Jinhe Wu

dblp:385/6555 · DBLP profile ↗
← Back
7ranked-venue papers
0as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Swallow: A Transfer-Robust Website Fingerprinting Attack via Consistent Feature Learning
abstract
Website fingerprinting (WF) attacks on Tor networks can analyze traffic patterns to identify the websites Tor users are visiting, and thus pose a significant threat to user privacy. In a real-world environment, Tor users face diverse network conditions and can also employ WF defenses, raising new challenges to launch WF attacks. The state-of-the-art (SOTA) WF attacks either rely on a strong assumption that WF classifiers are trained and deployed under the same network condition, or suffer from significant performance degradation against WF defenses. In this paper, we propose Swallow, a transfer-robust WF attack that can quickly transfer to new network conditions while maintaining robustness against various WF defenses. Specifically, we propose a novel trace representation named Consistent Interaction Feature (CIF), which aligns traffic distributions across different network conditions to capture consistent features. Then we design three data augmentation algorithms to simulate potential variations under various network conditions. We extensively evaluate Swallow using ten datasets, including both self-collected and public datasets. The closed- and open-world evaluation results demonstrate that Swallow significantly outperforms the SOTA attacks. In particular, with only 5 labeled instances per website for model fine-tuning, Swallow achieves an average improvement in accuracy of 17.50% over the SOTA WF attacks.
Meng Shen 0001, Jinhe Wu, Junyu Ai, Qi Li 0002, Chenchen Ren, Ke Xu 0002, Liehuang Zhu
CCS2
2025 A time series long-short term codec for compression and representation
abstract
Data compression is highly required to reduce the massive size of data while achieving lossless information over the transmission. In this paper, a novel multi-channel time series codec framework (LSCodec) is proposed to decouple long-term trend and short-term fluctuation using manually guided preprocessing data. The proposed LSCodec contains an encoder-decoder architecture network integrated with a group residual vector quantizer. The input data is decoupled through two paths layer by layer. In one path, a LSTM model is introduced for long-term trend feature learning. Another path produces fluctuation signal by subtracting between the real-time series and the trend signal to learn its hidden representation. The output of both path are then quantized using two individual residual vector quantization. A joint reconstruction loss combining its trend and fluctuation loss is used to support the training process. A balancer is used to stabilize training gradient of reconstruction loss to avoid local optimal solution or unstable state. Our experimental results show that the compression rate can vary to different bite rate according to strides setting. For multi-channel time series, it can compress data into average 10% with an acceptable reconstruction result. By reducing part of coding index, it is able to reconstruct part of curve with its main distribution. LSCodec can achieve a relatively good result in downstream task for a dataset that contains high ratio of anomaly. The proposed method can restore data distribution without losing its abnormal part. Several comparative studies are performed on with or without manually guided. The result shows the effectiveness of data guiding strategy. Code and models are available at https://github.com/HaiweiZuo/LSCodec.
Haiwei Zuo, Jinhe Wu, King Hann Lim, Yinping Liao, Luping Song, Zhenjun Li
Appl. Intell.2
2025 Fine-Grained and Class-Incremental Malicious Account Detection in Ethereum via Dynamic Graph Learning
abstract
Ethereum serves as the cornerstone for value transfer in Web 3.0, providing a decentralized and efficient trust mechanism for global connectivity. However, the anonymity of Ethereum undermines market regulatory capabilities, leading to frequent malicious behaviors such as Ponzi Scheme, Money Laundering, and Phishing. Therefore, in the face of the diverse and continuously emerging malicious behaviors, implementing fine-grained detection is crucial for maintaining the prosperous development of the blockchain ecosystem. In this paper, we propose FiMAD, a fine-grained and class-incremental malicious account detection framework based on dynamic graph learning. Specifically, we first propose a general graph structure calledDynamic Account Relation Graph (DARG), which dynamically models Ethereum accounts from a continuous-time perspective. Then, we design a cascade graph feature extraction method to capture deep temporal evolution patterns and neighbor interaction features in DARG. Next, we construct a pre-training universal encoder to transform account features into high-dimensional embeddings, followed by fine-tuning the model classifier with a few labeled samples, enabling accurate fine-grained detection and rapid updates for incremental classes. We conduct extensive experiments using real Ethereum data. The results demonstrate that FiMAD outperforms state-of-the-art (SOTA) methods in fine-grained detection across five typical scenarios: class-incremental, full data, new malicious accounts, imbalanced data, and binary classification. In the class-incremental scenario, FiMAD improves the Macro-F1 by up to 26.4% compared to SOTA methods.
Hanbiao Du, Meng Shen 0001, Yang Liu 0171, Zheng Che, Jinhe Wu, Wei Wang 0012, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.5
2025 Robust Detection of Malicious Encrypted Traffic via Contrastive Learning
abstract
Traffic encryption is widely used to protect communication privacy but is increasingly exploited by attackers to conceal malicious activities. Existing malicious encrypted traffic detection methods rely on large amounts of labeled samples for training, limiting their ability to quickly respond to new attacks. These methods also are vulnerable to traffic obfuscation strategies, such as injecting dummy packets. In this paper, we proposeSmartDetector, a robust malicious encrypted traffic detection method via contrastive learning. We first propose a novel traffic representation named Semantic Attribute Matrix (SAM), which can effectively distinguish between malicious and benign traffic. We also design a data augmentation method to generate diverse traffic samples, which makes the detection model more robust against different traffic obfuscation strategies. We propose a malicious encrypted traffic classifier that first pre-trains a model via contrastive learning to learn deep representations from unlabeled data, then fine-tunes the model with a supervised classifier to achieve accurate detection even with only a few labeled samples. We conduct extensive experiments with five public datasets to evaluate the performance of SmartDetector. The results demonstrate that it outperforms the state-of-the-art (SOTA) methods in three typical scenarios. Specifically, in the evasion attack detection scenario, SmartDetector achieves an F1 score and AUC above 93%, with average improvements of 19.84% and 18.17% over the SOTA method, respectively.
Meng Shen 0001, Jinhe Wu, Ke Ye, Ke Xu 0002, Gang Xiong 0001, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.2
2024 Encrypted Malware Traffic Detection Via Time-Frequency Domain Analysis
Jizhe Jia, Jinhe Wu, Junyu Ai, Meng Shen 0001, Liehuang Zhu
ICA3PP (5)3
2024 Towards Lightweight User Identification of Anonymous Cryptocurrency Wallet via Encrypted Traffic Correlation
abstract
With the widespread use of cryptocurrencies and the development of anonymity network technology, how to effectively identify cryptocurrency transactions through anonymity networks such as Tor has become a major challenge in cybersecurity. We introduce a new traffic correlation technique, TSMCorr, aimed at identifying cryptocurrency transactions through anonymous networks like Tor. Traditional traffic correlation methods struggle with the high cost of deployment, while we leverage advanced feature engineering and deep learning, including a Traffic Volume Matrix (TSM), to develop a more accurate and efficient flow correlation model. TSMCorr not only improves upon existing methods in terms of F1 score by $15.5 \%$ on DeepCoFFEA dataset, but also lowers the computational time by $89 \%$, RAM consumption by $77.4 \%$, and model parameters by $11.5 \%$.
Jizhe Jia, Jinhe Wu, Meng Shen 0001, Liehuang Zhu
ICPADS3
2024 Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization
abstract
Website Fingerprinting (WF) attacks significantly threaten user privacy in anonymity networks such as Tor. While numerous defenses have been proposed, they are unable to efficiently defend against recent deep learning based WF attacks. In this paper, we propose Palette, a novel and practical WF defense that utilizes traffic cluster anonymization to protect live Tor traffic. By clustering websites with high similarity in traffic patterns and regulating them into a well-designed uniform pattern for a cluster (i.e., a group of similar websites), Palette prevents attackers from distinguishing between these similar websites within the cluster and further provides a strong anonymity guarantee. Comprehensive evaluations with public real-world datasets show that Palette is superior to the existing defenses, greatly reducing the accuracy of the state-of-the-art (SOTA) WF attacks with acceptable overheads. Furthermore, we implement Palette as a Pluggable Transport in the Tor network. The experiment results demonstrate that, on average, Palette effectively reduces the accuracy of the SOTA WF attacks by 73.60%, which improves the existing defenses by 33.50%-43.47%.
Meng Shen 0001, Kexin Ji, Jinhe Wu, Qi Li 0002, Ke Xu 0002, Liehuang Zhu
SP3