Weijie Han

dblp:231/5089 · DBLP profile ↗
← Back
12ranked-venue papers
5as first author
9since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 A Survey on Malware Analysis with Large Language Models
Wenjie Guo, Haoyuan Wen, Lingming Kong, Jingfeng Xue, Weijie Han, Yong Wang 0010
KSEM (6)6
2025 MalFSLDF: A Few-Shot Learning-Based Malware Family Detection Framework
abstract
The evolution of malware has led to the development of increasingly sophisticated evasion techniques, significantly escalating the challenges for researchers in obtaining and labeling new instances for analysis. Conventional deep learning detection approaches struggle to identify new malware variants with limited sample availability. Recently, researchers have proposed few‐shot detection models to address the above issues. However, existing studies predominantly focus on model‐level improvements, overlooking the potential of domain adaptation to leverage the unique characteristics of malware. Motivated by these challenges, we propose a few‐shot learning‐based malware family detection framework (MalFSLDF). We introduce a novel method for malware representation using structural features and a feature fusion strategy. Specifically, our framework employs contrastive learning to capture the unique textural features of malware families, enhancing the identification capability for novel malware variants. In addition, we integrate entropy graphs (EGs) and gray‐level co‐occurrence matrices (GLCMs) into the feature fusion strategy to enrich sample representations and mitigate information loss. Furthermore, a domain alignment strategy is proposed to adjust the feature distribution of samples from new classes, enhancing the model’s generalization performance. Finally, comprehensive evaluations of the MaleVis and BIG‐2015 datasets show significant performance improvements in both 5‐way 1‐shot and 5‐way 5‐shot scenarios, demonstrating the effectiveness of the proposed framework.
Wenjie Guo, Jingfeng Xue, Wenbiao Du, Ning Shi, Weijie Han
Int. J. Intell. Syst.7
2025 TransfficFormer: A novel Transformer-based framework to generate evasive malicious traffic
Wenbiao Du, Jingfeng Xue, Xiuqi Yang, Wenjie Guo, Dujuan Gu, Weijie Han
Knowl. Based Syst.6
2025 Malgta: large language model-based guided malware tactical analysis
Wenjie Guo, Jingfeng Xue, Weijie Han
J. Supercomput.4
2024 Certificate-Based Transport Layer Security Encrypted Malicious Traffic Detection in Real-Time Network Environments
Yiran Suo, Jingfeng Xue, Wenjie Guo, Wenbiao Du, Weijie Han
ICA3PP (1)5
2022 A 200mA-Load 0.62fs-FOM Active-Capacitor-Assisted Dual-loop Output Capacitorless Low-Dropout Regulator in Standard 65nm CMOS
abstract
This paper presents a new active-capacitor-assisted dual-loop output-capacitorless low-dropout regulator (OCLDO). As opposed to the conventional PMOS-based OCLDOs where the current load range is limited due to significant output variations under large load step changes, a dual-loop control scheme is proposed to improve the slew rates at transient-critical nodes and the regulation accuracy. To further speed up the loop response, a single-point-detection (SPD) active capacitor located at the output detects both positive and negative output variation together and reduces undershoot/overshoot and settling time without using any passive output capacitor. Implemented in a standard 65nm CMOS process, the proposed OCLDO delivers a maximum load current of 200mA. It only uses a small compensation capacitor of 0.86pF and achieves fast settling time of 110ns. It also has small undershoot / overshoot voltages of ≤ 160mV under load step changes of 200mA/100ns. Compared with previous designs, this work presents a fully on-chip PMOS OCLDO that provides the best transient FOM of 0.62fs.
Weijie Han, Chen Chen 0154, Jin Liu 0004, Hoi Lee
ISCAS1
2022 MaliCage: A packed malware family classification framework based on DNN and GAN
Xianwei Gao, Changzhen Hu, Chun Shan, Weijie Han
J. Inf. Secur. Appl.4
2021 APTMalInsight: Identify and cognize APT malware based on system call information and ontology knowledge framework
abstract
APT attacks have posed serious threats to the security of cyberspace nowadays which are usually tailored for specific targets. Identification and understanding of APT attacks remains a key issue for society. Attackers often utilize malware as the weapons to launch cyber-attacks. For this reason, detecting APT malware and gaining an insight of its malicious behaviors can strengthen the power to understand and counteract APT attacks. Based on the above motivation, this paper proposes a novel APT malware detection and cognition framework named APTMalInsight aiming at identifying and cognizing APT malware by leveraging system call information and ontology knowledge. We systematically study APT malware and extracts dynamic system call information to describe its behavioral characteristics. With respect to the established feature vectors, the APT malware can be detected and clustered into their belonging families accurately. Furthermore, a horizontal comparison between APT malware and the traditional malware is conducted from the perspective of behavior types, to understand the behavioral characteristics of APT malware in depth. On the above basis, the ontology model is introduced to construct the APT malware knowledge framework to represent its typical malicious behaviors, thereby implementing the systematic cognition of APT malware and providing contextual understanding of APT attacks. The evaluation results based on real APT malware samples demonstrate that the detection and clustering accuracy can reach up to 99.28% and 98.85% respectively. In addition, APTMalInsight supplies an effective cognition framework for APT malware and enhances the capability to understand APT attacks.
Weijie Han, Jingfeng Xue, Yong Wang 0010, Xianwei Gao
Inf. Sci.1
2021 An ultrahigh-resolution image encryption algorithm using random super-pixel strategy
Wei Zhang 0150, Weijie Han, Zhiliang Zhu 0001, Hai Yu 0001
Multim. Tools Appl.2
2019 MalDAE: Detecting and explaining malware based on correlation and fusion of static and dynamic characteristics
abstract
It is a wide-spread way to detect malware by analyzing its behavioral characteristics based on API call sequences. However, previous studies usually just focus on its static or dynamic API call sequence, while neglecting the correlation between them. Our experimental results show that there exists an underlying relation between the dynamic and static API call sequences of malware. The relation can be described as “the syntax is different, but the semantics is similar”. Based on this discovery, this paper first attempts to explore the difference and relation between the static and dynamic API sequences of malicious programs. We correlate and fuse their dynamic and static API sequences into one hybrid sequence based on semantics mapping and then construct the hybrid feature vector space. Furthermore, we mine and define the malicious behavior types of the programs, and provide explainable results for malware detection. Our study has addressed the shortcoming of the previous approaches that they usually pay attention to detection but neglect explanation. By correlation and fusion of the static and dynamic API sequences, we establish an explainable malware detection framework, called MalDAE. The evaluation results show that the detection and classification accuracy of MalDAE can reach up to 97.89% and 94.39% respectively outperforming the previous similar studies by comprehensive comparison. In addition, MalDAE gives an understandable explanation for common types of malware and provides predictive support for understanding and resisting malware.
Weijie Han, Jingfeng Xue, Yong Wang 0010, Lu Huang 0002, Zixiao Kong, Limin Mao
Comput. Secur.1
2019 Detecting anomalous traffic in the controlled network based on cross entropy and support vector machine
abstract
Network anomaly detection is an effective way for analysing and detecting malicious attacks. However, the typical anomaly detection techniques cannot perform the desired effect in the controlled network just as in the general network. In the circumstance of the controlled network, the detection performance will be lowered due to its special characteristics including the stronger regularity, higher dimensionality and subtler fluctuation of its traffic. On the motivation, the study proposes a novel classifier framework based on cross entropy and support vector machine (SVM). The technique first subtracts the representative traffic characteristics from the network traffic and defines a 7‐tuple feature vector for the controlled network by extending the traditional 5‐tuple representation of the usual network. Then the probability distributions and cross entropies of the 7 tuples are calculated during the defined statistical window so as to generate the 7‐tuple cross‐entropy feature vector for profiling the network traffic fluctuation in the controlled network. Finally, the multi‐class SVM classifier is trained by importing the 7‐tuple cross‐entropy feature vectors. Experimental results show that the proposed classifier can achieve higher detection rates and is more suitable to be used in the controlled network than the typical detection techniques.
Weijie Han, Jingfeng Xue
IET Inf. Secur.1
2019 MalInsight: A systematic profiling based malware detection framework
abstract
To handle the security threat faced by the widespread use of Internet of Things (IoT) devices due to the ever-lasting increase of malware, the security researchers increasingly rely on machine learning techniques based on various static and/or dynamic features. Unfortunately, the state-of-the-art detection techniques may fail to identify the malware effectively because the malware is often obfuscated to camouflage its characteristics and thwart the analysis process. In order to identify the disguised malware accurately, a malware detection framework named MalInsight is proposed by profiling malware from three aspects which are basic structure, low-level behavior, and high-level behavior. These aspects reflect the structural features, the underlying operations interacting with the OS, and the operations on the files, the registry, and the network respectively. Based on the above findings, an accurate and rich feature space is built which enables to depict and detect malware more effectively. In order to validate the effectiveness of MalInsight, an extensive experiment is conducted on a real-world malware dataset. Our experimental results show that MalInsight can detect not only obfuscated malware instances with an accuracy of 99.76% but also unseen and new malware with an accuracy of 97.21%. Furthermore, MalInsight can classify the malware samples into their families with an accuracy of 94.2% outperforming the typical detection approach based on the API sequence as the dynamic behavior features by almost 9%. In addition, the importance of the three aspects is evaluated and sorted quantitatively demonstrating that these aspects play the same effects with the optimal feature set.
Weijie Han, Jingfeng Xue, Yong Wang 0010, Zhenyan Liu, Zixiao Kong
J. Netw. Comput. Appl.1