EDBT 2026 Demo / reviewers in the wild / expert
Chang Liu 0049
dblp:52/5716-49
· DBLP profile ↗
44ranked-venue papers
7as first author
33since 2021 · last 2026
0000-0002-4798-0443ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 4 first-author · 12 since 2021Security and privacy · 10 · 9 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ATOPOS: Dynamic Path Exploration with Adaptive Probe Construction for Extensive and Efficient Network Topology Discovery
Yaochen Ren, Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011, Tianyu Cui, Junzheng Shi |
INFOCOM | 2 |
| 2026 | TrafficCL: Contrastive learning on network traffic for accurate, efficient and robust IP cross-regional detection
Mingxin Cui, Gaopeng Gou, Chang Liu 0049, Yong Wang 0046, Guoming Ren, Gang Xiong 0001 |
Comput. Networks | 4 |
| 2026 | BAPTISM: A Robust Framework for Encrypted Malicious Traffic Identification With Low-Quality Training DataabstractMachine learning (ML) is highly effective for accurate encrypted malicious traffic identification by using highquality training data. In fact, obtaining such data is costly and challenging. As a result, many ML-based models are inevitably trained on low-quality data and perform poorly. To enhance performance, some methods utilize various sample selection techniques to choose confident samples for model training. However, they often rely on a single metric for this selection, which restricts their adaptability across diverse datasets and noise conditions. In this paper, we propose a robust framework BAPTISM for identifying encrypted malicious traffic with low-quality training data. Particularly, BAPTISM selects a suitable base model for each task, and trains it with early stopping to generate traffic representation before overfitting occurs. Then, we devise an adaptive metric selection strategy to select confident samples. By employing two metrics (JSD and CSD) to assess the characteristic of traffic representation from distinct perspective, we find the more proper metric for each class and apply it for confident sample selection. According to the confident samples and selected metric for each class, we develop a label correction tactic which adapts to class nature to improve the quality of training data. Finally, we employ parallel training strategy to train the base model with the corrected data, further mitigating the impact of low-quality data. We conduct experiments across three real-world malicious traffic datasets with various noise settings. The results demonstrate that BAPTISM is compatible with different base models and outperforms across noise ratios ranging from 20% to 90%. Meanwhile, BAPTISM consistently selects the confident samples with the highest purity and volume under each setting. Chang Liu 0049, Gang Xiong 0001, Gaopeng Gou, Zhen Li 0011, Junzheng Shi, Li Guo 0001, Binxing Fang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | IPv6 Prefix Target Generation through Pattern and Distribution Learning using Vision-Transformer and Guided-Diffusion
Yaochen Ren, Gaopeng Gou, Chengshang Hou, Tianyu Cui, Zhen Li 0011, Gang Xiong 0001, Chang Liu 0049 |
INFOCOM | 7 |
| 2025 | 6RIS: IPv6 Address Correlation Attacks on TLS Encrypted Traffic Using Joint Representation of Interaction and Sequential BehaviorabstractIPv6 address correlation attacks determine whether two temporary addresses belong to the same user, compromising user privacy. Particularly, existing works have shown that methods based on TLS traffic analysis can be used to perform correlation attacks. However, they suffer from inaccurate differentiation of complex user behaviors and low correlation efficiency, leading to limitations in practical applications. In this paper, we propose a 6RIS model to improve IPv6 address correlation attacks on TLS-encrypted traffic. 6RIS learns the joint representation of interaction and sequential behavior from traffic, which is used to construct a KD-Tree for efficient correlation. Statistical aggregation and semantic preference modules are designed to extract generalized features from complex interaction behavior. To model sequential behavior, we utilize a sequence learning module to capture service dependencies, enhancing behavior representation. Experiments on a real-world IPv6 dataset show that 6RIS ($\mathbf{9 1. 8 6 \%}$TPR,$\mathbf{0. 8 3 \%}$FPR) outperforms state-of-theart methods. The correlation efficiency of 6RIS improves by at least 57 % compared to existing methods. Additionally, we further confirm through 6RIS that persistent session IDs in TLS session resumption can directly expose IPv6 temporary addresses to correlation attacks. Yang Li 0002, Chang Liu 0049, Gaopeng Gou, Tianyu Cui, Gang Xiong 0001, Zhen Li 0011, Li Guo 0001 |
IWQoS | 2 |
| 2025 | ET-FS: Functional Specialization Method for Multi-Task Learning in Encrypted Traffic ClassificationabstractPre-trained Transformer models have demonstrated remarkable ability in learning generalizable feature representations for encrypted traffic analysis, driving the development of effective methods in this field. Their separate hidden and output layer architecture supports efficient multi-task joint classification. However, in real-world multi-task scenarios, these models face challenges due to high computational overhead and performance degradation on individual tasks during joint training. To address these, we introduce ET-FS (Encrypted Traffic Classification via Functional Specialization), a novel three-stage framework for efficient multi-task training in encrypted traffic classification. In the first stage, ET-FS constructs a multi-task joint model based on pre-trained encrypted traffic models and task groups, followed by joint fine-tuning using single-task labeled datasets. In the second stage, we propose an innovative method to assess the nature of tasks within the model and groups, allowing identification of optimal parameters. In the third stage, we leverage the functional specialization of multi-head attention in Transformer architectures, introducing a partially frozen multi-task fine-tuning strategy. Specifically, during the final phase of training, only a selected proportion of task-related attention heads are updated, while irrelevant heads are frozen, mitigating gradient interference between tasks. Experimental results show that the ET-FS Final Model, trained with the proposed framework, is applicable across diverse scenarios. With sufficient resources, it surpasses baselines on all tasks and metrics, achieving 93% accuracy for app classification, 98% for service classification, and over 99% for other tasks. Even with limited resources and imbalanced datasets, it maintains robust performance and good generalization, highlighting its practical potential for encrypted traffic classification. Xinzhu Feng, Gaopeng Gou, Chang Liu 0049, Wenqi Dong, Famei He, Xuren Wang |
TrustCom | 3 |
| 2025 | DecETT: Accurate App Fingerprinting Under Encrypted Tunnels via Dual Decouple-based Semantic EnhancementabstractDue to the growing demand for privacy protection, encrypted tunnels have become increasingly popular among mobile app users, which brings new challenges to app fingerprinting (AF)-based network management. Existing methods primarily transfer traditional AF methods to encrypted tunnels directly, ignoring the core obfuscation and re-encapsulation mechanism of encrypted tunnels, thus resulting in unsatisfactory performance. In this paper, we propose DecETT, a dual decouple-based semantic enhancement method for accurate AF under encrypted tunnels. Specifically, DecETT improves AF under encrypted tunnels from two perspectives: app-specific feature enhancement and irrelevant tunnel feature decoupling. Considering the obfuscated app-specific information in encrypted tunnel traffic, DecETT introduces TLS traffic with stronger app-specific information as a semantic anchor to guide and enhance the fingerprint generation for tunnel traffic. Furthermore, to address the app-irrelevant tunnel feature introduced by the re-encapsulation mechanism, DecETT is designed with a dual decouple-based fingerprint enhancement module, which decouples the tunnel feature and app semantic feature from tunnel traffic separately, thereby minimizing the impact of tunnel features on accurate app fingerprint extraction. Evaluation under five prevalent encrypted tunnels indicates that DecETT outperforms state-of-the-art methods in accurate AF under encrypted tunnels, and further demonstrates its superiority under tunnels with more complicated obfuscation. Project page: https://github.com/DecETT/DecETT Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
WWW | 2 |
| 2024 | WebPromptM2: A Website Classification Method Leveraging Prompt-Based Learning with Multimodal FeaturesabstractWebsite classification proves crucial for tasks like malicious website detection and information management. Current methods typically focus on effective feature extraction and algorithm selection to create balanced website datasets, often leading to decreased performance due to data imbalance. In this study, we propose an intelligent website classification method(WebPromptM2) based on prompt-based learning with multimodal features. We design a prompt template which incorporates the textual and visual elements of the website, thereby facilitating a multimodal representation of the website, then leverage domain-specific expertise to establish mapping relationships between website categories and a label word set. Finally, we fine-tune the masked pre-trained language model (PLM) and map the prediction results to the categories. We find that our method increases recognition accuracy of tail classes and achieves superior performance on long-tail and short-tail datasets. Mengyan Liu, Gaopeng Gou, Gang Xiong 0001, Junzheng Shi, Chang Liu 0049 |
CSCWD | 5 |
| 2024 | Optimizing evasive maneuvering of planes using a flight quality driven model
Chang Liu 0049, Shaoshan Sun, Chenggang Tao, Yingxin Shou, Bin Xu 0003 |
Sci. China Inf. Sci. | 1 |
| 2024 | Identifying malicious traffic under concept drift based on intraclass consistency enhanced variational autoencoder
Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011, Binxing Fang |
Sci. China Inf. Sci. | 2 |
| 2024 | Let gambling hide nowhere: Detecting illegal mobile gambling apps via heterogeneous graph-based encrypted traffic analysis
Gaopeng Gou, Chang Liu 0049, Zhen Li 0011, Gang Xiong 0001 |
Comput. Networks | 3 |
| 2024 | A blind flow fingerprinting and correlation method against disturbed anonymous traffic based on pattern reconstruction
Chang Liu 0049, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Yangyang Ding, Chengshang Hou |
Comput. Networks | 2 |
| 2023 | TGC: Transaction Graph Contrast Network for Ethereum Phishing Scam DetectionabstractPhishing scams have become the most serious type of crime involved in Ethereum. However, existing methods ignore the natural camouflage and sparse distribution of phishing scams in Ethereum leading to unsatisfactory performance, and they are also limited by the data scale which cannot be applied to real-world dynamic scenarios. In this paper, we propose a Transaction Graph Contrast network (TGC) to enhance phishing scam detection performance on Ethereum. TGC inputs subgraphs instead of the entire graph for training, which eases the model’s requirements for machine configuration and data connectivity. Motivated by phishing nodes are surrounded by normal nodes, we design the comparison between node-level to help phishing nodes learn the unique properties of themselves different from their neighbors. Observing the small number and sparse distribution of phishing nodes, we narrow the distance between phishing nodes by comparing node context-level structures, so as to learn universal transaction patterns. We further combine the obtained features with common statistics to identify phishing addresses. Evaluated on real-world Ethereum phishing scams datasets, our TGC outperforms the state-of-the-art methods in detecting phishing addresses and has obvious advantages in large-scale and dynamic scenarios. Gaopeng Gou, Chang Liu 0049, Gang Xiong 0001, Zhen Li 0011, Junchao Xiao, Xinyu Xing 0001 |
ACSAC | 3 |
| 2023 | PTC: Prompt-based Continual Encrypted Traffic ClassificationabstractEncrypted traffic classification (ETC) is necessary for network security, which is the process of identifying encrypted network traffic into a specific class, thus there are numerous applications in the security of network. The rapid development of network web services (applications) makes it attractive to tackle classification of encrypted traffic in a continual learning environment. However, the traffic ambiguity and privacy leakage, restrict existing incremental approaches from achieving satisfactory results in the traffic. We introduce a prompt-based continual encrypted traffic classification method (PTC) in this research to progressively learn tasks under multiple process transitions. Prompts are tiny, learnable parameters that are stored in ram according to our suggested structure. The objective is to find the best way to use prompts to help models make predictions, keep both task-peculiar and task-constant knowledge in model, and prevent catastrophic forgetting. We carry out extensive tests using both real-world and open datasets. PTC method can strengthen the existing offline traffic classification works, make them adapt to online scenarios, and outperforms the SOTA online traffic classification method in three datasets. (by 4.54 %, 7.28 % and 11.68 % on three datasets, respectively) Wei Cai 0007, Chengshang Hou, Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
CSCWD | 3 |
| 2023 | A Recurrent Self-learning Labeler for Building Network Traffic Ground TruthabstractWith the increasing number of traffic category, machine learning-based methods have gradually become the mainstream way of traffic classification to support network security and management. Machine learning-based methods require a large amount of high quality labelled data to learn network behavior patterns to achieve better recognition results. In the field of network traffic labeling, manual labeling can achieve more accurate labeling results, but the labeling efficiency is low and the labor cost is high. Deep packet inspection (DPI) technology can greatly improve labeling efficiency and reduce labor costs, but DPI labeling suffers from the problem of inaccurate and incomplete labeling. In this paper, we propose a recurrent self-learning framework (RSL-Labeler) for traffic labeling, which can solve the problem of inaccurate and incomplete DPI labeling. This framework consists of three components: high-quality data generation, class behavior pattern learning, and confidence filtering. Based on high-quality data labeled by multiple DPIs, we build three classifiers to learn the behavior patterns of DPI labeling intelligently from three perspectives. Then, we propose the idea of confidence filtering, which combines the pseudo-labeled data and the confidence values of three learning models to filter the credible samples by combined voting. These samples are added to the self-learning model for recurrent training. Experiments show that our method is able to label application traffic with accuracy of 99%, which is at least 8% better than single DPI. Qingya Yang, Chang Liu 0049, Peipei Fu, Bingxu Wang, Gaopeng Gou, Gang Xiong 0001 |
CSCWD | 2 |
| 2023 | FedMP: Robust and Communication-Efficient Federated Multi-Prototype Intrusion Detection Framework in IoTabstractDue to its excellent performance in privacy protection, federated learning (FL) technology is gradually introduced into the IoT environment to build a distributed intrusion detection framework. However, the previous frameworks have two limitations: 1) high communication overhead caused by the frequent exchange of model parameters is not friendly for resource-constrained IoT devices; 2) single global model hardly handles not independent and identically distributed (Non-IID) intrusion data on different IoT clients. In this paper, we propose a Federated Multi-Prototype intrusion detection framework (FedMP) to address the above limitations. Specifically, FedMP includes a k-means clustering module that extracts low-dimensional local prototypes for IoT clients and a novel aggregation algorithm that fairly aggregates all local prototypes on the central server to generate global prototypes. By exchanging prototypes instead of model parameters between IoT clients and the central server, FedMP aims to train a unique personalized model for each IoT client to adapt to its local intrusion detection tasks. Experimental results on real-world intrusion detection datasets show that FedMP achieves the best detection performance in Non-IID scenarios while significantly reducing communication overhead compared to other state-of-the-art methods. Minsheng Le, Zhen Li 0011, Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001 |
ICPADS | 3 |
| 2023 | Zero-relabelling mobile-app identification over drifted encrypted network traffic
Mingxin Cui, Chang Liu 0049, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
Comput. Networks | 3 |
| 2023 | Few-shot encrypted traffic classification via multi-task representation enhanced meta-learning
Gang Xiong 0001, Junzheng Shi, Gaopeng Gou, Zhen Li 0011, Chang Liu 0049 |
Comput. Networks | 7 |
| 2023 | FlowTracker: Improved flow correlation attacks with denoising and contrastive learning
Chang Liu 0049, Gang Xiong 0001, Zhen Li 0011, Gaopeng Gou |
Comput. Secur. | 2 |
| 2023 | BoAu: Malicious traffic detection with noise labels based on boundary augmentation
Qingjun Yuan, Chang Liu 0049, Yuefei Zhu, Gang Xiong 0001, Yongjuan Wang, Gaopeng Gou |
Comput. Secur. | 2 |
| 2022 | GALG: Linking Addresses in Tracking Ecosystem Using Graph Autoencoder with Link Generation
Tianyu Cui, Gang Xiong 0001, Chang Liu 0049, Junzheng Shi, Peipei Fu, Gaopeng Gou |
ECML/PKDD (6) | 3 |
| 2022 | BSBA: Burst Series Based Approach for Identifying Fake Free-trafficabstractIn recent years, mobile traffic has gradually become a major part of network traffic. To attract customers, mobile network operators provide free-traffic, which is a preferential policy that is free of charge for specific application traffic. Since the emergence of free-traffic, fake free-traffic also appeared soon. Fake free-traffic is a malicious behavior, which helps attackers illegally use network resources and evade network resource charging. The appearance of fake free-traffic maliciously harms the interests of operators and disrupts the rules of network resource charging. Because of the uniqueness of free-traffic, it encapsulates a layer of the HTTP protocol in addition to the actual application communication protocol, existing studies on encrypted traffic analysis are not applicable to identify fake free-traffic. In this paper, we propose Burst Series Based Approach (BSBA), a novel method for identifying fake free-traffic. The key idea behind BSBA is to construct effective features by capturing the differences of burst series among fake free-traffic, free-traffic and non-free traffic, and combine the constructed features with machine learning algorithms to identify fake free-traffic. We collect a real-world traffic dataset and conduct evaluations to verify the effectiveness of the BSBA. Experiment results demonstrate that the BSBA achieves excellent performances (96.82% Accuracy, 96.46% Precision, 96.57% Recall and 96.51% F1-score) and is superior to the state-of-the-art methods. Chang Liu 0049, Zhen Li 0011, Qingya Yang, Anlin Xu, Gaopeng Gou |
WoWMoM | 2 |
| 2022 | TTAGN: Temporal Transaction Aggregation Graph Network for Ethereum Phishing Scams DetectionabstractIn recent years, phishing scams have become the most serious type of crime involved in Ethereum, the second-largest blockchain platform. The existing phishing scams detection technology on Ethereum mostly uses traditional machine learning or network representation learning to mine the key information from the transaction network to identify phishing addresses. However, these methods adopt the last transaction record or even completely ignore these records, and only manual-designed features are taken for the node representation. In this paper, we propose a Temporal Transaction Aggregation Graph Network (TTAGN) to enhance phishing scams detection performance on Ethereum. Specifically, in the temporal edges representation module, we model the temporal relationship of historical transaction records between nodes to construct the edge representation of the Ethereum transaction network. Moreover, the edge representations around the node are aggregated to fuse topological interactive relationships into its representation, also named as trading features, in the edge2node module. We further combine trading features with common statistical and structural features obtained by graph neural networks to identify phishing addresses. Evaluated on real-world Ethereum phishing scams datasets, our TTAGN (92.8% AUC, and 81.6% F1-score) outperforms the state-of-the-art methods, and the effectiveness of temporal edges representation and edge2node module is also demonstrated. Gaopeng Gou, Chang Liu 0049, Chengshang Hou, Gang Xiong 0001 |
WWW | 3 |
| 2021 | BAPM: Block Attention Profiling Model for Multi-tab Website Fingerprinting Attacks on TorabstractWebsite fingerprinting attacks on Tor pose an security issue in anonymity privacy, in which attackers can identify websites visited by victims through passively capturing and analyzing encrypted packet traces. Although related works have been studied over a long period, most of them focus on single-tab packet traces which only contain one page tab’s data. However, users often open multiple page tabs successively when browsing the web, and multi-tab packet traces generated will corrupt common single-tab attacks. Existing multi-tab attacks still depend on an elaborate feature engineering, besides, they fail to exploit the overlapping area which contains the mixed data of two adjacent page tabs, thus suffering from the information lost or confusion. In this paper, we propose a Block Attention Profiling Model named BAPM as a new multi-tab attacking model. Specifically, BAPM fully utilizes the whole multi-tab packet trace including the overlapping area to avoid information lost. It generates a tab-aware representation from direction sequences and performs the block division to separate mixed page tabs as clearly as possible, thus relieving the information confusion. Then the attention-based profiling is used to group blocks belonging to the same page tab and finally multiple websites are simultaneously identified under a global view. We compare BAPM with state of the art multi-tab attacks, and BAPM outperforms comparison methods even with larger overlapping area. The effectiveness of model design is also validated through ablation, sensitivity and generalization analysis. Gang Xiong 0001, Gaopeng Gou, Zhen Li 0011, Mingxin Cui, Chang Liu 0049 |
ACSAC | 6 |
| 2021 | GAP-WF: Graph Attention Pooling Network for Fine-grained SSL/TLS Website FingerprintingabstractAs an important part of network management, website fingerprinting has become one of the hottest topics in the field of encrypted traffic classification. Website fingerprinting aims to identify the specific webpages in encrypted traffic by observing patterns of traffic traces. Prior studies proposed several machine-learning-based methods using statistical features and deep-learning-based methods using packet length sequences. However, these works mainly focus on the website homepage fingerprinting. In fact, people are usually not limited to visiting the homepage. Compared with the homepage classification of websites, it is more difficult to identify different webpages within the same website due to the traffic traces are very similar. In this paper, we propose the Graph Attention Pooling Network for fine-grained website fingerprinting (GAP-WF). We introduce the trace graph to describe the contextual relationship between flows in webpage loading. Then we utilize the Graph Neural Networks to learn the intra-flow and inter-flow features. Considering different flows may have different importance, we utilize the graph attention mechanism to pay attention to key nodes. We collect four datasets covering three different granularity scenarios to evaluate our proposed method. Experimental results demonstrate that GAP-WF not only achieves the best performance of 99.86% in website homepage fingerprinting, but also outperforms other state-of-art methods in all fine-grained webpage fingerprinting scenarios. Moreover, GAP-WF can achieve better performance with fewer training samples. Gaopeng Gou, Majing Su, Dong Song, Chang Liu 0049, Yangyang Guan |
IJCNN | 5 |
| 2021 | 6GAN: IPv6 Multi-Pattern Target Generation via Generative Adversarial Nets with Reinforcement LearningabstractGlobal IPv6 scanning has always been a challenge for researchers because of the limited network speed and computational power. Target generation algorithms are recently proposed to overcome the problem for Internet assessments by predicting a candidate set to scan. However, IPv6 custom address configuration emerges diverse addressing patterns discouraging algorithmic inference. Widespread IPv6 alias could also mislead the algorithm to discover aliased regions rather than valid host targets. In this paper, we introduce 6GAN, a novel architecture built with Generative Adversarial Net (GAN) and reinforcement learning for multi-pattern target generation. 6GAN forces multiple generators to train with a multi-class discriminator and an alias detector to generate non-aliased active targets with different addressing pattern types. The rewards from the discriminator and the alias detector help supervise the address sequence decision-making process. After adversarial training, 6GAN's generators could keep a strong imitating ability for each pattern and 6GAN's discriminator obtains outstanding pattern discrimination ability with a 0.966 accuracy. Experiments indicate that our work outperformed the state-of-the-art target generation algorithms by reaching a higher-quality candidate set. Tianyu Cui, Gaopeng Gou, Gang Xiong 0001, Chang Liu 0049, Peipei Fu, Zhen Li 0011 |
INFOCOM | 4 |
| 2021 | Universal Perturbation for Flow Correlation Attack on TorabstractTor is a popular anonymous social network. However, it is also concerned by censors or other malicious attackers. A large body of work examines Tor’s susceptibility to flow correlation attacks. Moreover, the existing methods to defend against such attacks have two inherent drawbacks. One is they will bring high delay to the system, the other is they lack of theoretical basis to prove their effectiveness.This paper conducts the first experimental study of how to effectively defeat flow correlation attacks on Tor. We propose a new universal perturbation generation algorithm, a defense to achieve the goal of flawing flow correlation attacks by apply tiny perturbations to the traffic. Our approach uses adversarial sample technique to incorporate Tor traffic constraints and avoid the two drawbacks mentioned above. We evaluate it over five typical flow correlation attacks. Our results show the effectiveness and high transferability of the generated perturbations. For instance, by applying a perturbation with a tiny variance of only 10ms, the TP of original flow correlation attack is reduced from 82% to 60% and the surrogate attack decreases from 71% to 52%. Gaopeng Gou, Yangyang Guan, Gang Xiong 0001, Chang Liu 0049 |
IPCCC | 6 |
| 2021 | RecGraph: Graph Recovery Attack using Variational Graph AutoencodersabstractGraph-structured data contains a lot of sensitive information about individuals. In order to protect users’ privacy, many anonymization mechanisms for graph-structured data are proposed. However, one common drawback of these mechanisms is that they only consider to hide the local characteristics, such as the degree of nodes or their neighbors. They lack the consideration for the nodes’ attribute features and the features of potential global graph structure, which leads to the failure of these mechanisms to provide sufficient security.To address this shortcoming, we propose RecGraph, a framework for graph recovery attack based on variational graph autoencoders. We use RecGraph to perform graph recovery attack on three real social network datasets, and compare it with five existing baselines, to prove the effectiveness of our method. We also evaluate the privacy wastage after performing the graph recovery attack using RecGraph to demonstrate the serious security risks faced by the existing graph anonymization mechanisms. Chang Liu 0049, Gaopeng Gou, Zhen Li 0011, Gang Xiong 0001, Yangyang Guan |
IPCCC | 2 |
| 2021 | CQNet: A Clustering-Based Quadruplet Network for Decentralized Application Classification via Encrypted Traffic
Yu Wang 0134, Gang Xiong 0001, Chang Liu 0049, Zhen Li 0011, Mingxin Cui, Gaopeng Gou |
ECML/PKDD (4) | 3 |
| 2021 | TMT-RF: Tunnel Mixed Traffic Classification Based on Random Forest
Panpan Zhao, Gaopeng Gou, Chang Liu 0049, Yangyang Guan, Mingxin Cui, Gang Xiong 0001 |
SecureComm (1) | 3 |
| 2021 | SiamHAN: IPv6 Address Correlation Attacks on TLS Encrypted Traffic via Siamese Heterogeneous Graph Attention Network
Tianyu Cui, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011, Mingxin Cui, Chang Liu 0049 |
USENIX Security Symposium | 6 |
| 2021 | Survey of security supervision on blockchain from the perspective of technology
Yu Wang 0134, Gaopeng Gou, Chang Liu 0049, Mingxin Cui, Zhen Li 0011, Gang Xiong 0001 |
J. Inf. Secur. Appl. | 3 |
| 2021 | Classifying encrypted traffic using adaptive fingerprints with multi-level attributes
Chang Liu 0049, Gang Xiong 0001, Gaopeng Gou, Siu-Ming Yiu, Zhen Li 0011, Zhihong Tian 0001 |
World Wide Web | 1 |
| 2020 | Not Afraid of the Unseen: a Siamese Network based Scheme for Unknown Traffic DiscoveryabstractAs an essential task for network management and security, network traffic classification has attracted increasing attention in recent years. Traditional traffic classification methods achieve certain success in identifying specific application traffic but fail with un-predefined unknown classes. Existing unknown traffic discovery methods commonly pick out some unlabeled testing data as part of training data to train the classification models, which is not in line with the real-world open environments. In this paper, we propose a novel scheme named SEEN to achieve unknown traffic detection in network traffic classification. There are three crucial phases in the SEEN: unknown discovery, unknown clustering, and system update. In the first step, using a metric-based approach with siamese network, SEEN identifies unknown traffic as well as accurately classifies the traffic generated by pre-defined application classes. After discovery, unknown traffic is automatically clustered into more fine-grained categories in the unknown clustering step. In the system update step, inspired by low-shot learning, SEEN allows new classes to be added or unnecessary known classes to be deleted quickly without retraining from the sketch, which can complement the system’s knowledge. Experimental results exhibit that SEEN can achieve outstanding performances both on known and unknown traffic identification on two open real-world datasets, and the proposed scheme can address the problem of unknown traffic effectively. Zhen Li 0011, Junzheng Shi, Gaopeng Gou, Chang Liu 0049, Gang Xiong 0001 |
ISCC | 5 |
| 2020 | NSA-Net: A NetFlow Sequence Attention Network for Virtual Private Network Traffic Detection
Peipei Fu, Chang Liu 0049, Qingya Yang, Gaopeng Gou, Gang Xiong 0001, Zhen Li 0011 |
WISE (1) | 2 |
| 2019 | A Multi-View Deep Learning Model for Encrypted Website Service ClassificationabstractThis paper presents a multi-view deep learning model for encrypted traffic classification which uses different neural network structures to process different types of features. Compared to previous work, our multi-view deep learning model can make full use of different types of features extracted from the flow. We evaluate our deep learning model in the real- world datasets acquired from the website servers of a large internet corporation. We found that the proposed multi-view deep learning model gets better performance than the state-of-the-art. Moreover, this paper focuses on a new traffic classification scenario in which the traffic under the specific website is classified on the basis of different website services. Each website service represents a specific website function which can be composed of several webpages. Therefore, the granularity of website service classification is between website classification and webpage classification. Kaiqi Liang, Gaopeng Gou, Cuicui Kang, Chang Liu 0049 |
GLOBECOM | 4 |
| 2019 | DLchain: A Covert Channel over Blockchain Based on Dynamic Labels
Gaopeng Gou, Chang Liu 0049, Gang Xiong 0001, Zhen Li 0011 |
ICICS | 3 |
| 2019 | Vision Information and Laser Module Based UAV Target TrackingabstractThis paper investigates the target tracking mission of an Unmanned Aerial Vehicle (UAV) equipped with a camera and a laser module. Firstly, utilizing Deep Neural Network (DNN) and Kernelized Correlation Filters (KCF), target recognition and location in the pixel coordinate system is achieved based on vision. Furthermore, by combining the laser ranging information and the distance estimation algorithm based on image, the distance between the UAV and the target is well estimated. To ensure the target tracking, a PID controller based on the distance error is applied to the UAV. The effectiveness of the system is verified on an actual UAV target tracking scenario. Chang Liu 0049, Yansui Song, Yuyan Guo, Bin Xu 0003, Yu Zhang 0018, Zhen Li 0011 |
IECON | 1 |
| 2019 | FS-Net: A Flow Sequence Network For Encrypted Traffic ClassificationabstractWith more attention paid to user privacy and communication security, the volume of encrypted traffic rises sharply, which brings a huge challenge to traditional rule-based traffic classification methods. Combining machine learning algorithms and manual-design features has become the mainstream methods to solve this problem. However, these features depend on professional experience heavily, which needs lots of human effort. And these methods divide the encrypted traffic classification problem into piece-wise sub-problems, which could not guarantee the optimal solution. In this paper, we apply the recurrent neural network to the encrypted traffic classification problem and propose the Flow Sequence Network (FS-Net). The FS-Net is an end-to-end classification model that learns representative features from the raw flows, and then classifies them in a unified framework. Moreover, we adopt a multi-layer encoder-decoder structure which can mine the potential sequential characteristics of flows deeply, and import the reconstruction mechanism which can enhance the effectiveness of features. Our comprehensive experiments on the real-world dataset covering 18 applications indicate that FS-Net achieves an excellent performance (99.14% TPR, 0.05% FPR and 0.9906 FTF) and outperforms the state-of-the-art methods. Chang Liu 0049, Longtao He, Gang Xiong 0001, Zigang Cao, Zhen Li 0011 |
INFOCOM | 1 |
| 2019 | A Comprehensive Study of Accelerating IPv6 DeploymentabstractSince the lack of IPv6 network development, China is currently accelerating IPv6 deployment. In this scenario, traffic and network structure show a huge shift. However, due to the long-term prosperity, we are ignorant of the problems behind such outbreak of traffic and performance improvement events in accelerating deployment. IPv6 development in some regions will still face similar challenges in the future. To contribute to solving this problem, in this paper, we produce a new measurement framework and implement a 5-month passive measurement on the IPv6 network during the accelerating deployment in China. We combine 6 global-scale datasets to form the normal status of IPv6 network, which is against to the accelerating status formed by the passive traffic. Moreover, we compare with the traffic during World IPv6 Day 2011 and Launch 2012 to discuss the common nature of accelerating deployment. Finally, the results indicate that the IPv6 accelerating deployment is often accompanied by an unbalanced network status. It exposes unresolved security issues including the challenge of user privacy and inappropriate access methods. According to the investigation, we point the future IPv6 development after accelerating deployment. Tianyu Cui, Chang Liu 0049, Gaopeng Gou, Junzheng Shi, Gang Xiong 0001 |
IPCCC | 2 |
| 2019 | Malicious Domain Detection via Domain Relationship and Graph ModelsabstractMalicious domain is a vital component of various cyber attacks. Recent techniques detect malicious domains by building classifiers based on domain character features which may be easily evaded by attackers. In this paper, we propose a malicious domain detection approach based on domain relationship features, PDNS features, and domain character features. The key insight is that malicious domains deploy on IP that is loosely regulated and the domains on such IP have similar network characteristics including domain relationships, resolution characteristics, and network behaviors. We find that the relationship of malicious domains is different from that of benign domains. Take this into account, we build meaningful associations among domains and extract the domains relationship features by a modified graph embedding algorithm from Passive DNS data. Besides, we mine more features from PDNS which have not been mentioned in previous work. These PDNS features can enhance the effectiveness of the classifier. Finally, we combine domain character features, PDNS features and relationship features as the feature set. We evaluate the performance of our model on a real-world dataset from DNS servers. We achieve excellent performance by applying several classifiers based on domain character features, PDNS features and relationship features with an accuracy of 94.0%, a recall of 94.3% and a precision of 93.8% in the challenging scenario where domains deploy on the same IP and malicious domains share similar character features with benign domains. We also compare our method with two state-of-the-art detection approaches and find that our approach outperforms those SOTA approaches. Based on the comparison results, we point out that our way to construct a domain relationship graph can effectively mine the domain association features and the features combined with PDNS features and domain character features can effectively identify malicious domains which are similar to benign domains. Gaopeng Gou, Cuicui Kang, Chang Liu 0049, Zhen Li 0011, Gang Xiong 0001 |
IPCCC | 4 |
| 2018 | LaFFT: Length-Aware FFT Based Fingerprinting for Encrypted Network Traffic ClassificationabstractEncrypted traffic classficiation has become an emergent and challenging task for network monitoring and management. Traditional classification methods for encrypted traffic rely on complex statistical characteristic construction and in-depth packet resolution, which produce huge loads. In this paper, we develop Length-aware FFT (LaFFT) fingerprinting to identify different encrypted application traffic with packet length sequences. We apply FFT to packet length sequences to generate the frequency domain vectors as LaFFT features. We verify the distinguishability of LaFFT fingerprinting by data analysis. Furthermore, the linear inseparability and the front superiority of LaFFT fingerprinting are demonstrated by comprehensive experiments. In the real-world dataset, the LaFFT fingerprinting with random forest classifier can achieve 96.8% TPR, 0.32% FPR and 0.959 FFT, which significantly outperform the state-of-the-art methods. Chang Liu 0049, Zigang Cao, Zhen Li 0011, Gang Xiong 0001 |
ISCC | 1 |
| 2018 | MaMPF: Encrypted Traffic Classification Based on Multi-Attribute Markov Probability FingerprintsabstractWith the explosion of network applications, network anomaly detection and security management face a big challenge, of which the first and a fundamental step is traffic classification. However, for the sake of user privacy, encrypted communication protocols, e.g. the SSL/TLS protocol, are extensively used, which results in the ineffectiveness of traditional rule-based classification methods. Existing methods cannot have a satisfactory accuracy of encrypted traffic classification because of insufficient distinguishable characteristics. In this paper, we propose the Multi-attribute Markov Probability Fingerprints (MaMPF), for encrypted traffic classification. The key idea behind MaMPF is to consider multi-attributes, which includes a critical feature, namely “length block sequence” that captures the time-series packet lengths effectively using power-law distributions and relative occurrence probabilities of all considered applications. Based on the message type and length block sequences, Markov models are trained and the probabilities of all the applications are concatenated as the fingerprints for classification. MaMPF achieves 96.4% TPR and 0.2% FPR performance on a real-world dataset from campus network (including 950,000+ encrypted traffic flows and covering 18 applications), and outperforms the state-of-the-art methods. Chang Liu 0049, Zigang Cao, Gang Xiong 0001, Gaopeng Gou, Siu-Ming Yiu, Longtao He |
IWQoS | 1 |
| 2017 | Auto-identification of background traffic based on autonomous periodic interactionabstractBackground traffic of web applications refers to the traffic not generated directly due to user activities (e.g. user behavior profiling) that is usually useful to the application providers, but not the users. A recent study indicated that background traffic, contributing 51.8% bandwidth, has exceeded user-generated traffic. Accurate identification of background traffic can help network managers to optimize network resource allocation and avoid network congestion. However, identification of background traffic is not easy and the solution must be robust enough for all applications. In this paper, we propose the first method that can self-learn background traffic rules from unlabeled data and automatically identify online background traffic. The accuracy of the extracted rules is 90.51%. When applying our method in a real enterprise network, the false positive rate (FPR) is only 3% showing that our method is accurate and effective. Our method is derived from a critical observation that the background traffic exhibits a periodic behavior (referred as autonomous periodic interaction (AuPI)). Technically, we propose two indexes, Time Regularity Factor (TRF) and Time Interval Factor (TIF), to capture this AuPI pattern from unlabeled communication traffic. As a side contribution, we created a public benchmark dataset of 45 hot applications with 97,000+ background traffic flows that can be used by researchers to further investigate background traffic. Chang Liu 0049, Lingwu Zeng, Junzheng Shi, Gang Xiong 0001, Siu-Ming Yiu |
IPCCC | 1 |