Hengwei Zhang

dblp:200/1688 · DBLP profile ↗
← Back
22ranked-venue papers
5as first author
18since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 1 first-author · 10 since 2021Computer networks · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Rethinking adversarial transferability from a random and average perspective
abstract
Abstract Deep learning models are vulnerable to adversarial examples generated by adding imperceptible perturbations to original images. Transfer-based adversarial attacks have attracted tremendous attention as they can utilize adversarial examples crafted on surrogate models to mislead target models. An effective strategy to boost adversarial transferability is to create diverse input patterns through input transformation. However, previous works rely on probability to control the diverse input patterns, ignoring the influence of randomness brought by probability on transferability. In this work, we rethink the randomness in these input transformation methods and identify the flaw of excessive randomness, which affects further improvement of transferability. From a statistical perspective, we propose a gradient average attack, which approximates the expected value of gradients by averaging multiple gradients, alleviating the impact of excessive randomness, and generating more transferable adversarial examples. Extensive experiments on the ImageNet dataset demonstrate that our method can remarkably enhance the input transformation attacks of multiple random transformation forms (e.g. resizing and padding, cropping, rotation, translation etc.) and gains heightened transferability. In addition, our method can be seamlessly incorporated with many existing attack methods to further achieve higher attack success rates. Moreover, when attacking a practical image recognition system on the Baidu AI Cloud, the 83.0% attack success rate reveals that real-world-implemented intelligent systems are subject to serious security threats.
Bo Yang 0049, Hengwei Zhang, Jindong Wang 0002
Comput. J.2
2026 Prototype-driven contrastive learning enables transferable seismic representation
Fanchun Meng, Hengwei Zhang
Eng. Appl. Artif. Intell.3
2026 DJSCC-Enabled Multiuser Semantic CSI Feedback for Hybrid Beamforming in Dual-Polarized cmWave Massive MIMO
abstract
Driven by the ultra-high throughput requirements of 6G, wireless communications are migrating to centimeter wave (cmWave) bands to overcome the limitations of current spectral resources. Massive multiple-input multiple-output (MIMO) and orthogonal frequency division multiplexing (OFDM) systems aim to achieve high spectral efficiency in cmWave regimes but are often constrained by the heavy overhead of downlink channel state information (CSI) feedback. This paper proposes a deep learning scheme based on the multi-axis multi-layer perceptron for image processing (MAXIM) architecture for joint semantic CSI feedback and hybrid beamforming in multi-user cmWave MIMO-OFDM systems, which maximizes the downlink sum rate by end-to-end optimization. Specifically, distributed encoders at multiple user equipments (UEs) perform limited CSI feedback, while the decoder at the base station (BS) jointly designs the hybrid beamforming matrices without explicit CSI reconstruction. The uplink transmission is implemented via deep joint source–channel coding (DJSCC) to enhance CSI compression efficiency and noise robustness. Furthermore, considering the high correlation between vertical and horizontal polarization channels in dual-polarized massive MIMO systems, a cross-polarization interaction module is introduced at the UEs to exploit polarization correlations for joint CSI compression. Simulation results demonstrate that the proposed method improves the downlink sum rate under various signal-to-noise ratio (SNR) conditions with a limited number of feedback symbols, validating its robustness and superiority in multi-user dual-polarized cmWave MIMO-OFDM systems.
Ziqi Han, Ziwei Wan, Hengwei Zhang, Keke Ying, Chabalala S. Chabalala, Wei Wang 0209, Zhen Gao 0001
IEEE Internet Things J.3
2026 A Deep Reinforcement Learning Approach to Time Delay Differential Game Deception Resource Deployment
abstract
Current methods for deploying cyber deception do not consider the impact of time delays on the effectiveness of actions by both attackers and defenders, nor can they make real-time decisions on the deployment of deception assets in complex network environments. To address these issues, this paper proposes a deception resource deployment method based on deep reinforcement learning with time-delay differential game theory. First, we constructed the security evolution process of nodes in complex network environments by analyzing the threat models of attackers and defense models of defenders, presenting time-delay differential state equations for nodes with varying degrees. Furthermore, we introduced a cyber deception time-delay differential game model, quantifying the gains for both sides. We then designed a deep reinforcement learning algorithm, employing proximal policy optimization (PPO) to determine the optimal deception deployment strategy, based on the analysis of the network deception time-delay differential game model. Finally, the effectiveness of the proposed method in determining the optimal deception deployment strategy was validated through the construction of a scale-free complex network. Experimental results show that the proposed model could effectively discern the evolutionary processes of nodes with different degrees and the strategies of both attackers and defenders. Compared with other methods, the proposed method showed distinct advantages in stability and effectiveness. The results indicate that the proposed method can be effectively deployed in cyber deception.
Weizhen He, Jinglei Tan, Zhiquan Liu 0001, Xiangyang Luo 0001, Hengwei Zhang
IEEE Trans. Dependable Secur. Comput.7
2025 A Strategy-Making Method for PIoT PLC Honeypoint Defense Against Attacks Based on the Time-Delay Evolutionary Game
Jinglei Tan, Tianshuai Zheng, Yuan Liu 0002, Hengwei Zhang, Zhihong Tian 0001
IEEE Trans. Inf. Forensics Secur.5
2025 Adversarial Example Soups: Improving Transferability and Stealthiness for Free
abstract
Transferable adversarial examples cause practical security risks since they can mislead a target model without knowing its internal knowledge. A conventional recipe for maximizing transferability is to keep only the optimal adversarial example from all those obtained in the optimization pipeline. In this paper, for the first time, we revisit this convention and demonstrate that those discarded, sub-optimal adversarial examples can be reused to boost transferability. Specifically, we propose “Adversarial Example Soups” (AES), with AES-tune for averaging discarded adversarial examples in hyperparameter tuning and AES-rand for stability testing. In addition, our AES is inspired by “model soups”, which averages weights of multiple fine-tuned models for improved accuracy without increasing inference time. Extensive experiments validate the global effectiveness of our AES, boosting 10 state-of-the-art transfer attacks and their combinations by up to 13% against 10 diverse (defensive) target models. We also show the possibility of generalizing AES to other types, e.g., directly averaging multiple in-the-wild adversarial examples that yield comparable success. A promising byproduct of AES is the improved stealthiness of adversarial examples since the perturbation variances are naturally reduced.
Bo Yang 0049, Hengwei Zhang, Jindong Wang 0002, Yulong Yang 0002, Chenhao Lin, Chao Shen 0001, Zhengyu Zhao 0001
IEEE Trans. Inf. Forensics Secur.2
2024 A Weighted Flat Lattice Transformer-based Knowledge Extraction Architecture for Chinese Named Entity Recognition
abstract
Named Entity Recognition (NER) is one of the contents of Knowledge Extraction (KE) that transforms data into knowledge representation. However, Chinese NER faces the problem of lacking clear word boundaries that limit the effectiveness of the KE. Although the flat lattice Transformer (FLAT) framework, which converts lattice structure into a flat structure including a set of spans, can effectively improve this problem and obtain advanced results, there still exist the problems of insensitivity to entity importance weights and insufficient feature learning. This paper proposes a weighted flat lattice Transformer architecture for Chinese NER, namely WFLAT. The WFLAT first adds a weight matrix into self-attention calculation, which can obtain finer-grained partitioning of entities to improve experimental performance, and then adopts a multi-layer Transformer encoder with each layer using a multi-head self-attention mechanism. Extensive experimental results on benchmarks demonstrate that our proposed KE model can obtain state-of-the-art performance for the Chinese NER task.
Hengwei Zhang, Yuejia Wu
CSCWD1
2024 A Deep Reinforcement Learning-Based Deception Asset Selection Algorithm in Differential Games
abstract
Currently, there are various problems in the field of network attack-defense analysis and deception asset deployment of game theory-based, such as difficulties in constructing attack and defense models and determining real-time attack and defense strategies. To address these problems, this study proposes a differential game deception asset selection algorithm based on multi-agent deep reinforcement learning. Specifically, by analyzing the attack and defense strategies, the infectious disease model is developed to conduct the evolution analysis of the network security state, and the differential equation of the node state in the deception defense system is derived. In addition, a differential game model for the cyber deception attack-defense process is constructed, and the reward functions of the attacker and defender are designed. A deception asset selection algorithm is established based on the deep Q network method to solve optimal deception assets. The effectiveness of the proposed model is validated through a microservices attack-defense example in a cloud-native environment. The results show that compared to the deception asset selection algorithms based on the Fictitious Self Play and Policy Space Response Oracles, the convergence speed of the proposed algorithm is improved by 77.8% and 95.6%, respectively.
Weizhen He, Jinglei Tan, Ke Shang 0005, Hengwei Zhang
IEEE Trans. Inf. Forensics Secur.5
2023 Adversarial example generation with adabelief optimizer and crop invariance
Bo Yang 0049, Hengwei Zhang, Zheming Li, Kaiyong Xu, Jindong Wang 0002
Appl. Intell.2
2023 A differential game approach for real-time security defense decision in scale-free networks
Hengwei Zhang, Jindong Wang 0002, Jinglei Tan
Comput. Networks1
2023 Security defense decision method based on potential differential game for complex networks
abstract
Most defense strategies in complex networks are developed from the defense perspective, overlooking the key attack-defense characteristics in cybersecurity. A defense decision algorithm is ineffective when dealing with dynamic attacking behaviors, and when based on attack-defense analysis, stochastic uniform network models are generally used to model the target network, while most networks are large and complex. Thus, the algorithms and their results do not well suit small-world, scale-free, and high-aggregation networks. In this study, considering the structural characteristics of complex networks and the attack-defense characteristics of cybersecurity, potential differential game theory is integrated with complex networks, and a global optimal defense decision algorithm is proposed according to the overall network defense objective. Based on the evolutionary analysis of network security states, a network attack-defense potential differential game model is constructed. Adversarial analysis is carried out on the overall attack-defense strategy, and a defense decision algorithm is designed based on a saddle point equilibrium strategy. Simulation tests are carried out on small-world and scale-free networks to evaluate the effectiveness of the proposed method by comparing its performance with that of random defense strategies and classic decision algorithms.
Hengwei Zhang, Yumeng Fu, Jindong Wang 0002, Jinglei Tan
Comput. Secur.1
2023 WF-MTD: Evolutionary Decision Method for Moving Target Defense Based on Wright-Fisher Process
abstract
The limitations of the professional knowledge and cognitive capabilities of both attackers and defenders mean that moving target attack-defense conflicts are not completely rational, which makes it difficult to select optimal moving target defense strategies difficult for use in real-world attack-defense scenarios. Starting from the imperfect rationality of both attack-defense, we construct a Wright-Fisher process-based moving target defense strategy evolution model called WF-MTD. In our method, we introduce rationality parameters to describe the strategy learning capabilities of both the attacker and the defender. By solving for the evolutionarily stable equilibrium, we develop a method for selecting the optimal defense strategy for moving targets and describe the evolution trajectories of the attack-defense strategies. Our experimental results in our example of a typical network information system show that WF-MTD selects appropriate MTD strategies in different states along different attack paths, with good effectiveness and broad applicability. In addition, compared with no hopping strategy, fixed periodic route hopping strategy, and random periodic route hopping strategy, the route hopping strategy based on WF-MTD increase defense payoffs by 58.7%, 27.6%, and 24.6%, respectively.
Jinglei Tan, Hao Hu 0005, Ruiqin Hu, Hengwei Zhang
IEEE Trans. Dependable Secur. Comput.6
2022 Cybersecurity Threat Assessment Integrating Qualitative Differential and Evolutionary Games
abstract
Most current game theory-based cybersecurity analysis methods use traditional game models, which do not meet realistic conditions of continuous dynamic changes in attack-defense behaviors and decision makers without perfect rationality, and therefore they adapt with difficulty to the practical requirements of cybersecurity threat assessment. This paper draws on infectious disease dynamics methods to describe the cybersecurity threat propagation process. It constructs a dynamic game model of a cybersecurity threat based on continuous attack-defense confrontation and boundedly rational decision makers, combining qualitative differential and evolutionary game theories. Qualitative differential games are used to analyze the confrontation process of security threats, calculate attack-defense barriers, and construct a benchmark to measure the degree of a security threat. Evolutionary games are used to analyze the dynamic change of attack-defense strategy-selection probabilities based on replicator dynamics, and to deduce the evolutionary trajectory of the network security state. We then calculate the multidimensional Euclidean distance between the evolutionary trajectory and the attack-defense barrier metric benchmark, and use it as the basis for a dynamic threat assessment algorithm to improve the timeliness and objectivity of threat assessment. Simulation experiments show that the model and algorithm are effective and feasible.
Hengwei Zhang, Jinglei Tan, Shirui Huang, Hao Hu 0005
IEEE Trans. Netw. Serv. Manag.1
2021 Network defense decision-making based on a stochastic game system and a deep recurrent Q-network
Hengwei Zhang, Shuqin Dong
Comput. Secur.2
2021 Optimal temporospatial strategy selection approach to moving target defense: A FlipIt differential game model
Jinglei Tan, Hengwei Zhang, Hao Hu 0005, Zhenxiang Qin
Comput. Secur.2
2021 Predicting potential palliative care beneficiaries for health plans: A generalized machine learning pipeline
Hengwei Zhang, Yan Li 0018, William McConnell
J. Biomed. Informatics1
2021 Optimal Network Defense Strategy Selection Method: A Stochastic Differential Game Model
abstract
In a real-world network confrontation process, attack and defense actions change rapidly and continuously. The network environment is complex and dynamically random. Therefore, attack and defense strategies are inevitably subject to random disturbances during their execution, and the transition of the network security state is affected accordingly. In this paper, we construct a network security state transition model by referring to the epidemic evolution process, use Gaussian noise to describe random effects during the strategy execution, and introduce a random disturbance intensity factor to describe the degree of random effects. On this basis, we establish an attack-defense stochastic differential game model, propose a saddle point equilibrium solution method, and provide an algorithm to select the optimal defense strategy. Our method achieves real-time defense decision-making in network attack-defense scenarios with random disturbances and has better real-time performance and practicality than current methods. Results of a simulation experiment show that our model and algorithm are effective and feasible.
Hengwei Zhang, Hao Hu 0005, Jinglei Tan, Jindong Wang 0002
Secur. Commun. Networks2
2021 Boosting Adversarial Attacks on Neural Networks with Better Optimizer
abstract
Convolutional neural networks have outperformed humans in image recognition tasks, but they remain vulnerable to attacks from adversarial examples. Since these data are crafted by adding imperceptible noise to normal images, their existence poses potential security threats to deep learning systems. Sophisticated adversarial examples with strong attack performance can also be used as a tool to evaluate the robustness of a model. However, the success rate of adversarial attacks can be further improved in black-box environments. Therefore, this study combines a modified Adam gradient descent algorithm with the iterative gradient-based attack method. The proposed Adam iterative fast gradient method is then used to improve the transferability of adversarial examples. Extensive experiments on ImageNet showed that the proposed method offers a higher attack success rate than existing iterative methods. By extending our method, we achieved a state-of-the-art attack success rate of 95.0% on defense models.
Hengwei Zhang, Jindong Wang 0002, Ruiyu Dou
Secur. Commun. Networks2
2020 Optimal Network Defense Strategy Selection Method Based on Evolutionary Network Game
abstract
The basic hypothesis of evolutionary game theory is that the players in the game possess limited rationality. The interactive behavior of players can be described by a learning mechanism that has theoretical advantages in modeling the network security problem in a real society. The current network security evolutionary game model generally adopts a replicator dynamic learning mechanism and assumes that the interaction between players in the group conforms to the characteristics of uniform mixed distribution. However, in an actual network attack and defense scenario, the players in the game have limited learning capability and can only interact with others within a limited range. To address this, we improved the learning mechanism based on the network topology, established the learning object set based on the learning range of the players, used the Fermi function to calculate the transition probability to the learning object strategy, and employed random noise to describe the degree of irrational influence in the learning process. On this basis, we built an attack and defense evolutionary network game model, analyzed the evolutionary process of attack and defense strategy, solved the evolution equilibrium, and designed a defense strategy selection algorithm. The effectiveness of the model and method is verified by conducting simulation experiments for the transition probability of the players and the evolutionary process of the defense group strategy.
Hengwei Zhang, Lulu Shao
Secur. Commun. Networks2
2020 Optimal Timing Selection Approach to Moving Target Defense: A FlipIt Attack-Defense Game Model
abstract
The centralized control characteristics of software-defined networks (SDNs) make them susceptible to advanced persistent threats (APTs). Moving target defense, as an effective defense means, is constantly developing. It is difficult to effectively characterize an MTD attack and defense game with existing game models and effectively select the defense timing to balance SDN service quality and MTD decision-making benefits. From the hidden confrontation between the actual attack and defense sides, existing attack-defense scenarios are abstractly characterized and analyzed. Based on the APT attack process of the Cyber Kill Chain (CKC), a state transition model of the MTD attack surface based on the susceptible-infective-recuperative-malfunctioned (SIRM) infectious disease model is defined. An MTD attack-defense timing decision model based on the FlipIt game (FG-MTD) is constructed, which expands the static analysis in the traditional game to a dynamic continuous process. The Nash equilibrium of the proposed method is analyzed, and the optimal timing selection algorithm of the MTD is designed to provide decision support for the selection of MTD timing under moderate security. Finally, the application model is used to verify the model and method. Through numerical analysis, the timings of different types of attack-defense strategies are summarized.
Jinglei Tan, Hengwei Zhang, Hao Hu 0005
Secur. Commun. Networks2
2019 Active Defense Strategy Selection Method Based on Two-Way Signaling Game
abstract
Most network security research studies based on signaling games assume that either the attacker or the defender is the sender of the signal and the other party is the receiver of the signal. The attack and defense process is commonly modeled and analyzed from the perspective of one-way signal transmission. Aiming at the reality of two-way signal transmission in network attack and defense confrontation, we propose a method of active defense strategy selection based on a two-way signaling game. In this paper, a two-way signaling game model is constructed to analyze the network attack and defense processes. Based on the solution of a perfect Bayesian equilibrium, a defense strategy selection algorithm is presented. The feasibility and effectiveness of the method are verified using examples from real-world applications. In addition, the mechanism of the deception signal is analyzed, and conclusions for guiding the selection of active defense strategies are provided.
Hengwei Zhang, Lulu Shao, Jihong Han
Secur. Commun. Networks2
2018 Diversified recommendation method combining topic model and random walk
Hengwei Zhang, Jindong Wang 0002
Multim. Tools Appl.2