Weiwei Liu 0002

dblp:54/6677-2 · DBLP profile ↗
← Back
21ranked-venue papers
5as first author
14since 2021 · last 2027
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 6 since 2021Computer networks · 6 · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2027 Cross-level graph learning on packet-cluster representations of encrypted traffic for network intrusion detection
Weiwei Liu 0002, Jianan Huang 0001, Fengyuan Nie 0001
Expert Syst. Appl.1
2026 Lightweight Graph Mining for Website Fingerprinting Guided by Structure Knowledge
Bo Gao 0005, Weiwei Liu 0002, Guangjie Liu 0001, Fengyuan Nie 0001, Jianan Huang 0001
IEEE Trans. Comput. Soc. Syst.2
2026 SSH-CAM: Fine-Grained SSH Behavior Identification in Encrypted Tunnel Traffic Using Curriculum-Adaptive Mixup
Guangjie Liu 0001, Jiangtao Zhai, Weiwei Liu 0002, Yuewei Dai
IEEE Trans. Netw. Serv. Manag.4
2025 IoT-AMLHP: Aligned multimodal learning of header-payload representations for resource-efficient malicious IoT traffic classification
Fengyuan Nie 0001, Guangjie Liu 0001, Weiwei Liu 0002, Jianan Huang 0001, Bo Gao 0005
Ad Hoc Networks3
2025 Empowering Anomaly Detection in IoT Traffic Through Multiview Subspace Learning
abstract
With the frequent occurrence of information security incidents within the Internet of Things (IoT) landscape, there has been an increasing emphasis on anomaly detection in IoT traffic. Recently, supervised machine learning techniques have shown significant potential on this topic. However, the intricate nature of IoT network environments has posed a challenge in acquiring sufficient labeled samples of abnormal traffic. In comparison to supervised learning, unsupervised learning has more lenient sample requirements. Researchers have proposed various unsupervised detection methods, yet limitations persist. First, unsupervised learning, lacking guidance from labeled information, necessitates a more diverse range of traffic perspectives for comprehensive information coverage. Second, despite efforts to extract multiview traffic features from various perspectives, existing methods struggle to integrate these features effectively, limiting interpretability and introducing redundancy and noise. Lastly, conventional unsupervised methods often rely heavily on manually crafted features, potentially leading to biased and limited representations. In this article, we propose an unsupervised IoT traffic anomaly detection method based on multiview subspace learning. Specifically, we first construct a multiview traffic representation, including a protocol field view and a payload semantic view. Subsequently, a multiview subspace learning algorithm is designed to project the different views of traffic onto a unified and low-rank subspace, optimized using the augmented lagrangian multiplier with alternating direction minimization (ALM-ADM) strategy. Finally, spectral clustering is employed to accomplish IoT traffic anomaly detection. We benchmark the proposed method on multiple IoT traffic datasets and diverse computational platforms. The experimental results demonstrate that the method outperforms other state-of-the-art approaches in terms of accuracy and computational efficiency.
Fengyuan Nie 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Jianan Huang 0001, Chau Yuen
IEEE Internet Things J.2
2025 Lightweight Identification of Malicious IoT Traffic via Cross-View Knowledge Distillation
abstract
Accurately identifying malicious traffic in heterogeneous IoT environments is critical for network security. Although deep learning-based methods can effectively extract multi-dimensional features and achieve high accuracy, deploying complex models on resource-constrained IoT devices remains challenging. To balance performance and efficiency, we propose IoT-CVKD, a novel malicious IoT traffic identification framework leveraging cross-view knowledge distillation. IoT-CVKD consists of a multi-view teacher model and a lightweight single-view student model. The teacher model characterizes heterogeneous traffic from different perspectives by capturing flow-level global and packet-level spatio-temporal local burst information, and efficiently fuses these features using a cross-attention mechanism. The student model, composed of lightweight and computationally efficient modules, takes only packet-level features as input. Multi-view knowledge from the teacher is then implicitly distilled into the student through cross-view knowledge distillation during training, thereby significantly enhancing the student’s classification capability. Extensive evaluations demonstrate that IoT-CVKD achieves superior classification performance compared to state-of-the-art methods while substantially reducing computational complexity, making it highly suitable for resource-constrained IoT deployments.
Fengyuan Nie 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Jianan Huang 0001, Chau Yuen
IEEE Internet Things J.2
2025 QuicCourier: Leveraging the Dynamics of QUIC- Based Website Browsing Behaviors Through Proxy for Covert Communication
abstract
Network covert channels transmit secret messages by manipulating network traffic, including packet headers, timing intervals, and communication patterns. The growth of network services has spurred interest in exploring these channels. Yet, the practical application of these channels faces challenges in transmission rate and reliability due to unpredictable network interference. QUIC-based websites offer promising opportunities for covert communication, given their inherent dynamic nature from web resource updates and network interferences. Repeated visits or refresh actions on the same website generate substantial statistical redundancy. Furthermore, widely used proxy tools introduce additional traffic morphology changes. This paper presentsQuicCourier, a covert channel leveraging web traffic's dynamic characteristics and proxy service encapsulation to hide messages in QUIC packets from the service node to the client. Guided by a generative model for web resource patterns,QuicCourierensures that covert traffic closely resembles legitimate traffic, employing three packet-wise meta operations. The altered QUIC flows are then encased in proxy protocols, complicating the detection of embedded information. The covert receiver is incorporated into the proxy client. The efficacy ofQuicCourieris evaluated using a dataset of over 30,000 web browsing traffic samples, demonstrating its exceptional undetectability against state-of-the-art traffic classification tools and a high covert transmission rate.
Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Multi-Level Resource-Coherented Graph Learning for Website Fingerprinting Attacks
abstract
Deep learning-based website fingerprinting (WF) attacks dominate website traffic classification. In the real world, the main challenges limiting their effectiveness are, on the one hand, the difficulty in countering the effect of content updates on the basis of accurate descriptions of page features in traffic representations. On the other hand, the model’s accuracy relies on training numerous samples, requiring constant manual labeling. The key to solving the problem is to find a website traffic representation that can stably and accurately display page features, as well as to perform self-supervised learning that is not reliant on manual labeling. This study introduces the multi-level resource-coherented graph convolutional neural network (MRCGCN), a self-supervised learning-based WF attack. It analyzes website traffic using resources as the basic unit, which are coarser than packets, ensuring the page’s unique resource layout while improving the robustness of the representations. Then, we utilized an echelon-ordered graph kernel function to extract the graph topology as the label for website traffic. Finally, a two-channel graph convolutional neural network is designed for constructing a self-supervised learning-based traffic classifier. We evaluated the WF attacks using real data in both closed- and open-world scenarios. The results demonstrate that the proposed WF attack has superior and more comprehensive performance compared to state-of-the-art methods.
Bo Gao 0005, Weiwei Liu 0002, Guangjie Liu 0001, Fengyuan Nie 0001, Jianan Huang 0001
IEEE Trans. Inf. Forensics Secur.2
2025 WF-A2D: Enhancing Privacy With Asymmetric Adversarial Defense Against Website Fingerprinting
abstract
Despite the end-to-end encryption capabilities provided by network protocols such as QUIC in HTTP/3 and the additional tunneling functions offered by proxy tools like virtual private networks (VPNs) and the onion router (Tor), website fingerprinting (WF) techniques can still identify specific network services by exploiting the spatio-temporal characteristics of network traffic. Therefore, defending against WF attacks is crucial for ensuring comprehensive privacy protection for network services. Existing WF defenses typically rely on proxy-based solutions that require coordinated packet manipulations between the client and the proxy node to counteract WF attacks. These symmetric architectures cannot protect network traffic between proxy nodes and web servers from WF attacks. Furthermore, the ability to counter more powerful traffic analysis tools remains a challenging issue. In this paper, we propose WF-A2D, an asymmetric adversarial defense method against website fingerprinting for HTTP/3. WF-A2D employs a two-stage cascading adversarial learning strategy, leveraging packet direction and length patterns to enhance defense performance. Position-based perturbation vectors representing packet operations are generated for packet-by-packet manipulations to achieve real-time WF defense. Experimental results on a real-world HTTP/3-QUIC website browsing traffic dataset demonstrate that WF-A2D can achieve a defense success rate of 97.10% on average against seven state-of-the-art traffic analysis tools, while incurring less than 2% bandwidth overhead. More importantly, WF-A2D can operate independently on the client side and ensure end-to-end protection to web servers.
Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001
IEEE Trans. Inf. Forensics Secur.2
2025 STAP: Leveraging State-Transition Adversarial Perturbations for Asymmetric Website Fingerprinting Defenses
abstract
Web services, as the most ubiquitous form of online services, have consistently attracted research attention due to privacy concerns. Although VPNs and anonymous communication methods can partially protect users’ online privacy, advancements in website fingerprinting (WF) attacks still exploit the spatio-temporal characteristics of Web resource transmission to identify Web services. The challenge lies in defending against WF attacks efficiently, with limited bandwidth costs. Server-side WF defenses, deployed on Web servers, can achieve end-to-end obfuscation across both clients and servers. However, existing defenses often consume significant bandwidth and require additional removal operations on the client side. Given the growing use of QUIC with HTTP/3 and the need for robust privacy protections, this paper introduces an asymmetric server-side WF defense scheme using State-Transition Adversarial Perturbations (STAP). STAP introduces the concept of latent resource-state transitions, which represent hidden patterns in resource transmission. Utilizing perturbation models containing these transitions, STAP subtly alters traffic through packet padding and insertion, with inherent transport layer encryption enhancing the concealment. STAP can operate independently, removing the necessity for user involvement. Experimental results demonstrate that STAP outperforms other schemes, achieving reductions in True Positive Rate (TPR) by up to 22% and reductions in bandwidth overhead by up to 30%.
Jianan Huang 0001, Weiwei Liu 0002, Guangjie Liu 0001, Bo Gao 0005, Fengyuan Nie 0001, Marco Mellia
IEEE Trans. Netw. Serv. Manag.2
2023 A deep learning-based framework to identify and characterise heterogeneous secure network traffic
abstract
Abstract The evergrowing diversity of encrypted and anonymous network traffic makes network management more formidable to manage the network traffic. An intelligent system is essential to analyse and identify network traffic accurately. Network management needs such techniques to improve the Quality of Service and ensure the flow of secure network traffic. However, due to the usage of non‐standard ports and encryption of data payloads, the classical port‐based and payload‐based classification techniques fail to classify the secured network traffic. To solve the above‐mentioned problems, this paper proposed an effective deep learning‐based framework employed with flow‐time‐based features to predict heterogeneous secure network traffic best. The state‐of‐the‐art machine learning strategies (C4.5, random forest, and K‐nearest neighbour) are investigated for comparison. The proposed 1D‐CNN model achieved higher accuracy in classifying the heterogeneous secure network traffic. In the next step, the proposed deep learning model characterises the major categories (virtual private network traffic, the onion router network traffic, and plain encrypted network traffic) into several application types. The experimental results show the effectiveness and feasibility of the proposed deep learning framework, which yields improved predictive power compared to the state‐of‐the‐art machine learning techniques employed for secure network traffic analysis.
Faiz Ul Islam, Guangjie Liu 0001, Weiwei Liu 0002, Qazi Mazhar ul Haq
IET Inf. Secur.3
2021 A correlation-based approach to detecting wireless physical covert channels
Shuhua Huang, Weiwei Liu 0002, Guangjie Liu 0001, Yuewei Dai, Huiwen Bai
Comput. Commun.2
2021 N-Gram, Semantic-Based Neural Network for Mobile Malware Network Traffic Detection
abstract
Mobile malware poses a great challenge to mobile devices and mobile communication. With the explosive growth of mobile networks, it is significant to detect mobile malware for mobile security. Since most mobile malware relies on the networks to coordinate operations, steal information, or launch attacks, evading network monitor is difficult for the mobile malware. In this paper, we present an N-gram, semantic-based neural modeling method to detect the network traffic generated by the mobile malware. In the proposed scheme, we segment the network traffic into flows and extract the application layer payload from each packet. Then, the generated flow payload data are converted into the text form as the input of the proposed model. Each flow text consists of several domains with 20 words. The proposed scheme models the domain representation using convolutional neural network with multiwidth kernels from each domain. Afterward, relationships of domains are adaptively encoded in flow representation using gated recurrent network and then the classification result is obtained from an attention layer. A series of experiments have been conducted to verify the effectiveness of our proposed scheme. In addition, to compare with the state-of-the-art methods, several comparative experiments also are conducted. The experiment results depict that our proposed scheme is better in terms of accuracy.
Huiwen Bai, Guangjie Liu 0001, Weiwei Liu 0002, Yingxue Quan, Shuhua Huang
Secur. Commun. Networks3
2021 Detecting Multielement Algorithmically Generated Domain Names Based on Adaptive Embedding Model
abstract
With the development of detection algorithms on malicious dynamic domain names, domain generation algorithms have developed to be more stealthy. The use of multiple elements for generating domains will lead to higher detection difficulty. To effectively improve the detection accuracy of algorithmically generated domain names based on multiple elements, a domain name syntax model is proposed, which analyzes the multiple elements in domain names and their syntactic relationship, and an adaptive embedding method is proposed to achieve effective element parsing of domain names. A parallel convolutional model based on the feature selection module combined with an improved dynamic loss function based on curriculum learning is proposed, which can achieve effective detection on multielement malicious domain names. A series of experiments are designed and the proposed model is compared with five previous algorithms. The experimental results denote that the detection accuracy of the proposed model for multiple-element malicious domain names is significantly higher than that of the comparison algorithms and also has good adaptability to other types of malicious domain names.
Luhui Yang, Guangjie Liu 0001, Weiwei Liu 0002, Huiwen Bai, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks3
2019 An end-to-end generative network for environmental sound-based covert communication
Yuewei Dai, Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai
Multim. Tools Appl.2
2018 A Wireless Covert Channel Based on Constellation Shaping Modulation
abstract
Wireless covert channel is an emerging covert communication technique which conceals the very existence of secret information in wireless signal including GSM, CDMA, and LTE. The secret message bits are always modulated into artificial noise superposed with cover signal, which is then demodulated with the shared codebook at the receiver. In this paper, we first extend the traditional KS test and regularity test in covert timing channel detection into wireless covert channel, which can be used to reveal the very existence of secret data in wireless covert channel from the aspect of multiorder statistics. In order to improve the undetectability, a wireless covert channel for OFDM-based communication system based on constellation shaping modulation is proposed, which generates additional constellation points around the standard points in normal constellations. The carrier signal is then modulated with the dirty constellation and the secret message bits are represented by the selection mode of the additional constellation points; shaping modulation is employed to keep the distribution of constellation errors unchanged. Experimental results show that the proposed wireless covert channel scheme can resist various statistical detections. The communication reliability under typical interference is also proved.
Pengcheng Cao, Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks2
2018 Using Insider Swapping of Time Intervals to Perform Highly Invisible Network Flow Watermarking
abstract
Network flow watermarking (NFW) is an emerging flow correlation technique to deanonymize an anonymous communication system or detect stepping stones, in which a watermark is encoded into a network flow by manipulating some flow characteristics, predominantly by altering timing information. Although interval-based NFWs that employ time intervals as carrier have proven to be capable of resisting moderate network interference, they are vulnerable to some statistic-based attacks, which may expose the very existence of watermark and enable attackers to damage or remove watermark from the observed flow. In this study, using insider swapping of time intervals and an adaptive centroid quantization framework, we design a highly invisible NFW scheme, which is undetectable by multi-flow attacks (MFA), Kullback-Leibler divergence (KLD) test, Kolmogorov-Smirnov (K-S) test, and spread spectrum flow watermark (SSFW) detection. Experimental results using real traffic and public dataset show that the proposed NFW scheme can outperform three typical NFW schemes on invisibility while maintaining a strong interference-resistance capability of network jitter, packet loss, and dummy packet insertion.
Weiwei Liu 0002, Guangjie Liu 0001, Xiaopeng Ji, Jiangtao Zhai, Yuewei Dai
Secur. Commun. Networks1
2016 Matrix embedding in multicast steganography: analysis in privacy, security and immediacy
Weiwei Liu 0002, Guangjie Liu 0001, Yuewei Dai
Secur. Commun. Networks1
2016 Designing Analog Fountain Timing Channels: Undetectability, Robustness, and Model-Adaptation
abstract
In existing model-based timing channels, the requirement for the target model to be shared between the sender and the receiver limits the sender's ability to adapt to changes in the inter-packet delay (IPD) distribution of the application traffic. In this paper, using analog fountain codes (AFCs) with a general model-fitting coding framework, we design timing channel schemes that allow the sender to change the target model without synchronizing with the receiver. We first propose analog fountain timing channels based on symbol transition when the application packet streams have IPD distribution that is shape similar to the distribution of AFC code symbol values. For more general packet streams, we then propose analog fountain timing channels based on symbol split in which the linearly mapped symbols are split using a symbol probability split matrix to mimic the IPD distribution of the application traffic. We use real VoIP and SSH traffic to compare the proposed schemes with model-based timing channels using LT codes and AFC. Experimental results show that both the proposed schemes are model-secure. The robustness of the two schemes is higher than the model-based timing channels using LT codes whereas not as good as those using AFC when the sender and receiver sides are synchronized with respect to the target model. Moreover, when the sender and the receiver are not synchronized with respect to the model, the robustness of the proposed schemes is significantly higher than model-based timing channels.
Weiwei Liu 0002, Guangjie Liu 0001, Jiangtao Zhai, Yuewei Dai, Dipak Ghosal
IEEE Trans. Inf. Forensics Secur.1
2015 Damage-resistance matrix embedding framework: the contradiction between robustness and embedding efficiency
abstract
Abstract Matrix embedding schemes based on linear codes have been widely used in the field of steganography, which is an important branch of covert communication. Nevertheless, they appear weak for some conditions of high reliability demand or “active attack” because of the poor robustness. In this paper, with robustness analysis of matrix embedding based on Tanner graph, a general framework of damage‐resistance matrix embedding (DR‐ME) is described to take account of both robustness and embedding efficiency, which has a fair chance to recover the secret message when stego object is partly damaged. The approximated robustness–efficiency bound is derived to reveal the contradiction between robustness and embedding efficiency. Then, based on the parity‐check concatenation of systematic convolutional codes and syndrome‐trellis codes (STCs), we propose the practical damage‐resistance STCs (DR‐STCs). Experimental results show that DR‐STCs are near‐optimal DR‐ME schemes, which can approach the derived upper bound. Copyright © 2014 John Wiley & Sons, Ltd.
Weiwei Liu 0002, Guangjie Liu 0001, Yuewei Dai
Secur. Commun. Networks1
2014 Adaptive steganography based on block complexity and matrix embedding
Guangjie Liu 0001, Weiwei Liu 0002, Yuewei Dai, Shiguo Lian
Multim. Syst.2