EDBT 2026 Demo / reviewers in the wild / expert
Maohua Guo
dblp:122/1596
· DBLP profile ↗
6ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0001-7990-4165ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ProInfer: inference of binary protocol keywords based on probabilistic statisticsabstractAbstract Protocol reverse engineering is crucial in normative verification, and malware behavior analysis and vulnerability discovery. However, uncovering the structural features of binary protocols concealed within dense data representations remains a significant challenge. Accurately identifying keyword segments associated with message types is a prerequisite for meaningful semantic analysis and protocol state machine reduction. In this work, we introduce a novel approach for inferring keywords from binary protocols based on probabilistic statistics. Our method in terms of Byte employs heuristic rules to filter offset positions that are clearly unrelated to message types. We further filter candidate Byte-offsets utilizing constraint relations and provide the probabilistic ranking of each offset as the keyword segment. To enhance the reliability of keyword segment inference, we utilize the Monte Carlo algorithm to assess the difference between message clustering with candidate Byte-offset and random message clustering, and reorder candidate offsets according to the results. Then we can observe optimal values from both orderings and present the ultimate inference results. Experimental results demonstrate that our method excels in the accuracy of keyword segments identification compared with previous techniques. Maohua Guo, Yuefei Zhu, Jinlong Fei |
Comput. J. | 1 |
| 2025 | Active inference of protocol state machines from incomplete message domainsabstractInferring protocol state machines from observable information presents a significant challenge in protocol reverse engineering (PRE), especially when passively collected traffic suffers from message loss, resulting in an incomplete protocol state space. This paper introduces an innovative method for actively inferring protocol state machines using the minimally adequate teacher (MAT) framework. By incorporating session completion and deterministic mutation techniques, this method broadens the range of protocol messages, thereby constructing a more comprehensive input space for the protocol state machine from an incomplete message domain. Additionally, the efficiency of active inference is improved through several optimizations for the L M + algorithm, including traffic deduplication, the construction of an expanded prefix tree acceptor (EPTA), query optimization based on responses, and random counterexample generation. Experiments on the real-time streaming protocol (RTSP) and simple mail transfer protocol (SMTP), which use Live555 and Exim implementations across multiple versions, demonstrate that this method yields more comprehensive protocol state machines with enhanced execution efficiency. Compared to the L M + algorithm implemented by AALpy, Act_Infer achieves an average reduction of approximately 40.7% in execution time and significantly reduces the number of connections and interactions by approximately 28.6% and 46.6%, respectively. Maohua Guo, Yuefei Zhu, Jinlong Fei |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2021 | Website Fingerprinting Attacks Based on Homology AnalysisabstractWebsite fingerprinting attacks allow attackers to determine the websites that users are linked to, by examining the encrypted traffic between the users and the anonymous network portals. Recent research demonstrated the feasibility of website fingerprinting attacks on Tor anonymous networks with only a few samples. Thus, this paper proposes a novel small-sample website fingerprinting attack method for SSH and Shadowsocks single-agent anonymity network systems, which focuses on analyzing homology relationships between website fingerprinting. Based on the latter, we design a Convolutional Neural Network-Bidirectional Long Short-Term Memory (CNN-BiLSTM) attack classification model that achieves 94.8% and 98.1% accuracy in classifying SSH and Shadowsocks anonymous encrypted traffic, respectively, when only 20 samples per site are available. We also highlight that the CNN-BiLSTM model has significantly better migration capabilities than traditional methods, achieving over 90% accuracy when applied on a new set of monitored sites with only five samples per site. Overall, our experiments demonstrate that CNN-BiLSTM is an efficient, flexible, and robust model for website fingerprinting attack classification. Maohua Guo, Jinlong Fei |
Secur. Commun. Networks | 1 |
| 2021 | Deep Nearest Neighbor Website Fingerprinting Attack TechnologyabstractBy website fingerprinting (WF) technologies, local listeners are enabled to track the specific website visited by users through an investigation of the encrypted traffic between the users and the Tor network entry node. The current triplet fingerprinting (TF) technique proved the possibility of small sample WF attacks. Previous research methods only concentrate on extracting the overall features of website traffic while ignoring the importance of website local fingerprinting characteristics for small sample WF attacks. Thus, in the present paper, a deep nearest neighbor website fingerprinting (DNNF) attack technology is proposed. The deep local fingerprinting features of websites are extracted via the convolutional neural network (CNN), and then the k-nearest neighbor (k-NN) classifier is utilized to classify the prediction. When the website provides only 20 samples, the accuracy can reach 96.2%. We also found that the DNNF method acts well compared to the traditional methods in coping with transfer learning and concept drift problems. In comparison to the TF method, the classification accuracy of the proposed method is improved by 2%–5% and it is only dropped by 3% when classifying the data collected from the same website after two months. These experiments revealed that the DNNF is a more flexible, efficient, and robust website fingerprinting attack technology, and the local fingerprinting features of websites are particularly important for small sample WF attacks. Maohua Guo, Jinlong Fei, Yitong Meng |
Secur. Commun. Networks | 1 |
| 2016 | Marine environmental monitoring with GF-1 dataabstractGF-1 is the first satellite of this Chinese civilian remote sensing satellites series. This paper presents some typical applications on marine environmental monitoring with high resolution and wide swath satellite data, especial on the marine disaster monitoring such as oil spill, sea ice, and red tide. With these data, we can get the detailed information about different disaster. Mingsen Lin, Bin Zou 0003, Lijian Shi, Maohua Guo |
IGARSS | 6 |
| 2012 | Multisite Calibration Tracking for FY-3A MERSI Solar BandsabstractThe MEdium-Resolution Spectral Imager (MERSI), onboard the second-generation Chinese polar-orbit meteorological satellite FY-3A, is a MODIS-like sensor with 19 solar bands and one thermal infrared band. Although there is a visible onboard calibration device, it can only be used for tracking temporal instrument degradation. The vicarious calibration (VC) campaign at the Dunhuang site, conducted once a year, has been the main postlaunch absolute radiometric calibration method for MERSI in the solar bands. To increase the in-flight calibration frequency, a multisite radiometric calibration tracking method is presented. This method relies on simulated radiation over several stable sites, and a daily calibration updating model is built from long-term trending of calibration coefficient series. The MERSI calibration reference is evaluated against the observations of Aqua MODIS, showing mean relative biases within 5% from 0.4 to 2.1 μm . The short-wave channels of MERSI are found to experience large degradation, particularly the 412-nm band with an annual degradation rate of 9.7%, whereas the red and near-infrared bands are relatively stable with annual degradation rates within ±1%. Several approaches have been used to analyze the reliability of MERSI calibration results. A comparison of the calibration slopes shows that the relative biases between the multisite method and the annual Dunhuang VC campaign are below 3.8%. Aqua MODIS is used as a reference to monitor the data quality of the recalibrated MERSI. A double-difference analysis shows that the mean relative biases are almost within 5% over stable deserts, and the synchronous nadir observation analysis also reveals good agreement. Ling Sun 0003, Xiuqing Hu, Maohua Guo, Na Xu 0001 |
IEEE Trans. Geosci. Remote. Sens. | 3 |