EDBT 2026 Demo / reviewers in the wild / expert
Zhefeng Nan
dblp:338/9900
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Steering Representations, Safeguarding Privacy: A Cross-Modal Privacy Protection Method for Generative AIabstractPrivacy concerns have long been a critical issue in AI models. With the rapid advancement of generative AI, the privacy awareness of models has drawn attention, raising new challenges for privacy protection that is independent of data and tasks. This paper introduces a novel framework for enhancing privacy protection through directional steering in representation space, which seamlessly integrates with both language and vision-language models. Specifically, we first construct a comprehensive privacy-related dataset based on the Solove taxonomy of privacy. Then, we leverage this dataset to enhance model privacy awareness in the representation space, steering the model to protect privacy during inference. Experiments on 12 models validate the effectiveness and generalization of our method. Moreover, we demonstrate the transferability of privacy-enhanced representations between same-source large language models (LLMs) and vision-language models (VLMs), offering a scalable solution for privacy protection in frontier AI models. Zhefeng Nan, Yangyan Xu, Jinta Weng |
AAAI | 3 |
| 2025 | Towards Open-World DoH Tunnel Detection: A Dual-View Contrastive Learning Framework with Adaptive Feature BoundariesabstractThe emergence of DNS-over-HTTPS (DoH) tunnels poses significant challenges to network security, particularly when encountering unknown traffic patterns not seen during training. Existing approaches struggle to effectively identify novel DoH tunnel variants while maintaining accurate classi-fication of known traffic patterns. In this paper, we propose DualConBound, a novel framework that combines dual-view contrastive learning with dynamic feature boundary estimation to address open-set network traffic classification. Our approach leverages complementary traffic representations and adaptive decision boundaries to better distinguish between known and unknown traffic patterns. Through extensive experiments on real-world network traffic datasets, we demonstrate that our framework achieves 91 % accuracy on known traffic patterns and 71 % accuracy on unknown variants, outperforming other methods by 6% in open-set scenarios. Our work provides a robust solution for identifying emerging DoH tunnel threats in real-world network environments and establishes a new paradigm for open-set network traffic classification. Beibei Feng, Zhefeng Nan, Jiang Xie 0004, Tianning Zang, Jingrun Ma |
CSCWD | 3 |
| 2024 | Path Generation Method of Anti-Tracking Network based on Dynamic Asymmetric Hierarchical ArchitectureabstractThe continuous advancement of digital processes has significantly increased the risk to users’ data privacy. To protect private data, it is crucial to provide anonymous, anti-tracking secure communication services. However, Existing anti-tracking data transmission technologies has problems such as centralized node, unstable links, low transmission efficiency, and vulnerable static transmission, which fail to meet users’ privacy and security requirements. This paper proposes a dynamic asymmetric hierarchical architecture path generation method(DAHP) for anti-tracking network. The method adopts a hierarchical architecture design, comprising a Secure Access Layer responsible for link construction and a Secret Transmission Layer handling the actual transmission. A node hybrid selection strategy, combined with a dynamic asymmetric path generation strategy, minimizes the risk of node exposure and enables dynamic variation in path generation. The efficacy of the DAHP method is validated through extensive testing on representative network and existing path generation methods. Experimental results demonstrate that the proposed method exhibits superior scalability and anti-tracking performance. Zhefeng Nan, Changbo Tian, Tianning Zang, Dongwei Zhu |
TrustCom | 1 |
| 2023 | Automated Behavior Identification of Home Security Camera TrafficabstractWith the widespread use of IoT devices in the market, home security cameras (HSCs) have become one of the most commonly used devices. However, the security risks of these devices, such as cyber attacks and privacy breaches, still remain a concern. To analyze the behavior of HSC devices, researchers and intruders often rely on traffic data. However, identifying the behavioral traffic of HSC devices is a challenging task because it is difficult to distinguish it from dynamic video traffic during transmission. We propose a new approach to solve this problem by analyzing the features of unidirectional packets present in non-TLS network traffic. Additionally, we found that manually labeling device behavior traffic data is time-consuming and often inaccurate. We introduce a two-factor automatic behavior labeling approach based on reverse traffic and operation logs to address this concern. Finally, we test the performance of multiple classifiers on two datasets: a real-world dataset and the IMC 2019 payload public dataset. Our experiments show that the proposed framework is able to extract and identify behavioral traffic automatically. The CNN-based classifier can accurately identify fine-grained behavioral traffic of HSC devices based on unidirectional upload traffic features. This study has implications for improving security threat awareness of IoT products and anomalous behavior detection of HSC devices. Shuhe Liu, Zhefeng Nan |
IJCNN | 3 |
| 2023 | Topology construction method of anti-tracking network based on cross-domain decentralized gravity modelabstractWith the increasing threats of network tracking and information leakage, privacy protection has become a widely concern in the field of network security. As an important means of protecting the privacy of network users, anti-tracking networks have gradually become one of the important research directions. However, the existing topology structures of anti-tracking networks still have problems such as intra-domain aggregation and key nodes, which are vulnerable to attack, tracking and destruction, and can not meet the privacy requirements. Therefore, this paper proposes a topology construction method based on cross-domain decentralized gravity model (CDTC). Firstly, the model comprehensively considers the local neighbor information, the location information of nodes, and the path information between nodes to calculate the node attraction. Secondly, each node determines its link status with other nodes through the model by ranking its local nodes, achieving optimization of the network topology. Finally, experiments on typical network structures and open network datasets, the experimental results show that the proposed model has better decentralization, cross-domain, and anti-tracking performance. Zhefeng Nan, Qian Qiang, Tianning Zang, Changbo Tian, Shuhe Liu |
TrustCom | 1 |
| 2022 | ACS: An Efficient Messaging System with Strong Tracking-Resistance
Zhefeng Nan, Changbo Tian, Yafei Sang, Guangze Zhao |
CollaborateCom (2) | 1 |
| 2022 | Device Behavior Identification in Encrypted Home Security Camera TrafficabstractHome security cameras have become one of the most popular IoT devices due to rigid demand and low cost. However, these devices have become a disaster area where security issues such as cyberattacks and privacy breaches often occur. Researchers and intruders often employ traffic behavior analyzing methods to mine vulnerabilities. Nevertheless, the content transmitted by the HSC device contains a lot of dynamic interference video traffic, so it is hard to mine the behavior information of the HSC device from it. In contrast, the HSC device's non-TLS one-way response packets carry more efficient behavior information. Therefore, we propose an approach to identify device behavior based on the features of one-way response packets in non-TLS traffic. Based on the functional characteristics of the HSC device, we have a more fine-grained type division of behaviors, including eight behaviors and five states. In addition, we propose an automatic labeling approach based on countercurrent and operation logs for the problem of tedious and inaccurate manual labeling. Based on the features of three attributes, we compared the recognition effects of nine classifiers on two datasets, the real-world dataset and the IMC 2019 payload public dataset. Finally, the CNN-based classifier can achieve the most desirable identification effect with an accuracy rate of 97.47%, a recall rate of 97.42%, and an F1 score of 97.4%. The results show that the proposed approach can accurately identify the behavior and state of HSC at a fine-grained level. Moreover, this work has a significant reference value for device anomalous behavior detection and threat awareness. Shuhe Liu, Zhefeng Nan |
ICTAI | 3 |
| 2022 | CNN-Based Autonomous Traffic Detection on Unknown Home Security CamerasabstractAs a popular IoT device, home security cameras (HSCs) generate large amounts of traffic, but the security mechanisms are weak, making them often exploited to launch DDoS attacks. Moreover, the lurking HSC device significantly threatens user privacy, so it is necessary to detect the HSC traffic. With the current service upgrade of HSC devices and the popularity of the open-source DIY community, the HSC types have become numerous. However, current traffic classification methods can only rely on complex feature extraction, expertise, and static datasets for identification, making it challenging to detect unknown devices in the open world. To solve this problem, we propose an autonomous update framework, called CATD-HSC, to constantly improve the classifier’s detection ability on unknown HSC devices. First, we use a CNN-based classifier model to train known HSC traffic. Then, we collect the classifier’s output as a new feature and use the threshold filtering approach to filter the unknown HSC traffic. Finally, we cluster the unknown HSC traffic by connecting the original feature to the generated feature. Moreover, we make the process autonomous to reduce the repeated trivial training. We evaluate the performance of CATD-HSC on both the UNSW open dataset and the real-world HSC traces. The updated model achieves an average accuracy rate of 99.3% and a recall rate of 99.4% for unknown HSC traffic in three interference environments. Our further evaluation shows that CATD-HSC can successfully implement the classifier’s autonomous update and dynamic classification on unknown HSC devices. Shuhe Liu, Zhefeng Nan |
TrustCom | 3 |