Zhengqiu Weng

dblp:191/8659 · DBLP profile ↗
← Back
16ranked-venue papers
1as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 1 first-author · 4 since 2021Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Systems, architecture and hardware · 3 · 1 since 2021
YearPublicationVenuePosition
2026 Lotldetector: living off the land attacks detection system based on feature fusion
abstract
Abstract In recent years, Living off the Land (LotL) attacks have been drawing attention due to their flexibility and difficulty in detection. These attacks exploit legitimate tools already in the system to conduct malicious activities, hiding their malicious intent behind normal benign programs. However, detection methods for such attacks largely rely on expert rules. While rule tags can effectively detect known attacks, this also leads to a high false positive rate, resulting in low detection accuracy for the models. To address these issues, we propose a detection system called LOTLDetector, which combines deep learning methods with expert rules to detect malicious command lines in LotL attacks from both data and knowledge perspectives. LOTLDetector learns the semantics of command line text through neural networks and combines rule tags from expert knowledge, enabling a more comprehensive detection of LotL attacks. We extensively evaluated our method, validated it on a Windows dataset containing 27,448 command lines and a Linux dataset containing 27,093 command lines, and compared it with existing methods. The results show that our method significantly outperforms existing methods in detecting malicious command lines. For the Linux dataset, the detection system achieved a detection performance with an accuracy of 0.9728; for the Windows dataset, the system’s detection accuracy also reached 0.9598, which is about 8% higher than the best existing method. In addition, our project has been open-sourced at https://github.com/csedikaf/LOTLDetector .
Tiantian Zhu 0001, Tieming Chen, Mingqi Lv, Chun-lin Xiong, Zhengqiu Weng, Xiangyang Zheng
Cybersecur.6
2026 SLATSCOG: A secure authentication framework via federated data generation and temporally-enhanced split learning
Tiantian Zhu 0001, Zhengqiu Weng, Zhizhong Ma, Suyu Zhang
Knowl. Based Syst.3
2026 ProGrasp: Storage-efficient provenance graph compression for APT forensics via structure prediction and attribute aggregation
Tiantian Zhu 0001, Yiqian Yang, Zhengqiu Weng, Haofei Sun, Zhizhong Ma, Guolang Chen
Knowl. Based Syst.3
2025 MIRDETECTOR: Applying malicious intent representation for enhanced APT anomaly detection
Tiantian Zhu 0001, Tieming Chen, Mingqi Lv, Jian-Ping Mei, Zhengqiu Weng, Lili Shi
Comput. Secur.7
2025 LinTracer: An efficient tracking system for cyberattack chains fusing entity and event semantics
Tiantian Zhu 0001, Wenya He, Tieming Chen, Jiabo Zhang, Mingqi Lv, Aohan Zheng, Xiangyang Zheng, Zhengqiu Weng, Shuying Wu
Comput. Secur.11
2025 GANDACOG: Implicit Mobile User Authentication in Multi Environments With Scarce Data
abstract
Mobile device user authentication technologies have been studied for decades in the context of personal information security. To strike a balance between security, privacy, and usability, authentication methods based on motion sensors have gained widespread attention in recent years. However, these methods still face several challenges, such as the limited training samples, the finite scene coverage, and the high-cost models. Therefore, there is an urgent need to develop more efficient and reliable solutions to enhance the user experience. To address these challenges, we introduce, which offers the following features: 1) It uses a novel data augmentation method (AUTHGANS) to expand the dataset. 2) It employs a differential attention mechanism to reduce noise interference, improve model scene coverage, and simultaneously reduce the model size during the model training phase, and improve the model’s accuracy. 3) It uses a model distillation strategy (AuthFusion), ensuring high accuracy while reducing the model’s computational requirements on devices. Experiments on a dataset with 1,513 users and noise show that achieves high accuracy while requiring less computational power than other state-of-the-art authentication methods.
Tiantian Zhu 0001, Tieming Chen, Mingqi Lv, Zhengqiu Weng, Suyu Zhang
IEEE Internet Things J.6
2025 ThreatCog: An adaptive and lightweight mobile user authentication system with enhanced motion sensory signals
Tiantian Zhu 0001, Jian-Ping Mei, Xue Leng, Xiangyang Zheng, Zhengqiu Weng
J. Inf. Secur. Appl.9
2025 RT-APT: A real-time APT anomaly detection method for large-scale provenance graph
Zhengqiu Weng, Weinuo Zhang, Tiantian Zhu 0001, Zhenhao Dou, Haofei Sun, Zhanxiang Ye, Ye Tian 0027
J. Netw. Comput. Appl.1
2025 Actminer: Applying causality tracking and increment aligning for graph-based threat hunting
Tiantian Zhu 0001, Tieming Chen, Mingqi Lv, Zhengqiu Weng, Guolang Chen
Knowl. Based Syst.6
2024 Intelligent botnet detection in IoT networks using parallel CNN-LSTM fusion
abstract
Summary With the development of the Internet of Things (IoT), the number of terminal devices is rapidly growing and at the same time, their security is facing serious challenges. For the industrial control system, there are challenges in detecting and preventing botnet. Traditional detection methods focus on capturing and reverse analyzing the botnet programs first and then parsing the extracted features from the malicious code or attacks. However, their accuracy is very low and their latency is relatively high. Moreover, they sometimes even cannot recognize the unknown botnets. The machine learning based detection methods rely on manual feature engineering and have a weak generalization. The deep learning‐based methods mostly rely on the system log, which does not take into account the multisource information such as traffic. To address the above issues, from the perspective of the botnet features, this paper proposes an intelligent detection method over parallel CNN‐LSTM, integrating the spatial and temporal features to identify botnets. Experimental demonstrate that the accuracy, recall, and F1‐score of our proposed method achieve up to over 98%, and the precision, 97.8%, is not the highest but reasonable. It reveals compared with the existing start‐of‐the‐art methods, our proposed method outperforms in the botnet detection. Our methodology's strength lies in its ability to harness the multifaceted information present in IoT traffic, offering a more nuanced and comprehensive analysis. The parallel CNN‐LSTM architecture ensures that spatial and temporal data are processed concurrently, preserving the integrity of the information and enabling a more robust detection mechanism. The result is a detection system that not only performs exceptionally well in a controlled environment but also holds promise for real‐world application, where the rapid and accurate identification of botnets is paramount.
Rongrong Jiang, Zhengqiu Weng, Lili Shi, Erxuan Weng, Wuzhao Li
Concurr. Comput. Pract. Exp.2
2024 TrapCog: An Anti-Noise, Transferable, and Privacy-Preserving Real-Time Mobile User Authentication System With High Accuracy
abstract
The authentication technology of mobile device users has been studied for decades. To balance security, privacy, and usability, motion sensors-based user authentication methods are widely investigated in recent years. However, existing studies meet the problems such as scarcity of training samples, underutilization of data, poor de-noising ability, insufficient transferability, privacy leakage, and low accuracy. To overcome these difficulties, we propose a system, calledTrapCog, with the following capabilities: 1) In the phase of data collection,TrapCogcan eliminate man-made noise (mislabeling) through differential training based on down-sampling. 2) In the model training stage, the siamese neural network with Long Short-Term Memory (LSTM) as the sub-network is used to achieve sufficient coverage of sample patterns and the transferability of the model. 3) In the phase of real-world authentication, the privacy of the user is tremendously protected through end-side model deployment and local authentication. Experimental results on a dataset composed of 1,513 users with real-world noise show thatTrapCoghas high accuracy and strong transferability, which is much better than state-of-the-art studies.
Tiantian Zhu 0001, Qiang Liu 0034, Chun-lin Xiong, Zhengqiu Weng, Tieming Chen, Mingqi Lv, Ting Wang 0004, Yan Chen 0004
IEEE Trans. Mob. Comput.5
2022 EspialCog: General, Efficient and Robust Mobile User Implicit Authentication in Noisy Environment
abstract
Mobile authentication is a fundamental factor in the protection of user’s private resources. In recent years, motion sensor-based biometric authentication has been widely used for privacy-preserving. However, it faces with the problems including low data collection efficiency, insufficient authentication scenario coverage rate, weak de-noising ability, and poor robustness of models, rendering existing methods difficult to meet the security, privacy, and usability requirements jointly in the real-world scenario. To overcome these difficulties, we propose a system calledEspialCog, which is able to 1) collect the sensor data embedded in mobile devices self-adaptively, unobtrusively and efficiently through the evolutionary stable participation game mechanism (ESPGM) with a high scenario coverage rate; 2) minimize noise from collected data by analyzing three types of abnormalities; and 3) authenticate the ownership of mobile devices in real-time by adopting optimized LSTM model with an enhanced stochastic gradient descent (SGD) algorithm. The simulation experiment on 6000 users shows that the efficiency and coverage rates increase dramatically by deploying our ESPGM. Moreover, we conduct experiments on a large-scale real-world noisy dataset with 1513 users and two other small pure real-world datasets. The experimental results show the high accuracy and favorable robustness ofEspialCogin the noisy environment.
Tiantian Zhu 0001, Zhengqiu Weng, Qijie Song, Qiang Liu 0034, Yan Chen 0004, Mingqi Lv, Tieming Chen
IEEE Trans. Mob. Comput.2
2020 WebSmell: An Efficient Malicious HTTP Traffic Detection Framework Using Data Augmentation
Tieming Chen, Zhengqiu Weng, YunPeng Chen, Chenqiang Jin, Mingqi Lv, Tiantian Zhu 0001, Jianhong Lin
Inscrypt2
2019 A Target Wake Time Based Power Conservation Scheme for Maximizing Throughput in IEEE 802.11ax WLANs
abstract
IEEE 802.11ax, introducing Target Wake Time (TWT) mechanism, was proved as the next generation Wireless Local Area Network (WLAN) technology to improve QoS and QoE in dense scenarios. A novel broadcast TWT mechanism is proposed to save power by leveraging the new capability of uplink Orthogonal Frequency Division Multiple Access (OFDMA) based multiuser transmission. However, if the TWT is not properly scheduled, deteriorated throughput and high power consumption occur because of collisions. This paper investigates several key aspects, such as the number of simultaneously awake stations, the number of eligible random access resource units, and backoff stages, that have great impacts on the throughput and power efficiency. Based on the derived relationship, we further propose a TWT scheduling scheme (TSS) for negotiating Target Beacon Transmission Times (TBTTs) by making decisions on whether accepting the TWT request or not to maximize throughput. Besides, an algorithm on arranging stations to wake up in different beacon slots with appropriate offsets (i.e., first TBTTs) is presented. Simulation results demonstrate the effectiveness in terms of average throughput and power efficiency.
Guoxi Liang, Zhengqiu Weng
ICPADS3
2018 Leveraging Mobile Nodes for Preserving Node Privacy in Mobile Crowd Sensing
abstract
Mobile crowd sensing has been a very important paradigm for collecting sensing data from a large number of mobile nodes dispersed over a wide area. Although it provides a powerful means for sensing data collection, mobile nodes are subject to privacy leakage risks since the sensing data from a mobile node may contain sensitive information about the sensor node such as physical locations. Therefore, it is essential for mobile crowd sensing to have a privacy preserving scheme to protect the privacy of mobile nodes. A number of approaches have been proposed for preserving node privacy in mobile crowd sensing. Many of the existing approaches manipulate the sensing data so that attackers could not obtain the privacy‐sensitive data. The main drawback of these approaches is that the manipulated data have a lower utility in real‐world applications. In this paper, we propose an approach calledP3to preserve the privacy of the mobile nodes in a mobile crowd sensing system, leveraging node mobility. In essence, a mobile node determines a routing path that consists of a sequence of intermediate mobile nodes and then forwards the sensing data along the routing path. By using asymmetric encryptions, it is ensured that a malicious node is not able to determine the source nodes by tracing back along the path. With our approach, upper‐layer applications are able to access the original sensing data from mobile nodes, while the privacy of the mobile node is not compromised. Our theoretical analysis shows that the proposed approach achieves a high level of privacy preserving capability. The simulation results also show that the proposed approach incurs only modest overhead.
Shengbao Zheng, Zhengqiu Weng
Wirel. Commun. Mob. Comput.3
2017 Data Collection with Privacy Preserving in Participatory Sensing
abstract
Participatory sensing has increasingly become a new paradigm of data collection from a wide physical area and a large population. One of the major challenges in participatory sensing is the privacy issue. Sensing data from smartphones may contain sensitive information such as user locations. Thus, it is of great importance to preserve privacy throughout the data collection process in participatory sensing. It is however very challenging because of the distributed nature of the network, many potential malicious attackers and the convergecast model of data collection. In this paper, we present a data collection approach which preserves user privacy in participatory sensing. In this approach, a smartphone node utilizes other smartphones as intermediate nodes to transfer its sensing data. In addition, asymmetric encryption is used to prevent malicious reverse tracking along the data forwarding route, hence anonymizing the originator of the data. We analyze the security of the approach and show that it achieves a high level of security. Extensive simulations demonstrate that the proposed approach has a low overhead.
Shengbao Zheng, Zhengqiu Weng
ICPADS3