VLDB 2026 Research / reviewers in the wild / expert
Dawei Zhao 0001
dblp:52/266-1
· DBLP profile ↗
54ranked-venue papers
7as first author
48since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 15 · 1 first-author · 15 since 2021Security and privacy · 11 · 2 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 8 · 3 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 5 since 2021Computer networks · 5 · 5 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | C2graph: A Compression-Collaboration Algorithm for CPU-GPU Hybrid Weighted Graph Traversals
Ning Wang 0026, Huaibei Li, Shen Su, Yu Gu 0002, Ge Yu 0001, Zhigang Wang 0001, Dawei Zhao 0001, Hui Lu 0005, Zhihong Tian 0001 |
ICDE | 7 |
| 2026 | DHA-Net: Dynamic Heterogeneity-Aware Network for Multimodal Medical Image Segmentation
Dong Lian, Lijuan Xu 0001, Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001 |
ICIC (10) | 5 |
| 2026 | Intrusion detection for multi-modal data in the internet of vehicles employing large-scale temporal semantic modeling: A survey
Wei Wu 0046, Jingqi Zhao, Yifan Ren, Fenghua Tong, Dawei Zhao 0001, Haipeng Peng |
Expert Syst. Appl. | 6 |
| 2026 | Semantic structure fusion graph for abstractive dialogue summarization
Furui Wang, Zhenfang Zhu, Qiang Lu 0006, Shuai Gong, Hongli Pei, Zhenrui Fu, Dawei Zhao 0001 |
Neurocomputing | 7 |
| 2026 | Machine Learning for Edge-Centric Indoor Visible Light Positioning: A Comprehensive Survey and Future DirectionsabstractWith the deepening of the Internet of Things (IOT) and industrial digital transformation, the core of positioning services is shifting from “serving people” to “connecting everything”, which poses a comprehensive challenge to indoor positioning technology in terms of high accuracy, low latency, low power consumption, and low cost. Traditional radio frequency positioning technology has shown many limitations in this context, while visible light positioning (VLP) technology has become a highly promising supplementary solution due to its unique advantages, such as the absence of authorized spectrum, no electromagnetic interference, high security, and the ability to balance lighting. However, traditional VLP methods heavily rely on accurate channel models and are difficult to cope with complex non-line-of-sight environments, resulting in increasingly prominent performance bottlenecks. In recent years, the rapid development of machine learning technology has provided a new paradigm for solving the above-mentioned problems. From the perspective of the IOT and edge computing, this paper systematically summarizes the latest progress of how machine learning can improve the performance of indoor VLP.We first elaborate on the architecture and basic principles of edge-oriented VLP systems. Then, a comprehensive review and comparison are performed on VLP methods based on traditional machine learning and deep learning. Moving on, we provide the analysis on how they improve system accuracy and robustness through data-driven approaches. Moreover, this article delves into the application and value of different learning paradigms, such as centralized learning, online learning, and federated learning in VLP systems. In addition, we have developed a multi-dimensional evaluation system that includes core positioning accuracy and edge performance indicators to comprehensively measure the feasibility of the system in practical deployment. Finally, we present the identified challenges and future research directions in this under-explored field from aspects of standardized scenario modeling, high generalization base models, dynamic environment robustness, heterogeneous terminal adaptation, and edge lightweight models. Yonghao Yu 0001, Youyang Qu, Dawei Zhao 0001, Tie Zhong, Tom H. Luan, Shui Yu 0001 |
IEEE Internet Things J. | 3 |
| 2026 | TECL: Time-Equivariant Contrastive Learning for weakly-supervised Grounded Video Question Answering
Zhenfang Zhu, Shengtai Zhang, Dawei Zhao 0001, Menglin Zhu |
Knowl. Based Syst. | 6 |
| 2026 | A Prompt-Driven framework for compensation and fusion in multimodal sentiment analysis with missing modalities
Zhenfang Zhu, Qiang Lu 0006, Hongli Pei, Kefeng Li 0003, Yuzhi Ren, Meng Li 0049, Xiaowen Sun, Dawei Zhao 0001 |
Knowl. Based Syst. | 9 |
| 2026 | Mgsc: multimodal generation and self-supervised contrast learning for mitigating language bias in visual question answering
Zhenfang Zhu, Jiangtao Qi, Yanhan Sun, Dawei Zhao 0001, Xuejuan Wang |
Multim. Syst. | 7 |
| 2026 | Frequency-selective boundary transition learning for mixed-modality medical image segmentation
Dong Lian, Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001 |
Pattern Recognit. | 7 |
| 2026 | Accelerating Heterogeneous Tensor Parallelism via Flexible Workload ControlabstractTransformer-based foundation models are becoming deeper and larger. For fast training, their billions of parameters (tensors) are split onto parallel tasks running on many modern yet expensive accelerators. To amortize the huge hardware investments, it is cost-effective to share the aggregated resources among multi-tenants. However, resource contention yields the heavy straggling problem. Existing works feature contributions for the traditional data parallelism. They cannot work well for the new tensor parallelism, due to the dependency among split tensors. This paper is the first attempt on accelerating heterogeneous tensor parallelism. We summarize specific challenges, including the very frequent synchronizations and the heavy tensor computation workloads. Our solution is to resize dimensions of parameters on demand, to quickly and dynamically balance workloads. The accuracy loss is reduced through priority resizing. We also migrate workloads between tasks, without any loss of accuracy. The most efficient communication primitives are selected and then scheduled in a non-redundant manner, to reduce the runtime latency. Our final hybrid solution is built on top of resizing and migration. By studying the tradeoff between accuracy and efficiency, it can smartly hit the “sweet spot”. Extensive experiments validate the effectiveness of our proposals. Zhigang Wang 0001, Ning Wang 0026, Chuanfei Xu, Yu Gu 0002, Hui Lu 0005, Dawei Zhao 0001, Zhihong Tian 0001 |
IEEE Trans. Big Data | 7 |
| 2026 | A Secure and Efficient Image Sharing Method Based on Bilateral Compressive Sensing With Multilevel Privacy Preserving FunctionabstractWith the advent of intelligent technologies, miscellaneous data containing sensitive information are explosively generated and shared. Compressive sensing methods are naturally suitable for such scenarios due to their joint compression and encryption capabilities. However, data users of most existing compressive sensing methods need to reconstruct original images before use, which brings two disadvantages. First, indiscriminately requiring every data user to reconstruct images without considering their exact requirements is neither advisable nor efficient. Second, allowing all data users to reconstruct original images may cause private or confidential information exposure. To address these issues, in this paper, a novel image sharing method is proposed, which realizes efficient multilevel privacy preservation. Specifically, data owners compress the original images with designed measurement matrices through the proposed Tℓ1-B2DLDA algorithm, which outputs dimension-reduced data with the ability to simultaneously support the subsequent classification tasks for level I data users and reconstruction tasks for level II data users. Therefore, low level data users could achieve their goals without obtaining any private or confidential information in the original images. Experiments are conducted to verify the feasibility, performance and robustness of the proposed method. Furthermore, the security of the proposed method is analyzed both theoretically and practically. The source code of the proposed method is publicly available at https://github.com/xchuxiao23/TL1-B2DLDA. Wei Wu 0046, Chuxiao Xu, Dawei Zhao 0001, Haipeng Peng, Fenghua Tong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | TraceCluster: A Lightweight and Adaptive Clustering-Based Subgraph Attention Network for APT Detection in Provenance GraphsabstractProvenance graph-based anomaly detection, particularly for Advanced Persistent Threat (APT) detection, addresses the issues of large-scale graphs and data imbalance. However, existing methods struggle with information loss, high computational complexity, and low detection accuracy. To address the above challenges, this paper proposes TraceCluster, a lightweight and adaptive clustering-based Subgraph Attention Network (SAN) for APT detection in provenance graph. TraceCluster mitigates the neighborhood explosion problem by clustering nodes to partition large-scale graphs, thus reducing reliance on the global graph while preserving local neighborhood information. Furthermore, the method dynamically models complex inter-node dependencies within subgraphs. It employs an attention mechanism to adaptively highlight the most relevant connections. This enhances node representations and improves overall feature extraction. This design substantially reduces memory consumption and avoids the high computational complexity of global graph processing. In addition, an adaptive category-weighting loss function assigns variable weights to different classes, improving the detection of rare and anomalous behaviors. Experimental results show that on the OpTC dataset, the currently faster method is 37-fold and 3-fold slower than our approach in terms of inference time respectively. Furthermore, in the nine real-world scenarios of four evaluated datasets, TraceCluster outperforms state-of-the-art (SOTA) approaches in terms of overall performance, especially in node-level APT detection tasks. Lijuan Xu 0001, Zicheng Zhao, Dawei Zhao 0001, Zhen Wang 0004, Chunpeng Ge 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Reinforcement Learning Can Be a Double-Edged Sword for Cooperation on Higher-Order NetworksabstractCollective cooperation is fundamental to individual survival and social development, and exploring its mechanism of emergence is of great significance. However, most existing studies related to the evolutionary dynamics on higher order networks assume that all agents within a population follow the same strategy updating rule. This assumption does not align with reality and is an oversimplification. To this end, we propose a higher order network game framework featuring a hybrid strategy updating rule. Specifically, we use scale-free random hypergraphs (SRHs) to characterize the underlying network topology of the population. Then, we categorize agents into two types: imitation learners and autonomous learners according to social learning and behaviorism theories. For imitation learners, we apply the Fermi rule to characterize their probabilistic imitation behaviors, while for autonomous learners, we adopt the reinforcement learning method to highlight their decision-making features. Through a series of simulation experiments and theoretical analyses, we find that autonomous learners have a dual impact on cooperation in groups: they inhibit cooperation at low dilemma intensities but promote cooperation at high dilemma intensities. In addition, we show that smaller group sizes are more conducive to cooperation. Our findings provide valuable insights for better understanding the impact of hybrid updating mechanisms on the evolutionary dynamics of collective cooperation in higher order networks. Dawei Zhao 0001, Tina P. Benko, Chengyi Xia, Matjaz Perc |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2025 | CBAT-ASG: Adversarial Sample Generation Method Based on CBA-TransformerabstractIn recent years, machine learning models have become prevalent for anomaly detection in industrial control systems (ICS). However, their vulnerability to adversarial samples poses a significant security threat. Current methods for adversarial sample attacks in ICS are inadequate, requiring urgent research. Present adversarial samples mainly target machine learning-based anomaly detection models, overlooking invariant rule detectors in ICS, which reduces attack success rates. This paper introduces CBAT-ASG, a novel adversarial sample generation method based on CBA-Transformer. We enhance the Transformer with channel and spatial attention modules, creating the CBA-Transformer generative model. This model improves performance and generates initial adversarial samples that better match industrial control data. To avoid detection by invariant rule detectors, we use an invariant rule checker to refine adversarial samples, increasing their resistance to detection. Experiments on public datasets show CBAT-ASG significantly reduces the detection capabilities of the advanced anomaly detection model GDN, with Precision decreasing by 0.94, and Recall and F1-Score dropping by over 0.4. Comparisons with three state-of-the-art adversarial sample generation methods across four anomaly detection models show CBAT-ASG's attack efficacy is approximately 0.7 higher in the best-case scenario. Lijuan Xu 0001, Zhiang Yao, Chengcai Diao, Guangrun Zhou, Dawei Zhao 0001 |
CSCWD | 6 |
| 2025 | Multi-Level Privacy Preserving Scheme for Visual IoT Data Based on Compressive SensingabstractWith the rapid growth of IoT technology, Visual IoT (VIoT) plays a key role in areas like security surveillance and intelligent transportation, where large volumes of sensitive data are collected and transmitted. Many applications face limitations in computing and storage, such as challenges in managing traffic data. Recently, Compressed Sensing (CS) theory has been applied to improve data acquisition and processing efficiency. However, existing CS-based privacy methods focus mainly on protecting single privacy zones through key-based control and lack support for hierarchical protection across multiple sensitive regions. To address this, we propose a multi-level privacy-preserving scheme for VIoT data using CS, offering full, partial, and no access levels to meet varying security needs. We also implement watermarks to prevent key-sharing attacks among partially authorized users. Experimental results demonstrate that the scheme ensures data security while minimizing time and space overhead, making it suitable for resource-limited VIoT scenarios. Dawei Zhao 0001, Le Ju, Fenghua Tong, Fuqiang Yu, Xin Li 0002 |
CSCWD | 1 |
| 2025 | Research on Firmware Simulation of Windows Embedded Compact SystemabstractFirmware simulation of embedded devices is an important technology to support security testing of embedded devices. However, most of the current firmware emulation targets are bare-metal or Linux-based firmware. The number of embedded devices based on Windows Embedded Compact (Windows CE) as the operating system occupies a certain market size, and there are certain security risks. Firmware extraction and system state simulation of embedded devices based on Windows CE are difficult. In order to solve the problem that embedded devices based on Windows CE system need firmware simulation methods and better support the security testing of embedded devices using Windows CE system, We propose a firmware simulation method for Windows CE systems. Combining the development board framework supported by QEMU and the specific application of embedded devices to be simulated, we make a simulation image that can run in QEMU. We verify our method on two commercial PLCs, and the experimental results show that our method can simulate the system state of PLC firmware. Dawei Zhao 0001, Lei Zhang 0136, Lijuan Xu 0001 |
CSCWD | 1 |
| 2025 | DCCT-Net: A Network Combined Dynamic CNN and Transformer for Image Compressive SensingabstractRecent end-to-end image compressive sensing networks primarily use Convolutional Neural Networks (CNNs) and Transformers, each with distinct limitations: CNNs struggle with global feature capture, while Transformers lack local feature extraction. We propose a novel network, DCCT-Net, which combines Dynamic CNN (DCNN) and Transformer. This integration leverages DCNN’s local feature strengths and the Transformer’s global representation capabilities, resulting in superior image reconstruction quality. To further enhance the network’s performance, we propose a Feature Dynamic Augment Module (FDAM), which dynamically extracts features based on the saliency of segmented image regions, thereby amplifying the CNN’s local feature expression. Additionally, we design a Weighted Fusion Module (WFM), which optimizes the combination of local and global features extracted by the DCNN and Transformer, respectively. Extensive experiments demonstrate that our proposed DCCT-Net significantly outperforms most existing state-of-the-art methods in the field. Lijuan Xu 0001, Haixiao Mei, Fenghua Tong, Dawei Zhao 0001, Fuqiang Yu |
ICASSP | 4 |
| 2025 | ElaD-Net: An Elastic Semantic Decoupling Network for Lesion Segmentation in Breast Ultrasound ImagesabstractBreast diseases pose a significant threat to women’s health. Automatic lesion segmentation in breast ultrasound images (BUSI) plays a crucial role in fast diagnosis. While various enhanced U-Net-based models have achieved success in multi-scale feature analysis and handling blurred boundaries, two key challenges persist that could guide the improvement of BUSI segmentation networks: 1) significant fluctuations in pixel intensity distribution similarity between the lesion and surrounding tissues, and 2) inconsistent transmission of spatial detail due to multi-scale lesion sampling. These issues highlight the necessity of semantic elasticity understanding and consistency control. To this end, we propose ElaD-Net, an Elastic Semantic Decoupling Network for lesion segmentation in BUSI. This network uses the pre-trained EfficientNet-B2 for multi-scale encoding of BUSI. The decoding stage features two key modules: Elastic Semantic Decoupling (ESD) and Spatial Semantic Reconstruction (SSR). ESD learns and decouples multi-frequency semantics in multi-scale channels with a self-calibration mechanism, enabling dynamic adjustment of receptive depth to resist similarity fluctuations. SSR further optimizes ESD outputs via feature branching, compression, and excitation to ensure spatial semantic consistency, thereby separately reconstructing edge and body. Lijuan Xu 0001, Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001 |
IJCAI | 6 |
| 2025 | Fed-CLIDS: Network intrusion detection system based on federated meta-continuous learningabstractWith the widespread adoption of IoT devices and the increasing diversity of network attacks, traditional centralized intrusion detection systems face significant challenges in processing real-time data and ensuring privacy protection. Federated learning, as an effective solution, enables distributed collaborative training while preserving data privacy. However, traditional federated learning methods struggle to adapt to dynamic network environments and often suffer catastrophic forgetting when learning new network attacks. This paper proposes a malicious network traffic detection method based on federated meta-continuous learning, integrating attention-enhanced BiLSTM models, SMOTE oversampling, and continual learning strategies. The proposed approach leverages federated learning to ensure data privacy, enhances the model’s capability to capture critical traffic features, and improves adaptability to concept drift. Experimental results show that the proposed method performs exceptionally well on the CICIDS2017 network traffic intrusion detection dataset and the NF-ToN-IoT industrial Internet dataset, demonstrating its effectiveness in dynamic network environments. Shumian Yang, Guoqing Lou, Lijuan Xu 0001, Dawei Zhao 0001 |
IJCNN | 4 |
| 2025 | Investigation into Auto-scaling Mechanisms in Cloud Computing
Xin Li 0002, Jiming Dong, Wenkang Xiang, Dawei Zhao 0001, Lijuan Xu 0001, Fenghua Tong |
KSEM (5) | 4 |
| 2025 | DualCBR: Cross-Modal Collaborative Filtering with Bidirectional Alignment for Long-Tail Recommendation
Xin Li 0002, Dekai Zhang, Dawei Zhao 0001, Lijuan Xu 0001, Fuqiang Yu |
KSEM (5) | 4 |
| 2025 | AJSAGE: A intrusion detection scheme based on Jump-Knowledge Connection To GraphSAGE
Lijuan Xu 0001, Zicheng Zhao, Dawei Zhao 0001, Xin Li 0002, Xiyu Lu, Dingyu Yan |
Comput. Secur. | 3 |
| 2025 | High-Precision Indoor Visible Light Positioning Method for Line-Of-Sight Scenes Based on a Spatiotemporal Sequence Attention MechanismabstractABSTRACT Using deep learning to improve the accuracy of indoor visible light positioning (VLP) systems has gradually become a widely used research strategy in the field. However, current deep learning‐based indoor visible light localization algorithms have not been able to effectively mine the deep temporal and spatial sequence features in signals, resulting in complex network construction and low localization accuracy. To address this issue, the text proposes a deep learning framework that utilizes an attention mechanism to train a small number of randomly continuously sampled spatial received signals to predict the coordinates of the received signals and encode the spatiotemporal sequence attributes of the received signals as a feature into the data, constructed a highly reliable spatiotemporal sequence attention mechanism for indoor visible light localization method. Combined with Convolutional Neural Networks (CNN), the localization accuracy is further improved. Through simulation experiments, it has been verified that the neural network structure designed in this paper has better positioning accuracy compared to advanced algorithms, and can still achieve centimeter‐level (9.886cm) average positioning error under low signal‐to‐noise ratio (SNR) conditions. It is proved that the method proposed in this paper is reliable in the indoor VLP system. Yonghao Yu 0001, Dawei Zhao 0001, Yongwei Tang, WengTak Kuok |
Concurr. Comput. Pract. Exp. | 2 |
| 2025 | DAN: Neural network based on dual attention for anomaly detection in ICS
Lijuan Xu 0001, Bailing Wang, Dawei Zhao 0001 |
Expert Syst. Appl. | 3 |
| 2025 | An intrusion response approach based on multi-objective optimization and deep Q network for industrial control systems
Yiqun Yue, Dawei Zhao 0001, Lijuan Xu 0001, Yongwei Tang, Haipeng Peng |
Expert Syst. Appl. | 2 |
| 2025 | TFHSVul: A Fine-Grained Hybrid Semantic Vulnerability Detection Method Based on Self-Attention Mechanism in IoTabstractCurrent vulnerability detection methods encounter challenges, such as inadequate feature representation, constrained feature extraction capabilities, and coarse-grained detection. To address these issues, we propose a fine-grained hybrid semantic vulnerability detection framework based on Transformer, named TFHSVul. Initially, the source code is transformed into sequential and graph-based representations to capture multilevel features, thereby solving the problem of insufficient information caused by a single intermediate representation. To enhance feature extraction capabilities, TFHSVul integrates multiscale fusion convolutional neural network, residual graph convolutional network, and pretrained language model into the core architecture, significantly boosting performance. We design a fine-grained detection method based on a self-attention mechanism, achieving statement-level detection to address the issue of coarse detection granularity. In comparison to existing baseline methods on public data sets, TFHSVul achieves a 0.58 improvement in F1 score at the function level compared to the best performing model. Moreover, it demonstrates a 10% enhancement in Top-10 accuracy at the statement-level detection compared to the best performing method. Lijuan Xu 0001, Baolong An, Xin Li 0002, Dawei Zhao 0001, Haipeng Peng, Weizhao Song, Fenghua Tong, Xiaohui Han |
IEEE Internet Things J. | 4 |
| 2025 | MACS-BNet: A Stealthy Multiconstraint Adversarial Backdoor Network Against Compressed LearningabstractDeep learning-based compressed sensing techniques have exhibited exceptional prowess in signal reconstruction and data-sharing applications, particularly within the realm of IoT sensor data processing. However, existing methods overlook a critical security vulnerability: the susceptibility of compressed sensing techniques to backdoor attacks during the reconstruction phase, which could pose severe security risks to downstream applications. This study pioneers an investigation into the feasibility of backdoor injection during the reconstruction phase, presenting the stealthy multi-constraint adversarial backdoor network against compressed learning (MACS-BNet) and substantiating its efficacy in subverting downstream classification tasks. MACS-BNet synergistically incorporates detailed sensing enhancement, fortified by local information relative positional encoding (LiRPE), to elevate image reconstruction fidelity. Concurrently, it employs a multi-constrained adversarial optimization that integrates sparsity, amplitude regulation, and spatial smoothness constraints, achieving an optimal trade-off between perturbation imperceptibility and attack efficacy. Consequently, victim models are subtly manipulated to yield outputs consistent with the attacker’s objectives. Extensive empirical evaluations reveal that MACS-BNet consistently surpasses seven cutting-edge attack methodologies across attack success rate, clean sample classification accuracy, and stealthiness under both all-to-one and all-to-all attack paradigms. Specifically, MACS-BNet attains an unparalleled clean classification accuracy of 99.52% and an attack success rate of 99.43% in the all-to-one mode, while simultaneously ensuring high-quality image reconstruction. Furthermore, MACS-BNet exhibits formidable resistance against detection by seven state-of-the-art defense mechanisms, underscoring its superior stealth and robustness. Wei Wu 0046, Haipeng Peng, Dawei Zhao 0001 |
IEEE Internet Things J. | 4 |
| 2025 | A Variant-Sensitive Malware Detection Method Based on Feature Contrast EnhancementabstractMalware poses a great threat to information security such as user data, privacy, and assets. Early detection before it has a real impact is the main countermeasure. However, the diversity of carriers and technologies has led to a huge gap between the training scenarios and actual scenarios of detection methods. This makes it difficult for supervision-based detection frameworks to identify new malware variants and complicates threat response. We propose a novel method that integrates frequency domain techniques with feature alignment to enhance variant malware detection, reducing distribution differences between labeled (source) and new (target) samples. By converting malware into grayscale images and applying discrete cosine transform (DCT) for improved feature extraction, followed by feature extraction via a deep residual network from both domains, our model systematically aligns features. This alignment is achieved through a tailored domain adaptation technique involving the minimization of classification and domain alignment losses, which ensures the consistent learning of features across varied domains. Such rigorous alignment not only enhances detection accuracy for both known and variant malware but also supports simultaneous detection across significant distribution differences. We conduct extensive experiments on two real-world datasets to evaluate the performance of various deep learning models under consistent and inconsistent domain distributions. Compared to existing methods, our approach improves accuracy by an average of 1.4% on the BIG2015 dataset, 3.2% on the MDA dataset, 2.75% on the Malimg dataset, and also achieves the best performance on the MaleVis dataset, with similar gains in precision, recall, and F1-score across all datasets. Shumian Yang, Jiarui Hu 0007, Xin Li 0002, Dawei Zhao 0001, Lijuan Xu 0001, Fuqiang Yu |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2025 | DRCAD: Dual-View Experts Routing and Counterfactual Generation for Explainable Time Series Anomaly DetectionabstractTime series anomaly detection is critical in domains such as cybersecurity monitoring, network operations, and industrial control systems. Lately, unsupervised anomaly detection methods that utilize contrastive learning have shown promise. However, existing approaches often struggle to model high-dimensional temporal dependencies efficiently and rely on rigid feature-fusion schemes that can inadvertently amplify noise. These factors increase computational overhead and sensitivity to irrelevant signals, hindering the capture of salient patterns. Additionally, the explainability of anomalies detected by these mechanisms is often limited, restricting their application in traceable detection processes and an explicit decision-making basis. In this paper, we propose dual-view experts routing and counterfactual generation for explainable time series anomaly detection (DRCAD), a novel framework that detects anomalies within time series data while providing intuitive and actionable explanations for model predictions. DRCAD uses in-patch and patch-wise perspectives as input views for the contrastive learning model, employing a flattened attention mechanism with lightweight spatial projections and a Patch Mixture of Experts (MoE) layer for adaptive routing and information fusion. It identifies anomalies by expanding the discrepancy between normal and anomalous points in the representation space, subsequently outputting anomaly scores. These anomaly scores guide the generation of counterfactual samples, integrating feature change tendencies with normalized feature impacts to derive a feature importance ranking as the explanation. We evaluate DRCAD on six widely used datasets, observe state-of-the-art (SOTA) performance. Moreover, in the explainability evaluation on SWaT dataset, DRCAD achieves superior realism and sparsity in counterfactual generation compared to existing methods, with top-ranked features closely matching officially documented attack characteristics. Dawei Zhao 0001, Lijuan Xu 0001, Zhen Wang 0004, Haipeng Peng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | GNN-ASG: A Double Feature Selection-based Adversarial Sample Generation Method in Industrial Control SystemabstractDue to the unique constraints of industrial control data, industrial control adversarial sample attacks are particularly challenging. Existing methods strive to conduct adversarial sample attacks under the conditions of satisfying industrial control data constraints, however, the results are not ideal. Therefore, this study proposes a new adversarial sample generation method GNN-ASG based on double feature selection. GNN-ASG uses data constraints to ensure the rationality of generated data, and uses Graph Deviation Network (GDN) and Autoencoder to improve the quality and versatility of adversarial samples. A new adversarial sample evaluation metrics Adversarial Sample Attack Impact Rate (ASAIR) is proposed to address the problem that existing evaluation metrics are difficult to accurately judge the effectiveness of adversarial sample attacks. This method considers the principle and application environment of adversarial samples, and fully demonstrates the practical effect of adversarial samples. In a comprehensive experiment conducted on three public datasets, GNN-ASG achieves an impressive ASAIR of 21.83%, higher than existing methods of 13.94%. This paper demonstrates the versatility and effectiveness of GNN-ASG by comparing its performance with three state-of-the-art adversarial sample generation methods on four anomaly detection models. GNN-ASG can maximally reduce the F1-Score of the detection model by 0.7605. Lijuan Xu 0001, Zhiang Yao, Dawei Zhao 0001, Xin Li 0002 |
CSCWD | 3 |
| 2024 | Knowledge Embedding Enabled Cyber Security Defense for Networked System: A Novel Risk Detection Method based on Knowledge GraphabstractKnowledge graph (KG) is universally recognized for Knowledge representation. However, valuable information is usually distributed across multi-source heterogeneous data, especially in cyberspace security, which increases the difficulty of mining latent risk in KG. In this paper, we define four kinds of knowledge patterns to form cyberspace security data, and use KG embedding methods to enable the computation and reasoning ability in low-dimensional vector space. Based on our method, we can enable more effective risk detection than common KG embedding methods. We conduct experiments on the Peng Cheng Cyber Range, the experimental results validate the higher prediction accuracy and detection performance. The method can greatly improve the cyberspace security defense capabilities for networked system. Angxiao Zhao, Wenying Feng 0003, Dawei Zhao 0001, Zhaoquan Gu |
CSCWD | 4 |
| 2024 | Multi-Interest Granularity Guided Semi-Joint Learning for N-Successive POI Recommendation
Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001, Lijuan Xu 0001 |
DASFAA (2) | 3 |
| 2024 | Speech Encryption Scheme Based on Chaotic Memristor Neural Network and S-Box
Dawei Zhao 0001, Chuan Chen 0001, Lixiang Li 0001, Ling Mi |
NLPCC (4) | 1 |
| 2024 | Adversarial sample attacks and defenses based on LSTM-ED in industrial control systems
Lijuan Xu 0001, Shumian Yang, Dawei Zhao 0001, Xin Li 0002 |
Comput. Secur. | 4 |
| 2024 | Dual-domain sampling and feature-domain optimization network for image compressive sensing
Xinxin Xiang, Fenghua Tong, Dawei Zhao 0001, Xin Li 0002, Shumian Yang |
Eng. Appl. Artif. Intell. | 3 |
| 2024 | Reinforcement learning and collective cooperation on higher-order networks
Juan Wang 0010, Dawei Zhao 0001, Mahmut Özer, Chengyi Xia, Matjaz Perc |
Knowl. Based Syst. | 4 |
| 2024 | Finding Component Relationships: A Deep-Learning-Based Anomaly Detection InterpreterabstractWhile the interpretability of deep learning (DL)-based models has been extensively explored in academia, applying existing interpretation methods to anomaly detection in industrial control systems (ICSs) poses challenges for two primary reasons. First, security experts in ICS have distinct interpretive priorities, emphasizing the need for stability and readability. Second, there are various types of device components in ICS, and the potential interactions between sensors and actuators are yet to be explored. To tackle the above challenges, we propose DeepINT, an interpreter for anomaly detection in ICS. In DeepINT, we adopt a search optimization algorithm to find the reference and capture feature importance by the backpropagation gradient to improve interpretation performance and reliability. In addition, we construct a finite difference-based interaction detection, which tests the interaction of different device components, in order to address the problem that actuators in ICS are not easily interpreted, meanwhile improving the comprehensiveness and accuracy of the interpretation results. In comprehensive experiments on two real water treatment datasets [secure water treatment (SWaT) and water distribution (WADI)], DeepINT shows excellent interpretation performance compared to the six state-of-the-art baseline methods, especially on the SWaT dataset, with a 60% improvement in interpretation accuracy. In addition, our method significantly improves the efficiency of interaction detection, which balances interpretation performance and time efficiency. Lijuan Xu 0001, Ziyu Han, Zhen Wang 0004, Dawei Zhao 0001 |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | Addressing Concept Drift in IoT Anomaly Detection: Drift Detection, Interpretation, and AdaptationabstractAnomaly detection plays a vital role as a crucial security measure for edge devices in Artificial Intelligence and Internet of Things (AIoT). With the rapid development of IoT ( Internet of Things), changes in system configurations and the introduction of new devices can lead to significant alterations in device relationships and data flows within the IoT, thereby triggering concept drift. Previously trained anomaly detection models fail to adapt to the changed distribution of streaming data, resulting in a high number of false positive events. This paper aims to address the issue of concept drift in IoT anomaly detection by proposing a comprehensive Concept Drift Detection, Interpretation, and Adaptation framework (CDDIA). We focus on accurately capturing the concept drift of normal data in unsupervised scenarios. To interpret drift samples, we integrate a search optimization algorithm and the SHAP method, providing a comprehensive interpretation of drift samples at both the sample and feature levels. Simultaneously, by utilizing the sample-level interpretation results for filtering new and old samples, we retrain the anomaly detection model to mitigate the impact of concept drift and reduce the false positive rate. This integrated strategy demonstrates significant advantages in maintaining model stability and reliability. The experimental results indicate that our method outperforms five baseline methods in adaptability across three datasets and provides interpretability for samples experiencing concept drift. Lijuan Xu 0001, Ziyu Han, Dawei Zhao 0001, Xin Li 0002, Fuqiang Yu, Chuan Chen 0001 |
IEEE Trans. Sustain. Comput. | 3 |
| 2023 | Image Compressed Sensing Using Multi-Scale Characteristic Residual LearningabstractDeep network-based image compressed sensing (CS) methods have attracted much attention in recent years due to their low reconstruction complexity and high reconstruction quality. However, the existing methods usually use one or multiple convolution layer(s) consisting of convolutional kernels with the same size to extract image features in image sampling, which results in incomplete feature extraction. Besides, the existing models usually focus on the extraction of deep features in image reconstruction, while ignoring the influence of shallow features. To overcome these issues, this paper proposes a multi-scale characteristic residual learning network (dubbed MSCRLNet) for image CS. In this network, convolutional kernels with different sizes are used to capture multi-level spatial features in image sampling, and a multi-scale residual network with channel attention is used to speed up network convergence in image reconstruction. Experiments show that the proposed MSCRLNet outperforms many existing state-of-the-art methods. Shumian Yang, Xinxin Xiang, Fenghua Tong, Dawei Zhao 0001, Xin Li 0002 |
ICME | 4 |
| 2023 | A Malicious Code Family Classification Method Based on RGB Images and Lightweight Model
Dawei Zhao 0001, Shumian Yang, Lijuan Xu 0001, Xin Li 0002 |
ICONIP (14) | 2 |
| 2023 | GRU-Based Interpretable Multivariate Time Series Anomaly Detection in Industrial Control SystemabstractInterpretable multivariate time series anomaly detection is an important technology to prevent accidents and ensure the reliable operation of Industrial Control Systems . A key limitation lies in the lack of a model to achieve better detection performance and more reliable interpretability , and keep a balance between performance efficiency and training optimization. In this paper, we propose GRN, an Interpretable Multivariate Time Series Anomaly Detection method based on neural graph networks and gated recurrent units (GRU). GRN can automatically learn potential correlations between sensors from multidimensional industrial control time series data , quickly mine long-term and short-term dependencies, to improve detection performance and help users to infer the root cause of detected anomalies . Based on GRU, GRN preserves the original advantages of processing the sequences and capturing the time series dependencies, moreover solves the problem of gradient disappearance and gradient explosion. We compare the performance of nine state-of-the-art algorithms on two real water treatment datasets (SWaT, WADI). GRN achieves better detection precision and recall. Meanwhile, the comparison of Area Under the Curve (AUC) demonstrates that GRN has the effect of maintaining balance between detection performance and training optimization. Compared with a Graph Deviation Network(GDN), GRN has achieved greater interpretability. Chaofan Tang, Lijuan Xu 0001, Yongwei Tang, Dawei Zhao 0001 |
Comput. Secur. | 5 |
| 2023 | ADTCD: An Adaptive Anomaly Detection Approach Toward Concept Drift in IoTabstractThe data collected by sensors is streaming data in the Internet of Things (IoT). Although existing deep-learning-based anomaly detection methods generally perform well on static data, they struggle to respond timely to streaming data after distribution changes. However, streaming data suffers from conceptual drift due to the highly dynamic nature of IoT. In network security, concept drift-oriented anomaly detection is a crucial task, because it can adjust the model to adapt to the latest data, and detect attacks in time. Existing streaming anomaly detection methods are confronted with some challenges, including the latency of model updates, the uneven importance of new data, and the self-poisoning due to model self-updates. To tackle the above challenges, we propose a knowledge distillation-based adaptive anomaly detection model toward concept drift, ADTCD. ADTCD transfers the knowledge of the teacher model to the student model and only updates the student model to reduce the delay. We construct an algorithm of dynamically adjusting model parameters, which dynamically adjusts model weights through local inference on new samples, in order to improve the model’s responsiveness to new distribution data, meanwhile solving the problem of uneven importance of new data. In addition, we adopt a one-class support vector-based outlier removal method to tackle the self-poisoning problem. In comprehensive experiments on seven high-dimensional data sets, ADTCD achieves an AUC improvement of 12.46% compared to the state-of-the-art streaming anomaly detection methods. Our future direction will focus on exploring the concept-drift problem using methods beyond autoencoders. Lijuan Xu 0001, Haipeng Peng, Dawei Zhao 0001, Xin Li 0002 |
IEEE Internet Things J. | 4 |
| 2023 | Coherence-penalty minimization method for incoherent unit-norm tight frame design
Fenghua Tong, Dawei Zhao 0001, Chuan Chen 0001, Lixiang Li 0001 |
Signal Process. | 2 |
| 2023 | Composite Effective Degree Markov Chain for Epidemic Dynamics on Higher-Order NetworksabstractEpidemiological models based on traditional networks have made important contributions to the analysis and control of malware, disease, and rumor propagation. However, higher-order networks are becoming a more effective means for modeling epidemic spread and characterizing the topology of group interactions. In this article, we propose a composite effective degree Markov chain approach (CEDMA) to describe the discrete-time epidemic dynamics on higher-order networks. In this approach, nodes are classified according to the number of neighbors and hyperedges in different states to characterize the topology of higher-order networks. By comparing with the microscopic Markov chain approach, CEDMA can better match the numerical simulations based on Monte Carlo and accurately capture discontinuous phase transitions and bistability phenomena caused by higher-order interactions. In particular, the theoretical solution to CEDMA can well predict the critical point at continuous phase transition and corroborate the existence of the discontinuous phase transition in the susceptible–infectious–susceptible (SIS) process. Moreover, CEDMA can be further extended to depict the susceptible–infectious–recovered (SIR) process on higher-order networks. Meiling Feng, Dawei Zhao 0001, Chengyi Xia, Zhen Wang 0004 |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2023 | BotFinder: a novel framework for social bots detection in online social networks based on graph embedding and community detection
Shudong Li, Chuanyu Zhao, Qing Li 0006, Jiuming Huang, Dawei Zhao 0001, Peican Zhu |
World Wide Web (WWW) | 5 |
| 2022 | Providing impersonation resistance for biometric-based authentication scheme in mobile cloud computing service
Yanrong Lu, Dawei Zhao 0001 |
Comput. Commun. | 2 |
| 2022 | Progressive coherence and spectral norm minimization scheme for measurement matrices in compressed sensing
Fenghua Tong, Lixiang Li 0001, Haipeng Peng, Dawei Zhao 0001 |
Signal Process. | 4 |
| 2021 | Minimum Dominating Set of Multiplex Networks: Definition, Application, and IdentificationabstractThe minimum dominating set (MDS) of the network is a node subset of smallest size that every node in the network is either in this subset or is adjacent to one or more nodes of this subset. MDS has found wide applications, ranging from network monitoring, routing, to epidemic control, and text processing. However, the majority of existing studies on MDS problem are confined to single networks. In real world, more and more complex systems consist of a set of elements linked up by different types of connections, which are best modeled as multiplex networks with interacting network layers. Though vastly important, the MDS of the multiplex networks has not yet been formally defined and its application and identification remain open issues. In this article, we present the definition of the MDS of the multiplex network and show some of its possible applications. For solving the MDS problem of the multiplex network, we built a spin-glass model and solve it through the belief-propagation (BP) equations under the replica symmetry mean-field theory. As a consequence, we can predict the relative size of the MDS of the multiplex network theoretically and we can propose a BP-guided decimation algorithm to construct an approximate optimal dominating set in practice. Then the algorithm is improved in both accuracy and efficiency by embedding a novel multiplex network-oriented leaf-removal strategy. The effectiveness of the proposed algorithms is finally verified by comparing with other methods on a number of the multiplex network examples. Dawei Zhao 0001, Gaoxi Xiao, Zhen Wang 0004, Lianhai Wang, Lijuan Xu 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2020 | PLC-SEIFF: A programmable logic controller security incident forensics framework based on automatic construction of security constraints
Lijuan Xu 0001, Bailing Wang, Lianhai Wang, Dawei Zhao 0001, Xiaohui Han, Shumian Yang |
Comput. Secur. | 4 |
| 2019 | Recognizing roles of online illegal gambling participants: An ensemble learning approach
Xiaohui Han, Lianhai Wang, Shujiang Xu, Dawei Zhao 0001, Guangqi Liu |
Comput. Secur. | 4 |
| 2019 | Virus Propagation and Patch Distribution in Multiplex Networks: Modeling, Analysis, and Optimal AllocationabstractEfficient security patch distribution is of essential importance for updating anti-virus software to ensure effective and timely virus detection and cleanup. In this paper, we propose a mixed strategy of patch distribution to combine the advantages of the traditional centralized patch distribution strategy and decentralized patch distribution strategy. A novel network model that contains a central node and a multiplex network composed of patch dissemination network layer and virus propagation network layer is presented, and a competing spreading dynamical process on top of the network model that simulates the interplay between virus propagation and patch dissemination is developed. Such a new framework helps in effectively analyzing the impacts of patches distribution on virus propagation, and developing more realizable schemes for restraining virus propagation. Furthermore, considering the constraints of the capacity of the central node and the bandwidth of network links, an optimal allocation approach of patches is proposed, which could simultaneously optimize multiple dynamical parameters to effectively restrain the virus propagation with a given budget. Dawei Zhao 0001, Lianhai Wang, Zhen Wang 0004, Gaoxi Xiao |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Role Recognition of Illegal Online Gambling Participants Using Monetary Transaction Data
Xiaohui Han, Lianhai Wang, Shujiang Xu, Dawei Zhao 0001, Guangqi Liu |
ICICS | 4 |
| 2017 | Linking social network accounts by modeling user spatiotemporal habitsabstractIdentifying the physical person behind an SNS account has become a critical issue in investigations of SNS-involved crime cases. It is a challenging task because information provided by users on an SNS platform could be false, conflicting, missing and deceptive. One way to gain an accurate profile of a user is to link up all their multiple accounts created on different social platforms, which is referred to as Account Linkage (AL). However, existing AL techniques suffer from the problem of information unreliability. Recent advances in location acquisition and wireless communication technologies give rise to new opportunities for AL. In this paper, we propose a framework that links up multiple accounts belonging to the same individual by comparing habit patterns extracted from user-generated location data. We built a topic model to capture users habit patterns in both spatial and temporal dimensions. Results of experiments carried out on a real-world dataset demonstrate the feasibility and validity of the proposed framework. Xiaohui Han, Lianhai Wang, Shujiang Xu, Guangqi Liu, Dawei Zhao 0001 |
ISI | 5 |
| 2014 | Novel way to research nonlinear feedback shift register
Dawei Zhao 0001, Haipeng Peng, Lixiang Li 0001, SiLi Hui, Yixian Yang |
Sci. China Inf. Sci. | 1 |