Yang Xin 0001

dblp:72/2718-1 · DBLP profile ↗
← Back
17ranked-venue papers
0as first author
17since 2021 · last 2026
0000-0002-9706-3950ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 8 since 2021Computer networks · 4 · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 High-Performance Personalized Federated Continual Learning Framework for Dynamic Data Sharing in IoV
abstract
The Internet of Vehicles (IoV) connects vehicles to the internet, delivering smarter and more convenient mobility services to users. Traditional intelligent service models typically employ federated learning (FL) for training. However, as vehicles continuously encounter new data and exhibit heterogeneous computational capabilities, these models often suffer from catastrophic forgetting and performance degradation. To address the above challenges, this paper focuses on training a personalized federated continual learning (PFCL) model that is expected to achieve good performance on all local tasks. The new PFCL scheme, called adaptive personalized federated continual learning (Adp-PFCL), handles catastrophic forgetting and the lack of personalized solutions. In Adp-PFCL, 1) each vehicle client uses the online continual learning (OCL) algorithm to train its local model in the local training stage to mitigate the forgetting of old knowledge; 2) during the local model update phase, each vehicle client locally executes the privacy-preserving federated deep mutual learning (PP-FedDML) strategy to facilitate personalization and improve the performance of the global model on local data. Extensive experimental results demonstrate that the Adp-PFCL scheme achieves at least a 28.36% improvement in average accuracy while reducing runtime by 7.75% compared with current mainstream approaches, validating its high adaptability to dynamic data and computational efficiency.
Zhaoxia Li, Jinchun Liu, Yang Xin 0001, Jeng-Shyang Pan 0001
IEEE Internet Things J.5
2026 A Lightweight Android Malware Detection Framework Based on Markov Images and Knowledge Distillation
abstract
The Android system has been widely used in mobile devices and embedded terminals, significantly enhancing user interaction and service efficiency. However, its openness has also led to increasingly frequent and evolving malware attacks, seriously threatening system and data security. Existing detection methods generally suffer from problems such as large model size, high computational overhead, and high deployment costs, making it difficult to run efficiently on resource-constrained devices and have limited generalization ability for new or unknown malware. To this end, this paper proposes a high-precision, low-overhead, lightweight Android malware detection framework. The framework first performs fine-grained static analysis on APK files, extracts Dalvik opcode sequences, and generates grayscale images based on Markov transition probabilities, thereby transforming program behavior patterns into learnable visual representations. Secondly, a lightweight adaptive channel attention (ACA) mechanism is designed and embedded into a lightweight CNN to enhance the model’s perception of crucial feature channels. Finally, a knowledge distillation strategy is introduced to guide student model training using a high-performance teacher model, improving its generalization ability. Experiments are conducted on the publicly available datasets CICMalDroid2020, CICAndMal2017, and the newly constructed dataset. The results show that the proposed framework achieves accuracy of 98.50%, 98.63%, and 81.16%, respectively, while maintaining low computational overhead and small model size, significantly outperforming existing advanced methods. The framework achieves a good balance between detection accuracy, efficiency, and deployment feasibility, and has strong potential for widespread application on mobile and IoT devices.
Liangwei Yao, Yang Xin 0001
IEEE Internet Things J.2
2025 Vulnerability detection with Graph Attention Network and Metric Learning
Chunyong Zhang, Liangwei Yao, Yang Xin 0001
Inf. Softw. Technol.3
2025 A Fair and Trustworthy Hierarchical Federated Learning Scheme for Digital Twins in the Internet of Vehicles
abstract
Digital twins (DTs) support real time analysis and provide a reliable simulation platform for the Internet of Vehicles (IoV). DT modeling relies on a large amount of data, based on their own safety considerations, most clients are not willing to provide relevant data. Due to the characteristics of distributed collaboration and privacy protection, federated learning (FL) is a promising technique for DT modeling. The combination of the above two technologies can greatly accelerate the development of the IoV. However, an important challenge is the unbalanced distribution of local data across clients, which leads to client drift and affects the performance of the global model. Malicious clients uploading false parameters or low-quality models will also cause unsatisfactory model accuracy. In addition, trust between clients is not established in advance, and hidden safety issues arise when clients perform cooperative training with each other. Therefore, in this article, we propose a hierarchical FL (HFL) scheme for performing DT modeling tasks. To solve the problems of performance degradation and the divergence of FL models caused by nonindependent and identical distribution (Non-IID) data, we design a regularization algorithm and a data enhancement algorithm from the client-side and edge server-side, respectively. In addition, we design an auditing method to defend against attacks from malicious clients. To build trust between clients, we present a reputation management model that can effectively prevent swing attacks. The numerical results show that our proposed scheme not only outperforms the baseline methods in terms of model accuracy and attack resistance, but also filters out malicious clients to perform fair and efficient reputation computations.
Yang Xin 0001
IEEE Internet Things J.2
2025 VPCDIR: Verifiable and Privacy-Preserving Cross-Domain Image Retrieval in Internet of Things
abstract
The advancement of cloud computing and Internet of Things (IoT) has driven progress in image-based searchable encryption technology, which meets the escalating security demands of outsourced multimedia data in IoT scenarios. However, existing encrypted image retrieval schemes still face critical challenges, such as lack of cross-domain support, low retrieval efficiency and accuracy, and absence of reliable verifiability. To address these issues, this paper proposes a verifiable and privacy-preserving cross-domain image retrieval scheme (VPCDIR) in IoT. In our scheme, the re-encryption and key transformation technologies are implemented to achieve the availability of cross-domain image retrieval, and the learning with errors (LWE)-based enhanced secure k-nearest neighbor (kNN) algorithm is used to preserve the privacy of image features. Furthermore, the hybrid index mechanism that combines clustering and locality-sensitive hashing (LSH) is designed to enhance retrieval efficiency and accuracy, and the Merkle hash tree (MHT) with the short signature realizes reliable authenticity verification of the retrieval result. Finally, formal security analysis confirms the security of our scheme. Extensive experiments on the real dataset demonstrate the efficiency and practicability of VPCDIR for cross-domain image retrieval in IoT.
Guangcan Yang, Ziheng Yuan, Yang Xin 0001, Chunlai Du, Yunhua He, Fenghua Tong
IEEE Internet Things J.3
2025 Res2Next with attention mechanisms for malware classification based on feature visualization
Liangwei Yao, Yang Xin 0001
J. Inf. Secur. Appl.3
2024 Vulnerability detection based on federated learning
Chunyong Zhang, Tianxiang Yu, Bin Liu 0069, Yang Xin 0001
Inf. Softw. Technol.4
2024 Visualization-based comprehensive feature representation with improved EfficientNet for malicious file and variant recognition
Liangwei Yao, Bin Liu 0069, Yang Xin 0001
J. Inf. Secur. Appl.3
2023 Malware Detection Using Contrastive Learning Based on Multi-Feature Fusion
abstract
The continuous emergence of malicious software poses a serious threat to computer security. Traditional malware detection approaches rely on single or limited datas for feature extraction, which may not fully capture the effective information provided by different information dimensions in PE files. Furthermore, attackers always employ code obfuscation and evasion techniques to interfere with detection results while still maintaining malicious intent. To address these issues, we designed and implemented a model, called MFFCL. Firstly, our approach uses data feature fusion technology to mine as much effective information as possible from execution records, forming the original dataset. Secondly, to effectively resist code obfuscation, we utilize supervised contrastive learning to constitute software features from high-dimensional space. Experiments on public datasets demonstrate that MFFCL can detect malware with high accuracy and stability. Specifically, during training, MFFCL achieved a precision rate of 97.25% and a recall rate of 94.1%.
Kailu Guo, Yang Xin 0001, Tianxiang Yu
TrustCom2
2023 Cross-domain vulnerability detection using graph embedding and domain adaptation
Xin Li 0002, Yang Xin 0001, Yixian Yang, Yuling Chen 0002
Comput. Secur.2
2023 VulGAI: vulnerability detection based on graphs and images
Chunyong Zhang, Yang Xin 0001
Comput. Secur.2
2023 Static vulnerability detection based on class separation
Chunyong Zhang, Yang Xin 0001
J. Syst. Softw.2
2023 COBATS: A Novel Consortium Blockchain-Based Trust Model for Data Sharing in Vehicular Networks
abstract
Achieving efficient and secure shared data in vehicular networks is important for the development of smart transportation. Sharing data among intelligent vehicles not only enriches vehicle services but also improves traffic safety and efficiency. However, due to the specific nature of vehicular networks, security and privacy concerns prevent data providers from participating in the data sharing process. In addition, the quality of the data shared in the vehicular network is uneven and unreliable, and the reliability and authenticity of data sharing need to be further improved. In this paper, we propose a novel consortium blockchain-based trust model in vehicular networks (COBATS) to achieve secure storage and data sharing. To improve the quality of data sharing, we also design a trust management model capable of filtering malicious recommendations, which reduces the hazard of malicious nodes and ensures high-quality data sharing among vehicles. Moreover, we present a consensus mechanism with joint Proof-of-Stake (PoS) and Practical Byzantine Fault Tolerance (PBFT) to reduce resource consumption and improve the algorithm’s efficiency. The simulation results show that COBATS can improve the security and quality of data sharing. Furthermore, our model also can effectively handle certain attacks.
Yang Xin 0001, Yang Zhang 0091, Pinxiang Wang
IEEE Trans. Intell. Transp. Syst.2
2023 CPVD: Cross Project Vulnerability Detection Based on Graph Attention Network and Domain Adaptation
abstract
Code vulnerability detection is critical for software security prevention. Vulnerability annotation in large-scale software code is quite tedious and challenging, which requires domain experts to spend a lot of time annotating. This work offers CPVD, a cross-domain vulnerability detection approach based on the challenge of ”learning to predict the vulnerability labels of another item quickly using one item with rich vulnerability labels.” CPVD uses the code property graph to represent the code and uses the Graph Attention Network and Convolution Pooling Network to extract the graph feature vector. It reduces the distribution between the source domain and target domain data in the Domain Adaptation Representation Learning stage for cross-domain vulnerability detection. In this paper, we test each other on different real-world project codes. Compared with methods without domain adaptation and domain adaptation methods based on natural language processing, CPVD is more general and performs better in cross-domain vulnerability detection tasks. Specifically, for the four datasets of chr_deb, qemu, libav, and sard, they achieved the best results of 70.2%, 81.1%, 59.7%, and 78.1% respectively on the F1-Score, and 88.4%,86.3%, 85.2%, and 88.6% on the AUC.
Chunyong Zhang, Bin Liu 0069, Yang Xin 0001, Liangwei Yao
IEEE Trans. Software Eng.3
2022 Privacy-Preserving Query Scheme (PPQS) for Location-Based Services in Outsourced Cloud
abstract
Pervasive smartphones boost the prosperity of location-based service (LBS) and the increasing data prompt LBS providers to outsource their LBS datasets to the cloud side. The privacy issues of LBS in the outsourced cloud scenario have attracted considerable interest recently. However, current schemes cannot provide sufficient privacy preservation against practical challenges and are little concerned about the data retrieval efficiency of the cloud side. Therefore, we present an efficient Privacy-Preserving LBS Query Scheme (i.e., PPQS ). In our scheme, two cloud entities are employed to store the sensitive information of the outsourced data and provide the query service, which enhances the ability of privacy preservation for sensitive information. Besides, by using the techniques of homomorphic encryption and searchable symmetric encryption, the proposed scheme supports both the type query and the range query, which can significantly improve the data retrieval efficiency of the cloud side and reduce the computation burden on the cloud side and the user side. Through detailed analysis on security and computation cost, we show the enhanced ability of privacy preservation and the lower computation cost compared to previous schemes. Based on a real dataset, extensive simulations are performed to validate the effectiveness and performance of our scheme.
Guangcan Yang, Yunhua He, Qifeng Tang, Yang Xin 0001
Secur. Commun. Networks5
2021 Cross-Platform Strong Privacy Protection Mechanism for Review Publication
abstract
As a review system, the Crowd-Sourced Local Businesses Service System (CSLBSS) allows users to publicly publish reviews for businesses that include display name, avatar, and review content. While these reviews can maintain the business reputation and provide valuable references for others, the adversary also can legitimately obtain the user’s display name and a large number of historical reviews. For this problem, we show that the adversary can launch connecting user identities attack (CUIA) and statistical inference attack (SIA) to obtain user privacy by exploiting the acquired display names and historical reviews. However, the existing methods based on anonymity and suppressing reviews cannot resist these two attacks. Also, suppressing reviews may result in some reiews with the higher usefulness not being published. To solve these problems, we propose a cross-platform strong privacy protection mechanism (CSPPM) based on the partial publication and the complete anonymity mechanism. In CSPPM, based on the consistency between the user score and the business score, we propose a partial publication mechanism to publish reviews with the higher usefulness of review and filter false or untrue reviews. It ensures that our mechanism does not suppress reviews with the higher usefulness of reviews and improves system utility. We also propose a complete anonymity mechanism to anonymize the display name and avatars of reviews that are publicly published. It ensures that the adversary cannot obtain user privacy through CUIA and SIA. Finally, we evaluate CSPPM from both theoretical and experimental aspects. The results show that it can resist CUIA and SIA and improve system utility.
Yang Xin 0001, Qifeng Tang, Yuling Chen 0002, Yixian Yang, Guangcan Yang
Secur. Commun. Networks3
2021 Representativeness-Based Instance Selection for Intrusion Detection
abstract
With the continuous development of network technology, an intrusion detection system needs to face detection efficiency and storage requirement when dealing with large data. A reasonable way of alleviating this problem is instance selection, which can reduce the storage space and improve intrusion detection efficiency by selecting representative instances. An instance is representative not only in its class but also in different classes. This representativeness reflects the importance of an instance. Since the existing instance selection algorithm does not take into account the above situations, some selected instances are redundant and some important instances are removed, increasing storage space and reducing efficiency. Therefore, a new representativeness of instance is proposed and considers not only the influence of all instances of the same class on the selected instance but also the influence of instances of different classes on the selected instance. Moreover, it considers the influence of instances of different classes as an advantageous factor. Based on this representativeness, two instance selection algorithms are proposed to handle balanced and imbalanced data problems for intrusion detection. One is a representative-based instance selection for balanced data, which is named RBIS and selects the same proportion of instances from each class. The other is a representative-based instance selection for imbalanced data, which is named RBIS-IM and selects important majority instances according to the number of instances of the minority class. Compared with other algorithms on the benchmark data sets of intrusion detection, experimental results verify the effectiveness of the proposed RBIS and RBIS-IM algorithms and demonstrate that the proposed algorithms can achieve a better balance between accuracy and reduction rate or between balanced accuracy and reduction rate.
Fei Zhao 0004, Yang Xin 0001, Kai Zhang 0035, Xinxin Niu
Secur. Commun. Networks2