Chao Zha

dblp:384/1198 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
6since 2021 · last 2026
0009-0004-6611-2328ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Normality in Anomaly: Rethinking Traffic Labels
Chao Zha, Dakun Shen, Ruyun Zhang 0001, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.1
2026 FlowXpert: Context-Aware Flow Embedding for Enhanced Traffic Detection in IoT Network
abstract
In the Internet of Things (IoT) environment, continuous interaction among a large number of devices generates complex and dynamic network traffic, which poses significant challenges to rule-based detection approaches. Machine learning (ML)-based traffic detection technology, capable of identifying anomalous patterns and potential threats within this traffic, serves as a critical component in ensuring network security. This study first identifies a significant issue with widely adopted feature extraction tools (e.g., CICFlowMeter): the extensive use of time- and length-related features leads to high sparsity, which adversely affects model convergence. Furthermore, existing traffic detection methods generally lack an embedding mechanism capable of efficiently and comprehensively capturing the semantic characteristics of network traffic. To address these challenges, we propose a novel feature extraction tool that eliminates traditional time and length features in favor of context-aware semantic features related to the source host, thus improving the generalizability of the model. In addition, we design an embedding training framework that integrates the unsupervised DBSCAN clustering algorithm with a contrastive learning strategy to effectively capture fine-grained semantic representations of traffic. Extensive empirical evaluations are conducted on the real-world dataset (Mawi) and two simulated datasets (CICIDS-2017 and UNSW-NB15) to validate the proposed method in terms of detection accuracy, robustness, and generalization. Comparative experiments against several state-of-the-art (SOTA) models demonstrate the superior performance of our approach. Furthermore, we confirm its applicability and deployability in real-time scenarios.
Chao Zha, Haolin Pan, Ruyun Zhang 0001
IEEE Trans. Mob. Comput.1
2025 CFP-Gen: Combinatorial Functional Protein Generation via Diffusion Language Models
abstract
Existing PLMs generate protein sequences based on a single-condition constraint from a specific modality, struggling to simultaneously satisfy multiple constraints across different modalities. In this work, we introduce CFP-GEN, a novel diffusion language model for Combinatorial Functional Protein GENeration. CFP-GEN facilitates the de novo protein design by integrating multimodal conditions with functional, sequence, and structural constraints. Specifically, an Annotation-Guided Feature Modulation (AGFM) module is introduced to dynamically adjust the protein feature distribution based on composable functional annotations, e.g., GO terms, IPR domains and EC numbers. Meanwhile, the ResidueControlled Functional Encoding (RCFE) module captures residue-wise interaction to ensure more precise control. Additionally, off-the-shelf 3D structure encoders can be seamlessly integrated to impose geometric constraints. We demonstrate that CFP-GEN enables high-throughput generation of novel proteins with functionality comparable to natural proteins, while achieving a high success rate in designing multifunctional proteins.
Junbo Yin, Chao Zha, Chencheng Xu, Xin Gao 0001
ICML2
2025 A-NIDS: Adaptive Network Intrusion Detection System Based on Clustering and Stacked CTGAN
abstract
Intrusion detection systems (IDS) are crucial tools for detecting anomalous network traffic in cybersecurity. In recent years, significant progress has been made in applying artificial intelligence to IDS. However, existing research often assumes that training and testing data are static and identically distributed, whereas in reality, data drift is inevitable. Moreover, to enhance model versatility and detection performance, models have become increasingly complex, posing challenges to real-time deployment. To address these challenges, we propose an adaptive network intrusion detection system named A-NIDS, consisting of a main task and two bypass tasks. The main task is to develop a fully connected and shallow network with strong detection performance and real-time capability. The first bypass task is a clustering model that helps the main task detect data drift in an unsupervised manner. The second bypass task is a generation model to generate old data to address catastrophic forgetting in new model iterations and the storage cost issue caused by accumulating old data. We conduct extensive experiments on the CICIDS-2017 and CSE-CICIDS-2018 datasets, demonstrating the superior performance of A-NIDS on new and old data. Furthermore, our detection module achieves a detection latency of 5 microseconds, highlighting its suitability for real-time applications. All the related code is publicly available at:https://github.com/ids-sec-hub/A-NIDS.
Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001
IEEE Trans. Inf. Forensics Secur.1
2025 DM-IDS - A Network Intrusion Detection Method Based on Dual-Modal Fusion
abstract
The machine learning-based approach to network intrusion detection presents a groundbreaking research paradigm, positioned to replace traditional rule-based and signature-based methods. However, prior research methodologies have predominantly focused on flow-based approaches, which may not be effective in detecting all types of attacks at a granular level. In this study, we introduce DM-IDS, an attention-convolution architecture model for bimodal network intrusion detection in both flow and payload modalities, using bilinear fusion. Notably, we present a novel method for constructing binary-form feature vectors under the payload modality, with the goal of extracting additional security semantic features. To facilitate this, we independently develop a feature generation tool named Beeman. Finally, we conduct a series of comparative and ablation experiments on two publicly available datasets, CICIDS-2017 and CICIoT-2023, achieving state-of-the-art model performance.
Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001
IEEE Trans. Netw. Serv. Manag.1
2024 SKT-IDS: Unknown attack detection method based on Sigmoid Kernel Transformation and encoder-decoder architecture
Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001
Comput. Secur.1