EDBT 2026 Demo / reviewers in the wild / expert
Chengshang Hou
dblp:241/0259
· DBLP profile ↗
18ranked-venue papers
5as first author
15since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 6 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhanced Dynamics of IP Allocation: Fine-Grained IP Geolocation via Temporal-Spatial Correlation
Gang Xiong 0001, Gaopeng Gou, Chengshang Hou, Jing Yu 0007 |
IEEE Trans. Netw. | 4 |
| 2025 | Splash: Adversarial Defense with Short Perturbation Blocks Against Adversarial Training Aided Website FingerprintingabstractAdversarial perturbation generation allows network users to mislead website fingerprinting (WF) classifiers without compromising real-time transmission or data integrity, causing misclassification. However, adversarial perturbations are vulnerable to adversarial training (AT), which enables attackers to improve their classifiers using perturbed adversarial samples, rendering user defenses ineffective. Due to reliance on real and non-redundant data, existing defenses against AT fail to scale to large-scale user scenarios. This paper proposes an improved adversarial perturbation generation method named Splash, which mitigates performance degradation caused by defense configuration collisions in traditional AT-aided attack defenses by applying two real-time traffic obfuscation steps using both global adversarial perturbations and Short Perturbation Blocks placed at random positions. Evaluation shows that Splash performs better traffic obfuscation than three other representative defenses, causing attacker classifiers to misclassify over 97% of traffic. In addition, it offers enhanced functionality by causing 45-60% of traffic to be misclassified into arbitrary target classes. Splash outperforms SOTA defenses such as AWA and ALERT against AT-aided attacks, reducing success rates to below 30%. Furthermore, it demonstrates significantly stronger resilience when attackers adopt the same defense configurations as users. Runsheng Ma, Chengshang Hou, Gaopeng Gou, Junzheng Shi, Zhen Li 0011, Gang Xiong 0001 |
ACSAC | 2 |
| 2025 | IPv6 Prefix Target Generation through Pattern and Distribution Learning using Vision-Transformer and Guided-Diffusion
Yaochen Ren, Gaopeng Gou, Chengshang Hou, Tianyu Cui, Zhen Li 0011, Gang Xiong 0001, Chang Liu 0049 |
INFOCOM | 3 |
| 2024 | Smart Contract Vulnerability Detection Based on AST-Augmented Heterogeneous GraphsabstractSmart contracts have been increasingly deployed and applied on various blockchain platforms. Nevertheless, vulnerabilities may cause significant financial losses due to the involvement of substantial funds in smart contracts. Traditional analysis tools heavily rely on manually predefined rules. Recent studies have demonstrated the promising potential of deep learning techniques in smart contract vulnerability detection. However, existing approaches often disregard cross-function and cross-contract vulnerability scenarios, focusing primarily on characterization or detection tasks at the function level. In this study, we propose CL-HGAN, a novel framework for smart contract vulnerability detection at the contract level. Firstly, we construct a contract-level heterogeneous graph to embody the relationships between contracts and functions. Specifically, we build the backbone of the heterogeneous graph based on the abstract syntax tree (AST) and multiple types of edges and then incorporate two additional categories of edges to augment its structural information. Subsequently, we design a two-phase feature learning method to automatically generate graph-level representations based on a heterogeneous graph attention network and meta-paths specific to the constructed graph. Finally, we employ a classifier to perform vulnerability detection tasks. In particular, the proposed CL-HGAN comprehensively captures vulnerability features and accurately identifies vulnerabilities at the contract level. Furthermore, we evaluate the CL-HGAN framework on an Ethereum smart contract dataset containing thirty types of vulnerabilities. The experimental results show that the average metrics of our approach outperform the state-of-the-art baselines. Haikuo Li, Gang Xiong 0001, Chengshang Hou, Gaopeng Gou, Ziqian Chen, Zhen Li 0011 |
IPCCC | 3 |
| 2024 | Incremental encrypted traffic classification via contrastive prototype networks
Wei Cai 0007, Chengshang Hou, Mingxin Cui, Bingxu Wang, Gang Xiong 0001, Gaopeng Gou |
Comput. Networks | 2 |
| 2024 | A blind flow fingerprinting and correlation method against disturbed anonymous traffic based on pattern reconstruction
Chang Liu 0049, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Yangyang Ding, Chengshang Hou |
Comput. Networks | 7 |
| 2023 | PTC: Prompt-based Continual Encrypted Traffic ClassificationabstractEncrypted traffic classification (ETC) is necessary for network security, which is the process of identifying encrypted network traffic into a specific class, thus there are numerous applications in the security of network. The rapid development of network web services (applications) makes it attractive to tackle classification of encrypted traffic in a continual learning environment. However, the traffic ambiguity and privacy leakage, restrict existing incremental approaches from achieving satisfactory results in the traffic. We introduce a prompt-based continual encrypted traffic classification method (PTC) in this research to progressively learn tasks under multiple process transitions. Prompts are tiny, learnable parameters that are stored in ram according to our suggested structure. The objective is to find the best way to use prompts to help models make predictions, keep both task-peculiar and task-constant knowledge in model, and prevent catastrophic forgetting. We carry out extensive tests using both real-world and open datasets. PTC method can strengthen the existing offline traffic classification works, make them adapt to online scenarios, and outperforms the SOTA online traffic classification method in three datasets. (by 4.54 %, 7.28 % and 11.68 % on three datasets, respectively) Wei Cai 0007, Chengshang Hou, Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
CSCWD | 2 |
| 2023 | FA-Net: More Accurate Encrypted Network Traffic Classification Based on Burst with Self-AttentionabstractEncrypted network traffic classification (ENTC) is crucial in fields including network cyberspace security, network administration and service quality. Combining the machine learning algorithms with manual-designed burst features has been studied extensively in the ENTC community. However, these features depend on professional experience heavily, which needs lots of human effort. These hand-crafted features are task-oriented and incomplete in various complex tasks. What's more, they are also affected by the potential network jitters. In this paper, we propose a novel encrypted traffic classification method FA-Net to mine burst features. We adopt two hierarchical multi-head self-attention encoders to enumerate all potential intra-burst features and inter-burst dependencies completely, and select the optimal associations automatically. For more robust against network jitter, we design an additional burst positional encoding to loose the model's sensitivity about out-of-order packets within bursts. We evaluate the FA-Net on multiple datasets, including website and mobile application classification tasks. The results show the FA-Net model outperforms other state-of-the-art methods in all the datasets, even gains more than 5% absolute improvement in accuracy. Additionally, the quantitative measurements about burst feature similarity show that the burst features learned by FA-Net exhibits more intraclass similarity and more inter-class separation. Mingxin Cui, Chengshang Hou, Wei Cai 0007, Zhen Li 0011, Gang Xiong 0001, Gaopeng Gou |
IJCNN | 3 |
| 2023 | Identifying Exposed ICS Remote Management Device using Multimodal Feature in the WildabstractIndustrial Control System (ICS) devices with Internet-accessible IP addresses are critical to the smooth functioning of industries, power grids, and other critical infrastructures. Previous methods used to identify ICS devices exposed to the Internet often ignored these remotely managed devices. Specifically, these systems, which do not openly provide ICS-specific port services, remain undetected during Internet-wide scans for such services. The existing method for scanning and discovering this part of remote management devices has a single feature extraction, and discovering such remote management devices is inefficient. In this paper, we propose a novel strategy dedicated to identifying exposed remote managed devices on the Internet by using multidimensional approaches, such as traffic periodicity analysis, device customized field identification, key content extraction via image-to-text conversion, and remote management device access HTTP traffic feature analysis. We have effectively identified 26 different types of remote management devices in Japan, comprising a total of 983 exposed devices, in a shorter timeframe. When juxtaposed with previous methods, our strategy has identified more devices faster. Therefore, our method holds considerable potential for identifying and reducing the attack surface of critical infrastructures on the Internet. Furthermore, it also has substantial significance for protecting global network security. Liuxing Su, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Chengshang Hou |
IPCCC | 6 |
| 2023 | MENDER: Multi-level Feature Fusion Discovery Framework for Exposed ICS Remote Management Devices in the WildabstractWith the development of the Internet, many industrial control system (ICS) remote management devices for key infrastructure, such as solar power plants, sewage treatment, and buildings, are easily exposed to the Internet through network connections. Existing studies on ICS detection can not detect these remote management devices, which are not open to specific industrial control protocol services. Effectively identifying exposed real-world ICS remote management devices while minimizing the attack surface remains an enormous challenge. To address this challenge, we propose a Multi-level fEature fusioN DiscovEry fRamework (MENDER) for discovering neglected ICS remote management devices. First, we conduct a comprehensive and multi-level data collection in the detection process, including the traffic generated by website access, web resource files and HTML. We build an efficient and comprehensive data detection and acquisition module. Second, we design a novel multi-level feature extraction and fusion model to mine key features from raw data. We perform hierarchical clustering based on HTML features and combine the extracted multi-layered key features to filter potential ICS remote management devices. Third, we use the Random Forest model to classify and predict ICS devices based on the extracted multi-level features, aiming to learn inherent features profoundly for enhanced detection of these remote management devices. In a month, we detect 1, 069 devices in Japan, some of devices are insecure, i.e. allowing access to the status or even the control industrial devices without proper authentication. Compared with existing method, MENDER’s time spent on device discovery has been reduced by 94.1%, the number of device discovery is increased by 20.1%, and 26 different types of devices are found. Our MENDER’s device discover ability is superior to it both in time and quantity. Liuxing Su, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Chengshang Hou |
TrustCom | 6 |
| 2022 | TTAGN: Temporal Transaction Aggregation Graph Network for Ethereum Phishing Scams DetectionabstractIn recent years, phishing scams have become the most serious type of crime involved in Ethereum, the second-largest blockchain platform. The existing phishing scams detection technology on Ethereum mostly uses traditional machine learning or network representation learning to mine the key information from the transaction network to identify phishing addresses. However, these methods adopt the last transaction record or even completely ignore these records, and only manual-designed features are taken for the node representation. In this paper, we propose a Temporal Transaction Aggregation Graph Network (TTAGN) to enhance phishing scams detection performance on Ethereum. Specifically, in the temporal edges representation module, we model the temporal relationship of historical transaction records between nodes to construct the edge representation of the Ethereum transaction network. Moreover, the edge representations around the node are aggregated to fuse topological interactive relationships into its representation, also named as trading features, in the edge2node module. We further combine trading features with common statistical and structural features obtained by graph neural networks to identify phishing addresses. Evaluated on real-world Ethereum phishing scams datasets, our TTAGN (92.8% AUC, and 81.6% F1-score) outperforms the state-of-the-art methods, and the effectiveness of temporal edges representation and edge2node module is also demonstrated. Gaopeng Gou, Chang Liu 0049, Chengshang Hou, Gang Xiong 0001 |
WWW | 4 |
| 2021 | UMVD-FSL: Unseen Malware Variants Detection Using Few-Shot LearningabstractAs the tool for launching cyber attacks, the ever-increasing malware variants pose a significant threat to the interconnected network community. The detection methods based on conventional machine learning techniques require lots of samples for training. However, in real-world scenarios, such as in the early stage of novel attacks appearance, only a small number of malicious samples can be obtained. Applying data-intensive traditional methods in the above scenarios will cause serious overfitting problems. Therefore, there is a need for few-shot detection. In his paper, we propose UMVD-FSL, a framework based on few-shot learning to detect unseen malware variants with a small set of data. We start with network traffic data generated by malware variants and benign applications and then convert them to grayscale images. The prototype-based few-shot learning model takes the grayscale images as the input and utilizes meta-training to generalize the meta-learner for adapting new tasks. When a new sample appears, the model performs classification by computing distances to prototype representation of each class. We evaluate different methods through a series of comparative experiments. Our method has the best performance on all subtasks. The experimental results indicate that our method is universal and robust in detecting malware variants from the same network environment and different network environments. The above points prove that our method can accomplish the task of few-shot unseen malware variants detection. Candong Rong, Gaopeng Gou, Chengshang Hou, Zhen Li 0011, Gang Xiong 0001, Li Guo 0001 |
IJCNN | 3 |
| 2021 | LFETT2021: A Large-scale Fine-grained Encrypted Tunnel Traffic DatasetabstractWith the widespread use of tunnel technology, the volume of encrypted tunnel traffic rises sharply, which brings a new challenge to traditional encrypted traffic identification. A number of real-world application scenarios, including Quality of Service and intrusion detection, have put forward new re-quirements for identifying numerous tunnels, applications, and fine-grained behavior. However, previous studies and datasets on encrypted tunnel traffic identification fail to meet these requirements due to their low dataset coverage and coarse label granularity. These weaknesses further affect the extracted features based on these datasets, making them unable to adequately characterize encrypted tunnel traffic. In this paper, we refine the previous tunnel traffic identification granularity from prevalent application identification to behavior identification, and propose LFETT2021, a large-scale fine-grained encrypted tunnel traffic dataset. Our dataset expands the coverage to two operating system platforms, five tunnels, 23 applications, and 76 behaviors. Furthermore, we propose a set of Time-Packet-Related features to better characterize encrypted tunnel traffic. Our comprehensive experiments on LFETT2021 and Time-Packet-Related features show the best average precision of 85% and recall of 88% in 3 different granularity identification scenarios. Gaopeng Gou, Chengshang Hou, Gang Xiong 0001, Zhen Li 0011 |
TrustCom | 3 |
| 2021 | Universal Website Fingerprinting Defense Based on Adversarial ExamplesabstractWebsite fingerprinting (WF) attacks pose a threat to privacy of web activity, especially on anonymity networks such as Tor. Recent studies show that the deep neural network (DNN) significantly improves the impact of website fingerprinting attacks. Especially, DNN-based attack undermines the existing defense methods which are mainly rely on the manually designed rule. In this paper, we present a novel defense that generates universal perturbation that can transform original examples to adversarial examples which is effectively defending against a specific WF model. The proposed defense is evaluated on state-of-the-art DNN attack over a public Tor traffic dataset. The experimental results show our adversarial example generation method performs better than the baseline methods. The proposed defense defeats all existing WF attacks based on deep neural networks with a low overhead. Comparing with state-of-the-art defenses such as Walkie-Talkie and WTF-PAD with a lower bound of 31% and 64% overheads, the proposed defense achieves identical defense performance with at least 50% bandwidth overhead saving. Chengshang Hou, Junzheng Shi, Mingxin Cui, Mengyan Liu, Jing Yu 0007 |
TrustCom | 1 |
| 2021 | Attack versus Attack: Toward Adversarial Example Defend Website Fingerprinting AttackabstractWebsite Fingerprinting (WF) attack is a side channel attack against encrypted tunnels which infers network activities of encrypted tunnels users. WF attack has been successfully applied to the Tor network, which poses a huge threat to the privacy of Tor visitors. A lot of countermeasures are therefore proposed to defend against such attacks. However, the newest attack successfully undermined the existing defense leveraging deep learning technique. In this paper, we propose an defense named Attack to Attack (A2A) that leverages adversarial example to attack the attacker's classifier. A2A treats website fingerprinting model as a black box. In order to find effective adversarial examples for the attacker's model, A2A manipulates traffic iteratively according to the output of a substitute model which is an elaborate model intentionally learning a similar classification boundary with the attacker's model. We evaluate the effectiveness of A2A on a public tor traffic dataset and the newest WF attack. The experimental results show that the proposed method provides effective defense with a bandwidth overhead of 2.2%, which significantly outperforms the manually designed defense (typically has a bandwidth overhead of 31%). Chengshang Hou, Junzheng Shi, Mingxin Cui, Qingya Yang |
TrustCom | 1 |
| 2020 | Joint Analysis of Port and Protocol via Endpoint Measurement: An Empirical StudyabstractAs network services continuously evolving, accurately classifying traffic is important for network operators to optimize QoS and customize policy. Network service uses non-standard ports and protocol obfuscation causing damage to the accurate port-based and payload-based traffic classification. However, Deep Packet Inspection (DPI) technique, which combines the payload-based method and port-based method, is still adopted by practitioners from the academic and industrial community. In this paper, we investigate the DPI classification result on a large network to estimate the impact of two factors. We qualify the popularity of non-standard port among different protocols. By endpoint filtering, we discover a large proportion of non-standard ports are opened temporally. We show there still is strong association between P2P protocols and camouflaged protocol. In particular, using both host and label association between endpoints, we find camouflaged protocols exhibit an abnormal port span that is different with the original protocol and are similar to the port span of P2P protocols. Chengshang Hou, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
APNOMS | 1 |
| 2020 | WF-GAN: Fighting Back Against Website Fingerprinting Attack Using Adversarial LearningabstractWebsite Fingerprinting (WF) attack is an side-channel attack which aims at encrypted web traffic. WF attackers recognize encrypted website traffic through constructing fingerprinting for each website using the flow-based features extracted from encrypted traffic. WF defense typically aims at modifying the features of the encrypted websites. However, those countermeasures either cause high overhead or fail to counter the subsequent WF attacks. Especially, the newest WF attacks, which are based on deep neural network, is able to classify the defended traffic by directly learning from the labeled defended traffic. In this paper, we propose an novel defense through making use of the trick that machine learning models are vulnerable to adversarial exmaples. We design WF-GAN, a GAN with an additional WF classifier component, to generate adversarial examples for WF classifiers through adversarial learning. As the website set is divided into source and target website, WF-GAN are trained to map websites features from source set to adversarial examples and make adversarial examples more similar to the website features in the target set. The experimental result shows that WF-GAN achieves 90% success rate with at most 15% overhead for untargeted defense, which outperforms previous defense. In addition, adversarial examples based defense support targeted defense, which is not support by traditional defense. The result shows that WF-GAN achieves over 90% targeted defense success rate when the target websites set is twice as many as the source website set. Chengshang Hou, Gaopeng Gou, Junzheng Shi, Peipei Fu, Gang Xiong 0001 |
ISCC | 1 |
| 2018 | Classifying User Activities in the Encrypted WeChat TrafficabstractThe security and privacy of encrypted mobile applications have attracted the attention of researchers. However, most of the existing researches focus on analysis of SSL/TLS traffic, while few studies focus on proprietary encrypted traffic, which is also important and challenging. In this paper, we make a deep study of WeChat, which is one of the most popular social applications in the world with over one billion active users. The application uses a proprietary encryption protocol called as MMTLS for most of its communications. It is designed based on Transport Layer Security (TLS) 1.3 drafts for both performance and security. We explore the fine-grained classification of typical user activities inside the MMTLS encrypted channels and compare the MMTLS with the HTTPS (e.g. flow duration and packet size), which are jointly used in WeChat. It is found that MMTLS is suitable for scenarios of low latency and lightweight messaging. With the WeChat traffic collected from different platforms (Android, iOS) and devices (Huawei, Samsung, iPhone, iPad, etc.) by different users, we classify seven typical activities, encrypted by MMTLS protocol such as payment, advertisement click, browsing moments and so on. The experimental results show that both of the average precision and recall can reach over 92%. Our work is the first to perform classification on this proprietary encrypted protocol and understanding the difference between MMTLS and TLS. It is believed that the work will benefit the security and privacy of WeChat and other proprietary encryption applications. Chengshang Hou, Junzheng Shi, Cuicui Kang, Zigang Cao, Xiong Gang |
IPCCC | 1 |