EDBT 2026 Demo / reviewers in the wild / expert
Bing Zhang 0011
dblp:74/2272-11
· DBLP profile ↗
35ranked-venue papers
10as first author
32since 2021 · last 2026
0000-0002-9867-8439ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 4 first-author · 13 since 2021Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Computer networks · 5 · 5 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A self-supervised learning framework with hierarchical residual cross fusion network for sleep apnea detection
Haitao He, Bing Zhang 0011, Jiadong Ren |
Artif. Intell. Medicine | 4 |
| 2026 | VulMamba: multi-dimensional state space modeling for software vulnerability detection via self-supervised contrastive learning
Haoyi Shi, Jiadong Ren, Bing Zhang 0011, Dekai Zhang |
Autom. Softw. Eng. | 3 |
| 2026 | Convolutional neural network-based vulnerability detection using image representations fused from key code slice text features and complex network metrics
Bing Zhang 0011, Ni Liao, Wenqi Xue, Rong Ren, Xu Kang 0001 |
Eng. Appl. Artif. Intell. | 1 |
| 2026 | Vul2image: A quick image-inspired and CNN-based vulnerability detection system
Rong Ren, Mushi Zhou, Ni Liao, Bing Zhang 0011, Guoyan Huang, Haitao He, Qian Wang 0009 |
Expert Syst. Appl. | 4 |
| 2026 | TPP: A temporal-enhanced propagation probability model for identifying influential nodes in complex networks
Bing Zhang 0011, Rong Ren, Jiadong Ren, Qian Wang 0009 |
Expert Syst. Appl. | 1 |
| 2026 | SSRFinder: SSRF vulnerability detection and validation based on program dependency graphs and pre-trained models
Bing Zhang 0011, Chenhua Lou, Yanxuan Lou, Rong Ren, Qian Wang 0009 |
Expert Syst. Appl. | 1 |
| 2026 | PRWHA: RGB Image-Based Hybrid Attention for Cross-File SQLI/XSS Vulnerability Detection in PHP Web ApplicationsabstractAs the most widely used server-side programming language for web applications, PHP has a large number of SQL injection (SQLI) and cross-site scripting (XSS) vulnerabilities that are exploited maliciously, making the detection of such vulnerabilities increasingly critical. Existing source code detection methods suffer from issues such as uncleaned redundant information, limited representation dimensions and poor detection performance. To address these challenges, we propose a PHP vulnerability detection method based on RGB image representation and hybrid attention mechanisms — PHP ResNet with Hybrid Attention (PRWHA). First, PRWHA marks the input sources and sensitive functions, constructs data flow and control flow graphs between source and sink points and adds function call edges. This method uniquely identifies nodes in the graph using filenames and line numbers to enable inter-procedural and cross-file detection. Next, it leverages both the topological information (including data flow, control flow and function call relationships) and textual information of the code’s graph structure to generate RGB images. These images are then processed by a ResNet-50 model enhanced with a hybrid attention layer to detect SQLI and XSS vulnerabilities. To validate the effectiveness of PRWHA, we evaluated it on both publicly available datasets and real-world software datasets. The results demonstrate that PRWHA outperforms traditional methods as well as other machine learning, deep learning and Large Language Model (LLM)-based detection approaches. On the public dataset, PRWHA achieved an accuracy of 99.00% and an F1-score of 97.13% on the test set. On the real-world software dataset, it achieved an accuracy of 73% and a vulnerability detection rate of approximately 83.67%. Rong Ren, Qingyu Song 0006, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2026 | HVDet: Heap Vulnerability Detection Method Based on P-PDG Representation and Bi-GRU AlgorithmabstractHeap vulnerabilities pose a significant risk to software, leading to stability issues such as slowdown and resource depletion. These vulnerabilities can potentially disrupt critical operations and compromise the overall system performance, especially in the case of automated control systems implemented in C/C[Formula: see text] language. While various artificial intelligence-based detection methods have been studied, there has been limited analysis of the detection process and the structural and semantic features, resulting in lower detection efficiency. This paper proposes a novel heap vulnerability detection (HVDet) method based on the Pointer Program Dependency Graph (P-PDG) representation and Bidirectional Gated Recurrent Unit (Bi-GRU) algorithm for software. Through inter-procedural analysis, the P-PDG serves as an innovative code representation model that places emphasis on pointer operations, which are closely associated with heap vulnerabilities. It leads to a reduction in code size while simultaneously capturing a broader range of structural and semantic features of the source code. Subsequently, a mixed feature matrix incorporating these features from code slices is generated as input for the Bi-GRU algorithm. When compared with 7 state-of-the-art (SOTA) vulnerability detection tools, HVDet demonstrates superior performance. It successfully identified three heap vulnerabilities in real-world software such as Linux Kernel, Espruino and LibreDWG. Rong Ren, Bing Zhang 0011, Haitao He, Qian Wang 0009, Guoyan Huang |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2026 | A Domain Adaptive IoT Intrusion Detection Algorithm Based on AEC-GAT Feature Extraction and Joint Domain AdversaryabstractThe high heterogeneity of Internet of Things (IoT) devices causes severe imbalance in network traffic data, and the cost of collecting and labeling sufficient intrusion samples is high or impossible, resulting in data scarcity in IoT security. Therefore, this article proposes a domain adaptive IoT intrusion detection algorithm based on causal embedding autoencoder and a graph attention network (AEC–GAT) feature extraction and joint domain adversary, which leverages abundant data resources from traditional network intrusion detection to improve the detection accuracy in IoT environments. First, a feature extraction method combining an AEC–GAT is designed. The AEC uses causal inference to uncover deep semantic links between domains, while GAT captures device interaction patterns to enhance semantic relevance and structure awareness in the features. Second, to address the pronounced class imbalance in IoT datasets, focal loss is introduced to replace the traditional cross-entropy (CE) loss. This formulation dynamically adjusts the sample weight through the scaling factor to guide the algorithm to focus on the minority samples that are difficult to classify. Meanwhile, a class adaptive independent domain discriminator method is proposed, which incorporates a class-level alignment mechanism within a joint adversarial training method. This method dynamically adjusts both the training intensity and the loss weight of each class specific domain discriminator. The experimental results show that the algorithm in this article significantly improves the detection performance of IoT intrusion detection by migrating traditional network intrusion detection domain knowledge, and has superior performance in various indicators compared to existing algorithms. Qian Wang 0009, Menghui Fan, Zhijuan Wu, Hongnian Yu, Yongqiang Cheng 0001, Bing Zhang 0011 |
IEEE Trans. Ind. Informatics | 6 |
| 2025 | Interprocedural Call Graph Embedding with GAT for Memory safety Vulnerability DetectionabstractMemory safety vulnerabilities remain a critical threat to software security, often leading to system crashes, data leakage, and service disruptions. Existing deep learning-based detection methods mainly rely on intra-procedural analysis, which limits their ability to capture complex memory behaviors involving pointer variable flows across function boundaries. This study proposes IpGAT, an InterProcedural memory vulnerability detection framework based on Graph Attention Network (GAT) that aims to overcome the limitations of intra-procedural approaches by modeling cross-function data flows of pointer variables. IpGAT constructs an Interprocedural Program Call Graph (IpCG) that integrates Abstract Syntax Trees (AST), Control Flow Graphs (CFG), and Data Flow Graphs (DFG) to represent memory-sensitive function interactions. The IpCG is embedded using Word2Vec and then fed into a GAT for vulnerability classification. Experimental results show that IpGAT achieves an accuracy of 88.9%, a precision of 86.5%, and an F1-score of 89.1%, significantly outperforming six state-of-the-art tools and intra-procedural baselines. Furthermore, IpGAT successfully identified eight real-world memory safety vulnerabilities in open-source projects such as ffdshow, Libav, Seamonkey, and VLC, all of which have been confirmed in the CVE database. By incorporating interprocedural analysis and graph-based learning, IpGAT effectively captures the semantics of memory-sensitive operations and demonstrates strong generalizability across both benchmark datasets and real-world software. Rong Ren, JingYi Wu, HongBo Jin, QingYu Song, Bing Zhang 0011, Qian Wang 0009 |
TrustCom | 5 |
| 2025 | An adaptive XSS vulnerability detection method based on hierarchical multi-objective reward-enhanced Dueling Double Deep Q-Network
Haitao He, Yufeng Jia, Bing Zhang 0011 |
Comput. Networks | 6 |
| 2025 | Sample-customized implicit semantic data augmentation for neural networks regularization
Xu Kang 0001, Jia Jia 0007, Bing Zhang 0011, Xinzhi Li |
Neurocomputing | 3 |
| 2025 | A Systematic Literature Review of Software Vulnerability Mining Approaches Based on Symbolic ExecutionabstractWith the rapid development of the software industry, the escalating issue of software vulnerabilities has posed significant risks to users. Symbolic execution as a vulnerability mining technology offers a high-test coverage. The existing reviews of symbolic execution methods focus on summarizing various techniques and tools. While some studies have analyzed the technical challenges, classification frameworks and development trends of these methods, they lack a comprehensive and systematic review. This study aims to address the gap in existing reviews by providing a comprehensive, systematic analysis of symbolic execution techniques for vulnerability mining. We conducted a detailed review of 60 peer-reviewed papers published between 2005 and 2024, focusing on symbolic execution techniques for vulnerability mining. First, we reviewed the main techniques used in the symbolic execution process, including program instrumentation, path selection strategy and constraint-solving techniques. Second, we extracted the main information from the selected papers, and the detailed information on the symbolic execution tools is in the form of a table. Compared and analyzed the research object, the execution process at the same time, the software architecture and the application on different system platforms. Finally, we present a comprehensive and systematic summary of current challenges and corresponding solutions in the field. This study provides an in-depth analysis of vulnerability detection technologies based on symbolic execution, serving as a valuable guide for researchers in this domain. Lining Li, Rong Ren, Bing Zhang 0011, Xu Kang 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2025 | MalRGBDet: Windows Malware Detection Method Based on RGB Image Representation and Heterogeneous Neural NetworkabstractAs the world’s most widely used operating system, Windows has long been a primary target for malware attacks, causing severe economic losses and threats to data security for users and enterprises. Existing detection methods often struggle with low accuracy when dealing with complex malware, suffering from high false-negative and false-positive rates. Additionally, malware detection in Windows faces challenges such as limited datasets, a lack of benign sample contrast and insufficient original feature information. To address these issues, we propose a malware detection method based on RGB image representation and heterogeneous neural network (MalRGBDet). First, we collected malware samples from the GitHub and VirusShare platforms, along with benign software from Windows systems, to build a dataset named MalDet. This data set contains unprocessed malicious and benign samples, providing original feature information and addressing the lack of benign samples in existing data sets. Next, we extracted three key features from the malware samples: code sections, data sections and API call sequences. These features closely relate to the behavior of malware and accurately describe its operations. We then transformed these features into uniformly sized RGB images, which helped reveal hidden patterns. Finally, we employ a heterogeneous neural network that integrates ResNet and AlexNet for classification. ResNet, with its deep architecture and residual learning mechanism, significantly enhances the model’s representation capability and classification performance, thereby improving detection accuracy. Meanwhile, AlexNet’s Dropout regularization strategy effectively boosts the model’s generalization ability. In our data set of 1952 Windows software samples, MalRGBDet achieved more than 95% in accuracy, precision, recall and F1-score, improving these metrics by up to 4% compared to the latest methods. Furthermore, false-negative and false-positive rates were kept below 5%. Rong Ren, Hongchang Zhang, Bing Zhang 0011, Haitao He, Guoyan Huang, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2025 | VulEPEDE: A Function-Level Vulnerability Detection Method via Enhanced Positional Encoding and Dependency EmbeddingabstractAs software complexity increases, integrating vulnerability detection becomes essential to ensure the security and integrity of modern systems. Traditional static and dynamic analysis methods face limitations in efficiency and accuracy, particularly for large-scale vulnerability detection, while existing deep learning methods struggle to fully capture structural information and dependencies in code, leading to incomplete identification of vulnerabilities. In this paper, we propose VulEPEDE, an innovative function-level vulnerability detection method. VulEPEDE leverages Program Dependency Graphs (PDG) to represent function code and constructs a Vulnerability Semantic Dependency Graph (VSDG) using slicing techniques, introducing function parameter nodes as slicing candidates to capture more comprehensive vulnerability trigger chains. It integrates two core modules: the Enhanced Positional Encoding (EPE) module and the Dependency Embedding (DE) module. The EPE module combines node attribute encoding with positional encoding using a Transformer and multi-head attention mechanism to capture complex features and contextual semantics of code, while the DE module learns dependency embeddings between code nodes through convolutional neural networks. We evaluate VulEPEDE on three widely used datasets, comparing its performance against state-of-the-art deep learning-based methods. Experimental results demonstrate that VulEPEDE outperforms the best baseline methods by 1.66%, 17.54%, and 28.96% in F1-score across the three datasets, with considerable computational efficiency. Shuailin Yang, Jiadong Ren, Jiazheng Li 0005, Bing Zhang 0011 |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2025 | DRacv: Detecting and auto-repairing vulnerabilities in role-based access control in web application
Bing Zhang 0011, Jingyue Li, Haitao He, Rong Ren, Jiadong Ren |
J. Netw. Comput. Appl. | 2 |
| 2025 | Multi-Stage Network Attack Detection Algorithm Based on Gaussian Mixture Hidden Markov Model and Transfer LearningabstractMulti-stage network attack (MSA) is a serious threat to data security. The high-dimensionality of the alert data along with the diverse features, leads to poor detection performance for MSA. Consequently, this paper proposes a multi-stage network attack detection algorithm based on Gaussian mixture hidden Markov model and transfer learning. Firstly, a sequence modeling framework of Gaussian mixture hidden Markov models is proposed. It uses a Gaussian mixture model to cluster high-dimensional alert data and a hidden Markov model to fully consider the temporal structure of MSA, the alert features of each stage, and transitions between stages. Secondly, optimized Baum-Welch and Viterbi algorithms are proposed, combined with the forward-backward algorithm to train the parameter of the Gaussian mixture hidden Markov model and detect the attack sequence of MSA. Finally, an improved transfer learning method is proposed, which addresses the sparsity of labeled data in MSA scenarios, a Kullback-Leibler (KL) divergence value is added as a penalty term to narrow the distribution differences between the source and target domains and solves the bias problem in the transfer learning process. The proposed algorithm is validated on the datasets DARPA 2000 and CSE-CIC-IDS2018, and the effectiveness and superiority is verified on multiple evaluation indicators.Note to Practitioners—Network attacks gradually show the large-scale, coordinated and multi-stage characteristics. Complex multi-step attacks with strong concealment and persistence have become the development trend of network attacks, which seriously threaten and infringe the secure storage and transmission of information. Most existing studies use hidden Markov model (HMM) to model multi-stage network attacks. HMM is usually more suitable for multi-step attacks occurring in a specific sequence within a continuous time interval. However, in actual multi-stage network attacks, attackers do not need to follow the exact sequence of multi-step attacks, and the intervals between successive stages of an attack can be hours, days, or even months. Attackers may also perform interleaved attacks to hide attacks. Therefore, this paper proposes a multi-stage network attack detection algorithm based on Gaussian hybrid hidden Markov and transfer learning. The optimized Gaussian hybrid hidden Markov model is used to model the alert data of multi-stage network attacks, and the improved transfer learning method is adopted to apply the knowledge learned from the source domain to the multi-stage network attack detection model of the target domain. The experimental results show that the proposed algorithm can effectively process the alert data of different attack stages under complex multi-stage network attacks, distinguish the real threat alert, false alert and irrelevant alert, and improve the performance of detecting multi-stage network attacks. The method presented in this paper can provide a valuable solution for complex multi-stage network attack detection such as advanced persistent threat (APT). Future work will further combine adversarial generation network methods to avoid the interference of adversarial attack samples, and explore more ways to improve the performance of multi-step attack detection. Qian Wang 0009, Jiadong Ren, Bing Zhang 0011 |
IEEE Trans Autom. Sci. Eng. | 5 |
| 2025 | Enhancing Java Web Application Security: Injection Vulnerability Detection via Interprocedural Analysis and Deep LearningabstractInjection attacks exploit vulnerabilities in how applications handle user input, allowing malicious code to infiltrate the execution environment of web applications, leading to severe consequences, such as data leaks and system crashes. Traditional dynamic and static detection methods suffer from limitations in manual rule or pattern design and intraprocedural analysis, lacking the capability to automatically learn complex features. Meanwhile, deep learning models encounter challenges, such as feature redundancy and inefficiency, in processing long code sequences. Here, we propose a prototype for detectingInjectionVulnerabilities in Java web applications based onInterprocedural analysis and the bidirectional encoder representations from transformersBERT-BiLSTM-CRF model (IVIB), effectively transforming vulnerability detection into text sequence annotation. IVIB employs interprocedural analysis to trace complete program data flow, control flow, method and class dependencies, reducing redundancy through a system dependency graph. Then, we develop intermediate language representation rules and conversion mechanisms specifically for Java programs, symbolically representing code snippets and annotating them to construct a corpus. IVIB achieves remarkable results, with over 96% accuracy, precision, recall, and F1-score in binary classification, surpassing other state-of-the-art models in multiclassification performance. Evaluation on real-world projects demonstrates IVIB's effectiveness, detecting 28 vulnerabilities out of 30 vulnerable slices with low false positives and no false negatives. Bing Zhang 0011, Xu Zhi, Rong Ren |
IEEE Trans. Reliab. | 1 |
| 2024 | An intrusion detection algorithm based on joint symmetric uncertainty and hyperparameter optimized fusion neural network
Qian Wang 0009, Haiyang Jiang 0006, Jiadong Ren, Xuehang Wang, Bing Zhang 0011 |
Expert Syst. Appl. | 6 |
| 2024 | Approach to Detect Windows Malware Based on Malicious Tendency Image and ResNet AlgorithmabstractTimely detection of self-replicating malware in the high market share Windows operating system can effectively prevent personal or corporate financial losses. The form and characteristics of malware are constantly evolving, leading to a concept drift issue that gradually decreases the effectiveness of traditional detection methods. Therefore, we propose WinMDet, a Windows malware detection method based on malicious tendency image and ResNet algorithm. First, to tackle the complexity and difficulty in accurately characterizing malware features, WinMDet retains detailed malware features and encodes them into malicious tendency images to better describe malware across different periods. Secondly, WinMDet utilizes previously generated malicious tendency images to train the initial detection model. Then, to alleviate the issue of malware concept drift, WinMDet employs Local Maximum Mean Discrepancy (LMMD) as the criterion for model transfer, enhancing the initial detection model’s ability to distinguish between malware and benign software. We conducted a comprehensive evaluation of WinMDet using common metrics such as accuracy, precision and recall. The results indicate that WinMDet performs remarkably well in terms of accuracy, exceeding 82%. Additionally, significant improvements were observed in precision and recall, surpassing 82.42% and 82.06%, respectively. After employing our LMMD-based transfer method, the initial detection model improved the detection accuracy of malware in 2021 and 2022 by approximately 4.22% to 8.06%. The false negative rate decreased by at most 4.34%, and the false positive rate decreased by at most 4.61%. Bing Zhang 0011, Hongchang Zhang, Rong Ren, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2024 | A Domain Adaptive IoT Intrusion Detection Algorithm Based on GWR-GCN Feature Extraction and Conditional Domain AdversaryabstractIn the field of Internet of Things (IoT), the intrusion detection data is scarce because of the network security and privacy. This article proposes a domain adaptive IoT intrusion detection algorithm based on GWR-GCN feature extraction and conditional domain adversary, which aims to improve intrusion detection in the IoT domain by learning from other intrusion detection domains with rich data. First, a GWR-GCN-based domain-invariant feature extraction method is proposed, where the growing when required network (GWR) calculates the correlation between the original data, and the related data is connected into a graph by the Hebb learning principle. The graph convolutional neural network (GCN) is used to mine the feature information of the graph-structured data and extract the optimal domain-invariant features. Second, a Copula-based data distribution alignment method is proposed to decompose the overall feature distribution difference between the source and target domains into the marginal distribution difference of a single feature and the joint distribution difference between features. Meanwhile, the correlation between features on the data distribution is considered to further reduce the data distribution difference and improve the cross-domain ability. Finally, a conditional domain adversarial intrusion detection model is proposed to improve the detection performance by adding the class information as a condition in the discriminator, considering the correlation between features and classes, and reducing the effect of domain shift on distributional alignment. In order to verify the proposed algorithm, experiments are conducted on the traditional network and the IoT domain data sets, and the superiority is verified on multiple evaluation indicators. Qian Wang 0009, Xuehang Wang, Jiadong Ren, Bing Zhang 0011 |
IEEE Internet Things J. | 6 |
| 2024 | SQLPsdem: A Proxy-Based Mechanism Towards Detecting, Locating and Preventing Second-Order SQL InjectionsabstractDue to well-hidden and stage-triggered properties of second-order SQL injections in web applications, current approaches are ineffective in addressing them and still report high false negatives and false positives. To reduce false results, we propose a Proxy-based static analysis and dynamic execution mechanism towards detecting, locating and preventing second-order SQL injections (SQLPsdem). The static analysis first locates SQL statements in web applications and identifies all data sources and injection points (e.g., Post, Sessions, Database, File names) that injection attacks can exploit. After that, we reconstruct the SQL statements and use attack engines to jointly generate attacks to cover all the state-of-the-art attack patterns so as to exploit these applications. We then use proxy-based dynamic execution to capture the data transmitted between web applications and their databases. The data are the reconstructed SQL statements with variable values from the attack payloads. If a web application is vulnerable, the data will contain malicious attacks on the database. We match the data with rules formulated by attack patterns to detect first and second-order SQL injection vulnerabilities in web applications, particularly the second-order ones. We use a representative and complete coverage of attack patterns and precise matching rules to reduce false results. By escaping and truncating malicious payloads in the data transmitted from the web application to the database, we can eliminate the possible negative impact of the data on the database. In the evaluation, by generating 52,771 SQL injection attacks using four attack generators, SQLPsdem successfully detects 26 second-order (including 13 newly discovered ones) and 375 first-order SQL injection vulnerabilities in 12 open-source web applications. SQLPsdem can also 100% eliminate the malicious impact of the data with negligible overhead. Bing Zhang 0011, Rong Ren, Mingcai Jiang, Jiadong Ren, Jingyue Li |
IEEE Trans. Software Eng. | 1 |
| 2023 | Intelligent and survivable resource slicing for 6G-oriented UAV-assisted edge computing networks
Guoquan Wu, Bing Zhang 0011, Ya Li 0013 |
Comput. Commun. | 2 |
| 2023 | An automatic classification algorithm for software vulnerability based on weighted word vector and fusion neural network
Qian Wang 0009, Yuying Gao, Jiadong Ren, Bing Zhang 0011 |
Comput. Secur. | 4 |
| 2023 | DetAC: Approach to Detect Access Control Vulnerability in Web Application Based on Sitemap Model with Global Information RepresentationabstractAccess control vulnerabilities that lead to elevated privileges are among the most dangerous vulnerabilities in Web applications. Most of the existing detection methods use dynamic or static analysis techniques alone, which suffer from high manual involvement, low automation, high leakage rate, low page coverage, and other deficiencies. To this end, this paper proposes a novel access control vulnerability detection method (DetAC) based on a sitemap model with global information representation. This method first constructs a static site-wide sitemap model based on the page link addresses in the Web application source code through static analysis techniques. After that, the application is logged in and executed dynamically with different role users. During this process, execution traces and request parameters are collected and converted into annotations to fill the corresponding edges of the static site-wide sitemap model. Then, the sitemap model with global information representation is obtained. This model can represent both the global control flow and data flow of the application. Then DetAC analyzes the role-based and user-based access control policies of the Web application based on the node reachability and annotated data features of the model. And according to the information such as role, user, and access resources, it generates attack vectors to achieve different roles and the same role of different users to access each other’s resources. Finally, access control vulnerabilities are detected based on the equivalence of the results obtained using attack vector access and normal access to the Web application server. DetAC was validated on five real open-source Web applications, and the results showed that DetAC successfully detected up to 12 access control vulnerabilities, which are more than those of the traditional seven tools. The dynamic analysis page coverage rate was significantly improved during the detection process, reaching an average of 91.37%. Jiadong Ren, Mingyou Wu, Bing Zhang 0011, Shangyang Li, Qian Wang 0009 |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2023 | A multitype software buffer overflow vulnerability prediction method based on a software graph structure and a self-attentive graph neural network
Zhangqi Zheng, Yongshan Liu, Bing Zhang 0011, Xinqian Liu, HongYan He |
Inf. Softw. Technol. | 3 |
| 2022 | Identifying Influential Spreaders in Complex Networks Based on Degree Centrality
Qian Wang 0009, Jiadong Ren, Honghao Zhang, Bing Zhang 0011 |
WISA | 5 |
| 2022 | An approach for predicting multiple-type overflow vulnerabilities based on combination features and a time series neural network algorithm
Zhangqi Zheng, Bing Zhang 0011, Yongshan Liu, Jiadong Ren, Qian Wang 0009 |
Comput. Secur. | 2 |
| 2022 | Intrusion Detection Algorithm Based on Convolutional Neural Network and Light Gradient Boosting MachineabstractAiming at the limitations of existing algorithms of network intrusion detection in dealing with complex data of imbalance and high dimensionality, this paper proposes an intrusion detection algorithm based on convolutional neural network (CNN) and Light Gradient Boosting Machine (LightGBM). First, the data-type conversion, oversampling technology and image data conversion are included in the data preprocessing to make the data balanced and adapt to the input format. Then, by the convolutional layer, pooling layer and fully connected layer of the CNN model, the main features are abstracted from the converted image data. Finally, data of the main features is used for training and testing the LightGBM model, so as to get the final classification results. This paper uses KDDCUP99 dataset to carry out multi-classification experiments. By comparing the experiments before and after balancing the dataset, and comparing with similar algorithms, it verifies the superiority of the proposed algorithm in the classification performance of intrusion detection, especially for the minority attack classes. Qian Wang 0009, Wenfang Zhao, Jiadong Ren, Yuying Gao, Bing Zhang 0011 |
Int. J. Softw. Eng. Knowl. Eng. | 6 |
| 2022 | Approach to Predict Software Vulnerability Based on Multiple-Level N-gram Feature Extraction and Heterogeneous Ensemble LearningabstractSoftware vulnerabilities are one of the roots of computer security problems. The traditional static analysis and dynamic analysis methods based on software source code mainly have some deficiencies, such as high false positive rate, high false negative rate and insufficient semantic information captured. Nevertheless, the application of machine learning, Natural Language Processing and other technologies in software vulnerability prediction can effectively mitigate such issues. This paper proposed a vulnerability prediction method based on multiple-level N-gram feature extraction and heterogeneous ensemble learning. First, by code intermediate representation and constructing a multiple-level N-gram feature generation model, two kinds of N-gram semantic features with different window size and different granularity at word and char level were extracted to retain the semantic and structural information of code. Second, TF–IDF was used to construct the vector space model as the input of prediction model. As a single classifier was prone to overfitting and poor generalization, this paper conducted benchmark testing on five classical machine learning algorithms (NB, SVM, DT, LR, RF), and then combined four (SVM, DT, LR, RF) among them, which had better performance as the base classifiers to form the stacking heterogeneous ensemble method to build the vulnerability prediction model. Finally, the proposed method was verified on buffer overflow vulnerability and resource management vulnerability datasets, with a lowest false positive rate and false negative rate which can reach 1.58% and 4.06%, respectively. Bing Zhang 0011, Qian Wang 0009, Jiadong Ren |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2021 | Critical Understanding of Security Vulnerability Detection Plugin Evaluation ReportsabstractIntegrated development environment (IDE) plugins aimed at detecting web application security vulnerabilities can help developers create secure applications in the first place. Most of such IDE plugins use static source code analysis approaches. Although several empirical studies evaluated the plugins and compared their precision and recall of detecting web application security, few follow-up studies tried to understand the evaluation results. We analyzed more than 20,000 vulnerability reports based on 7,215 distinct test cases spanning 11 categories of web application vulnerabilities to understand the evaluation results of three open-source IDE plugins, namely, SpotBugs, FindSecBugs, and Early Security Vulnerability Detector (ESVD), which aimed at detecting security vulnerabilities of Java-based web applications. Our results identify many factors besides the source code analysis approach that can dramatically bias the detection performance. Based on our insights, we improved the studied plugins. In addition, our study raises the alarm that, without solid root cause analyses, the evaluation and comparisons of security vulnerability detection approaches and tools could be misleading. Thus, we proposed a guideline on reporting the evaluation results of the security vulnerability detection approaches. Sindre Beba, Magnus Melseth Karlsen, Jingyue Li, Bing Zhang 0011 |
APSEC | 4 |
| 2021 | A fast all-packets-based DDoS attack detection approach based on network graph and graph kernel
Xinqian Liu, Jiadong Ren, Haitao He, Bing Zhang 0011, Yunxue Wang |
J. Netw. Comput. Appl. | 4 |
| 2020 | Software Crucial Functions Ranking and Detection in Dynamic Execution Sequence PatternsabstractBecause of the sequence and number of calls of functions, software network cannot reflect the real execution of software. Thus, to detect crucial functions (DCF) based on software network is controversial. To address this issue, from the viewpoint of software dynamic execution, a novel approach to DCF is proposed in this paper. It firstly models, the dynamic execution process as an execution sequence by taking functions as nodes and tracing the stack changes occurring. Second, an algorithm for deleting repetitive patterns is designed to simplify execution sequence and construct software sequence pattern sets. Third, the crucial function detection algorithm is presented to identify the distribution law of the numbers of patterns at different levels and rank those functions so as to generate a decision-function-ranking-list (DFRL) by occurrence times. Finally, top-k discriminative functions in DFRL are chosen as crucial functions, and similarity the index of decision function sets is set up. Comparing with the results from Degree Centrality Ranking and Betweenness Centrality Ranking approaches, our approach can increase the node coverage to 80%, which is proven to be an effective and accurate one by combining advantages of the two classic algorithms in the experiments of different test cases on four open source software. The monitoring and protection on crucial functions can help increase the efficiency of software testing, strength software reliability and reduce software costs. Bing Zhang 0011, Chun Shan, Munawar Hussain, Jiadong Ren, Guoyan Huang |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2019 | Predicting blood pressure from physiological index data using the SVR algorithmabstractBlood pressure diseases have increasingly been identified as among the main factors threatening human health. How to accurately and conveniently measure blood pressure is the key to the implementation of effective prevention and control measures for blood pressure diseases. Traditional blood pressure measurement methods exhibit many inherent disadvantages, for example, the time needed for each measurement is difficult to determine, continuous measurement causes discomfort, and the measurement process is relatively cumbersome. Wearable devices that enable continuous measurement of blood pressure provide new opportunities and hopes. Although machine learning methods for blood pressure prediction have been studied, the accuracy of the results does not satisfy the needs of practical applications. This paper proposes an efficient blood pressure prediction method based on the support vector machine regression (SVR) algorithm to solve the key gap between the need for continuous measurement for prophylaxis and the lack of an effective method for continuous measurement. The results of the algorithm were compared with those obtained from two classical machine learning algorithms, i.e., linear regression (LinearR), back propagation neural network (BP), with respect to six evaluation indexes (accuracy, pass rate, mean absolute percentage error (MAPE), mean absolute error (MAE), R-squared coefficient of determination ( R 2 ) and Spearman’s rank correlation coefficient). The experimental results showed that the SVR model can accurately and effectively predict blood pressure. The multi-feature joint training and predicting techniques in machine learning can potentially complement and greatly improve the accuracy of traditional blood pressure measurement, resulting in better disease classification and more accurate clinical judgements. Bing Zhang 0011, Huihui Ren, Guoyan Huang, Yongqiang Cheng 0001, Changzhen Hu |
BMC Bioinform. | 1 |
| 2018 | Network Intrusion Detection Method Based on PCA and Bayes AlgorithmabstractIntrusion detection refers to monitoring network data information, quickly detecting intrusion behavior, can avoid the harm caused by intrusion to a certain extent. Traditional intrusion detection methods are mainly focused on rule files and data mining. They have the disadvantage of not being able to detect new types of attacks and have the slow detection speed. To address these issues, an intrusion detection method based on improved PCA combined with Gaussian Naive Bayes was proposed. By weighting the first few feature vectors of the traditional PCA, data pollution can be reduced. The number of final weighted principal components is 2 through sequential selection. The dimensionality reduction of the data is achieved through improved PCA. Finally, the intrusion behaviors were detected by using the Gaussian Naive Bayes classifier. The indexes of detection accuracy, detection time, precision rate, and recall rate were applied to evaluate the results. The experimental results show that, comparing with the traditional Bayes method, the method proposed in this article can reduce the detection time by 60%, shorten it to 0.5s, and increase the detection rate to 91.06%. The mean value of detection accuracy is about 86% by cross-validation. Bing Zhang 0011, Yanguo Jia, Jiadong Ren |
Secur. Commun. Networks | 1 |