Xiaojian Li 0002

dblp:89/4955-2 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
6since 2021 · last 2025
0009-0001-0466-108XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 HIDIM: A novel framework of network intrusion detection for hierarchical dependency and class imbalance
Weidong Zhou 0001, Chunhe Xia, Tianbo Wang 0001, Xiaopeng Liang, Wanshuang Lin, Xiaojian Li 0002
Comput. Secur.6
2024 AIDE: Attack Inference Based on Heterogeneous Dependency Graphs with MITRE ATT&CK
Weidong Zhou 0001, Chunhe Xia, Xinyi Pan, Tianbo Wang 0001, Xiaojian Li 0002
TrustCom6
2024 GRASS: Learning Spatial-Temporal Properties From Chainlike Cascade Data for Microscopic Diffusion Prediction
abstract
Information diffusion prediction captures diffusion dynamics of online messages in social networks. Thus, it is the basis of many essential tasks such as popularity prediction and viral marketing. However, there are two thorny problems caused by the loss of spatial-temporal properties of cascade data: "position-hopping" and "branch-independency." The former means no exact propagation relationship between any two consecutive infected users. The latter indicates that not all previously infected users contribute to the prediction of the next infected user. This article proposes the GRU-like Attention Unit and Structural Spreading (GRASS) model for microscopic cascade prediction to overcome the above two problems. First, we introduce the attention mechanism into the gated recurrent unit (GRU) component to expand the restricted receptive field of the recurrent neural network (RNN)-type module, thus addressing the "position-hopping" problem. Second, the structural spreading (SS) mechanism leverages structural features to filter out related users and controls the generation of cascade hidden states, thereby solving the "branch-independency" problem. Experiments on multiple real-world datasets show that our model significantly outperforms state-of-the-art baseline models on both hits@κ and map@κ metrics. Furthermore, the visualization of latent representations by t-distributed stochastic neighbor embedding (t-SNE) indicates that our model makes different cascades more discriminative during the encoding process.
Huacheng Li, Chunhe Xia, Tianbo Wang 0001, Peng Cui 0001, Xiaojian Li 0002
IEEE Trans. Neural Networks Learn. Syst.6
2023 FedDLM: A Fine-Grained Assessment Scheme for Risk of Sensitive Information Leakage in Federated Learning-based Android Malware Classifier
abstract
In the traditional centralized Android malware classification framework, privacy concerns arise as it requires collecting users’ app samples containing sensitive information directly. To address this problem, new classification frameworks based on Federated Learning (FL) have emerged for privacy preservation. However, research shows that these frameworks still face risks of indirect information leakage due to adversary inference. Unfortunately, existing research lacks an effective assessment of the extent and location of this leakage risk. To bridge the gap, we propose the FedDLM, which provides a fine-grained assessment of the risk of sensitive information leakage in an FL-based Android malware classifier. FedDLM estimates attackers’ theoretical maximum inference ability from the information theory perspective to gauge the degree of leakage risk in the classifier effectively. It precisely identifies critical positions in the shared gradient where the leakage risk exists by utilizing characteristics of class activation in classifiers. Through extensive experiments on the Androzoo dataset, FedDLM demonstrates its superior effectiveness and precision compared to baseline methods in evaluating the risk of sensitive information leakage. The evaluation results provide valuable insights into information leakage problems in classifiers and targeted privacy protection methods.
Changnan Jiang, Chunhe Xia, Chen Chen 0098, Huacheng Li, Tianbo Wang 0001, Xiaojian Li 0002
TrustCom6
2023 HF-Mid: A Hybrid Framework of Network Intrusion Detection for Multi-type and Imbalanced Data
abstract
The data-driven deep learning methods have brought significant progress and potential to intrusion detection. However, there are two thorny problems caused by the characteristics of intrusion data: "multi-type features" and "data imbalance". The former means that forcefully and improperly transforming intrusion features from distinct metric spaces can result in semantic loss and noise. The latter indicates that the intrusion data is imbalanced in quantity and quality due to its complex spatial distribution. We propose a Hybrid Framework for Multi-type and Imbalance Data (HF-Mid) to address the above two problems. Firstly, we divide the intrusion features into equivalent and non-equivalent groups, and then embed them sequentially using Supervised Paragraph Vector-Distributed Memory (SPV-DM), which excels at modeling co-occurrence relationships, and Deep Neural Network (DNN), which is suitable for modeling non-linear relationships, thereby solving the "multitype features" problem. Secondly, we adopt a low-noise collective matrix factorization (CMF) model to fuse the two obtained features for dimensionality reduction. Finally, we employ a multiple classifier to detect intrusion. During the classifier training stage, we design a genetic algorithm-based proportional sampling method to select high-quality samples in each training batch. thus addressing the "data imbalance" problem. The experimental results demonstrate the proposed framework exhibits an overall improvement of 5.9% and 1.5% in terms of accuracy and false positive rate on average, respectively.
Weidong Zhou 0001, Tianbo Wang 0001, Guotao Huang, Xiaopeng Liang, Chunhe Xia, Xiaojian Li 0002
TrustCom6
2022 Epidemic Heterogeneity and Hierarchy: A Study of Wireless Hybrid Worm Propagation
abstract
With the growth in the use of smart mobile devices and the development of information technologies, worms and malware can spread from mobile networks into heterogeneous and hierarchical networks. Thus, the spread of these worms constitutes an increasing potential threat. For understanding the propagation of the aforementioned wireless hybrid worms, current researches have three critical problems:Structural simplification of network topologies(previous research object for wireless worms is the mobile network),Homogenous population of network devices(properties of network devices are the same), andInaccuracy of propagation models(traditional deterministic differential or stochastic difference models cannot model propagation of wireless hybrid worms accurately). To address them, we propose a novel compartmental population-based propagation model oriented towards heterogeneous and hierarchical networks with human behaviors, and then study the impacts of user mobility and operation behaviors on worm propagation. Meanwhile, we conduct extensive simulations to show our model can characterize propagation features accurately. The results in this paper not only provide a deep understanding of new worm propagation, but also serve as fundamental defense guidelines.
Tianbo Wang 0001, Chunhe Xia, Xiaojian Li 0002, Yang Xiang 0001
IEEE Trans. Mob. Comput.3
2020 A Novel Violation Tracing Model for Cloud Service Accountability
abstract
There are essential differences in the tracing to attacks versus violations. Attack tracing cannot be used, and there is no directly applicable model of violation tracing. To assist cloud service accountability, this paper presents a violation tracing (VTR) model that extracts the violation points originating from or involved with the claim point(s). In this process, in addition to determining the internal responsibility of the current point, we also need analyze the external factors possibly causing the violation of the current point. This enables us to infer the next hops that are violated, instead of simply jumping to the end to find an isolated original point(s) of the violation, and then organize them into a violation chain with the weight of responsibility. We validate our violation chain by a VTR experiment based on Alibaba's dataset. The results show some characteristics of the VTR: trace extraction, analysis of violation cause, and measure of responsibility weight. Because of these characteristics, the functional integrity of VTR reaches 0.833, which is much higher than those of other traditional tracing methods (<; 0.500). Thus, the presented method has superior functional completeness.
Xiaojian Li 0002, Hailan Wang, Haopeng Yang
TrustCom1
2020 A behavior-aware SLA-based framework for guaranteeing the security conformance of cloud service
Chunhe Xia, Tianbo Wang 0001, Xiaojian Li 0002
Frontiers Comput. Sci.5
2010 A Tactical Intelligence Production Model of Computer Network Self-Organizing Operations
Shan Yao, Chunhe Xia, Xiaojian Li 0002
ICIC (2)4
2007 P2P worm detection based on application identification
Chunhe Xia, Yunping Shi, Xiaojian Li 0002
Frontiers Comput. Sci. China3