VLDB 2026 Research / reviewers in the wild / expert
Xinbo Han
dblp:343/4111
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2026
0009-0005-6387-3890ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MT-DEGCL: Multi-Task Encrypted Traffic Classification With Dual Embedding and Graph Contrastive LearningabstractAlthough encryption offers strong anonymity, it also facilitates the concealment of malicious activities, allowing adversaries to evade detection, and posing a great challenge to cybersecurity surveillance. Many existing encrypted traffic classification methods struggle to integrate flow- and packet-level tasks effectively, as they are trained independently, which is redundancy. Additionally, packet header and payload are treated equally, leading to the rich information in raw bytes remains fully unexplored, particularly in the abundant payload data. Moreover, they neglect the semantic invariance and common features between data samples, which ultimately results in suboptimal performance. To address these challenges, we propose an effective Multi-Task model using Dual Embedding and Graph Contrastive Learning (MT-DEGCL). Based on the byte-packet-flow structure of network traffic, a parallel dual embedding embeds the header and payload separately, followed by a cross-gated feature fusion strategy to capture the strong local packet-level representation. Then, we construct the traffic interaction graph and further utilize graph contrastive learning to extract the robust global flow-level representation. Finally, a multi-task model is trained for joint flow- and packet-level classification, leveraging the complementary learning between tasks to enhance overall performance. The experimental results on four real datasets highlight the effectiveness of MT-DEGCL, demonstrating superior performance in both tasks. Specifically, on the ISCX-Tor dataset, MT-DEGCL achieves F1 scores of 98.63% for flow-level classification and 98.10% at the packet level, surpassing the state-of-the-art (i.e., DE-GNN) by 2.03% and 83.21%, respectively. Furthermore, MT-DEGCL maximizes the rich information in raw payload bytes, significantly reducing or even nearly eliminating classification loss when using only payload data. Xiaolan Zhu, Junfeng Wang 0003, Wenhan Ge, Xinbo Han |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | DFilter: A Network Access Layer Collaborative Defense Model for Moving Target DefenseabstractDue to the inherent properties of IT networks, such as the determinacy of network composition, the statics of network structure, and the homogeneity of network elements, network defense is always in a passive position in cyberattack-defense con-frontations. In response, cybersecurity researchers have proposed using Moving Target Defense technology to reverse it. However, in practical application scenarios, while Moving Target Defense demonstrates its defensive value, it also introduces several issues such as increased network complexity, limited processing performance due to restricted by network protocol stack, and inherent limitations of related technologies themselves. This article constructs a network access layer collaborative defense model, DFilter based on XDP-eBPF. The policy preprocessing layer implements the O(1) time complexity network traffic filtering and matching algorithm, and further refines the control strength of the state-of-the-art algorithm based on security labels. On this basis, the multi-dimensional and fine-grained collaborative defense methods proposed by the policy disposal layer, enriching the diversity of model defense capabilities. Based on the model and algorithm proposed in this article, an experimental topology environment was constructed and comprehensive experimental evaluation were completed. The experimental results showed that DFilter effectively improved the preprocessing efficiency of network access layer traffic, further refined the control strength and significantly enhanced the variability of the network traffic. Degang Sun, Xinbo Han, Weiqing Huang |
CSCWD | 4 |
| 2024 | TBA-GNN: A Traffic Behavior Analysis Model with Graph Neural Networks for Malicious Traffic Detection
Xinbo Han, Meng Zhang 0020 |
WASA (1) | 1 |
| 2024 | DE-GNN: Dual embedding with graph neural network for fine-grained encrypted traffic classification
Xinbo Han, Guizhong Xu, Meng Zhang 0020, Weiqing Huang |
Comput. Networks | 1 |
| 2023 | ABTD-Net: Autonomous Baggage Threat Detection Networks for X-ray ImagesabstractAutomated security screening has a significant role In protecting public spaces from security threats by employing X-ray images to detect prohibited items. However, there are challenges of noise production due to squeezing, occlusion, and penetration of luggage objects. Additionally, the hues of objects are monotonous and lack luster. To solve these problems, we propose an Autonomous Baggage Threat Detection Network (ABTD-Net) for accurate prohibited item detection. To tackle the difficulty of capturing distinctive visual features, we constructed a Feature Adjustment Head (FAH) to refine pyramid features. Specifically, we designed an Attention Module (AM) at several places after initially using a Dense Unidirectional Propagation (DUP) to filter noise. Furthermore, we created a Feature Fusion Head (FFH) that dynamically fuses hierarchical visual information under object occlusion, including early-fusion and late-fusion. Extensive experiments on security inspection X-ray datasets OPIXray and HiXray demonstrate the superiority of our proposed method. Degang Sun, Yan Wang 0081, Zhongyuan Chen, Xinbo Han, Haitian Yang |
ICME | 5 |
| 2023 | DTrap: A cyberattack-defense confrontation technique based on Moving Target DefenseabstractIn the evolution process of cyberattack-defense confrontation, both sides have always been in a state of mutual confrontation and collaborative development, continuously upgrading their tools to improve adversarial capabilities. However, in this arms race, the positions of the both sides are imbalanced. As the party actively initiating the attack, attackers always is able to actively adjust the attack strategy based on the detected defense vulnerabilities to launch effective attacks. While the defenders always detecting defense vulnerabilities after suffering losses and filling them in a "patching" manner. This post awareness security protection strategy has a "fatal time difference" when dealing with unknown attacks. This paper aims to change the imbalanced state. Therefore, a attack confrontation model DTrap is proposed based on the concept of moving target defense, which introduce of high simulation trap hosts to achieve IP address and service port confusion. It can simulate real hosts to achieve various common network protocol requests and responses, and it can provide better dynamism than Honeypot when adjusting trap policies. DTrap can reverse the imbalance situation by increasing attack costs and promoting attack difficulty. We constructed a real adversarial environment, the security effectiveness of the DTrap model was evaluated through comprehensive and multi-dimensional experiments. The results indicate that DTrap can exert expected effectiveness in resisting network attacks of different dimensions, and effectively enhance the network attack confrontation ability. Degang Sun, Yan Wang 0081, Xinbo Han, Weiqing Huang |
TrustCom | 4 |
| 2022 | MFFAN: Multiple Features Fusion with Attention Networks for Malicious Traffic DetectionabstractMalicious traffic detection is an important task in network security, which protects the target network from privacy leakage and service paralysis. The complexity of the network and the hierarchical structure of network traffic, i.e, byte-packet-flow, indicate the diversity of traffic information. Most of the existing work only uses one feature or statistical feature, and cannot learn network traffic from multiple perspectives, i.e, shortsighted, which results in the lack of important information in network traffic. Meanwhile, after obtaining multiple features, the effective fusion of multiple features is also an urgent problem to be solved. In this paper, we propose a Multiple Features Fusion with Attention Networks (MFFAN). According to the hierarchical structure of network traffic, we extract byte, packet, and statistical features from original traffic files to learn traffic from multiple perspectives, overcoming shortsighted. To effectively fuse multiple features, we use the self-attention to learn the intra-feature relationship with each feature and use the co-attention to learn the inter-feature relationship between features. We conduct experiments on the ISCIDS2012 dataset and CICIDS2017 dataset, and the results show that our model achieves an effective fusion of multiple features and high accuracy. Weiqing Huang, Xinbo Han, Meng Zhang 0020, Haitian Yang |
TrustCom | 2 |