EDBT 2026 Demo / reviewers in the wild / expert
Jianan Huang 0001
dblp:150/8628-1
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2027
0009-0005-8216-5478ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Cross-level graph learning on packet-cluster representations of encrypted traffic for network intrusion detection
Weiwei Liu 0002, Jianan Huang 0001, Fengyuan Nie 0001 |
Expert Syst. Appl. | 3 |
| 2026 | Lightweight Graph Mining for Website Fingerprinting Guided by Structure Knowledge
Bo Gao 0005, Weiwei Liu 0002, Guangjie Liu 0001, Fengyuan Nie 0001, Jianan Huang 0001 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2025 | IoT-AMLHP: Aligned multimodal learning of header-payload representations for resource-efficient malicious IoT traffic classification
Fengyuan Nie 0001, Guangjie Liu 0001, Weiwei Liu 0002, Jianan Huang 0001, Bo Gao 0005 |
Ad Hoc Networks | 4 |
| 2025 | Empowering Anomaly Detection in IoT Traffic Through Multiview Subspace LearningabstractWith the frequent occurrence of information security incidents within the Internet of Things (IoT) landscape, there has been an increasing emphasis on anomaly detection in IoT traffic. Recently, supervised machine learning techniques have shown significant potential on this topic. However, the intricate nature of IoT network environments has posed a challenge in acquiring sufficient labeled samples of abnormal traffic. In comparison to supervised learning, unsupervised learning has more lenient sample requirements. Researchers have proposed various unsupervised detection methods, yet limitations persist. First, unsupervised learning, lacking guidance from labeled information, necessitates a more diverse range of traffic perspectives for comprehensive information coverage. Second, despite efforts to extract multiview traffic features from various perspectives, existing methods struggle to integrate these features effectively, limiting interpretability and introducing redundancy and noise. Lastly, conventional unsupervised methods often rely heavily on manually crafted features, potentially leading to biased and limited representations. In this article, we propose an unsupervised IoT traffic anomaly detection method based on multiview subspace learning. Specifically, we first construct a multiview traffic representation, including a protocol field view and a payload semantic view. Subsequently, a multiview subspace learning algorithm is designed to project the different views of traffic onto a unified and low-rank subspace, optimized using the augmented lagrangian multiplier with alternating direction minimization (ALM-ADM) strategy. Finally, spectral clustering is employed to accomplish IoT traffic anomaly detection. We benchmark the proposed method on multiple IoT traffic datasets and diverse computational platforms. The experimental results demonstrate that the method outperforms other state-of-the-art approaches in terms of accuracy and computational efficiency. Fengyuan Nie 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Jianan Huang 0001, Chau Yuen |
IEEE Internet Things J. | 5 |
| 2025 | Lightweight Identification of Malicious IoT Traffic via Cross-View Knowledge DistillationabstractAccurately identifying malicious traffic in heterogeneous IoT environments is critical for network security. Although deep learning-based methods can effectively extract multi-dimensional features and achieve high accuracy, deploying complex models on resource-constrained IoT devices remains challenging. To balance performance and efficiency, we propose IoT-CVKD, a novel malicious IoT traffic identification framework leveraging cross-view knowledge distillation. IoT-CVKD consists of a multi-view teacher model and a lightweight single-view student model. The teacher model characterizes heterogeneous traffic from different perspectives by capturing flow-level global and packet-level spatio-temporal local burst information, and efficiently fuses these features using a cross-attention mechanism. The student model, composed of lightweight and computationally efficient modules, takes only packet-level features as input. Multi-view knowledge from the teacher is then implicitly distilled into the student through cross-view knowledge distillation during training, thereby significantly enhancing the student’s classification capability. Extensive evaluations demonstrate that IoT-CVKD achieves superior classification performance compared to state-of-the-art methods while substantially reducing computational complexity, making it highly suitable for resource-constrained IoT deployments. Fengyuan Nie 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Jianan Huang 0001, Chau Yuen |
IEEE Internet Things J. | 5 |
| 2025 | QuicCourier: Leveraging the Dynamics of QUIC- Based Website Browsing Behaviors Through Proxy for Covert CommunicationabstractNetwork covert channels transmit secret messages by manipulating network traffic, including packet headers, timing intervals, and communication patterns. The growth of network services has spurred interest in exploring these channels. Yet, the practical application of these channels faces challenges in transmission rate and reliability due to unpredictable network interference. QUIC-based websites offer promising opportunities for covert communication, given their inherent dynamic nature from web resource updates and network interferences. Repeated visits or refresh actions on the same website generate substantial statistical redundancy. Furthermore, widely used proxy tools introduce additional traffic morphology changes. This paper presentsQuicCourier, a covert channel leveraging web traffic's dynamic characteristics and proxy service encapsulation to hide messages in QUIC packets from the service node to the client. Guided by a generative model for web resource patterns,QuicCourierensures that covert traffic closely resembles legitimate traffic, employing three packet-wise meta operations. The altered QUIC flows are then encased in proxy protocols, complicating the detection of embedded information. The covert receiver is incorporated into the proxy client. The efficacy ofQuicCourieris evaluated using a dataset of over 30,000 web browsing traffic samples, demonstrating its exceptional undetectability against state-of-the-art traffic classification tools and a high covert transmission rate. Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Multi-Level Resource-Coherented Graph Learning for Website Fingerprinting AttacksabstractDeep learning-based website fingerprinting (WF) attacks dominate website traffic classification. In the real world, the main challenges limiting their effectiveness are, on the one hand, the difficulty in countering the effect of content updates on the basis of accurate descriptions of page features in traffic representations. On the other hand, the model’s accuracy relies on training numerous samples, requiring constant manual labeling. The key to solving the problem is to find a website traffic representation that can stably and accurately display page features, as well as to perform self-supervised learning that is not reliant on manual labeling. This study introduces the multi-level resource-coherented graph convolutional neural network (MRCGCN), a self-supervised learning-based WF attack. It analyzes website traffic using resources as the basic unit, which are coarser than packets, ensuring the page’s unique resource layout while improving the robustness of the representations. Then, we utilized an echelon-ordered graph kernel function to extract the graph topology as the label for website traffic. Finally, a two-channel graph convolutional neural network is designed for constructing a self-supervised learning-based traffic classifier. We evaluated the WF attacks using real data in both closed- and open-world scenarios. The results demonstrate that the proposed WF attack has superior and more comprehensive performance compared to state-of-the-art methods. Bo Gao 0005, Weiwei Liu 0002, Guangjie Liu 0001, Fengyuan Nie 0001, Jianan Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | WF-A2D: Enhancing Privacy With Asymmetric Adversarial Defense Against Website FingerprintingabstractDespite the end-to-end encryption capabilities provided by network protocols such as QUIC in HTTP/3 and the additional tunneling functions offered by proxy tools like virtual private networks (VPNs) and the onion router (Tor), website fingerprinting (WF) techniques can still identify specific network services by exploiting the spatio-temporal characteristics of network traffic. Therefore, defending against WF attacks is crucial for ensuring comprehensive privacy protection for network services. Existing WF defenses typically rely on proxy-based solutions that require coordinated packet manipulations between the client and the proxy node to counteract WF attacks. These symmetric architectures cannot protect network traffic between proxy nodes and web servers from WF attacks. Furthermore, the ability to counter more powerful traffic analysis tools remains a challenging issue. In this paper, we propose WF-A2D, an asymmetric adversarial defense method against website fingerprinting for HTTP/3. WF-A2D employs a two-stage cascading adversarial learning strategy, leveraging packet direction and length patterns to enhance defense performance. Position-based perturbation vectors representing packet operations are generated for packet-by-packet manipulations to achieve real-time WF defense. Experimental results on a real-world HTTP/3-QUIC website browsing traffic dataset demonstrate that WF-A2D can achieve a defense success rate of 97.10% on average against seven state-of-the-art traffic analysis tools, while incurring less than 2% bandwidth overhead. More importantly, WF-A2D can operate independently on the client side and ensure end-to-end protection to web servers. Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | STAP: Leveraging State-Transition Adversarial Perturbations for Asymmetric Website Fingerprinting DefensesabstractWeb services, as the most ubiquitous form of online services, have consistently attracted research attention due to privacy concerns. Although VPNs and anonymous communication methods can partially protect users’ online privacy, advancements in website fingerprinting (WF) attacks still exploit the spatio-temporal characteristics of Web resource transmission to identify Web services. The challenge lies in defending against WF attacks efficiently, with limited bandwidth costs. Server-side WF defenses, deployed on Web servers, can achieve end-to-end obfuscation across both clients and servers. However, existing defenses often consume significant bandwidth and require additional removal operations on the client side. Given the growing use of QUIC with HTTP/3 and the need for robust privacy protections, this paper introduces an asymmetric server-side WF defense scheme using State-Transition Adversarial Perturbations (STAP). STAP introduces the concept of latent resource-state transitions, which represent hidden patterns in resource transmission. Utilizing perturbation models containing these transitions, STAP subtly alters traffic through packet padding and insertion, with inherent transport layer encryption enhancing the concealment. STAP can operate independently, removing the necessity for user involvement. Experimental results demonstrate that STAP outperforms other schemes, achieving reductions in True Positive Rate (TPR) by up to 22% and reductions in bandwidth overhead by up to 30%. Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001, Marco Mellia |
IEEE Trans. Netw. Serv. Manag. | 1 |