Wenhao Li 0005

dblp:11/444-5 · DBLP profile ↗
← Back
16ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0003-2268-7416ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 8 since 2021Computer networks · 5 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DAAPS: Distributed anonymous access control for pervasive edge computing services
Jie Chen 0093, Wenhao Li 0005, Shuai Wang 0079, Huamin Jin, Changsong Jiang
Comput. Secur.2
2026 Online Traffic Camouflage Against Network Analyzers via Deep Reinforcement Learning
abstract
Traffic analysis plays a pivotal role in network management. However, despite the prevalence of encryption, attackers are still able to deduce privacy elements such as user behavior and OS identification through advanced learning-based methods that exploit side-channel features. Existing defense strategies, which manipulate feature distribution to evade traffic analyzers, are often hampered by the need for impractical decoder deployment across all routes in symmetric framework methods. Moreover, reversing feature distribution modifications to real-time traffic, especially through dummy packet crafting or padding, is a complex task. In response to these challenges, we propose Veil, a novel and practical defender designed to protect live connections against encrypted network traffic analyzers. Leveraging an asymmetric deployment structure, Veil is capable of reconstructing live streams at the packet-block level, thereby allowing for seamless deployment on any connection node while enforcing transmission constraints. By employing a traffic-customized DQN framework, Veil not only reverses statistical feature perturbations back to the traffic space but also directs the distribution towards a target class. Extensive experiments conducted on real-world datasets validate the efficacy of Veil in efficiently evading analyzers in both targeted and untargeted modes, outperforming existing defense mechanisms. Notably, Veil addresses the key issues of impractical decoder deployment and complex real-time traffic manipulation, offering a more viable solution for network traffic privacy protection. The source code is publicly available at https://github.com/SecTeamPolaris/Veil, facilitating further research and application in the field of network security.
Wenhao Li 0005, Jie Chen 0093, Zhaoxuan Li, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
IEEE Trans. Netw. Serv. Manag.1
2025 Magnifier: Detecting Network Access via Lightweight Traffic-Based Fingerprints
Wenhao Li 0005, Qiang Wang 0059, Huaifeng Bao, Xiaoyu Zhang 0002, Lingyun Ying, Zhaoxuan Li, Huamin Jin, Shuai Wang 0079
IEEE Trans. Inf. Forensics Secur.1
2025 Nüwa: Enhancing Network Traffic Analysis With Pre-Trained Side-Channel Feature Imputation
abstract
Network traffic classification stands as an essential endeavor within the realms of network security and management. The recent advances in learning-based methodologies have underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic, especially focusing on the temporal attributes of missing packets within a traffic session. Firstly, we propose a word-level Sequence2Embedding (S2E) module to transform side-channel features into tokens for model pre-training, as well as a Traffic Feature Masking strategy (TFM) to simulate the original flows changes in packet loss network. Besides, we also introduce a Traffic Feature Imputation (TFI) module to restore the missing values of original traffic flows in an efficient and context-aware manner. Experiments across four diverse real-world scenarios substantiate Nüwa’s capacity to restore the performance of prevalent temporal models, while maintaining the integrity of the imputed features. Notably, Nüwa has also demonstrated an impressive resilience, even under conditions of extensive feature loss and domain adaptation. The Nüwa prototype has been made accessible to the public for further research and development (https://github.com/Timeless-zfqi/Nuwa).
Faqi Zhao, Wenhao Li 0005, Huaifeng Bao, Zhaoxuan Li, Guoqiao Zhou, Wen Wang 0008, Feng Liu 0001
IEEE Trans. Netw.2
2024 Poster: PGPNet: Classify APT Malware Using Prediction-Guided Prototype Network
abstract
As the popularity of Advanced Persistent Threat (APT) grows, APT malware group classification has attracted more attention recently.However, most of previous methods use simple classifiers for group classification, ignoring the bias caused by the sparse number of revealed malware and the differences in functionality distribution of most groups.In this paper, we propose a Prediction-Guided Prototype Network (PGPNet) that could quickly adapt to new classification tasks with limited supervised samples based on the metalearning architecture.Adding malware functionality classification as an auxiliary task is beneficial for feature learning, and the bias of distribution differences is eliminated by intervening the predicted results into the group classifier.Experimental results on a APT malware dataset show that PGPNet successfully exploits the contextual information and predictions of the auxiliary task and achieves state-of-the-art performance.
Huaifeng Bao, Wenhao Li 0005, Zhaoxuan Li, Han Miao, Wen Wang 0008, Feng Liu 0001
CCS2
2024 Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic Execution
abstract
The frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX.
Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010
CCS3
2024 Poster: Towards Real-Time Intrusion Detection with Explainable AI-Based Detector
abstract
Identifying malicious traffic is crucial for safeguarding internal networks from privacy breaches.Intrusion Detection Systems (IDS) traditionally rely on inefficient and outdated rule-sets, necessitating a shift towards AI-driven, learning-based algorithms for enhanced detection capabilities.Despite their promise, AI-integrated IDS face deployment challenges due to complex, opaque decision-making processes that can lead to latency and an increased risk of false positives.This paper presents the Explainable AI-based Intrusion Detection System (XAI-IDS), addressing the limitations of both rule-based and AI-driven IDS by integrating interpretable deep learning models.XAI-IDS employs tree regularization to transform complex models into efficient, transparent decision trees, facilitating real-time detection with improved accuracy and explainability.Experiments on two benchmark datasets demonstrate XAI-IDS's superior performance, offering a scalable solution to the challenge of identifying malicious traffic with reduced risk of false positives.
Wenhao Li 0005, Duohe Ma, Zhaoxuan Li, Huaifeng Bao, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
CCS1
2024 Poster: Enhancing Network Traffic Analysis with Pre-trained Side-channel Feature Imputation
abstract
The recent advances in learning-based methodologies has underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. Nonetheless, the distribution of these features has been identified as susceptible, particularly in the expansive and intricate network topologies characteristic of the modern Internet. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based augmentation framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic. The crux of Nüwa lies in its ability to reconstruct the side-channel features, with a particular focus on the temporal attributes of the missing packets within a traffic session. Nüwa is comprised of a word-level Sequence2Embedding module, a Traffic Noise-based Self-supervised Pre-trained Masking Strategy, and a Traffic Side-Channel Feature Imputation Module. Experiments across four diverse real-world scenarios substantiate Nüwa's capacity to restore the performance of prevalent temporal models while maintaining the integrity of the imputed features.
Faqi Zhao, Duohe Ma, Wenhao Li 0005, Feng Liu 0001, Wen Wang 0008
CCS3
2024 CAFE: Robust Detection of Malicious Macro based on Cross-modal Feature Extraction
abstract
The detection of malicious macros has been a prominent focus of research. Previous approaches exhibit two notable shortcomings. Firstly, methods centered on document and macro code features often fall short in effectively countering targeted adversarial strategies. Secondly, detection techniques relying on deceptive information, such as visual and textual cues, although alleviating certain challenges, introduce a new vulnerability to adversarial machine learning techniques. In this paper, we present Collaborative Adaptive Feature Extraction method (CAFE), designed for robust detection based on deceptive information. The core of CAFE is a feature fusion network architecture, where modality-shared associations and modalityprivate information are modeled from feature of different modalities, resulting in independently valid and comprehensive feature representations. An adaptive feature sampling module is introduced to address partial feature absence, enhancing detection robustness. Experimental results, conducted on two datasets, demonstrate that CAFE adeptly captures shared and complementary information from two modalities, showcasing its capability for robust malicious macro detection in the presence of input noise and adversarial samples. Index Terms—Malicious Macro Detection, Multi-modal Features, Model Robustness, Security Wen Wang is corresponding author.
Huaifeng Bao, Xingyu Wang 0003, Wenhao Li 0005, Jinpeng Xu, Peng Yin 0001, Wen Wang 0008, Feng Liu 0001
CSCWD3
2024 Trident: A Universal Framework for Fine-Grained and Class-Incremental Unknown Traffic Detection
abstract
To detect unknown attack traffic, anomaly-based network intrusion detection systems (NIDSs) are widely used in Internet infrastructure. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained emerging attack detection and (ii) incremental updates/adaptations. To tackle these problems, we propose to decouple the need for model capabilities by transforming known/new class identification issues into multiple independent one-class learning tasks. Based on the above core ideas, we develop Trident, a universal framework for fine-grained unknown encrypted traffic detection. It consists of three main modules, i.e., tSieve, tScissors, and tMagnifier are used for profiling traffic, determining outlier thresholds, and clustering respectively, each of which supports custom configuration. Using four popular datasets of network traces, we show that Trident significantly outperforms 16 state-of-the-art (SOTA) methods. Furthermore, a series of experiments (concept drift, overhead/parameter evaluation) demonstrate the stability, scalability, and practicality of Trident.
Ziming Zhao 0008, Zhaoxuan Li, Zhuoxue Song, Wenhao Li 0005, Fan Zhang 0010
WWW4
2024 metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001
Comput. Networks5
2024 Stories behind decisions: Towards interpretable malware family classification with hierarchical attention
Huaifeng Bao, Wenhao Li 0005, Huashan Chen, Han Miao, Qiang Wang 0059, Zixian Tang, Feng Liu 0001, Wen Wang 0008
Comput. Secur.2
2023 Prism: Real-Time Privacy Protection Against Temporal Network Traffic Analyzers
abstract
Traffic analysis is widely used in network monitoring. However, the attackers can sometimes infer sensitive information from the patterns of the encrypted network traffic, which poses a threat to network security. Most existing countermeasures are proposed to obfuscate traffic flows using adversarial examples. However, there are two challenges when adding perturbations to live network traffic. Firstly, the perturbations imposed on the feature space cannot be conveniently projected to original traffic flows in feature-space based methods. Secondly, it is laborious and impractical to apply symmetrical framework to encode/decode the adversarial traffic in traffic-space based approaches. To address the above issues, in this paper, we propose an asymmetric defending scheme, namelyPrism, to protect theliveconnection privacy against attacks of temporal network traffic analyzers. Specifically,Prismfirst extracts standardized temporal features via Power-Law Division (PLD) algorithm, and then employs Time-stacked State Transition Model (TSTM) to obtain the fingerprint of each application. Finally,Prismdefends against the analyzers with online traffic perturbation. Since thePrismis designed as a traffic-space based defender with asymmetric defending structure, the deployment is lightweight and efficient. Experimental results on two real-world datasets demonstrate the effectiveness and generalization of our adversarial perturbations. In particular, it is encouraging to see that our proposed defending scheme outperforms the advanced countermeasures, such as adversarial training and traffic filter.
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Zhaoxuan Li, Haichao Shi, Qiang Wang 0059
IEEE Trans. Inf. Forensics Secur.1
2023 ProGraph: Robust Network Traffic Identification With Graph Propagation
abstract
Network traffic identification is critical for effective network management. Existing methods mostly focus on invariant network environments with stable attribute distributions. Unfortunately, however, they can hardly be adaptive to the variation of practical networks and suffer from significant performance degradation. This problem largely stems from the over-dependence of existing methods on the vulnerable side-channel features. To address this issue, in this paper we propose a graph-based approach, namely ProGraph, to ensure robust network traffic classification among various network environments. The core idea of ProGraph is to construct a correlation graph with session clusters aggregated from different networks, based on which graph propagation can be effectively implemented to predict labels of testing nodes in an iterative manner. ProGraph enhances the correlation between clusters of the same class to provide reliable paths for label dissemination from the labeled clusters to the testing ones. It is encouraging to see that the proposed ProGraph achieves an accuracy of 92.25% in networks with constant attributes, while remaining stable with the accuracy of 90.89% when deployed in different networks, which significantly outperforms the state-of-the-art approaches. Meanwhile, ProGraph can accurately identify the novel classes which do not exist in the training dataset, with an AUC of 95.11. Last but not least, a carefully constructed dataset, namely CrossNet2021, containing network traffic of 20 classes of applications from two distinct networking scenarios, is made publicly available to support further research.
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Haichao Shi, Qiang Wang 0059
IEEE/ACM Trans. Netw.1
2023 VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance Learning
abstract
With the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle.
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002
IEEE Trans. Software Eng.7
2022 Robust network traffic identification with graph matching
Wenhao Li 0005, Xiaoyu Zhang 0002, Huaifeng Bao, Qiang Wang 0059, Zhaoxuan Li
Comput. Networks1