EDBT 2026 Demo / reviewers in the wild / expert
Xianwen Deng
dblp:315/6039
· DBLP profile ↗
20ranked-venue papers
6as first author
20since 2021 · last 2026
0000-0002-6611-5295ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Computer networks · 5 · 5 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Z-Solver: A Zero-Label Captcha Solver via Unsupervised Domain Adaptation from Synthetic Data
Weiqi Bai, Xianwen Deng, Zhi Xue |
ICC | 2 |
| 2026 | RateSniffer: A Lightweight and Robust Website Fingerprinting Defense via Rate-Aware Morphing
Xianwen Deng, Weiqi Bai, Zhi Xue |
ICC | 2 |
| 2026 | Learning Flow Semantics for Encrypted Traffic Analysis: A Contrastive Pre-Training ApproachabstractEncrypted traffic analysis is crucial for cyberspace security. Self-supervised learning shows great promise to enhance traffic analysis with the pre-trained traffic encoder, which is constructed using large-scale, readily available unlabeled traffic data. However, existing approaches struggle to handle the increasingly prevalent encrypted traffic, as their generative reconstruction tasks cannot process encrypted content. To this end, we propose TACO, a robust and flexible encrypted traffic analysis system based on flow semantics learning. Specifically, we first design several feasible traffic data augmentation strategies to prepare flow semantics knowledge from the unlabeled traffic. Then, our traffic encoder with a traffic partition module learns the semantics knowledge based on the contrastive pre-training paradigm. It serves as a traffic foundation encoder that can comprehend flow semantics and extract effective semantic representations. Finally, we fine-tune the traffic encoder to leverage flow semantics for various downstream encrypted traffic analysis tasks. The experimental results illustrate that TACO outperforms the optimal baseline by 7.5% in average F1 score on four traffic classification datasets and achieves an improvement of at least 11.62% in average F1 score on the three transfer tasks, while indicating superior efficiency. We will release the source code as well as the experiment data upon publication to foster future research. Ruijie Zhao 0001, Mingwei Zhan, Qi Li 0002, Zhuotao Liu, Xianwen Deng, Guang Cheng 0001, Zhi Xue, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Leveraging Frozen Batch Normalization for Co-Training in Source-Free Domain AdaptationabstractSource-free domain adaptation (SFDA) aims to adapt a source model, initially trained on a fully-labeled source domain, to an unlabeled target domain. Previous works assume that the statistics of Batch Normalization layers in the source model capture domain-specific knowledge and directly replace them with target domain-related statistics during training. However, our observations indicate that \emph{source-like} samples in target data exhibit less deviation in the feature space of the source model when preserving the source domain-relevant statistics. In this paper, we propose co-training the source model with frozen Batch Normalization layers as part of the domain adaptation process. Specifically, we combine the source model and the target model to produce more robust pseudo-labels for \emph{global} class clustering and to identify more precise neighbor samples for \emph{local} neighbor clustering. Extensive experiments validate the effectiveness of our approach, showcasing its superiority over current state-of-the-art methods on three standard benchmarks. Our codes are available on \url{https://github.com/SJTU-dxw/BN-SFDA.} Xianwen Deng, Zhi Xue |
AISTATS | 1 |
| 2025 | Robust Training of Efficient Traffic Classifier with Noisy Labels
Zuoyu Qiu, Mingwei Zhan, Xianwen Deng, Zhi Xue, Ruijie Zhao 0001 |
Inscrypt (2) | 3 |
| 2025 | Multi-modal Datagram Representation with Spatial-Temporal State Space Models and Inter-flow Contrastive Learning for Encrypted Traffic Classification
Xianwen Deng, Ruijie Zhao 0001, Mingwei Zhan, Shaoqian Wu, Zhi Xue |
ICICS (3) | 1 |
| 2025 | FlowRefiner: A Robust Traffic Classification Framework against Label NoiseabstractNetwork traffic classification is essential for network management and security. In recent years, deep learning (DL) algorithms have emerged as essential tools for classifying complex traffic. However, they rely heavily on high-quality labeled training data. In practice, traffic data is often noisy due to human error or inaccurate automated labeling, which could render classification unreliable and lead to severe consequences. Although some studies have alleviated the label noise issue in specific scenarios, they are difficult to generalize to general traffic classification tasks due to the inherent semantic complexity of traffic data. In this paper, we propose FlowRefiner, a robust and general traffic classification framework against label noise. FlowRefiner consists of three core components: a traffic semantics-driven noise detector, a confidence-guided label correction mechanism, and a cross-granularity robust classifier. First, the noise detector utilizes traffic semantics extracted from a pre-trained encoder to identify mislabeled flows. Next, the confidence-guided label correction module fine-tunes a label predictor to correct noisy labels and construct refined flows. Finally, the cross-granularity robust classifier learns generalized patterns of both flow-level and packet-level, improving classification robustness against noisy labels. We evaluate our method on four traffic datasets with various classification scenarios across varying noise ratios. Experimental results demonstrate that FlowRefiner mitigates the impact of label noise and consistently outperforms state-of-the-art baselines by a large margin. The code is available at https://github.com/NSSL-SJTU/FlowRefiner. Mingwei Zhan, Ruijie Zhao 0001, Xianwen Deng, Zhi Xue, Qi Li 0002, Zhuotao Liu, Guang Cheng 0001, Ke Xu 0002 |
NeurIPS | 3 |
| 2025 | Countmamba: A Generalized Website Fingerprinting Attack via Coarse-Grained Representation and Fine-Grained PredictionabstractTor is the leading low-latency anonymous communication network, widely used to protect users' privacy through mechanisms such as random relay selection. However, despite these defenses, Tor traffic remains susceptible to website finger-printing (WF) attacks, where attackers analyze side-channel information (e.g., packet size, direction, inter-packet timing) to infer visited websites. Although WF attacks have shown high success rates in controlled settings, they rely on complete, unperturbed traffic, making them vulnerable to real-world de-fense mechanisms. Traditional WF approaches, which typically employ Machine Learning (ML) or Deep Learning (DL) to classify packet sequences as a single-label prediction, struggle to generalize in practical scenarios, especially under defenses that alter packet patterns or in environments requiring multi-label, early-stage analysis. In this work, we introduce Countmamba, a robust and adaptable WF attack framework designed to address the challenges posed by real-world defenses, early-stage traffic analysis, and multi-tab browsing. Countmamba employs a Windowed Traffic Counting Matrix (WTCM) to create re-silient, coarse-grained traffic representations by aggregating packet events within fixed time intervals, allowing it to with-stand moderate perturbations from defenses. Additionally, a state-space-oriented (SSO) classifier incrementally generates fine-grained predictions from partial traffic data, maintaining high attack accuracy while enabling early-stage and multi-tab attack capabilities. Unlike prior WF methods, Countmamba iteratively updates predictions as new data arrives, eliminating the need for complete traffic capture and enabling reliable inference even in complex, multi-tab environments. Extensive experiments demonstrate that Countmamba outperforms state-of-the-art WF attacks across robust, early-stage, and multi-tab scenarios, highlighting its applicability for realistic, adaptive WF analysis in Tor networks. The source code as well as the experiment data is available at https://github.com/SJTU-dxw/CountMamba-WF. Xianwen Deng, Ruijie Zhao 0001, Mingwei Zhan, Zhi Xue |
SP | 1 |
| 2024 | CaptchaSAM: Segment Anything in Text-based CaptchasabstractWhile text-based captchas, designed to distinguish between human users and bots, have encountered numerous attack methods, they remain a prevalent security mechanism employed by various websites. Some deep learning-based approaches can recognize captcha character sequences end-to-end; however, the labor-intensive and time-consuming labeling process severely restricts their feasibility. In this study, we introduce CaptchaSAM, to segment anything in text-based captchas. Our insight lies in the fact that identifying individual characters is a simpler task compared to recognizing character sequences, leading to a substantial reduction in labeling dependency. To accomplish this, we utilize the Segment Anything Model (SAM) for character-level semi-automatic annotation. Subsequently, we leverage the annotated data to train a semantic segmentation model. Our experiments with real-world captcha systems demonstrate that CaptchaSAM significantly outperforms state-of-the-art methods with just a few labeled captchas. We anticipate that our research will encourage security experts to reconsider the design and deployment of text-based captchas. The source code is accessible at https://github.com/SJTU-dxw/CaptchaSAM. Weiqi Bai, Ruijie Zhao 0001, Xianwen Deng |
TrustCom | 5 |
| 2024 | AN-Net: an Anti-Noise Network for Anonymous Traffic Classification
Xianwen Deng, Zhi Xue |
WWW | 1 |
| 2024 | A Novel Self-Supervised Framework Based on Masked Autoencoder for Traffic ClassificationabstractTraffic classification is a critical task in network security and management. Recent research has demonstrated the effectiveness of the deep learning-based traffic classification method. However, the following limitations remain: (1) the traffic representation is simply generated from raw packet bytes, resulting in the absence of important information; (2) the model structure of directly applying deep learning algorithms does not take traffic characteristics into account; and (3) scenario-specific classifier training usually requires a labor-intensive and time-consuming process to label data. In this paper, we introduce a masked autoencoder (MAE) based traffic transformer with multi-level flow representation to tackle these problems. To model raw traffic data, we design a formatted traffic representation matrix with hierarchical flow information. After that, we develop an efficient Traffic Transformer, in which packet-level and flow-level attention mechanisms implement more efficient feature extraction with lower complexity. At last, we utilize MAE paradigm to pre-train our classifier with a large amount of unlabeled data, and perform fine-tuning with a few labeled data for a series of traffic classification tasks. Experiment findings reveal that our method outperforms state-of-the-art methods on five real-world traffic datasets by a large margin. The code is available at https://github.com/NSSL-SJTU/YaTC. Ruijie Zhao 0001, Mingwei Zhan, Xianwen Deng, Fangqi Li 0001, Guan Gui 0001, Zhi Xue |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | Yet Another Traffic Classifier: A Masked Autoencoder Based Traffic Transformer with Multi-Level Flow RepresentationabstractTraffic classification is a critical task in network security and management. Recent research has demonstrated the effectiveness of the deep learning-based traffic classification method. However, the following limitations remain: (1) the traffic representation is simply generated from raw packet bytes, resulting in the absence of important information; (2) the model structure of directly applying deep learning algorithms does not take traffic characteristics into account; and (3) scenario-specific classifier training usually requires a labor-intensive and time-consuming process to label data. In this paper, we introduce a masked autoencoder (MAE) based traffic transformer with multi-level flow representation to tackle these problems. To model raw traffic data, we design a formatted traffic representation matrix with hierarchical flow information. After that, we develop an efficient Traffic Transformer, in which packet-level and flow-level attention mechanisms implement more efficient feature extraction with lower complexity. At last, we utilize the MAE paradigm to pre-train our classifier with a large amount of unlabeled data, and perform fine-tuning with a few labeled data for a series of traffic classification tasks. Experiment findings reveal that our method outperforms state-of-the-art methods on five real-world traffic datasets by a large margin. The code is available at https://github.com/NSSL-SJTU/YaTC. Ruijie Zhao 0001, Mingwei Zhan, Xianwen Deng, Guan Gui 0001, Zhi Xue |
AAAI | 3 |
| 2023 | SAWD: Structural-Aware Webshell Detection System with Control Flow GraphabstractWith the increasing prevalence of web servers, protecting them from cyber attacks has become a crucial task for online service providers.Webshells, which are backdoors to websites, are commonly used by hackers to gain unauthorized access to web servers.However, traditional methods for detecting webshells often fail to produce satisfactory results due to the use of obfuscation or encryption to conceal their characteristics.In recent years, webshell detection methods based on deep learning (DL) have received significant attention, but they struggle to preserve the syntax and semantic information contained in the source code.In this paper, we propose a structuralaware webshell detection system to address these problems, denoted as SAWD.Specifically, we first generate the control flow graph (CFG) with syntax and semantic information from the PHP source code.Then, we leverage CFG to build our graph representation, which consists of the adjacency matrix and keywords-based basic block features.Finally, based on our graph representation, we adopt convolutional neural networks (GCN) combined with graph pooling to detect webshells more efficiently.Experimental results demonstrate that our method outperforms state-of-the-art webshell detection systems on the collected dataset. Junmin Zhu, Yizhao Yao, Xianwen Deng, Yaoguang Yong, Libo Chen 0001, Zhi Xue, Ruijie Zhao 0001 |
SEKE | 3 |
| 2023 | GeeSolver: A Generic, Efficient, and Effortless Solver with Self-Supervised Learning for Breaking Text CaptchasabstractAlthough text-based captcha, which is used to differentiate between human users and bots, has faced many attack methods, it remains a widely used security mechanism and is employed by some websites. Some deep learning-based text captcha solvers have shown excellent results, but the labor-intensive and time-consuming labeling process severely limits their viability. Previous works attempted to create easy-to-use solvers using a limited collection of labeled data. However, they are hampered by inefficient preprocessing procedures and inability to recognize the captchas with complicated security features.In this paper, we propose GeeSolver, a generic, efficient, and effortless solver for breaking text-based captchas based on self-supervised learning. Our insight is that numerous difficult-to-attack captcha schemes that "damage" the standard font of characters are similar to image masks. And we could leverage masked autoencoders (MAE) to improve the captcha solver to learn the latent representation from the "unmasked" part of the captcha images. Specifically, our model consists of a ViT encoder as latent representation extractor and a well-designed decoder for captcha recognition. We apply MAE paradigm to train our encoder, which enables the encoder to extract latent representation from local information (i.e., without masking part) that can infer the corresponding character. Further, we freeze the parameters of the encoder and leverage a few labeled captchas and many unlabeled captchas to train our captcha decoder with semi-supervised learning.Our experiments with real-world captcha schemes demonstrate that GeeSolver outperforms the state-of-the-art methods by a large margin using a few labeled captchas. We also show that GeeSolver is highly efficient as it can solve a captcha within 25 ms using a desktop CPU and 9 ms using a desktop GPU. Besides, thanks to latent representation extraction, we successfully break the hard-to-attack captcha schemes, proving the generality of our solver. We hope that our work will help security experts to revisit the design and availability of text-based captchas. The code is available at https://github.com/NSSL-SJTU/GeeSolver. Ruijie Zhao 0001, Xianwen Deng, Zhicong Yan, Zhengguang Han, Libo Chen 0001, Zhi Xue |
SP | 2 |
| 2023 | A Novel Traffic Classifier With Attention Mechanism for Industrial Internet of ThingsabstractWith the development of the Industrial Internet of Things (IIoT), the complex traffic generated by large-scale IIoT devices presents challenges for traffic analysis. Most of existing deep learning-based traffic analysis methods use a single flow for classification, resulting in being misled by the irrelevant flow. Thus, it is necessary to use flow sequences for traffic analysis. However, existing models fail to effectively distinguish unimportant flows in flow sequence, which affects the classification performance. To address the aforementioned challenges, we propose a novel traffic classifier called flow transformer to perform traffic analysis with flow sequences, which leverages multihead attention mechanism to strengthen the information interaction between related flows. Besides, the RF-based feature selection method is designed to select the optimal feature combination, avoiding insignificant features from reducing the performance of the classifier. Experimental results on three real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Yiteng Huang, Xianwen Deng, Yong Shi 0009, Jiabin Li, Zijing Huang, Zhi Xue |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | 3E-Solver: An Effortless, Easy-to-Update, and End-to-End Solver with Semi-Supervised Learning for Breaking Text-Based CaptchasabstractText-based captchas are the most widely used security mechanism currently. Due to the limitations and specificity of the segmentation algorithm, the early segmentation-based attack method has been unable to deal with the current captchas with newly introduced security features (e.g., occluding lines and overlapping). Recently, some works have designed captcha solvers based on deep learning methods with powerful feature extraction capabilities, which have greater generality and higher accuracy. However, these works still suffer from two main intrinsic limitations: (1) many labor costs are required to label the training data, and (2) the solver cannot be updated with unlabeled data to recognize captchas more accurately. In this paper, we present a novel solver using improved FixMatch for semi-supervised captcha recognition to tackle these problems. Specifically, we first build an end-to-end baseline model to effectively break text-based captchas by leveraging encoder-decoder architecture and attention mechanism. Then we construct our solver with a few labeled samples and many unlabeled samples by improved FixMatch, which introduces teacher forcing, adaptive batch normalization, and consistency loss to achieve more effective training. Experiment results show that our solver outperforms state-of-the-arts by a large margin on current captcha schemes. We hope that our work can help security experts to revisit the design and usability of text-based captchas. The source code of this work is available at https://github.com/SJTU-dxw/3E-Solver-CAPTCHA. Xianwen Deng, Ruijie Zhao 0001, Libo Chen 0001, Zhi Xue |
IJCAI | 1 |
| 2022 | Flow Sequence-Based Anonymity Network Traffic Identification with Residual Graph Convolutional NetworksabstractIdentifying anonymity services from network traffic is a crucial task for network management and security. Currently, some works based on deep learning have achieved excellent performance for traffic analysis, especially those based on flow sequence (FS), which utilizes information and features of the traffic flow. However, these models still face a serious challenge because of lacking a mechanism to take into account relationships between flows, resulting in mistakenly recognizing irrelevant flows in FS as clues for identifying traffic. In this paper, we propose a novel FS-based anonymity network traffic identification framework to tackle this problem, which leverages Residual Graph Convolutional Network (ResGCN) to exploit relationships between flows for FS feature extraction. Moreover, we design a practical scheme to preprocess the raw data of real-world traffic, which further improves identification performance and efficiency. Experimental results on two real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods by a large margin. Ruijie Zhao 0001, Xianwen Deng, Libo Chen 0001, Zhi Xue |
IWQoS | 2 |
| 2022 | MT-FlowFormer: A Semi-Supervised Flow Transformer for Encrypted Traffic ClassificationabstractWith the increasing demand for the protection of personal network meta-data, encrypted networks have grown in popularity, so do the challenge of monitoring and analyzing encrypted network traffic. Currently, some deep learning-based methods have been proposed to leverage statistical features for encrypted traffic classification, which are barely affected by encryption techniques. However, these works still suffer from two main intrinsic limitations: (1) the feature extraction process lacks a mechanism to take into account correlations between flows in the flow sequence; and (2) a large volume of manually-labeled data is required for training an effective deep classifier. In this paper, we propose a novel semi-supervised framework to address these problems. To be specific, an efficient classifier with attention mechanism is proposed to extract features from flow sequences with low computational cost. Then, a Mean Teacher-style semi-supervised framework is adopted to exploit the unlabeled traffic data, where a spatiotemporal data augmentation method is designed as the key component to explore the spatial and temporal relationship within the unlabeled traffic data. Experimental results on two real-world traffic datasets demonstrate that our method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Xianwen Deng, Zhicong Yan, Zhi Xue |
KDD | 2 |
| 2021 | Flow Transformer: A Novel Anonymity Network Traffic Classifier with Attention MechanismabstractSupervising anonymity network is a critical issue in the field of network security, and traditional traffic analysis methods cannot cope with complex anonymity traffic. In recent years, the traffic analysis method based on deep learning has achieved good performance. However, most of the existing studies do not consider the temporal-spatial correlation of the traffic, and only use a single flow for classification. A few works take continuous flows as flow sequence for traffic classification, but they do not distinguish the different importance of each flow. To tackle this issue, we propose a novel flow-based traffic classifier called FLOW TRANSFORMER to classify anonymity network traffic. FLOW TRANSFORMER uses multi-head attention mechanism to set higher weights for important flows, and extracts flow sequence features according to the importance weights. Besides, the RF-based feature selection method is designed to select the optimal feature combination, which can effectively avoid the insignificant features from reducing the performance and efficiency of the classifier. Experimental results on two real-world traffic datasets demonstrate that the proposed method outperforms state-of-the-art methods with a large margin. Ruijie Zhao 0001, Yiteng Huang, Xianwen Deng, Zhi Xue, Jiabin Li, Zijing Huang |
MSN | 3 |
| 2021 | A Semi-supervised Deep Learning-Based Solver for Breaking Text-Based CAPTCHAsabstractText-based CAPTCHAs are still the most widely used CAPTCHA mode. Many researchers have proposed attack methods to break them. In previous attacks, segmentation-based methods require at least three steps: preprocessing, segmentation, and recognition, which means that different modes of CAPTCHA require various preprocessing and segmentation algorithms. In recent years, a series of deep learning (DL) models have been designed for cracking text-based CAPTCHAs. However, these methods require annotating numerous images, which are time-consuming and labor-intensive. In this paper, we propose a semi-supervised DL-based solver for breaking text-based CAPTCHAs, which can use a small number of labeled CAPTCHAs to achieve a high-performance attack model. The CNN module and the attention-based Seq2Seq module are two key components for effective feature extraction and character recognition. The experimental results show that our solver successfully attacked 9 types of most popular text-based CAPTCHAs, and the attack success rate is better than the four latest attack models. In addition, our model does not perform any data preprocessing and has a fast attack speed, making it more suitable for real-time attacks. The code and dataset are available on the github. Xianwen Deng, Ruijie Zhao 0001, Zhi Xue, Libo Chen 0001 |
TrustCom | 1 |