EDBT 2026 Demo / reviewers in the wild / expert
Wenbo Fang
dblp:63/7666
· DBLP profile ↗
22ranked-venue papers
3as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Computer networks · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ProActive-Shard: A GNN and RL-Enabled Proactive Sharding Framework for Load Balancing in Blockchain
Yuetong Weng, Wenbo Fang, Yumin Yuan, Junjiang He |
ICIC (26) | 5 |
| 2026 | Generating Black-Box Adversarial Examples for Industrial Control Systems via Immune Co-Evolution
Chenyi Huang, Junjiang He, Wenshan Li 0001, Tao Li 0016, Wengang Ma, Wenbo Fang, Xiaolong Lan |
IEEE Internet Things J. | 6 |
| 2026 | A feature selection method based on clonal selection with beneficial noise
Wenshan Li 0001, Chenyi Huang, Ao Liu 0005, Beibei Li 0002, Junjiang He, Wenbo Fang |
Pattern Recognit. | 7 |
| 2026 | Exploratory Detection of Unknown Cyber-Attacks via Evolutionary Strategy and Machine LearningabstractWith the open-source development of cyber-attack technologies, attackers’ ability to modify existing strategies and exploit vulnerabilities has increased, leading to numerous unknown cyber-attacks. Traditional detection methods face two main challenges: (a) requiring abundant labeled attack samples, which deep learning-based detection methods find difficult to obtain in practice, and (b) struggling to effectively detect novel and previously unseen attacks, especially those that are unknown. In this paper, we propose Exploratory Detection of Unknown Cyber-Attacks via Evolutionary Strategy and Machine Learning. Specifically, firstly, we train kernel-based Ramp-OCSVM models on full features of known attacks to derive class-specific thresholds, while inferring unknown attack thresholds via Gaussian distribution. Next, we define known sample features as “genes” and generate evolutionary feature representations through multi-strategy evolution. Subsequently, these features are processed by the trained Ramp-OCSVM and the thresholds to separate known-attack variants from unknown samples. Finally, we iteratively train a RF classifier using evolved features, selecting the optimal iteration-trained model based on detection performance. We conducted extensive experiments on authoritative datasets. The results achieves F1 scores of 82.70% and 87.64% for detecting unknown attack under different configurations. The mean F1 scores improve to 99.84% and 95.80% for detecting known and unknown attacks in the few-shot learning scenario. Compared to SOTA methods, our proposed method achieves an increase of 2.19% in the F1 score, while demonstrating 53.99% higher F1-score than detection methods via GAN and VAE. Wenbo Fang, Sunjun Liu, Linlin Zhang 0005, Menghao Ao, Qikai Wang, Junjiang He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | GPBFT: A Dynamic Reputation and Group-Optimized PBFT for Scalable Consortium Blockchains
Shusen Zhang, Wenshou Wu, Xuehua Bi, Wenbo Fang |
ICA3PP (6) | 5 |
| 2025 | AugGP-VD: A Smart Contract Vulnerability Detection Approach Based on Augmented Graph Convolutional Networks and Pooling
Nianlu Liu, Wenbo Fang |
ICICS (3) | 3 |
| 2025 | Weak Population-Empowered Large-Scale Multiobjective Immune AlgorithmabstractThe multiobjective immune optimization algorithms (MOIAs) utilize the principle of clonal selection, iteratively evolving by replicating a small number of superior solutions to optimize decision vectors. However, this method often leads to a lack of diversity and is particularly ineffective when facing large‐scale optimization problems. Moreover, an overemphasis on elite solutions may result in a large number of redundant offspring, reducing evolutionary efficiency. By delving into the causes of these issues, we find that a key factor is that existing algorithms overlook the role of weak solutions during the evolutionary process. With this in mind, we propose a weak population–empowered large‐scale multiobjective immune algorithm (WP–MOIA). The core of this algorithm is to construct, in addition to the traditional elite population, a cooperative evolutionary population based on a portion of the remaining solutions, referred to as the weak population. During the evolution, both populations work together: the elite population maximizes its advantageous status for local searches, focusing on exploitation, while the weak population seeks greater variation to escape its disadvantaged position, engaging in broader exploration. At the same time, the sizes of both populations are dynamically adjusted to collaboratively maintain the balance of evolution. Through comparisons with nine state‐of‐the‐art multiobjective evolutionary algorithms (MOEAs) and four powerful MOIAs on 30 benchmark problems, the proposed algorithm demonstrates superior performance in both small‐scale and large‐scale multiobjective optimization problems (MOPs), and exhibits better convergence efficiency. Especially in large‐scale MOPs, the new algorithm’s performance nearly surpasses all 13 advanced algorithms being compared. Wenshan Li 0001, Junjiang He, Tao Li 0016, Wenbo Fang, Xiaolong Lan |
Int. J. Intell. Syst. | 5 |
| 2025 | NSA-AE: An inadequately represented immune spaces NSA augmented via autoencoders
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
Neurocomputing | 4 |
| 2025 | Defending Against APT Attacks in Cloud Computing Environments Using Grouped Multiagent Deep Reinforcement LearningabstractAdvanced persistent threats (APTs) pose a significant challenge to cloud computing security in the evolving landscape of cyber threats. Traditional defense models rely heavily on the attacker’s historical attack information, which greatly limits the effectiveness of actually dealing with APT attacks. To address this issues, we investigate an attack-defense game model in clouding computing environments, where multiple attackers and multiple defenders are supposed to compete for resource allocation on the cloud servers. In order to develop more effective defense strategies, we formulate the optimization problem to maximize the average rewards of defenders under constraints of the maximum available resource and acceptable cost. To solve this, we propose to use the multiagent deep reinforcement learning (RL) method to cope with the high uncertainty and dynamics of attack behavior. Then it is proposed to divide all defenders into cooperative groups and allow defenders within each group can jointly optimize the defense strategy through sharing information and experience. On this basis, we propose a novel grouped multiagent deep RL defense (GMADRLD) algorithm, which can effectively mitigate the issue of state space explosion while achieving good defense effect. Simulation results not only demonstrate the effectiveness of the proposed GMADRLD algorithm in dealing with the attacker’s ever-changing strategies, but also show that it is able to strike a balance between defense performance and computational complexity. Xiaolong Lan, Wengang Ma, Wenbo Fang, Junjiang He |
IEEE Internet Things J. | 5 |
| 2025 | CSCAD: An Adaptive LightGBM Algorithm to Detect Cache Side-Channel AttacksabstractCache side-channel attacks have become more sophisticated and more destructive to the security of computer architectures and cloud platforms than ever before, resulting in the leakage of privacy information. Prior efforts focused on designing countermeasures instead of timely detection. To address the challenges introduced by cache side-channel attacks, anomaly detection and feature detection were proposed. However, these methods have drawbacks in terms of computational performance and detection effectiveness. In this article, we proposed Cache Side-Channel Attack Detector(CSCAD), a novel tool for detecting cache side-channel attacks against memory events in real time. Specifically, we design a collector using Hardware Performance Counters and use improved Maximum Information Coefficient to generate feature vectors. Meanwhile, an adaptive genetic algorithm with crossover and mutation probability is proposed to optimize hyperparameters of LightGBM. Additionally, an adaptive loss function weight model with low overhead is introduced to enhance efficiency of attack detection. It is encouraging to see that CSCAD achieved a recall of 98.14%. In detecting 1000 samples, it boosted the detection speed by approximately 75% compared to conventional machine learning methods. CSCAD has outperformed the state-of-the-art methods by simultaneously achieving excellent detection speed and effectiveness. Sirui Hao, Junjiang He, Wenshan Li 0001, Tao Li 0016, Geying Yang, Wenbo Fang, Wanying Chen |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Unknown Cyber Threat Discovery Empowered by Genetic Evolution Without Prior KnowledgeabstractWith the continuous development of cyber-attack technologies, attackers increasingly exploit zero-day vulnerabilities or leverage emerging techniques to launch sophisticated attacks, resulting in the persistent emergence of unknown cyber-attacks. However, traditional DL-based cyber-attack detection methods heavily rely on large-scale labeled training data. In practice, obtaining sufficient samples of unknown attacks is challenging, which makes it difficult for these methods to effectively defend against unknown cyber-attacks. In this paper, we propose a method for discovering unknown cyber threats empowered by genetic evolution without prior knowledge. Specifically, We, first mapped the network feature space into a gene framework, and divided the attack genes into a static gene region (SGZ) and a dynamic gene region (DGZ) according to the importance of the cyber-attack genes. Subsequently, leveraging the known attack genes, we utilized different gene evolution strategies and a Convolutional Autoencoder (CAE) to generate attack variants and potential unknown attack genes. Finally, we constructed a cyber-attack detection model incorporating both the global attention mechanism (GAM) and the local attention mechanism (LAM). The generated attack variants and unknown attack genes are the used to enhance the detection ability of the detection model for variants and unknown cyber-attacks. We conducted a large number of experiments on six real and authoritative network datasets. The experimental results show that in different scenario settings, the F1 scores of our proposed method for detecting unknown attacks are 84.64% and 95.77% respectively. The F1 score for detecting unknown attacks on the UNSW-NB15 dataset exceeds that of the baseline classifier. The F1 score for detecting unknown attacks on the CSE-CIC-IDS2018 dataset is 98.85%. In comparison with SOTA methods, the average F1 score is improved by 3.14%. In the evaluation of variant detection performance, the generation method we proposed improves the detection of variants by approximately 11.2%, surpassing generation methods such as the Conditional Generative Adversarial Network (CGAN) and the Variational Autoencoder (VAE). Meanwhile, we also comprehensively evaluated the generalization ability of our proposed method and the evolution ability of different evolution strategies on different datasets and through ablation experiments. Wenbo Fang, Junjiang He, Wenshan Li 0001, Wengang Ma, Linlin Zhang 0005, Xiaolong Lan, Geying Yang, Jiangchuan Chen, Tao Li 0016 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Automatic penetration testing model based on reinforcement learning for complex network environments
Junjiang He, Wenbo Fang, Shenwen Yang, Jiangchuan Chen, Tao Li 0016, Xiaolong Lan |
J. Supercomput. | 3 |
| 2024 | Auto-TFCE: Automatic Traffic Feature Code Extraction Method and Its Application in Cyber Security
Junjiang He, Jiayan Wang, Jiangchuan Chen, Wenbo Fang, Tao Li 0016 |
ICDF2C (2) | 4 |
| 2024 | SPAW-SMOTE: Space Partitioning Adaptive Weighted Synthetic Minority Oversampling Technique For Imbalanced Data Set LearningabstractAbstract The problem of data imbalance is common in reality, which greatly affects the performance of classifiers. Most of the solutions are to balance the data set by generating new minority class samples, which are faced with the problems of selecting the appropriate area for generating samples, fuzzy classification boundary and uneven distribution of samples. To solve these problems, we propose a novel oversampling algorithm named space partitioning adaptive weighted synthetic minority oversampling technique (SPAW-SMOTE). We first divide the data space into boundary space and non-boundary space based on spatial partitioning techniques. The number of samples to be generated is assigned to different spaces by the designed adaptive weighting algorithm, which is used to solve the problems of uneven distribution of samples and easy to blur the classification boundary. Finally, we also endeavor to develop a new generation algorithm to reduce the probability of overlapping samples generated when synthesizing new samples and to ensure the diversity of new samples. Experimental results on 18 real-world data sets show that the average performance (G-mean, F1-measure and Area Under Curve) of SPAW-SMOTE is significantly better than other existing oversampling techniques. Junjiang He, Tao Li 0016, Xiaolong Lan, Wenbo Fang |
Comput. J. | 5 |
| 2024 | SynDroid: An adaptive enhanced Android malware classification method based on CTGAN-SVM
Junjiang He, Wenshan Li 0001, Wenbo Fang, Geying Yang, Tao Li 0016 |
Comput. Secur. | 4 |
| 2024 | Two-stage video anomaly detection based on dual-stream networks and multi-instance learningabstractAbstract To promptly detect abnormal events in surveillance videos, this article designs a video anomaly detection method based on multiple instance learning. Generally, abnormal events occur less frequently compared to normal events. Traditional video surveillance relies on manual operation to monitor scenes and detect abnormal events by watching surveillance videos. However, watching surveillance footage is a labor‐intensive task, and prolonged observation can lead to visual fatigue and lack of concentration, which in turn results in missed detections and false positives [1]. Therefore, it is crucial to develop intelligent algorithms for video anomaly detection. The method can detect whether segments of a video contain abnormal events. First, the I3D network is used as a feature extractor to capture spatiotemporal features from the input video. Then, the spatiotemporal information is processed and input into a segment‐level anomaly detector based on multiple instance learning for detection. The authors treat abnormal videos as positive bags and normal videos as negative bags, and automatically learn a deep anomaly ranking model that can predict abnormal segments. Finally, the results of the training were tested and analyzed, demonstrating that the model is capable of detecting abnormal traffic segments. Dejun Zhang, Wenbo Fang, Zirong Lyu, Chen Xiong |
IET Image Process. | 2 |
| 2024 | Efficient Based on Improved Random Forest Defense System Against Application-Layer DDoS AttacksabstractApplication‐layer distributed denial of service (DDoS) attacks have become the main threat to Web server security. Because application‐layer DDoS attacks have strong concealability and high authenticity, intrusion detection technologies that rely solely on judging client authenticity cannot accurately detect such attacks. In addition, application‐layer DDoS attacks are periodic and repetitive, and attack targets suddenly in a short period. In this study, we propose an efficient application‐layer DDoS detection system based on improved random forest. Firstly, the Web logs are preprocessed to extract the user session characteristics. Subsequently, we propose a Session Identification based on Separation and Aggregation (SISA) method to accurately capture user sessions. Lastly, we propose an improved random forest classification algorithm based on feature weighting to address the issue of an increasing number of features leading to prolonged calculation times in the random forest algorithm, and as the feature dimension increases, there might be instances where no subfeature is related to the category to be classified. More importantly, we compare the request source IP with the malicious IP in the threat intelligence library to deal with the periodicity and repetition of application‐layer DDoS attacks. We conducted a comprehensive experiment on the publicly available Web log dataset and the threat intelligence database of the laboratory as well as the simulated generated attack log dataset in the laboratory environment. The experimental results show that the proposed detection system can control the false alarm rate and false alarm rate within a reasonable range, improving the detection efficiency further, the detection rate is 99.85%. In secondary attack detection experiments, our proposed detection method achieves a higher detection rate in a shorter time. Junjiang He, Wenbo Fang, Xiaolong Lan, Geying Yang, Tao Li 0016, Jiangchuan Chen |
Int. J. Intell. Syst. | 2 |
| 2024 | A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine DistributionabstractUnmanned aerial vehicles (UAVs) have experienced rapid development, permeating diverse domains. However, addressing security challenges in UAV networks remains daunting due to resource limitations and the high autonomy of UAV terminals. The current research on the UAV network intrusion detection lacks an efficient process covering each UAV terminal and a lightweight collaborative response mechanism between the UAVs and ground stations, which affects the performance of the UAV network intrusion detection. In this article, inspired by the vaccine distribution mechanism in artificial immune systems, we propose a hierarchical UAV network intrusion detection and response approach based on the vaccine distribution. Specifically, we first implement an immune game-based negative selection algorithm at the ground station, to effectively generate vaccines covering the immune space. Then, we distribute vaccines to the UAV terminals, empowering them with intrusion detection capabilities. Finally, we introduce a collaborative response mechanism to enable the intrusion detection at the UAV terminals and perform terminal state assessments. We evaluate the performance of our proposed approach on a large number of the real UAV network data sets. The experimental results indicate that our proposed intrusion detection approach for the UAV networks at the ground stations surpasses all the baseline models. In scenarios involving air-ground coordination, our suggested collaborative response approach proves to be effective in enabling intrusion detection at the UAV terminal, facilitating timely and efficient UAV intrusion detection. Moreover, we demonstrate on the ALFA and NSL-KDD data sets that our approach excels in detecting UAV network intrusions. Particularly, on real UAV network data (ALFA), the detection rate reaches 99.05% and the accuracy is 96.13% surpassing the other models by approximately 6%. Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 4 |
| 2024 | Corrections to "A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution"abstractPresents corrections to the paper, (Corrections to “A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution”). Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016 |
IEEE Internet Things J. | 4 |
| 2024 | A fast dual-module hybrid high-dimensional feature selection algorithm
Geying Yang, Junjiang He, Xiaolong Lan, Tao Li 0016, Wenbo Fang |
Inf. Sci. | 5 |
| 2023 | An Attack Entity Deducing Model for Attack Forensics
Junjiang He, Tao Li 0016, Wenbo Fang, Wenshan Li 0001, Cong Tang |
ICONIP (15) | 4 |
| 2023 | Comprehensive Android Malware Detection Based on Federated Learning ArchitectureabstractAndroid malware and its variants are a major challenge for mobile platforms. However, there are two main problems in the existing detection methods:a) The detection method lacks the evolution ability for Android malware, which leads to the low detection rate of the detection model for malware and its variants.b) Traditional detection methods require centralized data for model training, however, the aggregation of training samples is limited due to the infectivity of malware and growing data privacy concerns, centralized detection methods are difficult to be applied in actual detection scenarios. In this paper, we propose FEDriod, a comprehensive Android malware detection method based on federated learning architecture that protects against growing Android malware or emerging Android malware variants. Specifically, we employ genetic evolution strategy to simulate the evolution of Android malware and develop potential malware variants from typical Android malware. Then, we customize the Android malware detection model based on residual neural network to achieve high detection accuracy. Finally, to achieve the protection sensitive data, we develope a federated learning framework to allows multiple Android malware detection agencies to jointly build a comprehensive Android malware detection model. We comprehensively evaluate the performance of FEDriod on the CIC, Drebin, and Contagio authoritative datasets. Experimental results show that our local model outperforms all baseline classifiers. In the federal scenario, our proposed method is superior to the state-of-the-art detection methods, especially in the cross-dataset evaluation, the F1 of FEDriod is 98.53%. More important, we performed genetic evolution experiments on the Drebin dataset, and the results showed that our proposed method has the ability to detect Android malware variants. Wenbo Fang, Junjiang He, Wenshan Li 0001, Xiaolong Lan, Tao Li 0016, Jiwu Huang, Linlin Zhang 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |