Jiangtao Zhai

dblp:26/10767 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0001-8557-9899ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 SSH-Pulse: Detecting SSH communication in tunneled traffic
Jiangtao Zhai, Guangjie Liu 0001, Li Yang 0010, Yuewei Dai
Comput. Networks2
2026 PAST-IoT: Self-supervised IoT intrusion detection via pattern-aware anomaly injection and spectral-temporal dual-tower decomposition
Jiangtao Zhai, Lejun Shen, Guangjie Liu 0001
Expert Syst. Appl.1
2026 Self-supervised encrypted traffic classification via importance-aware masked clustering
Jiangtao Zhai, Lejun Shen, Guangjie Liu 0001
J. Inf. Secur. Appl.1
2026 SSH-CAM: Fine-Grained SSH Behavior Identification in Encrypted Tunnel Traffic Using Curriculum-Adaptive Mixup
Guangjie Liu 0001, Jiangtao Zhai, Weiwei Liu 0002, Yuewei Dai
IEEE Trans. Netw. Serv. Manag.3
2024 FlowCorrGCN: Enhancing Flow Correlation Through Graph Convolutional Networks and Triplet Networks
abstract
Anonymous network tracing is a significant research subject in the field of network security, and flow correlation technology serves as a fundamental technique for deanonymizing network traffic. Existing flow correlation techniques are considered ineffective and unreliable when applied on a large scale because they exhibit high false‐positive rates or require impractically long periods of traffic observation to achieve reliable correlations. To address this issue, this paper proposed an innovative flow correlation approach for the typical and most widely used Tor anonymous network by combining graph convolutional neural networks with triplet networks. Our proposed method involves extracting features such as packet intervals, packet lengths, and directions from Tor network traffic and encoding each flow into a graph representation. The integration of triplet networks enhances the internode relationships, which can effectively fuse flow representations with node associations. The graph convolutional neural network extracts features from the input graph topology, mapping them to distinct representations in the embedding space, thus effectively distinguishing different Tor flows. Experimental results demonstrate that with a false‐positive rate as low as 0.1%, the correlation accuracy reaches 86.4%, showcasing a 5.1% accuracy improvement compared to the existing state‐of‐the‐art methods.
Jiangtao Zhai, Xiaolong Zeng, Yufei Meng, Guangjie Liu 0001
Int. J. Intell. Syst.1
2022 A semantic element representation model for malicious domain name detection
Luhui Yang, Guangjie Liu 0001, Jiangtao Zhai, Yuewei Dai
J. Inf. Secur. Appl.4
2021 Fast3DS: A real-time full-convolutional malicious domain name detection system
Luhui Yang, Guangjie Liu 0001, Huiwen Bai, Jiangtao Zhai, Yuewei Dai
J. Inf. Secur. Appl.5
2021 Detecting Multielement Algorithmically Generated Domain Names Based on Adaptive Embedding Model
abstract
With the development of detection algorithms on malicious dynamic domain names, domain generation algorithms have developed to be more stealthy. The use of multiple elements for generating domains will lead to higher detection difficulty. To effectively improve the detection accuracy of algorithmically generated domain names based on multiple elements, a domain name syntax model is proposed, which analyzes the multiple elements in domain names and their syntactic relationship, and an adaptive embedding method is proposed to achieve effective element parsing of domain names. A parallel convolutional model based on the feature selection module combined with an improved dynamic loss function based on curriculum learning is proposed, which can achieve effective detection on multielement malicious domain names. A series of experiments are designed and the proposed model is compared with five previous algorithms. The experimental results denote that the detection accuracy of the proposed model for multiple-element malicious domain names is significantly higher than that of the comparison algorithms and also has good adaptability to other types of malicious domain names.
Luhui Yang, Guangjie Liu 0001, Weiwei Liu 0002, Huiwen Bai, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks5
2020 An Encrypted Traffic Identification Scheme Based on the Multilevel Structure and Variational Automatic Encoder
abstract
With the rapid growth of the encrypted network traffic, the identification to it becomes a hot topic in information security. Since the existing methods have difficulties in identifying the application which the encrypted traffic belongs to, a new encrypted traffic identification scheme is proposed in this paper. The proposed scheme has two levels. In the first level, the entropy and estimation of Monte Carlo π value as features are used to identify the encrypted traffic by C4.5 decision tree. In the second level, the application types are distinguished from the encrypted traffic selected above. First, the variational automatic encoder is used to extract the layer features, which is combined with the frequently-used stream features. Meanwhile, the mutual information is used to reduce the dimensionality of the combination features. Finally, the random forest classifier is used to obtain the optimal result. Compared with the existing methods, the experimental results show that the proposed scheme not only has faster convergence speed but also achieves better performance in the recognition accuracy, recall rate, and F1-Measure, which is higher than 97%.
Jiangtao Zhai, Huaifeng Shi, Zhongjun Sun, Junjun Xing
Secur. Commun. Networks1
2019 An end-to-end generative network for environmental sound-based covert communication
Yuewei Dai, Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai
Multim. Tools Appl.5
2018 A Wireless Covert Channel Based on Constellation Shaping Modulation
abstract
Wireless covert channel is an emerging covert communication technique which conceals the very existence of secret information in wireless signal including GSM, CDMA, and LTE. The secret message bits are always modulated into artificial noise superposed with cover signal, which is then demodulated with the shared codebook at the receiver. In this paper, we first extend the traditional KS test and regularity test in covert timing channel detection into wireless covert channel, which can be used to reveal the very existence of secret data in wireless covert channel from the aspect of multiorder statistics. In order to improve the undetectability, a wireless covert channel for OFDM-based communication system based on constellation shaping modulation is proposed, which generates additional constellation points around the standard points in normal constellations. The carrier signal is then modulated with the dirty constellation and the secret message bits are represented by the selection mode of the additional constellation points; shaping modulation is employed to keep the distribution of constellation errors unchanged. Experimental results show that the proposed wireless covert channel scheme can resist various statistical detections. The communication reliability under typical interference is also proved.
Pengcheng Cao, Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks5
2018 Using Insider Swapping of Time Intervals to Perform Highly Invisible Network Flow Watermarking
abstract
Network flow watermarking (NFW) is an emerging flow correlation technique to deanonymize an anonymous communication system or detect stepping stones, in which a watermark is encoded into a network flow by manipulating some flow characteristics, predominantly by altering timing information. Although interval-based NFWs that employ time intervals as carrier have proven to be capable of resisting moderate network interference, they are vulnerable to some statistic-based attacks, which may expose the very existence of watermark and enable attackers to damage or remove watermark from the observed flow. In this study, using insider swapping of time intervals and an adaptive centroid quantization framework, we design a highly invisible NFW scheme, which is undetectable by multi-flow attacks (MFA), Kullback-Leibler divergence (KLD) test, Kolmogorov-Smirnov (K-S) test, and spread spectrum flow watermark (SSFW) detection. Experimental results using real traffic and public dataset show that the proposed NFW scheme can outperform three typical NFW schemes on invisibility while maintaining a strong interference-resistance capability of network jitter, packet loss, and dummy packet insertion.
Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks5
2016 Detecting JitterBug covert timing channel with sparse embedding
abstract
Abstract As the detection methods of covert channels can provide a better way to detect the existence of advanced persistent threat, it has become a hot research topic in the field of network security. Although the existing methods can achieve feasible performance for detecting the JitterBug covert timing channel, they are ineffective when the covert timing channels are implemented with sparse embedding, especially for low embedding probability. In this paper, a new method to detect JitterBug covert timing channel with sparse embedding is proposed, in which the timing intervals are first modeled in histogram statistics, and then the Kolmogorov–Smirnov statistic is used for detection. In addition, the diversifications of the references and the model updating scheme in practical usage are analyzed. The experimental results show that the proposed method is effective when the embedding probability is 0.3, while the existing methods can effective only when the embedding probability is larger than 0.6. Copyright © 2016 John Wiley & Sons, Ltd.
Jiangtao Zhai, Guangjie Liu 0001, Yuewei Dai
Secur. Commun. Networks1
2016 Designing Analog Fountain Timing Channels: Undetectability, Robustness, and Model-Adaptation
abstract
In existing model-based timing channels, the requirement for the target model to be shared between the sender and the receiver limits the sender's ability to adapt to changes in the inter-packet delay (IPD) distribution of the application traffic. In this paper, using analog fountain codes (AFCs) with a general model-fitting coding framework, we design timing channel schemes that allow the sender to change the target model without synchronizing with the receiver. We first propose analog fountain timing channels based on symbol transition when the application packet streams have IPD distribution that is shape similar to the distribution of AFC code symbol values. For more general packet streams, we then propose analog fountain timing channels based on symbol split in which the linearly mapped symbols are split using a symbol probability split matrix to mimic the IPD distribution of the application traffic. We use real VoIP and SSH traffic to compare the proposed schemes with model-based timing channels using LT codes and AFC. Experimental results show that both the proposed schemes are model-secure. The robustness of the two schemes is higher than the model-based timing channels using LT codes whereas not as good as those using AFC when the sender and receiver sides are synchronized with respect to the target model. Moreover, when the sender and the receiver are not synchronized with respect to the model, the robustness of the proposed schemes is significantly higher than model-based timing channels.
Weiwei Liu 0002, Guangjie Liu 0001, Jiangtao Zhai, Yuewei Dai, Dipak Ghosal
IEEE Trans. Inf. Forensics Secur.3