EDBT 2026 Demo / reviewers in the wild / expert
Bang Wu 0002
dblp:220/9034-2
· DBLP profile ↗
6ranked-venue papers
0as first author
6since 2021 · last 2026
0009-0008-2218-3991ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Why Not Diversify Triggers? APK-Specific Backdoor Attack Against Android Malware DetectionabstractMachine learning-based Android malware detection (AMD) models require abundant data for training robust app classifiers, creating vulnerability to poisoning attacks. Attackers inject poisoned samples into Android app markets, leading to the insertion of a backdoor into the model upon adoption in the training process. Subsequently, attackers can generate evasive malware by embedding a backdoor trigger in malware samples. Currently, research on backdoor attacks towards AMD has just begun to emerge. Existing attacks produce a fixed trigger and apply it to various malware. Once the trigger is discovered by static analysis methods (e.g., software similarity analysis), however, multiple malware carrying this trigger will be simultaneously exposed. To diversify the trigger, we propose anAPK-SpecificBackdoorAttack algorithm (ASBA), which trains a generative adversarial network to generate a specific trigger for every malware sample. Moreover, ASBA manages to make the generated triggers as different as possible, in order to further reduce the likelihood of malware being collectively captured. Extensive experiments have demonstrated that ASBA achieves a 94.6% average attack success rate (ASR) on three datasets, five feature extraction methods and three classification models. Furthermore, compared to state-of-the-art poisoning attack algorithms, ASBA produces more diverse and more effective triggers. Heng Li 0008, Bang Wu 0002, Cuiying Gao, Wei Yuan 0001, Beihao Xia, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Automated Mass Malware Factory: The Convergence of Piggybacking and Adversarial Example in Android Malicious Software Generation
Heng Li 0008, Bang Wu 0002, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
NDSS | 3 |
| 2025 | An Efficient Adversarial Attack on FCG-Based Android Malware Detection Systems
Heng Li 0008, Bang Wu 0002, Wei Yuan 0001, Cuiying Gao, Xinge You, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Trace-agnostic and Adversarial Training-resilient Website Fingerprinting DefenseabstractDeep neural network (DNN) based website fingerprinting (WF) attacks can achieve an attack success rate (ASR) of over 90%, seriously threatening the privacy of Tor users. At present, adversarial example (AE) based defenses have demonstrated great potential to defend against WF attacks. However, existing AE-based defenses require knowing a complete traffic trace for adversarial perturbation calculation, which is unrealistic in practice. Moreover, they may become ineffective once adversarial training (AT) is adopted by attackers. To mitigate these two problems, we propose a defense called ALERT. It generates adversarial perturbations without knowing traffic traces, and can effectively resist AT-aided WF attacks. The key idea of ALERT is to produce universal perturbations that vary from user to user. We conduct extensive experiments to evaluate ALERT. In the closed world, ALERT significantly surpasses four representative WF defenses, including the state-of-the-art (SOTA) defense AWA. Specifically, ALERT reduces the ASR of the SOTA DF attack to 12.68% and uses only 20.13% of communication bandwidth. In the open world, ALERT uses only 19.91% of bandwidth, reduces the True Positive Rate (TPR) of the DF attack to 37.46%, obviously outperforming the other defenses. Litao Qiao, Bang Wu 0002, Heng Li 0008, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
INFOCOM | 2 |
| 2023 | Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature Information
Heng Li 0008, Zhang Cheng, Bang Wu 0002, Liheng Yuan, Cuiying Gao, Wei Yuan 0001, Xiapu Luo |
USENIX Security Symposium | 3 |
| 2023 | Resisting DNN-Based Website Fingerprinting Attacks Enhanced by Adversarial TrainingabstractDeep neural network (DNN) based website fingerprinting (WF) attacks pose a severe threat to the privacy of Tor users. To overcome this challenge, adversarial perturbation based WF defenses have been recently proposed to fool the classifiers of attackers, through purposefully perturbing the user’s traffic traces. Unfortunately, these defenses significantly deteriorate once the WF attacks are enhanced withadversarial training(AT). AT endows the WF attacks with more powerful website recognition capability, through learning the perturbed traffic traces generated by attackers. To resist the WF attacks enhanced by AT, we develop ablack-boxWF defense, called Acup3. First, Acup3 leveragesmany-to-one website imitationto make the traffic traces associated with different websites look more like each other, increasing the difficulty of website classification. Second, Acup3 generatestrace-agnosticperturbations without accessing traffic traces, making it suitable for practical deployment. Third, Acup3 employsperturbation variationto diversify the traffic traces of different users visiting the same website, making the knowledge learnt from AT less helpful for WF attacks. Therefore, Acup3 is more robust against AT. Experiments demonstrate Acup3 markedly surpasses four representative WF defenses (e.g., Mockingbird and AWA) in defense capability and bandwidth overhead. Facing the state-of-the-art (SOTA) attack Var-CNN enhanced with AT, Acup3 depresses its attack success rate (ASR) from 98% to 24.29% with only 13.95% bandwidth overhead. Compared to the SOTA defense AWA, Acup3 causes a 24.5% larger decrement in ASR of WF attacks, and achieves a more than 100 times faster speed of perturbation generation. Litao Qiao, Bang Wu 0002, Shuijun Yin, Heng Li 0008, Wei Yuan 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 2 |