Weiqing Huang

dblp:42/3576 · DBLP profile ↗
← Back
117ranked-venue papers
19as first author
83since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 46 · 10 first-author · 33 since 2021Artificial intelligence and machine learning · 28 · 5 first-author · 16 since 2021Security and privacy · 19 · 3 first-author · 14 since 2021Databases, data management, data science and information retrieval · 13 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 6 since 2021Human-computer interaction and ubiquitous computing · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 The Digital Dunning-Kruger Effect: Decoupling Hallucinations via Geometric Hidden-state Observation for Semantic Truthfulness
abstract
Yueheng Mao, Min Yu, Gengwang Li, Jianguo Jiang, Gang Li, Meng Zhang, Zhen Xu, Weiqing Huang, Ming Liu. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Yueheng Mao, Min Yu 0001, Gengwang Li, Gang Li 0009, Meng Zhang 0020, Weiqing Huang, Ming Liu 0003
ACL (1)8
2026 Thinking in High-Frequency: Practical Defense for Deepfake Detectors Against Black-box Adversarial Attacks
abstract
Deepfake detectors have demonstrated vulnerability when faced with adversarial attacks. In real-world scenarios, attackers can generate adversarial examples that mislead detectors through query-based black-box attack methods. Recently, several defense methods against query-based adversarial attacks have achieved promising performance. However, their effectiveness significantly declines when applied to deepfake detection tasks. In this work, we propose a novel defense method specifically designed to counter adversarial attacks in deepfake detection scenarios. Unlike existing approaches, our method focuses on the high-frequency components of images to uncover subtle traces left by adversarial perturbations. Specifically, we analyze the high-frequency residual between similar images within the queries to detect adversarial examples. We evaluate our method against three advanced black-box attack strategies. Extensive experiments demonstrate that our approach achieves highly effective attack detection while significantly reducing FPR.
Fuqiang Du, Min Yu 0001, Yachao Liang, Meng Zhang 0020, Weiqing Huang
ICMR7
2026 FPFA: Flexible Polarization Fingerprint Authentication Framework for Large-Scale Devices
Jinlong Xu, Weiqing Huang
SECON4
2026 A Spatio-Temporal Bayesian Graph Neural Network for Proactive Anomaly Prediction in Dynamic Wireless Networks
Xiaoyu Kang, Weiqing Huang, Zhixin Shi
WCNC3
2026 Heterogeneous data-driven resolution generation for software systems via large language models
Degang Sun, Haitian Yang, Weiqing Huang
Inf. Process. Manag.5
2026 Manod: A multi-modal anomaly detection framework for distributed system
Degang Sun, Haitian Yang, Weiqing Huang
Neural Networks5
2025 DFilter: A Network Access Layer Collaborative Defense Model for Moving Target Defense
abstract
Due to the inherent properties of IT networks, such as the determinacy of network composition, the statics of network structure, and the homogeneity of network elements, network defense is always in a passive position in cyberattack-defense con-frontations. In response, cybersecurity researchers have proposed using Moving Target Defense technology to reverse it. However, in practical application scenarios, while Moving Target Defense demonstrates its defensive value, it also introduces several issues such as increased network complexity, limited processing performance due to restricted by network protocol stack, and inherent limitations of related technologies themselves. This article constructs a network access layer collaborative defense model, DFilter based on XDP-eBPF. The policy preprocessing layer implements the O(1) time complexity network traffic filtering and matching algorithm, and further refines the control strength of the state-of-the-art algorithm based on security labels. On this basis, the multi-dimensional and fine-grained collaborative defense methods proposed by the policy disposal layer, enriching the diversity of model defense capabilities. Based on the model and algorithm proposed in this article, an experimental topology environment was constructed and comprehensive experimental evaluation were completed. The experimental results showed that DFilter effectively improved the preprocessing efficiency of network access layer traffic, further refined the control strength and significantly enhanced the variability of the network traffic.
Degang Sun, Xinbo Han, Weiqing Huang
CSCWD6
2025 VN-GT: Optimizing Virtual Network Deployment via Game Theory
abstract
The static and homogeneous nature of traditional networks presents a significant challenge for our defense efforts. These characteristics enable an experienced attacker to quickly determine our network topology and gather detailed information about the internal hosts through systematic scanning techniques. Implementing a virtual network view can mitigate this by simulating a virtual topology, thereby consuming the attacker’s resources and time. However, deploying a virtual network view reduces network throughput and increase latency. Additionally, an improperly configured virtual network view can waste resources and degrade Quality of Service (QoS). Most existing studies have focused solely on the defender’s perspective, resulting in overly idealistic solutions that are ineffective in real-world scenarios. To address this, we propose VN-GT, a game-theoretic based model that optimizes virtual network deployment by considering both attackers and defenders. We provide a detailed example scenario, analyze the game’s equilibrium, and validate the effectiveness of our method through a real attack and defense experiment.
Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Zuxin Chen, Siyuan Li 0014, Min Yu 0001, Weiqing Huang, Degang Sun
ICASSP7
2025 Data-Driven Random Feature Selection for Deep Kernel Learning with Kernel Alignment
Xiaoyu Kang, Weiqing Huang, Chonghui Zheng
ICIC (18)3
2025 ML-MultiLoc: Device-Free Passive Multi-target Indoor Localization Using Multi-label Learning
Zhiliang Yang, Weiqing Huang, Siye Wang
ICIC (17)2
2025 UPEA: A Novel BGP Convergence Verification Algorithm with Zero False Positives and Minimal False Negatives
abstract
The Border Gateway Protocol (BGP) is the core routing protocol for inter-domain routing, providing substantial flexibility but lacking convergence guarantees, which can lead to network oscillations and instability. Despite prior research proposing various methods to address these issues, existing algorithms still fall short in terms of accuracy and efficiency.In this paper, we introduce a novel and efficient algorithm that statically analyzes BGP configurations to accurately determine routing convergence. Our algorithm achieves several major advancements:•Superior Accuracy: It outperforms the state-of-the-art algorithm by correctly identifying a broader range of configurations.•Scalability: It is highly efficient, capable of analyzing Internet-scale configurations within polynomial time complexity.•Reliability: It eliminates false positives, ensuring that potentially oscillating configurations are never incorrectly reported as convergence.Our experimental results demonstrate that the proposed algorithm significantly enhances accuracy and efficiency compared to existing methods, making it highly suitable for large-scale Internet applications. This work represents a substantial step forward in ensuring the stability and reliability of BGP routing, addressing critical challenges in modern Internet infrastructure.
Wenwu Yan, Weiqing Huang, Xiaobin Tian, Dong Wei 0002
ICNP3
2025 Multi-Modal Fake News Detection with LLMs and Knowledge-Aligned Attention Networks
abstract
With the booming rise of the Internet and social media, semantically rich multimodal data has gradually become the mainstream carrier of news dissemination. Among them, multi-modal fake news with illustrations and text has attracted widespread attention due to its greater deceptiveness. However, existing research methods are mainly limited to the analysis of images and text within the news itself, failing to fully consider the consistency and discrepancy characteristics between different modalities, which hinders the full exploitation of the advantages of multi-modal fusion. To address this issue, this study proposes a multi-modal fake news detection method with large language models(LLMs) and Knowledge-Aligned Attention Networks(MFDnet). This method first leverages the powerful semantic understanding capabilities of large language models to generate detailed text descriptions for images, serving as a knowledge supplement for the image model. Subsequently, by constructing a Knowledge-Aligned Attention Networks, it achieves efficient semantic fusion between the knowledge-supplemented image model and text modal information, thereby effectively extracting the consistency and complementary features between different modalities. Experimental results demonstrate that this model exhibits excellent performance on multiple public fake news detection datasets.
Degang Sun, Yan Wang 0081, Xuan Zhao 0011, Haitian Yang, Weiqing Huang
ISCC6
2025 Denoising Trajectory Biases for Zero-Shot AI-Generated Image Detection
abstract
The rapid advancement of generative models has led to the widespread emergence of highly realistic synthetic images, making the detection of AI-generated content increasingly critical. In particular, diffusion models have recently achieved unprecedented levels of visual fidelity, further raising concerns. While most existing approaches rely on supervised learning, zero-shot detection methods have attracted growing interest due to their ability to bypass data collection and maintenance. Nevertheless, the performance of current zero-shot methods remains limited. In this paper, we introduce a novel zero-shot AI-generated image detection method. Unlike previous works that primarily focus on identifying artifacts in the final generated images, our work explores features within the image generation process that can be leveraged for detection. Specifically, we simulate the image sampling process via diffusion-based inversion and observe that the denoising outputs of generated images converge to the target image more rapidly than those of real images. Inspired by this observation, we compute the similarity between the original image and the outputs along the denoising trajectory, which is then used as an indicator of image authenticity.Since our method requires no training on any generated images, it avoids overfitting to specific generative models or dataset biases. Experiments across a wide range of generators demonstrate that our method achieves significant improvements over state-of-the-art supervised and zero-shot counterparts.
Yachao Liang, Min Yu 0001, Gang Li 0009, Fuqiang Du, Jingyuan Li 0002, Lanchi Xie, Weiqing Huang
NeurIPS9
2025 Device Identification Based on Artificial Polarization Fingerprint Injection
abstract
Polarization fingerprint (PF) is a promising technique for low-cost Internet of Things (IoT) device identification, which has better performance compared to radio frequency fingerprint (RFF). However, due to the manufacturing technology improvement, PF and RFF suffer from critical drawbacks, especially the reduction in fingerprint differences among devices. To solve this problem, we propose an artificial polarization fingerprint injection (APFI) scheme based on convenient antenna surface slotting. First, we find slotting can produce frequencydependent variation in polarization, which increases the fingerprint difference. Subsequently, we proposed the polarization frequency gradient matrix as a classification feature, based on the characteristics of the injected fingerprints, which eliminates the spatial instability of the original PFs. Extensive simulations and experiments demonstrate that APFI improves the device capability more than 7 times compared with the original PFs under 99.5% identification accuracy.
Jinlong Xu, Dong Wei 0002, Weiqing Huang
WCNC4
2025 Spectrum Painting for On-Device Signal Classification
abstract
Achieving accurate and low-latency spectrum sensing on resource-constrained devices is essential but very difficult. Traditional In-phase and Quadrature (I/Q)-based and the ShortTime Fourier Transform (STFT)-based methods fail to balance the computational overhead and classification accuracy. In this paper, we propose a novel framework –Spectrum Painting (SP)– which enables on-device signal classification with low latency and high accuracy. We design new signal processing methods to compress spectrograms while keeping global signal features and augmenting the salient features of small objects. SP achieves high-accuracy signal classification, assisted further by our proposed Dual-channel Convolutional Neural Network (DualCNN). We collect diverse datasets to evaluate the proposed SP, including synthesized data, and testbed data (from up to 18 commodity devices) obtained from real-world environments in the wild and office settings. Experimental results of SP running on Raspberry Pi 4B show a great reduction in latency up to $20 \times$ while maintaining a 95% accuracy. Furthermore, SP demonstrates superior performance within both the centralized learning architecture and the Federated Learning (FL) architecture. For example, the challenging cross-environment evaluation of the SP in the iid-FL scenario yields a substantial accuracy improvement, on average from 24.6% to 83.8%.
Weiqing Huang, Wen Wang 0014, Qing Wang 0007
WoWMoM2
2025 A systematic survey on physical layer security oriented to reconfigurable intelligent surface empowered 6G
Shunliang Zhang, Weiqing Huang, Yinlong Liu
Comput. Secur.2
2025 SPPsolver: a SAT-based algorithm for solving any stable paths problem correctly
abstract
Abstract The Stable Paths Problem (SPP) is a widely adopted model for analyzing the convergence of Border Gateway Protocol (BGP). Solving SPP correctly is of great significance for determining BGP convergence. Existing studies have proposed some SPP solving algorithms that can only solve a part of SPP instances and have limited capabilities. To fill this gap, in this paper we transform SPP into Boolean Satisfiability Problem (SAT) and propose a new SPP solving algorithm called SPPsolver , which can support the solution of any SPP instance. We use Binary Decision Diagrams (BDD) to encode and calculate the SAT formula and apply two optimization methods to accelerate SPPsolver . We use real-world datasets to perform experiments and compare with state-of-the-art algorithms, the results demonstrate the superiority and efficiency of SPPsolver .
Wenwu Yan, Weiqing Huang, Xiaobin Tian
Cybersecur.3
2025 Passive Multi-User Traffic Analysis Based on 5G NR/LTE Physical Layer
abstract
Information leakage through wireless channels poses a significant security concern within contemporary cellular networks, such as 5G new radio (NR). Among the myriad of potential attack vectors, passive traffic analysis (PTA) stands out as a pervasive and surreptitious threat, which allows attackers to discern the specific services utilized by unsuspecting victims without their noticing. In this work, we present a pioneering approach to achieve fine-grained service identification by adopting an unexplored perspective: mapping traffic transmission patterns to physical layer time-frequency occupancy patterns, which we refer to as Passive Time-Frequency Traffic (PTTF). Additionally, it selects the uplink control channel that carries the acknowledgment/negative acknowledgment (ACK/NACK) feedback within the Hybrid Automatic Repeat reQuest (HARQ) process as the data source. Statistical features of ACK/NACK time-frequency resources are extracted for traffic classification, and activities are recognized from a three-tier classification algorithm. For validation, we conduct field experiments targeting commercialized smartphones within the real-world operator’s network. This setup effectively mirrors practical scenarios, as the resources within the target frequency band can also be allocated to other equipment in the operator’s network. Furthermore, cross-validation experiments involving different smartphone brands and various network formats are conducted in order to ascertain the generalizability of the proposed PTTF.
Dong Wei 0002, Nan Jiang 0004, Meng Zhang 0020, Xiang Meng 0008, Yang Yang 0057, Weiqing Huang
IEEE Trans. Inf. Forensics Secur.7
2024 RP-Fusion: Robust RFID Indoor Localization Via Fusion RSSI and Phase Fingerprint
abstract
With the rapid development of the Internet of Things (IoT), indoor localization has become a critical component of numerous applications. Among them, non-contact indoor localization techniques based on Radio Frequency Identification (RFID) fingerprints have garnered significant attention. However, due to the complexity of indoor environments, existing methods achieve satisfactory localization performance on training data, but still face challenges in accurately recognizing the locations of individuals who were not part of the training data. To address these challenges, we propose the RP-Fusion. In our work, we construct a two-stream fusion network to extract fused fingerprint features from both Received Signal Strength Indication (RSSI) and phase. These fused fingerprint features can better map to location characteristics, reduce the impact of individual differences. Experimental results demonstrate the effectiveness of our method in achieving robust localization for untrained individuals, with the accuracy of 99.23%. This outperforms the majority of existing RF fingerprint-based indoor localization results.
Siye Wang, Yue Feng 0001, Weiqing Huang
CSCWD4
2024 MLNT: A Multi-Level Network Traps Deployment Method
abstract
Traditional honeypot technology combines trap deployment component with attack deception response component, and the more network traps are deployed, the more system resources, such as virtual machines and containers, are required. To alleviate this problem, we propose a transparent network deception defense method called MLNT. MLNT decouples the trap deployment component and attack deception response component, reducing the dependence of high-density traps on system resources. First, MLNT can complete multi-layer network trap deployment, including trap service ports of real assets, network node traps of security domains, and security domain traps. Second, MLNT can transparently deploy network traps on real protection targets. It protects valuable assets in Industrial Control Networks and the Internet of Things, where software agents can not be installed. Finally, we implemented the MLNT framework using FPGA and tested it’s capability of delaying the attackers’ progress. The experimental results demonstrate the effectiveness and feasibility of MLNT.
Guokun Xu, Weijie Wang 0005, Degang Sun, Yanpeng Ma, Yan Wang 0081, Weiqing Huang
CSCWD6
2024 GLIMMER: Incorporating Graph and Lexical Features in Unsupervised Multi-Document Summarization
abstract
Pre-trained language models are increasingly being used in multi-document summarization tasks. However, these models need large-scale corpora for pre-training and are domain-dependent. Other non-neural unsupervised summarization approaches mostly rely on key sentence extraction, which can lead to information loss. To address these challenges, we propose a lightweight yet effective unsupervised approach called GLIMMER: a Graph and LexIcal features based unsupervised Multi-docuMEnt summaRization approach. It first constructs a sentence graph from the source documents, then automatically identifies semantic clusters by mining low-level features from raw texts, thereby improving intra-cluster correlation and the fluency of generated sentences. Finally, it summarizes clusters into natural sentences. Experiments conducted on Multi-News, Multi-XScience and DUC-2004 demonstrate that our approach outperforms existing unsupervised approaches. Furthermore, it surpasses state-of-the-art pre-trained multi-document summarization models (e.g. PEGASUS and PRIMERA) under zero-shot settings in terms of ROUGE scores. Additionally, human evaluations indicate that summaries generated by GLIMMER achieve high readability and informativeness scores. Our code is available at https://github.com/Oswald1997/GLIMMER.
Ran Liu 0011, Ming Liu 0003, Min Yu 0001, Gang Li 0009, Jingyuan Li 0002, Weiqing Huang
ECAI9
2024 HOICS: Zero-Shot Hoi Detection via Compatibility Self-Learning
abstract
In recent years, the computer vision community has increasingly focused on detecting and recognizing human-object interactions (HOIs), which are crucial for tasks such as action recognition and scene understanding. However, the imbalanced distribution of interaction categories presents challenges, especially in scenarios with limited data. To address this issue, we propose an innovative end-to-end parallel HOI detection framework that incorporates compatibility self-learning (HOICS) for zero-shot HOI detection. Specifically, our approach introduces a compatibility self-learning strategy that allows the model to extract insights from HOI compatibility data and refine the interaction prediction head. This method involves utilizing combination probabilities and compatibility scores during the self-learning process, which significantly enhances zero-shot detection performance. Additionally, HOICS employs mosaic augmentation to broaden the model’s capabilities. Our extensive experiments on benchmark datasets demonstrate HOICS’ superiority over state-of-the-art methods, achieving a noteworthy 2.16 percent improvement in zero-shot HOI detection for previously unseen categories.
Junxing Ren, Weiqing Huang
ICASSP4
2024 Manticore: An Unsupervised Intrusion Detection System Based on Contrastive Learning in 5G Networks
abstract
The increasing complexity and openness of 5G networks naturally enlarge the attack surface and introduce new vulnerabilities, thereby posing challenges to the performance of existing intrusion detection systems (IDSs). Current IDSs solely rely on statistical features, which may suffer from low accuracy due to the complex traffic patterns in 5G networks. Additionally, recent IDSs apply contrastive learning to improve detection capabilities, but the reliance on costly manual labeling hinders the adaptability to complex attacks in 5G networks.In this paper, we present Manticore, an unsupervised intrusion detection system based on contrastive learning for 5G networks. Specifically, Manticore leverages both statistical features and original features of packets to capture the holistic information of traffic in 5G networks. Moreover, it automatically establishes positive and negative pairs without manual labeling. We further explore the combination patterns between reconstruction loss and contrastive loss to attain a more precise model. Our experimental evaluation of two datasets demonstrates the proposed Manticore outperforms the relevant state-of-the-art methods.
Jiyan Sun, Shangyuan Zhuang, Yinlong Liu, Liru Geng, Peizhe Xin, Weiqing Huang
ICASSP8
2024 SecureSem: Sensitive Text Classification Based on Semantic Feature Optimization
Kangyuan Qin, Ran Liu 0011, Min Yu 0001, Gang Li 0009, Mingqi Liu, Jingyuan Li 0002, Weiqing Huang
ICDF2C (1)7
2024 Assessing Backdoor Risk in Deepfake Detection
Boquan Li 0002, Min Yu 0001, Kam-Pui Chow, Fuqiang Du, Weiqing Huang
IFIP Int. Conf. Digital Forensics8
2024 LONGAN: Detecting Lateral Movement based on Heterogeneous Graph Neural Networks with Temporal Features
abstract
Lateral movement (LM) plays a pivotal role in Advanced Persistent Threats (APTs), constituting a significant cybersecurity concern. Recent graph-based LM detection methods have demonstrated satisfactory performance by harnessing the potent representation capabilities of graph learning techniques. However, the evolving nature and increasing sophistication of LMs necessitate novel defensive strategies to thwart these attacks. In this paper, we introduce LONGAN, an innovative LM detection system leveraging heterogeneous graph neural networks incorporating temporal features to tackle this challenge. Specifically, we first introduce a formalized heterogeneous graph encompassing various network entities to model the intricate LM scenario. Subsequently, to capture LM dynamics, we employ a heterogeneous temporal graph to model LM evolution by integrating heterogeneous spatial information across temporal dimensions. Building upon this foundation, we devise HSTA, a framework for heterogeneous temporal graph learning, to aggregate both spatial and temporal features for LM detection. In the HSTA, we devise a heterogeneous spatial aggregation module to learn representations for diverse entity types and relations; we design a temporal aggregation module to consolidate historical node sequences into their representations. These modules synergistically operate to identify LMs. Evaluation on public datasets demonstrates that our LONGAN achieves superior performance (98.09% AUC and 96.56% F1-score) compared to state-of-the-art approaches.
Yangyang Zong, Zhixin Shi, Weiqing Huang
ISCC3
2024 RF-AcSense: Device-Free Activity Localization and Recognition via Passive RFID Tag Array
abstract
Position and behavior are indispensable as indicators of a human’s state, which in turn is the basis of various intelligent scenarios, e.g., smart home, smart city. Most of the pioneer systems focus unilaterally on the meticulous level of localization or the accuracy of activity recognition. In this paper, we build a real-time framework RF-AcSense that can identify both location and activity of the human in a passive and flexible way, which completes the perception by the changes of surrounding signals induced by the human. Specifically, through the Radio-Frequency IDentification (RFID) based context-aware smart space, two radio images can be acquired separately for the ground plane and the tag array plane, which are subsequently used for upper-lower layer combined localization and upper-lower limb separated activity recognition. In particular, a 3D-convolution based deep learning network is designed to capture the comprehensive deep features from time-sequence radio images, and pruning operation is supplemented to further improve the classification accuracy and the processing speed of the system. We implement RF-AcSense with COTS RFID devices, and the experimental results demonstrate the superiority of RF-AcSense on both localization and activity recognition.
Shaoyi Zhu, Hanfei Lv, Weiqing Huang
LCN3
2024 SpeechForensics: Audio-Visual Speech Representation Learning for Face Forgery Detection
abstract
Detection of face forgery videos remains a formidable challenge in the field of digital forensics, especially the generalization to unseen datasets and common perturbations. In this paper, we tackle this issue by leveraging the synergy between audio and visual speech elements, embarking on a novel approach through audio-visual speech representation learning. Our work is motivated by the finding that audio signals, enriched with speech content, can provide precise information effectively reflecting facial movements. To this end, we first learn precise audio-visual speech representations on real videos via a self-supervised masked prediction task, which encodes both local and global semantic information simultaneously. Then, the derived model is directly transferred to the forgery detection task. Extensive experiments demonstrate that our method outperforms the state-of-the-art methods in terms of cross-dataset generalization and robustness, without the participation of any fake video in model training.
Yachao Liang, Min Yu 0001, Gang Li 0009, Boquan Li 0002, Weiqing Huang
NeurIPS9
2024 Autocue : Targeted Textual Adversarial Attacks with Adversarial Prompts
Haitian Yang, Yan Wang 0081, Weiqing Huang
WASA (3)5
2024 DE-GNN: Dual embedding with graph neural network for fine-grained encrypted traffic classification
Xinbo Han, Guizhong Xu, Meng Zhang 0020, Weiqing Huang
Comput. Networks6
2024 DSGN: Log-based anomaly diagnosis with dynamic semantic gate networks
Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang
Inf. Sci.4
2024 DualAttlog: Context aware dual attention networks for log-based anomaly detection
Haitian Yang, Degang Sun, Weiqing Huang
Neural Networks3
2023 TransRF: Towards a Generalized and Cross-Domain RFID Sensing System Using Few-Shot Learning
abstract
RFID-based human activity recognition has attracted extensive attention due to its low cost, non-invasiveness, and privacy protection. However, existing methods may limit cross-domain sensing as the mapping between activities and signals is destroyed when the environment changes. Meanwhile, these methods lack generalization as their systems need to be fully retrained whenever new activities are added, which incurs data collection and retraining overheads. This paper proposes a few-shot learning-based RFID sensing system, TransRF, composed of a signal processing module, a feature extraction module, and a classification module. Specifically, to recognize novel classes in unknown domains with limited samples, the feature extraction module consists of multi-head self-attention and multi-scale hybrid dilated convolution and pre-train it with source domain data. Therefore, when the system is applied to the target domain, a few samples are required to fine-tune the classification module for domain adaptation. Experimental results on the genuine RFID dataset show that TransRF achieves an accuracy of 98.0% in unknown domains, a 31.4% improvement over the state-of-the-art. Additionally, we published our dataset containing three scenarios with 1.728 million pieces of data.
Weiqing Huang, Siye Wang
CSCWD2
2023 ACG: Attack Classification on Encrypted Network Traffic using Graph Convolution Attention Networks
abstract
Attack classification of network traffic is valuable for many security solutions as it points out a clear direction for attack responses. Nowadays, most network traffic is encrypted, which protects user privacy but hides attack traces, further hindering identifying attacks to inspect traffic packages. Machine Learning(ML) methods are widely applied to attack classification on encrypted traffic owing to no need for manual analysis. However, existing studies only concentrate on basic statistical features, which are easily modified, and cannot obtain the crucial attack behaviors hiding in the encrypted traffic. In this paper, we propose an attack classification method, ACG. We create attack graphs to depict interaction behaviors of attack-victim hosts from network traffic containing crucial attack behaviors. Besides, we divide a specific duration for each attack to precisely elaborate attack graphs, where temporal, statistical, and aggregate features are extracted to portray attack behaviors. Finally, we utilize Graph Neural Networks (GNNs) to mine and grasp the crucial behavior patterns from attack graphs to generate fingerprints and classify attacks. Extensive experiments are conducted on three datasets to verify our method. It achieves a precision of 99% in attack classification on encrypted traffic, an average higher than other ML methods of 50%.
Leiqi Wang, Qiujian Lv, Yan Wang 0081, Shixiang Zhang, Weiqing Huang
CSCWD6
2023 Prompt Makes mask Language Models Better Adversarial Attackers
abstract
Generating high-quality synonymous perturbations is a core challenge for textual adversarial tasks. However, candidates generated from the masked language model often contain many words that are antonyms or irrelevant to the original words, which limit the perturbation space and affect the attack’s effectiveness. We present ProAttacker1which uses Prompt to make the mask language models better adversarial Attackers. ProAttacker inverts the prompt paradigm by leveraging the prompt with the class label to guide the language model to generate more semantically-consistent perturbations. We present a systematic evaluation to analyze the attack performance on 6 NLP datasets, covering text classification and inference. Our experiments demonstrate that ProAttacker outperforms state-of-the-art attack strategies in both success rate and perturb rate.
Haitian Yang, Yan Wang 0081, Weiqing Huang
ICASSP5
2023 ASGNet: Adaptive Semantic Gate Networks for Log-Based Anomaly Diagnosis
Haitian Yang, Degang Sun, Yanshu Li, Yan Wang 0081, Weiqing Huang
ICONIP (4)6
2023 UDA-HOID: Unsupervised Domain Adaptation for Human-Object Interaction Detection
abstract
Human-object interaction (HOI) detection has witnessed remarkable advancements in recent years, primarily driven by deep learning networks and the availability of large-scale HOI datasets. However, there are still scenarios where HOI detection lacks a suitable training database. The process of expanding existing datasets by manually annotating more images can be challenging because it is time-consuming and labor-intensive. In response to this challenge, domain adaptation has emerged as a promising approach to address the scarcity of annotated data. Drawing inspiration from this, we propose an innovative unsupervised adaptive approach for HOI detection called UDA-HOID. Our method aims to adapt HOI detection from a label-rich source domain to a label-poor target domain, thereby reducing annotation costs and enhancing detection performance. Specifically, UDA-HOID leverages attention-based full alignment for low-level features, which tackles domain shifts caused by image style, illumination, and other factors. Additionally, semantic-based weak alignment is applied to high-level features, as domain shifts in these features contain more semantic information. Adversarial learning techniques are employed to facilitate this alignment process. To evaluate the effectiveness of our proposed method, we conduct experiments on the test data of the low-light HOI image set (LLHOI). The results demonstrate that our approach achieves a relative improvement of 9.8 percent in the mean average precision of roles compared to existing methods.
Weiqing Huang, Bo Meng 0006, Junxing Ren, Ruwen Bai, Yang Yang 0087
ICTAI2
2023 A Dynamic Malicious Document Detection Method Based on Multi-Memory Features
Gengwang Li, Min Yu 0001, Kam-Pui Chow, Weiqing Huang
IFIP Int. Conf. Digital Forensics7
2023 AdaptParse: Adaptive Contextual Aware Attention Network for Log Parsing via Word Classification
abstract
Logs are widely used during the development and maintenance of software systems. Logs assist developers and operation & maintenance personnel to understand the state and behavior of systems at runtime. Also, logs can diagnose system failures and conduct abnormal analyses to provide further protection to the security of systems. However, large software systems generate large amounts of semi-structured logging routinely. The first step to support further analysis is how to parse semi-structured records with free-form text log messages into structured templates. Therefore, log parsing is rather challenging. Because logs are generated by static templates (i.e., log statements) in the source code, templates are often not accessible when parsing logs. It is worth noting that most proposed approaches still rely on log-specific heuristics or manual rule extraction. Those existed methods are often specialized for parsing certain log types and often neglect the semantic meaning of log messages, thus limiting performance scores and generalization, hence, in this paper, we propose a new parsing technique - Adaptive Contextual Aware Attention Network for Log Parsing via Word Classification, named AdaptParse. Adapt-Parse transforms the template generation problem into a word classification task, then learns the features of template words and variable words. We evaluate our AdaptParse on 5 realworld log datasets and compare the performance with 7 parsing techniques. Our experimental results show that the proposed approach can effectively understand the semantic meaning of log messages and achieve accurate log parsing results. Overall, AdaptParse achieves state-of-the-art performance on five realworld log datasets, outperforming all the baseline models.
Haitian Yang, Degang Sun, Yan Wang 0081, Shixiang Zhang, Weiqing Huang
IJCNN6
2023 MESCAL: Malicious Login Detection Based on Heterogeneous Graph Embedding with Supervised Contrastive Learning
abstract
Malicious logins via stolen credentials have become a primary threat in cybersecurity due to their stealthy nature. Recent malicious login detection methods based on graph learning techniques have made progress due to their ability to capture interconnected relationships among log entries. However, limited malicious samples pose a critical challenge to the detection performance of existing methods. In this paper, we propose MESCAL, a novel approach based on heterogeneous graph embedding with supervised contrastive learning to solve this challenge. Concretely, we construct authentication heterogeneous graphs to represent multiple and interconnected log events. Then, we pretrain a feature extractor with supervised contrastive learning to capture rich semantics on the graphs from limited malicious samples. Based on this, cost-sensitive learning is adopted to distinguish malicious logins on imbalanced data. Extensive evaluations show that the F1 score of MESCAL based on the imbalance dataset is 94.63%, which outperforms state-of-the-art approaches.
Weiqing Huang, Yangyang Zong, Zhixin Shi, Puzhuo Liu
ISCC1
2023 FindSpy: A Wireless Camera Detection System Based on Pre-Trained Transformers
abstract
The wireless cameras have become a major concern in cybersecurity due to privacy breaches. Recent flow based methods for wireless cameras detection have achieved promising results. However, these methods require specialized equipment for deployment and massive labeled data for training, which makes them impractical in real-world scenarios. In this paper, we propose FindSpy, a lightweight wireless camera detection method based on Pre-trained Transformers to address the challenge. By utilizing the air interface technique, FindSpy can obtain data without connecting to the wireless network where the camera is located. Additionally, FindSpy learns air interface WiFi traffic representation by pre-training a traffic representation model from large-scale unlabeled data and fine-tuning it on few labeled data. FindSpy can accurately detect wireless cameras with CNN-LSTM classifier. Extensive experiments show that FindSpy outperforms the state-of-the-art methods on few data. Concretely, FindSpy achieves a detection accuracy of over 98% by analyzing just five data packets.
Zhixin Shi, Weiqing Huang
ISCC5
2023 An Interference Mitigation Strategy for LEO Satellite Systems based on Adaptive Beamforming with Sidelobe Suppression
abstract
In this paper, we propose an interference mitigation strategy for low Earth orbit (LEO) satellite systems based on adaptive beamforming that incorporates both sidelobe level (SLL) control and dynamic adaptation to reduce co-frequency interference by analyzing the real-time positions of interfering satellites and serving satellite relative to the user terminal. In this study, we consider a uniform rectangular array (URA) as the user terminal antenna configuration in the LEO satellite system. The adaptive beamforming technique based on the Taylor weighting algorithm is applied for sidelobe suppression by generating a beam pattern with the desired SLL. The real-time positions of interfering satellites and serving satellite relative to the user terminal are computed by solving the orbital parameters. Based on real-time position information, the adaptive beamforming technique is utilized to dynamically adjust the beam pattern and generate an appropriate SLL, thereby minimizing the impact of co-frequency interference to its maximum extent. The simulation results demonstrate that the proposed strategy achieves a user terminal received carrier-to-interference ratio (C/I) exceeding 27dB for 95% of the simulation time, representing a significant improvement of 47.5% compared to conventional methods. Moreover, the upper limit of C/I has also significantly escalated from 40dB to 80dB. These findings strongly validate the effectiveness of the proposed strategy in mitigating interference and enhancing overall system performance.
Huadong Guo, Weiqing Huang, Wen Wang 0014, Jinglong Guo, Zhaohua Qiu
MSN2
2023 DTrap: A cyberattack-defense confrontation technique based on Moving Target Defense
abstract
In the evolution process of cyberattack-defense confrontation, both sides have always been in a state of mutual confrontation and collaborative development, continuously upgrading their tools to improve adversarial capabilities. However, in this arms race, the positions of the both sides are imbalanced. As the party actively initiating the attack, attackers always is able to actively adjust the attack strategy based on the detected defense vulnerabilities to launch effective attacks. While the defenders always detecting defense vulnerabilities after suffering losses and filling them in a "patching" manner. This post awareness security protection strategy has a "fatal time difference" when dealing with unknown attacks. This paper aims to change the imbalanced state. Therefore, a attack confrontation model DTrap is proposed based on the concept of moving target defense, which introduce of high simulation trap hosts to achieve IP address and service port confusion. It can simulate real hosts to achieve various common network protocol requests and responses, and it can provide better dynamism than Honeypot when adjusting trap policies. DTrap can reverse the imbalance situation by increasing attack costs and promoting attack difficulty. We constructed a real adversarial environment, the security effectiveness of the DTrap model was evaluated through comprehensive and multi-dimensional experiments. The results indicate that DTrap can exert expected effectiveness in resisting network attacks of different dimensions, and effectively enhance the network attack confrontation ability.
Degang Sun, Yan Wang 0081, Xinbo Han, Weiqing Huang
TrustCom6
2023 A Novel Approach based on Improved Naive Bayes for 5G Air Interface DDoS Detection
abstract
The network security architecture of 5G defined by 3rd Generation Partnership Project (3GPP) in version 15, is vulnerable to the attack on wireless transmission due to its imperfect security design. The Distributed Denial of Service (DDoS) Attack is currently one of the biggest threats to air interface security of 5G. Attackers use controlled equipment to send a large number of authentication signaling to target base station, forming an instantaneous DDoS attack to achieve the purpose of destroying available resources. DDoS attack is simple to operate, hard to detect, and hugely harmful. From the perspective of signaling changes, this paper focuses on analyzing the authentication process that is most prone to DDoS attack, and extracts seven features based on the signaling change of the authentication process. We innovatively establish a classifier to detect DDoS attack using a novel improved naive Bayes algorithm. The algorithm not only comprehensively considers the independency and dependency between features through structural improvement, but also uses genetic algorithm to solve the optimal combination of attributes for category weights. At the end of the paper, we give simulation results which show the effectiveness of the proposed algorithm in detecting DDoS attack.
Weiqing Huang, Dali Zhu
WCNC3
2023 TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks
Leiqi Wang, Xiu Ma, Qiujian Lv, Yan Wang 0081, Weiqing Huang
Comput. Secur.6
2023 CKDAN: Content and keystroke dual attention networks with pre-trained models for continuous authentication
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Yuejun Liu, Xiaoyu Kang, Jiahui Shen, Weiqing Huang
Comput. Secur.8
2023 Physical Layer Authentication Based on Channel Polarization Response in Dual-Polarized Antenna Communication Systems
abstract
This study presents a novel approach for physical layer authentication based on channel polarization response (CPR). CPR is sensitive to variation in the physical properties of scatterers, and the CPR difference between various channels is higher than the channel frequency response (CFR) under rich scattering scenarios. Additionally, the estimation of CPR is continuous, the authentication interval can be adjusted according to the channel coherence time, then the proposed scheme can be applied to any rich scattering scenarios, including highly dynamic scenarios. Since the received polarization state is fixed during the channel coherence time, we can coherently stack the received polarization state to improve the signal to noise ratio (SNR) and the estimation accuracy of CPR, thereby achieving high authentication accuracy under ultra-low SNR. Moreover, since the transmitted polarization state of various transmitters is different, because of their unique hardware deficiencies, and since the CPR is dependent on the transmitted polarization state, the CPR of other transmitters is different, allowing the resolution of co-located attacks. We theoretically drive the false alarm probability, detection probability, optimal discriminant threshold, computational complexity, optimal stacking numbers, and optimal CPR points for authentication. Furthermore, extensive simulations and experiments are performed to verify the validity and effectiveness of the proposed scheme.
Yuemei Wu, Dong Wei 0002, Caili Guo, Weiqing Huang
IEEE Trans. Inf. Forensics Secur.4
2022 Anti-Clone: A Lightweight Approach for RFID Cloning Attacks Detection
Yue Feng 0001, Weiqing Huang, Siye Wang, Ziwen Cao
CollaborateCom (2)2
2022 Detecting USB Storage Device Behaviors by Exploiting Electromagnetic Emanations
abstract
Universal Serial Bus (USB) generates compromising emanations (CE) during data transmission, which is a weakness in the information security of information equipment. The radiated electromagnetic signal from the USB keyboard can be collected and processed to restore the key information. ‘USBee’, a malware, steals information from information equipment through the electromagnetic leakage signal generated by the data writing behavior of USB. This paper investigates the compromising emanations from USB to detect the behaviors of USB storage device including data reading, data writing and silence. We extract multiscale sample entropy (MSE) features and statistical features to quantify the characteristics of the radiated signal. The extracted features are fed into the k-Nearest-Neighbors (k-NN) classifier to achieve behaviors recognition. Finally, five USB flash disks and three computers are used to provide experimental examples for testing. The experimental results show that the proposed method can recognize the behaviors of USB storage devices effectively by analyzing the compromising emanations. Meanwhile, it is illustrated that the CE from USB contains the information of device individuals.
Bo Liu 0053, Yanyun Xu, Weiqing Huang, Shaoying Guo
ICC3
2022 PEPC: A Deep Parallel Convolutional Neural Network Model with Pre-trained Embeddings for DGA Detection
abstract
Discovering domain generation algorithms (DGAs) used to build command and control (C&C) infrastructures of botnets is crucial for recognizing botnets. Recent studies in DGA detection benefit from deep learning, such as convolutional neural network (CNN) and long short-term memory neural network (LSTM). However, these studies need massive supervised data to train their models, while obtaining enough labeled samples is consistently time-consuming and labor-intensive. In this paper, we propose a deep learning model, called PEPC, to detect and classify DGA domain names with only a small dataset. PEPC consists of two modules: (1) the pre-trained embeddings (PTE) module to quantify domain names to numeric vectors; and (2) the deep parallel convolutional neural networks (DPCNN) module to better extract features of vectors for prediction. Comparing our model with the 5 common deep learning-based DGA detection approaches, results show that our model yields an average improvement of 10 F1 points, while it requires just 30 training samples for each class. Significantly, PTE can help models achieve better detection and classification performances on small training samples.
Weiqing Huang, Yangyang Zong, Zhixin Shi, Leiqi Wang, Pengcheng Liu 0007
IJCNN1
2022 SeqA-ITD: User Behavior Sequence Augmentation for Insider Threat Detection at Multiple Time Granularities
abstract
Insider threat problems have occurred frequently and caused significant damage to organizations. Many existing techniques represent the user activities recorded in audit data as sequential data to capture the differences between benign and malicious users' behavior. However, multi-granular temporal information of user activity has not been explored adequately, especially for these rare malicious samples. This paper focuses on user behavior Sequences and proposes an Augmentation framework to boost the performance on Insider Threat Detection (SeqA-ITD). SeqA-ITD first embeds temporal information into user behavior sequences and then captures malicious user behavior's temporal and sequential patterns to generate discrete temporal sequences. A multi-granular enhanced Long Short-Term Memory (LSTM) model learns the original and generated temporal sequences with distinct temporal granularities to detect abnormal ones. To verify the effectiveness of our proposed method, we conduct comparison experiments on the Cert 4.2 dataset. Our proposed model achieves an F1-score of 0.9585 in day-level insider threat detection and outperforms baselines.
Fangtao Zhang, Xiu Ma, Weiqing Huang
IJCNN3
2022 Physical Layer Authentication Based on Full Channel Information under Dual-polarized Antenna Communication Systems
abstract
In this paper, we propose a physical authentication scheme based on the full channel information (FCI) in dual-polarized antenna communication systems. Different from channel impulse response (CIR) and channel frequency response (CFR), which only characterize the spatial fading of the channel, FCI reflects the spatial fading and polarization fading of channel, and completely characterizes the channel. Specifically, we use the least square (LS) to estimate channel spatial fading and polarization fading separately. Then based on statistical signal processing and binary hypothesis model, we establish an authen-tication scheme based on FCI and theoretically deduce the false alarm probability, detection probability, and optimal threshold of the proposed scheme. Besides, we conduct numerous simulation analysis on the proposed scheme. The simulation results show that the proposed scheme has higher authentication accuracy than that of CFR based schemes, especially in the case of low SNR.
Yuemei Wu, Dong Wei 0002, Jing Li 0176, Weiqing Huang, Xiang Meng 0008
ISCC4
2022 Specific Emitter Identification via Spatial Characteristic of Polarization Fingerprint
abstract
Radio frequency fingerprint (RFF) is a mature physical-layer identification technique for specific emitter identifi-cation (SEI). However, RFF faces the problem of low discrepancy. Therefore we propose polarization fingerprint (PF). PF has frequency characteristics derived from antenna hardware im-perfections and spatial characteristics derived from the vectorial properties of polarization. Based on these two characteristics, the mathematical model of PF is constructed. Because the spatial characteristics are not limited by the improvement of hardware manufacturing process, it still has a significant discrepancy. We also propose a spatial polarization compensation (SPC) for PF changes due to emitter movement. With spatial characteristics and SPC, PF can be effectively applied to SEI. However, the spatial characteristics also bring a trade-off between the identi-fication accuracy and the maximum emitter capacity. Finally, these two characteristics of PF and the proposed SPC are experimentally verified, then the identification accuracy of the proposed method is measured in real scenarios.
Jinlong Xu, Dong Wei 0002, Weiqing Huang
ISCC3
2022 Physical Layer Authentication Based on Continuous Channel Polarization Response in Low SNR scenes
abstract
In this paper, we propose a physical layer authentication scheme based on channel polarization response (CPR) in low SNR scenes, such as IoT, 5G, and 6G communication systems. We use the transmitting polarization state as the “pilot” to estimate CPR. Then, using the property that the polarization state of the signal is independent of the transmission content, the coherent superposition is used to stack the signal piecewise to improve the SNR. We derive the false alarm probability, detection probability, optimal threshold, and computational complexity of the proposed scheme, and give the solution method of the optimal stacking numbers under specific SNR and authentication performance. Besides, we analyze the effectiveness of the proposed scheme through numerical simulation. Simulation results show that the proposed scheme can still achieve good authentication performance under ultra low SNR, such as when SNR = -20dB, the detection probability is 99.6%, and the false alarm probability is 2%.
Yuemei Wu, Dong Wei 0002, Qiaoyu Zhang, Weiqing Huang, Xiang Meng 0008
PIMRC4
2022 DGQAN: Dual Graph Question-Answer Attention Networks for Answer Selection
abstract
Community question answering (CQA) becomes increasingly prevalent in recent years, providing platforms for users with various backgrounds to obtain information and share knowledge. However, the redundancy and lengthiness issues of crowd-sourced answers limit the performance of answer selection, thus leading to difficulties in reading or even misunderstandings for community users. To solve these problems, we propose the dual graph question-answer attention networks (DGQAN) for answer selection task. Aims to fully understand the internal structure of the question and the corresponding answer, firstly, we construct a dual-CQA concept graph with graph convolution networks using the original question and answer text. Specifically, our CQA concept graph exploits the correlation information between question-answer pairs to construct two sub-graphs (QSubject-Answer and QBody-Answer), respectively. Further, a novel dual attention mechanism is incorporated to model both the internal and external semantic relations among questions and answers. More importantly, we conduct experiment to investigate the impact of each layer in the BERT model. The experimental results show that DGQAN model achieves state-of-the-art performance on three datasets (SemEval-2015, 2016, and 2017), outperforming all the baseline models.
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Weiqing Huang
SIGIR6
2022 MFFAN: Multiple Features Fusion with Attention Networks for Malicious Traffic Detection
abstract
Malicious traffic detection is an important task in network security, which protects the target network from privacy leakage and service paralysis. The complexity of the network and the hierarchical structure of network traffic, i.e, byte-packet-flow, indicate the diversity of traffic information. Most of the existing work only uses one feature or statistical feature, and cannot learn network traffic from multiple perspectives, i.e, shortsighted, which results in the lack of important information in network traffic. Meanwhile, after obtaining multiple features, the effective fusion of multiple features is also an urgent problem to be solved. In this paper, we propose a Multiple Features Fusion with Attention Networks (MFFAN). According to the hierarchical structure of network traffic, we extract byte, packet, and statistical features from original traffic files to learn traffic from multiple perspectives, overcoming shortsighted. To effectively fuse multiple features, we use the self-attention to learn the intra-feature relationship with each feature and use the co-attention to learn the inter-feature relationship between features. We conduct experiments on the ISCIDS2012 dataset and CICIDS2017 dataset, and the results show that our model achieves an effective fusion of multiple features and high accuracy.
Weiqing Huang, Xinbo Han, Meng Zhang 0020, Haitian Yang
TrustCom1
2022 MEBV: Resource Optimization for Packet Classification Based on Mapping Encoding Bit Vectors
Qian Zou, Qingshan Kong, Zhiqiang Lv, Weiqing Huang
WASA (3)6
2022 An Efficient Interference Calculation Model Based on Large Scale Constellations Probabilistic Analysis
Weiqing Huang, Wen Wang 0014, Jingru Geng, Zhaohua Qiu
WASA (2)2
2022 Polarization Fingerprint: A Novel Physical-Layer Authentication in Wireless IoT
abstract
Radio frequency (RF) fingerprinting is a low-cost, high-efficiency, and high-security authentication technique for wireless IoT devices with limited resources, but RF fingerprinting faces problems such as small fingerprint differences, low finger-print stability, and high implementation difficulty. In order to solve these problems, we propose a novel concept of polarization fingerprinting. Polarization fingerprint (PF) is manifested as the correlation between polarization state and frequency. The properties of PF include group feature, individual feature and directionality. Group feature characterizes the antenna structure, and individual feature characterizes the antenna hardware imperfections. The directionality comes from the vector property of polarization and contains the relative position information of the communicating devices. The directionality solves the problem of similar fingerprints that may occur when the number of devices increases, which cannot be solved by RF fingerprinting. Compared to RF fingerprint, PF can exist stably and continuously, which not only solves the problem of low fingerprint stability, but also makes polarization fingerprinting based authentication easier to be implemented. The stability and continuity of PF allow more samples to be obtained during authentication. We also proved that increasing the sample amount can reduce the false alarm rate of authentication. Finally, we conducted experiments based on wireless IoT devices. Experiment results show that polarization fingerprinting based authentication has better performance than RF fingerprinting based under the same conditions.
Jinlong Xu, Dong Wei 0002, Weiqing Huang
WoWMoM3
2022 BertHANK: hierarchical attention networks with enhanced knowledge and pre-trained model for answer selection
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Degang Sun, Weiqing Huang
Knowl. Inf. Syst.6
2021 BERTDAN: Question-Answer Dual Attention Fusion Networks with Pre-trained Models for Answer Selection
Haitian Yang, Chonghui Zheng, Xuan Zhao 0011, Yan Wang 0081, Weiqing Huang
ICONIP (3)8
2021 Sprelog: Log-Based Anomaly Detection with Self-matching Networks and Pre-trained Models
Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang
ICSOC5
2021 Causal Intervention for Object Detection
abstract
We present a causal intervention module (CIM) to improve object detection methods. State-of-the-art object detectors learn the association between image pixels and bounding boxes with labels, which implicitly use contextual information in the backbone. Intuitively, context is such a rich source of information that an improvement due to contextual information is relatively modest. Inspired by this, we use the context explicitly in a novel framework of causal intervention for object detection. Specifically, we use a structural causal model to reveal how context confounders affect the object detection model, and adopt causal intervention to deal with the effect. The proposed CIM is applied to a two-stage object detection baseline, and extensive experiments show its effectiveness.
Weiqing Huang, Bo Meng 0006, Junxing Ren, Shixian Zhao, Ruwen Bai, Yang Yang 0087
ICTAI1
2021 Detecting Malicious PDF Documents Using Semi-Supervised Machine Learning
Nan Song, Min Yu 0001, Kam-Pui Chow, Gang Li 0009, Chao Liu 0020, Weiqing Huang
IFIP Int. Conf. Digital Forensics7
2021 FUNC-ESIM: A Dual Pairwise Attention Network for Cross-version Binary Function Matching
abstract
Binary function matching compares two pieces of binary functions to identify their similarities, which has wide applications in the field of malware origin tracing, vulnerability searching, binary level plagiarism detection, etc. Up-to-date methods commonly independently map each function to an embedding and rarely consider fine-grained pairwise semantic similarity, which influences the accuracy of matching. Moreover, few methods are available to detect similarities between versions spanning a long period for cross-version vulnerability detection or patch positioning. To solve these issues, we propose a novel binary function matching method, which takes a pair of binary functions as input, and then computes a similarity score jointly on the pair through a specifical dual pairwise cross-attention network. Specially, we apply our method to detecting similarities between cross-version binaries. The experimental analysis demonstrates that FUNC-ESIM achieves promising results on the cross-version binary matching task, where the average recall@1 reaches 85.98%.
Degang Sun, Yunting Guo, Min Yu 0001, Gang Li 0009, Chao Liu 0020, Weiqing Huang
IJCNN7
2021 UTANSA: Static Approach for Multi-Language Malicious Web Scripts Detection
abstract
In order to detect malicious web scripts automatically, many detection methods using static features and machine learning are proposed. However, the existing detection methods can only detect web scripts of specific programming languages. This paper proposes the unified text features and abstract syntax tree(AST) node sequence features algorithm(UTANSA) that exploits the text feature classification method and AST node classification method, together with the corresponding unified method to enhance the generalization ability of the model. Through the algorithm, two unified approaches are proposed based on text features and AST node features respectively, so that the detection model can detect multi-language web scripts. We choose scripts written in the JavaScript(JS) and PHP languages for experimentation to evaluate our approach. The results show that the detection model trained with the proposed method has a similar detection effect as trained with only JS samples or PHP samples.
Weiqing Huang, Chenggang Jia, Min Yu 0001, Gang Li 0009, Chao Liu 0020
ISCC1
2021 ITDBERT: Temporal-semantic Representation for Insider Threat Detection
abstract
The objective and universal nature of user behavior data make it the primary data for insider threat detection. Existing solutions treat user behavior as atomic symbols and do not consider behavior semantic information. Meanwhile, fine-grained temporal information is ignored despite its relevance to describe user behavior. Such approaches inevitably lead to unsatisfactory performance and generalization. In this paper, we propose ITDBERT which embeds temporal information into behavior and catches the fused semantic representation via pre-trained language models. ITDBERT also leverages attention-based Bi-LSTM to provide behavior-level detection results. To verify the effectiveness of our proposed method, we conduct comparison experiments on Cert datasets. Our proposed model achieves an F1-score of 0.9243 in day-level insider threat detection, which outperforms baselines.
Weiqing Huang, Qiujian Lv, Yan Wang 0081, Haitian Yang
ISCC1
2021 A GSO Protected Area Calculation Model based on Controllable NGSO System Parameters
abstract
According to ITU rules and recommendations, all NGSO systems must protect the GSO system from co-frequency harmful interference. However, the existing methods normally calculate the relative positions of satellites and earth stations through real-time data acquisition, and choose strategies such as satellite switching or isolation zone. As for the mega-constellations under construction, these methods still have great challenges to completely avoid harmful interference. In this circumstance, we establish a novel GSO protected area calculation model based on controllable NGSO system parameters. The proposed model not only has the advantages of low complexity and small calculation load, but also suitable for any NGSO constellation configuration as well as GSO earth station which located anywhere. The theoretical and simulation results both show that the harmful interference can be completely eliminated by setting the proposed GSO protected area. Furthermore, beams off and power control technologies are considered to lessen the protected area in a quantifiable degree, which is more achievable and more likely to be adopted by the existing NGSO systems.
Weiqing Huang, Wen Wang 0014, Jingru Geng
ISCC1
2021 Adaptive Smooth L1 Loss: A Better Way to Regress Scene Texts with Extreme Aspect Ratios
abstract
In recent years, scene text detection has experienced rapid development. Regression-based methods are currently a mainstream method for scene text detection, and the effect of bounding box regression is a major factor limiting their detection performance. The regression of bounding boxes is greatly affected by the aspect ratio of texts since the text in natural scenes varies greatly in height and width. However, the existing methods ignore the difference between the height and width of the text in the bounding box regression, which leads to an imperfect regression effect and thus suppresses the performance of the scene text detection. In this paper, we propose an Adaptive Smooth L1 Loss function (abbreviated as ASLL) for bounding box regression, which can adaptively determine the weight of each regression variable according to the current state of the model during the training process, so as to guide the bounding box to regress in a more critical direction. The experimental results demonstrate that ASLL achieves promising performance on scene text detection. Specially, an F-measure of 84.56% is achieved on CTW-1500 dataset, surpassing the state-of-the-art detectors, and the detection results on TotalText and ICDAR2015 datasets are competitive to those of state-of-the-art methods.
Chao Liu 0020, Min Yu 0001, Baole Wei, Boquan Li 0002, Gang Li 0009, Weiqing Huang
ISCC7
2021 FKTAN: Fusion Keystroke Time-Textual Attention Networks for Continuous Authentication
abstract
With the rapid development of computer technology, the traditional Internet data security and information privacy issues are gradually expanding to all aspects of society as a whole. As the first line of defense for information security, identity authentication technology becomes crucial. Among the many authentication technologies, continuous authentication technology has gained increasing attention. In this paper, we design fusion keystroke time-textual attention networks for continuous authentication based on the keystroke data (keystroke time series, keystroke text) when users enter free-text. Specifically, the corresponding keystroke time series and the corresponding keystroke text are first obtained based on the original keystroke data, and then the keystroke time series and the keystroke text are input into the BiLSTM model and the pre-training model, respectively; the BiLSTM can better capture the temporal features, and the pre-training model can better capture the textual features when authenticating the user. Finally, the two information are fed into the cross attention model to better integrate the two information. Experiments show that the FKTAN model achieves promising results on two datasets, Clarkson II keystroke dataset and Buffalo dataset, outperforming all baseline models.
Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang
ISCC6
2021 Multi-Modal fake news Detection on Social Media with Dual Attention Fusion Networks
abstract
Most of the existed fake news detection works on social media driven-fake news mainly focused on text. However, more and more social media platforms like Twitter, facebook, etc, allow users to create multi-modal contents, including text, image and video. Hence, it is obvious that only investigating text contents is insufficient to achieve solid detection. In this paper, we study the fake news on social media platforms composed of multimodal contents (text and images), and propose Dual Attention Fusion Networks for fake news detection on social media. We explore three modalities, (text modality, image modality and image attributes modality), and further propose a Dual Attention Fusion Networks (DAFN) model for this task. First, our proposed model extracts text modality and image modality, respectively. We then pass combinations of image attributes modality and text modality through BERT to extract text features. Finally, we reconstruct features of three modalities and fuse them into a feature vector for prediction. Our method is verified on realworld datasets consisting of collected social media platforms. Experiments show that the our method achieves promising results on real world datasets. outperforming all baseline models.
Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang
ISCC7
2021 Landscape-Enhanced Graph Attention Network for Rumor Detection
Min Yu 0001, Gang Li 0009, Mingqi Liu, Chao Liu 0020, Weiqing Huang
KSEM7
2021 Aspect and Opinion Terms Co-extraction Using Position-Aware Attention and Auxiliary Labels
Chao Liu 0020, Xintong Wei, Min Yu 0001, Gang Li 0009, Xiangmei Ma, Weiqing Huang
KSEM7
2021 AWGAN: Unsupervised Spectrum Anomaly Detection with Wasserstein Generative Adversarial Network along with Random Reverse Mapping
abstract
Automatic wireless spectrum anomaly detection is vital to intelligent management of electromagnetic spectrum, which aims to detect various jamming and anomalous working states, especially intentional jamming. The intentional jamming has evolved in a variety of ways, but the existing spectrum anomaly detection efforts give little consideration to the diverse intentional jamming. Here, we firstly generate a rich dataset consisting of five types of normal signals and four types of intentional jamming. In order to effectively detect anomalies, we propose AWGAN, a novel anomaly detection method based on Wasserstein generative adversarial network. AWGAN can not only learn the distribution of normal time-frequency waterfall images in a latent space, but also remember the detailed features of normal images, and generate same images as the normal images by adversarial training. To detect anomalies, we propose a random reverse mapping (RRM) method based on backpropagation, to map a new time-frequency waterfall image into the latent space, so as to find the vector closest to the distribution of the new image in the latent space. We also define a scoring criterion to score images indicating their fit into the learned distribution. The experimental results show that the comprehensive detection ability of our method is superior to other methods for detecting the four types of anomalies.
Weiqing Huang, Wen Wang 0014, Meng Zhang 0020, Sixue Lu, Yushan Han
MSN1
2021 Method for Detecting and Analyzing the Compromising Emanations of USB Storage Devices
abstract
Compromising emanations (CE) is produced in-evitably by the electronic information equipment while processing and transmitting information. Malicious software and side-channel attack can achieve information interception and cause information leakage by enhancing the compromising radiation or intentionally generating controlled electromagnetic emanations. To detect and analyze compromising emanations is of great significance to maintain information security. In this paper, we present a method to detect and analyze the compromising electromagnetic emanations of USB storage devices. The method is composed of three parts: signal preprocessing, electromagnetic emanations detection and electromagnetic emanations analysis. Firstly, the collected signal is denoised by the empirical mode decomposition (EMD) algorithm. Then singular value decomposition (SVD) is utilized to process the denoised signal. And microframe parameter of the denoised signal is analyzed to determine whether the compromising radiation is from USB. Finally, the radiation signal from the USB device is analyzed by the correlation function to assess whether there is a potential threat about this device. Experiments are carried out in normal scenarios and practical attack scenarios with “USBee”, which shows that the proposed method is effective and has practical application value.
Bo Liu 0053, Yanyun Xu, Weiqing Huang, Shaoying Guo
MSN3
2021 Specific Emitter Identification for WiFi Devices via Bezier Curve Fitting
abstract
A well-done specific emitter identification (SEI) method via radio frequency (RF) fingerprint is a physical-layer-based approach for wireless communication network security. In this paper, we propose an efficient SEI method based on the spectrum trace skeleton and Bezier curve fitting. The method utilizes the original spectrum trace directly instead of collecting and processing time-domain data. The control points obtained by Bezier curve fitting with the spectrum trace skeleton are selected to act as the new features for identification. It can retain the information of the spectrum trace to the most extent while reducing feature dimension. It is proved that the proposed method has effective and reliable performance for identifying WiFi devices. The total identification accuracy can reach 98.4% even at a low signal-to-noise ratio (SNR). Furthermore, compared with time-domain methods, the proposed method has a lower feature dimension and saves running time and storage space.
Shaoying Guo, Yanyun Xu, Weiqing Huang, Bo Liu 0053
PIMRC3
2021 NFDD: A Dynamic Malicious Document Detection Method Without Manual Feature Dictionary
Chenghao Wang 0010, Min Yu 0001, Chenggang Jia, Gang Li 0009, Chao Liu 0020, Weiqing Huang
WASA (2)7
2021 AOPL: Attention Enhanced Oversampling and Parallel Deep Learning Model for Attack Detection in Imbalanced Network Traffic
Leiqi Wang, Weiqing Huang, Qiujian Lv, Yan Wang 0081
WASA (2)2
2021 A Novel Method for Malicious Implanted Computer Video Cable Detection via Electromagnetic Features
abstract
Electromagnetic (EM) radiation is an inherent phenomenon in the operation of electronic information equipment. The side-channel attack, malicious hardware and software implantation attack by using the EM radiation are implemented to steal information. This form of attacks can be used in air-gap information equipment, which bring great danger for information security. The malicious implantation hidden in circuits are difficult to detect. How to detect the implantation is a challenging problem. In this paper, a malicious hardware implantation is analyzed. A method that leverages EM signals for Trojan-embedded computer video cable detection is proposed. The method neither needs activating the Trojan nor requires near-field probe approaching at close. It utilizes recognizable patterns in the spectrum of EM to predict potential risks. This paper focuses on the extraction of feature vectors via the empirical mode decomposition (EMD) algorithm. Intrinsic mode functions (IMFs) are analyzed and selected to be eigenvectors. Using a common classification technique, we can achieve both effective and reliable detection results.
Weiqing Huang, Zhaowen Feng, Yanyun Xu
WCNC1
2021 QAAN: Question Answering Attention Network for Community Question Classification
abstract
Community Question Answering (CQA) provides platforms for users with various backgrounds to obtain information and share knowledge. In recent years, with the rapid development of such online platforms, an enormous amount of archive data has accumulated, it becomes more and more difficult for expert users to identify desirable questions. In order to reduce the proportion of unanswered questions in CQA, facilitate expert users to find the questions they are interested in, question classification becomes an important task of CQA, which aims to assign a newly posted question to a specific preset category. In this paper, we propose a novel question answering attention network (QAAN) for investigating the role of the paired answer of questions for classification. Specifically, QAAN studies the correlation between question and paired answer, taking the questions as the primary part of the question representation, and the answer information is aggregated based on similarity and disparity with the answer. Our experiment is implemented on Yahoo! Answers dataset. The results show that QAAN outperforms all the baseline models.
Weiqing Huang
WCNC2
2021 Detection of RFID cloning attacks: A spatiotemporal trajectory data stream-based practical approach
Yue Feng 0001, Weiqing Huang, Siye Wang
Comput. Networks2
2021 An end-to-end text spotter with text relation networks
abstract
Abstract Reading text in images automatically has become an attractive research topic in computer vision. Specifically, end-to-end spotting of scene text has attracted significant research attention, and relatively ideal accuracy has been achieved on several datasets. However, most of the existing works overlooked the semantic connection between the scene text instances, and had limitations in situations such as occlusion, blurring, and unseen characters, which result in some semantic information lost in the text regions. The relevance between texts generally lies in the scene images. From the perspective of cognitive psychology, humans often combine the nearby easy-to-recognize texts to infer the unidentifiable text. In this paper, we propose a novel graph-based method for intermediate semantic features enhancement, called Text Relation Networks. Specifically, we model the co-occurrence relationship of scene texts as a graph. The nodes in the graph represent the text instances in a scene image, and the corresponding semantic features are defined as representations of the nodes. The relative positions between text instances are measured as the weights of edges in the established graph. Then, a convolution operation is performed on the graph to aggregate semantic information and enhance the intermediate features corresponding to text instances. We evaluate the proposed method through comprehensive experiments on several mainstream benchmarks, and get highly competitive results. For example, on the , our method surpasses the previous top works by 2.1% on the word spotting task.
Baole Wei, Min Yu 0001, Gang Li 0009, Boquan Li 0002, Chao Liu 0020, Weiqing Huang
Cybersecur.8
2021 FakeFilter: A cross-distribution Deepfake detection system with domain adaptation
abstract
Abuse of face swap techniques poses serious threats to the integrity and authenticity of digital visual media. More alarmingly, fake images or videos created by deep learning technologies, also known as Deepfakes, are more realistic, high-quality, and reveal few tampering traces, which attracts great attention in digital multimedia forensics research. To address those threats imposed by Deepfakes, previous work attempted to classify real and fake faces by discriminative visual features, which is subjected to various objective conditions such as the angle or posture of a face. Differently, some research devises deep neural networks to discriminate Deepfakes at the microscopic-level semantics of images, which achieves promising results. Nevertheless, such methods show limited success as encountering unseen Deepfakes created with different methods from the training sets. Therefore, we propose a novel Deepfake detection system, named FakeFilter, in which we formulate the challenge of unseen Deepfake detection into a problem of cross-distribution data classification, and address the issue with a strategy of domain adaptation. By mapping different distributions of Deepfakes into similar features in a certain space, the detection system achieves comparable performance on both seen and unseen Deepfakes. Further evaluation and comparison results indicate that the challenge has been successfully addressed by FakeFilter.
Boquan Li 0002, Baole Wei, Gang Li 0009, Chao Liu 0020, Weiqing Huang, Meimei Li, Min Yu 0001
J. Comput. Secur.6
2020 CIDetector: Semi-Supervised Method for Multi-Topic Confidential Information Detection
abstract
Confidential information firewalling with text classifier is to identify the text containing confidential information whose publication might be harmful to national security, business trade, or personal life. Traditional methods, e.g., listing a set of suspicious keywords together with regular-expression based filter, fail to solve the multi-topic phenomenon, i.e., one text containing the confidential information with different topics. In this paper, we propose a semi-supervised method, CIDetector, for multi-topic confidential information detection. We introduce coarse confidential polarity as prior knowledge into word embeddings, which can regularize the distribution of words to have a clear task classification boundary. Then we introduce a multi-attention network classifier to extract task-related features and model dependencies between features for multi-topic classification. Experiments are conducted by real-world data from WikiLeaks and demonstrated the superiority of our proposed method.
Min Yu 0001, Yantao Jia, Jiafeng Guo, Chao Liu 0020, Weiqing Huang
ECAI7
2020 Similarity of Binaries Across Optimization Levels and Obfuscation
Gengwang Li, Min Yu 0001, Gang Li 0009, Chao Liu 0020, Zhiqiang Lv, Weiqing Huang
ESORICS (1)8
2020 Adversarial Attack against LSTM-based DDoS Intrusion Detection System
abstract
Nowadays, machine learning is a popular method for DDoS detection. However, machine learning algorithms are very vulnerable under the attacks of adversarial samples. Up to now, multiple methods of generating adversarial samples have been proposed. However, they cannot be applied to LSTM-based DDoS detection directly because of the discrete property and the utility requirement of its input samples. In this paper, we propose two methods to generate DDoS adversarial samples, named Genetic Attack (GA) and Probability Weighted Packet Saliency Attack (PWPSA) respectively. Both methods modify original input sample by inserting or replacing partial packets. In GA, we evolve a set of modified samples with genetic algorithm and find the evasive variant from it. In PWPSA, we modify original sample iteratively and use the position saliency as well as the packet score to determine insertion or replacement order at each step. Experimental results on CICIDS2017 dataset show that both methods can bypass DDoS detectors with high success rate.
Weiqing Huang, Zhixin Shi, Yuru Ma
ICTAI1
2020 Enhancing the Feature Profiles of Web Shells by Analyzing the Performance of Multiple Detectors
Weiqing Huang, Chenggang Jia, Min Yu 0001, Kam-Pui Chow, Jiuming Chen, Chao Liu 0020
IFIP Int. Conf. Digital Forensics1
2020 TSCNN: A 3D Convolutional Activity Recognition Network Based on RFID RSSI
abstract
Human activity recognition has a wide range of applications, especially for the care of elderly people living alone and the monitoring of abnormal behaviors of key personnel. Although conventional video surveillance technology has made many research advances in this field, this technology destroys people's privacy. Activity recognition technology based on RFID avoids damage to people's privacy, and is being widely studied and applied. This paper uses RFID Received Signal Strength Indicator (RSSI) to identify and classify human behaviors. Predecessors employed CNN and LSTM for human activity identification, but there were still some shortcomings: 1) The 2D convolution loses the temporal information of continuous actions and reduces the classification accuracy. 2) LSTM network has a series of training difficulties. 3) No available public dataset for the current mission. To solve these problems, this paper proposes a convolutional neural network called temporal spatial convolutional neural network (TSCNN). Taking the continuous frame sequence as input, the network is designed using 3D convolution to realize realtime activities recognition. The average classification accuracy of our network is 94.6%, 15.6% higher than the state-of-the- art - Tagfree. Our lowest accuracy is 81.8%, and Tagfree is 35.4%. Besides, the ablation experiment proves the necessity of the design in the TSCNN network. Furthermore, we collect more than 60000 RFID signal data and transform them into corresponding pixel maps to form a new dataset. We present and expose the dataset called RF-men.
Weiqing Huang, Shaoyi Zhu, Siye Wang
IJCNN1
2020 CES2Vec: A Confidentiality-Oriented Word Embedding for Confidential Information Detection
abstract
Confidential information firewalling with text classifiers is to recognize the text containing confidential information whose publication might pose a threat to national security, business trade, or personal life. Word embedding is a component of the detector and plays an important role. Existing word embeddings, e.g., Word2Vec, fail to learn a clear task classification boundary, i.e., the confidential polarities of words are opposite but the embedding vectors of the words are close to each other. We propose a confidentiality-oriented word embedding, CES2Vec, for confidential information detection. We embed confidentiality into semantics to catch both of them together, which can learn the word embedding with a clear task classification boundary. We use real-world data from WikiLeaks and conduct the comparison experiments of our CES2Vec and popular methods. The experimental results show that our proposed method is better than the previously reported methods in detecting confidential information.
Min Yu 0001, Gang Li 0009, Chao Liu 0020, Shaohua An, Weiqing Huang
ISCC7
2020 SCX-SD: Semi-supervised Method for Contextual Sarcasm Detection
Meimei Li, Chen Lang, Min Yu 0001, Chao Liu 0020, Weiqing Huang
KSEM (2)7
2020 A Robust Representation with Pre-trained Start and End Characters Vectors for Noisy Word Recognition
Chao Liu 0020, Xiangmei Ma, Min Yu 0001, Xinghua Wu, Mingqi Liu, Weiqing Huang
KSEM (1)7
2020 Depthwise Separable Convolutional Neural Network for Confidential Information Analysis
Min Yu 0001, Chao Liu 0020, Chaochao Liu, Weiqing Huang, Zhiqiang Lv
KSEM (2)6
2020 AMQAN: Adaptive Multi-Attention Question-Answer Networks for Answer Selection
Haitian Yang, Weiqing Huang, Xuan Zhao 0011, Yan Wang 0081, Yuyan Chen, Rui Mao 0004
ECML/PKDD (3)2
2020 Novel design of Hardware Trojan: A generic approach for defeating testability based detection
abstract
Hardware design, especially the very large scale integration(VLSI) and systems on chip design(SOC), utilizes many codes from third-party intellectual property (IP) providers and former designers. Hardware Trojans (HTs) are easily inserted in this process. Recently researchers have proposed many HTs detection techniques targeting the design codes. State-of-art detections are based on the testability including Controllability and Observability, which are effective to all HTs from TrustHub, and advanced HTs like DeTrust. Meanwhile, testability based detections have advantages in the timing complexity and can be easily integrated into recently industrial verification. Undoubtedly, the adversaries will upgrade their designs accordingly to evade these detection techniques. Designing a variety of complex trojans is a significant way to perfect the existing detection, therefore, we present a novel design of HTs to defeat the testability based detection methods, namely DeTest. Our approach is simple and straight forward, yet it proves to be effective at adding some logic. Without changing HTs malicious function, DeTest decreases controllability and observability values to about 10% of the original, which invalidates distinguishers like clustering and support vector machines (SVM). As shown in our practical attack results, adversaries can easily use DeTest to upgrade their HTs to evade testability based detections. Combined with advanced HTs design techniques like DeTrust, DeTest can evade previous detecions, like UCI, VeriTrust and FANCI. We further discuss how to extend existing solutions to reduce the threat posed by DeTest.
Zhiqiang Lv, Yanlin Zhang, Weiqing Huang
TrustCom6
2020 RF-AMOC: Human-related RFID Tag Movement Identification in Access Management of Carries
abstract
The use of radio-frequency identification (RFID) technology in supply chain has been a fairly mature application in recent years, which can be extended to the field of carrier management for the inventory and access control of sensitive files and mobile storage medium. To address the inherent defects of false readings of RFID, we present RF-AMOC, a tag movement identification system that leverages the signal variation patterns between the opposite antennas and the tag to accurately determine whether someone takes the sensitive carrier out of the room or just the normal carrier usage activity in the room. Particularly, we focus on two kinds of signal variation modes: Direct side models, where the RSSI is sensed by one antenna on the tag side, and obstruction side models, where the RSSI is sensed by the other antenna that was obstructed by the person. Then, Pearson Coefficient and crest comparison algorithms are adopted to match the theoretical and actual RF-signal curves on the two sides, respectively. Additionally, a starting point acquisition method is proposed to extract the meaningful time period. A prototype of RF-AMOC is realized in two different environments with various persons, and the results validate that it is superior in terms of sensitivity and specificity with strong robustness.
Shaoyi Zhu, Weiqing Huang, Chenggang Jia, Siye Wang, Bowen Li 0010
ACM Trans. Sens. Networks2
2020 A Temporal and Spatial Data Redundancy Processing Algorithm for RFID Surveillance Data
abstract
The Radio Frequency Identification (RFID) data acquisition rate used for monitoring is so high that the RFID data stream contains a large amount of redundant data, which increases the system overhead. To balance the accuracy and real-time performance of monitoring, it is necessary to filter out redundant RFID data. We propose an algorithm called Time-Distance Bloom Filter (TDBF) that takes into account the read time and read distance of RFID tags, which greatly reduces data redundancy. In addition, we have proposed a measurement of the filter performance evaluation indicators. In experiments, we found that the performance score of the TDBF algorithm was 5.2, while the Time Bloom Filter (TBF) score was only 0.03, which indicates that the TDBF algorithm can achieve a lower false negative rate, lower false positive rate, and higher data compression rate. Furthermore, in a dynamic scenario, the TDBF algorithm can filter out valid data according to the actual scenario requirements.
Siye Wang, Ziwen Cao, Weiqing Huang
Wirel. Commun. Mob. Comput.4
2019 A SeqGAN-Based Method for Mimicking Attack
Weiqing Huang, Zhixin Shi
Inscrypt1
2019 Sparse Representation for Device-Free Human Detection and Localization with COTS RFID
Weiqing Huang, Shaoyi Zhu, Siye Wang, Jinxing Xie
ICA3PP (1)1
2019 Restoration as a Defense Against Adversarial Perturbations for Spam Image Detection
Boquan Li 0002, Min Yu 0001, Chao Liu 0020, Weiqing Huang, Lejun Fan, Jianfeng Xia
ICANN (3)5
2019 Adversarial Attack Against DoS Intrusion Detection: An Improved Boundary-Based Method
abstract
Denial of Service (DoS) attacks pose serious threats to network security. With the rapid development of machine learning technologies, artificial neural network (ANN) has been used to classify DoS attacks. However, ANN models are vulnerable to adversarial samples: inputs that are specially crafted to yield incorrect outputs. In this work, we explore a kind of DoS adversarial attacks which aim to bypass ANN-based DoS intrusion detection systems. By analyzing features of DoS samples, we propose an improved boundary-based method to craft adversarial DoS samples. The key idea is to optimize a Mahalanobis distance by perturbing continuous features and discrete features of DoS samples respectively. We experimentally study the effectiveness of our method in two trained ANN classifiers on KDDcup99 dataset and CICIDS2017 dataset. Results show that our method can craft adversarial DoS samples with limited queries.
Weiqing Huang, Zhixin Shi
ICTAI2
2019 Attention Networks for Band Weighting And Selection In Hyperspectral Remote Sensing Image Classification
abstract
Hyperspectral imaging is widely used in remote sensing because of its capability to capture the detailed spectral reflection of the ground object. The acquired rich band information brings significant benefits to better discriminate the target pixels. However, this imaging method also introduces redundant and noisy bands which may lower the classification accuracy. In addition, the contribution of different bands towards the final classification task are not necessarily the same. Therefore, band weighting and band selection are often adopted to model the relationship among the bands and remove the irrelevant ones. Attention mechanism is a method in neural networks to guide the algorithm to focus on the important information. In this paper, we propose an attention based deep learning framework to achieve band weighting and selection. The experimental results on two hyperspectral image datasets show the effectiveness of the proposed framework.
Jing Wang 0062, Jun Zhou 0001, Weiqing Huang, Jackie Fang Chen
IGARSS3
2019 Android Malware Family Classification Based on Sensitive Opcode Sequence
abstract
Android malware family classification is an advanced task in Android malware analysis, detection and forensics. Existing methods and models have achieved a certain success for Android malware detection, but the accuracy and the efficiency are still not up to the expectation, especially in the context of multiple class classification with imbalanced training data. To address those challenges, we propose an Android malware family classification model by analyzing the code's specific semantic information based on sensitive opcode sequence. In this work, we construct a sensitive semantic feature-sensitive opcode sequence using opcodes, sensitive APIs, STRs and actions, and propose to analyze the code's specific semantic information, generate a semantic related vector for Android malware family classification based on this feature. Besides, aiming at the families with minority, we adopt an oversampling technique based on the sensitive opcode sequence. Finally, we evaluate our method on Drebin dataset, and select the top 40 malware families for experiments. The experimental results show that the Total Accuracy and Average AUC (Area Under Curve, AUC) reach 99.50% and 98.86% with 45. 17s per Android malware, and even if the number of malware families increases, these results remain good.
Min Yu 0001, Gang Li 0009, Chao Liu 0020, Weiqing Huang
ISCC8
2019 A Two-Stage Model Based on BERT for Short Fake News Detection
Chao Liu 0020, Xinghua Wu, Min Yu 0001, Gang Li 0009, Weiqing Huang
KSEM (2)6
2019 Machine Tools Fingerprinting for Distributed Numerical Control Systems
abstract
As machine tools are connected to Industrial Ethernet and external interfaces in the wave of the fourth industrial revolution, new attacks and vulnerabilities are emerging. However, there is little security analysis on Distributed Numerical Control (DNC) system and Computerized Numerical Control (CNC) system. Researchers have demonstrated how to combine the characteristics of Industrial Control System (ICS) to augment existing Intrusion Detection System (IDS) solutions. To the best of our knowledge, there is no such work on DNC network. In response to this situation, a fingerprinting method is proposed as an enhancement technology to existing IDS for DNC systems. The first step is to extract the number of data collection points of each machine tool and the length of TCP payload of each packet. And the second step is to use data response processing times of machine tools to construct unique fingerprint for each machine. Finally, the optimum period slice k is selected and classification accuracy is evaluated using a real-world dataset from a small-scale smart factory. It is demonstrated that our fingerprinting method can be a valuable tool to enhance IDS for DNC network.
Weiqing Huang, Zhongfeng Jin, Chao Liu 0020, Meimei Li
LCN1
2019 Research on Physical Layer Security Scheme Based on OAM - Modulation for Wireless Communications
Weiqing Huang, Dong Wei 0002, Qiaoyu Zhang
WASA1
2019 Malicious documents detection for business process management based on multi-layer abstract model
Min Yu 0001, Gang Li 0009, Chenzhe Lou, Yunzheng Liu, Chao Liu 0020, Weiqing Huang
Future Gener. Comput. Syst.7
2018 URefFlow: A Unified Android Malware Detection Model Based on Reflective Calls
abstract
In Android malware detection, sensitive data-flows provide more accurate information on the application's behavior than regular features such as signatures and permissions. Currently, Android static taint analysis is widely adopted to identify sensitive data-flows because of its high code coverage and low false negative rate. However, existing static taint analysis tools cannot effectively analyze applications that adopt Android reflection mechanism. Reflection mechanism can block the control-flows and data-flows of the application. When constructing a call graph, the call information will point directly to the system's reflection processing method, rather than the actual method invoked by the application. This significantly affects the accurate representation of the application's behavior. To address this issue, this paper proposes a unified Android malware detection model based on reflective calls named URefFlow, in which the reflective call statement is replaced by the non-reflective call statement to make the reflective calls explicit by combining the parameters of the reflective calls into standard function calls. After extracting the complete sensitive data-flows with reflective calls from an application, we analyze the characteristics of these data-flows to determine whether the application is malicious. Evaluation results on thousands of applications show that URefFlow can achieve an impressive detection accuracy of 95.6% with a false positive rate of 0.8%. In addition, the proposed approach complements well with existing static stain analysis techniques.
Chao Liu 0020, Min Yu 0001, Gang Li 0009, Bo Luo, Weiqing Huang
IPCCC8
2018 MPP: A Join-dividing Method for Multi-table Privacy Preservation
abstract
In regard to relational databases, studies in this area typically focus on individual privacy leakage in one table. However, in reality, a database usually has many tables, some of them contain correlation information about individual, which can provide additional implication as background knowledge to attacker. In this paper, we innovatively propose a new method named MPP (Multi-table Privacy Preservation) which combines Lossy-join with Bucketization to enhance the individual privacy in database. We consider the privacy disclosure problem from the global sight of the entire dataset instead of a table. Based on this method, we not only solve the correlation information leakage by other tables, but also improve the data utility. Extensive experiments on 32.8GB real-world Express data demonstrate the effectiveness and efficiency of our approach in terms of data utility and computational cost.
Weiqing Huang, Jianfeng Xia, Min Yu 0001, Chao Liu 0020
ISCC1
2018 Sentiment Embedded Semantic Space for More Accurate Sentiment Analysis
Min Yu 0001, Gang Li 0009, Chao Liu 0020, Weiqing Huang, Fangtao Zhang
KSEM (2)6
2018 MRDroid: A Multi-act Classification Model for Android Malware Risk Assessment
abstract
Risk Score (RS) on Android is aiming at offering measurement to users for evaluating the apps' trustworthiness. Much work has been done to assess Android app's risk, but few jobs use various assessment systems to analyze Android apps with various malicious acts. However, it is hard for a single system to analyze those multiple categories Android apps. To overcome such limitations, we propose a multi-act classification model MRDroid for Android malware risk assessment in this paper, which presorts an app to one category, then uses the most suitable subsystem corresponding to that category to analyze the app for giving a RS. Base on this model, we implement an Android malware risk assessment system utilizing a machine learning solution with k-means algorithm for clustering benign and malware samples to various categories and the supervised algorithms for generating specific subsystems. It can be also used for Android malware detection under the condition of human confirmation. Experiments show that MRDroid provides high detection precision and offers stable and reliable risk assessment. Though testing our system using the dataset different from the system used, the result indicates it is also effective in detecting some unknown samples.
Min Yu 0001, Chao Liu 0020, Weiqing Huang, Gang Li 0009
MASS6
2018 FGFDect: A Fine-Grained Features Classification Model for Android Malware Detection
Chao Liu 0020, Min Yu 0001, Bo Luo, Weiqing Huang
SecureComm (1)7
2018 HEVC Lossless Compression Coding Based on Hadamard Butterfly Transformation
Xi Yin 0005, Weiqing Huang, Mohsen Guizani
WASA2
2017 Electromagnetic side channel analysis of laser facsimile
abstract
This study attempts to characterize the electromagnetic compromising emanations from Laser Facsimile. Electromagnetic radiation is inevitable when electronic equipment works. The radiations can deteriorate the performance of a part of device itself or of another system. This phenomenon is a subject in the field of electromagnetic compatibility (EMC). But concerning people who process classified information, there is another threat that such electromagnetic radiation could be intercepted, deciphered and finally reveal the data being processed by the equipment. In this paper, electromagnetic side channel of laser facsimile and countermeasures are analyzed and discussed. It shows that the electromagnetic side channel of electronic information equipments is a real threat of information security.
Yanyun Xu, Jianlin Hu, Meng Zhang 0020, Weiqing Huang
ICC4
2017 Design and Realization of an Indoor Positioning Algorithm Based on Differential Positioning Method
Weiqing Huang, Siye Wang, Shaoyi Zhu
WASA1
2017 Recognition of Electro-Magnetic Information Leakage of Computer Based on Multi-image Blind Deconvolution
Shanjing Yang, Jianlin Hu, Weiqing Huang
WASA3
2000 A learning controller for robot manipulators using Fourier series
abstract
We proposed a new learning controller for decentralized tracking control of nonlinear robot manipulators. When the desired trajectory of each subsystem of the robot lasts for a finite duration, it can be approximated by a Fourier series with constant harmonic magnitudes. For each subsystem of the robot, a learning controller is designed to individually control each harmonic component of the actual output, although it is cross-related to other components in nonlinear systems. The learning algorithm is designed such that each harmonic magnitude of the actual output converges to that of the desired trajectory within the system bandwidth. Since this decentralized learning controller is designed in Fourier space instead of time domain, the system's time-delay could be easily compensated. This learning controller is only based on the local input and output information; no a priori structure or parameters of the system model are required. The experimental results on a 3-DOF direct-drive robot are presented.
Xiaoqi Tang, Lilong Cai, Weiqing Huang
IEEE Trans. Robotics Autom.3
1999 Decentralized Learning Control for Robot Manipulators
abstract
A decentralized learning control scheme for tracking control of robot manipulators is presented. In this scheme, each joint is considered as a subsystem and controlled independently. The interactions from other subsystems are treated as deterministic uncertainties. The desired trajectory and the output of each subsystem are reparametrized by Fourier series (FS). A learning controller designed in Fourier space regulates each harmonic component individually by forcing Fourier coefficients (FCs) of the actual output approach to the corresponding FCs of the desired trajectory which are known constants. Since the information of the system phase-delay is included in FCs, the time-delay of the system can be easily compensated. The learning controller only uses the input and output information of the subsystem, no a priori knowledge about the system models is required. The asymptotic convergence of the tracking is proved in the paper. The experimental results on a 3 DOF direct-drive robot show that convergence rate is faster compared with many other learning controllers and the performance of the closed-loop system is dramatically improved.
Weiqing Huang, Lilong Cai, Xiaoqi Tang
ICRA1