wang 0027, Yuliang Wei, Mingjin Zhang, Bailing Wang
Inf. Sci.5
2020 PLC-SEIFF: A programmable logic controller security incident forensics framework based on automatic construction of security constraints
Lijuan Xu 0001, Bailing Wang, Lianhai Wang, Dawei Zhao 0001, Xiaohui Han, Shumian Yang
Comput. Secur.2
2020 Anomaly Detection for Industrial Control System Based on Autoencoder Neural Network
abstract
As the Industrial Internet of Things (IIoT) develops rapidly, cloud computing and fog computing become effective measures to solve some problems, e.g., limited computing resources and increased network latency. The Industrial Control Systems (ICS) play a key factor within the development of IIoT, whose security affects the whole IIoT. ICS involves many aspects, like water supply systems and electric utilities, which are closely related to people’s lives. ICS is connected to the Internet and exposed in the cyberspace instead of isolating with the outside recent years. The risk of being attacked increases as a result. In order to protect these assets, intrusion detection systems (IDS) have drawn much attention. As one kind of intrusion detection, anomaly detection provides the ability to detect unknown attacks compared with signature-based techniques, which are another kind of IDS. In this paper, an anomaly detection method with a composite autoencoder model learning the normal pattern is proposed. Unlike the common autoencoder neural network that predicts or reconstructs data separately, our model makes prediction and reconstruction on input data at the same time, which overcomes the shortcoming of using each one alone. With the error obtained by the model, a change ratio is put forward to locate the most suspicious devices that may be under attack. In the last part, we verify the performance of our method by conducting experiments on the SWaT dataset. The results show that the proposed method exhibits improved performance with 88.5% recall and 87.0% F1-score.
Bailing Wang, Hongri Liu, Haikuo Qu
Wirel. Commun. Mob. Comput.2
2019 PRS: efficient range skyline computation on massive data via presorting
Xixian Han, Xue Li 0001, Bailing Wang, Hong Gao 0001
Knowl. Inf. Syst.3
2019 Dynamic skyline computation on massive data
Xixian Han, Bailing Wang, Guojun Lai 0001
Knowl. Inf. Syst.2
2019 Ranking the big sky: efficient top-k skyline computation on massive data
Xixian Han, Bailing Wang, Jianzhong Li 0001, Hong Gao 0001
Knowl. Inf. Syst.2
2019 An algorithm for calculating coverage rate of WSNs based on geometry decomposition approach
Bailing Wang, Song Jia, Haohan Hong
Peer-to-Peer Netw. Appl.2
2019 A novel approach for Web page modeling in personal information extraction
Yuliang Wei, Zhou Qi, Xixian Han, Guodong Xin, Bailing Wang
World Wide Web6
2018 Research Notes: User Identification Model Based on Mouse Behaviors
abstract
This study investigates the user identification method based on the computer mouse dynamic behaviors. One of the purposes is to refine seven types of mouse actions, and about 110 dimensional features have been employed from user session statistics and operating characteristics. And then, two basic techniques, principal component analysis (PCA) and weighted multiclassifier, are used to lay out the mouse behavior. Combing PCA and the new proposed classifier, two experiments on identification and authentication have been carried out. By validating the selected mouse data, the accuracy rate is as high as 85% in the identification experiment, and the false rejection rate (FRR) reaches 5.5% and false acceptance rate (FAR) reaches 8.8% in the authentication experiment. The results show that the proposed methods and the selected features can be well applied in practice.
Bailing Wang, Hongri Liu, Guodong Xin
Int. J. Softw. Eng. Knowl. Eng.1
2018 Efficiently processing deterministic approximate aggregation query on massive data
Xixian Han, Bailing Wang, Jianzhong Li 0001, Hong Gao 0001
Knowl. Inf. Syst.2
2016 Biological entity relationship extraction method based on multiple kernel learning
abstract
The authors combine feature-based kernel with extension path graph kernel into a multiple kernels learning method. Feature-based kernel method, extension path graph kernel method and multiple kernels learning method are conducted on experiment on the most authoritative five evaluation corpuses. Experimental results indicate that the performance of the fused kernel method in five corpus sets is superior to that of the two separate single-kernel method.
Dongliang Xu, Jingchang Pan, Bailing Wang, Xinyi Zou
BIBM3
2016 A Communication Supportable Generic Model for Mobile VPN on Android OS
abstract
Mobile Virtual Private Network (MVPN) technology is already widely used for secure connections between two endpoints. However, most existing MVPNs are designed as an optimized and parallel transplantation of traditional Virtual Private Network, which leads to incompatibility between MVPNs and mobile network environment. This paper proposes and evaluates a Communication Supportable Generic Model (CSGM) for MVPN. CSGM is born to break the gap between MVPNs and mobile network environment, and to provide a stable and scalable VPN service. CSGM entails three main contributions: (1) designs a Politely-Interrupt and Smartly-Recover Mechanism (PISRM) for MVPN. This mechanism re-defines how MVPN works, and provides Work State Model (WSM) and Network State Model (NSM) for MVPN; (2) designs a PISRM-to-MVPN mapping strategy to guarantee high quality VPN service in complicated mobile network environments; (3) presents CSGM based on the two points mentioned above and implements a MVPN prototype system on Android OS. This model is superior in its generality and scalability, which can be reused in other common MVPNs for communication support. Experimental results prove that CSGM has remarkable performance on stability and applicability. It is especially suitable for MVPN to interrupt politely and recover smartly in complicated network environments.
Chunle Fu, Qinggang He, Bailing Wang, Xixian Han
ISCC3
2015 A proactive discovery and filtering solution on phishing websites
abstract
Phishing website is becoming a major threat to the information security in Social Network. The attacks not only lessen the users' trust but also influence the benefit of the third party who develops the platform. In order to solve the time lag in phishing website passive detection, this paper proposes a solution to discover phishing website initiatively based on blacklist, in which the anomalies of its URL and WHOIS information are analyzed, and based on this, the heuristic rules that aim to generate suspicious URLs are made. In order to filter out noise sites in the suspicious set, a website filtering solution based on webpages image-layout is presented. We firstly propose a Ray Scan Method to generate the location feature of webpage images quickly, and then, we proposed a method of calculating the webpage layout similarity, which will be compared against the preset threshold to decide whether it will be filtered. The experimental results show that the solution successfully detects some phishing websites out before they are widely spread, and further, the webpage filtering method guarantees both high filtration ratio and high phishing website retention ratio.
Bailing Wang, Junheng Huang, Yushan Sun, Yuliang Wei
IEEE BigData2
2015 A collaborative filtering algorithm fusing user-based, item-based and social networks
abstract
The traditional collaborative filtering recommendation algorithm can be divided into the user-based and the item-based two methods, which only uses the information in the rating matrix. Because of the limitation of the information capacity they used, it is difficult to further improve the accuracy of the recommendation, and cold start problem also affects the normal operation of the recommendation system. This paper presented a collaborative filtering recommendation algorithm (UISA) fusing user-based, item-based and social networks data. The algorithm uses the data of the neighbor relations in social networks, calculating the users' friends not reflected in the rating matrix. At the same time, we can calculate the similarity between items by using the data of item text in social networks, mining similar items not reflected in the rating matrix. In this way, it can fundamentally expand available information capacity of the traditional filtering collaboration recommendation algorithms, improve the recommendation accuracy, alleviate cold start problem. Experimental results based on KDD CUP 2012 real data show that compared with the traditional collaborative filtering system, this system has obvious advantages in the recommendation accuracy and ease of cold start.
Bailing Wang, Junheng Huang, Libing Ou
IEEE BigData1
2015 A collaborative filtering algorithm based on social network information
abstract
In traditional collaborative filtering recommendation, the matrix sparsity and cold start restricted the accuracy of system. In this paper, we develop a way to enhance the recommendation effectiveness by merging neighborhood relationship and users keyword of social network information into collaborative filtering. We extend the calculation method of the TOP N neighbors which is the most important from two aspects. Our method expands the information capacity which can be used by collaborative filtering, improves the accuracy of recommendation and eases the cold start problem in recommendation system. We conducts experiment based on KDD 2012 real data set. The result indicates that our algorithm performs more superior than traditional collaborative filtering algorithm.
Bailing Wang, Junheng Huang
IEEE BigData2