Yuedong Pan

dblp:350/8505 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0001-3977-106XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DriftTrace: Combating Concept Drift in Security Applications Through Detection and Explanation
Yuedong Pan, Lixin Zhao, Tao Leng, Zhexi Luo, Dan Meng 0002
IEEE Trans. Inf. Forensics Secur.1
2025 TDBA: Towards Transferable Data-free Black-box Attack with Stable Diffusion
abstract
Existing data-free black-box attacks leverage generative adversarial networks (GANs) to synthesize images for substitute model distillation. However, these studies suffer from inefficiency due to the additional training required for the generator and produce poor-quality images. Additionally, they do not investigate advanced attack methods capable of generating highly transferable adversarial examples, resulting in a low attack success rate (ASR). In this paper, we propose a transferable data-free black-box attack (TDBA) scheme based on fine-tuning Stable Diffusion using Low-Rank Adaptation (LoRA) to obtain a substitute model with improved accuracy. To achieve a higher ASR, we integrate attention loss and relax the greedy search to enhance the gradient-based attack method, thereby improving the transferability of adversarial examples. Comprehensive experiments conducted on three benchmark datasets demonstrate the effectiveness of TDBA, which outperforms state-of-the-art GAN-based strategies in terms of the ASR under the same query budget. Furthermore, when combined with the improved gradient-based attacks, our approach further boosts the ASR and achieves a trade-off between ASR and attack cost.
Qingwen Jin, Yuedong Pan
CSCWD2
2025 TaintAttack: rapid attack investigation based on information flow tracking
abstract
Abstract The perpetual battle between defenses and attacks in computing systems keeps evolving. In response to the growing complexity of attacks, data provenance has emerged as a vital solution for analysing alarms and conducting attack investigation by capturing intricate relationships among system entities. Despite its potential, the challenges of dealing with large-scale provenance graphs and a high volume of alarms persist, leading to inefficiencies in alarm analysis and attack investigation. To tackle these challenges, we present TaintAttack, an innovative approach for attack investigation. When performing provenance graph construction, TaintAttack conducts real-time tagging for system entities. To emphasize the critical threats, TaintAttack quantifies the threat levels of alarms based on event rarity, contextual features, and impact severity. Furthermore, guided by information flow tagging, TaintAttack commences attack investigation from alarms with high threat levels, greatly enhancing the overall efficiency of the investigation process. The evaluation results on 12 multi-stage attacks show that TaintAttack performs better in attack investigation compared to existing studies, reducing the investigation time by 2 orders of magnitude.
Yuedong Pan, Lixin Zhao, Tao Leng, Chaofei Li
Comput. J.1
2024 ATKHunter: Towards Automated Attack Detection by Behavior Pattern Learning
Yuedong Pan, Lixin Zhao, Chaofei Li, Tao Leng, Dan Meng 0002
ICDF2C (1)1
2024 Enhancing Adversarial Robustness for Deep Metric Learning via Attention-Aware Knowledge Guidance
Chaofei Li, Yuedong Pan, Ruicheng Niu
ICIC (12)3
2024 Early Detection of Fileless Attacks Based on Multi-Feature Fusion of Complex Attack Vectors
abstract
The initial manifestations of fileless attacks were predominantly document-based attacks, extensively leveraged in Advanced Persistent Threat (APT) campaigns and cybercriminal activities. Malicious documents leveraging macros, DDE, template injection, and other attack vectors evade conventional signature-based detection techniques. Additionally, the constant influx of new samples undermines models trained only on single attack vector features. Herein, we introduce DocInspect, a methodological framework predicated on the multi-feature fusion of complex attack vectors. Through observational analyses of attack vectors, static analysis extracts keywords and indicators of compromise from vectors like macro code, simulated execution retrieves shellcode function calls and parameters, and deceptive images and text are concurrently extracted. These multi-dimensional features are then fused to construct feature vectors. Ultimately, leveraging the Extra Trees model on our latest sample set, we achieve an F1 score of 99.96%, while demonstrating commendable robustness.
Tao Leng, Lixin Zhao, Yuedong Pan, Dan Meng 0002
ISCC3
2023 MemInspect: Memory Forensics for investigating Fileless Attacks
abstract
Traditional security solutions focus on identifying threats that leave traces on the system’s hard drive. However, fileless attacks have become increasingly popular among cybercriminals due to their ability to evade detection and persist undetected for prolonged periods. In response, memory forensics facilitates the extraction of system memory activities, presenting an opportunity to detect fileless attacks executed directly in memory. This paper presents MemInspect, a specialized memory forensics approach designed to extract features and accurately identify and locate suspicious memory regions, effectively aiding analysts in investigating fileless malware attacks. Specifically, By Utilizing virtual address descriptor nodes as samples, MemInspect constructs a comprehensive set of 42 features to detect code injection, script-based attacks, and living off the land attacks. Subsequently, these features are employed for classification using ensemble learning algorithms. In this study, we meticulously designed comprehensive attack experiments, accurately simulating three prevalent types of fileless attacks. Through rigorous analysis and extensive training on the experimental data, MemInspect demonstrates remarkable performance, achieving an impressive Area Under the Curve (AUC) value of 98%. Additionally, the paper provides two detailed analysis cases of attack investigations, furnishing concrete evidence of MemInspect’s efficacy in detecting fileless attacks.
Tao Leng, Yuedong Pan, Lixin Zhao, Dan Meng 0002
TrustCom2
2022 AttackMiner: A Graph Neural Network Based Approach for Attack Detection from Audit Logs
Yuedong Pan, Tao Leng, Lixin Zhao, Jiangang Ma, Dan Meng 0002
SecureComm1