EDBT 2026 Demo / reviewers in the wild / expert
Xueying Han
dblp:254/1260
· DBLP profile ↗
16ranked-venue papers
7as first author
15since 2021 · last 2026
0009-0001-2881-9259ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 9 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GranulNet: A unified framework for traffic identification using multi-grained feature fusion
Xueying Han, Yunpeng Li 0006, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu |
Comput. Networks | 2 |
| 2026 | No train, no pain: a training-free few-shot traffic classifier based on LLMsabstractAbstract Encrypted web traffic and evolving Internet technologies pose an increasing challenge to network traffic analysis. However, existing traffic classification methods, though effective, require large labeled datasets and complex training. This makes sustaining them prohibitively expensive and difficult in real-world scenarios. To narrow this gap, we propose a novel training-free few-shot network traffic classification framework based on large language models (LLMs). By integrating meta-learning with LLMs, it reduces reliance on labeled data, eliminates task-specific training, and improves performance. Specifically, we first apply an efficient feature extraction method to extract features from traffic flows. We then design meta-tasks that combine task descriptions with textualized features to produce natural language meta-task formulations. Building on these meta-tasks, the LLM performs reasoning to carry out traffic classification. Finally, to mitigate hallucination in the LLM outputs, we exploit the temporal characteristics of network traffic and aggregate predictions over samples within a defined time window. Extensive experiments on three widely-used encrypted traffic datasets demonstrate that our proposed framework outperforms the state-of-the-art methods, achieving an average absolute improvement in F1 score of 9.75, 9.82, and 12.06 percentage points on the three datasets, respectively. Xingmao Guan, Xueying Han, Jinlai Huang, Tao Wang 0029, Zelin Cui, Zhigang Lu 0002, Baoxu Liu |
Cybersecur. | 3 |
| 2026 | Robust Malicious Network Traffic Detection Framework With Automated Drift Detection, Identification, and AdaptationabstractThe rise in network attacks has made robust malicious traffic detection crucial. However, the dynamic nature of network traffic causes concept drift, undermining the efficacy of traditional detection methods, which often rely on a static i.i.d data environment and struggle to adapt to new patterns. To overcome these limitations, we propose Argus, a novel framework for malicious traffic detection that operates in a comprehensive, automated, and adaptive manner. Argus tackles three core challenges: accurately classifying known traffic while detecting drift, automatically identifying malicious drifting traffic, and maintaining performance through continuous updates. To address these challenges, Argus integrates a contrastive learningbased module to produce compact representations of traffic and implements a fine-grained drift detection method using category-specific reconstruction loss distributions. For drifting traffic, Argus uses clustering-based automated identification to detect attacks without human intervention. Furthermore, a distance-constrained update mechanism ensures smooth model adaptation, preserving stability and accuracy. Extensive experiments demonstrate that Argus achieves superior performance, with an average F1 score exceeding 95% under various conditions and retaining robust performance even under extreme drift scenarios. Xueying Han, Changzhi Zhao, Weike Fang, Weihang Wang 0001, Bo Jiang 0013, Susu Cui, Zhigang Lu 0002, Baoxu Liu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | CMD-EPD: A Graph Contrastive Learning Framework with Multi-Dimensional Fusion for Ethereum Phishing DetectionabstractThe burgeoning prevalence of Ethereum phishing behavior has iCSUR-2025-0155mposed substantial constraints on the advancement of blockchain finance, resulting in losses of more than $7.7 billion to date, so it is urgent to detect it in time. Currently, available detection methods usually focus on the spatial features within transaction graphs. These methods often employ shallow mining techniques on small samples. As a result, they may overlook certain aspects of interaction patterns, such as temporal behavior. Additionally, their data mining capability is limited due to the small sample sizes. In this study, we propose a graph contrastive learning framework to enrich features of accounts behavior patterns with restricted samples to overcome these limitations. Firstly, we construct an Ethereum interaction graph with the multi-graph involving more temporal information centered with labeled nodes and lighten it with our strategy. Secondly, to comprehensively characterize the accounts pattern, we design the encoder part with the GAT-LSTM model based on attention mechanism fusing statistical features , fine-grained temporal behavioral features and graph structural semantic features . Thirdly, to moderate the sparsity of phishing nodes, we employ data augmentation and contrastive learning to fully mine sparse node information. Moreover, we carried out an in-depth experimental evaluation. The CMD-EPD approach, boasting an F 1 -score of 0.87, outperformed all comparison methods. We also executed a thorough case study to analyze phishing accounts phenomenological indicators which back up the superiority of our framework. Chuyi Yan, Yinhao Qi, Xueying Han, Dan Du, Zhigang Lu 0002, Meng Shen 0001 |
ACM Trans. Priv. Secur. | 3 |
| 2025 | FG-SAT: Efficient Flow Graph for Encrypted Traffic Classification Under Environment ShiftsabstractEncrypted traffic classification plays a critical role in network security and management. Currently, mining deep patterns from side-channel contents and plaintext fields through neural networks is a major solution. However, existing methods have two major limitations: (1) They fail to recognize the critical link between transport layer mechanisms and applications, missing the opportunity to learn internal structure features for accurate traffic classification. (2) They assume network traffic in an unrealistically stable and singular environment, making it difficult to effectively classify real-world traffic under environment shifts. In this paper, we propose FG-SAT, the first end-to-end method for encrypted traffic analysis under environment shifts. We propose a key abstraction, theFlow Graph, to represent flow internal relationship structures and rich node attributes, which enables robust and generalized representation. Additionally, to address the problem of inconsistent data distribution under environment shifts, we introduce a novel feature selection algorithm based on Jensen-Shannon divergence (JSD) to select robust node attributes. Finally, we design a classifier, GraphSAT, which integrates Graph-SAGE and GAT to deeply learn Flow Graph features, enabling accurate encrypted traffic identification. FG-SAT exhibits both efficient and robust classification performance under environment shifts and outperforms state-of-the-art methods in encrypted attack detection and application classification. Susu Cui, Xueying Han, Weihang Wang 0001, Bo Jiang 0013, Baoxu Liu, Zhigang Lu 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Multi-language Webshell Detection based on Abstract Syntax Tree and TreeLSTMabstractWebshell is a command execution environment existing in web containers, which is used by attackers to remotely control servers and illegally access website resources. Accurately detecting Webshells is of great significance for maintaining web security. Current research faces several challenges. On the one hand, in order to evade detection, Webshells use a large amount of obfuscation, and existing research methods often use source code or opcode, which cannot fully utilize the semantic and syntactic information of Webshell code. On the other hand, Webshells can be constructed using any web application programming language, while most existing methods only detect one or a few types of Webshells. This paper proposes a novel approach called WS-Tree, which effectively utilizes the semantics and syntax of Webshells by using abstract syntax tree as input features. The TreeLSTM model is used as an encoder to handle node relationships in the syntax tree, thereby achieving the detection of obfuscated and multi-language Webshells. We also propose a new dataset of Webshells containing obfuscated and non-obfuscated to prevent dataset leakage. Extensive experiments demonstrate that our proposed model performs better than the state-of-theart baselines under different webshell programming languages and improves model generalizability. Mengchuan Shang, Xueying Han, Changzhi Zhao, Zelin Cui, Dan Du, Bo Jiang 0013 |
CSCWD | 2 |
| 2024 | ContraMTD: An Unsupervised Malicious Network Traffic Detection Method based on Contrastive LearningabstractMalicious traffic detection has been a focal point in the field of network security, and deep learning-based approaches are emerging as a new paradigm. However, most of them are supervised methods, which highly depend on well-labeled data, and fail to handle unknown or continuously evolving attacks. Unsupervised methods alleviate the need for labeled data, but existing methods are often limited to detecting anomalies either in vertical perspective through historical comparisons or in horizontal perspective by comparing with concurrent entities. Relying on data from a single perspective is unreliable, and it limits the model's accuracy and generalizability. In this paper, we propose a novel method ContraMTD based on contrastive learning, which comprehensively considers both vertical and horizontal perspectives. ContraMTD extracts local behavior features and global interaction features from normal network traffic by proposed SEC and DE-GAT respectively, then employs contrastive learning to learn the relationship, especially consistency between them, and finally detects malicious traffic through a multi-round scoring approach. We conduct extensive experiments on three datasets, including a self-collected dataset, and the results demonstrate that our method outperforms many state-of-the-art methods in the domain of unsupervised malicious traffic detection. Xueying Han, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002, Baoxu Liu |
WWW | 1 |
| 2024 | Phishing behavior detection on different blockchains via adversarial domain adaptationabstractAbstract Despite the growing attention on blockchain, phishing activities have surged, particularly on newly established chains. Acknowledging the challenge of limited intelligence in the early stages of new chains, we propose ADA-Spear-an automatic phishing detection model utilizing a dversarial d omain a daptive learning which symbolizes the method’s ability to penetrate various heterogeneous blockchains for phishing detection. The model effectively identifies phishing behavior in new chains with limited reliable labels, addressing challenges such as significant distribution drift, low attribute overlap, and limited inter-chain connections. Our approach includes a subgraph construction strategy to align heterogeneous chains, a layered deep learning encoder capturing both temporal and spatial information, and integrated adversarial domain adaptive learning in end-to-end model training. Validation in Ethereum, Bitcoin, and EOSIO environments demonstrates ADA-Spear’s effectiveness, achieving an average F1 score of 77.41 on new chains after knowledge transfer, surpassing existing detection methods. Chuyi Yan, Xueying Han, Dan Du, Zhigang Lu 0002 |
Cybersecur. | 2 |
| 2024 | MVDet: Encrypted malware traffic detection via multi-view analysisabstractDetecting encrypted malware traffic promptly to halt the further propagation of an attack is critical. Currently, machine learning becomes a key technique for extracting encrypted malware traffic patterns. However, due to the dynamic nature of network environments and the frequent updates of malware, current methods face the challenges of detecting unknown malware traffic in open-world environment. To address the issue, we introduce MVDet, a novel method that employs machine learning to mine the behavioral features of malware traffic based on multi-view analysis. Unlike traditional methods, MVDet innovatively characterizes the behavioral features of malware traffic at 4-tuple flows from four views: statistical view, DNS view, TLS view, and business view, which is a more stable feature representation capable of handling complex network environments and malware updates. Additionally, we achieve a short-time behavioral features construction, significantly reducing the time cost for feature extraction and malware detection. As a result, we can detect malware behavior at an early stage promptly. Our evaluation demonstrates that MVDet can detect a wide variety of known malware traffic and exhibits efficient and robust detection in both open-world and unknown malware scenarios. MVDet outperforms state-of-the-art methods in closed-world known malware detection, open-world known malware detection, and open-world unknown malware detection. Susu Cui, Xueying Han, Cong Dong, Zhigang Lu 0002 |
J. Comput. Secur. | 2 |
| 2024 | Combining graph neural network with deep reinforcement learning for resource allocation in computing force networksabstractFueled by the explosive growth of ultra-low-latency and real-time applications with specific computing and network performance requirements, the computing force network (CFN) has become a hot research subject. The primary CFN challenge is to leverage network resources and computing resources. Although recent advances in deep reinforcement learning (DRL) have brought significant improvement in network optimization, these methods still suffer from topology changes and fail to generalize for those topologies not seen in training. This paper proposes a graph neural network (GNN) based DRL framework to accommodate network traffic and computing resources jointly and efficiently. By taking advantage of the generalization capability in GNN, the proposed method can operate over variable topologies and obtain higher performance than the other DRL methods. Xueying Han, Mingxi Xie, Ke Yu 0001, Xiaohong Huang 0003, Zongpeng Du, Huijuan Yao |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2024 | ECNet: Robust Malicious Network Traffic Detection With Multi-View Feature and Confidence MechanismabstractMalicious traffic detection in the real world faces the challenge of dealing with a diverse mix of known, unknown, and variant malicious traffic, requiring methods that are accurate, generalizable, and reliable for identifying both known and emerging threats. However, existing methods are unable to fully meet these requirements. Supervised methods can accurately detect known malicious traffic, but their performance declines significantly when encountering unknown attacks. Additionally, the misclassification is usually silent, leading to doubts about the reliability and practicality. Unsupervised methods can deal with unknown attacks, but their high false positive rate and inability to utilize the knowledge of existing attack data constitute obvious shortcomings. To overcome these limitations, we propose ECNet, an end-to-end robust malicious network traffic detection method. Particularly, ECNet incorporates multi-view features, including content and pattern features, and employs a gated-based feature fusion approach, providing an efficient and robust representation. Moreover, ECNet introduces a confidence mechanism and combines category probability and confidence values during training and detection; therefore, it can accurately detect both known and unknown malicious traffic while ensuring the credibility of results. To validate the performance of ECNet, we conduct comprehensive experiments on six reorganized datasets and compare ECNet with seven state-of-the-art methods. The results demonstrate that ECNet outperforms others, particularly showing significant improvements in detecting unknown attacks, with up to a 14.15% increase in F1 compared to the best-performing method. Xueying Han, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | TAElog: A Novel Transformer AutoEncoder-Based Log Anomaly Detection Method
Changzhi Zhao, Kezhen Huang, Xueying Han, Dan Du, Yutian Zhou, Zhigang Lu 0002 |
Inscrypt (2) | 4 |
| 2023 | Few-Shot Network Traffic Anomaly Detection Based on Siamese Neural NetworkabstractNetwork traffic anomaly detection is a critical means to detect network attacks, and plays a very important role in ensuring network security. However, existing network traffic anomaly detection methods rely on large-scale, well-labeled, class-balanced datasets, which are difficult to apply in practical application. Thus, this paper proposes a few shot network traffic anomaly detection method, called “SN-IDS”. “SN-IDS” includes a raw traffic encoding module and a convolution based siamese net(CSNet). The raw traffic encoding module converts the traffic into 3D images. The CSNet uses 3D convolution operations to extract the feature vectors of different traffic sessions from the 3D images and compares them in a metric way to detect anomalies. Experiments on the CICIDS2017 dataset show that the detection accuracy of our proposed method in the 5-shot scenario exceeds the current state-of-the-art methods. Simin Xu, Xueying Han, Bo Jiang 0013, Zhigang Lu 0002 |
ICC | 2 |
| 2023 | Network intrusion detection based on n-gram frequency and time-aware transformer
Xueying Han, Susu Cui, Bo Jiang 0013, Zhigang Lu 0002 |
Comput. Secur. | 1 |
| 2022 | IV-IDM: Reliable Intrusion Detection Method based on Involution and VotingabstractIntrusion detection is critical in the area of cyberspace security. Deep learning methods, especially CNN, have been widely used in intrusion detection in recent years. Network traffic is usually converted into images for processing. However, images converted from network traffic do not have multi-channel features like real-world pictures and have explicit long-distance dependencies between pixels. These characteristics will cause weak performance and poor explanation, making images converted from network traffic unsuitable to be processed by CNN. Besides, most works only consider the first few packets (named head packets) in a flow, which contains the information about connection establishment and interaction between two parts. However, the last few packets (named tail packets) are omitted, resulting in the loss of information about disconnection. To handle the above problems, we propose a reliable intrusion detection model called IV-IDM. Instead of convolution, IV-IDM uses a new structure, involution. Involution has the properties of spatial-specific and channel-agnostic and is more suitable for intrusion detection tasks than convolution. We also propose I-Res, which is constructed based on involution and is used as the base classifier of IV-IDM. We use head and tail packets of a flow as the inputs to two I-Res respectively to learn richer information and employ a voting algorithm to integrate the results of these two parts to promote the robustness of the model. Finally, IV-IDM is evaluated by the ISCX-IDS-2012 and the CIC-IDS-2017 datasets. The experimental results demonstrate that IV-IDM outperforms the state-of-the-art models and is qualified for intrusion detection. Xueying Han, Pu Dong, Bo Jiang 0013, Zhigang Lu 0002, Zelin Cui |
ICC | 1 |
| 2020 | STIDM: A Spatial and Temporal Aware Intrusion Detection ModelabstractNetwork intrusion detection plays a critical role in cyberspace security. Most existing conventional detection methods mostly rely on manually-designed features to detect intrusion behaviours from large-scale flow data. Recent studies show that deep learning-based methods are effective for network intrusion detection due to the ability to learn discriminative features from data automatically. However, these models ignore the problem of the irregular time intervals between packets in a flow, causing the degradation of detection performance. To this end, we propose a Spatial and Temporal Aware Intrusion Detection model (STIDM). The proposed STIDM model first uses a one-dimensional Convolutional Neural Network (1D-CNN) to extract spatial features based on the nature of flow and packet. Then we design a Time and Length sensitive LSTM (TL-LSTM) method to learn richer temporal features from the irregular flows. The two parts are trained simultaneously to achieve global optimum. Through extensive experiments on the ISCX2012 dataset and the CICIDS2017 dataset, we demonstrate that STIDM outperforms state-of-the-art models. Xueying Han, Rongchao Yin, Zhigang Lu 0002, Bo Jiang 0013, Chonghua Wang |
TrustCom | 1 |