Liangwei Yao

dblp:355/0150 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0007-2944-4632ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A Lightweight Android Malware Detection Framework Based on Markov Images and Knowledge Distillation
abstract
The Android system has been widely used in mobile devices and embedded terminals, significantly enhancing user interaction and service efficiency. However, its openness has also led to increasingly frequent and evolving malware attacks, seriously threatening system and data security. Existing detection methods generally suffer from problems such as large model size, high computational overhead, and high deployment costs, making it difficult to run efficiently on resource-constrained devices and have limited generalization ability for new or unknown malware. To this end, this paper proposes a high-precision, low-overhead, lightweight Android malware detection framework. The framework first performs fine-grained static analysis on APK files, extracts Dalvik opcode sequences, and generates grayscale images based on Markov transition probabilities, thereby transforming program behavior patterns into learnable visual representations. Secondly, a lightweight adaptive channel attention (ACA) mechanism is designed and embedded into a lightweight CNN to enhance the model’s perception of crucial feature channels. Finally, a knowledge distillation strategy is introduced to guide student model training using a high-performance teacher model, improving its generalization ability. Experiments are conducted on the publicly available datasets CICMalDroid2020, CICAndMal2017, and the newly constructed dataset. The results show that the proposed framework achieves accuracy of 98.50%, 98.63%, and 81.16%, respectively, while maintaining low computational overhead and small model size, significantly outperforming existing advanced methods. The framework achieves a good balance between detection accuracy, efficiency, and deployment feasibility, and has strong potential for widespread application on mobile and IoT devices.
Liangwei Yao, Yang Xin 0001
IEEE Internet Things J.1
2026 Only less labeled: How to learn representations from multi-domain
Chunyong Zhang, Liangwei Yao
J. Syst. Softw.2
2025 Vulnerability detection with Graph Attention Network and Metric Learning
Chunyong Zhang, Liangwei Yao, Yang Xin 0001
Inf. Softw. Technol.2
2025 Res2Next with attention mechanisms for malware classification based on feature visualization
Liangwei Yao, Yang Xin 0001
J. Inf. Secur. Appl.1
2024 Visualization-based comprehensive feature representation with improved EfficientNet for malicious file and variant recognition
Liangwei Yao, Bin Liu 0069, Yang Xin 0001
J. Inf. Secur. Appl.1
2023 CPVD: Cross Project Vulnerability Detection Based on Graph Attention Network and Domain Adaptation
abstract
Code vulnerability detection is critical for software security prevention. Vulnerability annotation in large-scale software code is quite tedious and challenging, which requires domain experts to spend a lot of time annotating. This work offers CPVD, a cross-domain vulnerability detection approach based on the challenge of ”learning to predict the vulnerability labels of another item quickly using one item with rich vulnerability labels.” CPVD uses the code property graph to represent the code and uses the Graph Attention Network and Convolution Pooling Network to extract the graph feature vector. It reduces the distribution between the source domain and target domain data in the Domain Adaptation Representation Learning stage for cross-domain vulnerability detection. In this paper, we test each other on different real-world project codes. Compared with methods without domain adaptation and domain adaptation methods based on natural language processing, CPVD is more general and performs better in cross-domain vulnerability detection tasks. Specifically, for the four datasets of chr_deb, qemu, libav, and sard, they achieved the best results of 70.2%, 81.1%, 59.7%, and 78.1% respectively on the F1-Score, and 88.4%,86.3%, 85.2%, and 88.6% on the AUC.
Chunyong Zhang, Bin Liu 0069, Yang Xin 0001, Liangwei Yao
IEEE Trans. Software Eng.4