Ying Hu 0007

dblp:92/4882-7 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0002-6261-6965ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Network security · 100%
Computer networks
1 paper
Network measurement and analytics · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics › protocol analysis
protocol reverse engineering
1.012026
Private Protocol Reverse Engineering via Self-Supervised Learning-Based Message Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Network security
protocol reverse engineering
1.012026
Private Protocol Reverse Engineering via Self-Supervised Learning-Based Message Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Network security
traffic analysis
1.012026
Private Protocol Reverse Engineering via Self-Supervised Learning-Based Message Segmentation · IEEE Trans. Inf. Forensics Secur. 2026

Methods — techniques the papers use, named apart from their topics

self-supervised learning · 2.0
YearPublicationVenuePosition
2026 Private Protocol Reverse Engineering via Self-Supervised Learning-Based Message Segmentation
Junchen Li, Guang Cheng 0001, Ying Hu 0007, Qinghua Shang
IEEE Trans. Inf. Forensics Secur.4
2025 Attention-based Multi-label Multi-class Classification for Multiplexed VPN Traffic Identification
Ying Hu 0007, Guang Cheng 0001, Deyu Zhao
IEEE Big Data1
2022 Attribute-Based Zero-Shot Learning for Encrypted Traffic Classification
abstract
As more and more network applications have adopted encryption for user privacy, it poses a great challenge to identify increasing types of encrypted traffic. Recent methods mainly focus on leveraging machine learning or deep learning to improve the effectiveness of classification, and achieve good results in their experiments. However, most methods are developed for a limited number of traffic types on a close-world dataset, lacking the ability to transfer knowledge learned from available labeled data of known classes to the identification of unknown classes, of which the data is unseen during training. In this paper, we propose a novel attribute-based zero-shot learning (ZSL) framework for encrypted traffic classification, with both fine granularity for general classification and good scalability for identifying unknown classes. The framework is based on our defined attribute semantic space, consisting of two components: i) a feature-attribute embedding model to learn the mapping between flow features and attributes from seen classes. We use Temporal Convolution Network (TCN) for flow feature embedding and Simple Recurrent Units (SRU) for attribute embedding, with attention mechanisms introduced in both models for interpretability. ii) a GAN-based feature generation model FAE-G that leverages the trained FAE model to improve the generalization of the classifier for unseen classes. For generalized ZSL (GZSL) tasks, we introduce gradient-based rejection to classify both seen and unseen classes in a two-step way. The experimental results demonstrate that our method shows excellent performance in fine-grained classification, and also achieves presentable results in the identification of unknown classes.
Ying Hu 0007, Guang Cheng 0001, Bomiao Jiang
IEEE Trans. Netw. Serv. Manag.1
2021 RT-SAD: Real-Time Sketch-Based Adaptive DDoS Detection for ISP Network
abstract
With the great changes in network scale and network topology, the difficulty of DDoS attack detection increases significantly. Most of the methods proposed in the past rarely considered the real-time, adaptive ability, and other practical issues in the real-world network attack detection environment. In this paper, we proposed a real-time adaptive DDoS attack detection method RT-SAD, based on the response to the external network when attacked. We designed a feature extraction method based on sketch and an adaptive updating algorithm, which makes the method suitable for the high-speed network environment. Experiment results show that our method can detect DDoS attacks using sampled Netflowunder high-speed network environment, with good real-time performance, low resource consumption, and high detection accuracy.
Haibin Shi, Guang Cheng 0001, Ying Hu 0007, Fuzhou Wang, Haoxuan Ding
Secur. Commun. Networks3
2020 A practical design of hash functions for IPv6 using multi-objective genetic programming
Ying Hu 0007, Guang Cheng 0001, Yongning Tang, Feng Wang 0017
Comput. Commun.1