EDBT 2026 Demo / reviewers in the wild / expert
Shuijun Yin
dblp:226/3733
· DBLP profile ↗
5ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0006-8185-0999ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving the transferability of targeted adversarial examples by style-agnostic attack
Zimin Mao, Shuijun Yin, Hanwen Zhang 0016, Heng Li 0008, Tiejun Wu, Wei Yuan 0001 |
Comput. Secur. | 3 |
| 2023 | Detecting Android Malware With Pre-Existing Image Classification Neural NetworksabstractAndroid malware detection has attracted increasing attention due to the rapid growth of mobile malware. However, running an in-cloud Android malware detection system usually incurs high hardware and bandwidth costs. This dilemma motivates us to develop a method to repurpose an in-cloud image-classification neural network to detect Android malware. Given an Android app, the proposed method first embeds its features into an image, skillfully perturbs the feature-embedded image, and then feeds the modified image into the in-cloud image classifier. The classifier's outputs are finally mapped into a malware detection result. In addition, two new techniques (perturbation hiding and group mapping) are proposed to reduce the risk of repurposing behavior being recognized and improve detection performance. Experiments show that our perturbations are usually imperceptible to humans, and our method outperforms both traditional machine learning-based detectors and deep learning-based detectors in detection performance. Shuijun Yin, Heng Li 0008, Minghui Cai, Wei Yuan 0001 |
IEEE Signal Process. Lett. | 2 |
| 2023 | Obfuscation-Resilient Android Malware Analysis Based on Complementary FeaturesabstractExisting Android malware detection methods are usually hard to simultaneously resist various obfuscation techniques. Therefore, bytecode-based code obfuscation becomes an effective means to circumvent Android malware analysis. Building obfuscation-resilient Android malware analysis methods is a challenging task, due to the fact that various obfuscation techniques have vastly different effects on code and detection features. To mitigate this problem, we propose combining multiple features that are complementary in combating code obfuscation. Accordingly, we develop an obfuscation-resilient Android malware analysis methodCorDroid, based on two new features: Enhanced Sensitive Function Call Graph (E-SFCG) and Opcode-based Markov transition Matrix (OMM). The first describes sensitive function call relationships, while the second reflects transition probabilities among opcodes. Combining E-SFCG and OMM can well characterize the runtime behavior of Android apps from different perspectives, hence increasing the difficulty of misleading malware analysis through using code obfuscation to affect detection features. To evaluate CorDroid, we generate 74,138 obfuscated samples with 14 different obfuscation techniques, and compare CorDroid with the state-of-the-art detection methods (e.g., MaMaDroid, RevealDroid and APIGraph). In terms of average F1-Score, CorDroid is 29.69% higher than MaMaDroid, 21.80% higher than APIGraph, and 9.71% higher than RevealDroid, respectively. Experiments also validate the complementarity between E-SFCG and OMM, and exhibit the high execution efficiency of CorDroid. Cuiying Gao, Minghui Cai, Shuijun Yin, Gaozhun Huang, Heng Li 0008, Wei Yuan 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Resisting DNN-Based Website Fingerprinting Attacks Enhanced by Adversarial TrainingabstractDeep neural network (DNN) based website fingerprinting (WF) attacks pose a severe threat to the privacy of Tor users. To overcome this challenge, adversarial perturbation based WF defenses have been recently proposed to fool the classifiers of attackers, through purposefully perturbing the user’s traffic traces. Unfortunately, these defenses significantly deteriorate once the WF attacks are enhanced withadversarial training(AT). AT endows the WF attacks with more powerful website recognition capability, through learning the perturbed traffic traces generated by attackers. To resist the WF attacks enhanced by AT, we develop ablack-boxWF defense, called Acup3. First, Acup3 leveragesmany-to-one website imitationto make the traffic traces associated with different websites look more like each other, increasing the difficulty of website classification. Second, Acup3 generatestrace-agnosticperturbations without accessing traffic traces, making it suitable for practical deployment. Third, Acup3 employsperturbation variationto diversify the traffic traces of different users visiting the same website, making the knowledge learnt from AT less helpful for WF attacks. Therefore, Acup3 is more robust against AT. Experiments demonstrate Acup3 markedly surpasses four representative WF defenses (e.g., Mockingbird and AWA) in defense capability and bandwidth overhead. Facing the state-of-the-art (SOTA) attack Var-CNN enhanced with AT, Acup3 depresses its attack success rate (ASR) from 98% to 24.29% with only 13.95% bandwidth overhead. Compared to the SOTA defense AWA, Acup3 causes a 24.5% larger decrement in ASR of WF attacks, and achieves a more than 100 times faster speed of perturbation generation. Litao Qiao, Bang Wu 0002, Shuijun Yin, Heng Li 0008, Wei Yuan 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | A lightweight authentication scheme with privacy protection for smart grid communications
Liping Zhang 0003, Lanchao Zhao, Shuijun Yin, Chihung Chi |
Future Gener. Comput. Syst. | 3 |