VLDB 2026 Research / reviewers in the wild / expert
Weiwu Ren
dblp:93/4384
· DBLP profile ↗
16ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-3787-636XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A knowledge extrapolation model for attack inference based on graph attention networks and relation mapping
Weiwu Ren |
Knowl. Inf. Syst. | 1 |
| 2026 | GA-ConvE: An APT attack prediction method based on combination of graph attention network and 2D convolution
Yazhou Du, Weiwu Ren, Minyue Wang, Wanxiang Wang, Hewen Zhang, Mingqi Xia |
Neural Networks | 2 |
| 2026 | Adaptive aggregation relational graph convolutional neural network semi-supervised classification method for APT attack recognition
Weiwu Ren, Mingqi Xia, Cong Liang |
J. Supercomput. | 1 |
| 2025 | GC-PTransE: multi-step attack inference method based on graph convolutional neural network and translation embedding
Weiwu Ren, Yazhou Du, Hewen Zhang, Mingqi Xia |
Knowl. Inf. Syst. | 1 |
| 2025 | GPCNKB: An Attack Prediction and Reasoning Model Based on an Improved Graph Convolutional NetworkabstractWith the advancement of artificial intelligence technology, network attack scenarios are becoming increasingly intricate. On the one hand, the amount of attack knowledge is increasing; on the other hand, the potential relationships between these pieces of knowledge are becoming more difficult to discover and identify. Existing methods struggle to characterize these complex attack scenarios effectively and accurately predicting attack patterns. To address these issues, this paper introduces a novel network attack prediction and reasoning method, GPCNKB, which adopts the design idea of“classification-first, reasoning-later”. First, knowledge graphs and embedding techniques are used to represent attack scenarios, then graph convolutional networks (GCNs) are applied to classify the scenarios, and finally, the knowledge graph embedding model is utilized to reason the attack knowledge within scenarios of the same category. This design reduces the scope of reasoning and enhances its accuracy, enabling more effective network attack predictions. Additionally, the method incorporates concepts from evolutionary computation to refine the GCN classification model. This refinement optimizes the training parameters of the graph convolution network and improve the universality of the model. Experimental results reveal that GPCNKB exhibits notable advantages in reasoning speed and effectively uncovers potential relationships among attack knowledge within the same attack category. This work provides a novel approach for reasoning and predicting complex multi-step network attacks. Weiwu Ren, Jinyu Yao |
Neural Process. Lett. | 1 |
| 2025 | Research on APT group classification method based on graph attention networks
Yazhou Du, Weiwu Ren, Xintong Song |
J. Supercomput. | 2 |
| 2025 | Inter-satellite link allocation in low-earth-orbit mega-constellation networks
Weiwu Ren, Bingsen Wang |
J. Supercomput. | 1 |
| 2024 | DeepARR: Alert risk rating based on deep learningabstractAlert fatigue has caused serious consequences for enterprise security. When analysts are inundated with a vast number of alerts, high-risk alerts may be overlooked or responded to with delay, thereby exposing the organization to potential cyber threats or data breaches. Although there are many alert classification research focusing on reducing alerts, it’s still impossible to investigate all alerts due to the resource shortage. Therefore, it is necessary to prioritize alerts based on their potential severity, allowing analysts to address higher-risk alerts first. This paper proposes a novel alert risk rating DeepARR (Deep Learning-based Alert Risk Rating), that utilizes deep learning technology to rate alert risk levels in bulk instead of investigating each alert individually. It first employs a dynamic time window segmentation approach to merge alerts, reducing the overall number. Subsequently, a directed graph-based method is proposed to handle data imbalance. Both temporal-spatial features and event features are extracted. Finally, deep learning techniques are used to classify alert levels. The proposed method is evaluated on the public CPTC-2018 alert dataset. Compared with existing methods, DeepARR achieves an average precision of 95.73%, a recall of 94.83%, and an F1 Score of 94.84% in risk rating, demonstrating its higher effectiveness. Qiyue Tang, Xiaoqiang Di, Xu Liu 0010, Ligang Cong, Weiwu Ren, Zhengping Ni |
ISPA | 5 |
| 2024 | Towards robust log parsing using self-supervised learning for system security analysisabstractLogs play an important role in anomaly detection, fault diagnosis, and trace checking of software and network systems. Log parsing, which converts each raw log line to a constant template and a variable parameter list, is a prerequisite for system security analysis. Traditional parsing methods utilizing specific rules can only parse logs of specific formats, and most parsing methods based on deep learning require labels. However, the existing parsing methods are not applicable to logs of inconsistent formats and insufficient labels. To address these issues, we propose a robust Log parsing method based on Self-supervised Learning (LogSL), which can extract templates from logs of different formats. The essential idea of LogSL is modeling log parsing as a multi-token prediction task, which makes the multi-token prediction model learn the distribution of tokens belonging to the template in raw log lines by self-supervision mode. Furthermore, to accurately predict the tokens of the template without labeled data, we construct a Multi-token Prediction Model (MPM) combining the pre-trained XLNet module, the n-layer stacked Long Short-Term Memory Net module, and the Self-attention module. We validate LogSL on 12 benchmark log datasets, resulting in the average parsing accuracy of our parser being 3.9% higher than that of the best baseline method. Experimental results show that LogSL has superiority in terms of robustness and accuracy. In addition, a case study of anomaly detection is conducted to demonstrate the support of the proposed MPM to system security tasks based on logs. Jinhui Cao, Xiaoqiang Di, Xu Liu 0010, Rui Xu 0019, Weiwu Ren |
Intell. Data Anal. | 6 |
| 2024 | Research on satellite link allocation algorithm for Earth-Moon space information network
Weiwu Ren, Hongbing Chen |
J. Supercomput. | 1 |
| 2023 | MPQUIC Transmission Control Strategy for SDN-Based Satellite Network
Jinyao Liu, Xiaoqiang Di, Weiwu Ren, Ligang Cong |
ICA3PP (6) | 3 |
| 2023 | Subflow scheduling strategy for multipath transmission in SDN-based spatial network
Junrui Si, Jiahui Hou, Zhe Tian, Aowei Zhang, Jing Chen 0041, Weiwu Ren, Xiaoqiang Di |
Wirel. Networks | 7 |
| 2022 | SDN-based dynamic multi-path routing strategy for satellite networks
Yingjun Guo, Dinghui Hou, Ziyang Xing, Weiwu Ren, Ligang Cong, Xiaoqiang Di |
Future Gener. Comput. Syst. | 5 |
| 2021 | QuickLogS: A Quick Log Parsing Algorithm based on Template SimilarityabstractLogs are widely used in network security and management because they record runtime details in IT systems. It is difficult to gain insights from raw unstructured logs, so many researches first parse raw logs into structured templates. However, as the volume of logs grows rapidly, efficiency becomes a major concern in log parsing. In this paper, we propose a quick log parsing algorithm QuickLogS based on template similarity. QuickLogS utilizes regular expressions to replace the variables with wildcard and filters the reduplicate data to parse huge volume of unstructured logs into finite structured templates. To improve parsing efficiency, SimHash algorithm and Hamming distance are used to merge the similar templates of the same length. To the best of our knowledge, we are the first to apply the SimHash algorithm to log parsing. Besides, different with other work, we also merge the similar templates of different lengths based on the cosine similarity algorithm, which contributes to improve the parsing accuracy. QuickLogS is evaluated on six real public log datasets, and compared with four state-of-the-art log parsing algorithms. The experimental results show that QuicklogS outperforms the other parsers in terms of efficiency and accuracy. Luyue Fang, Xiaoqiang Di, Xu Liu 0010, Yiping Qin, Weiwu Ren |
TrustCom | 5 |
| 2021 | LogNADS: Network anomaly detection scheme based on log semantics representation
Xu Liu 0010, Weiyou Liu, Xiaoqiang Di, Binbin Cai, Weiwu Ren |
Future Gener. Comput. Syst. | 6 |
| 2017 | The Fusion Model of Multidomain Context Information for the Internet of ThingsabstractThe Internet of Things aims to provide the user with deep adaptive intelligence services according to the user’s personalized characteristics. Most of the characteristics are presented in the form of high-level context. But it often lacks methods to obtain high-level context information directly in the Internet of Things. In this paper, so as to achieve the corresponding high-level context information using the specific low-level multidomain context directly obtained by different sensors in the Internet of Things, we present a machine learning method to construct a context fusion model based on the feature selection algorithm and the multiclassification algorithm. First, we propose a wrapper feature selection method based on the genetic algorithm to obtain a simpler and more important subset of the context features from the low-level multidomain context, by defining a suitable fitness function and a convergence condition. Then, we use the decision tree algorithm which is a multiclassification algorithm, based on the rules obtained by training the subset of context features, to determine which high-level context the record set of the low-level context information belongs to. Experiments confirm that the model can be used to achieve higher classification accuracy without more significant time consumption. Bing Jia, Shuai Liu 0002, Yushuai Guan, Wuyungerile Li, Weiwu Ren |
Wirel. Commun. Mob. Comput. | 5 |