Most Read articles

    Published in last 1 year |  In last 2 years |  In last 3 years |  All

    Published in last 1 year
    Please wait a minute...
    For Selected: Toggle Thumbnails
    Journal of Information Security Reserach    2025, 11 (E2): 277-.  
    Abstract1016)      PDF (1198KB)(13)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E1): 19-.  
    Abstract836)      PDF (1799KB)(24)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 80-.  
    Abstract793)      PDF (1807KB)(20)       Save
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E2): 295-.  
    Abstract432)      PDF (893KB)(14)       Save
    Reference | Related Articles | Metrics
    A Survey on Backdoor Attacks and Defenses in Federated Learning
    Journal of Information Security Reserach    2025, 11 (9): 778-.  
    Abstract272)      PDF (2638KB)(78)       Save
    Federated learning is a machine learning framework that enables participants in different fields to participate in largescale centralized model training together under the condition of protecting local data privacy. In the context of addressing the pressing issue of data silos, federated learning has rapidly emerged as a research hotspot. However, the heterogeneity of training data among different participants in federated learning also makes it more vulnerable to model robustness attacks from malicious participants, such as backdoor attacks. Backdoor attacks inject backdoors into the global model by submitting malicious model updates. These backdoors can only be triggered by carefully designed inputs and behave normally when input clean data samples, which poses a great threat to the robustness of the model. This paper presents a comprehensive review of the current backdoor attack methods and backdoor defense strategies in federated learning. Firstly, the concept of federated learning, the main types of backdoor attacks and backdoor defenses and their evaluation metrics were introduced. Then, the main backdoor attacks and defenses were analyzed and compared, and their advantages and disadvantages were pointed out. On this basis, we further discusses the challenges of backdoor attacks and backdoor defenses in federated learning, and prospects their research directions in the future.
    Reference | Related Articles | Metrics
    A Symbioticbased Framework for AI Safety Governance
    Journal of Information Security Reserach    2025, 11 (10): 897-.  
    Abstract272)      PDF (2070KB)(75)       Save
    Artificial intelligence technology is currently developing at an unprecedented pace, with safety concerns becoming a global focal point. Traditional AI safety research has predominantly relied on a “control paradigm”, emphasizing limitations, regulations, and value alignment to control AI behavior and prevent potential risks. However, as AI capabilities continue to strengthen, unidirectional control strategies are revealing increasingly significant limitations, with issues such as transparency illusions, adversarial evolution, and innovation suppression gradually emerging. Industry leaders like Sam Altman and Dario Amodei predict that AI may comprehensively surpass human capabilities in multiple fields within the next 23 years, making the reconstruction of AI governance paradigms particularly urgent. This paper proposes a new perspective—the “symbiotic paradigm”—emphasizing humanmachine collaboration as the core and understanding and trust as the foundation. Through establishing four pillars: transparent communication, bidirectional understanding, creative resonance, and dynamic boundaries, it promotes AI safety’s transition from control to cocreation, serving as one of the foundational paths for digital governance transformation. This paper systematically demonstrates the feasibility and necessity of the symbiotic paradigm through four dimensions: theoretical analysis, technological paths, practical cases, and governance recommendations, aiming to provide a sustainable alternative for future AI safety research and digital governance practices.
    Reference | Related Articles | Metrics
    Design of a Large Model Data Supervision System Based on Blockchain
    Journal of Information Security Reserach    2025, 11 (8): 682-.  
    Abstract244)      PDF (2618KB)(85)       Save
    Large model (LM) has shown great potential in the fields of natural language processing, image and speech recognition, and has become a key force driving the technological revolution and social progress. However, the wide application of LM technology brings challenges such as data privacy risks, data compliance regulation, and data regulatory activation and intelligence.  This paper aims to explore how to utilize blockchain to design and construct an effective data regulatory system to promote its healthy development, in order to meet the challenges brought by the application of massive data to LM. This paper analyzes the trends and current status of the development of LM at home and abroad, and points out the main challenges to LM data regulation, including data privacy risks, data compliance, and the difficulty of effective supervision by regulators . A blockchainbased data regulation system design scheme is proposed to address these challenges, which realizes the fullcycle data regulation of LM data from the native metadata to the input of training until the posttraining feedback through four interconnected modules, namely, privacy protection, consensus algorithm, incentive mechanism, and smart contract. Finally, the application prospect of blockchain in LM data supervision is summarized, and the future trend of data supervision is outlooked.
    Reference | Related Articles | Metrics
    Fake News Detection Model Based on Crossmodal Attention Mechanism and#br#  Weaksupervised Contrastive Learning#br#
    Journal of Information Security Reserach    2025, 11 (8): 693-.  
    Abstract216)      PDF (1508KB)(49)       Save
    With the widespread popularization of the Internet and smart devices, social media has become a major platform for news dissemination. However, it also provides conditions for the widespread of fake news. In the current social media environment, fake news exists in multiple modalities such as text and images, while existing multimodal fake news detection techniques usually fail to fully explore the intrinsic connection between different modalities, which limits the overall performance of the detection model. To address this issue, this paper proposes a hybrid model of crossmodal attention mechanism and weaksupervised contrastive learning(CMAWSCL) for fake news detection. The model utilizes pretrained BERT and ViT models to extract text and image features respectively, and effectively fuses multimodal features through the crossmodal attention mechanism. At the same time, the model introduces weaksupervised contrast learning, which utilizes the prediction results of effective modalities as supervisory signals to guide the contrast learning process. This approach can effectively capture and utilize the complementary information between text and image, thus enhancing the performance and robustness of the model in multimodal environments. Simulation experiments show that the CMAWSCL performs well on the publicly available Weibo17 and Weibo21 datasets, with an average improvement of 1.17 percentage points in accuracy and 1.66 percentage points in F1 score compared to the current stateoftheart methods, which verifies its effectiveness and feasibility in coping with the task of multimodal fake news detection.
    Reference | Related Articles | Metrics
    TCNGANbased Temporal Traffic Anomaly Detection
    Journal of Information Security Reserach    2025, 11 (10): 907-.  
    Abstract210)      PDF (2708KB)(57)       Save
    In recent years, generative adversarial networks have been widely used in the field of temporal anomaly detection. However, temporal data often has complex timedependence, and problems such as gradient vanishing and training instability are common in existing anomaly detection models. To this end, this paper proposes an unsupervised temporal traffic anomaly detection model based on the combination of temporal convolutional network (TCN) and GAN. The model uses TCN as the infrastructure of generator and discriminator, which can effectively capture the temporal features of the temporal traffic data. During the anomaly detection process, the model constructs an anomaly scoring function based on the reconstruction loss and discriminator loss, and performs anomaly judgment by setting a threshold, thus improving the accuracy of anomaly detection. To verify the performance of the proposed model, experiments are conducted on five different types of datasets. The results show that the average F1 score of the proposed model is 11.02% higher than that of the TAnoGAN model.
    Reference | Related Articles | Metrics
    Research on Critical Information Infrastructure Security Protection
    Journal of Information Security Reserach    2025, 11 (10): 878-.  
    Abstract199)      PDF (324KB)(76)       Save
    Related Articles | Metrics
    Research on Network Unknown Attack Detection Based on Machine Learning#br#
    #br#
    Journal of Information Security Reserach    2025, 11 (9): 807-.  
    Abstract190)      PDF (1297KB)(47)       Save
    In the complex context of the continuous evolution of cybersecurity threats, the threats posed by unknown network attacks to digital infrastructure are increasing daily. Consequently, The technology for detecting unknown network attacks based on machine learning has emerged as a focal point in research. This paper first discusses the classification of intrusion detection systems and the commonly used technologies for detecting unknown network attacks. Subsequently, it conducts an indepth exploration of the methods for detecting unknown attacks based on machine learning from three dimensions: anomaly detection, openset recognition, and zeroshot learning. Furthermore, it summarizes the commonly used datasets and key evaluation indicators. Finally, it summarizes and looks ahead to the development trends and challenges of unknown attack detection. This article can provide references for further exploring new methods and technologies in the field of cyberspace security.
    Reference | Related Articles | Metrics
    Research on Security Assurance of Egovernment
    Journal of Information Security Reserach    2025, 11 (10): 879-.  
    Abstract189)      PDF (865KB)(56)       Save
    government encompasses critical domains including government operations, public services, and data management, and its security directly affects national interests, public wellbeing, and social stability. In recent years, cyberattacks targeting Egovernment systems have become more frequent and continue to rise, security risks of government administrative networks continued to mount up and challenge security protection. This paper analyzes the development paths of Egovernment security protection at home and abroad and proposes relevant policy recommendations, with the aim of providing strong support for building a more perfect and optimized Egovernment security protection system.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E1): 9-.  
    Abstract189)      PDF (1462KB)(18)       Save
    Reference | Related Articles | Metrics
    Encrypted Traffic Detection Method Based on Knowledge Distillation
    Journal of Information Security Reserach    2025, 11 (8): 702-.  
    Abstract179)      PDF (2774KB)(54)       Save
    In recent years, with the rapid growth of Internet traffic, especially the popularity of encrypted communication, malicious traffic detection is facing a huge challenge, due to the limited resources and performance of mobile devices, which makes it more difficult to identify malicious behaviors in encrypted traffic on mobile. Therefore this paper proposes a knowledge distillation based encrypted traffic detection method. First, the traffic is transformed into images through visualization techniques; second, based on the ConvNeXt network architecture, the SK_SwiGLU_ConvNeXt network is constructed as the teacher network by introducing the SKNet attention mechanism and replacing the activation function GELU with SwiGLU; finally, the lightweight MobileNetV2 is selected as the student network and the use the teacher network to guide the student network training. The experimental results of this paper’s detection method on the publicly available dataset ISCX VPNNonVPN show that even in the resourceconstrained mobile device environment, the student network can improve the detection effect of the teacher model while reducing the model complexity, which proves that this method has efficient deployment potential on mobile devices.
    Reference | Related Articles | Metrics
    Research on Traffic Anomaly Detection Method and System for API Gateway
    Journal of Information Security Reserach    2025, 11 (10): 917-.  
    Abstract171)      PDF (1061KB)(40)       Save
    With the rise of cloud services and the widespread use of API technology, many network capabilities of operators are usually outputted and empowered through APIs. API gateways have become an important way for northsouth and eastwest system interconnection and data sharing. This paper proposes a method for API gateway traffic anomaly detection based deep learning. Firstly, a heterogeneous graph is constructed to comprehensively represent the gateway traffic network. Then, based on graph attention neural network, node representations in the heterogeneous graph are learned by considering both structural and temporal dimensions. We introduce graph structure refinement to compensate for sparse connections between entities in the heterogeneous graph and obtain more robust node representation learning; Finally, the meta learning algorithm is used to optimize the model and improve its generalization ability in small sample scenarios. The model can be deployed on gateway devices. The algorithm model was experimentally evaluated on the CICIDS2017 dataset, and the results showed that compared with the baseline algorithm, the detection method proposed in this paper has good performance in small sample and multi classification problems.
    Reference | Related Articles | Metrics
    Implicit Harmful Text Detection Technology Based on Knowledgeenhanced #br# Multitask Learning#br#
    Journal of Information Security Reserach    2025, 11 (8): 718-.  
    Abstract170)      PDF (1578KB)(57)       Save
    A large number of harmful texts on the Internet adopt implicit and euphemistic expressions to evade detection by censorship systems. Most of the current work focuses on explicit harmful speech and cannot effectively detect implicit harmful text. This paper investigates the detection of implicit euphemistic harmful text in Chinese using a multitask learning approach, where euphemistic sentence recognition is used to assist harmful text detection. Firstly, methods for integrating euphemistic language vocabulary features are explored to enhance the model’s representation of implicit meanings. Subsequently, contrastive learning is applied to enhance latent semantic representations and extract common features from implicitly harmful discourse. Finally, a multitask learning framework is constructed by combining euphemistic sentence recognition tasks with harmful text detection tasks, aiming to improve the detection performance through shared multitask parameters and multifeature fusion loss functions. The experimental results demonstrate the effectiveness of the model in detecting implicit harmful text.
    Reference | Related Articles | Metrics
    The Enlightenment and Reference of Cybersecurity Protection Policies for  Critical Information Infrastructure
    Journal of Information Security Reserach    2025, 11 (10): 885-.  
    Abstract168)      PDF (920KB)(36)       Save
    The security and stability of critical information infrastructure (CII) are of crucial importance to national security, economic development, and social stability. The insights and lessons learned from the CII security safeguards policies of countries and organizations such as the European Union, Japan, the United States, and Russia merit reference. CII security safeguards policies in China has gone through the stages of early exploration, rapid development, and comprehensive advancement; it is confronted with real predicaments including insufficient policy foresight, inadequate crossdomain coordination and collaboration, poor coordination and alignment of standards, and weak discourse power in international rules. It is suggested that China should strengthen the strategic guidance and toplevel design for CII, improve the crossdomain overall planning and linkage mechanism, formulate and refine CII protection standards.
    Reference | Related Articles | Metrics
    Compound Admissibility Rules of Blockchain Evidence in Online Litigation
    Journal of Information Security Reserach    2026, 12 (2): 134-.  
    Abstract163)      PDF (1088KB)(46)       Save
    Blockchain evidence offers a solution to the limitations of traditional electronic evidence by establishing a new model of “evidence selfauthentication”. However, current regulations in China exhibit obvious limitations, failing to fully cover the application of blockchain evidence in both online and offline spaces, while prioritizing authenticity at the expense of admissibility. To realize the proper application of blockchain evidence in the Chinese context, this paper proposes a dualspace framework integrating technological selfauthentication with legal presumptions. This approach aims to achieve consensual justice, composite admissibility rules for preservation, presentation, crossexamination, and authentication, and thereby foster a novel form of evidence rule of law with benign interaction between rule of law and technical rule of law.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2026, 12 (2): 98-.  
    Abstract162)      PDF (532KB)(124)       Save
    Related Articles | Metrics
    Research on Analysis and Detection Methods of Adversarial Crosssite #br# Scripting Attacks Based on LSTM and CNN#br#
    Journal of Information Security Reserach    2025, 11 (8): 761-.  
    Abstract160)      PDF (1115KB)(35)       Save
    In recent years, machine learning and deep learning techniques have achieved significant success in detecting crosssite scripting (XSS) attacks. However, they still face challenges in defending adversarial attacks. To address this issue, this paper proposes an optimized method based on soft actorcritic (SAC) reinforcement learning combined with long shortterm memory (LSTM) and convolutional neural network (CNN). Firstly, adversarial samples are generated by leveraging the SAC and LSTMCNN detection model to simulate attacker strategies. These samples are then used for incremental training of the detection model, progressively narrowing the adversarial data generation space and improving the model’s robustness and detection accuracy. Experimental results show that the generated adversarial data achieves an evasion success rate of over 90% across multiple detection tools. After incremental training, the detection model’s defense capability against adversarial XSS attacks is significantly enhanced, with the evasion rate continuously decreasing.
    Reference | Related Articles | Metrics
    Research on Frontier Technologies for Critical Information  Infrastructure Security Protection
    Journal of Information Security Reserach    2025, 11 (12): 1075-.  
    Abstract153)      PDF (994KB)(48)       Save
    Currently, China’s critical information infrastructure (CII) faces significant threats, including statesponsored cyber attacks and supply chain disruptions. This research aims to systematically analyze the key technological frameworks and development trends in CII security protection, assess China’s current technological capabilities and core bottlenecks in this domain, and propose development strategies and implementation pathways aligned with national conditions. Focusing on key technology clusters such as dynamic active defense, intelligent analysis and response, and resilience architectures, the study explores their synergistic application mechanisms and integration points with existing policies. The study seeks to provide critical technical support and policy recommendations for enhancing the security resilience and compliance of CII.
    Reference | Related Articles | Metrics
    A Deep Learning Differential Privacy Protection Scheme Based on  Adaptive Clipping
    Journal of Information Security Reserach    2026, 12 (6): 490-.  
    Abstract149)      PDF (1728KB)(94)       Save
    To address the issues of utility degradation in deep learning models under differential privacy protection and the gap between theoretical and actual privacy protection effectiveness, this paper proposes a deep learning differential privacy protection scheme based on adaptive clipping. The scheme optimizes the process through a fourstep mechanism: firstly, gradient adaptive clipping controls the gradient magnitude during training by dynamically adjusting the gradient clipping threshold, thereby enabling the control of the magnitude of noise added subsequently; secondly, group label selection identifies the group with the smallest gradient as the privacypreserving object, and more accurate privacy loss can be obtained by training this group; thirdly, optimized privacy loss calculation combines the gaussian mechanism based on subsampling to reduce the computational overhead of model privacy loss calculation; finally, optimized gradient adaptive descent realizes the adaptive descent of gradients by adjusting the conditional smoothing parameter, thus improving the usability of the model. Experiments were conducted on the VGG architecture using the MNIST, CIFAR10, and MedicalMNIST datasets. The results show that the model accuracy rates after training with this scheme are 81.08%, 72.30%, and 67.91% respectively, representing improvements of 15.60%, 10.60%, and 9.71% compared to the traditional DPSGD, and 0.63%, 2.50%, and 4.40% over the widely used Nadam algorithm in recent years. The model training efficiency has been improved by 35.5% and 39.4%, respectively.
    Reference | Related Articles | Metrics
    Internet of Things Intrusion Detection Model Based on Federated Learning
    Journal of Information Security Reserach    2025, 11 (9): 788-.  
    Abstract148)      PDF (1432KB)(39)       Save
    The Internet of things (IoT) has shown a wide range of application prospects and huge development potential in many fields. However, as the scale of the IoT continues to expand, independent IoT devices lack highquality attack instances, making it difficult to effectively respond to increasingly complex and diverse attack behaviors. Consequently, addressing IoT security issues has become a critical challenge that requires urgent attention. To address this problem, the paper proposes an IoT intrusion detection model based on federated learning and attention mechanisms, which allows multiple devices to train the global model collaboratively while protecting their data privacy. Firstly, this paper constructs an intrusion detection model combining convolutional neural network and mixed attention mechanism to extract key features of network traffic data, so as to improve detection accuracy. Secondly, the paper introduces the model contrast loss to correct the training direction of the local model to alleviate the global model convergence difficulties caused by the nonindependent and same distribution of data between devices. The experimental results show that the proposed model is significantly superior to the existing methods in terms of accuracy, accuracy and recall, demonstrating stronger intrusion detection capabilities, and can effectively deal with complex data distribution problems in the IoT environment.
    Reference | Related Articles | Metrics
    SM9based Decentration Crosschain Medical Data Sharing Scheme
    Yu Huifang and Li Shunkai
    Journal of Information Security Reserach    2025, 11 (9): 832-.  
    Abstract146)      PDF (2204KB)(64)       Save
    To solve the problems of data leakage and data silos between medical institutions in medical system, a SM9based decentration crosschain medical data sharing scheme (DCCMDSS) is proposed in this article. Relay chain and hash time lock contract (HTLC) realize the crosschain data sharing between medical institutions, the interplanetary file system (IPFS) reduces the storage pressure of blockchain and ensures the integrity of medical data. SM9based algorithm encrypts medical data and group signature allows the group members to sign the data on behalf of the whole group without revealing their personal identities. Consequently, DCCMDSS effectively avoids the privacy leakage and ensures the traceability of signature. DCCMDSS reduces the crosschain transaction overhead and improves the security of medical data.
    Reference | Related Articles | Metrics
    Government Data Catalog Security Sharing Model Based on Editable Blockchain
    Journal of Information Security Reserach    2025, 11 (10): 966-.  
    Abstract146)      PDF (6159KB)(72)       Save
    As government demand for data sharing rises, ensuring data security and reliability has become critical. This paper proposes a secure sharing model for government data catalogs using editable blockchain, which facilitates collaborative updates both onchain and offchain, incorporates finegrained editing permissions, and implements robust security controls. The model employs a dualtrapdoor chameleon hash function with a temporary trapdoor key for onchain updates, addressing the problem that traditional key splitting and recovery schemes cannot balance security and efficiency. Additionally, it introduces an editing permission authorization mechanism that combines user IDbased multiinstitution attribute encryption with temporary trapdoor keys, ensuring accurate permission management across departments. A thorough security analysis confirms the model’s effectiveness in mitigating various security threats. The analysis reveals that the proposed model significantly enhances the trustworthiness of government data sharing by effectively addressing security challenges and ensuring data integrity. These findings highlight the potential of editable blockchain technology in transforming how government entities manage and share sensitive information.
    Reference | Related Articles | Metrics
    Lightweighted Mutual Authentication and Key Agreement in V2N IoV
    Journal of Information Security Reserach    2025, 11 (8): 753-.  
    Abstract144)      PDF (2403KB)(56)       Save
    Aiming at the scenario of vehicle secure access to application servers in the V2N (vehicle to network) environment, a Kerberos extension protocol is proposed based on the PUF (physical unclonable function). This protocol provides the twoway authentication and key agreement between the vehicle and the remoted application server and ensured the confidentiality and authentication of the V2N data transmission. The CRP (challenge response pair) generated by the PUF is used to replace the password in standard Kerberos to prevent the threats of key leakage caused by physical attacks such as intrusion, semiintrusion, sidechannel attacks, etc. The characteristics of Kerberos’s lightweighted twoway authentication protocol can overcome the defects of high calculation complexity and slow speed of the public key authentication algorithms, and effectively provide the secure data transmission between vehicles and application servers.
    Reference | Related Articles | Metrics
    Research on Domain Adaptive Intrusion Detection Method Based on  Dynamic Feature Fusion
    Journal of Information Security Reserach    2026, 12 (4): 294-.  
    Abstract144)      PDF (1452KB)(101)       Save
    Aiming at the problems of incomplete feature extraction and limited model generalization ability in intrusion detection research, a domain adaptive intrusion detection method with dynamic feature fusion is proposed. Firstly, a convolutional neural network is used to extract spatial features, while a bidirectional long shortterm memory network is utilized for temporal feature extraction. This approach enables comprehensive extraction of multidimensional feature information from network traffic data. Secondly, the uncertainty is measured by calculating the information entropy of the two features, and different weights are assigned according to the entropy value, and the extracted features are weighted and fused according to the weights. Finally, during the training process, the proposed adaptive domain weight loss algorithm is used to dynamically adjust the contribution of the source domain and target domain data to improve the generalization ability of the model on the target domain data. Experiments are carried out using the NSLKDD and UNSWNB15 datasets. Compared with the existing mainstream methods, this method has higher detection accuracy, which is 0.8563 and 0.916 respectively.
    Reference | Related Articles | Metrics
    Research on the Governance System of Ensuring Both Crossborder #br# Data Flow and Safety#br#
    #br#
    Journal of Information Security Reserach    2025, 11 (9): 840-.  
    Abstract142)      PDF (1493KB)(27)       Save
    Crossborder data flow is a fundamental part of digital trade, and it is also a key issue in the international data governance game. At present, China has preliminarily formed a system of rules and regulations for crossborder data flow, but there are still prominent problems such as difficulties in crossborder risk screening, slightly rough rules and systems, difficulties in the dominance of international rules, and weak crossborder regulatory means. To seriously  solve the problem of crossborder data flow, it is urgent to better coordinate development, security and openness to build a crossborder data governance system. The policy system clarifies basic propositions, improves the legal system, refines institutional rules, consolidates technology platforms and expands practice carriers, in order to align with highstandard international economic and trade rules, and gradually form a plan for crossborder data flow with Chinese characteristics.
    Reference | Related Articles | Metrics
    Robust Malicious Encrypted Traffic Detection Method Based on  Dual Confidence Sample Selection
    Journal of Information Security Reserach    2025, 11 (10): 924-.  
    Abstract137)      PDF (1679KB)(23)       Save
    In the task of detecting malicious encrypted traffic, the existence of noise tags seriously affects the generalization ability and detection accuracy of the model. To solve the above problems, a noise label learning method based on DCASS (dualconfidence adaptive sample selection) is proposed to realize robust malicious encryption traffic detection. Firstly, the low dimensional features of samples are extracted by self encoder, and the feature confidence of samples is constructed.Then, the label confidence of samples is evaluated according to their performance in classification training. Finally, an adaptive selection threshold is proposed to select samples based on the dual confidence of feature space and label space, and filter noise samples dynamically to improve the robustness of the model. Experiments on CIRACICDoHBrw2020 dataset show that the proposed method has good performance and stability in dealing with noise labels. The F1 scores of the method reach 86.686%, 86.749%, 83.199% respectively when the noise rate is 20%, 30%, 40%. Compared with the existing three methods, the method proposed in this paper shows the best performance under different noise rates, with the average performance improvement of 18.89%, 37.34%, 6.32% respectively.
    Reference | Related Articles | Metrics
    DGA Domain Name Generation Method of BiLSTM Model  Based on Bayesian HPO
    Journal of Information Security Reserach    2025, 11 (10): 950-.  
    Abstract136)      PDF (1488KB)(21)       Save
    In recent years, domain generation algorithms (DGA) have been extensively utilized in network attacks to dynamically generate large quantities of random domain names for malicious software communications, posing a severe challenge for security defenses. As DGA structures grow increasingly complex, traditional domain classification methods that rely on manually extracted features struggle to adapt to new variants in a timely manner. Although generationbased deep models can automatically capture latent patterns from data, their large parameter sizes and intricate hyperparameter tuning often hinder stable performance across diverse DGA. To tackle these issues, this paper proposes a DGA domain generation approach based on a bidirectional long shortterm memory (BiLSTM) model enhanced by Bayesian hyperparameter optimization(Bayesian HPO). By automating the tuning of critical hyperparameter, our method significantly reduces manual intervention and training overhead, while strengthening the robustness and generalization capability of the model against various DGA. Experimental results demonstrate that the proposed approach achieves excellent generation accuracy on multiple DGA families, providing a proactive, forwardlooking defense strategy for network security.
    Reference | Related Articles | Metrics
    Journal of Information Security Reserach    2025, 11 (E1): 14-.  
    Abstract136)      PDF (999KB)(39)       Save
    Reference | Related Articles | Metrics
    Research on Security Challenges and Countermeasures for Critical  Information Infrastructure in the Artificial Intelligence Era
    Journal of Information Security Reserach    2025, 11 (12): 1087-.  
    Abstract135)      PDF (944KB)(41)       Save
    With the rapid advancement of artificial intelligence (AI) technologies, critical information infrastructure is confronting unprecedented security challenges. This paper employs systematic analysis and comparative research methods to examine the security threats faced by critical information infrastructure in the AI era, specifically focusing on structural vulnerabilities, governance lag, and dual technical risks. Drawing on the strategic practices of major economies such as the United States, the European Union, and Japan, it proposes that China should enhance AI security policy standards, establish a security risk governance framework, and strengthen security technology innovation. Through these pathways, China can build a selfreliant, secure, and reliable AIenabled critical information infrastructure system, thereby enhancing national digital security capabilities and global competitiveness.
    Reference | Related Articles | Metrics
    Imperceptible Proactive Defense Method Against Face Attribute Editing
    Journal of Information Security Reserach    2025, 11 (10): 941-.  
    Abstract134)      PDF (2504KB)(24)       Save
    Although the face attribute editing forgery active defense method based on generative adversarial network (GAN) generates adversarial perturbations faster than the gradient attackbased methods, existing methods still fail in balancing the proactive defense effect with the imperceptibility of generated perturbations. Therefore, this paper proposed a highly imperceptible proactive defense method against face attribute editing based on GAN. To enhance the imperceptibility of the perturbations, the method designed a highfrequency information compensation mechanism to enable the generator to generate more highfrequency perturbations that are less sensitive to the human eye. To improve the proactive defense performance of generated perturbations, the proposed method also designed a multilevel dense connection mechanism for reducing semantic loss during the encoding process. Meanwhile, the method introduced face saliency adversarial loss in training stage to enable perturbations to disrupt face forgery areas better. The experiments were conducted in both singlemodel and crossmodel defense scenarios. The results indicate that compared to existing methods, the proposed method generates more imperceptible adversarial perturbations and obtains high success rates for defending against target models.
    Related Articles | Metrics
    Research on Highquality Development of New Infrastructures Under  Critical Information Infrastructure Security Protection
    Journal of Information Security Reserach    2025, 11 (10): 891-.  
    Abstract134)      PDF (957KB)(30)       Save
    Developing new infrastructure plays a crucial role in enhancing the security protection capabilities of critical information infrastructure. The approaches adopted by relevant countries in advancing new infrastructure—such as boosting global competitiveness, prioritizing key technology R&D, attracting deep private sector participation, promoting unified standards and regulations, and strengthening supply chain resilience—offer valuable insights. Although China’s new infrastructure has seen continuous improvements in recent years regarding development scale, technological autonomy, digital and intelligent capabilities, and its capacity to support critical infrastructure, it also faces challenges such as significant intrinsic security risks, risks associated with introducing new technologies, and lagging standardization efforts. It is recommended in terms of to drive the highquality development of new infrastructure by leveraging intelligent upgrades as the driving force, functional expansion as the connecting link, and boundary governance as the focal point.
    Reference | Related Articles | Metrics
    Design of Intrusion Detection System for Oil and Gas Production IoT #br# Based on Edgecloud Collaboration#br#
    Journal of Information Security Reserach    2025, 11 (9): 868-.  
    Abstract132)      PDF (2738KB)(21)       Save
    Aiming at the multifaceted intrusion threats in the oil and gas production IoT, this paper proposes an intrusion detection system based on edgecloud collaboration. The system is designed to meet the high requirements for realtime performance and accuracy, while overcoming challenges such as limited edge computing resources and data heterogeneity between edge and cloud environments. The system adopts a cloudedge collaborative architecture, with different intrusion detection subsystems deployed at the edgecloud, working in coordination to ensure comprehensive protection. The edge uses a model based on independent classification and joint analysis to accurately detect anomalies in multiple physical data, achieving detection speeds within 100 milliseconds. The cloud uses a model based on feature extraction + XGBoost, and adopts pretraining and finetuning to obtain a detection model with both anomaly traffic detection capability and low false alarm rate. The simulation results show that the system achieves high accuracy and realtime performance, adapts to the differences in available computing resources of the edge and cloud devices, and satisfies the performance requirements of intrusion detection across different levels.
    Reference | Related Articles | Metrics
    Research on Lightweight Implicit Certificate Scheme for #br# Resourceconstrained Devices in Distribution Networks#br#
    #br#
    Journal of Information Security Reserach    2025, 11 (9): 845-.  
    Abstract132)      PDF (1576KB)(18)       Save
    As resourceconstrained terminal devices such as fault indicators and smart meters are increasingly deployed in power distribution networks, the security requirements for identity authentication systems have also intensified. However, existing regulations remain inadequate, and traditional public key infrastructure (PKI) technologies are difficult to apply directly due to its heavy burden. To address this issue, this paper proposes a lightweight implicit certificate scheme, improving the elliptic curve QuVanstone (ECQV) implicit certificate algorithm tailored for resourceconstrained environments. The scheme incorporates certificate field optimization and the concise binary object representation (CBOR) encoding, significantly reducing the storage and computational overhead for devices while enhancing system security. Through several simulation analyses under the computer platform, comparing the ECQV implicit certificate scheme before improvement with the traditional X.509 authentication scheme, the results show that the performance of this scheme is more superior. Through experimental verification, the proposed scheme is able to meet the multiple needs of authentication of resourceconstrained devices in the power distribution network, such as storage, computing, energy consumption, and so on.
    Reference | Related Articles | Metrics
    A Privacy Budget Allocation Method Based on Differential #br# Privacy kmeans++#br#
    Journal of Information Security Reserach    2025, 11 (8): 710-.  
    Abstract131)      PDF (1126KB)(31)       Save
    For the traditional differential privacy kmeans++ algorithm, uniform budget allocation by the equal division method cannot meet varying privacy needs. Meanwhile, binary division rapidly depletes the budget, leading to excessive noise later on, both impairing clustering performance. To solve this problem, a new privacy budget allocation method combining the arithmetic and equal allocation methods was proposed. For initial center selection, use an equal division budget allocation. For center updates, early stage uses arithmetic progression, later stage switches to equal division, both focused on minimal budget. This approach ensures substantial initial privacy budget for minimal cluster center distortion, and moderate budget depletion later to prevent excessive noise that could compromise clustering outcomes. A series of experiments based on real data show that, compared to the original kmeans++, the minimum error is only 0.09%. Compared to the equal distribution method and the binary method, the clustering accuracy is improved by up to 14.9% and 16.9% respectively. It can be seen that this method is significantly better than the equal division and the binary division, and can improve the usability and accuracy of clustering results to a certain extent.
    Reference | Related Articles | Metrics
    Fileless Obfuscation Attack Recognition Based on Semantic Recovery and  Large Language Model
    Journal of Information Security Reserach    2025, 11 (12): 1125-.  
    Abstract127)      PDF (1478KB)(18)       Save
    With the continuous advancement of fileless attack techniques and strategies, research on identifying fileless malicious attack has garnered significant attention. Among these, fileless obfuscation attack, as a new type of covert, dynamic, and complex attack, can rapidly bypass existing attack engines and rulebased frameworks. To address this problem, this paper proposes an attack script restoration method guided by dynamic partial execution and semantic analysis tree guidance, enabling the restoration of obfuscated code. Furthermore, leveraging the efficiency of large models in attack understanding and semantic recognition, we integrate large models to achieve efficient identification and classification of fileless code. To further alleviate the limitations of large models in handling large code files and long passages, we also provide a semantic code compression strategy to retain critical attack semantics. Experimental results demonstrate that our proposed semantic restoration and large model identification methods can enhance effectiveness by around 10% compared to existing models and methods, while maintaining efficient attack identification efficiency.
    Reference | Related Articles | Metrics
    A Lightweight PUFbased Anonymous Authentication Protocol for  Wireless Medical Sensor Networks
    Journal of Information Security Reserach    2025, 11 (12): 1134-.  
    Abstract125)      PDF (2231KB)(29)       Save
    In response to the current challenges of resource constraints and the vulnerability of wireless medical sensor nodes, this paper proposes a lightweight anonymous authentication protocol specifically designed for wireless medical sensor networks. The protocol utilizes a physical unclonable function (PUF), deployed by the gateway, to facilitate secure authentication and key negotiation between medical experts and wireless medical sensor nodes via the gateway. The Proverif protocol analysis tool, the ROR Oracle model and nonformal analysis demonstrate that this protocol achieves mutual authentication and session key negotiation between medical specialists and wireless medical sensors, and is resistant to common attacks with good security properties. A comparison of the proposed protocol with other authentication protocols from recent years reveals that it has the lowest computational costs, with the total computational costs outperforming other protocols by more than 22.7% when the number of authentication times reaches 3500. Furthermore, experiments demonstrate that the protocol has good security attributes and lightweight characteristics, making it suitable for resourceconstrained wireless medical sensor networks.
    Reference | Related Articles | Metrics
    A Privacy Protection Scheme for Blockchain Transaction Based on #br# Threshold Homomorphic Encryption#br#
    Journal of Information Security Reserach    2025, 11 (8): 746-.  
    Abstract125)      PDF (1142KB)(16)       Save
    Blockchain is widely used because of its distributed processing, multiparty consensus, and immutable data. However, the open and transparent processing method will leak the privacy of users, and it is particularly important to use encryption technology to prevent the leakage of sensitive information. This paper proposes a privacy protection scheme for blockchain transactions based on threshold homomorphic encryption algorithm. Firstly, the confidentiality of sensitive transaction data is guaranteed by homomorphic encryption of the user’s account balance and transfer amount; Then, the corresponding transaction confirmation and transaction verification methods are designed. Finally, the security analysis and experimental verification of the proposed scheme are carried out, and the results show that the scheme has good stability and scalability, and is suitable for the general account model blockchain system.
    Reference | Related Articles | Metrics