VLDB 2026 Research / reviewers in the wild / expert
Peishuai Sun
dblp:322/3977
· DBLP profile ↗
15ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0003-1135-8297ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Computer networks · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | You can run but you can never hide: A multi-module collaborative detection framework based on network traffic
Chengxiang Si, Zhou Zhou 0007, Zhenyu Cheng 0001, Peishuai Sun |
Comput. Networks | 5 |
| 2025 | APTSniffer: Detecting APT Attack Traffic Using Retrieval-Augmented Large Language ModelsabstractAdvanced Persistent Threats (APT) differ from traditional attacks by using more complex and covert strategies for long-term assaults, posing a severe threat to organizational and national security. Due to problems like the shortage of APT traffic data and encrypted traffic obfuscation, existing methods cannot accurately identify APT traffic with just a few traffic samples. To overcome the above limitation, we propose a novel encrypted APT traffic detection model, APTSniffer, which combines large language models (LLM) and retrieval-augmented technology. APTSniffer utilizes the few-shot inference and generalization abilities of large language models by converting raw traffic data into natural language inference examples understandable by the LLM. Experimental results show that, compared to other baseline models, APTSniffer exhibits SOTA performance. It achieves F1 scores above 97% on three APT datasets, making it practically applicable for APT traffic detection tasks. Chengxiang Si, Zhou Zhou 0007, Chenxu Wang 0006, Peishuai Sun, Qingyun Liu 0001 |
ICASSP | 5 |
| 2025 | FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic Classification
Chengxiang Si, Zhenyu Cheng 0001, Chenxu Wang 0006, Jiang Xie 0004, Peishuai Sun, Qingyun Liu 0001 |
INFOCOM | 7 |
| 2025 | TGF-JA4: LLM-Aware Multi-Feature Temporal Graph For Malware Detection Under Concept DriftabstractOnce deployed for malicious traffic detection, a statically trained supervised model swiftly sees its false-positive and false-negative rates soar as evolving attack tactics and resources trigger concept drift. Previous studies have predominantly employed methods such as incremental learning, online learning, periodic retraining, and event-triggered updates to address concept drift. However, they still struggle to eliminate the burden of frequent updates fully. To address this issue, we propose a method named TGF-JA4, which integrates temporal and graph-based multi-feature representations for robust malicious traffic detection under concept drift, eliminating the need for model retraining. Specifically, we first leverage a Transformer to extract three-layer structural features (data packets, bursts, and flows) as the initial representation of graph nodes. We then construct a robust heterogeneous graph by combining inter-flow temporal edges with the newly introduced JA4 edges. Subsequently, it extracts deep graph-level features using GNN. Finally, it accomplishes malicious traffic detection under concept drift by fine-tuning LLMs. In concept drift experiments on both experimental datasets and real-world network environment datasets, this method achieved accuracies exceeding 90% and 99%, respectively, outperforming SOTA models and effectively reducing the requirement for model retraining. Peishuai Sun, He Wang 0014, Yuqing Zhang 0001 |
TrustCom | 3 |
| 2025 | HOLMES & WATSON: A Robust and Lightweight HTTPS Website Fingerprinting through HTTP Version ParallelismabstractWebsite Fingerprinting (WF) is a traffic analysis technique that aims to identify websites visited by users through the analysis of encrypted traffic patterns.Existing approaches often exhibit limited robustness against network variability and concept drift, resulting in significant performance degradation under real-world HTTPS conditions.Moreover, these methods typically require large-scale training datasets and substantial computational resources, which further increases the complexity of deployment.In this paper, we propose HOLMES, a novel approach that exploits HTTP version parallelism to extract enhanced application-layer features.These features, including the number of web resources transmitting in various HTTP versions, expose up to 4.28 bits of information-surpassing 98% of previously reported features and demonstrate increased stability across varying network conditions.Complementary to this, we introduce WATSON, a lightweight classification method based on lazy learning, which substantially reduces the dependency on large training datasets.To further enhance the identification accuracy, we incorporate two fingerprint-specific distance metrics that ensure high intra-class similarity.Our experimental evaluation demonstrates that HOLMES & WATSON significantly enhance both robustness and efficiency, achieving an average accuracy of 87.7% with only a single sample per website, marking an improvement of over 15% compared to state-of-the-art methods. Yujia Zhu, Baiyang Li, Peishuai Sun, Xinhao Deng 0001, Qingyun Liu 0001 |
WWW | 4 |
| 2025 | AdvTG: An Adversarial Traffic Generation Framework to Deceive DL-Based Malicious Traffic Detection ModelsabstractDeep learning-based (DL-based) malicious traffic detection models are effective but vulnerable to adversarial attacks. Existing adversarial attacks have shown promising results when targeting traffic detection models based on statistics and sequence features. However, these attacks are less effective against models that rely on payload analysis. The main reason is the difficulty in generating semantic, compliant, and functional payloads, which limits their practical application. Peishuai Sun, Xiao-chun Yun, Chengxiang Si, Jiang Xie 0004 |
WWW | 1 |
| 2025 | Traffic2Chain: Revealing Covert Multi-Step Attacks Through Unsupervised Traffic Behaviour CorrelationabstractWith the continuous development of network technology, covert multi-step attacks have become one of the significant attack methods. It is a multi-step attack with the intention of destroying the system- or data-privacy, such as network stealing. Current methods usually generate single-step alerts first and then perform correlation analysis. However, it is difficult for these methods to perform fine-grained annotation and alert amount control for single-step alerts, as well as to completely correlate the alerts of different phases into a chain due to alert fatigue. In this paper, we propose Traffic2Chain, an innovative unsupervised traffic behaviour correlation method to detect covert multi-step attacks from the network side. Traffic2Chain (1) generates alerts at different phases in real-time and annotates to sub-techniques based on MITRE ATT&CK knowledge database; (2) performs alert clustering based on SIMCSE and automatically generates event descriptions based on the Large Language Model (LLM) technique, and (3) extracts the attack chain through multi-dimensional information correlation to reveal the complete attack process. Experimental results demonstrate that the F1 score of Traffic2Chain reaches 98.36%, which has a significant advantage over other methods. In the real-world network, the detection speed can reach 40 Gbps. Most importantly, we discovered an unknown attack pattern based on Traffic2Chain - attackers delivered a variant of the Silver Fox Trojan by impersonating VPN services, eventually building a botnet with stealing capabilities and a node size of more than one million. Jiang Xie 0004, Xiao-chun Yun, Peishuai Sun |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | ProxyKiller: An Anonymous Proxy Traffic Attack Model Based on Traffic Behavior Graphs
Zhenyu Cheng 0001, Chenxu Wang 0006, Peishuai Sun, Jiang Xie 0004, Qingyun Liu 0001 |
ESORICS (2) | 5 |
| 2024 | A Targeted Adversarial Attack Method for Multi-Classification Malicious Traffic DetectionabstractLeveraging deep learning to detect malicious network traffic is a crucial technology in network management and network security. However, deep learning security has raised concerns among scholars. In this work, we explore executing targeted adversarial attacks for multi-classification malicious traffic detection with limited interactions. Specifically, we constrain the number of interactions with detection and employ a hop-skip-jump attack (HSJA) to generate a small number of adversarial samples. These adversarial samples are then heuristically used to train a generative adversarial network (GAN) to generate a substantial quantity of adversarial samples. Experiments demonstrate that our method is more adversarial and displays a certain degree of generalization compared with other methods. Peishuai Sun, Chengxiang Si, Zhenyu Cheng 0001, Qingyun Liu 0001 |
ICASSP | 1 |
| 2023 | GPMT: Generating practical malicious traffic based on adversarial attacks with little prior knowledge
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
Comput. Secur. | 1 |
| 2022 | VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network
Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
CollaborateCom (2) | 6 |
| 2022 | TrafficGCN: Mobile Application Encrypted Traffic Classification Based on GCNabstractWith the gradual adoption of 4G and 5G communication technologies, the number of mobile devices has increased dramatically. Identifying apps can provide technical support for fine-grained network management or optimizing the quality of network connections. The current development of new technologies, such as HTTPS and content delivery networks (CDN) technology, presents new challenges to mobile application classification. Existing techniques either ignore the implicit graph relationships in the traffic or lack comprehensive traffic features analysis, resulting in poor classification accuracy or inapplicability to large-scale data. In this paper, we propose TrafficGCN, a novel mobile application classification technique to solve the above problem. TrafficGCN constructs communication behavior graphs by combining packet-level and flow-level traffic data. The graph convolutional neural network (GCN) is then used to learn a large number of graph connectivity relations and node properties generated by different applications. In addition, we present a traffic graph dataset for mobile application classification. Comparing TrafficGCN with traditional deep learning algorithms (DNN, CNN, LSTM) and the recently developed techniques (MAppGraph, FlowPrint, AppScanner), the experimental results show that it significantly improves classification performance 5.44%-18.72% in various metrics. These results demonstrate that TrafficGCN has great potential for mobile network management, Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
GLOBECOM | 6 |
| 2022 | RAAM: A Restricted Adversarial Attack Model with Adding Perturbations to Traffic Features
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
SEC | 1 |
| 2022 | Analysis and Detection against Network Attacks in the Overlapping Phenomenon of Behavior Attribute
Jiang Xie 0004, Yongzheng Zhang 0002, Peishuai Sun |
Comput. Secur. | 4 |
| 2022 | Detecting unknown HTTP-based malicious communication behavior via generated adversarial flows and hierarchical traffic features
Xiao-chun Yun, Jiang Xie 0004, Yongzheng Zhang 0002, Peishuai Sun |
Comput. Secur. | 5 |