Guangsong Li

dblp:23/2536 · DBLP profile ↗
← Back
12ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0001-8251-0634ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 since 2021Systems, architecture and hardware · 3 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 UI2C: An Adaptive Boundary Learning Method for Imbalanced Malicious Traffic Detection
Qingjun Yuan, Yanbei Zhu, Yongjuan Wang, Guangsong Li
ICIC (11)5
2026 When Unknown Threat Meets Label Noise: A Self-Correcting Framework
abstract
Network intrusion detection systems (NIDS) are crucial for network management and security. However, in real-world scenarios, NIDS faces two core challenges: (i) label noise, where mislabeled samples in the training data distort the model's decision boundaries; (ii) unknown attack detection, where existing methods struggle to identify novel attack patterns in dynamic attack environments. More critically, these two challenges are interlinked, forming a vicious cycle that continuously degrades the overall reliability of NIDS. Existing research often addresses these issues in isolation, and no method has yet been proposed to coordinate their antagonistic effects systematically. To tackle this open problem, we propose AEGIS-Net for the first time—a dual anti-noise framework based on multi-prototype correction and model-agnostic detection. AEGIS-Net introduces a density-difference-driven multi-prototype competition mechanism, which achieves fine-grained noise label correction through feature space sub-cluster analysis. We also design a distribution-independent k-nearest neighbors detection paradigm, using the corrected compact feature space to determine unknown attacks in open environments. The two modules are collaboratively optimized through a shared encoder, forming a positive cycle of noise suppression and detection enhancement. Extensive experiments on real-world datasets validate the effectiveness of AEGIS-Net in addressing these dual challenges. Notably, under 50% asymmetric noise conditions, AEGIS-Net achieves classification accuracy of 89.02% for known attacks and 98.76% for unknown attack detection on the MAL_TLS2023 dataset. Theoretical proofs and visualization analysis reveal the anti-noise properties of AEGIS-Net under feature space stability constraints. Our code is available athttps://github.com/niebikong/AEGIS-Net.
Qianwei Meng, Qingjun Yuan, Pinghui Wang, Siqi Lu, Guangsong Li, Yongjuan Wang, Xiaohong Guan
IEEE Trans. Dependable Secur. Comput.6
2025 Beyond known threats: A novel strategy for isolating and detecting unknown malicious traffic
Qianwei Meng, Qingjun Yuan, Xiangbin Wang, Yongjuan Wang, Guangsong Li, Yanbei Zhu, Siqi Lu
J. Inf. Secur. Appl.5
2025 Detection of Unknown Attacks Through Encrypted Traffic: A Gaussian Prototype-Aided Variational Autoencoder Framework
abstract
The identification of encrypted network traffic presents a pivotal challenge in detecting unknown malicious traffic. Unlike closed-set identification, which primarily classifies known traffic classes, detecting unknown malicious traffic necessitates both accurate classification of known traffic and the identification of previously unseen traffic classes. Existing methods often face difficulties in effectively constraining the distribution size of known classes in the representation space and frequently misclassifying unknown classes as known. To address these challenges, we propose Open-Detect, a robust theoretical framework for detecting unknown malicious traffic, which leverages advanced deep learning techniques, such as variational autoencoders and Gaussian prototypes. Open-Detect introduces two primary constraints: a generative constraint, which enhances intra-class compactness, and a discriminative constraint, which optimizes inter-class separation. These constraints collectively mitigate the risks of misclassifying known classes and failing to detect unknown classes. In Open-Detect, network flows are transformed into grayscale images, and each known traffic class is mapped to a unique Gaussian prototype in the latent space. This design ensures tight clustering of samples within the same class and clear separation of samples between different classes. The detection of unknown malicious traffic is performed based on the distance between samples and these prototypes. Extensive experiments conducted on multiple publicly available datasets substantiate the efficacy of Open-Detect. The results reveal significant improvements in intra-class compactness and inter-class separation, enabling superior performance in both closed-world and open-world scenarios, particularly for detecting unknown malicious traffic. Our code is available at: https://github.com/niebikong/Open-Detect.
Qianwei Meng, Qingjun Yuan, Guangsong Li, Yongjuan Wang, Siqi Lu
IEEE Trans. Inf. Forensics Secur.4
2025 IIT: Accurate Decentralized Application Identification Through Mining Intra- and Inter-Flow Relationships
abstract
Identifying Decentralized Applications (DApps) from encrypted network traffic plays an important role in areas such as network management and threat detection. However, DApps deployed on the same platform use the same encryption settings, resulting in DApps generating encrypted traffic with great similarity. In addition, existing flow-based methods only consider each flow as an isolated individual and feed it sequentially into the neural network for feature extraction, ignoring other rich information introduced between flows, and therefore the relationship between different flows is not effectively utilized. In this study, we propose a novel encrypted traffic classification model IIT to heterogeneously mine the potential features of intra- and inter-flows, which contain two types of encoders based on the multi-head self-attention mechanism. By combining the complementary intra- and inter-flow perspectives, the entire process of information flow can be more completely understood and described. IIT provides a more complete perspective on network flows, with the intra-flow perspective focusing on information transfer between different packets within a flow, and the inter-flow perspective placing more emphasis on information interaction between different flows. We captured 44 classes of DApps in the real world and evaluated the IIT model on two datasets, including DApps and malicious traffic classification tasks. The results demonstrate that the IIT model achieves a classification accuracy of greater than 97% on the real-world dataset of 44 DApps, outperforming other state-of-the-art methods. In addition, the IIT model exhibits good generalization in the malicious traffic classification task.
Qianwei Meng, Qingjun Yuan, Weina Niu, Yongjuan Wang, Siqi Lu, Guangsong Li, Xiangbin Wang, Wenqi He
IEEE Trans. Netw. Serv. Manag.6
2024 SyntaxBridge: Protocol Description Transformer for Enhanced Formal Analysis of Security Protocols
Liujia Cai, Siqi Lu, Hanjie Dong, Guangying Cai, Guangsong Li, Yongjuan Wang
TrustCom7
2024 Observational equivalence and security games: Enhancing the formal analysis of security protocols
Liujia Cai, Guangying Cai, Siqi Lu, Guangsong Li, Yongjuan Wang
Comput. Secur.4
2022 Modelization and analysis of dynamic heterogeneous redundant system
abstract
Summary With the development and popularization of Internet technology, network security has become the focus of attention. Vulnerabilities and back doors are regarded as two of the main reasons of network security problems. Dynamic heterogeneous redundant (DHR) architecture is a typical framework of cyberspace mimic defense. It can make use of untrusted hardware and software components to construct a high reliable and high security information system. In this article, a mathematical model is set up for the DHR architecture, and the system security is characterized by vulnerability consistency rate and success rate of system attack. The antiattack ability of the DHR system is analyzed using the mathematical model.
Guangsong Li, Keke Gai, Yazhe Tang, Benchao Yang, Xueming Si
Concurr. Comput. Pract. Exp.2
2021 A fine-grained anonymous handover authentication protocol based on consortium blockchain for wireless networks
Guangsong Li, Siqi Lu
J. Parallel Distributed Comput.1
2018 A Novel Multiserver Authentication Protocol with Multifactors for Cloud Service
abstract
Secure and efficient authentication protocols are necessary for cloud service. Multifactor authentication protocols taking advantage of smart card, user’s password, and biometric, are more secure than password-based single-factor authentication protocols which are widely used in practice. However, most of the multiserver authentication protocols may have weak points, such as smart card loss attack, man-in-the-middle attack, anonymity, and high computation cost of authentication center. In order to overcome the above weaknesses, we propose a novel multiserver multifactor authentication protocol based on the Kerberos protocol using the extended Chebyshev chaotic mapping as a cryptographic algorithm. The proposed protocol achieves anonymity without sharing secret keys in advance and needs the user to register with the authentication center only once. Finally, we prove the security of the new protocol with BAN logic and compare it with other multifactor authentication protocols for multiserver environment. The results show that our proposed protocol is more secure and efficient and better for practical application.
Jian Song 0002, Guangsong Li, Bo-ru Xu, Chuangui Ma
Secur. Commun. Networks2
2018 Attribute-Based Anonymous Handover Authentication Protocol for Wireless Networks
abstract
Mobile wireless networks are widely used in our daily lives. Seamless handover occurs frequently and how to guarantee security and efficiency during handover procedure is a major challenge. A handover authentication protocol with nice properties can achieve goals. Protocols proposed in recent years more or less have some security vulnerability. In this paper, we outline security requirements for handover authentication protocols and then propose an anonymous protocol based on a new attribute-based signature scheme. The proposed protocol realizes conditional privacy preserving, user revocation, and session key update as well as mutual authentication and anonymity. Besides, it achieves fine-grained access control due to attributes representing real identity. What is more, experiment shows the proposed protocol has a superior performance.
Yongbin Zeng, Hui Guang, Guangsong Li
Secur. Commun. Networks3
2011 A novel re-authentication scheme based on tickets in wireless local area networks
Guangsong Li, Jianfeng Ma 0001, Qi Jiang 0001
J. Parallel Distributed Comput.1