Yi Chen 0008

dblp:49/6574-8 · DBLP profile ↗
← Back
28ranked-venue papers
5as first author
19since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 9 · 3 first-author · 4 since 2021Security and privacy · 7 · 2 first-author · 5 since 2021Computer networks · 5 · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 MCPDS: image-based malware classification method using PE metadata alone
abstract
Abstract In response to the increasing threat posed by the exponential growth of malware in cybersecurity, researchers have developed a number of malware classification methods based on malware images and deep learning in recent years. Newly proposed methods of this type tend to focus on generating malware images by extracting multiple types of information from a PE file, as well as on using complex convolutional neural network (CNN) models, to achieve high classification accuracy. Methods that involve extracting multiple types of information, especially those that require file disassembly for acquisition and the subsequent use of complex CNN models, result in a lengthy process for generating malware images and significantly increase model training durations. To alleviate this problem, we adopt the idea of using only a small part of the content that can be easily extracted from a PE file to efficiently generate a malware image, and implement malware classification without relying on complex CNN models. As a key component of a PE file, the PE header and the section table (we call them PE metadata) are characterized by a relatively low byte count and are likely to be useful for malware classification according to the similarities observed in the PE metadata between malware from both the same family and different families. Therefore, in this work, we explore the feasibility of using PE metadata alone to generate an image for malware classification and propose an Image of PE metadata (IPM) generated from PE metadata to represent malware. Based on the proposed IPM, we then construct a shallow CNN model and combine it with a support vector machine classifier to introduce a novel malware classification method called MCPDS ( M alware c lassification method using P E metadata, d eep learning and s upport vector machine). The experimental results show that the MCPDS not only achieves high accuracy in terms of classifying malware on two malware datasets but also exhibits high efficiency in terms of image generation and good robustness against adversarial samples.
Yonglin Zhao, Chun Guo 0004, Yuan Ping 0003, Yi Chen 0008, Yunhe Cui, Guowei Shen
Cybersecur.4
2026 A lightweight malware classification method based on short bit sequence visualization
Chun Guo 0004, Guowei Shen, Yuan Ping 0003, Yunhe Cui, Yi Chen 0008
Eng. Appl. Artif. Intell.6
2026 Tide: Intra- and Inter-Timeslot Enhanced Node Embedding for Probing Attack Detection in SDN
abstract
Probing the configurations of the Software-Defined Networking (SDN) switches is the essential preliminary for attacking SDN. This study points out a critical bottleneck in detecting probing attack: the dynamically changing character of different kinds of probing attacks makes the existing detection methods fail to detect probing attack. In this paper, we propose Tide, a probing attack detection method based on a Dynamic Flow-Packet graph (DFP-Graph), along with an intra-and inter-timeslot enhanced node embedding strategy. Tide constructs a (FP-Graph) across multiple timeslots, thereby modeling the intra-timeslot DFP-Graph consisting of multiple static Flow-Packet Graphs correlations that include the flow to flow, packet to packet, flow to packet, and packet to flow relationships while representing the inter-timeslot correlation of flows. Furthermore, Tide proposes an intra-timeslot node embedding module, an inter-timeslot node embedding module, and a probing attack flow detection module. The intra-timeslot node embedding module is designed to update the node representations based on the intra-timeslot correlation among different flows, while the inter-timeslot node embedding module is proposed to track the time-varying characters of a single flow. Finally, the probing attack flow detection module is employed to integrate the flow nodes’ representations in each timeslot and identify the probing attack flows. The experimental results demonstrate that Tide can effectively detect probing attack. It achieves the average detection accuracy at 87.51%, which outperforms the state-of-the-art methods.
Longyan Ran, Yunhe Cui, Guowei Shen, Chun Guo 0004, Yi Chen 0008, Qing Qian 0001
IEEE Internet Things J.5
2026 HSMNet: A multi-resolution grayscale image steganalysis method based on hybrid dilated convolution and self-attention multi-channel network
Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Guowei Shen, Hanzhou Wu
Inf. Sci.3
2026 E2DE: An edge frequency domain coefficient prediction-based fast video dual-watermarking scheme for eliminating edge-discontinuity effects
Jianmu Wang, Guowei Shen, Yi Chen 0008, Yunhe Cui, Chun Guo 0004, Zhenghui Liu, Hanzhou Wu
Signal Process.3
2025 FTOA-RP: A 'group'-based flow entry replacement policy probing and flow table overflow attack method
Yunhe Cui, Rongfei He, Yi Chen 0008, Chun Guo 0004, Guowei Shen
Comput. Secur.4
2025 A Clustering-Based Color Reordering Method for Reversible Data Hiding in Palette Images
abstract
ABSTRACT A recent research work pointed out that the reversible data hiding algorithms proposed for gray‐scale images can be implemented on the reconstructed palette images to improve embedding capacity and visual quality by reordering the color table. However, the reordering effect has a significant impact on performance improvement. Therefore, we propose a clustering‐based color reordering method for reversible data hiding in palette images to improve the reordering effect and further enhance the performance. In this method, we first design a centroid initialization method to select the initial centroids and then exploit the K‐means algorithm to generate clusters for the colors in the original color table. In the following, our proposed method, respectively, reorders the colors of these clusters by a greedy strategy and concatenates them into the reordered color table. Based on the relationship between the original and the reordered color tables, a novel index matrix can be reconstructed. Finally, state‐of‐the‐art reversible data hiding algorithms can be implemented on the reconstructed index matrix for performance improvement. Since our proposed method improves the reordering effect, enhances the correlation of the reconstructed index matrix, and reduces the length of the encoded location map, the maximal embedding capacities and the visual quality under the fixed embedding capacities are improved. We conducted experiments on two image datasets and six standard images to verify that the performance improvement of our proposed reordering method is better than that of the state‐of‐the‐art methods.
Jianxuan Deng, Yi Chen 0008, Chun Guo 0004, Yunhe Cui, Guowei Shen
IET Image Process.2
2025 PRAETOR:Packet flow graph and dynamic spatio-temporal graph neural network-based flow table overflow attack detection method
Kaixi Wang, Yunhe Cui, Guowei Shen, Chun Guo 0004, Yi Chen 0008, Qing Qian 0001
J. Netw. Comput. Appl.5
2025 CPSketch: A 'couple' sketch-based heavy flow detection method
Renpin Yao, Yunhe Cui, Yi Chen 0008, Chun Guo 0004, Guowei Shen
J. Netw. Comput. Appl.4
2025 A multi-level additive distortion method for security improvement in palette image steganography
Yi Chen 0008, Hongxia Wang 0001, Yunhe Cui, Guowei Shen, Chun Guo 0004, Hanzhou Wu
J. Vis. Commun. Image Represent.1
2025 The DUDFTO Attack: Towards Down-to-UP Timeout Probing and Dynamically Flow Table Overflowing in SDN
abstract
As a new network structure, the decoupling of the control plane and forwarding plane makes Software-Defined Networking (SDN) widely used in large-scale network scenarios. However, the decoupling network architecture also brings new vulnerabilities. The flow table overflow attack is an attack strategy that can overwhelm SDN switches. Nevertheless, the existing flow table overflow attacks may fail in probing timeouts and match fields of flow entries, due to link failure, measurement of the round-trip time (RTT) of different packets, interference of hard-timeout and idle-timeout. Meanwhile, the stealthiness of the existing attacks may also reduce, as these attacks use fixed attack rate. To improve the timeout probing accuracy and the stealthiness of attack, a new flow table overflow attack strategy, DUDFTO, is proposed to accurately probe timeout settings and match fields, then stealthily overflow SDN flow tables. Firstly, it probes the match fields by measuring the one-sided transmission delay of the packets. After that, DUDFTO designs a down-to-up feedback-based timeout probing algorithm to eliminate the issues caused by high RTT, link failure, interference between hard-timeout and idle-timeout. Then, DUDFTO designs a dynamic attack packets sending algorithm to improve its stealthiness. Finally, DUDFTO probes the flow table state to stop sending new attack packets. The evaluation results demonstrate that DUDFTO outperforms the existing attacks in terms of match fields probing ability, timeout probing relative error, number of packet_in and flow_mod messages generated by the attack, rate distribution of packet_in and flow_mod messages generated during the attack, and number of detected attack packets.
Jiasong Li, Yunhe Cui, Yi Chen 0008, Guowei Shen, Chun Guo 0004, Qing Qian 0001
IEEE Trans. Netw. Serv. Manag.3
2024 NFAERCOM: A Near-Far Area Experience Replay-based Computation Offloading Method
abstract
Computation offloading technology plays an important role in Mobile Edge Computing (MEC). Most mainstream Deep Reinforcement Learning (DRL)-based computation offloading methods employ random experience replay to train networks. This training method does not take into account the value differences between experiences, resulting in the decrease of training speeds and the increase of task completion delay, energy consumption, and task drop rate. Prioritized Experience Replay (PER) alleviates this issue to some extent. However, using Temporal Difference (TD) error as the criterion for the importance of experiences does not allow for the selection of experiences that are more "concerned" by the Actor network under the Actor-Critic framework. This limitation restricts the performance of the algorithm. To address these issues, this paper focuses on the computation offloading problem in scenarios with multiple mobile devices (MDs) and multiple MEC servers. A near-far area experience replay algorithm-based computation offloading method named NFAERCOM is proposed. NFAERCOM additionally considers the queuing delay at the MEC server and introduces a new near-far area experience replay algorithm. Evaluation results demonstrate that NFAERCOM effectively reduces the task completion delay, energy consumption, and task drop rate of tasks.
Yunhe Cui, Chun Guo 0004, Yi Chen 0008, Guowei Shen
ISPA5
2024 SNDMI: Spyware network traffic detection method based on inducement operations
Chun Guo 0004, Yuan Ping 0003, Yunhe Cui, Yi Chen 0008, Guowei Shen
Comput. Secur.5
2023 USAGE : Uncertain flow graph and spatio-temporal graph convolutional network-based saturation attack detection method
Kaixi Wang, Yunhe Cui, Qing Qian 0001, Yi Chen 0008, Chun Guo 0004, Guowei Shen
J. Netw. Comput. Appl.4
2023 NACA: A Joint Distortion-Based Non-Additive Cost Assignment Method for Video Steganography
abstract
Lots of non-additive cost assignment methods designed for image steganography have improved the security of stego images, but surprisingly there are only a few such non-additive cost assignment methods for video steganography. In this paper, we first analyze the distortion propagation by decomposing it into inner-block, inter-block, and inter-frame distortion drifts. Then, we determine the inner-block distortion drift (caused by the embedding modifications) that induces the inter-block and the inter-frame distortion drifts, using prediction. Based on the findings, we compose a joint distortion for all transform coefficients in each transform block. Finally, we propose a joint distortion-based non-additive cost assignment (NACA) method to reduce the inner-block distortion drift by distortion compensation. This allows us to further reduce both intra-frame (inter-block) and inter-frame distortion drifts, and achieve enhanced security. We conduct extensive experiments to evaluate the performance of NACA, in terms of security and coding performance. The evaluation results demonstrate that NACA achieves improved security and visual stego video quality, and maintains a very marginal increase in bit-rate, in comparison to four other competing additive cost assignment approaches.
Yi Chen 0008, Zoran A. Salcic, Hongxia Wang 0001, Kim-Kwang Raymond Choo, Xuyun Zhang
IEEE Trans. Dependable Secur. Comput.1
2022 DDCA: A Distortion Drift-Based Cost Assignment Method for Adaptive Video Steganography in the Transform Domain
abstract
Cost assignment plays a key role in coding performance and security of video steganography. Existing cost assignment methods (for adaptive video steganography) are designed for specific transform coefficients rather than all transform coefficients. In addition, existing video steganographic frameworks do not allow Syndrome-Trellis Codes (STCs) to modify all transform coefficients in both intra-coded and inter-coded frames at the same time. To address these limitations, in this article, we first propose a novel video steganographic framework. Then, we give a theoretical analysis of distortion drift in both intra- and inter-coding procedures. Based on the analysis, we design a Distortion Drift-Based Cost Assignment method, hereafter referred to as DDCA. DDCA considers the inner-block, inter-block and inter-frame distortion costs in order to improve the coding performance and the security of stego videos when the embedding payload is fixed. We conducted extensive experiments using two video datasets to evaluate the proposed video steganographic framework and DDCA, in terms of the coding performance and the security. Our experiments show that the proposed framework outperforms three recent state-of-the-art methods, for example the coding performance and the security of stego videos can benefit from DDCA by making full use of all nonzero transform coefficients.
Yi Chen 0008, Hongxia Wang 0001, Kim-Kwang Raymond Choo, Peisong He, Zoran A. Salcic, Mohamed Ali Kâafar, Xuyun Zhang
IEEE Trans. Dependable Secur. Comput.1
2021 EAR: An Enhanced Adversarial Regularization Approach against Membership Inference Attacks
abstract
Membership inference attacks on a machine learning model aim to determine whether a given data record is a member of the training set. They pose severe privacy risks to individuals, e.g., identifying an individual's participation in a hospital's health analytic training set reveals that this individual was once a patient in that hospital. Adversarial regularization (AR) is one of the state-of-the-art defense methods that mitigate such attacks while preserving a model's prediction accuracy. AR adds membership inference attacks as a new regularization term to the target model during the training process. It is an adversarial training algorithm that is trained on a defended model which is essentially the same as training the generator of generative adversarial networks (GANs). We observe that many GAN variants are able to generate higher quality samples and offer more stability during the training phase than GANs. However, whether these GAN variants are available to improve the effectiveness of AR has not been investigated. In this paper, we propose an enhanced adversarial regularization (EAR) method based on Least Square GANs (LSGANs). The new EAR surpasses the existing AR in offering more powerful defensive ability while preserving the same prediction accuracy of the protected classifiers. We systematically evaluate EAR on five datasets with different target classifiers under four different attack methods and compare it with four other defense methods. We experimentally show that our new method performs the best among other defense methods.
Hongsheng Hu, Zoran A. Salcic, Gillian Dobbie, Yi Chen 0008, Xuyun Zhang
IJCNN4
2021 Exploiting texture characteristics and spatial correlations for robustness metric of data hiding with noisy transmission
abstract
Abstract Data hiding aims to embed a secret message into a digital object such as image by slightly modifying the object content without arousing noticeable artefacts. The resultant object containing hidden information will be sent to a desired receiver via some insecure channels, e.g. images transmitted through noisy channel, social networks are vulnerable to unknown pollution or compression by a third party, which may lead the transmitted objects to be attacked such that the reconstructed message has a significant error rate. It therefore requires us to use robust embedding strategies for data hiding to realise reliable message retrieval. To this end, in this paper, a metric model to estimate the robustness of data hiding for noisy transmission based on the statistical characteristics of cover and embedding operation is presented, the former is mainly reflected by spatial frequency and texture feature, and the latter embedding operation is mainly reflected by embedding modification. The goal is to ensure that both statistical characteristics and embedding operation can be used to maximise the embedding robustness. To the best knowledge, it is the first time to estimate robustness before data hiding by a special metric model. Experimental results show that, by combining the proposed metric model in three classical data hiding methods, i.e. BPS, DE and QIM, the robustness can be significantly improved, which demonstrates its superiority and applicability.
Yanli Chen 0001, Hongxia Wang 0001, Hanzhou Wu, Yonghui Zhou, Limengnan Zhou, Yi Chen 0008
IET Image Process.6
2021 A blockchain-based computation offloading method for edge computing in 5G networks
abstract
Summary Edge computing (EC) emerges as a novel computing paradigm to offload computing tasks from user equipments (UEs) to edge notes (ENs) in fifth‐generation networks, which definitely breaks the resource limitation of UEs to a certain degree. However, it is troublesome to guarantee the overall operating performance of ENs due to the uneven distributed resource demands of UEs, the resulting transmission delay and the data loss for computation offloading between the covered EN and the deployed destination EN. In view of this challenge, a blockchain‐based computation offloading method, named BCO, is proposed in this paper. Technically, since blockchain is a promising technique for the decentralized system, a blockchain‐based EC framework is designed to degrade the data loss possibility by integrating blockchain and EC. Then, the nondominated sorting genetic algorithm, the third version (NSGA‐III), is leveraged to acquire the balanced offloading strategies. Furthermore, by taking advantage of Simple Additive Weighting and Multiple Criteria Decision Making, the optimal offloading strategy is identified. Finally, systematic experiments and analyses on the comparative experiment are conducted to verify the efficiency of our proposed method BCO.
Xiaolong Xu 0001, Yi Chen 0008, Xuyun Zhang, Qingxiang Liu 0004, Xihua Liu, Lianyong Qi
Softw. Pract. Exp.2
2020 A passive forensic scheme for copy-move forgery based on superpixel segmentation and K-means clustering
Hongxia Wang 0001, Yi Chen 0008, Hanzhou Wu, Huan Wang 0010
Multim. Tools Appl.3
2020 Reversible data hiding based on a modified difference expansion for H.264/AVC video streams
Xiaoxu Tang, Hongxia Wang 0001, Yi Chen 0008
Multim. Tools Appl.3
2020 Blockchain-based cloudlet management for multimedia workflow in mobile cloud computing
Xiaolong Xu 0001, Yi Chen 0008, Yuan Yuan 0004, Xuyun Zhang, Lianyong Qi
Multim. Tools Appl.2
2020 A QoS-aware virtual machine scheduling method for energy conservation in cloud-based cyber-physical systems
Lianyong Qi, Yi Chen 0008, Yuan Yuan 0004, Shucun Fu, Xuyun Zhang, Xiaolong Xu 0001
World Wide Web2
2019 GRU-SVM Model for Synthetic Speech Detection
Hongxia Wang 0001, Yi Chen 0008, Peisong He
IWDW3
2019 A Novel Lossless Data Hiding Scheme in Homomorphically Encrypted Images
Asad Malik 0002, Hongxia Wang 0001, Ahmad Neyaz Khan, Yanli Chen 0001, Yi Chen 0008
IWDW5
2019 Reversible video data hiding using zero QDCT coefficient-pairs
Yi Chen 0008, Hongxia Wang 0001, Hanzhou Wu
Multim. Tools Appl.1
2018 An adaptive data hiding algorithm with low bitrate growth for H.264/AVC video stream
Yi Chen 0008, Hongxia Wang 0001, Hanzhou Wu
Multim. Tools Appl.1
2018 An efficient fingerprint identification algorithm based on minutiae and invariant moment
Jing Sang, Hongxia Wang 0001, Qing Qian 0001, Hanzhou Wu, Yi Chen 0008
Pers. Ubiquitous Comput.5