EDBT 2026 Demo / reviewers in the wild / expert
Shuaishuai Tan
dblp:156/3799
· DBLP profile ↗
15ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-8882-405XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 7 since 2021Computer networks · 5 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fast and robust outlier detection: A granular-ball center isolation and region consistency approach
Rongxiang Wang, Jihong Wan, Xiaoping Li 0001, Shuaishuai Tan |
Pattern Recognit. | 4 |
| 2025 | Dual Modal Featuring Scheme for Learning Based Android Malware Prevention
Jiaxiong Chen, Jinchuan Liu, Shuaishuai Tan, Junhang Fu, Qiannan Lin, Haowen Tan |
Inscrypt (3) | 3 |
| 2025 | Early Detection of Malicious Traffic Based on Graph Modeling and Spatio-Temporal Attention Approach
Jinchuan Liu, Shuaishuai Tan, Jiaxiong Chen, Qiannan Lin, Zhaoyan Chen, Junhang Fu |
Inscrypt (2) | 2 |
| 2025 | Mixture of Experts Representation Learning Scheme for Multi-View Android Malware DetectionabstractThe continuous evolution of Android malware threatens device security, while existing visualization-based schemes often rely on single or random views, limiting their ability to capture malicious behavior comprehensively. To address this limitation, we propose CansDroid, a multi-view detection scheme integrating three complementary views: API sensitivity, operational context, and runtime environment. Each view is processed with dedicated filtering strategies and deep learning techniques. We introduce a Mixture of Experts (MoE) model that enables early-stage multi-view feature collaboration, regularized by balance loss and expert diversity enhancement loss to ensure balanced expert utilization and representation diversity. Experimental results show that CansDroid achieves a detection accuracy of 99.38%, outperforming state-of-the-art schemes, and successfully identifies 674 previously unseen malware samples, demonstrating its effectiveness in detecting evolving Android threats. Jiaxiong Chen, Shuaishuai Tan, Jinchuan Liu, Qiannan Lin, Haowen Tan |
TrustCom | 2 |
| 2025 | A Multi-User Effective Computation Offloading Mechanism for MEC System: Batched Multi-Armed Bandits ApproachabstractWith the development of the fifth generation (5G) technology, Mobile Edge Computing (MEC) is becoming a useful architecture, which is envisioned as a cloud extension version. Users within the MEC system could save more time on data transmission, in which the tasks can be executed on the edge side. Multi-armed bandits (MAB) are powerful tools that help users offload tasks to their best servers in the MEC system. However, as the system scale grows, the traditional MAB algorithms are weak and the channel condition deteriorates rapidly, which will lead to an increasing time cost of edge tasks offloading and computing. Therefore, in this paper, we propose aBatch-basedMulti-userServerElimination (BMSE) to solve such a problem. BMSE contains two sub-algorithms, BMSE inUserLevel (BMSE-UL) and BMSE inSystemLevel (BMSE-SL). BMSE-UL is applied among users for the initial stage which can help them discard servers with obvious bad performance. BMSE-SL is applied in the whole MEC system which can guide users offloading tasks collectively. Furthermore, we establish the optimality of the proposed algorithms by proving the sub-linearity convergence of their regrets and demonstrate the effectiveness through extensive experiments. Hangfan Li, Shuaishuai Tan, Xiaoxiong Zhong |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Enhancing Flow Embedding Through Trace: A Novel Self-supervised Approach for Encrypted Traffic ClassificationabstractTraffic classification is a crucial task in network security and management. Recent research has shown the effectiveness of deep learning when applied to encrypted traffic classification. However, the reliance of deep learning models on abundant labeled and balanced data poses challenges, particularly in traffic analysis where labeling is costly and imbalanced traffic distribution is common. To tackle this challenge, researchers have proposed self-supervised representation learning. This approach aims to derive universal traffic representations from vast amounts of unlabeled data, reducing the need for extensive labeling in downstream tasks. Current representation learning methods predominantly focus on exploring flow-level information, neglecting valuable trace information crucial for effective flow representation learning. In this study, we introduce SAFE, a self-supervised learning methodology tailored for flow representation learning. SAFE specifically delves into trace-level (i.e., a mixture of correlated flows) information to enhance flow embedding. Moreover, our analysis reveals that existing encrypted traffic datasets often contain numerous invalid samples. SAFE conducts a comprehensive examination of dataset characteristics, filtering out these invalid samples, thereby advancing the field significantly. Extensive experiments demonstrate that SAFE outperforms state-of-the-art methods. Zefei Luo, Yu Li 0007, Shuaishuai Tan, Daojing He |
IJCNN | 3 |
| 2024 | You Can Glimpse but You Cannot Identify: Protect IoT Devices From Being FingerprintedabstractWith pervasive IoT networking, traffic-analysis-based IoT fingerprinting techniques have been well researched. For example, by integrating blockchain technology and device fingerprinting, authentication of devices connected to a network can be achieved. Though the primary motivations are identifying vulnerabilities and implementing access control, the techniques could be exploited to trace IoT users’ privacy. We propose a traffic morphing scheme to protect IoT devices from being identified by fingerprinting models. The scheme mainly consists of a morphing policy learning algorithm, a rewarding model, and a time-series-based feature estimation algorithm. Backed by the timely rewarding model, a learning agent produces an optimal policy that perturbs the target fingerprinting model while preserving the original traffic function. The estimation algorithm predicts the feature vectors of unfinished flows to enable live traffic morphing. The scheme's advantage is that it requires minimal knowledge of the fingerprinting model and supports live morphing. Experimental results show that over 81% of the IoT devices become unidentifiable, and the scheme degrades the average F1 score of mainstream fingerprinting models from 0.996 to 0.526. For certain devices and target models, the scheme even reaches 100% effectiveness. Shuaishuai Tan, Shui Yu 0001, Wenyin Liu, Daojing He, Sammy Chan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | The Role of Class Information in Model Inversion Attacks Against Image Deep Learning ClassifiersabstractModel inversion attacks can reconstruct the training samples of victim deep learning models. The existing efforts heavily rely on auxiliary information of the target samples (prior target information) to achieve their adversarial goals. However, prior target information is hard to obtain in practice. In this paper, we explore the effect of class information in model inversion attacks to reduce the reliance of prior target information. Our contributions on class information exploitation are two-fold. Firstly, we propose a supervised inversion model, Supervised Model Inversion (SMI). The proposed inversion model learns pixel-level features and data-to-class features from the rounded-outputs of the victim model and labeled auxiliary dataset. Secondly, we leverage victim model's rounded-outputs to guide the optimization of reconstructing inversion samples after trained inversion model. Our experimental results show that inversion samples reconstructed by SMI are more visually plausible with more details, comparing to the three representative model inversion attacks. We further perform an extensive study on various auxiliary dataset settings. It is found that the class combination in the auxiliary dataset rather than the number of classes that determines the quality of inversion samples. The ground-truth labels can improve the qualities of inversion samples but not essential to inversion attacks. Zhiyi Tian, Lei Cui 0006, Chenhan Zhang, Shuaishuai Tan, Shui Yu 0001, Yonghong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Hitting Moving Targets: Intelligent Prevention of IoT Intrusions on the FlyabstractMassive Internet of Things (IoT) devices have been playing a critical role in both the cyber and physical worlds. Various cyber attacks pose significant risks to IoT. Machine learning-based intrusion detection system (IDS) has earned much research attention. However, the intrusion prevention system (IPS) is rarely explored. Realtime intrusion prevention is quite challenging because the decision has to be made during a flow rather than after it finishes. Restricted by aligning with the shortest flows, existing IPSs generally inspect only the very first packets, leading to information loss for accurate detection. In this article, we first measure the information loss quantitatively. Then we devise Sniper, an IoT IPS scheme consisting of a flow length predictor, a novel feature space, and an enhanced ensemble learning algorithm. The flow length predictor guides a proper prevention time point to preserve as much information as possible. The proposed Markov matrix-based feature encoding method further saves more information than existing ones. The enhanced learning algorithm ensures a low-false positive rate (FPR), which is critical for IPSs. We benchmark Sniper with one closed-world and three open-world data sets. The results show that Sniper achieves a 99.89% prevention rate and 0.03% FPR, which is superior to the five state-of-the-art baseline models. Shuaishuai Tan, Wenyin Liu, Qingkuan Dong, Sammy Chan, Shui Yu 0001, Xiaoxiong Zhong, Daojing He |
IEEE Internet Things J. | 1 |
| 2022 | Sneaking Through Security: Mutating Live Network Traffic to Evade Learning-Based NIDSabstractMachine learning based network intrusion system (NIDS) is known to be vulnerable to evasions. Attackers conceal intrusion activities to make them undetected. Researching evasion techniques contributes to evaluating and increasing the robustness of NIDS. Previous evasion approaches modify feature values or packets of an offline network trace as a whole. However, in real scenarios, attackers are constrained to manipulate only outbound packets on the fly. To bridge this assumption gap, we present the first evasion solution for live network traffic against learning based NIDSs. The solution consists of three components: a devised Kalman filter based algorithm to predicate the feature values of live flows, a set of formally constructed atomic packet mutation operators, and a proposed Strength Enhanced Deep Q-learning (SE-DQN) to determine effective mutation operators on outbound packets according to the predicted features. A defense scheme based on adaptive decision threshold adjustment is also provided. Experimental evaluation is presented on various NIDS classifiers and cyber attacks. Results show that SE-DQN achieves an evasion rate of at least 64.2% on most classifiers and even more than 90% on certain ones, and it is three times faster than DQN on learning mutation policy. The defense scheme shows an improvement of at least 76.4% on recall measurement. Shuaishuai Tan, Xiaoxiong Zhong, Zhiyi Tian, Qingkuan Dong |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | A Novel Android Malware Detection Method Based on Visible User InterfaceabstractMachine learning has been increasingly adopted to detect Android malwares. Most existing studies depend on features in code space such as information flows and API calls. Malware variants would engage these models in a never-ending war. Inspired by the observation that some variants share similar or even identical user interfaces (UIs), this paper explores employing visible UI screenshot as the indicator to build a novel Android malware detection method. To achieve this vision, we built the first Android Application Screenshot Dataset (AnASD) consisting of more than twenty thousand UI screenshots produced by both benign applications and malwares. A thorough analysis was conducted to characterize the dataset, especially the UI difference between benign applications and malwares. Then a set of state of the art deep learning classifiers on AnASD were trained and evaluated. The results of both sim-ilarity measurement and classification performance proved the feasibility to detect Android malwares based on user interfaces. To facilitate the research community, the dataset is free available at https://doi.org/10.6084/m9.figshare.14445768. Shuaishuai Tan, Zhiyi Tian, Xiaoxiong Zhong, Shui Yu 0001, Weizhe Zhang, Guozhong Dong |
TrustCom | 1 |
| 2021 | EOM-NPOSESs: Emergency Ontology Model Based on Network Public Opinion Spread ElementsabstractThe construction of an emergency ontology model plays an important role in emergency management, which is an important basis for emergency public opinion management and decision-making. Integration of network public opinion spread elements into the emergency ontology model is crucial for realizing knowledge sharing in the field of emergency and public opinion responses. In this study, we crawl a large amount of emergency data from different data sources and construct an emergency dataset. Based on this dataset, we analyze the public opinion elements of emergencies and propose an emergency ontology model based on network public opinion spread elements (EOM-NPOSESs). Thereafter, we consider the coronavirus disease (COVID-19) emergency as an example to construct the EOM-NPOSESs. Finally, we design some strategies to realize rule reasoning and present the COVID-19 emergency application based on the constructed EOM-NPOSESs and the geographic information system platform. The results demonstrate that EOM-NPOSESs can not only describe the semantic relationship between emergencies and emergency elements but also perform semantic logical reasoning on different emergencies. Guozhong Dong, Weizhe Zhang, Haowen Tan, Shuaishuai Tan |
Secur. Commun. Networks | 5 |
| 2020 | Network-based Malware Detection with a Two-tier Architecture for Online Incremental UpdateabstractAs smartphones carry more and more private information, it has become the main target of malware attacks. Threats on mobile devices have become increasingly sophisticated, making it imperative to develop effective tools that are able to detect and counter such threats. Unfortunately, existing malware detection tools based on machine learning techniques struggle to keep up due to the difficulty in performing online incremental update on the detection models. In this paper, a Two-tier Architecture Malware Detection (TAMD) method is proposed, which can learn from the statistical features of network traffic to detect malware. The first layer of TAMD identifies uncertain samples in the training set through a preliminary classification, whereas the second layer builds an improved classifier by filtering out such samples. We enhance TAMD with an incremental leaning based technique (TAMD-IL), which allows to incrementally update the detection models without retraining it from scratch by removing and adding sub-models in TAMD. We experimentally demonstrate that TAMD outperforms the existing methods with up to 98.72% on precision and 96.57% on recall. We also evaluate TAMD-IL on four concept drift datasets and compare it with classical machine learning algorithms, two state-of-the-art malware detection technologies, and three incremental learning technologies. Experimental results show that TAMD-IL is efficient in terms of both update time and memory usage. Anli Yan, Riccardo Spolaor, Shuaishuai Tan, Lizhi Peng, Bo Yang 0001 |
IWQoS | 4 |
| 2016 | A similarity-based indirect trust model with anti-spoofing capabilityabstractAbstract Trust management has become an emerging security paradigm in various areas such as ad hoc networks and cloud computing. One core element of trust management is the indirect trust model that evaluates the trustworthiness of a target based on others' recommendations. The research on indirect trust is still at an early stage, and some problems are not addressed yet. Because of the subjectivity of trust, entities would have different views on a same target. Consequently, after receiving recommendations, the evaluating entity should first measure their credibility. Existing methods often distort recommendations. We propose a more reasonable method based on the similarity between recommenders and evaluating entities. Furthermore, considering the characteristics of one‐hop and multi‐hop recommendations, the similarity calculation methods for them were developed individually. Another problem is the spoofed recommendations aiming at tarnishing someone or harboring conspirators. We design a simple but efficient algorithm to detect and remove them. The proposed methods and algorithms constitute the integrated indirect trust model. This model is not bound to any specific domain, and thus it can be widely applied. Simulation results show that the model is effective in obtaining an objective indirect trust value with the existence of personalized and dishonest recommenders. Copyright © 2017 John Wiley & Sons, Ltd. Shuaishuai Tan, Yanming Liu 0001, Xiaoping Li 0004, Qingkuan Dong |
Secur. Commun. Networks | 1 |
| 2015 | Trust based routing mechanism for securing OSLR-based MANET
Shuaishuai Tan, Qingkuan Dong |
Ad Hoc Networks | 1 |