Weihong Han

dblp:33/4604 · DBLP profile ↗
← Back
44ranked-venue papers
7as first author
27since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 13 · 6 first-author · 5 since 2021Security and privacy · 9 · 8 since 2021Computer networks · 6 · 6 since 2021Artificial intelligence and machine learning · 5 · 3 since 2021Databases, data management, data science and information retrieval · 5 · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 A Stackelberg game based deception defense strategy against APT under resource constraints
Pengdeng Li, Rui Wang 0007, Yuan Liu 0002, Weihong Han, Zhihong Tian 0001
Sci. China Inf. Sci.6
2026 AutoGuard: Unified and lightweight cross-layer intrusion detection for automotive ethernet via contextual traffic analysis
Wentao Shang, Shuyuan Jin, Weihong Han
Comput. Networks3
2026 MTDecipher: robust encrypted malicious traffic detection via multi-task graph neural networks
abstract
Abstract The widespread adoption of encrypted traffic protocols has significantly increased the challenge of detecting malicious traffic. Existing detection methods based on deep learning typically rely on fine-grained features of data packets, such as length sequences and intra-flow interaction graphs. However, these features are highly susceptible to disruption by diverse network environments and traffic obfuscation. This paper proposes MTDecipher, a robust method for detecting encrypted malicious traffic based on multi-task Graph Neural Network (GNN). MTDecipher employs a bidirectional attentive sequence encoder to mitigate the impact of diverse network environments and traffic obfuscation on packet length sequences, along with an edge-block dual sampling method and a multi-task GNN model to mitigate the training bias introduced by the unbalanced distribution of traffic. In the bidirectional attentive sequence encoder, a combination of a Bi-GRU layer and an attention pooling layer is utilized to enhance the bidirectional encoding by generating weights for each element in the sequence, thereby obtaining robust encrypted traffic sequence features. In the edge-block dual sampling method, two rounds of sampling are involved to generate more evenly distributed subgraphs as training data, which reduces the local structural bias resulting from the aggregation of malicious flows. In the multi-task GNN model, the losses for both edge and node classification tasks are simultaneously optimized, thereby minimizing the homogeneity of adjacent edges. Experimental results on two real-world datasets with traffic obfuscation demonstrate that MTDecipher outperforms eight existing methods in terms of effectiveness in detecting encrypted malicious traffic.
Fan Li 0019, Weihong Han, Binxing Fang, Lihua Yin
Cybersecur.3
2026 BotEvolver: Continuous Botnet Detection in Unlabeled Incremental Network Flows
abstract
In dynamic Internet of Things (IoT) networks, unlabeled incremental network flows with evolving distributions severely degrade the performance of deep learning-based botnet detection systems, primarily due to catastrophic forgetting and reliance on labeled data. This work proposes BotEvolver, a novel framework for continuous, efficient, and interpretable botnet detection in incremental flow environments. BotEvolver integrates two core components: (1) an experience replay-enabled incremental detection model via an attention-based inductive Graph Neural Network (GNN), that preserves key botnet subgraphs to mitigate catastrophic forgetting and enhance interpretability; (2) a multi-feature active annotation model that generates high-precision pseudo-labels while reducing the number of IPs requiring manual annotation in incremental data from the CTU13 dataset to98.6% F1-score across incremental rounds. Overhead tests confirm its practicality where peak Graphics Processing Unit (GPU) VRAM occupancy is ≈1GB, throughput reaches 55.46k flows/sec and 12.83k IPs/sec, and pre-trained models are ≈12MB, enabling distributed deployment for real-time monitoring.
Fan Li 0019, Weihong Han, Binxing Fang, Lihua Yin, Jianye Yang 0001
IEEE Internet Things J.3
2026 An Improved Quantitative Assessment Method for Cybersecurity Situation Awareness
Omar I. Alsaleh, Hafiz Muhammad Jamsheed Nazir, Weihong Han
IEEE Trans. Dependable Secur. Comput.3
2026 Learning Sequential Deception Defense Strategy Against APT Using Stackelberg Markov Game
abstract
Advanced Persistent Threats (APTs) have become one of the most prominent cybersecurity risks globally. The external network-facing (ENF) services (e.g., e-commerce platforms) within a system are particularly vulnerable, as they are directly exposed to the Internet and often serve as the primary targets for attackers. By deploying deception resources to protect these ENF services, defenders can detect threats early, block potential attacks, and enhance overall system resilience. However, most existing studies on cyber deception strategies assume simultaneous moves by both attacker and defender. Furthermore, few works have considered the evolution of the system state resulting from APT attacks on the ENF services. To address these limitations, this paper proposes a Cyber Deception Stackelberg Markov Game (CDSMG) for protecting ENF services, which dynamically captures state transitions and accurately characterizes the strategic interactions between defenders and APT attackers. In CDSMG, the defender acts as the leader, who proactively selects a subset of services to deploy the deception resources based on the current system state, while the APT attacker plays as the follower, making a best response which incorporates the defender’s policy into its own strategy. To overcome the challenge of the combinatorial optimization problem of selecting a subset of services, we propose a revised version of the PPO algorithm by using no-replacement sampling to select multiple services at once, thereby significantly reducing the action space size. Finally, experimental results demonstrate that our approach effectively defends against APT attacks. It not only outperforms several baseline methods but also exhibits better scalability and robustness under varied model parameter settings.
Pengdeng Li, Rui Wang 0007, Jinglei Tan, Yuan Liu 0002, Weihong Han, Zhihong Tian 0001
IEEE Trans. Inf. Forensics Secur.6
2025 IntelliTopo: An IaC Generation Service for Industrial Network Topology Construction
abstract
Network topology construction in this paper refers to designing the structural layouts and configuration rules among network devices according to natural language requirements in network simulation. Relatedly, Infrastructure as Code (IaC) enables the configuration and management of network devices through machine-readable code. Although there exist IaC generation approaches powered by Large Language Models (LLMs), they only focus on generating isolated configurations without consideration for holistic topology structure, leading to failure to form a complete, functional topology. Additionally, due to the LLMs’ limited knowledge of industry-specific device images, existing approaches struggle to adapt to diverse industry scenarios.In this paper, we introduce IntelliTopo, which, to the best of our knowledge, is the first IaC generation framework targeted at industrial network topology construction. Specifically, IntelliTopo enhances the capabilities of LLMs through two novel mechanisms: (1) Through semantic topology parsing, we enhance the LLMs’ understanding of the holistic topology structure; (2) Through domain-aware image retrieval, the outputs of IntelliTopo are more aligned with real-world industry scenarios. Deployed on our PaaS system, the IntelliTopo service has operated continuously for 3 months, handling 50+ network simulation tasks across 10+ industries. IntelliTopo reduces average network topology deployment time from days to hours while requiring less computational power for LLM reasoning. This work bridges the gap between high-level requirements and executable infrastructure, providing a scalable solution for network topology construction.
Mingyu Shao, Zhao Liu 0006, Weihong Han, Cuiyun Gao 0001, Qing Liao 0001
ASE3
2025 Quantization-based deep diversified ensemble for medical image segmentation
Qi Wang 0044, Yanchun Zhang, Weihong Han, Yangyang Mei, Yiyu Shi 0001, Jian Zhuang, Meiping Huang, Xiaowei Xu 0004
Eng. Appl. Artif. Intell.5
2025 CCM-Net: image splicing localization network based on context-aware and cross-domain multi-scale fusion
Weihong Han, Zhongxiang Xie, Xiu-Li Chai
Multim. Syst.2
2025 Autonomous Discovery of Cyber Attack Paths With Complex Causal Relationships Among Optional Actions
abstract
Reinforcement Learning (RL), particularly deep reinforcement learning (DRL) has shown significant potential in addressing optimal attack path discovery problems (OAPDPs) for cybersecurity. However, existing approaches often oversimplify the causal relationships among attack actions, limiting their applicability to complex systems. This study pioneers DRL-based solutions for OAPDPs in Intelligent Transportation Systems (ITS), specifically targeting scenarios where attack actions exhibit disjunctive, conjunctive, and hybrid causal relationships. We propose TTCRT, a novel attack pattern template that formalizes attack logic through vector-compatible representations of OAPDP-related attack components, while developing a refinement method for TTCRT-derived attack patterns and presenting a rigorous framework for formalizing OAPDPs as Markov Decision Processes (MDPs) based on refined attack patterns. Through extensive experiments, we demonstrate TTCRT’s capability to rigorously capture disjunctive, conjunctive, and hybrid causal relationships among attack actions, achieving semantic equivalence with Logical Attack Graphs (LAGs) while resolving their implementation bottlenecks in highly complex systems like ITS environments. The framework seamlessly integrates with established DRL algorithms to accurately identify optimal attack paths in an intelligent traffic management system. These findings establish TTCRT as a foundational framework for RL-driven OAPDP resolution in ITS and other sophisticated systems with complex attack dynamics.
Shudong Li, Ruichen Huang, Weihong Han, Shumei Li, Zhihong Tian 0001
IEEE Trans. Intell. Transp. Syst.3
2025 CGoFed: Constrained Gradient Optimization Strategy for Federated Class Incremental Learning
abstract
Federated Class Incremental Learning (FCIL) has emerged as a new paradigm due to its applicability in real-world scenarios. In FCIL, clients continuously generate new data with unseen class labels and do not share local data due to privacy restrictions, and each client’s class distribution evolves dynamically and independently. However, existing work still faces two significant challenges. Firstly, current methods lack a better balance between maintaining sound anti-forgetting effects over old data (stability) and ensuring good adaptability for new tasks (plasticity). Secondly, some FCIL methods overlook that the incremental data will also have a non-identical label distribution, leading to poor performance. This paper proposes CGoFed, which includes relax-constrained gradient update and cross-task gradient regularization modules. The relax-constrained gradient update prevents forgetting the knowledge about old data while quickly adapting to the new data by constraining the gradient update direction to a gradient space that minimizes interference with historical tasks. The cross-task gradient regularization also finds applicable historical models from other clients and trains a personalized global model to address the non-identical label distribution problem. The results demonstrate that the CGoFed performs well in alleviating catastrophic forgetting and improves model performance by 8% -23% compared with the SOTA comparison method.
Jiyuan Feng, Liwen Liang, Weihong Han, Binxing Fang, Qing Liao 0001
IEEE Trans. Knowl. Data Eng.4
2025 Overcoming Catastrophic Forgetting in Federated Continual Graph Learning for Resource-Limited Mobile Devices
abstract
Federated Graph Learning (FGL) enables multiple clients to collaboratively learn node representations from private subgraph data, such as user transactions or social networks. Local models are trained on clients and then aggregated by a central server, supporting large-scale graph learning without sharing raw data. However, most existing FGL methods assume that the number of nodes in the graph remains constant, while real-world scenarios often evolve, with new nodes and edges continually added and older ones removed due to limited device memory. We define this setting as Federated Continual Graph Learning (FCGL). In FCGL, global model aggregation may cause interference occur inter-task and inter-client, therefore, FCGL suffers from the global catastrophic forgetting: as the global model adapts to newly added nodes, it loses knowledge acquired from earlier graph data of clients. To address this, we propose GRE-FL, a generative replay framework, which can mitigate global catastrophic forgetting by generating a global summary graph at the server to preserve critical information from historical nodes. It also improves performance by equipping local models with a gating graph attention network for better feature extraction. Experiments show that GRE-FL achieves strong performance across multiple datasets.
Jiyuan Feng, Dongyi Zheng, Weihong Han, Binxing Fang, Qing Liao 0001
IEEE Trans. Mob. Comput.4
2025 DPP-CL: orthogonal subspace continual learning for dialogue policy planning
Rong Jiang 0001, Yinxuan Huang, Aiping Li, Weihong Han
World Wide Web (WWW)5
2024 Vulnerabilities are collaborating to compromise your system: A network risk assessment method based on cooperative game and attack graph
abstract
The swift advancement of internet technologies has had profound effects across numerous sectors, placing cyber-security at the forefront of concerns for both businesses and governmental entities. Effective cyber risk assessment enables network administrators to reinforce their defenses against cyber attacks and mitigate potential losses. However, traditional approaches frequently concentrate solely on either the difficulty of exploiting vulnerabilities or the topological characteristics of attack graphs, and some require knowledge of the attacker’s strategies. This paper presents a novel network risk assessment methodology that combines cooperative game theory with host probabilistic Attack Graphs, called RACAG. Specifically, Shapley values is employed to provide an unbiased assessment the impact of each attack path on the overall system damage. The proposed approach does not require any prior knowledge of the attacker’s strategies but instead focuses on comprehensive analysis of the exploit difficulty of vulnerabilities in the system, asset information, network topology, and attacker traces detected by defense mechanisms. Experiments have confirmed the efficacy of RACAG in assessing the impact of attack paths on overall system damage. Additionally, they highlighted its advantages in the deployment of deceptive resources, enhancement of risk perception abilities, and its support for defenders in analyzing smokescreen tactic.
Rui Wang 0007, Weihong Han, Zhihong Tian 0001
TrustCom3
2024 HOCM-Net: 3D coarse-to-fine structural prior fusion based segmentation network for the surgical planning of hypertrophic obstructive cardiomyopathy
Hailong Qiu, Yanchun Zhang, Weihong Han, Yiyu Shi 0001, Meiping Huang, Jian Zhuang, Huiming Guo, Xiaowei Xu 0004
Expert Syst. Appl.5
2024 MF2POSE: Multi-task Feature Fusion Pseudo-Siamese Network for intrusion detection using Category-distance Promotion Loss
abstract
Intrusion detection is a crucial aspect of modern cybersecurity, aimed at identifying and responding to potential security threats within computer systems , networks, and applications. One of the major challenges faced by intrusion detection systems is the accurate detection and response to attack traffic, which is typically much lower in volume compared to normal traffic. This challenge becomes even more pronounced when the attack traffic is further classified into different attack categories, which may suffer from more severe data imbalance. To address these challenges, we present a novel approach to intrusion detection using a Multi-task Feature Fusion Pseudo-Siamese Network (MF2POSE) and a Category-distance Promotion Loss (CP Loss). The proposed MF2POSE leverages the Pseudo-Siamese Network (POSE-Net), which incorporates both a main network and a siamese network, to simultaneously perform binary-class and multi-class classification of the traffic. Furthermore, the Multi-task Feature Fusion (MF2) module enhances the multi-class classification performance of the main network by incorporating multi-scale internal features from the siamese network. Additionally, the CP Loss is introduced to aggregate the internal feature from the main network belonging to the same category, and separate the internal feature belonging to the different categories. We have conducted comprehensive experiments across two popular intrusion detection datasets, and the experimental results demonstrate the superior performance of our MF2POSE compared to existing state-of-the-art techniques, particularly in multi-class classification scenarios.
Yanchun Zhang, Weihong Han, Zhaoquan Gu, Shuqiang Yang, Yongquan Fu
Knowl. Based Syst.4
2024 Disentangled Orchestration on Cyber Ranges
abstract
Cyber ranges require networked applications to test cyberspace events effectively. As testing becomes more advanced, it involves multiple real-world applications with flexible execution orders. However, it is increasingly challenging to orchestrate large-scale, chained, and heterogeneous Internet applications. State-of-the-art orchestration techniques face scalability issues due to inefficient representation models and entangled scheduling of events and applications. To address these issues, we present Wukong, a disentangled orchestration system in cyber ranges that disaggregates the scheduling and execution of workflows and their applications in a decentralized coordination approach. First, we overcome the heterogeneity of events with a workflow model that encodes event chains with compositional Directed Acyclic Graphs (DAGs) and unified event triggers. Second, Wukong disaggregates the execution of DAGs and applications with push-pull decentralized coordination over distributed agents. Our evaluation of Wukong on a real-world cyber range demonstrates its expressive, scalable, and efficient abilities for automatically emulating diverse event chains. The storage footprint of compositional modeling is up to 57 times smaller than that of baseline models. Wukong's response delay is 1.52 to 2.74 times shorter than state-of-the-art orchestration engines, and the scheduling delay is up to 2.16 times smaller than the baseline approach.
Yongquan Fu, Weihong Han, Dong Yuan 0001
IEEE Trans. Dependable Secur. Comput.2
2024 A Novel Network Forensic Framework for Advanced Persistent Threat Attack Attribution Through Deep Learning
abstract
The Internet now plays a pivotal role in the social and economic landspace, providing individuals and businesses with access to essential daily services and tasks. However, it has also become a breeding ground for conflicts. Advanced Persistent Threats (APTs) pose a formidable chanllenge when directed at organizations and governments, exposing the entire network to substantial security risks. Employing network fornesics for attributing cyber-attacks and acquiring timely, credible forensic results is a fundamental challenge in maintaining cyber security. This paper introduces a Deep Learning-based network forensics framework for digitally identifying and tracking network attacks, providing a comprehensive overview of the network forensics process. Specifically, we extract network traffic and employ encryption to ensure the integrity and security of data. Subsequently, we apply feature filtering techniques to retain essential traceability information, and Deep Learning model parameters are automatically optimized using hyperparameter optimization techniques. Lastly, we develop a Multi-Layer Perceptual Deep Neural Network (MLP DNN) model with perceptual capabilities for detecting anomalous events within the network. We evaluated the framework’s effectiveness using the UNSW-NB15 dataset. The experiments demonstrate that the proposed framework is applicable to APT attack forensics scenarios. In comparison to other AI methods, our framework excels in discovering and tracking network attack events with high performance.
Yangyang Mei, Weihong Han, Shudong Li, Kaihan Lin, Zhihong Tian 0001, Shumei Li
IEEE Trans. Intell. Transp. Syst.2
2024 Detecting Deepfake Videos using Spatiotemporal Trident Network
abstract
The widespread dissemination of Deepfake in social networks has posed serious security risks, thus necessitating the development of an effective Deepfake detection technique. Currently, video-based detectors have not been explored as extensively as image-based detectors. Most existing video-based methods only consider temporal features without combining spatial features, and do not mine deeper-level subtle forgeries, resulting in limited detection performance. In this paper, a novel spatiotemporal trident network (STN) is proposed to detect both spatial and temporal inconsistencies of Deepfake videos. Since there is a large amount of redundant information in Deepfake video frames, we introduce convolutional block attention module (CBAM) on the basis of the I3D network and optimize the structure to make the network better focus on the meaningful information of the input video. Aiming at the defects in the deeper-level subtle forgeries, we designed three feature extraction modules (FEMs) of RGB, optical flow, and noise to further extract deeper video frame information. Extensive experiments on several well-known datasets demonstrate that our method has promising performance, surpassing several state-of-the-art Deepfake video detection methods.
Kaihan Lin, Weihong Han, Shudong Li, Zhaoquan Gu, Huimin Zhao 0001, Yangyang Mei
ACM Trans. Multim. Comput. Commun. Appl.2
2023 REMSF: A Robust Ensemble Model of Malware Detection Based on Semantic Feature Fusion
abstract
With the rapid development of Internet of Things, the amount and distribution of malware has greatly increased. Internet of Things platform needs new defense technologies to protect users from new the increasing number and complexity of malware. This article extracts import Dlls and import APIs from the original portable executable (PE) file, and uses heterogeneous graph to describe higher-level semantic relationship between two PE files. Besides this we construct four static features to comprehensively describe PE file. Based on ensemble learning we develop a model called robust ensemble model based on semantic feature fusion (REMSF) which fuses five features mentioned above. To evaluate REMSF, we collect 5370 executable PE files from the real world for series of experiments, in which REMSF’s detection accuracy can reach 99.07%.
Zhuocheng Yu, Shudong Li, Youming Bai, Weihong Han, Zhihong Tian 0001
IEEE Internet Things J.4
2022 Generic Construction of Trace-and-Revoke Inner Product Functional Encryption
Saif M. Al-Kuwari, Haiyan Wang 0009, Weihong Han
ESORICS (1)4
2022 Orchestrating Heterogeneous Cyber-range Event Chains With Serverless-container Workflow
abstract
Cyber ranges need to run versatile network applications to increase the fidelity of the tests. With the growing complexity of cyberspace events that involve tens to hundreds of diverse applications and flexible execution orders of applications, it is increasingly challenging to orchestrate large-scale, complicated chains of heterogeneous Internet applications. State-of-the-art orchestration techniques do not scale out well due to the inefficient representation model and scheduling of network-centric and correlated Internet application activities. We present a serverless-container workflow orchestration scheme called Wukong. First, we overcome the heterogeneity of events with a workflow model that encodes event chains with compositional DAGs and unified serverless-container event triggers. Second, Wukong scales the scheduling of serverless-container workflows by automatically decomposing DAGs and push-pull coordinated event executions over distributed serverless-container runtime agents. Our evaluation on a real-world cyber range shows that Wukong is expressive, scalable and efficient for automatically emulating diverse event chains, in that the compositional modeling reduces the storage footprint over 57 to 58 times compared to baseline models, the response delay of Wukong is 1.52 to 2.74 times shorter than state-of-the-art orchestration engines, and the scheduling delay is 1.14 to 2.16 times smaller than those of the baseline approach.
Yongquan Fu, Weihong Han, Dong Yuan 0001
MASCOTS2
2022 False Alert Detection Based on Deep Learning and Machine Learning
abstract
Among the large number of network attack alerts generated every day, actual security incidents are usually overwhelmed by a large number of redundant alerts. Therefore, how to remove these redundant alerts in real time and improve the quality of alerts is an urgent problem to be solved in large-scale network security protection. This paper uses the method of combining machine learning and deep learning to improve the effect of false alarm detection and then more accurately identify real alarms, that is, in the process of training the model, the features of a hidden layer output of the DNN model are used as input to train the machine learning model. In order to verify the proposed method, we use the marked alert data to do classification experiments, and finally use the accuracy recall rate, precision, and F1 value to evaluate the model. Good results have been obtained.
Shudong Li, Danyi Qin, Baohui Li, Weihong Han
Int. J. Semantic Web Inf. Syst.6
2022 Proliferation of Cyber Situational Awareness: Today's Truly Pervasive Drive of Cybersecurity
abstract
Situation awareness (SA) issues necessitate a comprehension of present activities, the ability to forecast, what will happen next, and strategies to assess the threat or impact of current internet activities and projections. These SA procedures are universal, domain-independent and can be used to detect cyber intrusions. This study introduces cyber situation awareness (CSA), its origin, conception, aim, and characteristics based on an analysis of function shortages and development requirements. Furthermore, we discussed the CSA research framework and examined the research history, which is the essential aspect, and assessed the present issues of the research as well. The assessment approaches were divided into three methods: mathematics model, knowledge reasoning, and pattern recognition. The study then goes into detail regarding the core idea, assessment procedure, strengths, and weaknesses of novel approaches, and then, it addresses CSA from three perspectives: model, knowledge representation, and assessment methods. Many common approaches are contrasted, and current CSA application research in the realms of security, transmission, survivability, and system evaluation is discussed. Finally, this study summarized the findings of the present from technical and application systems, outlined CSA’s future development directions, and provided adversary activities and information that can be used to improve an organization’s SA operations.
Hafiz Muhammad Jamsheed Nazir, Weihong Han
Secur. Commun. Networks2
2022 A Hybrid Intelligent Approach to Attribute Advanced Persistent Threat Organization Using PSO-MSVM Algorithm
abstract
In recent years, extensive research has been conducted in Advanced Persistent Threat (APT) attack defence. However, most existing defence solutions can only identify and temporarily disrupt cyber attacks, seeking to deny the threat from the intranet, it’s difficult to defence against APT attacks. Attributing the APT organization is an excellent complement to the existing defence solutions, which not only can expose the attacker’s true identity, but also provide evidence to bring the attacker to justice. However, research on attributing APT Organization is still few, poses complex tasks because APT attacks are highly targeted, stealthy, persistent and organized. To answer thie question, we propose a Particle Swarm Optimization Multiclass Support Vector Machine (PSO-MSVM) approach to identify the organization behind complex APT attacks automatically. Firstly, we have collected a large amount of data on the traces of APT attack tools executed in the sandbox, and selected data closely related to APT organizations to construct the feature set. Secondly, based on the strategy of keeping the personal best (pbest) and global best (gbest) particles in the particle swarm algorithm away from the adaptation values generated by the misclassification information as they move, the particle positions are updated frequently to eventually obtain the optimal parameters (i.e., penalty parameter (${C}$) and sigma parameter ($\sigma $)) for MSVM, thus enabling the MSVM technique to accurately identify APT organizations. The results obtained from the PSO-MSVM approach showed the superiority of this technique in three different measures of accuracy, precision and F1,compared with other six classical methods.
Yangyang Mei, Weihong Han, Shudong Li, Kaihan Lin, Cui Luo
IEEE Trans. Netw. Serv. Manag.2
2021 Attribution Classification Method of APT Malware in IoT Using Machine Learning Techniques
abstract
In recent years, the popularity of IoT (Internet of Things) applications and services has brought great convenience to people's lives, but ubiquitous IoT has also brought many security problems. Among them, advanced persistent threat (APT) is one of the most representative attacks, and its continuous outbreak has brought unprecedented security challenges for the large-scale deployment of the IoT. However, important research on analyzing the attribution of APT malware samples is still relatively few. Therefore, we propose a classification method for attribution organizations with APT malware in IoT using machine learning. It aims to mark the real attacking organization entities to better identify APT attack activity and protect the security of IoT. This method performs feature representation and feature selection based on APT behavior data obtained from devices in the Internet of Things and selects the features with a high degree of differentiation among organizations. Then, it trains a multiclass model named SMOTE-RF that can better deal with imbalance and multiclassification problems. Our experiments on real dynamic behavior data are combined to verify the effectiveness of the method proposed in this paper for attribution analysis of APT malware samples and achieve good performance. Our method could identify the organization behind complex APT attacks in IoT devices and services.
Shudong Li, Qianqing Zhang, Weihong Han, Zhihong Tian 0001
Secur. Commun. Networks4
2021 A Topic Representation Model for Online Social Networks Based on Hybrid Human-Artificial Intelligence
abstract
With the widespread use of online social networks, billions of pieces of information are generated every day. How to detect new topics quickly and accurately at such data scale plays a vital role in information recommendation and public opinion control. One of the basic research tasks of topic detection is how to represent a topic. The existing topic representation models do not focus on how to select better differentiated words to represent topics, are still computer-centered, and do not effectively combine human intelligence and artificial intelligence (AI). To solve these problems, this article proposes a word-distributed sensitive topic representation model (WDS-LDA) based on hybrid human-AI (H-AI). The basic idea is that the distribution of words within a topic or among different topics has a great influence on the selection of topic expression words. If a word is evenly distributed among all documents of a certain topic, it indicates that the word is the common word of all documents in the topic, and it is more suitable to represent this topic. If a word is more evenly distributed among various topics, it indicates that the word is a common word of all topics, and cannot be used for the purpose of distinguishing among topics, becoming less suitable to represent any topic. At the same time, the human cognitive ability and cognitive models are introduced into topic representation based on H-AI. We introduce the user's modification of topic expression words into the topic model representation so that the topic model can learn human wisdom and become more and more accurate. Therefore, three different weights are introduced: inside weight; outside weight; and manual adjustment weight. The inside weight describes the uniform distribution of a word in the given topic, the outside weight describes the uniform distribution of a word in all topics, and the manual adjustment weight reflects whether a word is suitable as a representative vocabulary in the past manual adjustment. Tests using Sina microblog's actual data sets show that the WDS-LDA algorithm makes the representative words more important, the distinction among different topic words higher, and effectively improves the precision of subsequent algorithms, such as topic detection and topic evolutionary analysis using the topic model.
Weihong Han, Zhihong Tian 0001, Chunsheng Zhu, Zizhong Huang, Yan Jia 0001, Mohsen Guizani
IEEE Trans. Comput. Soc. Syst.1
2020 Long-Term Spatiotemporal Trend Analysis (1998-2016) of PM2.5 in China Using Satellite Product
abstract
Atmospheric fine particulate matter (PM2.5) pollution has brought a strong focus on public health and environmental quality in China because of its adverse effects. To evaluate the effect of technological and social development on environmental quality in China, it's in urgent need of understanding the long-term spatiotemporal trend of PM2.5 concentrations. In this paper, satellite-derived annual mean PM2.5 estimates (1998-2016) were validated using ground-based PM2.5 measurements (2015-2016) and then used for spatiotemporal trend analysis. The results indicated that national mean PM2.5 concentrations in China increased primarily before 2008, and then decreased. The spatial distribution of PM2.5 concentration is high level in the east and while low in the west of Heihe-Tengchong Line in China. Our findings provided a profound understanding of PM2.5 variations and affirmed the effectiveness of implemented measures of reducing PM2.5 loadings in China, offering important reference data for relevant policy making of air pollution prevention in the future.
Weihong Han, Ling Tong 0001, Jiang Wen
IGARSS1
2020 Topic representation model based on microblogging behavior analysis
Weihong Han, Zhihong Tian 0001, Zizhong Huang, Shudong Li, Yan Jia 0001
World Wide Web1
2019 Bidirectional self-adaptive resampling in internet of things big data learning
Weihong Han, Zhihong Tian 0001, Zizhong Huang, Shudong Li, Yan Jia 0001
Multim. Tools Appl.1
2017 A Multi-attention-Based Bidirectional Long Short-Term Memory Network for Relation Extraction
Yuanping Nie, Weihong Han, Jiuming Huang
ICONIP (5)3
2017 A new algorithm for high temporal and spatial resolution aerosol retrieval using gaofen-4 and landsat-8 data
abstract
High temporal and spactial resolution aerosol retrieval is a difficult task because of the absence of corresponding satellite data. Due to the lack of a shortwave infrared band near 2.1 um aboard on Gaofen-4 instrument, which is critical for determining surface reflectance. In this paper, a new algorithm resolving the problem based on Gaofen-4 that was placed in Geosynchronous (GEO) orbit and Landsat-8 data was proposed. Also, Gaofen-4 sensor band mean solar irradiance (BMSI) was calculated which was not open to public until now. In the algorithm, normalized difference vegetation index (NDVI) was used to identify dark target pixels that have certain linear relationship over blue and red bands' surface reflectance. In order to remove Gaofen-4's geometric deformation, the data were processed with RPC Landsat-8 panchromatic data. The algorithm was applied to two cities, Beijing and Chengdu. The result, aerosol optical thickness (AOT) with a 50m × 50m resolution, indicated the algorithm can be effective for vegetation area or low surface reflectance area. The algorithm is very useful and significant for environmental protection, air quality monitoring and atmospheric pollutants sources tracing.
Weihong Han, Ling Tong 0001, Yunping Chen
IGARSS1
2016 A new air pollution sources identification method based on remotely sensed aerosol and swarm intelligence
abstract
In this paper, a novel method was developed to orientate and quantify the air pollution sources based on remotely sensed aerosol data and Glowworm Swarm Optimization (GSO). In practice, based on source apportionment technique, the air pollution sources could just be identified to certain industries, such as transportation, power plants, biomass burning, and et.al. To our knowledge, the problem of orientating and quantifying the pollution to the individual factories is faced for the first time. In this study, the aerosol retrieved from remotely sensed image (MODIS) and GIS were used to locate and quantify the pollution to each enterprise in the study area based on an improved Glowworm Swarm Optimization and meteorological condition. As a result, the polluting contribution of each factory were be listed, and the most polluting factories were be found. Some experiments were carried out to validate the method, and the Key monitoring factories by authority was ferreted out accurately.
Yunping Chen, Weihong Han, Wenhuan Wang, Yaju Xiong, Tong Ling
IGARSS2
2016 A new algorithm for aerosol retrieval using HJ-1 CCD and MODIS NDVI data over urban areas
abstract
Aerosol retrieval over urban areas is a difficult task because of the high reflectance of the underlying surface. In this paper, a new aerosol retrieval algorithm based on the spectral analysis of soil and vegetation from spectral library was proposed, the simulated correlation between the normalized difference vegetation index (NDVI) and the surface reflectance of red, blue bands was established. And also to solve scale problem, a conversion method based on maximizing mutual information (MI) was used. The algorithm was applied to Beijing city using the China HJ-1A/1B of the Environment and Disaster Monitoring Microsatellite Constellation Charge-Coupled Device (CCD) and MODIS NDVI data. The result, aerosol optical thickness (AOT) with a 100m×100m resolution, was compared to the ground measurement data from Aerosol Robotic Network (AERONET), which shows a high consistency with observation data, and the overall correlation coefficient of approximately 0.935 and a root-mean-square error (RMSE) of about 0.34. The algorithm is very useful and significant for environmental protection and air quality monitoring over urban areas.
Weihong Han, Ling Tong 0001, Yunping Chen
IGARSS1
2016 A new aerosol retrieval algorithm based on statistical segmentation using Landsat-8 OLI data
abstract
In this paper, a new aerosol retrieval algorithm based on a method, named statistical segmentation, was proposed. Firstly, the image of Landsat 8 OLI was divided into many segments by the statistical segmentation method based on band 6 and band 7. Then, according to the characteristics of the segmentation, two ways based on the segmented results were used to get the surface reflectance. And then combined with the apparent reflectance equation and a lookup table built by 6S model, aerosol retrieval could be performed. In principle, this algorithm is based on clean pixels (almost no aerosol) at band 1 to retrieve contaminated pixels in the same segment. The retrieved results show that, compared with DDV (Dense Dark Vegetation) algorithm, this algorithm is more suitable for bright surfaces, such as urban areas.
Yaju Xiong, Yunping Chen, Weihong Han, Ling Tong 0001
IGARSS3
2016 Sockpuppet gang detection on social media sites
Quanyuan Wu, Weihong Han, Bin Zhou 0004
Frontiers Comput. Sci.3
2014 A Top K Relative Outlier Detection Algorithm in Uncertain Datasets
Fei Liu 0016, Weihong Han
APWeb3
2013 Spatial distribution of PM2.5 concentration based on aerosol optical thickness inverted by Landsat ETM+ data over Chengdu
abstract
This paper proposes a new method of spatial distribution of PM2.5concentration, which is based on Aerosol Optical Thickness (AOT) inverted by Landsat7 ETM+ Enhanced Thematic Mapper Plus (ETM+) data and PM2.5ground-based instruments. The main steps of the method are as follows:(1) Determination of dark pixels, search for the dark surface targets with the 2.2- μm channel; (2) Determination of the surface reflectance in the blue and red channels;(3) AOT retrieval, inverted from Look-up Tables (LUT) established from a set of atmospheric geometrical conditions;(4)Establish the model of PM2.5predicting with predictors and estimate the PM2.5value. The study results show that the method is an effective means for predicting the PM2.5concentration, and a beneficial supplement to the conventional ground-based measurement.
Weihong Han, Ling Tong 0001, Jinping Bai, Yunping Chen
IGARSS1
2013 Chinese Text Classification Based on Neural Network
Weihong Han
ISNN (1)3
2009 Effective Feature Selection on Data with Uncertain Labels
abstract
Nowadays, various learning technologies are required on uncertain data. As an important pre-processing step in data mining, feature selection needs to consider this vagueness or uncertainty. In this paper, we propose a novel algorithm to evaluate the correlation between features and uncertain class labels on the basis of Hilbert-Schmidt Independence Criterion. Consequently, the features can be ranked according to this criterion. Experimental results on extensive datasets demonstrate the benefits of our method.
Yan Jia 0001, Yi Han 0006, Weihong Han
ICDE4
2007 Context-Aware Middleware Support for Component Based Applications in Pervasive Computing
Yan Jia 0001, Weihong Han
APPT4
2007 Middleware Based Context Management for the Component-Based Pervasive Computing
Jun Wang 0063, Yan Jia 0001, Weihong Han
ATC4
2007 Continuous Adaptive Outlier Detection on Distributed Data Streams
Weihong Han, Shuqiang Yang, Yan Jia 0001
HPCC2
2007 Deployment of Context-Aware Component-Based Applications Based on Middleware
Jun Wang 0063, Yan Jia 0001, Weihong Han
UIC4