EDBT 2026 Demo / reviewers in the wild / expert
Yuedong Pan
dblp:350/8505
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0001-3977-106XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DriftTrace: Combating Concept Drift in Security Applications Through Detection and Explanation
Yuedong Pan, Lixin Zhao, Tao Leng, Zhexi Luo, Dan Meng 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | TDBA: Towards Transferable Data-free Black-box Attack with Stable DiffusionabstractExisting data-free black-box attacks leverage generative adversarial networks (GANs) to synthesize images for substitute model distillation. However, these studies suffer from inefficiency due to the additional training required for the generator and produce poor-quality images. Additionally, they do not investigate advanced attack methods capable of generating highly transferable adversarial examples, resulting in a low attack success rate (ASR). In this paper, we propose a transferable data-free black-box attack (TDBA) scheme based on fine-tuning Stable Diffusion using Low-Rank Adaptation (LoRA) to obtain a substitute model with improved accuracy. To achieve a higher ASR, we integrate attention loss and relax the greedy search to enhance the gradient-based attack method, thereby improving the transferability of adversarial examples. Comprehensive experiments conducted on three benchmark datasets demonstrate the effectiveness of TDBA, which outperforms state-of-the-art GAN-based strategies in terms of the ASR under the same query budget. Furthermore, when combined with the improved gradient-based attacks, our approach further boosts the ASR and achieves a trade-off between ASR and attack cost. Qingwen Jin, Yuedong Pan |
CSCWD | 2 |
| 2025 | TaintAttack: rapid attack investigation based on information flow trackingabstractAbstract The perpetual battle between defenses and attacks in computing systems keeps evolving. In response to the growing complexity of attacks, data provenance has emerged as a vital solution for analysing alarms and conducting attack investigation by capturing intricate relationships among system entities. Despite its potential, the challenges of dealing with large-scale provenance graphs and a high volume of alarms persist, leading to inefficiencies in alarm analysis and attack investigation. To tackle these challenges, we present TaintAttack, an innovative approach for attack investigation. When performing provenance graph construction, TaintAttack conducts real-time tagging for system entities. To emphasize the critical threats, TaintAttack quantifies the threat levels of alarms based on event rarity, contextual features, and impact severity. Furthermore, guided by information flow tagging, TaintAttack commences attack investigation from alarms with high threat levels, greatly enhancing the overall efficiency of the investigation process. The evaluation results on 12 multi-stage attacks show that TaintAttack performs better in attack investigation compared to existing studies, reducing the investigation time by 2 orders of magnitude. Yuedong Pan, Lixin Zhao, Tao Leng, Chaofei Li |
Comput. J. | 1 |
| 2024 | ATKHunter: Towards Automated Attack Detection by Behavior Pattern Learning
Yuedong Pan, Lixin Zhao, Chaofei Li, Tao Leng, Dan Meng 0002 |
ICDF2C (1) | 1 |
| 2024 | Enhancing Adversarial Robustness for Deep Metric Learning via Attention-Aware Knowledge Guidance
Chaofei Li, Yuedong Pan, Ruicheng Niu |
ICIC (12) | 3 |
| 2024 | Early Detection of Fileless Attacks Based on Multi-Feature Fusion of Complex Attack VectorsabstractThe initial manifestations of fileless attacks were predominantly document-based attacks, extensively leveraged in Advanced Persistent Threat (APT) campaigns and cybercriminal activities. Malicious documents leveraging macros, DDE, template injection, and other attack vectors evade conventional signature-based detection techniques. Additionally, the constant influx of new samples undermines models trained only on single attack vector features. Herein, we introduce DocInspect, a methodological framework predicated on the multi-feature fusion of complex attack vectors. Through observational analyses of attack vectors, static analysis extracts keywords and indicators of compromise from vectors like macro code, simulated execution retrieves shellcode function calls and parameters, and deceptive images and text are concurrently extracted. These multi-dimensional features are then fused to construct feature vectors. Ultimately, leveraging the Extra Trees model on our latest sample set, we achieve an F1 score of 99.96%, while demonstrating commendable robustness. Tao Leng, Lixin Zhao, Yuedong Pan, Dan Meng 0002 |
ISCC | 3 |
| 2023 | MemInspect: Memory Forensics for investigating Fileless AttacksabstractTraditional security solutions focus on identifying threats that leave traces on the system’s hard drive. However, fileless attacks have become increasingly popular among cybercriminals due to their ability to evade detection and persist undetected for prolonged periods. In response, memory forensics facilitates the extraction of system memory activities, presenting an opportunity to detect fileless attacks executed directly in memory. This paper presents MemInspect, a specialized memory forensics approach designed to extract features and accurately identify and locate suspicious memory regions, effectively aiding analysts in investigating fileless malware attacks. Specifically, By Utilizing virtual address descriptor nodes as samples, MemInspect constructs a comprehensive set of 42 features to detect code injection, script-based attacks, and living off the land attacks. Subsequently, these features are employed for classification using ensemble learning algorithms. In this study, we meticulously designed comprehensive attack experiments, accurately simulating three prevalent types of fileless attacks. Through rigorous analysis and extensive training on the experimental data, MemInspect demonstrates remarkable performance, achieving an impressive Area Under the Curve (AUC) value of 98%. Additionally, the paper provides two detailed analysis cases of attack investigations, furnishing concrete evidence of MemInspect’s efficacy in detecting fileless attacks. Tao Leng, Yuedong Pan, Lixin Zhao, Dan Meng 0002 |
TrustCom | 2 |
| 2022 | AttackMiner: A Graph Neural Network Based Approach for Attack Detection from Audit Logs
Yuedong Pan, Tao Leng, Lixin Zhao, Jiangang Ma, Dan Meng 0002 |
SecureComm | 1 |