Chun Long

dblp:242/2856 · DBLP profile ↗
← Back
17ranked-venue papers
1as first author
14since 2021 · last 2026
0000-0003-0351-6486ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 1 first-author · 3 since 2021Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Beyond Token Attention: Contiguous and Interpretable Payload Identification for Web Attacks
Jing Zhao 0051, Changhua Pei, Chun Long, Guanyao Du, Yawei Liu
DSN5
2026 LogAMF: Adaptive Multi-Feature Fusion for Log Anomaly Detection
Guanyao Du, Chun Long, Yize Wu
ICIC (4)6
2026 AEGIS: A Multi-agent Collaborative Framework with Adversarial Self-Play for Encrypted Malware Traffic Detection
Degang Sun, Guanyao Du, Chun Long
KSEM (4)6
2026 PAOSC: Plug-and-play Attention Optimization for Semantic Consistency in LLMs
abstract
Attention mechanisms are essential to the success of Large Language Models (LLMs). In practice, models often overemphasize semantically low-value tokens, forming attention sinks while failing to capture truly informative tokens. Existing inference-time optimization methods mainly rely on static adjustments or attention redistribution, which often disrupt the correspondence between attention distribution and the actual semantics of the input, leading to a loss of semantic consistency and degraded performance. To address this problem, we propose PAOSC, a plug-and-play attention optimization model designed to maintain semantic consistency by dynamically adjusting attention. PAOSC employs a generator to identify informative tokens and a discriminator to optimize the generator via policy gradients based on confidence changes and loss fluctuations. Experiments on eight LLMs show up to a 9.68% improvement in the F1 score. On the constructed HTTP-RL dataset, PAOSC eliminates 18% of low-value tokens, improving inference efficiency while maintaining semantic consistency. Our code is available at https://github.com/ChangLi000/PAOSC.
Yawei Liu, Chun Long, Jing Zhao 0051, Guanyao Du
WWW3
2026 When BERT meets BLOCK: A pre-training and fine-tuning malicious encrypted traffic detection method based on protocol semantic units
Degang Sun, Guanyao Du, Chun Long
Comput. Networks6
2025 TAD-FC: An Adaptive Network Attack Detection and Feature Capture Approach for Real-World Network Environments
abstract
To address the limitations of existing network attack detection methods, which often rely on static security rules and exhibit limited adaptability in real-world network environments, we propose an Adaptive Network Attack Detection and Feature Capture Framework (TAD-FC). This paper designs an “attack detection-feature capture-rule update” structure to facilitate the adaptive updating of rules and proposes a mechanism based on Bayesian theory to optimize the adjustment threshold to accommodate new patterns in attack traffic distributions. The framework employs a two-stage attack detection mechanism to effectively respond to evolving attack methodologies. In the first stage, CASI is proposed to identify mutated attacks similar to known covert threats and the sparse group sparse lasso method is used for feature location and capture. In the second stage, an incremental decision tree based on pseudo-labeling of latent features identifies novel attacks, then the feature importance distribution and incremental decision tree abnormal splitting path are used to determine the attack features. Experimental results show strong performance on datasets such as CIC-DDoS 2019, NSL-KDD, and CIC-IDS 2018, achieving 95.12% accuracy on CST-Cloud traffic.
Guanyao Du, Yuhai Lu, Chun Long
CSCWD7
2025 MetaSSL-ETD: Robust Detection of Malicious Encrypted Traffic Based on Semi-supervised Meta-learning
Guanyao Du, Yuhai Lu, Chun Long, Degang Sun
ICIC (4)4
2025 PPIA-MTL: Efficient Property Proportion Inference Attacks on Tabular Generative Models via Multi-Task Learning
abstract
While generative models for tabular data offer strong capabilities in data synthesis, they also raise serious privacy concerns. Property Proportion Inference Attacks (PPIAs) pose a critical threat by aiming to infer the distribution of sensitive attributes in the training data. Existing approaches often struggle with low efficiency and limited adaptability in high-dimensional tabular settings.In this paper, we propose PPIA-MTL, a novel attack framework based on Multi-Task Learning (MTL) that enables efficient parallel inference of multiple attributes, significantly reducing computational cost. We further extend the framework to support continuous attributes and introduce a unified evaluation metric, CACRS (Continuous Attribute Comprehensive Reasoning Score), which comprehensively assesses inference performance from the perspectives of distributional consistency, numerical error, and more.Experiments on real-world datasets show that PPIA-MTL achieves a minimum MAE of 1.55% on binary attributes and improves inference accuracy for continuous attributes by up to 15.5 over existing methods. As the number of inference tasks increases, training cost is reduced by more than 10×. Finally, we apply PPIA-MTL as a privacy auditing tool and find that some diffusion models exhibit lower inference risk while maintaining high utility, demonstrating promising potential for balancing privacy and utility under the Group-Level Statistical Privacy Risk (GSPR).
Ninghui Zhang, Chun Long, Yuhao Fu, Haojie Nie, Xingbo Pan
TrustCom2
2025 T-VAE: Transformer-Based Variational AutoEncoder for Perceiving Anomalies in Multivariate Time Series Data
abstract
ABSTRACT Anomaly perception in multivariate time series data has crucial applications in various domains such as industrial control and intrusion detection. In real‐world scenarios, the sequence information in multivariate time series data, which encompasses the temporal order and dependencies among high‐dimensional samples and features, can be complex and nonlinear. Additionally, the time series data often exhibit high volatility and are interspersed with noise data. These factors make anomaly perception in multivariate time series challenging. Despite the recent development of deep learning methods, only a few are able to address all of these challenges. In this paper, we propose a Transformer‐based Variational AutoEncoder (T‐VAE) for anomaly perception in multivariate time series data. The T‐VAE consists of two sub‐networks, the Representation Network and the Memory Network, and achieves end‐to‐end jointly optimisation. The Representation Network leverages self‐attention mechanisms and residual network structures to capture sequence information and metaphorical patterns from multivariate time series data. The Memory Network employs a Variational AutoEncoder to learn the distribution of normal data. It employs Maximum Mean Discrepancy to approximate the distribution of high‐volatility and noisy data to the distribution of the normal data. We evaluate T‐VAE on five datasets, showing superior performance and validating its effectiveness and robustness through comprehensive ablation studies and sensitivity analyses.
Chai Kiat Yeo, Jiwu Jing, Chun Long
Expert Syst. J. Knowl. Eng.4
2025 Flow Microelement-Driven Traffic Relationship Analysis: Robust Detection of Malicious Encrypted Traffic
abstract
Encryption technologies randomize network communication to protect user privacy. However, attackers exploit encrypted traffic to conceal malicious activities. The existing detection methods rely primarily on traffic content or interactive patterns. Nevertheless, static methods can be easily obfuscated by advanced attacks. Since the set of potential attacks is open and infinite, models regularly lose effectiveness against novel attacks. Robust encrypted malicious traffic detection remains a valuable research area. In this paper, we propose BSTS-Net, a robust unsupervised encrypted malicious traffic detection model based entirely on traffic relations. The key motivations are to construct a relation-based traffic contextual representation and to establish dynamic baselines for anomaly detection. To represent local relations within flows, we innovatively introduce the concept of traffic microelements, which capture fine-grained interaction pattern relations. To integrate the global relationships between flows, we construct a traffic microelement space based on the Siamese neural network. Three optimization functions are proposed to optimize the intraservice, interservice and internode relations. For robust detection, we introduce a reputation-enhanced dynamic encrypted traffic detection algorithm that constructs dynamic baselines and continuously detects novel anomalies. We evaluate BSTS-Net through extensive experiments on three datasets and compare it with seven SOTA methods. Our results demonstrate its superiority, with an F1 score of more than 99.63% across all the datasets in multiclassification scenarios. Additionally, we simulate three adversarial scenarios for robustness analysis. Although the baseline methods experience an F1 score degradation of 32.21%, BSTS-Net achieves high performance, with only 1% degradation.
Hao Fu 0030, Degang Sun, Jinxia Wei, Chun Long
IEEE Trans. Inf. Forensics Secur.5
2024 Robust Malicious Domain Detection Based on Spatio-Temporal Hypergraph Networks
abstract
Malicious domains serve as significant resources for adversaries to execute cyber attacks and are crucial indicators for detecting network intrusions. In practical scenarios, malicious domains associated with various attacks are intermingled within DNS traffic, leading to variability in the performance of machine learning-based detection methods. To address this challenge, we have collected extensive DNS traffic data spanning 12 months from a real-world large-scale network with 1 million users. From this dataset, we have extracted numerous requested domains, encompassing 267 attacks that exploit malicious domain names. Furthermore, we have observed that the distinct properties of malicious domains associated with different attacks contribute to the fluctuating performance of machine learning-based detection models. Consequently, we have introduced a spatiotemporal hypergraph network model, which establishes high-order relationships among domain properties to enhance the generalization capability and robustness of the detection model. The results of extensive testing experiments demonstrate that our model achieves remarkable performance, with an average precision of 97% and recall of 98%.
Liangyi Gong, Kunxian Lv, Chun Long, Huanran Wang
ISPA3
2024 A Measurement Study of DNS Query Protocols in Mobile Networks: Efficiency, Reliability and Choice
abstract
The Domain Name System (DNS) runs as a fundamental infrastructure of the mobile Internet. Various DNS protocols employed in the current network ecology can be predominantly classified as unencrypted DNS and encrypted DNS. However, existing research mainly focuses on assessing DNS performance within conventional internet structures, neglecting their evaluation in mobile contexts. In our pioneering study examining DNS within mobile networks, we developed an Android-based application to evaluate the efficiency and reliability of DNS protocols. The App issues nine domain name lookups to four cloud DNS providers supporting unencrypted and encrypted DNS protocols. Collaborating with volunteers from four countries, we collected about 52,000 test records. Our findings reveal substantial variability in the efficiency and reliability of all DNS protocols across different mobile scenarios. Overall, encrypted DNS protocols exhibit superior efficiency compared to plaintext DNS when oriented towards cloud DNS resolvers. In high-speed mobile scenarios, all DNS protocols demonstrate reduced efficiency, with encrypted DNS protocols showing relatively higher reliability. Our broad-scale measurement results indicate that the performance of DNS protocols varies across mobile contexts, but users are typically uninformed about these differences and do not realize how to break free. Intending to assist users in selecting an optimal DNS protocol, we propose a protocol choice model based on auto-encoding LSTM networks which leverages features of networking and protocols to predict the most suitable DNS protocol with reduced query time and enhanced reliability in the current scenario. Notably, we have achieved the prediction of the optimal DNS protocol for the future by foreseeing the network status ahead. Empirical results demonstrate an impressive 98.73% accuracy in prediction of DNS protocol selection.
Liangyi Gong, Lanqi Yang, Chun Long, Xiaochen Fan, Daibo Liu, Changhua Pei
MSN4
2024 ZKFDT: A Fair Exchange Scheme for Data Trading Based on Efficient Zero-Knowledge Proofs
abstract
In zero-trust environments, fair exchange schemes have long faced challenges of low efficiency and high computational overhead when verifying the integrity of large-scale data. To address these issues, this paper proposes ZKFDT, an efficient data fair exchange scheme based on optimized zero-knowledge proof algorithms, offering improvements in efficiency, fairness, and security. In terms of efficiency, ZKFDT leverages IPFS’s hash-based addressing mechanism to significantly reduce network communication overhead compared to traditional data transmission methods, while also optimizing the multi-scalar multiplication algorithm, improving proof generation efficiency by 2x. Regarding security, ZKFDT adopts the more secure ABR23 protocol, addressing the malleability attack vulnerabilities of Groth16 while maintaining its low communication overhead. Through the implementation of smart contracts, including proof verification, atomic swaps, and time-lock functionality, ZKFDT ensures fairness and immutability in data transactions. Experimental results show that ZKFDT demonstrates high efficiency and practical feasibility in large-scale data transaction applications.
Chun Long, Yuhao Fu
TrustCom3
2021 ELSV: An Effective Anomaly Detection System from Web Access Logs
abstract
As network technologies have been developing rapidly, web applications have been widely used. Meanwhile, more and more web attacks have appeared. These attacks have caused a lot of losses to individuals or organizations. A large number of web access logs also bring huge challenges to the attack detection. In this paper, we propose a system ELSV(Ensemble Learning classification with Semantic Vectorization) to detect anomaly web access logs. We use the difference of word occurrence between different types of web access logs to refine the formatted log data, strengthening the distinction between them. The Word2Vec method and TextCNN model are applied to extract vectorized features, making feature extraction more automated and intelligent. We use the ensemble learning classification algorithm as the final classifier, improving the overall classification performance. ELSV is tested on the HTTP DATASET CSIC 2010. The final experimental results show that ELSV achieved 98.48% F1-score and 99.74% AUC, proving the efficacy of it.
Jinxia Wei, Jing Zhao 0051, Chun Long
IPCCC5
2020 An intrusion detection algorithm based on bag representation with ensemble support vector machine in cloud computing
abstract
Summary The increase of security incidents brings a challenge to the cloud computing security. Intrusion detection technologies have been applied to protect information in cloud from being compromised, and complicated learning‐based detection methods have been used to improve the performance of intrusion detection systems. Higher quality and well‐formed samples are crucial to the performance of detection algorithm. Therefore, we mainly study the intrusion detection model based on data optimization processing. In this article, we establish an intrusion detection algorithm based on ensemble support vector machine with bag representation. Specifically, the sample flows are divided into bags, where the sample flows in each bag are related to each other. Each bag contains multiple related data flows that can accurately reflect intrusion behavior, especially persistent intrusion. What's more, ensemble algorithm is applied to detection model, which greatly optimizes the performance of detection algorithm. The experimental results on open access datasets show that the proposed model detects the persistent attack with 90.58% recall.
Jinxia Wei, Chun Long
Concurr. Comput. Pract. Exp.2
2019 A Hybrid Intrusion Detection Algorithm Based on Gaussian Mixture Model and Nearest Neighbors
abstract
Hybrid learning approaches prove to be superior to single technologies in the field of intrusion detection. Moreover, the representative feature is a determinant of generating accurate signatures and improving detection performance. In this paper, we propose a hybrid intrusion detection algorithm based on Gaussian Mixture Model (GMM) and k-Nearest Neighbors (k-NN). More specifically, we first implement GMM to characterize the spatial distribution of each category. Then, a novel GMM-based data formation method is performed to extract distance and density features, called GMDD. By sufficiently utilizing the classification information contained in the original data, GMDD constructs concise and high-quality characteristics. Finally, k-NN is trained and tested on newly transformed datasets to build the detection model. The experimental results on KDD'99 and NSL-KDD datasets indicate that the proposed method not only outperforms other recent studies in terms of accuracy, detection rate and false alarm rate, but also provides excellent computational efficiency.
Chun Long, Yurou Zhang, Jinxia Wei, Guanyao Du
LCN1
2019 An Attack Behaviors Prediction Model Based on Bag Representation in Time Series
abstract
At present, intrusion detection system (IDS) focuses on classifying the network traffic individually and may overlook underlying correlation among adjacent attack behaviors. This paper proposes an attack behaviors prediction model based on bag representation in time series. We aggregate traffic flows into bags, and describe the distribution of data within each bag using Gaussian mixture model (GMM). The change of history data is measured and added into current bag features. The experimental results based on the Kyoto 2006+ dataset show that the approach successfully predicting the number of security incidents.
Chun Long, Jinxia Wei, Guanyao Du
LCN3