EDBT 2026 Demo / reviewers in the wild / expert
Kai Tan 0007
dblp:63/2156-7
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0009-0002-7149-4637ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-author · 4 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DA-MLAD: Drift-Decomposed Meta-Learning for Continual Log Anomaly Detection in Supercomputing Systems
Kai Tan 0007, Yangliu Du, Dongyang Zhan, Haining Yu |
ICS | 1 |
| 2026 | Semantic Curriculum for Anomaly Detection: A Unified Language-Driven Meta-Optimization Framework
Kai Tan 0007, Yangliu Du, Dongyang Zhan, Haining Yu, Zhaofeng Yu, Wenqi Zhang 0006 |
INFOCOM | 1 |
| 2025 | ChatGPT in threefold: As attacker, target, and evaluator in adversarial attacks
Yunting Zhang, Kai Tan 0007, Zeshu Tian, Baisong Li, Hongli Zhang 0001 |
Neurocomputing | 3 |
| 2025 | A high-performance real-time container file monitoring approach based on virtual machine introspection
Kai Tan 0007, Dongyang Zhan, Hongli Zhang 0001, Binxing Fang, Zhihong Tian 0001 |
J. Supercomput. | 1 |
| 2024 | Multi-Stage Defense: Enhancing Robustness in Sequence-Based Log Anomaly DetectionabstractSequence-based deep learning models are commonly used to detect anomalies in system logs to ensure the security of communication and information systems. However, recent research has shown that adversarial attack methods against these detection models reveal their vulnerabilities. Attackers can bypass these sequence-based classifiers by tampering with the sequence (e.g., adding or replacing sequence events). In this paper, we propose a novel Multi-Stage Defensive strategy for sequence-based log anomaly detection aimed at combating adversarial attacks. Systematically integrated, this strategy spans the entire detection process, from data embedding representation to anomaly classification, thereby forming a robust defensive approach that is strategically orchestrated to ensure comprehensive protection against a variety of adversarial attacks. Firstly, we compress the semantic feature space of sequences to enhance the anti-interference ability of attack operations on substitution sequences. Then, we propose a novel adaptive sparse multi-head attention mechanism to improve the Transformer model, allowing it to adaptively extract different key patterns in the sequence, thus eliminating irrelevant sequence events added in adversarial sequences. Our approach also integrates the learning of temporal patterns, offering enhanced robustness against deletion operations. Through extensive experiments on two public datasets, the experimental results demonstrate that our approach has high detection performance and robustness against different adversarial attacks. Kai Tan 0007, Dongyang Zhan, Zhaofeng Yu, Hongli Zhang 0001, Binxing Fang |
ICC | 1 |
| 2024 | A Practical Adversarial Attack Against Sequence-Based Deep Learning Malware ClassifiersabstractSequence-based deep learning models (e.g., RNNs), can detect malware by analyzing its behavioral sequences. Meanwhile, these models are susceptible to adversarial attacks. Attackers can create adversarial samples that alter the sequence characteristics of behavior sequences to deceive malware classifiers. The existing methods for generating adversarial samples typically involve deleting or replacing crucial behaviors in the original data sequences, or inserting benign behaviors that may violate the behavior constraints. However, these methods that directly manipulate sequences make adversarial samples difficult to implement or apply in practice. In this paper, we propose an adversarial attack approach based on Deep Q-Network and a heuristic backtracking search strategy, which can generate perturbation sequences that satisfy practical conditions for successful attacks. Subsequently, we utilize a novel transformation approach that maps modifications back to the source code, thereby avoiding the need to directly modify the behavior log sequences. We conduct an evaluation of our approach, and the results confirm its effectiveness in generating adversarial samples from real-world malware behavior sequences, which have a high success rate in evading anomaly detection models. Furthermore, our approach is practical and can generate adversarial samples while maintaining the functionality of the modified software. Kai Tan 0007, Dongyang Zhan, Hongli Zhang 0001, Binxing Fang |
IEEE Trans. Computers | 1 |
| 2023 | An Adversarial Robust Behavior Sequence Anomaly Detection Approach Based on Critical Behavior Unit LearningabstractSequential deep learning models (e.g., RNN and LSTM) can learn the sequence features of software behaviors, such as API or syscall sequences. However, recent studies have shown that these deep learning-based approaches are vulnerable to adversarial samples. Attackers can use adversarial samples to change the sequential characteristics of behavior sequences and mislead malware classifiers. In this paper, an adversarial robustness anomaly detection method based on the analysis of behavior units is proposed to overcome this problem. We extract related behaviors that usually perform a behavior intention as a behavior unit, which contains the representative semantic information of local behaviors and can be used to improve the robustness of behavior analysis. By learning the overall semantics of each behavior unit and the contextual relationships among behavior units based on a multilevel deep learning model, our approach can mitigate perturbation attacks that target local and large-scale behaviors. In addition, our approach can be applied to both low-level and high-level behavior logs (e.g., API and syscall logs). The experimental results show that our approach outperforms all the compared methods, which indicates that our approach has better performance against obfuscation attacks. Dongyang Zhan, Kai Tan 0007, Xiangzhan Yu, Hongli Zhang 0001 |
IEEE Trans. Computers | 2 |