VLDB 2026 Research / reviewers in the wild / expert
Yan Wang 0173
dblp:59/2227-173
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0004-3040-3131ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Warning-Graph: An Early Warning Framework for APT Attacks Based on Threat Intelligence ModelingabstractAdvanced Persistent Threats (APTs) have become increasingly sophisticated and covert, necessitating the acquisition of an overall view of the rapidly evolving cyber threat landscape by security defenders. However, integrating threat intelligence from diverse sources poses significant challenges due to limited labeled data and noise interference. To address the requirement for the early detection of APT attacks, this paper introduces a lightweight framework named Warning-Graph, based on threat intelligence modeling. Warning-Graph leverages a limited set of IoCs to infer the type of ongoing APT attack. Initially, attack-related infrastructure nodes are modeled as a heterogeneous information network. Subsequently, heterogeneous graph contrastive learning is employed for pre-training. Two asymmetric graph encoders are constructed to obtain node embeddings without the need to generate negative samples or labeled data. In addition, a loss function based on the information bottleneck is specifically employed to reduce the noise in the original graph. In downstream tasks, multiclass classifiers are trained using embedding representations with fewer labeled samples. Experimental results demonstrate that the proposed framework achieves a 3- to 5-point increase in identification performance for APT attack types compared to baselines, while utilizing fewer labeled samples. Sanfeng Zhang 0002, Yan Wang 0173, Qingyu Hao, Yujie Hou, Linfeng Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | BWG: An IOC Identification Method for Imbalanced Threat Intelligence DatasetsabstractAPT attacks are becoming increasingly complex and stealthy. To effectively counter APT attacks, modelling threat intelligence data based on graphs, identifying Indicators of Compromise (IOC) nodes, and providing early warnings have become new research hotspots. However, the problem of node category imbalance in such graph datasets restricts the identification capabilities of these methods. Therefore, this paper proposes a supervised graph data augmentation method. In the training phase, graph disentangled representation learning is utilized to perform feature embedding for minority class nodes, effectively alleviating the sparsity problem faced by traditional methods and effectively integrating neighbourhood information of minority class nodes at a higher semantic level. Additionally, two loss functions designed based on link prediction and prototype constraints enhance node type consistency and semantic consistency, respectively. Experimental results on the APT and PDNS datasets demonstrate that the proposed method outperforms other baseline models in identification performance; even in highly imbalanced scenarios, it surpasses the second-best model. Juncheng Lu, Yan Wang 0173, Jiyuan Cui, Sanfeng Zhang 0002 |
TrustCom | 3 |
| 2024 | MDD-FedGNN: A vertical federated graph learning framework for malicious domain detection
Sanfeng Zhang 0002, Qingyu Hao, Zijian Gong, Fengzhou Zhu, Yan Wang 0173 |
Comput. Secur. | 5 |