EDBT 2026 Demo / reviewers in the wild / expert
Guozheng Yang
dblp:180/2871
· DBLP profile ↗
24ranked-venue papers
2as first author
19since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 8 · 1 first-author · 3 since 2021Computer networks · 5 · 5 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CT-Sketch: Persistent Item Lookup Based on Collision Statistics and Thresholds
Lailong Luo, Yuliang Lu, Qianzhen Zhang, Guozheng Yang |
IWQoS | 5 |
| 2026 | PaT: An enhanced pretrained framework via Mamba-2 for network traffic analysisabstractEfficient encrypted traffic identification plays an indispensable role in the cybersecurity ecosystem. With the rapid advancement of AI technologies, a growing number of machine learning-based and deep learning-based approaches have emerged. Among them, the pretraining-finetuning paradigm has become increasingly popular, as labeling traffic data is costly while large-scale unlabeled traffic data are easily accessible. However, existing pretraining frameworks largely rely on reconstruction tasks, which limit the model’s ability to focus on critical information within traffic data, thereby hindering recognition performance. To address this issue, we propose PaT, an enhanced pretraining framework for encrypted traffic analysis. Specifically, we introduce a novel contrastive learning task to complement the reconstruction objective and strengthen representation learning. Meanwhile, we integrate the Mamba-2 module into both encoder and decoder designs and develop a new representation extraction paradigm to expand the model’s global receptive field. Extensive experiments demonstrate the effectiveness of PaT, achieving superior encrypted traffic recognition performance while maintaining a lightweight architecture. Zijia Song, Zhengyi Ma, Qiming Yu, Xiaohui Xie, Yelin Wang, Guozheng Yang |
Comput. Networks | 6 |
| 2026 | Debapt: Ontology-driven multi-agent debate for APT adversary profile construction from cyber threat intelligenceabstractCyber threat intelligence (CTI) reports contain rich information about advanced persistent threat (APT) groups. This information is useful for adversary profile construction. However, turning long and fragmented CTI reports into structured adversary profiles remains difficult. Existing methods mainly rely on named entity and relation extraction pipelines or single large language models (LLMs). These methods often lack explicit semantic constraints for profile-oriented tasks. They are also prone to omission and hallucination when processing long reports. In this paper, we study APT adversary profile construction from CTI reports. We formulate this task as an ontology-constrained profile information extraction task. To support this task, we develop VICTOR, a domain-specific ontology that organizes profile-relevant information into six dimensions. We then propose Debapt, an ontology-driven multi-agent debate framework. Guided by VICTOR, Debapt performs APT adversary profile construction through two debate loops in the entity extraction phase and relation extraction phase. In each loop, role-specialized agents iteratively extract, review, and adjudicate candidate profile-relevant facts under moderator supervision. These extracted results can be further aggregated across reports to support actor-centric adversary profile construction. To evaluate Debapt, we re-annotate three public CTI datasets under a unified profiling schema. Experimental results show that Debapt improves profile-oriented entity and relation extraction over competitive baselines. It extracts more complete and better grounded profile-relevant facts from CTI reports. Case studies further show that these extracted results can support the construction of analytically useful adversary profiles. Xinyun Zhao, Lanlan Qi, Yongheng Zhang 0002, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010 |
Comput. Secur. | 5 |
| 2026 | MM-AttacKG: A multimodal approach to attack graph construction with large language modelsabstractCyber Threat Intelligence (CTI) parsing aims to extract key threat information from massive data, transform it into actionable intelligence, enhance threat detection and defense efficiency, including attack graph construction, intelligence fusion, and indicator extraction. Among these research topics, Attack Graph Construction (AGC) is essential for visualizing and understanding the potential attack paths of threat events from CTI reports. Existing approaches primarily construct the attack graphs purely from the textual data to reveal the logical threat relationships between entities within the attack behavioral sequence. However, they typically overlook the specific threat information inherent in visual modalities, which preserves key threat details from inherently multimodal CTI reports. Inspired by the remarkable multimodal understanding capabilities of Multimodal Large Language Models (MLLMs), we explore their potential in enhancing multimodal attack graph construction. To be specific, we propose a novel framework, MM-AttacKG, which can effectively extract key information from threat images and integrate it into attack graph construction, thereby enhancing the comprehensiveness and accuracy of attack graphs. It first employs a threat image parsing module to extract critical threat information from images and generate textual descriptions using MLLMs. Subsequently, it builds an iterative question-answering pipeline tailored for image parsing to refine the understanding of threat images. Finally, it achieves content-level integration between attack graphs and image-based answers through MLLMs, completing threat information enhancement. We construct a new multimodal dataset, AG-LLM-mm, and conduct extensive experiments to evaluate the effectiveness of MM-AttacKG. The results demonstrate that MM-AttacKG can accurately identify key information in threat images and significantly improve the quality of multimodal attack graph construction, effectively addressing the shortcomings of existing methods in utilizing image-based threat information. The code and the corresponding dataset will be released upon acceptance. Yongheng Zhang 0002, Xinyun Zhao, Yunshan Ma 0002, Haokai Ma, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010 |
Knowl. Based Syst. | 6 |
| 2025 | 6Scout: IPv6 Target Generation with Hybrid Trees and Reinforcement Learning for Internet-Wide Scanning
Zhaobin Shen, Guozheng Yang, Zijia Song |
ICA3PP (5) | 2 |
| 2025 | 6RLD: A Seedless Region Active IPv6 Address Dynamic Detection Method Based on Large Language Model and RAG Technology
Zhaobin Shen, Siyuan Zhu, Zijia Song, Guozheng Yang |
ICA3PP (4) | 4 |
| 2025 | Efficient Encrypted Traffic Classification with Multiple Knowledge DistillationabstractTo achieve efficient and accurate identification of encrypted traffic, we propose an encrypted traffic classification model based on multi-knowledge distillation named as SD-MKD, aiming to reduce the size of traffic recognition models and enhance their recognition accuracy through knowledge distillation technology. Specifically, we employ the Stacking method to distill the knowledge of three teacher models into a single student model, thereby strengthening the student model’s generalization ability and recognition performance. Moreover, to more precisely evaluate the distribution differences between the teacher and student models, we introduce the Sinkhorn Distance into the loss function. We conducted experiments on the ISCXVPN2016, ISCXTor2016 and USTC-TFC2016 datasets and tested the classification of cross-platform traffic transmission. Finally, ablation studies were performed to verify the performance improvement brought about by the SinKD component. The experimental results show that the model outperforms existing mainstream traffic classification models both qualitatively and quantitatively. Guozheng Yang, Zijia Song |
IJCNN | 1 |
| 2025 | AttacKG+: Boosting attack graph construction with Large Language ModelsabstractAttack graph construction seeks to convert textual cyber threat intelligence (CTI) reports into structured representations, portraying the evolutionary traces of cyber attacks. Even though previous research has proposed various methods to construct attack graphs, they generally suffer from limited generalization capability to diverse knowledge types as well as requirement of expertise in model design and tuning. Addressing these limitations, we seek to utilize Large Language Models (LLMs), which have achieved enormous success in a broad range of tasks given exceptional capabilities in both language understanding and zero-shot task fulfillment. Thus, we propose a fully automatic LLM-based framework to construct attack graphs named: AttacKG + . Our framework consists of four consecutive modules: rewriter, parser, identifier, and summarizer, each of which is implemented by instruction prompting and in-context learning empowered by LLMs. Furthermore, we upgrade the existing attack knowledge schema and propose a comprehensive version. We represent a cyber attack as a temporally unfolding event, each temporal step of which encapsulates three layers of representation, including behavior graph, MITRE TTP labels, and state summary. Extensive evaluation demonstrates that: (1) our formulation seamlessly satisfies the information needs in threat event analysis, (2) our construction framework is effective in faithfully and accurately extracting the information defined by AttacKG + . and (3) our attack graph directly benefits downstream security practices such as attack reconstruction. All the code and datasets will be released upon acceptance. Yongheng Zhang 0002, Tingwen Du, Yunshan Ma 0002, Xiang Wang 0010, Guozheng Yang, Yuliang Lu, Ee-Chien Chang |
Comput. Secur. | 6 |
| 2025 | Meaningful secret image sharing with improved visual quality
Rui Wang 0127, Xuehu Yan, Wei Yan 0014, Guozheng Yang |
Signal Process. | 6 |
| 2025 | On Some Properties for Universal Coding of Integers and Its GeneralizationabstractIn the field of lossless source coding, universal coding of integers (UCI) and generalized universal coding of integers (GUCI) are binary codes that are suitable for probability distributions without prior knowledge. UCICis defined as a prefix coding in which the constant expansion factor KC times max{1,H(P)} is greater than or equal to the expected codeword length, wherePis the decreasing probability distribution of the source andH(P)is the entropy ofP. SincePis decreasing, when the set of codewords of the prefix codeCis determined, the length of then+1-th codeword of the prefix codeCis greater than or equal to the length of then-th codeword for any positive integer n, at which time the expected codeword length ofCis minimized, andCis said to be minimal. GUCIGis defined as a prefix variable-to-variable length (VV) coding for which the constant expansion factor KG timesH(P)is greater than or equal to the coding rate. In this paper, we prove two important theorems for UCI. First, we provide and prove the necessary and sufficient conditions for a minimal prefix code to be UCI. Second, we provide the first proof of an essential theorem for VV codes. This theorem can reveal the connection between UCI and GUCI and prove the converse part of Shannon’s first theorem concerning VV codes. Wei Yan 0014, Yunghsiang Sam Han, Guozheng Yang |
IEEE Trans. Commun. | 3 |
| 2024 | SGES: A General and Space-efficient Framework for Graphlet Counting in Graph StreamsabstractGraphlets are small, connected, and non-isomorphic induced subgraphs that describe the topological structure of a graph. Counting graphlets is a fundamental task in graph mining and social network analysis. It has numerous applications in many fields, including dense subgraph discovery, anomaly detection, etc. Most existing work assumes a static graph. However, graphs are dynamic in the real world, which can be described as graph streams. Counting graphlets in graph streams is a challenge due to the streaming nature of the input. While there have been several studies on counting graphlets in graph streams, these works are limited to simple graphlets like triangles and butterflies. In this paper, we propose SGES algorithm to estimate more complex graphlets in graph streams. In SGES, we first propose an unbiased sampling strategy to maintain fixed-size sampled edges, which in turn allows us to unbiasedly estimate the number of subgraphs and then count graphlets based on the combinational relationship between the number of subgraphs and the number of graphlets. Extensive experiments over large real-world graph streams prove that our algorithm can obtain accurate estimation values of graphlet counts with high throughput. Lailong Luo, Yuliang Lu, Chu Huang, Qianzhen Zhang, Guozheng Yang, Deke Guo |
CIKM | 6 |
| 2024 | ZBanner: Fast Stateless Scanning Capable of Obtaining Responses over TCPabstractFast large-scale network scanning is an important way to understand internet service configurations and security in real time, among which stateless scan is representative. Existing stateless scanners can perform single-packet scans for internet-wide network measurements but are limited to host discovery or port scanning. To obtain further information over TCP, slower stateful scanners must be used in conjunction which spend more time and memory because of connection state maintenance. This paper proposes a novel stateless scanning method, which can establish TCP connections and obtain further responses in a completely stateless manner. Based on this method, we implement a stateless scanner named ZBanner. Experiments show that ZBanner performs better than current state-of-the-art solutions in terms of scan rate and memory usage. ZBanner achieves a scan rate at least three times faster than current tools for generic ports and over 90 times faster for open ports while keeping a minimum and stable memory usage. Chiyu Chen, Yuliang Lu, Guozheng Yang, Shasha Guo 0001 |
IPCCC | 3 |
| 2024 | Secret image sharing in the encrypted domain
Rui Wang 0127, Guozheng Yang, Xuehu Yan, Shengyang Luo |
J. Vis. Commun. Image Represent. | 2 |
| 2024 | Secret Cracking and Security Enhancement for the Image Application of CRT-Based Secret SharingabstractThe Asmuth and Bloom threshold secret sharing (AB-SS) is a classical introduction of the Chinese remainder theorem (CRT) to secret sharing, offering low computational complexity compared to other branches of secret sharing. For decades, numerous schemes have been proposed for practical applications of AB-SS, such as secret image sharing (SIS). However, in terms of security, AB-SS has proved to be neither ideal nor perfect, and its derivatives in image sharing exhibit vulnerabilities associated with secret leakage. This paper studies the security issues in the SIS schemes derived from AB-SS and improves the core sharing principle of AB-SS to enhance security in image protection. First, for$(2,n)$-CRTSIS schemes, we exploit the vulnerability in a single share image to crack the confidential information of the original image, including secret pixel values and the ratio of different pixels. Then, by employing the XOR operation, we introduce a chain obfuscation technology and propose a secure image sharing scheme based on the Chinese remainder theorem (COxor-CRTSIS). The COxor-CRTSIS scheme utilizes integer linear programming for achieving lossless recovery without segmentation and eliminates potential secret disclosure risks without additional encryption. Furthermore, to comprehensively evaluate the security of existing schemes, this paper presents three metrics, information loss rate, fluctuation degree, and coverage rate, enabling a quantitative comparison of security for the first time. Theoretical analyses and experiments are conducted to validate the effectiveness of our scheme. Rui Wang 0127, Guozheng Yang, Xuehu Yan, Wei Yan 0014 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Robust Secret Image Sharing Resistant to JPEG Recompression Based on Stable Block Conditionabstract$(k,n)$Threshold secret image sharing (SIS) hides a secret image within$n$shadows, and at least$k$shadows are needed for recovery. Due to the popularity and frequency of JPEG recompression, there is a need for robust secret image sharing (ROSIS) designed for JPEG images that is resilient to recompression for practical SIS applications. The current state-of-the-art ROSIS, which relies on error-correcting codes (ECC), is effective only for JPEG compression with quality factors (QFs) of 99 and 100. However, it generates noise-like shadow images that are confined to the spatial domain. In this paper, we present SBC-ROSIS (Robust Secret Image Sharing Scheme Resistant to JPEG Recompression Based on Stable Block Condition), a novel ROSIS scheme that utilizes a stable block condition to guarantee the invariance of discrete cosine transform (DCT) coefficients during JPEG recompression, significantly enhancing the robustness of the scheme. By employing a polynomial-based secret sharing (SS) algorithm, we construct DCT blocks that adhere to stable block condition either directly or through strategic global regulation. Additionally, we carefully consider the similarity between the generated DCT blocks and the original cover DCT blocks. Furthermore, we devised a tailored evaluation methodology specifically for ROSIS. Extensive experimental results indicate that SBC-ROSIS can effectively process JPEG images, achieving a balance among security, robustness, concealment, and adherence to the$(k, n)$threshold, without relying on steganography, ECC, or pixel expansion, and demonstrating robust performance in realistic recompression scenarios. Kejiang Chen, Wei Yan 0014, Xuehu Yan, Guozheng Yang |
IEEE Trans. Multim. | 5 |
| 2023 | FuzzyCAT: A Framework for Network Configuration Verification Based on FuzzingabstractNetwork configuration verification is a crucial concern within the realm of network operation and maintenance. The current works primarily investigate detection methods and verification tools for reachability-related network properties, such as forwarding loops, black holes, waypointing, and isolation, from the control plane and data plane perspectives. However, there remain limitations in terms of evaluating verification coverage and identifying implicit problems, such as asymmetric routing. Drawing upon the concepts of fuzzing and coverage calculation methods utilized in the software security field, we present a network configuration verification method that leverages fuzzing and design the FuzzyCAT framework. We create an implementation algorithm consisting of three stages: test packet generation, global forwarding, and state determination recording. Additionally, we propose a series of evaluation parameters and calculation methods for network verification coverage. Experimental results demonstrate that FuzzyCAT can identify asymmetric routing in addition to reachability-related problems. Furthermore, it quantifies the coverage of network configuration verification, providing a novel technical solution. Jianfei Cai 0002, Guozheng Yang, Jingju Liu |
IPCCC | 2 |
| 2023 | Catch: Collaborative Feature Set Search for Automated Feature EngineeringabstractFeature engineering often plays a crucial role in building mining systems for tabular data, which traditionally requires experienced human experts to perform. Thanks to the rapid advances in reinforcement learning, it has offered an automated alternative, i.e. automated feature engineering (AutoFE). In this work, through scrutiny of the prior AutoFE methods, we characterize several research challenges that remained in this regime, concerning system-wide efficiency, efficacy, and practicality toward production. We then propose Catch, a full-fledged new AutoFE framework that comprehensively addresses the aforementioned challenges. The core to Catch composes a hierarchical-policy reinforcement learning scheme that manifests a collaborative feature engineering exploration and exploitation grounded on the granularity of the whole feature set. At a higher level of the hierarchy, a decision-making module controls the post-processing of the attained feature engineering transformation. We extensively experiment with Catch on 26 academic standardized tabular datasets and 9 industrialized real-world datasets. Measured by numerous metrics and analyses, Catch establishes a new state-of-the-art, from perspectives performance, latency as well as its practicality towards production. Source code1 can be found at https://github.com/1171000709/Catch. Guoshan Lu, Haobo Wang 0001, Saisai Yang, Guozheng Yang, Cheng Zang, Gang Chen 0001, Junbo Zhao 0002 |
WWW | 5 |
| 2022 | Fingersound: A Low-cost and Deployable Authentication System with Fingertip Sliding SoundabstractFingerprint recognition technology is the most widely used technology in the field of biometrics and is also the preferred solution for mobile devices and the financial industry. However, traditional fingerprint recognition technology requires expensive sensors on the one hand and risks leaking fingerprint images on the other hand. In this paper, we propose Fingersound, a low-cost and deployable authentication system that utilizes the sound generated by finger sliding as an identity feature. We use a microphone array to record continuous sliding sound and extract multiple features in the frequency and time domains. Then we use various algorithms including a deep neural network to perform user authentication. We also design a mobile phone application that can interact with the embedded system to manage users and record authentication history. In our experiments, 100 participants used this system and achieved an equal error rate of 5.2%. Additionally, we investigate the system’s robustness within different sliding materials, texturesand under noise disturbances. We further demonstrate the resistance of Fingersound to replay attack. Zhanglei Shu, Zhangsen Wang, Guozheng Yang, Cheng Zang, Feng Lin 0004, Kui Ren 0001 |
ICPADS | 3 |
| 2021 | Multiparty verification in image secret sharingabstractMultiparties in image secret sharing (ISS) need to verify (detect and recognize) each other, which is seldom considered and realized in traditional methods. In this paper, we introduce the definition of multiparty verification. It includes two stages, i.e., a detection stage and a recognition stage, with evaluation methods that are also discussed. A multiparty verification scheme without pixel expansion is developed, which is suitable for both dealer attendance and nonattendance. The classic hash function, public key cryptography and visual cryptography are technically fused in the developed scheme. In the shadow distribution phase, each participant can verify the received shadow using his private key. In the restoration phase, for the case of dealer attendance, he can verify each shadow received using his secret key; for the case of dealer nonattendance, participants can verify each other before exchanging their shadows. We conduct analyses and illustrations to validate the developed scheme. Xuehu Yan, Zulie Pan, Xiaofeng Zhong, Guozheng Yang |
Inf. Sci. | 5 |
| 2020 | Application of random elements in ISSabstractThe ‐threshold image secret sharing (ISS) encodes a secret image into n shares. When k or more shares are obtained, the secret image can be decoded; however, less than k shares could decode none of the secret image. ISS primarily includes polynomial‐based ISS and visual secret sharing (VSS). In this study, the authors find that the random elements in ISS can be used not only to hide information but also to obtain more features such as multiple decryptions and comprehensible share. They have established an application model of random elements that is suitable for both polynomial‐based ISS and VSS. On the basis of the model, they have extended three algorithms to achieve information hiding, multiple decryptions and comprehensible share. Experiments indicate the effectiveness of these algorithms. Xuehu Yan, Yuliang Lu, Lintao Liu, Jingju Liu, Guozheng Yang |
IET Image Process. | 6 |
| 2020 | Visual secret sharing scheme with (n, n) threshold for selective secret content based on QR codes
Song Wan, Lanlan Qi, Guozheng Yang, Yuliang Lu, Xuehu Yan |
Multim. Tools Appl. | 3 |
| 2020 | Weighted visual cryptographic scheme with improved image quality
Xuehu Yan, Feng Liu 0032, Wei Qi Yan 0001, Guozheng Yang, Yuliang Lu |
Multim. Tools Appl. | 4 |
| 2020 | Secret image sharing with separate shadow authentication ability
Xuehu Yan, Qinghong Gong, Guozheng Yang, Yuliang Lu, Jingju Liu |
Signal Process. Image Commun. | 4 |
| 2016 | Ship wake detection for SAR images with complex backgrounds based on morphological dictionary learningabstractThe ship wake detection of SAR images is useful not only in estimating the speed and the direction of moving ships, but also in finding small ships which are hard to be detected. The traditional ship wake detection methods of SAR images can achieve satisfactory results in simple backgrounds, but hardly work in complex backgrounds. In this paper, we propose a novel method based on the morphological component analysis and the dictionary learning to detect ship wakes in complex backgrounds. In our method, the SAR image is decomposed into a cartoon component containing ship wakes and a sea-background texture component by adaptive-ly learning the ship wake dictionary and the sea-background texture dictionary; and then the shearlet transform is used to enhance ship wakes in the cartoon component. Experimental results show our method outperforms the traditional methods for SAR images in complex backgrounds. Guozheng Yang, Jing Yu 0005, Chuangbai Xiao |
ICASSP | 1 |