EDBT 2026 Demo / reviewers in the wild / expert
Yongjuan Wang
dblp:06/10367
· DBLP profile ↗
44ranked-venue papers
0as first author
41since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 17 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 9 since 2021Computer networks · 7 · 7 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | SCALA-NIDS: Safety-constrained LLM-Advised closed-loop adaptation for online open-world network intrusion detection
Xiaojie Qin, Qingjun Yuan, Haopeng Fan, Pinghui Wang, Jihong Teng, Siqi Lu, Yongjuan Wang |
Expert Syst. Appl. | 8 |
| 2026 | UI2C: An Adaptive Boundary Learning Method for Imbalanced Malicious Traffic Detection
Qingjun Yuan, Yanbei Zhu, Yongjuan Wang, Guangsong Li |
ICIC (11) | 4 |
| 2026 | Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsabstractLarge Language Models (LLMs), as common components of modern web application backends and online services, are being widely deployed across various web infrastructures in the .gguf single-file format. This trend exposes their model parameter space to an unprecedented hardware attack surface, such as Bit-Flip attacks (BFA). This paper is the first to systematically discover and validate the existence of single-bit vulnerabilities in LLMs weight files: In the .gguf quantization format of mainstream open-source models (such as DeepSeek, QWEN), flipping a single bit can induce three types of targeted semantic-level faults, respectively-Artificial Flawed Intelligence (outputting factual errors), Artificial Weak Intelligence (catastrophic model failure), and Artificial Bad Intelligence (generating harmful content). By building an information-theoretic weight sensitivity entropy model and a probabilistic heuristic scanning framework called BitSifter, we achieved efficient localization of critical vulnerable bits in models with hundreds of millions of parameters. Furthermore, an end-to-end remote BFA chain was designed, enabling semantic-level attacks in real-world web server deployment scenarios: At an attack frequency of 464.3 times per second, the average time required for the first successful flip of the target bit is 31.7 seconds, without requiring high-cost equipment or complex prompt engineering. This study reveals a critical finding: under relatively modest remote-attack conditions, requiring only conventional network connectivity, flipping a single vulnerable bit within the tensor data segment can cause models deployed in web service environments to autonomously generate extremely malicious responses, such as ''humans should be exterminated'', or produce naturally fluent and difficult-to-detect erroneous replies to ordinary user queries. This demonstrates a pervasive and exploitable security vulnerability in LLMs systems at the fundamental hardware level. Siqi Lu, Zhaoxuan Li, Ziming Zhao 0008, Qingjun Yuan, Yongjuan Wang |
WWW | 7 |
| 2026 | DelegateTracker: Delegatecall vulnerability detection tool based on read-write data flow capture algorithmabstractDelegatecall vulnerability, as one of the most cunning vulnerabilities, has caused great trouble to the development of smart contracts. Aiming at the high false-positive rate of detection results of existing smart contract vulnerability detection tools and the irrationality of delegatecall by discarding, this paper innovatively proposes a delegatecall vulnerability detection tool DelegateTracker. It is based on the delegatecall vulnerability detection logic of the read-write data flow capture algorithm, and through the attack path search module to determine the execution path of the function that can modify the state variables in the called contract, to prove the necessary conditions for the existence of the vulnerability, and then through the attack path validation module to prove the sufficient conditions for the existence of the vulnerability, so as to discover the vulnerability. The tool not only successfully corroborates the existence of delegatecall vulnerabilities in Parity Wallet, but also discovers untriggered delegatecall vulnerabilities and their trigger paths among them. We used DelegateTracker to discover for the first time a caller contract with a delegatecall vulnerability on 1 existing public chain, outputting 3 attack paths with a value of 0.19 ETH. In addition, we use DelegateTracker to analyze 12,402 smart contracts for alerts when called by delegatecall, and find that 215 contracts have delegatecall vulnerabilities and output caller warning messages. Wenrui Cao, Peixuan Feng, Siqi Lu, Yongjuan Wang, Runnan Yang |
Blockchain Res. Appl. | 4 |
| 2026 | Robust intrusion detection in CPS: A pre-training-based multi-view feature collaboration and correlation analysis method
Qingjun Yuan, Qianwei Meng, Yanbei Zhu, Gang Yu 0005, Xiangbin Wang, Yongjuan Wang |
Comput. Networks | 8 |
| 2026 | Who is the wolf in sheep's clothing? a context-aware trust evaluation model for malicious UAV detection during authentication
Qingjun Yuan, Pinghui Wang, Lidong Li, Yongjuan Wang |
Comput. Networks | 8 |
| 2026 | Statistical fault analysis of Ascon: multiple distinguishers and impossible-state exploitationabstractAbstract With the widespread deployment of the lightweight cryptography (LWC) standard Ascon in resource-constrained devices, research on physical attacks against Ascon, especially fault attacks, has made noticeable progress in recent years. Existing fault attacks on Ascon often require substantial fault injections. To address this, we propose scoring functions with multiple distinguishers for statistical ineffective fault analysis (SIFA), statistical effective fault analysis (SEFA), and statistical hybrid fault analysis (SHFA) to recover key bits. In addition, we propose an impossible statistical effective fault analysis (ISEFA) that exploits an impossible event in the fault-induced distribution to directly eliminate incorrect key hypotheses, reducing reliance on complex computations of distinguishers. We conduct extensive simulations and evaluate the number of fault injections, recovery accuracy, success rate, and time overhead across different distinguisher-analysis combinations. The results show that, under SHFA with the GF distinguisher, only 34 fault injections are sufficient to achieve a 99% success rate for recovering a 128-bit key, which is fewer than prior results on Ascon fault analysis. Moreover, we discuss the practical feasibility of the proposed methods and outline two conceptually motivated directions for potential countermeasures. Zhaoxuan Li, Siqi Lu, Qingjun Yuan, Yongjuan Wang |
Cybersecur. | 5 |
| 2026 | Enhanced Template Attack Against Dilithium: Leveraging Dual-Loss Feature ExtractionabstractAs a post-quantum digital signature scheme, Dilithium was specifically designed to withstand known quantum algorithm attacks, and its side-channel resistance has garnered significant research attention. However, current side-channel attacks against Dilithium exhibit several limitations: (1) failure to leverage low-correlation characteristics in power traces, (2) loss functions limited to categorical information extraction from power traces, (3) dependency on specific coefficient recovery conditions while neglecting inter-coefficient statistical dependencies, (4) requirement for separate profiling models per intermediate value, resulting in substantial information loss. To address these limitations, we propose an enhanced template attack framework integrating deep learning with classical template attack methodology. Our approach employs a dual-loss similarity learning mechanism for feature extraction from high-dimensional power traces, enabling the construction of more discriminative templates while preserving weakly correlated features. Through assembly-level analysis of the y polynomial generation routine, we reveal inherent correlations among coefficientsyk0,yk1,yk2,yk3. Building on this discovery, our dual-loss similarity learning framework is designed to capture these inter-coefficient relationships, preserving their intrinsic dependencies while achieving effective inter-class separation and intra-class aggregation properties, which significantly enhances the effectiveness of subsequent template attacks. Experimental results on Cortex-M4 power traces demonstrate our method achieves 32.94% polynomial coefficient recovery accuracy for polynomial coefficients y, outperforming conventional SOD-based (83% improvement), T-Test-based (97%), and PCA-based template attacks (197% enhancement). Furthermore, complete private key recovery is achieved with merely 14 power traces under specific conditions. This DL-enhanced template attack framework demonstrates superior side-channel leakage exploitation, yielding substantial performance enhancements over conventional approaches. Haojin Zhang, Qingjun Yuan, Yaoling Ding, An Wang 0001, Hailong Zhang 0001, Haopeng Fan, Siqi Lu, Yongjuan Wang |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 8 |
| 2026 | When Unknown Threat Meets Label Noise: A Self-Correcting FrameworkabstractNetwork intrusion detection systems (NIDS) are crucial for network management and security. However, in real-world scenarios, NIDS faces two core challenges: (i) label noise, where mislabeled samples in the training data distort the model's decision boundaries; (ii) unknown attack detection, where existing methods struggle to identify novel attack patterns in dynamic attack environments. More critically, these two challenges are interlinked, forming a vicious cycle that continuously degrades the overall reliability of NIDS. Existing research often addresses these issues in isolation, and no method has yet been proposed to coordinate their antagonistic effects systematically. To tackle this open problem, we propose AEGIS-Net for the first time—a dual anti-noise framework based on multi-prototype correction and model-agnostic detection. AEGIS-Net introduces a density-difference-driven multi-prototype competition mechanism, which achieves fine-grained noise label correction through feature space sub-cluster analysis. We also design a distribution-independent k-nearest neighbors detection paradigm, using the corrected compact feature space to determine unknown attacks in open environments. The two modules are collaboratively optimized through a shared encoder, forming a positive cycle of noise suppression and detection enhancement. Extensive experiments on real-world datasets validate the effectiveness of AEGIS-Net in addressing these dual challenges. Notably, under 50% asymmetric noise conditions, AEGIS-Net achieves classification accuracy of 89.02% for known attacks and 98.76% for unknown attack detection on the MAL_TLS2023 dataset. Theoretical proofs and visualization analysis reveal the anti-noise properties of AEGIS-Net under feature space stability constraints. Our code is available athttps://github.com/niebikong/AEGIS-Net. Qianwei Meng, Qingjun Yuan, Pinghui Wang, Siqi Lu, Guangsong Li, Yongjuan Wang, Xiaohong Guan |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | An Enhanced and Lightweight Anonymous Authentication Protocol Based on PUF for VANETsabstractWith the rapid advancement of mobile communication technologies, privacy preservation in VANETs has emerged as a pivotal research frontier. Previous authentication protocols often face challenges such as key leakage risks and high computational overhead. Physical Unclonable Functions (PUFs), as a lightweight hardware primitive, offer a promising solution for enhancing security in VANETs. Recently, Xie et al. designed an anonymous authentication protocol for VANETs. Unfortunately, our analysis reveals that their protocol cannot resist ephemeral key leakage attacks. To address these limitations, we propose an enhanced PUF-based anonymous authentication protocol, referred to as iXDZ. Our protocol leverages PUF challenge-response mechanisms to generate real-time vehicle keys, eliminating the need to store long-term keys on vehicles and thereby preventing physical key extraction attacks. Our protocol not only resists ephemeral key leakage attacks but also utilizes the uniqueness, unpredictability, and tamper-resistance of PUF to defend against RSU capture attacks and various physical attacks, meeting the diverse security requirements of VANETs. Furthermore, it is anonymous and lightweight, protecting user privacy and enhancing overall network trust. We rigorously demonstrate the security of iXDZ under the random oracle model and supplement the proof utilizing the Scyther formal analysis tool. Performance evaluations reveal that iXDZ significantly enhances security while reducing computational and communication overhead. Additionally, a case study highlights that iXDZ achieves a 33.3% reduction in execution time compared to the original protocol. Yidan Liu, Xingyun Hu, Yanbei Zhu, Qingjun Yuan, Yongjuan Wang |
IEEE Trans. Intell. Transp. Syst. | 7 |
| 2025 | A Multimodal Asynchronous Federated Learning Approach for Encrypted Traffic Classification
Xiangbin Wang, Qingjun Yuan, Yongjuan Wang |
Inscrypt (2) | 3 |
| 2025 | MH-GAT: A Buffer Overflow Vulnerability Detection Method via Cross-Graph Semantic Alignment
Qunlong Wang, Peixuan Feng, Wenrui Cao, Yuxin Zhong, Siqi Lu, Yongjuan Wang |
ICA3PP (7) | 7 |
| 2025 | FCAL: An Asynchronous Federated Contrastive Semi-supervised Learning Approach for Network Traffic Classification
Qingjun Yuan, Weina Niu, Yanbei Zhu, Yongjuan Wang |
ICICS (3) | 6 |
| 2025 | SM2-VBKE: Achieving Cryptographic Binding Between Verification Integrity and Key Generation
Siqi Lu, Yongjuan Wang, Liujia Cai, Wenyi Chen, Fenghua Jiang |
ICICS (1) | 3 |
| 2025 | PSI-TR-ABE: A Traceable and Policy-Hidden Attribute-Based Encryption Scheme for Medical Data SharingabstractAmidst rapid advancements in precision and translational medicine, cross-institutional and cross-regional sharing of medical research data is increasingly critical. However, such data contains sensitive patient privacy and institutional intellectual property, subject to stringent security and ethical constraints, while cloud adoption exacerbates data leakage risks – making the balance between data utility and privacy protection a core challenge. As a key solution for medical data sharing, existing Attribute-Based Encryption (ABE) schemes suffer from limitations including unidirectional privacy protection, difficulty in tracing key leakage, and inefficient policy matching. To address these, we propose PSI-TR-ABE, a Private Set Intersection-based Traceable Policy-Hidden ABE scheme, which integrates Private Set Intersection(PSI) protocols with Paillier homomorphic encryption to achieve bidirectional policy-attribute privacy protection, employs an Linear Secret Sharing Scheme(LSSS)-based policy pre-verification mechanism to reduce futile decryption, and embeds hashed user identities into key structures for precise traceability. Theoretical proofs and comparative evaluations demonstrate enhanced efficiency without compromising security, providing a novel solution for secure and efficient medical data sharing. Siqi Lu, Liujia Cai, Xingyun Hu, Yongjuan Wang |
TrustCom | 6 |
| 2025 | ACOFuzz: An ant colony algorithm-based fuzzer for smart contractsabstractIn today's blockchain landscape, smart contracts are assuming a pivotal role, albeit accompanied by a heightened risk of exploitation by attackers. As smart contracts grow in complexity, vulnerabilities lurking within deeper layers of code become more prevalent. Existing analysis tools primarily focus on data flow and a priori knowledge based on symbolic execution as a test case generation strategy, often falling short in uncovering vulnerabilities nested within intricate conditional statements. To address this challenge, we present ACOFuzz, an advanced fuzzer for Ethereum smart contracts. ACOFuzz employs the ant colony optimization (ACO) algorithm to traverse the control flow graph (CFG) of smart contracts, systematically exploring execution paths and generating test cases. Subsequently, it strategically directs the search towards paths that are more susceptible to vulnerabilities within the CFG, leveraging block coverage data obtained from executing the test cases. In a comprehensive evaluation, we demonstrate that ACOFuzz excels in covering a wider array of paths within a contract while exhibiting enhanced accuracy in pinpointing specific vulnerabilities compared to contemporary fuzzers. Peixuan Feng, Wenrui Cao, Siqi Lu, Yongjuan Wang, Haoyuan Xue, Runnan Yang |
Blockchain Res. Appl. | 4 |
| 2025 | SAAChain: release and storage platform of digital works based on non-fungible tokensabstractAbstract The rapid growth in the speed and convenience of information dissemination has made copyright infringement increasingly common. Blockchain technology solves pain points such as difficulties in traditional copyright registration, easy infringement, and difficulties in confirming and safeguarding rights. It also realises the decentralised management of copyright, network-wide tracking and monitoring, trusted certificate deposits, among others. However, the efficient original authentication of works and the function of blockchain to create copyright trading channels in the field of copyright are often ignored. This paper designed a self-adaptive learning similarity detection fusion strategy to protect the copyright of original digital works, namely SAAChain, and built a platform for releasing and storing original works based on non-fungible tokens. SAAChain first measures the similarity of a work based on adaptive learning to realise the originality authentication of works. Secondly, the works are stored on the InterPlanetary File System as NFTs, along with copyright information. Finally, a smart contract based on Ethereum and ERC-721 is designed to realise the free circulation of digital rights while simultaneously constructing an efficient and convenient digital rights protection system. Experiments show that the accuracy of the fusion strategy for adaptive work similarity detection can reach above 97%, which meets the requirements of work originality verification. Because of the storage mode of the platform, the system has good performance in terms of response speed and storage efficiency. The entire process provides a full-process and transparent transaction platform for all parties and guarantees the copyright ownership of works as well as the non-tampering and traceability of copyright information. Yongjuan Wang, Siqi Lu, Peixuan Feng |
Comput. J. | 2 |
| 2025 | EUAV: An enhanced blockchain-based two-factor anonymous authentication key agreement protocol for UAV networks
Yidan Liu, Liujia Cai, Haoyuan Xue, Siqi Lu, Yongjuan Wang |
Comput. Networks | 7 |
| 2025 | TRACE: Trusted Return-Path Authentication via Context and Lightweight Encryption for IoT DevicesabstractReturn-Oriented Programming (ROP) attacks pose a significant threat to the control-flow integrity of Internet of Things (IoT) devices, which operate in resource-constrained environments with limited memory isolation and runtime protection. Existing defenses, such as shadow stacks and message authentication code (MAC)-based schemes, face key limitations in IoT: shadow stacks depend on trusted hardware often absent in lightweight devices, while message authentication code (MAC) schemes lack semantic binding to the call path, making them vulnerable to replay attacks during recursion or stack reuse. To address these challenges, this paper proposes TRACE, a lightweight return-path authentication mechanism with path-semantic awareness, designed for IoT devices. TRACE dynamically encodes the function call context into an evolving path-state vector, which is then combined with the return address and cryptographically processed to generate a semantically unique authentication tag. At each function return, TRACE reconstructs the path state and verifies the tag to enforce precise runtime control-flow integrity. We evaluate TRACE in both synthetic and real-world attack scenarios. With the RIPE test suite, we demonstrate its robustness across five representative attack dimensions. Additionally, we identify a stack overflow vulnerability in the widely used libmodbus v2.9.3 protocol stack, construct a complete attack chain in a realistic IoT context, and validate TRACE’s effectiveness in mitigating such attacks. Experimental results show that TRACE reliably detects return-path tampering even without Address Space Layout Randomization (ASLR) or stack protections and incurs only a 5.3% runtime overhead, offering strong security with lightweight performance suitable for resource-constrained IoT deployments. Rongkuan Ma, Yong Yu 0002, Siqi Lu, Yongjuan Wang |
IEEE Internet Things J. | 8 |
| 2025 | Beyond known threats: A novel strategy for isolating and detecting unknown malicious traffic
Qianwei Meng, Qingjun Yuan, Xiangbin Wang, Yongjuan Wang, Guangsong Li, Yanbei Zhu, Siqi Lu |
J. Inf. Secur. Appl. | 4 |
| 2025 | Evaluation Framework for Smart Contract FuzzersabstractABSTRACT With the widespread application of smart contracts in economics and asset management, the security of smart contracts has been widely addressed by academia and industry. Fuzz is an effective technique for vulnerability detection. Several fuzzers are currently available for smart contracts, how to choose the most appropriate tools to test smart contracts is a problem that needs to be solved. To this end, we propose an evaluation framework for a smart contract fuzzers, which sets eight evaluation indicators from five aspects to comprehensively evaluate the usability, transparency, detection ability, branch coverage, and design of oracle of the smart contract fuzzers. In order to verify the scientificity and rationality of the framework, we selected six state‐of‐the‐art (SOTA) smart contract fuzzers for evaluation. By evaluating the usability of six fuzzers, the level of difficulty in using them was verified; by evaluating the transparency of six fuzzers, the usability of the tool's output information during use was verified; the branch coverage and rationality of oracle design of the six fuzzers was validated by evaluating their detection ability on the dataset. The final evaluation results validated the effectiveness of our proposed framework in guiding users to choose smart contract fuzzers. Peixuan Feng, Yongjuan Wang, Siqi Lu, Qingjun Yuan, Huaiguang Wu |
J. Softw. Evol. Process. | 2 |
| 2025 | ECP: Coprocessor Architecture to Protect Program Logic ConsistencyabstractABSTRACT Contemporary program protection methods focus on safeguarding either program generation, storage, or execution; however, no unified protection strategy exists for ensuring the security of a full program lifecycle. In this study, we combine the static security of program generation with the dynamic security of process execution and propose a novel program logic consistency security property. An encryption core processing (ECP) architecture is presented that provides coprocessor solutions to protect the program logic consistency at the granularity of instructions and data flows. The new authenticated encryption mode in the architecture uses the offset value of the program's instructions and data in relation to the segment‐based address as its encryption parameters. Lightweight cryptographic primitives are adopted to ensure that the hardware burden added by the ECP is limited, especially under 64 architectures. We prove that the proposed scheme in the ECP architecture satisfies indistinguishability under chosen plaintext attack and demonstrate the effectiveness of the architecture against various attacks. Additionally, a theoretical performance analysis is provided for estimating the overhead introduced by the ECP architecture. Siqi Lu, Yongjuan Wang, Haopeng Fan, Qingdi Han, Jingsheng Li |
J. Softw. Evol. Process. | 3 |
| 2025 | Multivariate Template Attack Against NTT-Based Polynomial Multiplication of Dilithium
Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | CL-SCA: A Contrastive Learning Approach for Profiled Side-Channel AnalysisabstractSide-channel analysis (SCA) based on machine learning, particularly neural networks, has gained considerable attention in recent years. However, previous works predominantly focus on establishing connections between labels and related profiled traces. These approaches primarily capture label-related features and often overlook the connections between traces of the same label, resulting in the loss of some valuable information. Besides, the attack traces also contain valuable information that can be used in the training process to assist model learning. In this paper, we propose a profiled SCA approach based on contrastive learning named CL-SCA to address these issues. This approach extracts features by emphasizing the similarities among traces, thereby improving the effectiveness of key recovery while maintaining the advantages of the original SCA approach. Through experiments of different datasets from different platforms, we demonstrate that CL-SCA significantly outperforms other approaches. Moreover, by incorporating attack traces into the training process using our approach, we can further enhance its performance. This extension can improve the effectiveness of key recovery, which is fully verified through experiments on different datasets. Annyu Liu, An Wang 0001, Shaofei Sun, Congming Wei, Yaoling Ding, Yongjuan Wang, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Detection of Unknown Attacks Through Encrypted Traffic: A Gaussian Prototype-Aided Variational Autoencoder FrameworkabstractThe identification of encrypted network traffic presents a pivotal challenge in detecting unknown malicious traffic. Unlike closed-set identification, which primarily classifies known traffic classes, detecting unknown malicious traffic necessitates both accurate classification of known traffic and the identification of previously unseen traffic classes. Existing methods often face difficulties in effectively constraining the distribution size of known classes in the representation space and frequently misclassifying unknown classes as known. To address these challenges, we propose Open-Detect, a robust theoretical framework for detecting unknown malicious traffic, which leverages advanced deep learning techniques, such as variational autoencoders and Gaussian prototypes. Open-Detect introduces two primary constraints: a generative constraint, which enhances intra-class compactness, and a discriminative constraint, which optimizes inter-class separation. These constraints collectively mitigate the risks of misclassifying known classes and failing to detect unknown classes. In Open-Detect, network flows are transformed into grayscale images, and each known traffic class is mapped to a unique Gaussian prototype in the latent space. This design ensures tight clustering of samples within the same class and clear separation of samples between different classes. The detection of unknown malicious traffic is performed based on the distance between samples and these prototypes. Extensive experiments conducted on multiple publicly available datasets substantiate the efficacy of Open-Detect. The results reveal significant improvements in intra-class compactness and inter-class separation, enabling superior performance in both closed-world and open-world scenarios, particularly for detecting unknown malicious traffic. Our code is available at: https://github.com/niebikong/Open-Detect. Qianwei Meng, Qingjun Yuan, Guangsong Li, Yongjuan Wang, Siqi Lu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Enhancing privacy and security in IoT: a CoAP protocol analysis and improvement approach
Guangying Cai, Liujia Cai, Siqi Lu, Yongjuan Wang, Haoyuan Xue |
J. Supercomput. | 5 |
| 2025 | IIT: Accurate Decentralized Application Identification Through Mining Intra- and Inter-Flow RelationshipsabstractIdentifying Decentralized Applications (DApps) from encrypted network traffic plays an important role in areas such as network management and threat detection. However, DApps deployed on the same platform use the same encryption settings, resulting in DApps generating encrypted traffic with great similarity. In addition, existing flow-based methods only consider each flow as an isolated individual and feed it sequentially into the neural network for feature extraction, ignoring other rich information introduced between flows, and therefore the relationship between different flows is not effectively utilized. In this study, we propose a novel encrypted traffic classification model IIT to heterogeneously mine the potential features of intra- and inter-flows, which contain two types of encoders based on the multi-head self-attention mechanism. By combining the complementary intra- and inter-flow perspectives, the entire process of information flow can be more completely understood and described. IIT provides a more complete perspective on network flows, with the intra-flow perspective focusing on information transfer between different packets within a flow, and the inter-flow perspective placing more emphasis on information interaction between different flows. We captured 44 classes of DApps in the real world and evaluated the IIT model on two datasets, including DApps and malicious traffic classification tasks. The results demonstrate that the IIT model achieves a classification accuracy of greater than 97% on the real-world dataset of 44 DApps, outperforming other state-of-the-art methods. In addition, the IIT model exhibits good generalization in the malicious traffic classification task. Qianwei Meng, Qingjun Yuan, Weina Niu, Yongjuan Wang, Siqi Lu, Guangsong Li, Xiangbin Wang, Wenqi He |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | SyntaxBridge: Protocol Description Transformer for Enhanced Formal Analysis of Security Protocols
Liujia Cai, Siqi Lu, Hanjie Dong, Guangying Cai, Guangsong Li, Yongjuan Wang |
TrustCom | 8 |
| 2024 | ULDC: Unsupervised Learning-Based Data Cleaning for Malicious Traffic With High NoiseabstractAbstract Since the traffic of novel attacks exceeds current knowledge, realistic traffic labeling methods are prone to mislabeling, which has a significant impact on machine learning-based intrusion detection systems. Data cleaning typically relies on the ability of supervised deep neural networks to learn correct knowledge. Under high noise conditions, noisy labels can affect a supervised network and render it ineffective. To clean traffic datasets under high noise conditions, we propose an unsupervised learning-based data cleaning framework (called ULDC) that does not rely on labels and powerful supervised networks, hence reducing the impact of noisy labels. ULDC evaluates the confidence of observed labels through the distribution and similarity of samples in low dimensions. Moreover, ULDC maximizes the retention of hard samples through adaptive intra-class threshold evaluation, preserving more hard samples for training and improving generalization. In evaluations of ULDC on the CIRA-CIC-DoHBrw-2020 dataset, the percentage of data correction reached more than 75% under high noise, which is better than that of the state-of-the-art methods. ULDC is applicable to traffic data cleaning in both traditional networks and novel networks such as the Internet of Things and mobile networks, and it has been validated on datasets including CIC-IDS-2017 and IoT-23. Qingjun Yuan, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang, Bin Luo 0001, Gaopeng Gou |
Comput. J. | 4 |
| 2024 | Combine intra- and inter-flow: A multimodal encrypted traffic classification model driven by diverse features
Xiangbin Wang, Qingjun Yuan, Yongjuan Wang, Gaopeng Gou, Gang Xiong 0001 |
Comput. Networks | 3 |
| 2024 | Observational equivalence and security games: Enhancing the formal analysis of security protocols
Liujia Cai, Guangying Cai, Siqi Lu, Guangsong Li, Yongjuan Wang |
Comput. Secur. | 5 |
| 2024 | MMCo: using multimodal deep learning to detect malicious traffic with noisy labels
Qingjun Yuan, Gaopeng Gou, Yuefei Zhu, Yongjuan Wang |
Frontiers Comput. Sci. | 4 |
| 2024 | An efficient heuristic power analysis framework based on hill-climbing algorithm
Shaofei Sun, Shijun Ding, An Wang 0001, Yaoling Ding, Congming Wei, Liehuang Zhu, Yongjuan Wang |
Inf. Sci. | 7 |
| 2024 | Cache attacks on subkey calculation of BlowfishabstractCache attacks pose a serious security threat to cryptographic implementations in processor architectures. In this paper, we first propose cache attacks against Blowfish, which can break the protection of key-dependent S-box. This attack targets at the subkey calculation of Blowfish, and fully exploits features of the subkey calculation to construct a leakage equation group about the key. Without any knowledge of plaintext and ciphertext, the attacker only needs to obtain the cache leakage once to recover a variable-length key in minute-level time. More than that, we establish a leakage model for cache attack situations to evaluate the exhausting space of the intermediate value of block ciphers, and estimate the time complexity of cache attacks. In our experiments, we perform Flush + Reload and Prime + Probe attacks and recover the random key of Blowfish in OpenSSL 1.1.1h in 4 minutes. Furthermore, we have applied our attacks to existing systems, such as JavaScript-blowfish and Bcrypt. Our attack on JavaScript-blowfish can recover any plaintext input by the user. As for Bcrypt, our attack can recover the hash values stored in the database, thereby allowing attackers to impersonate the user’s identity. Haopeng Fan, Yongjuan Wang, Xiangbin Wang |
J. Comput. Secur. | 3 |
| 2024 | Screening Least Square Technique Assisted Multivariate Template Attack Against the Random Polynomial Generation of DilithiumabstractIn recent years, the security of Dilithium against side-channel attacks (SCA) has attracted great attentions from the cryptographic engineering community. However, existing power analysis attacks cannot fully utilize the side-channel leakages of the Dilithium reference implementation to efficiently recover the private key. In light of this, a screening least square technique assisted multivariate template attack (SLST assisted MTA) is proposed in this paper. In SLST assisted MTA, side-channel leakages of coefficient$y_{i}$of random polynomial y, unsigned number$x_{i}$and random byte string$a_{i^{\prime }}$can be utilized simultaneously to recover coefficient$y_{i}$of random polynomial y with MTA. Then, one can build error-tolerant equations, and the private key$\mathbf {s_{1}}$can be solved with SLST efficiently. We evaluate the private key recovery efficiency of SLST assisted MTA with real traces measured from the Cortex-M4 processor based Dilithium reference implementation, and the evaluation results show that with MTA, 19.41%, 15.70% and 16.88% of the coefficients of y can be accurately recovered in cases of Dilithium 2, 3 and 5. Besides, using SLST, after five times screening, only 38, 40 and 39 power traces are enough to recover private key$\mathbf {s_{1}}$of Dilithium 2, 3 and 5 with 100% of success rate. Haopeng Fan, Hailong Zhang 0001, Yongjuan Wang, Wenhao Wang 0001, Yanbei Zhu, Haojin Zhang, Qingjun Yuan |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | MCRe: A Unified Framework for Handling Malicious Traffic With Noise Labels Based on Multidimensional Constraint RepresentationabstractDue to the limitations of the existing annotation methods, the prevalence of label noise can be caused in realistic malicious traffic datasets, which has a significant impact on the training and evaluation of deep learning-based intrusion detection models. Recently, various methods have been proposed to deal with noise-containing labeled datasets, and they can be roughly divided into two categories: data cleaning and robust training. However, the different processing ideas lead these two types of methods to ignore the information in different components of the dataset, resulting in a cliff-like drop in performance under high noise conditions. To this end, this study proposes a unified framework for handling noise malicious traffic based on the multidimensional constrained representations named MCRe, which unifies data cleaning and robust training into an ideal representation function approximation. According to the properties of the ideal representation function, information integrity constraints, cluster separability constraints and core proximity constraints are defined to drive MCRe to approximate the ideal representation during iteration. These constraints led MCRe to learn the individual, intra-class, and global levels of distributed knowledge, thus avoiding irrational domain knowledge extraction and ensuring strong label noise robustness of the representation network. We validated MCRe on a dataset that includes 22 types of realistic malicious traffic. Experimental results show that MCRe can outperform the state-of-the-art methods in both data cleaning and robust training downstream tasks, achieving 85% pure sample rate and 82% classification accuracy even under the condition of up to 90% noise labels. In addition, the generalizability of MCRe was verified on several public datasets. Finally, MCRe was also well-extended to enhance other data cleaning and robust training approaches. Qingjun Yuan, Gaopeng Gou, Yanbei Zhu, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | CRPWarner: Warning the Risk of Contract-Related Rug Pull in DeFi Smart ContractsabstractIn recent years, Decentralized Finance (DeFi) has grown rapidly due to the development of blockchain technology and smart contracts. As of March 2023, the estimated global cryptocurrency market cap has reached approximately $949 billion. However, security incidents continue to plague the DeFi ecosystem, and one of the most notorious examples is the “Rug Pull” scam. This type of cryptocurrency scam occurs when the developer of a particular token project intentionally abandons the project and disappears with investors’ funds. Despite only emerging in recent years, Rug Pull events have already caused significant financial losses. In this work, we manually collected and analyzed 103 real-world rug pull events, categorizing them based on their scam methods. Two primary categories were identified:Contract-relatedRug Pull (through malicious functions in smart contracts) andTransaction-relatedRug Pull (through cryptocurrency trading without utilizing malicious functions). Based on the analysis of rug pull events, we propose CRPWarner (short forContract-relatedRugPull RiskWarner) to identify malicious functions in smart contracts and issue warnings regarding potential rug pulls. We evaluated CRPWarner on 69 open-source smart contracts related to rug pull events and achieved a 91.8% precision, 85.9% recall, and 88.7% F1-score. Additionally, when evaluating CRPWarner on 13,484 real-world token contracts on Ethereum, it successfully detected 4168 smart contracts with malicious functions, including zero-day examples. The precision of large-scale experiments reaches 84.9%. Zewei Lin, Jiachi Chen, Jiajing Wu, Weizhe Zhang, Yongjuan Wang, Zibin Zheng |
IEEE Trans. Software Eng. | 5 |
| 2023 | BoAu: Malicious traffic detection with noise labels based on boundary augmentation
Qingjun Yuan, Chang Liu 0049, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang, Gaopeng Gou |
Comput. Secur. | 6 |
| 2022 | A survey on cryptographic techniques for protecting big data security: present and forthcoming
Siqi Lu, Jianhua Zheng, Zhenfu Cao, Yongjuan Wang |
Sci. China Inf. Sci. | 4 |
| 2021 | Efficient Framework for Genetic Algorithm-Based Correlation Power AnalysisabstractVarious Artificial Intelligence (AI) techniques are combined with classic side-channel methods to improve the efficiency of attacks. Among them, Genetic-Algorithms-based Correlation Power Analysis (GA-CPA) is proposed to launch attacks on hardware cryptosystems to extract the secret key efficiently. However, the convergence efficiency of GA-CPA is unsatisfactory due to two problems: the randomly generated initial population generally have low fitness, and the mutation operation in each iteration hardly produces high-quality individuals because of the confusion and diffusion characteristics of S-boxes. In this paper, we propose an analysis framework of GA-CPA which focuses on solving these two problems. First, we explore the list of candidate key bytes which is the result of Correlation Power Analysis (CPA) on a limited number of power traces, so that the population can be initialized with high quality candidates. Second, we improve the mutation operation by guiding the candidate key to mutate in a higher-fitness direction instead of randomly. Third, we make full use of the fitness calculation method and combine it with key enumeration algorithms to further improve the efficiency of key recovery. Simulation experimental results show that our method reduces the number of traces by 33.3% and 43.9% compared to CPA with key enumeration and GA-CPA respectively when the success rate is fixed to 90%. Real experiments performed on SAKURA-G confirm that the number of traces required in our method is much less than the numbers of traces required in CPA and GA-CPA. Besides, we adjust our method to deal with DPA contest v1 dataset, and achieve a better result of 40.76 traces than the winning proposal of 42.42 traces. The computation cost of our proposal is nearly 16.7% of the winner. An Wang 0001, Yaoling Ding, Liehuang Zhu, Yongjuan Wang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2021 | A Multiple Sieve Approach Based on Artificial Intelligent Techniques and Correlation Power AnalysisabstractSide-channel analysis achieves key recovery by analyzing physical signals generated during the operation of cryptographic devices. Power consumption is one kind of these signals and can be regarded as a multimedia form. In recent years, many artificial intelligence technologies have been combined with classical side-channel analysis methods to improve the efficiency and accuracy. A simple genetic algorithm was employed in Correlation Power Analysis (CPA) when apply to cryptographic algorithms implemented in parallel. However, premature convergence caused failure in recovering the whole key, especially when plenty of large S-boxes were employed in the target primitive, such as in the case of AES. In this article, we investigate the reason of premature convergence and propose a Multiple Sieve Method (MS-CPA), which overcomes this problem and reduces the number of traces required in correlation power analysis. Our method can be adjusted to combine with key enumeration algorithms and further improves the efficiency. Simulation experimental results depict that our method reduces the required number of traces by and , compared to classic CPA and the Simple-Genetic-Algorithm-based CPA (SGA-CPA), respectively, when the success rate is fixed to . Real experiments performed on SAKURA-G confirm that the number of traces required for recovering the correct key in our method is almost equal to the minimum number that makes the correlation coefficients of correct keys stand out from the wrong ones and is much less than the numbers of traces required in CPA and SGA-CPA. When combining with key enumeration algorithms, our method has better performance. For the traces number being 200 (noise standard deviation ), the attacks success rate of our method is , which is much higher than the classic CPA with key enumeration ( success rate). Moreover, we adjust our method to work on that DPA contest v1 dataset and achieve a better result (40.04 traces) than the winning proposal (42.42 traces). Yaoling Ding, Liehuang Zhu, An Wang 0001, Yongjuan Wang, Siu-Ming Yiu, Keke Gai |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2020 | Block-oriented correlation power analysis with bitwise linear leakage: An artificial intelligence approach based on genetic algorithms
Yaoling Ding, An Wang 0001, Yongjuan Wang, Guoshuang Zhang |
Future Gener. Comput. Syst. | 4 |
| 2019 | Aggregate Signature Consensus Scheme Based on FPGA
Jinhua Fu, Yongzhong Huang, Xueming Si, Yongjuan Wang, Bin Li 0023 |
BlockSys | 5 |
| 2019 | Manual Audit for BitUnits Contracts
Siqi Lu, Haopeng Fan, Yongjuan Wang, Huizhe Mi |
BlockSys | 3 |