EDBT 2026 Demo / reviewers in the wild / expert
Yanhui Du
dblp:135/7552
· DBLP profile ↗
13ranked-venue papers
0as first author
10since 2021 · last 2026
0000-0003-1711-1156ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VDM-IOG, a framework of inference on graph in retrieval-augmented generation for vulnerability description mappingabstractAbstract To address the vulnerability description mapping (VDM) task, current approaches employ deep learning and large language models (LLMs) through prompt engineering, framing VDM as multi-class classification, multi-label classification, and text generation problems. However, existing methods exhibit significant limitations, including suboptimal identification accuracy, limited category coverage, inadequate interpretability, susceptibility to hallucinations, and challenges related to class imbalance. To address these limitations, this study proposes VDM-IOG, an inference on graph framework in retrieval-augmented generation for vulnerability description mapping. By transforming the VDM methodology into an intelligence graph, the proposed approach leverages a large language model to perform reasoning through five steps: identification, querying, scoring, questioning, and reflection. Experimental results demonstrate that the proposed method achieves a Macro-F1 score of 74.88% and a Micro-F1 score of 82.17%. Compared to existing research, the proposed approach expands detection coverage across 42 technical categories, effectively mitigates class imbalance, and enhances process interpretability and controllability through explicit reasoning traces. Fengrui Yu, Yanhui Du |
Cybersecur. | 2 |
| 2026 | A diffusion-based visual monitoring framework for detecting human behaviors and hazards in chemical plants
Ligang Chang, Binhan Xu, Yanhui Du |
Eng. Appl. Artif. Intell. | 7 |
| 2026 | REISD: Detecting LLM-generated text via iterative semantic difference
Kaiqi Qian, Yanhui Du, Chenrui Yang |
Neurocomputing | 2 |
| 2026 | Harnessing attention for cropping and fusion in CLIP-based AIGC detection
Yanhui Du, Liangwei Lyu, Chenrui Yang |
Neurocomputing | 2 |
| 2025 | Prompt suffix-attack against text-to-image diffusion models
Siyun Xiong, Yanhui Du, Zhuohao Wang, Peiqi Sun |
Neurocomputing | 2 |
| 2024 | Break-Pad: effective padding machines for tor with break burst paddingabstractAbstract Website Fingerprinting (WF) attacks enable a local eavesdropper to use metadata of packet flow, such as size, timing, and direction, to infer the websites a user is visiting. This can damage the user privacy provided by anonymity systems such as Tor. Tor has implemented the WF defense called Circuit Padding Framework, which provides an interface for developers to implement their own defenses. However, these defenses in the framework were overcome by the Deep Fingerprinting (DF) attack. In this paper, we propose a novel defense approach called break burst padding (Break-Pad), which injects a random number of padding packets into an incoming burst once the number of consecutive incoming packets exceeds a set number. We integrated Break-Pad into the existing Circuit Padding Framework. In addition, we have implemented two padding machines named August and October in the new framework and conducted experiments to evaluate these machines. In the open-world setting, our results show that August, with 29% bandwidth overhead, reduces Tik-Tok’s TPR by 14.48% and DF’s TPR by 22%. October outperforms the best padding machine, RBB. With 36% bandwidth overhead, it drops Tik-Tok’s TPR to 74.24% and DF’s TPR to 65.36%. In the one-page setting, October further reduces the bandwidth overhead by 11% while achieving similar performance to RBB. In the information leak analysis, for the burst sequence feature of the traffic, October leaks at 2.453 bits, while the best comparable padding machine Interspace leaks at 2.629 bits. Yanhui Du |
Cybersecur. | 2 |
| 2024 | Nearest neighbors and density-based undersampling for imbalanced data classification with class overlap
Peiqi Sun, Yanhui Du, Siyun Xiong |
Neurocomputing | 2 |
| 2024 | Mitigating data imbalance to improve the generalizability in IoT DDoS detection tasks
Yi Qing, Yanhui Du |
J. Supercomput. | 3 |
| 2023 | Discovering onion services through circuit fingerprinting attacksabstractTor onion services provide anonymous service to clients using the Tor browser without disclosing the real address of the server. But an adversary could use a circuit fingerprinting attack to classify circuit types and discovers the network address of the onion service. Recently, Tor has used padding defenses to inject dummy cells to protect against circuit fingerprinting attacks. But we found that circuits still expose much information to the adversary. In this paper, we present a novel circuit fingerprinting attack, which divides the circuit into the circuit generated by the client and the circuit generated by the onion service. To get a more effective attack, we tried three state-of-the-art classification models called SVM, Random Forest and XGBoost, respectively. As the best performance, we attain 99.99% precision and 99.99% recall when using Random Forest and XGBoost classification models, respectively. And we also tried to classify circuit types using our features and the classification model mentioned above, which was first proposed by Kwon. The best performance was achieved with 99.99% precision and 99.99% recall when using the random forest classifier in circuit type classification. The experimental results show that we achieved highly accurate circuit fingerprinting attacks even when application-layer traffic is identical and some type of circuits using the defenses provided by Tor. Yanhui Du |
High Confid. Comput. | 2 |
| 2022 | Discovering Onion Services Through Circuit Fingerprinting AttacksabstractTor onion services provide anonymous service to clients using the Tor browser without disclosing the real address of the server. But an adversary could use a circuit fingerprinting attack to classify circuit types and discover the network address of the onion service. Recently, Tor has used padding defenses to inject dummy cells to protect against circuit fingerprinting attacks. But we found that circuits still expose much information to the adversary. In this paper, we present a novel circuit fingerprinting attack, which divides the circuit into the circuit generated by the client and the circuit generated by the onion service. To get a more effective attack, we tried three state-of-the-art classification models called SVM, Random Forest and XG-Boost, respectively. As the best performance, we attain 99.99 % precision and 99.99% recall when using Random Forest and X G Boost classification models, respectively. And we also tried to classify circuit types using our features and the classification model mentioned above, which was first proposed by Kwon. The best performance was achieved with 99.99% precision and 99.99% recall when using the random forest classifier in circuit type classification. The experimental results show that we achieved highly accurate circuit fingerprinting attacks even when application-layer traffic is identical and some type of circuits using the defenses provided by Tor. Yanhui Du |
SEC | 2 |
| 2020 | Android Malware Detection Based on a Hybrid Deep Learning ModelabstractIn recent years, the number of malware on the Android platform has been increasing, and with the widespread use of code obfuscation technology, the accuracy of antivirus software and traditional detection algorithms is low. Current state-of-the-art research shows that researchers started applying deep learning methods for malware detection. We proposed an Android malware detection algorithm based on a hybrid deep learning model which combines deep belief network (DBN) and gate recurrent unit (GRU). First of all, analyze the Android malware; in addition to extracting static features, dynamic behavioral features with strong antiobfuscation ability are also extracted. Then, build a hybrid deep learning model for Android malware detection. Because the static features are relatively independent, the DBN is used to process the static features. Because the dynamic features have temporal correlation, the GRU is used to process the dynamic feature sequence. Finally, the training results of DBN and GRU are input into the BP neural network, and the final classification results are output. Experimental results show that, compared with the traditional machine learning algorithms, the Android malware detection model based on hybrid deep learning algorithms has a higher detection accuracy, and it also has a better detection effect on obfuscated malware. Tianliang Lu, Yanhui Du, Li Ouyang, Qiuyu Chen, Xirui Wang |
Secur. Commun. Networks | 2 |
| 2017 | Static detection of Android malware based on improved random forest algorithmabstractIn recent years, smart phone becomes more and more popular. At the same time, the security threat of smart phone is growing. According to “Motive Security Labs Malware Report-H1 2015” [1] report, the number of Android malware is growing year by year. Many researchers focus on the security of Android applications based on permission. Felt et al. [2] designed the stowaway tool to detect the application's over-privilege. This tool can also identify and quantify the over-privilege triggered by developer errors. Enck et al. [3] proposed a security mechanism called Kirin. The Kirin consisted of nine permission rules. The more rules the application has, the more dangerous it is. But few studies use two-layer models for detection to improve accuracy. Su Hou, Tianliang Lu, Yanhui Du |
ISI | 3 |
| 2013 | Aggregating vulnerability metrics in enterprise networks using attack graphsabstractQuantifying security risk is an important and yet difficult task in enterprise network security management. While metrics exist for individual software vulnerabilities, there is currently no standard way of aggregating such metrics. We present a model that can be used to aggregate vulnerability metrics in an enterprise network, producing quantitative metrics that measure the likelihood breaches can occur within a given network configuration. A clear semantic model for this aggregation is an important first step toward a comprehensive network security metric model. We utilize existing work in attack graphs and apply probabilistic reasoning to produce an aggregation that has clear semantics and sound computation. We ensure that shared dependencies between attack paths have a proportional effect on the final calculation. We correctly reason over cycles, ensuring that privileges are evaluated without any self-referencing effect. We introduce additional modeling artifacts in our probabilistic graphical model to capture and account for hidden correlations among exploit steps. The paper shows that a clear semantic model for aggregation is critical in interpreting the results, calibrating the metric model, and explaining insights gained from empirical evaluation. Our approach has been rigorously evaluated using a number of network models, as well as data from production systems. John Homer, Xinming Ou, Yanhui Du, S. Raj Rajagopalan, Anoop Singhal |
J. Comput. Secur. | 5 |