Yingjun Lin

dblp:65/6516 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
3since 2021 · last 2025
0009-0004-5749-2058ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 since 2021
YearPublicationVenuePosition
2025 CARD: Robustness-Preserving Transfer Learning for Network Intrusion Detection via Contrastive Adversarial Representation Distillation
abstract
Robust neural networks are essential to build network intrusion detection systems resilient to evasion attacks. Learning such models via adversarial training demands extensive labeled data and high model capacity, making it impractical in evolving, resource-constrained threat environments. Transfer learning (TL) uses pre-trained models to enhance downstream tasks, offering a promising mitigation approach. However, most TL approaches prioritize performance on clean examples without addressing robustness against adversarial examples and random variations. Our empirical study reveals that standard fine-tuning and distillation often yield accurate but not robust models, while the few existing adversarial TL provide limited robustness. In this paper, we propose a novel robustness-preserving TL framework, Contrastive Adversarial Representation Distillation (CARD), to generate a robust target model by transferring robustness and performance from a robust source model into the target task. CARD tackles three issues: (i) target domain data scarcity; (ii) differences in data domains and model architectures between target and source tasks; and (iii) target model robustness against static and adaptive evasion attacks, and natural corruptions. Experiments on binary and multiclass detection show that CARD outperforms state-of-the-art methods in various TL tasks across data domains and model architectures when only 5% training data is available, achieving 17.67% and 8.38% higher adversarial robust accuracy as well as 9.75% and 11.42% higher natural robust accuracy than adversarial fine-tuning and distillation.
Mengdie Huang, Yingjun Lin, Ninghui Li 0001, Xiaofeng Chen 0001, Elisa Bertino
IEEE Trans. Dependable Secur. Comput.2
2025 Dimensional Robustness Certification for Deep Neural Networks in Network Intrusion Detection Systems
abstract
Network intrusion detection systems based on deep learning are gaining significant traction in cyber security due to their high prediction accuracy and strong adaptability to evolving cyber threats. However, a serious drawback is their vulnerability to evasion attacks that rely on adversarial examples. To provide robustness guarantees for deep neural networks against any possible perturbations, certified defenses against perturbations within a l p -bounded region around the input are being increasingly explored. Unfortunately, unlike existing image domain approaches that concentrate on homogeneous input feature spaces, the progress on certified defense for the network traffic domain, which is characterized by heterogeneous features, has been very limited. To address such a gap, we present the design and practicality of a novel framework, Multi-order Adaptive Randomized Smoothing (MARS), for certifying the robustness of network intrusion detectors based on deep neural networks. Experiments on various network intrusion detection systems show that MARS significantly improves the tightness of robustness certification (12.23% increase in l 2 certified radius), detection accuracy on evasion attack (7.17% improvement on \(l_{\infty }\) -PGD, 10.11% improvement on l 1 -EAD), and prediction accuracy on natural corruption (16.65% enhancement on latency, 18.23% enhancement on packet loss) compared to the SOTA method. We have also conducted an extensive analysis of the dimension-wise certified robustness of the network intrusion detector. The results indicate that the dimensional certified radii obtained using MARS reveal the robustness differences across feature dimensions, aligning with the empirical evaluation findings.
Mengdie Huang, Yingjun Lin, Xiaofeng Chen 0001, Elisa Bertino
ACM Trans. Priv. Secur.2
2024 MARS: Robustness Certification for Deep Network Intrusion Detectors via Multi-Order Adaptive Randomized Smoothing
abstract
Network intrusion detectors based on deep learning have high detection accuracy and the ability to adapt to evolving cyber threats. However, a serious drawback is their vulnerability to adversarial example attacks aimed at evading detectors and natural corruptions caused by random noise in the network environment. To provide robustness guarantees for deep neural networks against various perturbations, certified defenses against any possible perturbed inputs in the lp-bounded region are gaining attention. mHowever, unlike existing approaches that focus on homogeneous image feature spaces, the progress on certified defense for the network traffic domain, which is characterized by heterogeneous features, has been very limited. To address such a gap, we propose a novel framework, Multi-order Adaptive Randomized Smoothing (MARS), for certifying the robustness of network intrusion detectors. Experiments on various deep learning-based network intrusion detector architectures show that MARS significantly improves the certification tightness (12.23% average increase in the l2certified radius), evasion attack detection accuracy (7.17% improvement on l∞-PGD, 10.11% improvement on l1-EAD), and natural corruption detection accuracy (16.65% enhancement on latency, 18.23% enhancement on packet loss) compared to BARS, the leading and only certified defense for network intrusion detectors.
Mengdie Huang, Yingjun Lin, Xiaofeng Chen 0001, Elisa Bertino
TrustCom2
2005 A Scalable and Reliable Multiple Home Regions Based Location Service in Mobile Ad Hoc Networks
Guojun Wang 0001, Yingjun Lin, Minyi Guo
EUC2