Wenmao Liu

dblp:62/9032 · DBLP profile ↗
← Back
29ranked-venue papers
1as first author
25since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 7 since 2021Computer networks · 8 · 8 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Towards Efficient and Reliable Training Assurance of Untrusted Federated Learning Participants Under Hardware Non-Determinism
abstract
Federated learning (FL) is a popular privacy-preserving machine learning paradigm, enabling collaborative training across participants without exposing local data. Since FL loses direct control over participants' training executions, a fundamental requirement is to verify that participants faithfully perform the assigned training tasks. In this paper, we present TrustFL+, an efficient, scalable, and reliable verification scheme that ensures the training correctness of federated learning participants by leveraging both Trusted Execution Environments (TEEs) and GPUs. Essentially, it pushes all local training on high-performance but untrusted GPUs, while the TEE replicates the random parts for tunable levels of assurance. A key challenge is that hardware non-determinism can cause the same floating-point operations to yield different results between GPUs and TEEs, leading to false positives when participants behave honestly. TrustFL+ builds on deterministic training by recording rounding directions of intermediate operations during GPU-side model training and reusing them in TEE-based verification. It especially introduces adaptive rounding precisions to practically control non-determinism while maintaining global model performance in federated learning systems with lots of heterogeneous GPUs and iterative training. We prototype TrustFL+ using a range of NVIDIA GPUs covering multiple hardware architectures, along with Intel SGX, and evaluate its performance across convolutional neural networks and transformer-based networks. The experimental results demonstrate that TrustFL+ delivers up to an order of magnitude speedup compared to naive SGX-based training. Furthermore, all models trained with TrustFL+ on different GPU architectures successfully pass verification within SGX, resulting in 0 false positives.
Xiaoli Zhang 0003, Jiaqing Cheng, Wenmao Liu, Xiaohu Ye, Ke Xu 0002, Qi Li 0002, Xu-Cheng Yin
IEEE Trans. Dependable Secur. Comput.4
2026 Characterizing Network-Layer Vulnerabilities in LiDAR Subsystems of Autonomous Vehicles: A Mechanism-Aware Propagation Analysis
Rujun Hu, Angang Feng, Lei Xue 0001, Kelei Zhang, Wenmao Liu, Xiapu Luo
IEEE Trans. Inf. Forensics Secur.5
2026 Do Not Fall Into the Trap: Efficiently Discovering IPv6 Fully Responsive Prefixes in the Wild
Lin He 0004, Chentian Wei, Daguo Cheng, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu
IEEE Trans. Netw.12
2025 TA-PDC: Provable Data Contribution with Traceable Anonymous for Group Transactions
Xiaocong Lin, Weijing You, Wenmao Liu
ICICS (1)4
2025 Critical Node-aware Augmentation for Hypergraph Contrastive Learning
abstract
Hypergraph contrastive learning enables effective representation learning for hypergraphs without requiring labels. However, existing methods typically rely on randomly deleting or replacing nodes during hypergraph augmentation, which may lead to the absence of critical nodes and further disrupt the higher-order structural relationships within augmented hypergraphs. To address this issue, we propose a Critical Node-aware hypergraph contrastive learning method, which is the first attempt to leverage hyperedge prediction to retain critical nodes and accordingly maintain the reliable higher-order structural relationships within augmented hypergraphs. Specifically, we first employ contrastive learning to align the augmented hypergraphs, and then generate hyperedge embeddings to characterize node representations and their structural correlations. During the hyperedge embedding encoding process, we introduce a hyperedge prediction discriminator to score these embeddings, which quantifies the nodes' contributions to identify the critical nodes and maintain the higher-order structural relationships within augmented hypergraphs. Compared with previous studies, our proposed method can effectively alleviate the erroneous deletion or replacement of critical nodes and steadily maintain the inherent structural relationships between original hypergraph and augmented hypergraphs, naturally guiding better hypergraph representations for downstream tasks. Extensive experiments on various tasks demonstrate that our method is significantly superior to state-of-the-art methods.
Yuena Lin, Yipeng Wang 0001, Wenmao Liu, Mingliang Yu, Zhen Yang 0004, Gengyu Lyu
IJCAI4
2025 CertBA: A Decentralized Authentication Scheme via Blockchain and Dynamic Cryptographic Accumulator
Wenmao Liu, Wei Ren 0002, Xianchao Zhang 0002
KSEM (4)2
2025 Adversarial Example Based Fingerprint Embedding for Robust Copyright Protection in Split Learning
abstract
Currently, deep learning models are easily exposed to data leakage risks. As a distributed model, Split Learning thus emerged as a solution to address this issue. The model is splitted to avoid data uploading to the server and reduce computing requirements while ensuring data privacy and security. However, the transmission of data between clients and server creates a potential vulnerability. In particular, model is vulnerable to intellectual property (IP) infringement such as piracy. Alarmingly, a dedicated copyright protection framework tailored for Split Learning models is still lacking. To this end, we propose the first copyright protection scheme for Split Learning model, leveraging fingerprint to ensure effective and robust copyright protection. The proposed method first generates a set of specifically designed adversarial examples. Then, we select those examples that would induce misclassifications to form the fingerprint set. These adversarial examples are embedded as fingerprints into the model during the training process. Exhaustive experiments highlight the effectiveness of the scheme. This is demonstrated by a remarkable fingerprint verification success rate (FVSR) of 100% on MNIST, 98% on CIFAR-10, and 100% on ImageNet, respectively. Meanwhile, the model’s accuracy only decreases slightly, indicating that the embedded fingerprints do not compromise model performance. Even under label inference attack, our approach consistently achieves a high fingerprint verification success rate that ensures robust verification.
Zhangting Lin, Mingfu Xue, Wenmao Liu, Liquan Chen
TrustCom3
2025 A Lightweight Transformation Method for Privacy Protection in Image Classification
Wei Ren 0002, Wenmao Liu, Xianchao Zhang 0002, Tianqing Zhu
WASA (3)4
2025 A Context-Aware Clustering Approach for Assisting Operators in Classifying Security Alerts
abstract
Modern software has evolved from delivering software products to web services and applications, which need to be protected by security operation centers (SOC) against ubiquitous cyber attacks. Numerous security alerts are continuously generated every day, which have to be efficiently and correctly processed to identify potential threats. Many AIOps (artificial intelligence for IT operations) approaches have been proposed to (semi-)automate the inspection of alerts so as to reduce manual effort as much as possible. However, due to the ever-complicating attacks, a significant amount of manual work is still required in practice to ensure correct analysis results. In this paper, we propose a Context-Aware cLustering approach for cLassifying sEcurity alErts (CALLEE), which fully exploits the rich relationships among alerts in order to precisely identify similar alerts, significantly reducing the workload of SOC. Specifically, we first design a core conceptual model to capture connections among security alerts, based on which we establish corresponding heterogeneous information networks. Next, we systematically design a set of meta-paths to profile typical alert scenarios precisely, contributing to obtaining the representation of security alerts. We then cluster security alerts based on their contextual similarities, considering the tradeoff between the number of clusters and the homogeneity of each cluster. Finally, security operators only need to manually inspect a limited number of alerts within each cluster, pragmatically reducing their workload while ensuring the accuracy of alert classification. To evaluate the effectiveness of our approach, we collaborate with our industrial partner and pragmatically apply the approach to a real alert dataset. The results show that our approach can reduce the workload of SOC by 99.76%, outperforming baseline approaches. In addition, we further investigate the integration of our proposal with the real business scenario of our industrial partner. The feedback from practitioners shows that CALLEE is pragmatically applicable and helpful in industrial settings.
Yu Liu 0090, Tong Li 0001, Runzi Zhang, Mingkai Tong, Wenmao Liu, Zhen Yang 0004
IEEE Trans. Software Eng.6
2024 Masked Transformer-based Multi-GAN for 5G Core Network KPI Anomaly Detection
abstract
The fifth generation (5G) network is a crucial foundation for the industrial Internet. Key performance indicator (KPI) anomaly detection in the 5G core network (5GC) plays a pivotal role in 5G applications. Some researchers have introduced Generative Adversarial Networks (GAN)-based techniques to detect anomalies. However, these methods remain limited, such as pattern collapse. In this paper, we propose MTMG, a Masked Transformer-based Multi-GAN model, to achieve highly accurate and robust anomaly detection. We use Transformer to learn the associations between data better. Specifically, MTMG employs multiple generators and a discriminator to deflect the pattern collapse dilemma. In addition, we introduce the mask mechanism to learn the normal distribution of data better and prevent the model degradation caused by anomalies in the training set. We also adopt a root cause strategy to locate the anomalies. Experimental results demonstrate that our model outperforms the baselines significantly in terms of detection performance.
Enze Zhao, Peng Li 0046, Zhang Cheng, Wenmao Liu, Lei Nie 0004, Haizhou Bao, Qin Liu 0003
CSCWD4
2024 A Data Watermark Scheme Base on Data Converted Bitmap for Data Trading
Wei Ren 0002, Wenmao Liu, Xianghan Zheng
ICA3PP (4)3
2024 Luori: Active Probing and Evaluation of Internet-Wide IPv6 Fully Responsive Prefixes
abstract
With the large-scale deployment and application of IPv6, IPv6 network measurements will become increasingly important. However, a special type of IPv6 prefix called Fully Responsive Prefix (FRP) is having a significant impact on IPv6 measurement campaigns, which is defined as all addresses under a prefix responding to scans. Obviously, there cannot be a real responder behind each of these addresses. To reveal the current status and impact of Internet-wide IPv6 FRPs, we propose for the first time an active probing method for Internet-wide IPv6 FRPs, Luori, which transforms the active probing process under IPv6 huge prefix space (potential range of prefix presence) into a dynamic search process in a tree based on reinforcement learning, achieving efficient probing of arbitrary routing prefixes. The evaluation results show that Luori found 31.7K largest FRPs in a single Internet-wide probing with 11 M budget, covering$1.5 \times 10^{30}$address space, which is$10^{6} \times$that of existing methods. More importantly, after six months of Internet-wide probing, we have found 516 K largest FRPs, which covers$1.3 \times 10^{33}$address space and 795 ASes, making it the largest publicly known FRP list. Based on this list, we screen out$20 \%$of the addresses covered by FRPs from a well-known IPv6 active address dataset. Furthermore, we further analyze and find that the distribution of these FRPs is extensive and their implementation methods are diverse, which can provide beneficial references for the practical application of FRPs. We also make this list publicly available and maintain it long-term for use and study by relevant researchers.
Daguo Cheng, Lin He 0004, Chentian Wei, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu
ICNP12
2024 Multivariate time series anomaly detection by fusion of deep convolution residual autoencoding reconstruction model and ConvLstm forecasting model
Hongsong Chen, Wenmao Liu
Comput. Secur.3
2024 BABD: A Bitcoin Address Behavior Dataset for Pattern Analysis
abstract
Cryptocurrencies have dramatically increased adoption in mainstream applications in various fields such as financial and online services, however, there are still a few amounts of cryptocurrency transactions that involve illicit or criminal activities. It is essential to identify and monitor addresses associated with illegal behaviors to ensure the security and stability of the cryptocurrency ecosystem. In this paper, we propose a framework to build a dataset comprising Bitcoin transactions between 12 July 2019 and 26 May 2021. This dataset (hereafter referred to as BABD-13) contains 13 types of Bitcoin addresses, 5 categories of indicators with 148 features, and 544,462 labeled data, which is the largest labeled Bitcoin address behavior dataset publicly available to our knowledge. We also propose a novel and efficient subgraph generation algorithm called BTC-SubGen to extract a${k}$-hop subgraph from the entire Bitcoin transaction graph constructed by the directed heterogeneous multigraph starting from a specific Bitcoin address node. We then conduct 13-class classification tasks on BABD-13 by five machine learning models namely${k}$-nearest neighbors algorithm, decision tree, random forest, multilayer perceptron, and XGBoost, the results show that the accuracy rates are between 93.24% and 97.13%. In addition, we study the relations and importance of the proposed features and analyze how they affect the effect of machine learning models. Finally, we conduct a preliminary analysis of the behavior patterns of different types of Bitcoin addresses using concrete features and find several meaningful and explainable modes.
Yuexin Xiang, Yuchen Lei, Ding Bao, Tiantian Li 0004, Wenmao Liu, Wei Ren 0002, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.6
2024 On Smartly Scanning of the Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and real-world experiments demonstrate that our system can scan up to around 40 times as many IP-device mapping mutations as random/sequential scanning.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.3
2023 Unsupervised Graph-Sequence Anomaly Detection for 5G Core Network Control Plane Traffic
abstract
5G Core network (5GC) employs a Service Based Architecture (SBA). This architecture decomposes the control plane into multiple independent Network Functions (NFs). NFs open interfaces to provide services to other NFs, which makes the control plane more susceptible to external malicious attacks. However, existing anomaly detection methods focus more on traffic statistics features and are difficult to apply to the 5GC control plane. In this paper, we proposed GSAD, a Graph-Sequence analysis-based Anomaly Detection method for 5GC control plane traffic. We model control plane traffic as a directed graph to depict topological and NF interaction information. Further, we use the normalizing flows with temporal dependencies to mine the sequential information in the traffic. GSAD combines the topological and sequential information to provide fine-grained detection. We evaluate our proposed framework on the 5GC testbed using Free5GC and UERANSIM in various scenarios. Experimental results demonstrate that our framework outperforms the baselines significantly in terms of detection performance.
Peng Li 0046, Zhang Cheng, Wenmao Liu, Lei Nie 0004, Haizhou Bao, Qin Liu 0003
ICPADS4
2023 Who is DNS serving for? A human-software perspective of modeling DNS services
Jian Qu, Xiaobo Ma 0001, Wenmao Liu
Knowl. Based Syst.3
2022 Landing Reinforcement Learning onto Smart Scanning of The Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and find that our system would achieve growing advantages with the proliferation of IoT devices.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
INFOCOM3
2022 Threat identification model for suspected Internet of Things attack groups
abstract
In order to solve the problem that the general intrusion detection model cannot effectively identify the increasingly complex, multi-source, and organized collaborative attacks. This paper proposed a threat identification model for suspected Internet of Things attack groups. Firstly, this paper constructed a PBT feature model from the three-dimensionality of attack path, attack behavior and attack time. Secondly, the paper used spectral clustering algorithm to cluster attackers to effectively identify suspected Internet of Things attack groups. Finally, a threat assessment model was proposed to classify different suspected attack groups into threat levels, and corresponding defensive measures were proposed based on this level to achieve a complete IoT threat early warning system. The experimental results showed that the model proposed in this paper can more effectively identify suspected Internet of Things attack groups, and is of great significance for improving the Internet of Things defense system.
Wenmao Liu, Hongqing Sang
ICSS3
2022 Context2Vector: Accelerating security event triage via context representation learning
Runzi Zhang, Wenmao Liu, Dujuan Gu, Mingkai Tong, Jianxin Xue, Huanran Wang
Inf. Softw. Technol.3
2022 Towards time evolved malware identification using two-head neural network
Chong Yuan, Jingxuan Cai, Donghai Tian, Rui Ma 0004, Xiaoqi Jia, Wenmao Liu
J. Inf. Secur. Appl.6
2022 Real-Time Prediction of Docker Container Resource Load Based on a Hybrid Model of ARIMA and Triple Exponential Smoothing
abstract
More and more enterprises are beginning to use Docker containers to build cloud platforms. Predicting the resource usage of container workload has been an important and challenging problem to improve the performance of cloud computing platform. The existing prediction models either incur large time overhead or have insufficient accuracy. This article proposes a hybrid model of the ARIMA and triple exponential smoothing. It can accurately predict both linear and nonlinear relationships in the container resource load sequence. To deal with the dynamic Docker container resource load, the weighting values of the two single models in the hybrid model are chosen according to the sum of squares of their predicted errors for a period of time. We also design and implement a real-time prediction system that consists of the collection, storage, prediction of Docker container resource load data and scheduling optimization of CPU and memory resource usage based on predicted values. The experimental results show that the predicting accuracy of the hybrid model improves by 52.64, 20.15, and 203.72 percent on average compared to the ARIMA, the triple exponential smoothing model and ANN+SaDE model respectively with a small time overhead.
Yulai Xie 0002, Minpeng Jin, Zhuping Zou, Gongming Xu, Dan Feng 0001, Wenmao Liu, Darrell D. E. Long
IEEE Trans. Cloud Comput.6
2022 Inferring Hidden IoT Devices and User Interactions via Spatial-Temporal Traffic Fingerprinting
abstract
With the popularization of Internet of Things (IoT) devices in smart home and industry fields, a huge number of IoT devices are connected to the Internet. However, what devices are connected to a network may not be known by the Internet Service Provider (ISP), since many IoT devices are placed within small networks (e.g., home networks) and are hidden behind network address translation (NAT). Without pinpointing IoT devices in a network, it is unlikely for the ISP to appropriately configure security policies and effectively manage the network. Additionally, inferring fine-grained user interactions of IoT devices is also an interesting yet unresolved problem. In this paper, we design an efficient and scalable system via spatial-temporal traffic fingerprinting from an ISP’s perspective in consideration of practical issues like learning-testing asymmetry. Our system can accurately identify typical IoT devices in a network, with the additional capability of identifying what devices are hidden behind NAT and the number of each type of device that share the same IP address. Our system can also detect user interactions and meanwhile identify their (concurrent) number through a multi-output regression model. Through extensive evaluation, we demonstrate that the system can generally identify IoT devices with an F1-Score above 0.999, and estimate the number of the same type of IoT device behind NAT with an average error below 5%. By studying 29 user interactions of 7 devices, we show that our system is promising in detecting user interactions.
Xiaobo Ma 0001, Jian Qu, Jianfeng Li 0006, John C. S. Lui, Zhenhua Li 0001, Wenmao Liu, Xiaohong Guan
IEEE/ACM Trans. Netw.6
2021 MDCHD: A novel malware detection method in cloud using hardware trace and deep learning
Donghai Tian, Qianjin Ying, Xiaoqi Jia, Rui Ma 0004, Changzhen Hu, Wenmao Liu
Comput. Networks6
2021 An Evolutionary Study of IoT Malware
abstract
Recent years have witnessed lots of attacks targeted at the widespread Internet of Things (IoT) devices and malicious activities conducted by compromised IoT devices. After some notorious IoT malware released their source code, many new variants emerge, which are usually more powerful and stealthy. Although numerous existing studies have analyzed some exposed families, there is a lack of systematic study to make full use of them, which can be a fundamental step for provenance, triage, labeling, lineage analysis, and authorship attribution. The key challenge of conducting an IoT malware evolutionary study is how to collect sufficient and accurate information about malware and identify the relationships among them. In this article, we take the first step to investigate the IoT malware evolution by leveraging the information from two sources that complement each other. First, we crawl online articles about IoT malware and employ natural language processing techniques to extract the features of malware samples and their relationships with other malware family, which allow us to form the basic lineage graph. Second, we collect real malware samples through our widely deployed honeypots and design a new classifier to group them into families and identify lineage relationships among them. Such results are used to enhance the basic lineage graph. Eventually, we construct the final lineage graph for 72 IoT malware families by correlating the information from the aforementioned sources, which can help the research community better understand and fight IoT malware now and in the future. Our study has been incorporated into the threat awareness system of NSFOCUS company.
Huanran Wang, Weizhe Zhang, Peng Liu 0005, Xiapu Luo, Yang Liu 0039, Yan Li 0075, Wenmao Liu, Runzi Zhang, Xing Lan
IEEE Internet Things J.10
2020 Far from classification algorithm: dive into the preprocessing stage in DGA detection
abstract
Domain-Flux technique has been widely used by attackers to maintain a botnet for many years and the core of it is the adoption of domain generation algorithm (DGA). To combat attackers, there are lots of works in DGA domain detection area recently. But they usually collect quite limited data and conduct experiments in a closed dataset, meaning that the DGA data and the benign data they collected can not well represent the real distribution between them. Moreover, they handle the domains roughly and use the origin data to train the classifier directly, which is also not adequate to classify these two types of domains with lots of false positives and false negatives happening during the real-world deployment. In this paper, we conduct the first large-scale DGA domain analysis in traffic level and argue that the preprocessing stage is also vital for the final classifier, which is usually ignored by the existing works. We collect the largest amount of DGA domain data than prior works and collect DNS log offered by a big company, whose DNS data covers most important industries in China. Based on this data, we analyze the distribution of DGA domains in traffic and give quantifiable results showing that NXDomain (domain not exist) is more suitable for DGA detection. Moreover, we give detailed preprocessing steps to handle the original domains. Our experiment shows that with the preprocessing stage mentioned above, classifier performs better in DGA detection task. Our research indicates that improving the classification algorithm is far from enough in DGA detection and the preprocessing stage is also the key component in bringing the DGA detection methods from lab to product.
Mingkai Tong, Runzi Zhang, Jianxin Xue, Wenmao Liu, Jiahai Yang 0001
TrustCom5
2020 CMIRGen: Automatic Signature Generation Algorithm for Malicious Network Traffic
abstract
Although machine learning (ML) based solutions are ever-evolving for the attack defending paradigm, signatures of malicious network traffic are vital resources for intrusion detection systems (IDSs) and network forensic procedure, covering the lack of interpretability and stability for ML models. However, signature extraction is still a time and labor consuming task nowadays, resulting in possible increase of the attackers' dwell time. Existing automatic solutions rely too much on sequence similarity based and heuristic based methods, encountering performance degradation in large scale and dynamic network environment. In this paper, we present a novel method, called Clustering and Model Inference-based Rule Generation (CMIRGen), automatically generating token-set based signature rules for malicious traffic payloads to be inspected. CMIRGen leverages both optimized sequence similarity based and black-box model inference based methods to extract patterns from homogeneous and heterogeneous payloads respectively. Experimental evaluations have been conducted on several datasets and show the CMIRGen framework can extract discriminative signatures, presenting high recall rate and low false positive rate at the same time for malicious content recognition.
Runzi Zhang, Mingkai Tong, Jianxin Xue, Wenmao Liu
TrustCom5
2019 A Combined Micro-block Chain Truncation Attack on Bitcoin-NG
Ziyu Wang 0009, Jianwei Liu 0001, Zongyang Zhang, Yanting Zhang 0002, Jiayuan Yin, Wenmao Liu
ACISP7
2010 A General Distributed Object Locating Architecture in the Internet of Things
abstract
This paper proposes a novel platform for object locating application in the Internet of Things environment. In this platform, objects and inquirers access and query locations using uniform service entry interfaces in heterogeneous services. To build a virtual storage system, services entries integrate enterprise database clusters and a DHT peer-to-peer network built with inquirers' devices. The DHT network is originally designed for accurate object locating, to enable fuzzy object locating we construct a hierarchical storage overlay network based on the DHT network. This LBS platform simplifies the object locating operation for ordinary inquirers greatly, moreover it provides huge virtual computing and storage resources for small companies and individual developers.
Wenmao Liu, Lihua Yin, Weizhe Zhang, Hongli Zhang 0001
ICPADS1