VLDB 2026 Research / reviewers in the wild / expert
Qian Wang 0009
dblp:75/5723-9
· DBLP profile ↗
29ranked-venue papers
12as first author
23since 2021 · last 2026
0000-0001-7159-1424ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Security and privacy · 7 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A lesion region awareness and adaptive label-relation graph algorithm for multi-label chest X-ray image classification
Qian Wang 0009, Weilun Meng, Congfan Gan, Hongnian Yu, Yongqiang Cheng 0001 |
Eng. Appl. Artif. Intell. | 1 |
| 2026 | Vul2image: A quick image-inspired and CNN-based vulnerability detection system
Rong Ren, Mushi Zhou, Ni Liao, Bing Zhang 0011, Guoyan Huang, Haitao He, Qian Wang 0009 |
Expert Syst. Appl. | 7 |
| 2026 | A multi-label chest X-ray image classification algorithm based on multi-scale and attribute-aware semantic graph
Qian Wang 0009, Zhijuan Wu, Jiyu Gao, Hongnian Yu, Yongqiang Cheng 0001 |
Expert Syst. Appl. | 1 |
| 2026 | TPP: A temporal-enhanced propagation probability model for identifying influential nodes in complex networks
Bing Zhang 0011, Rong Ren, Jiadong Ren, Qian Wang 0009 |
Expert Syst. Appl. | 5 |
| 2026 | SSRFinder: SSRF vulnerability detection and validation based on program dependency graphs and pre-trained models
Bing Zhang 0011, Chenhua Lou, Yanxuan Lou, Rong Ren, Qian Wang 0009 |
Expert Syst. Appl. | 5 |
| 2026 | PRWHA: RGB Image-Based Hybrid Attention for Cross-File SQLI/XSS Vulnerability Detection in PHP Web ApplicationsabstractAs the most widely used server-side programming language for web applications, PHP has a large number of SQL injection (SQLI) and cross-site scripting (XSS) vulnerabilities that are exploited maliciously, making the detection of such vulnerabilities increasingly critical. Existing source code detection methods suffer from issues such as uncleaned redundant information, limited representation dimensions and poor detection performance. To address these challenges, we propose a PHP vulnerability detection method based on RGB image representation and hybrid attention mechanisms — PHP ResNet with Hybrid Attention (PRWHA). First, PRWHA marks the input sources and sensitive functions, constructs data flow and control flow graphs between source and sink points and adds function call edges. This method uniquely identifies nodes in the graph using filenames and line numbers to enable inter-procedural and cross-file detection. Next, it leverages both the topological information (including data flow, control flow and function call relationships) and textual information of the code’s graph structure to generate RGB images. These images are then processed by a ResNet-50 model enhanced with a hybrid attention layer to detect SQLI and XSS vulnerabilities. To validate the effectiveness of PRWHA, we evaluated it on both publicly available datasets and real-world software datasets. The results demonstrate that PRWHA outperforms traditional methods as well as other machine learning, deep learning and Large Language Model (LLM)-based detection approaches. On the public dataset, PRWHA achieved an accuracy of 99.00% and an F1-score of 97.13% on the test set. On the real-world software dataset, it achieved an accuracy of 73% and a vulnerability detection rate of approximately 83.67%. Rong Ren, Qingyu Song 0006, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2026 | HVDet: Heap Vulnerability Detection Method Based on P-PDG Representation and Bi-GRU AlgorithmabstractHeap vulnerabilities pose a significant risk to software, leading to stability issues such as slowdown and resource depletion. These vulnerabilities can potentially disrupt critical operations and compromise the overall system performance, especially in the case of automated control systems implemented in C/C[Formula: see text] language. While various artificial intelligence-based detection methods have been studied, there has been limited analysis of the detection process and the structural and semantic features, resulting in lower detection efficiency. This paper proposes a novel heap vulnerability detection (HVDet) method based on the Pointer Program Dependency Graph (P-PDG) representation and Bidirectional Gated Recurrent Unit (Bi-GRU) algorithm for software. Through inter-procedural analysis, the P-PDG serves as an innovative code representation model that places emphasis on pointer operations, which are closely associated with heap vulnerabilities. It leads to a reduction in code size while simultaneously capturing a broader range of structural and semantic features of the source code. Subsequently, a mixed feature matrix incorporating these features from code slices is generated as input for the Bi-GRU algorithm. When compared with 7 state-of-the-art (SOTA) vulnerability detection tools, HVDet demonstrates superior performance. It successfully identified three heap vulnerabilities in real-world software such as Linux Kernel, Espruino and LibreDWG. Rong Ren, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2026 | Multi-label ECG diagnosis via adversarial view decoupling and hierarchical label constraints
Weilun Meng, Qian Wang 0009, Congfan Gan, Hongnian Yu, Yongqiang Cheng 0001 |
Knowl. Based Syst. | 2 |
| 2026 | A Domain Adaptive IoT Intrusion Detection Algorithm Based on AEC-GAT Feature Extraction and Joint Domain AdversaryabstractThe high heterogeneity of Internet of Things (IoT) devices causes severe imbalance in network traffic data, and the cost of collecting and labeling sufficient intrusion samples is high or impossible, resulting in data scarcity in IoT security. Therefore, this article proposes a domain adaptive IoT intrusion detection algorithm based on causal embedding autoencoder and a graph attention network (AEC–GAT) feature extraction and joint domain adversary, which leverages abundant data resources from traditional network intrusion detection to improve the detection accuracy in IoT environments. First, a feature extraction method combining an AEC–GAT is designed. The AEC uses causal inference to uncover deep semantic links between domains, while GAT captures device interaction patterns to enhance semantic relevance and structure awareness in the features. Second, to address the pronounced class imbalance in IoT datasets, focal loss is introduced to replace the traditional cross-entropy (CE) loss. This formulation dynamically adjusts the sample weight through the scaling factor to guide the algorithm to focus on the minority samples that are difficult to classify. Meanwhile, a class adaptive independent domain discriminator method is proposed, which incorporates a class-level alignment mechanism within a joint adversarial training method. This method dynamically adjusts both the training intensity and the loss weight of each class specific domain discriminator. The experimental results show that the algorithm in this article significantly improves the detection performance of IoT intrusion detection by migrating traditional network intrusion detection domain knowledge, and has superior performance in various indicators compared to existing algorithms. Qian Wang 0009, Menghui Fan, Zhijuan Wu, Hongnian Yu, Yongqiang Cheng 0001, Bing Zhang 0011 |
IEEE Trans. Ind. Informatics | 1 |
| 2025 | Interprocedural Call Graph Embedding with GAT for Memory safety Vulnerability DetectionabstractMemory safety vulnerabilities remain a critical threat to software security, often leading to system crashes, data leakage, and service disruptions. Existing deep learning-based detection methods mainly rely on intra-procedural analysis, which limits their ability to capture complex memory behaviors involving pointer variable flows across function boundaries. This study proposes IpGAT, an InterProcedural memory vulnerability detection framework based on Graph Attention Network (GAT) that aims to overcome the limitations of intra-procedural approaches by modeling cross-function data flows of pointer variables. IpGAT constructs an Interprocedural Program Call Graph (IpCG) that integrates Abstract Syntax Trees (AST), Control Flow Graphs (CFG), and Data Flow Graphs (DFG) to represent memory-sensitive function interactions. The IpCG is embedded using Word2Vec and then fed into a GAT for vulnerability classification. Experimental results show that IpGAT achieves an accuracy of 88.9%, a precision of 86.5%, and an F1-score of 89.1%, significantly outperforming six state-of-the-art tools and intra-procedural baselines. Furthermore, IpGAT successfully identified eight real-world memory safety vulnerabilities in open-source projects such as ffdshow, Libav, Seamonkey, and VLC, all of which have been confirmed in the CVE database. By incorporating interprocedural analysis and graph-based learning, IpGAT effectively captures the semantics of memory-sensitive operations and demonstrates strong generalizability across both benchmark datasets and real-world software. Rong Ren, JingYi Wu, HongBo Jin, QingYu Song, Bing Zhang 0011, Qian Wang 0009 |
TrustCom | 6 |
| 2025 | MalRGBDet: Windows Malware Detection Method Based on RGB Image Representation and Heterogeneous Neural NetworkabstractAs the world’s most widely used operating system, Windows has long been a primary target for malware attacks, causing severe economic losses and threats to data security for users and enterprises. Existing detection methods often struggle with low accuracy when dealing with complex malware, suffering from high false-negative and false-positive rates. Additionally, malware detection in Windows faces challenges such as limited datasets, a lack of benign sample contrast and insufficient original feature information. To address these issues, we propose a malware detection method based on RGB image representation and heterogeneous neural network (MalRGBDet). First, we collected malware samples from the GitHub and VirusShare platforms, along with benign software from Windows systems, to build a dataset named MalDet. This data set contains unprocessed malicious and benign samples, providing original feature information and addressing the lack of benign samples in existing data sets. Next, we extracted three key features from the malware samples: code sections, data sections and API call sequences. These features closely relate to the behavior of malware and accurately describe its operations. We then transformed these features into uniformly sized RGB images, which helped reveal hidden patterns. Finally, we employ a heterogeneous neural network that integrates ResNet and AlexNet for classification. ResNet, with its deep architecture and residual learning mechanism, significantly enhances the model’s representation capability and classification performance, thereby improving detection accuracy. Meanwhile, AlexNet’s Dropout regularization strategy effectively boosts the model’s generalization ability. In our data set of 1952 Windows software samples, MalRGBDet achieved more than 95% in accuracy, precision, recall and F1-score, improving these metrics by up to 4% compared to the latest methods. Furthermore, false-negative and false-positive rates were kept below 5%. Rong Ren, Hongchang Zhang, Bing Zhang 0011, Haitao He, Guoyan Huang, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 6 |
| 2025 | Multi-Stage Network Attack Detection Algorithm Based on Gaussian Mixture Hidden Markov Model and Transfer LearningabstractMulti-stage network attack (MSA) is a serious threat to data security. The high-dimensionality of the alert data along with the diverse features, leads to poor detection performance for MSA. Consequently, this paper proposes a multi-stage network attack detection algorithm based on Gaussian mixture hidden Markov model and transfer learning. Firstly, a sequence modeling framework of Gaussian mixture hidden Markov models is proposed. It uses a Gaussian mixture model to cluster high-dimensional alert data and a hidden Markov model to fully consider the temporal structure of MSA, the alert features of each stage, and transitions between stages. Secondly, optimized Baum-Welch and Viterbi algorithms are proposed, combined with the forward-backward algorithm to train the parameter of the Gaussian mixture hidden Markov model and detect the attack sequence of MSA. Finally, an improved transfer learning method is proposed, which addresses the sparsity of labeled data in MSA scenarios, a Kullback-Leibler (KL) divergence value is added as a penalty term to narrow the distribution differences between the source and target domains and solves the bias problem in the transfer learning process. The proposed algorithm is validated on the datasets DARPA 2000 and CSE-CIC-IDS2018, and the effectiveness and superiority is verified on multiple evaluation indicators.Note to Practitioners—Network attacks gradually show the large-scale, coordinated and multi-stage characteristics. Complex multi-step attacks with strong concealment and persistence have become the development trend of network attacks, which seriously threaten and infringe the secure storage and transmission of information. Most existing studies use hidden Markov model (HMM) to model multi-stage network attacks. HMM is usually more suitable for multi-step attacks occurring in a specific sequence within a continuous time interval. However, in actual multi-stage network attacks, attackers do not need to follow the exact sequence of multi-step attacks, and the intervals between successive stages of an attack can be hours, days, or even months. Attackers may also perform interleaved attacks to hide attacks. Therefore, this paper proposes a multi-stage network attack detection algorithm based on Gaussian hybrid hidden Markov and transfer learning. The optimized Gaussian hybrid hidden Markov model is used to model the alert data of multi-stage network attacks, and the improved transfer learning method is adopted to apply the knowledge learned from the source domain to the multi-stage network attack detection model of the target domain. The experimental results show that the proposed algorithm can effectively process the alert data of different attack stages under complex multi-stage network attacks, distinguish the real threat alert, false alert and irrelevant alert, and improve the performance of detecting multi-stage network attacks. The method presented in this paper can provide a valuable solution for complex multi-stage network attack detection such as advanced persistent threat (APT). Future work will further combine adversarial generation network methods to avoid the interference of adversarial attack samples, and explore more ways to improve the performance of multi-step attack detection. Qian Wang 0009, Jiadong Ren, Bing Zhang 0011 |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2024 | An intrusion detection algorithm based on joint symmetric uncertainty and hyperparameter optimized fusion neural network
Qian Wang 0009, Haiyang Jiang 0006, Jiadong Ren, Xuehang Wang, Bing Zhang 0011 |
Expert Syst. Appl. | 1 |
| 2024 | Approach to Detect Windows Malware Based on Malicious Tendency Image and ResNet AlgorithmabstractTimely detection of self-replicating malware in the high market share Windows operating system can effectively prevent personal or corporate financial losses. The form and characteristics of malware are constantly evolving, leading to a concept drift issue that gradually decreases the effectiveness of traditional detection methods. Therefore, we propose WinMDet, a Windows malware detection method based on malicious tendency image and ResNet algorithm. First, to tackle the complexity and difficulty in accurately characterizing malware features, WinMDet retains detailed malware features and encodes them into malicious tendency images to better describe malware across different periods. Secondly, WinMDet utilizes previously generated malicious tendency images to train the initial detection model. Then, to alleviate the issue of malware concept drift, WinMDet employs Local Maximum Mean Discrepancy (LMMD) as the criterion for model transfer, enhancing the initial detection model’s ability to distinguish between malware and benign software. We conducted a comprehensive evaluation of WinMDet using common metrics such as accuracy, precision and recall. The results indicate that WinMDet performs remarkably well in terms of accuracy, exceeding 82%. Additionally, significant improvements were observed in precision and recall, surpassing 82.42% and 82.06%, respectively. After employing our LMMD-based transfer method, the initial detection model improved the detection accuracy of malware in 2021 and 2022 by approximately 4.22% to 8.06%. The false negative rate decreased by at most 4.34%, and the false positive rate decreased by at most 4.61%. Bing Zhang 0011, Hongchang Zhang, Rong Ren, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2024 | A Domain Adaptive IoT Intrusion Detection Algorithm Based on GWR-GCN Feature Extraction and Conditional Domain AdversaryabstractIn the field of Internet of Things (IoT), the intrusion detection data is scarce because of the network security and privacy. This article proposes a domain adaptive IoT intrusion detection algorithm based on GWR-GCN feature extraction and conditional domain adversary, which aims to improve intrusion detection in the IoT domain by learning from other intrusion detection domains with rich data. First, a GWR-GCN-based domain-invariant feature extraction method is proposed, where the growing when required network (GWR) calculates the correlation between the original data, and the related data is connected into a graph by the Hebb learning principle. The graph convolutional neural network (GCN) is used to mine the feature information of the graph-structured data and extract the optimal domain-invariant features. Second, a Copula-based data distribution alignment method is proposed to decompose the overall feature distribution difference between the source and target domains into the marginal distribution difference of a single feature and the joint distribution difference between features. Meanwhile, the correlation between features on the data distribution is considered to further reduce the data distribution difference and improve the cross-domain ability. Finally, a conditional domain adversarial intrusion detection model is proposed to improve the detection performance by adding the class information as a condition in the discriminator, considering the correlation between features and classes, and reducing the effect of domain shift on distributional alignment. In order to verify the proposed algorithm, experiments are conducted on the traditional network and the IoT domain data sets, and the superiority is verified on multiple evaluation indicators. Qian Wang 0009, Xuehang Wang, Jiadong Ren, Bing Zhang 0011 |
IEEE Internet Things J. | 1 |
| 2023 | An automatic classification algorithm for software vulnerability based on weighted word vector and fusion neural network
Qian Wang 0009, Yuying Gao, Jiadong Ren, Bing Zhang 0011 |
Comput. Secur. | 1 |
| 2023 | DetAC: Approach to Detect Access Control Vulnerability in Web Application Based on Sitemap Model with Global Information RepresentationabstractAccess control vulnerabilities that lead to elevated privileges are among the most dangerous vulnerabilities in Web applications. Most of the existing detection methods use dynamic or static analysis techniques alone, which suffer from high manual involvement, low automation, high leakage rate, low page coverage, and other deficiencies. To this end, this paper proposes a novel access control vulnerability detection method (DetAC) based on a sitemap model with global information representation. This method first constructs a static site-wide sitemap model based on the page link addresses in the Web application source code through static analysis techniques. After that, the application is logged in and executed dynamically with different role users. During this process, execution traces and request parameters are collected and converted into annotations to fill the corresponding edges of the static site-wide sitemap model. Then, the sitemap model with global information representation is obtained. This model can represent both the global control flow and data flow of the application. Then DetAC analyzes the role-based and user-based access control policies of the Web application based on the node reachability and annotated data features of the model. And according to the information such as role, user, and access resources, it generates attack vectors to achieve different roles and the same role of different users to access each other’s resources. Finally, access control vulnerabilities are detected based on the equivalence of the results obtained using attack vector access and normal access to the Web application server. DetAC was validated on five real open-source Web applications, and the results showed that DetAC successfully detected up to 12 access control vulnerabilities, which are more than those of the traditional seven tools. The dynamic analysis page coverage rate was significantly improved during the detection process, reaching an average of 91.37%. Jiadong Ren, Mingyou Wu, Bing Zhang 0011, Shangyang Li, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 6 |
| 2022 | Identifying Influential Spreaders in Complex Networks Based on Degree Centrality
Qian Wang 0009, Jiadong Ren, Honghao Zhang, Bing Zhang 0011 |
WISA | 1 |
| 2022 | An approach for predicting multiple-type overflow vulnerabilities based on combination features and a time series neural network algorithm
Zhangqi Zheng, Bing Zhang 0011, Yongshan Liu, Jiadong Ren, Qian Wang 0009 |
Comput. Secur. | 6 |
| 2022 | Intrusion Detection Algorithm Based on Convolutional Neural Network and Light Gradient Boosting MachineabstractAiming at the limitations of existing algorithms of network intrusion detection in dealing with complex data of imbalance and high dimensionality, this paper proposes an intrusion detection algorithm based on convolutional neural network (CNN) and Light Gradient Boosting Machine (LightGBM). First, the data-type conversion, oversampling technology and image data conversion are included in the data preprocessing to make the data balanced and adapt to the input format. Then, by the convolutional layer, pooling layer and fully connected layer of the CNN model, the main features are abstracted from the converted image data. Finally, data of the main features is used for training and testing the LightGBM model, so as to get the final classification results. This paper uses KDDCUP99 dataset to carry out multi-classification experiments. By comparing the experiments before and after balancing the dataset, and comparing with similar algorithms, it verifies the superiority of the proposed algorithm in the classification performance of intrusion detection, especially for the minority attack classes. Qian Wang 0009, Wenfang Zhao, Jiadong Ren, Yuying Gao, Bing Zhang 0011 |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2022 | Approach to Predict Software Vulnerability Based on Multiple-Level N-gram Feature Extraction and Heterogeneous Ensemble LearningabstractSoftware vulnerabilities are one of the roots of computer security problems. The traditional static analysis and dynamic analysis methods based on software source code mainly have some deficiencies, such as high false positive rate, high false negative rate and insufficient semantic information captured. Nevertheless, the application of machine learning, Natural Language Processing and other technologies in software vulnerability prediction can effectively mitigate such issues. This paper proposed a vulnerability prediction method based on multiple-level N-gram feature extraction and heterogeneous ensemble learning. First, by code intermediate representation and constructing a multiple-level N-gram feature generation model, two kinds of N-gram semantic features with different window size and different granularity at word and char level were extracted to retain the semantic and structural information of code. Second, TF–IDF was used to construct the vector space model as the input of prediction model. As a single classifier was prone to overfitting and poor generalization, this paper conducted benchmark testing on five classical machine learning algorithms (NB, SVM, DT, LR, RF), and then combined four (SVM, DT, LR, RF) among them, which had better performance as the base classifiers to form the stacking heterogeneous ensemble method to build the vulnerability prediction model. Finally, the proposed method was verified on buffer overflow vulnerability and resource management vulnerability datasets, with a lowest false positive rate and false negative rate which can reach 1.58% and 4.06%, respectively. Bing Zhang 0011, Qian Wang 0009, Jiadong Ren |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2022 | An automatic algorithm for software vulnerability classification based on CNN and GRU
Qian Wang 0009, Jiadong Ren |
Multim. Tools Appl. | 1 |
| 2021 | Low-rate DDoS attacks detection method using data compression and behavior divergence measurement
Xinqian Liu, Jiadong Ren, Haitao He, Qian Wang 0009 |
Comput. Secur. | 4 |
| 2019 | A Novel Algorithm for Identifying Key Function Nodes in Software Network Based on Evidence TheoryabstractIn a software network system, it is of great significance to identify key functions for software fault detection and maintenance. In order to better understand the characteristics and internal structure of software, a key Node Discovery algorithm based on Evidence Theory called NDET is proposed in this paper. First, the software complex network model is constructed according to the execution process of the software. Based on the Dempster-Shafer evidence theory (D-S evidence theory), the discernment frame is formed, the maximum and minimum values of the network degree and strength are determined. Second, the Basic Probability Assignment (BPA) of each node degree is calculated by considering the node degree distribution ratio value. Third, based on Dempster’s rule of combination, the evidential centrality of the node itself and the fluctuation value of the node influenced by neighbor nodes are considered for the key measurement. Finally, by using the Susceptible–Infected–Recovered (SIR) model to simulate the spreading process on real software networks, the performance of NDET is evaluated. Experiment results verify the validity and accuracy of NDET for identifying key function nodes in software. Qian Wang 0009, Chun Shan, Jiadong Ren |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2019 | Mining the Key Nodes from Software Network Based on Fault Accumulation and PropagationabstractThe increasement of software complexity directly results in the augment of software fault and costs a lot in the process of software development and maintenance. The complex network model is used to study the accumulation and accumulation of faults in complex software as a whole. Then key nodes with high fault probability and powerful fault propagation capability can be found, and the faults can be discovered as soon as possible and the severity of the damage to the system can be reduced effectively. In this paper, the algorithm MFS_AN (mining fault severity of all nodes) is proposed to mine the key nodes from software network. A weighted software network model is built by using functions as nodes, call relationships as edges, and call times as weight. Exploiting recursive method, a fault probability metric FP of a function, is defined according to the fault accumulation characteristic, and a fault propagation capability metric FPC of a function is proposed according to the fault propagation characteristic. Based on the FP and FPC, the fault severity metric FS is put forward to obtain the function nodes with larger fault severity in software network. Experimental results on two real software networks show that the algorithm MFS_AN can discover the key function nodes correctly and effectively. Guoyan Huang, Qian Wang 0009, Xinqian Liu, Xiaobing Hao, Huaizhi Yan |
Secur. Commun. Networks | 2 |
| 2019 | Building an Effective Intrusion Detection System by Using Hybrid Data Optimization Based on Machine Learning AlgorithmsabstractIntrusion detection system (IDS) can effectively identify anomaly behaviors in the network; however, it still has low detection rate and high false alarm rate especially for anomalies with fewer records. In this paper, we propose an effective IDS by using hybrid data optimization which consists of two parts: data sampling and feature selection, called DO_IDS. In data sampling, the Isolation Forest (iForest) is used to eliminate outliers, genetic algorithm (GA) to optimize the sampling ratio, and the Random Forest (RF) classifier as the evaluation criteria to obtain the optimal training dataset. In feature selection, GA and RF are used again to obtain the optimal feature subset. Finally, an intrusion detection system based on RF is built using the optimal training dataset obtained by data sampling and the features selected by feature selection. The experiment will be carried out on the UNSW-NB15 dataset. Compared with other algorithms, the model has obvious advantages in detecting rare anomaly behaviors. Jiadong Ren, Jiawei Guo 0003, Qian Wang 0009, Yuan Huang 0012, Xiaobing Hao, Hu Jingjing |
Secur. Commun. Networks | 3 |
| 2018 | Security Feature Measurement for Frequent Dynamic Execution Paths in Software SystemabstractThe scale and complexity of software systems are constantly increasing, imposing new challenges for software fault location and daily maintenance. In this paper, the Security Feature measurement algorithm of Frequent dynamic execution Paths in Software, SFFPS, is proposed to provide a basis for improving the security and reliability of software. First, the dynamic execution of a complex software system is mapped onto a complex network model and sequence model. This, combined with the invocation and dependency relationships between function nodes, fault cumulative effect, and spread effect, can be analyzed. The function node security features of the software complex network are defined and measured according to the degree distribution and global step attenuation factor. Finally, frequent software execution paths are mined and weighted, and security metrics of the frequent paths are obtained and sorted. The experimental results show that SFFPS has good time performance and scalability, and the security features of the important paths in the software can be effectively measured. This study provides a guide for the research of defect propagation, software reliability, and software integration testing. Qian Wang 0009, Jiadong Ren, Yongqiang Cheng 0001, Darryl N. Davis, Changzhen Hu |
Secur. Commun. Networks | 1 |
| 2017 | Mining Frequent Patterns for Item-Oriented and Customer-Oriented AnalysisabstractFrequent pattern mining can well extract insight from transaction patterns, and it is a desired capability for fully understanding the customer's purchase behavior. However, most of the algorithms are focus on the transverse relationship and the longitudinal analysis is missed. To address this defect, FP-ICA, a Frequent Pattern mining algorithm for Item-oriented and Customer-oriented Analysis is proposed. A pattern with its items occur in the same transaction is item-oriented, and a pattern with its items occur cross several transactions of a customer is customer-oriented. FP-ICA transforms the transactions to a bitmap which contains a header for recording customer information, and the frequent patterns are obtained by logic And-operation. Different mining rules are used for item-oriented and customer-oriented discovery. Experiments are conducted to demonstrate the fast speed achievement and good scalability of FP-ICA. Wenzhe Liao, Qian Wang 0009, Jiadong Ren, Yongqiang Cheng 0001, Changzhen Hu |
WISA | 2 |
| 2017 | Mining Frequent Intra-Sequence and Inter-Sequence Patterns Using Bitmap with a Maximal SpanabstractFrequent intra-sequence pattern mining and inter-sequence pattern mining are both important ways of association rule mining for different applications. However, most algorithms focus on just one of them, as attempting both is usually inefficient. To address this deficiency, FIIP-BM, a Frequent Intra-sequence and Inter-sequence Pattern mining algorithm using Bitmap with a maxSpan is proposed. FIIP-BM transforms each transaction to a bit vector, adjusts the maximal span according to user's demand and obtains the frequent sequences by logic And-operation. For candidate 2-pattern generation, the subscripts of the joining items should be checked first; the bit vector of the joining item will be left-shifted before calculation if the subscript is not 0. Left alignment rule is used for different bit vector length problems. FIIP-BM can mine both intra-sequence and inter-sequence patterns. Experiments are conducted to demonstrate the computational speed and memory efficiency of the FIIP-BM algorithm. Wenzhe Liao, Qian Wang 0009, Luqun Yang, Jiadong Ren, Darryl N. Davis, Changzhen Hu |
WISA | 2 |