Jingzhang Sun

dblp:206/9449 · DBLP profile ↗
← Back
9ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0002-6961-6677ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 5 since 2021Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Diffbias: Harnessing diffusion models' prediction bias for adversarial patch defense
Xudong Ye, Qi Zhang 0059, Yapeng Wang 0001, Xu Yang 0010, Zuobin Ying, Jingzhang Sun, Xia Du
Neurocomputing6
2025 Localization and Elimination: Object Detection Physical Patch Defense Based on Adversarial Patch Characterization
abstract
Object detection plays an important role in areas such as intelligent surveillance and autonomous driving but is also faces the threat of adversarial patch attacks. Because adversarial patch attacks are highly stealthy, efficient and physically realizable, they pose a huge security risk to real-world object detectors. Therefore, we propose a segmented defense method, Localization and Elimination (LAE), for physically realizable adversarial patch attacks. The method designs three localization modules, namely, image information segmentation, heterogeneous region extraction, and local region preservation, as well as a feature fusion module, by analyzing the three intrinsic features of adversarial patches. By fusing the feature maps output from the three localization modules, the patch region feature map is finally output through the feature fusion module. Then the localized patch regions are filled with black pixels. This approach is different from other defense methods in that it can provide excellent defense performance against physically adversarial patches of different sizes, numbers, locations, and appearances in a variety of complex environmental contexts. We have demonstrated through extensive experiments that this defense method provides excellent defense performance and greater robustness than current state-of-the-art defense methods.
Zesheng Zhou, Sizheng Fu, Chunjie Cao, Fangjian Tao, Jingzhang Sun
IJCNN6
2025 Feature Graph Construction With Static Features for Malware Detection
abstract
Malware can greatly compromise the integrity and trustworthiness of information and is in a constant state of evolution. Existing feature fusion‐based detection methods generally overlook the correlation between features. And mere concatenation of features will reduce the model’s characterization ability, lead to low detection accuracy. Moreover, these methods are susceptible to concept drift and significant degradation of the model. To address those challenges, we introduce a feature graph‐based malware detection method, malware feature graph (MFGraph), to characterize applications by learning feature‐to‐feature relationships to achieve improved detection accuracy while mitigating the impact of concept drift. In MFGraph, we construct a feature graph using static features extracted from binary PE files, then apply a deep graph convolutional network to learn the representation of the feature graph. Finally, we employ the representation vectors obtained from the output of a three‐layer perceptron to differentiate between benign and malicious software. We evaluated our method on the EMBER dataset, and the experimental results demonstrate that it achieves an AUC score of 0.98756 on the malware detection task, outperforming other baseline models. Furthermore, the AUC score of MFGraph decreases by only 5.884% in 1 year, indicating that it is the least affected by concept drift.
Binghui Zou, Chunjie Cao, Longjuan Wang, Yinan Cheng, Chenxi Dang, Jingzhang Sun
IET Inf. Secur.7
2025 JPEG-Domain Malware Detection With Pretrained Lightweight Vision Transformer Model
abstract
Malware is proliferating at an exponential rate in cyberspace, posing serious threats to on-device systems characterized by limited computational capabilities. In this work, we address the critical challenge posed by data imbalance—where rare malware families receive inadequate representation—by proposing MalViT, a lightweight Vision Transformer (ViT) architecture that directly operates in the JPEG frequency domain. Rather than converting Huffman-coded signals into RGB spatial images, MalViT leverages Discrete Cosine Transform (DCT) coefficients to reduce data redundancy and computational overhead. We further improve the model’s generalization through both pre-training and fine-tuning workflows. Comprehensive evaluations on two large-scale, real-world malware datasets, MalNet-Image (1.26 M samples) and BODMAS (51 K samples), demonstrate that MalViT accelerates data loading by nearly threefold compared to existing methods. On GPU and CPU, MalViT achieves approximately 2.0× and 4.7× faster inference throughput than MobileViT, respectively, while incurring minimal or even improved accuracy loss. When processing 224 × 224-pixel JPEG images, MalViT completes inference within an average of 3.12ms per sample, which is 8.79× faster than VisMal and 5.91× faster than ViT4Mal. Furthermore, its compact design comprises only 1.1M parameters and requires 10M MACs, making it particularly suitable for resource-constrained on-device deployment.
Binghui Zou, Chunjie Cao, Fangjian Tao, Longjuan Wang, Jingzhang Sun
IEEE Trans. Dependable Secur. Comput.7
2024 A Weighted Discrete Wavelet Transform-Based Capsule Network for Malware Classification
Tonghua Qiao, Chunjie Cao, Binghui Zou, Fangjian Tao, Yinan Cheng, Jingzhang Sun
ICPR (4)7
2024 ML-AGNN: Smart Contract Vulnerability Detection Method Based on a Multi-Level Attention Graph Neural Network
abstract
Smart contracts and blockchain mutually reinforce each other, leveraging their core attribute of decentralized interoperability to play crucial roles in both on-chain code and off-chain data. Nonetheless, this dual-edged nature, characterized by immutability once deployed and an immature language ecosystem, introduces significant risks. Consequently, smart contract vulnerabilities have emerged as a major security threat within trusted blockchain environments. With the exponential growth in the number of smart contracts, traditional detection methods necessitate considerable data overhead. On the other hand, the growing complexity of code semantic relationships and the cumulative error effects of conventional detection techniques further compound the issue. To address these challenges and enhance the learning capability for complex semantic relationships, we proposed a novel deep learning approach: Multi-Level Attention Graph Neural Network (ML-AGNN). This method integrates adaptive attention mechanisms and channel aggregation within a message passing neural network, effectively tackling the limitations of local semantic information and inaccuracies in modeling semantic information due to deeper network layers. We have implemented this approach in a prototype named GNN and validated it using over 40,000 smart contracts from Ethereum. Our extensive results demonstrated that this solution achieves an accuracy of 91.77%and a recall of 87.17% in detecting reentrancy vulnerabilities, significantly surpassing state-of-the-art methods. Additionally, another experiment confirms that our approach markedly outperforms contemporary methods in detecting timestamp dependency vulnerabilities.
Chunjie Cao, Mengnan Wang, Jingzhang Sun
MSN6
2024 FACILE: A capsule network with fewer capsules and richer hierarchical information for malware image classification
Binghui Zou, Chunjie Cao, Longjuan Wang, Sizheng Fu, Tonghua Qiao, Jingzhang Sun
Comput. Secur.6
2023 Revisiting Graph Contrastive Learning for Anomaly Detection
abstract
Combining Graph neural networks (GNNs) with contrastive learning for anomaly detection has drawn rising attention recently. Existing graph contrastive anomaly detection (GCAD) methods have primarily focused on improving detection capability through graph augmentation and multi-scale contrast modules. However, the underlying mechanisms of how these modules work have not been fully explored. We dive into the multi-scale and graph augmentation mechanism and observed that multi-scale contrast modules do not enhance the expression, while the multi-GNN modules are the hidden contributors. Previous studies have tended to attribute the benefits brought by multi-GNN to the multi-scale modules. In the paper, we delve into the misconception and propose Multi-GNN and Augmented Graph contrastive framework MAG, which unified the existing GCAD methods in the contrastive self-supervised perspective. We extracted two variants from the MAG framework, L-MAG and M-MAG. The L-MAG is the lightweight instance of the MAG, which outperform the state-of-the-art on Cora and Pubmed with the low computational cost. The variant M-MAG equipped with multi-GNN modules further improve the detection performance. Our study sheds light on the drawback of the existing GCAD methods and demonstrates the potential of multi-GNN and graph augmentation modules. Our code is available at https://anonymous.4open.science/r/MAG-Framework-74D0.
Chunjie Cao, Fangjian Tao, Jingzhang Sun
ECAI4
2023 LGWAE: Label-Guided Weighted Autoencoder Network for Flexible Targeted Attacks of Deep Hashing
abstract
Deep hashing is frequently utilized in large-scale image retrieval because of its strong representation learning capabilities and effective processing capacity. However, deep hashing models are susceptible to adversarial examples. We propose a label-guided weighted autoencoder network (LGWAE) to generate adversarial examples for targeted hashing attacks. Specifically, we first introduce a multi-label learning network to extract the semantic features and the category code of different labels. Then, the semantic features and the benign image are collectively fed into an autoencoder in order to generate a natural-looking adversarial example. The category code is used as target hash code to supervise the generation of the adversarial example. To efficiently generate better-performing adversarial examples, we design a weighted Hamming distance loss that dynamically adjusts the loss value based on the label similarity between the benign image label and the target label. Numerous experiments demonstrate that we are capable of efficiently and effectively generating better quality adversarial samples.
Sizheng Fu, Chunjie Cao, Fangjian Tao, Binghui Zou, Jingzhang Sun
IJCNN6