VLDB 2026 Research / reviewers in the wild / expert
Wei Ou
dblp:34/4936
· DBLP profile ↗
17ranked-venue papers
8as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 1 first-author · 2 since 2021Security and privacy · 5 · 2 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving targeted password guessing attacks by using personally identifiable information and old passwordabstractAbstract Text-based passwords serve as a primary means of authentication and play a crucial role in securing information systems. However, easy-to-remember passwords are often vulnerable to targeted password guessing attacks. Research on targeted password guessing not only deepens our understanding of password security but also contributes to enhancing the security of information systems. Although the use of Personally Identifiable Information (PII) and old passwords has been shown to significantly improve the accuracy of targeted password guessing, there has been little research on the combined use of both PII and old passwords for guessing. In an era where PII and old passwords are increasingly accessible, assessing the threat posed by attackers using both PII and old passwords in targeted password guessing is an urgent security issue. To address this gap, we first analyze leaked password and personal information datasets, demonstrating that PII and old passwords critically influence users’ password creation behavior. Then, to simulate the security risks posed by attackers who know both PII and old passwords, we propose the PassGLM model, a model fine-tuned on a targeted password guessing task dataset based on glm-4-9b. PassGLM is capable of generating highly targeted guesses by leveraging both PII and old passwords. Experiments show that PassGLM significantly outperforms leading models that use only PII or only old passwords in terms of guess success rates. Our research demonstrates that combining PII and old passwords can substantially improve the accuracy of password guessing, and that using large language models as tools is an effective way to achieve this improvement. Wei Ou, Chengliang Sun, Mengxue Pang, Qiuling Yue, Yanshuo Zhang, Wenbao Han |
Cybersecur. | 1 |
| 2026 | MSGL: A multi-scale group learning model for insider threat detectionabstractThe insider threat refers to actions of organizational users who abuse their authorized privileges to compromise information assets, and the detection of it has become a crucial task in cybersecurity management. Existing approaches primarily rely on user behavior logs for detection, but they often fail to capture the multi-scale temporal dynamics of user behaviors and the structural relationships within user groups, which limits their effectiveness in insider threat detection. To address these limitations, we propose a multi-scale group learning model (MSGL) for insider threat detection. It mainly consists of three key components: (1) a multi-scale collaborative temporal feature extraction module that leverages a weighted attention mechanism to model behavioral dynamics at different granularities and achieves cross-scale information fusion; (2) the group structure-aware module is designed to capture structural dependencies among users by the aggregation mechanism of graph neural networks, while incorporating group-sparsity regularization to attenuate spurious associations and accentuate underlying common patterns; and (3) an individual learning module for capturing deviations via sparse attention, which facilitates disentangled representations of group-level commonalities and specific characteristics of users. Experimental results on the CERT r4.2 and CERT r5.2 datasets demonstrate the effectiveness of MSGL, achieving detection accuracies of 96.28% and 97.41%, respectively. Mengxue Pang, Wei Ou, Weizhi Meng 0001, Meng Shen 0001, Qiuling Yue, Wenbao Han |
Expert Syst. Appl. | 2 |
| 2025 | Double landmines: invisible textual backdoor attacks based on dual-triggerabstractAbstract Backdoor attacks pose an important security threat to textual large language models. Exploring textual backdoor attacks not only helps reveal the potential security risks of models, but also promotes innovation and development of defense mechanisms. Currently, most textual backdoor attack methods are based on a single trigger. For example, inserting specific content into text as a trigger or changing the abstract text features to be a trigger. However, the adoption of this single-trigger mode makes the existing backdoor attacks subject to certain limitations: either they are easily identified by the existing defense strategies, or they have certain shortcomings in attack performance and in the construction of poisoned datasets. In order to solve these issues, a dual-trigger backdoor attack method is proposed in this paper. Specifically, we use two different attributes, syntax and mood (we use subjunctive mood as an example in this article), as two different triggers. It makes our backdoor attack method similar to a double landmine which can have completely different trigger conditions simultaneously. Therefore, this method not only improves the flexibility of trigger mode, but also enhances the robustness against defense detection. A large number of experimental results show that this method significantly outperforms the previous methods based on abstract features in attack performance, and achieves comparable attack performance (almost 100% attack success rate) with the insertion-based method. In addition, in order to further improve the attack performance, we also give the construction method of the poisoned dataset. The code and data of this paper can be obtained at https://github.com/HoyaAm/Double-Landmines. Qiuling Yue, Lujia Chai, Guozhao Liao, Wenbao Han, Wei Ou |
Cybersecur. | 6 |
| 2024 | Telemedicine data secure sharing scheme based on heterogeneous federated learningabstractAbstract The forward triage characteristic of telemedicine highlights its importance again in the COVID-19 pandemic. Telemedicine can provide timely emergency response in the case of environmental or biological hazards, and the patient’s medical privacy data generated in this process can also accelerate the establishment of models for preventing and treating infectious diseases. However, the reuse process of telemedicine user privacy data based on federated learning also faces significant challenges. Differences in regions, economic levels, and grades lead to heterogeneous data and resource-constrained environments, seriously damaging the federated learning process. Besides, the weak password authentication of medical terminals and eavesdropping attacks on transmission channels may cause illegal access to terminals and platforms and leakage of sensitive data. This paper proposed a telemedicine data secure-sharing scheme based on heterogeneous federated learning. Specifically, we proposed a heterogeneous federated learning scheme with model alignment to guide telemedicine practice through the reuse of telemedicine data; in addition, we designed an SM9 threshold identity authentication scheme to guarantee that the patient’s medical privacy data is protected from leakage during the federated learning process. We evaluated our scheme using two third-party medical datasets. The evaluation results indicate that this scheme can still assist the federated learning process in resisting data heterogeneity and resource constraints with almost no performance cost. Nansen Wang, Ju Huang, Wei Ou, Wenbao Han, Qionglu Zhang |
Cybersecur. | 4 |
| 2024 | Conditional variational autoencoder for query expansion in ad-hoc information retrieval
Wei Ou, Van-Nam Huynh |
Inf. Sci. | 1 |
| 2024 | Aspect-level item recommendation based on user reviews with variational autoencoders
Wei Ou, Van-Nam Huynh |
Inf. Sci. | 1 |
| 2023 | A data sharing method for remote medical system based on federated distillation learning and consortium blockchainabstractWith the development of Medical Internet of Things (MIoT) technology and the global COVID-19 pandemic, hospitals gain access to patients’ health data from remote wearable medical equipment. Federated learning (FL) addresses the difficulty of sharing data in remote medical systems. However, some key issues and challenges persist, such as heterogeneous health data stored in hospitals, which leads to high communication cost and low model accuracy. There are many approaches of federated distillation (FD) methods used to solve these problems, but FD is very vulnerable to poisoning attacks and requires a centralised server for aggregation, which is prone to single-node failure. To tackle this issue, we combine FD and blockchain to solve data sharing in remote medical system called FedRMD. FedRMD use reputation incentive to defend against poisoning attacks and store reputation values and soft labels of FD in Hyperledger Fabric. Experimenting on COVID-19 radiography and COVID-Chestxray datasets shows our method can reduce communication cost, and the performance is higher than FedAvg, FedDF, and FedGen. In addition, the reputation incentive can reduce the impact of poisoning attacks. Chengyu Zhu, Wei Ou, Wenbao Han, Qionglu Zhang |
Connect. Sci. | 4 |
| 2023 | A zero trust and blockchain-based defense model for smart electric vehicle chargersabstractElectric vehicles (EVs) have rapidly developed over the last decade due to their environmental benefits. As a key component of EVs, electric vehicle chargers are becoming increasingly digital and intelligent. However, due to the vast attack surface and the lack of systematic study, EV chargers and charging management cloud platforms are facing cyber security problems. These problems include weak cryptographic mechanisms, insecure data communication, and malicious firmware attacks. Through specific vulnerabilities, attackers can tamper with the data communication or replay network requests between EV chargers and cloud platforms. It will cause threats such as user-level privacy leakage, power fluctuations in the smart grid, and damage to Electric vehicles, damaging public life and property safety. Given the above, this paper proposes a security protection scheme incorporating blockchain, zero trust, and ShangMi cryptographic (SM) algorithms. The scheme uses Hyperledger Fabric for key management and trust evaluation event storage to guarantee the authenticity, non-repudiation, and tamper-proof of keys and events. In addition, zero trust is applied to secure valuable resources and enforce identity and access management (IAM) for accessing entities. We adopt the dynamic trust evaluation method to assess the trustworthiness of accessing entities in real time to implement dynamic authorization. Furthermore, the SM algorithms SM2, SM3, and SM4 are used to protect data confidentiality, integrity, and authenticity. Experimental results demonstrate that our scheme can effectively resist replay and tampering attacks, securing data communication between EV chargers and cloud platforms. And the performance of the cryptographic algorithm, blockchain system, and Secure Sockets Layer (SSL) meets Chinese national and industry standards. Peirong Li, Wei Ou, Haozhe Liang, Wenbao Han, Qionglu Zhang |
J. Netw. Comput. Appl. | 2 |
| 2022 | An overview on cross-chain: Mechanism, platforms, challenges and advancesabstractAfter years of in-depth development of blockchain, various blockchains with different characteristics and suitable for different application scenarios coexist in large numbers. Due to the isolation of blockchains and the high degree of heterogeneity between chains, value transfer and data communication between existing blockchains are facing unprecedented challenges, and the phenomenon of value isolated island is gradually emerging. The cross-chain technology of blockchain is an important technical means to realize the interconnection of blockchains and improve the interoperability and scalability of blockchains. In this paper, the development and application of blockchain cross-chain technology are studied, the background and significance of cross-chain technology are described, the research status of cross-chain technology is expounded, the current mainstream cross-chain technologies and cross-chain projects are introduced, the mentioned cross-chain technologies and cross-chain projects are analyzed and compared. In addition, this paper also summarizes the difficulties existing in the current cross-chain technology and provides solutions for reference, so as to lead to the discussion of the development trend of cross-chain technology, and finally complete the summary of the research content of the full text and the prospect of cross-chain technology. It is hoped that the relevant summary results can help relevant researchers and practitioners quickly grasp the research progress in the field of blockchain interoperability, and obtain relevant knowledge and application methods in this field. Wei Ou, Shiying Huang, Qionglu Zhang, Wenbao Han |
Comput. Networks | 1 |
| 2021 | BSVMS: Novel Autonomous Trustworthy Scheme for Video MonitoringabstractWith the continuous development and application of monitoring technology, which involves increasingly more sensitive information, the global demand for video monitoring systems has surged. As a result, video monitoring technology has received widespread attention both at home and abroad. Traditional video monitoring systems experience security threats, with differing levels of severity, in terms of attack, storage, transmission, etc., which results in different degrees of damage to users’ rights. Therefore, we propose a blockchain‐SM‐based video monitoring system called BSVMS. For the front‐end device invasion risk, internal attack risk, and security storage problem of the monitoring system, we use commercial cryptography algorithms to complete the encryption processing of images through a visual change network in the imaging process, thereby ensuring the security of the video data from the source. To address the problem that the video monitoring application software and data are vulnerable to damage, we use blockchain technologies that are tamper‐proof and traceable to build a trustworthy video monitoring system. In the system, no member can query the original monitoring data. To address the security issues in network transmission, we use a commercial cryptography algorithm for multilayer encryption to ensure the security of data during transmission, guarantee the confidentiality of the system, and realize domestic autonomous control. We then conduct tests and security analysis of the encryption and decryption efficiency of the SM4 algorithm used in the system, the blockchain performance, and the overall performance. The experimental results show that in this system environment, the SM4 algorithm encryption and decryption efficiency is better than other algorithms and that the blockchain used meets industry standards. Xuan Wang 0038, Wei Ou, Wenbao Han |
Wirel. Commun. Mob. Comput. | 4 |
| 2020 | A Privacy-Protection Model for PatientsabstractThe collection and analysis of patient cases can effectively help researchers to extract case feature and to achieve the objectives of precision medicine, but it may cause privacy issues for patients. Although encryption is a good way to protect privacy, it is not conducive to the sharing and analysis of medical cases. In order to address this problem, this paper proposes a federated learning verification model, which combines blockchain technology, homomorphic encryption, and federated learning technology to effectively solve privacy issues. Moreover, we present a FL-EM-GMM Algorithm (Federated Learning Expectation Maximization Gaussian Mixture Model Algorithm), which can make model training without data exchange for protecting patient’s privacy. Finally, we conducted experiments on the federated task of datasets from two organizations in our model system, where the data has the same sample ID with different subset features, and this system is capable of handling privacy and security issues. The results show that the model was trained by our system with better usability, security, and higher efficiency, which is compared with the model trained by traditional machine learning methods. Wenzhi Cheng, Wei Ou, Xiangdong Yin, Wanqin Yan, Dingwan Liu |
Secur. Commun. Networks | 2 |
| 2019 | A Decentralized and Anonymous Data Transaction Scheme Based on Blockchain and Zero-Knowledge Proof in Vehicle Networking (Workshop Paper)
Wei Ou, Mingwei Deng |
CollaborateCom | 1 |
| 2019 | A Multi-attributes-Based Trust Model of Internet of Vehicle
Wei Ou, Zhiyuan Tan 0001, Lihong Xiang, Qin Yi, Chen Tian 0009 |
NSS | 1 |
| 2016 | Rating Supervised Latent Topic Model for Aspect Discovery and Sentiment Classification in On-Line Review Mining
Wei Ou, Van-Nam Huynh |
MDAI | 1 |
| 2015 | Spatially Regularized Latent Topic Model for Simultaneous Object Discovery and SegmentationabstractLatent Dirichlet Allocation (LDA) has been increasingly applied in the area of computer vision. LDA is based on the 'bag of words' assumption that ignores the spatial structure of images. This problem poses a non-trivial impact on the performance of the model. There exist a number of methods that attempt to address the limit. One representative work can be Spatial Latent Topic Model (Spatial-LTM) for unsupervised joint object discovery and segmentation, which improves over LDA by assigning locally co-occurring visual words with the same topic. However, this model still ignores the spatial relations between visual words which are spatially distant from each other. In this paper, we add a spatial regularization term to the model's posterior distribution that regulates the difference of multinomial weight between each pair of visual words in a topic based on their spatial distance apart in an image set. We call the improved model Spatially Regularized Latent Topic Model (SR-LTM). Experiment result shows that SR-LTM outperforms Spatial-LTM in both unsupervised object discovery accuracy and segmentation accuracy. Wei Ou, Zanfu Xie, Zhihan Lyu |
SMC | 1 |
| 2009 | Corrigendum "Evaluating knowledge management capability of organizations: A fuzzy linguistic method" [Experts Systems with Applications 36 (2P2) (2009) 3346-3354]
Zhi-Ping Fan, Bo Feng 0003, Yong-Hong Sun, Wei Ou |
Expert Syst. Appl. | 4 |
| 2009 | Evaluating knowledge management capability of organizations: a fuzzy linguistic method
Zhi-Ping Fan, Bo Feng 0003, Yong-Hong Sun, Wei Ou |
Expert Syst. Appl. | 4 |