EDBT 2026 Demo / reviewers in the wild / expert
Wengang Ma
dblp:290/6605
· DBLP profile ↗
23ranked-venue papers
6as first author
23since 2021 · last 2026
0000-0001-6828-0633ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 11 · 3 first-author · 11 since 2021Computer networks · 8 · 2 first-author · 8 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CIL-FGGM: A class-incremental learning framework based on fine-grained Gaussian mixture modeling for open-set fault recognition in rotating machinery
Hekun Yang, Wengang Ma, Junjiang He, Xiaolong Lan, Tao Li 0016 |
Adv. Eng. Informatics | 3 |
| 2026 | Open-set Internet of Things intrusion detection via an adaptive few-shot incremental learning framework enhanced with feature augmentation
Wengang Ma, Hekun Yang, Junjiang He, Xiaolong Lan, Jiangchuan Chen, Tao Li 0016 |
Eng. Appl. Artif. Intell. | 1 |
| 2026 | Generating Black-Box Adversarial Examples for Industrial Control Systems via Immune Co-Evolution
Chenyi Huang, Junjiang He, Wenshan Li 0001, Tao Li 0016, Wengang Ma, Wenbo Fang, Xiaolong Lan |
IEEE Internet Things J. | 5 |
| 2025 | Grimm: A Plug-and-Play Perturbation Rectifier for Graph Neural Networks Defending Against Poisoning AttacksabstractRecent studies have revealed the vulnerability of graph neural networks (GNNs) to adversarial poisoning attacks on node classification tasks. Current defensive methods require substituting the original GNNs with defense models, regardless of the original's type. This approach, while targeting adversarial robustness, compromises the enhancements developed in prior research to boost GNNs' practical performance. Here we introduce Grimm, the first plug-and-play defense model. With just a minimal interface requirement for extracting features from any layer of the protected GNNs, Grimm is thus enabled to seamlessly rectify perturbations. Specifically, we utilize the feature trajectories (FTs) generated by GNNs, as they evolve through epochs, to reflect the training status of the networks. We then theoretically prove that the FTs of victim nodes will inevitably exhibit discriminable anomalies. Consequently, inspired by the natural parallelism between the biological nervous and immune systems, we construct Grimm, a comprehensive artificial immune system for GNNs. Grimm not only detects abnormal FTs and rectifies adversarial edges during training but also operates efficiently in parallel, thereby mirroring the concurrent functionalities of its biological counterparts. We experimentally confirm that Grimm offers four empirically validated advantages: 1) Harmlessness, as it does not actively interfere with GNN training; 2) Parallelism, ensuring monitoring, detection, and rectification functions operate independently of the GNN training process; 3) Generalizability, demonstrating compatibility with mainstream GNNs such as GCN, GAT, and GraphSAGE; and 4) Transferability, as the detectors for abnormal FTs can be efficiently transferred across different systems for one-step rectification. Ao Liu 0005, Wenshan Li 0001, Beibei Li 0002, Wengang Ma, Tao Li 0016, Pan Zhou 0001 |
AAAI | 4 |
| 2025 | Graph Agent Network: Empowering Nodes with Inference Capabilities for Adversarial ResilienceabstractEnd-to-end training with global optimization have popularized graph neural networks (GNNs) for node classification, yet inadvertently introduced vulnerabilities to adversarial edge-perturbing attacks. Adversaries can exploit the inherent opened interfaces of GNNs' input and output, perturbing critical edges and thus manipulating the classification results. Current defenses, due to their persistent utilization of global-optimization-based end-to-end training schemes, inherently encapsulate the vulnerabilities of GNNs. This is specifically evidenced in their inability to defend against targeted secondary attacks. In this paper, we propose the Graph Agent Network (GAgN) to address the aforementioned vulnerabilities of GNNs. GAgN is a graph-structured agent network in which each node is designed as an 1-hop-view agent. Through the decentralized interactions between agents, they can learn to infer global perceptions to perform tasks including inferring embeddings, degrees and neighbor relationships for given nodes. This empowers nodes to filtering adversarial edges while carrying out classification tasks. Furthermore, agents' limited view prevents malicious messages from propagating globally in GAgN, thereby resisting global-optimization-based secondary attacks. We prove that single-hidden-layer multilayer perceptrons (MLPs) are theoretically sufficient to achieve these functionalities. Experimental results show that GAgN effectively implements all its intended capabilities and, compared to state-of-the-art defenses, achieves optimal classification accuracy on the perturbed datasets. Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Guangquan Xu, Pan Zhou 0001, Wengang Ma, Hanyuan Huang |
AAAI | 7 |
| 2025 | Adaptive fault prototype network with joint learning transferability and discriminability for cross-domain bearing fault diagnosis
Wengang Ma |
Eng. Appl. Artif. Intell. | 2 |
| 2025 | Bearing fault diagnosis for variable working conditions via lightweight transformer and homogeneous generalized contrastive learning with inter-class repulsive discriminant
Wengang Ma |
Eng. Appl. Artif. Intell. | 2 |
| 2025 | NSA-AE: An inadequately represented immune spaces NSA augmented via autoencoders
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
Neurocomputing | 6 |
| 2025 | Defending Against APT Attacks in Cloud Computing Environments Using Grouped Multiagent Deep Reinforcement LearningabstractAdvanced persistent threats (APTs) pose a significant challenge to cloud computing security in the evolving landscape of cyber threats. Traditional defense models rely heavily on the attacker’s historical attack information, which greatly limits the effectiveness of actually dealing with APT attacks. To address this issues, we investigate an attack-defense game model in clouding computing environments, where multiple attackers and multiple defenders are supposed to compete for resource allocation on the cloud servers. In order to develop more effective defense strategies, we formulate the optimization problem to maximize the average rewards of defenders under constraints of the maximum available resource and acceptable cost. To solve this, we propose to use the multiagent deep reinforcement learning (RL) method to cope with the high uncertainty and dynamics of attack behavior. Then it is proposed to divide all defenders into cooperative groups and allow defenders within each group can jointly optimize the defense strategy through sharing information and experience. On this basis, we propose a novel grouped multiagent deep RL defense (GMADRLD) algorithm, which can effectively mitigate the issue of state space explosion while achieving good defense effect. Simulation results not only demonstrate the effectiveness of the proposed GMADRLD algorithm in dealing with the attacker’s ever-changing strategies, but also show that it is able to strike a balance between defense performance and computational complexity. Xiaolong Lan, Wengang Ma, Wenbo Fang, Junjiang He |
IEEE Internet Things J. | 4 |
| 2025 | A Dual Active Domain Adaptation Approach With Loss Prediction for IIoT Intrusion Detection Under Imperfect SamplesabstractThe introduction of wireless terminals has disrupted the previously enclosed landscape of Internet of Things (IIoT), resulting in an expanded cyber-attack surface. Therefore, it is crucial to investigate intrusion detection in the IIoT. Current models rely on big data for training, but imperfect labeled data hampers robust intrusion detection. However, traditional models cannot achieve robust IIoT intrusion detection in the face of imperfect data constraints. Addressing this, we propose IIoT intrusion detection approach under imperfect samples using a hierarchical-split with knowledge distillation neural network (HS-KDNet) and dual active domain adaptation fusion loss prediction (DADA-LP). First, we construct a lightweight feature extraction model (HS-KDNet). HS-KDNet leverages soft labels from knowledge distillation to characterize the similarity between different categories. Next, we develop a single active domain adaptation algorithm through active learning evaluation, which can be used to select a sample of target domains with an active learning value evaluation. Finally, we enhance it into a DADA-LP algorithm, incorporating a loss prediction strategy in the source domain. Moreover, this model ensures outstanding IIoT intrusion detection under imperfect samples, effectively addressing the negative transfer issue. Four datasets from the IIoT are employed to validate the performance of our model. The results unequivocally demonstrate the excellent detection performance when applied to IIoT intrusion detection scenarios under imperfect samples. Wengang Ma, Xiaolong Lan |
IEEE Internet Things J. | 1 |
| 2025 | Unknown Cyber Threat Discovery Empowered by Genetic Evolution Without Prior KnowledgeabstractWith the continuous development of cyber-attack technologies, attackers increasingly exploit zero-day vulnerabilities or leverage emerging techniques to launch sophisticated attacks, resulting in the persistent emergence of unknown cyber-attacks. However, traditional DL-based cyber-attack detection methods heavily rely on large-scale labeled training data. In practice, obtaining sufficient samples of unknown attacks is challenging, which makes it difficult for these methods to effectively defend against unknown cyber-attacks. In this paper, we propose a method for discovering unknown cyber threats empowered by genetic evolution without prior knowledge. Specifically, We, first mapped the network feature space into a gene framework, and divided the attack genes into a static gene region (SGZ) and a dynamic gene region (DGZ) according to the importance of the cyber-attack genes. Subsequently, leveraging the known attack genes, we utilized different gene evolution strategies and a Convolutional Autoencoder (CAE) to generate attack variants and potential unknown attack genes. Finally, we constructed a cyber-attack detection model incorporating both the global attention mechanism (GAM) and the local attention mechanism (LAM). The generated attack variants and unknown attack genes are the used to enhance the detection ability of the detection model for variants and unknown cyber-attacks. We conducted a large number of experiments on six real and authoritative network datasets. The experimental results show that in different scenario settings, the F1 scores of our proposed method for detecting unknown attacks are 84.64% and 95.77% respectively. The F1 score for detecting unknown attacks on the UNSW-NB15 dataset exceeds that of the baseline classifier. The F1 score for detecting unknown attacks on the CSE-CIC-IDS2018 dataset is 98.85%. In comparison with SOTA methods, the average F1 score is improved by 3.14%. In the evaluation of variant detection performance, the generation method we proposed improves the detection of variants by approximately 11.2%, surpassing generation methods such as the Conditional Generative Adversarial Network (CGAN) and the Variational Autoencoder (VAE). Meanwhile, we also comprehensively evaluated the generalization ability of our proposed method and the evolution ability of different evolution strategies on different datasets and through ablation experiments. Wenbo Fang, Junjiang He, Wenshan Li 0001, Wengang Ma, Linlin Zhang 0005, Xiaolong Lan, Geying Yang, Jiangchuan Chen, Tao Li 0016 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | A multi-constraint transfer approach with additional auxiliary domains for IoT intrusion detection under unbalanced samples distribution
Ruiqi Liu 0004, Wengang Ma |
Appl. Intell. | 2 |
| 2024 | Multi-source refined adversarial domain adaptation with transfer complementarity infusion for IoT intrusion detection under limited samples
Kehong Li, Wengang Ma, Huawei Duan |
Expert Syst. Appl. | 2 |
| 2024 | A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine DistributionabstractUnmanned aerial vehicles (UAVs) have experienced rapid development, permeating diverse domains. However, addressing security challenges in UAV networks remains daunting due to resource limitations and the high autonomy of UAV terminals. The current research on the UAV network intrusion detection lacks an efficient process covering each UAV terminal and a lightweight collaborative response mechanism between the UAVs and ground stations, which affects the performance of the UAV network intrusion detection. In this article, inspired by the vaccine distribution mechanism in artificial immune systems, we propose a hierarchical UAV network intrusion detection and response approach based on the vaccine distribution. Specifically, we first implement an immune game-based negative selection algorithm at the ground station, to effectively generate vaccines covering the immune space. Then, we distribute vaccines to the UAV terminals, empowering them with intrusion detection capabilities. Finally, we introduce a collaborative response mechanism to enable the intrusion detection at the UAV terminals and perform terminal state assessments. We evaluate the performance of our proposed approach on a large number of the real UAV network data sets. The experimental results indicate that our proposed intrusion detection approach for the UAV networks at the ground stations surpasses all the baseline models. In scenarios involving air-ground coordination, our suggested collaborative response approach proves to be effective in enabling intrusion detection at the UAV terminal, facilitating timely and efficient UAV intrusion detection. Moreover, we demonstrate on the ALFA and NSL-KDD data sets that our approach excels in detecting UAV network intrusions. Particularly, on real UAV network data (ALFA), the detection rate reaches 99.05% and the accuracy is 96.13% surpassing the other models by approximately 6%. Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 6 |
| 2024 | Corrections to "A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution"abstractPresents corrections to the paper, (Corrections to “A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution”). Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 6 |
| 2024 | Optimal Age of Information and Throughput Scheduling in Heterogeneous Traffic Wireless Physical-Layer Security CommunicationsabstractA wireless multi-user uplink heterogeneous network is investigated in this paper, which comprises an access point and two distinct user groups including throughput-oriented users and age of information (AoI)-oriented users, in which throughput-oriented users prioritize achieving as high throughput as possible, while AoI-oriented users emphasize timely transmission of information. It is assumed that the transmitted information needs to be kept strictly confidential to unintended users, and the time-division multiple access (TDMA) approach is adopted to transmit confidential information of each user. For such a network, all users who are not scheduled for transmission will be treated as potential eavesdroppers. The objective of our work is to maximize the average achievable secrecy rate of throughput-oriented users while minimizing the average AoI of AoI-oriented users subject to the data queue causality and stability constraints, the sampling rate requirements of AoI-oriented users, the time-averaged and peak transmission power constraints, and the user scheduling constraint. We propose using Lyapunov optimization to convert the original time-averaged optimization problem into a sequence of real-time ones associated with both queue sizes and AoI involved in the current time slot. On this basis, an adaptive heterogeneous traffic security transmission (AHTST) strategy is proposed to determine the optimal strategies for the flow control of throughput-oriented users, the sampling rate control of AoI-oriented users, the power allocation, as well as the user scheduling. Numerical results demonstrate that the AHTST strategy surpasses the considered benchmark schemes in both achievable average secrecy rate and average AoI. Xiaolong Lan, Junjiang He, Wengang Ma, Qingchun Chen |
IEEE Internet Things J. | 6 |
| 2024 | A source free robust domain adaptation approach with pseudo-labels uncertainty estimation for rolling bearing fault diagnosis under limited sample conditions
Wengang Ma, Feipeng Kuang |
Knowl. Based Syst. | 2 |
| 2023 | LDoS attack traffic detection based on feature optimization extraction and DPSA-WGAN
Wengang Ma |
Appl. Intell. | 1 |
| 2023 | An unsupervised domain adaptation approach with enhanced transferability and discriminability for bearing fault diagnosis under few-shot samples
Wengang Ma, Shan Yan |
Expert Syst. Appl. | 1 |
| 2023 | An adversarial domain adaptation approach combining dual domain pairing strategy for IoT intrusion detection under few-shot samples
Wengang Ma, Ruiqi Liu 0004, Kehong Li, Shan Yan |
Inf. Sci. | 1 |
| 2022 | Unbalanced network attack traffic detection based on feature extraction and GFDA-WGAN
Kehong Li, Wengang Ma, Huawei Duan, Juanxiu Zhu |
Comput. Networks | 2 |
| 2022 | Few-shot IoT attack detection based on RFP-CNN and adversarial unsupervised domain-adaptive regularization
Kehong Li, Wengang Ma, Huawei Duan, Juanxiu Zhu |
Comput. Secur. | 2 |
| 2021 | Unbalanced abnormal traffic detection based on improved Res-BIGRU and integrated dynamic ELM optimization
Wengang Ma, Kehong Li |
Comput. Commun. | 1 |