VLDB 2026 Research / reviewers in the wild / expert
Xiaoliang Wang 0004
dblp:02/3450-4
· DBLP profile ↗
12ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-5290-3023ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 3 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Desi: Revisiting Signature Verification in Blockchain-based Storage System
Songsong Xu, Xiaoliang Wang 0004, Yangfei Guo, Shenglin Jiang, Ke Xu 0002 |
IWQoS | 4 |
| 2025 | Secure Fault Localization in Path Aware NetworkingabstractSecure data forwarding is critical for users to meet their requirements. In this paper, we propose D3 (Demon Detector in Data Plane), a source-driven, secure fault localization mechanism, which empowers the source to localize faulty link in Path Aware Networking, thus circumventing faulty link to guarantee secure data forwarding. D3 utilizes the source to instruct the on-path routers, thus empowering it to detect whether the on-path routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the heavy storage, computation, and communication overhead, D3 offloads most of the on-path router's storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, thus having a low communication overhead. Besides that, the destination in D3 could keep stateless processing, thus having backward compatibility and eliminating the opportunity for DoS attacks toward a stateful destination. The BMv2 and Barefoot Tofino hardware evaluations show that D3 could achieve high fault localization accuracy and process the packet at line rate. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Toward Practical Inter-Domain Source Address ValidationabstractThe Internet Protocol (IP) is the most fundamental building block of the Internet. However, it provides no explicit notion of packet-level authenticity. Such a weakness allows malicious actors to spoof IP packet headers and launch a wide variety of attacks. Meanwhile, the highly decentralized management of Internet infrastructure makes large-scale source address validation challenging in terms of overhead, validity, and flexibility. This paper presents a practical anti-spoofing approach, Source Address Validation Architecture eXternal (SAVA-X). SAVA-X introduces the concept of Address Domain to enable address validation in finer, prefix-level granularity. The address domains are organized in nested hierarchies to provide higher scalability and lower maintenance costs for partial deployment. We implement SAVA-X on commercial backbone routers and the P4 platform. The experiments indicate that the hardware implementation of SAVA-X can achieve 98% throughput on 100 Gbps links and close to the native IP forwarding in per-packet overhead, with less than 10 microseconds additional processing latency. Xiaoliang Wang 0004, Ke Xu 0002, Yangfei Guo, Songtao Fu, Qi Li 0002 |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | MASK: Practical Source and Path Verification Based on Multi-AS-KeyabstractThe source and path verification in Path-Aware Networking considers the two critical issues: (1) end hosts could verify that the network follows their forwarding decisions, and (2) both on-path routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the state-of-the-art mechanisms require heavy communication overhead in the network and computation overhead in the router; moreover, it is difficult to meet the dynamic requirements of the end host. We propose a user-driven mechanism, source and path verification based on Multi-AS-Key (MASK). MASK decreases the communication overhead by a short additional packet header and reduces the computation overhead by separating the control and data plane in terms of the cryptographic operation. Furthermore, it utilizes the stateful user to instruct the stateless routers to process the packet with a user-driven policy, thus satisfying the user’s requirements such as detecting the packet drop and replay attack. With the plausible design, the communication overhead for realistic path lengths is 1/2 to 1/10 compared with the state-of-the-art mechanisms. We implement MASK in the BMv2 environment and commodity Barefoot Tofino programmable switch, testify that MASK introduces significantly less overhead than the state-of-the-art mechanisms, and demonstrate that MASK could achieve the verification in the programmable switch at line rate. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du, Ke Xu 0002 |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | DIP: unifying network layer innovations using shared L3 core functionsabstractThe IP protocol has made a great contribution to the development of the Internet and has become the narrow waist of the Internet. However, the fixed packet processing of IP hinders the functional expansion and evolution of the Internet. In order to solve the rigidity of the Internet, our community has proposed various new L3 protocols to better support various network functions at the network layer. In this paper, we propose DIP (Dynamic Internet Protocol), a novel primitive to unify these protocols. DIP builds a common network function core shared by these L3 protocols based on a new L3 function core primitive, named Field Operation (FN). With FNs, each standalone L3 protocol can be decomposed into a combination of multiple FNs, and meanwhile it is feasible to compose various FNs to realize new (derived) L3 protocols. We demonstrate the feasibility of DIP by realizing five radically different network layer protocols1: the canonical IP forwarding, NDN [41], XIA [12], OPT [16], and NDN+OPT (a derived L3 protocol combining the merits of both NDN and OPT). We implement a prototype of DIP and evaluate its forwarding performance. Zhuotao Liu, Xiaoliang Wang 0004, Songtao Fu, Ke Xu 0002 |
HotNets | 3 |
| 2022 | D3: Lightweight Secure Fault Localization in Edge CloudabstractIn pursuit of high-performance applications, the cloud is moving out of the data center and towards the edge. Secure data forwarding is critical for the users between the edge and the remote cloud. In this paper, we propose D3 (Demon Detector in Data Plane), a lightweight, secure fault localization mechanism, which can enable the users in the edge cloud to localize faulty links and thus avoid the faulty links to guarantee secure data forwarding along the path to the remote cloud. D3 utilizes the user to instruct the transit routers, thus empowering the user to detect whether the transit routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the incurred heavy storage, computation, and communication overhead, D3 offloads most of the transit router’s storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, and the extra control packet overhead is ten times less while keeping a little constant storage overhead in the data plane. The evaluations in BMv2 and Barefoot Tofino hardware show that D3 could achieve high fault localization accuracy and efficiency. Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002 |
ICDCS | 3 |
| 2021 | MASK: Practical Source and Path Verification based on Multi-AS-KeyabstractThe source and path verification in path-aware Internet consider the two critical issues: (1) end hosts could verify that their forwarding decisions followed by the network, (2) both intermediate routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the current verification mechanism requires validation operations in each router on the path in an inter-domain environment, thus requiring high communication and computation overhead, reducing its usefulness; besides, it is also difficult to meet the dynamic requirements of the end host. Ideally, the verification should be secure and provide the customized capability to meet the end host’s requirements. We propose a new mechanism called source and path verification based on Multi-AS-Key (MASK). Instead of each packet verified and marked at each router on the path, MASK improves the verification by empowering the end hosts to instruct the routers to achieve the verification, thus decreasing the router’s overhead while ensuring security performance to meet the end host’s requirements. With the plausible design, the communication overhead for realistic path lengths is 3–8 times smaller than the state-of-the-art mechanisms. The computation overhead in the routers is 2-5 times smaller. We implement our design in the BMv2 environment and commodity Barefoot Tofino programmable switch, demonstrating that MASK introduces significantly less overhead than the existing mechanisms. Songtao Fu, Ke Xu 0002, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du |
IWQoS | 4 |
| 2021 | TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS MitigationabstractIn recent years, Distributed Denial-of-Service (DDoS) attacks have become more rampant and continue to be one of the most serious security threats facing network infrastructure. In a classic DDoS attack, the attacker controls numerous bots from many sources to send a significant volume of traffic to flood the victim end or the bottleneck link. In practical networks, it is inefficient and costly to request all partner routers to collaboratively mitigate DDoS attacks. The common feature of DDoS attacks is the abnormal distribution of traffic to the victim. In this paper, we propose TAP, a collaborative DDoS mitigation framework, based on traffic-aware probabilistic packet marking (PPM). TAP enables the victim to select a few hit routers as collaborators to mitigate attack traffic efficiently depending on the traffic distribution. Our evaluation results show that TAP greatly reduces attack traffic within seconds and mitigate the damage caused by DDoS with less overhead, which demonstrates that TAP is an effective, efficient, and rapid-response scheme for collaborative DDoS mitigation. Mingxing Liu, Ying Liu 0024, Ke Xu 0002, Lin He 0004, Xiaoliang Wang 0004, Yangfei Guo, Weiyu Jiang |
MSN | 5 |
| 2020 | NoPTPeer: Protecting Android Devices from Stealthy Spoofing and Stealing in WLANs without PrivilegeabstractAndroid devices are prone to spoofing attacks in Wireless Local Area Networks (WLANs), and many of them access numerous unknown networks in daily use. Moreover, because of the weak authentication between Android smartphones, attackers can steal data in a stealthier way based on Address Resolution Protocol (ARP) spoofing. These facts bring a gap in the study of device-side spoofing defense for Android devices. So in this paper a framework is proposed which requires No Privilege but can guarantee the True identity of Peers (NoPTPeer), to protect Android's device-to-device communication in WLANs. Its main features include realizing strong authentication between Android devices, controlling dangerous outgoing connections, and monitoring suspicious incoming connections. These features are realized by an Identity-Based-Signature (IBS) scheme, an Android base class VpnService, and information read from Android system files, which all require no root privilege and are independent of network infrastructures. We implement this framework as an Android smartphone application. The experiments show its effectiveness in detecting spoofing and monitoring stealing, as well as acceptable overhead in memory, Central Processing Unit (CPU) usage and communication latency. Shuying Wei, Xiaoliang Wang 0004, Ke Xu 0002 |
MSN | 2 |
| 2018 | GreenLink: An Energy Efficient Scatternet Formation for BLE DevicesabstractFormation technology of Bluetooth scatternet has been researched for over a decade and promoted by rapid development of wearable computing. Limited by technical features, the traditional scatternet formation technology has not been widely used in real commercial chipsets. As new features are introduced into the Bluetooth core field, the ability to use Bluetooth Low Energy (BLE) technology to construct a network becomes the reality and puts forward new challenges. The scatternet formation technology facing to BLE and wearable devices requires significant improvement in energy efficiency. According to our experiments, 92% of the system energy consumption can be attributed to central nodes. In this paper, we presented a Bluetooth scatternet formation technology focused on energy efficiency, GreenLink, which minimizes the amount of central nodes by enhancing system aggregation degree to ensure excellent energy‐saving performance. Meanwhile, we implemented a prototype of GreenLink on Nordic nRF51822 chipsets, conducted experiments, and verified in practice. According to the experiments, GreenLink used only 30% central nodes and reduced 50% system energy consumption compared with traditional technology. Xiaoliang Wang 0004, Ke Xu 0002, Bo Mao 0002 |
Wirel. Commun. Mob. Comput. | 1 |
| 2017 | SmartFix: Indoor Locating Optimization Algorithm for Energy-Constrained Wearable DevicesabstractIndoor localization technology based on Wi-Fi has long been a hot research topic in the past decade. Despite numerous solutions, new challenges have arisen along with the trend of smart home and wearable computing. For example, power efficiency needs to be significantly improved for resource-constrained wearable devices, such as smart watch and wristband. For a Wi-Fi-based locating system, most of the energy consumption can be attributed to real-time radio scan; however, simply reducing radio data collection will cause a serious loss of locating accuracy because of unstable Wi-Fi signals. In this paper, we present SmartFix, an optimization algorithm for indoor locating based on Wi-Fi RSS. SmartFix utilizes user motion features, extracts characteristic value from history trajectory, and corrects deviation caused by unstable Wi-Fi signals. We implemented a prototype of SmartFix both on Moto 360 2nd-generation Smartwatch and on HTC One Smartphone. We conducted experiments both in a large open area and in an office hall. Experiment results demonstrate that average locating error is less than 2 meters for more than 80% cases, and energy consumption is only 30% of Wi-Fi fingerprinting method under the same experiment circumstances. Xiaoliang Wang 0004, Ke Xu 0002 |
Wirel. Commun. Mob. Comput. | 1 |
| 2015 | TSP: A traffic sharing platform for mobile networksabstractIn mobile Internet era, wireless traffic has become a rare resource and there is no effective ways for users to share their unused traffic with each other. This paper introduces a system solution requiring no sophisticated hardware. An incentive mechanism is designed and implemented in a novel system named Traffic Sharing Platform (TSP) for mobile users, which can optimize network resource configuration and achieve Pareto optimality of the society. Simulation results show the TSP is available and the incentive mechanism is effective. Hui Su, Tong Li 0014, Ke Xu 0002, Shenglin Zhang, Xiaoliang Wang 0004 |
IWQoS | 5 |