EDBT 2026 Demo / reviewers in the wild / expert
Xiaolei Liu 0001
dblp:34/8893-1 · also Xiao-Lei Liu 0001
· DBLP profile ↗
26ranked-venue papers
2as first author
19since 2021 · last 2026
0000-0001-8510-4025ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 4 since 2021Computer networks · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CLlog: A collaborative learning-based anomalous log detection model
Zhiquan Liu 0001, Xiaolei Liu 0001 |
Comput. Networks | 4 |
| 2026 | SEADGAT: A Heterogeneous Graph Attention Network With Cross-Distillation for Encrypted Traffic ClassificationabstractWith the increasing severity of network security threats, encrypted traffic identification has become a core challenge in the field of network security. Graph Neural Networks (GNNs) have demonstrated significant potential in capturing the complex association patterns among encrypted traffic byte units, owing to their powerful structural modeling capabilities. However, traditional homogeneous graph modeling methods struggle to fully characterize the multidimensional heterogeneous relationships between headers and payloads in encrypted traffic. Although Heterogeneous Graph Neural Networks (HGNNs) can address such complexity, they suffer from parameter redundancy and a sharp increase in training overhead due to independent edge-type modeling, while lacking a mechanism for collaborative knowledge transfer across edge types. To address this, this paper proposes a Cross-Type Distillation mechanism, which constructs a unified structural representation path to enable bidirectional knowledge transfer between heterogeneous edge types. This approach enhancing the feature expression capability of weak semantic edges. Building on this foundation, we introduce the malicious traffic detection model SEADGAT, which employs an edge-type weight-sharing mechanism to compress the propagation weights of multiple edge types into a unified representation space and integrates them into graph attention computation. This substantially reduces training time while preserving the ability to perceive structural differences. Based on a heterogeneous graph framework, SEADGAT accurately characterizes the complex dependencies between byte units and between headers and payloads, combined with a dynamic fusion mechanism to generate comprehensive traffic representations. DFUSE is enhanced with gated cross-interactions for adaptive multimodal fusion. Experiments on packet-level and flow-level classification across multiple encrypted traffic datasets demonstrate that SEADGAT outperforms existing methods in classification accuracy, training efficiency, and model parameter scale. Yuanyuan Huang 0007, Zhitan Wei, Jia-Li Yin, Xiaolei Liu 0001 |
IEEE Internet Things J. | 6 |
| 2026 | Adversarial Sample Based on Structured Fusion Noise for Botnet Detection in Industrial Control SystemsabstractThe industrial control system’s artificial intelligence-based botnet intrusion detection system has a high detection performance and efficiency in an environment without interference. However, these systems are not immune to evasion through adversarial samples. In this study, we introduce a feature extraction technique tailored for ICS botnet detection. This approach classifies traffic packets based on network traffic attributes and ICS-specific identification codes, encompassing the statuses of ICS devices, enhancing detection precision. Meanwhile, this strategy addresses challenges in ICS data collection and bolsters experimental efficacy. To build a comprehensive botnet intrusion dataset within an ICS, we concurrently utilized existing ICS devices to collect both standard ICS and botnet traffic. Additionally, we present an innovative adversarial sample generation method for botnet detection models, integrating both time-domain and frequency-domain noise. Testing under three real-world ICS attack scenarios revealed our technique can markedly degrade the classification performance of eight leading AI-based detection models, emphasizing its potential for evading AI-based ICS intrusion detectors. Jimin Peng, Jia-Li Yin, Xiaolei Liu 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Focus on Generalization: Improving Adversarial Transferability via Bi-Level Bias MitigationabstractTransfer-based adversarial attacks have endowed adversarial examples with the ability to transfer from a source model to an unknown target model, which poses a more realistic threat to security-critical applications. Existing transferable adversarial attacks generally suffer from overfitting to the source model, i.e., the perturbations are locally optimal in the source model and focus on the model-specific information. We demand the adversarial perturbation to contain more generalized knowledge, which reveals the intrinsic general properties and can introduce model-general optimum into adversarial examples, for improving transferability. To this end, we devise a Bi-level Bias Mitigated Attack (BBMA), which empowers the transferability of adversarial examples by exploring generalization in two levels: 1) Progressive filtering of high-frequency sample components. We first propose to remove the sample-specific high-frequency components of samples to explore model-level generation. To simulate how a model evaluates feature importance at different stages, we devise a stride-wise step-tuning strategy to progressively produce multiple samples for aggregating the gradients. 2) Accumulated gradient-guided model attention shift. To facilitate the sample-level bias mitigation, we employ an accumulated gradient-guided attention map to distort the more generalized features during perturbation generation. Comprehensive experiments on several benchmarks demonstrate the superiority of our method in attack transferability over state-of-the-art attacks. Yiqiang Guo, Bin Chen 0020, Jia-Li Yin, Xiaolei Liu 0001, Shouling Ji |
ACM Multimedia | 5 |
| 2025 | Backdoor Attack and Defense on Deep Learning: A SurveyabstractDeep learning, as an important branch of machine learning, has been widely applied in computer vision, natural language processing, speech recognition, and more. However, recent studies have revealed that deep learning systems are vulnerable to backdoor attacks. Backdoor attackers inject a hidden backdoor into the deep learning model, such that the predictions of the infected model will be maliciously changed if the hidden backdoor is activated by input with a backdoor trigger while behaving normally on any benign sample. This kind of attack can potentially result in severe consequences in the real world. Therefore, research on defending against backdoor attacks has emerged rapidly. In this article, we have provided a comprehensive survey of backdoor attacks, detections, and defenses previously demonstrated on deep learning. We have investigated widely used model architectures, benchmark datasets, and metrics in backdoor research and have classified attacks, detections and defenses based on different criteria. Furthermore, we have analyzed some limitations in existing methods and, based on this, pointed out several promising future research directions. Through this survey, beginners can gain a preliminary understanding of backdoor attacks and defenses. Furthermore, we anticipate that this work will provide new perspectives and inspire extra research into the backdoor attack and defense methods in deep learning. Yang Bai 0011, Gaojie Xing, Zhihong Rao, Chuan Ma 0001, Shiping Wang, Xiaolei Liu 0001, Yimin Zhou 0002, Jiajia Tang, Kaijun Huang, Jiale Kang |
IEEE Trans. Comput. Soc. Syst. | 7 |
| 2025 | Query-Efficient Model Inversion Attacks: An Information Flow ViewabstractModel Inversion Attacks (MIAs) pose a certain threat to the data privacy of learning-based systems, as they enable adversaries to reconstruct identifiable features of the training distribution with only query access to the victim model. In the context of deep learning, the primary challenges associated with MIAs are suboptimal attack success rates and the corresponding high computational costs. Prior efforts assumed that the expansive search space caused these limitations, employing generative models to constrain the dimensions of the search space. Despite the initial success of these generative-based solutions, recent experiments have cast doubt on this fundamental assumption, leaving two open questions about the influential factors determining MIA performance and how to manipulate these factors to improve MIAs. To answer these questions, we reframe MIAs from the perspective of information flow. This new formulation allows us to establish a lower bound for the error probability of MIAs, determined by two critical factors: (1) the size of the search space and (2) the mutual information between input and output random variables. Through a detailed analysis of generative-based MIAs within this theoretical framework, we uncover a trade-off between the size of the search space and the generation capability of generative models. Based on the theoretical conclusions, we introduce the Query-Efficient Model Inversion Approach (QE-MIA). By strategically selecting an appropriate search space and introducing additional mutual information, QE-MIA achieves a reduction of$60\%\sim 70\%$in query overhead while concurrently enhancing the attack success rate by$5\%\sim 25\%$. Yixiao Xu, Binxing Fang, Mohan Li, Xiaolei Liu 0001, Zhihong Tian 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | SUB-PLAY: Adversarial Policies against Partially Observed Multi-Agent Reinforcement Learning SystemsabstractRecent advancements in multi-agent reinforcement learning (MARL) have opened up vast application prospects, such as swarm control of drones, collaborative manipulation by robotic arms, and multi-target encirclement. However, potential security threats during the MARL deployment need more attention and thorough investigation. Recent research reveals that attackers can rapidly exploit the victim's vulnerabilities, generating adversarial policies that result in the failure of specific tasks. For instance, reducing the winning rate of a superhuman-level Go AI to around 20%. Existing studies predominantly focus on two-player competitive environments, assuming attackers possess complete global state observation. Oubo Ma, Yuwen Pu, Linkang Du, Ruo Wang, Xiaolei Liu 0001, Yingcai Wu, Shouling Ji |
CCS | 6 |
| 2024 | Snopy: Bridging Sample Denoising with Causal Graph Learning for Effective Vulnerability DetectionabstractDeep Learning (DL) has emerged as a promising means for vulnerability detection due to its ability to automatically derive features from vulnerable code. Unfortunately, current solutions struggle to focus on vulnerability-related parts of vulnerable functions, and tend to exploit spurious correlations for prediction, thus undermining their effectiveness in practice. In this paper, we propose Snopy, a novel DL-based approach, which bridges sample denoising with causal graph learning to capture real vulnerability patterns from vulnerable samples with numerous noise for effective detection. Specifically, Snopy adopts a change-based sample denoising approach to automatically weed out vulnerability-irrelevant code elements in the vulnerable functions without sacrificing the label accuracy. Then, Snopy constructs a novel Causality-Aware Graph Attention Network (CA-GAT) with Feature Caching Scheme (FCS) to learn causal vulnerability features while maintaining efficiency. Experiments on the three public benchmark datasets show that Snopy outperforms the state-of-the-art baselines by an average of 27.22%, 85.89%, and 75.50% in terms of F1-score, respectively. Sicong Cao, Xiaobing Sun 0001, Xiaoxue Wu 0001, David Lo 0001, Lili Bo, Bin Li 0006, Xiaolei Liu 0001, Xingwei Lin, Wei Liu 0010 |
ASE | 7 |
| 2024 | Unstoppable Attack: Label-Only Model Inversion Via Conditional Diffusion ModelabstractModel inversion attacks (MIAs) aim to recover private data from inaccessible training sets of deep learning models, posing a privacy threat. MIAs primarily focus on the white-box scenario where attackers have full access to the model’s structure and parameters. However, practical applications are usually in black-box scenarios or label-only scenarios, i.e., the attackers can only obtain the output confidence vectors or labels by accessing the model. Therefore, the attack models in existing MIAs are difficult to effectively train with the knowledge of the target model, resulting in sub-optimal attacks. To the best of our knowledge, we pioneer the research of a powerful and practical attack model in the label-only scenario. In this paper, we develop a novel MIA method, leveraging a conditional diffusion model (CDM) to recover representative samples under the target label from the training set. Two techniques are introduced: selecting an auxiliary dataset relevant to the target model task and using predicted labels as conditions to guide training CDM; and inputting target label, pre-defined guidance strength, and random noise into the trained attack model to generate and correct multiple results for final selection. This method is evaluated using Learned Perceptual Image Patch Similarity as a new metric and as a judgment basis for deciding the values of hyper-parameters. Experimental results show that this method can generate similar and accurate samples to the target label, outperforming generators of previous approaches. Rongke Liu, Dong Wang 0019, Yizhi Ren, Zhen Wang 0013, Kaitian Guo, Qianqian Qin, Xiaolei Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Sparse Black-Box Inversion Attack with Limited InformationabstractExisting black-box model inversion attacks mainly focus on training and attacking surrogate models. However, due to the deployment process of face recognition models, training surrogate models becomes extremely difficult in practice. At the same time, query-based black-box inversion attacks still suffer from low image quality and high computational costs. To bridge these gaps, in this paper, we propose BMI-S, a sparse black-box inversion attack against face recognition models. BMI-S first introduces evolution strategies to perform efficient black-box gradient estimation and achieve query-based attacks. Meanwhile, BMI-S performs sparse attacks on the key styles that contribute most to the face recognition process. By only optimizing key style control vectors, BMI-S further narrows the dimensions of the search space and accelerates the inversion attacks. Yixiao Xu, Xiaolei Liu 0001, Bangzhou Xin |
ICASSP | 2 |
| 2023 | Anti-Attack Intrusion Detection Model Based on MPNN and Traffic Spatiotemporal Characteristics
Jin Lan, Yuanyuan Huang 0007, Maojia Song, Xiaolei Liu 0001 |
J. Grid Comput. | 5 |
| 2022 | Sparse Adversarial Attack For Video Via Gradient-Based Keyframe SelectionabstractVideos have a higher dimensionality compared with images, making adversarial video attacks more challenging. We propose a gradient-based method for self-adaptive white-box video keyframe selection and video adversarial example generation, taking advantage of that perturbations are transferable between video frames. More specifically, a gradient-based method is proposed to determine different video frames’ contribution to classification results. Based on the weights of different frames and the given boundary values, the proposed method adaptively selects a subset of frames as keyframes for perturbation. Experimental results of attacking two widely used video classification models on UCF-101 and HMDB-51 datasets show that the proposed method effectively improves the generation efficiency as well as the steganography of adversarial video examples, leading to a reduction of more than 21% of the required number of iterations and more than 25% of the average perturbation size for the untargeted attack. Yixiao Xu, Xiaolei Liu 0001, Mingyong Yin, Kangyi Ding |
ICASSP | 2 |
| 2022 | Targeted Anonymization: A Face Image Anonymization Method for Unauthorized ModelsabstractAs an important biometric feature of every person, face data has faced serious risks of leakage in recent years. Lawbreakers can use face recognition systems (FRS) to analyze the leaked face data and then correlate other private information, causing serious privacy leaks. For security reasons, we hope our face images can only be recognized by the organizations' authorized models. To achieve this goal, this work proposes a targeted face image anonymization method that only enables anonymization for unauthorized facial recognition models, whilst authorized models, human eyes can still accurately recognize faces. Our method mainly uses transfer-based adversarial attacks to achieve anonymization. On this basis, we propose constraints for generating targeted anonymization samples and boundary walking strategy, focusing on improving the anonymization for unauthorized models while guaranteeing the accurate recognition of authorized models. Local experiments prove that our method can reduce the recognition probability of unauthorized models while guaranteeing the correctness of authorized models. Finally, we apply our approach to an online face recognition API and experimentally demonstrate that our approach can significantly reduce the recognition accuracy of the commercial face recognition model. Kangyi Ding, Xiaolei Liu 0001, Weina Niu, Xiaosong Zhang 0001 |
ICME | 3 |
| 2021 | Transaction-based classification and detection approach for Ethereum smart contract
Xiaolei Liu 0001, Ting Chen 0002, Xiaosong Zhang 0001, Weina Niu |
Inf. Process. Manag. | 2 |
| 2021 | A low-query black-box adversarial attack based on transferability
Kangyi Ding, Xiaolei Liu 0001, Weina Niu, Xiaosong Zhang 0001 |
Knowl. Based Syst. | 2 |
| 2021 | Research on information steganography based on network data stream
Weisha Zhang, Ziye Deng, Shibin Zhang, Yan Chang, Xiaolei Liu 0001 |
Neural Comput. Appl. | 6 |
| 2021 | A Hybrid Association Rule-Based Method to Detect and Classify BotnetsabstractNowadays, botnet has become a threat in the area of cybersecurity, and, worse still, it is difficult to be detected in complex network environments. Thus, traffic analysis is adopted to detect the botnet since this kind of method is practical and effective; however, the false rate is very high. The reason is that normal traffic and botnet traffic are quite close to the border, making it so difficult to be recognized. In this paper, we propose an algorithm based on a hybrid association rule to detect and classify the botnets, which can calculate botnets’ boundary traffic features and receive effects in the identification between normal and botnet traffic ideally. First, after collecting the data of different botnets in a laboratory, we analyze botnets traffic features by processing a data mining on it. The suspicious botnet traffic is filtered through DNS protocol, black and white list, and real-time feature filtering methods. Second, we analyze the correlation between domain names and IP addresses. Combining with the advantages of the existing time-based detection methods, we do a global correlation analysis on the characteristics of botnets, to judge whether the detection objects can be botnets according to these indicators. Then, we calculate these parameters, including the support, trust, and membership functions for association rules, to determine which type of botnet it belongs to. Finally, we process the test by using the public dataset and it turns out that the accuracy of our algorithm is higher. Yuanyuan Huang 0007, Haozhe Tang, Xiaolei Liu 0001 |
Secur. Commun. Networks | 4 |
| 2021 | HTTP-Based APT Malware Infection Detection Using URL Correlation AnalysisabstractAPT malware exploits HTTP to establish communication with a C & C server to hide their malicious activities. Thus, HTTP-based APT malware infection can be discovered by analyzing HTTP traffic. Recent methods have been dependent on the extraction of statistical features from HTTP traffic, which is suitable for machine learning. However, the features they extract from the limited HTTP-based APT malware traffic dataset are too simple to detect APT malware with strong randomness insufficiently. In this paper, we propose an innovative approach which could uncover APT malware traffic related to data exfiltration and other suspect APT activities by analyzing the header fields of HTTP traffic. We use the Referer field in the HTTP header to construct a web request graph. Then, we optimize the web request graph by combining URL similarity and redirect reconstruction. We also use a normal uncorrelated request filter to filter the remaining unrelated legitimate requests. We have evaluated the proposed method using 1.48 GB normal HTTP flow from clickminer and 280 MB APT malware HTTP flow from Stratosphere Lab, Contagiodump, and pcapanalysis. The experimental results have shown that the URL-correlation-based APT malware traffic detection method can correctly detect 96.08% APT malware traffic, and its recall rate is 98.87%. We have also conducted experiments to compare our approach against Jiang’s method, MalHunter, and BotDet, and the experimental results have confirmed that our detection approach has a better performance, the accuracy of which reached 96.08% and the F1 value increased by more than 5%. Weina Niu, Jiao Xie, Xiaosong Zhang 0001, Xin-Qiang Li, Rui-dong Chen, Xiaolei Liu 0001 |
Secur. Commun. Networks | 7 |
| 2021 | Compiler-Based Efficient CNN Model Construction for 5G Edge DevicesabstractWith the increasing demand to deploy convolutional neural networks (CNNs) on 5G mobile platforms, architecture designs with efficient sparse kernels (SKs) were proposed, which can save more parameters than the standard convolution while maintaining the high accuracy. Despite the great potential, neural network designs with SKs still require a lot of expert knowledge and take ample time. In this paper, we first propose a search scheme that effectively reduces the SK design space based on three aspects: composition, performance, and efficiency. Meanwhile, we completely eliminate the model training from our search scheme. Instead, an easily measurable quantity, the information field, is identified and used to predict the model accuracy in the searching process. Additionally, we provide a detailed efficiency analysis on the final designs found by our scheme. Second, based on the analysis we propose a model transformation scheme to better utilize the SK designs on existing models to either reduce the number of parameters or increase the accuracy. Last, considering the extra programming overhead and the expert knowledge required by the model transformation scheme, we develop a compiler prototype to automate the entire process, given the source code of an existing model. Experimental results show that models composed of the sparse kernel designs searched by our search scheme can beat state-of-the-art networks such as ResNets in terms of the accuracy and the efficiency. Also by using our model transformation scheme we can easily improve the accuracy (the same number of parameters) or the efficiency (the same accuracy) upon existing state-of-the-art models. Kun Wan 0001, Xiaolei Liu 0001, Jianyu Yu, Xiaosong Zhang 0001, Xiaojiang Du, Nadra Guizani |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2020 | Weighted-Sampling Audio Adversarial Example AttackabstractRecent studies have highlighted audio adversarial examples as a ubiquitous threat to state-of-the-art automatic speech recognition systems. Thorough studies on how to effectively generate adversarial examples are essential to prevent potential attacks. Despite many research on this, the efficiency and the robustness of existing works are not yet satisfactory. In this paper, we propose weighted-sampling audio adversarial examples, focusing on the numbers and the weights of distortion to reinforce the attack. Further, we apply a denoising method in the loss function to make the adversarial attack more imperceptible. Experiments show that our method is the first in the field to generate audio adversarial examples with low noise and high audio robustness at the minute time-consuming level 1. Xiaolei Liu 0001, Kun Wan 0001, Yufei Ding 0001, Xiaosong Zhang 0001, Qingxin Zhu |
AAAI | 1 |
| 2020 | A Black-Box Attack on Neural Networks Based on Swarm Evolutionary Algorithm
Xiaolei Liu 0001, Kangyi Ding, Yang Bai 0011, Weina Niu |
ACISP | 1 |
| 2020 | Research and Analysis of Electromagnetic Trojan Detection Based on Deep LearningabstractThe electromagnetic Trojan attack can break through the physical isolation to attack, and the leaked channel does not use the system network resources, which makes the traditional firewall and other intrusion detection devices unable to effectively prevent. Based on the existing research results, this paper proposes an electromagnetic Trojan detection method based on deep learning, which makes the work of electromagnetic Trojan analysis more intelligent. First, the electromagnetic wave signal is captured using software-defined radio technology, and then the signal is initially filtered in combination with a white list, a demodulated signal, and a rate of change in intensity. Secondly, the signal in the frequency domain is divided into blocks in a time-window mode, and the electromagnetic signals are represented by features such as time, information amount, and energy. Finally, the serialized signal feature vector is further extracted using the LSTM algorithm to identify the electromagnetic Trojan. This experiment uses the electromagnetic Trojan data published by Gurion University to test. And it can effectively defend electromagnetic Trojans, improve the participation of computers in electromagnetic Trojan detection, and reduce the cost of manual testing. Xiaolei Liu 0001, Shibin Zhang, Yan Chang |
Secur. Commun. Networks | 2 |
| 2019 | Network Intrusion Feature Map Node Equalization Algorithm Based on Modified Variable Step-Size Constant ModulusabstractWhen the network is subject to intrusion and attack, the node output channel equalization will be affected, resulting in bit error and distortion in the output of network transmission symbols. In order to improve the anti-attack ability and equalization of network node, a network intrusion feature map node equalization algorithm based on modified variable step-size constant modulus blind equalization algorithm (MISO-VSS-MCMA) is proposed. In this algorithm, the node transmission channel model after network intrusion is constructed, and sequential processing is performed to intruded nodes with the variable structure feedback link control method. With diversity spread spectrum technology, the channel loss after network intrusion is compensated and the network intrusion map feature is extracted. According to the extracted feature amount, channel equalization processing is performed for the cost function with the MISO-VSS-MCMA method to reduce the damage of network intrusion to the channel. Simulation results show that in node transmission channel equalization after network intrusion, this algorithm can reduce the error bit rate of signal transmission in network, and provide a good ability of correcting phase deflection in the output constellation, thus avoiding the error bit distortion and channel damage caused by network intrusion to the signal with a good equalization effect. This algorithm provides stronger convergence and map concentration, which demonstrates that its anti-interference and signal recovery capabilities are better, so it improves the anti-attack ability of the network. Xiaolei Liu 0001, Jianwei Zhang 0001, Xiaosong Zhang 0001 |
Int. J. Pattern Recognit. Artif. Intell. | 2 |
| 2019 | A Lockable Abnormal Electromagnetic Signal Joint Detection AlgorithmabstractWith the development of computers and network technologies, network security has gradually become a global problem. Network security defenses need to be carried out not only on the Internet, but also on other communication media, such as electromagnetic signals. Existing electromagnetic signal communication is easily intercepted or infiltrated. In order to effectively detect the abnormal electromagnetic signal to find out the specific location, then classify it, it is necessary to study the way of communication. The existing electromagnetic signal detection accuracy is low and cannot be located. Considering the characteristics of different power sources in different locations, combined with spark streaming technology and machine learning classification technology, a joint platform for electromagnetic signal anomaly detection based on big data analysis is proposed. The electromagnetic signal is abnormally detected by feature comparison and small signal analysis, and the position and number between the signal sources are determined by three-point positioning and signal attenuation. The experimental results show that the method can detect abnormal electromagnetic signals and classify abnormal electromagnetic signals well, the accuracy rate can reach 95%, and the positioning accuracy can reach 89%. Weina Niu, Xiaolei Liu 0001, Xiaosong Zhang 0001 |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2019 | An Insider Threat Detection Approach Based on Mouse Dynamics and Deep LearningabstractIn the current intranet environment, information is becoming more readily accessed and replicated across a wide range of interconnected systems. Anyone using the intranet computer may access content that he does not have permission to access. For an insider attacker, it is relatively easy to steal a colleague’s password or use an unattended computer to launch an attack. A common one-time user authentication method may not work in this situation. In this paper, we propose a user authentication method based on mouse biobehavioral characteristics and deep learning, which can accurately and efficiently perform continuous identity authentication on current computer users, thus to address insider threats. We used an open-source dataset with ten users to carry out experiments, and the experimental results demonstrated the effectiveness of the approach. This approach can complete a user authentication task approximately every 7 seconds, with a false acceptance rate of 2.94% and a false rejection rate of 2.28%. Weina Niu, Xiaosong Zhang 0001, Xiaolei Liu 0001 |
Secur. Commun. Networks | 4 |
| 2019 | Integrating Traffics with Network Device Logs for Anomaly DetectionabstractAdvanced cyberattacks are often featured by multiple types, layers, and stages, with the goal of cheating the monitors. Existing anomaly detection systems usually search logs or traffics alone for evidence of attacks but ignore further analysis about attack processes. For instance, the traffic detection methods can only detect the attack flows roughly but fail to reconstruct the attack event process and reveal the current network node status. As a result, they cannot fully model the complex multistage attack. To address these problems, we present Traffic-Log Combined Detection (TLCD), which is a multistage intrusion analysis system. Inspired by multiplatform intrusion detection techniques, we integrate traffics with network device logs through association rules. TLCD correlates log data with traffic characteristics to reflect the attack process and construct a federated detection platform. Specifically, TLCD can discover the process steps of a cyberattack attack, reflect the current network status, and reveal the behaviors of normal users. Our experimental results over different cyberattacks demonstrate that TLCD works well with high accuracy and low false positive rate. Fengmao Lv, Zhongliu Zhuo, Xiaosong Zhang 0001, Xiaolei Liu 0001, Wei Deng 0003 |
Secur. Commun. Networks | 5 |