Junwei Tang

dblp:143/0874 · DBLP profile ↗
← Back
21ranked-venue papers
9as first author
16since 2021 · last 2026
0000-0002-1627-3244ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 5 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Dapadv: Differentiated adversarial perturbation generation method in problem space for android malware detection
Junwei Tang, Tao Peng 0006
Comput. Secur.1
2026 HHGDroid: Hybrid heterogeneous graph-based android malware detection via multi-evidence similarity fusion
Junwei Tang, Xiaomei Tian, Jianfeng Lu 0002, Haozhao Wang, Ruixuan Li 0001
Expert Syst. Appl.1
2025 VULDA: Source Code Vulnerability Detection via Local Dependency Context Aggregation on Vulnerability-Aware Code Mapping Graph
Tao Peng 0006, Ling Gui, Junwei Tang, Aoshuang Ye
ICICS (3)4
2025 DTDroid: Adversarial Packed Android Malware Detection Based on Traffic and Dynamic Behavioral
abstract
Android has occupied an important share of the operating system of intelligent terminal devices in the Internet of Things (IoT), and the malicious applications of Android have increased rapidly, posing a serious threat to the security of IoT. Machine learning has advanced significantly in the detection of android malware. In order to protect intellectual property, Android developers have begun to use packing techniques to enhance the security of their applications. However, attackers can also pack their malware, which may make feature extraction ineffective and interfere with the prediction results of learning-based classifiers. For this issue, we have designed and implemented a tool by dynamically loading the original DEX using a shell DexClassLoader to generate a batch of packed Android applications. And we have verified that several existing methods fail when faced with packed samples. Therefore, we propose a novel malware detection method called DTDroid that can resist code packing. DTDroid automatically captures network traffic characteristics of target samples based on fuzzy testing and network traffic packet extraction. At the same time, the dynamic behavior characteristics of the target application can be obtained by monitoring the corresponding runtime function calls and system status. The extracted two types of features are contextually spliced and converted into grayscale images, and then detected based on deep learning model. Experimental results show that the detection accuracy of our method reaches 94.22% and 95.14%, respectively, on two kinds of packed datasets, indicating that DTDroid has better robustness for packed samples than the existing methods.
Junwei Tang, Tao Peng 0006, Xiaoyun Yan, Xinrong Hu
IEEE Internet Things J.1
2025 Sym-CS-HFL: A secure and efficient solution for privacy-preserving heterogeneous federated learning
Jinzhao Wang, Junwei Tang, Xuming Ye, Yaping Wan, Zhiyong Xu 0003, Lingna Chen
J. Inf. Secur. Appl.3
2024 AT-I-FGSM: A novel adversarial CAPTCHA generation method based on gradient adaptive truncation
abstract
Text-based CAPTCHA is widely used in fields such as user identity verification during human-computer interaction in real scenarios. With the development of artificial intelligence, several technologies that automatically bypass CAPTCHAs have emerged, weakening the robustness of CAPTCHAs. In-depth study of adversarial sample technology is needed to further reduce the accuracy of automatic verification code recognition of deep learning models while retaining correct human recognition. We propose a novel method based on gradient adaptive truncation to generate adversarial text-based CAPTCHAs more efficiently. Based on the generated model, our method dynamically adjusts the gradient truncation threshold according to the progress of the perturbation attack method, thereby improving the performance of the sample generation model. On the authoritative dataset, our method is compared with the existing state-of-the-art methods. The results show that our AT-I-FGSM can more effectively reduce the accuracy of automatic recognition models to identify CAPTCHAs and improve the security of CAPTCHAs. At the same time, our method consumes less time in generating CAPTCHAs.
Junwei Tang, Tao Peng 0006, Ruhan He, Xinrong Hu, Changzheng Liu
CSCWD1
2024 Open-Vocabulary RGB-Thermal Semantic Segmentation
Xiaoyun Yan, Zhaojing Wang, Junwei Tang, Yangjun Ou, Xinrong Hu, Tao Peng 0006
ECCV (74)5
2024 Android malware detection based on a novel mixed bytecode image combined with attention mechanism
Junwei Tang, Tao Peng 0006, Qiaosen Pi, Ruhan He, Xinrong Hu
J. Inf. Secur. Appl.1
2024 Attention mechanism-based generative adversarial networks for image cartoonization
Jianlin Zhu, Junwei Tang
Vis. Comput.5
2023 A lightweight method for Android malware classification based on teacher assistant distillation
abstract
In recent years, the growing concern over mobile security and the associated risks posed by mobile malware have prompted an increased focus on utilizing deep learning models for analyzing Android application security. However, the expansion of deep learning model sizes results in an exponential growth of model parameters, demanding significant computing resources for execution. To address this challenge, we propose a lightweight Android malware detection method based on teacher-assistant-student knowledge distillation. Our method enables predicting on local clients, eliminating the need for cloud-base service interactions, and protecting user privacy. We visualize the binary file of the target Android application as an RGB three-channel color image, using ResNeSt50 as the teacher model, and compress it based on knowledge distillation. An assistant model is incorporated to address the issue of insufficient distillation resulting from the significant gap between the teacher and student models. Additionally, we integrate a split-attention mechanism to enhance the ability of the professor model to acquire deep features of malware images. We conduct experiments on Drebin and CICMalDroid 2020 datasets and the results show that the proposed method can ensure that the detection results of student model are more similar to those of the teacher model while reducing model complexity. Our method reduces the number of model parameters by 95% compare to the teacher model while maintaining accuracy. And the accuracy is improved by 0.63% compare to the traditional distillation method.
Junwei Tang, Qiaosen Pi, Ruhan He, Tao Peng 0006, Xinrong Hu
MSN1
2023 PTLVD:Program Slicing and Transformer-based Line-level Vulnerability Detection System
abstract
In recent years, deep learning-based software vulnerability detection methods have made significant progress. However, most existing methods focus on detecting vulnerabilities at the function-level or slice-level and cannot pinpoint the exact lines of code that cause the vulnerabilities. Program slicing can extract control and data dependency information from the code to assist deep learning models in detecting vulnerabilities. We propose a novel vulnerability detection model, PTLVD, which generates code gadgets(CGs) by slicing the program based on variables in the code, uses a transformer model for binary classification, and employs our proposed method Integrated Gradients Enhanced with Saliency(IGS) to locate the lines of code that are likely to cause vulnerabilities. IGS enhances the interpretability of the model by integrating the Integrated Gradients and Saliency methods. PTLVD employs an improved method of generating CGs to selectively remove irrelevant code statements, resulting in CGs that contain richer information and enhance the model’s performance. Additionally, during the preprocessing stage, PTLVD removes comments and standardizes code statements onto the same line, which effectively enhances the performance and vulnerability localization capabilities of the model. Experimental results show that, compared to state-of-the-art function-level and slice-level vulnerability detection models, PTLVD improves precision and F1 by 5.25% and 1.79%, respectively. In line-level prediction, Compared to the baseline method, PTLVD not only improved the Top-5 Accuracy by 1.61%, but also successfully reduced the Mean First Ranking by 5.08%.
Tao Peng 0006, Shixu Chen, Junwei Tang, Junping Liu, Xinrong Hu
SCAM4
2023 Sym-Fed: Unleashing the Power of Symmetric Encryption in Cross-Silo Federated Learning
abstract
With the increasing number of big data applications, large amounts of valuable data are distributed in different organizations or regions. Federated Learning (FL) enables collaborative model training without sharing sensitive data and is widely used in AI medical diagnosis, economy, and autonomous driving scenarios. However, it still leaks the privacy from the gradient exchange in federated learning. What’s worse, state-of-the-art work, such as Batchcrypt, still suffers from computational overhead due to a considerable amount of computation and communication costs caused by homomorphic encryption. Therefore, we propose a novel symmetric key-based homomorphic encryption scheme, Sym-Fed. To unleash the power of symmetric encryption in federated learning, we combine random masking with symmetric encryption and keep the homomorphic property during the gradient exchange in the federated learning process. Finally, the security analysis and experimental results on real workloads show that our design achieves performance improvement 6× to 668× and reduces the communication overhead 1.2× to 107× compared with the state-of-the-art work, BatchCrypt and FATE, without model accuracy degradation and security compromise.
Jinzhao Wang, Ruixuan Li 0001, Junwei Tang, Xuming Ye, Yaping Wan, Zhiyong Xu 0003
TrustCom4
2022 A Mitmproxy-based Dynamic Vulnerability Detection System For Android Applications
abstract
During the process of pushing patch packets for Android application hotfix, the attacker can hijack and tamper with the dex file due to the lack of adding a digital signature, which leads to code injection with serious consequences. To address the above problems, an dynamic vulnerability detection system based on mitmproxy is primary proposed, which first utilizes mitmproxy to capture all the packets interacted between the client and the server while locating the dex file, then injects the test code into the dex and pushes it to the client for execution using a man-in-the-middle attack, and finally verifies through the log output by the application whether there is a code injection vulnerability. For 1000 applications in the application market, our system successfully detects 34 new unknown applications with dex injection, and the experimental results show that the system is effective in detecting real-world applications with vulnerabilities caused by hotfix.
Xinghang Lv, Tao Peng 0006, Junwei Tang, Ruhan He, Xinrong Hu, Minghua Jiang, Zaihui Deng, Wenli Cao
MSN3
2022 A Mitmproxy-based Dynamic Vulnerability Detection System For Android Applications
abstract
During the process of pushing patch packets for Android application hotfix, the attacker can hijack and tamper with the dex file due to the lack of adding a digital signature, which leads to code injection with serious consequences. To address the above problems, an dynamic vulnerability detection system based on mitmproxy is primary proposed, which first utilizes mitmproxy to capture all the packets interacted between the client and the server while locating the dex file, then injects the test code into the dex and pushes it to the client for execution using a man-in-the-middle attack, and finally verifies through the log output by the application whether there is a code injection vulnerability. For 1000 applications in the application market, our system successfully detects 34 new unknown applications with dex injection, and the experimental results show that the system is effective in detecting real-world applications with vulnerabilities caused by hotfix.
Xinghang Lv, Tao Peng 0006, Junwei Tang, Ruhan He, Xinrong Hu, Minghua Jiang, Zaihui Deng, Wenli Cao
MSN3
2022 Android malware obfuscation variants detection method based on multi-granularity opcode features
Junwei Tang, Ruixuan Li 0001, Xiwu Gu, Yuhua Li 0003
Future Gener. Comput. Syst.1
2021 Detecting Privacy Leaks in Android Hybrid Applications Based on Dynamic Taint Tracking
abstract
Android hybrid applications use the Web Kit engine on Android platform to render Web contents and process JavaScript codes, and enable JavaScript codes to access device sensitive resources and native APIs. Therefore, hybrid applications will bring different security issues compared to native applications. The existing privacy leak detection methods for Android native applications cannot be directly applied to hybrid applications. In addition to the Dalvik Virtual Machine (DVM), hybrid applications may also spread privacy in the WebView component, which increases the scope of privacy dissemination and increases the difficulty of taint tracking. We delve into the different characteristics of privacy spreading on the DVM, Webkit engine and JavaScript engine of hybrid ap-plications. We propose HTDroid, an efficient dynamic taint tracking system for hybrid applications. The core idea of HTDroid is to spread the taint tags in the DVM to the Web Kit engine, and add the function of tracking the spread of taint data to WebKit engine and JavaScript engine through source code instrumentation. Our experiments show that HTDroid can run on both Android emulators and devices and effectively detect privacy leaks in hybrid applications and can deal with the two ways of privacy leaks in hybrid applications while existing TaintDroid cannot. Compared to the original Android system, HTDroid incurs only 22% performance overhead on CaffenieMark benchmark and impose 4.3 % overhead on J avaScript V8 engine benchmark, which is acceptable for run-time taint tracking.
Junwei Tang, Ruixuan Li 0001, Zhiqiang Xiong, Hongmu Han, Xiwu Gu
EUC1
2020 Parallel Space Traveling: A Security Analysis of App-Level Virtualization in Android
abstract
App-level virtualization becomes increasingly popular. It allows multiple instances of an application to run simultaneously on the same Android system, without requiring modification of the Android firmware. These virtualization-capable apps are used by more than 100 million users worldwide. We conduct a systematic study of the implementation of app-level virtualization and the security threats that their users may face. First, we survey more than 160 apps collected from several popular app markets which can provide application virtualization capability. We find that these apps are implemented based on a similar design, and apps running in such a virtual environment are not completely isolated from each other. Second, we analyze malicious virtualized guest apps, and identify several areas of potential attack vectors, including privilege escalation, code injection, ransomware, etc. Malicious virtualized guest apps can launch reference hijacking attacks. Once a legitimate app is running in the virtual context, all of its sensitive data will be exposed to the host app. Third, we find a new type of repackaging attack. In our collection of 2 million app data set, we find that 68 apps pack and load malwares by using the virtualization technology to evade antivirus detection, 91 apps pack some legal apps for the purpose of wide distribution, and insert screen ads to gain profits at its startup. Finally, we discuss a variety of mitigation solutions for users, developers and vendors.
Deshun Dai, Ruixuan Li 0001, Junwei Tang, Ali Davanian, Heng Yin 0001
SACMAT3
2020 AOMDroid: Detecting Obfuscation Variants of Android Malware Using Transfer Learning
Ruixuan Li 0001, Junwei Tang, Ali Davanian, Heng Yin 0001
SecureComm (2)3
2020 Automated Rogue Behavior Detection for Android Applications
Shuangmin Zhang, Ruixuan Li 0001, Junwei Tang, Xiwu Gu
SEKE3
2019 SSLDetecter: Detecting SSL Security Vulnerabilities of Android Applications Based on a Novel Automatic Traversal Method
abstract
Android usually employs the Secure Socket Layer (SSL) protocol to protect the user’s privacy in network transmission. However, developers may misuse SSL-related APIs, which would lead attackers to steal user’s privacy through man-in-the-middle attacks. Existing methods based on static decompiling technology to detect SSL security vulnerabilities of Android applications cannot cope with the increasingly common packed applications. Meanwhile, dynamic analysis approaches have the disadvantages of excessive resource consumption and time-consuming. In this paper, we propose a dynamic method to solve this issue based on our novel automatic traversal model. At first, we propose several new traversal strategies to optimize the widget tree according to the user interface (UI) types and the interface state similarity. Furthermore, we develop a more granular traversal model by refining the traversal level from the Activity component to the Widget and implement a heuristic depth-first traversal algorithm in combination with our customized traversal strategy. In addition, the man-in-the-middle agent plug-in is extended to implement real-time attack test and return the attack results. Based on the above ideas, we have implemented SSLDetecter, an efficient automated detection system of Android application SSL security vulnerability. We apply it on multiple devices in parallel to detect 2456 popular applications in several mainstream application markets and find that 424 applications are suffering from SSL security vulnerabilities. Compared with the existing system SMV-HUNTER, the time efficiency of our system increases by 38% and the average detection rate increases by 6.39 percentage points, with many types of SSL vulnerabilities detected.
Junwei Tang, Ruixuan Li 0001, Hongmu Han, Xiwu Gu, Zhiyong Xu 0003
Secur. Commun. Networks1
2013 Energy and Spectral Efficient Inter Base Station Relaying in Cellular Systems
abstract
This paper considers a classic relay channel which consists of a source, a relay and a destination node and investigates the energy-spectral efficiency tradeoff under three different relay protocols: amplify-and-forward; decode-and-forward; and compress-and-forward. We focus on a cellular scenario where a neighbour base station can potentially act as the relay node to help on the transmissions of the source base station to its assigned mobile device. We employ a realistic power model and introduce a framework to evaluate the performance of different communication schemes for various deployments in a practical macrocell scenario. The results of this paper demonstrate that the proposed framework can be applied flexibly in practical scenarios to identify the pragmatic energy-spectral efficiency tradeoffs and choose the most appropriate scheme optimising the overall performance of inter base station relaying communications.
Efstathios Katranaras, Junwei Tang, Muhammad Ali Imran 0001
VTC Spring2