Susu Cui

dblp:250/0712 · DBLP profile ↗
← Back
15ranked-venue papers
4as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Computer networks · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Forge: A Robust Multi-tab Website Fingerprinting Attack via Blind Source Separation
abstract
While Tor's strong anonymity shields users' privacy, it also enables malicious activities, motivating attacks that bypass its protections. Website Fingerprinting (WF) has emerged as a primary threat in this domain. However, existing WF methods struggle with realistic multi-tab browsing scenarios, often relying on prior knowledge of the number of open tabs and lacking robustness against network noise and defenses.
Yitan Huang, Wei Qiao 0005, Meng Shen 0001, Linxu Li, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
WWW7
2026 GranulNet: A unified framework for traffic identification using multi-grained feature fusion
Xueying Han, Yunpeng Li 0006, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
Comput. Networks5
2026 Robust Malicious Network Traffic Detection Framework With Automated Drift Detection, Identification, and Adaptation
abstract
The rise in network attacks has made robust malicious traffic detection crucial. However, the dynamic nature of network traffic causes concept drift, undermining the efficacy of traditional detection methods, which often rely on a static i.i.d data environment and struggle to adapt to new patterns. To overcome these limitations, we propose Argus, a novel framework for malicious traffic detection that operates in a comprehensive, automated, and adaptive manner. Argus tackles three core challenges: accurately classifying known traffic while detecting drift, automatically identifying malicious drifting traffic, and maintaining performance through continuous updates. To address these challenges, Argus integrates a contrastive learningbased module to produce compact representations of traffic and implements a fine-grained drift detection method using category-specific reconstruction loss distributions. For drifting traffic, Argus uses clustering-based automated identification to detect attacks without human intervention. Furthermore, a distance-constrained update mechanism ensures smooth model adaptation, preserving stability and accuracy. Extensive experiments demonstrate that Argus achieves superior performance, with an average F1 score exceeding 95% under various conditions and retaining robust performance even under extreme drift scenarios.
Xueying Han, Changzhi Zhao, Weike Fang, Weihang Wang 0001, Bo Jiang 0013, Susu Cui, Zhigang Lu 0002, Baoxu Liu
IEEE Trans. Inf. Forensics Secur.8
2026 Early-Stage Detection of Encrypted Malware Traffic via Multi-Flow Temporal Graph Learning
abstract
Malware widely adopts network traffic encryption techniques to conceal malicious activities. Recent research has demonstrated the effectiveness of machine learning (ML)-, deep learning (DL)-, and pre-training-based malware traffic detection methods. However, a vast majority of these methods rely on the collected complete traffic during the malware attack. While certain methods can operate on partial traffic, their detection accuracy often significantly decreases when the available data is restricted to the extreme early stage, where information is most sparse. In this paper, we proposeDawnGuard, an effective early-stage encrypted malware traffic detection framework through multi-flow temporal graph learning. Specifically, based on the temporal packet density distribution analysis,DawnGuardinnovatively proposes a self-adjusting data augmentation strategy for early-stage malware traffic, which can force the model to focus on the early-stage interaction phase with more distinguishable properties. Meanwhile, considering that temporal-topological correlations among multiple flows can provide more distinguishable properties in a malware attack, we further develop a temporal graph learning framework to extract features, which can formMulti-Flow Graph Features (MGF). By utilizingMGF,Dawn-Guardimplements a Vision Transformer-based detection mechanism, enabling accurate and precise encrypted malware traffic detection with early-stage traffic by capturing both local and global contextual relationships. Extensive experiments with two real-world datasets demonstrate thatDawnGuardoutperforms the state-of-the-art (SOTA) methods in three typical scenarios: varying early-stage time windows, imbalanced data, and unseen malware detection. Particularly,DawnGuardachieves an average F1 of 95.11%, 8.7% higher than the SOTA method, by only utilizing the first 20% loading ratio of complete traffic.
Jizhe Jia, Yi Zhao 0011, Meng Shen 0001, Susu Cui, Jing Wang 0150, Bufan Zhao 0001, Wei Wang 0012, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2026 HGBHAN: A Novel Framework for Microbe-Drug Interaction Prediction Using Heterogeneous Graphs and Bi-LSTM With Hierarchical Attention
abstract
Predicting microbe-drug associations (MDAs) is vital for accelerating drug discovery and optimizing clinical interventions in biomedical research. Traditional laboratory-based methods, though reliable, are constrained by high costs and limited scalability. While many computational approaches have utilized feature similarities to infer MDAs, they often overlook the complex and heterogeneous relationships inherent in biological networks, as well as the challenge posed by imbalanced datasets. In this study, we propose HGBHAN, a novel framework for MDAs prediction using heterogeneous graphs and bidirectional long short-term memory (Bi-LSTM) with hierarchical attention, for robust MDAs prediction. HGBHAN constructs a comprehensive heterogeneous network by integrating microbe and drug similarities with known association information, capturing multi-level structural and sequential dependencies. The model employs Bi-LSTM modules and a hierarchical attention mechanism to learn discriminative node embeddings, while residual connections are incorporated to address the over-smoothing issue in graph neural networks. Extensive experiments conducted on three public benchmark datasets demonstrate that HGBHAN outperforms existing models across multiple evaluation metrics, validating its efficacy in accurately predicting microbe-drug associations.
Jing Chen 0036, Leyang Zhang, Susu Cui, Zhipan Liang, Xu Lu 0002
IEEE J. Biomed. Health Informatics4
2026 DRL-HNet: A Deep Residual Learning Framework for Microbe-Drug Associations Prediction Using Heterogeneous Network Feature
abstract
In the field of biomedicine, predicting microbe-drug associations (MDAs) is crucial for advancing drug discovery and personalized therapy. However, traditional experimental approaches often fall short in meeting requirements for accuracy and scalability. Previous studies have primarily relied on feature similarities to predict microbe-drug associations, largely ignoring the complex interdependencies essential for improved prediction. In this paper, we propose a novel framework named Deep Residual Learning Framework Using Heterogeneous Network Feature (DRL-HNet) for MDAs prediction. DRL-HNet constructs a heterogeneous network representation by integrating relationships and features from multiple data sources for both microbes and drugs. The model incorporates deep residual learning with bottleneck layers to effectively reduce computational complexity while enhancing network expressiveness. Multi-source feature fusion is leveraged to capture complex interaction patterns, while residual connections mitigate overfitting and enhance training efficiency. Extensive cross-validation experiments demonstrate that DRL-HNet outperforms existing models across multiple evaluation metrics, validating its efficacy in accurately predicting microbe-drug associations.
Jing Chen 0036, Leyang Zhang, Susu Cui, Zhipan Liang, Xu Lu 0002
IEEE J. Biomed. Health Informatics4
2025 Towards effective black-box attacks on DoH tunnel detection systems
Linghao Li, Wei Qiao 0005, Zelin Cui, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002
Comput. Networks6
2025 FG-SAT: Efficient Flow Graph for Encrypted Traffic Classification Under Environment Shifts
abstract
Encrypted traffic classification plays a critical role in network security and management. Currently, mining deep patterns from side-channel contents and plaintext fields through neural networks is a major solution. However, existing methods have two major limitations: (1) They fail to recognize the critical link between transport layer mechanisms and applications, missing the opportunity to learn internal structure features for accurate traffic classification. (2) They assume network traffic in an unrealistically stable and singular environment, making it difficult to effectively classify real-world traffic under environment shifts. In this paper, we propose FG-SAT, the first end-to-end method for encrypted traffic analysis under environment shifts. We propose a key abstraction, theFlow Graph, to represent flow internal relationship structures and rich node attributes, which enables robust and generalized representation. Additionally, to address the problem of inconsistent data distribution under environment shifts, we introduce a novel feature selection algorithm based on Jensen-Shannon divergence (JSD) to select robust node attributes. Finally, we design a classifier, GraphSAT, which integrates Graph-SAGE and GAT to deeply learn Flow Graph features, enabling accurate encrypted traffic identification. FG-SAT exhibits both efficient and robust classification performance under environment shifts and outperforms state-of-the-art methods in encrypted attack detection and application classification.
Susu Cui, Xueying Han, Weihang Wang 0001, Bo Jiang 0013, Baoxu Liu, Zhigang Lu 0002
IEEE Trans. Inf. Forensics Secur.1
2024 ContraMTD: An Unsupervised Malicious Network Traffic Detection Method based on Contrastive Learning
abstract
Malicious traffic detection has been a focal point in the field of network security, and deep learning-based approaches are emerging as a new paradigm. However, most of them are supervised methods, which highly depend on well-labeled data, and fail to handle unknown or continuously evolving attacks. Unsupervised methods alleviate the need for labeled data, but existing methods are often limited to detecting anomalies either in vertical perspective through historical comparisons or in horizontal perspective by comparing with concurrent entities. Relying on data from a single perspective is unreliable, and it limits the model's accuracy and generalizability. In this paper, we propose a novel method ContraMTD based on contrastive learning, which comprehensively considers both vertical and horizontal perspectives. ContraMTD extracts local behavior features and global interaction features from normal network traffic by proposed SEC and DE-GAT respectively, then employs contrastive learning to learn the relationship, especially consistency between them, and finally detects malicious traffic through a multi-round scoring approach. We conduct extensive experiments on three datasets, including a self-collected dataset, and the results demonstrate that our method outperforms many state-of-the-art methods in the domain of unsupervised malicious traffic detection.
Xueying Han, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002, Baoxu Liu
WWW2
2024 Graph-based insider threat detection: A survey
Yiru Gong, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002
Comput. Networks2
2024 Unveiling encrypted traffic types through hierarchical network characteristics
Susu Cui, Cong Dong, Bo Jiang 0013, Zhigang Lu 0002
Comput. Secur.3
2024 MVDet: Encrypted malware traffic detection via multi-view analysis
abstract
Detecting encrypted malware traffic promptly to halt the further propagation of an attack is critical. Currently, machine learning becomes a key technique for extracting encrypted malware traffic patterns. However, due to the dynamic nature of network environments and the frequent updates of malware, current methods face the challenges of detecting unknown malware traffic in open-world environment. To address the issue, we introduce MVDet, a novel method that employs machine learning to mine the behavioral features of malware traffic based on multi-view analysis. Unlike traditional methods, MVDet innovatively characterizes the behavioral features of malware traffic at 4-tuple flows from four views: statistical view, DNS view, TLS view, and business view, which is a more stable feature representation capable of handling complex network environments and malware updates. Additionally, we achieve a short-time behavioral features construction, significantly reducing the time cost for feature extraction and malware detection. As a result, we can detect malware behavior at an early stage promptly. Our evaluation demonstrates that MVDet can detect a wide variety of known malware traffic and exhibits efficient and robust detection in both open-world and unknown malware scenarios. MVDet outperforms state-of-the-art methods in closed-world known malware detection, open-world known malware detection, and open-world unknown malware detection.
Susu Cui, Xueying Han, Cong Dong, Zhigang Lu 0002
J. Comput. Secur.1
2023 Network intrusion detection based on n-gram frequency and time-aware transformer
Xueying Han, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002
Comput. Secur.2
2023 CBSeq: A Channel-Level Behavior Sequence for Encrypted Malware Traffic Detection
abstract
Machine learning and neural networks have become increasingly popular solutions for encrypted malware traffic detection. They mine and learn complex traffic patterns, enabling detection by fitting boundaries between malware traffic and benign traffic. Compared with signature-based methods, they have higher scalability and flexibility. However, affected by the frequent variants and updates of malware, current methods suffer from a high false positive rate and do not work well for unknown malware traffic detection. It remains a critical task to achieve effective malware traffic detection. In this paper, we introduce CBSeq to address the above problems. CBSeq is a method that constructs a stable traffic representation, behavior sequence, to characterize attacking intent and achieve malware traffic detection. We novelly propose the channels with similar behavior as the detection object and extract side-channel content to construct behavior sequence. Unlike benign activities, the behavior sequences of malware and its variant’s traffic exhibit solid internal correlations. Moreover, we design the MSFormer, a powerful Transformer-based multi-sequence fusion classifier. It captures the internal similarity of behavior sequence, thereby distinguishing malware traffic from benign traffic. Our evaluations demonstrate that CBSeq performs effectively in various known malware traffic detection and exhibits superior performance in unknown malware traffic detection, outperforming state-of-the-art methods.
Susu Cui, Cong Dong, Meng Shen 0001, Bo Jiang 0013, Zhigang Lu 0002
IEEE Trans. Inf. Forensics Secur.1
2022 Only Header: a reliable encrypted traffic classification framework without privacy risk
Susu Cui, Cong Dong, Zhigang Lu 0002, Dan Du
Soft Comput.1