Yingchang Jiang

dblp:419/1123 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2026
0009-0005-1632-6413ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021
YearPublicationVenuePosition
2026 FusionITD: enhanced cross-modal insider threat perception framework via behavior-semantic fusion
abstract
Abstract In recent years, insider threat incidents have occurred with increasing frequency, leading to severe data breaches and substantial economic losses. Most existing insider threat detection methods rely primarily on single-modal features, such as system logs and registry data, while failing to fully exploit the rich semantic information embedded in instant messaging and email content of insider users. To address the above issues, we propose FusionITD, a cross-modal insider threat perception enhancement framework based on the fusion of behavioral and semantic features. This framework combines users’ temporal behavioral characteristics such as file operations and login device patterns with the semantic information derived from web browsing and email content. By modeling user behavior baselines from multiple dimensions, FusionITD enables more accurate anomaly detection when deviations from the baseline occur. Firstly, based on the temporal distribution of user behaviors, the behavior data is segmented and aggregated according to the time window to form a user behavior graph. We propose WR-GNN based on graph representation learning to capture temporal behavioral features, and introduce the Focal MSE loss function to address the data imbalance problem caused by sparse abnormal behavior data. Secondly, we propose a retrieval-augmented generation-based semantic analysis algorithm. We use cosine similarity to perform semantic matching and ranking between behavioral contents and historical behaviors. We extract features such as emotion, intention, and focus to achieve fine-grained anomaly detection for user behavior. Finally, we designed an adaptive weighting mechanism based on logistic regression to dynamically integrate the outputs of the previous two parts, enhancing the generalization ability for different threat scenarios. Experimental results conducted on the CERT datasets show that FusionITD outperforms other methods by achieving a 5% increase in AUC, a higher TPR, and a lower false positive rate.
Lu Yuan 0002, Dexian Chang, Hao Hu 0005, Yingchang Jiang, Heyu Chang, Liguo Fang
Cybersecur.4
2026 Attack Path Planning in 5G-ICPS Penetration Testing: Leveraging TGNN and DRL for Large-Scale Network
abstract
Path planning constitutes a critical component of penetration testing for 5G-ICPS networks. The diversity of interfaces and protocols necessitates deep analysis of vulnerability exploitation methods and cross-protocol combination strategies, significantly increasing attack path planning complexity. Furthermore, dynamic network slice configurations and physical-information coupling effects drive continuous topological evolution, causing state-space explosion and challenging path planning under uncertainty with incomplete information. To address these issues, we construct a temporal attack graph modeling 5G-ICPS attack processes, and design a GraphSAGE-based environment representation encoder. This encoder undergoes multi-tiered self-supervised pre-training, employing node-level and graph-level training to encode diverse reinforcement learning environments across attack scenarios into fixed-dimensional vector representations. This achieves decoupling from underlying topology, vulnerability specifics, and security configurations, effectively mitigating state-space explosion in large-scale networks. Subsequently, we cluster highly similar vulnerabilities and filter invalid attack actions using three typical 5G-ICPS attack constraints, compressing the agent’s exploration space. Especially, we design a customized reward function that dynamically incentivizes/penalizes actions based on compromised assets. Experimental results demonstrate significant improvements: penetration testing invalid action rates decrease from 22.3% to 7.5%, while average steps to achieve attack targets reduce by >54%. These advancements effectively reduce penetration testing costs and increase attack success rates.
Feiyang Li, Hao Hu 0005, Yingchang Jiang, Yixiao Peng
IEEE Internet Things J.3
2026 Enhancing Cloud Network Resilience via a Robust LLM-Empowered Multi-Agent Reinforcement Learning Framework
abstract
While virtualization and resource pooling empower cloud networks with structural flexibility and elastic scalability, they inevitably expand the attack surface and challenge cyber resilience. Reinforcement Learning (RL)-based defense strategies have been developed to optimize resource deployment and isolation policies under adversarial conditions, aiming to enhance system resilience by maintaining and restoring network availability. However, existing approaches lack robustness as they require retraining to adapt to dynamic changes in network structure, node scale, attack strategies, and attack intensity. Furthermore, the lack of Human-in-the-Loop (HITL) support limits interpretability and flexibility. To address these limitations, we propose CyberOps-Bots, a hierarchical multi agent reinforcement learning framework empowered by Large Language Models (LLMs). Inspired by MITRE ATT&CK's “Tactics-Techniques” model, CyberOps-Bots features a two-layer architecture: (1) An upper-level LLM agent with four mod ules—ReAct planning, IPDRR-based perception, long-short term memory, and action/tool integration—performs global awareness, human intent recognition, and tactical planning; (2) Lower-level RL agents, developed via heterogeneous separated pre-training, execute atomic defense actions within localized network regions. This synergy preserves LLM adaptability and interpretability while ensuring reliable RL execution. Experiments on real cloud datasets show that, compared to state-of-the-art algorithms, CyberOps-Bots maintains network availability 68.5% higher and achieves a 34.7% jumpstart performance gain when shifting the scenarios without retraining. To our knowledge, this is the first study to establish a robust LLM-RL framework with HITL support for cloud defense.
Yixiao Peng, Hao Hu 0005, Feiyang Li, Xinye Cao, Yingchang Jiang, Jipeng Tang, Guoshun Nan
IEEE Trans. Dependable Secur. Comput.5
2025 LLM4Game: Multi-agent reinforcement learning with knowledge injection for dynamic defense resource allocation in cloud storage
Yixiao Peng, Hao Hu 0005, Feiyang Li, Yingchang Jiang, Jipeng Tang
Comput. Networks4
2025 A zero-shot self-improving NER method for cyber threat intelligence via knowledge injection
abstract
Abstract The rapid evolution of cyber threats demands efficient entity extraction from Cyber Threat Intelligence (CTI) reports to support proactive analysis and sharing. Current methods for CTI extraction falter due to a lack of domain knowledge, which can lead to the overlooking of critical entities. Moreover, the hallucinations in LLM’s outputs result in insufficient accuracy. To address these limitations, we propose a zero-shot, self-improving NER method for CTI via knowledge injection. The framework consists of four modules: a domain knowledge extractor, a reliable data annotator, a high-consistency annotation filter, and a self-retrieval reasoner. The domain knowledge extractor enhances LLM comprehension of specialized threat intelligence, while the others work in a multi-stage reasoning process to mitigate hallucinations by generating, filtering, and reasoning upon high-consistency data. These modules collaborate to improve the model’s entity recognition ability through continuous in-context learning. Experimental results show that under strict zero-shot conditions, the proposed method achieves F1 scores of 67.7%, 61.41%, 74.56%, and 65.83% on the LLM-TIKG, APT-NER, LADDER, and CDTier datasets, respectively. This represents an improvement of 7.66% over the average F1 score of other baseline methods, demonstrating superior adaptability in low-resource security scenarios.
Yingchang Jiang, Feiyang Li, Changzhi Zhao, Canhua Chen
Cybersecur.1