VLDB 2026 Research / reviewers in the wild / expert
Quanyan Zhu
dblp:03/6207
· DBLP profile ↗
82ranked-venue papers
16as first author
28since 2021 · last 2026
0000-0002-0008-2953ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27 · 13 first-author · 6 since 2021Security and privacy · 24 · 1 first-author · 9 since 2021Artificial intelligence and machine learning · 8 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 5 since 2021Systems, architecture and hardware · 6 · 5 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Internet of Agentic AI: Incentive-Compatible Distributed Teaming and Workflow
Ya-Ting Yang, Quanyan Zhu |
WiOpt | 2 |
| 2025 | PACT: A Contract-Theoretic Framework for Pricing Agentic AI Services Powered by Large Language ModelsabstractAgentic AI, often powered by large language models (LLMs), is becoming increasingly popular and adopted to support autonomous reasoning, decision-making, and task execution across various domains. While agentic AI holds great promise, its deployment as services for easy access raises critical challenges in pricing, due to high infrastructure and computation costs, multidimensional and task-dependent Quality of Service (QoS), and liability concerns in high-stakes applications. In this work, we propose PACT, a Pricing framework for cloud-based Agentic AI services through a Contract-Theoretic approach. PACT models quality of service along both objective and subjective dimensions, while accounting for computational, infrastructure, and liability costs on the provider side. It enables heterogeneous users to select tailored service options that align with their needs. Numerical evaluations demonstrate that PACT ensures 100% QoS alignment between users and providers while offering a scalable and liable approach to pricing agentic AI services. Ya-Ting Yang, Quanyan Zhu |
GLOBECOM | 2 |
| 2025 | Exploring Prosocial Irrationality for LLM Agents: A Social Cognition ViewabstractLarge language models (LLMs) have been shown to face hallucination issues due to the data they trained on often containing human bias; whether this is reflected in the decision-making process of LLM agents remains under-explored. As LLM Agents are increasingly employed in intricate social environments, a pressing and natural question emerges: Can we utilize LLM Agents' systematic hallucinations to mirror human cognitive biases, thus exhibiting irrational social intelligence? In this paper, we probe the irrational behavior among contemporary LLM agents by melding practical social science experiments with theoretical insights. Specifically, we propose CogMir, an open-ended Multi-LLM Agents framework that utilizes hallucination properties to assess and enhance LLM Agents’ social intelligence through cognitive biases. Experimental results on CogMir subsets show that LLM Agents and humans exhibit high consistency in irrational and prosocial decision-making under uncertain conditions, underscoring the prosociality of LLM Agents as social entities and highlighting the significance of hallucination properties. Additionally, CogMir framework demonstrates its potential as a valuable platform for encouraging more research into the social intelligence of LLM Agents. Xuan Liu 0001, Jie Zhang 0076, Haoyang Shang, Song Guo 0001, Chengxu Yang, Quanyan Zhu |
ICLR | 6 |
| 2025 | Guest Editorial: Co-Design of Communication, Computing, and Control in Industrial Cyber-Physical Systems - Part IabstractGuest Editorial: Co-Design of Communication, Computing, and Control in Industrial Cyber-Physical Systems—Part I Jiong Jin, Zhibo Pang, Jonathan Kua, Quanyan Zhu, Karl Henrik Johansson, Nikolaj Marchenko, Dave Cavalcanti 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2025 | Cloud-Fog Automation: The New Paradigm Toward Autonomous Industrial Cyber-Physical SystemsabstractAutonomous Industrial Cyber-Physical Systems (ICPS) represent a future vision where industrial systems achieve full autonomy, integrating physical processes seamlessly with communication, computing and control technologies while holistically embedding intelligence. Cloud-Fog Automation is a new digitalized industrial automation reference architecture that has been recently proposed. This architecture is a fundamental paradigm shift from the traditional International Society of Automation (ISA)-95 model to accelerate the convergence and synergy of communication, computing, and control towards a fully autonomous ICPS. With the deployment of new wireless technologies to enable almost-deterministic ultra-reliable low-latency communications, a joint design of optimal control and computing has become increasingly important in modern ICPS. It is also imperative that system-wide cyber-physical security are critically enforced. Despite recent advancements in the field, there are still significant research gaps and open technical challenges. Therefore, a deliberate rethink in co-designing and synergizing communications, computing, and control (which we term “3C co-design”) is required. In this paper, we position Cloud-Fog Automation with 3C co-design as the new paradigm to realize the vision of autonomous ICPS. We articulate the state-of-the-art and future directions in the field, and specifically discuss how goal-oriented communication, virtualization-empowered computing, and Quality of Service (QoS)-aware control can drive Cloud-Fog Automation towards a fully autonomous ICPS, while accounting for system-wide cyber-physical security. Jiong Jin, Zhibo Pang, Jonathan Kua, Quanyan Zhu, Karl Henrik Johansson, Nikolaj Marchenko, Dave Cavalcanti 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2025 | Guest Editorial: Co-Design of Communication, Computing, and Control in Industrial Cyber-Physical Systems - Part IIabstractGuest Editorial: Co-Design of Communication, Computing, and Control in Industrial Cyber-Physical Systems—Part II Jiong Jin, Zhibo Pang, Jonathan Kua, Quanyan Zhu, Karl Henrik Johansson, Nikolaj Marchenko, Dave Cavalcanti 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2025 | Adaptive Security Response Strategies Through Conjectural Online LearningabstractWe study the problem of learning adaptive security response strategies for an it infrastructure. We formulate the interaction between an attacker and a defender as a partially observed, non-stationary game. We relax the standard assumption that the game model is correctly specified and consider that each player has a probabilistic conjecture about the model, which may be misspecified in the sense that the true model has probability 0. This formulation allows us to capture uncertainty and misconception about the infrastructure and the intents of the players. To learn effective game strategies online, we design Conjectural Online Learning (col), a novel method where a player iteratively adapts its conjecture using Bayesian learning and updates its strategy through rollout. We prove that the conjectures converge to best fits, and we provide a bound on the performance improvement that rollout enables with a conjectured model. To characterize the steady state of the game, we propose a variant of the Berk-Nash equilibrium. We present col through an intrusion response use case. Testbed evaluations show that col produces effective security strategies that adapt to a changing environment. We also find that col enables faster convergence than current reinforcement learning techniques. Kim Hammar, Tao Li 0046, Rolf Stadler, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Game-Theoretic Neyman-Pearson Detection to Combat Strategic EvasionabstractThe security in networked systems depends greatly on recognizing and identifying adversarial behaviors. Traditional detection methods target specific categories of attacks and have become inadequate against increasingly stealthy and deceptive attacks that are designed to bypass detection strategically. This work proposes game-theoretical frameworks to recognize and combat such evasive attacks. We focus on extending a fundamental class of statistical-based detection methods based on Neyman-Pearson’s (NP) hypothesis testing formulation. We capture the conflicting relationship between a strategic evasive attacker and an evasion-aware NP detector. By analyzing both the equilibrium behaviors of the attacker and the NP detector, we characterize their performance using Equilibrium Receiver-Operational-Characteristic (EROC) curves. We show that the evasion-aware NP detectors outperform the non-strategic ones by allowing them to take advantage of the attacker’s messages to adaptively modify their decision rules to enhance their success rate in detecting anomalies. In addition, we extend our framework to a sequential setting where the user sends out identically distributed messages. We corroborate the analytical results with a case study of an intrusion detection evasion problem. Yinan Hu, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | PRADA: Proactive Risk Assessment and Mitigation of Misinformed Demand Attacks on Navigational Route RecommendationsabstractLeveraging recent advances in wireless communication, IoT, and AI, intelligent transportation systems (ITS) played an important role in reducing traffic congestion and enhancing user experience. Within ITS, navigational recommendation systems (NRS) are essential for helping users simplify route choices in urban environments. However, NRS are vulnerable to information-based attacks that can manipulate both the NRS and users to achieve the objectives of the malicious entities. This study aims to assess the risks of misinformed demand attacks, where attackers use techniques like Sybil-based attacks to manipulate the demands of certain origins and destinations considered by the NRS. We propose a game-theoretic framework for proactive risk assessment of demand attacks (PRADA) and treat the interaction between attackers and the NRS as a Stackelberg game. Specifically, we consider the case of local-targeted attacks, in which the attacker aims to make the NRS recommend the authentic users towards a specific road that favors certain groups. Our analysis unveils the equivalence between users’ incentive compatibility and Wardrop equilibrium recommendations and shows that the NRS and its users are at high risk when encountering intelligent attackers who can significantly alter user routes by strategically fabricating non-existent demands. To mitigate these risks, we introduce a trust mechanism that leverages users’ confidence in the integrity of the NRS, and show that it can effectively reduce the impact of misinformed demand attacks. Numerical experiments are used to corroborate the results and support our discussion of the Resilience Paradox, where locally targeted attacks can sometimes benefit the overall traffic conditions. Our framework not only assists risk assessment in automating the evaluation process and estimating potential impacts but also aligns with standards like ISO/IEC 27005, offering a proactive approach to managing risks in ITS. Ya-Ting Yang, Haozhe Lei, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Herd Accountability of Privacy-Preserving Algorithms: A Stackelberg Game ApproachabstractAI-driven algorithmic systems are increasingly adopted across various sectors, yet the lack of transparency can raise accountability concerns about claimed privacy protection measures. While machine-based audits offer one avenue for addressing these issues, they are often costly and time-consuming. Herd audit, on the other hand, offers a promising alternative by leveraging collective intelligence from end-users. However, the presence of epistemic disparity among auditors, resulting in varying levels of domain expertise and access to relevant knowledge, captured by the rational inattention model, may impact audit assurance. An effective herd audit must establish a credible accountability threat for algorithm developers, incentivizing them not to breach user trust. In this work, our objective is to develop a systematic framework that explores the impact of herd audits on algorithm developers through the lens of the Stackelberg game. Our analysis reveals the importance of easy access to information and the appropriate design of rewards, as they increase the auditors’ assurance in the audit process. In this context, herd audit serves as a deterrent to negligent behavior. Therefore, by enhancing herd accountability, herd audit contributes to responsible algorithm development, fostering trust between users and algorithms. Ya-Ting Yang, Tao Zhang 0011, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Digital Twin-Based Driver Risk-Aware Predictive Mobility Analytics for Real-Time Situational Awareness Through Cooperative SensingabstractTraffic safety risk significantly impacts road users in urban mobility systems, making it important in transportation management decision-making. Current mobility management strategies predominantly focus on macro-level monitoring through traffic sensing infrastructure, and struggle to capture network-wide, real-time safety risks due to the limited spread of vehicle-based sensors. To address this, we propose a Digital Twin-based Driver Risk-aware Predictive Mobility Analytics (DT-DIMA) system. The DT-DIMA system integrates real-time traffic information from pan-tilt-cameras (PTCs), synchronizes this data into a digital twin to accurately replicate the physical world, and predicts network-wide mobility and safety risks in real time. The system’s innovation lies in its integration of spatial-temporal modeling, simulation, and online control modules. Tested and evaluated under normal traffic conditions and incidental situations (e.g., unexpected accidents, pre-planned work zones) in a simulated testbed in Brooklyn, New York, DT-DIMA demonstrated mean absolute percentage errors (MAPEs) ranging from 9.40% to 13.12% in estimating network-level traffic volume and MAPEs from 2.12% to 12.97% in network-level safety risk prediction. In addition, the highly accurate safety risk prediction enables PTCs to preemptively monitor road segments with high driving risks before incidents take place. Such proactive PTC surveillance creates around a 5-minute lead time in capturing traffic incidents. The DT-DIMA system enables transportation managers to understand mobility not only in terms of traffic patterns but also driver-experienced safety risks, allowing for proactive resource allocation in response to various traffic situations. Tao Li 0046, Zilin Bian, Haozhe Lei, Fan Zuo, Ya-Ting Yang, Quanyan Zhu, Zhenning Li 0001, Zhibin Chen 0001, Kaan Özbay |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2024 | Zero-Shot Wireless Indoor Navigation through Physics-Informed Reinforcement LearningabstractThe growing focus on indoor robot navigation utilizing wireless signals has stemmed from the capability of these signals to capture high-resolution angular and temporal measurements. Prior heuristic-based methods, based on radio frequency (RF) propagation, are intuitive and generalizable across simple scenarios, yet fail to navigate in complex environments. On the other hand, end-to-end (e2e) deep reinforcement learning (RL) can explore a rich class of policies, delivering surprising performance when facing complex wireless environments. However, the price to pay is the astronomical amount of training samples, and the resulting policy, without fine-tuning (zero-shot), is unable to navigate efficiently in new scenarios unseen in the training phase. To equip the navigation agent with sample-efficient learning and zero-shot generalization, this work proposes a novel physics-informed RL (PIRL) where a distance-to-target-based cost (standard in e2e) is augmented with physics-informed reward shaping. The key intuition is that wireless environments vary, but physics laws persist. After learning to utilize the physics information, the agent can transfer this knowledge across different tasks and navigate in an unknown environment without fine-tuning. The proposed PIRL is evaluated using a wireless digital twin (WDT) built upon simulations of a large class of indoor environments from the AI Habitat dataset augmented with electromagnetic radiation simulation for wireless signals. It is shown that the PIRL significantly outperforms both e2e RL and heuristic-based solutions in terms of generalization and performance. Source code is available at https://github.com/Panshark/PIRL-WIN. Mingsheng Yin, Tao Li 0046, Haozhe Lei, Yaqi Hu, Sundeep Rangan, Quanyan Zhu |
ICRA | 6 |
| 2024 | Stackelberg Game-Theoretic Trajectory Guidance for Multi-Robot Systems with Koopman OperatorabstractGuided trajectory planning involves a leader robot strategically directing a follower robot to collaboratively reach a designated destination. However, this task becomes notably challenging when the leader lacks complete knowledge of the follower’s decision-making model. There is a need for learning-based methods to effectively design the cooperative plan. To this end, we develop a Stackelberg game-theoretic approach based on the Koopman operator to address the challenge. We first formulate the guided trajectory planning problem through the lens of a dynamic Stackelberg game. We then leverage Koopman operator theory to acquire a learning-based linear system model that approximates the follower’s feedback dynamics. Based on this learned model, the leader devises a collision-free trajectory to guide the follower using receding horizon planning. We use simulations to elaborate on the effectiveness of our approach in generating learning models that accurately predict the follower’s multi-step behavior when compared to alternative learning techniques. Moreover, our approach successfully accomplishes the guidance task and notably reduces the leader’s planning time to nearly half when contrasted with the model-based baseline method1. Quanyan Zhu |
ICRA | 2 |
| 2024 | ZETAR: Modeling and Computational Design of Strategic and Adaptive Compliance PoliciesabstractCompliance management plays an important role in mitigating insider threats. Incentive design is a proactive and noninvasive approach to achieving compliance by aligning an insider’s incentive with the defender’s security objective, which motivates (rather than commands) an insider to act in the organization’s interests. Controlling insiders’ incentives for population-level compliance is challenging because they are neither precisely known nor directly controllable. To this end, we develop ZEro-Trust Audit with strategic Recommendation (ZETAR), a zero-trust audit and recommendation framework, to provide a quantitative approach to model insiders’ incentives and design customized recommendation policies to improve their compliance. We formulate primal and dual convex programs to compute the optimal bespoke recommendation policies. We create the theoretical underpinning for understanding trust, compliance, and satisfaction, which leads to scoring mechanisms of how compliant and persuadable an insider is. After classifying insiders as malicious, self-interested, or amenable based on their incentive misalignment levels with the defender, we establish bespoke information disclosure principles for these insiders of different incentive categories. We identify the policy separability principle and the set convexity, which enable finite-step algorithms to efficiently learn the completely trustworthy (CT) policy set when insiders’ incentives are unknown. Finally, we present a case study to corroborate the design. Our results show that ZETAR can well adapt to insiders with different risk and compliance attitudes and significantly improve compliance. Moreover, trustworthy recommendations can provably promote cyber hygiene and insiders’ satisfaction. Linan Huang, Quanyan Zhu |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | GAZETA: GAme-Theoretic ZEro-Trust Authentication for Defense Against Lateral Movement in 5G IoT NetworksabstractThe increasing connectivity in the 5G Internet of Things networks has enlarged the attack surface and made the traditional security defense inadequate for sophisticated attackers, who can move laterally from node to node with stored credentials once build a foothold in the network. There is a need to shift from the perimeter-based defense to a zero-trust security framework that focuses on agent-centric trust evaluation and access policies to identify malicious attackers, and proactively delay their lateral movement while ensuring system performance. In this work, we propose a GAme-theoretic ZEro-Trust Authentication framework, known as GAZETA, to design interdependent trust evaluation and authentication policies using dynamic game models. The stealthy and dynamic behaviors of the agent are captured by a Markov game with one-sided incomplete information. We provide a quantitative trust evaluation mechanism for the agent and update the trust score continuously based on observations. The analysis of the equilibrium not only provides a way to quantitatively assess the security posture of the network but also enables a formal method to design zero-trust authentication policies. We propose a moving-horizon computational method to enable online decisions and rapid responses to environmental changes. This online computation also enables a dynamic trust evaluation that integrates multiple sources of security evidence. We use a case study to illustrate the resilience, robustness, and efficiency of the proposed zero-trust approach. Yunfei Ge, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Human-in-the-Loop Cyber Intrusion Detection Using Active LearningabstractTimely detection of cyber attacks is essential for minimizing attack impact, but it requires accurate real-time situational awareness (SA). In practice, SA is hampered by frequent false alerts from anomaly-based intrusion detection systems (IDS), causing alarm fatigue. Investigating alerts by humans can enhance SA, but it is resource-intensive and it is often unclear which alerts to prioritize. In this paper, we propose a framework for optimizing human-in-the-loop attack detection, consisting of three key components: 1) dynamic alert prioritization, which ranks alerts based on previous alerts and investigations, 2) human alert investigation, referring to the manual analysis of alerts, and 3) sequential hypothesis testing, a method that confirms a hypothesis based on incoming alerts, with pruned hidden Markov models (HMMs). We formulate the problem as that of active learning in an HMM, and we propose two alert prioritization policies, namely Max Ratio and Max KL. The proposed policies aim to select the most informative alerts based on historical data and prior investigations, thereby minimizing the detection time. Simulation results show that our proposed policies reduce the time to detection by up to 79% compared to a static baseline policy, while maintaining a target mean time between false detections (MTBFD). Yeongwoo Kim, György Dán, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Self-Adaptive Driving in Nonstationary Environments through Conjectural Online Lookahead AdaptationabstractPowered by deep representation learning, re-inforcement learning (RL) provides an end-to-end learning framework capable of solving self-driving (SD) tasks without manual designs. However, time-varying nonstationary environments cause proficient but specialized RL policies to fail at execution time. For example, an RL-based SD policy trained under sunny days does not generalize well to rainy weather. Even though meta learning enables the RL agent to adapt to new tasks/environments, its offline operation fails to equip the agent with online adaptation ability when facing nonstationary environments. This work proposes an online meta reinforcement learning algorithm based on the conjectural online lookahead adaptation (COLA). COLA determines the online adaptation at every step by maximizing the agent's conjecture of the future performance in a lookahead horizon. Experimental results demonstrate that under dynamically changing weather and lighting conditions, the COLA-based self-adaptive driving outperforms the baseline policies regarding online adaptability. A demo video, source code, and appendixes are available at https://github.com/Panshark/COLA Tao Li 0046, Haozhe Lei, Quanyan Zhu |
ICRA | 3 |
| 2023 | Stackelberg Meta-Learning for Strategic Guidance in Multi-Robot Trajectory PlanningabstractTrajectory guidance requires a leader robotic agent to assist a follower robotic agent to cooperatively reach the target destination. However, planning cooperation becomes difficult when the leader serves a family of different followers and has incomplete information about the followers. There is a need for learning and fast adaptation of different cooperation plans. We develop a Stackelberg meta-learning approach to address this challenge. We first formulate the guided trajectory planning problem as a dynamic Stackelberg game to capture the leader-follower interactions. Then, we leverage meta-learning to develop cooperative strategies for different followers. The leader learns a meta-best-response model from a prescribed set of followers. When a specific follower initiates a guidance query, the leader quickly adapts to the follower-specific model with a small amount of learning data and uses it to perform trajectory guidance. We use simulations to elaborate that our method provides a better generalization and adaptation per-formance on learning followers' behavior than other learning approaches. The value and the effectiveness of guidance are also demonstrated by the comparison with zero guidance scenarios11The simulation codes are available at https://github.com/yuhan16/Stackelberg-Meta-Learning.. Quanyan Zhu |
IROS | 2 |
| 2023 | Designing Policies for Truth: Combating Misinformation with Transparency and Information DesignabstractMisinformation has become a growing issue on online social platforms (OSPs), especially during elections or pandemics. To combat this, OSPs have implemented various policies, such as tagging, to notify users about potentially misleading information. However, these policies are often trans-parent and therefore susceptible to being exploited by content creators, who may not be willing to invest effort into producing authentic content, causing the viral spread of misinformation. Instead of mitigating the reach of existing misinformation, this work focuses on a solution of prevention, aiming to stop the spread of misinformation before it has a chance to gain mo-mentum. We propose a Bayesian persuaded branching process$(\text{BP}^{2})$to model the strategic interactions among the OSP, the content creator, and the user. The misinformation spread on OSP is modeled by a multi-type branching process, where users' positive and negative comments influence the misinformation spreading. Using a Lagrangian induced by Bayesian plausibility, we characterize the OSP's optimal policy under the perfect Bayesian equilibrium. The convexity of the Lagrangian implies that the OSP's optimal policy is simply the fully informative tagging policy: revealing the content's accuracy to the user. Such a tagging policy solicits the best effort from the content creator in reducing misinformation, even though the OSP exerts no direct control over the content creator. We corroborate our findings using numerical simulations. Ya-Ting Yang, Tao Li 0046, Quanyan Zhu |
WiOpt | 3 |
| 2023 | QoS-Based Contract Design for Profit Maximization in IoT-Enabled Data MarketsabstractThe massive deployment of Internet of Things (IoT) devices, including sensors and actuators, is ushering in smart and connected communities of the future. The massive deployment of IoT devices, including sensors and actuators, is ushering in smart and connected communities of the future. The availability of real-time and high-quality sensor data is crucial for various IoT applications, particularly in healthcare, energy, transportation, etc. However, data collection may have to be outsourced to external service providers (SPs) due to cost considerations or lack of specialized equipment. Hence, the data market plays a critical role in such scenarios where SPs have different quality levels of available data, and IoT users have different application-specific data needs. The pairing between data available to the SP and users in the data market requires an effective mechanism design that considers the SPs’ profitability and the Quality-of-Service (QoS) needs of the users. We develop a generic framework to analyze and enable such interactions efficiently, leveraging tools from contract theory and mechanism design theory. It can enable and empower emerging data-sharing paradigms, such as Sensing-as-a-Service (SaaS). The contract design creates a pricing structure for on-demand sensing data for IoT users. By considering a continuum of user types, we capture a diverse range of application requirements and propose optimal pricing and allocation rules that ensure QoS provisioning and maximum profitability for the SP. Furthermore, we provide analytical solutions for fixed distributions of user types to analyze the developed approach. For comparison, we consider the benchmark case assuming complete information of the user types and obtain optimal contract solutions. Finally, a case study based on the example of a virtual reality application delivered using unmanned aerial vehicles (UAVs) is presented to demonstrate the efficacy of the proposed contract design framework. Muhammad Junaid Farooq, Quanyan Zhu |
IEEE Internet Things J. | 3 |
| 2023 | A Cross-Layer Design Approach to Strategic Cyber Defense and Robust Switching Control of Cyber-Physical Wind Energy SystemsabstractDue to the increasing adoption of smart sensing and Internet of things (IoT) devices, wind energy system (WES) becomes more vulnerable to cyber and physical attacks. Therefore, designing a secure and resilient WES is critical. This paper first proposes a system-of-systems (SoS) framework for the cyber-physical WES. Specifically, on the one hand, we adopt a game-theoretic model to capture the interactions between the WES system defender and the adversary at the cyber layer. The outcome of this cyber defense game is reflected by control-aware Nash equilibria. On the other hand, we devise a cyber-aware robust and resilient switching controller based on a Markov jump linear system model for the physical WES. The performances of the WES cyber and physical layers are interdependent due to their natural couplings. We further investigate the SoS equilibrium of the integrated WES, which considers the system security, robustness, and resilience holistically. Finally, we use case studies to corroborate the developed cross-layer design principles for the cyber-physical WES. Note to Practitioners—Cybersecurity becomes a critical concern of wind energy system (WES) operators as an increasing amount of IoT devices are adopted for WES’s communication, monitoring, and operation support purposes. This cyber-physical integration in WES creates a much broader attack surface because adversaries can compromise the physical WES by attacking its dependent cyberspace. To mitigate the impact of attacks, the operator should not only design intelligent control strategies for WES but also strategically secure the WES’s cyber layer. These two goals are naturally coupled together. On the one hand, the WES operates under different compromised conditions depending on the attack actions at the cyber layer. Thus, the control design needs to be adversary-aware by taking the real-time cyber state into account. On the other hand, the adversary’s cyberattack strategy is influenced by the induced performance degradation of WES. Hence, the corresponding attack measures and countermeasures, in turn, should be physically control-aware. This paper establishes a holistic mathematical framework to simultaneously address these two challenging objectives. The obtained solution provides guidelines for the WES operator on the optimal security resource investment in defending against cyberattacks and the robust switching control design to mitigate the impacts of attacks further. This methodology creates a defense-in-depth paradigm for the WES operators to maintain the energy system efficiency in the adversarial environment. This cross-layer design approach is also efficient and user-friendly for online implementation with the developed iterative algorithm. The simulated-based case studies in this paper show the effectiveness of the proposed approach. However, a more thorough validation of the method in practice is necessary before its integration with the production standard. Quanyan Zhu |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2022 | Stackelberg Strategic Guidance for Heterogeneous Robots CollaborationabstractIn this study, we explore the application of game theory, in particular Stackelberg games, to address the issue of effective coordination strategy generation for heterogeneous robots with one-way communication. To that end, focusing on the task of multi-object rearrangement, we develop a theoretical and algorithmic framework that provides strategic guidance for a pair of robot arms, a leader and a follower where the leader has a model of the follower's decision-making process, through the computation of a feedback Stackelberg equilibrium. With built-in tolerance of model uncertainty, the strategic guidance generated by our planning algorithm not only improves the overall efficiency in solving the rearrangement tasks, but is also robust to common pitfalls in collaboration, e.g., chattering. Baichuan Huang, Jingjin Yu, Quanyan Zhu |
ICRA | 4 |
| 2022 | RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks
Linan Huang, Quanyan Zhu |
Comput. Secur. | 2 |
| 2022 | A Dynamic Game Framework for Rational and Persistent Robot Deception With an Application to Deceptive Pursuit-EvasionabstractThis article studies rational and persistent deception among intelligent robots to enhance security and operational efficiency. We present an$N$-player$K$-stage game with an asymmetric information structure where each robot’s private information is modeled as a random variable or its type. The deception is persistent as each robot’s private type remains unknown to other robots for all stages. The deception is rational as robots aim to achieve their deception goals at minimum cost. Each robot forms a dynamic belief of others’ types based on intrinsic or extrinsic information. Perfect Bayesian Nash equilibrium (PBNE) is a natural solution concept for dynamic games of incomplete information. Due to its requirements of sequential rationality and belief consistency, PBNE provides a reliable prediction of players’ actions, beliefs, and expected cumulative costs over the entire$K$stages. The contribution of this work is fourfold. First, we identify the PBNE computation as a nonlinear stochastic control problem and characterize the structures of players’ actions and costs under PBNE. We further derive a set of extended Riccati equations with cognitive coupling under the linear-quadratic (LQ) setting and extrinsic belief dynamics. Second, we develop a receding-horizon algorithm with low temporal and spatial complexity to compute PBNE under intrinsic belief dynamics. Third, we investigate a deceptive pursuit-evasion game as a case study and use numerical experiments to corroborate the results. Finally, we propose metrics, such as deceivability, reachability, and the price of deception (PoD), to evaluate the strategy design and the system performance under deception. Note to Practitioners—Recent advances in automation and adaptive control in multi-agent systems enable robots to use deception to accomplish their objectives. Deception involves intentional information hiding to compromise the security and operational efficiency of the robotic systems. This work proposes a dynamic game framework to quantify the impact of deception, understand the robots’ behaviors and intentions, and design cost-efficient strategies under the deception that persists over stages. Existing research studies on robot deception have relied on experiments while this work aims to lay a theoretical foundation of deception with quantitative metrics, such as deceivability and the PoD. The proposed model has wide applications, including cooperative robots, pursuit and evasion, and human–robot teaming. The pursuit-evasion games are used as case studies to show how the deceiver can amplify the deception by belief manipulation and how the deceived robots can reduce the negative impact of deception by enhanced maneuverability and Bayesian learning. The future work would focus on designing cooperative deception among swarm robotics and robotic systems that are robust to or further benefit from the deception. Linan Huang, Quanyan Zhu |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2022 | Optimal Cyber-Insurance Contract Design for Dynamic Risk Management and MitigationabstractWith the recent growing number of cyberattacks and the constant lack of effective defense methods, cyber risks have become ubiquitous in enterprise networks, manufacturing plants, and government computer systems. Cyber insurance provides a valuable approach to transfer the cyber risks to insurance companies and further improve the security status of the insured. The designation of effective cyber-insurance contracts requires considerations from both the insurance market and the dynamic properties of the cyber risks. To capture the interactions between the users and the insurers, we present a dynamic moral-hazard type of principal–agent model incorporated with Markov decision processes, which are used to capture the dynamics and correlations of the cyber risks as well as the user’s decisions on the protections. We study and fully analyze a case with a two-state two-action user under linear coverage insurance and further show the risk compensation, Peltzman effect, linear insurance contract principle, and zero-operating profit principle in this case. Numerical experiments are provided to verify our conclusions and further extend to cases of a four-state three-action user under linear coverage insurance and threshold coverage insurance. Rui Zhang 0020, Quanyan Zhu |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2022 | ADVERT: An Adaptive and Data-Driven Attention Enhancement Mechanism for Phishing PreventionabstractAttacks exploiting theinnateand theacquiredvulnerabilities of human users have posed severe threats to cybersecurity. This work proposes ADVERT, ahuman-technical solutionthat generates adaptive visual aids in real-time to prevent users from inadvertence and reduce their susceptibility to phishing attacks. Based on the eye-tracking data, we extractvisual statesandattention statesas system-level sufficient statistics to characterize the user’s visual behaviors and attention status. By adopting a data-driven approach and two learning feedback of different time scales, this work lays out a theoretical foundation toanalyze,evaluate, and particularlymodifyhumans’ attention processes while they vet and recognize phishing emails. We corroborate theeffectiveness,efficiency, androbustnessof ADVERT through a case study based on the data set collected from human subject experiments conducted at New York University. The results show that the visual aids can statistically increase the attention level and improve the accuracy of phishing recognition from 74.6% to a minimum of 86%. The meta-adaptation can further improve the accuracy to 91.5% (resp. 93.7%) in less than 3 (resp. 50) tuning stages. Linan Huang, Shumeng Jia, Emily Balcetis, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Duplicity Games for Deception Design With an Application to Insider Threat MitigationabstractRecent incidents such as the Colonial Pipeline ransomware attack and the SolarWinds hack have shown that traditional defense techniques are becoming insufficient to deter adversaries of growing sophistication. Proactive and deceptive defenses are an emerging class of methods to defend against zero-day and advanced attacks. This work develops a new game-theoretic framework called the duplicity game to design deception mechanisms that consist of a generator, an incentive modulator, and a trust manipulator, referred to as the GMM mechanism. We formulate a mathematical programming problem to compute the optimal GMM mechanism, quantify the upper limit of enforceable security policies, and characterize conditions on user's identifiability and manageability for cyber attribution and user management. We develop a separation principle that decouples the design of the modulator from the GMM mechanism and an equivalence principle that turns the joint design of the generator and the manipulator into the single design of the manipulator. A case study of dynamic honeypot configurations is presented to mitigate insider threats. The numerical experiments corroborate the results that the optimal GMM mechanism can elicit desirable actions from both selfish and adversarial insiders and consequently improve the security posture of the insider network. In particular, a proper modulator can reduce the \textcolor{black}{incentive misalignment} between the players and achieve win-win situations for the selfish insider and the defender. Meanwhile, we observe that the defender always benefits from faking the percentage of honeypots when the optimal generator is presented. Linan Huang, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | QoE Based Revenue Maximizing Dynamic Resource Allocation and Pricing for Fog-Enabled Mission-Critical IoT ApplicationsabstractFog computing is becoming a vital component for Internet of things (IoT) applications, acting as its computational engine. Mission-critical IoT applications are highly sensitive to latency, which depends on the physical location of the cloud server. Fog nodes of varying response rates are available to the cloud service provider (CSP) and it is faced with a challenge of forwarding the sequentially received IoT data to one of the fog nodes for processing. Since the arrival times and nature of requests is random, it is important to optimally classify the requests in real-time and allocate available virtual machine instances (VMIs) at the fog nodes to provide a high QoE to the users and consequently generate higher revenues for the CSP. In this paper, we use a pricing policy based on the QoE of the applications as a result of the allocation and obtain an optimal dynamic allocation rule based on the statistical information of the computational requests. The developed solution is statistically optimal, dynamic, and implementable in real-time as opposed to other static matching schemes in the literature. The performance of the proposed framework has been evaluated using simulations and the results show significant improvement as compared with benchmark schemes. Muhammad Junaid Farooq, Quanyan Zhu |
IEEE Trans. Mob. Comput. | 2 |
| 2020 | A Connection between Feedback Capacity and Kalman Filter for Colored Gaussian NoisesabstractIn this paper, we establish a connection between the feedback capacity of additive colored Gaussian noise channels and the Kalman filters with additive colored Gaussian noises. In light of this, we are able to provide lower bounds on feedback capacity of such channels with finite-order auto-regressive moving average colored noises, and the bounds are seen to be consistent with various existing results in the literature; particularly, the bound is tight in the case of first-order auto-regressive moving average colored noises. On the other hand, the Kalman filtering systems, after certain equivalence transformations, can be employed as recursive coding schemes/algorithms to achieve the lower bounds. In general, our results provide an alternative perspective while pointing to potentially tighter bounds for the feedback capacity problem. Quanyan Zhu |
ISIT | 2 |
| 2020 | A dynamic games approach to proactive defense strategies against Advanced Persistent Threats in cyber-physical systems
Linan Huang, Quanyan Zhu |
Comput. Secur. | 2 |
| 2020 | Computer & security special issue editorial
Stefan Rass, Quanyan Zhu |
Comput. Secur. | 2 |
| 2020 | A Dynamic Game Approach to Strategic Design of Secure and Resilient Infrastructure NetworkabstractInfrastructure networks are vulnerable to both cyber and physical attacks. Building a secure and resilient networked system is essential for providing reliable and dependable services. To this end, we establish a two-player three-stage game framework to capture the dynamics in the infrastructure protection and recovery phases. Specifically, the goal of the infrastructure network designer is to keep the network connected before and after the attack, while the adversary aims to disconnect the network by compromising a set of links. With costs for creating and removing links, the two players aim to maximize their utilities while minimizing the costs. In this paper, we use the concept of subgame perfect equilibrium (SPE) to characterize the optimal strategies of the network defender and attacker. We derive the SPE explicitly in terms of system parameters. We further investigate the resilience planning of the defender and the strategic timing of attack of the adversary. Finally, we use case studies of UAV-enabled communication networks for disaster recovery to corroborate the obtained analytical results. Corinne Touati, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | <tt>FlipIn</tt>: A Game-Theoretic Cyber Insurance Framework for Incentive-Compatible Cyber Risk Management of Internet of ThingsabstractInternet of Things (IoT) is highly vulnerable to emerging Advanced Persistent Threats (APTs) that are often operated by well-resourced adversaries. Achieving perfect security for IoT networks is often cost-prohibitive if not impossible. Cyber insurance is a valuable mechanism to mitigate cyber risks for IoT systems. In this work, we propose a bi-level game-theoretic framework called FlipIn to design incentive-compatible and welfare-maximizing cyber insurance contracts. The framework captures the strategic interactions among APT attackers, IoT defenders, and cyber insurance insurers, and incorporates influence networks to assess the systemic cyber risks of interconnected IoT devices. The FlipIn framework formulates a game over networks within a principal-agent problem of moral-hazard type to design a cyber risk-aware insurance contract. We completely characterize the equilibrium solutions of the bi-level games for a network of distributed defenders and a semi-homogeneous centralized defender and show that the optimal insurance contracts cover half of the defenders' losses. Our framework predicts the risk compensation of defenders and the Peltzman effect of insurance. We study a centralized security management scenario and its decentralized counterpart, and leverage numerical experiments to show that network connectivity plays an important role in the security of the IoT devices and the insurability of both distributed and centralized defenders. Rui Zhang 0020, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Generic Variance Bounds on Estimation and Prediction Errors in Time Series Analysis: An Entropy PerspectiveabstractIn this paper, we obtain generic bounds on the variances of estimation and prediction errors in time series analysis via an information-theoretic approach. It is seen in general that the error bounds are determined by the conditional entropy of the data point to be estimated or predicted given the side information or past observations. Additionally, we discover that in order to achieve the prediction error bounds asymptotically, the necessary and sufficient condition is that the “innovation” is asymptotically white Gaussian. When restricted to Gaussian processes and 1-step prediction, our bounds are shown to reduce to the Kolmogorov-Szegö formula and Wiener-Masani formula known from linear prediction theory. Mikael Skoglund, Karl Henrik Johansson, Hideaki Ishii, Quanyan Zhu |
ITW | 5 |
| 2019 | Optimal Timing in Dynamic and Robust Attacker Engagement During Advanced Persistent ThreatsabstractAdvanced persistent threats (APTs) are stealthy attacks which make use of social engineering and deception to give adversaries insider access to networked systems. Against APTs, active defense technologies aim to create and exploit information asymmetry for defenders. In this paper, we study a scenario in which a powerful defender uses honeynets for active defense in order to observe an attacker who has penetrated the network. Rather than immediately eject the attacker, the defender may elect to gather information. We introduce an undiscounted, infinite-horizon Markov decision process on a continuous state space in order to model the defender's problem. We find a threshold of information that the defender should gather about the attacker before ejecting him. Then we study the robustness of this policy using a Stackelberg game. Finally, we simulate the policy for a conceptual network. Our results provide a quantitative foundation for studying optimal timing for attacker engagement in network defense. Jeffrey Pawlick, Thi Thu Hang Nguyen, Edward Colbert, Quanyan Zhu |
WiOpt | 4 |
| 2019 | Interdependent Strategic Security Risk Management With Bounded Rationality in the Internet of ThingsabstractWith the increasing connectivity enabled by the Internet of Things (IoT), security becomes a critical concern, and users should invest to secure their IoT applications. Due to the massive devices in the IoT network, users cannot be aware of the security policies taken by all its connected neighbors. Instead, a user makes security decisions based on the cyber risks that he perceives by observing a selected number of nodes. To this end, we propose a model which incorporates the limited attention or bounded rationality nature of players in the IoT. Specifically, each individual builds a sparse cognitive network of nodes to respond to. Based on this simplified cognitive network representation, each user then determines his security management policy by minimizing his own real-world security cost. The bounded rational decision-makings of players and their cognitive network formations are interdependent and thus should be addressed in a holistic manner. We establish a games-in-games framework and propose a Gestalt Nash equilibrium (GNE) solution concept to characterize the decisions of agents and quantify their risk of bounded perception due to the limited attention. In addition, we design a proximal-based iterative algorithm to compute the GNE. With case studies of smart communities, the designed algorithm can successfully identify the critical users whose decisions need to be taken into account by the other users during the security management. Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | Modeling, Analysis, and Mitigation of Dynamic Botnet Formation in Wireless IoT NetworksabstractThe Internet of Things (IoT) relies heavily on wireless communication devices that are able to discover and interact with other wireless devices in their vicinity. The communication flexibility coupled with software vulnerabilities in devices, due to low cost and short time-to-market, exposes them to a high risk of malware infiltration. Malware may infect a large number of network devices using device-to-device (D2D) communication resulting in the formation of a botnet, i.e., a network of infected devices controlled by a common malware. A botmaster may exploit it to launch a network-wide attack sabotaging infrastructure and facilities, or for malicious purposes such as collecting ransom. In this paper, we propose an analytical model to study the D2D propagation of malware in wireless IoT networks. Leveraging tools from dynamic population processes and point process theory, we capture malware infiltration and coordination process over a network topology. The analysis of mean-field equilibrium in the population is used to construct and solve an optimization problem for the network defender to prevent botnet formation by patching devices while causing minimum overhead to network operation. The developed analytical model serves as a basis for assisting the planning, design, and defense of such networks from a defender’s standpoint. Muhammad Junaid Farooq, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | iSTRICT: An Interdependent Strategic Trust Mechanism for the Cloud-Enabled Internet of Controlled ThingsabstractThe cloud-enabled Internet of controlled things (IoCT) envisions a network of sensors, controllers, and actuators connected through a local cloud in order to intelligently control physical devices. Because cloud services are vulnerable to advanced persistent threats (APTs), each device in the IoCT must strategically decide whether to trust cloud services that may be compromised. In this paper, we present iSTRICT, an interdependent strategic trust mechanism for the cloud-enabled IoCT. iSTRICT is composed of three interdependent layers. In the cloud layer, iSTRICT uses FlipIt games to conceptualize APTs. In the communication layer, it captures the interaction between devices and the cloud using signaling games. In the physical layer, iSTRICT uses optimal control to quantify the utilities in the higher level games. Best response dynamics link the three layers in an overall “game-of-games,” for which the outcome is captured by a concept called Gestalt Nash equilibrium (GNE). We prove the existence of a GNE under a set of natural assumptions and develop an adaptive algorithm to iteratively compute the equilibrium. Finally, we apply iSTRICT to trust management for autonomous vehicles that rely on measurements from remote sources. We show that strategic trust in the communication layer achieves a worst-case probability of compromise for any attack and defense costs in the cyber layer. Jeffrey Pawlick, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Modeling and Analysis of Leaky Deception Using Signaling Games With EvidenceabstractDeception plays critical roles in economics and technology, especially in emerging interactions in cyberspace. Holistic models of deception are needed in order to analyze interactions and to design mechanisms that improve them. Game theory provides such models. In particular, existing work models deception using signaling games. But signaling games inherently model deception that is undetectable. In this paper, we extend signaling games by including a detector that gives off probabilistic warnings when the sender acts deceptively. Then, we derive pooling and partially separating equilibria of the game. We find that: 1) high quality detectors eliminate some pure-strategy equilibria; 2) detectors with high true-positive rates encourage more honest signaling than detectors with low false-positive rates; 3) receivers obtain optimal outcomes for equal-error-rate detectors; and 4) surprisingly, deceptive senders sometimes benefit from highly accurate deception detectors. We illustrate these results with an application to defensive deception for network security. Our results provide a quantitative and rigorous analysis of the fundamental aspects of detectable deception. Jeffrey Pawlick, Edward Colbert, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Game Theory Meets Network Security: A TutorialabstractThe increasingly pervasive connectivity of today's information systems brings up new challenges to security. Traditional security has accomplished a long way toward protecting well-defined goals such as confidentiality, integrity, availability, and authenticity. However, with the growing sophistication of the attacks and the complexity of the system, the protection using traditional methods could be cost-prohibitive. A new perspective and a new theoretical foundation are needed to understand security from a strategic and decision-making perspective. Game theory provides a natural framework to capture the adversarial and defensive interactions between an attacker and a defender. It provides a quantitative assessment of security, prediction of security outcomes, and a mechanism design tool that can enable security-by-design and reverse the attacker's advantage. This tutorial provides an overview of diverse methodologies from game theory that includes games of incomplete information, dynamic games, mechanism design theory to offer a modern theoretic underpinning of a science of cybersecurity. The tutorial will also discuss open problems and research challenges that the CCS community can address and contribute with an objective to build a multidisciplinary bridge between cybersecurity, economics, game and decision theory. Quanyan Zhu, Stefan Rass |
CCS | 1 |
| 2018 | Optimal dynamic contract for spectrum reservation in mission-critical UNB-IoT systemsabstractSpectrum reservation is emerging as one of the potential solutions to cater for the communication needs of massive number of wireless Internet of Things (IoT) devices with reliability constraints particularly in mission-critical scenarios. In most mission-critical systems, the true utility of a reservation may not be completely known ahead of time as the unforseen events might not be completely predictable. In this paper, we present a dynamic contract approach where an advance payment is made at the time of reservation based on partial information about spectrum reservation utility. Once the complete information is obtained, a rebate on the payment is made if the reservation is released. In this paper, we present a contract theoretic approach to design an incentivized mechanism that coerces the applications to reveal their true application type resulting in greater profitability of the IoT network operator. The operator offers a menu of contracts with advanced payments and rebate to the IoT applications without having knowledge about the types of applications. The decision of the applications in selecting a contract leads to a revelation of their true type to the operator which allows it to generate higher profits than a traditional spectrum auction mechanism. Under some assumptions on distribution of the utility of the applications, closed form solutions for the optimal dynamic spectrum reservation contract are provided and the sensitivity against system parameters is analyzed. Muhammad Junaid Farooq, Quanyan Zhu |
WiOpt | 2 |
| 2018 | A Game-Theoretic Approach to Design Secure and Resilient Distributed Support Vector MachinesabstractDistributed support vector machines (DSVMs) have been developed to solve large-scale classification problems in networked systems with a large number of sensors and control units. However, the systems become more vulnerable, as detection and defense are increasingly difficult and expensive. This paper aims to develop secure and resilient DSVM algorithms under adversarial environments in which an attacker can manipulate the training data to achieve his objective. We establish a game-theoretic framework to capture the conflicting interests between an adversary and a set of distributed data processing units. The Nash equilibrium of the game allows predicting the outcome of learning algorithms in adversarial environments and enhancing the resilience of the machine learning through dynamic distributed learning algorithms. We prove that the convergence of the distributed algorithm is guaranteed without assumptions on the training data or network topologies. Numerical experiments are conducted to corroborate the results. We show that the network topology plays an important role in the security of DSVM. Networks with fewer nodes and higher average degrees are more secure. Moreover, a balanced network is found to be less vulnerable to attacks. Rui Zhang 0020, Quanyan Zhu |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2018 | On the Secure and Reconfigurable Multi-Layer Network Design for Critical Information Dissemination in the Internet of Battlefield Things (IoBT)abstractThe Internet of things (IoT) is revolutionizing the management and control of automated systems leading to a paradigm shift in areas, such as smart homes, smart cities, health care, and transportation. The IoT technology is also envisioned to play an important role in improving the effectiveness of military operations in battlefields. The interconnection of combat equipment and other battlefield resources for coordinated automated decisions is referred to as the Internet of battlefield things (IoBT). IoBT networks are significantly different from traditional IoT networks due to battlefield specific challenges, such as the absence of communication infrastructure, heterogeneity of devices, and susceptibility to cyber-physical attacks. The combat efficiency and coordinated decision-making in war scenarios depends highly on real-time data collection, which in turn relies on the connectivity of the network and information dissemination in the presence of adversaries. This paper aims to build the theoretical foundations of designing secure and reconfigurable IoBT networks. Leveraging the theories of stochastic geometry and mathematical epidemiology, we develop an integrated framework to quantify the information dissemination among heterogeneous network devices. Consequently, a tractable optimization problem is formulated that can assist commanders in cost effectively planning the network and reconfiguring it according to the changing mission requirements. Muhammad Junaid Farooq, Quanyan Zhu |
IEEE Trans. Wirel. Commun. | 2 |
| 2017 | Heterogeneous Multi-Layer Adversarial Network Design for the IoT-Enabled InfrastructuresabstractThe emerging Internet of Things (IoT) applications that leverage ubiquitous connectivity and big data are facilitating the realization of smart everything initiatives. IoT-enabled infrastructures have naturally a multi-layer system architecture with an overlaid or underlaid device network and its coexisting infrastructure network. The connectivity between different components in these two heterogeneous networks plays an important role in delivering real-time information and ensuring a high-level situational awareness. However, IoT- enabled infrastructures face cyber threats due to the wireless nature of communications. Therefore, maintaining the network connectivity in the presence of adversaries is a critical task for the infrastructure network operators. In this paper, we establish a three-player three-stage game-theoretic framework including two network operators and one attacker to capture the secure design of multi- layer infrastructure networks by allocating limited resources. We use subgame perfect Nash equilibrium (SPE) to characterize the strategies of players with sequential moves. In addition, we assess the efficiency of the equilibrium network by comparing with its team optimal solution counterparts in which two network operators can coordinate. We further design a scalable algorithm to guide the construction of the equilibrium IoT-enabled infrastructure networks. Finally, we use case studies on the emerging paradigm of Internet of Battlefield Things (IoBT) to corroborate the obtained results. Corinne Touati, Quanyan Zhu |
GLOBECOM | 3 |
| 2017 | Cognitive Connectivity Resilience in Multi-Layer Remotely Deployed Mobile Internet of ThingsabstractEnabling the Internet of things in remote areas without traditional communication infrastructure requires a multi-layer network architecture. The devices in the overlay network are required to provide coverage to the underlay devices as well as to remain connected to other overlay devices. The coordination, planning, and design of such two-layer heterogeneous networks is an important problem to address. Moreover, the mobility of the nodes and their vulnerability to adversaries pose new challenges to the connectivity. For instance, the connectivity of devices can be affected by changes in the network, e.g., the mobility of the underlay devices or the unavailability of overlay devices due to failure or adversarial attacks. To this end, this work proposes a feedback based adaptive, self-configurable, and resilient framework for the overlay network that cognitively adapts to the changes in the network to provide reliable connectivity between spatially dispersed smart devices. Our results show that if sufficient overlay devices are available, the framework leads to a connected configuration that ensures a high coverage of the mobile underlay network. Moreover, the framework can actively reconfigure itself in the event of varying levels of device failure. Muhammad Junaid Farooq, Quanyan Zhu |
GLOBECOM | 2 |
| 2017 | Learning from experience: A dynamic closed-loop QoE optimization for video adaptation and deliveryabstractThe quality of experience (QoE) is known to be subjective and context-dependent. Identifying and calculating the factors that affect QoE is indeed a difficult task. Recently, a lot of effort has been devoted to estimate the users' QoE in order to improve video delivery. In the literature, most of the QoE-driven optimization schemes that realize trade-offs among different quality metrics have been addressed under the assumption of homogenous populations. Nevertheless, people perceptions on a given video quality may not be the same, which makes the QoE optimization a hard task. This paper aims at taking a step further in order to address this limitation and meet users' profiles. Specifically, we propose a closed-loop control framework based on the users' (subjective) feedbacks to learn the QoE function and optimize it at the same time. Extensive simulation results show that the proposed scheme converges to a steady state, where the resulting QoE function noticeably improves the users' feedbacks. Imen Triki, Rachid El Azouzi, Majed Haddad, Quanyan Zhu, Zhiheng Xu |
PIMRC | 4 |
| 2017 | Optimizing mission critical data dissemination in massive IoT networksabstractMission critical data dissemination in massive Internet of things (IoT) networks imposes constraints on the message transfer delay between devices. Due to low power and communication range of IoT devices, data is foreseen to be relayed over multiple device-to-device (D2D) links before reaching the destination. The coexistence of a massive number of IoT devices poses a challenge in maximizing the successful transmission capacity of the overall network alongside reducing the multi-hop transmission delay in order to support mission critical applications. There is a delicate interplay between the carrier sensing threshold of the contention based medium access protocol and the choice of packet forwarding strategy selected at each hop by the devices. The fundamental problem in optimizing the performance of such networks is to balance the tradeoff between conflicting performance objectives such as the spatial frequency reuse, transmission quality, and packet progress towards the destination. In this paper, we use a stochastic geometry approach to quantify the performance of multi-hop massive IoT networks in terms of the spatial frequency reuse and the transmission quality under different packet forwarding schemes. We also develop a comprehensive performance metric that can be used to optimize the system to achieve the best performance. The results can be used to select the best forwarding scheme and tune the carrier sensing threshold to optimize the performance of the network according to the delay constraints and transmission quality requirements. Muhammad Junaid Farooq, Hesham ElSawy, Quanyan Zhu, Mohamed-Slim Alouini |
WiOpt | 3 |
| 2017 | Secure and reconfigurable network design for critical information dissemination in the Internet of battlefield things (IoBT)abstractThe Internet of things (IoT) is revolutionizing the management and control of automated systems leading to a paradigm shift in areas such as smart homes, smart cities, health care, transportation, etc. The IoT technology is also envisioned to play an important role in improving the effectiveness of military operations in battlefields. The interconnection of combat equipment and other battlefield resources for coordinated automated decisions is referred to as the Internet of battlefield things (IoBT). IoBT networks are significantly different from traditional IoT networks due to the battlefield specific challenges such as the absence of communication infrastructure, and the susceptibility of devices to cyber and physical attacks. The combat efficiency and coordinated decision-making in war scenarios depends highly on real-time data collection, which in turn relies on the connectivity of the network and the information dissemination in the presence of adversaries. This work aims to build the theoretical foundations of designing secure and reconfigurable IoBT networks. Leveraging the theories of stochastic geometry and mathematical epidemiology, we develop an integrated framework to study the communication of mission-critical data among different types of network devices and consequently design the network in a cost effective manner. Muhammad Junaid Farooq, Quanyan Zhu |
WiOpt | 2 |
| 2017 | Throughput maximization of large-scale secondary networks over licensed and unlicensed spectraabstractThroughput of a mobile ad hoc network (MANET) operating on an unlicensed spectrum can increase if nodes can also transmit on a (shared) licensed spectrum. However, the transmissions on the licensed spectrum has to be limited to avoid degradation of quality of service (QoS) to primary users (PUs). We address the problem of how the nodes of a MANET or secondary users (SUs) should spread their transmissions on both licensed and unlicensed spectra to maximize network throughput, and characterize ‘throughput gain’ achieved in such spectrum sharing systems. We show that the gain can be significant and is increasing in the density of the SUs. The primary and secondary users are modeled as two independent Poisson point processes and their performance is evaluated using techniques from stochastic geometry. Manjesh Kumar Hanawal, Yezekael Hayel, Quanyan Zhu |
WiOpt | 3 |
| 2017 | A Bi-Level Game Approach to Attack-Aware Cyber Insurance of Computer NetworksabstractCyber insurance is a valuable approach to mitigate further the cyber risk and its loss in addition to the deployment of technological cyber defense solutions, such as intrusion detection systems and firewalls. An effective cyber insurance policy can reduce the number of successful cyber attacks by incentivizing the adoption of preventative measures and the implementation of best practices of the users. To study cyber insurance in a holistic manner, we first establish a bi-level game-theoretic model that nests a zero-sum game in a moral-hazard type of principal-agent game to capture complex interactions between a user, an attacker, and the insurer. The game framework provides an integrative view of the cyber insurance and enables a systematic design of incentive compatible and attack-aware insurance policy. The framework is further extended to study a network of users and their risk interdependencies. We completely characterize the equilibrium solutions of the bi-level game. Our analytical results provide a fundamental limit on insurability, predict the Peltzman effect, and reveal the principles of zero operating profit and the linear insurance policy of the insurer. We provide analytical results and numerical experiments to corroborate the analytical results and demonstrate the network effects as a result of the strategic interactions among the three types of players. Rui Zhang 0020, Quanyan Zhu, Yezekael Hayel |
IEEE J. Sel. Areas Commun. | 2 |
| 2017 | CONGRESS: A Hybrid Reputation System for Coping with Rating SubjectivityabstractIn electronic commerce, buyers and sellers conduct transactions without physical interactions. In reputation systems, the trustworthiness of sellers is achieved by aggregating the ratings shared by other buyers with whom the sellers have ever conducted transactions. However, the ratings provided by buyers for evaluating the same seller could be diverse due to their different judgment criteria, which is referred as the subjectivity problem of reputation systems. It indicates that the ratings shared by some buyers may mislead other buyers with different personalities, making it challenging to aggregate the ratings properly in reputation systems. In this paper, in order to cope with the subjectivity problem, a hybrid architecture of reputation systems is proposed, which is based on coalition formation game theory. In the proposed module, buyers with the same subjectivity will automatically form a club, and share their ratings so as to build seller reputation within their club. The utility of a club is the profit created by the reputation system, which is further divided among the buyers of the club. Two utility allocation algorithms have been investigated, i.e., the proportional and Shapley allocations, respectively. Theoretical analysis and experimental results have shown that buyers with the same personality have the incentive to form a separate pure club if specific conditions are satisfied. Yuan Liu 0002, Jie Zhang 0002, Quanyan Zhu, Xingwei Wang 0001 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2017 | Security as a Service for Cloud-Enabled Internet of Controlled Things Under Advanced Persistent Threats: A Contract Design ApproachabstractIn this paper, we aim to establish a holistic framework that integrates the cyber-physical layers of a cloud-enabled Internet of Controlled Things (IoCT) through the lens of contract theory. At the physical layer, the device uses cloud services to operate the system. The quality of cloud services is unknown to the device, and hence the device designs a menu of contracts to enable a reliable and incentive-compatible service. Based on the received contracts, the cloud service provider (SP) serves the device by determining its optimal cyber defense strategy. A contract-based FlipCloud game is used to assess the security risk and the cloud quality of service (QoS) under advanced persistent threats. The contract design approach creates a pricing mechanism for on-demand security as a service for cloud-enabled IoCT. By focusing on high and low QoS types of cloud SPs, we find that the contract design can be divided into two regimes (regimes I and II) with respect to the provided cloud QoS. Specifically, the physical devices whose optimal contracts are in regime I always request the best possible cloud security service. In contrast, the device only asks for a cloud security level that can stabilize the system when the optimal contracts lie in regime II. We illustrate the obtained results via case studies of a cloud-enabled smart home. Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Epidemic Protection Over Heterogeneous Networks Using Evolutionary Poisson GamesabstractMalware is increasingly sophisticated and affects the wellbeing of a large population of heterogeneous and highly connected devices. The users of these devices can make strategic and dynamic decisions to choose whether or not to adopt the antivirus software, not only to secure their individual devices but also to protect the network they are part of. Motivated by the strategic behaviors of the antivirus adoption, we establish an evolutionary Poisson game framework to capture the random, dynamic, and heterogeneous interactions of agents in a holistic fashion, and design mechanisms to control their behaviors to achieve a system-wide objective. We first prove the existence and uniqueness of a mixed Nash equilibrium of the large population game and show that the equilibrium is an evolutionary stable strategy. Finally, we develop online algorithms using the techniques of stochastic approximation coupled with the population dynamics, and they are shown to converge to the optimal solution of the controller problem. Numerical examples are used to illustrate and corroborate our results. Yezekael Hayel, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Strategic Trust in Cloud-Enabled Cyber-Physical Systems With an Application to Glucose ControlabstractAdvances in computation, sensing, and networking have led to interest in the Internet of Things (IoT) and cyber-physical systems (CPS). Developments concerning the IoT and CPS will improve critical infrastructure, vehicle networks, and personal health products. Unfortunately, these systems are vulnerable to attack. Advanced persistent threats (APTs) are a class of long-term attacks in which well-resourced adversaries infiltrate a network and use obfuscation to remain undetected. In a CPS under APTs, each device must decide whether to trust other components that may be compromised. In this paper, we propose a concept of trust (strategic trust) that uses game theory to capture the adversarial and strategic nature of CPS security. Specifically, we model an interaction between the administrator of a cloud service, an attacker, and a device that decides whether to trust signals from the vulnerable cloud. Our framework consists of a simultaneous signaling game and the FlipIt game. The equilibrium outcome in the signaling game determines the incentives in the FlipIt game. In turn, the equilibrium outcome in the FlipIt game determines the prior probabilities in the signaling game. The Gestalt Nash equilibrium (GNE) characterizes the steady state of the overall macro-game. The novel contributions of this paper include proofs of the existence, uniqueness, and stability of the GNE. We also apply GNEs to strategically design a trust mechanism for a cloud-assisted insulin pump. Without requiring the use of historical data, the GNE obtains a risk threshold beyond which the pump should not trust messages from the cloud. Our framework contributes to a modeling paradigm called games-of-games. Jeffrey Pawlick, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Dynamic Differential Privacy for ADMM-Based Distributed Classification LearningabstractPrivacy-preserving distributed machine learning becomes increasingly important due to the recent rapid growth of data. This paper focuses on a class of regularized empirical risk minimization machine learning problems, and develops two methods to provide differential privacy to distributed learning algorithms over a network. We first decentralize the learning algorithm using the alternating direction method of multipliers, and propose the methods of dual variable perturbation and primal variable perturbation to provide dynamic differential privacy. The two mechanisms lead to algorithms that can provide privacy guarantees under mild conditions of the convexity and differentiability of the loss function and the regularizer. We study the performance of the algorithms, and show that the dual variable perturbation outperforms its primal counterpart. To design an optimal privacy mechanism, we analyze the fundamental tradeoff between privacy and accuracy, and provide guidelines to choose privacy parameters. Numerical experiments using customer information database are performed to corroborate the results on privacy and utility tradeoffs and design. Tao Zhang 0011, Quanyan Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Adaptive Exponential Synchronization of Multislave Time-Delayed Recurrent Neural Networks With Lévy Noise and Regime SwitchingabstractThis paper discusses the problem of adaptive exponential synchronization in mean square for a new neural network model with the following features: 1) the noise is characterized by the Lévy process and the parameters of the model change in line with the Markovian process; 2) the master system is also disturbed by the same Lévy noise; and 3) there are multiple slave systems, and the state matrix of each slave system is an affine function of the state matrices of all slave systems. Based on the Lyapunov functional theory, the generalized Itô's formula, -matrix method, and the adaptive control technique, some criteria are established to ensure the adaptive exponential synchronization in the mean square of the master system and each slave system. Moreover, the update law of the control gain and the dynamic variation of the parameters of the slave systems are provided. Finally, the effectiveness of the synchronization criteria proposed in this paper is verified by a practical example. Liuwei Zhou, Quanyan Zhu, Zhijie Wang 0001, Wuneng Zhou |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2016 | FACID: A trust-based collaborative decision framework for intrusion detection networks
Carol J. Fung, Quanyan Zhu |
Ad Hoc Networks | 2 |
| 2015 | Secure and resilient distributed machine learning under adversarial environments
Rui Zhang 0020, Quanyan Zhu |
FUSION | 2 |
| 2015 | Physical layer location privacy issue in wireless small cell networksabstractHigh data rates are essential for next-generation wireless networks to support a growing number of computing devices and networking services. Small cell base station (SCBS) (e.g., picocells, microcells, femtocells) technology is a cost-effective solution to address this issue. However, one challenging issue with the increasingly dense network is the need for a distributed and scalable access point association protocol. In addition, the reduced cell size makes it easy for an adversary to map out the geographical locations of the mobile users, and hence breaching their location privacy. To address these issues, we establish a game-theoretic framework to develop a privacy-preserving stable matching algorithm that captures the large scale and heterogeneity nature of 5G networks. We show that without the privacy-preserving mechanism, an attacker can infer the location of the users by observing wireless connections and the knowledge of physical-layer system parameters. The protocol presented in this work provides a decentralized differentially private association algorithm which guarantees privacy to a large number of users in the network. We evaluate our algorithm using case studies, and demonstrate the tradeoff between privacy and system-wide performance for different privacy requirements and a varying number of mobile users in the network. Our simulation results corroborate the result that the total number of mobile users should be lower than the overall network capacity to achieve desirable levels of privacy and QoS. Sadegh Farhang, Yezekael Hayel, Quanyan Zhu |
WISEC | 3 |
| 2014 | Interference-aware QoS multicast routing for smart grid
Ronghui Hou, Chuqing Wang, Quanyan Zhu, Jiandong Li 0001 |
Ad Hoc Networks | 3 |
| 2013 | Dynamic Service Placement in Geographically Distributed CloudsabstractLarge-scale online service providers have been increasingly relying on geographically distributed cloud infrastructures for service hosting and delivery. In this context, a key challenge faced by service providers is to determine the locations where service applications should be placed such that the hosting cost is minimized while key performance requirements (e.g., response time) are ensured. Furthermore, the dynamic nature of both demand pattern and infrastructure cost favors a dynamic solution to this problem. Currently most of the existing solutions for service placement have either ignored dynamics, or provided solutions inadequate to achieve this objective. In this paper, we present a framework for dynamic service placement problems based on control- and game-theoretic models. In particular, we present a solution that optimizes the hosting cost dynamically over time according to both demand and resource price fluctuations. We further consider the case where multiple service providers compete for resources in a dynamic manner. This paper extends our previous work [1] by analyzing the outcome of the competition in terms of both price of stability and price of anarchy. Our analysis suggests that in an uncoordinated scenario where service providers behave in a selfish manner, the resulting Nash equilibrium can be arbitrarily worse than the optimal centralized solution in terms of social welfare. Based on this observation, we present a coordination mechanism that can be employed by the infrastructure provider to maximize the social welfare of the system. Finally, we demonstrate the effectiveness of our solutions using realistic simulations. Qi Zhang 0008, Quanyan Zhu, Mohamed Faten Zhani, Raouf Boutaba, Joseph L. Hellerstein |
IEEE J. Sel. Areas Commun. | 2 |
| 2012 | A differential game approach to distributed demand side management in smart gridabstractSmart grid is a visionary user-centric system that will elevate the conventional power grid system to one which functions more cooperatively, responsively, and economically. Dynamic demand side management is one of the key issues that enable the implementation of smart grid. In this paper, we use the framework of dynamic games to model the distribution demand side management. The market price is characterized as the dynamic state using a sticky price model. A two-layer optimization framework is established. At the lower level, for each player (such as one household), different appliances are scheduled for energy consumption. At the upper level, the dynamic game is used to capture the interaction among different players in their demand responses through the market price. We analyze the N-person nonzero-sum stochastic differential game and characterize its feedback Nash equilibrium. A special case of homogeneous users is investigated in detail and we provide a closed-form solution for the optimal demand response. From the simulation results, we demonstrate the use of demand response strategy from the game-theoretic framework and study the behavior of market price and demand responses to different parameters. Quanyan Zhu, Zhu Han 0001, Tamer Basar |
ICC | 1 |
| 2012 | Dynamic Service Placement in Geographically Distributed CloudsabstractLarge-scale online service providers have been increasingly relying on geographically distributed cloud infrastructures for service hosting and delivery. In this context, a key challenge faced by service providers is to determine the locations where service applications should be placed such that the hosting cost is minimized while key performance requirements (e.g. response time) are assured. Furthermore, the dynamic nature of both demand pattern and infrastructure cost favors a dynamic solution to this problem. Currently most of the existing solutions for service placement have either ignored dynamics, or provided inadequate solutions that achieve both objectives at the same time. In this paper, we present a framework for dynamic service placement problems based on control- and game-theoretic models. In particular, we present a solution that optimizes the desired objective dynamically over time according to both demand and resource price fluctuations. We further consider the case where multiple service providers compete for resource in a dynamic manner, and show that there is a Nash equilibrium solution which is socially optimal. Using simulations based on realistic topologies, demand and resource prices, we demonstrate the effectiveness of our solution in realistic settings. Qi Zhang 0008, Quanyan Zhu, Mohamed Faten Zhani, Raouf Boutaba |
ICDCS | 2 |
| 2012 | GUIDEX: A Game-Theoretic Incentive-Based Mechanism for Intrusion Detection NetworksabstractTraditional intrusion detection systems (IDSs) work in isolation and can be easily compromised by unknown threats. An intrusion detection network (IDN) is a collaborative IDS network intended to overcome this weakness by allowing IDS peers to share detection knowledge and experience, and hence improve the overall accuracy of intrusion assessment. In this work, we design an IDN system, called GUIDEX, using game-theoretic modeling and trust management for peers to collaborate truthfully and actively. We first describe the system architecture and its individual components, and then establish a game-theoretic framework for the resource management component of GUIDEX. We establish the existence and uniqueness of a Nash equilibrium under which peers can communicate in a reciprocal incentive compatible manner. Based on the duality of the problem, we develop an iterative algorithm that converges geometrically to the equilibrium. Our numerical experiments and discrete event simulation demonstrate the convergence to the Nash equilibrium and the security features of GUIDEX against free riders, dishonest insiders and DoS attacks. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
IEEE J. Sel. Areas Commun. | 1 |
| 2012 | Interference Aware Routing Game for Cognitive Radio Multi-Hop NetworksabstractIn this paper, we introduce a distributed dynamic routing algorithm in multi-hop cognitive radio (CR) networks, in which secondary users (SUs) want to minimize their interference to the primary users (PUs) while keeping the delay along the route low. We employ a cognitive pilot channel (CPC) for SUs to be able to access the information about PUs, including PUs' locations and channel conditions. Medial axis with a relaxation factor is used as a reference path for the routing, along which we develop a hierarchical structure for multiple sources to reach their destinations. We introduce a temporal and spatial dynamic non-cooperative game to model the interactions among the SUs as well as their influences on the PUs, and obtain by backward induction a set of mixed (behavioral) Nash equilibrium strategies. We also employ a multi-stage fictitious play learning algorithm for distributed routing, which minimizes the overall interference from the SUs to the PUs, as well as the average packet delay along the route from the SU nodes to their destinations. Simulation results show that our proposed algorithm can avoid congestion in the CR network and minimize delay while keeping the interference level low. Quanyan Zhu, Zhou Yuan, Ju Bin Song, Zhu Han 0001, Tamer Basar |
IEEE J. Sel. Areas Commun. | 1 |
| 2011 | Poster: SMURFEN: a rule sharing collaborative intrusion detection network
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CCS | 2 |
| 2011 | SMURFEN: A system framework for rule sharing collaborative intrusion detection
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CNSM | 2 |
| 2011 | Nash meets Van Valkenburg: A game-theoretic approach to effective learning and teaching in engineeringabstractThis work uses game-theoretic approaches to understand the strategic behaviors of students and to achieve an effective teaching and evaluation tool for instructors to adapt their instructions to students' behaviors. We propose game-theoretic models to quantitatively investigate two specific education scenarios. One is on the curriculum design and the other is on the inventory-based test design for first-year undergraduate level courses. The game-theoretic approach allows us to consider multiple factors into one model and provides solution concepts from a holistic viewpoint combining sociology, psychology and engineering education. In addition, this work provides a theoretic and quantitative basis for future studies on effective learning and teaching in engineering community. Quanyan Zhu |
FIE | 1 |
| 2011 | Dynamic Secure Routing Game in Distributed Cognitive Radio NetworksabstractIn this paper, we propose a dynamic secure routing game framework to effectively combat jamming attacks in distributed cognitive radio networks. We first propose a stochastic multi-stage zero-sum game framework based on the directional exploration of ad hoc on-demand distance vector (AODV) algorithms. The zero-sum game captures the conflicting goals between malicious attackers and honest nodes and considers packet error probability and delay as performance metrics. The game-theoretic routing protocol guarantees a performance level given by the value of the game. Distributed Boltzmann-Gibbs learning is used for an on-line routing algorithm, in which the users do not have the knowledge of the attackers and the utility function. Instead, the users learn the payoffs based on their past observations. We use simulations to illustrate the proposed routing mechanism and compare the algorithm with fictitious-play learning. Unlike typical distributed routing algorithms such as AODV routing, the proposed secure routing algorithm supports a novel recovery of routing path failure against unknown attackers. Quanyan Zhu, Ju Bin Song, Tamer Basar |
GLOBECOM | 1 |
| 2010 | Dynamic Interference Minimization Routing Game for On-Demand Cognitive Pilot ChannelabstractIn this paper, we introduce a distributed dynamic routing algorithm for secondary users (SUs) to minimize their interference with the primary users (PUs) in multi-hop cognitive radio (CR) networks. We use the medial axis with a relaxation factor as a reference path which is contingent on the states of the PUs. Along the axis, we construct a hierarchical structure for multiple sources to reach cognitive pilot channel (CPC) base stations. We use a temporal and spatial dynamic non-cooperative game to model the interactions among SUs as well as their influences from PUs in the multi-hop structure of the network. A multi-stage fictitious play learning is used for distributed routing in multi-hop CR networks. We obtain a set of mixed (behavioral) Nash equilibrium strategies of the dynamic game in closed form by backward induction. The proposed algorithm minimizes the overall interference and the average packet delay along the routing path from SU nodes to CPC base stations in an optimal and distributed manner. Quanyan Zhu, Zhou Yuan, Ju Bin Song, Zhu Han 0001, Tamer Basar |
GLOBECOM | 1 |
| 2010 | Distributed correlated Q-learning for dynamic transmission control of sensor networksabstractThis paper considers a Markovian dynamical game theoretic setting for distributed transmission control in a wireless sensor network. The available spectrum bandwidth is modeled as a Markov chain. A distributed algorithm named correlated Q-learning algorithm is proposed to obtain the correlated equilibrium policies of the system. This algorithm has the decentralized feature and is easily implementable in a real system. Numerical example is also provided to verify the performances of the proposed algorithms. Jane W. Huang, Quanyan Zhu, Vikram Krishnamurthy, Tamer Basar |
ICASSP | 2 |
| 2010 | A Distributed Sequential Algorithm for Collaborative Intrusion Detection NetworksabstractCollaborative intrusion detection networks are often used to gain better detection accuracy and cost efficiency as compared to a single host-based intrusion detection system (IDS). Through cooperation, it is possible for a local IDS to detect new attacks that may be known to other experienced acquaintances. In this paper, we present a sequential hypothesis testing method for feedback aggregation for each individual IDS in the network. Our simulation results corroborate our theoretical results and demonstrate the properties of cost efficiency and accuracy compared to other heuristic methods. The analytical result on the lower-bound of the average number of acquaintances for consultation is essential for the design and configuration of IDSs in a collaborative environment. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
ICC | 1 |
| 2010 | No-Regret Learning in Collaborative Spectrum Sensing with Malicious NodesabstractIn cognitive radio network, spectrum sensing is a key component to detect spectrum holes (i.e., channels not used by any primary users). Collaborative spectrum sensing among the cognitive radio nodes is expected to improve fidelity of primary user detection. However, malicious nodes can significantly impair the collaborative spectrum sensing by sending the wrong reports to the fusion center. To overcome this problem, in this paper we propose non- regret learning algorithms to study the non-constructive secondary users caused either by evil-intention or altruistical incapability. Both perfect observation and partial monitoring are investigated, and two algorithms are proposed respectively. Some convergence properties are also shown. Moreover, we also analyze the case in which the nature is assumed to be a player. Illustration example and simulation results demonstrate the proposed schemes can automatically pick the malicious nodes in a distributed way. Quanyan Zhu, Zhu Han 0001, Tamer Basar |
ICC | 1 |
| 2010 | A Stochastic Game Model for Jamming in Multi-Channel Cognitive Radio SystemsabstractThe security issue in collaborative sensing in cognitive radio networks can be modeled as attackers and secondary users in a jamming and anti-jamming scenario. In this paper, we introduce a stochastic zero-sum game model to study the strategies. Primary users, secondary users and jammers are the three types of agents in the system. The primary users dictate the system states and their transitions while the secondary users and jammers behave non-cooperatively to achieve their goals independently under different system environment. Our Markovian game model captures not only the zero-sum interactions between secondary users and the jammers but also the dynamics of the system. Our results indicate that the secondary users can enhance their security level or increase their long-term payoff by either improving their sensing capabilities to confuse the jammer with the choice or choosing to communicate under states where the available channels are less prone to jamming. In the numerical experiments, we point out that the payoff of the secondary users increases with the number of available jamming-free channels and is eventually limited by the behavior of primary users. Quanyan Zhu, Husheng Li, Zhu Han 0001, Tamer Basar |
ICC | 1 |
| 2010 | Bayesian decision aggregation in collaborative intrusion detection networksabstractCooperation between intrusion detection systems (IDSs) allow collective information and experience from a network of IDSs to be shared for improving the accuracy of detection. A critical component of a collaborative network is the mechanism of feedback aggregation in which each IDS makes an overall security evaluation based on peer opinions and assessments. In this paper, we propose a collaboration framework for intrusion detection networks (CIDNs) and use a Bayesian approach for feedback aggregation by minimizing the combined costs of missed detection and false alarm. The proposed model is highly scalable, robust, and cost effective. Experimental results demonstrate an improvement in the true positive detection rate and a reduction in the average cost of our mechanism compared to existing models. Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
NOMS | 2 |
| 2009 | Hierarchical Network Formation Games in the Uplink of Multi-Hop Wireless NetworksabstractIn this paper, we propose a game theoretic approach to tackle the problem of the distributed formation of the hierarchical network architecture that connects the nodes in the uplink of a wireless multi-hop network. Unlike existing literature which focused on the performance assessment of hierarchical multi-hop networks given an existing topology, this paper investigates the problem of the formation of this topology among a number of nodes that seek to send data in the uplink to a central base station through multihop. We model the problem as a hierarchical network formation game and we divide the network into different hierarchy levels, whereby the nodes belonging to the same level engage in a noncooperative Nash game for selecting their next hop. As a solution to the game, we propose a novel equilibrium concept, the hierarchical Nash equilibrium, for a sequence of multi-stage Nash games, which can be found by backward induction analytically. For finding this equilibrium, we propose a distributed myopic dynamics algorithm, based on fictitious play, in which each node computes the mixed strategies that maximize its utility which represents the probability of successful transmission over the multi-hop communication path in the presence of interference. Simulation results show that the proposed algorithm presents significant gains in terms of average achieved expected utility per user up to 125.6% relative to a nearest neighbor algorithm. Walid Saad 0001, Quanyan Zhu, Tamer Basar, Zhu Han 0001, Are Hjørungnes |
GLOBECOM | 2 |
| 2009 | Evolutionary Games for Hybrid Additive White Gaussian Noise Multiple Access ControlabstractIn this paper, we propose an evolutionary game-theoretic framework for hybrid additive white Gaussian noise multiple access channels. We consider a communication system consisting of multiple users and multiple receivers, where each user chooses a rate and splits it over the receivers. Users have coupled constraints determined by the capacity regions. We show the existence of Nash equilibrium under general conditions and characterize the equilibria of the static game. Building upon the static game, we formulate a system of hybrid evolutionary game dynamics using G-function dynamics and Smith dynamics on rate control and channel selection, respectively. We show that the evolutionary hybrid multiple access game has an equilibrium and illustrate these dynamics with numerical examples. Quanyan Zhu, Hamidou Tembine, Tamer Basar |
GLOBECOM | 1 |
| 2009 | Enabling differentiated services using generalized power control model in optical networksabstractThis paper considers a generalized framework to study OSNR optimization-based end-to-end link level power control problems in optical networks. We combine favorable features of game-theoretical approach and central cost approach to allow different service groups within the network. We develop solutions concepts for both cases of empty and nonempty feasible sets. In addition, we derive and prove the convergence of a distributed iterative algorithm for different classes of users. In the end, we use numerical examples to illustrate the novel framework. Quanyan Zhu, Lacra Pavel |
IEEE Trans. Commun. | 1 |
| 2008 | Nonlinear Quadratic Pricing for Concavifiable Utilities in Network Rate ControlabstractThis paper deals with a category of concavifiable functions that can be used to model inelastic traffic in the network. Such class of functions can be concavified within an interval of interest using a quadratic pricing term so that we obtain as a result a concave objective function. We use a game- theoretical framework as well as a centralized optimization approach to discuss the heterogeneous network with nonlinear quadratic pricing. We point out the equivalence between these two frameworks and use a Stackelberg player as an extra degree of freedom to design pricing policy for the network. In the end, we propose an auction-like iterative algorithm and illustrate it with a numerical example. Quanyan Zhu, Raouf Boutaba |
GLOBECOM | 1 |
| 2008 | Service Differentiation via Power Management in WDM Optical NetworksabstractThis paper considers a generalized framework to study OSNR optimization-based end-to-end link level power control problems in optical networks. We combine favorable features of game-theoretical approach and central cost approach to allow different service groups within the network. We develop a novel solution concept for the case of nonempty feasible set. In addition, we derive and prove the convergence of a distributed iterative algorithm for different classes of users. In the end, we use numerical examples to illustrate the novel framework. Quanyan Zhu, Lacra Pavel |
ICC | 1 |
| 2008 | Theory of Linear Games with Constraints and Its Application to Power Control of Optical NetworksabstractIn this paper, we introduce a class of linear non- cooperative games with linearly coupled constraints. It bears striking connections with classical linear systems theory and finds itself pervasively used in network engineering applications. In the second part of the paper, we will illustrate this type of games by an application from OSNR-based power control in optical networks, where we can view the slack variables as fictitious players. This powerful interpretation allows us to bridge over the theory and the issue of implementation in engineering. Quanyan Zhu, Lacra Pavel |
INFOCOM | 1 |
| 2007 | Solving constrained OSNR Nash game in WDM optical networks with a fictitious playerabstractNon-cooperative game theory is a powerful modeling tool for resource allocation problems in modern communication networks. However, practical concerns of capacity constraints and allocation efficiency have been a challenge for network engineers. In this paper, we base our results in the context of link-level power control of optical networks and propose a special form of games with an additional player to overcome these difficulties.We introduce a novel framework with a fictitious player (GFP) to extend the current OSNR Nash game framework with capacity constraints. We characterize a more analytically tractable solution in comparison to other approaches and propose a first-order iterative algorithm to find the equilibrium. Quanyan Zhu, Lacra Pavel |
BROADNETS | 1 |