EDBT 2026 Demo / reviewers in the wild / expert
Changzhi Zhao
dblp:97/2179
· DBLP profile ↗
11ranked-venue papers
1as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GARNET: GoT-Based Alert Reduction and Narrative Event TracingabstractAlerts generated by Security Operations Centers (SOCs) are often numerous and scattered, requiring significant effort from security analysts to manage, which severely slows response times. While recent alert correlation graph methods can effectively reduce alert volume, these graphs are often too complex for analysts to understand. As a result, analysts are increasingly seeking ways to automatically correlate alerts and generate concise, human-readable attack path summaries. Recently, Large Language Models (LLMs) have demonstrated superior performance due to their advanced capabilities in knowledge reserve and reasoning. In this work, we propose GARNET, a framework that uses LLMs for reasoning on alert correlation graphs. GARNET addresses three key technical challenges: 1) modality alignment between alert graphs and logs; 2) semantic alignment between alert graphs and logs; 3) enabling LLMs reasoning along graph paths. Specifically, we first project the embeddings of the graph and logs into the same vector space using contrastive learning. Then, we design self-supervised graph-log instructions to bridge the semantic gap between the graph and logs by training a novel LLM. Finally, GARNET uses a novel Graph-of-Thought (GoT)-based interaction reasoning approach to guide LLM reasoning along graph paths, ultimately generating structured, concise, and human-readable attack path summaries. Experimental results across six attack scenarios show that GARNET reduces false positives by an average of 80%, lowering the false positive rate to below 0.0037. It outperforms the latest approaches and provides more explainable attribution. Yiru Gong, Changzhi Zhao, Bo Jiang 0013, Zhigang Lu 0002 |
AAAI | 3 |
| 2026 | Robust Malicious Network Traffic Detection Framework With Automated Drift Detection, Identification, and AdaptationabstractThe rise in network attacks has made robust malicious traffic detection crucial. However, the dynamic nature of network traffic causes concept drift, undermining the efficacy of traditional detection methods, which often rely on a static i.i.d data environment and struggle to adapt to new patterns. To overcome these limitations, we propose Argus, a novel framework for malicious traffic detection that operates in a comprehensive, automated, and adaptive manner. Argus tackles three core challenges: accurately classifying known traffic while detecting drift, automatically identifying malicious drifting traffic, and maintaining performance through continuous updates. To address these challenges, Argus integrates a contrastive learningbased module to produce compact representations of traffic and implements a fine-grained drift detection method using category-specific reconstruction loss distributions. For drifting traffic, Argus uses clustering-based automated identification to detect attacks without human intervention. Furthermore, a distance-constrained update mechanism ensures smooth model adaptation, preserving stability and accuracy. Extensive experiments demonstrate that Argus achieves superior performance, with an average F1 score exceeding 95% under various conditions and retaining robust performance even under extreme drift scenarios. Xueying Han, Changzhi Zhao, Weike Fang, Weihang Wang 0001, Bo Jiang 0013, Susu Cui, Zhigang Lu 0002, Baoxu Liu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | HINHJ: Hierarchical Attention-Based Heterogeneous Graph Neural Network for DNS Hijacking DetectionabstractThe Domain Name System (DNS) is a critical internet infrastructure that translates human-readable domain names into machine-routable IP addresses. However, DNS is inherently vulnerable to manipulation, with hijacking attacks growing in both frequency and sophistication. Existing detection methods primarily rely on traffic analysis at specific network points. However, they suffer from limited coverage and low accuracy in complex environments, such as when CDN is employed. While recent approaches employ graph-based techniques, they still suffer from detection inaccuracy issues due to their failure to account for the complex interdependencies among multiple types of nodes. To address these limitations, we propose a novel heterogeneous graph-based detection framework. Based on the collected DNS records from distributed scanners, our method extracts activity and security features and constructs a heterogeneous graph to capture resolution patterns and cross-entity relationships. We further design a time-decay graph neural network TNHAN that enhances traditional Heterogeneous Graph Attention Networks (HAN) by dynamically weighting recent records. This network improves adaptability to legitimate DNS changes. For evaluation, we conduct experiments on real-world resolvers and domain datasets. Experiment results demonstrate the effectiveness of our method. Our method can achieve an F1-score of 0.96, outperforming the best baseline by 0.057 on average, and up to 0.113 under low label proportion. Moreover, we conduct several case studies on detected incidents, including cases related to geopolitical conflicts, censorship-related hijacking, and manipulation by malicious resolvers. These cases demonstrate the method’s effectiveness in identifying diverse hijacking behaviors in practice. Haoran Jiao, Cong Dong, Chenglong Li 0006, Jiahai Yang 0001, Leyao Nie, Changzhi Zhao, Xia Yin 0001 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | An Approach for Attack Chain Context Inference and Completion Based on Large Language ModelsabstractAlert underreporting presents a significant challenge to the reconstruction of attack chains, as it often leads to the absence of critical information necessary for fully presenting the entire attack. To address this issue, this paper proposes an approach for attack chain context inference and completion based on Large Language Models. By integrating an attack knowledge base, this approach leverages LLM-driven inference to identify missing attack stages and uncover potential attack behaviors. Experimental results demonstrate that this approach can effectively detect omitted alerts and complete the attack chain, thereby enhancing the integrity of attack detection. Dan Du, Changzhi Zhao, Yunpeng Li 0006, Dongxu Han, Bo Jiang 0013, Zhigang Lu 0002 |
SMC | 2 |
| 2025 | A zero-shot self-improving NER method for cyber threat intelligence via knowledge injectionabstractAbstract The rapid evolution of cyber threats demands efficient entity extraction from Cyber Threat Intelligence (CTI) reports to support proactive analysis and sharing. Current methods for CTI extraction falter due to a lack of domain knowledge, which can lead to the overlooking of critical entities. Moreover, the hallucinations in LLM’s outputs result in insufficient accuracy. To address these limitations, we propose a zero-shot, self-improving NER method for CTI via knowledge injection. The framework consists of four modules: a domain knowledge extractor, a reliable data annotator, a high-consistency annotation filter, and a self-retrieval reasoner. The domain knowledge extractor enhances LLM comprehension of specialized threat intelligence, while the others work in a multi-stage reasoning process to mitigate hallucinations by generating, filtering, and reasoning upon high-consistency data. These modules collaborate to improve the model’s entity recognition ability through continuous in-context learning. Experimental results show that under strict zero-shot conditions, the proposed method achieves F1 scores of 67.7%, 61.41%, 74.56%, and 65.83% on the LLM-TIKG, APT-NER, LADDER, and CDTier datasets, respectively. This represents an improvement of 7.66% over the average F1 score of other baseline methods, demonstrating superior adaptability in low-resource security scenarios. Yingchang Jiang, Feiyang Li, Changzhi Zhao, Canhua Chen |
Cybersecur. | 5 |
| 2024 | Multi-language Webshell Detection based on Abstract Syntax Tree and TreeLSTMabstractWebshell is a command execution environment existing in web containers, which is used by attackers to remotely control servers and illegally access website resources. Accurately detecting Webshells is of great significance for maintaining web security. Current research faces several challenges. On the one hand, in order to evade detection, Webshells use a large amount of obfuscation, and existing research methods often use source code or opcode, which cannot fully utilize the semantic and syntactic information of Webshell code. On the other hand, Webshells can be constructed using any web application programming language, while most existing methods only detect one or a few types of Webshells. This paper proposes a novel approach called WS-Tree, which effectively utilizes the semantics and syntax of Webshells by using abstract syntax tree as input features. The TreeLSTM model is used as an encoder to handle node relationships in the syntax tree, thereby achieving the detection of obfuscated and multi-language Webshells. We also propose a new dataset of Webshells containing obfuscated and non-obfuscated to prevent dataset leakage. Extensive experiments demonstrate that our proposed model performs better than the state-of-theart baselines under different webshell programming languages and improves model generalizability. Mengchuan Shang, Xueying Han, Changzhi Zhao, Zelin Cui, Dan Du, Bo Jiang 0013 |
CSCWD | 3 |
| 2024 | FREDet: Fine-Grained Malicious Traffic Detection Based on Frequency Domain FeaturesabstractMachine learning methods have shown significant advantages in detecting malicious traffic, particularly identifying zero-day attacks and unknown threats. However, existing detection methods based on statistical features are susceptible to deception and evasion by attackers, resulting in reduced detection accuracy and challenges in achieving fine-grained detection. To address these issues, we propose FREDet, a fine-grained malicious traffic detection method based on frequency domain features. FREDet employs discrete wavelet transform to extract frequency domain features from network traffic and incorporates a new traffic aggregation method, significantly enhancing feature representativeness and detection accuracy for robust, fine-grained detection. Experiments on a multi-type attack dataset demonstrate that FREDet can detect malicious traffic with high precision, outperforming existing state-of-the-art methods, achieving accuracies of over 98.63% and 99.93% in detecting fine-grained attack categories and known attack subcategories, respectively. Zekai Song, Yunpeng Li 0006, Changzhi Zhao, Dongxu Han |
TrustCom | 4 |
| 2023 | TAElog: A Novel Transformer AutoEncoder-Based Log Anomaly Detection Method
Changzhi Zhao, Kezhen Huang, Xueying Han, Dan Du, Yutian Zhou, Zhigang Lu 0002 |
Inscrypt (2) | 1 |
| 2019 | sRNAPrimerDB: comprehensive primer design and search web service for small non-coding RNAsabstractMOTIVATION: Small non-coding RNAs (ncRNAs), especially microRNAs (miRNAs) and piwi-interacting RNAs (piRNAs), play key roles in many biological processes. However, only a few tools can be used to develop the optimal primer or probe design for the expression profile of small ncRNAs. Here, we developed sRNAPrimerDB, the first automated primer designing and query web service for small ncRNAs. RESULTS: The primer online designing module of sRNAPrimerDB is composed of primer design algorithms and quality evaluation of the polymerase chain reaction (PCR) primer. Five types of primers, namely, generic or specific reverse transcription primers, specific PCR primers pairs, TaqMan probe, double-hairpin probe and hybridization probe for different small ncRNA detection methods, can be designed and searched using this service. The quality of PCR primers is further evaluated using melting temperature, primer dimer, hairpin structure and specificity. Moreover, the sequence and size of each amplicon are also provided for the subsequent experiment verification. At present, 531 306 and 2 941 669 primer pairs exist across 223 species for miRNAs and piRNAs, respectively, according to sRNAPrimerDB. Several primers designed by sRNAPrimerDB are further successfully validated by subsequent experiments. AVAILABILITY AND IMPLEMENTATION: sRNAPrimerDB is a valuable platform that can be used to detect small ncRNAs. This module can be publicly accessible at http://www.srnaprimerdb.com or http://123.57.239.141. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Shengsong Xie, Wubin Qu, Zhong Xu, Xinyun Li, Wubin Ma, Yiliang Miao, Lisheng Zhang, Wuzi Dong, Changzhi Zhao, Yaping Fang, Shuhong Zhao |
Bioinform. | 14 |
| 2012 | Anticipatory active monitoring for safety- and security-critical software
Wei Dong 0006, Changzhi Zhao, Shaoxian Shu, Martin Leucker |
Sci. China Inf. Sci. | 2 |
| 2008 | Automating Software FMEA via Formal Analysis of Dependence RelationsabstractThe paper presents the ongoing work of studying FMEA method for embedded safely critical software via formal analysis of various dependence relations among software elements, which can fairly improve the automation and precision of both system level and detailed level FMEA. These dependence relations are depicted by the formal models abstracted from software design and implementation, and the FMEA processes for both structural and object-oriented software are proposed respectively. The initial result of case study shows the effectiveness of the approach. Wei Dong 0006, Ji Wang 0001, Changzhi Zhao |
COMPSAC | 3 |