EDBT 2026 Demo / reviewers in the wild / expert
Hanjun Li 0005
dblp:376/8521
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0002-7017-8782ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-View Few-Shot Malware Classification With Support-Query PrototypesabstractArtificial Intelligence (AI) technology has been widely used in malware detection and has significantly improved defense against cyberattacks. Existing deep learning-based methods rely on training with large-scale data and only on predefined categories, making them inadequate for rapidly responding to novel malware attacks. Malware classification based on few-shot learning has made some progress in identifying unknown malware using limited data. However, existing methods struggle to achieve high performance because they typically focus on a single malicious feature, such as a single malware image or an API call sequence, thereby ignoring the multi-dimensional nature of malware. To deal with these challenges, we propose a multi-view few-shot learning method for malware classification. We propose a multi-view malicious feature engineering scheme, which combines domain knowledge and expert experience to analyze the malware from various perspectives. Furthermore, we propose a support-query prototype generation method based on multi-view malicious features to generate higher-quality malware prototypes, which enhances the representation of novel malware family distributions. Extensive experiments show that the proposed method outperforms existing state-of-the-art approaches. With only two samples per family, the accuracy still exceeds 90%. Our method demonstrates superior cross-dataset recognition capabilities, thereby fully illustrating its robustness and generalizability across different data distributions. Shuhong Chen, Hanjun Li 0005, Sheng Wen, Guojun Wang 0001, Tianqing Zhu, Yang Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Enhancing Few-Shot Malware Classification Through Joint Learning of Malware Images and Opcode SequencesabstractAn unending stream of malware variations presents a severe threat to the Internet community as a way of initiating cyber-attacks. Although few-shot learning-based malware classification methods have achieved some success in detecting unknown malware and using limited data for training, the majority of current techniques still struggle with classification performance because they only take into account a single malware image or API call sequence feature, ignoring the multi-dimensional nature of malware. To deal with these challenges, this paper proposes a malware image and opcode joint learning method for few-shot malware classification. We employ a cross-modal attention mechanism to determine the weight representing the correlation between the malware’s binary and assembly codes. Furthermore, we compute a weighted prototype based on the fused feature vector of binary and assembly codes to enhance the prototype’s generalizability. Extensive experiments demonstrate the superiority of our method compared to existing few-shot malware classification models, with an average accuracy of more than 83% in the 5-way settings with only two samples on both LargePE and VirusShare datasets. Hanjun Li 0005, Shuhong Chen, Guojun Wang 0001, Liu Cheng, Haojie Yin, Zhenkun Luo |
ISPA | 1 |
| 2024 | Boosting Transferability of Adversarial Examples by Joint Training and Dual Feature MixupabstractThe transferability of adversarial examples is pivotal in black-box attacks on deep learning models. The existing transfer-based attacks typically rely on a single data augmentation technique, which hampers the diversity of generated adversarial examples. Additionally, applying a single adversarial noise generation path may impose limitations on the perturbation strength of the generated noise, thereby compromising the transferability of these examples. To address these issues, we propose a framework called Joint Training and Dual Feature Mixiup (JFM), which comprises the dual feature mixup module and joint training module. The dual feature mixup module performs feature mixing between benign and augmented images, enabling the comprehensive extraction of benign example features and enhancing the diversity of adversarial examples. Furthermore, the joint training module designs a dual-path prediction loss function that incorporates both the loss between mixed feature examples and benign examples, as well as the loss between augmented examples and benign examples, thereby enhancing the transferability of the generated examples. Empirical evaluation of the ImageNet-compatible dataset demonstrates that our JFM method exhibits superior attack capability and significantly outperforms state-of-the-art methods. Mengmeng Tang, Shuhong Chen, Hanjun Li 0005, Zhuyi Yao, Sheng Wen |
TrustCom | 4 |
| 2023 | Two-Stage Smart Contract Vulnerability Detection Combining Semantic Features and Graph FeaturesabstractSmart contract vulnerability detection is an important security practice aimed at identifying and fixing potential vulnerabilities. This detection technique involves using static and dynamic analysis methods to inspect and test contract code, in order to identify code patterns and logical errors that may lead to security vulnerabilities. However, summarizing previous research reveals limitations in terms of scalability and generalizability, which can result in higher rates of false positives and false negatives in detection results. Therefore, we propose a novel smart contract detection framework called TSCSG: Two-Stage Smart Contract Vulnerability Detection Combining Semantic Features and Graph Features. In the graph extraction stage, TSCSG utilizes the data flow graph and control flow graph of smart contracts to extract the required contract graph. After processing the graph data, TSCSG employs our proposed RTMP network to extract smart contract graph features. In the semantic extraction stage of contract vulnerabilities, TSCSG utilizes smart contract data propagation chains to extract semantic features of smart contract vulnerabilities, which are then combined with the graph features to obtain the final detection results. Our large-scale empirical study on the EtherScan dataset demonstrates that TSCSG achieves satisfactory results in detecting reentrancy and timestamp vulnerabilities, outperforming 9 state-of-the-art vulnerability detection methods. Zhenkun Luo, Shuhong Chen, Guojun Wang 0001, Hanjun Li 0005 |
TrustCom | 4 |
| 2023 | Multi-Scale Feature Aggregation for Rumor Detection: Unveiling the Truth within TextabstractSocial media plays a significant role in our lives, providing convenience in accessing information and expressing opinions through various platforms. However, this convenience has also led to the proliferation of rumors. Therefore, detecting rumors on social media has become increasingly important. Many existing works focus on detecting rumors by analyzing source posts and comments posted by users, utilizing pre-trained language models to capture text representations. However, simply averaging the comments from different users fails to capture the correlation between comments and source posts, which is crucial for rumor detection. To address this issue, in this paper, we propose a multi-scale feature aggregation method. We utilize a BERT-based pre-trained language model to encode the source posts and comment texts, obtaining token scale feature representations. Furthermore, to differentiate between different comments, we perform secondary aggregation of features at the comment scale, mitigating the limitations of previous methods that treat all comments equally. We then employ an attention layer to obtain a correlation weight matrix between the source posts and comments, which represents their correlation. This approach significantly extracts comment content most relevant to the current event being detected. Experimental results on existing datasets in both Chinese and English demonstrate the superiority of our method compared to other existing approaches. Further experiments also confirm the importance of the multi-scale approach in mining the correlation between source posts and comments for rumor detection. Shuhong Chen, Guojun Wang 0001, Hanjun Li 0005 |
TrustCom | 5 |