Wenhan Ge

dblp:243/8987 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-9680-7313ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 LiteJam: A Lightweight Deep Learning Architecture for Real-Time GNSS Interference Detection and Characterization in UAVs
abstract
Global Navigation Satellite System (GNSS) interference poses a serious threat to Unmanned Aerial Vehicles (UAVs), potentially leading to navigation failures, airspace violations, or even loss of flight control. Although deep learning methods have demonstrated strong performance in interference detection and characterization, most models remain too computationally expensive for onboard deployment due to high computational cost. To address this challenge, we propose LiteJam, a lightweight architecture that utilizes pre-correlation in-phase and quadrature (I/Q) data to construct pseudo-image representations without requiring additional hardware. Specifically, LiteJam adopts a multi-scale convolutional architecture to capture interference patterns, employs a dynamic sparse attention mechanism to adaptively emphasize spatio-spectral cues, and leverages a hierarchical multi-head module for interference detection and characterization. Experimental results show that LiteJam outperforms all baselines. The F1-score of interference classification is 95.74%, outperforming lightweight baselines by 4.37%–24.51%, and generalizes well across diverse scenarios, while maintaining high computational efficiency for real-time UAV applications. Our codes are available at https://github.com/CynthiaCYX/LiteJam.
Yuxue Chen, Junfeng Wang 0003, Zhiyang Fang, Tianjie Ni, Jiaxuan Geng, Wenhan Ge
IEEE Internet Things J.6
2026 ThreatMAMBA: Achieving High-Robustness Cyber Threat Attribution During the Evolution of Attacks
Wenhan Ge, Junfeng Wang 0003, Zeyuan Cui, Zhiyang Fang, Weilu Zhan
IEEE Trans. Inf. Forensics Secur.1
2026 MT-DEGCL: Multi-Task Encrypted Traffic Classification With Dual Embedding and Graph Contrastive Learning
abstract
Although encryption offers strong anonymity, it also facilitates the concealment of malicious activities, allowing adversaries to evade detection, and posing a great challenge to cybersecurity surveillance. Many existing encrypted traffic classification methods struggle to integrate flow- and packet-level tasks effectively, as they are trained independently, which is redundancy. Additionally, packet header and payload are treated equally, leading to the rich information in raw bytes remains fully unexplored, particularly in the abundant payload data. Moreover, they neglect the semantic invariance and common features between data samples, which ultimately results in suboptimal performance. To address these challenges, we propose an effective Multi-Task model using Dual Embedding and Graph Contrastive Learning (MT-DEGCL). Based on the byte-packet-flow structure of network traffic, a parallel dual embedding embeds the header and payload separately, followed by a cross-gated feature fusion strategy to capture the strong local packet-level representation. Then, we construct the traffic interaction graph and further utilize graph contrastive learning to extract the robust global flow-level representation. Finally, a multi-task model is trained for joint flow- and packet-level classification, leveraging the complementary learning between tasks to enhance overall performance. The experimental results on four real datasets highlight the effectiveness of MT-DEGCL, demonstrating superior performance in both tasks. Specifically, on the ISCX-Tor dataset, MT-DEGCL achieves F1 scores of 98.63% for flow-level classification and 98.10% at the packet level, surpassing the state-of-the-art (i.e., DE-GNN) by 2.03% and 83.21%, respectively. Furthermore, MT-DEGCL maximizes the rich information in raw payload bytes, significantly reducing or even nearly eliminating classification loss when using only payload data.
Xiaolan Zhu, Junfeng Wang 0003, Wenhan Ge, Xinbo Han
IEEE Trans. Inf. Forensics Secur.3
2025 CorreFlow: A Covert Fingerprinting Modulation for Flow Correlation in Open Heterogeneous Networks
abstract
The constantly changing landscape of the Internet presents a significant challenge in the detection and tracking of covert attackers and their sophisticated methods. To address this issue, various techniques, such as network flow watermarking (NFW) and traffic correlation, embed attack labels in data streams to identify attack pathways or aid post-analysis. However, existing solutions are often tailored to specific scenarios, resulting in lacking robustness, adaptability, and anonymity under non-cooperative or incomplete information heterogeneous environments. To this end, this paper proposesCorreFlow, a Transfer Learning (TL) based invisible network flow correlation framework utilizing time channel graph fingerprinting modulation. It considers the fragmentation and reassembly of data packets during transmission. In simple network environments,CorreFlowutilizes TL for rapid correlation across flows, enabling efficient linkage of related traffic segments. In complex heterogeneous network, where traditional correlation methods may fail due to encryption and variability, it leverages Inter Packet Delay (IPD) for encrypted flow matching and accurately identifies the optimal watermark point. Multiple experiments conducted on real network traffic and public datasets have demonstrated thatCorreFlowachieves highly efficient traffic correlation with minimal false positive rate, improved adaptability, and steganography. Specifically, it has achieved over 97.31% accuracy in various network environments and promotes network traffic correlation in open heterogeneous network environments from low correlation to 95%.
Junfeng Wang 0003, Wenhan Ge, Lingfeng Tan
IEEE Trans. Inf. Forensics Secur.4
2025 WF-TFC: An Open-World Few-Shot Anonymous Website Fingerprinting via Time-Frequency Consistency
abstract
While Tor provides strong anonymity, it also facilitates the concealment of malicious activities, which poses a significant challenge to cybersecurity surveillance. As an effective anti-anonymity technique, Website Fingerprinting(WF) enables the inference of which websites a user is visiting, thereby uncovering potential attacker activities. State-of-the-art(SOTA) methods have demonstrated remarkable effectiveness. However, a large number of labeled traffic is required to ensure effectiveness, and without timely updates, these models will encounter serious challenges of concept drift due to the dynamic nature of website content and network conditions. The core reasons lie in the independently and identically distributed assumption, while in challenging open-world scenarios, the long-term spatial and temporal dynamics complicates data consistency and effective knowledge transfer. To address these issues, this paper presents WF-TFC, an open-world few-shot anonymous WF model via self-supervised contrastive learning and time-frequency consistency. It aligns time- and frequency-based representations in the latent time-frequency space, enhancing the sustained effectiveness of inherent patterns across various websites. Consequently, it accommodates diverse few-shot target domains with varying dynamics, facilitating data consistency and knowledge transfer in unobserved long-term temporal and spatial environments. For instance, with only 5 traces per website, WF-TFC achieves 92.62% accuracy on traces collected six weeks after pre-training, exceeding the SOTA(i.e., NetCLR) by 2.12%. On similar but mutually exclusive traces, it attains an F1 score of 87.20%, surpassing the SOTA by 6.12%.
Xiaolan Zhu, Junfeng Wang 0003, Wenhan Ge, Yizhao Huang
IEEE Trans. Inf. Forensics Secur.3
2024 SeqMask: Behavior Extraction Over Cyber Threat Intelligence Via Multi-Instance Learning
abstract
Abstract Identification and extraction of Tactics, Techniques and Procedures (TTPs) for Cyber Threat Intelligence (CTI) restore the full picture of cyber attacks and guide the analysts to assess the system risk. Existing frameworks can hardly provide uniform and complete processing mechanisms for TTPs information extraction without adequate knowledge background. A multi-instance learning approach named SeqMask is proposed in this paper as a solution. SeqMask extracts behavior keywords from CTI evaluated by the semantic impact, and predicts TTPs labels by conditional probabilities. Still, the framework has two mechanisms to determine the validity of keywords. One using expert experience verification. The other verifies the distortion of the classification effect by blocking existing keywords. In the experiments, SeqMask reached 86.07% and 73.99% in F1 scores for TTPs classifications. For the top 20% of keywords, the expert approval rating is 92.20%, where the average repetition of keywords whose scores between 100% and 90% is 60.02%. Particularly, when the top 65% of the keywords were blocked, the F1 decreased to about 50%; when removing the top 50%, the F1 was under 31%. Further, we also validate the possibility of extracting TTPs from full-size CTI and malware whose F1 are improved by 2.16% and 0.81%.
Wenhan Ge, Junfeng Wang 0003
Comput. J.1
2024 A survey of strategy-driven evasion methods for PE malware: Transformation, concealment, and attack
Jiaxuan Geng, Junfeng Wang 0003, Zhiyang Fang, Wenhan Ge
Comput. Secur.6
2024 MetaCluster: A Universal Interpretable Classification Framework for Cybersecurity
abstract
Rising cyber threats have created an immediate demand for Deep Learning (DL) in cybersecurity. Nevertheless, the opaque nature of DL models poses challenges in deploying, collaborating, and assessing their effectiveness in less reliable cybersecurity environments. Despite eXplainable Artificial Intelligence (XAI) playing a role in enhancing cybersecurity analytics, the limited task scope, the propensity for data overfitting, and the stochastic explanations hinder its broader application. To fill the gap, this paper introduces a generic interpretable classification framework, named MetaCluster. MetaCluster generates semantic prototypes for features, patterns, and domains at varying granular levels by following three fundamental steps: embedding representations, acquiring prototypes, and aggregating semantics. These mechanisms guarantee that MetaCluster achieves critical information extraction and reliable classification at minimal cost. The experiments encompass cybersecurity classification tasks and assess the interpretability of the framework. These tasks encompass malware family classification, threat behavior analysis, and malicious traffic identification. In particular, when compared to other DL models, MetaCluster exhibits a significant reduction in parameter consumption by 79.52% to 91.78%, and boosts operational speed up to 71.37%, while its F1 scores remain stable or slightly increase. Additionally, MetaCluster possesses the ability to assess and visually represent the significance of image, text, and statistical features. This capability leads to a reduction of Mean Squared Error (MSE) between expected and actual predictions by 0.0101 to 0.1020.
Wenhan Ge, Zeyuan Cui, Junfeng Wang 0003, Binhui Tang
IEEE Trans. Inf. Forensics Secur.1
2023 Explainable cyber threat behavior identification based on self-adversarial topic generation
Wenhan Ge, Junfeng Wang 0003, Tongcan Lin, Binhui Tang
Comput. Secur.1