Hui Wen 0001

dblp:78/7230-1 · DBLP profile ↗
← Back
31ranked-venue papers
3as first author
18since 2021 · last 2025
0000-0002-3786-3358ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 12 since 2021Computer networks · 10 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Dynamic Vulnerability Patching for Heterogeneous Embedded Systems Using Stack Frame Reconstruction
abstract
Existing dynamic vulnerability patching techniques are not well-suited for embedded devices, especially mission-critical ones such as medical equipment, as they have limited computational power and memory but uninterrupted service requirements. Those devices often lack sufficient idle memory for dynamic patching, and the diverse architectures of embedded systems further complicate the creation of patch triggers that are compatible across various system kernels and hardware platforms. To address these challenges, we propose a hot patching framework called StackPatch that facilitates patch development based on stack frame reconstruction. StackPatch introduces different triggering strategies to update programs stored in memory units. We leverage the exception-handling mechanisms commonly available in embedded processors to enhance StackPatch's adaptability across different processor architectures for control flow redirection. We evaluated StackPatch on embedded devices featuring three major microcontroller (MCU) architectures: ARM, RISC-V, and Xtensa. In the experiments, we used StackPatch to successfully fix 102 publicly disclosed vulnerabilities in real-time operating systems (RTOSes). We applied patching to medical devices, soft programmable logic controllers (PLCs), and network services, with StackPatch consistently completing each vulnerability remediation in less than 260 MCU clock cycles.
Ming Zhou 0010, Xupu Hu, Haining Wang 0001, Hui Wen 0001, Limin Sun 0001, Peng Zhang 0044
CCS5
2025 Microservice Dependency Discovery Based on Spatio-Temporal Network Flow Behavior Modeling
abstract
The microservice architectural style offers significant application scalability and development advantages. Composing monolithic systems into loosely coupled, containerized services reduces deployment and development costs while enhancing the flexibility and resilience of the overall system. However, in large-scale internet applications involving multi-party collaboration and global deployment, the formation of complex microservice dependencies increases the risk of cascading failures. It complicates the process of identifying the source of a fault. Identifying such dependencies in uncontrolled conditions with limited observational data represents a significant challenge. This paper proposes Microservice Dependency Discovery based on Spatio-Temporal Network Flow Behaviour Modelling (Cross-MSDD). This method infers microservice dependencies by modeling spatiotemporal interactions of network traffic. The method employs network flow characteristics to mine frequent behavioral patterns, thereby inferring dependency chains without the necessity for additional tracing tools. The method utilizes network flow characteristics to mine frequent behavior patterns, inferring dependency chains without additional tracing tools, minimizing system interruptions, and protecting request content privacy. To verify the effectiveness of the proposed method, a semi-simulated experimental environment was set up using traffic data from typical microservice applications. The results demonstrate that the method attains an accuracy rate exceeding 96.3% in cross-domain dependency identification, markedly surpassing the performance of existing techniques. This facilitates the practical detection of faults and the mitigation of cascading failure risks, thereby ensuring system stability.
Jinfa Wang, Chunyang Zheng, Hui Wen 0001, Hong Li 0004, Hongsong Zhu
CSCWD4
2025 Automated Penetration on Multi-Subnet Environments with Dual-Stage DRL Models
abstract
With the advent of artificial intelligence techniques, the field of Network Attack Defense (NAD) has witnessed a surge in research efforts towards automating penetration testing (PenTest). Our work presents a dual-stage PenTest model aiming at predicting attack paths in network topology and determining payload for vulnerabilities in hosts with deep reinforcement learning models. While constructing training environments, our approach integrates real-world vulnerability environments with virtual network topologies. This allows the model to take into account the process of vulnerability validation with success rate compared to existing work based on fully virtualized targets, while retaining the efficiency of deployment and training provided by virtualization. And we introduce a method that simulate hierarchical network topology with randomized subnets to simulate complex network environments, challenging the agent to adapt and learn effective policies across diverse configurations of the target networks. Our experiments demonstrate the effectiveness of our model in various network sizes. In addition, the results indicate that our approach not only achieves high performance but also maintains stability under the different success rate of vulnerability exploitation, showcasing the robustness and adaptability. Our work contributes to the advancement of automated PenTest by providing a more generalized and efficient solution.
Haoyu Bu, Hui Wen 0001, Hongsong Zhu, Hong Li 0004, Xirui Song, Yimo Ren
SMC2
2025 TimeTravel: Real-time Timing Drift Attack on System Time Using Acoustic Waves
Jianshuo Liu, Hong Li 0004, Haining Wang 0001, Mengjie Sun, Hui Wen 0001, Jinfa Wang, Limin Sun 0001
USENIX Security Symposium5
2025 When LLMs meet cybersecurity: a systematic literature review
abstract
Abstract The rapid development of large language models (LLMs) has opened new avenues across various fields, including cybersecurity, which faces an evolving threat landscape and demand for innovative technologies. Despite initial explorations into the application of LLMs in cybersecurity, there is a lack of a comprehensive overview of this research area. This paper addresses this gap by providing a systematic literature review, covering the analysis of over 300 works, encompassing 25 LLMs and more than 10 downstream scenarios. Our comprehensive overview addresses three key research questions: the construction of cybersecurity-oriented LLMs, the application of LLMs to various cybersecurity tasks, the challenges and further research in this area. This study aims to shed light on the extensive potential of LLMs in enhancing cybersecurity practices and serve as a valuable resource for applying LLMs in this field. We also maintain and regularly update a list of practical guides on LLMs for cybersecurity at https://github.com/tmylla/Awesome-LLM4Cybersecurity .
Jie Zhang 0121, Haoyu Bu, Hui Wen 0001, Yongji Liu, Haiqiang Fei, Rongrong Xi, Hongsong Zhu
Cybersecur.3
2025 Automated tactics planning for cyber attack and defense based on large language model agents
Yimo Ren, Jinfa Wang, Hui Wen 0001, Hong Li 0004, Hongsong Zhu
Neural Networks4
2024 FirmPorter: Porting RTOSes at the Binary Level for Firmware Re-hosting
Mingfeng Xin, Hui Wen 0001, Liting Deng, Hong Li 0004, Qiang Li 0007, Limin Sun 0001
ICICS (2)2
2024 Fast Firmware Fuzz with Input/Output Reposition
Mingfeng Xin, Liting Deng, Hui Wen 0001, Dongliang Fang, Shichao Lv, Limin Sun 0001
SecureComm (3)3
2024 NFCEraser: A Security Threat of NFC Message Modification Caused by Quartz Crystal Oscillator
abstract
Near Field Communication (NFC) has been widely used for rapid data exchange between electronic devices over a very short distance. In this paper, we reveal a new security vulnerability in NFC passive communication channels where transferred data can be modified in real-time. The security threat of data modification posed by this vulnerability is called NFCEraser. Exploiting electromagnetic interference (EMI), NFCEraser injects signals into the crystal oscillator’s electrode and adjusts the amplitude of carrier signals in NFC communication channels. By manipulating the parameters of EMI signals, NFCEraser is able to arbitrarily flip the bits in data payload sent from an NFC peer device, which may cause serious security outcomes. To assess the severity of NFCEraser, we examine six NFC modules under NFC-A/B communication modes and successfully perform reading operations under a variety of data lengths. The experimental results show that NFCEraser can modify data bits in response frames from NFC peer devices with the maximum 89% accuracy, under around 0.21μs latency. Our analysis further shows that NFCEraser can maintain an attack success rate of no less than 85% in environments with typical levels of electromagnetic noise.
Jianshuo Liu, Hong Li 0004, Mengjie Sun, Haining Wang 0001, Hui Wen 0001, Zhi Li 0018, Limin Sun 0001
SP5
2024 UniTTP: A Unified Framework for Tactics, Techniques, and Procedures Mapping in Cyber Threats
abstract
The increasing complexity of cyber threats necessitates advanced methods for understanding and countering adversarial tactics, techniques, and procedures (TTPs). Despite the support provided by the ATT&CK framework, challenges such as imbalanced sample distribution and technique overlap limit the effective mapping of complex attack patterns. To address these challenges, we propose a framework that integrates language models and advanced artificial intelligence techniques, including hierarchical attention embedding and contrastive learning, to achieve TTP recognition and classification in complex cyber threats. UniTTP consists of five modules: data processing, tactic classification, multi-feature embedding, techniques classification, and LLM post-assistance. By combining these modules, our method not only accurately identifies TTPs within cyber threats, improving the F1 score by 3.23% to 13.66% across different datasets, but also leverages the capabilities of large language models to verify recognition results and deepen the understanding of attack behaviors. This study lays the foundation for robust cyber defense by providing deeper insights into adversary behaviors and enhancing the predictability of complex threats.
Jie Zhang 0121, Hui Wen 0001, Hongsong Zhu
TrustCom2
2024 Few-Shot Malware Classification via Attention-Based Transductive Learning Network
Liting Deng, Chengli Yu, Hui Wen 0001, Mingfeng Xin, Limin Sun 0001, Hongsong Zhu
Mob. Networks Appl.3
2023 MalAder: Decision-Based Black-Box Attack Against API Sequence Based Malware Detectors
abstract
The API call sequence based malware detectors have proven to be promising, especially when incorporated with deep neural networks (DNNs). Several adversarial attack methods are proposed to fool these detectors by introducing undetectable perturbations into normal samples. However, in real-world scenarios, the malware detector provides only the predicted label for a given sample, without exposing its network architecture or output probability, making it challenging for adversarial attacks under the decision-based black-box. Existing work in this area typically relies on random-based methods that suffer high costs and low attack success rates. To address these limitations, we propose a novel decision-based black-box attack against API sequence based malware detectors, called MalAder. Our approach aims to improve the attack success rate as well as query efficiency through a directional perturbation algorithm. First, it utilizes attention-based API ranking to assess the importance of API calls in the context of different API sequences. This assessment guides the insertion position for perturbation. Then, the perturbation is carried out using benign distance perturbing, which gradually shortens the semantic distance from adversarial API sequences to a set of benign samples. Finally, our algorithm iteratively generates adversarial malware samples by performing perturbations. In addition, we have implemented MalAder and evaluated its performance against two classic malware detectors. The results show that MalAder outperforms state-of-the-art decision-based black-box adversarial attacks, proving its effectiveness.
Lei Cui 0003, Hui Wen 0001, Zhi Li 0018, Hongsong Zhu, Zhiyu Hao, Limin Sun 0001
DSN3
2023 Denoising Network of Dynamic Features for Enhanced Malware Classification
abstract
Malware classification based on dynamic feature analysis works by running malware in controlled and isolated environments to observe how it behaves. This technology widely uses the sequence of run-time API calls to classify. Malware often adopts evasion techniques such as obfuscation, encryption, and code injection to obfuscate classification results by introducing noise into the API sequence. The existing methods lack explicit means of filtering noise components in the data, which affects the accuracy of malware detection. To address this issue, we propose DenoMC, a malware classification method with an explicit denoising module. Firstly, we employ dynamic analysis and embedding techniques to encode the API sequence. Then, we introduce a soft thresholding mechanism in the residual network to achieve active filtering of noise components in API sequences. Finally, a BiLSTM model is adopted to enhance the temporal correlation among sequence of API calls and improve classification performance. Experiments conducted on real datasets demonstrate that DenoMC significantly improves malware classification accuracy compared to other state-of-art models. In addition, we validate the effectiveness of each module in DenoMC through extensive ablation studies.
Siyuan Li 0014, Hui Wen 0001, Liting Deng, Zhi Li 0018, Limin Sun 0001
IPCCC2
2023 HackMentor: Fine-Tuning Large Language Models for Cybersecurity
abstract
The democratization of artificial intelligence has made substantial progress by leveraging open-source large language models (LLMs), enabling researchers across domains to train customized models to meet their specific needs. Given the confidentiality and significance of cybersecurity, obtaining private and localized LLMs is imperative. However, general LLMs are not designed to cater specifically to this field, their general knowledge often falls short when addressing such specialized problems. In this paper, we categorize the domain instructions based on cybersecurity knowledge to guide the construction of high-quality instructions and conversations, ultimately enhancing the specialized capabilities of LLMs. The resulting fine-tuned LLMs, collectively termed HackMentor, are evaluated using WinRate, EloRating, and ZenoEval methods along with other popular LLMs. The experiments demonstrate that the proposed method yields significant performance improvements, surpassing the native LLMs by 10-25% when aligned with cybersecurity prompts. More, HackMentor exhibits comparable conversational quality to ChatGPT, while providing more concise and humanlike responses. This study demonstrates the efficacy of HackMentor in augmenting LLMs for cybersecurity requirements, paving the way for localized LLMs that meet specialized needs without compromising general capabilities.
Jie Zhang 0121, Hui Wen 0001, Liting Deng, Mingfeng Xin, Zhi Li 0018, Hongsong Zhu, Limin Sun 0001
TrustCom2
2023 Enimanal: Augmented cross-architecture IoT malware analysis using graph neural networks
Liting Deng, Hui Wen 0001, Mingfeng Xin, Hong Li 0004, Zhiwen Pan, Limin Sun 0001
Comput. Secur.2
2022 ShadowPLCs: A Novel Scheme for Remote Detection of Industrial Process Control Attacks
abstract
Industrial Control System (ICS) security has become increasingly important as attacks targeting ICSs are more prominent. Although many off-the-shelf industrial network intrusion detection mechanisms have been presented in the past, attackers have always found unique disguisable ways to bypass detections and disrupt actual industrial control processes. To mitigate this deficiency, we present a novel scheme for the detection of industrial process control attacks, calledShadowPLCs. Specifically, the scheme first automatically analyzes the PLC control code, then extracts key parameters of the PLCs including valid register addresses, valid range of values, and control logic rules as a basis for evaluating attacks. The attack behavior is detected in real-time from different perspectives through active communication with PLCs and passive monitoring of the network traffic. We implemented a prototype system with Siemens S7-300 series PLCs as a case study. Our scheme was evaluated using two Siemens S7-300 PLCs deployed on a gas pipeline network platform. Experiments demonstrate that the presented scheme can accurately detect process control attacks in real-time without affecting the normal operations of PLCs. Compared with the other four representative detection models, our scheme has better detection performance with detection accuracy of 97.3 percent.
Junjiao Liu, Xiaodong Lin 0001, Xin Chen 0123, Hui Wen 0001, Hong Li 0004, Zhiqiang Shi, Limin Sun 0001
IEEE Trans. Dependable Secur. Comput.4
2021 DSS: Discrepancy-Aware Seed Selection Method for ICS Protocol Fuzzing
Shuangpeng Bai, Hui Wen 0001, Dongliang Fang, Puzhuo Liu, Limin Sun 0001
ACNS (2)2
2021 HoneyVP: A Cost-Effective Hybrid Honeypot Architecture for Industrial Control Systems
abstract
As a decoy for hackers, honeypots have been proved to be a very valuable tool for collecting real data. However, due to closed source and vendor-specific firmware, there are significant limitations in cost for researchers to design an easy-to-use and high-interaction honeypot for industrial control systems (ICSs). To solve this problem, it’s necessary to find a cost-effective solution. In this paper, we propose a novel honeypot architecture termed HoneyVP to support a semi-virtual and semi-physical honeypot design and implementation to enable high cost performance. Specially, we first analyze cyber-attacks on ICS devices in view of different interaction levels. Then, in order to deal with these attacks, our HoneyVP architecture clearly defines three basic independent and cooperative components, namely, the virtual component, the physical component, and the coordinator. Finally, a local-remote cooperative ICS honeypot system is implemented to validate its feasibility and effectiveness. Our experimental results show the advantages of using the proposed architecture compared with the previous honeypot solutions. HoneyVP provides a cost-effective solution for ICS security researchers, making ICS honeypots more attractive and making it possible to capture physical interactions.
Jianzhou You, Shichao Lv, Hui Wen 0001, Limin Sun 0001
ICC4
2020 Malware Classification Using Attention-Based Transductive Learning Network
Liting Deng, Hui Wen 0001, Mingfeng Xin, Limin Sun 0001, Hongsong Zhu
SecureComm (2)2
2020 Detecting Internet-Scale NATs for IoT Devices Based on Tri-Net
Zhaoteng Yan, Hui Wen 0001, Zhi Li 0018, Hongsong Zhu, Limin Sun 0001
WASA (1)3
2019 Side-Channel Information Leakage of Traffic Data in Instant Messaging
abstract
Instant Messaging has been widely applied for both corporate use and personal use in recent years. Major Instant Messaging service providers adopt the Push Technology to ensure the immediacy of message forwarding, which efficiently provides a great convenience for user. However, the immediacy feature causes side-channel information leakage even if some protection measures has been implemented, such as information encryption strategy. In particular, we observe that senders' traffic flows have a strong temporal correlation with those of corresponding recipients, since the messages are forwarded to recipients as soon as they are received by servers. Based on the observation, attackers can infer real-time communications between pairwise users and even the social connections of users. In this paper, we present a methodology framework to validate this side-channel information leakage, which identifies users of real-time communications by matching the pairwise time sequences of traffic flows. We evaluate the method on the collected real-world data. The experimental results show that users' communications can be identified with a high accuracy, and 6 groups of users are inferred to have strong connections based on the data collected from a local area networks.
Ke Li 0042, Hong Li 0004, Hongsong Zhu, Limin Sun 0001, Hui Wen 0001
IPCCC5
2019 Lightweight IoT Malware Visualization Analysis via Two-Bits Networks
Hui Wen 0001, Hongsong Zhu, Limin Sun 0001
WASA1
2018 A graph neural network based efficient firmware information extraction method for IoT devices
abstract
The firmware information for IoT devices includes the manufacturer, the device type, the device model and the firmware version, etc. Identifying firmware information helps build firmware knowledge graph for many security applications, such as homologous analysis and vulnerability detection of firmware. The traditional firmware information identifying method only utilizes the content-based information, lacks the utilization of the structure information of the firmware, and more importantly, it lacks the use of timing information. Lacking of structural information can reduce prediction accuracy, and lacking of timing information will make it difficult to predict the firmware version. In order to address the disadvantages of the existing method, this paper abstracts the directories or files (components) of the firmware into the nodes of the graph and abstracts the relationships between the nodes into the edges of the graph. Timing information such as component creation time and component version are also attached to the node properties to introduce the time sequence features. As a result, the experimental results show that the accuracy of our method is better than that of random forest for the all four tasks (manufacture, device type, device model and firmware version identification). Particularly, and the accuracy rate is greatly improved in the firmware version identification task.
Hong Li 0004, Hui Wen 0001, Hongsong Zhu, Limin Sun 0001
IPCCC3
2018 Mining Human Periodic Behaviors Using Mobility Intention and Relative Entropy
Feng Yi, Libo Yin, Hui Wen 0001, Hongsong Zhu, Limin Sun 0001, Gang Li 0009
PAKDD (1)3
2018 Context-aware personalized path inference from large-scale GPS snippets
Hongtao Wang 0002, Feng Yi, Hui Wen 0001, Gang Li 0009, Limin Sun 0001
Expert Syst. Appl.4
2017 Discovering Routers as Secondary Landmarks for Accurate IP Geolocation
abstract
IP geolocation determines geographic location by the IP address of Internet hosts. The physical location of Internet hosts is critical for many location-aware applications. Most geolocation methods are based on linear assumption of correlation between network latency and geographic distance on a large scale. In this paper, a lightweight geolocation approach is proposed to accurately determine the location of Internet hosts. This approach takes advantage of relative delay measurement and common routers. We studied localized delay- distance correlation in small region. We proposed an approach of discovering the accurate positions of common routers and converted common routers as secondary landmarks on a small scale and evaluated the efficiency of our method in the city level. The evaluation results show that the proposed algorithm improves the accuracy of IP geolocation by about 9.5% compared to Street-level Geolocation (SLG), one of the latest methods.
Yongle Chen, Hui Wen 0001, Lian Zhao, Limin Sun 0001
VTC Fall3
2017 Mobility Intention-Based Relationship Inference from Spatiotemporal Data
Feng Yi, Hong Li 0004, Hongtao Wang 0002, Hui Wen 0001, Limin Sun 0001
WASA4
2016 Tensor Filter: Collaborative Path Inference from GPS Snippets of Vehicles
Hongtao Wang 0002, Hui Wen 0001, Feng Yi, Zhi Li 0018, Limin Sun 0001
WASA2
2015 Abnormal event detection via adaptive cascade dictionary learning
abstract
Detecting abnormal events plays an essential role in video content analysis and has received increasing attention in surveillance system. One of the major problems in abnormal event detection is the imbalanced classification issue due to the rare abnormal samples. Another problem is the difficulty of detecting anomalies within a reasonable amount of computation time. To address these problems, we propose an adaptive cascade dictionary learning framework for detecting the anomalies. The framework considers anomaly detection as an one-class classification problem with a cascade of dictionaries. Each stage of the cascade constructs an adaptive dictionary to detect the anomalies with costless least square optimization solution. The experiments on benchmark datasets demonstrate that the proposed method has a better performance while comparing with several state-of-the-art methods.
Hui Wen 0001, Shiming Ge, Shuixian Chen, Hongtao Wang 0002, Limin Sun 0001
ICIP1
2014 Eye localization based on correlation filter bank
abstract
Eye localization is a key step in many face analysis related applications. In this paper, we present a novel eye localization method based on a group of trained filters called correlation filter bank (CFB). We formulate the eye localization problem as an optimization problem with a well-defined cost function based on CFB. The CFB is trained with an EM-like adaptive clustering approach. The trained filter bank includes several discriminative filter templates, each of them suits to a different face condition from the others, thus can provide accurate eye localization ability for variable poses, appearances and illuminations. Simulation comparisons with cascade classifier-based method [1], traditional single correlation filter based methods [2][3] and pictorial structure model based method [4] demonstrates the superiority of the proposed method both in detection ratio and localization accuracy.
Shiming Ge, Hui Wen 0001, Shuixian Chen, Limin Sun 0001
ICME3
2014 Poster: Crowdsourcing for video traffic surveillance
abstract
No abstract available.
Hui Wen 0001, Qiang Li 0007, Qi Han 0001, Shiming Ge, Limin Sun 0001
MobiSys1