Haodi Xie

dblp:343/4251 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2026
0009-0004-6747-2931ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021
YearPublicationVenuePosition
2026 GS-HF: An anomaly detection method for network traffic based on heterogeneous features and GraphSAGE
abstract
With the rapid growth of network traffic, data has become increasingly complex and voluminous, posing significant challenges for accurate anomaly detection. Traditional deep learning approaches often fail to capture the rich interdependencies and heterogeneous nature of traffic features, limiting their effectiveness in identifying subtle or evolving abnormal patterns. To address these challenges, this paper proposes GS-HF (GraphSAGE with heterogeneous features), an anomaly detection framework. The method integrates both statistical and image-like features extracted from raw traffic data to capture multi-dimensional characteristics, and then constructs a graph based on the fused heterogeneous features to better represent relationships among traffic flows. An improved GraphSAGE model is applied for detection, incorporating Focal Loss to handle class imbalance in real-world anomaly datasets. Extensive experiments on multiple network traffic datasets demonstrate that GS-HF achieves superior detection performance compared to existing methods, highlighting its robustness and effectiveness in handling diverse and complex traffic patterns.
Bo Geng, Jinfu Chen 0001, Saihua Cai, Haodi Xie, Yisong Liu
J. Comput. Secur.4
2024 GCN-MHSA: A novel malicious traffic detection method based on graph convolutional neural network and multi-head self-attention mechanism
Jinfu Chen 0001, Haodi Xie, Saihua Cai, Luo Song, Bo Geng, Wuhao Guo
Comput. Secur.2
2023 TLS-MHSA: An Efficient Detection Model for Encrypted Malicious Traffic based on Multi-Head Self-Attention Mechanism
abstract
In recent years, the use of TLS (Transport Layer Security) protocol to protect communication information has become increasingly popular as users are more aware of network security. However, hackers have also exploited the salient features of the TLS protocol to carry out covert malicious attacks, which threaten the security of network space. Currently, the commonly used traffic detection methods are not always reliable when applied to the problem of encrypted malicious traffic detection due to their limitations. The most significant problem is that these methods do not focus on the key features of encrypted traffic. To address this problem, this study proposes an efficient detection model for encrypted malicious traffic based on transport layer security protocol and a multi-head self-attention mechanism called TLS-MHSA. Firstly, we extract the features of TLS traffic during pre-processing and perform traffic statistics to filter redundant features. Then, we use a multi-head self-attention mechanism to focus on learning key features as well as generate the most important combined features to construct the detection model, thereby detecting the encrypted malicious traffic. Finally, we use a public dataset to verify the effectiveness and efficiency of the TLS-MHSA model, and the experimental results show that the proposed TLS-MHSA model has high precision, recall, F1-measure, AUC-ROC as well as higher stability than seven state-of-the-art detection models.
Jinfu Chen 0001, Luo Song, Saihua Cai, Haodi Xie, Shang Yin
ACM Trans. Priv. Secur.4
2022 A formalization-based vulnerability detection method for cross-subject network components
abstract
With the rapid development of computer technology, the cross-subject network components (CSNC) is widely used in software. However, the existing of vulnerabilities in CSNC may seriously affect the security of software, which attracts the attention of software tester. This paper proposes a formal-based vulnerability detection method called FVDM for CSNC to detect the security vulnerabilities and defects in the logic of components. The proposed FVDM firstly selects the singleton as the medium of abstract computation as well as uses the formal description language to construct a vulnerability propagation model; And then, the FVDM classifies the vulnerabilities into explicit and implicit vulnerabilities through analyzing the types of vulnerabilities, thereby designing the vulnerability detection algorithm for explicit vulnerabilities and implicit vulnerabilities respectively. The experimental results on several COM (Component Object Model) components show that the proposed FVDM can detect the buffer overflow as well as illegal access vulnerabilities in the components.
Jinfu Chen 0001, Haodi Xie, Saihua Cai, Ye Geng, Yemin Yin, Zikang Zhang
TrustCom2