Fangming Dong

dblp:245/0614 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0003-1846-4236ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 MoPHoney: An adaptive honeyword generation system based on Mixture-of-prompts
Fangming Dong, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
J. Syst. Archit.3
2025 From Threat Report to ATT&CK: Automated Extraction and Reasoning of TTPs Using Large Language Models
abstract
The escalating frequency and increasing complexity of cyber attacks underscore the importance of Cyber Threat Intelligence (CTI). Tactics, Techniques, and Procedures (TTPs), as advanced CTI capable of characterizing adversarial behaviors and intentions, have garnered increased attention. However, TTPs are predominantly found embedded within unstructured natural language texts of threat reports. The accurate extraction and standardization of TTPs pose significant challenges. Existing methods exhibit limitations in terms of accuracy, generalizability, and interpretability. This paper presents a pipeline for automatically extracting TTPs from threat reports and providing rationales using large language models. To support this approach, we have developed three datasets using advanced commercial LLMs for data synthesis. These datasets are made publicly available to facilitate further research. Experimental results demonstrate the superior performance of our proposed approach, achieving an F1-score of 97.15% and accuracies of 79.22% and 92.97% in the respective tasks. These results surpass state-of-the-art methods by 15.39%, 12.87%, and 27.57%, respectively. To the best of our knowledge, this paper is the first to simultaneously extract TTPs while providing the underlying rationales for the extraction. This novel approach significantly improves the usability of the results by providing a richer context for threats.
Fangming Dong, Zhengwei Jiang, Qiying He, Peian Yang, Yepeng Yao
CSCWD1
2025 Graph Representation Learning via Generative-Contrastive Fusion for Advanced Persistent Threat Detection
Yijiao Jiang, Fangming Dong, Zhengwei Jiang, Tianming Zheng, Baoxu Liu, Liling Xin
ICA3PP (4)3
2025 Fast Private Retrieval on Key-Value Store with Multiple Values per Key
abstract
Querying desired data from the key-value store on a cloud server is a prevalent scenario. Client queries might include sensitive information that the client prefers to keep confidential from the server. This occasion resembles the Keyword Private Information Retrieval (KPIR). Prior works on keyword PIR consider that there are no duplicated key-value pairs in the store, i.e., each key only occurs once with only a single value attached. This is one of the cases in practical applications. However, there is also a typical case where a key may occur multiple times with different values. Straightly applying the existing keyword PIR to this case doesn't work and may finally obtain a false query result. We are the first to extend the setting that keys in the store may appear with different values multiple times. To solve this problem, we propose FEDPIR, a fast single-server keyword PIR protocol that supports querying a large-scale key-value store with multiple values per key. FEDPIR uses a novel encoding and decoding strategy combined with a high-throughput linear homomorphic encryption to improve performance significantly. Our extensive experiments on different store configurations show that our FEDPIR achieves 1.2-65.6x lower query latency and 1.5-37.9x lower cost monetarily compared with the baseline methods.
Fangming Dong, Pinghui Wang, Yuance Wang, Li-Zhen Cui 0001
ICDE1
2025 Poisoning Attacks and Defenses to Learned Bloom Filters for Malicious URL Detection
abstract
Approximate membership query (AMQ) structures represented by the Bloom Filter and its variants have been popularly researched in recent years. Researchers have recently combined machine learning with this type of structure to reduce space consumption and computation overhead further and make remarkable progress. However, with the booming performance in space or other metrics, researchers tend to ignore the security of the trained model. The machine learning model is vulnerable to poisoning attacks, and naturally, we infer that the learning-based filters also have the same deficiencies. Hence, in this article, to confirm the inference mentioned above, experiments on the real-world datasets of URLs are conducted and prove that it is necessary to consider the security issue when using learning-based filters. We show that by data poisoning, the attacker can deflect learned Bloom Filters to make a false identification, which can lead to a significant loss in some cases. Aiming to solve this issue, we put forward a method named Defensive Learned Bloom Filter (DLBF) to diminish the influence of data poisoning and achieve a better performance compared to types of learned Bloom Filters.
Fangming Dong, Pinghui Wang, Rundong Li 0002, Xueyao Cui, Junzhou Zhao, Chen Zhang 0010, Xiaohong Guan
IEEE Trans. Dependable Secur. Comput.1
2024 CTIFuser: Cyber Threat Intelligence Fusion via Unsupervised Learning Model
abstract
Cyber attack campaigns are becoming increasingly complex and severe, causing significant impacts on institutions and individuals. Cyber Threat Intelligence (CTI) provides important evidential knowledge about attackers and is critical to the shift from reactive to proactive defense against cyber attacks. Attack detection based on Indicators of Compromise (IOCs), a type of CTI, is vulnerable to the limitation of insufficient context of attack scenarios. In contrast, attack behavior intelligence is associated with information on attackers’ techniques, targets, and intentions, providing a solid foundation for security practitioners to conduct attack investigations or other applications. Many current CTI mining systems are limited to extracting CTI from a single source, leading to challenges such as fragmented attack behavior view and low-value density. To address these issues, we propose an unsupervised fusion framework named CTIFuser, which includes a comprehensive pipeline of four subtasks aimed at mining and fusing multi-source attack behaviors at the attack technique level. In our evaluation of 739 real-world CTI reports from 542 sources, experimental results demonstrate that CTIFuser can obtain a complete view of the attack behaviors at the attack technique level.
Zhengwei Jiang, Peian Yang, Mengjiao Cui, Fangming Dong, Huamin Feng
ISPA6