Jiahong Yang 0003

dblp:218/8247-3 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 5 since 2021Security and privacy · 3 · 3 since 2021
YearPublicationVenuePosition
2025 GET-AID: Graph-Enhanced Transformer for Provenance-Based Advanced Persistent Threats Investigation and Detection
Fengyuan Xu, Jiahong Yang 0003, Wenting Li 0002, Zonghua Zhang, Chenbin Zhang, Meng Ma 0001, Ping Wang 0003
ESORICS (4)3
2025 Personalized Password Guessing via Modeling Multiple Leaked Credentials of the Same User
Fugeng Huang, Jiahong Yang 0003, Haibo Cheng 0001, Wenting Li 0002, Ping Wang 0003
ESORICS (3)2
2025 Username-Password Models Beyond Traditional Password Guessability Assessment
abstract
Passwords are widely used for website authentication, but they are vulnerable to guessing attacks. To measure password guessability, the commonly used approach involves modeling the distribution of passwords with a password probability model and then estimating the guessability using Monte Carlo methods based on the model. We found that users’ passwords are closely linked to their usernames. However, few password models proposed by previous research consider this connection, which significantly overestimates the security of passwords and can result in inadequate security measures, potentially leading to data breaches and financial losses. In this paper, we propose a new category of password model called username-password model, which models the conditional probability of passwords given usernames. We also provide an instance of the username-password model using Transformer (TUPM). The experimental results of guessing attacks show that TUPM outperforms other password models in terms of crack rate across any number of guesses (up to 1020). Notably, TUPM cracks 100%–175% more passwords compared to the state-of-the-art models, within the first 1,000 guesses. This indicates that TUPM can provide a more accurate estimation of password guessability.
Jiahong Yang 0003, Wenting Li 0002, Haibo Cheng 0001, Ping Wang 0003
ICASSP1
2025 Targeted Password Guessing Using Neural Language Models
abstract
With the increasing prevalence of personal information breaches, targeted password guessing based on user-specific data has emerged as a serious security threat. Existing targeted password guessing attacks primarily rely on traditional statistical language models, which have limited capability in addressing the complexities of password structures and user behavior. Recent advancements in neural language models, particularly Transformer-based architectures, have achieved significant success in natural language processing tasks by capturing complex patterns and dependencies. However, their potential for improving targeted password guessing remains largely unexplored.To address this gap, we conduct a systematic evaluation of several widely used neural language models from NLP and assess their effectiveness in targeted password guessing. Experimental results on multiple real-world password datasets show that neural language models outperform existing approaches. Our proposed models achieve an improvement of 1.4%–4.6% compared to RFGuess-PII model, and 18%–40% compared to TarPCFG model. This work provides new insights into the potential of neural language models to enhance the effectiveness of targeted password guessing attacks.
Jiahong Yang 0003, Wenting Li 0002, Haibo Cheng 0001, Ping Wang 0003
ICASSP1
2025 Adaptive Password Guessing Framework Using Various Datasets
abstract
Password guessing attack is a significant threat to account security. Understanding this attack is crucial for identifying the vulnerabilities of current password systems and for developing more effective methods to protect user accounts. Adaptive password guessing techniques can dynamically adjust their strategies based on cracked passwords, resulting in improved performance under varying password distributions. However, existing adaptive password guessing models are typically trained on a single password dataset and attempt to crack a target website through dynamic adjustments. In recent years, the number of leaked password datasets has increased significantly. To fully leverage the diversity of various datasets and accurately assess the threat of password guessing, we propose an adaptive password guessing framework that employs a transformer architecture capable of learning multiple password distributions from various datasets and generate password guesses adaptively for the target. Through experiments involving 29 real-world leaked password datasets, we demonstrate that our framework achieves an average improvement of 44.63% over the state-of-the-art adaptive password guessing models.
Haibo Cheng 0001, Mingli Zheng, Jiahong Yang 0003, Ping Wang 0003
ICASSP4
2025 To Learn Better Character Embeddings in Generative Models for Password Attack
abstract
Variational Autoencoder (VAE) has been used as password generative model for trawling attack in multiple works. Its sample distribution can be easily changed by controling the mean and variance of the prior distribution, which makes it natively suitable for dynamic attack scenario. Combining transformer blocks with VAE can achieve better performance since attention mechanisms can handle sequence data better. But such design is unstable for password generation tasks. The encoder-decoder model tends to degrade into decoder-only model due to the KL vanishing problem, making it hard to train. To handle this problem, we performed an in-depth analysis and proposed a new transformer-based VAE model specifically designed for password generation. It out-performs former encoder-decoder generative model by 4%–15% in cracking rate. Moreover, we make an improvement to dynamic attack by using a 3-period strategy, with which our method becomes competitive with probabilistic ordered attack models such as PCFG [11] and FLA [8].
Mingli Zheng, Haibo Cheng 0001, Jiahong Yang 0003, Ping Wang 0003
ICASSP3
2025 Practically Secure Honey Password Vaults: New Design and New Evaluation against Online Guessing
Haibo Cheng 0001, Fugeng Huang, Jiahong Yang 0003, Wenting Li 0002, Ping Wang 0003
USENIX Security Symposium3
2023 Improved Wordpcfg for Passwords with Maximum Probability Segmentation
abstract
Modeling password distributions is a fundamental problem in password security, benefiting the research and applications on password guessing, password strength meters, honey password vaults, etc. As one of the best segment-based password models, WordPCFG has been proposed to capture individual semantic segments (called words) in passwords. However, we find WordPCFG does not address well the ambiguity of password segmentation by maximum matching, leading to the unreasonable segmentation of many password and further the inaccuracy of modeling password distributions. To address the ambiguity, we improve WordPCFG by maximum probability segmentation with A*-like pruning algorithm. The experimental results show that the improved WordPCFG cracks 99.26%–99.95% passwords, with nearly 5.67%–18.01% improvement.
Wenting Li 0002, Jiahong Yang 0003, Haibo Cheng 0001, Ping Wang 0003, Kaitai Liang
ICASSP2