VLDB 2026 Research / reviewers in the wild / expert
Meimei Li
dblp:92/5641
· DBLP profile ↗
23ranked-venue papers
5as first author
13since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 9 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 8 · 2 first-author · 6 since 2021Computer networks · 4 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MalHdb:Malware Detection Based on Heterogeneous Dual-Branch Neural Networks
Meichen Liu, Meimei Li |
ADMA (1) | 4 |
| 2025 | DASA-Trans-STM: Adaptive Efficient Transformer for Short Text Matching using Data Augmentation and Semantic AwarenessabstractRencent advancements in large language models (LLM) have shown impressive versatility across various tasks.Short text matching is one of the fundamental technologies in natural language processing.In previous studies, the common approach to applying them to Chinese is segmenting each sentence into words, and then taking these words as input.However, existing approaches have three limitations: 1) Some Chinese words are polysemous, and semantic information is not fully utilized.2) Some models suffer potential issues caused by word segmentation and incorrect recognition of negative words affects the semantic understanding of the whole sentence.3) Fuzzy negation words in ancient Chinese are difficult to recognize and match.In this work, we propose a novel adaptive Transformer for Chinese short text matching using Data Augmentation and Semantic Awareness (DASA), which can fully mine the information expressed in Chinese text to deal with word ambiguity.DASA is based on a Graph Attention Transformer Encoder that takes two word lattice graphs as input and integrates sense information from N-HowNet to moderate word ambiguity.Specially, we use an LLM to generate similar sentences for the optimal text representation.Experimental results show that the augmentation done using DASA can considerably boost the performance of our system and achieve significantly better results than previous state-of-theart methods on four available datasets, namely MNS, LCQMC, AFQMC, and BQ. Jiguo Liu, Chao Liu 0020, Meimei Li, Shihao Gao, Dali Zhu |
EMNLP | 3 |
| 2025 | DiB-ETC: A Distillation Framework with BERT Teacher Model for Imbalanced Encrypted Traffic ClassificationabstractEncrypted Traffic Classification (ETC) plays a crucial role in managing the mobile Internet and ensuring the quality of service(QoS), especially with the explosion of mobile applications using encrypted communications. Although some existing ETC methods have shown good analysis results, they still grapple with the serious classification bias problem inherent in encrypted traffic classification methods. This issue suggests that models tend to classify the majority of classes while ignoring the minority class. To tackle these challenges, most existing models attempt to enhance their feature extraction capabilities by increasing the number of model parameters. However, in order to deploy models in real-world environments with limited resources, how to enable smaller models to achieve such capabilities remains an unresolved challenge. In this paper, we propose a novel distillation-based ETC framework called DiB-ETC. Our primary insight involves designing three training tasks for the BERT-based teacher model to aid in the deployment of strong encrypted traffic classification feature extraction capabilities. We employ distillation technology to transfer its classification capabilities to our student model, enabling it to achieve performance on par with the teacher model, even with smaller-scale parameters. DiB-ETC demonstrates strong performance on four classification tasks on three public datasets with significant class imbalances, and significantly improves the accuracy and F1 score in the two tasks of ISCX-VPN-app and ISCX-Tor. Furthermore, we validated the effectiveness of auxiliary training in the teacher model and augmentation techniques in the student model within our framework. Ablation experiments proved that these components contribute to improving the overall classification performance of the framework. Xingchen Zhan, Meimei Li, Chao Liu 0020 |
HPCC | 3 |
| 2025 | WCAT: The Multi-scale Wavelet Channel Attention Module for Deepfake Detection
Lijia Guo, Meimei Li |
ICIC (5) | 2 |
| 2025 | SWV: A Large-Scale Sensitive Word Variants Dataset for Semantic Text Matching
Jiguo Liu, Chao Liu 0020, Meimei Li, Shihao Gao, Dali Zhu |
KSEM (1) | 3 |
| 2024 | EFCC-IeT: Cross-Modal Electronic File Content Correlation via Image-Enhanced Text
Pengfei Jing, Jiguo Liu, Meimei Li |
KSEM (1) | 4 |
| 2023 | Intrusion Detection Method for SCADA System Based on Spatio-Temporal CharacteristicsabstractSupervisory Control and Data Acquisition (SCADA) systems are one of the most common industrial control systems (ICS). As the security threat of SCADA systems has been rising in recent years, intrusion detection has become indispensable. Among SCADA systems, there is a lack of research on intrusion detection of temporal and spatial characteristics, and the effectiveness of the existing intrusion detection approaches could be improved. This paper proposes an intrusion detection model based on spatio-temporal characteristics of SCADA systems, combining the attention mechanism, called STAM, allows a full understanding of the correlation between sensor and controller parameters. Experiments on three typical SCADA system datasets show that STAM proposed in this paper achieves state-of-the-art results and can be better applied to intrusion detection in SCADA systems. The effectiveness of STAM is evaluated by accuracy, precision, recall, and F1-score. The accuracy rates on new gas pipeline, water storage tank, and Secure Water Treatment (SWaT) datasets can reach 95.34%, 98.92% and 99.95% respectively. Meimei Li, Zhongfeng Jin, Jiguo Liu, Chao Liu 0020 |
CSCWD | 1 |
| 2023 | GHGA-Net: Global Heterogeneous Graph Attention Network for Chinese Short Text Classification
Meimei Li, Yuzhi Bao, Jiguo Liu, Chao Liu 0020, Shihao Gao |
PRICAI (2) | 1 |
| 2022 | Frequency Hopping Signal Recognition Based on Horizontal Spatial AttentionabstractFrequency hopping (FH) technology is one of the most effective technologies in the field of radio countermeasures, meanwhile, the recognition of FH signal has become a research hotspot. FH signal is a typical non-stationary signal whose frequency varies nonlinearly with time and the time-frequency analysis technique provides a very effective method for processing this kind of signal. With the renaissance of deep learning, methods based on time-frequency analysis and deep learning are widely studied. Although these methods have achieved good results, the recognition accuracy still needs to be improved. Through the observation of the datasets, we found that there are still difficult samples that are difficult to identify. Through further analysis, we propose a horizontal spatial attention (HSA) block, which can generate spatial weight vector according to the signal distribution, and then readjust the feature map. The HSA block is a plug-and-play module that can be integrated into common convolutional neural network (CNN) to further improve their performance and these networks with HSA block are collectively called HANets. The HSA block also has the advantages of high recognition accuracy (especially under low SNRs), easy to implant, and almost no influence on the number of parameters. We verified our method on two datasets and a series of comparative experiments show that the proposed method achieves good results on FH datasets. Pengcheng Liu 0007, Zhen Han 0001, Zhixin Shi, Meimei Li, Meichen Liu |
ISCC | 4 |
| 2022 | Adversarial Attacks on Deep Learning-Based Methods for Network Traffic ClassificationabstractThe network traffic data is easily monitored and obtained by attackers. Attacks against different network traffic threaten the environment of the intranet. Deep learning methods have been widely used to classify network traffic for their high classification performance. The application of adversarial samples in computer vision confirms that deep learning methods are flawed, allowing existing methods to generate incorrect results with high confidence. In this paper, the adversarial samples are used on the network traffic classification model, causing the CNN model to produce incorrect classification results for network traffic. By training the classification model adversarially, we validate the training effect and improve the classification accuracy by means of the FGSM attack method. By using the adversarial samples to the network traffic data, our approach enables proactive defence against intranet eavesdropping before the attack occurs by influencing the attacker’s classification model to misclassify. Meimei Li, Yiyan Xu, Zhongfeng Jin |
TrustCom | 1 |
| 2021 | DeepMIT: A Novel Malicious Insider Threat Detection Framework based on Recurrent Neural NetworkabstractCurrently, more and more malicious insiders are making threats, and the detection of insider threats is becoming more challenging. The malicious insider often uses legitimate access privileges and mimic normal behaviors to evade detection, which is difficult to be detected via using traditional defensive solutions. In this paper, we propose DeepMIT, a malicious insider threat detection framework, which utilizes Recurrent Neural Network (RNN) to model user behaviors as time sequences and predict the probabilities of anomalies. This framework allows DeepMIT to continue learning, and the detections are made in real time, that is, the anomaly alerts are output as rapidly as data input. Also, our framework conducts further insight of the anomaly scores and provides the contributions to the scores and, thus, significantly helps the operators to understand anomaly scores and take further steps quickly(e.g. Block insider's activity). In addition, DeepMIT utilizes user-attributes (e.g. the personality of the user, the role of the user) as categorical features to identify the user's truly typical behavior, which help detect malicious insiders who mimic normal behaviors. Extensive experimental evaluations over a public insider threat dataset CERT (version 6.2) have demonstrated that DeepMIT has outperformed other existing malicious insider threat solutions. Degang Sun, Meichen Liu, Meimei Li, Zhixin Shi, Pengcheng Liu 0007 |
CSCWD | 3 |
| 2021 | FHSR: A Successful Application of Deep Learning Technology in Signal RetrievalabstractWith the widespread application of frequency hop-ping (FH) technology, a large number of FH signal monitoring data have been accumulated. Big data brings new opportunities and challenges to radio supervision, one of which is signal retrieval. The task of signal retrieval is to find similar signals for a given segment of signal. In this paper, we propose an idea of FH signal retrieval. Firstly, transform the FH signal into two-dimensional images, and the radio signal retrieval problem is transformed into an image retrieval problem. Then, the advanced achievements in the field of image retrieval can be used to complete signal retrieval. Based on this idea, we propose an FH signal retrieval algorithm named FHSR. In order to extract the signal information better, we also propose a data augmentation algorithm. Experiments show that our method achieves good results in retrieval accuracy and speed, which meets the actual needs. Pengcheng Liu 0007, Zhen Han 0001, Meimei Li, Meichen Liu |
ICTAI | 3 |
| 2021 | FakeFilter: A cross-distribution Deepfake detection system with domain adaptationabstractAbuse of face swap techniques poses serious threats to the integrity and authenticity of digital visual media. More alarmingly, fake images or videos created by deep learning technologies, also known as Deepfakes, are more realistic, high-quality, and reveal few tampering traces, which attracts great attention in digital multimedia forensics research. To address those threats imposed by Deepfakes, previous work attempted to classify real and fake faces by discriminative visual features, which is subjected to various objective conditions such as the angle or posture of a face. Differently, some research devises deep neural networks to discriminate Deepfakes at the microscopic-level semantics of images, which achieves promising results. Nevertheless, such methods show limited success as encountering unseen Deepfakes created with different methods from the training sets. Therefore, we propose a novel Deepfake detection system, named FakeFilter, in which we formulate the challenge of unseen Deepfake detection into a problem of cross-distribution data classification, and address the issue with a strategy of domain adaptation. By mapping different distributions of Deepfakes into similar features in a certain space, the detection system achieves comparable performance on both seen and unseen Deepfakes. Further evaluation and comparison results indicate that the challenge has been successfully addressed by FakeFilter. Boquan Li 0002, Baole Wei, Gang Li 0009, Chao Liu 0020, Weiqing Huang, Meimei Li, Min Yu 0001 |
J. Comput. Secur. | 7 |
| 2020 | Terminator: a data-level hybrid framework for intellectual property theft detection and preventionabstractRecently, high profile data breach incidents have highlighted the importance of insider Intellectual Property(IP) theft research. Matching the patterns of known attack (filtering-based or rule-based) and finding the deviation from normal behavior (anomaly-based) are two typical approaches to prevent insiders from stealing sensitive information. On the one hand, filtering-based or rule-based solutions provide accurate identification of known attacks, and thus they are suitable for IP theft prevention, but they cannot handle the insiders with in-depth knowledge of the protective measures. On the other hand, anomaly-based solutions can find unknown attacks but typically have a high false-positive rate, which limits their applicability to practice. Nowadays, more and more researchers believe that the insider attack could be improved when combining known attack pattern matching with anomaly detection technologies. Therefore, in this paper, we introduce a Data-level Hybrid Framework, dubbed as Terminator, which enabling both detection and prevention. Terminator integrates a prevention module with an anomaly detection module and uses feedback to improve the module for detection or prevention. Different from previous anomaly-based methods that could only detect anomalous activities, Terminator could detect the stealing actions proactively and take real-time actions on these actions. The effectiveness of Terminator is demonstrated by its excellent performances on a collected dataset, involving detailed information in a real-world insider network and attack data simulated by impersonating the genuine users. Meichen Liu, Meimei Li, Degang Sun, Zhixin Shi, Pengcheng Liu 0007 |
CF | 2 |
| 2020 | SCX-SD: Semi-supervised Method for Contextual Sarcasm Detection
Meimei Li, Chen Lang, Min Yu 0001, Chao Liu 0020, Weiqing Huang |
KSEM (2) | 1 |
| 2019 | A New C&C Channel Detection Framework Using Heuristic Rule and Transfer LearningabstractA great many of botnet detection methods focus on recognizing the significant C&C channels. Most of them require a C&C training set to build a behavior detection model. However, when lacking such training set for new or unknown botnets, these methods may become inefficient or even invalid.To overcome it, we propose a new general framework for C&C channel detection. It neither needs us to know the families of bots or prepare a training set nor requires deploying malicious activity monitors. Also, it is capable of mining useful knowledge from the historical dataset to boost its detection performance. In our framework, we put forward a clustering method and several heuristic rules to aggregate and label partial C&C traffic, a sample selection function to mine useful historical knowledge and a transfer learning based model to find other C&C channels. We evaluated our framework on two datasets and achieved the best C&C F-measure of about 0.886 and 0.960 respectively. Moreover, the comparison result further indicates its performance advantage and better behavior learning ability. Qilei Yin, Zhixin Shi, Meimei Li |
IPCCC | 4 |
| 2019 | A Novel Method for Highly Imbalanced Classification with Weighted Support Vector Machine
Biao Qi, Zhixin Shi, Meimei Li |
KSEM (1) | 4 |
| 2019 | Machine Tools Fingerprinting for Distributed Numerical Control SystemsabstractAs machine tools are connected to Industrial Ethernet and external interfaces in the wave of the fourth industrial revolution, new attacks and vulnerabilities are emerging. However, there is little security analysis on Distributed Numerical Control (DNC) system and Computerized Numerical Control (CNC) system. Researchers have demonstrated how to combine the characteristics of Industrial Control System (ICS) to augment existing Intrusion Detection System (IDS) solutions. To the best of our knowledge, there is no such work on DNC network. In response to this situation, a fingerprinting method is proposed as an enhancement technology to existing IDS for DNC systems. The first step is to extract the number of data collection points of each machine tool and the length of TCP payload of each packet. And the second step is to use data response processing times of machine tools to construct unique fingerprint for each machine. Finally, the optimum period slice k is selected and classification accuracy is evaluated using a real-world dataset from a small-scale smart factory. It is demonstrated that our fingerprinting method can be a valuable tool to enhance IDS for DNC network. Weiqing Huang, Zhongfeng Jin, Chao Liu 0020, Meimei Li |
LCN | 5 |
| 2018 | Comprehensive Behavior Profiling Model for Malware ClassificationabstractIn view of the great threat posed by malware and the rapid growing trend about malware variants, it is necessary to determine the category of new samples accurately for further analysis and taking appropriate countermeasures. The network behavior based classification methods have become more popular now. However, the behavior profiling models they used usually only depict partial network behavior of samples or require specific traffic selection in advance, which may lead to adverse effects on categorizing advanced malware with complex activities. In this paper, to overcome the shortages of traditional models, we raise a comprehensive behavior model for profiling the behavior of malware network activities. And we also propose a corresponding malware classification method which can extract and compare the major behavior of samples. The experimental and comparison results not only demonstrate our method can categorize samples accurately in both criteria, but also prove the advantage of our profiling model to two other approaches in accuracy performance, especially under scenario based criteria. Qilei Yin, Zhixin Shi, Meimei Li |
ISCC | 4 |
| 2008 | PASE: A Prototype for Ad-hoc Process-Aware Information System Declaratively Constructing EnvironmentabstractTraditional workflow management technology can deal with pre-defined business processes well. However, a practical ad-hoc process case in knowledge-intensive domain is often driven by not only process control, but also the real-time application data or user interactions. So the structure of those processes are hard to be completely fixed ahead. In addition, as the only basic element in traditional process, task, is often too coarse or too fine in real applications. Even though the process structure could be pre-defined completely, there is only a non-declarative way to build the process by traditional methods. To solve the above problems, we developed a declaratively constructing environment, named PASE. We propose a multi-layer model to percept ad-hoc process. And we adopt a transformation strategy to translate the model to process specifications based on logic reasoning and calculus. We also provide a graphical tool to help user construct information systems declaratively. Meimei Li |
WAIM | 5 |
| 2006 | WISE: A Prototype for Ontology Driven Development of Web Information Systems
Lv-an Tang, Hongyan Li 0002, Baojun Qiu, Meimei Li, Dongqing Yang, Shiwei Tang |
APWeb | 4 |
| 2006 | DOPA: A Data-Driven and Ontology-Based Method for Ad Hoc Process Awareness in Web Information Systems
Meimei Li, Hongyan Li 0002, Lv-an Tang, Baojun Qiu |
WISE | 1 |
| 2005 | An Ontology Based Approach to Construct Behaviors in Web Information Systems
Lv-an Tang, Hongyan Li 0002, Zhiyong Pan, Dongqing Yang, Meimei Li, Shiwei Tang, Ying Ying |
WAIM | 5 |