VLDB 2026 Research / reviewers in the wild / expert
Jiang Xie 0004
dblp:x/JXie-4
· DBLP profile ↗
18ranked-venue papers
5as first author
15since 2021 · last 2025
0000-0003-3219-3102ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 7 since 2021Computer networks · 7 · 2 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Open-World DoH Tunnel Detection: A Dual-View Contrastive Learning Framework with Adaptive Feature BoundariesabstractThe emergence of DNS-over-HTTPS (DoH) tunnels poses significant challenges to network security, particularly when encountering unknown traffic patterns not seen during training. Existing approaches struggle to effectively identify novel DoH tunnel variants while maintaining accurate classi-fication of known traffic patterns. In this paper, we propose DualConBound, a novel framework that combines dual-view contrastive learning with dynamic feature boundary estimation to address open-set network traffic classification. Our approach leverages complementary traffic representations and adaptive decision boundaries to better distinguish between known and unknown traffic patterns. Through extensive experiments on real-world network traffic datasets, we demonstrate that our framework achieves 91 % accuracy on known traffic patterns and 71 % accuracy on unknown variants, outperforming other methods by 6% in open-set scenarios. Our work provides a robust solution for identifying emerging DoH tunnel threats in real-world network environments and establishes a new paradigm for open-set network traffic classification. Beibei Feng, Zhefeng Nan, Jiang Xie 0004, Tianning Zang, Jingrun Ma |
CSCWD | 4 |
| 2025 | FlowMiner: A Powerful Model Based on Flow Correlation Mining for Encrypted Traffic Classification
Chengxiang Si, Zhenyu Cheng 0001, Chenxu Wang 0006, Jiang Xie 0004, Peishuai Sun, Qingyun Liu 0001 |
INFOCOM | 6 |
| 2025 | AdvTG: An Adversarial Traffic Generation Framework to Deceive DL-Based Malicious Traffic Detection ModelsabstractDeep learning-based (DL-based) malicious traffic detection models are effective but vulnerable to adversarial attacks. Existing adversarial attacks have shown promising results when targeting traffic detection models based on statistics and sequence features. However, these attacks are less effective against models that rely on payload analysis. The main reason is the difficulty in generating semantic, compliant, and functional payloads, which limits their practical application. Peishuai Sun, Xiao-chun Yun, Chengxiang Si, Jiang Xie 0004 |
WWW | 6 |
| 2025 | Sample analysis and multi-label classification for malicious sample datasets
Jiang Xie 0004, Xiao-chun Yun, Chengxiang Si |
Comput. Networks | 1 |
| 2025 | Traffic2Chain: Revealing Covert Multi-Step Attacks Through Unsupervised Traffic Behaviour CorrelationabstractWith the continuous development of network technology, covert multi-step attacks have become one of the significant attack methods. It is a multi-step attack with the intention of destroying the system- or data-privacy, such as network stealing. Current methods usually generate single-step alerts first and then perform correlation analysis. However, it is difficult for these methods to perform fine-grained annotation and alert amount control for single-step alerts, as well as to completely correlate the alerts of different phases into a chain due to alert fatigue. In this paper, we propose Traffic2Chain, an innovative unsupervised traffic behaviour correlation method to detect covert multi-step attacks from the network side. Traffic2Chain (1) generates alerts at different phases in real-time and annotates to sub-techniques based on MITRE ATT&CK knowledge database; (2) performs alert clustering based on SIMCSE and automatically generates event descriptions based on the Large Language Model (LLM) technique, and (3) extracts the attack chain through multi-dimensional information correlation to reveal the complete attack process. Experimental results demonstrate that the F1 score of Traffic2Chain reaches 98.36%, which has a significant advantage over other methods. In the real-world network, the detection speed can reach 40 Gbps. Most importantly, we discovered an unknown attack pattern based on Traffic2Chain - attackers delivered a variant of the Silver Fox Trojan by impersonating VPN services, eventually building a botnet with stealing capabilities and a node size of more than one million. Jiang Xie 0004, Xiao-chun Yun, Peishuai Sun |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | ProxyKiller: An Anonymous Proxy Traffic Attack Model Based on Traffic Behavior Graphs
Zhenyu Cheng 0001, Chenxu Wang 0006, Peishuai Sun, Jiang Xie 0004, Qingyun Liu 0001 |
ESORICS (2) | 6 |
| 2024 | Let model keep evolving: Incremental learning for encrypted traffic classification
Xiang Li 0135, Jiang Xie 0004, Qige Song, Yafei Sang, Yongzheng Zhang 0002, Tianning Zang |
Comput. Secur. | 2 |
| 2023 | DRDoSHunter: A Novel Approach Based on FDA and Inter-flow Features for DRDoS DetectionabstractIn recent years, Distributed Reflective Denial of Service (DRDoS) attacks have emerged as a major threat to network security, utilizing IP spoofing and amplification mechanisms to drain network bandwidth. Existing approaches for DRDoS detection lack sophistication in feature selection and focus primarily on detection rather than fine-grained classification and targeted mitigation. In this paper, we propose DRDoSHunter, a novel approach that addresses these limitations. DRDoSHunter employs Frequency Domain Analysis (FDA) and inter-flow features to extract effective and robust features from continuous time series data. By utilizing a deep residual network model, our approach achieves accurate and efficient classification of DRDoS attacks at a fine-grained level. Experimental results on the CIC-DDoS2019 public dataset demonstrate that DRDoSHunter outperforms popular detection models, achieving an Fl-Score of over 98.44% for DRDoS attack detection and classification. Yujia Zhu, Jiang Xie 0004, Yitong Cai |
ISCC | 4 |
| 2023 | Listen to Minority: Encrypted Traffic Classification for Class Imbalance with Contrastive Pre-TrainingabstractMobile Internet has profoundly reshaped modern lifestyles in various aspects. Encrypted Traffic Classification (ETC) naturally plays a crucial role in managing mobile Internet, especially with the explosive growth of mobile apps using encrypted communication. Despite some existing learning-based ETC methods showing promising results, three-fold limitations still remain in real-world network environments, i) label bias caused by traffic class imbalance, ii) traffic homogeneity caused by component sharing, and iii) training with reliance on sufficient labeled traffic. None of the existing ETC methods can address all these limitations. In this paper, we propose a novel Pre-trAining Semi-Supervised ETC framework, dubbed PASS. Our key insight is to resample the original train dataset and perform contrastive pre-training without using individual app labels directly to avoid label bias issues caused by class imbalance, while obtaining a robust feature representation to differentiate overlapping homogeneous traffic by pulling positive traffic pairs closer and pushing negative pairs away. Meanwhile, PASS designs a semi-supervised optimization strategy based on pseudo-label iteration and dynamic loss weighting algorithms in order to effectively utilize massive unlabeled traffic data and alleviate manual train dataset annotation workload. PASS outperforms state-of-the-art ETC methods and generic sampling approaches on four public datasets with significant class imbalance and traffic homogeneity, remarkably pushing the F1 of Cross-Platform215 with 1.31%$\uparrow$, ISCX-17 with 9.12%$\uparrow$. Furthermore, we validate the generality of the contrastive pre-training and pseudo-label iteration components of PASS, which can adaptively benefit ETC methods with diverse feature extractors. Xiang Li 0135, Juncheng Guo, Qige Song, Jiang Xie 0004, Yafei Sang, Yongzheng Zhang 0002 |
SECON | 4 |
| 2023 | GPMT: Generating practical malicious traffic based on adversarial attacks with little prior knowledge
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
Comput. Secur. | 3 |
| 2022 | VT-GAT: A Novel VPN Encrypted Traffic Classification Model Based on Graph Attention Neural Network
Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
CollaborateCom (2) | 5 |
| 2022 | TrafficGCN: Mobile Application Encrypted Traffic Classification Based on GCNabstractWith the gradual adoption of 4G and 5G communication technologies, the number of mobile devices has increased dramatically. Identifying apps can provide technical support for fine-grained network management or optimizing the quality of network connections. The current development of new technologies, such as HTTPS and content delivery networks (CDN) technology, presents new challenges to mobile application classification. Existing techniques either ignore the implicit graph relationships in the traffic or lack comprehensive traffic features analysis, resulting in poor classification accuracy or inapplicability to large-scale data. In this paper, we propose TrafficGCN, a novel mobile application classification technique to solve the above problem. TrafficGCN constructs communication behavior graphs by combining packet-level and flow-level traffic data. The graph convolutional neural network (GCN) is then used to learn a large number of graph connectivity relations and node properties generated by different applications. In addition, we present a traffic graph dataset for mobile application classification. Comparing TrafficGCN with traditional deep learning algorithms (DNN, CNN, LSTM) and the recently developed techniques (MAppGraph, FlowPrint, AppScanner), the experimental results show that it significantly improves classification performance 5.44%-18.72% in various metrics. These results demonstrate that TrafficGCN has great potential for mobile network management, Zhenyu Cheng 0001, Jiang Xie 0004, Peishuai Sun |
GLOBECOM | 5 |
| 2022 | RAAM: A Restricted Adversarial Attack Model with Adding Perturbations to Traffic Features
Peishuai Sun, Jiang Xie 0004, Zhenyu Cheng 0001 |
SEC | 3 |
| 2022 | Analysis and Detection against Network Attacks in the Overlapping Phenomenon of Behavior Attribute
Jiang Xie 0004, Yongzheng Zhang 0002, Peishuai Sun |
Comput. Secur. | 1 |
| 2022 | Detecting unknown HTTP-based malicious communication behavior via generated adversarial flows and hierarchical traffic features
Xiao-chun Yun, Jiang Xie 0004, Yongzheng Zhang 0002, Peishuai Sun |
Comput. Secur. | 2 |
| 2020 | HSTF-Model: An HTTP-based Trojan detection model via the Hierarchical Spatio-temporal Features of Traffics
Jiang Xie 0004, Xiao-chun Yun, Yongzheng Zhang 0002 |
Comput. Secur. | 1 |
| 2019 | A Method Based on Hierarchical Spatiotemporal Features for Trojan Traffic DetectionabstractTrojans are one of the most threatening network attacks currently. HTTP-based Trojan, in particular, accounts for a considerable proportion of them. Moreover, as the network environment becomes more complex, HTTP-based Trojan is more concealed than others. At present, many intrusion detection systems (IDSs) are increasingly difficult to effectively detect such Trojan traffic due to the inherent shortcomings of the methods used and the backwardness of training data. Classical anomaly detection and traditional machine learning-based (TML-based) anomaly detection are highly dependent on expert knowledge to extract features artificially, which is difficult to implement in HTTP-based Trojan traffic detection. Deep learning-based (DL-based) anomaly detection has been locally applied to IDSs, but it cannot be transplanted to HTTP-based Trojan traffic detection directly. To solve this problem, in this paper, we propose a neural network detection model (HSTF-Model) based on hierarchical spatiotemporal features of traffic. Meanwhile, we combine deep learning algorithms with expert knowledge through feature encoders and statistical characteristics to improve the self-learning ability of the model. Experiments indicate that F1of HSTF-Model can reach 99.4% in real traffic. In addition, we present a dataset BTHT consisting of HTTP-based benign and Trojan traffic to facilitate related research in the field. Jiang Xie 0004, Yongzheng Zhang 0002, Xiao-chun Yun |
IPCCC | 1 |
| 2019 | A Method of HTTP Malicious Traffic Detection on Mobile NetworksabstractAiming at solving the problem of HTTP malicious traffic detection on mobile networks, we propose a method of HMTD(HTTP Malicious Traffic Detection) based on the spatiotemporal sequence characteristics of traffic data. The traditional malicious traffic detection methods are relatively simple and mainly biased towards misuse detection or abnormal detection and probably suffer from a high false positive rate or false negative rate, so they are difficult to adapt to the current rapid development of the Internet. HMTD uses neural networks for malicious traffic identification, and extracts features from malicious and normal HTTP traffic, which can produce excellent detection results. HMTD utilizes CNN to extract the packet spatial characteristics in the traffic, and utilizes LSTM to extract the temporal characteristics between the packets in the traffic. The experimental results demonstrate that the proposed method can achieve an accuracy of more than 99.4% in the actual network environment and has excellent performance in terms of Precision and Recall. Xiao-chun Yun, Mao Tian, Jiang Xie 0004, Yongzheng Zhang 0002, Yu Zhou 0028 |
WCNC | 4 |