Wenrui Ma

dblp:159/1204 · DBLP profile ↗
← Back
18ranked-venue papers
6as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 4 first-author · 4 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ENDeliver: An Energy-Aware Framework of Large Spatio-Temporal Model for E-Bike Delivery Route Planning
Yuduo Shi, Zhao Li 0007, Wenrui Ma, Haitao Xu 0002
DASFAA (6)3
2026 SOFA: Service-Oriented Fine-Grained Attack Traffic Detection With Meta Learning
abstract
Enterprise networks face an ever-growing threat from various unknown cyberattacks originating from the Internet. Anomaly-based Network Intrusion Detection Systems (NIDS) have become essential for safeguarding corporate networks, but existing technologies have some limitations in practice. (i) The interweaving of traffic from different service types increases the difficulty of identification. (ii) The scarcity of labeled malicious samples hinders the detection of both known and emerging threats. To tackle these issues, we propose a service-oriented approach to model benign traffic and leverage meta-learning to construct a robust metric space for precise sample comparison. Based on this, we develop SOFA, a two-stage traffic detection framework. In the first stage, SOFA identifies distinct service types within the network and trains independent one-class models for each, ensuring service-specific attack traffic is detected with high precision. The second stage employs a ResNet-based Siamese network to overcome the limitations posed by scarce malicious samples, enhancing detection of both known and emerging attacks. We evaluate SOFA on four widely used network tracing datasets, demonstrating that it achieves state-of-the-art performance and significantly outperforms a diverse set of existing methods in fine-grained attack detection. These results highlight the potential of SOFA for improving network security in a highly dynamic and unbalanced threat environment.
Feiyang Huang, Ziming Zhao 0008, Fan Zhang 0010, Wenrui Ma
IEEE Trans. Netw.5
2025 Pharmaformer: A Transformer-Based Pharmacokinetic Prediction System
Linjie Shen, Zhao Li 0007, Kuifen Ma, Saiping Jiang, Wenrui Ma
DASFAA (6)5
2025 Understanding the Business of Online Affiliate Marketing: An Empirical Study
abstract
Affiliate marketing is a revenue-sharing marketing scheme by which an affiliate, such as a blogger or YouTuber, garners commissions for promoting a merchant's goods or services, thereby aiming to foster a mutually beneficial relationship between affiliates and merchants. Despite being a multi-billion-dollar global industry, affiliate marketing remains inadequately explored, and the research community lacks a comprehensive understanding of its intricate ecosystem. In this paper, we present the first comprehensive empirical study of the affiliate marketing ecosystem. We conduct thorough measurements to assess the prevalence of affiliate marketing, estimate the market size, and elucidate the characteristics of affiliates, merchants, and intermediary affiliate networks. Over a continuous span of 13 months, we monitored four of the most prominent affiliate aggregation platforms, yielding a substantial dataset. We observed 467,219 unique offers - tasks to be undertaken by affiliates - involving 37,109 merchants and 556 affiliate networks across the four platforms. Notably, these offers would cost the merchants more than 19 million USD for the completion of all the actions pre-defined in these offers, such as signing up or making a transaction. Additionally, we compiled a large-scale dataset comprising 124,462 affiliate links, enabling us to conduct a comprehensive investigation. Finally, we propose machine learning models incorporating the characteristics of affiliate links to detect real-world affiliate marketing campaigns.
Haitao Xu 0002, Kaleem Ullah Qasim, Shuai Hao 0001, Wenrui Ma, Zhenyuan Li, Fan Zhang 0010, Zhao Li 0007
INFOCOM5
2025 Spatiotemporal Cross-Domain Integrated Insights: Mitigating Fraudulent Activities on Ethereum
Yuduo Shi, Zhao Li 0007, Haitao Xu 0002, Wenrui Ma, Ji Zhang 0001
SecureComm (5)5
2025 Effective PII Extraction from LLMs through Augmented Few-Shot Learning
Shu Meng, Haitao Xu 0002, Shuai Hao 0001, Chuan Yue, Wenrui Ma, Fan Zhang 0010, Zhao Li 0007
USENIX Security Symposium7
2024 Balanced Data, Imbalanced Spectra: Unveiling Class Disparities with Spectral Imbalance
abstract
Classification models are expected to perform equally well for different classes, yet in practice, there are often large gaps in their performance. This issue of class bias is widely studied in cases of datasets with sample imbalance, but is relatively overlooked in balanced datasets. In this work, we introduce the concept of spectral imbalance in features as a potential source for class disparities and study the connections between spectral imbalance and class bias in both theory and practice. To build the connection between spectral imbalance and class gap, we develop a theoretical framework for studying class disparities and derive exact expressions for the per-class error in a high-dimensional mixture model setting. We then study this phenomenon in 11 different state-of-the-art pre-trained encoders, and show how our proposed framework can be used to compare the quality of encoders, as well as evaluate and combine data augmentation strategies to mitigate the issue. Our work sheds light on the class-dependent effects of learning, and provides new insights into how state-of-the-art pre-trained features may have unknown biases that can be diagnosed through their spectra.
Chiraag Kaushik, Chi-Heng Lin, Amrit Khera, Matthew Jin, Wenrui Ma, Vidya Muthukumar, Eva L. Dyer
ICML6
2024 TransURL: Improving malicious URL detection with multi-layer Transformer encoding and multi-scale pyramid features
Zhenhao Guo, Haitao Xu 0002, Zhan Qin, Wenrui Ma, Fan Zhang 0010
Comput. Networks6
2024 Time Is Not Enough: Timing Leakage Analysis on Cryptographic Chips via Plaintext-Ciphertext Correlation in Non-Timing Channel
abstract
In side-channel testing, the standard timing analysis works when the vendor can provide a measurement to indicate the execution time of cryptographic algorithms. In this paper, we find that there exists timing leakage in power/electromagnetic channels, which is often ignored in traditional timing analysis. Hence a new method of timing analysis is proposed to deal with the case where execution time is not available. Different execution time leads to different execution intervals, affecting the locations of plaintext and ciphertext transmission. Our method detects timing leakage by studying changes in plaintext-ciphertext correlation when traces are aligned forward and backward. Experiments are then carried out on different cryptographic devices. Furthermore, we propose an improved timing analysis framework which gives appropriate methods for different scenarios.
Congming Wei, Guangze Hong, An Wang 0001, Jing Wang 0150, Shaofei Sun, Yaoling Ding, Liehuang Zhu, Wenrui Ma
IEEE Trans. Inf. Forensics Secur.8
2024 FOSS: Towards Fine-Grained Unknown Class Detection Against the Open-Set Attack Spectrum With Variable Legitimate Traffic
abstract
Anomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. By analyzing the popular dataset of network intrusion traces, we show that FOSS significantly outperforms the state-of-the-art methods. Further, we perform an initial deployment of FOSS by working with the Internet Service Provider (ISP) to detect distributed denial of service (DDoS) attacks. With real-world tests and manual analysis, we demonstrate the effectiveness of FOSS to identify previously-unseen attacks in a fine-grained manner.
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang 0010, Rui Zhang 0016, Binbin Chen 0001, Xiangyang Luo 0001, Ming Hu 0003, Wenrui Ma
IEEE/ACM Trans. Netw.10
2023 A Large-Scale Pretrained Deep Model for Phishing URL Detection
abstract
Phishing attacks have always been a security issue that has attracted great attention in the cyber security community. Recently, the famous pre-trained models is being used as an anti-phishing solution. However, existing studies either simply transfer models pre-trained on text to phishing detection task, or pre-train models using only extremely small phishing samples. In this paper, we propose PhishBERT, a veritable pretrained deep transformer network model for phishing URL detection. Using a tailor pre-training objective, PhishBERT obtained a general understanding of various URLs by being pretrained on a corpus of more than 3 billion unlabeled URL data. It is then transferred to the detection task of benign and malicious URL data, with supervised fine-tuning using adversarial methods. Extensive and rigorous benchmark studies verify that PhishBERT is significantly superior to the current state-of-the-art methods in terms of efficiency, robustness and accuracy on the task of phishing website detection.
Weifan Zhu, Haitao Xu 0002, Zhan Qin, Kui Ren 0001, Wenrui Ma
ICASSP6
2023 Investigating Fraud and Misconduct in Legitimate Internet Economy based on Customer Complaints
abstract
Different forms of cybercrimes, ranging from email spam and click fraud to the most sophisticated underground economy, have been studied extensively. Fraud and misconduct in legitimate Internet economy, however, have not received sufficient attention, even though potential damages may not be as severe as regular cybercrimes. In this paper, we have performed the first in-depth empirical investigation of fraud and misconduct in legitimate Internet businesses by collecting 6.6 million customer complaints, which were filed over 45 months by 2.7 million customers against 117 thousand merchants on one of the largest customer complaint platforms in the world, along with more than 13 million customer-uploaded images as photographic evidence. We characterized the complaints in terms of merchants, main issues, desired remedy, amount of money involved, customer ratings, and etc. Most importantly, we were able to uncover various fraud and misconduct in different Internet businesses, some of which should have caught law enforcement's attention. The sum of the amount of money involved in these complaints is 5.4 billion US dollars. We also investigated the privacy inference of the images, and found that the image content could disclose an unexpected amount of customers' personal information.
Wenrui Ma, Ying Cong, Haitao Xu 0002, Fan Zhang 0010, Zhao Li 0007, Siqi Ren
TrustCom1
2021 A Study of the Partnership Between Advertisers and Publishers
Wenrui Ma, Haitao Xu 0002
PAM1
2019 Placing Traffic-Changing and Partially-Ordered NFV Middleboxes via SDN
abstract
Network Function Virtualization (NFV) enables flexible implementation of network functions, also called middleboxes, as virtual machines running on standard servers. However, the flexibility also makes it a challenge to optimally place middleboxes, because a middlebox may be hosted by different servers at different locations. The middlebox placement challenge is further complicated by additional constraints, including the capability of middleboxes to change traffic volumes and dependency between them. In this paper, we address the optimal placement challenge of NFV middleboxes for the data plane using a software-defined networking (SDN) approach. First, we formulate the optimization problem to place traffic-changing and interdependent middleboxes. When the flow path is predetermined, we design optimal algorithms to place a non-ordered or totally-ordered middlebox set, and propose a low-complexity solution for the general scenario of a partially-ordered middlebox set after proving its NP-hardness. When the flow path is not predetermined, we show that the problem is NP-hard even for a non-ordered or totally-ordered middlebox set, and propose an efficient traffic and space aware routing algorithm. We have evaluated the proposed algorithms using large scale simulations and a real application based SDN prototype, and present extensive evaluation results to demonstrate the superiority of our design over benchmark solutions.
Wenrui Ma, Jonathan Beltran, Deng Pan 0002, Niki Pissinou
IEEE Trans. Netw. Serv. Manag.1
2017 Traffic aware placement of interdependent NFV middleboxes
abstract
Network function virtualization enables flexible implementation of network functions, or middleboxes, as virtual machines running on standard servers. However, the flexibility also creates a challenge for efficiently placing such middleboxes, due to the availability of multiple hosting servers, capability of middleboxes to change traffic volumes, and dependency between middleboxes. In this paper, we address the optimal placement challenge of NFV middleboxes, and propose solutions for middleboxes of different traffic changing effects and with different dependency relations. First, we formulate the Traffic Aware Placement of Interdependent Middleboxes problem as a graph optimization problem. When the flow path is predetermined, we design optimal algorithms to place a non-ordered or totally-ordered middlebox set, and propose an efficient heuristic for the general scenario of a partially-ordered middlebox set after proving its NP-hardness. When the flow path is not predetermined, we show that the problem is NP-hard even for a non-ordered middlebox set, and propose a traffic and space aware routing heuristic. We have evaluated the proposed algorithms using large scale simulations and prototype experiments, and present extensive evaluation results to demonstrate the effectiveness of our design.
Wenrui Ma, Oscar Sandoval, Jonathan Beltran, Deng Pan 0002, Niki Pissinou
INFOCOM1
2017 SDN-Based Traffic Aware Placement of NFV Middleboxes
abstract
Network function virtualization (NFV) enables flexible deployment of middleboxes as virtual machines running on general hardware. Since different middleboxes may change the volume of processed traffic in different ways, improper deployment of NFV middleboxes will result in hot spots and congestion. In this paper, we study the traffic changing effects of middleboxes, and propose software-defined networking based middlebox placement solutions to achieve optimal load balancing. We formulate the traffic aware middlebox placement (TAMP) problem as a graph optimization problem with the objective to minimize the maximum link load ratio. First, we solve the TAMP problem when the flow paths are predetermined, such as the case in a tree. For a single flow, we propose the least-first-greatest-last (LFGL) rule and prove its optimality; for multiple flows, we first show the NP-hardness of the problem, and then propose an efficient heuristic. Next, for the general TAMP problem without predetermined flow paths, we prove that it is NP-hard even for a single flow, and propose the LFGL based MinMax routing algorithm by integrating LFGL with MinMax routing. We use a joint emulation and simulation approach to evaluate the proposed solutions, and present extensive experimental and simulation results to demonstrate the effectiveness of our design.
Wenrui Ma, Jonathan Beltran, Zhenglin Pan, Deng Pan 0002, Niki Pissinou
IEEE Trans. Netw. Serv. Manag.1
2015 Traffic-Aware Placement of NFV Middleboxes
abstract
Network Function Virtualization (NFV) enables flexible deployment of middleboxes as Virtual Machines (VMs) running on general hardware. Different types of middleboxes have the potential to either increase or decrease the volume of processed traffic. In this paper, we investigate the traffic changing effects of middleboxes, and study efficient deployment of NFV middleboxes in Software-Defined Networks (SDNs). To begin with, we formulate the Traffic-Aware Middlebox Placement (TAMP) problem as a graph optimization problem, and show that it is NP-hard when there are multiple flows to consider. Next, by observing that in reality flows arrive one at a time, we leverage the SDN central control mechanism, and propose an optimal solution for the TAMP problem with a single flow. We develop the solution in two steps. First, when the flow path has been determined, we present the Least-First-Greatest- Last (LFGL) rule to place middleboxes. Second, we integrate the LFGL rule with widest-path routing to propose the LFGL based MinMax routing algorithm. Further, we have implemented the proposed algorithm as a module running on top of the Floodlight SDN controller, and conducted experiments in the Mininet emulation system. The experiment results fully demonstrate the superiority of our algorithm over other benchmark solutions.
Wenrui Ma, Carlos Medina
GLOBECOM1
2014 Emulation Performance Study of Traffic-Aware Policy Enforcement in Software Defined Networks
abstract
Modern networks require robust traffic handling policies in order to minimize unwanted traffic and maximize performance. These policies are enforced by the placement of rules on network devices such as routers and switches. For high-speed processing, the rules are stored in Ternary Content Addressable Memory (TCAM) [3]. Because it is expensive, there is only a limited amount of TCAM on each network device. Software Defined Networking (SDN) [2] and the OpenFlow [1] protocol provide the capability to control the way rules are generated and placed within a network. This allows researchers to design algorithms that control TCAM usage while optimizing performance. The goal of this project is to develop a test bed for researchers to easily implement and evaluate their performance-optimizing algorithms. In this paper, we describe a test bed that emulates SDN activity and captures network performance data for rule placement algorithm evaluation.
Isaac Vawter, Wenrui Ma
MASS3