Fangjiao Zhang

dblp:153/5781 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0005-5720-8253ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 DAB-LLM: Detection of Anomalies in API Call Behavior Based on Large Language Model
abstract
APIs are now central to digital transformation, carrying the core business logic and sensitive data of enterprises. Attackers can gain access to important information systems and sensitive data by attacking APIs, allowing them to steal high-value data. Besides being vulnerable to traditional attacks, APIs also face unique threats tailored to their characteristics, such as attacks targeting API business logic threats. This type of API attacks are complex, and the attack requests are very similar to legitimate traffic, making them difficult to distinguish from benign requests. Therefore, traditional single-request detection methods are ineffective against such complex attacks. By employing intelligent context-aware natural language processing techniques, we can understand API call behavior and establish a baseline of normal API call behavior to identify anomalies. In this paper, we propose DAB-LLM, a model for Detecting Anomalies in API call Behavior based on Large Language Model. Our approach utilizes extraction and representation methods for API call chains and API call graphs, prompt optimization algorithm, and LoRA fine-tuning technique to enable the model to deeply understand of API call behavior and enhance detection capabilities. Experimental results indicate that DAB-LLM excels in detecting attack behaviors and anomalies in API calls, achieving an f1-score of 97.35% along with significant improvements in recall rate, accuracy and precision. The overall performance of the model shows that our proposed model significantly outperforms other models in API call behavior anomaly detection.
Fangjiao Zhang, Baihang Liu, Baoxu Liu, Qixu Liu
CSCWD2
2025 Shadowkube: enhancing Kubernetes security with behavioral monitoring and honeypot integration
abstract
Abstract As cloud-native technologies continue to evolve, containerization and orchestration have become fundamental for deploying microservices. However, this advancement introduces significant security vulnerabilities, particularly due to vulnerabilities and misconfigurations that grant attackers excessive control over clusters. Existing works, including model-based learning and static rule-based approaches, suffer from limitations such as false positives and maintenance overhead, which pose significant challenges to cloud-native security. To mitigate intrusion targeting container orchestration, we present ShadowKube, an innovative active defense framework tailored for Kubernetes. ShadowKube integrates behavioral monitoring with shadow honeypots to effectively detect and neutralize anomalous behavior. By establishing behavioral baselines to identify deviations and converting compromised nodes into honeypots, ShadowKube isolates and traps attackers, thereby mitigating the threats they pose. Comprehensive evaluations demonstrate ShadowKube’s ability to detect and migrate exploitations across 43 severe CVEs and 7 common misconfiguration types. Deployment in a live environment further validates its effectiveness, with ShadowKube identifying 635 attack attempts, successfully decoying 23 active attacks. Additionally, ShadowKube could isolate attackers and convert affected nodes into honeypots within seconds. These results highlight ShadowKube’s efficacy as a robust solution for enhancing security in Kubernetes clusters, offering a proactive defense mechanism against both current and emerging threats.
Qingwang Chen, Ru Tan, Ze Jin, Juxin Xiao, Fangjiao Zhang, Qixu Liu
Cybersecur.7
2025 EVFeX: An efficient vertical federated XGBoost algorithm based on optimized secure matrix multiplication
Fangjiao Zhang, Chang Cui, Qingshu Meng
Signal Process.1
2024 TAD-LLM: API Traffic Anomaly Detection Based on Large Language Model
abstract
APIs are increasingly prevalent in application environments, carrying the core business logic and sensitive data of enterprises, and have increasingly become the target of cyber attackers. The proportion of web attacks targeting APIs has exceeded half. The widespread use of APIs has expanded the attack surface, posing serious security challenges. Security risks, such as unauthorized access, misuse of business logic, data breaches, and complex cyber attacks, have intensified. Tr aditional security measures have proven inadequate in addressing API threats. There is an urgent demand for a more contextually aware and intelligent security mechanism capable of effectively mitigating API attacks. We proposed a novel model TAD-LLM based on Large Language Model for anomaly detection in API traffic. By using S2GS data transformation method, prompt optimization algorithm and LoRA fine-tuning technique, enables the model to acquire a profound comprehension of domain-specific knowledge in more elaborate detail, thereby enhancing the overall detection capability. Experimental results demonstrate that the proposed model TAD-LLM makes a significant advancement in securing APIs against cyber threats. The average f1-score of TAD-LLM reaches 99.27% in complex API attack scenarios. There are also notable improvements in precision, recall, and accuracy. Moreover, the overall performance of the model indicates that the model we proposed outperforms other models significantly and exhibits superior capability in handling complex API attack scenarios and advanced API attack techniques. It is worth noting that our model also shows strong performance on CSIC 2010, a widely used common http traffic dataset.
Baoxu Liu, Jingqiang Liu, Fangjiao Zhang, Qixu Liu
MSN4
2024 Dissecting zero trust: research landscape and its implementation in IoT
abstract
Abstract As a progressive security strategy, the zero trust model has attracted notable attention and importance within the realm of network security, especially in the context of the Internet of Things (IoT). This paper aims to evaluate the current research regarding zero trust and to highlight its practical applications in the IoT sphere through extensive bibliometric analysis. We also delve into the vulnerabilities of IoT and explore the potential role of zero trust security in mitigating these risks via a thorough review of relevant security schemes. Nevertheless, the challenges associated with implementing zero trust security are acknowledged. We provide a summary of these issues and suggest possible pathways for future research aimed at overcoming these challenges. Ultimately, this study aims to serve as a strategic analysis of the zero trust model, intending to empower scholars in the field to pursue deeper and more focused research in the future.
Chunwen Liu, Ru Tan, Yun Feng 0003, Ze Jin, Fangjiao Zhang, Qixu Liu
Cybersecur.6
2023 Secure vertical federated learning based on feature disentanglement
abstract
Federated learning (FL) faces many security threats. Although multiple robust FL frameworks have been proposed to defend against these malicious attacks in horizontal federated learning (HFL), security issues in vertical federated learning (VFL) have not been adequately studied. Recent studies show that VFL is vulnerable to inference attacks (e.g., label inference attacks), which puts VFL at risk. To solve this problem, we propose a new VFL framework SVFL (Secure Vertical Federated Learning) to defend against privacy breaches inspired by feature disentanglement. Specifically, in SVFL , the bottom models are feature extractors to extract samples’ features in the high-dimensional space, and the top model sews samples’ features of the same sample ID. Then, disentangling the samples’ features into the class-relevant feature and class-irrelevant one via two classifiers: one is to recognize the class-relevant feature by regular training, and another is to recognize the class-irrelevant feature by adversarial training . Our experiments show that SVFL not only defends against label inference attacks, no matter how many samples features a malicious participant occupies, but also improves the global model’s accuracy. Therefore, SVFL provides a privacy security guarantee for the vertical federated learning system .
Fangjiao Zhang, Zhufeng Suo, Chang Cui, Qingshu Meng
Signal Process.1
2018 Study on Advanced Botnet Based on Publicly Available Resources
Heyang Lv, Fangjiao Zhang, Zhihong Tian, Xiang Cui
ICICS3
2014 POSTER: Abusing URL Shortening Services for Stealthy and Resilient Message Transmitting
abstract
URL shortening services (USS) have been widely used on the Internet, but are currently prone to abuse. In this poster, we exploit the possibility of building a novel stealthy and robust message transmission channel through use of USS. A text string or binary file can be transmitted stealthily using this channel. Our preliminary results show that the proposed channel is feasible and affects many popular USS, thus posing a practical threat to attackers.
Fangjiao Zhang, Chaoge Liu
CCS2