VLDB 2026 Research / reviewers in the wild / expert
Zhenyu Cheng 0001
dblp:93/7649-1
· DBLP profile ↗
23ranked-venue papers
2as first author
18since 2021 · last 2026
0000-0003-3292-7428ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 6 since 2021Security and privacy · 5 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | You can run but you can never hide: A multi-module collaborative detection framework based on network traffic
Chengxiang Si, Zhou Zhou 0007, Zhenyu Cheng 0001, Peishuai Sun |
Comput. Networks | 4 |
| 2025 | FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic Classification
Chengxiang Si, Zhenyu Cheng 0001, Chenxu Wang 0006, Jiang Xie 0004, Peishuai Sun, Qingyun Liu 0001 |
INFOCOM | 4 |
| 2025 | Zero in on the Target: A Composite Robust Model for Retrieving Information in Traffic Data to Discover Network AttacksabstractWith the popularization of the Internet and the diversification of attack methods, web security has become an important part of information security. As a carrier of network behavior, traffic can reveal attack behaviors in the Web environment through malicious traffic detection. Since images can fully express spatial features and local associations, it is feasible to visualize traffic as images and retrieve key feature information to detect malicious traffic. However, existing methods are prone to redundancy during feature extraction. Secondly, a single perspective makes it difficult to learn patterns with universality from diverse feature information. In addition, the selection of segmentation thresholds in the preprocessing is closely related to the model's information retrieval effect. The commonly adopted preset thresholds are difficult to cope with the changes in traffic data, limiting the applicability of the existing methods. Therefore, this paper proposes a Multi-Module-Based Composite Robust Model for Network Attack Detection (MCNAD). The model adopts depthwise separable convolution (DSC) to reduce redundant information, proposes a multi-scale feature learning module to enhance the model characterization ability, and proposes a gray level co-occurrence matrix segmentation algorithm with adaptive threshold (GLCM-AT) to optimize data preprocessing. The results show that MCNAD improves detection performance with better detection efficiency, generalization ability, and robustness, demonstrating its wide applicability in multiple scenarios. Chengxiang Si, Zhenyu Cheng 0001 |
ACM Multimedia | 3 |
| 2025 | Digital Scapegoat: An Incentive Deception Model for Resisting Unknown APT Stealing Attacks on Critical Data ResourceabstractIt is a challenging problem to resist unknown advanced persistent threats (APTs) on stealing data resources in an information system of critical infrastructures, because APT attackers have very specific objectives and compromise the system stealthily and slowly. We observe that it is a necessary condition for APT attackers to achieve their campaigns via controlling unknown Trojans to access and exfiltrate critical files. We present a theoretical model called Digital Scapegoat (abbreviated as DS-IDep) that constructs an Incentive Deception defense schema to hijack the attacker’s access to critical files and redirect it to avatar files without awareness. We propose a FlipIDep Game model (GF) and a Markov Game model (GM) to characterize completely the payoffs, equilibria, and best strategies from the perspective of the attacker and the defender respectively. We also design an exponential risk propagation model to evaluate the ability of DS-IDep to eliminate stealing impact when the risk is propagated between states. Theoretically, we can achieve the objective of stealing impact elimination (LK0.7) and the probability of an attack operation bypassing the defense surface is less than 0.1 (r* × μ <0.1) under Stackelberg strategies. We develop a kernel-level incentive deception defense surface according to the theoretical parameters of the DS-IDep. The experimental results show that DS-IDep can resist APT stealing attacks from unknown Trojans. We also evaluate the DS-IDep in five well-known software applications. It demonstrates that DS-IDep can address unknown attacks from compromised software with less than 10% performance overhead. Xiao-chun Yun, Guangjun Wu, Qige Song, Zixian Tang, Zhenyu Cheng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | IMTCDF: A Multi-Module-Based Internet Malicious Traffic Classification and Detection FrameworkabstractRecently, research has shown that neural networks can be utilized for identifying malicious traffic. However, there are shortcomings in existing methods, such as detection rate bottleneck and fewer applicable scenarios. Furthermore, the time-consuming data preprocessing methods negatively impact efficiency of the models and the ability to learn feature information. Besides, the complex fingerprint extraction in traffic is required to solve urgently. Therefore, this paper proposes IMTCDF, a multi-module-based Internet Malicious Traffic Classification and Detection Framework, designed for fast and accurate classification and detection of malicious traffic. The preprocessing module adopts a segmentation method based on global threshold to simplify data processing. In the malicious traffic detection module, this paper designs a Depthwise Separable Convolution with Global Composite Attention Model (DSC-GCA model), benefiting from better capture and learning capability of feature information. We used the publicly available USTF-TFC2016 dataset and the TCD-2022 dataset obtained from autonomous collection in a real Internet environment for our experiments. Multiple groups of experiments show that IMTCDF has outstanding detection capabilities, and the performance remains stable in different scenarios. We selected some models and methods proposed in recent years, which are also used for malicious traffic detection tasks, as a control group for comparative experiments, and the results show that IMTCDF has lower time cost and significant progress in evaluation metrics such as accuracy, precision, recall, and F1-Score. Zhenyu Cheng 0001, Tianning Zang |
CSCWD | 3 |
| 2024 | ProxyKiller: An Anonymous Proxy Traffic Attack Model Based on Traffic Behavior Graphs
Zhenyu Cheng 0001, Chenxu Wang 0006, Peishuai Sun, Jiang Xie 0004, Qingyun Liu 0001 |
ESORICS (2) | 2 |
| 2024 | MLMTD: A Multi-Layer Malicious Traffic Detection Model Based on Multi-Branch Octave Convolution and Attention MechanismabstractMalicious traffic detection is important for the safe operation of cyberspace. Existing methods are difficult to extract discriminative features, leading to the detection rate bottleneck. In addition, the performance is significantly degraded in sample imbalanced scenarios, with poor generalization ability and insufficient scalability. Therefore, this paper proposes a multi-layer malicious traffic detection model based on multi-branch octave convolution and attention mechanism (MLMTD), which adopts multiple modules to extract more diverse feature information and learn important features more adequately in multiple dimensions. Ablation experiments validate the effectiveness of each module. The results in several experimental scenarios show that MLMTD can achieve better results with fewer features and attain superior robustness and generalization ability compared to the control models. Chengxiang Si, Zhenyu Cheng 0001 |
ICASSP | 3 |
| 2024 | A Targeted Adversarial Attack Method for Multi-Classification Malicious Traffic DetectionabstractLeveraging deep learning to detect malicious network traffic is a crucial technology in network management and network security. However, deep learning security has raised concerns among scholars. In this work, we explore executing targeted adversarial attacks for multi-classification malicious traffic detection with limited interactions. Specifically, we constrain the number of interactions with detection and employ a hop-skip-jump attack (HSJA) to generate a small number of adversarial samples. These adversarial samples are then heuristically used to train a generative adversarial network (GAN) to generate a substantial quantity of adversarial samples. Experiments demonstrate that our method is more adversarial and displays a certain degree of generalization compared with other methods. Peishuai Sun, Chengxiang Si, Zhenyu Cheng 0001, Qingyun Liu 0001 |
ICASSP | 4 |
| 2024 | MTDM-MS: A Malicious Traffic Detection Model Based on Multi-Category SignalsabstractThe demand for malicious traffic detection continues to rise along with the development of the Internet. Existing methods perform with flaws in complex feature extraction processes and interference by obfuscation techniques and other means. In addition, the performance is unstable in new scenarios, and the generalization ability is not good enough. Therefore, this paper proposes a malicious traffic detection model based on multi-category signals (MTDM-MS), which adopts multiple modules to extract the features of text sequence signals and image signals of the traffic, respectively, to realize the interaction of various feature information and improve the model's characterization ability. Ablation experiments verify the effectiveness of each module. Experimental results in several datasets show that MTDM-MS possesses considerable detection performance and generalization ability with a 2.2% to 8.4% improvement in macro-F1 compared with the control models. Chengxiang Si, Zhenyu Cheng 0001 |
ICME | 3 |
| 2023 | TCCN: A Network Traffic Classification and Detection Model Based on Capsule NetworkabstractPrivacy information theft traffic is usually detected using traffic classification methods, and deep learning-based detection methods are effective for this task. However, these methods have complex preprocessing processes as well as tend to ignore the deep features of network traffic, while the generalization ability is not outstanding. In this paper, a network traffic classification and detection model TCCN (Traffic Classification Capsule Network) based on capsule network is proposed. Meanwhile, PacketCGAN-based data balancing method is introduced to assist TCCN in traffic classification. A new feature graph vectorization method is used to improve the efficiency of TCCN. In addition, TCCN uses dynamic routing mechanism that can retain more valid traffic characteristics. In parallel, this paper proposes a new loss function to improve the generalization performance of TCCN. The results show that TCCN can show good performance in different experimental scenarios. After effective training, TCCN can also show high detection accuracy in new datasets, and the generalization ability of the model reaches a relatively excellent level. Yafei Sang, Zhenyu Cheng 0001, Tianning Zang |
ICC | 3 |
| 2023 | MTCD-Model: A Two-Layer Model for Malicious Traffic Classification and Detection Based on Hierarchical Feature LearningabstractThe rapid growth of cyber world and higher awareness of security in recent years have contributed to a significant demand in classification and detection of malicious traffic. Neural network is considered one of the effective methods. However, existing methods need to be improved. For example, the model performance is influenced by over dependance on manual design and extraction of feature. In addition, truncating or zero-complementing the traffic data results in loss of key traffic information or irrelevant input, which in turn affects the model performance in classifying and detecting malicious traffic. Motivated by these considerations and demands, this paper proposes a Malicious Traffic Classification and Detection Model (MTCD-Model), a two-layer model based on hierarchical feature learning. This model exploits both the CNN and Bi-SRU to learn the features of raw traffic data in indefinite length by hierarchical learning method, and achieve the classification and detection of malicious traffic with capsule network. The experimental results, based on the primary dataset TCD-2022, show that the F1-Score of MTCD-Model can reach 98.62, while the performance remains stable in different experimental scenarios. In addition, MTCD-Model generates different degrees of improvement in various evaluation metrics compared with the control model. Zhenyu Cheng 0001, Tianning Zang |
IJCNN | 2 |
| 2023 | GPMT: Generating practical malicious traffic based on adversarial attacks with little prior knowledge
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
Comput. Secur. | 5 |
| 2023 | AntCom: An effective and efficient anti-tracking system with dynamic and asymmetric communication channel
Changbo Tian, Zhenyu Cheng 0001 |
J. Netw. Comput. Appl. | 3 |
| 2022 | VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network
Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
CollaborateCom (2) | 3 |
| 2022 | TrafficGCN: Mobile Application Encrypted Traffic Classification Based on GCNabstractWith the gradual adoption of 4G and 5G communication technologies, the number of mobile devices has increased dramatically. Identifying apps can provide technical support for fine-grained network management or optimizing the quality of network connections. The current development of new technologies, such as HTTPS and content delivery networks (CDN) technology, presents new challenges to mobile application classification. Existing techniques either ignore the implicit graph relationships in the traffic or lack comprehensive traffic features analysis, resulting in poor classification accuracy or inapplicability to large-scale data. In this paper, we propose TrafficGCN, a novel mobile application classification technique to solve the above problem. TrafficGCN constructs communication behavior graphs by combining packet-level and flow-level traffic data. The graph convolutional neural network (GCN) is then used to learn a large number of graph connectivity relations and node properties generated by different applications. In addition, we present a traffic graph dataset for mobile application classification. Comparing TrafficGCN with traditional deep learning algorithms (DNN, CNN, LSTM) and the recently developed techniques (MAppGraph, FlowPrint, AppScanner), the experimental results show that it significantly improves classification performance 5.44%-18.72% in various metrics. These results demonstrate that TrafficGCN has great potential for mobile network management, Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
GLOBECOM | 3 |
| 2022 | Effective Malicious URL Detection by Using Generative Adversarial Networks
Jinbu Geng, Zhenyu Cheng 0001 |
ICWE | 4 |
| 2022 | RAAM: A Restricted Adversarial Attack Model with Adding Perturbations to Traffic Features
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
SEC | 5 |
| 2021 | LIFH: Learning Interactive Features from HTTP Payload using Image ReconstructionabstractThe complexity and intelligence of the attacks towards the application layer have raised to an unprecedented level. HyperText Transfer Protocol (HTTP), as the widely used application layer protocol, is part of the main vectors for various malicious attacks. The previous detection based on Deep Packet Inspection (DPI) relies heavily on packets, which leads to insufficient detection and a high false alarm rate. In this paper, we propose LIFH, a deep neural network model equipped with interactive information for detecting application-layer attacks. Firstly, the image reconstruction method is designed to reconstruct the HTTP traffic session into an image. Then, the latent features, instead of explicit features which are typically used in machine learning models, are extracted by HTTP-CNN in order to respond against forgery attacks. Finally, the high-level features are further fed to multi-classifiers to identify the traffic involved in malicious activities. We make exclusive experiments and evaluate the performance of LIFH on the standard dataset CICIDS_2017 and IIE_data collected from critical web servers. The results demonstrate that the proposed model can significantly improve the performance of malicious traffic detection with an accuracy of 99.07% and a false positive rate of 0.40% which is superior to the state of the arts. Jinbu Geng, Yongzheng Zhang 0002, Zhenyu Cheng 0001 |
ICC | 5 |
| 2020 | Efficient Malware Originated Traffic Classification by Using Generative Adversarial NetworksabstractWith the booming of malware-based cyber-security incidents and the sophistication of attacks, previous detections based on malware sample analysis appear powerless due to time-consuming and labor-intensive analysis process. The existing detection methods based on traffic analysis rely heavily on the available traffic patterns, which hinder detecting the zero-day attacks caused by malware variants. In this paper, we propose an approach based on deep learning referred to as TrafficGAN, which analyzes (HTTP) traffic sessions to distinguish between malware-related and normal traffic. We first try to explore traffic patterns of malware variants by adding noise and category condition to the Generative Adversarial Networks (GAN), thus generating various similar but slightly different traffic. And then, we use discriminative model to seek the deviation between abnormal traffic and normal traffic by extracting the essential difference. Notablely, we increase the diversity of data by generating samples adversarially, which enhances the robustness of the system to detect zero-day attacks and highlights the lack of sensitive data in the security community. We conduct extensive experiments on the public dataset and our data collected for specific targets. The results demonstrate that our method achieves superior performance to other methods and protects specific targets from the susceptibility of malware. Yongzheng Zhang 0002, Xiao-chun Yun, Zhenyu Cheng 0001 |
ISCC | 5 |
| 2018 | Important Member Discovery of Attribution Trace Based on Relevant Circle (Short Paper)
Jian Xu 0010, Xiao-chun Yun, Yongzheng Zhang 0002, Zhenyu Cheng 0001 |
CollaborateCom | 4 |
| 2018 | MUI-defender: CNN-Driven, Network Flow-Based Information Theft Detection for Mobile Users
Zhenyu Cheng 0001, Xunxun Chen, Yongzheng Zhang 0002, Jian Xu 0010 |
CollaborateCom | 1 |
| 2018 | Community Discovery of Attribution Trace Based on Deep Learning Approach
Jian Xu 0010, Xiao-chun Yun, Yongzheng Zhang 0002, Zhenyu Cheng 0001 |
ICICS | 4 |
| 2017 | Detecting Information Theft Based on Mobile Network Flows for Android UsersabstractWith the widespread use of smartphones, more and more malicious attacks happen with information leakage from apps installed on users' devices. The adversary always uses a malware as the client to take remote control of smartphones, and leverages the vulnerability of operation systems to send back the collected information without users' permissions. All the information has to be transferred by network traffic. In this paper, we consider that different apps maybe generate different network flows by different operations, and the "shapes" of the benign flows and malicious ones will be diverse. Thus we propose a detection model based on the analysis of relationships between behavior patterns and network flows, which achieves our goal by using the Random Forest machine learning algorithm to classify the network flows into benign or malicious. To further improve the controllability of the experiment, we design an app called Moledroid to simulate malwares by uploading the user's privacy without authorization, in addition, we can change the behavior pattern of the app to complete our evaluation. Finally, we run this app and several benign apps to generate traffic to detect the malicious network flows, and it shows that our detection model can achieve precision and accuracy higher than 95%, which demonstrates that our model is suitable for detecting the network flows of information theft. Zhenyu Cheng 0001, Xunxun Chen, Yongzheng Zhang 0002, Yafei Sang |
NAS | 1 |