EDBT 2026 Demo / reviewers in the wild / expert
Lijuan Xu 0001
dblp:81/20-1
· DBLP profile ↗
40ranked-venue papers
12as first author
37since 2021 · last 2026
0000-0003-3386-4756ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 2 first-author · 10 since 2021Security and privacy · 9 · 3 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DHA-Net: Dynamic Heterogeneity-Aware Network for Multimodal Medical Image Segmentation
Dong Lian, Lijuan Xu 0001, Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001 |
ICIC (10) | 2 |
| 2026 | TraceCluster: A Lightweight and Adaptive Clustering-Based Subgraph Attention Network for APT Detection in Provenance GraphsabstractProvenance graph-based anomaly detection, particularly for Advanced Persistent Threat (APT) detection, addresses the issues of large-scale graphs and data imbalance. However, existing methods struggle with information loss, high computational complexity, and low detection accuracy. To address the above challenges, this paper proposes TraceCluster, a lightweight and adaptive clustering-based Subgraph Attention Network (SAN) for APT detection in provenance graph. TraceCluster mitigates the neighborhood explosion problem by clustering nodes to partition large-scale graphs, thus reducing reliance on the global graph while preserving local neighborhood information. Furthermore, the method dynamically models complex inter-node dependencies within subgraphs. It employs an attention mechanism to adaptively highlight the most relevant connections. This enhances node representations and improves overall feature extraction. This design substantially reduces memory consumption and avoids the high computational complexity of global graph processing. In addition, an adaptive category-weighting loss function assigns variable weights to different classes, improving the detection of rare and anomalous behaviors. Experimental results show that on the OpTC dataset, the currently faster method is 37-fold and 3-fold slower than our approach in terms of inference time respectively. Furthermore, in the nine real-world scenarios of four evaluated datasets, TraceCluster outperforms state-of-the-art (SOTA) approaches in terms of overall performance, especially in node-level APT detection tasks. Lijuan Xu 0001, Zicheng Zhao, Dawei Zhao 0001, Zhen Wang 0004, Chunpeng Ge 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | CBAT-ASG: Adversarial Sample Generation Method Based on CBA-TransformerabstractIn recent years, machine learning models have become prevalent for anomaly detection in industrial control systems (ICS). However, their vulnerability to adversarial samples poses a significant security threat. Current methods for adversarial sample attacks in ICS are inadequate, requiring urgent research. Present adversarial samples mainly target machine learning-based anomaly detection models, overlooking invariant rule detectors in ICS, which reduces attack success rates. This paper introduces CBAT-ASG, a novel adversarial sample generation method based on CBA-Transformer. We enhance the Transformer with channel and spatial attention modules, creating the CBA-Transformer generative model. This model improves performance and generates initial adversarial samples that better match industrial control data. To avoid detection by invariant rule detectors, we use an invariant rule checker to refine adversarial samples, increasing their resistance to detection. Experiments on public datasets show CBAT-ASG significantly reduces the detection capabilities of the advanced anomaly detection model GDN, with Precision decreasing by 0.94, and Recall and F1-Score dropping by over 0.4. Comparisons with three state-of-the-art adversarial sample generation methods across four anomaly detection models show CBAT-ASG's attack efficacy is approximately 0.7 higher in the best-case scenario. Lijuan Xu 0001, Zhiang Yao, Chengcai Diao, Guangrun Zhou, Dawei Zhao 0001 |
CSCWD | 1 |
| 2025 | Research on Firmware Simulation of Windows Embedded Compact SystemabstractFirmware simulation of embedded devices is an important technology to support security testing of embedded devices. However, most of the current firmware emulation targets are bare-metal or Linux-based firmware. The number of embedded devices based on Windows Embedded Compact (Windows CE) as the operating system occupies a certain market size, and there are certain security risks. Firmware extraction and system state simulation of embedded devices based on Windows CE are difficult. In order to solve the problem that embedded devices based on Windows CE system need firmware simulation methods and better support the security testing of embedded devices using Windows CE system, We propose a firmware simulation method for Windows CE systems. Combining the development board framework supported by QEMU and the specific application of embedded devices to be simulated, we make a simulation image that can run in QEMU. We verify our method on two commercial PLCs, and the experimental results show that our method can simulate the system state of PLC firmware. Dawei Zhao 0001, Lei Zhang 0136, Lijuan Xu 0001 |
CSCWD | 4 |
| 2025 | DCCT-Net: A Network Combined Dynamic CNN and Transformer for Image Compressive SensingabstractRecent end-to-end image compressive sensing networks primarily use Convolutional Neural Networks (CNNs) and Transformers, each with distinct limitations: CNNs struggle with global feature capture, while Transformers lack local feature extraction. We propose a novel network, DCCT-Net, which combines Dynamic CNN (DCNN) and Transformer. This integration leverages DCNN’s local feature strengths and the Transformer’s global representation capabilities, resulting in superior image reconstruction quality. To further enhance the network’s performance, we propose a Feature Dynamic Augment Module (FDAM), which dynamically extracts features based on the saliency of segmented image regions, thereby amplifying the CNN’s local feature expression. Additionally, we design a Weighted Fusion Module (WFM), which optimizes the combination of local and global features extracted by the DCNN and Transformer, respectively. Extensive experiments demonstrate that our proposed DCCT-Net significantly outperforms most existing state-of-the-art methods in the field. Lijuan Xu 0001, Haixiao Mei, Fenghua Tong, Dawei Zhao 0001, Fuqiang Yu |
ICASSP | 1 |
| 2025 | Multi-Relational Variational Contrastive Learning for Next POI RecommendationabstractNext point-of-interest (POI) recommendation aims to predict the next interested POI to the user based on their historical check-in data in location-based social services. Most existing studies have attempted to model user visiting behaviors via sequence-based and graph-based models, and have achieved impressive performance. However, there is still room to explore the implicit transition preferences and contextual multiple semantic relationships among various POIs. To this end, we propose a novel graph-based Multi-Relational Variational Contrastive Learning (MRVCL) method for next POI recommendation, which captures local similarity associations and global contextual dependencies among POIs. Specifically, an order-free local-relational adaptive weighting module is designed to alleviate the problem of insufficient utilization of multi-hop neighbor information caused by the limit of neighbor order of nodes. We then develop a contextaware global-relational encoding module to capture implicit semantic sequential relationships. Finally, generative variational-contrastive learning is employed to construct a continuous representation of the latent features and reinforce the quality of representation learning. Extensive experiments on two real-world datasets validate that our MRVCL outperforms existing state-of-the-art methods on various evaluation metrics. To facilitate future research, our code and data are open-sourced at https://github.com/LinCH-en/MRVCL. Peipei Wang 0001, Xiaohui Han, Lijuan Xu 0001 |
ICASSP | 4 |
| 2025 | Source-free Domain Adaptation with Multiple Alignment for Efficient Image RetrievalabstractDomain adaptation techniques help models generalize to target domains by addressing domain discrepancies between the source and target domain data distributions. These techniques are particularly valuable for cross-domain hashing retrieval, as they reduce training costs while maintaining high retrieval efficiency. However, existing unsupervised domain adaptative hashing methods often require access to both source and target domain data, which may raise privacy concerns regarding source domain data. To address these concerns, restricting access to source domain data is crucial, but this restriction also makes the alignment process between domains more challenging. In this paper, we propose a Source-free Domain Adaptive Hashing with Multiple Alignment (SFDAH-MA) approach for image retrieval. SFDAH-MA integrates model structure alignment, class moment alignment, and semantic relationship alignment to maximize inter-domain knowledge transfer. This comprehensive alignment strategy not only enhances retrieval performance across domains but also minimizes reliance on source domain data, thereby supporting data privacy protection. Extensive experiments show that SFDAH-MA achieves state-of-the-art performance in source-free settings and achieves comparable results to existing unsupervised domain adaptive hashing methods under conventional settings. The source codes of our method are available at: https://github.com/Nikphyc/SFDAH-MA. Jinghui Ni, Hui Cui 0004, Lihai Zhao, Fengling Li 0001, Xiaohui Han, Lijuan Xu 0001 |
ICASSP | 6 |
| 2025 | ElaD-Net: An Elastic Semantic Decoupling Network for Lesion Segmentation in Breast Ultrasound ImagesabstractBreast diseases pose a significant threat to women’s health. Automatic lesion segmentation in breast ultrasound images (BUSI) plays a crucial role in fast diagnosis. While various enhanced U-Net-based models have achieved success in multi-scale feature analysis and handling blurred boundaries, two key challenges persist that could guide the improvement of BUSI segmentation networks: 1) significant fluctuations in pixel intensity distribution similarity between the lesion and surrounding tissues, and 2) inconsistent transmission of spatial detail due to multi-scale lesion sampling. These issues highlight the necessity of semantic elasticity understanding and consistency control. To this end, we propose ElaD-Net, an Elastic Semantic Decoupling Network for lesion segmentation in BUSI. This network uses the pre-trained EfficientNet-B2 for multi-scale encoding of BUSI. The decoding stage features two key modules: Elastic Semantic Decoupling (ESD) and Spatial Semantic Reconstruction (SSR). ESD learns and decouples multi-frequency semantics in multi-scale channels with a self-calibration mechanism, enabling dynamic adjustment of receptive depth to resist similarity fluctuations. SSR further optimizes ESD outputs via feature branching, compression, and excitation to ensure spatial semantic consistency, thereby separately reconstructing edge and body. Lijuan Xu 0001, Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001 |
IJCAI | 1 |
| 2025 | Fed-CLIDS: Network intrusion detection system based on federated meta-continuous learningabstractWith the widespread adoption of IoT devices and the increasing diversity of network attacks, traditional centralized intrusion detection systems face significant challenges in processing real-time data and ensuring privacy protection. Federated learning, as an effective solution, enables distributed collaborative training while preserving data privacy. However, traditional federated learning methods struggle to adapt to dynamic network environments and often suffer catastrophic forgetting when learning new network attacks. This paper proposes a malicious network traffic detection method based on federated meta-continuous learning, integrating attention-enhanced BiLSTM models, SMOTE oversampling, and continual learning strategies. The proposed approach leverages federated learning to ensure data privacy, enhances the model’s capability to capture critical traffic features, and improves adaptability to concept drift. Experimental results show that the proposed method performs exceptionally well on the CICIDS2017 network traffic intrusion detection dataset and the NF-ToN-IoT industrial Internet dataset, demonstrating its effectiveness in dynamic network environments. Shumian Yang, Guoqing Lou, Lijuan Xu 0001, Dawei Zhao 0001 |
IJCNN | 3 |
| 2025 | Investigation into Auto-scaling Mechanisms in Cloud Computing
Xin Li 0002, Jiming Dong, Wenkang Xiang, Dawei Zhao 0001, Lijuan Xu 0001, Fenghua Tong |
KSEM (5) | 5 |
| 2025 | DualCBR: Cross-Modal Collaborative Filtering with Bidirectional Alignment for Long-Tail Recommendation
Xin Li 0002, Dekai Zhang, Dawei Zhao 0001, Lijuan Xu 0001, Fuqiang Yu |
KSEM (5) | 5 |
| 2025 | DRL-based latency-energy offloading optimization strategy in wireless VR networks with edge computing
Jieru Wang, Hui Xia 0001, Lijuan Xu 0001, Rui Zhang 0050, Kunkun Jia |
Comput. Networks | 3 |
| 2025 | AJSAGE: A intrusion detection scheme based on Jump-Knowledge Connection To GraphSAGE
Lijuan Xu 0001, Zicheng Zhao, Dawei Zhao 0001, Xin Li 0002, Xiyu Lu, Dingyu Yan |
Comput. Secur. | 1 |
| 2025 | DAN: Neural network based on dual attention for anomaly detection in ICS
Lijuan Xu 0001, Bailing Wang, Dawei Zhao 0001 |
Expert Syst. Appl. | 1 |
| 2025 | An intrusion response approach based on multi-objective optimization and deep Q network for industrial control systems
Yiqun Yue, Dawei Zhao 0001, Lijuan Xu 0001, Yongwei Tang, Haipeng Peng |
Expert Syst. Appl. | 4 |
| 2025 | AdaptFL: Adaptive Federated Learning Framework for Heterogeneous Devices
Hui Xia 0001, Lijuan Xu 0001 |
Future Gener. Comput. Syst. | 5 |
| 2025 | Multiuser Privacy Preserving and Verifiable Spatial-Feature Data Query for IoT CloudsabstractThe large volume of spatial feature data generated by Internet of Things (IoT) devices is increasingly utilized in business location planning (BLP) services. reverse nearest neighbor (RNN) query techniques assist BLP in achieving more efficient business decisions by identifying candidate locations that are most attractive to users. However, existing RNN query schemes face significant challenges. First, there are some issues with data security and result integrity, as cloud servers can be both untrustworthy and malicious. Second, traditional query schemes commonly assume that the data users (DUs) are fully trusted and hold the key provided by the data owner (DO, IoT device users). In practice, however, once a DU’s key is compromised, the dataset of the DO is at risk. Regarding the above issues, this article proposes a privacy-preserving spatial feature data query scheme that supports multiple users without requiring key sharing. The proposed scheme is demonstrated using RNN queries, which are highly applicable in BLP services. Specifically, we first design a Quad-Tree for indexing spatial feature data. Then, we embed replicated secret sharing (RSS) technique into distributed two trapdoors public-key cryptosystem (DT-PKC) for key sharing. And based on this, a set of secure protocols that satisfy the mutual independence of DUs are designed for computing spatial distance and feature similarity. Finally, rigorous theoretical proofs and extensive experimental evaluations ensure the security and effectiveness of the scheme. Xinsheng Chen, Xiaochao Wei, Hao Wang 0007, Lijuan Xu 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Outsourced Secure Cross-Modal Retrieval Based on Secret Sharing for Lightweight ClientsabstractCross-modal retrieval is a technique that uses one modality to query another modality in multimedia data (e.g., retrieving images based on text, or retrieving text based on images). It can break down the barriers between different modalities and achieve seamless information connection. Secure cross-modal retrieval focuses on privacy issues in cross-modal retrieval, including private data of data owners and private query requests of users. Current work on secure cross-modal retrieval protects private information through homomorphic encryption, which makes the efficiency of the retrieval phase not ideal. Therefore, the conflict between retrieval efficiency and security has become an important issue that needs to be resolved in secure cross-modal retrieval. We propose a scheme to achieve secure cross-modal retrieval in the form of secret sharing in the IoT environment. In the scheme, the data owner (DO) can secretly divide all the original data into two parts and upload them to two non-collusive cloud servers respectively. The servers store the data and provide cross-modal retrieval for users. The security of the scheme is proved under semi-honest model, and the experiments show that our scheme is more efficient than previous work in the search phase. When the query dimension is 512 and the number of latent factors is 500, the search time is reduced by more than half compared with previous work. Ziyu Niu, Hao Wang 0007, Zhi Li 0056, Ye Su 0001, Lijuan Xu 0001, Yudi Zhang 0001, Willy Susilo |
IEEE Internet Things J. | 5 |
| 2025 | TFHSVul: A Fine-Grained Hybrid Semantic Vulnerability Detection Method Based on Self-Attention Mechanism in IoTabstractCurrent vulnerability detection methods encounter challenges, such as inadequate feature representation, constrained feature extraction capabilities, and coarse-grained detection. To address these issues, we propose a fine-grained hybrid semantic vulnerability detection framework based on Transformer, named TFHSVul. Initially, the source code is transformed into sequential and graph-based representations to capture multilevel features, thereby solving the problem of insufficient information caused by a single intermediate representation. To enhance feature extraction capabilities, TFHSVul integrates multiscale fusion convolutional neural network, residual graph convolutional network, and pretrained language model into the core architecture, significantly boosting performance. We design a fine-grained detection method based on a self-attention mechanism, achieving statement-level detection to address the issue of coarse detection granularity. In comparison to existing baseline methods on public data sets, TFHSVul achieves a 0.58 improvement in F1 score at the function level compared to the best performing model. Moreover, it demonstrates a 10% enhancement in Top-10 accuracy at the statement-level detection compared to the best performing method. Lijuan Xu 0001, Baolong An, Xin Li 0002, Dawei Zhao 0001, Haipeng Peng, Weizhao Song, Fenghua Tong, Xiaohui Han |
IEEE Internet Things J. | 1 |
| 2025 | Privacy-preserving and verifiable multi-task data aggregation for IoT-based healthcare
Xinzhe Zhang, Lei Wu 0011, Lijuan Xu 0001, Zhien Liu, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 3 |
| 2025 | PPSKSQ: Towards Efficient and Privacy-Preserving Spatial Keyword Similarity Query in CloudabstractThe growth of cloud computing has led to the widespread use of location-based services, such as spatial keyword queries, which return spatial data points within a given range that have the highest similarity in keyword sets to the user’s. As the volume of spatial data increases, providers commonly outsource data to powerful cloud servers. Because cloud servers are untrustworthy, privacy-preserving keyword query schemes have been proposed. However, existing schemes consider only location queries or exact keyword matching. To address these issues, we propose the Privacy-Preserving Spatial Keyword Similarity Query Scheme (PPSKSQ), designed to search for spatial data points with the highest similarity while protecting the privacy of outsourced data, query requests, and results. First, we design two sub-protocols based on improved symmetric homomorphic encryption (iSHE): iSHE-SC for secure size comparison and iSHE-SIP for secure inner product computation. Then, we encode range information and integrate it with a quadtree to construct a novel index structure. Additionally, we use the Jaccard to measure similarity in conjunction with the iSHE-SC protocol, transforming similarity comparison into a matrix trace operation. Finally, rigorous security analysis and extensive simulation experiments confirm the flexibility, efficiency, and scalability of our scheme. Changrui Wang, Lei Wu 0011, Lijuan Xu 0001, Hao Wang 0007, Wenying Zhang 0001, Weizhi Meng 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2025 | A Variant-Sensitive Malware Detection Method Based on Feature Contrast EnhancementabstractMalware poses a great threat to information security such as user data, privacy, and assets. Early detection before it has a real impact is the main countermeasure. However, the diversity of carriers and technologies has led to a huge gap between the training scenarios and actual scenarios of detection methods. This makes it difficult for supervision-based detection frameworks to identify new malware variants and complicates threat response. We propose a novel method that integrates frequency domain techniques with feature alignment to enhance variant malware detection, reducing distribution differences between labeled (source) and new (target) samples. By converting malware into grayscale images and applying discrete cosine transform (DCT) for improved feature extraction, followed by feature extraction via a deep residual network from both domains, our model systematically aligns features. This alignment is achieved through a tailored domain adaptation technique involving the minimization of classification and domain alignment losses, which ensures the consistent learning of features across varied domains. Such rigorous alignment not only enhances detection accuracy for both known and variant malware but also supports simultaneous detection across significant distribution differences. We conduct extensive experiments on two real-world datasets to evaluate the performance of various deep learning models under consistent and inconsistent domain distributions. Compared to existing methods, our approach improves accuracy by an average of 1.4% on the BIG2015 dataset, 3.2% on the MDA dataset, 2.75% on the Malimg dataset, and also achieves the best performance on the MaleVis dataset, with similar gains in precision, recall, and F1-score across all datasets. Shumian Yang, Jiarui Hu 0007, Xin Li 0002, Dawei Zhao 0001, Lijuan Xu 0001, Fuqiang Yu |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2025 | DRCAD: Dual-View Experts Routing and Counterfactual Generation for Explainable Time Series Anomaly DetectionabstractTime series anomaly detection is critical in domains such as cybersecurity monitoring, network operations, and industrial control systems. Lately, unsupervised anomaly detection methods that utilize contrastive learning have shown promise. However, existing approaches often struggle to model high-dimensional temporal dependencies efficiently and rely on rigid feature-fusion schemes that can inadvertently amplify noise. These factors increase computational overhead and sensitivity to irrelevant signals, hindering the capture of salient patterns. Additionally, the explainability of anomalies detected by these mechanisms is often limited, restricting their application in traceable detection processes and an explicit decision-making basis. In this paper, we propose dual-view experts routing and counterfactual generation for explainable time series anomaly detection (DRCAD), a novel framework that detects anomalies within time series data while providing intuitive and actionable explanations for model predictions. DRCAD uses in-patch and patch-wise perspectives as input views for the contrastive learning model, employing a flattened attention mechanism with lightweight spatial projections and a Patch Mixture of Experts (MoE) layer for adaptive routing and information fusion. It identifies anomalies by expanding the discrepancy between normal and anomalous points in the representation space, subsequently outputting anomaly scores. These anomaly scores guide the generation of counterfactual samples, integrating feature change tendencies with normalized feature impacts to derive a feature importance ranking as the explanation. We evaluate DRCAD on six widely used datasets, observe state-of-the-art (SOTA) performance. Moreover, in the explainability evaluation on SWaT dataset, DRCAD achieves superior realism and sparsity in counterfactual generation compared to existing methods, with top-ranked features closely matching officially documented attack characteristics. Dawei Zhao 0001, Lijuan Xu 0001, Zhen Wang 0004, Haipeng Peng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | GNN-ASG: A Double Feature Selection-based Adversarial Sample Generation Method in Industrial Control SystemabstractDue to the unique constraints of industrial control data, industrial control adversarial sample attacks are particularly challenging. Existing methods strive to conduct adversarial sample attacks under the conditions of satisfying industrial control data constraints, however, the results are not ideal. Therefore, this study proposes a new adversarial sample generation method GNN-ASG based on double feature selection. GNN-ASG uses data constraints to ensure the rationality of generated data, and uses Graph Deviation Network (GDN) and Autoencoder to improve the quality and versatility of adversarial samples. A new adversarial sample evaluation metrics Adversarial Sample Attack Impact Rate (ASAIR) is proposed to address the problem that existing evaluation metrics are difficult to accurately judge the effectiveness of adversarial sample attacks. This method considers the principle and application environment of adversarial samples, and fully demonstrates the practical effect of adversarial samples. In a comprehensive experiment conducted on three public datasets, GNN-ASG achieves an impressive ASAIR of 21.83%, higher than existing methods of 13.94%. This paper demonstrates the versatility and effectiveness of GNN-ASG by comparing its performance with three state-of-the-art adversarial sample generation methods on four anomaly detection models. GNN-ASG can maximally reduce the F1-Score of the detection model by 0.7605. Lijuan Xu 0001, Zhiang Yao, Dawei Zhao 0001, Xin Li 0002 |
CSCWD | 1 |
| 2024 | Multi-Interest Granularity Guided Semi-Joint Learning for N-Successive POI Recommendation
Fuqiang Yu, Fenghua Tong, Dawei Zhao 0001, Lijuan Xu 0001 |
DASFAA (2) | 4 |
| 2024 | Joint Entity and Relation Extraction Based on Prompt Learning and Multi-channel Heterogeneous Graph EnhancementabstractJoint extraction of entity and relation is crucial in information extraction, aiming to extract all relation triples from unstructured text. However, current joint extraction methods face two main issues. Firstly, they rarely consider the semantic information of entity and relation labels, leading to models that fail to fully understand and utilize the rich semantics in these labels, thereby limiting their performance. Secondly, although table-filling methods are widely used, they focus only on the start or end positions and ignore deep interactions between tables, relying solely on word-level information. To address these issues, we propose the P-MHE framework based on prompt learning and multi-channel heterogeneous graph enhancement. First, we use prompt templates to construct semantic nodes for entity and relation type labels, initializing them along with words as nodes in a heterogeneous graph. We iteratively fuse these semantic nodes through a message-passing mechanism to obtain node representations suitable for entity and relation extraction tasks. Secondly, we design a multi-channel heterogeneous graph to model node relationships from different perspectives, enhancing feature interactions among different types of nodes. Finally, we aggregate the semantic node information of entity and relation type labels after iteration, constructing separate decoding tables for each entity and relation type to better adapt to their respective characteristics. We evaluated our model on four public datasets. Experimental results show that P-MHE outperforms existing models on multiple public datasets. Extensive additional experiments further validate the effectiveness of our model. Haiqing Lv, Xiaohui Han, Peipei Wang 0001, Wenbo Zuo, Lijuan Xu 0001 |
ISPA | 6 |
| 2024 | Adversarial sample attacks and defenses based on LSTM-ED in industrial control systems
Lijuan Xu 0001, Shumian Yang, Dawei Zhao 0001, Xin Li 0002 |
Comput. Secur. | 2 |
| 2024 | Finding Component Relationships: A Deep-Learning-Based Anomaly Detection InterpreterabstractWhile the interpretability of deep learning (DL)-based models has been extensively explored in academia, applying existing interpretation methods to anomaly detection in industrial control systems (ICSs) poses challenges for two primary reasons. First, security experts in ICS have distinct interpretive priorities, emphasizing the need for stability and readability. Second, there are various types of device components in ICS, and the potential interactions between sensors and actuators are yet to be explored. To tackle the above challenges, we propose DeepINT, an interpreter for anomaly detection in ICS. In DeepINT, we adopt a search optimization algorithm to find the reference and capture feature importance by the backpropagation gradient to improve interpretation performance and reliability. In addition, we construct a finite difference-based interaction detection, which tests the interaction of different device components, in order to address the problem that actuators in ICS are not easily interpreted, meanwhile improving the comprehensiveness and accuracy of the interpretation results. In comprehensive experiments on two real water treatment datasets [secure water treatment (SWaT) and water distribution (WADI)], DeepINT shows excellent interpretation performance compared to the six state-of-the-art baseline methods, especially on the SWaT dataset, with a 60% improvement in interpretation accuracy. In addition, our method significantly improves the efficiency of interaction detection, which balances interpretation performance and time efficiency. Lijuan Xu 0001, Ziyu Han, Zhen Wang 0004, Dawei Zhao 0001 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2024 | Towards Auditable and Privacy-Preserving Online Medical Diagnosis Service Over CloudabstractWhile online medical diagnosis provides significant convenience to users, it also incurs the risk of privacy breaches, which inspired the emergence of various privacy-preserving online medical schemes. Nonetheless, existing schemes either compromise partial privacy to third parties or rely on cryptographic methods with high computational complexity. In particular, they do not anticipate user’s disputes to the extent that there is no audit process to guarantee the correctness of the diagnosis results and the fairness of the schemes. Consequently, we propose an efficient and privacy-preserving online medical diagnosis scheme based on additive secret sharing (ASS). First, the anonymity of the user is provided in the medical diagnosis process, which ensures that the cloud cannot link the diagnosis results to the user. Then, we devise a minimum value protocol and a range comparison protocol to enhance the security of the online diagnosis. In addition, considering user’s disputes that arise in realistic scenarios (e.g., malicious users may cheat the diagnosis system for personal benefits), we construct a blockchain-based audit process to detect user’s behaviors and settle controversies. Finally, we demonstrate the security and efficiency of the proposed scheme with theoretical analysis and experimental evaluation. Xinzhe Zhang, Lei Wu 0011, Zhien Liu, Hao Wang 0007, Lijuan Xu 0001, Songnian Zhang, Rongxing Lu |
IEEE Trans. Serv. Comput. | 5 |
| 2024 | Addressing Concept Drift in IoT Anomaly Detection: Drift Detection, Interpretation, and AdaptationabstractAnomaly detection plays a vital role as a crucial security measure for edge devices in Artificial Intelligence and Internet of Things (AIoT). With the rapid development of IoT ( Internet of Things), changes in system configurations and the introduction of new devices can lead to significant alterations in device relationships and data flows within the IoT, thereby triggering concept drift. Previously trained anomaly detection models fail to adapt to the changed distribution of streaming data, resulting in a high number of false positive events. This paper aims to address the issue of concept drift in IoT anomaly detection by proposing a comprehensive Concept Drift Detection, Interpretation, and Adaptation framework (CDDIA). We focus on accurately capturing the concept drift of normal data in unsupervised scenarios. To interpret drift samples, we integrate a search optimization algorithm and the SHAP method, providing a comprehensive interpretation of drift samples at both the sample and feature levels. Simultaneously, by utilizing the sample-level interpretation results for filtering new and old samples, we retrain the anomaly detection model to mitigate the impact of concept drift and reduce the false positive rate. This integrated strategy demonstrates significant advantages in maintaining model stability and reliability. The experimental results indicate that our method outperforms five baseline methods in adaptability across three datasets and provides interpretability for samples experiencing concept drift. Lijuan Xu 0001, Ziyu Han, Dawei Zhao 0001, Xin Li 0002, Fuqiang Yu, Chuan Chen 0001 |
IEEE Trans. Sustain. Comput. | 1 |
| 2023 | A Malicious Code Family Classification Method Based on RGB Images and Lightweight Model
Dawei Zhao 0001, Shumian Yang, Lijuan Xu 0001, Xin Li 0002 |
ICONIP (14) | 4 |
| 2023 | GRU-Based Interpretable Multivariate Time Series Anomaly Detection in Industrial Control SystemabstractInterpretable multivariate time series anomaly detection is an important technology to prevent accidents and ensure the reliable operation of Industrial Control Systems . A key limitation lies in the lack of a model to achieve better detection performance and more reliable interpretability , and keep a balance between performance efficiency and training optimization. In this paper, we propose GRN, an Interpretable Multivariate Time Series Anomaly Detection method based on neural graph networks and gated recurrent units (GRU). GRN can automatically learn potential correlations between sensors from multidimensional industrial control time series data , quickly mine long-term and short-term dependencies, to improve detection performance and help users to infer the root cause of detected anomalies . Based on GRU, GRN preserves the original advantages of processing the sequences and capturing the time series dependencies, moreover solves the problem of gradient disappearance and gradient explosion. We compare the performance of nine state-of-the-art algorithms on two real water treatment datasets (SWaT, WADI). GRN achieves better detection precision and recall. Meanwhile, the comparison of Area Under the Curve (AUC) demonstrates that GRN has the effect of maintaining balance between detection performance and training optimization. Compared with a Graph Deviation Network(GDN), GRN has achieved greater interpretability. Chaofan Tang, Lijuan Xu 0001, Yongwei Tang, Dawei Zhao 0001 |
Comput. Secur. | 2 |
| 2023 | TSGS: Two-stage security game solution based on deep reinforcement learning for Internet of Things
Xue-cai Feng, Hui Xia 0001, Lijuan Xu 0001, Rui Zhang 0050 |
Expert Syst. Appl. | 4 |
| 2023 | ADTCD: An Adaptive Anomaly Detection Approach Toward Concept Drift in IoTabstractThe data collected by sensors is streaming data in the Internet of Things (IoT). Although existing deep-learning-based anomaly detection methods generally perform well on static data, they struggle to respond timely to streaming data after distribution changes. However, streaming data suffers from conceptual drift due to the highly dynamic nature of IoT. In network security, concept drift-oriented anomaly detection is a crucial task, because it can adjust the model to adapt to the latest data, and detect attacks in time. Existing streaming anomaly detection methods are confronted with some challenges, including the latency of model updates, the uneven importance of new data, and the self-poisoning due to model self-updates. To tackle the above challenges, we propose a knowledge distillation-based adaptive anomaly detection model toward concept drift, ADTCD. ADTCD transfers the knowledge of the teacher model to the student model and only updates the student model to reduce the delay. We construct an algorithm of dynamically adjusting model parameters, which dynamically adjusts model weights through local inference on new samples, in order to improve the model’s responsiveness to new distribution data, meanwhile solving the problem of uneven importance of new data. In addition, we adopt a one-class support vector-based outlier removal method to tackle the self-poisoning problem. In comprehensive experiments on seven high-dimensional data sets, ADTCD achieves an AUC improvement of 12.46% compared to the state-of-the-art streaming anomaly detection methods. Our future direction will focus on exploring the concept-drift problem using methods beyond autoencoders. Lijuan Xu 0001, Haipeng Peng, Dawei Zhao 0001, Xin Li 0002 |
IEEE Internet Things J. | 1 |
| 2023 | A dynamic adaptive iterative clustered federated learning scheme
Run Du, Rui Zhang 0050, Lijuan Xu 0001, Hui Xia 0001 |
Knowl. Based Syst. | 4 |
| 2021 | Predefined-time synchronization of competitive neural networks
Chuan Chen 0001, Ling Mi, Zhongqiang Liu, Baolin Qiu, Hui Zhao 0009, Lijuan Xu 0001 |
Neural Networks | 6 |
| 2021 | Minimum Dominating Set of Multiplex Networks: Definition, Application, and IdentificationabstractThe minimum dominating set (MDS) of the network is a node subset of smallest size that every node in the network is either in this subset or is adjacent to one or more nodes of this subset. MDS has found wide applications, ranging from network monitoring, routing, to epidemic control, and text processing. However, the majority of existing studies on MDS problem are confined to single networks. In real world, more and more complex systems consist of a set of elements linked up by different types of connections, which are best modeled as multiplex networks with interacting network layers. Though vastly important, the MDS of the multiplex networks has not yet been formally defined and its application and identification remain open issues. In this article, we present the definition of the MDS of the multiplex network and show some of its possible applications. For solving the MDS problem of the multiplex network, we built a spin-glass model and solve it through the belief-propagation (BP) equations under the replica symmetry mean-field theory. As a consequence, we can predict the relative size of the MDS of the multiplex network theoretically and we can propose a BP-guided decimation algorithm to construct an approximate optimal dominating set in practice. Then the algorithm is improved in both accuracy and efficiency by embedding a novel multiplex network-oriented leaf-removal strategy. The effectiveness of the proposed algorithms is finally verified by comparing with other methods on a number of the multiplex network examples. Dawei Zhao 0001, Gaoxi Xiao, Zhen Wang 0004, Lianhai Wang, Lijuan Xu 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 5 |
| 2020 | PLC-SEIFF: A programmable logic controller security incident forensics framework based on automatic construction of security constraints
Lijuan Xu 0001, Bailing Wang, Lianhai Wang, Dawei Zhao 0001, Xiaohui Han, Shumian Yang |
Comput. Secur. | 1 |
| 2018 | Secure Virtualization Environment Based on Advanced Memory IntrospectionabstractMost existing virtual machine introspection (VMI) technologies analyze the status of a target virtual machine under the assumption that the operating system (OS) version and kernel structure information are known at the hypervisor level. In this paper, we propose a model of virtual machine (VM) security monitoring based on memory introspection. Using a hardware-based approach to acquire the physical memory of the host machine in real time, the security of the host machine and VM can be diagnosed. Furthermore, a novel approach for VM memory forensics based on the virtual machine control structure (VMCS) is put forward. By analyzing the memory of the host machine, the running VMs can be detected and their high-level semantic information can be reconstructed. Then, malicious activity in the VMs can be identified in a timely manner. Moreover, by mutually analyzing the memory content of the host machine and VMs, VM escape may be detected. Compared with previous memory introspection technologies, our solution can automatically reconstruct the comprehensive running state of a target VM without any prior knowledge and is strongly resistant to attacks with high reliability. We developed a prototype system called the VEDefender. Experimental results indicate that our system can handle the VMs of mainstream Linux and Windows OS versions with high efficiency and does not influence the performance of the host machine and VMs. Shuhui Zhang 0001, Xiangxu Meng, Lianhai Wang, Lijuan Xu 0001, Xiaohui Han |
Secur. Commun. Networks | 4 |
| 2016 | Social Media account linkage using user-generated geo-location dataabstractSince cyber offenders often create multiple accounts on different Social Media Platforms (SMPs) to serve their disparate malicious intentions, law enforcement agency investigators often encounter the task of recognizing all the accounts used by the same person across SMPs, i.e., account linkage (AL). Although a number of techniques have been proposed for AL, their performance may be degraded by factors such as information asymmetry, poor data quality, data unavailability, as well as application scope limitation. In this paper, we solve AL in an unsupervised manner by utilizing user-generated geo-location data in SMPs, which is more robust than common clues used in existing techniques. A co-clustering-based AL framework is proposed in which account clusterings in temporal and spatial dimensions are carried out synchronously and enhance the results of each other. Experiments carried out on a real-world dataset demonstrate the feasibility and validity of the proposed framework. Xiaohui Han, Lianhai Wang, Lijuan Xu 0001, Shuihui Zhang |
ISI | 3 |