EDBT 2026 Demo / reviewers in the wild / expert
Lansheng Han
dblp:36/4213
· DBLP profile ↗
35ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0001-7529-729XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 9 since 2021Systems, architecture and hardware · 9 · 2 first-author · 2 since 2021Computer networks · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Chebyshev Low-Pass Attention Filter for Multivariate Time Series Anomaly DetectionabstractThis paper introduces the Chebyshev Low-Pass Attention Filter (CLAF), a novel anomaly detection framework for multivariate time series in industrial sensor networks. The framework operates on Transformer attention weight matrices directly to address the limitation of raw data processing, which ignores multivariate dependencies and adapts poorly to pattern drift, within various existing offline static low-pass filters. Deployed only during testing as a plug-and-play component, CLAF constructs a dynamic normal baseline by performing spectral-domain smoothing on attention weight matrices adapted to non-stationary industrial data, and combines a hybrid anomaly score that integrates reconstruction error and Wasserstein distance to distinguish true anomalies from pattern drifts. Extensive experiments show that CLAF achieves state-of-the-art F1-scores of 0.9627 on SMD, 0.9570 on SMAP, 0.9541 on MSL, and 0.9139 on SWaT. CLAF maintains a recall above 0.98 and stable precision with high computational efficiency, offering it a practical solution for industrial intelligent maintenance. Dan Sun 0007, Lansheng Han |
IEEE Internet Things J. | 4 |
| 2025 | CLNX: Bridging Code and Natural Language for C/C++ Vulnerability-Contributing Commits IdentificationabstractLarge Language Models (LLMs) have shown great promise in vulnerability identification. As C/C++ comprise half of the open-source Software (OSS) vulnerabilities over the past decade and updates in OSS mainly occur through commits, enhancing LLMs' ability to identify C/C++ Vulnerability-Contributing Commits (VCCs) is essential. However, current studies primarily focus on further pre-training LLMs on massive code datasets, which is resource-intensive and poses efficiency challenges. In this paper, we enhance the ability of BERT-based LLMs to identify C/C++ VCCs in a lightweight manner. We propose CodeLinguaNexus (CLNX) as a bridge facilitating communication between C/C++ programs and LLMs. Based on commits, CLNX efficiently converts the source code into a more natural representation while preserving key details. Specifically, CLNX first applies Structure-level Naturalization to decompose complex programs, followed by Token-level Naturalization to interpret complex symbols. We evaluate CLNX on public datasets of 25,872 C/C++ functions with their commits. The results demonstrate that CLNX substantially improves the ability of LLMs to detect C/C++ VCCs. Moreover, CLNX-equipped CodeBERT achieves new state-of-the-art performance and identifies 38 OSS vulnerabilities in the real world. Zeqing Qin, Lansheng Han |
AAAI | 3 |
| 2025 | Blind Video Watermarking Resisting Camcorder Recording Based on Spatio-temporal SynchronizationabstractRobust video watermarking resisting camcorder recording has become an active research topic in recent years due to the increasing demand for preventing sensitive information displayed on computer screens from being recorded. In this paper, we propose a blind and robust watermarking method using spatio-temporal synchronization, in which the embedded information can be extracted from a marked and recorded video robustly by implementing the proposed spatial and temporal synchronizing technique. For a marked and recorded video, the proposed reverse difference pyramid transformation is applied to the temporal motion residuals of neighboring frames with recording ambient interference to register the watermarked regions. Then, to reduce the temporal distortion caused by frame rate conversion within recording, temporal synchronization information is embedded in special original frames periodically to synchronize the embedded authentication data, and two distinct transform domains are unitized to carry these two kinds of information respectively without false extraction. Experimental results show that the proposed method achieves superior video quality, low time cost, and high robustness against camcorder recording attacks, which demonstrates the superiority and applicability of the proposed work. Yifeng Shu, Lansheng Han, Xianjun Gu |
TrustCom | 3 |
| 2025 | Ripple2Detect: A semantic similarity learning based framework for insider threat multi-step evidence detection
Hongle Liu, Lansheng Han, Haili Sun, Cai Fu |
Comput. Secur. | 3 |
| 2025 | Strengthening edge defense: A differential game-based edge intelligence strategy against APT attacks
Man Zhou 0006, Lansheng Han |
Comput. Secur. | 2 |
| 2025 | Unmanned aerial vehicle swarm-assisted reliable federated learning for traffic flow prediction
Man Zhou 0006, Lansheng Han, Yangyang Geng |
Future Gener. Comput. Syst. | 2 |
| 2025 | DopSteg: Program steganography using data-oriented programming
Jianqiang Lv, Cai Fu, Liangheng Chen, Lansheng Han |
Sci. Comput. Program. | 7 |
| 2024 | Design and Optimization of Asymmetric Encryption Scheme Based on Blockchain and Its Application in Privacy Protection of Internet of VehiclesabstractWith the rapid development of intelligent road traffic management systems and autonomous vehicles, the Internet of Vehicles (IoVs) industry is showing a thriving trend. However, there are still many security issues with IoVs, which are susceptible to malicious attacks from potential factors, leading to privacy breaches. Blockchain is a reliable emerging technology that protects privacy and security, with advantages such as decentralization, data transparency, and secure data storage. Therefore, regarding the privacy leakage threat faced by passengers and drivers in the IoVs system, we designed a new IoVs privacy protection scheme based on the asymmetric encryption technology of blockchain blockchain. In this scheme, a blockchain-based asymmetric encryption scheme was first proposed and optimized to ensure the security and computational efficiency after encryption. The results indicated that the location information was well encrypted and protected. In addition, homomorphic encryption could perform specific calculations on encrypted data without decryption, and the ciphertext result was consistent with the decryption result. Therefore, by integrating Paillier homomorphic encryption algorithm, passengers and drivers in encrypted state could be matched for location, protecting the privacy of user location data. After safety and efficiency analysis, this scheme had good safety and efficiency, which could ensure the security of passengers and drivers' position privacy. This study laid the foundation for constructing efficient and secure methods for data security and privacy protection, providing new directions for the theoretical system of the IoVs data security, and promoting the healthy and stable development of the IoVs industry. Lansheng Han |
HPCC | 2 |
| 2024 | Enhancing Robustness of Code Authorship Attribution through Expert Feature KnowledgeabstractCode authorship attribution has been an interesting research problem for decades. Recent studies have revealed that existing methods for code authorship attribution suffer from weak robustness. Under the influence of small perturbations added by the attacker, the accuracy of the method will be greatly reduced. As of now, there is no code authorship attribution method capable of effectively handling such attacks. In this paper, we attribute the weak robustness of code authorship attribution methods to dataset bias and argue that this bias can be mitigated through adjustments to the feature learning strategy. We first propose a robust code authorship attribution feature combination framework, which is composed of only simple shallow neural network structures, and introduces controllability for the framework in the feature extraction by incorporating expert knowledge. Experiments show that the framework has significantly improved robustness over mainstream code authorship attribution methods, with an average drop of 23.4% (from 37.8% to 14.3%) in the success rate of targeted attacks and 25.9% (from 46.7% to 20.8%) in the success rate of untargeted attacks. At the same time, it can also achieve results comparable to mainstream code authorship attribution methods in terms of accuracy. Cai Fu, Hongle Liu, Lansheng Han, Wenjin Li |
ISSTA | 5 |
| 2024 | MTS-DVGAN: Anomaly detection in cyber-physical systems using a dual variational generative adversarial network
Haili Sun, Yan Huang 0026, Lansheng Han, Cai Fu, Hongle Liu, Xiang Long |
Comput. Secur. | 3 |
| 2024 | DCDroid: An APK Static Identification Method Based on Naïve Bayes Classifier and Dual-Centrality AnalysisabstractThe static scanning identification of android application packages (APK) has been widely proven to be an effective and scalable method. However, the existing identification methods either collect feature values from known APKs for inefficient comparative analysis, or use expensive program syntax or semantic analysis methods to extract features. Therefore, this paper proposes an APK static identification method that is different from traditional graph analysis. We match application programming interface (API) call graph to a complex network, and use a dual‐centrality analysis method to calculate the importance of sensitive nodes in the API call graph, while integrating the global and relative influence of sensitive nodes. Our key insight is that the dual‐centrality analysis method can more accurately characterize the graph semantic information of Android malicious APKs. We created and named a method DCDroid and evaluated it on a dataset of 4,428 benign samples and 4,626 malicious samples. The experimental results show that compared to the four advanced methods Drebin , MaMaDroid , MalScan , and HomeDroid , DCDroid can identify Android malicious APKs with an accuracy of 97.5%, with an F1 value of 96.7% and is two times faster than HomeDroid , eight times faster than Drebin , and 17 times faster than MaMaDroid . We grabbed 10,000 APKs from the Google Play Market, DCDroid was able to find 68 malicious APKs, of which 67 were confirmed Android malicious APKs, with a good ability to identify market‐level malicious APKs. Lansheng Han |
IET Inf. Secur. | 1 |
| 2024 | Sensor Spoofing Detection On Autonomous Vehicle Using Channel-spatial-temporal Attention Based Autoencoder Network
Lansheng Han |
Mob. Networks Appl. | 2 |
| 2024 | Space Decoupled Prototype Learning for Few-Shot Attack Detection in Cyber-Physical SystemsabstractDue to the lack of effective attack detection measures, cyberattacks may cause strong damage to industrial cyber–physical systems (CPSs). The embedding of attack categories learned by the existing attack detection methods is highly coupled to each other with fuzzy boundaries and overlapped neighborhood, leading to weak robustness and high false positive rates. To address these issues, in this article, we propose a few-shot attack detection method based on decoupled prototype learning (DPL-FSAD), aiming to enhance the detection accuracy and generalization capabilities for malicious attacks in CPS. Specifically, we first introduce feature contrastive learning to extract differentiated features from highly similar samples, achieving compact intraclass and sparse interclass feature embedding space. To solve the problem of fuzzy boundaries of different attack categories, prototype contrastive learning is then employed to reduce the coupling degree among prototypes and enhance their discriminability. A regularization term is exploited to mitigate the overfitting problem by reducing the gap between the feature embedding and prototypes. Furthermore, an orthogonal constraint is employed to separate prototypes of different attack types, generating a decoupled prototype embedding space. The experimental results on three public cyberattack datasets show that, compared with the suboptimal model a few-shot learning model with Siamese convolutional neural network (FSL-SCNN), the proposed DPL-FSAD can improve the precision by 5.53%,F1-score by 3.3%, and reduce the false positive rate by 2.37% in average, which proves that the space decoupled prototype learning is effective for improving the generalization and robustness of industrial CPS attack detection in few-shot scenario. Haili Sun, Yan Huang 0026, Chunjie Zhou, Lansheng Han, Hongle Liu, Xin Li 0005 |
IEEE Trans. Ind. Informatics | 4 |
| 2024 | BinCola: Diversity-Sensitive Contrastive Learning for Binary Code Similarity DetectionabstractBinary Code Similarity Detection (BCSD) is a fundamental binary analysis technique in the area of software security. Recently, advanced deep learning algorithms are integrated into BCSD platforms to achieve superior performance on well-known benchmarks. However, real-world large programs embed more complex diversities due to different compilers, various optimization levels, multiple architectures and even obfuscations. Existing BCSD solutions suffer from low accuracy issues in such complicated real-world application scenarios. In this paper, we propose BinCola, a novel Transformer-based dual diversity-sensitive contrastive learning framework that comprehensively considers the diversity of compiler options and candidate functions in the real-world application scenarios and employs the attention mechanism to fuse multi-granularity function features for enhancing generality and scalability. BinCola simultaneously compares multiple candidate functions across various compilation option scenarios to learn the differences caused by distinct compiler options and different candidate functions. We evaluate BinCola's performance in a variety of ways, including binary similarity detection and real-world vulnerability search in multiple application scenarios. The results demonstrate that BinCola achieves superior performance compared to state-of-the-art (SOTA) methods, with improvements of 2.80%, 33.62%, 22.41%, and 34.25% in cross-architecture, cross-optimization level, cross-compiler, and cross-obfuscation scenarios, respectively. Cai Fu, Jianqiang Lv, Lansheng Han, Hong Hu 0004 |
IEEE Trans. Software Eng. | 5 |
| 2023 | BTAD: A binary transformer deep neural network model for anomaly detection in multivariate time series data
Lansheng Han, Chunjie Zhou |
Adv. Eng. Informatics | 2 |
| 2023 | VDoTR: Vulnerability detection based on tensor representation of comprehensive code graphs
Yuanhai Fan, Chuanhao Wan, Cai Fu, Lansheng Han |
Comput. Secur. | 4 |
| 2022 | Neural-FacTOR: Neural Representation Learning for Website Fingerprinting Attack over TOR AnonymityabstractTOR (The Onion Router) network is a widely used open source anonymous communication tool, the abuse of TOR makes it difficult to monitor the proliferation of online crimes such as to access criminal websites. Most existing approches for TOR network de-anonymization heavily rely on manually extracted features resulting in time consuming and poor performance. To tackle the shortcomings, this paper proposes a neural representation learning approach to recognize website fingerprint based on classification algorithm. We constructed a new website fingerprinting attack model based on convolutional neural network (CNN) with dilation and causal convolution, which can improve the perception field of CNN as well as capture the sequential characteristic of input data. Experiments on three mainstream public datasets show that the proposed model is robust and effective for the website fingerprint classification and improves the accuracy by 12.21% compared with the state-of-the-art methods. Haili Sun, Yan Huang 0026, Lansheng Han, Xiang Long, Hongle Liu, Chunjie Zhou |
TrustCom | 3 |
| 2022 | IFAttn: Binary code similarity analysis based on interpretable features with attention
Cai Fu, Yekui Qian, Jianqiang Lv, Lansheng Han |
Comput. Secur. | 6 |
| 2021 | Function-level obfuscation detection method based on Graph Convolutional Networks
Hong Yao, Cai Fu, Yekui Qian, Lansheng Han |
J. Inf. Secur. Appl. | 5 |
| 2021 | Intrusion Detection System for IoT Heterogeneous Perceptual Network
Lansheng Han, Hongwei Lu, Cai Fu |
Mob. Networks Appl. | 2 |
| 2020 | Distributed collaborative intrusion detection system for vehicular Ad Hoc networks based on invariant
Lansheng Han, Hongwei Lu, Cai Fu |
Comput. Networks | 2 |
| 2020 | Cooperative malicious network behavior recognition algorithm in E-commerce
Man Zhou 0001, Lansheng Han, Hongwei Lu, Cai Fu, Dezhi An |
Comput. Secur. | 2 |
| 2019 | Targeting malware discrimination based on reversed association taskabstractSummary Regarding the current situation that the recognition rate of malware is decreasing, the article points out that the reason for this dilemma is that more and more targeting malware have emerged, which share little or no common feature with traditional malware. The premise of malware recognition judging whether a software is malicious or benign is actually a decision problem. We propose that malware discrimination should resort to the corresponding task or purpose. We first present a formal definition of a task and then provide further classifications of malicious tasks. Based on the decidable theory, we prove that task performed by any software is recursive and determinable. By establishing a mapping from software to task, we prove that software is many‐to‐one reducible to corresponding tasks. Thus, we demonstrate that software, including malware, is also recursive and can be determined by the corresponding tasks. Finally, we present the discrimination process of our method. Nine real malwares are presented, which were firstly discriminated by our method but at that time could not be identified by Kaspersky, McAfee, Symantec Norton, or Kingsoft Antivirus. Lansheng Han, Shuxia Han, Wenjing Jia, Changhua Sun, Cai Fu |
Concurr. Comput. Pract. Exp. | 1 |
| 2019 | Search engine: The social relationship driving power of Internet of Things
Cai Fu, Chenchen Peng, Xiao-Yang Liu, Laurence T. Yang, Lansheng Han |
Future Gener. Comput. Syst. | 6 |
| 2019 | Intrusion detection model of wireless sensor networks based on game theory and an autoregressive model
Lansheng Han, Wenjing Jia, Zakaria Dalil, Xingbo Xu |
Inf. Sci. | 1 |
| 2018 | An adaptive control momentum method as an optimizer in the cloud
Jianhao Ding, Lansheng Han, Dan Li 0012 |
Future Gener. Comput. Syst. | 2 |
| 2018 | Owner based malware discrimination
Lansheng Han, Shuxia Han, Wenjing Jia, Jingwei Lei |
Future Gener. Comput. Syst. | 1 |
| 2017 | Evolutionary virus immune strategy for temporal networks based on community vitality
Cai Fu, Xiao-Yang Liu, Tianqing Zhu, Lansheng Han |
Future Gener. Comput. Syst. | 6 |
| 2015 | Search Engine: A Hidden Power for Virus Propagation in Community NetworksabstractThe propagation methods of viruses are diverse and studying the virus propagation is a hot topic. There appears a new way that the search engine quickly spreads network viruses, and many researches overlook its impact of propagation and few researches set a model to quantifiabely analyze how the search engine spread viruses. Based on community networks, this paper designs a specific model how the search engine spreads viruses. Moreover, this paper quantifiabely calculate the virus propagation velocity and the propagation effect. First, by analyzing the propagation process of viruses under the search engine condition, we design a positive feedback model to analyze how the search engine and the community network influence the propagation process of viruses. Second, we define relationship functions of propagation factors and calculate the rate of infected nodes while establishing mathematical propagation formulas for two situations. One situation is with the search engine, and another is without the search engine. Third, we design the experiment to verify the model analysis. Compared with two situations, we show that viruses have a much quicker propagation velocity, and the growth rate of infected rate is larger under the search engine condition. When the immune vaccine replaces the virus, this paper is also applicable. Cai Fu, Deliang Xu, Lansheng Han, Xiao-Yang Liu |
CSCloud | 4 |
| 2015 | An Energy-Balanced WSN Algorithm Based on Active Hibernation and Data Recovery
Changming Liu, Cai Fu, Deliang Xu, Lansheng Han |
ICA3PP (1) | 5 |
| 2013 | Cryptanalysis and improvement of a certificateless threshold signature secure in the standard model
Guozheng Hu, Lansheng Han, Zhanqing Wang, Xiangsheng Xia |
Inf. Sci. | 2 |
| 2013 | A post-quantum provable data possession protocol in cloudabstractABSTRACT Provable data possession (PDP) is a model for efficiently checking the integrity of data in cloud storage. Most previous PDP protocols are insecure when quantum computers are considered. In this paper, we propose a homomorphic hash‐based PDP (HH‐PDP) protocol from ideal lattice assumptions. Firstly, we prove that a collision‐resistant hash function family is homomorphic. Then, we use the homomorphism to generate homomorphic verification tags and further construct a new PDP protocol. The security of the proposed protocol relies on the assumed worst‐case hardness of ideal lattice problems, which hold a great promise for post‐quantum cryptography. We prove that the proposed protocol guarantees data possession in the standard model if the shortest polynomial problem is hard. As the main operations in our construction are addition and multiplication on small integers, the proposed protocol is more efficient than previous protocols. Experimental result shows that HH‐PDP is approximately five times cheaper in preprocessing and checking proof, half cost in generating proof compared with the most efficient PDP protocol proposed by Ateniese et al. in 2011. Copyright © 2013 John Wiley & Sons, Ltd. Lansheng Han, Jiandu Jing, Dongping Hu |
Secur. Commun. Networks | 2 |
| 2011 | GRAP: Grey risk assessment based on projection in ad hoc networks
Cai Fu, Lansheng Han |
J. Parallel Distributed Comput. | 5 |
| 2009 | A Fuzzy Comprehensive Evaluation Model for Harms of Computer VirusabstractThe variety and complexity of virus harm cause there is few practical evaluation methods currently. The paper first presents harms' definition and classification of the virus. Then representative first-level and second-level evaluation indexes are proposed. However, as these evaluation factors could hardly be assigned with definite values and somewhat have fuzziness, the paper constructs a fuzzy evaluation model for the harm of computer virus. Once an obscure value is assigned to each evaluation indexes in the second level, the model can calculate the membership degree to each of the five harm grades, and then obtains a reasonable harm evaluation result. Finally, the paper evaluates the harms of ldquoWorm.WhBoy.hrdquo, ldquoAutoRunrdquo, ldquoJS.Yamanner.ardquo and ldquoAn-ti-virusrdquo by the fuzzy model; the evaluation result is similar to the statistics of the virus. Cong Zheng, Lansheng Han, Jihang Ye, Mengsong Zou, Qiwen Liu |
MASS | 2 |
| 2006 | Tracing the Source of Net-Virus within a SubnetabstractThe paper presents the definition for the source of viruses in a subnet: the start vertex of the spreading path of the virus. Then the paper points out state changing of the vertices caused by the spreading of the virus is the important hints to tracing the spreading path of the virus, the scanning and cleaning are main methods to get these hints. So the paper establishes the source tracing equations for the net virus. Combining with the practice, the paper presents the main steps and methods to get the solutions to the equations. Finally, the paper carries out the simulation test on an email group net. The results of the test verify the tracing model. Thus the paper opens a theoretic way to tracing the source of net viruses Lansheng Han, Varney Washington, Shuxia Han |
CSCWD | 1 |