EDBT 2026 Demo / reviewers in the wild / expert
Yan Wang 0081
dblp:59/2227-81
· DBLP profile ↗
46ranked-venue papers
1as first author
39since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 1 first-author · 14 since 2021Security and privacy · 10 · 8 since 2021Artificial intelligence and machine learning · 6 · 4 since 2021Human-computer interaction and ubiquitous computing · 6 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ASTDroid: Abstract Syntax Trees Enhanced GNNs for Android Malware Detection
Xingyuan Wei, Rui Mao 0004, Yan Wang 0081 |
WCNC | 4 |
| 2025 | A Jailbreak Prompt Detector Based on Selective Perturbation and Contrastive LearningabstractJailbreak attacks pose a significant threat to the reliable deployment of large language models (LLMs) in critical applications. Although existing LLMs are supervised fine-tuning and aligned through reinforcement learning from human feedback, automated jailbreak attack algorithms can still identify potential jailbreak prompts that lead to harmful outputs. In this paper, we propose JPS, a jailbreak attack detector based on selective perturbation and contrastive learning. JPS leverages the robustness of jailbreak attacks, which is achieved through complex multi-step optimization, by using perturbation methods to enhance the training data for jailbreak prompts. In order to mitigate noise from perturbation, we introduce a selective strategy based on token importance. Additionally, we employ supervised contrastive learning to effectively differentiate between jailbreak and benign samples. Extensive experiments on the popular jailbreak attacks and benign datasets show that JPS outperforms all the baseline approaches according to F1-score. Furthermore, detailed ablation experiments were conducted to analyze each module of the model, demonstrating the effectiveness of our approach. Yanshu Li, Yan Wang 0081, Haitian Yang |
CSCWD | 2 |
| 2025 | A Personalized Secondary Perturbation Mechanism Based on Local Differential PrivacyabstractWith the development of location-based services (LBS) in mobile internet and smart devices, privacy leakage concerns are escalating. While differential privacy has gained traction for location protection due to its rigorous guarantees, existing methods face two critical challenges: repeatedly applying identical mechanisms at a single location enables attackers to leverage background knowledge for inference attacks, compromising true location privacy; meanwhile, they lack personalized privacy configurations and associated service quality metrics. To address these issues, we propose PSPLDP, implementing dual Laplace perturbation under local differential privacy to fulfill location specific privacy requirements. And we introduce a service quality evaluation metric suitable for personalized privacy settings. Experiments on real world datasets demonstrate our method's effectiveness against inference attacks and the capability of the metric to quantify service quality across diverse privacy settings. Yan Wang 0081, Degang Sun |
CSCWD | 2 |
| 2025 | KanIDS: An Intrusion Detection System for All Kernel Interactions Based on Kolmogorov-Arnold NetworkabstractIn recent years, Advanced Persistent Threats have increasingly caused significant harm in cyberspace. Security researchers have been attempting to construct Intrusion Detection Systems based on provenance graphs to effectively detect these complex, persistent, and covert attacks. Most works treat prove-nance graphs as static graphs, ignoring the dynamic changes of APTs and kernel behaviors. Some recent works construct dynamic provenance graphs and achieve effective results in time window detection and attack reconstruction. However, these works either use snapshots to segment the dynamic graphs, resulting in insufficient extraction of temporal information, or use graph auto-encoders to fully extract temporal information but do not fully include all interaction types. These methods all lose the important information, and make the reconstruction and analysis of attacks incomplete. In this paper, we propose KanIDS, a temporal provenance graph-based intrusion detection system that includes all types of interactions. We inherit the basic method of the graph representation and dynamic graph auto-encoder used by Kairos, but we extend the limited types of interactions to all interaction types across datasets to ensure the completeness of anomaly detection and attack reconstruction. Additionally, we replace the decoder from a Multi-Layer Perceptron with a Kolmogorov-Arnold Network to address the issues of weak learning capabilities for sequential data and low parameter utilization efficiency. Experimental results show that our approach shows better graph learning abilities in the training phase. Moreover, the accuracy of KanIDS in time window detection with all interaction types exceeds the baseline by 1 %-3% and F-l score by 10%-30%. Baorui Zheng, Xiu Ma, Qiujian Lv, Yan Wang 0081 |
CSCWD | 6 |
| 2025 | VN-GT: Optimizing Virtual Network Deployment via Game TheoryabstractThe static and homogeneous nature of traditional networks presents a significant challenge for our defense efforts. These characteristics enable an experienced attacker to quickly determine our network topology and gather detailed information about the internal hosts through systematic scanning techniques. Implementing a virtual network view can mitigate this by simulating a virtual topology, thereby consuming the attacker’s resources and time. However, deploying a virtual network view reduces network throughput and increase latency. Additionally, an improperly configured virtual network view can waste resources and degrade Quality of Service (QoS). Most existing studies have focused solely on the defender’s perspective, resulting in overly idealistic solutions that are ineffective in real-world scenarios. To address this, we propose VN-GT, a game-theoretic based model that optimizes virtual network deployment by considering both attackers and defenders. We provide a detailed example scenario, analyze the game’s equilibrium, and validate the effectiveness of our method through a real attack and defense experiment. Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Zuxin Chen, Siyuan Li 0014, Min Yu 0001, Weiqing Huang, Degang Sun |
ICASSP | 2 |
| 2025 | Multi-Modal Fake News Detection with LLMs and Knowledge-Aligned Attention NetworksabstractWith the booming rise of the Internet and social media, semantically rich multimodal data has gradually become the mainstream carrier of news dissemination. Among them, multi-modal fake news with illustrations and text has attracted widespread attention due to its greater deceptiveness. However, existing research methods are mainly limited to the analysis of images and text within the news itself, failing to fully consider the consistency and discrepancy characteristics between different modalities, which hinders the full exploitation of the advantages of multi-modal fusion. To address this issue, this study proposes a multi-modal fake news detection method with large language models(LLMs) and Knowledge-Aligned Attention Networks(MFDnet). This method first leverages the powerful semantic understanding capabilities of large language models to generate detailed text descriptions for images, serving as a knowledge supplement for the image model. Subsequently, by constructing a Knowledge-Aligned Attention Networks, it achieves efficient semantic fusion between the knowledge-supplemented image model and text modal information, thereby effectively extracting the consistency and complementary features between different modalities. Experimental results demonstrate that this model exhibits excellent performance on multiple public fake news detection datasets. Degang Sun, Yan Wang 0081, Xuan Zhao 0011, Haitian Yang, Weiqing Huang |
ISCC | 3 |
| 2024 | MLNT: A Multi-Level Network Traps Deployment MethodabstractTraditional honeypot technology combines trap deployment component with attack deception response component, and the more network traps are deployed, the more system resources, such as virtual machines and containers, are required. To alleviate this problem, we propose a transparent network deception defense method called MLNT. MLNT decouples the trap deployment component and attack deception response component, reducing the dependence of high-density traps on system resources. First, MLNT can complete multi-layer network trap deployment, including trap service ports of real assets, network node traps of security domains, and security domain traps. Second, MLNT can transparently deploy network traps on real protection targets. It protects valuable assets in Industrial Control Networks and the Internet of Things, where software agents can not be installed. Finally, we implemented the MLNT framework using FPGA and tested it’s capability of delaying the attackers’ progress. The experimental results demonstrate the effectiveness and feasibility of MLNT. Guokun Xu, Weijie Wang 0005, Degang Sun, Yanpeng Ma, Yan Wang 0081, Weiqing Huang |
CSCWD | 5 |
| 2024 | Smartphone Gait Authentication Based on Activity Recognition Task in Unconstrained EnvironmentabstractGait authentication based on smartphone built-in sensor has attracted much attention, but most of the work restricts users’ behavior, which requires users to walk in a specified scene. Actually, non-walking activities are often accompanied by users’ normal walking in unconstrained environment, which brings a challenge to gait authentication. To avoid interference from non-walking activities, we propose an optimized gait extraction model consisting of an improved Inception-CNN and three-layer 1D-CNN. The proposed model extracts useful walking data from sensor data via activity recognition, which improves the robustness of authentication. By exploiting the advantages of CNN and RNN in extracting spatial and temporal features, we construct a CNN-RNN model for high-precision user authentication. Based on the UCI-HAR dataset, the learning ability of LSTM, GRU, Bi-LSTM and Bi-GRU variants is compared, and GRU stands out among them, so we use it as the RNN structure. The experiments show that the optimized gait extraction model has a walking recognition accuracy of 97.52%, and after extracting walking data by it, the CNN-GRU hybrid model achieves the authentication accuracy of 96.68% and equal error rate (EER) of 2.86%. Compared with the existing advanced models, the optimized gait extraction model is significantly superior to the same kind of models. Rui Mao 0004, Qing Hao, Yan Wang 0081 |
ISCC | 4 |
| 2024 | Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceabstractProvenance graphs are structured audit logs that describe the history of a system’s execution. Recent studies have explored a variety of techniques to analyze provenance graphs for automated host intrusion detection, focusing particularly on advanced persistent threats. Sifting through their design documents, we identify four common dimensions that drive the development of provenance-based intrusion detection systems (PIDSes): scope (can PIDSes detect modern attacks that infiltrate across application boundaries?), attack agnosticity (can PIDSes detect novel attacks without a priori knowledge of attack characteristics?), timeliness (can PIDSes efficiently monitor host systems as they run?), and attack reconstruction (can PIDSes distill attack activity from large provenance graphs so that sysadmins can easily understand and quickly respond to system intrusion?). We present Kairos, the first PIDS that simultaneously satisfies the desiderata in all four dimensions, whereas existing approaches sacrifice at least one and struggle to achieve comparable detection performance.Kairos leverages a novel graph neural network based encoder-decoder architecture that learns the temporal evolution of a provenance graph’s structural changes to quantify the degree of anomalousness for each system event. Then, based on this fine-grained information, Kairos reconstructs attack footprints, generating compact summary graphs that accurately describe malicious activity over a stream of system audit logs. Using state-of-the-art benchmark datasets, we demonstrate that Kairos outperforms previous approaches. Qiujian Lv, Jinyuan Liang, Yan Wang 0081, Degang Sun, Thomas Pasquier, Xueyuan Han |
SP | 4 |
| 2024 | Autocue : Targeted Textual Adversarial Attacks with Adversarial Prompts
Haitian Yang, Yan Wang 0081, Weiqing Huang |
WASA (3) | 4 |
| 2024 | DSGN: Log-based anomaly diagnosis with dynamic semantic gate networks
Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang |
Inf. Sci. | 3 |
| 2023 | GHunter: A Fast Subgraph Matching Method for Threat HuntingabstractThreat hunting is the process of proactively searching for known attack behavior in an organization’s information system. A popular approach to threat hunting uses cyber threat intelligence (CTI) to identify advanced persistent threats (APTs) that are hidden in kernel-level audit logs (e.g., whole-system data provenance). However, existing threat hunting mechanisms can-not produce timely results due to the enormous size of provenance data. As a result, threat hunting cannot help sysadmins to quickly recognize an ongoing APT campaign and immediately block any subsequent attack activity. In this paper, we propose GHunter, a system that performs approximate subgraph matching using graph neural networks (GNNs) to quickly and accurately hunt APTs. GHunter first converts known APT scenarios and provenance logs into graph data. Then, GHunter uses GNNs to embed APT scenario graphs and provenance graphs to discover any subgraph relationships. If an APT scenario graph is a subgraph of a provenance graph, GHunter alerts to sysadmins the presence of the corresponding APT scenario in the system. We use DARPA’s Transparent Computing (TC) datasets to evaluate GHunter’s performance. The results show that GHunter achieves 97% accuracy when hunting APTs from millions of provenance log entries and spends 195x less execution time than prior work. Rujie Dai, Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
CSCWD | 6 |
| 2023 | ACG: Attack Classification on Encrypted Network Traffic using Graph Convolution Attention NetworksabstractAttack classification of network traffic is valuable for many security solutions as it points out a clear direction for attack responses. Nowadays, most network traffic is encrypted, which protects user privacy but hides attack traces, further hindering identifying attacks to inspect traffic packages. Machine Learning(ML) methods are widely applied to attack classification on encrypted traffic owing to no need for manual analysis. However, existing studies only concentrate on basic statistical features, which are easily modified, and cannot obtain the crucial attack behaviors hiding in the encrypted traffic. In this paper, we propose an attack classification method, ACG. We create attack graphs to depict interaction behaviors of attack-victim hosts from network traffic containing crucial attack behaviors. Besides, we divide a specific duration for each attack to precisely elaborate attack graphs, where temporal, statistical, and aggregate features are extracted to portray attack behaviors. Finally, we utilize Graph Neural Networks (GNNs) to mine and grasp the crucial behavior patterns from attack graphs to generate fingerprints and classify attacks. Extensive experiments are conducted on three datasets to verify our method. It achieves a precision of 99% in attack classification on encrypted traffic, an average higher than other ML methods of 50%. Leiqi Wang, Qiujian Lv, Yan Wang 0081, Shixiang Zhang, Weiqing Huang |
CSCWD | 4 |
| 2023 | Prompt Makes mask Language Models Better Adversarial AttackersabstractGenerating high-quality synonymous perturbations is a core challenge for textual adversarial tasks. However, candidates generated from the masked language model often contain many words that are antonyms or irrelevant to the original words, which limit the perturbation space and affect the attack’s effectiveness. We present ProAttacker1which uses Prompt to make the mask language models better adversarial Attackers. ProAttacker inverts the prompt paradigm by leveraging the prompt with the class label to guide the language model to generate more semantically-consistent perturbations. We present a systematic evaluation to analyze the attack performance on 6 NLP datasets, covering text classification and inference. Our experiments demonstrate that ProAttacker outperforms state-of-the-art attack strategies in both success rate and perturb rate. Haitian Yang, Yan Wang 0081, Weiqing Huang |
ICASSP | 4 |
| 2023 | ABTD-Net: Autonomous Baggage Threat Detection Networks for X-ray ImagesabstractAutomated security screening has a significant role In protecting public spaces from security threats by employing X-ray images to detect prohibited items. However, there are challenges of noise production due to squeezing, occlusion, and penetration of luggage objects. Additionally, the hues of objects are monotonous and lack luster. To solve these problems, we propose an Autonomous Baggage Threat Detection Network (ABTD-Net) for accurate prohibited item detection. To tackle the difficulty of capturing distinctive visual features, we constructed a Feature Adjustment Head (FAH) to refine pyramid features. Specifically, we designed an Attention Module (AM) at several places after initially using a Dense Unidirectional Propagation (DUP) to filter noise. Furthermore, we created a Feature Fusion Head (FFH) that dynamically fuses hierarchical visual information under object occlusion, including early-fusion and late-fusion. Extensive experiments on security inspection X-ray datasets OPIXray and HiXray demonstrate the superiority of our proposed method. Degang Sun, Yan Wang 0081, Zhongyuan Chen, Xinbo Han, Haitian Yang |
ICME | 3 |
| 2023 | ASGNet: Adaptive Semantic Gate Networks for Log-Based Anomaly Diagnosis
Haitian Yang, Degang Sun, Yanshu Li, Yan Wang 0081, Weiqing Huang |
ICONIP (4) | 5 |
| 2023 | AdaptParse: Adaptive Contextual Aware Attention Network for Log Parsing via Word ClassificationabstractLogs are widely used during the development and maintenance of software systems. Logs assist developers and operation & maintenance personnel to understand the state and behavior of systems at runtime. Also, logs can diagnose system failures and conduct abnormal analyses to provide further protection to the security of systems. However, large software systems generate large amounts of semi-structured logging routinely. The first step to support further analysis is how to parse semi-structured records with free-form text log messages into structured templates. Therefore, log parsing is rather challenging. Because logs are generated by static templates (i.e., log statements) in the source code, templates are often not accessible when parsing logs. It is worth noting that most proposed approaches still rely on log-specific heuristics or manual rule extraction. Those existed methods are often specialized for parsing certain log types and often neglect the semantic meaning of log messages, thus limiting performance scores and generalization, hence, in this paper, we propose a new parsing technique - Adaptive Contextual Aware Attention Network for Log Parsing via Word Classification, named AdaptParse. Adapt-Parse transforms the template generation problem into a word classification task, then learns the features of template words and variable words. We evaluate our AdaptParse on 5 realworld log datasets and compare the performance with 7 parsing techniques. Our experimental results show that the proposed approach can effectively understand the semantic meaning of log messages and achieve accurate log parsing results. Overall, AdaptParse achieves state-of-the-art performance on five realworld log datasets, outperforming all the baseline models. Haitian Yang, Degang Sun, Yan Wang 0081, Shixiang Zhang, Weiqing Huang |
IJCNN | 3 |
| 2023 | UAG: User Action Graph Based on System Logs for Insider Threat DetectionabstractInsider threats pose significant risks to the network systems of organizations. Users have diverse behavioral habits within an organization, leading to variations in their activity patterns. Hence, data analysis and mining techniques are essential for modeling user behavior. Current methods analyze system logs and extract user action sequence features; however, they overlook the relationships between different actions, reducing detection accuracy. To address this issue, we propose a novel method called UAG (User Action Graph). UAG transforms user actions into a graph representing their chronological order and interrelationships, facilitating a more accurate and comprehensive understanding of user behavior. By extracting global and local features from the user action graph, UAG offers an extensive and detailed perspective of user behaviors. Ultimately, we develop a lightweight ensemble autoencoder model to detect insider threats. Comprehensive experiments demonstrate that UAG delivers outstanding performance and surpasses existing methods. Yan Wang 0081, Qiujian Lv, Leiqi Wang |
ISCC | 3 |
| 2023 | IAD-Net: Multivariate KPIs Interpretable Anomaly Detection with Dual Gated Residual Fusion NetworksabstractAnomaly detection of key performance indicators (KPIs), e.g., CPU load, network usage, is crucial for system behavior monitoring. In recent years, several anomaly detection approaches have been proposed. However, detecting anomalies of KPIs remains challenging because of the stochastic nature and complex temporal dependence of multivariate time series. Additionally, the presence of noise and the unavailability of labeled data in large-scale datasets limit the effectiveness of anomaly detection. In this paper, we propose IAD-Net, an interpretable anomaly detection method with Dual Gated Residual Fusion Networks. The main idea is to model the inter-metric and temporal dependencies simultaneously by using gated residual blocks and two-stream fusion. Additionally, we utilize Gated Recurrent Unit (GRU) to extract long-term global trend patterns of an input sequence. Finally, both the forecasting-based model and the reconstruction-based model are combined in order to focus on single-timestamp predictions and latent representations of time series. Extensive experiments on real-world data show that IAD-Net outperforms other state-of-the-art approaches according to F1-score. Further analysis confirms the effectiveness of our method in anomaly interpretation. Degang Sun, Haitian Yang, Yan Wang 0081 |
TrustCom | 5 |
| 2023 | LWVN: A Lightweight Virtual Network View Method to Defend Lateral MovementabstractDue to traditional network topologies’ static and homomorphic characteristics, attackers can rapidly expand their attack results through lateral movement (LM) attacks. Virtual Network View technology has emerged as an effective approach to disrupt attackers’ ability to detect and exploit network topologies during LM and can increase the difficulty of malicious activities. However, existing Virtual Network View deployS virtual views for each core asset, resulting in wasting of resource. To alleviate this problem, we propose a lightweight Virtual Network View deployment method called LWVN. First, the Location Centrality (LC) of the network nodes in the attack path is measured, the larger the LC is, the network node is more important and the more virtual network view costs we can invest. To further quantify the comprehensive impact of network nodes’ location centrality on high-value assets, we quantify the Assets’ Value(AV). Then, we model internal network risk and operational costs as constraints and find the optimal strategies for deploying a virtual network view. We define metrics for hidden capacity, detect capacity, and deployment cost to measure the effectiveness of deployment virtual network views. We conduct simulations to verify the effectiveness and feasibility of LWVN. Degang Sun, Guokun Xu, Weijie Wang 0005, Yan Wang 0081, Qiujian Lv |
TrustCom | 4 |
| 2023 | DTrap: A cyberattack-defense confrontation technique based on Moving Target DefenseabstractIn the evolution process of cyberattack-defense confrontation, both sides have always been in a state of mutual confrontation and collaborative development, continuously upgrading their tools to improve adversarial capabilities. However, in this arms race, the positions of the both sides are imbalanced. As the party actively initiating the attack, attackers always is able to actively adjust the attack strategy based on the detected defense vulnerabilities to launch effective attacks. While the defenders always detecting defense vulnerabilities after suffering losses and filling them in a "patching" manner. This post awareness security protection strategy has a "fatal time difference" when dealing with unknown attacks. This paper aims to change the imbalanced state. Therefore, a attack confrontation model DTrap is proposed based on the concept of moving target defense, which introduce of high simulation trap hosts to achieve IP address and service port confusion. It can simulate real hosts to achieve various common network protocol requests and responses, and it can provide better dynamism than Honeypot when adjusting trap policies. DTrap can reverse the imbalance situation by increasing attack costs and promoting attack difficulty. We constructed a real adversarial environment, the security effectiveness of the DTrap model was evaluated through comprehensive and multi-dimensional experiments. The results indicate that DTrap can exert expected effectiveness in resisting network attacks of different dimensions, and effectively enhance the network attack confrontation ability. Degang Sun, Yan Wang 0081, Xinbo Han, Weiqing Huang |
TrustCom | 3 |
| 2023 | VN-SMT: An SMT-based Construction Method on Virtual Network to Defend Insider ReconnaissanceabstractDue to networks’ static and homomorphic nature, experienced attackers can quickly get the target network’s topology and internal host information by scanning. The virtual network view prevents network reconnaissance by simulating a virtual network topology for the network hosts, to consume the attacker’s attack resources and time. However, deploying a virtual network view will reduce network throughput and increase network latency, and an unreasonable virtual network view configuration will waste resources and reduce Quality of Services(QoS). We, therefore, propose a method VN-SMT that can rationally configure virtual network view. This method generates an optimal virtual network view base on existing host configuration, risk constraints, and budget constraints. We define metrics for deception, concealment, and resource consumption to measure the effectiveness of virtual network views. We conduct simulations to verify the effectiveness and feasibility of VN-SMT. Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Qiujian Lv, Zuxin Chen, Siyuan Li 0014 |
WCNC | 2 |
| 2023 | TGPrint: Attack fingerprint classification on encrypted network traffic based graph convolution attention networks
Leiqi Wang, Xiu Ma, Qiujian Lv, Yan Wang 0081, Weiqing Huang |
Comput. Secur. | 5 |
| 2023 | CKDAN: Content and keystroke dual attention networks with pre-trained models for continuous authentication
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Yuejun Liu, Xiaoyu Kang, Jiahui Shen, Weiqing Huang |
Comput. Secur. | 4 |
| 2022 | CyEvent2vec: Attributed Heterogeneous Information Network based Event Embedding Framework for Cyber Security Events AnalysisabstractRecently, cyber security events have been gathered as a kind of Cyber Threat Intelligence(CTI) to fight against cyber attacks. Developing a cyber events analysis model to predict the possible threats can assist organizations in providing guidance for decision making. A cyber security event is a complete semantic unit containing all the participating objects (such as attacks assets and organizations) with rich attributes (such as the results and variety of the attack). However, existing cyber security events modeling works ignore the attributes of the objects and analyze the objects' relationships independently. To predict the possible threats for the organizations, we propose a cyber events embedding framework CyEvent2vec to model cyber security events with attributes. First, to effectively depict the cyber security events with attributes that happened in organizations, cyber security events are reconstructed by the organization and processed into the events matrices. Second, to explore the intricate relationships between heterogeneous objects in events, the events matrices are fed into the autoencoder model to get the low-dimensional embeddings. Third, to predict the possible threats for the victim organization, we apply the embeddings to two applications to measure the relevance between the objects: organization threats prediction and threat objects classification. Experiments show CyEvent2vec outperforms the other six representation learning methods on three real-world datasets. Xiu Ma, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
IJCNN | 4 |
| 2022 | MMSP: A LSTM Based Framework for Multi-Step Attack Prediction in Mixed ScenariosabstractA multi-step attack scenario consisting of more than one attack step is difficult to predict because of various attack steps and complex combinations. The multi-step attack scenarios occurring simultaneously construct a mixed attack scenario, which is more common than a single attack scenario in practical systems. However, most of the existing multi-step attack prediction approaches only focus on a single attack scenario. In this paper, a framework MMSP is proposed for multi-step attack prediction in mixed scenarios. MMSP fractionates alerts by separating them into different scenarios and removing redundant samples. The attack scenarios fingerprint database of MMSP is built by modeling the attack steps regarding different scenarios based on the long short-term memory (LSTM) model. Each scenario corresponds to an LSTM model. A scenario matching method is also proposed to find potential attack scenarios hiding in the real-time alerts from the database. Finally, MMSP feeds fractionated alerts into the matched scenarios' LSTM models to predict attack steps. Extensive evaluations based on real-world datasets show that MMSP outperforms the state-of-the-art attack step prediction model in both single and mixed scenarios. MMSP achieves a 14.3 % -38.1 % improvement in accuracy for attack step prediction in the single scenario. In particular, MMSP can maintain a high level accuracy in mixed attack scenarios. Degang Sun, Leiqi Wang, Qiujian Lv, Yan Wang 0081 |
ISCC | 5 |
| 2022 | Implicit Continuous Authentication Model Based on Mobile Terminal Touch BehaviorabstractMost existing identity authentication technologies rely on some ways for the first login authentication, such as personal identification number (PIN), track, or biological characteristics. However, these ways exist plenty of security risks, which make people face password guessing attacks, trace attacks, and shoulder surfing attacks for a long time. Once the illegal users forge identity to complete authentication or bypass first login authentication, their subsequent behavior will become out of control. To solve the above problems, we propose an implicit continuous authentication model based on the touch behavior of the mobile terminal. The model uses the data collected by the accelerometer, gyroscope, and magnetometer to generate feature vectors and extracts the feature vectors containing macroscopic features, microscopic features, and joint features. And we design a convolutional bidirectional recurrent neural network model to distinguish the sensor feature vectors. On this basis, we perform various experiments on a large dataset Hand Movement, Orientation, and Grasp (HMOG) with different sensor characteristics. Compared with the most advanced models proposed recently, the results show that our model achieves an equal error rate (EER) of 0.53%, which significantly improves authentication accuracy. Rui Mao 0004, Heming Ji, Yan Wang 0081, Degang Sun |
ISCC | 5 |
| 2022 | DGQAN: Dual Graph Question-Answer Attention Networks for Answer SelectionabstractCommunity question answering (CQA) becomes increasingly prevalent in recent years, providing platforms for users with various backgrounds to obtain information and share knowledge. However, the redundancy and lengthiness issues of crowd-sourced answers limit the performance of answer selection, thus leading to difficulties in reading or even misunderstandings for community users. To solve these problems, we propose the dual graph question-answer attention networks (DGQAN) for answer selection task. Aims to fully understand the internal structure of the question and the corresponding answer, firstly, we construct a dual-CQA concept graph with graph convolution networks using the original question and answer text. Specifically, our CQA concept graph exploits the correlation information between question-answer pairs to construct two sub-graphs (QSubject-Answer and QBody-Answer), respectively. Further, a novel dual attention mechanism is incorporated to model both the internal and external semantic relations among questions and answers. More importantly, we conduct experiment to investigate the impact of each layer in the BERT model. The experimental results show that DGQAN model achieves state-of-the-art performance on three datasets (SemEval-2015, 2016, and 2017), outperforming all the baseline models. Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Weiqing Huang |
SIGIR | 3 |
| 2022 | A Software Security Entity Relationships Prediction Framework Based on Knowledge Graph Embedding Using Sentence-Bert
Yan Wang 0081, Xiaowei Hou, Xiu Ma, Qiujian Lv |
WASA (2) | 1 |
| 2022 | DMalNet: Dynamic malware analysis based on API feature engineering and graph learning
Leiqi Wang, Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 6 |
| 2022 | A novel deep framework for dynamic malware detection based on API sequence intrinsic features
Qiujian Lv, Yan Wang 0081, Degang Sun |
Comput. Secur. | 4 |
| 2022 | BertHANK: hierarchical attention networks with enhanced knowledge and pre-trained model for answer selection
Haitian Yang, Xuan Zhao 0011, Yan Wang 0081, Degang Sun, Weiqing Huang |
Knowl. Inf. Syst. | 3 |
| 2021 | BERTDAN: Question-Answer Dual Attention Fusion Networks with Pre-trained Models for Answer Selection
Haitian Yang, Chonghui Zheng, Xuan Zhao 0011, Yan Wang 0081, Weiqing Huang |
ICONIP (3) | 4 |
| 2021 | Sprelog: Log-Based Anomaly Detection with Self-matching Networks and Pre-trained Models
Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang |
ICSOC | 4 |
| 2021 | ITDBERT: Temporal-semantic Representation for Insider Threat DetectionabstractThe objective and universal nature of user behavior data make it the primary data for insider threat detection. Existing solutions treat user behavior as atomic symbols and do not consider behavior semantic information. Meanwhile, fine-grained temporal information is ignored despite its relevance to describe user behavior. Such approaches inevitably lead to unsatisfactory performance and generalization. In this paper, we propose ITDBERT which embeds temporal information into behavior and catches the fused semantic representation via pre-trained language models. ITDBERT also leverages attention-based Bi-LSTM to provide behavior-level detection results. To verify the effectiveness of our proposed method, we conduct comparison experiments on Cert datasets. Our proposed model achieves an F1-score of 0.9243 in day-level insider threat detection, which outperforms baselines. Weiqing Huang, Qiujian Lv, Yan Wang 0081, Haitian Yang |
ISCC | 5 |
| 2021 | GSketch: A Comprehensive Graph Analytic Approach for Masquerader Detection Based on File Access GraphabstractMasqueraders are a severe insider threat and have become a conventional security issue for most organizations. The majority of existing techniques for detecting masqueraders extract statistical features from file access logs. However, the graph's features from these logs have not been fully explored. In this work, we introduce GSketch. First, it divides each user's file access logs into equal length, non-overlapping time windows. Then file access logs on each time window are transformed into a graph according to chronological order. GSketch extracts global features and local features from the graph. Global features provide a panoramic view of the graph, and local features mine small, induced sub-graphs. Finally, GSketch applies an abnormal detection algorithm to find anomalous points in the feature space and marks these points as masquerader's activities. The effectiveness of GSketch is demonstrated by its excellent performances on two public datasets - WUIL and TWOS. Yan Wang 0081, Qiujian Lv, Meichen Liu, Tingting Wang 0010, Leiqi Wang |
ISCC | 3 |
| 2021 | FKTAN: Fusion Keystroke Time-Textual Attention Networks for Continuous AuthenticationabstractWith the rapid development of computer technology, the traditional Internet data security and information privacy issues are gradually expanding to all aspects of society as a whole. As the first line of defense for information security, identity authentication technology becomes crucial. Among the many authentication technologies, continuous authentication technology has gained increasing attention. In this paper, we design fusion keystroke time-textual attention networks for continuous authentication based on the keystroke data (keystroke time series, keystroke text) when users enter free-text. Specifically, the corresponding keystroke time series and the corresponding keystroke text are first obtained based on the original keystroke data, and then the keystroke time series and the keystroke text are input into the BiLSTM model and the pre-training model, respectively; the BiLSTM can better capture the temporal features, and the pre-training model can better capture the textual features when authenticating the user. Finally, the two information are fed into the cross attention model to better integrate the two information. Experiments show that the FKTAN model achieves promising results on two datasets, Clarkson II keystroke dataset and Buffalo dataset, outperforming all baseline models. Haitian Yang, Degang Sun, Yan Wang 0081, Weiqing Huang |
ISCC | 3 |
| 2021 | Multi-Modal fake news Detection on Social Media with Dual Attention Fusion NetworksabstractMost of the existed fake news detection works on social media driven-fake news mainly focused on text. However, more and more social media platforms like Twitter, facebook, etc, allow users to create multi-modal contents, including text, image and video. Hence, it is obvious that only investigating text contents is insufficient to achieve solid detection. In this paper, we study the fake news on social media platforms composed of multimodal contents (text and images), and propose Dual Attention Fusion Networks for fake news detection on social media. We explore three modalities, (text modality, image modality and image attributes modality), and further propose a Dual Attention Fusion Networks (DAFN) model for this task. First, our proposed model extracts text modality and image modality, respectively. We then pass combinations of image attributes modality and text modality through BERT to extract text features. Finally, we reconstruct features of three modalities and fuse them into a feature vector for prediction. Our method is verified on realworld datasets consisting of collected social media platforms. Experiments show that the our method achieves promising results on real world datasets. outperforming all baseline models. Haitian Yang, Xuan Zhao 0011, Degang Sun, Yan Wang 0081, Weiqing Huang |
ISCC | 4 |
| 2021 | AOPL: Attention Enhanced Oversampling and Parallel Deep Learning Model for Attack Detection in Imbalanced Network Traffic
Leiqi Wang, Weiqing Huang, Qiujian Lv, Yan Wang 0081 |
WASA (2) | 4 |
| 2020 | AMQAN: Adaptive Multi-Attention Question-Answer Networks for Answer Selection
Haitian Yang, Weiqing Huang, Xuan Zhao 0011, Yan Wang 0081, Yuyan Chen, Rui Mao 0004 |
ECML/PKDD (3) | 4 |
| 2019 | Risk Prediction for Imbalanced Data in Cyber Security : A Siamese Network-based Deep Learning Classification FrameworkabstractRisk prediction plays an important role in network security which can be used to predict riskiest parts and then proactive measures can be adopted to avoid potential damage. Most existing literature model risk prediction problems as binary classification problems by using machine learning methods. However, these traditional machine learning models have poor performance - tending to misclassify the risky ones into the category of risk-free - on risk prediction task when the datasets are imbalanced or small in size. In this paper, we propose a Siamese Network Classification Framework (SNCF) that can map the Siamese network to a classification based on the similarity to alleviate imbalance for risk prediction. Experimental results on imbalanced data in risk prediction verify that the deep learning-based classification architecture SNCF has better efficiency when compared with other algorithms. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
IJCNN | 3 |
| 2019 | Cyber Profiles Based Risk Prediction of Application Systems for Effective Access ControlabstractApplication systems maintain critical sensitive information of an enterprise and especially huge number of data with specific ownership. Unauthorized modification or deletion of data caused by cyber attacks may bring tremendous loses for enterprises. To reduce the damage of cyber attacks, existing techniques have been proposed to predict the potential risk of external attacks at the level of an enterprise, a user, or a machine. However, risk prediction has not been conducted at the level of application systems, which may suffer from external attacks or insider threats. This paper proposes a model based on machine learning to predict whether the application systems of an enterprise have the risk of unauthorized access by using a cyber profile. In particular, the cyber profile is composed of features extracted from the information of the three domains in cyberspace: Information Infrastructure domain, Data domain, and Application domain. The core idea of the model selects the most significant features that have a large impact on the occurrence of unauthorized access to application systems. At last, by using a limited number of selected features, high forecast accuracy is achieved. These results verify the effectiveness of the prediction model, which can potentially be exploited to guide the adjustment of access control policies for effective access control. Degang Sun, Zhengrong Wu, Yan Wang 0081, Qiujian Lv |
ISCC | 3 |
| 2018 | A Hybrid Model Based on Multi-dimensional Features for Insider Threat Detection
Yan Wang 0081, Qiujian Lv |
WASA | 3 |
| 2017 | BotTokenizer: Exploring Network Tokens of HTTP-Based Botnet Using Malicious Network Traces
Biao Qi, Zhixin Shi, Yan Wang 0081, Jizhi Wang |
Inscrypt | 3 |
| 2017 | Detecting Flooding DDoS Under Flash Crowds Based on Mondrian Forest
Degang Sun, Zhixin Shi, Yan Wang 0081 |
WASA | 4 |
| 2015 | An Improved NPCUSUM Method with Adaptive Sliding Window to Detect DDoS Attacks
Degang Sun, Wei-qing Huang, Yan Wang 0081 |
ICICS | 4 |