EDBT 2026 Demo / reviewers in the wild / expert
Hao Hu 0005
dblp:67/6924-5
· DBLP profile ↗
20ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0003-4888-6368ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 3 first-author · 7 since 2021Computer networks · 5 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An improved transformer for entity recognition in chinese cyber threat intelligence reportsabstractAbstract Extracting Chinese Cyber Threat Intelligence (CTI) under increasingly complex advanced persistent threat scenarios is crucial, yet challenging due to domain-specific term ambiguity and frequent long, nested entities. To address polysemy, nested-label conflicts, and cross-sentence semantic discontinuity, we propose an enhanced Transformer-based entity recognition method formulated as a pointer network. On the encoder side, we build a RoBERTa model with Rotary Positional Embeddings. To handle complex positions and boundaries of heterogeneous entity types, we introduce tokenization compensation and positional-parameter compression to sharpen boundary sensitivity. In the decoder, we refine GlobalPointer and model recognition as 2D head–tail span matching, enabling direct detection of overlapping and nested entities. To mitigate long-tail bias, we introduce an entity-frequency-aware dynamic threshold and a reweighted zero-boundary log-loss to improve recall for rare entities. Experiments demonstrate an overall F1 improvement of 6.32% over baselines on Chinese CTI datasets, with absolute gains reaching 19.7% specifically on nested and long entities. These results validate the model’s effectiveness in Chinese-specific named entity recognition and its utility for high-accuracy automated CTI analysis. Jipeng Tang, Hao Hu 0005, Yixiao Peng, Feiyang Li |
Cybersecur. | 3 |
| 2026 | FusionITD: enhanced cross-modal insider threat perception framework via behavior-semantic fusionabstractAbstract In recent years, insider threat incidents have occurred with increasing frequency, leading to severe data breaches and substantial economic losses. Most existing insider threat detection methods rely primarily on single-modal features, such as system logs and registry data, while failing to fully exploit the rich semantic information embedded in instant messaging and email content of insider users. To address the above issues, we propose FusionITD, a cross-modal insider threat perception enhancement framework based on the fusion of behavioral and semantic features. This framework combines users’ temporal behavioral characteristics such as file operations and login device patterns with the semantic information derived from web browsing and email content. By modeling user behavior baselines from multiple dimensions, FusionITD enables more accurate anomaly detection when deviations from the baseline occur. Firstly, based on the temporal distribution of user behaviors, the behavior data is segmented and aggregated according to the time window to form a user behavior graph. We propose WR-GNN based on graph representation learning to capture temporal behavioral features, and introduce the Focal MSE loss function to address the data imbalance problem caused by sparse abnormal behavior data. Secondly, we propose a retrieval-augmented generation-based semantic analysis algorithm. We use cosine similarity to perform semantic matching and ranking between behavioral contents and historical behaviors. We extract features such as emotion, intention, and focus to achieve fine-grained anomaly detection for user behavior. Finally, we designed an adaptive weighting mechanism based on logistic regression to dynamically integrate the outputs of the previous two parts, enhancing the generalization ability for different threat scenarios. Experimental results conducted on the CERT datasets show that FusionITD outperforms other methods by achieving a 5% increase in AUC, a higher TPR, and a lower false positive rate. Lu Yuan 0002, Dexian Chang, Hao Hu 0005, Yingchang Jiang, Heyu Chang, Liguo Fang |
Cybersecur. | 3 |
| 2026 | Attack Path Planning in 5G-ICPS Penetration Testing: Leveraging TGNN and DRL for Large-Scale NetworkabstractPath planning constitutes a critical component of penetration testing for 5G-ICPS networks. The diversity of interfaces and protocols necessitates deep analysis of vulnerability exploitation methods and cross-protocol combination strategies, significantly increasing attack path planning complexity. Furthermore, dynamic network slice configurations and physical-information coupling effects drive continuous topological evolution, causing state-space explosion and challenging path planning under uncertainty with incomplete information. To address these issues, we construct a temporal attack graph modeling 5G-ICPS attack processes, and design a GraphSAGE-based environment representation encoder. This encoder undergoes multi-tiered self-supervised pre-training, employing node-level and graph-level training to encode diverse reinforcement learning environments across attack scenarios into fixed-dimensional vector representations. This achieves decoupling from underlying topology, vulnerability specifics, and security configurations, effectively mitigating state-space explosion in large-scale networks. Subsequently, we cluster highly similar vulnerabilities and filter invalid attack actions using three typical 5G-ICPS attack constraints, compressing the agent’s exploration space. Especially, we design a customized reward function that dynamically incentivizes/penalizes actions based on compromised assets. Experimental results demonstrate significant improvements: penetration testing invalid action rates decrease from 22.3% to 7.5%, while average steps to achieve attack targets reduce by >54%. These advancements effectively reduce penetration testing costs and increase attack success rates. Feiyang Li, Hao Hu 0005, Yingchang Jiang, Yixiao Peng |
IEEE Internet Things J. | 2 |
| 2026 | Enhancing Cloud Network Resilience via a Robust LLM-Empowered Multi-Agent Reinforcement Learning FrameworkabstractWhile virtualization and resource pooling empower cloud networks with structural flexibility and elastic scalability, they inevitably expand the attack surface and challenge cyber resilience. Reinforcement Learning (RL)-based defense strategies have been developed to optimize resource deployment and isolation policies under adversarial conditions, aiming to enhance system resilience by maintaining and restoring network availability. However, existing approaches lack robustness as they require retraining to adapt to dynamic changes in network structure, node scale, attack strategies, and attack intensity. Furthermore, the lack of Human-in-the-Loop (HITL) support limits interpretability and flexibility. To address these limitations, we propose CyberOps-Bots, a hierarchical multi agent reinforcement learning framework empowered by Large Language Models (LLMs). Inspired by MITRE ATT&CK's “Tactics-Techniques” model, CyberOps-Bots features a two-layer architecture: (1) An upper-level LLM agent with four mod ules—ReAct planning, IPDRR-based perception, long-short term memory, and action/tool integration—performs global awareness, human intent recognition, and tactical planning; (2) Lower-level RL agents, developed via heterogeneous separated pre-training, execute atomic defense actions within localized network regions. This synergy preserves LLM adaptability and interpretability while ensuring reliable RL execution. Experiments on real cloud datasets show that, compared to state-of-the-art algorithms, CyberOps-Bots maintains network availability 68.5% higher and achieves a 34.7% jumpstart performance gain when shifting the scenarios without retraining. To our knowledge, this is the first study to establish a robust LLM-RL framework with HITL support for cloud defense. Yixiao Peng, Hao Hu 0005, Feiyang Li, Xinye Cao, Yingchang Jiang, Jipeng Tang, Guoshun Nan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | LLM4Game: Multi-agent reinforcement learning with knowledge injection for dynamic defense resource allocation in cloud storage
Yixiao Peng, Hao Hu 0005, Feiyang Li, Yingchang Jiang, Jipeng Tang |
Comput. Networks | 2 |
| 2023 | WF-MTD: Evolutionary Decision Method for Moving Target Defense Based on Wright-Fisher ProcessabstractThe limitations of the professional knowledge and cognitive capabilities of both attackers and defenders mean that moving target attack-defense conflicts are not completely rational, which makes it difficult to select optimal moving target defense strategies difficult for use in real-world attack-defense scenarios. Starting from the imperfect rationality of both attack-defense, we construct a Wright-Fisher process-based moving target defense strategy evolution model called WF-MTD. In our method, we introduce rationality parameters to describe the strategy learning capabilities of both the attacker and the defender. By solving for the evolutionarily stable equilibrium, we develop a method for selecting the optimal defense strategy for moving targets and describe the evolution trajectories of the attack-defense strategies. Our experimental results in our example of a typical network information system show that WF-MTD selects appropriate MTD strategies in different states along different attack paths, with good effectiveness and broad applicability. In addition, compared with no hopping strategy, fixed periodic route hopping strategy, and random periodic route hopping strategy, the route hopping strategy based on WF-MTD increase defense payoffs by 58.7%, 27.6%, and 24.6%, respectively. Jinglei Tan, Hao Hu 0005, Ruiqin Hu, Hengwei Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Reinforcement Learning using Reward Expectations in Scenarios with Aleatoric UncertaintiesabstractIn scenarios with aleatoric uncertainties, the reward got by an agent when executing the same action in the same state is random, which can reduce the stability and convergence speed of the reinforcement algorithms. However, in most scenarios, reward functions have regularity, and their expectations are determined, which can be got through models or sample statistics. This paper discusses the distribution relationship between reward functions and value functions in scenarios with aleatoric uncertainties and proves the feasibility of using reward expectations for reinforcement learning. Finally, experiments show that algorithms have better stability and convergence speed when using reward expectations than random rewards. Yifeng Sun, Hao Hu 0005, Weigui Huang |
CoG | 4 |
| 2022 | Cybersecurity Threat Assessment Integrating Qualitative Differential and Evolutionary GamesabstractMost current game theory-based cybersecurity analysis methods use traditional game models, which do not meet realistic conditions of continuous dynamic changes in attack-defense behaviors and decision makers without perfect rationality, and therefore they adapt with difficulty to the practical requirements of cybersecurity threat assessment. This paper draws on infectious disease dynamics methods to describe the cybersecurity threat propagation process. It constructs a dynamic game model of a cybersecurity threat based on continuous attack-defense confrontation and boundedly rational decision makers, combining qualitative differential and evolutionary game theories. Qualitative differential games are used to analyze the confrontation process of security threats, calculate attack-defense barriers, and construct a benchmark to measure the degree of a security threat. Evolutionary games are used to analyze the dynamic change of attack-defense strategy-selection probabilities based on replicator dynamics, and to deduce the evolutionary trajectory of the network security state. We then calculate the multidimensional Euclidean distance between the evolutionary trajectory and the attack-defense barrier metric benchmark, and use it as the basis for a dynamic threat assessment algorithm to improve the timeliness and objectivity of threat assessment. Simulation experiments show that the model and algorithm are effective and feasible. Hengwei Zhang, Jinglei Tan, Shirui Huang, Hao Hu 0005 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | Optimal temporospatial strategy selection approach to moving target defense: A FlipIt differential game model
Jinglei Tan, Hengwei Zhang, Hao Hu 0005, Zhenxiang Qin |
Comput. Secur. | 4 |
| 2021 | Optimal Network Defense Strategy Selection Method: A Stochastic Differential Game ModelabstractIn a real-world network confrontation process, attack and defense actions change rapidly and continuously. The network environment is complex and dynamically random. Therefore, attack and defense strategies are inevitably subject to random disturbances during their execution, and the transition of the network security state is affected accordingly. In this paper, we construct a network security state transition model by referring to the epidemic evolution process, use Gaussian noise to describe random effects during the strategy execution, and introduce a random disturbance intensity factor to describe the degree of random effects. On this basis, we establish an attack-defense stochastic differential game model, propose a saddle point equilibrium solution method, and provide an algorithm to select the optimal defense strategy. Our method achieves real-time defense decision-making in network attack-defense scenarios with random disturbances and has better real-time performance and practicality than current methods. Results of a simulation experiment show that our model and algorithm are effective and feasible. Hengwei Zhang, Hao Hu 0005, Jinglei Tan, Jindong Wang 0002 |
Secur. Commun. Networks | 3 |
| 2021 | An Adaptive IP Hopping Approach for Moving Target Defense Using a Light-Weight CNN DetectorabstractScanning attack is normally the first step of many other network attacks such as DDoS and propagation worm. Because of easy implementation and high returns, scanning attack especially cooperative scanning attack is widely used by hackers, which has become a serious threat to network security. In order to defend against scanning attack, this paper proposes an adaptive IP hopping in software defined network for moving target defense (MTD). In order to accurately respond to attacker’s behavior in real time, a light-weight convolutional neural network (CNN) detector composed of three convolutional modules and a judgment module is proposed to sense scanning attack. Input data of the detector is generated via designed packets sampling and data preprocess. The detection result of the detector is used to trigger IP hopping. In order to provide some fault tolerance for the CNN detector, IP hopping can also be triggered by a preset timer. The CNN driving adaptability is applied to a three-level hopping strategy to make the MTD system optimize its behavior according to real time attack. Experiments show that compared with existing technologies, our proposed method can significantly improve the defense effect to mitigate scanning attack and its subsequent attacks which are based on hit list. Hopping frequency of the proposed method is also lower than that of other methods, so the proposed method shows lower system overhead. Hao Hu 0005, Dexian Chang |
Secur. Commun. Networks | 2 |
| 2020 | Attack scenario reconstruction approach using attack graph and alert data mining
Hao Hu 0005, Jing Liu 0036, Jinglei Tan |
J. Inf. Secur. Appl. | 1 |
| 2020 | Optimal Timing Selection Approach to Moving Target Defense: A FlipIt Attack-Defense Game ModelabstractThe centralized control characteristics of software-defined networks (SDNs) make them susceptible to advanced persistent threats (APTs). Moving target defense, as an effective defense means, is constantly developing. It is difficult to effectively characterize an MTD attack and defense game with existing game models and effectively select the defense timing to balance SDN service quality and MTD decision-making benefits. From the hidden confrontation between the actual attack and defense sides, existing attack-defense scenarios are abstractly characterized and analyzed. Based on the APT attack process of the Cyber Kill Chain (CKC), a state transition model of the MTD attack surface based on the susceptible-infective-recuperative-malfunctioned (SIRM) infectious disease model is defined. An MTD attack-defense timing decision model based on the FlipIt game (FG-MTD) is constructed, which expands the static analysis in the traditional game to a dynamic continuous process. The Nash equilibrium of the proposed method is analyzed, and the optimal timing selection algorithm of the MTD is designed to provide decision support for the selection of MTD timing under moderate security. Finally, the application model is used to verify the model and method. Through numerical analysis, the timings of different types of attack-defense strategies are summarized. Jinglei Tan, Hengwei Zhang, Hao Hu 0005 |
Secur. Commun. Networks | 7 |
| 2020 | Optimal Decision Making Approach for Cyber Security Defense Using Evolutionary GameabstractAt present, there are many techniques for cyber security defense such as firewall, intrusion detection and cryptography. Despite decades of studies and experiences on this issue, there still exists a problem that we always pay great attention to technology while overlooking strategy. In the traditional warfare, the level of decision-making and the formulation of optimal strategies have a great effect on the warfare result. Similarly, the timeliness and quality of decision-making in cyber attack-defense also make great significance. Since the attackers and defenders are oppositional, the selection of optimal defense strategy with the maximum payoff is difficult. To solve this problem, the stochastic evolutionary game model is utilized to simulate the dynamic adversary of cyber attack-defense. We add the parameter λ to the Logit Quantal Response Dynamics (LQRD) equation to quantify the cognitive differences of real-world players. By calculating the evolutionary stable equilibrium, the best decision-making approach is proposed, which makes a balance between defense cost and benefit. Cases studies on ransomware indicate that the proposed approach can help the defender predict possible attack action, select the related optimal defense strategy over time, and gain the maximum defense payoff. Hao Hu 0005, Yi Liu 0012 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | GDM: A General Distributed Method for Cross-Domain Service Function Chain EmbeddingabstractEmerging technologies such as network function virtualization (NFV) and software defined networking (SDN) provide a promising way to implement service function chain (SFC), a chain-ordered set of network functions, to support heterogeneous network services through a shared substrate network. A major challenge in this respect is the SFC embedding with respect to constraints of physical resources. Furthermore, for practical purposes, SFC embedding across multiple domains becomes essential. This challenge is referred to as the cross-domain SFC embedding problem, which is intractable due to various reasons, such as the confidentiality of intra-domain information and the domain's local autonomy. In this paper, we propose GDM, a general distributed method for cross-domain SFC embedding. Besides preserving the privacy and autonomy of domains, GDM guarantees fair competition among domains while balancing loads among domains. It first partitions SFC by utilizing an algorithm that can be instantiated to support different embedding goals. Then it allows domains to embed their assigned segments following their policies. Finally, to improve the capability of the whole substrate network to accommodate more SFCs, it implements domain-level load balancing by migrating the deployed VNFs while avoiding excessive influence on the SFC embedding solution. Evaluation results demonstrate that our method performs better in improving acceptance ratio and optimizing domains' embedding goals compared to the existing methods, and it has better scalability. Yi Liu 0012, Dexian Chang, Hao Hu 0005 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2019 | Improved schemes for visual secret sharing based on random grids
Hao Hu 0005, Zhengxin Fu, Bin Yu 0003 |
Multim. Tools Appl. | 1 |
| 2018 | Security risk situation quantification method based on threat prediction for multimedia communication network
Hao Hu 0005, Yingjie Yang |
Multim. Tools Appl. | 1 |
| 2018 | Security Metric Methods for Network Multistep Attacks Using AMC and Big Data Correlation AnalysisabstractNetwork security metrics allow quantitatively evaluating the overall resilience of networked systems against attacks. From this aim, security metrics are of great importance to the security-related decision-making process of enterprises. In this paper, we employ absorbing Markov chain (AMC) to estimate the network security combining with the technique of big data correlation analysis. Specifically, we construct the model of AMC using a large amount of alert data to describe the scenario of multistep attacks in the real world. In addition, we implement big data correlation analysis to generate the transition probability matrix from alert stream, which defines the probabilities of transferring from one attack action to another according to a given scenario before reaching one of some attack targets. Based on the probability reasoning, two metric algorithms are designed to estimate the attack scenario as well as the attackers, namely, the expected number of visits (ENV) and the expected success probability (ESP). The superiority is that the proposed model and algorithms assist the administrator in building new scenarios, prioritizing alerts, and ranking them. Hao Hu 0005 |
Secur. Commun. Networks | 1 |
| 2017 | Quantitative Method for Network Security Situation Based on Attack PredictionabstractMultistep attack prediction and security situation awareness are two big challenges for network administrators because future is generally unknown. In recent years, many investigations have been made. However, they are not sufficient. To improve the comprehensiveness of prediction, in this paper, we quantitatively convert attack threat into security situation. Actually, two algorithms are proposed, namely, attack prediction algorithm using dynamic Bayesian attack graph and security situation quantification algorithm based on attack prediction. The first algorithm aims to provide more abundant information of future attack behaviors by simulating incremental network penetration. Through timely evaluating the attack capacity of intruder and defense strategies of defender, the likely attack goal, path, and probability and time-cost are predicted dynamically along with the ongoing security events. Furthermore, in combination with the common vulnerability scoring system (CVSS) metric and network assets information, the second algorithm quantifies the concealed attack threat into the surfaced security risk from two levels: host and network. Examples show that our method is feasible and flexible for the attack-defense adversarial network environment, which benefits the administrator to infer the security situation in advance and prerepair the critical compromised hosts to maintain normal network communication. Hao Hu 0005 |
Secur. Commun. Networks | 1 |
| 2016 | General construction for XOR-based visual cryptography and its extended capability
Hao Hu 0005, Zhengxin Fu, Bin Yu 0003 |
Multim. Tools Appl. | 1 |