VLDB 2026 Research / reviewers in the wild / expert
Bingyang Liu
dblp:04/10609
· DBLP profile ↗
34ranked-venue papers
9as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 4 first-author · 9 since 2021Systems, architecture and hardware · 8 · 4 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GRAIN: A Design-Intent-Driven Analog Layout Migration FrameworkabstractMigrating a validated analog layout across technology nodes remains labor-intensive. Recent automatic migration methods often miss multi-level design intent embedded in expert layouts and may suffer from routing-induced LVS violations and unstable placement behaviors. We present GRAIN, a design-intent-driven analog layout migration framework that performs constraint-aware hierarchical placement migration to preserve multi-level placement behaviors, and uses guide-based routing that decouples similarity from legality via a maze router to reliably produce LVS-clean layouts. Experiments on real designs migrated from 65 nm to 40 nm and 28 nm show that, compared to a recent representative analog layout migration framework, GRAIN delivers 100% LVS-clean layouts without manual fixes and reduces area and wirelength by 13.8% and 29.2% on average, while also yielding post-layout metrics closer to the schematic. Bingyang Liu, Haoning Jiang, Haoyi Zhang, Xiaohan Gao, Zichen Kong, Xiyuan Tang, David Z. Pan, Yibo Lin |
DATE | 1 |
| 2026 | SwitchNN: In-Network CNN Inference for Edge-Assisted Smart Roadside Networks
Jianqiang Zhong, Jingpu Duan, Wenfei Wu, Deke Guo, Bingyang Liu, Xu Chen 0004 |
IWQoS | 9 |
| 2026 | Supercharging Packet-level Network Simulation of Large Model Training via Memoization and Fast-Forwarding
Kaihui Gao, Li Chen 0008, Dan Li 0001, Yiwei Zhang 0016, Fei Gui, Yitao Xing, Wenjia Wei, Bingyang Liu |
NSDI | 9 |
| 2026 | Balanced Sparse Tree: A Scalable Network Topology for Large Language ModelsabstractThe development of large language models (LLMs) has catalyzed unprecedented demand on the computing network, specifically for large-scale, few-hops, and low-latency, which directly underpin LLM task efficiency. However, mainstream topologies such as Clos suffer from costs and latency, while topologies with good scalability have symmetric or collective communication issues. In order to achieve a favorable balance among design metrics, we propose a novel topology named the Balanced Sparse Tree (BST), which is a topology characterized by symmetric design and sparse connections, motivated by hypergraph theory and Steiner Systems. Its degree-diameter upper-bound approaches the Moore Bound for Bipartite Biregular graphs, larger than other known dia-meter-2 topologies. Furthermore, we incorporate differentiated routing, deadlock freedom, and topology-affined deployment into BST. Testbed experiments, simulations, together with modeling analysis, demonstrate the superiority of BST over the state-of-the-art in network scale, latency, bandwidth, and cost. With equivalent scales, BST outperforms Clos with a 50% cost reduction while maintaining comparable performance for AI workloads. Furthermore, BST delivers a 3.9%–11.8% gain in collective communications and has 13.4% improvement over state-of-the-art topologies. Shaoteng Liu, Dejun Kong 0001, Huitian Wang, Hongji Dong, Fuguang Huang, Xiaofeng Gao 0001, Bingyang Liu, Guihai Chen |
SIGCOMM | 13 |
| 2026 | Reliable RDMA Over Lossy Fabrics via Data-Control Partitioning
Wenxue Li 0004, Xiangzhou Liu, Yunxuan Zhang, Gaoxiong Zeng, Shoushou Ren, Zhenghang Ren, Bowen Liu 0002, Junxue Zhang 0001, Bingyang Liu, Kai Chen 0005 |
IEEE Trans. Netw. | 13 |
| 2026 | Analysis of Pyrrha: Congestion-Root-Based Flow Control Is Most Cost-Effective to Eliminate Head-of-Line BlockingabstractIn modern datacenters, the effectiveness of end-to-end congestion control (CC) is quickly diminishing with the rapid bandwidth evolution. Per-hop flow control (FC) can react to congestion more promptly. However, a coarse-grained FC can result in Head-Of-Line (HOL) blocking. A fine-grained, per-flow FC can eliminate HOL blocking caused by flow control, however, it does not scale well. This paper presents Pyrrha, a scalable flow control approach that provably eliminates HOL blocking while using a minimum number of queues. In Pyrrha, flow control first takes effect on the root of the congestion, i.e., the port where congestion occurs. And then flows are controlled according to their contributed congestion roots. A prototype of Pyrrha is implemented on Tofino2 switches. Compared with state-of-the-art approaches, the average FCT of uncongested flows is reduced by 42%-98%, and 99th-tail latency can be$1.6\times $-$215\times $lower, without compromising the performance of congested flows. Zhaochen Zhang, Peirui Cao, Chang Liu 0001, Yizhi Wang 0004, Vamsi Addanki, Stefan Schmid 0001, Qingyue Wang, Xiaoliang Wang 0001, Jiaqi Zheng 0001, Tao Wu 0011, Bingyang Liu, Wan-Chun Dou, Guihai Chen, Chen Tian 0001, Fu Xiao 0001 |
IEEE Trans. Netw. | 17 |
| 2025 | LayoutCopilot: LLM-Empowered Analog Layout Design towards Enhanced Human-Machine InteractionabstractAnalog and mixed-signal circuits are crucial for interfacing digital systems with the real world, yet the layout design remains manual and highly labor-intensive. Fully automated tools for layout design have made significant progress in easing this burden, but they often restrict flexibility and designer control. Interactive design flows combine the strengths of both manual and automated design; however, designers still face challenges in human-machine interaction, such as complex command sets and manual code writing. In this paper, we introduce LayoutCopilot, an LLM-empowered interactive layout design framework that addresses this challenge by enabling the translation of high-level design intents expressed in natural language into actionable commands. It also incorporates automated constraint extraction, reducing repetitive tasks and enhancing interaction between designers and the tool. Our experiments demonstrate that this framework undergoes validation for syntactic and functional correctness and is successfully applied to real-world analog design tasks, from constraint extraction to layout refinement, achieving efficient designers’ involvement with reduced manual efforts. Bingyang Liu, Haoyi Zhang, Xiaohan Gao, Xiyuan Tang, Yibo Lin, Runsheng Wang, Ru Huang 0001 |
ISCAS | 1 |
| 2025 | Pyrrha: Congestion-Root-Based Flow Control to Eliminate Head-of-Line Blocking in Datacenter
Zhaochen Zhang, Chang Liu 0001, Yizhi Wang 0004, Vamsi Addanki, Stefan Schmid 0001, Qingyue Wang, Xiaoliang Wang 0001, Jiaqi Zheng 0001, Tao Wu 0011, Bingyang Liu, Wan-Chun Dou, Guihai Chen, Chen Tian 0001 |
NSDI | 16 |
| 2025 | Revisiting RDMA Reliability for Lossy FabricsabstractDue to the high operational complexity and limited deployment scale of lossless RDMA networks, the community has been exploring efficient RDMA communication over lossy fabrics. State-of-the-art (SOTA) lossy RDMA solutions implement a simplified selective repeat mechanism in RDMA NICs (RNICs) to enhance loss recovery efficiency. However, these solutions still face performance challenges, such as unavoidable ECMP hash collisions and excessive retransmission timeouts (RTOs). In this paper, we revisit RDMA reliability with the goals of being independent of PFC, compatible with packet-level load balancing, free from RTO, and friendly to hardware offloading. To this end, we propose DCP, a transport architecture that co-designs both the switch and RNICs, fully meeting the design goals. At its core, DCP-Switch introduces a simple yet effective lossless control plane, which is leveraged by DCP-RNIC to enhance reliability support for high-speed lossy fabrics, primarily including header-only-based retransmission and bitmap-free packet tracking. We prototype DCP-Switch using P4 switch and DCP-RNIC using FPGA. Extensive experiments demonstrate that DCP achieves 1.6× and 2.1× performance improvements, compared to SOTA lossless and lossy RDMA solutions, respectively. Wenxue Li 0004, Xiangzhou Liu, Yunxuan Zhang, Gaoxiong Zeng, Shoushou Ren, Zhenghang Ren, Bowen Liu 0002, Junxue Zhang 0001, Kai Chen 0005, Bingyang Liu |
SIGCOMM | 14 |
| 2025 | LayoutCopilot: An LLM-Powered Multiagent Collaborative Framework for Interactive Analog Layout DesignabstractAnalog layout design heavily involves interactive processes between humans and design tools. electronic design automation (EDA) tools for this task are usually designed to use scripting commands or visualized buttons for manipulation, especially for interactive automation functionalities, which have a steep learning curve and cumbersome user experience, making a notable barrier to designers’ adoption. Aiming to address such a usability issue, this article introduces LayoutCopilot, a pioneering multiagent collaborative framework powered by large language models (LLMs) for interactive analog layout design. LayoutCopilot simplifies human-tool interaction by converting natural language instructions into executable script commands, and it interprets high-level design intents into actionable suggestions, significantly streamlining the design process. Experimental results demonstrate the flexibility, efficiency, and accessibility of LayoutCopilot in handling real-world analog designs. Bingyang Liu, Haoyi Zhang, Xiaohan Gao, Zichen Kong, Xiyuan Tang, Yibo Lin, Runsheng Wang, Ru Huang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2025 | Pisces: In-Path Distributed Denial-of-Service Defense via Efficient Authentication Code Embedded in IP AddressabstractHigh-volume brute-force distributed denial-of-service (DDoS) attack is among the top threats on the Internet. Existing widely deployed methods (e.g., BGP blackhole and scrubbing center) have difficulty achieving legitimate traffic friendliness, low cost, low latency, and high accuracy. We present an in-path DDoS defense mechanism, namelyPisces. Without requiring modifications to existing IP protocols,Piscesembeds authentication information into the IP address. Simultaneously, we design a QUIC-based extension to distribute authentication information.Piscesincorporates a translator module and a filter module, which accurately identifies malicious and legitimate traffic. These multi-dimensional compatibility advantages make it easy to deploy in the real world. We implementPisceson a high-end commercial router with service processing units. Even without hardware acceleration, a single CPU can achieve$ 20\,\text{Gbps}$throughput and the performance can scale linearly with the number of CPUs. The additional latency for the victim-related traffic and other traffic is around$27\,\text{us}$and$0.5\,\text{us}$, respectively, whose cost is far less than the scrubbing center. Remarkably,Pisceswithout false positives can provide high-quality datasets for intelligent approaches and form a prominent complementary effect. Yi Zhao 0011, Bingyang Liu, Weiyu Jiang, Ke Xu 0002, Qi Li 0002, Chuang Wang 0012, Zongxin Dou |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Joint Placement Optimization for Hierarchical Analog/Mixed-Signal CircuitsabstractThe performance of Analog/Mixed Signal (AMS) circuits is highly dependent on the meticulous layout implementation. To meet performance and area requirements, real-world AMS layout design is thoroughly optimized to consider circuit hierarchy and a multitude of factors, such as system signal flow and regularity. Circuit hierarchy and these factors impose complicated constraints, which challenge layout design flow. In this paper, we propose a systematic AMS placement framework to address the challenges through joint optimization. We implement our framework in a unified and highly extensible workflow and validate our framework with broad types of real-world AMS circuits. Experiments show that our framework achieves promising results in both efficiency and quality. Xiaohan Gao, Haoyi Zhang, Bingyang Liu, Yibo Lin, Runsheng Wang, Ru Huang 0001 |
ICCAD | 3 |
| 2024 | Dissecting the Applicability of HTTP/3 in Content Delivery NetworksabstractHTTP/3 (H3) has experienced significant growth and extensive adoption in various scenarios, especially in Content Delivery Networks (CDNs). Over the past few years, there have been numerous insightful studies on its deployment in industrial CDNs. However, these studies often separately analyze H3 and CDN, overlooking their synergistic integration. In this work, we explore the applicability of H3 in CDN from a holistic perspective. We analyze 325 websites hosted by seven CDN providers and identify three key characteristics where CDN align perfectly with H3's strengths. Firstly, CDN resources dominate the composition of webpages, where enabling H3 can amplify H3's benefits in connection acceleration. Secondly, CDN providers also exhibit a dominant characteristic, with the majority of CDN resources hosted by a few large providers. This phenomenon makes different webpages share the same provider. When browsing consecutively, H3 helps to skip the connection phase by resuming the connections to the same CDN provider across pages. Thirdly, H3 mitigates the congestion problem on webpages serving multiple CDN resources. This work provides a deeper insight into the applicability of H3 in large-scale distributed systems like CDNs, holding promise for informing the development and optimization of industrial H3. Yang Chen 0001, Shihan Lin, Xin Wang 0002, Bingyang Liu, Aaron Yi Ding |
ICDCS | 5 |
| 2024 | A Deep Learning Framework for Petrophysical Properties Prediction in Gas ReservoirsabstractPredicting the petrophysical properties of rocks from seismic data is challenging because the relationship between petrophysical properties and their seismic response is nonlinear and multisolution. A targeted framework is presented to enhance the effectiveness of petrophysical properties prediction based on deep learning (DL) in this study. We utilize statistical rock physics and geological methods to tackle the challenge of the limited availability of labeled data. Moreover, in response to the issue of multiple solutions, we propose a multitask inversion neural network architecture for predicting petrophysical properties from multiinformation guided by a physical model. To evaluate the validity of the framework, we built a numerical model and carried out a quantitative analysis using threefold cross-validation and comparison of single trace predictive results. The framework is finally applied to a real work area of a deep tight dolomite reservoir in Southwest China, demonstrating promising prospects for practical application. Jinyong Gui, Jianhu Gao, Shengjun Li, Bingyang Liu, Qiyan Chen |
IEEE Geosci. Remote. Sens. Lett. | 4 |
| 2024 | Enhancing Low Latency Adaptive Live Streaming Through Precise Bandwidth PredictionabstractTo ensure high performance for HTTP adaptive streaming (HAS), it is critical to provide accurate prediction of end-to-end network bandwidth. Low Latency Live Streaming (LLLS), which has been gaining popularity, faces even greater challenges in this regard. Unlike Video-on-Demand (VOD) streaming, which only needs long-term bandwidth prediction and can tolerate some prediction errors, LLLS demands precise short-term bandwidth predictions. These challenges are amplified by the fact that short-term bandwidth experiences both large abrupt changes and uncertain fluctuations. Furthermore, obtaining valid bandwidth measurement samples in LLLS poses difficulties due to the on-off traffic pattern. In this work, we present DeeProphet, a system designed to enhance the performance of LLLS by achieving accurate bandwidth prediction. DeeProphet collects valid bandwidth samples by identifying intervals of packet continuous sending leveraging TCP state information, estimates the segment-level bandwidth robustly by filtering out noisy samples, and predicts both significant changes and uncertain fluctuations in future bandwidth by combining both time series and learning-based models. Experimental results demonstrate that DeeProphet effectively enhances the overall Quality of Experience (QoE) by 39.5% to 464.6% compared to state-of-the-art LLLS Adaptive Bitrate (ABR) algorithms. Bo Wang 0066, Muhan Su, Wufan Wang, Bingyang Liu, Fengyuan Ren, Mingwei Xu 0001, Jiangchuan Liu |
IEEE/ACM Trans. Netw. | 5 |
| 2021 | A Proof of Optimality on EDF Scheduling in Sink-tree Packetized NetworksabstractEarliest Deadline First (EDF) scheduling, is known to obtain the optimality of deterministic delay performance upon the single link. However, due to the generality of the network with multiple nodes and multiple flows transmitted within it, the optimal online scheduling is impossible. In this paper, we prove that EDF can still provide the optimal delay performance in a class of practical multiple-nodes-and-multiple-flows network scenarios, such as 5G Cloud VR/AR applications in up-link cases, namely in sink-tree networks multiple flows sharing the root node as the same destination node. The proof uses the delay-based schedulability region to quantify the performance of different scheduling policies. Finally, the proof indicates that EDF can achieve the largest schedulability region in sink-tree networks. Bingyang Liu, Shoushou Ren |
HPSR | 2 |
| 2021 | Towards Large-Scale Deterministic IP NetworksabstractDeterministic performance is a key enabler for 5G networking. In this context, we present a highly scalable Large-scale Deterministic Network (LDN) architecture providing end-to-end latency and bounded jitter guarantees in IP networks. At the data plane, flows are first shaped at ingress gateways using gate-control queues, achieving a very fine granularity compared to existing state of the art solutions. Inside the network, traffic is scheduled using an asynchronous cyclic queuing mechanism that can be implemented in real devices as it requires only 3 FIFO queues. The data plane relies on standard IP routing and a quasi-static mapping table to deterministically aggregate and forward packets over cycles with a low complexity in O(1). For the control plane, we present an advanced column generation algorithm to quickly take admission control decisions in large-scale networks. For a set of flows, it determines acceptance and selects the best shaping and routing policy. Through a proof-of-concept implementation and simulations, we show that our LDN architecture can guarantee end-to-end latency and bounded jitter. We also demonstrate that our advanced control plane algorithm brings an improvement up to 40% in terms of accepted traffic over classical routing. Bingyang Liu, Shoushou Ren, Chuang Wang 0012, Vincent Angilella, Paolo Medagliani, Sébastien Martin, Jeremie Leguay |
Networking | 1 |
| 2021 | Security-Oriented Network ArchitectureabstractInternet benefits societies by constantly connecting devices and transmitting data across the world. However, due to the lack of architectural built-in security, the pervasive network attacks faced by the entire information technology are considered to be unending and inevitable. As Internet evolves, security issues are regularly fixed according to a patch-like strategy. Nevertheless, the patch-like strategy generally results in arms races and passive situations, leaving an endless lag in both existing and emerging attacking surface. In this paper, we present NAIS (Network Architecture with Intrinsic Security)—a network architecture towards trustworthiness and security. By solving stubborn security issues like IP spoofing, MITM (man-in-the-middle) attacks, and DDoS (distributed denial of service) attacks at architectural level, NAIS is envisioned to provide the most secure end-to-end communication in the network layer. This paper first presents a comprehensive analysis of network security at Internet range. Then, the system design of NAIS is elaborated with particular design philosophies and four security techniques. Such philosophies and techniques intertwine internally and contribute to a communication environment with authenticity, privacy, accountability, confidentiality, integrity, and availability. Finally, we evaluate the security functionalities on the packet forwarding performance, demonstrating that NAIS can efficiently provide security and trustworthiness in Internet end-to-end communication. Weiyu Jiang, Bingyang Liu, Chuang Wang 0012 |
Secur. Commun. Networks | 2 |
| 2020 | The Trusted and Decentralized Network Resource ManagementabstractNetwork resource management relies on trusted infrastructures. However, current trusted infrastructures have centralized or hierarchical structures where root nodes often have privileges over subtrees. Hacked or malicious roots may affect subtrees by modifying IP ownership, routing and so on. Therefore, a trusted and decentralized network resource management becomes crucial. The emergence of blockchain such as Ethereum becomes a leading candidate for achieving trusted and decentralized network resource management. In this paper, based on Ethereum, we design a trusted authentication scheme that includes voting policy, endorsement, credibility model and rebinding mechanism to ensure the credibility of entities. Our scheme can allocate, delegate and transfer network resources in a trusted and decentralized style. The experimental results verify the feasibility and security of our scheme. When an entity is hacked or malicious, its endorsement authentication is revoked and the entity does not have the right to manage the network resources. In addition, the overhead increased by the trusted authentication scheme is within a reasonable range. Marcelo Bagnulo, Bingyang Liu, Xiaohong Huang 0003 |
ICCCN | 5 |
| 2020 | Preventing Route Leaks using a Decentralized Approach: An Experimental EvaluationabstractIn the inter-domain routing infrastructure, a route leak is defined as a violation of the routing policy agreed between two Autonomous Systems (AS). Route leaks have resulted in large-scale outages on the Internet, taking down several services. Although route leaks seem a simple problem, the solution is complex because: (i) ASes consider -partially- routing policy private, (ii) lack of a formal and standard language to express routing policy and (iii) BGP lacks adequate cryptographic-based security. In this paper, we present an experimental analysis of a distributed ledger-based architecture that provides a solution to route leaks. Specifically, the routing policy is unambiguously expressed using a formal language, that is then stored in a blockchain. This decentralized architecture allows private policies and interfaces seamlessly with the current BGP infrastructure, requiring no changes to routers. We build a prototype to evaluate our proposed architecture using Hyperledger, we analyze its performance using a real-world BGP dataset. Our results show that our architecture scales linearly with relevant metrics. Additionally, we validate the architecture preventing an artificially introduced route leak in a realistic 10 AS topology. Miquel Ferriol, Roger Coll Aumatell, Albert Cabellos-Aparicio, Shoushou Ren, Xinpeng Wei, Bingyang Liu |
ICNP | 6 |
| 2020 | Poster: Enhancing Remote Healthiness Attestation for Constrained IoT DevicesabstractThe Internet of Things (IoT), which has been rapidly implemented in the smart home, city, and industry, keeps shaping the way we live. However, the constrained resource of IoT leads to a constant vulnerability for its’ resident network and the whole Internet. To mitigate potential threats, a complementary method – Device Identifier Composition Engine (DICE) – is introduced to enable remote healthiness attestation for IoT devices. Although DICE narrows the gap between security necessity and the constrained resource of IoT, a replay attack is still possible to circumvent the method. In this paper, an enhanced DICE+ is proposed to address the weakness. Compared to the original DICE, DICE+ improves DICE with dynamic attestation evidence (other than static evidence in standard DICE), and thus alleviates the replay attack. Based on the evaluation, DICE+ enhances the standard DICE in three aspects simultaneously: (i) Replay attack resilience; (ii) Extreme lightweight overhead; (iii) Fine-grained firmware attestation. According to the chip specification from our product line, a ca. 60% size reduction of the chip security-related area is expectable if such the method applied along with a pure symmetric-cryptography tech-set. Yihao Jia, Bingyang Liu, Weiyu Jiang, Chuang Wang 0012 |
ICNP | 2 |
| 2020 | Preventing Route Leaks using a Decentralized Approach
Miquel Ferriol, Roger Coll Aumatell, Albert Cabellos-Aparicio, Shoushou Ren, Xinpeng Wei, Bingyang Liu |
Networking | 6 |
| 2019 | BlockDNS: Enhancing Domain Name Ownership and Data Authenticity with BlockchainabstractThe Domain Name System (DNS) is one of the most fundamental infrastructures of the Internet. However, due to its design philosophy and implementation architecture, the current DNS still suffers from the centralization problem and the data authenticity problem. In this paper, we analyze these two problems and propose a blockchain-based naming system called blockDNS to solve them simultaneously. In blockDNS, domain names can be applied and transferred freely in a decentralized way. Moreover, a lightweight verification mechanism is also proposed coupled with blockDNS. The verification mechanism allows website clients to verify the authenticity of resolution results with few overheads. Simulation results show that, compared to the Simplified Payment Verification method, blockDNS can cut down the overheads for data authenticity verification from 4.955KBytes to 380Bytes. Moreover, we also present an implementation case of blockDNS, which is compatible with the current naming system and can be deployed incrementally. Shoushou Ren, Bingyang Liu, Xinpeng Wei, Chuang Wang 0012 |
GLOBECOM | 2 |
| 2019 | SmartCrowd: Decentralized and Automated Incentives for Distributed IoT System DetectionabstractInternet of Things (IoT) devices achieve the rapid development and have been widely deployed recently. Meanwhile, inherent vulnerabilities of IoT systems (including firmware and software) have been continually uncovered and thus the systems are always exposed to various attacks. The root cause of the issue is that IoT systems always have design flaws and implementation bugs. In particular, the released systems (e.g., by third-party marketplaces and IoT vendors) may be maliciously repackaged with malware. Unfortunately, IoT consumers are not able to effectively capture such vulnerabilities because of the limited detection capabilities. In this paper, we propose SmartCrowd, a blockchain-based platform that aims to outsource security detection of IoT systems to distributed detectors with strong detection incentives. SmartCrowd enables built-in accountability for IoT providers and authoritative references of detection results for IoT consumers. By building smart contracts, we can incentivize the efficient and high-coverage security detection of IoT systems, while providing decentralized and automated incentives for both IoT providers releasing secure IoT systems and detectors uncovering vulnerabilities. We present the security and theoretical analysis that demonstrates the security of SmartCrowd and the incentives for participators. We prototype SmartCrowd by using Ethereum and the experimental results show that SmartCrowd has both technical feasibility and financial benefits, which can be applied to build a secure IoT ecosystem. Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Zhuotao Liu, Yih-Chun Hu, Xinle Du, Bingyang Liu, Shoushou Ren |
ICDCS | 8 |
| 2019 | Artemis: A Practical Low-latency Naming and Routing SystemabstractToday, Internet service deployment is typically implemented with server replication at multiple locations for the purpose of load balancing, failure tolerance, and user experience optimization. Domain name system (DNS) is responsible for translating human-readable domain names into network-routable IP addresses. When multiple replicas exist, upon the arrival of a query, DNS selects one replica and responds with its IP address. Thus, the delay caused by the process of DNS query including the selection of replica is part of the connection setup latency. Xuebing Li, Bingyang Liu, Yang Chen 0001, Yu Xiao 0001, Jiaxin Tang, Xin Wang 0002 |
ICPP | 2 |
| 2019 | RFL: Robust fault localization on unreliable communication channels
Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Bingyang Liu, Shoushou Ren, Meng Shen 0001, Kui Ren 0001 |
Comput. Networks | 4 |
| 2019 | P4DB: On-the-Fly Debugging for Programmable Data PlanesabstractWhile extending network programmability to a more considerable extent, P4 raises the difficulty of detecting and locating bugs, e.g., P4 program bugs and missed table rules, in runtime. These runtime bugs, without prompt disposal, can ruin the functionality and performance of networks. Unfortunately, the absence of efficient debugging tools makes runtime bug troubleshooting intricate for operators. This paper is devoted to on-the-fly debugging of runtime bugs for programmable data planes. We propose P4DB, a general debugging platform that empowers operators to debug P4 programs in three levels of visibility with rich primitives. By P4DB, operators can use the watch primitive to quickly narrow the debugging scope from the network level or the device level to the table level, then use the break and next primitives to decompose match-action tables and finely locate bugs. We implement a prototype of P4DB and evaluate the prototype on two widely-used P4 targets. On the software target, P4DB merely introduces a small throughput penalty (1.3% to 13.8%) and a little delay increase (0.6% to 11.9%). Notably, P4DB almost introduces no performance overhead on Tofino, the hardware P4 target. Yu Zhou 0008, Jun Bi, Cheng Zhang 0012, Bingyang Liu, Zhaogeng Li, Yangyang Wang 0001, Mingli Yu |
IEEE/ACM Trans. Netw. | 4 |
| 2017 | P4DB: On-the-fly debugging of the programmable data planeabstractWhile extending network programmability to a larger degree, P4 also raises the risks of incurring runtime bugs after the deployment of P4 programs. These runtime bugs, if not handled promptly and properly, can ruin the functionality and performance of networks. Unfortunately, the absence of runtime debuggers makes troubleshooting of P4 program bugs challenging and intricate for operators. This paper is devoted to the on-the-fly debugging of runtime bugs in P4-enabled networks. We propose P4DB, a general debugging platform that empowers operators to debug P4 programs in three levels of visibility by provisioning operator-friendly primitives. By P4DB, operators can use the watch primitive to quickly narrow the debugging scope from network level or device level to table level, then use the break and next primitives to decompose the match-action table into three steps and troubleshoot the runtime bugs step by step. We implemented a prototype of P4DB and evaluated the performance in terms of the data plane, control plane and control channel. On P4-specific programmable data plane, P4DB merely introduces a small throughput penalty (1.3%~13.8%) and imposes a little-increased delay (0.6%~11.9%). Cheng Zhang 0012, Jun Bi, Yu Zhou 0008, Bingyang Liu, Zhaogeng Li, Abdul Basit Dogar, Yangyang Wang 0001 |
ICNP | 5 |
| 2016 | Source Address Validation in Software Defined NetworksabstractIn this paper, we present the preliminary design and implementation of SDN-SAVI, an SDN application that enables SAVI functionalities in SDN networks. In this proposal, all the functionalities are implemented on the controller without modifying SDN switches. To enforce SAVI on packets in the data plane, the controller installs binding tables in switches using existing SDN techniques, such as OpenFlow. With SDN-SAVI, a network administrator can now enforce SAVI in her network by merely integrating a module on the controller, rather than purchasing SAVI-capable switches and replacing legacy ones. Bingyang Liu, Jun Bi, Yu Zhou 0008 |
SIGCOMM | 1 |
| 2015 | DISCS: A DIStributed Collaboration System for Inter-AS Spoofing DefenseabstractIP spoofing is prevalently used in DDoS attacks for anonymity and amplification, making them harder to prevent. Combating spoofing attacks requires the collaboration of different autonomous systems (ASes). Existing methods either lack flexibility in collaboration or require centralized control in the inter-AS environment. In this paper, we propose a Distributed Collaboration System (DISCS) for inter-AS spoofing defense, which allows ASes to flexibly collaborate in spoofing defense in a distributed manner. Each DISCS-enabled AS implements four defense functions. When a victim AS is under a spoofing attack, it can request other ASes to execute the most appropriate defense functions. We present the distributed and flexible control plane design and the backward compatible and incrementally deployable data plane design for both IPv4 and IPv6. We evaluate DISCS with theoretical proof and simulations using real Internet data. The results show that DISCS has strong deployment incentives, high effectiveness, minimal false positives, modest resource consumption and strong security. Bingyang Liu, Jun Bi |
ICPP | 1 |
| 2014 | Toward Incentivizing Anti-Spoofing DeploymentabstractIP spoofing-based flooding attacks are a serious and open security problem on the current Internet. The best current antispoofing practices have long been implemented in modern routers. However, they are not sufficiently applied due to the lack of deployment incentives, i.e., an autonomous system (AS) can hardly gain additional protection by deploying them. In this paper, we propose mutual egress filtering (MEF), a novel antispoofing method, which provides continuous deployment incentives. The MEF is implemented on the AS border routers using access control lists (ACLs). It drops an outbound packet whose source address does not belong to the local AS if the packet is related to a spoofing attack against other MEF-enabled ASes. By this means, only the deployers of the MEF can gain protection, whereas nondeployers cannot free ride. As more ASes deploy MEF, deployment incentives become higher. We present the system design of MEF, and propose an optimal prefix compression algorithm to compact the ACL into the routers' limited hardware resource. With theoretical analysis and simulations with real Internet data, our evaluation results show that MEF is the only method that achieves monotonically increasing deployment incentives for all types of spoofing attacks, and the system design is lightweight and practical. The prefix compression algorithm advances the state-of-the-art by generalizing the functionalities and reducing the overhead in both time and space. Bingyang Liu, Jun Bi, Athanasios V. Vasilakos |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | A Self-learning Template Approach for Recognizing Named Entities from Web Text
Bingyang Liu, Dayong Wu, Xueqi Cheng 0001 |
IJCNLP | 2 |
| 2012 | FaaS: filtering IP spoofing traffic as a serviceabstractNo abstract available. Bingyang Liu, Jun Bi, Xiaowei Yang 0001 |
SIGCOMM | 1 |
| 2011 | A deployable approach for inter-AS anti-spoofingabstractFiltering IP packets with spoofed source addresses not only improves network security, but also helps with network diagnosis and management. Compared with filtering spoofing packets at the edge of network which involves high deployment and maintenance cost, filtering at autonomous system (AS) borders is more cost-effective. Inter-AS anti-spoofing, as its name suggests, is implemented on AS border routers to filter spoofing packets before their entering or leaving an AS. Existing inter-AS anti-spoofing approaches focus on filtering efficiency, but lacks of deployability. In this paper we first introduce three properties of a deployable inter-AS anti-spoofing approach, incremental deployability, high deployment incentives and low deployment cost. Then we propose DIA, the first inter-AS anti-spoofing approach meeting the three properties. We present the design of DIA and evaluate its deployability with real Internet data. The evaluation results show that DIA provides high deployment incentives for Internet Service Providers by significantly mitigating spoofing based denial of service attacks. Our implementation proves that DIA can be easily implemented in commodity routers and minimize the deployment cost. Bingyang Liu, Jun Bi |
ICNP | 1 |