Xiuzhang Yang

dblp:209/5818 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-author · 4 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
YearPublicationVenuePosition
2026 CTI-Thinker: an LLM-driven system for CTI knowledge graph construction and attack reasoning
abstract
Abstract With the increasing frequency of APT attacks, cyber defense urgently demands high-quality threat intelligence support. Cyber threat intelligence (CTI) knowledge graphs have demonstrated significant potential in aiding threat detection and behavioral reasoning. However, existing CTI data often suffer from unstructured formats, fragmented knowledge, a reliance on manual annotation, and limited semantic mapping to attack techniques. These limitations hinder the robustness and accuracy of downstream reasoning tasks (e.g., attack attribution and intent inference). Moreover, traditional information extraction methods struggle to generalize in scenarios involving cross-paragraph dependencies, emerging threats, and low-resource samples, exhibiting weaknesses in context awareness and sensitivity to prompt variations. To this end, we propose CTI-Thinker, a novel system that integrates large language models with semantic alignment to the ATT&CK framework for CTI knowledge graph construction and threat reasoning. First, CTI-Thinker leverages in-context learning and LoRA-based fine-tuning to extract structured threat entities and relations. Then, it adopts vector-based alignment strategies to unify heterogeneous expressions, enabling entity normalization and knowledge fusion for constructing a high-quality CTI knowledge graph. Finally, a GraphRAG-based reasoning engine is built by incorporating the structured knowledge graph and external ATT&CK resources into a retrieval-augmented generation (RAG) framework, enabling tactical-level inference and CTI-driven question answering. Experimental results demonstrate that CTI-Thinker accurately extracts threat entities and relations and constructs a reliable CTI knowledge graph. It also effectively infers attack intent and supports intelligent reasoning. The system outperforms state-of-the-art methods in precision, robustness, and generalizability, offering a scalable and semantically enriched solution for cyber threat analysis and defense. Graphical abstract
Xiuzhang Yang, Ruijie Zhong, Yuling Chen 0002, Guojun Peng, Dongni Zhang
Cybersecur.1
2026 CTIExpert: Towards expert-level cyber threat intelligence extraction for constructing cybersecurity knowledge graphs
Ruijie Zhong, Yuling Chen 0002, Xiuzhang Yang, Xinyang Zhong, Zhongxiang He
Expert Syst. Appl.3
2026 Dual-Trust Graph Attention Network for Malicious Device Detection in Internet of Things
abstract
Internet of Things (IoT) systems face escalating security threats as the number of connected devices surpassed 18.5 billion in 2024 and is projected to reach 39 billion by 2030. The dynamic and heterogeneous characteristics of IoT networks create vulnerabilities to sophisticated attacks. Existing trust management approaches struggle with these threats due to static graph construction, feature redundancy between direct and indirect trust, and inflexible fusion strategies. This paper proposes a Dual-Trust graph attention network-based malicious device detection method for IoT environments, named DTEM. The proposed scheme constructs dynamic temporal graphs based on real interaction history. Then it designs a completely decoupled dual-trust learning architecture. Finally it introduces a hybrid fusion mechanism. Overall, the improvements significantly enhance the detection accuracy of malicious devices in complex environments and adaptability to heterogeneous scenarios. Experimental results on the UNSW-NB15 dataset demonstrate that DTEM achieves an average F1-Score of 0.973 and ROC-AUC of 0.994 across three threat scenarios, outperforming traditional methods.
Weijie Tan, Zhi Ouyang, Xiuzhang Yang, Yuling Chen 0002, Zhen Li 0036, Gang Xu 0006
IEEE Internet Things J.4
2026 TSGDroid: Trigger Semantic Graph Modeling for Detecting Suspicious Hidden Sensitive Operations
Dongni Zhang, Xiuzhang Yang, Side Liu, Jinwen Xin, Jianming Fu, Guojun Peng
IEEE Internet Things J.2
2026 LCAG: A Lightweight Consensus Algorithm Based on Graph for the Internet of Things
abstract
Consensus algorithms are the core technology of blockchain and a focus in the current distributed system research. The consensus algorithms are widely used in distributed systems, it has solved the decentralization problem. The traditional consensus algorithm needs the process of node legitimacy checking, identity authentication, and primary node view change, so the time cost of reaching an agreement between nodes is still exponential. In response to the problem, a lightweight consensus algorithm based on graph (LCAG) is proposed for the Internet of Things (IoT) in this paper, which is proposes an access control table, and reaches an agreement among nodes by calculating the probability of nodes in the control table, and reduces the time overhead of the reaching an agreement in distributed systems. We have carried out simulation experiments for the new algorithm, and the experiments show that: the new algorithm needs less time overhead than the classical Byzantine algorithm need, as well as Byzantine Generals problem (BGP), practical Byzantine fault-tolerant algorithm (PBFT) and directed acyclic graph (DAG) algorithm, and so on. The new algorithm can be applied to the devices of IoT, which have limited computing power.
Fusheng Wu, Xiuzhang Yang, Yanbin Li 0001, Mingtao Ni, Guangyan Jiang
IEEE Trans. Dependable Secur. Comput.2
2025 FDENet: Improving CTR Prediction via Feature Dynamic Enhancement
abstract
Click-through rate(CTR) prediction is a key task in the fields of e-commerce recommendation and online advertising, which needs to integrate various features of the item side and the user side, and has considerable complexity. Many works have made improvements in feature interaction learning, while a few have focused on improving feature representation. However, these works fail to capture both the feature context information and the contribution of features to CTR prediction task to improve the expression ability of the model. Therefore, to fill this gap, the CTR model for Feature Dynamic Enhancement(FDENet) is proposed. Specifically, for each sample, the model learns context aware feature representation by blending original features and complementary features, learns contribution aware feature representation by selecting salient features, and then combines the two to generate a unique adaptive dynamic feature representation of the sample, thereby achieving feature dynamic enhancement. Moreover, it integrates feature dynamic enhancement with high-order feature interactions into a unified architecture, achieving mutual enhancement and effectively improving the expression ability and prediction performance of the model. Extensive experiments on two real-world datasets show that the proposed model achieves better performance compared to the most relevant and advanced baselines.
Zilong Jiang, Meiyi Wang, Xiang Zuo, Xiuzhang Yang
IJCNN6
2025 A survey on Android dynamic evasive malware: Taxonomy, countermeasures and open challenges
Dongni Zhang, Xiuzhang Yang, Side Liu, Jianming Fu, Guojun Peng
Comput. Secur.2
2025 XLM4Detector: Multistage Deobfuscation and Semantic-Driven Excel 4.0 Macro Malware Detection
abstract
Excel 4.0 Macro leverages XLM code to directly invoke system APIs and automate complex tasks, making it a widely used tool in phishing attacks, APT campaigns, and IoT intrusions in recent years. By constructing various obfuscated macro malware, attackers can easily evade firewalls and detection systems, thereby achieving persistent attacks. However, existing XLM malware defense mechanisms lack in-depth analysis of XLM malware families and behaviors, failing to integrate multi-dimensional features and semantic relationships effectively. As a result, detection systems struggle to accurately identify malicious operations in real-world attacks, leading to low robustness and accuracy. To this end, we propose XLM4Detector, a novel Excel 4.0 Macro malware detection framework based on multi-stage deobfuscation and multi-view semantic fusion. First, XLM4Detector integrates AST analysis, simulated execution, and regular expression matching to construct a multi-stage deobfuscation algorithm, enabling precise deobfuscation and XLM code extraction. Second, we introduce four feature extraction methods that capture fine-grained features at the word (string), token (function), abstract syntax tree, and semantic relationship levels. Then, we design four embedding representations (XlmWord2Vec, XlmToken2Vec, XlmAst2Vec, XlmRela2Vec) and employ a multi-view semantic fusion algorithm for feature alignment. Finally, we develop an MHSACNN-BiGRU model to capture hierarchical semantic relationships, effectively enabling XLM malware behavior detection and family classification. Experimental results demonstrate that XLM4Detector effectively reconstructs obfuscated XLM source code and accurately detects XLM malware families and behaviors. It outperforms state-of-the-art methods in detection accuracy, robustness, and generalization. Our framework provides critical technical support for IoT security defense, malicious document detection, and APT tracking.
Xiuzhang Yang, Yuling Chen 0002, Zhi Ouyang, Guojun Peng
IEEE Internet Things J.1
2025 MODFuzz: A Multiobjective Directed Fuzzer for USB Drivers
abstract
USB interfaces have become ubiquitous in various Internet of Things (IoT) devices, all adhering to the same universal serial bus (USB) protocol. While enhancing convenience, they also widen the potential attack surface. Fuzzing is a proactive way to identify potential security threats for USB drivers. However, existing USB driver fuzzers primarily prioritize the code coverage of USB drivers, leading to a significant waste of computational resources on irrelevant code segments. To this end, we combine directed fuzzing and USB driver fuzzing for the first time, and present multiobjective directed fuzzer (MODFuzz), a pioneering multiobjective directed fuzzing method for USB drivers. MODFuzz autonomously locates the most vulnerable parts within USB drivers, concentrating fuzzing efforts on these areas. Diverging from the existing directed fuzzers, MODFuzz employs a dynamic direction instead of predetermined addresses to guide the fuzzing campaign toward the triggered execution traces with a greater probability of containing vulnerabilities. MODFuzz outperforms the strong baseline in terms of execution speed (about 14% improvement) and crash generation capabilities (about 69% improvement). Meanwhile, we found six previously unknown bugs (all confirmed and assigned vulnerability IDs) in Linux kernel v6.4.10 and received acknowledgment from Red Hat.
Guojun Peng, Xingliang Wang, Zichuan Li, Side Liu, Xiuzhang Yang, Jianming Fu
IEEE Internet Things J.8
2025 Privacy-Enhanced High-Fidelity Separable Lossless Reversible Data Hiding
abstract
Obtaining commercial value of private information from big data has become commonplace, which leads to misuse of information knowledge as well as violation of information owners’ rights, and curbing such behaviors has become a challenge. In this paper, we design an embedding scheme that can be applied to privacy protection of secret information, i.e., embedding confidential information such as copyright as secret information in cover images. The secret information is divided into multiple clusters, encrypted and compressed through the use of multiple-zone folding method to optimize the embedding efficiency and minimize the distortion caused by the embedding process, it realizes the privacy feature of traceability and security protection of secret information in circulation. Evaluated by security analysis and experimental results, this proposed scheme achieves IND-CPA high information security level for information protection. Compared with the state-of-the-art scheme, the computational complexity of this proposed scheme isO(Y) (Ydenotes the total number of pixels), at least 6 bits of information can be embedded per pixel which improves the efficiency of embedding. In terms of the impact on the quality of cover image information after the embedding of secret information, it has better performance, and improves the manageable traceability of information.
Yuling Chen 0002, Zhi Ouyang, Weijie Tan, Xiuzhang Yang
IEEE Trans. Inf. Forensics Secur.5