VLDB 2026 Research / reviewers in the wild / expert
Zhixin Shi
dblp:36/4482
· DBLP profile ↗
52ranked-venue papers
14as first author
23since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 25 · 11 first-author · 7 since 2021Databases, data management, data science and information retrieval · 16 · 6 first-author · 4 since 2021Computer networks · 14 · 3 first-author · 10 since 2021Systems, architecture and hardware · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-author · 1 since 2021Security and privacy · 2Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multimodal Fusion Case-Based Reasoning for Open-World Knowledge Graph Completion
Tengfan Weng, Xiaoyu Kang, Zhixin Shi |
KSEM (3) | 3 |
| 2026 | CGA-Net: Fusing Cross-Modal Attention and Gated Mechanisms for Multi-modal Knowledge Graph Completion
Xiaoyu Kang, Zhixin Shi, Yanqiu Zhang |
KSEM (3) | 4 |
| 2026 | A Spatio-Temporal Bayesian Graph Neural Network for Proactive Anomaly Prediction in Dynamic Wireless Networks
Xiaoyu Kang, Weiqing Huang, Zhixin Shi |
WCNC | 4 |
| 2025 | Heterogeneous Graph Neural Networks with Ordinal Regression for Legal Case Retrieval
Jianrong Zhang, Xiaoyu Kang, Zhixin Shi |
IEEE Big Data | 3 |
| 2025 | ProCom: Progressive Multi-modal Knowledge Graph Completion via Adaptive Function
Xiaoyu Kang, Zhixin Shi, Degang Sun, Tengfan Weng, Liyue Ren |
ICIC (8) | 2 |
| 2025 | APFedEmb: An Adaptive and Personalized Federated Knowledge Graph Embedding Framework for Link Prediction
Tengfan Weng, Xiaoyu Kang, Zhixin Shi |
ICIC (4) | 3 |
| 2025 | Fedcafe: Federated Context-Aware Recommendation Via Adaptive Fuzzy EmbeddingabstractMobile edge computing (MEC) is important in location-based social networks (LBSNs). It puts services near users to cut delays. Edge service recommendation needs to mix context details with user privacy. Data sparsity makes this hard. Traditional methods have trouble with little data. They miss small context details or hurt privacy with central systems. This paper introduces FedCAFE, a federated learning system for edge service recommendation with context awareness. FedCAFE uses three main parts. It has a denoising autoencoder to get strong user and service features from small data. This tool learns patterns by fixing noisy information. It helps when user-service interactions are few. FedCAFE also uses a new adaptive fuzzy clustering method to group users and services by context matches. This part looks at things like time and place. It changes how it groups based on different situations. FedCAFE applies federated learning to keep privacy safe. It trains on user devices. It sends only model updates, not personal data. This stops private stuff like location from leaving the device. We tested FedCAFE on the WSDream dataset with real service information. FedCAFE beats other methods in these tests. Xiaoyu Kang, Zhixin Shi |
MDM | 2 |
| 2025 | MEVE-FN: An Adaptive Learning Framework for Multimodal Fake News Detection using Mixture-of-ExpertsabstractThe rapid dissemination of multimodal fake news on social media platforms poses a significant challenge, as deceptive narratives often combine text and images to mislead users. To address this, we propose MEVE-FN, a novel fake news detection framework built upon a Mixture-of-Experts (MoE) architecture. Our model leverages modality-specific vision and language experts to extract specialized features. These features are then dynamically integrated using a Laplace Gating mechanism for adaptive fusion and a MEVE-Adapter module that enhances deep cross-modal interaction. Comprehensive experiments on three public benchmarks (Weibo, Weibo21, and Twitter) demonstrate that MEVE-FN consistently outperforms strong baseline models, achieving notable improvements in detection accuracy and robustness. Furthermore, ablation studies validate the effectiveness of our proposed components, confirming the critical contribution of both the Laplace gating and the MEVE-Adapter to the model’s superior performance. Xiaoyu Kang, Zhixin Shi |
SMC | 2 |
| 2024 | Boosting self-repair workflow with brainstorming for code generationabstractUtilizing large language models (LLMs) for code generation has greatly enhanced software development. However, despite the advances in automated code generation frameworks that incorporate self-repair strategies, successful outcomes are not always guaranteed. This led us to explore a different approach to improving code quality. So we implemented a brainstorm-select-repair framework. For a natural language query, our framework first generates multiple foundational code snippets. Then these snippets are tested on test cases, and a text-similarity-based algorithm is used to identify the most accurate code. If none of the generated code snippets successfully fulfills the test cases, our proposed self-repair strategy is used to rectify any flawed code snippets until a code snippet that can pass the test case is identified and then provided to the user. Based on ChatGPT3, our framework reached 89% Pass@1 on HumanEval dataset (at least 3% higher than ChatGPT-4 the best model to date on this dataset). Our framework also surpasses state-of-the-art methods and delivers superior performance on the HumanEval-ET, MBPP, and MBPP-ET datasets. To further validate our design rationale, we conducted comprehensive experiments and analyzed the impact of each component. Zhaoming Jin, Zhixin Shi |
ATS | 2 |
| 2024 | A Meta-Learning-Based Joint Two-View Framework for Inductive Knowledge Graph CompletionabstractInductive knowledge graph completion (KGC) aims at predicting triples involving new entities or relations not present during training. Recently proposed methods have achieved good performance in predicting triples involving only unseen entities, which either utilize the enclosing subgraph reasoning or learn transferable structural patterns by sampling local subgraphs. However, existing methods predominantly focus on modeling entities based on neighboring relations within independent subgraphs, posing challenges in handling sparse knowledge graphs and leading to the loss of global semantic information. In this paper, we introduce MeJo, a meta-learning-based joint two-view framework. MeJo incorporates the ontology view to provide rich, transferable type information for entity representation. The two-view interaction connects each independent subgraph, enabling the model to learn global contextual information. The model is trained to capture transferable structure knowledge from the instance view and comprehensive semantic information from the ontology view, incorporating hierarchy-aware encoding for ontologies with hierarchical structures. Furthermore, our approach can extend to handling both unseen entities and unseen relations simultaneously during the test. Extensive experimental analysis reveals that MeJo excels beyond current state-of-the-art approaches in both effectiveness and generalizability across prevalent benchmark datasets. Doudou Yang, Zhixin Shi, Yangyang Zong, Xiaoyu Kang |
IJCNN | 2 |
| 2024 | A New Method of Cyber Deception DefenseabstractNew network attacks such as Advanced Persistent Threats (APTs) have created an asymmetric dynamic between attackers and defenders. Traditional defense mechanisms typically focus on perimeter security, rendering them ineffective once attackers infiltrate the network. Cyber deception defense, on the other hand, proactively establishes a deceptive environment to manipulate attackers’ perceptions and decisions, thereby delaying, detecting, and potentially thwarting attacks. This paper introduces a novel approach rooted in cyber deception defense, utilizing FPGA technology. By harnessing network packet rewriting techniques on FPGA, this method rapidly generates numerous disguised hosts and ports. The implementation of this approach on an FPGA hardware platform allows for the evaluation of its effectiveness. In simulated environments, the method demonstrates remarkable efficiency in constructing deceptive environments, with a policy query time of approximately 50ns. Transitioning to real-world network scenarios, the prototype system extends the time required for attackers to identify genuine hosts by a factor of 4.5. Moreover, the average delay time of the prototype system in processing 64-byte data packets is approximately 5.68us, showcasing consistent performance across various deception strategies. Crucially, the system’s overhead remains minimal, effectively confounding and deterring attackers while increasing the complexity and cost associated with mounting successful attacks. Chaochao Liu, Degang Sun, Zhixin Shi |
ISCC | 3 |
| 2024 | SHTree: A Structural Encrypted Traffic Fingerprint Generation Method for Multiple Classification TasksabstractIn recent years, encrypted traffic classification has been found widespread applications in the field of cybersecurity. Its main challenge lies in accurately represent traffic when features are obscured due to encryption. To address this, researchers utilize fingerprint construction methods based on statistical information or employ Deep Learning (DL) for traffic representation. However, in previous methods of feature selection, flat key-value pair features, or raw packet bytes are often used, ignoring the structured information embedded in packets and flows. Therefore, We propose a novel structured encrypted traffic fingerprint generation method called SHTree. It constructs traffic fingerprints using a set of tree-based structures to represent traffic, encapsulating structural features from the traffic, enhancing the representation of traffic. This enables it to adapt to various classification tasks through general feature selection. The experiments demonstrate that our method achieves comparable accuracy to state-of-the-art Large Language Models (LLMs), with an F1 score higher by 0.5% on specific tasks. Meanwhile, it outperforms by three orders of magnitude in classification speed. In unsupervised abnormal detection tasks, the True Positive Rate (TPR) exceeds 99%, while maintaining a False Positive Rate (FPR) of 0.5%. Minghao Ma, Zhixin Shi, Qilei Yin, Yangyang Zong |
ISCC | 2 |
| 2024 | LONGAN: Detecting Lateral Movement based on Heterogeneous Graph Neural Networks with Temporal FeaturesabstractLateral movement (LM) plays a pivotal role in Advanced Persistent Threats (APTs), constituting a significant cybersecurity concern. Recent graph-based LM detection methods have demonstrated satisfactory performance by harnessing the potent representation capabilities of graph learning techniques. However, the evolving nature and increasing sophistication of LMs necessitate novel defensive strategies to thwart these attacks. In this paper, we introduce LONGAN, an innovative LM detection system leveraging heterogeneous graph neural networks incorporating temporal features to tackle this challenge. Specifically, we first introduce a formalized heterogeneous graph encompassing various network entities to model the intricate LM scenario. Subsequently, to capture LM dynamics, we employ a heterogeneous temporal graph to model LM evolution by integrating heterogeneous spatial information across temporal dimensions. Building upon this foundation, we devise HSTA, a framework for heterogeneous temporal graph learning, to aggregate both spatial and temporal features for LM detection. In the HSTA, we devise a heterogeneous spatial aggregation module to learn representations for diverse entity types and relations; we design a temporal aggregation module to consolidate historical node sequences into their representations. These modules synergistically operate to identify LMs. Evaluation on public datasets demonstrates that our LONGAN achieves superior performance (98.09% AUC and 96.56% F1-score) compared to state-of-the-art approaches. Yangyang Zong, Zhixin Shi, Weiqing Huang |
ISCC | 2 |
| 2023 | MESCAL: Malicious Login Detection Based on Heterogeneous Graph Embedding with Supervised Contrastive LearningabstractMalicious logins via stolen credentials have become a primary threat in cybersecurity due to their stealthy nature. Recent malicious login detection methods based on graph learning techniques have made progress due to their ability to capture interconnected relationships among log entries. However, limited malicious samples pose a critical challenge to the detection performance of existing methods. In this paper, we propose MESCAL, a novel approach based on heterogeneous graph embedding with supervised contrastive learning to solve this challenge. Concretely, we construct authentication heterogeneous graphs to represent multiple and interconnected log events. Then, we pretrain a feature extractor with supervised contrastive learning to capture rich semantics on the graphs from limited malicious samples. Based on this, cost-sensitive learning is adopted to distinguish malicious logins on imbalanced data. Extensive evaluations show that the F1 score of MESCAL based on the imbalance dataset is 94.63%, which outperforms state-of-the-art approaches. Weiqing Huang, Yangyang Zong, Zhixin Shi, Puzhuo Liu |
ISCC | 3 |
| 2023 | FindSpy: A Wireless Camera Detection System Based on Pre-Trained TransformersabstractThe wireless cameras have become a major concern in cybersecurity due to privacy breaches. Recent flow based methods for wireless cameras detection have achieved promising results. However, these methods require specialized equipment for deployment and massive labeled data for training, which makes them impractical in real-world scenarios. In this paper, we propose FindSpy, a lightweight wireless camera detection method based on Pre-trained Transformers to address the challenge. By utilizing the air interface technique, FindSpy can obtain data without connecting to the wireless network where the camera is located. Additionally, FindSpy learns air interface WiFi traffic representation by pre-training a traffic representation model from large-scale unlabeled data and fine-tuning it on few labeled data. FindSpy can accurately detect wireless cameras with CNN-LSTM classifier. Extensive experiments show that FindSpy outperforms the state-of-the-art methods on few data. Concretely, FindSpy achieves a detection accuracy of over 98% by analyzing just five data packets. Zhixin Shi, Weiqing Huang |
ISCC | 1 |
| 2023 | Few-Shot Network Intrusion Detection Based on Model-Agnostic Meta-Learning with L2F MethodabstractNetwork Intrusion Detection (NID) plays an important role in identifying network threats and ensuring the security of computer and communication systems. However, the existing NID methods face two shortages: 1) Most methods are data-hungry without considering the difficulty of collecting anomaly traffic data, such as zero-day attacks. 2) Few-shot Learning (FSL)-based methods have been proposed recently to relieve the first problem. Whereas these methods rely on the specific model, leading their universality unsatisfactory in different NID application scenarios. Then, we propose a few-shot Model-Agnostic Meta-Learning (MAML) NID framework to tackle the above challenges. We extract both statistical and sequence features from raw network traffic and explicitly find an optimal solution for the NID model by constructing intrusion detection tasks in the 2-way K-shot under the few-shot learning settings. Unfortunately, the MAML forcibly shares initialization, leading to conflicts among tasks and the inability to converge to the optimal position quickly. Therefore, we introduce the L2F (Learn to Forget) attenuation mechanism to dynamically control the conflicts’ influence. We conduct sufficient experiments to validate the suitability of our method on few-shot new tasks in various models and achieve the highest detection rate of 98.68% with 2K (K=5,10,15) training samples. Zhixin Shi, Mengyan Xing |
WCNC | 1 |
| 2022 | NBP-MS: Malware Signature Generation Based on Network Behavior ProfilingabstractWith the proliferation of malware, the detection and classification of malware have been hot topics in the academic and industrial circles of cyber security, and the generation of malware signatures is one of the important research directions. In this paper, we propose NBP-MS, a method of signature generation that is based on network traffic generated by malware. Specifically, we utilize the network traffic generated by malware to perform fine-grained profiling of its network behaviors first, and then cluster all the profiles to generate network behavior signatures to classify malware, providing support for subsequent analysis and defense. Zhixin Shi, Pengcheng Liu 0007 |
ICPR | 1 |
| 2022 | PEPC: A Deep Parallel Convolutional Neural Network Model with Pre-trained Embeddings for DGA DetectionabstractDiscovering domain generation algorithms (DGAs) used to build command and control (C&C) infrastructures of botnets is crucial for recognizing botnets. Recent studies in DGA detection benefit from deep learning, such as convolutional neural network (CNN) and long short-term memory neural network (LSTM). However, these studies need massive supervised data to train their models, while obtaining enough labeled samples is consistently time-consuming and labor-intensive. In this paper, we propose a deep learning model, called PEPC, to detect and classify DGA domain names with only a small dataset. PEPC consists of two modules: (1) the pre-trained embeddings (PTE) module to quantify domain names to numeric vectors; and (2) the deep parallel convolutional neural networks (DPCNN) module to better extract features of vectors for prediction. Comparing our model with the 5 common deep learning-based DGA detection approaches, results show that our model yields an average improvement of 10 F1 points, while it requires just 30 training samples for each class. Significantly, PTE can help models achieve better detection and classification performances on small training samples. Weiqing Huang, Yangyang Zong, Zhixin Shi, Leiqi Wang, Pengcheng Liu 0007 |
IJCNN | 3 |
| 2022 | Improving the Semantic Consistency of Textual Adversarial Attacks via PromptabstractAdversarial examples can expose the vulnerabilities of neural networks. State-of-the-art textual adversarial attacks have demonstrated their effectiveness in triggering errors in the output of natural language processing models. However, these attacks are limited to ensuring the semantic consistency between the adversarial example and the original input, increasing the possibility of the attacks being detected by human judges. In this paper, we propose a novel textual adversarial attack, Prompt-Attack, which aims to generate the adversarial examples having consistent semantics with the original input. Specifically, Prompt-Attack enhances the input's semantics with the prompts that represent the semantics of the different target segments extracted from the original input, to predict the substitutions having consistent semantics with the target segments. Then, it crafts the adversarial examples by replacing the important segments with their substitutions that can most affect the victim model's output. Besides, Prompt-Attack proposes a span-level segment identification strategy to extract more target segments from the input and a novel masking strategy to ensure the grammatical correctness of the generated adversarial examples. Extensive experiments on public datasets illustrate that Prompt-Attack significantly improves the semantic consistency score of the baseline attacks by an average of 48%. Further, Prompt-Attack achieves the best attack success rate of 0.906, showing an average improvement of 40% to the baselines. Moreover, the experimental results demonstrate that Prompt-Attack can achieve good performance in attacking different language models and Prompt-Attack is not sensitive to different settings. Qilei Yin, Zhixin Shi, Yuru Ma |
IJCNN | 3 |
| 2022 | Frequency Hopping Signal Recognition Based on Horizontal Spatial AttentionabstractFrequency hopping (FH) technology is one of the most effective technologies in the field of radio countermeasures, meanwhile, the recognition of FH signal has become a research hotspot. FH signal is a typical non-stationary signal whose frequency varies nonlinearly with time and the time-frequency analysis technique provides a very effective method for processing this kind of signal. With the renaissance of deep learning, methods based on time-frequency analysis and deep learning are widely studied. Although these methods have achieved good results, the recognition accuracy still needs to be improved. Through the observation of the datasets, we found that there are still difficult samples that are difficult to identify. Through further analysis, we propose a horizontal spatial attention (HSA) block, which can generate spatial weight vector according to the signal distribution, and then readjust the feature map. The HSA block is a plug-and-play module that can be integrated into common convolutional neural network (CNN) to further improve their performance and these networks with HSA block are collectively called HANets. The HSA block also has the advantages of high recognition accuracy (especially under low SNRs), easy to implant, and almost no influence on the number of parameters. We verified our method on two datasets and a series of comparative experiments show that the proposed method achieves good results on FH datasets. Pengcheng Liu 0007, Zhen Han 0001, Zhixin Shi, Meimei Li, Meichen Liu |
ISCC | 3 |
| 2022 | A Novel Self-supervised Few-shot Network Intrusion Detection Method
Zhixin Shi, Mengyan Xing |
WASA (1) | 2 |
| 2021 | DeepMIT: A Novel Malicious Insider Threat Detection Framework based on Recurrent Neural NetworkabstractCurrently, more and more malicious insiders are making threats, and the detection of insider threats is becoming more challenging. The malicious insider often uses legitimate access privileges and mimic normal behaviors to evade detection, which is difficult to be detected via using traditional defensive solutions. In this paper, we propose DeepMIT, a malicious insider threat detection framework, which utilizes Recurrent Neural Network (RNN) to model user behaviors as time sequences and predict the probabilities of anomalies. This framework allows DeepMIT to continue learning, and the detections are made in real time, that is, the anomaly alerts are output as rapidly as data input. Also, our framework conducts further insight of the anomaly scores and provides the contributions to the scores and, thus, significantly helps the operators to understand anomaly scores and take further steps quickly(e.g. Block insider's activity). In addition, DeepMIT utilizes user-attributes (e.g. the personality of the user, the role of the user) as categorical features to identify the user's truly typical behavior, which help detect malicious insiders who mimic normal behaviors. Extensive experimental evaluations over a public insider threat dataset CERT (version 6.2) have demonstrated that DeepMIT has outperformed other existing malicious insider threat solutions. Degang Sun, Meichen Liu, Meimei Li, Zhixin Shi, Pengcheng Liu 0007 |
CSCWD | 4 |
| 2021 | An Effective and Efficient Method for Word-Level Textual Adversarial AttackabstractAdversarial examples are used to reveal the vulnerability of deep neural networks (DNNs) and improve their robustness. The word-level attack is a well-studied class of textual adversarial attack methods. However, existing word-level attacks have unstable success rates in different application scenarios. And the attacks under black-box setting suffer from low efficiency because they need to query the target DNN model with a great quantity. In this paper, we present SynonymPSO, a word-level attack method for generating adversarial texts. Specifically, we use a variety of means to find and filter synonyms to construct a comprehensive candidate pool. Besides, we design a kind of modification record strategy to improve the efficiency of the particle swarm optimization algorithm. Compared with prior works, SynonymPSO has the following features: (1) effective - it outperforms the state-of-art attacks in terms of attack success rate on most occasions; (2) efficient - it generates adversarial examples with fewer queries and less time. We evaluate SynonymPSO on five datasets that belong to different text classification tasks, including sentiment analysis, natural language inference and spam detection. The experimental results demonstrate its effectiveness and efficiency. For instance, when attacking BiLSTM over Enron dataset, the attack success rate of our method is 20% higher than the baseline while the query number is reduced by 94%. Zhixin Shi, Yuru Ma |
ISCC | 1 |
| 2020 | Terminator: a data-level hybrid framework for intellectual property theft detection and preventionabstractRecently, high profile data breach incidents have highlighted the importance of insider Intellectual Property(IP) theft research. Matching the patterns of known attack (filtering-based or rule-based) and finding the deviation from normal behavior (anomaly-based) are two typical approaches to prevent insiders from stealing sensitive information. On the one hand, filtering-based or rule-based solutions provide accurate identification of known attacks, and thus they are suitable for IP theft prevention, but they cannot handle the insiders with in-depth knowledge of the protective measures. On the other hand, anomaly-based solutions can find unknown attacks but typically have a high false-positive rate, which limits their applicability to practice. Nowadays, more and more researchers believe that the insider attack could be improved when combining known attack pattern matching with anomaly detection technologies. Therefore, in this paper, we introduce a Data-level Hybrid Framework, dubbed as Terminator, which enabling both detection and prevention. Terminator integrates a prevention module with an anomaly detection module and uses feedback to improve the module for detection or prevention. Different from previous anomaly-based methods that could only detect anomalous activities, Terminator could detect the stealing actions proactively and take real-time actions on these actions. The effectiveness of Terminator is demonstrated by its excellent performances on a collected dataset, involving detailed information in a real-world insider network and attack data simulated by impersonating the genuine users. Meichen Liu, Meimei Li, Degang Sun, Zhixin Shi, Pengcheng Liu 0007 |
CF | 4 |
| 2020 | Adversarial Attack against LSTM-based DDoS Intrusion Detection SystemabstractNowadays, machine learning is a popular method for DDoS detection. However, machine learning algorithms are very vulnerable under the attacks of adversarial samples. Up to now, multiple methods of generating adversarial samples have been proposed. However, they cannot be applied to LSTM-based DDoS detection directly because of the discrete property and the utility requirement of its input samples. In this paper, we propose two methods to generate DDoS adversarial samples, named Genetic Attack (GA) and Probability Weighted Packet Saliency Attack (PWPSA) respectively. Both methods modify original input sample by inserting or replacing partial packets. In GA, we evolve a set of modified samples with genetic algorithm and find the evasive variant from it. In PWPSA, we modify original sample iteratively and use the position saliency as well as the packet score to determine insertion or replacement order at each step. Experimental results on CICIDS2017 dataset show that both methods can bypass DDoS detectors with high success rate. Weiqing Huang, Zhixin Shi, Yuru Ma |
ICTAI | 3 |
| 2019 | The parameter optimization based on LVPSO algorithm for detecting multi-step attacksabstractHow to detect intrusion attacks is a big challenge for network administrators since the attacks involve multi-step nowadays. The hidden markov model (HMM) is widely used in the field of multi-step attacks detection. However, the existing traditional Baum-Welch algorithm of HMM has two shortcomings: one is the number of attack states need to be determined in advance, the other is the algorithm may make the parameters converge to a local (not overall) optimal solution. In this paper, we propose a novel LVPSO-HMM algorithm based on variable length particle swarm optimization, which solves the shortcomings mentioned above. Concretely, it can optimize the number of attack states when the attacks state is unknown and it can make the model parameters converge to a global optimal solution. Then, we present a multi-step attack detection model architecture whose main idea is, when the number of attack states is unknown in the actual network environment LVPSO-HMM algorithm is used to solve the problem of relying on prior knowledge in current detection. Experiments on the well-known Darpa2000 dataset verify the efficiency of the method. Zhixin Shi |
CF | 3 |
| 2019 | A SeqGAN-Based Method for Mimicking Attack
Weiqing Huang, Zhixin Shi |
Inscrypt | 3 |
| 2019 | A Behavior-Based Method for Distinguishing the Type of C&C Channel
Qilei Yin, Zhixin Shi, Guokun Xu, Xiaoyu Kang |
ICA3PP (1) | 3 |
| 2019 | Adversarial Attack Against DoS Intrusion Detection: An Improved Boundary-Based MethodabstractDenial of Service (DoS) attacks pose serious threats to network security. With the rapid development of machine learning technologies, artificial neural network (ANN) has been used to classify DoS attacks. However, ANN models are vulnerable to adversarial samples: inputs that are specially crafted to yield incorrect outputs. In this work, we explore a kind of DoS adversarial attacks which aim to bypass ANN-based DoS intrusion detection systems. By analyzing features of DoS samples, we propose an improved boundary-based method to craft adversarial DoS samples. The key idea is to optimize a Mahalanobis distance by perturbing continuous features and discrete features of DoS samples respectively. We experimentally study the effectiveness of our method in two trained ANN classifiers on KDDcup99 dataset and CICIDS2017 dataset. Results show that our method can craft adversarial DoS samples with limited queries. Weiqing Huang, Zhixin Shi |
ICTAI | 3 |
| 2019 | A New C&C Channel Detection Framework Using Heuristic Rule and Transfer LearningabstractA great many of botnet detection methods focus on recognizing the significant C&C channels. Most of them require a C&C training set to build a behavior detection model. However, when lacking such training set for new or unknown botnets, these methods may become inefficient or even invalid.To overcome it, we propose a new general framework for C&C channel detection. It neither needs us to know the families of bots or prepare a training set nor requires deploying malicious activity monitors. Also, it is capable of mining useful knowledge from the historical dataset to boost its detection performance. In our framework, we put forward a clustering method and several heuristic rules to aggregate and label partial C&C traffic, a sample selection function to mine useful historical knowledge and a transfer learning based model to find other C&C channels. We evaluated our framework on two datasets and achieved the best C&C F-measure of about 0.886 and 0.960 respectively. Moreover, the comparison result further indicates its performance advantage and better behavior learning ability. Qilei Yin, Zhixin Shi, Meimei Li |
IPCCC | 3 |
| 2019 | A Novel Method for Highly Imbalanced Classification with Weighted Support Vector Machine
Biao Qi, Zhixin Shi, Meimei Li |
KSEM (1) | 3 |
| 2018 | Comprehensive Behavior Profiling Model for Malware ClassificationabstractIn view of the great threat posed by malware and the rapid growing trend about malware variants, it is necessary to determine the category of new samples accurately for further analysis and taking appropriate countermeasures. The network behavior based classification methods have become more popular now. However, the behavior profiling models they used usually only depict partial network behavior of samples or require specific traffic selection in advance, which may lead to adverse effects on categorizing advanced malware with complex activities. In this paper, to overcome the shortages of traditional models, we raise a comprehensive behavior model for profiling the behavior of malware network activities. And we also propose a corresponding malware classification method which can extract and compare the major behavior of samples. The experimental and comparison results not only demonstrate our method can categorize samples accurately in both criteria, but also prove the advantage of our profiling model to two other approaches in accuracy performance, especially under scenario based criteria. Qilei Yin, Zhixin Shi, Meimei Li |
ISCC | 3 |
| 2017 | Could we beat a new mimicking attack?abstractFlooding DDoS and Flash Crowds (FC) are difficult to be discriminated from network layer because both of them have too many statistical similarities. If attacker learnt those statistical difference and could produce some mimicking traffic which have little difference from traffic produced by legitimate uses in FC, which means existing methods will uselessness. In order to verify the existence of this possibility, this paper proposes an idea that employed Least Squares Generative Adversarial Networks (LSGANs) to generate mimicking traffic to make the defense system uselessness. By experiments evaluated, the proposed idea could mimicking traffic to fool the defense system. The proposed idea mainly focuses on traffic statistical information of each Bot and legitimate user, does not rely on network environments, so the possibility of this mimicking attack happened could be existed in other networks, such as wired network, wireless network and mobile network. Degang Sun, Zhixin Shi |
APNOMS | 4 |
| 2017 | BotTokenizer: Exploring Network Tokens of HTTP-Based Botnet Using Malicious Network Traces
Biao Qi, Zhixin Shi, Yan Wang 0081, Jizhi Wang |
Inscrypt | 2 |
| 2017 | A New Mimicking Attack by LSGANabstractDiscriminating Distributed Denial of Service Attacks (DDoS) from Flash Crowds (FC) is a tough and challenging problem. If attackers could generate mimicking traffic which have little difference from the traffic produced by legitimate users in FC, are existing methods and defense systems still able to distinguish DDoS from FC? To verify the possibility of the existence of this mimicking attack and prove the existing methods cannot discriminate this attack from FC, this paper proposes an idea employed Least Squares Generative Adversarial Networks (LSGAN) to generate mimicking traffic based on a statistical features achieved from an extensive analysis of user traffic behavior of DDoS and FC. Then to establish an efficient defense system employed Random Forest to prove it can achieve better performance on real network traffic traces, but cannot discriminate this mimicking attack traffic from FC. The experiments results show the proposed idea can generate this mimicking attack traffic and the defense system cannot discriminate it from FC. In addition, a comparison with GAN has been made to show that LSGAN is better than GAN in performance. Degang Sun, Zhixin Shi |
ICTAI | 3 |
| 2017 | A Behavior-Based Method for Distinction of Flooding DDoS and Flash Crowds
Degang Sun, Zhixin Shi |
KSEM | 3 |
| 2017 | Detecting Flooding DDoS Under Flash Crowds Based on Mondrian Forest
Degang Sun, Zhixin Shi, Yan Wang 0081 |
WASA | 3 |
| 2014 | A Two Level Algorithm for Text Detection in Natural Scene ImagesabstractIn this paper we present a two-level method to detect text in natural scene images. In the first level, connected components (referred as CCs) are got from the images. Then candidate text lines are extracted and groups of connected components that align in horizontal or vertical direction are got. We think CCs in these groups have high probability are texts. To validate which CC is text, a SVM is trained to make an initial decision. The output of SVM is calibrated to posterior probability. Then we use the information of posterior probability of SVM and information of whether the connected component is in a group to divide the connected components into four classes: texts, non-texts, probable texts and undetermined CCs. In the second level, a conditional random field model is used to make final decision. Relationship between CCs is modeled by a network G(V, E), Vertices of the graph correspond to CCs. The determination in the first level will influence the second levels determination by giving different parameters of data term for the four classes of CCs. By this way, we not only use information of a single CCs feature, but also use the information of whether a CC is in a group to make final decision of whether the CC is text or non-text. Experiments show that the method is effective. Suyu Wang, Zhixin Shi |
Document Analysis Systems | 3 |
| 2013 | A Model Based Framework for Table Processing in Degraded Document ImagesabstractThis paper describes a model based framework for detection and extraction of the contents of table cells from degraded handwritten document images that contain tables. Given the very poor quality of the target documents, the table cell detection problem is formulated conceptually as a two-step process. The first step is to identify the location of the table and extract the content of table cells given a model of the structure of the table present in the image. The second step is to identify the model of the table present in a document image from a list of given table models. A model-based representation for tables is introduced and is used for matching table candidates with the given model to identify and extract the contents of table cells. The approach for detecting potential table candidates is based on the detection of horizontal and vertical table line candidates. The table representation is a matrix of horizontal and vertical table line crossings, and the matching algorithm is formulated as a minimization problem where the optimal table candidate is obtained using the minimal distance between the candidate and model table matrices which is then used for extraction of the table cell contents. A similar approach is used to solve the model selection problem where the best fitting location in the document page for each of the candidate models is identified using the distance minimization approach along with a confidence score and the model with the highest confidence score is selected as the correct model. The approach was tested on document page images containing tables from the challenge set of the DARPA MADCAT handwritten document image data. Results indicate that the method is effective for both model selection as well as table cell content extraction. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju |
ICDAR | 1 |
| 2012 | Keyword Spotting Framework Using Dynamic Background ModelabstractAn important task in Keyword Spotting in handwritten documents is to separate Keywords from Non Keywords. Very often this is achieved by learning a filler or background model. A common method of building a background model is to allow all possible sequences or transitions of characters. However, due to large variation in handwriting styles, allowing all possible sequences of characters as background might result in an increased false reject. A weak background model could result in high false accept. We propose a novel way of learning the background model dynamically. The approach first used in word spotting in speech uses a feature vector of top K local scores per character and top N global scores of matching hypotheses. A two class classifier is learned on these features to classify between Keyword and Non Keyword. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju, Ramachandrula Sitaram |
ICFHR | 2 |
| 2011 | Image Enhancement for Degraded Binary Document ImagesabstractThis paper presents a novel set of image enhancement algorithms for binary images of poorly scanned real world page documents. Problems that are targeted by the methods described include large blobs or clutter noise, salt-and-pepper noise and detection and removal of non-text objects such as form lines or rule-lines. The algorithms described are shown to be very effective in removing clutter noise and pepper noise as well as form lines and rule-lines. A region growing algorithm is also described to enhance the quality of the text and to fix the problems arising from the salt noise which leaves holes in the text and creates broken strokes. The methods were tested on 204 images from the challenge set of the DARPA MADCAT Arabic handwritten document image data. The results indicate that the methods described are robust and are capable of significantly improving the image quality for downstream OCR systems. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju |
ICDAR | 1 |
| 2010 | Removing Rule-Lines from Binary Handwritten Arabic Document Images Using Directional Local ProfileabstractIn this paper, we present a novel approach for detecting and removing pre-printed rule-lines from binary handwritten Arabic document images. The proposed technique is based on a directional local profiling approach for the detection of the rule-line locations. Then a refined adaptive vertical run-length search is designed for removing the rule-line pixels without much damaging to the text. They are also tolerate to the variations in the rule-lines such as broken lines, orientation changes and variation in the thickness of the rule-lines. Analysis of experimental results on the DARPA MADCAT Arabic handwritten document data indicates that the method is robust and is capable of correctly removing rule-lines. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju |
ICPR | 1 |
| 2009 | A Steerable Directional Local Profile Technique for Extraction of Handwritten Arabic Text LinesabstractIn this paper, we present a new text line extraction method for handwritten Arabic documents. The proposed technique is based on a generalized adaptive local connectivity map (ALCM) using a steerable directional filter. The algorithm is designed to solve the particularly complex problems seen in handwritten documents such as fluctuating, touching or crossing text lines. The proposed algorithm consists of three steps. Firstly, a steerable filter is used to probe and determine foreground intensity along multiple directions at each pixel while generating the ALCM. The ALCM is then binarized using an adaptive thresholding algorithm to get a rough estimate of the location of the text lines. In the second step, connected component analysis is used to classify text and non text patterns in the generated ALCM to refine the location of the text lines. Finally, the text lines are separated by superimposing the text line patterns in the ALCM on the original document image and extracting the connected components covered by the pattern mask. Analysis of experimental results on the DARPA MADCAT Arabic handwritten document data indicate that the method is robust and is capable of correctly isolating handwritten text lines even on challenging document images. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju |
ICDAR | 1 |
| 2009 | Segmentation of Arabic Handwriting Based on both Contour and Skeleton SegmentationabstractWe propose a new algorithm for segmentation of off-line handwritten Arabic words. The algorithm segments the connected letters to smaller segments each of which contains no more than three letters. Each letter may be segmented to at most five pieces. In addition to improving the recognition of Arabic words, another potential application of the proposed segmentation method is to build lexicon of small size, consisting of no more than three letter combinations. Generally, it is very hard to generate lexicon for recognition of unconstraint handwritten Arabic documents due to the large number of words of Arabic language.The algorithm has been tested on over 6300 words from 45 different documents written by 18 writers. The system is able to segment more than 93% of the words into segments, each containing at most one letter, 6% of the words into segments that contains two letters and 3% of the words into segments that contains three letters. Safwan Wshah, Zhixin Shi, Venu Govindaraju |
ICDAR | 2 |
| 2007 | PDE-Based Enhancement of Low Quality DocumentsabstractPartial Differential Equations are becoming one of the core tools for low-level image processing. They are especially functional in diffusion processes and variational models. In this paper, we exploit the regional smoothing that occurs in a nonlinear diffusion process and use this to enhance text in a degraded document image. The proposed smoothing method is robust when applied to either a highly corrupted text document or one with little degradation. The technique was tested on historical documents, carbon copies with highly varying grayscale backgrounds and on synthetic noisy documents. The PDE-based method far outperformed other industry-standard binarization techniques when compared quantitatively and qualitatively. Ifeoma Nwogu, Zhixin Shi, Venu Govindaraju |
ICDAR | 2 |
| 2006 | A chaincode based scheme for fingerprint feature extraction
Zhixin Shi, Venu Govindaraju |
Pattern Recognit. Lett. | 1 |
| 2005 | Multi-scale Techniques for Document Page SegmentationabstractPage segmentation algorithms found in published literatures often rely on some predetermined parameters such as general font sizes, distances between text lines and document scan resolutions. Variations of these parameters in real document images greatly affect the performance of the algorithms. In this paper, we present a novel approach for document page segmentation using a multi-scale technique. An efficient implementation of a local connectivity algorithm transforms a document image into a parameter domain in which a parameter value at a pixel location represents a connectivity property for its neighboring foreground pixels in the original document image. Then a top-down approach with a linear search reveals the document regions at each scale levels as text block, text lines and graphics. We consider our algorithm a transform based multi-scale method. Our ongoing research shows that the algorithm is robust for variations of document parameters. Zhixin Shi, Venu Govindaraju |
ICDAR | 1 |
| 2005 | Text Extraction from Gray Scale Historical Document Images Using Adaptive Local Connectivity MapabstractThis paper presents an algorithm using adaptive local connectivity map for retrieving text lines from the complex handwritten documents such as handwritten historical manuscripts. The algorithm is designed for solving the particularly complex problems seen in handwritten documents. These problems include fluctuating text lines, touching or crossing text lines and low quality image that do not lend themselves easily to binarizations. The algorithm is based on connectivity features similar to local projection profiles, which can be directly extracted from gray scale images. The proposed technique is robust and has been tested on a set of complex historical handwritten documents such as Newton's and Galileo's manuscripts. A preliminary testing shows a successful location rate of above 95% for the test set. Zhixin Shi, Srirangaraj Setlur, Venu Govindaraju |
ICDAR | 1 |
| 2003 | A Format-Driven Handwritten Word Recognition SystemabstractA format-driven word recognition system is proposed for recognition of handwritten words. Unlike most traditional handwritten word recognizers being given a set of target words as lexicon, we assume that our system is given a set of format descriptions other than lexicon words. Applications of the pro-posed system include recognition of relatively more important keywords such as postal codes, titles or trademarks. The for-mat descriptions are in terms of the lengths of the keywords, the types of the characters in the keywords and positional in-formations. Due to the important role of the keywords in the applications, the recognition expectations in terms of recogni-tion rate and accuracy are usually higher then lexicon-driven word recognizers. 1. Zhixin Shi |
ICDAR | 2 |
| 2003 | Skew Detection for Complex Document Images Using Fuzzy RunlengthabstractA skew angle estimation approach based on the application of a fuzzy directional runlength is proposed for complex address images. The proposed technique was tested on a variety of USPS parcel images including both machine print and handwritten addresses. The testing results showed a successful rate more than 90% of the test set. Zhixin Shi, Venu Govindaraju |
ICDAR | 1 |
| 1997 | Segmentation and recognition of connected handwritten numeral strings
Zhixin Shi, Venu Govindaraju |
Pattern Recognit. | 1 |
| 1996 | Character image enhancement by selective region-growing
Zhixin Shi, Venu Govindaraju |
Pattern Recognit. Lett. | 1 |