EDBT 2026 Demo / reviewers in the wild / expert
Linru Ma
dblp:14/1999
· DBLP profile ↗
12ranked-venue papers
1as first author
12since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Parse-LLM: A Prior-Free LLM Parser for Unknown System LogsabstractLog parsing extracts structured information from unstructured logs and serves as a fundamental pre-processing step for various log-based analytics and monitoring tasks. Recent advances have leveraged Large Language Models (LLMs) to handle log format complexities and enhance parsing performance. However, these methods heavily rely on labeled data, which is often scarce in rapidly evolving industrial systems, limiting their applicability in real-world scenarios. Moreover, the sheer volume of logs results in slow parsing and high computational costs, further hindering the deployment of LLM-based log parsing systems. To address these issues, we propose Parse-LLM, an unsupervised end-to-end log parsing framework based on LLMs Specifically, we first developed a Log Decomposer Agent that leverages Chain-of-Thought (CoT) reasoning and callable tools, enabling the LLM to autonomously separate log headers from content. Next, we introduce the Hybrid Log Partition module, which segments logs by balancing commonalities and differences. Finally, we developed a novel Variation-aware Log Parsing module that allows the LLM to harness additional supervisory signals through comparative analysis of similar logs. Comprehensive experiments conducted on large-scale public datasets show that Parse-LLM outperforms state-of-the-art log parsers in an unsupervised setting, offering an effective and scalable solution for the practical application of unsupervised log parsing. Chengyu Song, Lin Yang 0031, Jianming Zheng, Jinzhi Liao, Linru Ma |
CIKM | 6 |
| 2025 | Poster: Boosting Inter-Procedural Vulnerability Detection via Retrieval-Augmented GenerationabstractTraditional LLM-based vulnerability detection methods face challenges like hallucinations and high false positive rates. In order to overcome these constraints, we propose an innovative RAG-based method for inter-procedural vulnerability detection named IPVRAG. The main innovation design of our IPVRAG is its multi-level feature extraction strategy: during knowledge base construction, it not only extracts functional semantics and vulnerability causes but also stores pruned Data Flow Graph structures and semantic identifier information. Evaluated on a widely-used dataset, IPVRAG outperformed many of LLM-based baselines. It achieved optimal overall performance in inter-procedural vulnerability detection, particularly demonstrating superior precision-recall balance that effectively reduced false negatives. Linru Ma, Hongquan Xu, Hongyu Kuang, Boyu Deng |
ICPADS | 1 |
| 2025 | Capturing Individuality and Commonality Between Anchor Graphs for Multi-View ClusteringabstractThe use of anchors often leads to better efficiency and scalability, making them highly favored. However, there is a challenge in anchor-based multi-view subspace learning. A unified anchor graph overly emphasize the commonality between views, failing to adequately capture the view-specific individuality. This has led some models to independently explore the individuality of each view before aligning and integrating them, often achieving better performance but making the process more cumbersome. Therefore, this paper proposes a new model, simultaneously capturing the individuality and commonality between anchor graphs for multi-view clustering. The model has three notable advantages: First, it allows view-specific anchor graphs to align in real-time with a common anchor graph as a reference, eliminating the need for post-alignment. Second, it enforces a cluster-wise structure among anchors and balances sample distribution among them, providing strong discriminative power. Lastly, it maintains linear complexity with respect to the numbers of samples and anchors, avoiding the significant time costs associated with their increase. Comprehensive experiments demonstrate the effectiveness and efficiency of our method compared to various state-of-the-art algorithms. Zhoumin Lu, Linru Ma, Feiping Nie 0001, Rong Wang 0001 |
IJCAI | 3 |
| 2025 | A network integrated performance evaluation method based on multi-attribute decisions of topology and traffic
Shengyuan Qi, Linru Ma, Shanqing Jiang, Lianxiao Meng, Guang Cheng 0001 |
Frontiers Comput. Sci. | 3 |
| 2025 | Intrusion Detection for Internet of Things: An Anchor Graph Clustering ApproachabstractIntrusion detection systems are a crucial technique for securing the Internet of Things (IoT) from malicious attacks. Additionally, due to the continuous emergence of new vulnerabilities and unknown attack types, only a small number of attack samples in the IoT environments can be captured for analysis. In this work, we introduce an anchor graph clustering (AGC) method for intrusion detection to address the challenge of limited labeled samples in the IoT environments. AGC initially transforms the raw data into the embedding space to obtain more representative anchors. Then, AGC unifies anchor graph construction, anchor graph learning, and graph clustering into a unified framework, solving the resulting optimization problem through an iterative solution algorithm. Finally, AGC leverages the powerful analytical capabilities of graph learning to achieve fine-grained classification of low-quality labels. Experimental results on both real and synthetic datasets confirm that AGC can identify intrusions with high precision, while also being time-efficient in detection. Long Zhang 0004, Lin Yang 0031, Linru Ma, Zhoumin Lu, Wen Jiang 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Simplifying Scalable Subspace Clustering and Its Multi-View Extension by Anchor-to-Sample KernelabstractAs we all known, sparse subspace learning can provide good input for spectral clustering, thereby producing high-quality cluster partitioning. However, it employs complete samples as the dictionary for representation learning, resulting in non-negligible computational costs. Therefore, replacing the complete samples with representative ones (anchors) as the dictionary has become a more popular choice, giving rise to a series of related works. Unfortunately, although these works are linear with respect to the number of samples, they are often quadratic or even cubic with respect to the number of anchors. In this paper, we derive a simpler problem to replace the original scalable subspace clustering, whose properties are utilized. This new problem is linear with respect to both the number of samples and anchors, further enhancing scalability and providing more efficient operations. Furthermore, thanks to the new problem formulation, we can adopt a separate fusion strategy for multi-view extensions. This strategy can better measure the inter-view difference and avoid alternate optimization, so as to achieve more robust and efficient multi-view clustering. Finally, comprehensive experiments demonstrate that our methods not only significantly reduce time overhead but also exhibit superior performance. Zhoumin Lu, Feiping Nie 0001, Linru Ma, Rong Wang 0001, Xuelong Li 0001 |
IEEE Trans. Image Process. | 3 |
| 2024 | Insider Threat Defense Strategies: Survey and Knowledge Integration
Chengyu Song, Jingjing Zhang 0005, Linru Ma, Xinxin Hu, Jianming Zheng, Lin Yang 0031 |
KSEM (5) | 3 |
| 2024 | Saliency-guided meta-hallucinator for few-shot learning
Linru Ma, Piotr Koniusz, Philip Torr 0001 |
Sci. China Inf. Sci. | 4 |
| 2024 | Adversarial Attacking and Defensing Modulation Recognition With Deep Learning in Cognitive-Radio-Enabled IoTabstractModulation recognition using deep learning (DL) can efficiently recognize modulated signals in cognitive radio-enabled Internet of Things (IoT). However, it is vulnerable to the attack of adversarial examples designed by attackers, leading to a decrease in its accuracy. Different adversarial techniques can be used for attacks, but these attacks have limited efficiency. This article proposes a double loop iterative method. Different from the traditional attack methods, the new method designs an additional external loop iteration for high efficiency. When generating adversarial examples, the initial conditions of each iteration can be updated as the number of iterations changes, so that the adversarial examples can cross the decision boundary of the model as much as possible. In addition, this article uses knowledge distillation to improve the traditional adversarial training defense, which improves the robustness of the model. Simulation results show that the proposed attack and defense methods have better performance than traditional methods. Zhenju Zhang, Linru Ma, Mingqian Liu, Yunfei Chen 0001, Nan Zhao 0001 |
IEEE Internet Things J. | 2 |
| 2022 | MADDC: Multi-Scale Anomaly Detection, Diagnosis and Correction for Discrete Event LogsabstractAnomaly detection for discrete event logs can provide critical information for building secure and reliable systems in various application domains, such as large scale data centers, autonomous driving, and intrusion detection. However, the task is very challenging due to the lack of a clear understanding and definition of anomaly in the specific problem space, and the log data is often highly complex with temporal correlation. Existing deep learning based methods mostly suffer from such issues as overfitting, uncertainty or low interpretability; consequently, the detection results may be inaccurate, with little information to help security analysts diagnose the reported anomalies with high confidence. To tackle this challenge, in this research, we propose a general framework named MADDC, which aims to (1) accurately perform Multi-scale Anomaly Detection, Diagnosis and Correction for discrete event logs, and (2) help analysts further mitigate anomalies based on diagnosis results. Specifically, we first design a new anomaly critic for LSTM variational autoencoder based model to alleviate overfitting and reduce false negatives during anomaly detection. As one of our main contributions, we then introduce process mining technique to build process-centric workflow models in an unsupervised manner, which forms the ‘normal’ context of an event sequence and help perform accurate and consistent anomaly diagnosis through global sequence alignment. Experiments on publicly available datasets show that MADDC not only outperformed several representative methods in terms of detection accuracy, but also could improve the visibility to abnormal deviations from normal execution, hence helping security analysts understand anomalies and make further corrections. Xiaolei Wang 0003, Lin Yang 0031, Linru Ma, Junchao Xiao, Jiyuan Liu 0003, Yuexiang Yang |
ACSAC | 4 |
| 2021 | A Survey on the Development of Self-Organizing Maps for Unsupervised Intrusion Detection
Xiaofei Qu, Linru Ma, Meng Sun 0001, Mingxing Ke |
Mob. Networks Appl. | 4 |
| 2021 | Image-Based Insider Threat Detection via Geometric TransformationabstractInsider threat detection has been a challenging task over decades; existing approaches generally employ the traditional generative unsupervised learning methods to produce normal user behavior model and detect significant deviations as anomalies. However, such approaches are insufficient in precision and computational complexity. In this paper, we propose a novel insider threat detection method, Image-based Insider Threat Detector via Geometric Transformation (IGT), which converts the unsupervised anomaly detection into supervised image classification task, and therefore the performance can be boosted via computer vision techniques. To illustrate, our IGT uses a novel image-based feature representation of user behavior by transforming audit logs into grayscale images. By applying multiple geometric transformations on these behavior grayscale images, IGT constructs a self-labelled dataset and then trains a behavior classifier to detect anomaly in a self-supervised manner. The motivation behind our proposed method is that images converted from normal behavior data may contain unique latent features which remain unchanged after geometric transformation, while malicious ones cannot. Experimental results on CERT dataset show that IGT outperforms the classical autoencoder-based unsupervised insider threat detection approaches, and improves the instance and user based Area under the Receiver Operating Characteristic Curve (AUROC) by 4% and 2%, respectively. Lin Yang 0031, Xiaolei Wang 0003, Linru Ma, Junchao Xiao |
Secur. Commun. Networks | 5 |