EDBT 2026 Demo / reviewers in the wild / expert
Dongxu Han
dblp:02/9013
· DBLP profile ↗
12ranked-venue papers
2as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3Security and privacy · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cross Page Recognition Methods for Encrypted Web Application FingerprintingabstractThe widespread implementation of the HTTPS protocol has greatly bolstered user privacy and data security. However, the widespread use of the HTTPS protocol has also provided criminals with a cloak to disseminate harmful content through websites, thereby undermining the integrity of the online environment. Web page fingerprinting has emerged as a highly popular method for web application identification. Yet, due to the frequent updates of web applications, existing methods struggle with accuracy issues. To tackle these challenges, this paper introduces a novel approach called CrossWP, which leverages cross-web page fingerprinting to enhance the security of the network environment. CrossWP aims at classifying web applications, which novelly constructs the cross web pages behavior sequences on handshake, request and response sequence. CrossWP uses the transformer model based on multi-sequence fusion to thoroughly learn and integrate these unique spatio-temporal sequence characteristics. This model can also capture the internal similarity of behavior sequence, and achieving high accuracy. The effectiveness of CrossWP is validated through closed-world and open-world evaluations, which involve identifying and classifying news websites, social websites, online video websites and e-commerce websites. The results indicate that CrossWP outperforms existing algorithms in terms of both robustness and accuracy. Zelin Cui, Pu Dong, Dongxu Han, Bo Jiang 0013, Zhigang Lu 0002, Huamin Feng |
CSCWD | 3 |
| 2025 | An Approach for Attack Chain Context Inference and Completion Based on Large Language ModelsabstractAlert underreporting presents a significant challenge to the reconstruction of attack chains, as it often leads to the absence of critical information necessary for fully presenting the entire attack. To address this issue, this paper proposes an approach for attack chain context inference and completion based on Large Language Models. By integrating an attack knowledge base, this approach leverages LLM-driven inference to identify missing attack stages and uncover potential attack behaviors. Experimental results demonstrate that this approach can effectively detect omitted alerts and complete the attack chain, thereby enhancing the integrity of attack detection. Dan Du, Changzhi Zhao, Yunpeng Li 0006, Dongxu Han, Bo Jiang 0013, Zhigang Lu 0002 |
SMC | 4 |
| 2025 | RaySHapke: A Bayesian Inversion Analysis of Lunar Surface Parameters Utilizing the Hapke Model Based on the Raytracing Shadowing FunctionabstractThe Moon’s distinctive spatial weathering environment and the internal dynamics of its evolutionary process have produced intricate lunar characteristics that make remote sensing data interpretation challenging. The variety of features and the absence of observational data have resulted in the issue of ill-posed inversion in lunar remote sensing. The Hapke radiative transfer model employed in the current inversion is often oversimplified by idealized assumptions, including applying a single-parameter Gaussian distribution to represent macroscopic roughness, significantly diverging from the actual lunar surface characteristics. In addition, the macroscopic roughness parameter of the Hapke model has some coupling with the single-scattering albedo, making inversion difficult. This study proposes an enhanced Hapke model defined as RaySHapke, to accurately represent the actual lunar surface parameters and simulate shading, shadowing, and multiple scattering effects by raytracing. This approach presents the macroroughness shadowing function and proposes an approximate Bayesian inversion framework to enhance the stability and efficiency of the inversion process. The results indicate that raytracing can proficiently replicate the terrain effect. Comparison of the original Hapke model with the RaySHapke model suggests that the raytracing shade function may enhance the accuracy and stability of the inversion of single-scattering albedo and phase function parameters. This study provides a solid foundation for interpreting the physical properties of the lunar surface, as well as lunar science and engineering analysis. Dongxu Han, Peng Zhang 0100, Chengbao Liu, Wanyue Liu, Zheng Bo |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2024 | FREDet: Fine-Grained Malicious Traffic Detection Based on Frequency Domain FeaturesabstractMachine learning methods have shown significant advantages in detecting malicious traffic, particularly identifying zero-day attacks and unknown threats. However, existing detection methods based on statistical features are susceptible to deception and evasion by attackers, resulting in reduced detection accuracy and challenges in achieving fine-grained detection. To address these issues, we propose FREDet, a fine-grained malicious traffic detection method based on frequency domain features. FREDet employs discrete wavelet transform to extract frequency domain features from network traffic and incorporates a new traffic aggregation method, significantly enhancing feature representativeness and detection accuracy for robust, fine-grained detection. Experiments on a multi-type attack dataset demonstrate that FREDet can detect malicious traffic with high precision, outperforming existing state-of-the-art methods, achieving accuracies of over 98.63% and 99.93% in detecting fine-grained attack categories and known attack subcategories, respectively. Zekai Song, Yunpeng Li 0006, Changzhi Zhao, Dongxu Han |
TrustCom | 5 |
| 2024 | Contrast-Guided Line Segment DetectionabstractDue to the effects of quantization error and image noise, detecting ‘meaningful’ line segments from an image with high continuity is a challenging task. To pursue this goal, a novel line segment detector, called thecontrast-guided line segment detector(CGLSD), is proposed in this paper. Our basic idea is to integrate a low-level image attribute, i.e.,edge contrast, into the line segment detection process for improving line continuity. After applying an edge detector to the input image, the edge contrast is exploited to guide the growth of aline-support regionfor each line segment individually. This is achieved by evaluating edge pixels as well as those non-edge pixels that are nearby the edges. As a result, some of the non-edge pixels are re-considered as ‘edge’ pixels and included for establishing the support region. Reversely, certain edge pixels might be treated as ‘non-edge’ pixels instead and excluded from the region. Since each support region is supposed to yield onlyoneline segment, each formed support region needs to have arefinementby removing those edge pixels that do not belong to it. Lastly, the support region is required to pass through avalidationcheck that might lead to a complete discard of the line segment due to its low confidence. Extensive experiments are conducted and compared with multiple state-of-the-arts on two datasets, including the one from us with manually-annotated ground truth. The results have shown that the proposed CGLSD can deliver superior performance in nearly all test cases. Zikai Wang 0007, Baojiang Zhong, Dongxu Han, Kai-Kuang Ma |
IEEE Signal Process. Lett. | 3 |
| 2023 | HANDOM: Heterogeneous Attention Network Model for Malicious Domain Detection
Qing Wang 0041, Cong Dong, Shijie Jian, Dan Du, Zhigang Lu 0002, Yinhao Qi, Dongxu Han, Xiaobo Ma 0001, Fei Wang 0014 |
Comput. Secur. | 7 |
| 2022 | DCC-Find: DNS Covert Channel Detection by Features Concatenation-Based LSTMabstractDNS (Domain Name System) plays an important role in network communication and it is rarely blocked by firewalls and intrusion detection systems (IDS). It is a suitable way for attackers to build DCC (DNS Covert Channel), which is used for data exfiltration. In recent years, some DCC detection methods have been proposed based on deep learning and there is no need for manual feature extraction. However, some expert knowledge is helpful to express the DNS characteristic. In this paper, we propose a FC-LSTM (Features Concatenation-based LSTM) model to detect DCC. The statistical features are concatenated with the output features of the LSTM model. This method makes the expression of DNS domain names more abundant. The experimental results have shown that the DCC traffic can be identified from normal traffic via this model, and the recognition rate is significantly improved compared with the traditional LSTM model and CNN model. In addition, we implement multi-classification in terms of the DCC tools (some of them are used in APT32). We also add generalization DNS packets (simulating APT34 traffic using DCC for stealing and attacking) to verify the robustness of our model. The FC-LSTM model has a good detection performance as well. Dongxu Han, Pu Dong, Xiang Cui, Jiawen Diao, Qing Wang 0041, Dan Du |
TrustCom | 1 |
| 2019 | Knowledge Distillation from Bert in Pre-Training and Fine-Tuning for Polyphone DisambiguationabstractPolyphone disambiguation aims to select the correct pronunciation for a polyphonic word from several candidates, which is important for text-to-speech synthesis. Since the pronunciation of a polyphonic word is usually decided by its context, polyphone disambiguation can be regarded as a language understanding task. Inspired by the success of BERT for language understanding, we propose to leverage pre-trained BERT models for polyphone disambiguation. However, BERT models are usually too heavy to be served online, in terms of both memory cost and inference speed. In this work, we focus on efficient model for polyphone disambiguation and propose a two-stage knowledge distillation method that transfers the knowledge from a heavy BERT model in both pre-training and fine-tuning stages to a lightweight BERT model, in order to reduce online serving cost. Experiments on Chinese and English polyphone disambiguation datasets demonstrate that our method reduces model parameters by a factor of 5 and improves inference speed by 7 times, while nearly matches the classification accuracy (95.4% on Chinese and 98.1% on English) to the original BERT model. Xu Tan 0003, Jun-Wei Gan, Sheng Zhao 0002, Dongxu Han, Hongzhi Liu 0001, Tao Qin 0001, Tie-Yan Liu |
ASRU | 5 |
| 2019 | An Approach for Scale Suspicious Network Events DetectionabstractDetecting the real suspicious events from a large number of low-quality alerts is a severe challenge to the security operations center teams. In this paper, we present an approach to this problem by following the sequence of machine learning steps. The highlight of our approach is the method to generate two simple but effective categories of features based on group and aggregation operations, which can scale with a large number of alerts using MapReduce framework. The two generated types of features are local features and global features. The local features cover the alert aggregation information of the same group of events, while the global features cover the network aggregation information of different groups of events. Moreover, we also introduce the model stacking mechanism to enhance the robustness of the model. The proposed approach achieves AUC scores of 0.9512 on the validating dataset and 0.9303 on the test set, which is the 2ndhighest final score in the competition. Cong Dong, YunJian Zhang, Bo Jiang 0013, Dongxu Han, Baoxu Liu |
IEEE BigData | 5 |
| 2019 | Retweeting Prediction Using Matrix Factorization with Binomial Distribution and Contextual Information
Bo Jiang 0013, Zhigang Lu 0002, Jianjun Wu 0004, Feng Yi, Dongxu Han |
DASFAA (2) | 6 |
| 2015 | The new architecture of FC storage network based on controllerabstractWith the rapid development of Internet technology and the explosive growth of data, the storage system designed by tightly coupled hardware and software is limiting the development of storage technology severely, and unable to meet the fast changing needs in the mobile Internet and exploding big data era. Software Defined Storage (SDS) as a new storage system architecture is more suitable for the development of the next-generation data centers. This paper proposed a new Controller-based FC Storage Network (CSN) architecture using the idea of SDS technology. CSN decoupling control plane protocol of FC switch from data plane deployed control plane protocol and distributed functions in the controller. This paper described the design and implementation of this architecture and verifies the feasibility through the actual development environment. Finally, as a result of experiments, server can establish a connection with the storage more quickly in CSN, furthermore, CSN has a faster convergence, as well as more reliability and scalability. Yifei Lu 0001, Dongxu Han |
APNOMS | 2 |
| 2010 | Enhancing Domain Portability of Chinese Segmentation Model Using Chi-Square Statistics and Bootstrapping
Baobao Chang, Dongxu Han |
EMNLP | 2 |