EDBT 2026 Demo / reviewers in the wild / expert
Weilin Gai
dblp:352/9310
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2025
0009-0004-2671-3559ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Malicious DoH Tunnel Traffic Identification Framework Based on DiffFlow-CNNabstractThis study proposes DiffFlow-CNN, a novel framework for identifying malicious DNS over HTTPS (DoH) tunnel traffic, addressing the critical challenge of data imbalance in network security. By transforming network traffic into grayscale images, the framework can leverage context-rich spatial feature extraction to improve the detection accuracy. A diffusion model is employed for data augmentation, generating diverse, highquality malicious traffic samples to mitigate class imbalance. The augmented data is processed by a 2D Convolutional Neural Network (CNN), which effectively classifies traffic into NonDoH, benign DoH, and malicious DoH categories, with further differentiation of malicious types such as Iodine, dns2tcp, and DNSCat2. Experimental results on the CIRA-CIC-DoHBrw-2020 dataset demonstrate that DiffFlow-CNN achieves near-perfect performance, with an accuracy of 99.97%, precision of 99.99%, recall of 99.09%, and F1-score of 99.52% with DiffFlow-CNN. Comparative analysis highlights the superiority of bidirectional flow representations, particularly the Session+MFR method, which leverages early packet information for optimal feature capture. The framework significantly enhances the detection of covert malicious DoH traffic, offering a robust solution for network security management. Weilin Gai, Runqing Zhang, Yunjun Ma, Peng Zhang 0044, Ruoxing Wang |
HPCC | 2 |
| 2025 | LLM-THP: A Large Language Model-Powered Terminal Honeypot Dialogue FrameworkabstractWith the acceleration of digital globalization, cyber threats are showing a trend of complexity and diversification, posing serious security challenges to critical information infrastructure and sensitive data. In this context, the development of efficient and accurate cyber threat detection technologies has become an urgent need to address potential risks and safeguard the security of the digital ecosystem. Terminal Honeypot is a security tool specifically designed to trap and analyze network attacks against end devices. It attracts attackers by simulating real terminal environments, thus collecting attacker behavioral data and attack methods. Development cycle, high resource consumption, and lack of the ability actively adapt to different attacker behaviors. These problems limit the analysis of the depth of the attack and the subsequent collection of attack information. Therefore, in order to adapt to the unknown attacks against Internet devices in the new situation, it is particularly important to design a terminal honeypot that is free from the predefined conditions and can flexibly respond to various attack scenarios. In this paper, a terminal honeypot design method based on LLM (Large Language Model), LLM-THP, is proposed to solve the problem that the existing honeypots are difficult to cope with unknown network threats. Firstly, we study to construct the initial honeypot environment by presetting prompts and design CoT-DPU, Chain-of-Thought Dynamic Prompt Update, which effectively avoids the token overflow problem in multiple attack interactions. For the challenges of attacker interaction, model invocation, and time asynchrony in practical deployment, the LLM-THP framework designs an efficient workflow. Experimental results show that LLM-THP is better than existing mainstream terminal honeypots in terms of honeypot attractiveness, correct response rate, and simulation. Laite Wang, Huan Qian, Weilin Gai, Zhijian Zheng, Peng Zhang 0044, Ruoxing Wang |
HPCC | 4 |
| 2025 | Encryption Traffic Classification Based on Mining Traffic Context and Transport RelationshipabstractThis paper proposes a novel ETC-MTCTR, which is designed to enable more accurate, versatile and efficient traffic classification in the context of multi-scenario, low-resource encrypted traffic. Through three modules of Datagram Token conversion, pretraining and fine-tuning, the method uses large-scale unlabeled encrypted traffic for pretraining, mining and learning the traffic context and transmission relationship of encrypted traffic classification tasks, so that a small number of labeled data samples can be effectively used in the fine-tuning stage. Significantly improve the performance of the model on specific downstream classification tasks, enhance the accuracy, adaptability and robustness of the model in diverse environments, limited resources and new encryption security protocols, and realize efficient encryption traffic classification in multi-scenario and low-resource background. The results show that ETC-MTCTR achieves the best performance on three tasks: encryption malware classification, VPN encrypted traffic classification, and TLS 1.3 encryption application classification. Its F1 score is improved by 0.22% in the classification task of encrypted malware, 1.4% in the classification task of VPN encrypted traffic App, 4.56% in the classification task of VPN encrypted traffic Service, and 9.89% in the classification task of TLS 1.3 encrypted application, which is significantly better than other comparison methods. Weilin Gai, Runqing Zhang, Peng Zhang 0044 |
WCNC | 1 |
| 2024 | MFC-DoH: DoH Tunnel Detection Based on the Fusion of MAML and F-CNNabstractDomain Name System (DNS) tunnels, used by attackers to transmit sensitive information through plaintext DNS protocols, have garnered significant attention. In addressing the security concerns of DNS, the Internet Engineering Task Force (IETF) introduced the DNS-over-HTTPS (DoH) protocol in 2018, aiming to encrypt DNS data transmission and effectively safeguard user privacy. However, attackers cleverly conceal DNS tunnels within HTTPS using the DoH protocol, rendering traditional detection methods ineffective and resulting in numerous areas being impacted by malicious events. Although there are studies on DoH tunnel detection, few are concerned with DoH tunnel detection in few-shot scenarios. This paper proposes a novel method called MFC-DoH, based on the combination of Model-Agnostic Meta-Learning (MAML) and the unique CNN network(F-CNN) with the introduction of the frequency domain layer and multi-head attention layer(MHSA). We evaluate our method on the public dataset. Experimental results exhibit that our method significantly outperforms the existing approach in detecting DoH tunnels in few-shot scenarios. Weilin Gai |
CF | 4 |
| 2024 | Enhancing Feature Selection in IoT Intrusion Detection Using the Ensemble StackingabstractThe Internet of Things (IoT) is increasingly vulnerable to security risks due to new network attacks. Deep learning-based intrusion detection systems (DL-IDS) have emerged as a key solution, but they face challenges like imbalanced datasets and lengthy training times in complex environments. While feature selection algorithms are commonly employed to mitigate these issues, mainstream methods can yield inconsistent results, failing to reflect data characteristics accurately and potentially introducing noise. To address this problem, we propose an ensemble stacking approach to combine multiple feature selection algorithms, thereby minimizing errors from individual approaches. Each feature selection method acts as a base learner to assess feature importance, while logistic regression is a meta-learner to integrate the outputs into a final result. Additionally, we developed a CNN-based intrusion detection model enhanced with BiLSTM and attention mechanisms to improve detection performance. Our approach was tested on the UNSW-NB15 and CIC-IDS2017 datasets, with results indicating a significant improvement in detection performance compared to using a single feature selection method. Zhijian Zheng, Weilin Gai, Peng Zhang 0044, Ming Zhou 0010 |
ISPA | 2 |
| 2023 | MFL-RAT: Multi-class Few-Shot Learning Method for Encrypted RAT Traffic Detection
Jianhuan Zhuo, Jianjun Lin, Weilin Gai, Yinliang Yue |
Inscrypt (1) | 5 |