VLDB 2026 Research / reviewers in the wild / expert
Sanfeng Zhang 0002
dblp:33/748-2
· DBLP profile ↗
21ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0001-6626-0487ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 1 since 2021Security and privacy · 6 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Warning-Graph: An Early Warning Framework for APT Attacks Based on Threat Intelligence ModelingabstractAdvanced Persistent Threats (APTs) have become increasingly sophisticated and covert, necessitating the acquisition of an overall view of the rapidly evolving cyber threat landscape by security defenders. However, integrating threat intelligence from diverse sources poses significant challenges due to limited labeled data and noise interference. To address the requirement for the early detection of APT attacks, this paper introduces a lightweight framework named Warning-Graph, based on threat intelligence modeling. Warning-Graph leverages a limited set of IoCs to infer the type of ongoing APT attack. Initially, attack-related infrastructure nodes are modeled as a heterogeneous information network. Subsequently, heterogeneous graph contrastive learning is employed for pre-training. Two asymmetric graph encoders are constructed to obtain node embeddings without the need to generate negative samples or labeled data. In addition, a loss function based on the information bottleneck is specifically employed to reduce the noise in the original graph. In downstream tasks, multiclass classifiers are trained using embedding representations with fewer labeled samples. Experimental results demonstrate that the proposed framework achieves a 3- to 5-point increase in identification performance for APT attack types compared to baselines, while utilizing fewer labeled samples. Sanfeng Zhang 0002, Yan Wang 0173, Qingyu Hao, Yujie Hou, Linfeng Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | PPFDroid: An Android Malware Detection Method Based on Pre-Training and Prompt-Based Fine-TuningabstractAndroid malware detection models frequently face the issue of model aging, as the rapid evolution of malware leads to a gradual decline in detection performance over time. This paper introduces PPFDroid, a novel Android malware detection approach designed to improve the long-term stability and adaptability of detection models by addressing the challenges posed by the evolving nature of malware. PPFDroid employs pre-trained graph neural networks (GNNs) and a prompt-based fine-tuning graph learning strategy. By fine-tuning only the prompt codebook while keeping the pre-trained model parameters unchanged, PPFDroid adapts to new malware features with significantly lower computational costs. The pre-trained GNN captures stable behavioral patterns and function call structures, while prompt vectors are integrated with input data to dynamically adjust feature representations for improved adaptability to evolving malware. Experimental evaluations on multiple real-world datasets show that PPFDroid effectively mitigates performance degradation associated with model aging, significantly improving detection accuracy compared to traditional methods. It also achieves substantial reductions in resource consumption for training and updates. PPFDroid provides a robust and efficient solution to address the challenges of model aging in Android malware detection, offering superior detection performance, adaptability, and computational efficiency. Xufeng Wang, Hongxian Liu, Sanfeng Zhang 0002 |
TrustCom | 4 |
| 2025 | AAR-Log: A robust log anomaly detection method resisting adversarial attacks
Sanfeng Zhang 0002, Hongxian Liu |
Comput. Networks | 2 |
| 2025 | Power-ASTNN: A deobfuscation and AST neural network enabled effective detection method for malicious PowerShell Scripts
Sanfeng Zhang 0002, Shangze Li, Juncheng Lu |
Comput. Secur. | 1 |
| 2025 | MPDroid: A multimodal pre-training Android malware detection method with static and dynamic features
Sanfeng Zhang 0002, Heng Su, Hongxian Liu |
Comput. Secur. | 1 |
| 2025 | APVFGL: A Robust Vertical Federated Graph Learning Framework Against Poisoning AttacksabstractABSTRACT Vertical federated graph learning (VFGL) is a distributed graph learning scheme that addresses data isolation and privacy protection in scenarios where different clients hold the same nodes with distinct feature sets. However, VFGL is also vulnerable to poisoning attacks, while current defense methods based on horizontal federated learning and vertical federated learning are not effective in this context. To address this, this paper proposes APVFGL (Anti‐Poison Vertical Federated Graph Learning), a robust VFGL framework resilient to poisoning attacks. APVFGL utilizes dual graph encoders and graph contrastive learning during the local training phase to derive robust node representations. The loss function, based on information bottleneck theory, reduces redundant information in the data to enhance the robustness of the model against poisoning attacks without the complexity of constructing negative samples. Additionally, a Shapley‐based aggregation method is introduced on the server side to dynamically assign weights to each client, mitigating the impact of malicious feature manipulation. Experimental results on benchmark datasets demonstrate the superior performance of APVFGL against various poisoning attacks. Even in the case where more than half of the clients are poisoned, APVFGL can still achieve an F1 score of 81.6% and 71.5% on the Cora and Citeseer datasets, with an average reduction of 23.6% in attack success rate, highlighting its robustness and practicality in vertical federated graph learning scenarios. Sanfeng Zhang 0002, Zijian Gong |
Concurr. Comput. Pract. Exp. | 1 |
| 2025 | RMD-Graph: Adversarial Attacks Resisting Malicious Domain Detection Based on Dual DenoisingabstractThe Domain Name System (DNS) is a critical Internet service that translates domain names into IPs, but it is often targeted by attackers, posing a serious security risk. Graph-based models for detecting malicious domains have shown high performance but are vulnerable to adversarial attacks. To address this issue, we propose RMD-Graph, which is characterized by its ability to resist adversarial attacks and its low dependency on labeled data. A dual denoising module is specifically designed based on two autoencoders to generate the reconstructed graph, where SVD, TOP-k and reconstruction loss are introduced to enhance the denoising capability of autoencoders. Subsequently, residual connections are employed to generate an optimized graph that retains essential information from the original graph. The reconstructed graph and the optimized graph are then utilized as two views for graph contrastive learning, thereby achieving an self-supervised representation learning task without labels. In the downstream malicious domain detection, the denoised node representations are employed for machine learning classification. Extensive experiments are conducted on publicly available DNS datasets, and the results demonstrate that RMD-Graph significantly outperforms known baseline methods, especially in adversarial scenarios. Sanfeng Zhang 0002, Luyao Huang, Wenduan Xu, Linfeng Liu 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2025 | GI-Graph: A Generative Invariant Graph Learning Scheme Towards Out-of-Distribution GeneralizationabstractWhen distribution shifts occur between testing and training graph data, out-of-distribution (OOD) samples undermine the performance of graph neural networks (GNNs). To improve adaptive OOD generalization of GNNs, this paper introduces a novel generative invariant graph learning framework, named GI-Graph. It consists of four modules: subgraph extractor, generative environment subgraph augmentation, generative invariant subgraph learning, and query feedback module. The subgraph extractor decomposes a graph sample into an environment subgraph and an invariant subgraph and improves extraction accuracy through query feedback. GI-Graph uses a diffusion model to generate diverse environment subgraphs, augmenting the OOD data. By combining diffusion models, contrastive learning, and attribute prediction networks, GI-Graph also generates augmented invariant subgraphs with significant identically distributed features and consistency of labels. Experimental results demonstrate that the controllable environment subgraph and invariant subgraph augmentation effectively improve the OOD generalization capability of GI-Graph, especially in capturing invariant features and maintaining category consistency across environments. Additionally, the contrastive learning-based finetuning method enables GI-Graph to quickly adapt to evolving environments. This paper verifies the effectiveness of the generative invariant graph learning scheme in graph OOD generalization. Sanfeng Zhang 0002, Zihao Qi, Xingchen Yan |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2024 | BWG: An IOC Identification Method for Imbalanced Threat Intelligence DatasetsabstractAPT attacks are becoming increasingly complex and stealthy. To effectively counter APT attacks, modelling threat intelligence data based on graphs, identifying Indicators of Compromise (IOC) nodes, and providing early warnings have become new research hotspots. However, the problem of node category imbalance in such graph datasets restricts the identification capabilities of these methods. Therefore, this paper proposes a supervised graph data augmentation method. In the training phase, graph disentangled representation learning is utilized to perform feature embedding for minority class nodes, effectively alleviating the sparsity problem faced by traditional methods and effectively integrating neighbourhood information of minority class nodes at a higher semantic level. Additionally, two loss functions designed based on link prediction and prototype constraints enhance node type consistency and semantic consistency, respectively. Experimental results on the APT and PDNS datasets demonstrate that the proposed method outperforms other baseline models in identification performance; even in highly imbalanced scenarios, it surpasses the second-best model. Juncheng Lu, Yan Wang 0173, Jiyuan Cui, Sanfeng Zhang 0002 |
TrustCom | 5 |
| 2024 | MDD-FedGNN: A vertical federated graph learning framework for malicious domain detection
Sanfeng Zhang 0002, Qingyu Hao, Zijian Gong, Fengzhou Zhu, Yan Wang 0173 |
Comput. Secur. | 1 |
| 2017 | Joint Optimization in Software Defined Wireless Networks with Network Coded Opportunistic RoutingabstractApplying network coding and opportunistic routing can significantly improve the throughput performance of wireless multi-hop networks, but a mismatch problem still exists among the upper flow rate, routing and lower transmission resource scheduling. This paper models the throughput optimization as a network utility function maximization in wireless multi-hop networks. By applying Lagrangian dual decomposition theory and the sub-gradient method, the total utility maximization problem is decomposed into source rate control, routing and scheduling problems. These three subproblems are solved independently and are linked by queue length to achieve coordination and joint optimization of network throughput. Based on OpenFlow, this paper implements the joint optimization algorithm in a software-defined network and verifies its performance through experiments. The results show that the joint optimization algorithm has better performance in terms of the total network throughput, network transmission efficiency and inter-flow fairness compared with the existing network coded opportunistic routing method, which only considers the optimization of routing. Haiping Wang 0002, Sanfeng Zhang 0002 |
MASS | 3 |
| 2016 | Analytic latency model for message dissemination in opportunistic networksabstractIn opportunistic networks, messages are delivered based on a store-forward-carry paradigm. Network topology varies with time and dynamism of the links between nodes has a primary effect on the message delay, one of the network performance indicators. To get a precise estimation of the network latency with less complexity, a rigorous framework modeling the information propagation process is developed. The model is based on a sophisticated 2N-1-state Markov chain and yields a closed-form expression under non-homogenous assumption, as well as an asymptotic formula under homogenous assumption. Finally, to assess our model's scalability and reliability, analytical results are validated by simulations on a real-life human mobility trace and two standard mobility models. The results demonstrate that the model predicts the routing performance accurately for networks of different size and mobility models. Sanfeng Zhang 0002 |
WCNC | 2 |
| 2015 | Dust: Real-Time Code Offloading System for Wearable ComputingabstractRuntime performance seriously bothers application developers and users for wearable devices such as Apple Watch and Google Glass. To ease such pains, one approach is to transplant the computation to the cloud, known as cloud offloading. This paradigm works well when the Internet is accessible. Another solution, known as device-to-device(D2D) offloading,is to utilize nearby devices for computation offloading. In this paper, propose the Dust, a D2D code offloading prototype for wearable computing. To our best knowledge, Dust is the first code offloading system for wearable computing with an implementation on Google Glass. Dust includes a programmer friendly framework based on Java annotation, a lightweight offloading service, and a runtime task scheduler to make offloading decisions. Extensive experiments demonstrate that Dust achieves real-time performance with speedup of 6.1X. Di Huang 0004, Luning Yang, Sanfeng Zhang 0002 |
GLOBECOM | 3 |
| 2015 | Combo-Pre: A Combination Link Prediction Method in Opportunistic NetworksabstractOpportunistic networks have emerged as prospective network architecture for smart mobile devices related applications. The main obstacle for designing routing protocol in opportunistic networks is their inherent dynamic nature. Unknown future link patterns lead to blind and inefficient packet forwarding behavior. Lots of efforts have focused on the future link prediction problem, but contact patterns among node pairs are too different to be predicted by one single method. To this end, we propose a combination link prediction method for opportunistic network routing named Combo-Pre. Combo-Pre applies periodic pattern mining methods to predict frequent and periodic contacts, decision tree method to predict frequent but non-periodic contacts and Adamic-Adar methods in complex networks to predict infrequent contacts. Experimental results show that Combo-Pre outperforms state-of-the-art link prediction methods in opportunistic networks. These results can be applied in routing protocol design to decrease routing cost and promote delivery rate. Yin Li 0008, Sanfeng Zhang 0002 |
ICCCN | 2 |
| 2014 | Minimum cost opportunistic routing with intra-session network codingabstractOpportunistic routing with intra-session network coding (NCOR) is a promising communication paradigm in wireless multi-hop networks with lossy links. Unlike traditional routing protocols, which use a single path to route traffic between node pairs, NCOR broadcasts data packets to a set of forwarding candidates. Each candidate combines the overheard packets to generate linearly independent packets, which are then forwarded to the destination. The focus of this paper is on the fundamental problem of how to select the candidate forwarder set (CFS) and how to allocate traffic among candidate forwarders to achieve optimal routing. In current literature, CFS selection and traffic allocation have typically been addressed separately. In this paper, we take an integrated approach and propose a minimum cost NCOR model, MIC-NCOR, which addresses the two aspects of the problem jointly. Based on the optimal substructure of MIC-NCOR, we derive a provable algorithm that can be implemented in a distributed fashion, to compute both the optimal CFS and traffic portion for each candidate. An extensive simulation study indicates that MIC-NCOR accurately predicts the quality of NCOR routes. The simulation results also show that the MIC-NCOR algorithm achieves significant throughput improvement over existing NCOR routing schemes, especially in networks with low NCOR cost and high node density. Sanfeng Zhang 0002, Guoxin Wu, Yongqiang Dong, Taieb Znati |
ICC | 2 |
| 2014 | MT-NCOR: A practical optimization method for network coded opportunistic routing in WMNabstractNetwork coded opportunistic routing (NCOR) is a potential communication paradigm in wireless multi-hop networks (WMN) with lossy links. It leverages the multipath diversity of wireless networks and applies network coding to resist random erasures. Related optimization work minimizing transmission cost or maximizing throughput are based on the collision-free assumption, which either requires perfect schedule of MAC layer or only considers low traffic load and thus few packet collisions will occur. However, the assumption doesn't hold true because real WMNs often need to support content distribution service and bear a high level of traffic load, and 802.11 protocols cannot guarantee an ideal schedule with no collisions. In order to achieve an optimal forwarding rate distribution and reduce conflicting packets, this paper proposes a throughput optimization algorithm which takes into consideration the channel capacity and interference between neighboring nodes. Based on this algorithm, we implement a practical NCOR protocol aiming at achieving maximum throughput named MT-NCOR. Through extensive experiments, we show that MT-NCOR outperforms the state-of-art NCOR protocols in both throughput and total cost, especially in networks backing high traffic loads. Xiang Lan 0002, Sanfeng Zhang 0002 |
ICCCN | 2 |
| 2014 | Analytic throughput model for TCP-NCabstractNetwork coding improves TCP's performance in lossy wireless networks. However, the complex congestion window evolution of network coded TCP (TCP-NC) makes the analysis of end-to-end throughput challenging. This paper analyzes the evolutionary process of TCP-NC against lossy links. An analytic model is established by applying a two-dimensional Markov chain. With maximum window size, end-to-end erasure rate and redundancy parameter as input parameters, the analytic model can reflect window evolution and calculate end-to-end throughput of TCP-NC precisely. The key point of our model is the novel definition for the states of Markov chain. It substantially reduces related states and much lower complexity is obtained. Our work helps understand the factors that affect TCP-NC's performance and lay the foundation of optimization. Extensive simulations on NS2 show that the analytic model features fairly high accuracy. Xiang Lan 0002, Chunnan Han, Sanfeng Zhang 0002 |
WCNC | 5 |
| 2013 | Network Coded TCP throughput Analysis in Wireless Mesh NetworksabstractNetwork coding not only improves TCP performance in lossy wireless multi-hop networks, but also changes other features of the TCP protocol such as the evolutionary process of the congestion window, which raises new issues about rate control, fairness etc. This paper analyzes the evolutionary process of network coded TCP against lossy links and error correcting coding. Ignoring the slow start phase, we describe the state transition process of congestion window and available window by a three-dimensional Markov chain model. With maximum window size, end-to-end erasure rate and redundancy factor as input parameters, the numerical analysis model calculates throughput of network coded TCP to carry quantitative analysis of factors that affect the network coded TCP performance. Simulation results on NS2 show that our numerical analysis model achieves fairly high accuracy. Xiang Lan 0002, Sanfeng Zhang 0002 |
MSN | 3 |
| 2013 | An Optimal Stopping Decision method for Routing in opportunistic networksabstractDelivery delay is an important performance metric in opportunistic networks. With given buffer size and copy numbers, how to select appropriate nodes to replicate message is the key to minimizing delivery delay. To solve this problem, this paper proposes an Optimal Stopping Decision method for Routing of opportunistic networks (OSDR). With OSDR, the average meeting time between a node and the destination is regarded as the forwarding utility of the node. A node carrying a message observes the random forwarding utilities of the nodes it meets, and replicates messages according to the optimal stopping rule, which turns out to be threshold-based. By making tradeoffs between the forwarding utility and waiting cost, OSDR achieves the minimum delivery delay expectation. This paper introduces the OSDR network model and existence proof and calculation of optimal stopping rule in detail. Simulation results show that OSDR outperforms other protocols in delivery delay and delivery rate. Di Huang 0004, Sanfeng Zhang 0002 |
WCNC | 2 |
| 2012 | An optimal stopping strategy for opportunistic broadcast channel accessabstractOpportunistic routing with network coding (NCOR) has recently emerged as a promising unicast paradigm in lossy wireless multihop networks. By combining the multi-user diversity advantage of the broadcast links and the erasure-codes property of random network coding, it raises an interesting question on the broadcast channel access control algorithm, since the reliability is guaranteed by upper-layer coding and thus it is not necessary to wait for all the receivers to be ready. In this paper, we formalize it as the opportunistic broadcast channel access control problem. By appealing to the theory of optimal stopping, we develop a strategy which can balance between the access delay and instantaneous delivery ability of the broadcast link. This strategy turns out to be a threshold-based policy, which allowing fully distributed implementation. Simulation results show that the proposed strategy outperforms existing schemes significantly in terms of end to end throughput under various traffic loads. Sanfeng Zhang 0002, Yongqiang Dong, Guoxin Wu |
ICC | 2 |
| 2012 | Transport Performance Optimization Based on Network Coding in WMNabstractWhen network coding is adopted to optimize transport performance of WMN networks, it has problems such as end to end delay and compatibility with wireless network environment emerge. With this in mind, this paper explores transport technologies based on network coding and TCP Reno protocol and reveals these problems by simulations. End to end delay optimized method is proposed based on optimal block size of file transported. And an automatic tuning method for the redundancy factor R is also proposed based on congestion detection and link quality detection. Performance of all these contributions is evaluated by simulation results. Yan Xue, Sanfeng Zhang 0002, Di Huang 0004 |
MSN | 2 |