EDBT 2026 Demo / reviewers in the wild / expert
Hao Li 0027
dblp:17/5705-27
· DBLP profile ↗
9ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0002-9045-561XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Traffic burst relational graph attention network combined position encoding for traffic classification
Xi Xiao 0001, Siji Chen, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan |
Comput. Networks | 7 |
| 2025 | Relational Graph Attention Network Combined with Burst Position Encoding for Traffic ClassificationabstractNetwork traffic classification has become an essential technology for information service providers. While existing methods predominantly focus on packet-level features such as port numbers and payload content, they fundamentally overlook the dynamic interaction patterns revealed by traffic burst sequences and the inherent relational characteristics between consecutive traffic bursts. To overcome the limitation of existing methods, we design a new burst position relational graph attention network (BP-RGAT) for traffic classification. We introduce the Heterogeneous Traffic Burst Graph (HTBG) to obtain more traffic interaction information. We also incorporate Relative Traffic Burst Position Encoding (RBPE) to capture sequence information between bursts. To evaluate the performance of BPRGAT, we conduct experiments with ISCX-VPN and USTC-TFC datasets. The results show that BP-RGAT achieves the highest F1 score compared to existing baseline methods (e.g. NetMamba, ET-BERT, BehavSniffer, TFE-GNN). Siji Chen, Xi Xiao 0001, Guangwu Hu, Le Yu 0002, Qing Li 0006, Hao Li 0027, Qingjun Yuan, Dengpan Ye |
IWQoS | 6 |
| 2025 | DTPN: A Diffusion-based Traffic Purification Network for Tor Website FingerprintingabstractWebsite Fingerprinting attack is a type of method used to classify network traffic generated by users on the Tor (The Onion Router) based on the websites they visit, leading to the leakage of individuals' privacy . For Website Fingerprinting attack, network traffic defense methods involve adding noise to the original network traffic to render the attacker's methods ineffective. Previous attack methods primarily focused on improving classification accuracy by enhancing the attack model, with adversarial training being the most common approach. However, adversarial training requires frequent updates and exhibits poor generalization when dealing with previously unseen network traffic protection methods. In order to address the limitations of adversarial training, a novel method is proposed leveraging a diffusion model for network traffic purification. This paper is the first to use a diffusion model to resist network traffic defense based on adversarial perturbations. The diffusion models are theoretically suited for data purification in the training mode, i.e., removing noises generated by adversarial perturbations from the data. Our method enables existing network traffic classification methods to maintain effective classification of network traffic after protection without requiring retraining, while also achieving good generalization performance with previously unseen network traffic defense methods. The purified network traffic data can effectively improve the robustness of existing website fingerprinting methods. Experiments conducted under various network traffic defense strategies demonstrate that the proposed method increases accuracy by up to 60.8% on DF dataset and 50.3% on CW100 dataset, respectively, compared to adversarial training. Xi Xiao 0001, Guangwu Hu, Zhen Ling 0001, Hao Li 0027, Bin Zhang 0048 |
WSDM | 5 |
| 2025 | Toward Open-World Network Intrusion Detection via Open Recognition and InspectionabstractDeep learning is promising in open-world network intrusion detection, but current deep learning-based methods mainly focus on open recognition with properties that may not always hold and significantly neglect the inspection of unknown samples, increasing open space risks and manual inspection overhead for deployed models. To address these challenges in real-world environments, we propose a novel system, ORI, designed to tackle two critical tasks: 1) open recognition, including classifying known class samples while recognizing unknown ones, and 2) inspection, involving further inspecting samples recognized as unknown. Specifically, we reformulate open recognition as a binary classification task and propose a density-based method to recognize low-density samples as unknown while classifying known class samples with a closed-world classifier, thereby minimizing the risk associated with open spaces. To reduce the inspection overhead of samples recognized as unknown, we treat unknown sample inspection as a constrained clustering task, using a few manually inspected samples as constraints, and then assign labels to the remaining unknown samples via clustering. We evaluate our system against established open recognition and unknown sample inspection baselines through extensive experiments on three public datasets. Additionally, we simulated a security analyst inspecting unknown samples labeled by ORI. The experimental results demonstrate that ORI accurately classifies known class samples, recognizes unknown samples, and effectively labels samples recognized as unknown, enhancing both open recognition and inspection capabilities. Yuhan Chai, Yan Jia 0001, Binxing Fang, Hao Li 0027, Zhaoquan Gu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Understanding the Influence of Extremely High-Degree Nodes on Graph Anomaly Detection
Xi Xiao 0001, Guangwu Hu, Xuhui Jiang, Bin Zhang 0048, Hao Li 0027 |
ICPR (7) | 7 |
| 2024 | LAN: Learning Adaptive Neighbors for Real-Time Insider Threat DetectionabstractEnterprises and organizations are faced with potential threats from insider employees that may lead to serious consequences. Previous studies on insider threat detection (ITD) mainly focus on detecting abnormal users or abnormal time periods (e.g., a week or a day). However, a user may have hundreds of thousands of activities in the log, and even within a day there may exist thousands of activities for a user, requiring a high investigation budget to verify abnormal users or activities given the detection results. On the other hand, existing works are mainly post-hoc methods rather than real-time detection, which can not report insider threats in time before they cause loss. In this paper, we conduct the first study towards real-time ITD at activity level, and present a fine-grained and efficient framework LAN. Specifically, LAN simultaneously learns the temporal dependencies within an activity sequence and the relationships between activities across sequences with graph structure learning. Moreover, to mitigate the data imbalance problem in ITD, we propose a novel hybrid prediction loss, which integrates self-supervision signals from normal activities and supervision signals from abnormal activities into a unified loss for anomaly detection. We evaluate the performance of LAN on two widely used datasets, i.e., CERT r4.2 and CERT r5.2. Extensive and comparative experiments demonstrate the superiority of LAN, outperforming 9 state-of-the-art baselines by at least 8.43% and 6.35% in AUC for real-time ITD on CERT r4.2 and r5.2, respectively. Moreover, LAN can be also applied to post-hoc ITD, surpassing 8 competitive baselines by at least 7.70% and 4.03% in AUC on two datasets. Finally, the ablation study, parameter analysis, and compatibility analysis evaluate the impact of each module and hyper-parameter in LAN. The source code can be obtained fromhttps://github.com/Li1Neo/LAN. Xiangrui Cai, Yang Wang 0128, Sihan Xu, Hao Li 0027, Ying Zhang 0015, Zheli Liu, Xiaojie Yuan |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Fuzz Testing for Rust Library FunctionsabstractRust is an emerging programming language that has gained popularity in many academic and industrial projects due to its memory safety features. However, despite its safety advantages, there are still many serious bugs in existing Rust projects. The lack of suitable fuzz targets has been a major challenge in Rust fuzz testing, as existing fuzzing tools often rely on manual efforts to write test targets, which is time-consuming and cannot be directly applied to library function interfaces. While the previous work has made significant progress in generating fuzz targets for Rust, it still cannot effectively test special functions with generics and polymorphism.To address this issue, this paper proposes an automated approach for generating fuzz targets for Rust library functions, called RVFuzz. RVFuzz addresses the challenges by performing static analysis through variable instantiation, ensuring that special functions in Rust, such as those with generics and polymorphism, are covered in the interface sequence analysis. It then traverses the library function dependency graph to generate a set of reasonable and non-redundant target function sequences for fuzz testing. Any compilation errors encountered during the process are used to refine the sequence generation. RVFuzz successfully generated fuzz targets for 10 popular Rust projects, achieving an impressive interface coverage rate of 92.3%. Yongjian Guo, Xi Xiao 0001, Yuanyi Lin, Hao Li 0027, Xiangbo Wu |
TrustCom | 4 |
| 2023 | A lightweight and high-precision approach for bulky JavaScript engines fuzzingabstractTraditional coverage-based fuzzing gives equal attention to every part of a code. Despite much progress, we observe that existing schemes still not comprehensively use the coverage feedback mechanism when fuzzing bulky JavaScript engines because of severe path collisions. To improve the precision of coverage feedback and target the vulnerable JIT compiler of Javascript engines, we presented our fuzzer, called LF(Light Fuzzer), a lightweight and high-precision fuzzer for bulky JavaScript engines fuzzing. First, LF advocates a technique to confine instrumentation to the JIT-related "critical functions" to mitigate collisions. Additionally, LF utilizes static analysis to establish dominant relationships between critical functions. Lastly, LF incorporates seed scheduling with feedback information of control flow at the function level to dynamically target JIT. These combined strategies make LF a lightweight and high-precision fuzzer for fuzzing bulky JavaScript engines. In our evaluation, LF outperforms the state-of-art coverage-guided JavaScript fuzzer DIE in different coverage types, and LF is also more effective in triggering unique crashes compared to DIE. Lianpei Zhou, Xi Xiao 0001, Guangwu Hu, Hao Li 0027, Xiangbo Wu |
TrustCom | 4 |
| 2020 | An image encryption scheme based on precision limited chaotic system
Hao Li 0027, Zhaoquan Gu |
Multim. Tools Appl. | 1 |