EDBT 2026 Demo / reviewers in the wild / expert
Wenbao Han
dblp:56/6513
· DBLP profile ↗
22ranked-venue papers
0as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 3 · 3 since 2021Theory of computation · 3Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving targeted password guessing attacks by using personally identifiable information and old passwordabstractAbstract Text-based passwords serve as a primary means of authentication and play a crucial role in securing information systems. However, easy-to-remember passwords are often vulnerable to targeted password guessing attacks. Research on targeted password guessing not only deepens our understanding of password security but also contributes to enhancing the security of information systems. Although the use of Personally Identifiable Information (PII) and old passwords has been shown to significantly improve the accuracy of targeted password guessing, there has been little research on the combined use of both PII and old passwords for guessing. In an era where PII and old passwords are increasingly accessible, assessing the threat posed by attackers using both PII and old passwords in targeted password guessing is an urgent security issue. To address this gap, we first analyze leaked password and personal information datasets, demonstrating that PII and old passwords critically influence users’ password creation behavior. Then, to simulate the security risks posed by attackers who know both PII and old passwords, we propose the PassGLM model, a model fine-tuned on a targeted password guessing task dataset based on glm-4-9b. PassGLM is capable of generating highly targeted guesses by leveraging both PII and old passwords. Experiments show that PassGLM significantly outperforms leading models that use only PII or only old passwords in terms of guess success rates. Our research demonstrates that combining PII and old passwords can substantially improve the accuracy of password guessing, and that using large language models as tools is an effective way to achieve this improvement. Wei Ou, Chengliang Sun, Mengxue Pang, Qiuling Yue, Yanshuo Zhang, Wenbao Han |
Cybersecur. | 6 |
| 2026 | MSGL: A multi-scale group learning model for insider threat detectionabstractThe insider threat refers to actions of organizational users who abuse their authorized privileges to compromise information assets, and the detection of it has become a crucial task in cybersecurity management. Existing approaches primarily rely on user behavior logs for detection, but they often fail to capture the multi-scale temporal dynamics of user behaviors and the structural relationships within user groups, which limits their effectiveness in insider threat detection. To address these limitations, we propose a multi-scale group learning model (MSGL) for insider threat detection. It mainly consists of three key components: (1) a multi-scale collaborative temporal feature extraction module that leverages a weighted attention mechanism to model behavioral dynamics at different granularities and achieves cross-scale information fusion; (2) the group structure-aware module is designed to capture structural dependencies among users by the aggregation mechanism of graph neural networks, while incorporating group-sparsity regularization to attenuate spurious associations and accentuate underlying common patterns; and (3) an individual learning module for capturing deviations via sparse attention, which facilitates disentangled representations of group-level commonalities and specific characteristics of users. Experimental results on the CERT r4.2 and CERT r5.2 datasets demonstrate the effectiveness of MSGL, achieving detection accuracies of 96.28% and 97.41%, respectively. Mengxue Pang, Wei Ou, Weizhi Meng 0001, Meng Shen 0001, Qiuling Yue, Wenbao Han |
Expert Syst. Appl. | 6 |
| 2025 | Double landmines: invisible textual backdoor attacks based on dual-triggerabstractAbstract Backdoor attacks pose an important security threat to textual large language models. Exploring textual backdoor attacks not only helps reveal the potential security risks of models, but also promotes innovation and development of defense mechanisms. Currently, most textual backdoor attack methods are based on a single trigger. For example, inserting specific content into text as a trigger or changing the abstract text features to be a trigger. However, the adoption of this single-trigger mode makes the existing backdoor attacks subject to certain limitations: either they are easily identified by the existing defense strategies, or they have certain shortcomings in attack performance and in the construction of poisoned datasets. In order to solve these issues, a dual-trigger backdoor attack method is proposed in this paper. Specifically, we use two different attributes, syntax and mood (we use subjunctive mood as an example in this article), as two different triggers. It makes our backdoor attack method similar to a double landmine which can have completely different trigger conditions simultaneously. Therefore, this method not only improves the flexibility of trigger mode, but also enhances the robustness against defense detection. A large number of experimental results show that this method significantly outperforms the previous methods based on abstract features in attack performance, and achieves comparable attack performance (almost 100% attack success rate) with the insertion-based method. In addition, in order to further improve the attack performance, we also give the construction method of the poisoned dataset. The code and data of this paper can be obtained at https://github.com/HoyaAm/Double-Landmines. Qiuling Yue, Lujia Chai, Guozhao Liao, Wenbao Han, Wei Ou |
Cybersecur. | 5 |
| 2024 | Telemedicine data secure sharing scheme based on heterogeneous federated learningabstractAbstract The forward triage characteristic of telemedicine highlights its importance again in the COVID-19 pandemic. Telemedicine can provide timely emergency response in the case of environmental or biological hazards, and the patient’s medical privacy data generated in this process can also accelerate the establishment of models for preventing and treating infectious diseases. However, the reuse process of telemedicine user privacy data based on federated learning also faces significant challenges. Differences in regions, economic levels, and grades lead to heterogeneous data and resource-constrained environments, seriously damaging the federated learning process. Besides, the weak password authentication of medical terminals and eavesdropping attacks on transmission channels may cause illegal access to terminals and platforms and leakage of sensitive data. This paper proposed a telemedicine data secure-sharing scheme based on heterogeneous federated learning. Specifically, we proposed a heterogeneous federated learning scheme with model alignment to guide telemedicine practice through the reuse of telemedicine data; in addition, we designed an SM9 threshold identity authentication scheme to guarantee that the patient’s medical privacy data is protected from leakage during the federated learning process. We evaluated our scheme using two third-party medical datasets. The evaluation results indicate that this scheme can still assist the federated learning process in resisting data heterogeneity and resource constraints with almost no performance cost. Nansen Wang, Ju Huang, Wei Ou, Wenbao Han, Qionglu Zhang |
Cybersecur. | 5 |
| 2024 | A metaheuristic image cryptosystem using improved parallel model and many-objective optimizationabstractAbstract Metaheuristic is one of the techniques to improve the security of image encryption. However, existing metaheuristic image cryptosystems based on metaheuristic may have convergence difficulties during the optimization process, which cause insecurity and slow convergence. Besides, the time cost of the parallel execution model applied to metaheuristic image cryptosystems is not low enough. Therefore, a parallel many‐objective optimized key generation framework is proposed. Firstly, if four or more security indicators of cryptosystem, which are the results of security test, need to be optimized, the many‐objective optimization algorithm is employed to the proposed framework. With method adjusts the chaotic system parameters as the optimization key, which effectively avoid the convergence difficulty of the encryption key. Secondly, a master‐slave parallel model is improved to metaheuristic encryption. The model allocates the most time‐consuming fitness calculation work to slave nodes, which makes the modified model more reasonable and thus reduces the encryption time. To evaluate the performance of the proposed framework, a specific encryption scheme is constructed, that utilizes a 2D quadric map and many‐objective optimization algorithm based on dominance and decomposition (MOEA/DD) to optimize five security indicators. Experimental results reveal that this scheme has good security performances and less parallel encryption time. Zihao Xin, Xiaoyi Zhou, Wenbao Han, Jianqiang Ma |
IET Image Process. | 4 |
| 2024 | TAE-RWP: Traceable Adversarial Examples With Recoverable Warping PerturbationabstractReversible adversarial example (RAE) is an effective cutting‐edge technology for protecting the intellectual property (IP) of datasets. However, existing RAE schemes primarily focus on the adversarial and restoration capabilities of adversarial examples (AE), with little attention paid to traceability, which is crucial for IP protection. This oversight leads to the inability to prevent authorized users from redistributing data, thereby posing significant IP security risks. To address this issue, we propose a novel approach named TAE‐RWP, wherein adversarial perturbations in AEs are treated as tools for IP verification. To enable the traceability of AEs, we introduce varying degrees of warping to the adversarial perturbations within the AEs of authorized users, utilizing the warping degree as a traceable feature. To further strengthen traceability, we adopt a technique named “random warping” to maintain the resilience of adversarial perturbations against distortions, and employ a strategy named “noise mode” to improve the verification model’s capacity to recognize distortion features. Experimental results indicate that AEs generated by TAE‐RWP exhibit remarkable adversarial strength and restoration abilities, while the verification model demonstrates excellence in recognizing distortion features. Fan Xing, Xiaoyi Zhou, Hongli Peng, Xuefeng Fan, Wenbao Han, Yuqing Zhang 0001 |
Int. J. Intell. Syst. | 5 |
| 2024 | General Pairwise Modification Framework for Reversible Data Hiding in JPEG ImagesabstractPairwise modification is one of the most effective ways to solve the critical issues of balancing the embedding capacity, image distortion, and file expansion in JPEG reversible data hiding (RDH). To design a satisfactory scheme based on pairwise modification, existing schemes focus on improving pairing rules, two-dimensional (2D) mappings, or ordering strategies separately while neglecting the connections between them. As a result, once pairing rules are changed, the correlative 2D mapping and ordering strategies are no longer available. To address such issues, this study proposes a framework that automatically generates optimal 2D mappings and efficient ordering strategies only by carefully initializing pairing rules. To construct optimal 2D mappings, a 2D mapping mathematical model is built to form a feasible 2D mapping solution space, in which optimal solutions are found, to assign efficient mappings for pairs with high probability. To design efficient ordering strategies, all frequencies are ranked according to an embedding evaluation model to determine more suitable ACs for data embedding. To initialize better pairing rules, this study selects nonzero ACs within ±2 for interblock pairing to form a more centralized pairwise histogram. The experimental results show that the proposed scheme introduces minor file expansion and obtains better visual quality than existing JPEG RDH schemes when the payload is the same as. Xiaoyi Zhou, Kaiyue Hou, Yu-Jian Zhuang, Zhao-Xia Yin, Wenbao Han |
IEEE Trans. Circuits Syst. Video Technol. | 5 |
| 2023 | A data sharing method for remote medical system based on federated distillation learning and consortium blockchainabstractWith the development of Medical Internet of Things (MIoT) technology and the global COVID-19 pandemic, hospitals gain access to patients’ health data from remote wearable medical equipment. Federated learning (FL) addresses the difficulty of sharing data in remote medical systems. However, some key issues and challenges persist, such as heterogeneous health data stored in hospitals, which leads to high communication cost and low model accuracy. There are many approaches of federated distillation (FD) methods used to solve these problems, but FD is very vulnerable to poisoning attacks and requires a centralised server for aggregation, which is prone to single-node failure. To tackle this issue, we combine FD and blockchain to solve data sharing in remote medical system called FedRMD. FedRMD use reputation incentive to defend against poisoning attacks and store reputation values and soft labels of FD in Hyperledger Fabric. Experimenting on COVID-19 radiography and COVID-Chestxray datasets shows our method can reduce communication cost, and the performance is higher than FedAvg, FedDF, and FedGen. In addition, the reputation incentive can reduce the impact of poisoning attacks. Chengyu Zhu, Wei Ou, Wenbao Han, Qionglu Zhang |
Connect. Sci. | 5 |
| 2023 | A zero trust and blockchain-based defense model for smart electric vehicle chargersabstractElectric vehicles (EVs) have rapidly developed over the last decade due to their environmental benefits. As a key component of EVs, electric vehicle chargers are becoming increasingly digital and intelligent. However, due to the vast attack surface and the lack of systematic study, EV chargers and charging management cloud platforms are facing cyber security problems. These problems include weak cryptographic mechanisms, insecure data communication, and malicious firmware attacks. Through specific vulnerabilities, attackers can tamper with the data communication or replay network requests between EV chargers and cloud platforms. It will cause threats such as user-level privacy leakage, power fluctuations in the smart grid, and damage to Electric vehicles, damaging public life and property safety. Given the above, this paper proposes a security protection scheme incorporating blockchain, zero trust, and ShangMi cryptographic (SM) algorithms. The scheme uses Hyperledger Fabric for key management and trust evaluation event storage to guarantee the authenticity, non-repudiation, and tamper-proof of keys and events. In addition, zero trust is applied to secure valuable resources and enforce identity and access management (IAM) for accessing entities. We adopt the dynamic trust evaluation method to assess the trustworthiness of accessing entities in real time to implement dynamic authorization. Furthermore, the SM algorithms SM2, SM3, and SM4 are used to protect data confidentiality, integrity, and authenticity. Experimental results demonstrate that our scheme can effectively resist replay and tampering attacks, securing data communication between EV chargers and cloud platforms. And the performance of the cryptographic algorithm, blockchain system, and Secure Sockets Layer (SSL) meets Chinese national and industry standards. Peirong Li, Wei Ou, Haozhe Liang, Wenbao Han, Qionglu Zhang |
J. Netw. Comput. Appl. | 4 |
| 2022 | An overview on cross-chain: Mechanism, platforms, challenges and advancesabstractAfter years of in-depth development of blockchain, various blockchains with different characteristics and suitable for different application scenarios coexist in large numbers. Due to the isolation of blockchains and the high degree of heterogeneity between chains, value transfer and data communication between existing blockchains are facing unprecedented challenges, and the phenomenon of value isolated island is gradually emerging. The cross-chain technology of blockchain is an important technical means to realize the interconnection of blockchains and improve the interoperability and scalability of blockchains. In this paper, the development and application of blockchain cross-chain technology are studied, the background and significance of cross-chain technology are described, the research status of cross-chain technology is expounded, the current mainstream cross-chain technologies and cross-chain projects are introduced, the mentioned cross-chain technologies and cross-chain projects are analyzed and compared. In addition, this paper also summarizes the difficulties existing in the current cross-chain technology and provides solutions for reference, so as to lead to the discussion of the development trend of cross-chain technology, and finally complete the summary of the research content of the full text and the prospect of cross-chain technology. It is hoped that the relevant summary results can help relevant researchers and practitioners quickly grasp the research progress in the field of blockchain interoperability, and obtain relevant knowledge and application methods in this field. Wei Ou, Shiying Huang, Qionglu Zhang, Wenbao Han |
Comput. Networks | 6 |
| 2021 | BSVMS: Novel Autonomous Trustworthy Scheme for Video MonitoringabstractWith the continuous development and application of monitoring technology, which involves increasingly more sensitive information, the global demand for video monitoring systems has surged. As a result, video monitoring technology has received widespread attention both at home and abroad. Traditional video monitoring systems experience security threats, with differing levels of severity, in terms of attack, storage, transmission, etc., which results in different degrees of damage to users’ rights. Therefore, we propose a blockchain‐SM‐based video monitoring system called BSVMS. For the front‐end device invasion risk, internal attack risk, and security storage problem of the monitoring system, we use commercial cryptography algorithms to complete the encryption processing of images through a visual change network in the imaging process, thereby ensuring the security of the video data from the source. To address the problem that the video monitoring application software and data are vulnerable to damage, we use blockchain technologies that are tamper‐proof and traceable to build a trustworthy video monitoring system. In the system, no member can query the original monitoring data. To address the security issues in network transmission, we use a commercial cryptography algorithm for multilayer encryption to ensure the security of data during transmission, guarantee the confidentiality of the system, and realize domestic autonomous control. We then conduct tests and security analysis of the encryption and decryption efficiency of the SM4 algorithm used in the system, the blockchain performance, and the overall performance. The experimental results show that in this system environment, the SM4 algorithm encryption and decryption efficiency is better than other algorithms and that the blockchain used meets industry standards. Xuan Wang 0038, Wei Ou, Wenbao Han |
Wirel. Commun. Mob. Comput. | 6 |
| 2017 | New strategy for searching disturbance vector of SHA-1 collision attack
Wenbao Han |
Sci. China Inf. Sci. | 3 |
| 2016 | Accountable Ciphertext-Policy Attribute-Based Encryption Scheme Supporting Public Verifiability and Nonrepudiation
Gang Yu 0005, Zhenfu Cao, Wenbao Han |
ProvSec | 4 |
| 2015 | Classification of disturbance vectors for collision attack in SHA-1
Wenbao Han |
Sci. China Inf. Sci. | 3 |
| 2015 | Survey on cyberspace security
Huanguo Zhang, Wenbao Han, Xuejia Lai, Dongdai Lin, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 2 |
| 2015 | Information diffusion network inferring and pathway tracking
Wenbao Han, Baodi Yuan |
Sci. China Inf. Sci. | 2 |
| 2014 | Symbolic Execution of Network Software Based on Unit TestingabstractComplex interactions and the distributed nature of network software make automated testing and debugging before deployment a necessity. Symbolic execution is a systematic program analysis technique that has become increasingly popular in network software testing, due to algorithmic advances and availability of computational power and constraint solving technology. However, A main challenge is to detect determining symbolic values for program variables related to library, loops and cryptograph algorithms which are widely used in network software. In this paper, we propose a unit symbolic analysis, a hybrid technique that enables fully automatic symbolic analysis even for the traditionally challenging code. The novelties of this work are threefold: 1) we flexibly employs static symbolic execution to amplify the effect of dynamic symbolic execution on demand, 2) dynamic executions and regression analysis are performed on the unit tests constructed from the code segments to infer program semantics needed by static analysis, and 3) symbolic analysis is utilized to tackle loop structure and cryptograph algorithm module. We developed the Net Sym framework, consisting of a static component that performs symbolic analysis and partitions a program, a dynamic analysis that synthesizes unit tests and automatically infers symbolic values for program variables, and a protocol that enables static and dynamic analyses to be run interactively and concurrently. Our experimental results show that by handling cryptograph algorithms, loops and library calls that a traditional symbolic analysis cannot process, unit symbolic analysis detects more vulnerabilities in less time. The technique is scalable for real-world programs such as GHttpd, SQL Server and GDI. Shuitao Gan, Xiaojun Qin, Wenbao Han |
NAS | 5 |
| 2010 | Provable secure identity based generalized signcryption scheme
Gang Yu 0005, Wenbao Han |
Theor. Comput. Sci. | 4 |
| 2008 | Reducible Polynomial over F2 Constructed by Trinomial sigma-LFSR
Wenbao Han, Shuqin Fan |
Inscrypt | 3 |
| 2007 | A trinomial type of σ-LFSR oriented toward software implementation
Kaicheng He, Wenbao Han |
Sci. China Ser. F Inf. Sci. | 3 |
| 2006 | Nonexistence of a Kind of Generalized Perfect Binary Array
Xiyong Zhang, Hua Guo 0001, Wenbao Han |
SETA | 3 |
| 2003 | Random properties of the highest level sequences of primitive sequences over Z(2e)abstractUsing the estimates of the exponential sums over Galois rings, we discuss the random properties of the highest level sequences /spl alpha//sub e-1/ of primitive sequences generated by a primitive polynomial of degree n over Z(2/sup e/). First we obtain an estimate of 0, 1 distribution in one period of /spl alpha//sub e-1/. On the other hand, we give an estimate of the absolute value of the autocorrelation function |C/sub N/(h)| of /spl alpha//sub e-1/, which is less than 2/sup e-1/(2/sup e-1/-1)/spl radic/3(2/sup 2e/-1)2/sup n/2/+2/sup e-1/ for h/spl ne/0. Both results show that the larger n is, the more random /spl alpha//sub e-1/ will be. Shuqin Fan, Wenbao Han |
IEEE Trans. Inf. Theory | 2 |