EDBT 2026 Demo / reviewers in the wild / expert
Junchao Xiao
dblp:44/4959
· DBLP profile ↗
25ranked-venue papers
7as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 3 first-authorArtificial intelligence and machine learning · 5 · 2 first-author · 2 since 2021Security and privacy · 5 · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowledge-aware neighbor collaborative multi-relationship multi-interest comparative recommender system for diversified book recommendations
Junchao Xiao, Linhui Wu, Fuli Zhong |
Expert Syst. Appl. | 1 |
| 2025 | HoleMal: A lightweight IoT malware detection framework based on efficient host-level traffic processing
Ziqian Chen, Zhen Li 0011, Gang Xiong 0001, Gaopeng Gou, Haikuo Li, Junchao Xiao |
Comput. Secur. | 8 |
| 2024 | TMGAN: A GAN-Based Traffic Morphing Defense Against Website FingerprintingabstractWith the rapid growth of encrypted traffic, methods that use side-channel information to monitor online user behavior have emerged, known as Website Fingerprinting (WF) attacks. These attacks pose a significant threat to the privacy of users’ online activities. To address the threat posed by various WF attacks to network behavior privacy, current methods lack defenses based on the source/target misclassification of traffic. Our goal is to design a WF defense method that transforms the side-channel information of the given original category traffic into that of another category to counter existing DNN-based WF attacks. We utilize adversarial examples and employ a Generative Adversarial Network (GAN) incorporating a WF model to generate perturbations. These perturbations are overlaid onto the given traffic, morphing it into traffic of another category, thereby enhancing the privacy of network behavior. We refer to the proposed method as the Traffic Morphing Generative Adversarial Network (TMGAN). Experimental results demonstrate that this method effectively counters most WF attacks, enhancing the privacy of users’ online behavior. In white-box scenarios, it achieves average perturbation rates of 90-99% and morphing rates of 31-75%. In black-box scenarios, it achieves average perturbation rates of 95-98% and morphing rates of 5-28%. Shukan Huang, Junchao Xiao, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
HPCC | 2 |
| 2023 | TGC: Transaction Graph Contrast Network for Ethereum Phishing Scam DetectionabstractPhishing scams have become the most serious type of crime involved in Ethereum. However, existing methods ignore the natural camouflage and sparse distribution of phishing scams in Ethereum leading to unsatisfactory performance, and they are also limited by the data scale which cannot be applied to real-world dynamic scenarios. In this paper, we propose a Transaction Graph Contrast network (TGC) to enhance phishing scam detection performance on Ethereum. TGC inputs subgraphs instead of the entire graph for training, which eases the model’s requirements for machine configuration and data connectivity. Motivated by phishing nodes are surrounded by normal nodes, we design the comparison between node-level to help phishing nodes learn the unique properties of themselves different from their neighbors. Observing the small number and sparse distribution of phishing nodes, we narrow the distance between phishing nodes by comparing node context-level structures, so as to learn universal transaction patterns. We further combine the obtained features with common statistics to identify phishing addresses. Evaluated on real-world Ethereum phishing scams datasets, our TGC outperforms the state-of-the-art methods in detecting phishing addresses and has obvious advantages in large-scale and dynamic scenarios. Gaopeng Gou, Chang Liu 0049, Gang Xiong 0001, Zhen Li 0011, Junchao Xiao, Xinyu Xing 0001 |
ACSAC | 6 |
| 2023 | Robust anomaly-based intrusion detection system for in-vehicle network by graph neural network framework
Junchao Xiao, Fuli Zhong, Xiangxue Li |
Appl. Intell. | 1 |
| 2023 | Robust Anomaly-Based Insider Threat Detection Using Graph Neural NetworkabstractMisuse or malicious access to critical assets of information systems by insiders usually causes significant loss to organizations. The issue of insider threat detection for information systems has received many researchers’ attention in both security and data mining fields, and a lot of related research results were presented. However, there are still many challenges in capturing the behavior difference between malicious insiders and normal users accurately, such as lack of labeled insider threats, the subtle and adaptive nature of insider threats, complexity, heterogeneity, sparsity of the underlying data, etc. To detect insider threats with large and complex audit data, a Multi-Edge Weight Relational Graph Neural Network method (MEWRGNN) for robust anomaly detection is proposed in this paper. Unlike most existing approaches, the MEWRGNN adopts several graph neural networks to capture the contextual relationship of user behaviors over a period of time, which is a critical factor for achieving accurate anomaly identification. The MEWRGNN achieves a certain degree of interpretability through ranking the contribution of different edge-representation features. Evaluation experimental results demonstrate that the MEWRGNN can learn a model from limited sample data sets, and achieve quick and accurate insider threat detection performance. In addition, other feature ranking results allow providing security analysts with understandable insights for investigating the detected insider threats. Junchao Xiao, Lin Yang 0031, Fuli Zhong, Xiaolei Wang 0003 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | MADDC: Multi-Scale Anomaly Detection, Diagnosis and Correction for Discrete Event LogsabstractAnomaly detection for discrete event logs can provide critical information for building secure and reliable systems in various application domains, such as large scale data centers, autonomous driving, and intrusion detection. However, the task is very challenging due to the lack of a clear understanding and definition of anomaly in the specific problem space, and the log data is often highly complex with temporal correlation. Existing deep learning based methods mostly suffer from such issues as overfitting, uncertainty or low interpretability; consequently, the detection results may be inaccurate, with little information to help security analysts diagnose the reported anomalies with high confidence. To tackle this challenge, in this research, we propose a general framework named MADDC, which aims to (1) accurately perform Multi-scale Anomaly Detection, Diagnosis and Correction for discrete event logs, and (2) help analysts further mitigate anomalies based on diagnosis results. Specifically, we first design a new anomaly critic for LSTM variational autoencoder based model to alleviate overfitting and reduce false negatives during anomaly detection. As one of our main contributions, we then introduce process mining technique to build process-centric workflow models in an unsupervised manner, which forms the ‘normal’ context of an event sequence and help perform accurate and consistent anomaly diagnosis through global sequence alignment. Experiments on publicly available datasets show that MADDC not only outperformed several representative methods in terms of detection accuracy, but also could improve the visibility to abnormal deviations from normal execution, hence helping security analysts understand anomalies and make further corrections. Xiaolei Wang 0003, Lin Yang 0031, Linru Ma, Junchao Xiao, Jiyuan Liu 0003, Yuexiang Yang |
ACSAC | 6 |
| 2022 | Voice Conversion Using Learnable Similarity-Guided Masked Autoencoder
Yewei Gu, Xianfeng Zhao, Xiaowei Yi, Junchao Xiao |
IWDW | 4 |
| 2021 | Image-Based Insider Threat Detection via Geometric TransformationabstractInsider threat detection has been a challenging task over decades; existing approaches generally employ the traditional generative unsupervised learning methods to produce normal user behavior model and detect significant deviations as anomalies. However, such approaches are insufficient in precision and computational complexity. In this paper, we propose a novel insider threat detection method, Image-based Insider Threat Detector via Geometric Transformation (IGT), which converts the unsupervised anomaly detection into supervised image classification task, and therefore the performance can be boosted via computer vision techniques. To illustrate, our IGT uses a novel image-based feature representation of user behavior by transforming audit logs into grayscale images. By applying multiple geometric transformations on these behavior grayscale images, IGT constructs a self-labelled dataset and then trains a behavior classifier to detect anomaly in a self-supervised manner. The motivation behind our proposed method is that images converted from normal behavior data may contain unique latent features which remain unchanged after geometric transformation, while malicious ones cannot. Experimental results on CERT dataset show that IGT outperforms the classical autoencoder-based unsupervised insider threat detection approaches, and improves the instance and user based Area under the Receiver Operating Characteristic Curve (AUROC) by 4% and 2%, respectively. Lin Yang 0031, Xiaolei Wang 0003, Linru Ma, Junchao Xiao |
Secur. Commun. Networks | 6 |
| 2019 | Practical IDS on In-vehicle Network Against Diversified Attack Models
Junchao Xiao, Hao Wu 0008, Xiangxue Li, Yuan Linghu |
ICA3PP (2) | 1 |
| 2016 | Perspectives on refactoring planning and practice: an empirical study
Jie Chen 0003, Junchao Xiao, Qing Wang 0001, Leon J. Osterweil, Mingshu Li 0001 |
Empir. Softw. Eng. | 2 |
| 2015 | Ant colony algorithm based scheduling for handling software project delayabstractDelay on a critical path may cause the failure in meeting the software project deadline. By adding extra employees with similar skills for help, the delay is expected to be eliminated or reduced. However, the originally scheduled activities may be suspended due to reallocation of employees, which may lead to the problem of delay propagation. So how to minimize and even eliminate the delay without delay propagation is worth investigation. In this paper, we first use a simple scenario to demonstrate the problem of employee scheduling which shows that in the scheduling process, one activity can have many ways for selecting employees from another project. In fact, the searching path in a multi-branch tree and its complete traversal is a NP hard problem. Furthermore when the scale of the problem becomes large, it is impractical to generate a search tree for implementation. Therefore, we propose an ant colony algorithm to address such a problem. Both case studies and initial simulation results demonstrate that our proposed algorithm can obtain feasible solutions under different circumstances. Wei Zhang 0098, Yun Yang 0001, Junchao Xiao, Xiao Liu 0004, Muhammad Ali Babar 0001 |
ICSSP | 3 |
| 2015 | Using simulation to evaluate error detection strategies: A case study of cloud-based deployment processes
Jie Chen 0003, Xiwei Xu 0001, Leon J. Osterweil, Liming Zhu 0001, Yuriy Brun, Leonard J. Bass, Junchao Xiao, Mingshu Li 0001, Qing Wang 0001 |
J. Syst. Softw. | 7 |
| 2014 | Refactoring planning and practice in agile software development: an empirical studyabstractAgile software engineering increasingly seeks to incorporate design modification and continuous refactoring in order to maintain code quality even in highly dynamic environments. However, there does not currently appear to be an industry-wide consensus on how to do this and research in this area expresses conflicting opinions. This paper presents an empirical study based upon an industry survey aimed at understanding the different ways that refactoring is thought of by the different people carrying out different roles in agile processes and how these different people weigh the importance of refactoring versus other kinds of tasks in the process. The study found good support for the importance of refactoring, but most respondents agreed that deferred refactoring impacts the agility of their process. Thus there was no universally agreed-upon strategy for planning refactoring. The survey findings also indicated that different roles have different perspectives on the different kinds of tasks in an agile process although all seem to want to increase the priority given to refactoring during planning for the iterations in agile development. Analysis of the survey raised many interesting questions suggesting the need for a considerable amount of future research. Jie Chen 0003, Junchao Xiao, Qing Wang 0001, Leon J. Osterweil, Mingshu Li 0001 |
ICSSP | 2 |
| 2013 | Analysis of the Key Factors for Software Quality in Crowdsourcing Development: An Empirical Study on TopCoder.comabstractCrowdsourcing is a distributed problem-solving and production model. It takes advantage of the internet technology, helps enterprises save cost and improve efficiency. However, uncertain quality is a significant challenge for crowdsourcing. On the basis of the existing literatures, this paper proposes 23 software quality factors from two aspects: platform and project. By using multiple regression analysis on the data of one of the most successful software crowdsourcing platforms TopCoder.com, this paper analyzes the impact of the factors on software quality and identifies six key factors, including the average quality score of the platform, the number of contemporary projects, the length of component document, the number of registered developers, the maximum rating of submitted developers, and the design score. According to the result, this paper suggests four aspects for enterprises to improve software quality: choosing the prosperous period of platform to post a project, reducing the scale of projects, attracting more and higher skillful developers to participate, and improving software design score. Junchao Xiao, Yongji Wang 0002, Qing Wang 0001 |
COMPSAC | 2 |
| 2013 | Search based risk mitigation planning in project portfolio managementabstractSoftware projects are always facing various risks. These risks should be identified, analyzed, prioritized, mitigated, monitored and controlled. After risks are identified and analyzed, resources must then be devoted to mitigation. However, risk prioritization and mitigation planning are complicated problems. Especially in project portfolio management (PPM), resource contention among projects leads to difficulty in choosing and executing mitigation actions. This paper introduces a search based risk mitigation planning method that is useful in PPM. It integrates the analysis of risks, consideration of available resources, and evaluation of possible effects when taking risk mitigation actions. The method uses a genetic algorithm to search for the risk mitigation plan of optimal value. A case study shows how this method can identify effective risk mitigation plans, thus providing useful decision support for managers. Junchao Xiao, Leon J. Osterweil, Jie Chen 0003, Qing Wang 0001, Mingshu Li 0001 |
ICSSP | 1 |
| 2013 | Creating Process-Agents incrementally by mining process asset library
Junchao Xiao, Qiusong Yang, Qing Wang 0001 |
Inf. Sci. | 2 |
| 2011 | Automatic mining of change set size information from repository for precise productivity estimationabstractProductivity is a crucial concern for most software organizations. It can help project managers to make project plan, supervise project progress, and measure the project members' performance. Thus it has been widely measured and analyzed by both industry and researchers. But in the actual software project management, the project data filled by the developers may be incomplete and imprecise. Especially it is very hard for the developers to give the precise work product scale of each task. Therefore, the productivity calculated basing on those data is also imprecise. To solve the problem, this paper presents a method for precise productivity estimation. The method calculates work product scale of each task using change set size information by rebuilding relationships between the tasks and the SVN commits, and then calculates the productivity. And an experimental study has been done basing on Qone. Qone is an integrated system for project management developed by Institute of Software Chinese Academy of Sciences (ISCAS). It has been used in more than 200 software companies in China. Qiusong Yang, Junchao Xiao, Jian Zhai |
ICSSP | 3 |
| 2010 | Dynamic Resource Scheduling in Disruption-Prone Software Development Environments
Junchao Xiao, Leon J. Osterweil, Qing Wang 0001, Mingshu Li 0001 |
FASE | 1 |
| 2009 | The role of software process simulation modeling in software risk management: A systematic reviewabstractNowadays software projects are still suffering from many problems due to various kinds of software risks. Software risk management is a crucial part of successful project management, but it is often not well implemented in real-world software projects. One reason is that project managers lack effective and practical tools to manage software risks. Software process simulation modeling (SPSM) has been emerging as a promising approach to address a variety of issues in software engineering area, including risk management. However, the current state of how SPSM supports software risk management is not yet clear. This paper presents a systematic literature review which purpose is to obtain the state of the art of the applications of SPSM in software risk management. We drew the following conclusions from the review results: (1) The number of SPSM studies on software risk management is relatively small, but increasing gradually in recent years. (2) SPSM is mainly applied in risk analysis and risk management planning activities. (3) Software risks related to requirements, development process and management process are the ones most studied by SPSM. (4) Discrete-event simulation and system dynamics are two most popular simulation paradigms, while Hybrid simulation methods are more and more widely used. (5) Extend, iThink and Vensim are the most popular simulation tools in SPSM. (6) Most of SPSM approaches and models have not been well applied into real-world risk management practices. Qing Wang 0001, Junchao Xiao |
ESEM | 3 |
| 2009 | PP-HAS: A Task Priority Based Preemptive Human Resource Scheduling Method
Lizi Xie, Qing Wang 0001, Junchao Xiao, Yongji Wang 0002 |
SEKE | 3 |
| 2008 | Mining Individual Performance Indicators in Collaborative Development Using Software RepositoriesabstractA better understanding of the individual developers¿ performance has been shown to result in benefits such as improved project estimation accuracy and enhanced software quality assurance. However, new challenges of distinguishing the individual activities involved in software evolution arise when considering collaborative development environments. Since software repositories such as version control systems (VCS) and bug tracking systems (BTS) are available for most software projects and hold a detailed and rich record of the historical development information, this paper presents our experiences mining individual performance indicators in collaborative development environments by using these repositories. The base of our key idea is to identify the complexity metrics (in the code base) and field defects (from bug tracking system) at individual-level by incorporating the historical data from version control system. We also remotely measure and analyze these indicators mined from a libre project jEdit, which involves around one hundred developer. The results show that these indicators are feasible and instructive in the understanding of the individual performance. Yongji Wang 0002, Junchao Xiao |
APSEC | 3 |
| 2008 | A constraint-driven human resource scheduling method in software development and maintenance processabstractSoftware processes are highly people-dependent and knowledge transfer-centric compared to traditional manufacturing processes. Different people are responsible for different types of knowledge transformation according to the skill set and expertise they master. This adds a great deal of complicated factors in resolving the scheduling problem in software development and maintenance process planning. The existing human resource scheduling methods do not take into account the differences between human resource capabilities and capacities in processes execution. This paper presents a constraint-driven human resource scheduling method in software development and maintenance process. A constraint model is set up based on the software process model and human resource model. A constraint-driven scheduling method is provided to realize the optimal human resource scheduling in software development and maintenance process. The method can be used in the mature organizations whose human resources have the determinate capabilities. It provides the excellent decision support to the project manager. Junchao Xiao, Qing Wang 0001, Mingshu Li 0001, Lizi Xie |
ICSM | 1 |
| 2008 | Dynamically Optimize Process Execution Based on Process-agent
Junchao Xiao, Qing Wang 0001, Mingshu Li 0001, Huaizhang Li |
SEKE | 2 |
| 2008 | A Project Scheduling Method Based on Human Resource Availability
Lizi Xie, Junchao Xiao, Qing Wang 0001 |
SEKE | 2 |