VLDB 2026 Research / reviewers in the wild / expert
Guozi Sun
dblp:91/1406
· DBLP profile ↗
52ranked-venue papers
4as first author
33since 2021 · last 2026
0000-0003-1888-7001ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 2 first-author · 10 since 2021Databases, data management, data science and information retrieval · 10 · 6 since 2021Artificial intelligence and machine learning · 7 · 5 since 2021Security and privacy · 6 · 3 since 2021Software engineering, systems software and programming languages · 6 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VKB-Hunter: Vulnerability Knowledge Base Based Black-box Protocol Fuzzer for IoT Devices
Zhijin Chen, Jiemin Wan, Guozi Sun |
COMPSAC | 4 |
| 2026 | Towards Multi-Label Text Interpretation with Chain-of-Thought Prompting and Contextualized KnowledgeabstractExisting multi-label topic models face several challenges when interpreting texts annotated with multiple labels: (1) they often associate irrelevant text segments with incorrect labels, which negatively impacts both segment and label interpretation; (2) they fail to effectively capture the semantic relationships between tokens and labels within the segment; (3) they do not integrate contextualized knowledge that could improve interpretability. To overcome these issues, we introduce the Contextualized Prompting Topic Model (CPTM). CPTM utilizes Chain-of-Thought (CoT) prompting to better align text segments with their semantically relevant labels. Furthermore, it integrates label-specific token visualization and topic mining procedure to facilitate the interpretation of tokens and labels. Experimental evaluations conducted on three multi-label text datasets show that CPTM significantly outperforms existing models in both segment and label interpretation. Human assessments also verify CPTM's effectiveness in accurately identifying label-relevant tokens within segments and providing insightful token-level interpretation. Rui Wang 0043, Haiping Huang, Jialin Yu 0001, Guozi Sun |
WWW | 6 |
| 2026 | A lightweight UAV authentication scheme in blockchain-assisted fog networks
Haoran Ji, Liefeng Cao, Junmin Cao, Guozi Sun |
Comput. Networks | 4 |
| 2026 | A comprehensive survey on table question answering: Datasets, methods and future directions
Weiqiang Xu 0003, Yang Liu 0490, Lingfeng Lu, Huakang Li, Guozi Sun |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | PawsPro: A proactive Paw-shaped framework for predictive modeling and optimal decision in hard drive failure prevention
Bin Xia 0003, Junmin Cao, Guozi Sun |
Future Gener. Comput. Syst. | 5 |
| 2026 | NASchecker: Automatically Identifying the Performance, Security, and Privacy Issues of NAS DevicesabstractNetwork attached storage (NAS) devices are widely deployed for personal data storage. However, their distributed architecture and limited inspection interfaces pose significant challenges for comprehensive performance, security, and privacy analysis. In this paper, we first establish a threat model for NAS ecosystems. Then, we present a systematic framework NASchecker for discovering performance optimization mechanisms, security threats, and privacy leakage in NAS devices. By analyzing traffic generated during varied file operations on crafted files, NASchecker infers implemented optimizations and identifies security flaws within the traffic (e.g., susceptibility to passive sniffing and replay attacks). NASchecker also integrates NAS-specific protocol fuzzing and firmware reverse engineering to uncover deep-seated command injection, memory corruption, and improper access control vulnerabilities. NASchecker compares personally identifiable information (PII) leaked in traffic against declarations in privacy policies to detect privacy compliance issues. We evaluated NASchecker on twelve commercial NAS devices. Our results reveal that none of the tested devices employ file compression or deduplication. From a security standpoint, ten devices are vulnerable to passive sniffing and seven to replay attacks. Moreover, seven devices are affected by command injection, four by memory corruption, and eleven by improper access control. From a privacy perspective, four devices leaked PIIs that were not disclosed in their respective privacy policies. After reporting the findings to the manufacturers, we have been acknowledged by several manufacturers, resulting in the assignment of 20 CVEs and 6 NVDB entries (16 of them are rated as high severity). These findings validate NASchecker’s effectiveness and underscore the urgent need for improved design and testing practices of NAS. Guangyue Ren, Le Yu 0002, Liping Han, Mingzhe Hu, Wei Chen 0006, Tingting Liu 0005, Xiapu Luo, Guozi Sun |
IEEE Internet Things J. | 9 |
| 2026 | BISE: Enhance data sharing security through consortium blockchain and IPFS
Mingxuan Chen, Puhe Hao, Weizhi Meng 0001, Yasen Aizezi, Guozi Sun |
J. Inf. Secur. Appl. | 5 |
| 2026 | Auditable cross-domain data sharing via threshold secret sharing and zero-knowledge proofsabstractCross-domain data sharing in decentralised environments faces persistent challenges related to confidentiality, auditability, and trust decentralisation, particularly when data transmission relies on centralised intermediaries or single proxy entities. To address these issues, this paper proposes a blockchain-enabled auditable data sharing scheme that integrates threshold secret sharing with non-interactive zero-knowledge proofs. In the proposed framework, the encrypted file fragments and secret key shares are decentralised across multiple blockchain nodes using threshold cryptography, preventing any single entity from reconstructing the encryption key or unilaterally performing ciphertext transformations. Zero-knowledge proofs are employed to publicly verify the correctness of the transmission and sharing operations without disclosing plaintexts, secret keys, or sensitive metadata, while the blockchain records verifiable proofs to support tamper-evident auditing. Security analysis shows that the scheme achieves confidentiality, collusion resistance, and verifiable correctness under standard cryptographic assumptions.Experimental evaluations indicate that the proposed scheme incurs acceptable computational and on-chain overhead, suggesting its feasibility in decentralised and cross-domain data sharing scenarios. Yuyang Yan, Zhexuan Yang, Junmin Cao, Weizhi Meng 0001, Guozi Sun |
J. Inf. Secur. Appl. | 5 |
| 2026 | Assessing the capability of android dynamic analysis tools to combat anti-runtime analysis techniques
Dewen Suo, Lei Xue 0001, Weihao Huang, Runze Tan, Guozi Sun |
J. Syst. Softw. | 5 |
| 2026 | Blockchain-based privacy-preserving authentication protocol for UAV cross-domainabstractAs unmanned aerial vehicles (UAVs) become increasingly integral in domains such as agriculture, logistics, and military operations, secure cross-domain authentication mechanisms are essential. Existing centralized protocols are prone to single points of failure, privacy vulnerabilities, and physical capture risks. This paper presents a novel blockchain-based, privacy-preserving authentication protocol for UAVs operating across multiple domains. By combining zero-Knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) and physical unclonable functions (PUFs), the proposed protocol ensures secure identity verification without disclosing sensitive information. The blockchain platform offers a decentralized, tamper-resistant environment for UAV authentication, addressing the challenges of scalability, privacy, and security in cross-domain operations. We demonstrate the security and effectiveness of the protocol through formal and informal security proofs and performance evaluations. The results indicate that the proposed protocol outperforms traditional methods, achieving significant reductions in both computational and communication costs while maintaining high security standards. Liefeng Cao, Haoran Ji, Quanwei Wang, Guozi Sun |
Peer Peer Netw. Appl. | 4 |
| 2026 | PingTactics: A Multimodal Dataset for Table Tennis Action Recognition and Tactical AnalysisabstractIn this article, we introduce PingTactics, a multimodal dataset tailored for table tennis action recognition and tactical analysis. Derived from professional table tennis matches, the dataset comprises annotated video clips capturing detailed player actions, positional dynamics, and scoring outcomes. A key feature of PingTactics is its comprehensive temporal annotation framework, which includes sequences of previous and next actions, enabling the study of fine-grained action relationships and their tactical implications. We ensured annotation quality through a semi-automated pipeline that combines machine-assisted pre-labeling with manual refinement by domain experts. To validate the dataset, we conducted extensive experiments using state-of-the-art deep learning models for action recognition, demonstrating PingTactics’ effectiveness for capturing the complex and dynamic action patterns typical of high-stakes matches. Beyond action recognition, PingTactics serves as a foundation for tactical evaluation, as evidenced by our quadrant-based scoring analysis, which reveals interaction patterns, key scoring strategies, and player tendencies. By offering fine-grained action annotations and enabling tactical insights, PingTactics provides a significant resource for advancing research in sports analytics, with implications for intelligent coaching, player performance evaluation, and strategic planning in table tennis and related domains. Lejun Gong, Ziyi Wei, Guozi Sun |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2025 | Towards Efficient and Auditable Heterogeneous Data Management in Vehicular Edge NetworksabstractWith the continuous and rapid development of the Internet of Vehicles, vehicular data is experiencing explosive growth. Vehicular edge computing and blockchain have been proposed to face this challenge, but today's data service providers find it challenging to adequately meet the demands of efficiency and security in time-sensitive scenarios with huge data volumes and heterogeneous data types. In this paper, we propose an efficient vehicular data management scheme to expand storage capacity and operational efficiency. Specifically, we coupled blockchain and the Interplanetary File System (IPFS) to tackle the heterogeneous data type issue. Attribute-based searchable encryption is exploited to facilitate the data management process. Real-time data tracker is proposed to enforce personalized driver behavior auditing and data tracking. We implement a prototype system based on FIBOS1blockchain platform. Experiments conducted show the storage efficiency of the system with a 98.76% storage reduction ratio and the high speed with a performance of approximately 1300 TPS (Transactions per second). The security analysis shows the promise of ensuring data confidentiality, integrity, and security. Puhe Hao, Mingfa Wan, Teng Yuan, Guozi Sun |
CSCWD | 6 |
| 2025 | Multi-Agent Deep Reinforcement Learning for Integrated Sensing and Communication in RIS-aided UAV NetworksabstractIntegrated Sensing and Communication (ISAC) is regarded as a promising approach to improve the original performance for unmanned aerial vehicle (UAV) networks. Nevertheless, it is still limited by the UAV's energy constraints and dynamic links with user equipment (UE). To address these issues, we attempt to deploy the Reconfigurable Intelligent Surface (RIS) for signal reflection, improving sensing and communication performance. Additionally, employing downlink-uplink decoupling (DUDe) can enable each UE to associate with diverse UAVs for downlink (DL) and uplink (UL), further enhancing transmission quality. Therefore, we study the RIS deployment, decoupled UE- UAV association and trajectory design for a RIS-aided UAV network. A joint optimization problem is formulated for maximizing the sum rate in UL and DL. Specifically, we transform the joint problem as a Markov Decision Process, and employ a distributed multi-agent deep reinforcement learning (MADRL) approach to select policies. Moreover, we develop a robust Proximal Policy Optimization (PPO) algorithm to train the AC networks, wherein the Random Environment Distribution is utilized for adapting to varying scenarios and we design an intrinsic reward to expand UAV s' exploration range. Simulation results validate the feasibility and superiority of the RED-PPO approach through comparative analysis. Chen Dai, Yiping Zuo, Guozi Sun |
CSCWD | 4 |
| 2025 | Mining User Preferences from Online Reviews with the Genre-aware Personalized Neural Topic ModelabstractCustomer-generated reviews on e-commerce websites often contain valuable insights into users' interests in product genres and provide a rich source for mining user preferences. However, most existing neural topic models tend to generate meaningless topics that share low correlations with product genres. Furthermore, they often fail to mine user preferences and discover personalized topic profiles due to the absence of explicit user modeling. To address these limitations, we propose a novel Genre-aware Personalized neural Topic Model (GPTM), which incorporates product genre information into the topic modeling process to ensure the relevance between mined topics and product genres. Moreover, it could produce a personalized topic profile for each user by performing user preference modeling. Extensive experimental results on three publicly available Amazon review corpora validate the effectiveness of the proposed GPTM in genre-aware topic modeling. Furthermore, GPTM surpasses state-of-the-art baselines in user preference mining and generates high-quality personalized topic profiles. Rui Wang 0043, Xincheng Lv, Shuyu Chang, Yansheng Wu, Yuanzhi Yao, Haiping Huang, Guozi Sun |
WWW | 8 |
| 2025 | Overcoming emergency HTTP/3 DDoS attack detection: A domain adaptation solution with graph neural network
Ziyi Wei, Guozi Sun |
Comput. Networks | 4 |
| 2025 | COIChain: Blockchain scheme for privacy data authentication in cross-organizational identification
Zhexuan Yang, Xiao Qu, Zeng Chen, Guozi Sun |
Comput. Commun. | 4 |
| 2025 | Number-enhanced relational graph encoding with hierarchical tree decoding for numerical reasoning
Weiqiang Xu 0003, Yang Liu 0490, Huakang Li, Guozi Sun |
Knowl. Based Syst. | 4 |
| 2025 | Learning multi-granularity representation with transformer for visible-infrared person re-identification
Yujian Feng, Feng Chen 0047, Guozi Sun, Fei Wu 0004, Yimu Ji 0001, Tianliang Liu, Shangdong Liu, Xiaoyuan Jing, Jiebo Luo 0001 |
Pattern Recognit. | 3 |
| 2025 | Distributed Keyword-guided Topic Model with Lexical Knowledge SupervisionabstractTopic models are often used to discover latent semantic patterns from document collections. However, existing unsupervised approaches have the following drawbacks: (1) The mined topics may not match user interests; (2) They are prone to extract semantically similar topics and sacrifice diversity; (3) The mined topics often have low interpretability, which does not meet common sense knowledge. To address these limitations, we propose the Distributed Keyword-guided Topic Model (DiskTM) that incorporates Gaussian-distributed keyword prior knowledge into the modeling process to mine user-interested topics. Furthermore, to inject common-sense knowledge and improve the topic’s interpretability, we extend DiskTM and propose the Distributed Keyword-guided Topic Model with Lexical Knowledge (DiskTM-LK). Experimental results on three publicly available text corpora show that our proposed approaches could extract topics that match user interests (keywords). Moreover, DiskTM and DiskTM-LK could also obtain more coherent and diverse topics, outperforming the state-of-the-art baseline approaches. Rui Wang 0043, Haitao Cheng, Guozi Sun |
ACM Trans. Knowl. Discov. Data | 5 |
| 2025 | An Active Defense Adjudication Method Based on Adaptive Anomaly Sensing for Mimic IoTabstractSecurity issues in the Internet of Things (IoT) are inevitable. Uncertain threats, such as known vulnerabilities and backdoors exist within IoT, and traditional passive network security technologies are ineffective against uncertain threats. To address the above issues, we propose an active defense adjudication method based on adaptive anomaly sensing for mimic IoT. The method constructs a mimic IoT active defense architecture, improving system security and reliability despite prevailing security threats. In addition, an intelligent anomaly sensing algorithm is integrated into the adjudication module of the mimic IoT active defense architecture to support arbitration. An adaptive anomaly sensing model based on multi-feature selection is used to determine the anomaly score of the IoT device outputs, and this model fully considers the reliability of the adjudication data and improves the accuracy of the adjudication. Finally, we conduct a comparative analysis of the proposed adjudication algorithm against three others via a mimic power communication IoT system as an application scenario. The experimental results show that our algorithm can improve security and reduce the failure rate of the mimic IoT system. Tiansheng Gu, Yijun Nie, Zongkai Ji, Fei Wu 0004, Zhongjie Ba, Yimu Ji 0001, Kui Ren 0001, Guozi Sun |
IEEE Trans. Serv. Comput. | 9 |
| 2025 | ARAP: Demystifying Anti Runtime Analysis Code in Android AppsabstractWith the continuous growth in the usage of Android apps, ensuring their security has become critically important. An increasing number of malicious apps adopt anti-analysis techniques to evade security measures. Although some research has started to consider anti-runtime analysis (ARA), it is unfortunate that they have not systematically examined ARA techniques. Furthermore, the rapid evolution of ARA technology exacerbates the issue, leading to increasingly inaccurate analysis results. To effectively analyze Android apps, understanding their adopted ARA techniques is necessary. However, no systematic investigation has been conducted thus far.In this paper, we conduct the first systematic study of the ARA implementations in a wide range of 117,270 Android apps (including both malicious and benign ones) collected between 2016 and 2023. Additionally, we propose a specific investigation tool namedARAPto assist this study by leveraging both static and dynamic analysis. According to the evaluation results,ARAPnot only effectively identifies the ARA implementations in Android apps but also reveals many important findings. For instance, almost all apps have implemented at least one category of ARA technology (99.6% for benign apps and 97.0% for malicious apps). Dewen Suo, Lei Xue 0001, Le Yu 0002, Runze Tan, Weihao Huang, Guozi Sun |
IEEE Trans. Software Eng. | 6 |
| 2024 | HDML: hybrid data-driven multi-task learning for China's stock price forecast
Weiqiang Xu 0003, Yang Liu 0490, Huakang Li, Guozi Sun |
Appl. Intell. | 5 |
| 2024 | Bridging spherical mixture distributions and word semantic knowledge for Neural Topic Modeling
Rui Wang 0043, Haiping Huang, Guozi Sun |
Expert Syst. Appl. | 5 |
| 2023 | RPChain: Regulatable Privacy-Preserving Group Data Sharing Based on Consortium Blockchain
Puhe Hao, Tianyu Pan 0004, Xiao Qu, Zhexuan Yang, Guozi Sun |
APNOMS | 6 |
| 2023 | A Privacy-Preserving Data Sharing Scheme Based on Blockchain for Vehicular Edge NetworksabstractThe advancing fifth-generation technology has brought the Internet of Vehicles (IoV) more and more attention. The vast amount of data collected and generated by vehicles has enabled enhanced driving security and intelligent transportation through data sharing between vehicles and roadside infrastructures. Due to the huge data volume and vehicle resource constraints, vehicular edge networks have been proposed to provide computational and storage resources. Vehicular data commonly contains sensitive information about geographical locations and personal identifiers, making it vulnerable to attacks and leaks. In this paper, we propose a privacy-preserving framework for blockchain-enabled data sharing in vehicular edge networks. Attribute-based ring signatures and threshold proxy re-encryption are used to address privacy concerns, and a decentralized regulatory approach has been proposed to track illegal data transfers. We address the security and trust issues by using the consortium blockchain as a distributed ledger of correlated information records. We also implement consent-based access control for data owners, which is rarely considered in currently proposed systems. Implementation and experiments show that our scheme can handle large throughput and data sizes. The security analysis shows the promise of our scheme in ensuring security against various attacks. Puhe Hao, Tianyu Pan 0004, Xiao Qu, Zhexuan Yang, Guozi Sun |
GLOBECOM | 6 |
| 2023 | Incorporating I Ching Knowledge Into Prediction Task via Data MiningabstractMany real-world applications require prediction that takes the most advantage of data. Classic data mining mechanisms tend to feed a prediction model pivotal data to achieve a promising result, which needs to be adjusted in different application scenarios. Recent studies have shown the potential of I Ching mechanism to improve prediction capacity. However, the I Ching prediction mechanism has several issues, including underutilized I Ching knowledge and incomplete data conversion. To address these issues, the authors designed a model to leverage I Ching knowledge and transform traditional I Ching prediction processing into data mining. The authors' investigation revealed promising results in the stock market compared to popular machine learning and deep learning algorithms such as support vector machine (SVM), extreme gradient boosting (XGBoost), and long short-term memory (LSTM). Sai Chen, Guoyao Huang, Lingfeng Lu, Huakang Li, Guozi Sun |
J. Database Manag. | 6 |
| 2023 | Modeling and Optimization of Multi-Model Waste Vehicle Routing Problem Based on the Time WindowabstractWith the development of China's economy, the urban floating population is also increasing, resulting in a sharp increase in the amount of urban waste. How to recycle and dispose of municipal waste more efficiently has become the top concern of municipalities and other relevant departments. In this article, the above problem is transformed into the municipal waste collection vehicle routing problem (MWCVRP) to solve the problem with the minimum total waste transportation cost. Because the carrying capacity of different models is different, this article introduces a cost calculation criterion that combines the total mileage of different models of transport vehicles and the number of station services. A multi-model garbage truck path optimization model is established, and then a heuristic-based task dynamic assignment algorithm is designed to solve the problem. The Solomon dataset is used to verify the feasibility and effectiveness of the model and algorithm through experiments. Hongjie Wan, Junchen Ma, Qiumei Yu, Guozi Sun, Hansen He, Huakang Li |
J. Database Manag. | 4 |
| 2023 | FIBPRO: Peer-to-peer data management and sharing cloud storage system based on blockchain
Mingfa Wan, Teng Yuan, Guozi Sun |
Peer Peer Netw. Appl. | 5 |
| 2022 | Self-supervised Learning for Sketch-Based 3D Shape Retrieval
Zhixiang Chen 0017, Haifeng Zhao 0002, Guozi Sun, Tianjian Wu |
PRCV (1) | 4 |
| 2022 | Triplet Embedding Convolutional Recurrent Neural Network for Long Text Semantic Analysis
Ouyang Huajiang, Guozi Sun, Huakang Li |
WISE | 4 |
| 2021 | Judicial Case Determination Methods Based on Event Tuple
Guozi Sun, Huakang Li, Xiangyu Tang |
WASA (1) | 1 |
| 2021 | ConGradetect: Blockchain-based detection of code and identity privacy vulnerabilities in crowdsourcing
Jitao Wang, Guozi Sun |
J. Syst. Archit. | 2 |
| 2021 | A Residual Learning-Based Network Intrusion Detection SystemabstractNeural networks have been proved to perform well in network intrusion detection. In order to acquire better features of network traffic, more learning layers are necessarily required. However, according to the results of the previous research, adding layers to the neural networks might fail to improve the classification results. In fact, after the number of layers has reached a certain threshold, performance of the model tends to degrade. In this paper, we propose a network intrusion detection model based on residual learning. After transforming the UNSW-NB15 data set into images, deeper convolutional neural networks with residual blocks are built to learn more critical features. Instead of the cross-entropy loss function, the modified focal loss is calculated to address the class imbalance problem in the training set and identify minor attacks in the testing set. Batch normalization and global average pooling are used to avoid overfitting and enhance the model. Experimental results show that the proposed model can improve attack detection accuracy compared with existing models. Jiarui Man, Guozi Sun |
Secur. Commun. Networks | 2 |
| 2019 | Characterization and graph embedding of weighted social networks through Diffusion WaveletsabstractMore and more graph embedding algorithms have been proposed, which makes the similarity judgment of graph structure more and more accurate. While exploring the similarity of neighborhood structures, the existence of weights should also be taken into account, so as to reflect the relational social network graph in the real world. We use Graphwave, a kind of algorithms for graph embedding with diffusion wavelets, to incorporate weight into numerical value to calculate, and to process the returned probability distribution parameters, so that we can get some analysis about the actual complex network. Our analysis can overcome the priori misjudgment problem based on the topological structure, and then obtain the actual similarity of the network structure from the results of graph embedding. Huakang Li, Guozi Sun |
IEEE BigData | 4 |
| 2018 | The Dynamic Data Integrity Verification and Recovery Scheme based on MHTabstractThe dynamic data integrity verification and recovery scheme based on MHT (Merkle Hashing Tree) is proposed to solve the problems of high communication overhead and dynamic data validation in the process of storing data integrity verification on cloud servers. It constructs a late-model layering authentication data structure, and organizes each replica block of a data block into a replica sub-tree to reduce the communication overhead of multiple copies update verification greatly. The authentication of server security index information is merged into data validation to avoid server attacks. Finally, the data can be recovered through binary chop and Shamir secret sharing mechanism when data corruption is found. The experimental results show that this scheme can not only reduce computing and communication overhead effectively, but also supports the dynamic operation of data well. Yasen Aizezi, Yuhua Feng, Guozi Sun |
AVSS | 4 |
| 2018 | DDoS Attacks and Flash Event Detection Based on Flow Characteristics in SDNabstractWith the development of Software-Defined Networking (SDN), its security has been increasingly emphasized. Due to the centralized management and programmability of SD-N, an attacker can easily exploit its security vulnerabilities to carry out distributed denial-of-service (DDoS) attacks. Targeting at the φ-entropy improved on basis of Shan-non entropy and generalized entropy, we presents a multi-type DDoS detection and Flash Event method based on flow characteristics. To conduct the DDoS attack detection while detecting and distinguishing DDoS and Flash Events (FE) correctly, samples are classified via the multi-dimension features of the flow table in the switch, such as protocol type, the duration of flow and the φ-entropy of source / destination IP, Among them, the adjustable of φ-entropy is more conducive to discovering the attack behavior in the early stage. Experiments show that this method can effectively improve the detection rate of DDoS and reduce the false alarm rate of Flash Events, which verifies the accuracy and effectiveness of the experiments. Guozi Sun, Wenti Jiang, Danni Ren, Huakang Li |
AVSS | 1 |
| 2018 | Web attack forensics based on network traffic behavior characteristics and URLsabstractWith the continuous development of Internet technology, the Internet has penetrated into every aspect of people's lives, and the importance of the network has also increased. The technology of network attack is constantly becoming more complex and diversified. Many network applications suffer from various network attacks and security threats, and network security problems are becoming more and more serious, new requirements are imposed on Web attack forensics. We propose a new Web attack forensics method combining network traffic characteristics with URLs based on the characteristics of network traffic. Our method achieved satisfactory results on the test data set. Guozi Sun, Huakang Li |
AVSS | 1 |
| 2018 | P2P Lending Platform Risk Observing Method Based on Short-Time Multi-Source Regression AlgorithmabstractPeer-to-Peer (P2P) lending is a popular way of lending in contemporary Internet financial filed. Comparing with the traditional bank lending, the annual risk evaluation is no longer applicable for P2P platform because of the short life cycle and a lot of transaction records. This paper presents a method to dynamically evaluate the operation risk of P2P plat- forms based on a short-time multi-source regression algorithm. Dynamic time windows are used to split up the lending records and linear regression method is used to quantify the dynamic risk index of P2P platforms. The experimental results show that the proposed method can reflect the visible operation situation of platforms, and give investors dynamic risk assessment and effective tips of the platforms. Huakang Li, Guozi Sun |
ICC | 3 |
| 2018 | An OpenvSwitch Extension for SDN Traceback
Danni Ren, Wenti Jiang, Huakang Li, Guozi Sun |
NSS | 4 |
| 2018 | Network Traffic Anomaly Detection Based on Wavelet AnalysisabstractNetwork traffic anomaly detection is an important research content in the field of network and security management. By analyzing network traffic, the health of the network environment can be intuitively evaluated. In particular, analyzing network traffic provides practical and effective guidance for identification and classification of anomaly. This paper proposes a network traffic anomaly detection method based on wavelet analysis for pcap files contain two different delay injections. The wavelet analysis can effectively extract information from the signal and is suitable for the detection of anomaly. Firstly, wavelet analysis is used to extract the waveform features, and then the support vector machine is used for classification. In particular, packet lengths in the pcap files is parsed out to form a sequence of packet lengths in chronological order. Then followed by the wavelet analysis based packet length sequence feature extraction and feature selection methods, the resulting eigenvectors are used as input features to support vector machine for training the classifier. Thus to differentiate the two types of anomaly in the mixed traffic with both normal and abnormal traffic. The qualitative and quantitative experimental results show that our approach achieves good classification results. Zhen Du, Lipeng Ma, Huakang Li, Guozi Sun, Zichang Liu |
SERA | 5 |
| 2017 | An optimized approach for massive web page classification using entity similarity based on semantic network
Huakang Li, Zheng Xu 0001, Tao Li 0016, Guozi Sun, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 4 |
| 2017 | A security carving approach for AVI video based on frame size and index
Zheng Xu 0001, Guozi Sun |
Multim. Tools Appl. | 4 |
| 2016 | A Demonstration of Encrypted Logistics Information System
Huakang Li, Xinwen Zhang, Guozi Sun |
APWeb (2) | 4 |
| 2016 | DFIPS: Toward Distributed Flexible Intrusion Prevention System in Software Defined NetworkabstractWith the evolution of the innovative software defined network (SDN), security issues have been taken into consideration.Intrusion prevention system (IPS) has widely deployed as a crucial measure in traditional network architecture to protect network from malignity.In spite of good capability of protection, IPS is still complained in many aspects, such as fixed deployment, single-point-detection and low utilization rate.In this paper, we propose a distributed flexible intrusion prevention system in software defined network (DFIPS).Our proposed DFIPS has three main modules: a classifier, a detector pool and a control agent.The classifier is in charge of slicing traffic.The detector pool then generates several detector nodes for detecting.The control agent interacts with the classifier and the detector pool, as well as higher level SDN controller APPs and OpenFlow switches.DFIPS integrating with SDN controller can easily achieve good load balancing among DFIPSs without repetitive deployment.We evaluate the two forms of DFIPS interaction and latency to show the advantage of DFIPS.In future, we would implement a more comprehensive DFIPS emulation to prove feasibility.We believe that the proposed DFIPS will be adapted in real networks eventually. Xuesong Jia, Danni Ren, Huakang Li, Guozi Sun |
SEKE | 5 |
| 2015 | AppTrace: Dynamic trace on Android devicesabstractMass vulnerabilities involved in the Android alternative applications could threaten the security of the launched device or users data. To analyze the alternative applications, generally, researchers would like to observe applications' runtime features first. Then they need to decompile the target application and read the complicated code to figure out what the application really does. Traditional dynamic analysis methodology, for instance, the TaintDroid, uses dynamic taint tracking technique to mark information at source APIs. However, TaintDroid is limited to constraint on requiring target application to run in custom sandbox that might be not compatible with all the Android versions. For solving this problem and helping analysts to have insight into the runtime behavior, this paper presents AppTrace, a novel dynamic analysis system that uses dynamic instrumentation technique to trace member methods of target application that could be deployed in any version above Android 4.0. The paper presents an evaluation of AppTrace with 8 apps from Google Play as well as 50 open source apps from F-Droid. The results show that AppTrace could trace methods of target applications successfully and notify users effectively when some sensitive APIs are invoked. Lingzhi Qiu, Zixiong Zhang, Ziyi Shen, Guozi Sun |
ICC | 4 |
| 2015 | Dump and analysis of Android volatile memory on WechatabstractWith the popularity of smartphones, various types of mobile crimes emerge endlessly. Evidence from mobile phones is mostly obtained by non-volatile physical memory dump and file system analysis. The two methods can extract lots of private data, but often invalid for encrypted and deleted data. In this paper, we discuss the Android volatile memory and introduce some methods to dump the memory. Analysis on the Android volatile memory are also presented using software tools. At last the paper provides an in-depth analysis of Android memory structures to extract the encrypted chats and deleted messages on a popular social network application called Wechat [1]. The results show that all chats can be extracted in the form of plaintext, including some deleted messages. Zhaokun Ding, Guozi Sun |
ICC | 4 |
| 2015 | Design and implementation of a malware detection system based on network behaviorabstractAbstract With the increasing of new malicious software attacks, the host‐based malware detection methods cannot always detect the latest unknown malware. Intrusion detection system does not focus on malware detection, whereas the behavior‐based detection methods still have some difficulties in being deployed in the network layer. This paper presents a malware detection method based on network behavior evidence chains. The proposed new method will detect the specific network behavior characteristics on three different stages as connection establishment, operating control, and connection maintenance. Then a final detection decision will be concluded according to the results detected in the different stages before. A system prototype is implemented to proof concept the proposed malware detection methods. Copyright © 2014 John Wiley & Sons, Ltd. L. Xue, Guozi Sun |
Secur. Commun. Networks | 2 |
| 2014 | Topic Detection from Microblog Based on Text Clustering and Topic Model AnalysisabstractThis paper raises a Microblog topic detection method based on text clustering and topic model analysis. It solves the problem that the traditional topic detection method is mainly applicable for traditional media text, which is not very effective in handling sparse Micro blog short texts. In consequence of the structural data of the Microblog, which exists rich inter-textual contextual information such as retweets, comments, user hash tag, embedded link URL, we first put forward a feature weight pre-processing method. We also use a clustering algorithm based on word vectors to enrich the feature information of the data. On this basis, we extend the conventional LDA (Latent Dirichlet allocation) topic model to extract the hot topics in the Micro blog data. Compared with the traditional methods, the method raised in this paper is much more effective in the collected text corpus in Sina Microblog. Huakang Li, Guozi Sun |
APSCC | 4 |
| 2014 | A privacy protection policy combined with privacy homomorphism in the Internet of ThingsabstractRecently, IOT (Internet of Things) develops very rapidly. However, the personal privacy protection is one of directly important factors that impact the large-scale applications of IOT. To solve this problem, this paper proposes a privacy protection policy based on privacy homomorphism. It can protect the security of personal information well by processing the needs of users without acquiring of plaintext. In another aspect, it also greatly improves the performance of the original multiplication homomorphism algorithm. Guozi Sun, Wan Bao, Zhiwei Wang 0003 |
ICCCN | 1 |
| 2014 | A new definition of homomorphic signature for identity management in mobile cloud computing
Zhiwei Wang 0003, Guozi Sun, Danwei Chen |
J. Comput. Syst. Sci. | 2 |
| 2009 | Similarity-Based Feature Selection for Learning from Examples with Continuous Values
Yun Li 0009, Su-Jun Hu, Wen-Jie Yang, Guozi Sun, Fang-Wu Yao, Geng Yang 0002 |
PAKDD | 4 |
| 2007 | Defending Against Jamming Attacks in Wireless Local Area Networks
Wei Chen 0006, Danwei Chen, Guozi Sun, Yingzhou Zhang |
ATC | 3 |