Heyu Chang

dblp:294/5627 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0001-8156-3347ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Intelligent malware detection method based on memory segments
abstract
Abstract To overcome the significant challenges posed by new variants of malware to conventional detection techniques, such as low automation, reliance on expert knowledge, and inadequate capability to detect unknown threats in existing memory analysis methods, this paper designs an intelligent detection algorithm for malicious memory segments based on a one-dimensional convolutional network. This algorithm takes raw memory byte sequences as input, referred to as memory segments, and employs a one-dimensional convolutional neural network to automatically learn their deep features and inherent relationships. This approach facilitates an end-to-end automated analysis from data to detection, thereby eliminating the need for complex manual feature engineering. Experimental results show that the designed algorithm achieves a maximum accuracy of 98.28%, precision of 98.94%, recall of 97.6%, F1-score of 0.9826, and AUC value of 0.9972 on the test set, showcasing outstanding detection performance and generalization capability for malicious memory segments. This research offers a novel and effective method for efficient and accurate memory-based malware detection, which can significantly enhance proactive security defense capabilities.
Shilong Yu, Binglong Li, Yifeng Sun, Heyu Chang
Cybersecur.6
2026 FusionITD: enhanced cross-modal insider threat perception framework via behavior-semantic fusion
abstract
Abstract In recent years, insider threat incidents have occurred with increasing frequency, leading to severe data breaches and substantial economic losses. Most existing insider threat detection methods rely primarily on single-modal features, such as system logs and registry data, while failing to fully exploit the rich semantic information embedded in instant messaging and email content of insider users. To address the above issues, we propose FusionITD, a cross-modal insider threat perception enhancement framework based on the fusion of behavioral and semantic features. This framework combines users’ temporal behavioral characteristics such as file operations and login device patterns with the semantic information derived from web browsing and email content. By modeling user behavior baselines from multiple dimensions, FusionITD enables more accurate anomaly detection when deviations from the baseline occur. Firstly, based on the temporal distribution of user behaviors, the behavior data is segmented and aggregated according to the time window to form a user behavior graph. We propose WR-GNN based on graph representation learning to capture temporal behavioral features, and introduce the Focal MSE loss function to address the data imbalance problem caused by sparse abnormal behavior data. Secondly, we propose a retrieval-augmented generation-based semantic analysis algorithm. We use cosine similarity to perform semantic matching and ranking between behavioral contents and historical behaviors. We extract features such as emotion, intention, and focus to achieve fine-grained anomaly detection for user behavior. Finally, we designed an adaptive weighting mechanism based on logistic regression to dynamically integrate the outputs of the previous two parts, enhancing the generalization ability for different threat scenarios. Experimental results conducted on the CERT datasets show that FusionITD outperforms other methods by achieving a 5% increase in AUC, a higher TPR, and a lower false positive rate.
Lu Yuan 0002, Dexian Chang, Hao Hu 0005, Yingchang Jiang, Heyu Chang, Liguo Fang
Cybersecur.5
2026 Gradient-aware knowledge distillation: Tackling gradient insensitivity through teacher guided gradient scaling
Nianwen Si, Hao Zhang 0109, Weiqiang Zhang 0001, Heyu Chang, Dan Qu 0003
Neural Networks5
2025 MPN: Leveraging Multilingual Patch Neuron for Cross-Lingual Model Editing
Nianwen Si, Heyu Chang, Weiqiang Zhang 0001
KSEM (2)2
2025 T-Sanitation: contrastive masked auto-encoder-based few-shot learning for malicious traffic detection
Lu Yuan 0002, Heyu Chang
J. Supercomput.5
2024 A lightweight packet forwarding verification in SDN using sketch
Heyu Chang, Nianwen Si
Comput. Secur.1
2022 Fine-grained visual explanations for the convolutional neural network via class discriminative deconvolution
Nianwen Si, Heyu Chang, Dongning Zhao
Multim. Tools Appl.4
2021 Spatial-Channel Attention-Based Class Activation Mapping for Interpreting CNN-Based Image Classification Models
abstract
Convolutional neural network (CNN) has been applied widely in various fields. However, it is always hindered by the unexplainable characteristics. Users cannot know why a CNN-based model produces certain recognition results, which is a vulnerability of CNN from the security perspective. To alleviate this problem, in this study, the three existing feature visualization methods of CNN are analyzed in detail firstly, and a unified visualization framework for interpreting the recognition results of CNN is presented. Here, class activation weight (CAW) is considered as the most important factor in the framework. Then, the different types of CAWs are further analyzed, and it is concluded that a linear correlation exists between them. Finally, on this basis, a spatial-channel attention-based class activation mapping (SCA-CAM) method is proposed. This method uses different types of CAWs as attention weights and combines spatial and channel attentions to generate class activation maps, which is capable of using richer features for interpreting the results of CNN. Experiments on four different networks are conducted. The results verify the linear correlation between different CAWs. In addition, compared with the existing methods, the proposed method SCA-CAM can effectively improve the visualization effect of the class activation map with higher flexibility on network structure.
Nianwen Si, Dan Qu 0003, Xiangyang Luo 0001, Heyu Chang
Secur. Commun. Networks5