Yunhe Cui

dblp:123/9238 · DBLP profile ↗
← Back
35ranked-venue papers
3as first author
32since 2021 · last 2026
0000-0002-0880-675XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 3 first-author · 11 since 2021Security and privacy · 9 · 9 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A packer identification method based on section-entropy plot
abstract
Abstract Although packers are useful tools for protecting applications, they can also be used to protect malware. This makes packer identification technology increasingly important for malware analysis. Most existing packer identification methods based on static analysis extract a large number of features from the binary code of an executable. However, these binary code-related features are sensitive to small changes in the executable’s binary code, and it is difficult to understand how these features influence the decision-making processes of machine learning models. To address the shortcomings of existing static analysis-based packer identification methods, we explore extraction of a small number of easily extractable and discriminative features for efficient and accurate packer identification. Specifically, we analyze the packing process and notice that the structures of the packed PEs differ according to the different packing patterns used by the packer. Based on this, a section-entropy plot is proposed, which is generated by a small number of easily extractable and discriminative features that can reflect the overall structure of a PE file. By using GoogLeNet to identify the packer characterized by the section-entropy plot, a p acker i dentification method based on the s ection- e ntropy p lot (PISEP) is constructed, which does not require PE file disassembly and complex feature engineering. The experimental results show that PISEP achieves 99.08% accuracy for identifying seen and unseen types of packers and requires only 0.165 s on average to identify the packer class of a test sample, and thus could be a highly competitive candidate for packer identification.
Yueting Wan, Chun Guo 0004, Yuan Ping 0003, Yunhe Cui, Xiaodan Lyu, Guowei Shen
Cybersecur.4
2026 MCPDS: image-based malware classification method using PE metadata alone
abstract
Abstract In response to the increasing threat posed by the exponential growth of malware in cybersecurity, researchers have developed a number of malware classification methods based on malware images and deep learning in recent years. Newly proposed methods of this type tend to focus on generating malware images by extracting multiple types of information from a PE file, as well as on using complex convolutional neural network (CNN) models, to achieve high classification accuracy. Methods that involve extracting multiple types of information, especially those that require file disassembly for acquisition and the subsequent use of complex CNN models, result in a lengthy process for generating malware images and significantly increase model training durations. To alleviate this problem, we adopt the idea of using only a small part of the content that can be easily extracted from a PE file to efficiently generate a malware image, and implement malware classification without relying on complex CNN models. As a key component of a PE file, the PE header and the section table (we call them PE metadata) are characterized by a relatively low byte count and are likely to be useful for malware classification according to the similarities observed in the PE metadata between malware from both the same family and different families. Therefore, in this work, we explore the feasibility of using PE metadata alone to generate an image for malware classification and propose an Image of PE metadata (IPM) generated from PE metadata to represent malware. Based on the proposed IPM, we then construct a shallow CNN model and combine it with a support vector machine classifier to introduce a novel malware classification method called MCPDS ( M alware c lassification method using P E metadata, d eep learning and s upport vector machine). The experimental results show that the MCPDS not only achieves high accuracy in terms of classifying malware on two malware datasets but also exhibits high efficiency in terms of image generation and good robustness against adversarial samples.
Yonglin Zhao, Chun Guo 0004, Yuan Ping 0003, Yi Chen 0008, Yunhe Cui, Guowei Shen
Cybersecur.5
2026 A lightweight malware classification method based on short bit sequence visualization
Chun Guo 0004, Guowei Shen, Yuan Ping 0003, Yunhe Cui, Yi Chen 0008
Eng. Appl. Artif. Intell.5
2026 PPF: A framework for real-time adaptive pruning of large language models via performance prediction
Zuxin Ma, Yunhe Cui, Yongbin Qin
Neurocomputing2
2026 Tide: Intra- and Inter-Timeslot Enhanced Node Embedding for Probing Attack Detection in SDN
abstract
Probing the configurations of the Software-Defined Networking (SDN) switches is the essential preliminary for attacking SDN. This study points out a critical bottleneck in detecting probing attack: the dynamically changing character of different kinds of probing attacks makes the existing detection methods fail to detect probing attack. In this paper, we propose Tide, a probing attack detection method based on a Dynamic Flow-Packet graph (DFP-Graph), along with an intra-and inter-timeslot enhanced node embedding strategy. Tide constructs a (FP-Graph) across multiple timeslots, thereby modeling the intra-timeslot DFP-Graph consisting of multiple static Flow-Packet Graphs correlations that include the flow to flow, packet to packet, flow to packet, and packet to flow relationships while representing the inter-timeslot correlation of flows. Furthermore, Tide proposes an intra-timeslot node embedding module, an inter-timeslot node embedding module, and a probing attack flow detection module. The intra-timeslot node embedding module is designed to update the node representations based on the intra-timeslot correlation among different flows, while the inter-timeslot node embedding module is proposed to track the time-varying characters of a single flow. Finally, the probing attack flow detection module is employed to integrate the flow nodes’ representations in each timeslot and identify the probing attack flows. The experimental results demonstrate that Tide can effectively detect probing attack. It achieves the average detection accuracy at 87.51%, which outperforms the state-of-the-art methods.
Longyan Ran, Yunhe Cui, Guowei Shen, Chun Guo 0004, Yi Chen 0008, Qing Qian 0001
IEEE Internet Things J.2
2026 HSMNet: A multi-resolution grayscale image steganalysis method based on hybrid dilated convolution and self-attention multi-channel network
Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Guowei Shen, Hanzhou Wu
Inf. Sci.4
2026 E2DE: An edge frequency domain coefficient prediction-based fast video dual-watermarking scheme for eliminating edge-discontinuity effects
Jianmu Wang, Guowei Shen, Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Zhenghui Liu, Hanzhou Wu
Signal Process.5
2025 Hawk: Saturation Attack Detection Based on Structured Spatial Interactions and Temporal Dependencies-Guided Graph Learning in SDN
Longwen Ran, Qing Qian 0001, Yunhe Cui, Ruixue Tang
ICA3PP (4)3
2025 DPA-TA2C: Dynamic Priority-Aware Workflow Scheduling Method with Transformer and A2C in Cloud Data Center
abstract
Workflow scheduling in cloud data centers faces challenges such as task dependencies, resource heterogeneity, and dynamic workloads. Heuristic and meta-heuristic algorithms lack environment awareness and fail to meet real-time scheduling requirements. Existing deep reinforcement learning algorithms exhibit specific environment-aware capabilities; however, their feature modeling capabilities are insufficient, making it challenging to effectively model the nonlinear relationships between tasks and resources. To address these issues, we design a dynamic priority-aware mechanism that computes task priority factors in real time to adjust scheduling strategies adaptively. In low-load scenarios, dependency release is accelerated based on the priority rule of the successor node quantity to improve resource utilization; in high-load scenarios, bottleneck subtasks are prioritized based on the priority rule of the weighted critical path to shorten overall task completion times. We propose a Dynamic Priority-Aware Transformer-based Advantage ActorCritic (DPA-TA2C) scheduling method. The proposed method models the task topology, resource states, and priority factors as a sequence of features via a Transformer encoder. It collaboratively optimizes scheduling decisions using the policy and value functions of the A2C network to achieve end-to-end scheduling. Experimental results show that DPA-TA2C improves resource utilization by 49.5 % on average in low-load scenarios and reduces makespan by 51.6 % in high-load scenarios, demonstrating the efficiency and robustness of the proposed method for scheduling in complex cloud environments.
Fashun Jian, Guowei Shen, Xiaodan Lv, Chun Guo 0004, Yunhe Cui
ICPADS5
2025 FTOA-RP: A 'group'-based flow entry replacement policy probing and flow table overflow attack method
Yunhe Cui, Rongfei He, Yi Chen 0008, Chun Guo 0004, Guowei Shen
Comput. Secur.2
2025 A Clustering-Based Color Reordering Method for Reversible Data Hiding in Palette Images
abstract
ABSTRACT A recent research work pointed out that the reversible data hiding algorithms proposed for gray‐scale images can be implemented on the reconstructed palette images to improve embedding capacity and visual quality by reordering the color table. However, the reordering effect has a significant impact on performance improvement. Therefore, we propose a clustering‐based color reordering method for reversible data hiding in palette images to improve the reordering effect and further enhance the performance. In this method, we first design a centroid initialization method to select the initial centroids and then exploit the K‐means algorithm to generate clusters for the colors in the original color table. In the following, our proposed method, respectively, reorders the colors of these clusters by a greedy strategy and concatenates them into the reordered color table. Based on the relationship between the original and the reordered color tables, a novel index matrix can be reconstructed. Finally, state‐of‐the‐art reversible data hiding algorithms can be implemented on the reconstructed index matrix for performance improvement. Since our proposed method improves the reordering effect, enhances the correlation of the reconstructed index matrix, and reduces the length of the encoded location map, the maximal embedding capacities and the visual quality under the fixed embedding capacities are improved. We conducted experiments on two image datasets and six standard images to verify that the performance improvement of our proposed reordering method is better than that of the state‐of‐the‐art methods.
Jianxuan Deng, Yi Chen 0008, Chun Guo 0004, Yunhe Cui, Guowei Shen
IET Image Process.5
2025 PRAETOR:Packet flow graph and dynamic spatio-temporal graph neural network-based flow table overflow attack detection method
Kaixi Wang, Yunhe Cui, Guowei Shen, Chun Guo 0004, Yi Chen 0008, Qing Qian 0001
J. Netw. Comput. Appl.2
2025 CPSketch: A 'couple' sketch-based heavy flow detection method
Renpin Yao, Yunhe Cui, Yi Chen 0008, Chun Guo 0004, Guowei Shen
J. Netw. Comput. Appl.3
2025 A multi-level additive distortion method for security improvement in palette image steganography
Yi Chen 0008, Hongxia Wang 0001, Yunhe Cui, Guowei Shen, Chun Guo 0004, Hanzhou Wu
J. Vis. Commun. Image Represent.3
2025 Security Enhanced Computation Offloading for Collaborative Inference at Semantic-Communication-Empowered Edge
abstract
Semantic communication (SC) has emerged as a promising paradigm for upcoming intelligent applications, enabling mobile devices to collaboratively execute intelligent tasks with edge servers through computation offloading. However, few studies have addressed the problem of collaborative inference in SC networks. Traditional collaborative inference mechanisms may suffer performance decline in SC systems and are vulnerable to eavesdroppers. To address these issues, first, we present an encryptor that encrypts semantic information to avoid privacy leakage and a decryptor for restoration. Besides, we propose a novel SC-empowered edge computing framework enabling mobile devices to deploy a partial semantic encoder and offload the rest to edge servers. Based on this framework, we formulate the collaborative inference optimization problem, jointly optimizing delay, energy consumption, and privacy leakage. DNNPart is devised based on deep deterministic policy gradient to address the problem, which consists of a semantic attention mechanism that enables it to focus on important state variables, a hybrid action representation method that makes it adapt to mixed discrete and continuous action spaces, a dynamic model splitting algorithm that locates the optimal partition layer and adaptively splits the semantic coders. Integrated with these components, DNNPart iteratively optimizes the offloading strategy to find the optimal offloading strategy. Extensive simulations were conducted to verify the effectiveness of the proposed method by comparing it with baseline mechanisms.
Huanlai Xing, Xiangyi Chen, Yang Li 0049, Yunhe Cui, Danyang Zheng 0001, Laha Ale
IEEE Trans. Mob. Comput.5
2025 The DUDFTO Attack: Towards Down-to-UP Timeout Probing and Dynamically Flow Table Overflowing in SDN
abstract
As a new network structure, the decoupling of the control plane and forwarding plane makes Software-Defined Networking (SDN) widely used in large-scale network scenarios. However, the decoupling network architecture also brings new vulnerabilities. The flow table overflow attack is an attack strategy that can overwhelm SDN switches. Nevertheless, the existing flow table overflow attacks may fail in probing timeouts and match fields of flow entries, due to link failure, measurement of the round-trip time (RTT) of different packets, interference of hard-timeout and idle-timeout. Meanwhile, the stealthiness of the existing attacks may also reduce, as these attacks use fixed attack rate. To improve the timeout probing accuracy and the stealthiness of attack, a new flow table overflow attack strategy, DUDFTO, is proposed to accurately probe timeout settings and match fields, then stealthily overflow SDN flow tables. Firstly, it probes the match fields by measuring the one-sided transmission delay of the packets. After that, DUDFTO designs a down-to-up feedback-based timeout probing algorithm to eliminate the issues caused by high RTT, link failure, interference between hard-timeout and idle-timeout. Then, DUDFTO designs a dynamic attack packets sending algorithm to improve its stealthiness. Finally, DUDFTO probes the flow table state to stop sending new attack packets. The evaluation results demonstrate that DUDFTO outperforms the existing attacks in terms of match fields probing ability, timeout probing relative error, number of packet_in and flow_mod messages generated by the attack, rate distribution of packet_in and flow_mod messages generated during the attack, and number of detected attack packets.
Jiasong Li, Yunhe Cui, Yi Chen 0008, Guowei Shen, Chun Guo 0004, Qing Qian 0001
IEEE Trans. Netw. Serv. Manag.2
2024 MT-EPTNet: Multi-task Acoustic Scene Classification with Efficient Parameter Tuning
Qing Qian 0001, Yilin Kuang, Huan Wang 0010, Yunhe Cui, Bingxiang Wu, Longwen Ran
ICONIP (9)5
2024 NFAERCOM: A Near-Far Area Experience Replay-based Computation Offloading Method
abstract
Computation offloading technology plays an important role in Mobile Edge Computing (MEC). Most mainstream Deep Reinforcement Learning (DRL)-based computation offloading methods employ random experience replay to train networks. This training method does not take into account the value differences between experiences, resulting in the decrease of training speeds and the increase of task completion delay, energy consumption, and task drop rate. Prioritized Experience Replay (PER) alleviates this issue to some extent. However, using Temporal Difference (TD) error as the criterion for the importance of experiences does not allow for the selection of experiences that are more "concerned" by the Actor network under the Actor-Critic framework. This limitation restricts the performance of the algorithm. To address these issues, this paper focuses on the computation offloading problem in scenarios with multiple mobile devices (MDs) and multiple MEC servers. A near-far area experience replay algorithm-based computation offloading method named NFAERCOM is proposed. NFAERCOM additionally considers the queuing delay at the MEC server and introduces a new near-far area experience replay algorithm. Evaluation results demonstrate that NFAERCOM effectively reduces the task completion delay, energy consumption, and task drop rate of tasks.
Yunhe Cui, Chun Guo 0004, Yi Chen 0008, Guowei Shen
ISPA3
2024 SNDMI: Spyware network traffic detection method based on inducement operations
Chun Guo 0004, Yuan Ping 0003, Yunhe Cui, Yi Chen 0008, Guowei Shen
Comput. Secur.4
2024 Remote access trojan traffic early detection method based on Markov matrices and deep learning
Ben Pi, Chun Guo 0004, Yunhe Cui, Guowei Shen, Jialong Yang, Yuan Ping 0003
Comput. Secur.3
2023 BFLS: Blockchain and Federated Learning for sharing threat detection models as Cyber Threat Intelligence
Tongtong Jiang, Guowei Shen, Chun Guo 0004, Yunhe Cui
Comput. Networks4
2023 MCTVD: A malware classification method based on three-channel visualization and deep learning
Huaxin Deng, Chun Guo 0004, Guowei Shen, Yunhe Cui, Yuan Ping 0003
Comput. Secur.4
2023 USAGE : Uncertain flow graph and spatio-temporal graph convolutional network-based saturation attack detection method
Kaixi Wang, Yunhe Cui, Qing Qian 0001, Yi Chen 0008, Chun Guo 0004, Guowei Shen
J. Netw. Comput. Appl.2
2022 Defending saturation attacks on SDN controller: A confusable instance analysis-based algorithm
Longyan Ran, Yunhe Cui, Chun Guo 0004, Qing Qian 0001, Guowei Shen, Huanlai Xing
Comput. Networks2
2022 KIND: A Novel Image-Mutual-Information-Based Decision Fusion Method for Saturation Attack Detection in SD-IoT
abstract
Software-defined networking for IoT (SD-IoT), as an emerging architecture, is suffering from numerous security issues. Saturation attacks against the SDN switches and controllers are major security concerns in SD-IoT. When using the Dempster–Shafer evidence theory (DSE) to detect various saturation attacks, the simple mutual information calculation may cause information loss problem, leading to the decrease of detection accuracy. Therefore, how to avoid information loss problem to improve the detection performance is a key issue. Aiming to solve the above-mentioned issues, we propose KIND, a novel image mutual information-based decision fusion method for saturation attack detection in SD-IoT. The main idea of KIND is that it converts the probability matrix of binary classifiers to images and detects the saturation attacks by fusing these images. More specifically, when executing the evidence fusion, each evidence is converted to an image by a nonlinear transformation method. Each image is converted from the related probability-supported matrix. Then, the evidence can be fixed by comparing structural similarities among different images. After that, all evidence can be utilized to obtain the final detection results using the conducted combination rule. The evaluation results demonstrate that KIND can achieve high detection performance, which outperforms other state-of-the-art methods, in terms of TPR, TNR, FPR, FNR, accuracy, precision, recall, F-score, confusion matrix, ROC curves, PR curves, Chi-square test, correlation coefficient, and the quantitative strategy test. In conclusion, KIND can detect saturation attacks with high precision while causing acceptable storage overload.
Yunhe Cui, Qing Qian 0001, Guowei Shen
IEEE Internet Things J.2
2021 METER: An Ensemble DWT-based Method for Identifying Low-rate DDoS Attack in SDN
abstract
As one of the next generation of network architectures, Software-Defined Networking (SDN) decouples the forwarding and control function of the traditional network device. However, it also faces new threats from network attacks, such as the Low-rate Distributed Denial of Service (L-DDoS) attack. To resist L-DDoS attack in SDN, this work proposes METER, an enseMble discrEte wavelet Transform-based method for idEntifying low-Rate DDoS attack in SDN. The rationale for METER is to identify L-DDoS attacks based on a new metric referred to as the Ensemble Wavelet Energy Entropy set (EWEEs), which is calculated by a novel ensemble DWT method. Firstly, the ensemble wavelet coefficients matrix is attained by METER using the ensemble DWT method. After that, METER combines the related entropy values with wavelet energy of the ensemble wavelet coefficients matrix to obtain EWEEs. Furthermore, to increase the precision of the L-DDoS detection method, machine learning methods are used to mine the correlation between EWEEs and L-DDoS attacks for identifying L-DDoS. The experiments were implemented on the RYU controller and Mininet, which demonstrates that METER outperforms the baseline method, in terms of precision, accuracy, F -score, recall, ROC curve, and P-R curve.
Yunhe Cui, Qing Qian 0001, Guowei Shen, Hongfeng Gao, Saifei Li
EUC2
2021 2-SPIFF: a 2-stage packer identification method based on function call graph and file attributes
Hao Liu 0058, Chun Guo 0004, Yunhe Cui, Guowei Shen, Yuan Ping 0003
Appl. Intell.3
2021 Image-based malware classification using section distribution information
Mao Xiao, Chun Guo 0004, Guowei Shen, Yunhe Cui, Chaohui Jiang
Comput. Secur.4
2021 ADVICE: Towards adaptive scheduling for data collection and DDoS detection in SDN
Jin-cheng Peng, Yunhe Cui, Qing Qian 0001, Chun Guo 0004, Chaohui Jiang, Saifei Li
J. Inf. Secur. Appl.2
2021 Towards DDoS detection mechanisms in Software-Defined Networking
Yunhe Cui, Qing Qian 0001, Chun Guo 0004, Guowei Shen, Youliang Tian, Huanlai Xing, Lianshan Yan
J. Netw. Comput. Appl.1
2021 EX-Action: Automatically Extracting Threat Actions from Cyber Threat Intelligence Report Based on Multimodal Learning
abstract
With the increasing complexity of network attacks, an active defense based on intelligence sharing becomes crucial. There is an important issue in intelligence analysis that automatically extracts threat actions from cyber threat intelligence (CTI) reports. To address this problem, we propose EX-Action, a framework for extracting threat actions from CTI reports. EX-Action finds threat actions by employing the natural language processing (NLP) technology and identifies actions by a multimodal learning algorithm. At the same time, a metric is used to evaluate the information completeness of the extracted action obtained by EX-Action. By the experiment on the CTI reports that consisted of sentences with complex structure, the experimental result indicates that EX-Action can achieve better performance than two state-of-the-art action extraction methods in terms of accuracy, recall, precision, and F1-score.
Huixia Zhang, Guowei Shen, Chun Guo 0004, Yunhe Cui, Chaohui Jiang
Secur. Commun. Networks4
2021 The Named Entity Recognition of Chinese Cybersecurity Using an Active Learning Strategy
abstract
In data‐driven big data security analysis, knowledge graph‐based multisource heterogeneous threat data organization, association mining, and inference analysis attach increasinginterest in the field of cybersecurity. Although the construction of knowledge graph based on deep learning has achieved great success, the construction of a largescale, high‐quality, and domain‐specific knowledge graph needs a manual annotation of large corpora, which means it is very difficult. To tackle this problem, we present a straightforward active learning strategy for cybersecurity entity recognition utilizing deep learning technology. BERT pre‐trained model and residual dilation convolutional neural networks (RDCNN) are introduced to learn entity context features, and the conditional random field (CRF) layer is employed as a tag decoder. Then, taking advantages of the output results and distribution of cybersecurity entities, we propose an active learning strategy named TPCL that considers the uncertainty, confidence, and diversity. We evaluated TPCL on the general domain datasets and cybersecurity datasets, respectively. The experimental results show that TPCL performs better than the traditional strategies in terms of accuracy and F1. Moreover, compared with the general field, it has better performance in the cybersecurity field and is more suitable for the Chinese entity recognition task in this field.
Guowei Shen, Chun Guo 0004, Yunhe Cui
Wirel. Commun. Mob. Comput.4
2017 SD-HDC: Software-Defined Hybrid Optical/Electrical Data Center Architecture
abstract
In order to dynamically assign the optical/electrical routing path and optimize the optical/electrical resource allocation, a software-defined hybrid optical/electrical data center architecture (SD-HDC for short) is proposed in this work. A control mechanism that consists of two parallel steps including the new request handle step and the hybrid resource optimize step is introduced in SD-HDC. The new request handle step is used to quickly process the new incoming request while the hybrid resource optimize step periodically optimizes the hybrid optical/electrical network resource. To validate the SD-HDC architecture, a hybrid optical/electical routing algorithm used for handling elephant/mice flows is also proposed in this paper. Experimental results show that the proposed SD- HDC architecture can effectively reduce the blocking probability and path provisioning latency.
Yunhe Cui, Lianshan Yan, Huanlai Xing, Wei Pan 0008
GLOBECOM1
2016 SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks
Yunhe Cui, Lianshan Yan, Saifei Li, Huanlai Xing, Wei Pan 0008
J. Netw. Comput. Appl.1
2012 An Improved Distance Estimation Algorithm Based on Generalized CRT
abstract
In wireless sensor and actuator network(WSAN), in order to determine the location of sensors based on the range-based location techniques, estimating accurately the distances between sensors and actuators is very important. In this paper, based on the analysis of Generalized Chinese Remainder Theorem(CRT), some improvement to the Generalized CRT was made and an improved distance estimation algorithm which can be used in WSAN was proposed. In addition, the derivation and proof of the improved algorithm were provided. The simulation results have shown the validity of this algorithm.
Yunhe Cui
VTC Fall2