EDBT 2026 Demo / reviewers in the wild / expert
Qiujian Lv
dblp:157/4789
· DBLP profile ↗
28ranked-venue papers
1as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 1 first-author · 9 since 2021Security and privacy · 6 · 6 since 2021Human-computer interaction and ubiquitous computing · 6 · 6 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating the Impact of Malware Evolution on API Sequence-Based Windows Malware DetectorsabstractIn dynamicWindows malware detection, deep learning models are extensively deployed to analyze API sequences. Methods based on API sequences play a crucial role in malware prevention. However, due to the continuous updates of APIs and the changes in API sequence calls leading to the constant evolution of malware variants, the detection capability of API sequence-based malware detection models significantly diminishes over time. We observe that the API sequences of malware samples before and after evolution usually have similar malicious semantics. Specifically, compared to the original samples, evolved malware samples often use the API sequences of the pre-evolution samples to achieve similar malicious behaviors. For instance, they access similar sensitive system resources and extend new malicious functions based on the original functionalities. In this paper, we propose a framework MME(Mitigating the impact of Malware Evolution), a framework that can enhance existing API sequence-based malware detectors and mitigate the adverse effects of malware evolution. To help detection models capture the similar semantics of these post-evolution API sequences, our framework represents API sequences using API knowledge graphs and system resource encodings and applies contrastive learning to enhance the model’s encoder. Results indicate that, compared to regular Text-CNN, our framework can significantly reduce the false positive rate by 13.10% and improve the F1-Score by 8.47% on five years of data, achieving the best experimental results. Additionally, evaluations show that our framework can save on the human costs required for model maintenance. We only need 1% of the budget per month to reduce the false positive rate by 11.16% and improve the F1-Score by 6.44%. Xingyuan Wei, Qiujian Lv, Degang Sun |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | PGAid: An Interpreter for Provenance-Based Intrusion Detection Based on DeepAidabstractThe Provenance Graph has been widely applied in host anomaly detection due to its ability to detect unforeseen threats, reveal correlations between host behaviors, and the superior performance offered by Graph Neural Networks. However, a barrier to the practical adoption of Provenance-based intrusion detection systems is the lack of interpretation. Unfortunately, existing interpretation approaches are proposed for either non-security domains or other kinds of anomaly detections like tabular, homogeneous graph or network intrusion detections, which are not suitable for Provenance-based intrusion detection systems and fail to satisfy special requirements in security domains. In this paper, we propose PGAid, a method aiming to interpret Provenance-based intrusion detection in security domains. Firstly, PGAid addresses the different interaction features between nodes in heterogeneous graphs by layering the provenance graph to be explained according to the types of source and destination nodes, segmenting it into different subgraphs for explanation. Then, we search for reference edge groups within each subgraph, adjusting the priority during the search process. Finally, we verified the effectiveness of our method from fidelity and stability, which respectively surpassed other baselines by 10% and 2-5%. Xingyuan Wei, Rujie Dai, Qiujian Lv |
CSCWD | 4 |
| 2025 | KanIDS: An Intrusion Detection System for All Kernel Interactions Based on Kolmogorov-Arnold NetworkabstractIn recent years, Advanced Persistent Threats have increasingly caused significant harm in cyberspace. Security researchers have been attempting to construct Intrusion Detection Systems based on provenance graphs to effectively detect these complex, persistent, and covert attacks. Most works treat prove-nance graphs as static graphs, ignoring the dynamic changes of APTs and kernel behaviors. Some recent works construct dynamic provenance graphs and achieve effective results in time window detection and attack reconstruction. However, these works either use snapshots to segment the dynamic graphs, resulting in insufficient extraction of temporal information, or use graph auto-encoders to fully extract temporal information but do not fully include all interaction types. These methods all lose the important information, and make the reconstruction and analysis of attacks incomplete. In this paper, we propose KanIDS, a temporal provenance graph-based intrusion detection system that includes all types of interactions. We inherit the basic method of the graph representation and dynamic graph auto-encoder used by Kairos, but we extend the limited types of interactions to all interaction types across datasets to ensure the completeness of anomaly detection and attack reconstruction. Additionally, we replace the decoder from a Multi-Layer Perceptron with a Kolmogorov-Arnold Network to address the issues of weak learning capabilities for sequential data and low parameter utilization efficiency. Experimental results show that our approach shows better graph learning abilities in the training phase. Moreover, the accuracy of KanIDS in time window detection with all interaction types exceeds the baseline by 1 %-3% and F-l score by 10%-30%. Baorui Zheng, Xiu Ma, Qiujian Lv, Yan Wang 0081 |
CSCWD | 4 |
| 2025 | NAHID: Node-Level Host Intrusion Detection Based on Provenance GraphabstractAttacks, including program exploits, malware implantation, and targeted intrusions such as advanced persistent threats (APTs), are increasingly used by modern adversaries. Recently, provenance-based host intrusion detection systems (HIDSs) have gained significant attention due to their superior performance in detecting complex attacks at the system level. Despite their potential, many existing approaches either do not fully utilize the rich information available in raw data or overlook the evolving topological structure of system behavior over time. Furthermore, some approaches lack fine granularity required for intrusion detection. These deficiencies may result in high false positives or false negatives. To address these limitations, we designed an anomaly-based node-level host intrusion detection system, NAHID, which does not require prior knowledge of attack patterns. It begins by extracting important entities (e.g., processes, files) and their interactions (e.g., read and write operations) from raw host data to construct a provenance graph. To effectively model the dynamic behavior of nodes over time, NAHID leverages temporal graph neural networks for graph representation learning, capturing both complex interaction patterns and temporal behavior evolution. The detection task is then formulated as a node-level multi-class classification problem. To address the inherent class imbalance present in host provenance data, we incorporate a class-weighted loss function that enhances the model’s ability to recognize minority-class anomalies. We evaluated our model on three public datasets and demonstrated that it outperforms our baseline host intrusion detection system. In addition, we also evaluated our model’s runtime and conducted ablation experiments. Xingyuan Wei, Qiujian Lv |
SMC | 3 |
| 2024 | Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceabstractProvenance graphs are structured audit logs that describe the history of a system’s execution. Recent studies have explored a variety of techniques to analyze provenance graphs for automated host intrusion detection, focusing particularly on advanced persistent threats. Sifting through their design documents, we identify four common dimensions that drive the development of provenance-based intrusion detection systems (PIDSes): scope (can PIDSes detect modern attacks that infiltrate across application boundaries?), attack agnosticity (can PIDSes detect novel attacks without a priori knowledge of attack characteristics?), timeliness (can PIDSes efficiently monitor host systems as they run?), and attack reconstruction (can PIDSes distill attack activity from large provenance graphs so that sysadmins can easily understand and quickly respond to system intrusion?). We present Kairos, the first PIDS that simultaneously satisfies the desiderata in all four dimensions, whereas existing approaches sacrifice at least one and struggle to achieve comparable detection performance.Kairos leverages a novel graph neural network based encoder-decoder architecture that learns the temporal evolution of a provenance graph’s structural changes to quantify the degree of anomalousness for each system event. Then, based on this fine-grained information, Kairos reconstructs attack footprints, generating compact summary graphs that accurately describe malicious activity over a stream of system audit logs. Using state-of-the-art benchmark datasets, we demonstrate that Kairos outperforms previous approaches. Qiujian Lv, Jinyuan Liang, Yan Wang 0081, Degang Sun, Thomas Pasquier, Xueyuan Han |
SP | 2 |
| 2024 | BehaMiner: System Behavior Mining for Audit Log Based on Graph Learning
Xiu Ma, Xiaoze Liu, Qi Zhang 0001, Qiujian Lv |
WASA (1) | 6 |
| 2023 | GHunter: A Fast Subgraph Matching Method for Threat HuntingabstractThreat hunting is the process of proactively searching for known attack behavior in an organization’s information system. A popular approach to threat hunting uses cyber threat intelligence (CTI) to identify advanced persistent threats (APTs) that are hidden in kernel-level audit logs (e.g., whole-system data provenance). However, existing threat hunting mechanisms can-not produce timely results due to the enormous size of provenance data. As a result, threat hunting cannot help sysadmins to quickly recognize an ongoing APT campaign and immediately block any subsequent attack activity. In this paper, we propose GHunter, a system that performs approximate subgraph matching using graph neural networks (GNNs) to quickly and accurately hunt APTs. GHunter first converts known APT scenarios and provenance logs into graph data. Then, GHunter uses GNNs to embed APT scenario graphs and provenance graphs to discover any subgraph relationships. If an APT scenario graph is a subgraph of a provenance graph, GHunter alerts to sysadmins the presence of the corresponding APT scenario in the system. We use DARPA’s Transparent Computing (TC) datasets to evaluate GHunter’s performance. The results show that GHunter achieves 97% accuracy when hunting APTs from millions of provenance log entries and spends 195x less execution time than prior work. Rujie Dai, Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
CSCWD | 5 |
| 2023 | ACG: Attack Classification on Encrypted Network Traffic using Graph Convolution Attention NetworksabstractAttack classification of network traffic is valuable for many security solutions as it points out a clear direction for attack responses. Nowadays, most network traffic is encrypted, which protects user privacy but hides attack traces, further hindering identifying attacks to inspect traffic packages. Machine Learning(ML) methods are widely applied to attack classification on encrypted traffic owing to no need for manual analysis. However, existing studies only concentrate on basic statistical features, which are easily modified, and cannot obtain the crucial attack behaviors hiding in the encrypted traffic. In this paper, we propose an attack classification method, ACG. We create attack graphs to depict interaction behaviors of attack-victim hosts from network traffic containing crucial attack behaviors. Besides, we divide a specific duration for each attack to precisely elaborate attack graphs, where temporal, statistical, and aggregate features are extracted to portray attack behaviors. Finally, we utilize Graph Neural Networks (GNNs) to mine and grasp the crucial behavior patterns from attack graphs to generate fingerprints and classify attacks. Extensive experiments are conducted on three datasets to verify our method. It achieves a precision of 99% in attack classification on encrypted traffic, an average higher than other ML methods of 50%. Leiqi Wang, Qiujian Lv, Yan Wang 0081, Shixiang Zhang, Weiqing Huang |
CSCWD | 3 |
| 2023 | UAG: User Action Graph Based on System Logs for Insider Threat DetectionabstractInsider threats pose significant risks to the network systems of organizations. Users have diverse behavioral habits within an organization, leading to variations in their activity patterns. Hence, data analysis and mining techniques are essential for modeling user behavior. Current methods analyze system logs and extract user action sequence features; however, they overlook the relationships between different actions, reducing detection accuracy. To address this issue, we propose a novel method called UAG (User Action Graph). UAG transforms user actions into a graph representing their chronological order and interrelationships, facilitating a more accurate and comprehensive understanding of user behavior. By extracting global and local features from the user action graph, UAG offers an extensive and detailed perspective of user behaviors. Ultimately, we develop a lightweight ensemble autoencoder model to detect insider threats. Comprehensive experiments demonstrate that UAG delivers outstanding performance and surpasses existing methods. Yan Wang 0081, Qiujian Lv, Leiqi Wang |
ISCC | 4 |
| 2023 | LWVN: A Lightweight Virtual Network View Method to Defend Lateral MovementabstractDue to traditional network topologies’ static and homomorphic characteristics, attackers can rapidly expand their attack results through lateral movement (LM) attacks. Virtual Network View technology has emerged as an effective approach to disrupt attackers’ ability to detect and exploit network topologies during LM and can increase the difficulty of malicious activities. However, existing Virtual Network View deployS virtual views for each core asset, resulting in wasting of resource. To alleviate this problem, we propose a lightweight Virtual Network View deployment method called LWVN. First, the Location Centrality (LC) of the network nodes in the attack path is measured, the larger the LC is, the network node is more important and the more virtual network view costs we can invest. To further quantify the comprehensive impact of network nodes’ location centrality on high-value assets, we quantify the Assets’ Value(AV). Then, we model internal network risk and operational costs as constraints and find the optimal strategies for deploying a virtual network view. We define metrics for hidden capacity, detect capacity, and deployment cost to measure the effectiveness of deployment virtual network views. We conduct simulations to verify the effectiveness and feasibility of LWVN. Degang Sun, Guokun Xu, Weijie Wang 0005, Yan Wang 0081, Qiujian Lv |
TrustCom | 5 |
| 2023 | VN-SMT: An SMT-based Construction Method on Virtual Network to Defend Insider ReconnaissanceabstractDue to networks’ static and homomorphic nature, experienced attackers can quickly get the target network’s topology and internal host information by scanning. The virtual network view prevents network reconnaissance by simulating a virtual network topology for the network hosts, to consume the attacker’s attack resources and time. However, deploying a virtual network view will reduce network throughput and increase network latency, and an unreasonable virtual network view configuration will waste resources and reduce Quality of Services(QoS). We, therefore, propose a method VN-SMT that can rationally configure virtual network view. This method generates an optimal virtual network view base on existing host configuration, risk constraints, and budget constraints. We define metrics for deception, concealment, and resource consumption to measure the effectiveness of virtual network views. We conduct simulations to verify the effectiveness and feasibility of VN-SMT. Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Qiujian Lv, Zuxin Chen, Siyuan Li 0014 |
WCNC | 4 |
| 2023 | TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks
Leiqi Wang, Xiu Ma, Qiujian Lv, Yan Wang 0081, Weiqing Huang |
Comput. Secur. | 4 |
| 2022 | CyEvent2vec: Attributed Heterogeneous Information Network based Event Embedding Framework for Cyber Security Events AnalysisabstractRecently, cyber security events have been gathered as a kind of Cyber Threat Intelligence(CTI) to fight against cyber attacks. Developing a cyber events analysis model to predict the possible threats can assist organizations in providing guidance for decision making. A cyber security event is a complete semantic unit containing all the participating objects (such as attacks assets and organizations) with rich attributes (such as the results and variety of the attack). However, existing cyber security events modeling works ignore the attributes of the objects and analyze the objects' relationships independently. To predict the possible threats for the organizations, we propose a cyber events embedding framework CyEvent2vec to model cyber security events with attributes. First, to effectively depict the cyber security events with attributes that happened in organizations, cyber security events are reconstructed by the organization and processed into the events matrices. Second, to explore the intricate relationships between heterogeneous objects in events, the events matrices are fed into the autoencoder model to get the low-dimensional embeddings. Third, to predict the possible threats for the victim organization, we apply the embeddings to two applications to measure the relevance between the objects: organization threats prediction and threat objects classification. Experiments show CyEvent2vec outperforms the other six representation learning methods on three real-world datasets. Xiu Ma, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
IJCNN | 3 |
| 2022 | MMSP: A LSTM Based Framework for Multi-Step Attack Prediction in Mixed ScenariosabstractA multi-step attack scenario consisting of more than one attack step is difficult to predict because of various attack steps and complex combinations. The multi-step attack scenarios occurring simultaneously construct a mixed attack scenario, which is more common than a single attack scenario in practical systems. However, most of the existing multi-step attack prediction approaches only focus on a single attack scenario. In this paper, a framework MMSP is proposed for multi-step attack prediction in mixed scenarios. MMSP fractionates alerts by separating them into different scenarios and removing redundant samples. The attack scenarios fingerprint database of MMSP is built by modeling the attack steps regarding different scenarios based on the long short-term memory (LSTM) model. Each scenario corresponds to an LSTM model. A scenario matching method is also proposed to find potential attack scenarios hiding in the real-time alerts from the database. Finally, MMSP feeds fractionated alerts into the matched scenarios' LSTM models to predict attack steps. Extensive evaluations based on real-world datasets show that MMSP outperforms the state-of-the-art attack step prediction model in both single and mixed scenarios. MMSP achieves a 14.3 % -38.1 % improvement in accuracy for attack step prediction in the single scenario. In particular, MMSP can maintain a high level accuracy in mixed attack scenarios. Degang Sun, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
ISCC | 4 |
| 2022 | A Software Security Entity Relationships Prediction Framework Based on Knowledge Graph Embedding Using Sentence-Bert
Yan Wang 0081, Xiaowei Hou, Xiu Ma, Qiujian Lv |
WASA (2) | 4 |
| 2022 | DMalNet: Dynamic malware analysis based on API feature engineering and graph learning
Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 5 |
| 2022 | A novel deep framework for dynamic malware detection based on API sequence intrinsic features
Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 2 |
| 2021 | Density Weighted Diversity Based Query Strategy for Active LearningabstractDeep learning has made remarkable achievements in various domains. Active learning, which aims to reduce the budget for training a machine-learning model, is especially useful for the Deep learning tasks with the demand of a large number of labeled samples. Unfortunately, our empirical study finds that many of the active learning heuristics are not effective when applied to Deep learning models in batch settings. To tackle these limitations, we propose a density weighted diversity based query strategy (DWDS), which makes use of the geometry of the samples. Within a limited labeling budget, DWDS enhances model performance by querying labels for the new training samples with the maximum informativeness and representativeness. Furthermore, we propose a beam-search based method to obtain a good approximation to the optimum of such samples. Our experiments show that DWDS outperforms existing algorithms in Deep learning tasks. Tingting Wang 0010, Xufeng Zhao 0002, Qiujian Lv, Degang Sun |
CSCWD | 3 |
| 2021 | A Few-Shot Class-Incremental Learning Approach for Intrusion DetectionabstractClassic network intrusion detection methods usually are supervised machine learning models, which are obtained by offline training and can achieve good performance in the initial stage of system construction. However, with the rapid and diverse evolution of intrusion methods, the learned knowledge is no longer suitable for new types of attacks. In addition, existing incremental learning approaches lack rapid learning capabilities and are hard to avoid potential risks and reduce property losses when there are few new samples. This can be attributed to the few-shot class-incremental intrusion detection issue. To address this issue, we propose a learning strategy, named ID-FSCIL, which could respond to the increase in attack categories by extending the origin detection system. It fully mines new intrusion patterns from few samples with meta-learning and maximizes the model’s generalization ability to deal with emerging attacks. Our evaluations show that ID-FSCIL significantly outperforms the state-of-the-art baselines on the NSL-KDD dataset under incremental learning settings. Tingting Wang 0010, Qiujian Lv, Degang Sun |
ICCCN | 2 |
| 2021 | ITDBERT: Temporal-semantic Representation for Insider Threat DetectionabstractThe objective and universal nature of user behavior data make it the primary data for insider threat detection. Existing solutions treat user behavior as atomic symbols and do not consider behavior semantic information. Meanwhile, fine-grained temporal information is ignored despite its relevance to describe user behavior. Such approaches inevitably lead to unsatisfactory performance and generalization. In this paper, we propose ITDBERT which embeds temporal information into behavior and catches the fused semantic representation via pre-trained language models. ITDBERT also leverages attention-based Bi-LSTM to provide behavior-level detection results. To verify the effectiveness of our proposed method, we conduct comparison experiments on Cert datasets. Our proposed model achieves an F1-score of 0.9243 in day-level insider threat detection, which outperforms baselines. Weiqing Huang, Qiujian Lv, Yan Wang 0081, Haitian Yang |
ISCC | 4 |
| 2021 | GSketch: A Comprehensive Graph Analytic Approach for Masquerader Detection Based on File Access GraphabstractMasqueraders are a severe insider threat and have become a conventional security issue for most organizations. The majority of existing techniques for detecting masqueraders extract statistical features from file access logs. However, the graph's features from these logs have not been fully explored. In this work, we introduce GSketch. First, it divides each user's file access logs into equal length, non-overlapping time windows. Then file access logs on each time window are transformed into a graph according to chronological order. GSketch extracts global features and local features from the graph. Global features provide a panoramic view of the graph, and local features mine small, induced sub-graphs. Finally, GSketch applies an abnormal detection algorithm to find anomalous points in the feature space and marks these points as masquerader's activities. The effectiveness of GSketch is demonstrated by its excellent performances on two public datasets - WUIL and TWOS. Yan Wang 0081, Qiujian Lv, Meichen Liu, Tingting Wang 0010, Leiqi Wang |
ISCC | 4 |
| 2021 | AOPL: Attention Enhanced Oversampling and Parallel Deep Learning Model for Attack Detection in Imbalanced Network Traffic
Leiqi Wang, Weiqing Huang, Qiujian Lv, Yan Wang 0081 |
WASA (2) | 3 |
| 2019 | Risk Prediction for Imbalanced Data in Cyber Security : A Siamese Network-based Deep Learning Classification FrameworkabstractRisk prediction plays an important role in network security which can be used to predict riskiest parts and then proactive measures can be adopted to avoid potential damage. Most existing literature model risk prediction problems as binary classification problems by using machine learning methods. However, these traditional machine learning models have poor performance - tending to misclassify the risky ones into the category of risk-free - on risk prediction task when the datasets are imbalanced or small in size. In this paper, we propose a Siamese Network Classification Framework (SNCF) that can map the Siamese network to a classification based on the similarity to alleviate imbalance for risk prediction. Experimental results on imbalanced data in risk prediction verify that the deep learning-based classification architecture SNCF has better efficiency when compared with other algorithms. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
IJCNN | 4 |
| 2019 | Cyber Profiles Based Risk Prediction of Application Systems for Effective Access ControlabstractApplication systems maintain critical sensitive information of an enterprise and especially huge number of data with specific ownership. Unauthorized modification or deletion of data caused by cyber attacks may bring tremendous loses for enterprises. To reduce the damage of cyber attacks, existing techniques have been proposed to predict the potential risk of external attacks at the level of an enterprise, a user, or a machine. However, risk prediction has not been conducted at the level of application systems, which may suffer from external attacks or insider threats. This paper proposes a model based on machine learning to predict whether the application systems of an enterprise have the risk of unauthorized access by using a cyber profile. In particular, the cyber profile is composed of features extracted from the information of the three domains in cyberspace: Information Infrastructure domain, Data domain, and Application domain. The core idea of the model selects the most significant features that have a large impact on the occurrence of unauthorized access to application systems. At last, by using a limited number of selected features, high forecast accuracy is achieved. These results verify the effectiveness of the prediction model, which can potentially be exploited to guide the adjustment of access control policies for effective access control. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
ISCC | 4 |
| 2018 | A Hybrid Model Based on Multi-dimensional Features for Insider Threat Detection
Yan Wang 0081, Qiujian Lv |
WASA | 4 |
| 2017 | Linking Virtual Identities across Service Domains: An Online Behavior Modeling ApproachabstractIn the era of the Internet, people are active in multiple online services, and they usually have accounts on more than one online service. Each account is a virtual identity of the user. In order to trace individual's online behavior at any time and any places, linking virtual identities belonging to the same natural person across different online service domains is very important. Existing methods usually tackle this problem by estimating the profile content similarity between identities under two different online services. However, the profile contents in various online services are unreliable or misaligned, and the proposed methods are always limited to services in a specific domain. In this paper, we propose VISD (Virtual Identity linkage cross Service Domain), a novel probability-based model, to link virtual identities across online services in various service domains. It derives several significant attributes from users' online behaviors, such as IP address usage, various fingerprints of terminals, and leverages a supervised classification method to discover the relationship between two identities. By using real-world network traffic collected from a large province of southern China, we evaluate the VISD model and the linkage precision achieves 88.31%. The result demonstrates the effectiveness of our proposed model, which is helpful for social recommendations, information security and privacy protection. Qiujian Lv, Yuanyuan Qiao 0002, Jie Yang 0023 |
Intelligent Environments | 2 |
| 2017 | A Comprehensive Analysis of Video Service Quality on IQIYI from Large-Scale Data Sets
Yao Guo 0004, Qiujian Lv, Fang Liu 0026, Jie Yang 0023 |
QSHINE | 2 |
| 2015 | Spatial and temporal mobility analysis in LTE mobile networkabstractAs smartphones and location-based services gain mainstream popularity, human location histories analysis and user's future location prediction attract increased interest. Predicting the human mobility mainly on users' spatial movement has been conducted in extensive studies. In this paper, we focus on the user mobility prediction from spatial-temporal perspective, and implement several slot-based continuous next-place prediction models considering various contexts. The entropy is also measured to explore the influence of the intrinsic of user's trace on prediction performance. We experiment with real-world data derived from the factual LTE mobile network, and evaluate the performance of proposed predictors with several metrics. By thoroughly experimental analysis, our finding shows that user mobility is highly dependent on both temporal and spatial behavior. Models considering the spatial context of current and previous locations can achieve high accuracy and robustness in both spatial and temporal prediction. Also, the spatial movement independent temporal predictors gain an edge for users whose mobility is in a regular pattern. Qiujian Lv, Yufei Di, Zhenming Lei |
WCNC | 1 |