VLDB 2026 Research / reviewers in the wild / expert
Ruidong Li 0001
dblp:06/7035-1
· DBLP profile ↗
155ranked-venue papers
18as first author
127since 2021 · last 2026
0000-0002-9905-8952ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 109 · 13 first-author · 88 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 1 first-author · 11 since 2021Systems, architecture and hardware · 12 · 1 first-author · 11 since 2021Security and privacy · 12 · 12 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Energy-Aware Usv-Uav Cooperative Task Offloading Optimization in Water Monitoring System
Chaogang Tang, Tiyu Yao, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
ICDCS | 5 |
| 2026 | AEPA: Adaptive Entanglement Pre-Allocation for Low-Latency Quantum Repeater Networks
Baoxia Du, Ruidong Li 0001 |
INFOCOM | 3 |
| 2026 | QuIKS: Near-Zero Latency Key Supply with Adaptive Buffering for Resource-Efficient Quantum Key Distribution Networks
Zite Xia, Jian Li 0031, Kaiping Xue, Zhonghui Li, Lutong Chen, Ruidong Li 0001 |
INFOCOM | 7 |
| 2026 | Network-Compute Trade-offs in Resource Depletion Attacks on LLM Inference Services
Zhiyuan Fu, Ruidong Li 0001, Qiuling Yue, Yuqing Zhang 0001 |
INFOCOM | 3 |
| 2026 | In-Network Model Aggregation in Federated Learning with Heterogeneous Resource
Shun Fukumoto, Ruidong Li 0001, Haihan Nan, Zhou Su 0001 |
INFOCOM | 2 |
| 2026 | FT-PromptFL: A Feature Transmission-based Framework for Communication-Efficient Prompt Federated Learning
Kai Zeng 0005, Hang Wen, Tao Shen 0004, Ruidong Li 0001 |
INFOCOM | 4 |
| 2026 | LRAF: LLM-Assisted Risk-Attribute Framework for Phishing Email Detection
Ruidong Li 0001, Yuqing Zhang 0001 |
INFOCOM | 2 |
| 2026 | H2I: A Handover-State Encoding-Based Data Inheritance Method for Mobile Crowdsensing
Siyuan Yin, Chaogang Tang, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
IWQoS | 6 |
| 2026 | BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw Detection
Lan Zhang 0008, Zhiyuan Fu, Jice Wang, Shangru Zhao, Qi Li 0002, Ruidong Li 0001, He Wang 0014, Yuqing Zhang 0001 |
NDSS | 9 |
| 2026 | MSDLO: Joint General Lotto games and explainable DRL with multi-head attention for agentic task offloading in IIoT systems
Xinmin Cheng, Chengquan Yu, Shigen Shen, Zhiquan Liu 0001, Tian Wang 0001, Ruidong Li 0001 |
Adv. Eng. Informatics | 7 |
| 2026 | DTCC: Decision Transformer-driven framework for adaptive network congestion controlabstractExisting learning-based congestion control methods suffer from myopic decision-making due to their reliance on single-timestep states and fail to model long-term dependencies due to architectural constraints (e.g., recurrent networks’ vanishing gradients). To address these issues, we propose a Decision Transformer-based network congestion control framework named DTCC. DTCC is the first to unify long-context modeling and real-time decision-making within a 4-layer autoregressive Transformer, replacing traditional Markov decision paradigms with sequence-to-action mapping. With enhancement learning strategy such as stochasticity-aware training, DTCC achieves efficient and generalizable performance from heterogeneous dataset. Extensive experiments demonstrate DTCC’s supremacy: it achieves 16.67–29.55% higher winning rate compared to state-of-the-art baselines (e.g., Sage) across diverse network scenarios and 8.33%–29.17% higher winning rate under unseen highly variable network. Leveraging a lightweight Transformer, DTCC enables real-time deployment with approximately 2.8 ms inference per step on general CPU devices. To the best of our knowledge, this is the first work to employ Decision Transformer for training an intelligent congestion control mechanism. Our work, therefore, showcases the potential of combining reinforcement learning with advanced Transformer architectures in real-time network control. Xiaolan Ji, Biao Han 0003, Xiaoliang Wang 0001, Ruidong Li 0001, Jinshu Su |
Comput. Networks | 4 |
| 2026 | FSG-NID: Early network intrusion detection via flow segment graph analysis
Bayi Xu, Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Comput. Networks | 4 |
| 2026 | Toward Evolvable IoT Device-Type Identification Using Few-Shot Incremental LearningabstractThe proliferation of Internet of Things (IoT) devices has profoundly transformed various industries. However, with the continual emergence of new IoT device types, their extensive heterogeneity and weak security have posed significant challenges for network management and security. Despite existing research excelling at classifying IoT traffic, they have yet to consider incremental updates and timely identification, which are critical for early device management and security in IoT networks. As a solution, we present EAPN, a novel and evolvable IoT device identification model that supports adapting to new IoT devices with limited traffic. EAPN extracts traffic features from only a few dozen packets and resorts to a metric-learning-based triplet network to capture accurate, discriminative behavioral representations among IoT devices. Then, inspired by Few-Shot Incremental Learning (FSIL), EAPN further considers advancing incremental model updates based on the relationship between traffic features of new and existing IoT devices. Extensive evaluations demonstrate that EAPN not only surpasses state-of-the-art adaptive IoT device-type identification methods but also achieves over 90% accuracy under almost all incremental conditions, maintaining satisfactory performance even after multiple updates. Bowen Ouyang, Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Internet Things J. | 5 |
| 2026 | Secrecy Rate Optimization Based on GNN for RIS-Assisted ISAC SystemabstractIntegrated Sensing and Communication (ISAC) systems are playing an increasingly crucial role in modern wireless networks. However, in the ISAC scenario, the high transmission power required for communicating and sensing signals poses an increased risk of signal interception by eavesdroppers. To address this issue and enhance the physical layer security (PLS) of ISAC, we utilize Reconfigurable Intelligent Surfaces (RIS) to optimize the secrecy rate in the ISAC context, improving link security and effectively preventing eavesdropping. In the ISAC scenario, the location of the eavesdropper can be obtained through sensing. Leveraging this advantage, we employ Graph Neural Networks (GNN) to aggregate the node information of users and eavesdroppers, which iteratively passes messages and updates node states, thereby adaptively optimizing the transmitting beamforming vector and the RIS phase shift matrix. Simulation results show that this method is superior to the benchmark algorithm. Jieling Zhang, Huijun Tang, Pengfei Jiao, Huaming Wu, Zhidong Zhao, Ruidong Li 0001 |
IEEE Internet Things J. | 6 |
| 2026 | UAV-USV collaborative task offloading for edge computing enabled smart lake monitoring
Chaogang Tang, Tiyu Yao, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
J. Syst. Archit. | 5 |
| 2026 | STMWF: Multi-Tab Website Fingerprinting via Spatial-Temporal Sequence AnalysisabstractWebsite fingerprinting (WF) attacks are employed to identify websites that utilize Tor encryption. Although State-Of-The-Art (SOTA) WF attacks demonstrate strong performance in single-tab scenarios, they face challenges in multi-tab scenarios. Many multi-tab WF attacks rely solely on direction sequence or process directional and temporal sequence separately. They ignore the coupling between directional and temporal features, which reflects distinct resource-loading processes for different websites. To address the limitations of existing approaches, this paper proposes a new multi-tab WF attack, STMWF. It leverages spatial-temporal sequence analysis and jointly models Inter Arrival Time (IAT) with the direction sequence. STMWF utilizes an SE-attention-based feature extractor to derive features from various website resources within the spatial-temporal sequence. It then employs correlation self-attention to integrate these resource features into their respective websites, ultimately constructing distinct fingerprints for each site. Additionally, the method incorporates correlation denoising to suppress noise in the website fingerprints, thereby enhancing the discriminability of the extracted features. We collected single-tab traces to synthesize a dataset with controlled overlap ratios. We also captured real-world multi-tab traffic with varying tab-opening intervals, evaluating performance under authentic conditions. The experimental results indicate that STMWF significantly outperforms the SOTA multi-tab attacks in both dynamic and static settings. Specifically, it achieves an average F1-score improvement of approximately 14.87% under static conditions and 34.81% under dynamic conditions compared to the SOTA multi-tab WF attack, ARES. Furthermore, STMWF exhibits greater robustness against WF defenses than SOTA attacks and consistently surpasses them across varying overlapping scenarios. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Data-Efficient Cross-Domain Few-Shot Website Fingerprinting With Unsupervised Domain AdaptationabstractWebsite fingerprinting (WF) attacks identify Torencrypted websites but struggle with cross-domain scenarios due to traffic distribution shifts. The existing few-shot WF attacks address the cross-domain problem with excessive auxiliary data, significantly reducing deployment efficiency. This work proposes UDA-WF, a data-efficient few-shot WF with Unsupervised Domain Adaptation (UDA). UDA-WF first pre-trains the feature extractor with limited auxiliary data in the source website domain. Then, it extracts the invariant feature space by computing the intersection of the source and target feature spaces through the unsupervised domain adaptation with the softmatch mechanism. Finally, UDA-WF fine-tunes the feature extractor and a single-layer perceptron to extract the discriminative unique feature space of the target website domain. We evaluate UDA-WF on our WF dataset collected over multiple months. UDA-WF significantly overcomes the cross-domain problem while reducing auxiliary data requirements by 95% and pre-training bootstrap time by 99% compared to the State-Of-The-Art (SOTA) methods. UDA-WF achieves an accuracy of 97.37% under the 20-shot setting in the closed-world scenario and outperforms SOTA methods. To further demonstrate the model’s adaptability to diverse real-world requirements, we validate it on the DF and Wang datasets, achieving accuracies exceeding 92% and 94%, respectively. Moreover, the results show that our UDA-WF is more resilient to concept drift and robust to WF defense. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Multivehicles Cooperation: USV and AUV Cooperative Data Collection for Underwater Wireless Sensor NetworksabstractTo advance the development of maritime intelligent transportation systems (MITS), underwater wireless sensor networks (UWSNs), composed of numerous sensor nodes, have been widely deployed for underwater information perception. However, UWSNs face critical challenges in achieving cost-effective and timely data collection due to their large-scale deployment and stringent data timeliness requirements. To address this challenge, this paper proposes an efficient data collection scheme for UWSNs through the collaboration between uncrewed surface vehicles (USVs) and autonomous underwater vehicles (AUVs). Specifically, we first introduce a cooperative framework where AUVs select appropriate USVs to form USV-AUV clusters. Within each cluster, AUVs are responsible for sensing data collection, while USVs act as relay nodes, moving toward the destination (e.g., data center). We then devise an evolutionary game-theoretic cluster forming mechanism, deriving evolutionarily stable strategies (ESS) through replicator dynamics analysis, which guarantees a provable Nash equilibrium. Next, we present a hierarchical optimization method that models the interaction between UWSNs and the cluster as a two-agent Markov decision process, where a dual-agent Q-learning algorithm is designed to jointly optimize the decisions of both entities. Finally, extensive simulations demonstrate that the proposed scheme outperforms conventional methods in improving the efficiency of sensing data collection for UWSNs. Qichao Xu, Zhou Su 0001, Minghui Dai, Ruidong Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2026 | Pao-Ding: Accelerating Cross-Edge Video Analytics via Automated CNN Model Partitioning
Guanping Liang, Biao Han 0003, Ruidong Li 0001, Xueqiang Han, Zhigang Sun 0002 |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Caching-Assisted Collaborative Task Offloading for Vehicular Edge Computing: A Deep Reinforcement Learning-Based ApproachabstractCollaborative task offloading in vehicular edge computing (VEC) primarily emphasizes the diversity of offloading destinations, such as cloud centers, roadside units (RSUs), and other entities with underutilized resources. However, it often neglects the collaborative potential among vehicles whose tasks are associated with the same service. In this paper, we propose a collaborative task offloading strategy from the perspective of vehicles with offloading requests. Vehicles collectively accomplish task offloading by dividing responsibilities for specific service component offloading. To enhance the performance of the VEC system, we introduce a caching-assisted collaborative task offloading strategy. An optimization problem is formulated to minimize the response latency of tasks in VEC. Due to the complexity of solving this Mixed Integer Nonlinear Programming (MINLP) problem, we decompose it into three subproblems: the Task Offloading and Service Caching (TOSA) problem, the Computing Resource Allocation (RA) problem, and the Service Component Assignment (CA) problem. We address the RA problem using a Lagrangian duality-based approach, solve the CA problem with a heuristic algorithm, and tackle the TOSA problem using a Proximal Policy Optimization (PPO)-based deep reinforcement learning (DRL) algorithm. Extensive simulations are conducted to evaluate the performance of the proposed strategy. The simulation results demonstrate that our solution outperforms existing methods in multiple dimensions, including convergence rate, average response latency, and task success rate. Chaogang Tang, Shucai Wang, Huaming Wu, Ruidong Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | VeCroToken: An Efficient, Verifiable, and Privacy-Preserving Cross-Chain Model for Consortium Blockchains Based on zk-SNARKsabstractConsortium blockchains enable secure economic applications through privacy-preserving architectures and efficient processing. Growing cross-chain demands require value-exchange mechanisms, yet expose privacy risks during external interactions. Encrypting cross-chain information is necessary, requiring third-party verification of relations within the encrypted content. Existing privacy-preserving cross-chain research for consortium chains struggles to balance transaction efficiency, transaction validity verification, and complex trust assumptions for relays. We present VeCroToken, an efficient, verifiable, and privacy-preserving cross-chain model for consortium blockchains. VeCroToken introduces a dual-balance mechanism and designs four types of cross-chain zero-knowledge transactions based on zk-SNARKs. These transactions encrypt two types of balances and transaction amounts, effectively protecting participant privacy. The encrypted cross-chain data and zero-knowledge proof credentials are stored on participants’ consortium blockchains and the relay chain. Relay nodes and third parties can validate transaction proofs with public parameters, preserving privacy while ensuring compliance and validity. We give a security analysis in the UC framework that proves verifiability and balance safety. We also provide a privacy analysis establishing the amount, balance, and fund-correlation privacy. We implement a prototype on Hyperledger Fabric. Our experimental results show that VeCroToken has a lower overall zero-knowledge proof overhead than the state-of-the-art models and performs well in transaction performance. Xiaoyan Hu 0007, Weicheng Zhou, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2026 | Privacy-Aware DRL for Differential Games-Assisted Malware Defense in Edge Intelligence-Enabled Social IoTabstractThe edge intelligence-enabled Social Internet of Things (SIoT) faces severe security threats from stealthy malware propagation, while existing defenses struggle to model complex behaviors or provide real-time and privacy-aware responses. Herein, we propose a comprehensive malware defense framework integrating a five-state propagation model, continuous-time differential games, and a privacy-aware reinforcement learning algorithm named PP-D3QN (Privacy-Preserving Dueling Double Deep Q Network). The malware propagation model includes susceptible, infectious, patched, quarantined, and removed states, accurately representing centralized and cooperative patching as well as quarantine detection mechanisms. Leveraging differential games, optimal defense strategies are theoretically derived by solving the Hamilton–Jacobi– Bellman equation, dynamically balancing infection risk, patching benefits, and quarantine costs. The PP-D3QN algorithm employs prioritized experience replay with strict control over private data sampling and Gaussian noise perturbation to ensure differential privacy, while learning effective defense strategies through practical interaction with dynamic edge intelligence-enabled SIoT systems. Extensive simulations demonstrate that the proposed method significantly improves malware suppression speed and SIoT nodes recovery rates, showcasing strong theoretical and practical value. This work offers a rigorous and applicable solution for dynamic malware defense under privacypreserving constraints in edge intelligence-enabled SIoT systems. Shigen Shen, Yizhou Shen, Jingnan Dong, Tian Wang 0001, Ruidong Li 0001 |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2026 | Rethinking Online Smart Contract Diagnosis in Blockchains: A Diffusion PerspectiveabstractDue to the immutable nature of smart contracts, online contract diagnosis is the only viable approach for revealing vulnerabilities in deployed contracts. Existing online approaches face significant challenges in terms of efficiency, adaptability, and reliance on vulnerability labels. This paper proposes ConWatcher+, a new adaptive and label-efficient online contract diagnosis framework from the diffusion perspective, which is capable to detect yet unknown attacks under evolving tactics without reliance on vulnerability labels. ConWatcher+ simulates the Advanced Persistent Threat (APT) tactics commonly used in yet unknown attacks by continuously applying minor perturbations to legitimate interaction behaviors. It then reversely learns the denoising process, guided by potential logic vulnerabilities (i.e., functionality dependencies), to adaptively identify stealthy anomalies and detect yet unknown attacks without needing vulnerability labels. ConWatcher+ proceeds in five steps. First,real-time data extraction. We design a cost-effective contract runtime information collector, incorporating on-demand data retrieval and event-driven data update mechanisms to reduce communication overhead in online contract diagnosis. Second,interaction behavior modeling. Via bytecode-level, account-level, revenue-level modeling, and side-channel level behavior modeling, we propose behavior-aware multivariate time series model to accurately represent long-term contract interactions with multi-faceted behaviors. Third,APT-like noise adding. We leverage the forward diffusion model to produce minor and stochastic APT-like noises with efficiency. Fourth,reverse denoising learning. To effectively guide reverse denoising using functionality dependencies, we devise an adaptive contract-level analysis engine equipped with heterogeneous control flow graph modeling and heterogeneous message passing mechanisms to extract function-level and bytecode-level functionality dependencies. Last,contract anomaly detection. We establish a label-efficient attack detector based on reconstruction error for contract anomaly detection. It combines complex dependency analysis and deterministic inference to ensure high-quality data reconstruction and low detection latency. Extensive empirical validations on a manually constructed dataset, covering both mainstream and novel vulnerabilities, demonstrate ConWatcher+’s effectiveness, adaptability, and label efficiency, with an average F1-score of 0.92 across all types of attacks without prior knowledge of corresponding vulnerabilities. Qinnan Hu, Yuntao Wang 0004, Zhou Su 0001, Tom H. Luan, Ruidong Li 0001 |
IEEE Trans. Netw. | 5 |
| 2025 | MAAP: A Self-Evolving Multi-Agent Automated Vulnerability Repair Framework for PythonabstractAutomating vulnerability repair (AVR) in Python remains constrained by low accuracy, long feedback loops, and rapidly escalating token spend when large repositories must be reasoned about. These challenges are amplified by the prevalence of multi-file, environment-dependent CVEs whose fixes span configuration, tests, and cross-module semantics. We introduce MAAP, a self-evolving, role-specialized LLM architecture for end-to-end automated patch synthesis in Python codebases. MAAP decomposes a vulnerable repository into fine-grained, dependency-aware subtasks and dispatches them via a contextual-bandit router that jointly optimizes correctness, latency, and cost. An experience-centric knowledge base surfaces successful semantic exemplars and failure signals to prune search. An agent factory dynamically spawns, retires, or coordinates agents when novel patterns or degraded rewards emerge. We evaluate MAAP on 120 real-world Python CVEs. MAAP achieves a 70.3% patch success rate, surpassing the SWE-agent baseline, which has a 56.7% success rate. This improvement incurs a 62.8% higher average token cost, but it results in a $\mathbf{1 5. 5 \%}$ lower cost per successful patch. Ablation studies show substantial drops in success when disabling the router, knowledge base, or cooperative spawning, underscoring the necessity of each component. Collectively, these results indicate that MAAP’s design can deliver robust, largely hands-free vulnerability repair for Python at practical cost envelopes and is readily extensible to other language ecosystems. Zhiyuan Fu, Ruidong Li 0001, Yuqing Zhang 0001 |
APSEC | 5 |
| 2025 | A Truth Discovery Method for Mobile Crowd Sensing in Mines Based on a Hybrid Bi-LSTM/GRU NetworkabstractEnsuring safety and operational continuity in underground coal mines requires robust mine monitoring. Traditional methods based on fixed sensors and manual inspections suffer from limited coverage, high cost, and poor real-time performance. Mobile Crowd Sensing (MCS), enabled by miner-carried devices, offers flexible coverage but introduces challenges such as data sparsity, noise, and heterogeneity due to device variability and electromagnetic interference. This article proposes a Bidirectional Long Short-Term Memory/Gated Recurrent Unit-based Truth Discovery (BLGTD) method for mine MCS. The model integrates spatiotemporal sequence modeling with Monte Carlo Dropout-based uncertainty quantification, enabling adaptive fusion of multi-source data. Experimental results show that BLGTD achieves a mean absolute error (MAE) of 0.19 ± 0.01 ppm in CH4concentration estimation when 90% of data comes from reliable miners, yielding a 57.8% improvement over traditional weighted averaging. The method demonstrates strong robustness under conditions of data incompleteness, device heterogeneity, and signal interference. Chaogang Tang, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
GLOBECOM | 6 |
| 2025 | Accurate and Early Detection of Iot Malware Via Dns Traffic Analysis with Deep LearningabstractMalware increasingly targets current Internet of Things (IoT) devices, causing significant economic losses. Accurate and early detection of malware is essential for defense. Existing IoT malware detection methods primarily analyze interactive traffic between compromised devices and C&C servers. Such detection needs to be performed while IoT devices are undergoing attacks, which still exposes IoT devices to danger. By analyzing real-world DNS traffic generated by IoT devices, we uncover that the DNS behavior patterns of benign IoT devices and malwareinfected devices differ. Therefore, this work proposes a method to accurately and early detect IoT malware via DNS traffic analysis with deep learning before attacks are launched, referred to as IoTMD-2D. IoTMD-2D first extracts a comprehensive set of DNS traffic features of IoT devices that effectively characterize DNS traffic behavioral patterns. Then, it integrates an attention-based LSTM to capture hidden relationships within domain names and a 1D-CNN to explore hidden patterns in DNS behavior-level features for generating feature representations that discriminate DNS traffic of benign IoT devices and malware-infected devices. Finally, IoTMD-2D accurately detects IoT malware based on the generated feature representation. Our experimental study on public IoT datasets demonstrates that our IoTMD-2D achieves an accuracy of 97.63 % in detecting IoT malware at an early stage via DNS traffic analysis. Chenxing Zhang, Xiaoyan Hu 0007, Xuanlin Pan, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
ICC | 5 |
| 2025 | A DRL-Based Load-Balanced Task Offloading Approach for Vehicular Edge ComputingabstractThe Vehicular Edge Computing (VEC) paradigm significantly reduces task processing latency in Internet of Vehicles (IoV) and Intelligent Transportation Systems (ITS) by deploying computational resources at Roadside Units (RSUs). However, the high mobility of vehicles and dynamic task arrivals lead to uneven load distribution among RSUs, severely impacting system performance. Actually, load balancing as an important evaluation metric for VEC system greatly affects the performance of individual edge servers in terms of latency, energy consumption, and task completion rates. In view of this, we propose a Proximal Policy Optimization (PPO) based deep reinforcement learning (DRL) approach to determine the task offloading and migration decisions and incorporate the fairness into the constraint, aiming to achieve efficient load-balanced task offloading in VEC. Particularly, we introduce a metric named Load Balancing Metric (LBM) to optimize RSU resource allocation and employ dynamical task migration strategies to optimize the metric. Simulation results demonstrate that this approach significantly enhances load balancing performance, reduces average latency and energy consumption, and provides an efficient resource scheduling solution for VEC systems. Shucai Wang, Chaogang Tang, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
ICPADS | 6 |
| 2025 | ConWatcher: Towards Adaptive and Label-Efficient Online Smart Contract Analysis in Blockchains
Qinnan Hu, Yuntao Wang 0004, Zhou Su 0001, Tom H. Luan, Ruidong Li 0001 |
INFOCOM | 5 |
| 2025 | NetRT: Enhancing RDMA with Retransmission Offloading in Data Center Networks
Jiangping Han, Kaiping Xue, Jian Li 0031, Kunpeng Ding, Ruidong Li 0001 |
INFOCOM | 6 |
| 2025 | Quantum Network Routing Design with Dynamic Requests Scheduling in Multi-User EnvironmentsabstractScheduling in quantum networks involves strategically allocating quantum resources to maximize entanglement distribution efficiency and overall performance. Unlike classical networks, quantum systems lack conventional buffering mechanisms, making traditional scheduling paradigms less effective. Existing quantum network algorithms predominantly focus on routing algorithms to identify optimal entanglement paths, often neglecting timeslot scheduling for mitigating resource contention and transmission latency, particularly under multi-user environments. To address these challenges, we propose a routing algorithm tightly integrated with priority-based dynamic scheduling. The algorithm not only discovers efficient entanglement paths but also optimizes resource utilization for concurrent requests. Simulation results confirm that this approach conserves quantum resources, reduces latency, and substantially boosts network performance, providing a robust solution for multi-user quantum environments. Ruidong Li 0001 |
IWCMC | 2 |
| 2025 | FDLLM: A Dedicated Detector for Black-Box LLMs FingerprintingabstractThe proliferation of black-box Large Language Models (LLMs) makes source attribution essential for accountability and security. Yet, progress is limited by the lack of a large multilingual benchmark and by fragile or computationally intensive methods. We introduce FD-Dataset, a bilingual benchmark of 90,000 samples from 20 major LLMs, and FDLLM, a LoRA-adapted detector that extracts persistent decoding fingerprints from a foundation model. LoRA induces intra-model clustering and inter-model separation in representation space, explaining its effectiveness for fingerprinting. On FD-Dataset, FDLLM surpasses the strongest baseline by 22.1% Macro F1, generalizes to newly released models with 95% accuracy, and remains robust to polishing, translation, and synonym substitution, reducing average attack success rate from 49.2% (LM-D) to 23.9%. Zhiyuan Fu, Lan Zhang 0008, Ruidong Li 0001, Peng Liu 0005, Jice Wang, Fannv He, Yuqing Zhang 0001 |
TrustCom | 7 |
| 2025 | MAP the Blockchain World: A Trustless and Scalable Blockchain Interoperability Protocol for Cross-chain ApplicationsabstractBlockchain interoperability protocols enable cross-chain asset transfers or data retrievals between isolated chains, which are considered as one of the core infrastructure for Web 3.0. However, existing protocols either face severe scalability issues due to high on-chain and off-chain cost, or suffer from trust concerns because of centralized architecture. Yinfeng Cao, Jiannong Cao 0001, Dongbin Bai, Long Wen 0002, Yang Liu 0007, Ruidong Li 0001 |
WWW | 6 |
| 2025 | BTG-RF: Recognizing Douyin payment behaviors based on behavioral traffic graph analysis
Xiaoyan Hu 0007, Xinghai Chen, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Comput. Networks | 5 |
| 2025 | WEDoHTool: Word embedding based early identification of DoH tunnel tool traffic in dynamic network environments
Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Comput. Secur. | 4 |
| 2025 | Investigations and Time Estimation on Federated Learning for Future Internet of VehiclesabstractFor future Internet of Vehicles (IoV), communications and computing will converge to provide services. Federated learning (FL), as one of the typical distributed computing technologies, needs to be integrated with IoV. For such integration, FL suffers from the straggler effect that the entire learning speed is lowered down, because of the existence of the devices, such as low-powered road side units and vehicles, taking more time to complete their tasks. Although the existing mechanisms reduce straggler effects by adopting asynchronous mechanisms and clustering mechanisms, they lack the detailed analysis of the reasons and the impacts of each cause, leading to inefficiencies in the design of algorithm. Additionally, most of the existing work only considered the impact of a single factor in computation, communication, or data distribution, which lacks comprehensive on research for causes of stragglers effects. The bottleneck is that it is laborious to observe the time delay precisely with the existing high-calculating evaluations. In this article, we elaborately explore the effects of computing power, communication capability, and data distributions on the straggler effects with carefully designing and conducting the extensive experiments. After investigations, we propose a novel learning completion time estimation formula for low computing capability devices with mini-batch stochastic gradient decent (SGD). We compare our proposed estimation formula with the one based on floating operation per second (FLOPs). Through the evaluations, our formula can demonstrate the improvement up to 72.4% at docker and 32.4% at Raspberry Pi device compared to the existing work. Shun Fukumoto, Ruidong Li 0001, Kai Zeng 0005, Haihan Nan, Zhou Su 0001 |
IEEE Internet Things J. | 2 |
| 2025 | Cooperative Energy Provisioning Services With Virtual Power Plants in Smart Grid Internet of Things: A Coalition-Stackelberg Game ApproachabstractWith the advancement of communication technologies within the smart grid Internet of Things (SGIoTs), virtual power plants (VPPs), which aggregate distributed energy resources, are increasingly encouraged to participate in energy provisioning services. However, the inherent variability in energy supplies among different VPPs, combined with the dynamic and heterogeneous nature of energy demands, poses significant challenges for efficient energy provisioning in a competitive environment involving multiple VPPs and numerous energy users. To address these challenges, this paper proposes a cooperative energy provisioning scheme based on a coalition-Stackelberg game to enhance demand response management for VPPs in SGIoTs. Firstly, a coalition formation game model is employed to create VPP clusters, enhancing both the reliability of energy supply and the profitability of individual VPPs. Subsequently, a multi-leader multi-follower (MLMF) Stackelberg game is utilized to model the competitive interactions between VPP coalitions and energy users, aiming to maximize the respective utilities of both parties. The existence of the Stackelberg equilibrium is rigorously analyzed and derived through an alternating direction method of multipliers (ADMM)-based energy requirement decision algorithm and an asynchronous gradient descent iteration-based pricing algorithm. These methods enable the determination of optimal electricity prices for VPP coalitions and optimal energy requirement decisions for individual users. Finally, extensive simulations are conducted to demonstrate that the proposed scheme significantly enhances the utilities of both VPPs and energy users compared to conventional approaches. Qichao Xu, Zhou Su 0001, Peiqi Li, Ruidong Li 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Mitigating Malware Propagation in Social Internet of Things Using an Exact Markov-Chain-Based Epidemic MethodabstractIn the Social Internet of Things (SIoT) environment, malware propagation is attracting more and more attention due to increasing damages. Markov chain models have been used to predict epidemic behavior qualitatively and quantitatively, but most of them model random propagation as a basic multiplicative factor. In this article, we propose an epidemic model Susceptible-Infected without command-Infected with command$(SII^{\prime })$, and derive an exact Markov chain for SIoT malware propagation. We also employ a Markov chain for an SIoT malware mitigation system that groups random devices alongside those with detected infections during the malware eradication process. This mitigation mechanism operates at the network scale, addressing the risks associated with large-scale SIoT deployments through a strategic, yet assertive, approach of widespread disconnections. Such a system effectively drives down the basic reproduction number to less than 1, preventing malware from gaining dominance over the network—all accomplished without modifying the recovery rate. We conducted experimental simulations of the proposed model’s dynamic predictions, and the experimental results show that the use of an exact Markov chain model better matches the benchmark results of our proposed model and also verifies the different effects of group-based mitigation in different SIoT contexts. Hong Zhang 0046, Yizhou Shen, Huibin Xu, Shigen Shen, Ruidong Li 0001 |
IEEE Internet Things J. | 6 |
| 2025 | Joint Optimization of Charging Time and Resource Allocation in Wireless Power Transfer Aided Federated LearningabstractAs a promising methodology of distributed Machine Learning (ML) paradigm, Federated Learning (FL) protects data privacy and reduces communication cost by aggregating model parameters rather than raw data. However, training superb FL models incurs a lot of energy consumption, which is a significant challenge for energy-limited Mobile Devices (MDs). To address this challenge, this paper proposes a Wireless Power Transfer (WPT)-aided FL framework, where MDs train local FL models for Base Station (BS) and get corresponding payoff, while Wireless Charge Provider (WCP) provides energy supplement for MDs and charges energy fees. Furthermore, we take into account the time-varying nature of MDs datasets, which affects their energy consumption and reward from BS. Then, we formulate the investigated problem to achieve joint optimization of WPT duration, computing resource allocation and the number of local iterations, with the goal of maximizing the total utility of all MDs throughout the whole FL process. The optimization problem is NP-hard and difficult to be solved by traditional optimization methods within limited timeframes. Therefore, we use Karush-Kuhn-Tucker (KKT) conditions and Lagrange dual method to analyze the problem, and propose a new Improved Lagrangian Subgradient Method (ILSM) as an efficient solution. Finally, extensive simulation experiments are conducted to demonstrate the effectiveness of the proposed scheme under various scenarios, and the results show that the proposed ILSM significantly outperforms other benchmarks in terms of the total utility of all MDs. Huan Zhou 0002, Jingjiao Wang, Liang Zhao 0014, Deng Meng, Guangsheng Feng, Ruidong Li 0001 |
IEEE Internet Things J. | 6 |
| 2025 | An effective and verifiable secure aggregation scheme with privacy-preserving for federated learning
Ling Xiong, Jiazhou Geng, Chun Xie, Ruidong Li 0001 |
J. Syst. Archit. | 5 |
| 2025 | Knowledge-Aware Privacy-Preserving Model Customization in Zero-Trust Federated Learning Model MarketplacesabstractFederated learning (FL) model marketplaces require qualified workers to collaboratively train customized models. However, recruiting optimal workers on a limited budget in non-independent and identically distributed (non-IID) data settings remains a fundamental issue. Moreover, inadequate quality verification exposes the marketplace to spoofing and poisoning attacks, while verifying data and model quality without accessing local storage remains a significant dilemma. To bridge the research gap, this paper proposes a knowledge-aware model customization scheme in FL model marketplaces, to facilitate zero-trust worker recruitment and verification while ensuring privacy preservation. Specifically, (i) we design a knowledge-aware quality evaluation mechanism by leveraging the knowledge of workers, i.e., soft-label predictions of their local models on a privacy-free reference dataset (provided by the customer), to assess their data quality in a privacy-preserving manner. (ii) We formulate the optimal worker recruitment problem under budget constraints as an NP-hard integer programming problem and design a dynamic programming-based optimal worker recruitment algorithm with budget feasibility and computational efficiency. (iii) We devise a two-stage zero-trust quality verification mechanism by utilizing zero-knowledge proof (ZKP) to exclude distrustful workers, thereby preventing spoofing and poisoning attacks. Extensive experimental results demonstrate that the proposed scheme enhances model customization performance by up to 34.3% on label-skewed non-IID data and 36.2% on feature-skewed non-IID data compared with existing representatives. Yanghe Pan, Zhou Su 0001, Yuntao Wang 0004, Ruidong Li 0001, Abderrahim Benslimane |
IEEE J. Sel. Areas Commun. | 5 |
| 2025 | Trust-Enhanced Game Incentive for Secure Quantum Federated Learning in UAV-Assisted Wireless NetworksabstractRecently, quantum federated learning (QFL) is advocated to leverage the robust computing power of quantum edge computing devices (QECDs) within unmanned aerial vehicle (UAV)-assisted wireless networks, to enhance the efficiency of distributed learning. However, the presence of malicious and selfish behaviors among some QECDs poses significant challenges for QFL model training to achieve high accuracy and rapid convergence. To tackle this issue, we introduce a trustenhanced incentive scheme for QFL in the UAV-assisted wireless networks. Specifically, a QECD-empowered QFL framework is first presented in the UAV-assisted wireless networks, where the QECDs independently train local models with their private data by using the quantum computing capabilities, while UAVs aggregate these trained local models to update the global model. Then, to ensure security and eliminate malicious participants, we devise a Bayesian inference-based trust assessment mechanism to select honest QECDs for local model training. Furthermore, we design a Stackelberg game-based incentive mechanism to incentivize QECDs to cooperatively provide high-quality training services. Afterwards, through game analysis using the backward induction method, we prove the existence of a Stackelberg equilibrium. The optimal payment strategies of the UAVs are obtained using the deep Q-learning network (DQN) algorithm in dynamic networks, and the optimal training contribution strategy of each QECD is derived using the convex optimization method. Finally, extensive simulations demonstrate that the proposed scheme can significantly enhance the accuracy and training speed of QFL in UAV-assisted wireless networks. Qichao Xu, Ruidong Li 0001, Yihao Qi, Zhou Su 0001, Dongfeng Fang |
IEEE J. Sel. Areas Commun. | 2 |
| 2025 | Joint Optimization of Task Offloading Content Caching and Resource Allocation in Vehicular Edge ComputingabstractIn Vehicular Edge Computing (VEC) environments, the increasingly complicated functional and non-functional requirements from vehicular applications such as MetaVehicles usually incur larger sizes of task-input data, which not only increase the transmission delay of task-input data via the front-haul links but also degrade the quality of experience for users, even if computation tasks can be offloaded and executed at the network edge. In this article, we put forward a caching-enabled task offloading strategy, by caching and reusing the universal context data at the edge server, to avoid duplicated data transmission in VEC systems. The goal is to minimize the overall response latency for all the tasks, by jointly optimizing task offloading, content caching, and resource allocation decisions in VEC. The optimization problem is formulated as a Mixed-Integer Nonlinear Programming (MINLP) problem. To efficiently solve this problem, we decompose this problem into two subproblems, namely, the computing Resource Allocation (RA) problem and the Joint Offloading and Caching (JOC) problem. The corresponding algorithms are put forward to solve the content caching and task offloading problems, respectively. Numeric evaluation reveals that our strategies and algorithms can achieve better performance in minimizing the overall response latency, in comparison with other approaches. Chaogang Tang, Huaming Wu, Ruidong Li 0001, Joel J. P. C. Rodrigues |
ACM Trans. Auton. Adapt. Syst. | 3 |
| 2025 | Fair-EAS: Entanglement Allocation and Selection for Process-Oriented Fairness in Quantum Communication NetworksabstractQuantum communication networks enable advanced quantum applications through remote entanglement distribution among source-destination pairs. Despite efforts to optimize entanglement distribution, fairness in multi-request scenarios has been neglected, potentially causing issues like “request starvation”. To address such issue, this paper concentrates on the unique properties of entangled systems and introduces a process-oriented fairness metric, i.e., expected throughput, departing from conventional approaches used in classical networks. Furthermore, we propose an entanglement distribution scheme named Fair-EAS, which prioritizes entanglement allocation and selection for batching multiple requests to maximize overall throughput while maintaining max-min fairness. To facilitate a convenient solution, we transform the nonlinearity of the problem into an equivalent linear programming formulation and decouple the solution into offline and online phases. In the offline phase, we design a multi-round water-filling-like optimization algorithm to determine the optimal path set for predicting entanglement allocation. In the online phase, we introduce an adaptive compensation algorithm and an entanglement “fragment” exhaustion algorithm to dynamically adjust the path set based on successfully generated entangled pairs. Comprehensive simulations show that Fair-EAS outperforms the existing schemes in terms of fairness by significantly enhancing the minimum throughput and throughput deviation among multiple requests while maintaining an overall throughput close to the optimal level. Jian Li 0031, Kaiping Xue, Zhonghui Li, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Commun. | 5 |
| 2025 | SSE-CTC: Search Over Encrypted Data With Owner-Enforced and Complete Time ConstraintsabstractSearchable symmetric encryption (SSE) is a technique that enables secure outsourcing of data to an untrusted cloud server without sacrificing search functionality. Recently, multi-user SSE schemes for data sharing, which support access control from various users, have gained attention. However, the access control mechanisms in existing schemes are not adequate for realistic data-sharing scenarios as they do not consider time constraints or only partially address them, making these mechanisms unsuitable for SSE schemes. To address this issue, we first highlight the importance of time constraints in multi-user SSE and propose a completely time-constrained SSE scheme under a two-server model. By taking advantage of the Lagrange interpolation and pre-computation, our proposed scheme enables searching over time-related encrypted data with owner-enforced time constraints. Additionally, we employ the blinding technique with the assistance of a semi-honest time server to ensure the completeness of time constraints, which is not guaranteed in existing works. Based on the leakage function, we prove the security of our proposed scheme in the simulation-based security model. Furthermore, extensive experiments demonstrate the practicality of our scheme in supporting time-constrained functions. Jinjiang Yang, Kaiping Xue, Feng Liu 0059, Bin Zhu 0010, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Privacy-Preserving Truth Discovery of Evolving Truths for Mobile Crowdsensing SystemsabstractPrivacy-preserving truth discovery (PPTD) enables the crowdsensing platform to extract reliable inferred truths from unreliable user sensory data. While mobile crowdsensing systems have driven the emergence of many applications, continuously extracting inferred truths of evolving objects over streaming data (continuous PPTD) remains a challenge. Most existing works focus on static scenarios and cannot handle the new challenges in continuous PPTD, such as accuracy decrease, user dynamics, real-time requirements, and outliers. To address these challenges, we present PTET, a PPTD framework for continuous PPTD. By mining evolving patterns, PTET extracts accurate inferred truths of evolving objects even when some epochs lack sufficient user sensory data. PTET ensures the privacy of both users and data requesters while achieving high accuracy. Furthermore, we present PTET-P for practical applications. It employs a virtual user combined with evolving patterns to effectively eliminate the impact of user dynamics in continuous PPTD. Meanwhile, PTET-P achieves “immediate on-arrival processing” to improve real-time performance significantly. In addition, we address the outliers problem with the help of evolving patterns. We provide security analysis to prove that our frameworks protect the privacy of both users and data requesters. Extensive experiments demonstrate that our frameworks dramatically outperform the existing schemes in extracting inferred truths of evolving objects in continuous PPTD. Jingcheng Zhao, Kaiping Xue, Ruidong Li 0001, Bin Zhu 0010, Meng Li 0006, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | TLCO: Topological Link-Aware Task Co-Offloading Method for Joint V2V and V2I SystemabstractJoint Vehicle-to-vehicle (V2V) and Vehicle-to-Infrastructure (V2I) offloading presents an efficient approach to leverage surplus computing resources from neighboring devices, thereby expanding the coverage of computing resources supply in the context of the Internet of Vehicles. However, many studies overlook the significance of topological communications caused by the rapid movement of vehicles, privacy, and communication intentions. To achieve efficient task offloading when facing various topological link structures, we first propose a novel topological link-aware task co-offloading (TLCO) method designed for partially offloading in the joint V2V and V2I system. Next, we model the sequential subtasks offloading process as the Markov Decision Process (MDP) and utilize the Double Deep Q-Network (DDQN) algorithm to optimize the total delay of the proposed system. Additionally, we put forth a prediction framework named Sliding Time Windows and TLCO algorithm (STW-TLCO) to accurately forecast the computation load at various time windows using pulsed parameters. Extensive experimental results demonstrate the effectiveness and superiority of the proposed TLCO-DDQN algorithm in comparison to other Deep Reiforcement Learning (DRL)-based and Greedy-based approaches. Furthermore, the STW-TLCO algorithm exhibits high accuracy, with an R-squared value exceeding 96%, confirming its predictive capabilities. Huijun Tang, Ming Du 0003, Huaming Wu, Pengfei Jiao, Ruidong Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | Deep Reinforcement Learning-Based Collaborative Computation Offloading for Distributed Vehicular Edge ComputingabstractIn Vehicular Edge Computing (VEC), apart from the Road Side Units (RSUs) that can undertake the computation, smart vehicles that incorporate high-end multi-core processors into On-Board Units (OBU) can also contribute their computing resources for vehicular tasks in a pay-as-you-go fashion. Designing an appropriate pricing strategy for vehicles with abundant computing resources is essential yet challenging, as it requires balancing profit-seeking objectives with the needs of service requestors. On the other hand, considering the perspective of vehicles with offloading requests, task offloading should strike a balance between achieving ultra-low task latency and minimizing the associated offloading costs. To tackle these issues, we propose a Collaborative Computation Offloading Scheme (CCOS) for the VEC system. In particular, we take into account the fluctuation of service pricing, to cater to the monetary constraints of service requesters. A Mixed-Integer Nonlinear Programming (MINLP) problem is formulated to minimize the weighted sum of task completion latency and the offloading costs. The optimization problem is decomposed into two subproblems, i.e., the task offloading problem and the computing resource allocation problem, respectively. The task offloading problem is essentially a combinatorial optimization problem that necessitates exponential time complexity for determining the optimal solution. Hence, a Deep Reinforcement Learning (DRL)-based algorithm is put forward to solve this subproblem. The resource allocation problem, however, has been proven to be a convex optimization problem, and the scheduling and allocation of computing resources can be performed in parallel, since each edge node is aware of its own task offloading requests. Simulation results demonstrate that our strategy outperforms other approaches in terms of the convergence rate, task completion rate, and optimal values. Chaogang Tang, Huaming Wu, Shuo Xiao, Ruidong Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | Graph Convolutional Reinforcement Learning-Guided Joint Trajectory Optimization and Task Offloading for Aerial Edge ComputingabstractThe unique capabilities of Unmanned Aerial Vehicles (UAVs), including their superior mobility, flexibility, and line-of-sight transmission, have made them well-suited for facilitating Aerial Edge Computing (AEC). This computing paradigm is particularly beneficial for meeting the computing demands of User Equipments (UEs) in emergency situations, as it offers efficient support for task offloading. Considering the service requirements of UEs, it is essential to minimize the processing delay experienced by UEs in AEC systems. This is accomplished through the joint optimization of the UAV trajectory, flight speed, and task offloading ratio allocation for UEs. Due to the non-convex nature and the continuous action space of the problem, recent studies have turned to the Deep Deterministic Policy Gradient (DDPG) to tackle similar challenges. However, Deep Neural Networks (DNNs) employed in DDPG are limited to extracting latent information solely from Euclidean data, and are similarly constrained by the highly dynamic changes in channel states within AEC networks, thereby disregarding the valuable features inherent in the structural information. In order to alleviate the task offloading problem in AEC systems, we propose a novel Graph Convolutional Pooling-DDPG (GCP-DDPG) algorithm by exploiting the graph-based multi-relational derivation capability of the multi-Relational Graph Convolutional Network (R-GCN) and employing the reinforcement learning technique. Extensive simulation experiments are conducted to evaluate the superiority and effectiveness of the GCP-DDPG algorithm. The results demonstrate a remarkable performance improvement of 34.6% compared to state-of-the-art approaches. Huaming Wu, Huijun Tang, Ruidong Li 0001, Pengfei Jiao |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Task-Oriented Semantic Communication in Large Multimodal Models-Based Vehicle NetworksabstractTask-oriented semantic communication has emerged as a fundamental approach for enhancing performance in various communication scenarios. While recent advances in Generative Artificial Intelligence (GenAI), such as Large Language Models (LLMs), have been applied to semantic communication designs, the potential of Large Multimodal Models (LMMs) remains largely unexplored. In this paper, we investigate an LMM-based vehicle AI assistant using a Large Language and Vision Assistant (LLaVA) and propose a task-oriented semantic communication framework to facilitate efficient interaction between users and cloud servers. To reduce computational demands and shorten response time, we optimize LLaVA's image slicing to selectively focus on areas of utmost interest to users. Additionally, we assess the importance of image patches by combining objective and subjective user attention, adjusting energy usage for transmitting semantic information. This strategy optimizes resource utilization, ensuring precise transmission of critical information. We construct a Visual Question Answering (VQA) dataset for traffic scenarios to evaluate effectiveness. Experimental results show that our semantic communication framework significantly increases accuracy in answering questions under the same channel conditions, performing particularly well in environments with poor Signal-to-Noise Ratios (SNR). Accuracy can be improved by 13.4% at an SNR of 12dB and 33.1% at 10dB, respectively. Baoxia Du, Hongyang Du 0001, Dusit Niyato, Ruidong Li 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Blockchain-Empowered Game Theoretical Incentive for Secure Bandwidth Allocation in UAV-Assisted Wireless NetworksabstractRecently, the promising unmanned aerial vehicle (UAV)-assisted wireless networks (UAWNs) have emerged by advocating the UAVs to provide wireless transmission services. However, owing to the ever-growing volume of data traffic and the untrusted network operation environment, efficiently and securely assigning limited bandwidth for high-quality wireless communication between UAVs and mobile users poses a significant challenge. To address this challenge, we propose a novel secure UAV-bandwidth allocation scheme to provision reliable wireless transmission services for mobile users in UAWNs. Specifically, we first introduce a novel blockchain-empowered framework for secure bandwidth allocation, designed to automate payment processes and deter malicious activities through the immutable logging of transactional and behavioral data. Wherein, a smart contract is designed to regulate the honest behaviors of both mobile users and UAVs during bandwidth allocation with a distributed manner. Besides, a delegated proof-of-stake (DPoS) with reputation consensus protocol is presented to ensure the authenticity and efficiency of the decision-making process. Further, we apply the Stackelberg game theory to model the dynamic of the bandwidth allocation between mobile users and UAVs. In this game, the UAVs act as game leaders to determine the bandwidth price, while each mobile user acts as a game follower, making decision on the bandwidth request. We utilize the backward induction method to derive the optimal strategies of both parties, culminating in the identification of the Stackelberg equilibrium of the formulated game. Finally, extensive simulations are carried out to show the superiority of the proposed scheme over conventional schemes in terms of security, efficiency, and fairness in bandwidth allocation. Qichao Xu, Zhou Su 0001, Haixia Peng, Yuan Wu 0001, Ruidong Li 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | A Novel Sequence-to-Sequence-Based Deep Learning Model for Multistep Load ForecastingabstractLoad forecasting is critical to the task of energy management in power systems, for example, balancing supply and demand and minimizing energy transaction costs. There are many approaches used for load forecasting such as the support vector regression (SVR), the autoregressive integrated moving average (ARIMA), and neural networks, but most of these methods focus on single-step load forecasting, whereas multistep load forecasting can provide better insights for optimizing the energy resource allocation and assisting the decision-making process. In this work, a novel sequence-to-sequence (Seq2Seq)-based deep learning model based on a time series decomposition strategy for multistep load forecasting is proposed. The model consists of a series of basic blocks, each of which includes one encoder and two decoders; and all basic blocks are connected by residuals. In the inner of each basic block, the encoder is realized by temporal convolution network (TCN) for its benefit of parallel computing, and the decoder is implemented by long short-term memory (LSTM) neural network to predict and estimate time series. During the forecasting process, each basic block is forecasted individually. The final forecasted result is the aggregation of the predicted results in all basic blocks. Several cases within multiple real-world datasets are conducted to evaluate the performance of the proposed model. The results demonstrate that the proposed model achieves the best accuracy compared with several benchmark models. Renzhi Lu, Ruichang Bai, Ruidong Li 0001, Lijun Zhu 0001, Feng Xiao 0002, Dong Wang 0003, Huaming Wu, Yuemin Ding |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2025 | An Efficient and Robust Resource Allocation Method for Quantum Key Distribution NetworksabstractQuantum Key Distribution (QKD) technology leverages its inherent security advantages to ensure information-theoretic security for data transmission in networks. However, existing QKD networks still face critical challenges, including network congestion that stems from limited key resources and uneven resource allocation methods. Thus, in this paper, we focus on the issue of network congestion caused by bottleneck links and aim to achieve load balancing. Considering the limited key resources, we first introduce the key resource utilization ratio as an indicator of bottleneck links and formulate the resource allocation problem as an Integer Linear Programming (ILP) problem. To deal with the complexity of the ILP problem, especially in large-scale network scenarios, we design a heuristic algorithm that can obtain near-optimal solutions within polynomial time. Finally, we implement the proposed key resource allocation scheme in various real-world network topologies using a full-stack quantum network simulator. Compared to the existing algorithms, extensive results show that our method can reduce key resource consumption by up to 50% on bottleneck links and improve the robustness of QKD networks when facing burst quantum key agreement requests. Jian Li 0031, Zhonghui Li, Kaiping Xue, Nenghai Yu, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2025 | DRM-ETP: A Dynamic Rate Matching-Based Entanglement Transport Protocol in Quantum NetworksabstractThe entanglement transport protocol with a connection-oriented mode ensures the reliable distribution of remote entanglement by reserving dedicated resources on the selected path for users in a quantum network. In most existing protocols, entanglement generation and resource allocation operate with the support of global network-synchronized time slot. However, such synchronization in a large-scale quantum network is challenging, and the idealized time slot model is not conducive to continuous and concurrent requests. Meanwhile, different link performance in memory capacity and entanglement generation rate brings out critical issues, such as long distribution delay and low resource utilization, which has not been adequately addressed by the existing protocols relying on a heuristic adoption of TCP-like transport modes. In light of these observations, we propose a dynamic rate matching-based entanglement transport protocol called DRM-ETP, which allocates different memory units on each link along an entanglement distribution path. Moreover, DRM-ETP incorporates periodic forward and backward interactions to implement fine-grained feedback and a dynamic memory allocation based on priority differentiation. These mechanisms mitigate congestion and unfairness arising from resource contention among burst requests on shared links. Extensive simulation results demonstrate that DRM-ETP significantly outperforms the existing protocols in terms of throughput and resource utilization, with less distribution delay and higher fidelity. Moreover, DRM-ETP exhibits rapid and fair convergence when handling burst requests. Our study opens up possibilities for deploying efficient entanglement transport in quantum networks, thereby holding the promise of enhanced compatibility and novel functionality. Jian Li 0031, Kaiping Xue, Zhonghui Li, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Netw. | 5 |
| 2024 | Enhancing Unknown Encrypted Traffic Clustering with Self-Supervised LearningabstractMany malicious attacks are launched through encrypted traffic from unknown proprietary network protocols. Timely identification of such malicious unknown encrypted traffic is essential for the defense. However, it is challenging to acquire labels for unknown protocols in the context of encrypted traffic. Due to the lack of prior knowledge, unsupervised learning is adopted to cluster unknown encrypted traffic. The existing unsupervised encrypted traffic clustering methods do not customize feature extraction and representation of unknown encrypted traffic, resulting in imperfect clustering results. This work innovatively proposes BiFR-SSL to accurately cluster unknown encrypted traffic without prior knowledge. BiFRSSL extracts features of each unknown encrypted bidirectional network flow based on the lengths, arrival time, and directions of packets within the flow to construct a Bidirectional Flowpic Representation (BiFR). Subsequently, it exploits Self-Supervised Learning (SSL) to pre-train a feature extractor that produces feature representations from BiFRs, guaranteeing the closeness of encrypted traffic flows from the same protocol in the representation space. Finally, it clusters unknown encrypted traffic based on their feature representations generated by the pre-trained feature extractor. Our experimental studies demonstrate that BiFR-SSL can effectively cluster encrypted traffic of unknown protocols and outperforms state-of-the-art methods. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
GLOBECOM | 5 |
| 2024 | Collaborative Task Offloading with Digital Twin in Multi-Vehicle and Multi-Edge EnvironmentsabstractIn recent years, the effective utilization of edge servers to assist vehicles in handling compute-intensive and latency-sensitive tasks has emerged as a pivotal concern in Vehicular Edge Computing (VEC). In this paper, we adopt a cooperative approach that leverages the collective capabilities of multiple edge servers. This strategy is designed to effectively manage tasks and alleviate the computational burden imposed on these servers. Specifically, Graph Neural Network (GNN) is applied to extract and classify features such as the geographical locations and communication statuses of multiple edge servers, enabling the selection of the most suitable servers for collaborative task execution. We have utilized solar energy for local computing, effectively achieving environmental protection and reducing the local energy burden on vehicles. Moreover, a novel edge attraction formula is defined to refine the rationality of clustering. In addition, Deep Reinforcement Learning (DRL) is employed to make real-time offloading decisions. To ensure experimental accuracy while mitigating costs, we establish a corresponding digital twin environment to acquire experimental data. By conducting a comparative analysis against three other baseline methods, we effectively reduce task completion time and thus meet the stringent demands of time-sensitive tasks. Anqi Gu, Huaming Wu, Yixiao Wang 0002, Ruidong Li 0001, Chaogang Tang |
GLOBECOM | 4 |
| 2024 | Reschedulable Task Allocation Strategy in Cloud-Edge-End Cooperative Mobile Crowd SensingabstractIn centralized mobile crowd sensing (MCS), the cloud platform assigns all the tasks to participants every time. Since the cloud platform consumes a lot of computing and communication resources to provide services for participants, it will bring about high communication delay and request congestion. The cloud-edge-end architecture for service provisioning has aroused extensive attention recently, owing to its advantages in resource provisioning in close proximity to the resource requestors. Despite the advantages of this architecture, we also observe that it cannot dynamically adjust the allocation scheme when the corresponding computing services are not available to the participants after the initial task allocation. To address this issue, we put forward a re-schedulable task allocation approach in the cloud-edge-end architecture. We aim to improve the efficiency of task execution such as the maximization of task completion rate, while considering service types provided by edge servers and multiple constraints such as resource balancing on the edge servers and deadlines for the task responses. An improved Grey Wolf Optimization (GWO) algorithm is adopted for task rescheduling in this paper. Simulation results indicate that the proposed algorithm performs well in terms of task completion rates and task average response time. Shuhao Wang, Chaogang Tang, Huaming Wu, Ruidong Li 0001 |
ICC | 5 |
| 2024 | TRACEGADGET: Detecting and Tracing Network Level Attack Through Federal Provenance GraphabstractProvenance graph-based auditing offers a promising direction for APT (Advanced Persistent Threat) detection with traceability guarantees. However, most of the existing methods are based on host-level causality analysis, which is ineffective in practical APT scenarios when well-organized adversaries exploit lateral movement attacks (e.g., multi-level proxies) across multiple compromised hosts. To bridge the research gap, this paper proposes a collaborative APT detection and tracing frame-work (TRACEGADGET) based on federal provenance graphs. TRACEGADGET can efficiently reveal the whole trace of APT lateral movements through the interactions between hosts in Intranet. Specifically, the proposed framework 1) characterizes the relevance weights of all events in the given provenance graph in comparison to the POI (Point of Interest) events, 2) identifies the network entries rankings of the POI events through backward trace analysis, 3) reveals the evolution of the alarm events and confirms the network exit of penetration chain through forward propagation, and 4) aligns the network entries and network exits to derive the complete path of the lateral movement attack. Finally, we construct a dataset consisting of 280,000 edges and more than 90,000 entities through ten sets of real APT attacks. We demonstrate the feasibility and effectiveness of the proposed framework in recovering APT attack links at the network level. Particularly, TRACEGADGET achieves 100% APT path reconstruction with high robustness in all the experiments. Yuntao Wang 0004, Zhou Su 0001, Zixuan Wang 0014, Yanghe Pan, Ruidong Li 0001 |
ICC | 6 |
| 2024 | ECPAS: A Blockchain-based E-Commerce Price Auditing SystemabstractIn recent years, with the widespread of the Internet and further big data, E-Commerce (EC) has emerged as a popular medium for users to engage in online transactions of products and services. Generally, Service Providers (SPs) of EC collect users' personal information and utilize advanced big data technologies to enhance their services. However, the price discrimination problem may also arise based on personalized information, where malicious SPs analyze users' historical orders to provide the same products or services at varying prices depending on their characteristics. In this paper, we propose a price auditing system called E-Commerce Price Auditing System (ECPAS) to resolve this problem. ECPAS consists of four smart contracts: User Registration Contract, Product Registration Contract, Insurance Purchasing Contract, and Price Auditing Contract, which realize EC price auditing and financial compensation for price discrimination based on a private blockchain. Meanwhile, ECPAS utilizes InterPlanetary File System (IPFS) to efficiently store product data. Experimental results demonstrate that ECPAS achieves a higher processing speed of 5 million price auditing per day while maintaining low gas and on-chain storage costs based on the IPFS. Toshiki Takakubo, Ruidong Li 0001, Haihan Nan, Qun Jin, Zhou Su 0001, Huaming Wu |
ICC | 2 |
| 2024 | Joint Optimization of Service Caching Task Offloading and Resource Allocation in Cloud-Edge Cooperative NetworkabstractThe cloud-edge cooperative network presents both opportunities and challenges for latency-sensitive and computation-intensive tasks. Effectively harnessing the strengths of edge computing and cloud computing enables real-time task handling, thus reaching a win-win situation where not only the stated quality of service (QoS) is delivered from the angle of service providers, but also the quality of experience (QoE) is improved from the angle of service requestors. However, due to the unpredictable task generation and time-varying environments, it is challenging to achieve optimal task scheduling and effective resource management and allocation. To address this issue, we propose an innovative cloud-edge framework that incorporates task offloading, service caching, and resource allocation in this paper. In this framework, we can determine where to offload the task, e.g., locally, at the edge, or in the cloud center. In view of the importance of the superior user experience, we aim to maximize the user satisfaction regarding task offloading in this framework. The problem is actually a mixed-integer nonlinear programming (MINLP) problem that entails simultaneously addressing cache decisions, offloading decisions, and resources allocation in a dynamic cloud-edge computing system. Owing to the NP-hardness, our original problem is decomposed into two layers of alternating problems. Specifically, we adopt a genetic algorithm (GA) based approach to jointly make cache and offloading decisions, and then iteratively optimize the communication and computing resources allocation. Extensive experimentation has demonstrated the feasibility and effectiveness of the proposed approach. Chaogang Tang, Yao Ding 0013, Shuo Xiao, Huaming Wu, Ruidong Li 0001 |
ICC | 5 |
| 2024 | Aquilas: Adaptive QoS-Oriented Multipath Packet Scheduler with Hierarchical Intelligence for QUICabstractMultipath packet scheduler is responsible for deliv-ering each packet to an appropriate path. However, rules-based schedulers struggle to adapt to varying network conditions and diverse Quality of Service (QoS) requirements. Despite learning- based scheduler can adapt to various network conditions, reacting quickly to network changes is still challenging. Moreover, for diverse QoS requirements, learning-based schedulers often neces-sitates training from scratch. To solve the above challenges, we propose a multi-head mapping model that selects an optimal sub- scheduler based on the current state. It works with a shared state encoder, a multi-head Q-value decoder, and QoS-oriented reward decomposition. Furthermore, we propose Aquilas, an adaptive multi path packet scheduler with hierarchical intelligence for the Quick UDP Internet Connection (QUIC) protocol. Aquilas adopts a learning-based scheduler selector, thereby enabling selection of an optimal policy from a pool of sub-schedulers. This sub- scheduler pool encompasses a wide range of knowledge for handling various network conditions. In coarse time intervals, the learning-based scheduler selector operates, while during fine- grained time intervals, the selected sub-scheduler delivers each packet to the corresponding path. Aquilas has been evaluated in both controlled emulation and real-world networks. Compared with the state-of-the-art schedulers, Aquilas improves transmis-sion performance in various network conditions and diverse traffic types. Congxi Song, Biao Han 0003, Ruidong Li 0001, Xueqiang Han, Jinshu Su |
ICDCS | 3 |
| 2024 | Cross View Capture for Distributed Image Compression with Decoder Side InformationabstractImage compression is increasingly important in applications like intelligent driving and smart surveillance systems. This study presents a novel cross view capture distributed image compression network (CVCDIC) to improve the compression quality by using decoder side information. The CVCDIC’s decoder utilizes feature extraction networks to extract features from both the primary image and the side information. Furthermore, a multi-level cross view attention module is designed to capture interrelated details between images at multiple hierarchical levels. Finally, a spatial refinement module, constructed on the foundation of information distillation networks, is designed to further refine the quality of reconstructed images. The results show that CVCDIC can achieve an MS-SSIM of 0.978 at 0.15 bpp, surpassing DSIN (0.925), NDIC (0.956), and ATN (0.955) on the KITTI Stereo dataset. Yankai Yin, Zhe Sun 0009, Peiying Ruan, Feng Duan 0006, Ruidong Li 0001, Chi Zhu 0001 |
ICRA | 5 |
| 2024 | RateMP: Optimizing Bandwidth Utilization with High Burst Tolerance in Data Center NetworksabstractLoad balancing in data center networks (DCNs) is a crucial and complex undertaking. Multi-path TCP (MPTCP) has been proposed as a cost-effective solution that aims to distribute workloads and improve network resource utilization. However, it can escalate buffer occupancy and undermine burst tolerance, particularly in scenarios involving incast short flows. To address these limitations, we propose a novel multi-path congestion control algorithm, RateMP, to optimize bandwidth utilization efficiency while ensuring burst tolerance in DCNs. RateMP employs a hybrid window and rate control loop with coupled gradient projection adjustment, enabling fast and fine-grained bandwidth allocation and accelerating convergence. Additionally, RateMP eliminates the limitation of cwnd with under-rate pacing to protect incast and busty flows. We prove that RateMP is Lyapunov stable and asymptotically stable, and show the improvement of RateMP through a kernel-based implementation and extended large-scale simulations. RateMP keeps high bandwidth utilization, cuts RTT by 2x and reduces flow completion times (FCT) by 45% in incast scenarios compared to existing algorithms. Jiangping Han, Kaiping Xue, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
INFOCOM | 4 |
| 2024 | AHDom: Algorithmically generated domain detection using attribute heterogeneous graph neural network
Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Comput. Networks | 5 |
| 2024 | Privacy-Enhanced and Efficient Federated Knowledge Transfer Framework in IoTabstractFederated learning (FL) has gained widespread adoption in Internet of Things (IoT) applications, promoting the evolution of IoT toward Artificial Intelligence of Things (AIoT). However, IoT devices are still vulnerable to various privacy inference attacks in FL. While current solutions aim to protect the privacy of devices during model training, the published model is still at risk from external privacy attacks during model deployment. To address the privacy concerns throughout the entire FL lifecycle, this article proposes a privacy-enhanced and efficient federated knowledge transfer framework for IoT, named PEFKT, which integrates the knowledge transfer method and local differential privacy (LDP) mechanism. In PEFKT, we devise a data diversity-driven grouping strategy to tackle the non-independent and identically distributed (non-IID) issue in IoT. Additionally, we design a quality-aware soft-label aggregation algorithm to facilitate effective knowledge transfer, thereby improving the performance of the student model. Finally, we provide rigorous privacy analysis and validate the feasibility and effectiveness of PEFKT through extensive experiments on real data sets. Yanghe Pan, Zhou Su 0001, Yuntao Wang 0004, Ruidong Li 0001, Yuan Wu 0001 |
IEEE Internet Things J. | 4 |
| 2024 | REDP: Reliable Entanglement Distribution Protocol Design for Large-Scale Quantum NetworksabstractRemote entanglement distribution in an efficient and reliable manner, especially in the context of a large-scale quantum network with multiple requests, remains an unsolved challenge. The key difficulties lie in achieving spontaneous and precise control over the entanglement distribution procedure, as multiple nodes need to reach a consensus on how to perform it. From the network aspect, allocating link-layer entangled pairs as resources to achieve high efficiency is also challenging. To address these issues, we propose a decentralized Reliable Entanglement Distribution Protocol (REDP) for large-scale networks. The protocol operates in a Forward-Backward Propagation (FBP) manner, where consensus is reached hop-by-hop and disseminated to all nodes on the path. We further use probabilistic analysis and quasi-static modeling to seek the fairness and efficiency of the network based on the above transmission model. Accordingly, we introduce a Source Window Strategy (SWS) and an Entanglement Allocation Strategy (EAS) to assign sending windows and allocate resources for multiple requests, ensuring a high level of fairness and efficiency from a network perspective. Through systematic simulations involving both classical and quantum communication protocols, we demonstrate that REDP outperforms existing approaches in terms of fairness, throughput, and fidelity performance. Lutong Chen, Kaiping Xue, Jian Li 0031, Zhonghui Li, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | An Efficient and Robust Fusion Positioning System Based on Entangled PhotonsabstractPrecise positioning is a key factor and enabler technology for many use cases on intelligent transportation systems (ITS) and connected and automated vehicles (CAVs). Recently, the quantum positioning system (QPS) based on quantum ranging has emerged as a novel way to improve security and precision. As a key process of QPS, the entangled photons based ranging technology has picosecond-level clock synchronization, and the ranging accuracy can reach the Heisenberg limit. If promising QPS is deployed in the ITS and CAVs, it will cause a profound change. However, the existing QPS still lacks accuracy and robustness in different scenarios. To solve this problem, we proposed an efficient and robust fusion positioning system based on entangled photons. In this system, we derive the ranging accuracy limit with many factors and propose a fast data grouping and selection algorithm to improve real-time performance. Furthermore, we propose a fusion extended fingerprint localization method for robust positioning in the dynamic environment. The effectiveness and robustness of the system are verified by extensive experiments. When the range is 15m, the ranging accuracy can be limited to 0.0018m. The proposed system achieves the probability of positioning errors 90% within 0.13m with only two APs. Yong Wang 0004, Mu Zhou, Ruidong Li 0001, Liangbo Xie, Zhou Su 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2024 | Spatio-Temporal Identity Multi-Graph Convolutional Network for Traffic Prediction in the MetaverseabstractThe metaverse is at the forefront of the next-generation internet application, where billions of users seamlessly immerse themselves in a hybrid reality of physical-virtual worlds and switch between virtual environments thanks to reliable resource allocation and synchronization. However, the exponential growth of users and computationally intensive applications make joint optimization of multiple indicators challenging. Therefore, predicting user behavior is pivotal in assisting the optimization process. Although graph neural networks have demonstrated remarkable performance in traffic prediction, most existing schemes link nodes based on their distances and require significant computational resources, limiting their generalization and deployment in the metaverse. To solve this problem, we propose an efficient Spatio-temporal Identity Multi-graph convolutional network Framework (SIMF) for application-level traffic prediction in the metaverse. In the SIMF, we design a spatio-temporal embedding layer and multi-graph convolutional module to jointly capture spatio-temporal correlations among nodes (avatars) and reduce the dependence on topology information, which is more consistent with the real relationship between avatars in the metaverse. We conduct extensive experiments to evaluate the SIMF, which show that our proposed framework achieves superior accuracy even without graph information while maintaining low time complexity, making it suitable for traffic prediction in the metaverse. Haihan Nan, Ruidong Li 0001, Xiaoyan Zhu 0005, Jianfeng Ma 0001, Kaiping Xue |
IEEE J. Sel. Areas Commun. | 2 |
| 2024 | Collecting Partial Ordered Data With Local Differential PrivacyabstractThe partial ordered data is typically used to describe the order of some elements within a set, and it widely exists in various fields, such as clinical investigations, preference ranking and voting. However, the collection of partial ordered data poses critical privacy concerns about abusing records to infer individuals’ identities and preferences. To solve this problem, this paper proposes a distribution analysis method for partial ordered data with local differential privacy (LDP). The private information of partial ordered data includes whether an element is associated with a partial order relation and either a relation is preceding or succeeding. To preserve privacy, we perturb partial ordered data by randomly responding raw data or the data with mapped elements. This makes it impossible to distinguish whether any element has a partial order relationship with other elements and what kind of partial order relationship exists. To maintain the logicality of partial ordered data, we utilize the transitivity of partial orders to distinguish between direct and indirect orders in the perturbation. The inherent properties of partial orders are still satisfied after perturbation, which reduces the possibility of servers inferring the raw data through logical errors. Moreover, we theoretically analyze the error bound and prove the security of our work. Extensive experimental results on synthetic and real-world datasets demonstrate that our scheme achieves better utility than existing state-of-the-art approaches. Yaxuan Huang, Kaiping Xue, Bin Zhu 0010, Jingcheng Zhao, Ruidong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Collaborative Honeypot Defense in UAV Networks: A Learning-Based Game ApproachabstractThe proliferation of unmanned aerial vehicles (UAVs) opens up new opportunities for on-demand service provision anywhere and anytime, but also exposes UAVs to a variety of cyber threats. Low/medium interaction honeypots offer a promising lightweight defense for actively protecting mobile Internet of things, particularly UAV networks. While previous research has primarily focused on honeypot system design and attack pattern recognition, the incentive issue for motivating UAVs’ participation (e.g., sharing trapped attack data in honeypots) to collaboratively resist distributed and sophisticated attacks remains unexplored. This paper proposes a novel game-theoretical collaborative defense approach to address optimal, fair, and feasible incentive design, in the presence of network dynamics and UAVs’ multi-dimensional private information (e.g., valid defense data (VDD) volume, communication delay, and UAV cost). Specifically, we first develop a honeypot game between UAVs and the network operator under both partial and complete information asymmetry scenarios. The optimal VDD-reward contract design problem with partial information asymmetry is then solved using a contract-theoretic approach that ensures budget feasibility, truthfulness, fairness, and computational efficiency. In addition, under complete information asymmetry, we devise a distributed reinforcement learning algorithm to dynamically design optimal contracts for distinct types of UAVs in the time-varying UAV network. Extensive simulations demonstrate that the proposed scheme can motivate UAV’s cooperation in VDD sharing and improve defensive effectiveness, compared with conventional schemes. Yuntao Wang 0004, Zhou Su 0001, Abderrahim Benslimane, Qichao Xu, Minghui Dai, Ruidong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Q-DDCA: Decentralized Dynamic Congestion Avoid Routing in Large-Scale Quantum NetworksabstractThe quantum network that allows users to communicate in a quantum way will be available in the foreseeable future. The network capable of distributing Bell state entangled pairs faces many challenges due to entanglement decoherence and limited network performance, especially when the network scale is enormous. Many entanglement distribution protocols have been proposed so far, and most of them are in a centralized and synchronized manner, which may be infeasible in large-scale networks. As such, in this paper, we propose a full spontaneous version of quantum networks in which the quantum nodes autonomously manage multiple entanglement distribution requests. However, one major issue is that quantum nodes have little knowledge about the network, especially the congestion (e.g., some nodes may have no usable quantum memories). We present a routing algorithm to adaptive evaluate the congestion on the neighbor nodes to avoid potential congestion. We use SimQN, the new network layer simulation platform built by our research team, to evaluate our proposed design. The result demonstrates that it can adapt to changes in network resources and reduce the drop rate that eventually leads to a higher entanglement distribution rate but remains fair for multiple requests to use the network resources fairly and achieve a more balanced throughput. Lutong Chen, Kaiping Xue, Jian Li 0031, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2024 | Social-Aware Clustered Federated Learning With Customized Privacy PreservationabstractA key feature of federated learning (FL) is to preserve the data privacy of end users. However, there still exist potential privacy leakage in exchanging gradients under FL. As a result, recent research often explores the differential privacy (DP) approaches to add noises to the computing results to address privacy concerns with low overheads, which however degrade the model performance. In this paper, we strike the balance of data privacy and efficiency by utilizing the pervasive social connections between users. Specifically, we propose SCFL, a novel Social-aware Clustered Federated Learning scheme, where mutually trusted individuals can freely form a social cluster and aggregate their raw model updates (e.g., gradients) inside each cluster before uploading to the cloud for global aggregation. By mixing model updates in a social group, adversaries can only eavesdrop the social-layer combined results, but not the privacy of individuals. As such, SCFL considerably enhances model utility without sacrificing privacy in a low-cost and highly feasible manner. We unfold the design of SCFL in three steps. i) Stable social cluster formation. Considering users’ heterogeneous training samples and data distributions, we formulate the optimal social cluster formation problem as a federation game and devise a fair revenue allocation mechanism to resist free-riders. ii) Differentiated trust-privacy mapping. For the clusters with low mutual trust, we design a customizable privacy preservation mechanism to adaptively sanitize participants’ model updates depending on social trust degrees. iii) Distributed convergence. A distributed two-sided matching algorithm is devised to attain an optimized disjoint partition with Nash-stable convergence. Experiments on Facebook network and MNIST/CIFAR-10 datasets validate that our SCFL can effectively enhance learning utility, improve user payoff, and enforce customizable privacy protection. Yuntao Wang 0004, Zhou Su 0001, Yanghe Pan, Tom H. Luan, Ruidong Li 0001, Shui Yu 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2024 | A Privacy-Preserving Incentive Scheme for Data Sensing in App-Assisted Mobile Edge CrowdsensingabstractApplication (App)-assisted mobile edge crowd- sensing is a promising paradigm, in which Apps are in charge of tagging the location of the sensing tasks as point-of-interest (PoI) to assist the platform in recruiting users to participate in the sensing tasks. However, there exist potential security, incentive, and privacy threats for App-assisted mobile edge crowdsensing (AMECS) due to the presence of malicious Apps, the low-quality shared sensing data, and the vulnerability of wireless communication. Therefore, we propose a differential privacy-based incentive (DPI) scheme for AMECS to provide secure and efficient crowdsensing services while protecting users’ privacy. Specifically, we first propose an App quality management mechanism to correlate the behavior of each App with its quality and then select reliable Apps based on quality thresholds to assist the platform in recruiting users. With the designed mechanism, we further present an auction game-based incentive mechanism to encourage Apps to mark the location of the sensing tasks as PoI. To protect the privacy of users, a privacy-preserving sensing data sharing algorithm is devised based on differential privacy. Further, given the difficulty of obtaining accurate network parameters in practice, a reinforcement learning-based incentive mechanism is designed to encourage users to participate in sensing tasks. Finally, simulation results and security analysis demonstrate that the proposed scheme can effectively improve the utilities of users, ensure the security of the crowdsensing process, and protect the privacy of users. Liang Xie 0011, Zhou Su 0001, Nan Chen 0006, Yuntao Wang 0004, Yiliang Liu, Ruidong Li 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2024 | Adaptive Multi-Source Multi-Path Congestion Control for Named Data NetworkingabstractNamed Data Networking (NDN), with a receiver-driven connectionless communication paradigm, naturally supports content delivery from multiple sources via multiple paths. In a dynamic environment, sources and paths may change unexpectedly and are uncontrollable for consumer, which requires flexible rate control and real-time multi-path management, still lacking investigations. To address this issue, we propose an Adaptive Multi-source Multi-path Congestion Control (AMM-CC) scheme based on online learning. AMM-CC explores source/path distribution with continuous micro-experiments and abstracts the empirically experienced performance by meticulously designed two-level utility functions. Specifically, AMM-CC enables each consumer to optimize a local transmission-level utility function that fuses multi-source characteristics, including congestion level and source weights. Then, a sub-gradient descent method is designed to adjust transmission rate adaptively and achieve fine-grained control. Moreover, AMM-CC coordinates consumer with the forwarding module to ensure efficient and on-time multi-path management. It enables consumer to determine congestion gap among multiple paths by a path-level utility that sensitively captures changes and congestion on each path. Then, consumer further notifies the forwarding module in achieving precise traffic transferring. We conducted comprehensive evaluations in dynamic scenario with various content distribution using the NDN simulator, ndnSIM. The evaluation results demonstrate that AMM-CC can adapt to flexible content acquisition from multi-sources and significantly improve bandwidth utilization of multi-path compared with state-of-the-art schemes. Kaiping Xue, Jiangping Han, Jian Li 0031, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2023 | Codecs for DNA-based Data Storage Systems with Multiple Constraints for Internet of ThingsabstractInternet of Things (IoT) devices are severely constrained in computational capacity, battery life, and data storage, which fail to meet the requirement of mass data storage. With the explosive growth of data to be stored, Deoxyribonucleic acid (DNA)-based storage has become a promising direction for IoT data storage due to its various advantages, e.g. high capacity, long durability and scalability. However, DNA synthesis and sequencing are subject to errors due to certain biochemical properties of DNA. In this paper, an explicit encoding and decoding scheme for constrained systems satisfying both 3-RLL constraint and strong-( 4,1)-locally-GC-balanced constraint is designed. We propose the use of a state-splitting algorithm to encode binary strong-(4,1)-locally-balanced constrained systems with the rate 2: 3, and a state-dependent decoding algorithm to decode the encoded data. The calculation results show that the codebook of the encoding scheme in this paper is larger than that of the existing scheme, and the total number of codewords with a length of 24 is more than 6 times that of the existing scheme. The information rate is higher than that of existing coding schemes. The encoding table size required is two orders of magnitude smaller than the existing scheme. Kaixin Fan, Huaming Wu, Ruidong Li 0001 |
GLOBECOM | 3 |
| 2023 | Towards Early and Accurate IoT Device-Type Identification with Global Attention MechanismabstractWith the rapid development of Internet of Things (loT) technology, there is explosive growth in the number of loT devices. Meanwhile, the low security and network heterogeneity of loT networks have brought new challenges to implementing network management and security strategies in smart homes and small offices. Early and accurate loT device-type identification is the first step towards the security management of loT networks. The existing machine learning-based and deep learning-based models for loT traffic classification have achieved decent results. However, most of these methods rely on a long-term window to collect loT device traffic for identification, resulting in limited real-time performance. This work proposes 10T-GFCN, an early and accurate loT device-type identification model with global attention mechanism. 10T-GFCN first constructs a multi-feature sequence for each device from a small packet window. Then 10T-GFCN resorts to the global attention mechanism to efficiently mine temporal information and feature relationships and obtain an updated embedding of each multi-feature sequence. Finally, a fully convolutional neural network is trained based on the updated embeddings of traffic features to identify loT device types. Our experimental study suggests that 10T-GFCN can efficiently capture distinguishable representations for packet-level features of loT traffic and outperforms state-of-the-art loT identification methods. It achieves an average accuracy of 98.88 % with a window size of 75 packets (the traffic of about three minutes) on the UNSW dataset. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
GLOBECOM | 4 |
| 2023 | AcCrowd: Blockchain-based Crowdsourcing with Worker Anonymity and Payment CorrectnessabstractTo improve the security of crowdsourcing, existing studies introduce blockchain to ensure reliability and utilize cryptography (e.g., encryption and zero-knowledge proof) to protect data privacy. Nevertheless, the crowdsourcing process may involve sensitive identity information, and identity protection remains unresolved during stages such as data submission and correct payment. Especially, when workers invoke a smart contract to submit data, it inevitably exposes their identities. Identity disclosure significantly impacts the credibility of crowdsourcing platforms. Existing solutions suggest solving the problem through anonymous token contracts such as Zether. However, tokens can easily result in fund freezing or extra information leakage. Moreover, invoking the contract to submit data will still disclose workers' blockchain accounts. To tackle the identity protection issue, in this paper, we propose AcCrowd which achieves worker anonymity and payment correctness in crowdsourcing systems atop blockchain. We first design a verifiable proxy submission mechanism for data submission, enabling workers to invoke contracts without disclosing their accounts. Then, we introduce and improve the BlockMaze architecture to replace previous anonymous token-based methods, enhancing privacy and flexibility. Besides, we designed a revealed payment mechanism that utilizes an adaptor signature to bind data reveal and reward payment together, simultaneously protecting the requester and worker. Our security and performance evaluations demonstrate the security and practicability of AcCrowd. Qiantong Jiang, Xianchao Zhang 0002, Kaiping Xue, Ruidong Li 0001 |
GLOBECOM | 6 |
| 2023 | Differential Privacy-Based Incentive Scheme for App-Assisted Mobile Edge CrowdsensingabstractThe combination of applications (Apps) and mobile edge crowdsensing technology has been viewed as a promising paradigm, where Apps are responsible for marking the location of the sensing task as point-of-interest (PoI) to assist the platform in recruiting users. However, there still exist potential incentive and privacy threats associated with App-assisted mobile edge crowdsensing (AMECS) due to the selfish nature of Apps and the vulnerability of wireless communication. To this end, we propose a differential privacy-based incentive (DPI) scheme for AMECS to support secure and efficient crowdsensing while protecting the privacy of users. Specifically, we first propose an App quality management mechanism to correlate the behavior of the App with its quality and then choose reliable Apps based on quality thresholds. Afterwards, a privacy-preserving sensing data sharing algorithm is designed to protect the privacy of users. Furthermore, given the difficulty of obtaining accurate network parameters in real life, a reinforcement learning-based incentive mechanism is devised to motivate users to actively engage in sensing tasks. Finally, simulation results and security analysis demonstrate that the proposed scheme is effective in improving the utility of participants and protecting the privacy of users. Liang Xie 0011, Zhou Su 0001, Nan Chen 0006, Ruidong Li 0001 |
GLOBECOM | 4 |
| 2023 | Achieving Privacy-Preserving Outsourced SVM Training with Non-Linear KernelabstractCloud-based Support Vector Machine (SVM) is a powerful technique for decision-assistance service. However, training data and models of SVM contain sensitive information, outsourcing these data to clouds may lead to severe privacy leakage. To address the privacy issue of SVM, many works focus on outsourced privacy-preserving SVM training. However, these works cannot support training SVM with non-linear kernel. This limitation renders these methods impractical for real-world scenarios where datasets are usually non-linear. In this paper, we propose a privacy-preserving SVM training scheme with support to non-linear kernel. Specifically, we redesign a gradient descent for SVM with kernel, which supports efficient kernel SVM training. We design basic computation protocols using secret sharing to achieve privacy preservation in outsourced SVM training. Additionally, we construct an incremental learning approach to support continuous data inflow. This approach is capable of reducing computational overhead significantly in practical scenario. Security analysis and efficiency evaluation illustrate that our proposed scheme achieves superior accuracy and less computation overhead compared to existing works, while also preserving privacy of training data and trained SVM model. Yuandong Xie, Jingcheng Zhao, Bin Zhu 0010, Ruidong Li 0001, Kaiping Xue |
GLOBECOM | 5 |
| 2023 | Performance Investigations on Integrating Federated Learning with Future NetworksabstractFor future networks, communications and computing will converge to provide services; Federated Learning (FL), as one of the typical distributed computing technologies, needs to be integrated with networking. For such integration, FL suffers from the straggler effect that the entire learning speed can be lowered down, because of the existence of the devices taking more time to complete their tasks. There are many existing works targeting at reducing straggler effects; However, they lacks the detailed investigations on the reasons and the impact of each cause when integrating FL with networking. To carefully investigate those aspects, we classify the reasons of such effects into 3 categories, computing power, communication capability and data distributions, and conduct the extensive experiments with carefully designs. After investigations, it is observed that learning completion time cannot be estimated by formulation with FLoating-point Operations Per second (FLOPs) if the device's computing capability is low. Also the communication time can be reduced by intentionally selecting appropriate devices when the computing powers of devices are heterogeneous, and the model parameters can be discarded if the device holds independent and identically distributed (i.i.d.) dataset. Shun Fukumoto, Ruidong Li 0001, Zhou Su 0001 |
ICC | 2 |
| 2023 | Detecting Cryptomining Traffic Over an Encrypted Proxy Based on K-S TestabstractIn recent years, the good revenue generated by cryptocurrency mining has attracted a lot of people to participate in it. It has also caught the attention of hackers, and cryptojacking attacks are becoming more common. Detecting cryptomining behavior can effectively reduce the lost caused by cryptojacking attacks. Existing host-based cryptomining detection methods can protect only end devices and violate users' privacy. Besides, network-based solutions can not better handle anti-reconnaissance means of encrypted proxy. To bridge this gap, we propose a cryptomining traffic detection model based on K-S Test(CMD-KST). Our traffic analysis study confirms that the feature distributions of cryptomining traffic over an encrypted proxy are still stable and unique. CMD-KST compares the feature distributions of a network flow segment with that of cryptomining traffic over the encrypted proxy to complete the detection task. CMD-KST is easily deployable and can detect cryptomining traffic at the entrance of the managed network. Our experimental results demonstrate that CMD-KST achieves a recall of 98.84% without generating false positives and takes only 6 minutes of analyzing mining traffic to complete the detection. CMD-KST is faster than other network-based cryptomining traffic detection methods and achieves a higher precision. Furthermore, the adversarial evaluation shows that it is challenging for the attackers to counteract our detection. Xiaoyan Hu 0007, Boquan Lin, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
ICC | 4 |
| 2023 | A Novel Darknet Traffic Classification Method Based on Knowledge Graph with Dynamic Embedding LearningabstractDarknet is described as an individual encrypted part of the Internet that can only be accessed with specific anonymity tools. Achieving accurate classification of darknet traffic is crucial for identifying anonymous network applications and combating cybercrimes. Machine learning-based and deep learning-based classifiers have achieved decent results in darknet traffic classification. However, these methods can not learn global and distinctive darknet flow embedding representations, resulting in limited classification performance. To tackle these issues, we propose Dark-DKGC, a novel darknet traffic classification method based on Knowledge Graph (KG) with Dynamic Knowledge Graph (DKG) embedding learning. Dark-DKGC first constructs Darknet Traffic Dynamic Knowledge Graph (Dark-DKG). Then Dark-DKGC utilizes the DKG embedding method to effectively learn the embedding representations of all flows. Finally, machine learning-based classifiers are trained based on the embedding representations of flows to identify darknet traffic. Our experimental studies suggest that Dark-DKGC can effectively capture distinguishable embedding representations for darknet flows. In multiclass classification scenario, its average accuracy is about 7%-13% higher than state-of-the-art methods and 1% higher than the static KG embedding-based classifier. Besides, compared to the static KG embedding method, Dark-DKGC takes advantage of its online embedding learning to improve test efficiency significantly. Moreover, the visualization of Dark-DKG allows a certain degree of interpretability for the classification results. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
ICC | 4 |
| 2023 | Trade Privacy for Utility: A Learning-Based Privacy Pricing Game in Federated LearningabstractTo prevent implicit privacy disclosure in sharing gradients among data owners (DOs) under federated learning (FL), differential privacy (DP) and its variants have become a common practice to offer formal privacy guarantees with low overheads. However, individual DOs generally tend to inject larger DP noises for stronger privacy provisions (which entails severe degradation of model utility), while the curator (i.e., aggregation server) aims to minimize the overall effect of added random noises for satisfactory model performance. To address this conflicting goal, we propose a novel dynamic privacy pricing (DyPP) game which allows DOs to sell individual privacy (by lowering the scale of locally added DP noise) for differentiated economic compensations (offered by the curator), thereby enhancing FL model utility. Considering multi-dimensional information asymmetry among players (e.g., DO's data distribution and privacy preference, and curator's maximum affordable payment) as well as their varying private information in distinct FL tasks, it is hard to directly attain the Nash equilibrium of the mixed-strategy DyPP game. Alternatively, we devise a fast reinforcement learning algorithm with two layers to quickly learn the optimal mixed noise-saving strategy of DOs and the optimal mixed pricing strategy of the curator without prior knowledge of players' private information. Experiments on real datasets validate the feasibility and effectiveness of the proposed scheme in terms of faster convergence speed and enhanced FL model utility with lower payment costs. Yuntao Wang 0004, Zhou Su 0001, Yanghe Pan, Abderrahim Benslimane, Yiliang Liu, Tom H. Luan, Ruidong Li 0001 |
ICC | 7 |
| 2023 | Covert Communication by Exploiting a Full-Duplex Cognitive Receiver in CR NetworkabstractCovert communications can enhance users's privacy by hiding the existence of communication. In this paper, we analyze a covert cooperative cognitive radio (CCCR) networks, where a primary transmitter (PT) transmits information with the aid of one secondary transmitter (ST). In return, ST attempts to transmit private information by exploiting PT's spectrum in presence of an eavesdropper (Eve). Specifically, a full-duplex secondary receiver (SR) sends jamming signals to the Eve to cause uncertainty by varying the jamming power. Then, the closed-form expression of the minimal detection error probability at Eve, the approximate expression for the optimal transmit power as well as the corresponding covert rate can be obtained under the given constraint. Numerical results show that the jamming signals and noise uncertainty have a significant influence on Eve's minimum detection error probability. Moreover, it can be seen that under the same covert constraints, the joint impact of noise uncertainty and jamming power on Eve's detection error probability, covert rate and covert outage probability (COP) is remarkable when noise uncertainty is large or the self-interference cancellation coefficient is small. Huan Zhou 0002, Ruidong Li 0001, Rui Chen 0031 |
ICC | 3 |
| 2023 | L2BM: Switch Buffer Management for Hybrid Traffic in Data Center NetworksabstractWith Remote Direct Memory Access (RDMA) extended to commercial Ethernet, modern Data Center Networks (DCNs) carry both traditional TCP and RDMA, to support diversified application requirements. RDMA flows are guaranteed lossless transmission through Priority-based Flow Control (PFC), while TCP flows are generally lossy traffic with packet loss. However, TCP is prone to excessively occupy the shared buffer, frequently triggering PFC pause frames and overflows at switches, damaging the performance of RDMA, which expose the vulnerability of existing buffer management policies. In this paper, we propose L2BM, a buffer management algorithm for shared-memory switches to support dynamic hybrid traffic. L2BM utilizes the average occupying time of packets in each ingress queues, to perceive the congestion states timely at ingress ports, allocating the ingress pool fairly and flexibly. Based on the perception, L2BM allocates more buffer for ingress queues with faster drain and lower congestion degrees to absorb micro-burst and reduce pause frames, less buffer for long-occupied queues to prevent excessive injection. As a result, L2BM achieves low tail latency, high burst traffic absorption capacity and low buffer occupancy. Evaluations show that L2BM enable to cut the tail latency of RDMA traffic by 50% at high workloads, reduce the buffer occupancy by 40% and decrease average query delay by 57%, while ensuring few PFC pause frames and maintaining good performance of TCP flows. Yi Liu 0147, Jiangping Han, Kaiping Xue, Ruidong Li 0001, Jian Li 0031 |
ICDCS | 4 |
| 2023 | SEREDACT: Secure and Efficient Redactable Blockchain with Verifiable ModificationabstractThe immutability of blockchains is an important security feature, but applications and studies have shown that it poses some problems. For instance, harmful information and vulnerable programs can be permanently stored on public blockchains such as Bitcoin and Ethereum, causing continuous damage. Therefore, researchers proposed the redactable blockchain to delete or modify those harmful data. Existing schemes usually adopt the Chameleon hash function (CHF) to keep the block hash unchanged so that other blocks remain unaffected. However, these schemes suffer from two security problems: (i) (unknown-version) users cannot determine whether a received block is the up-to-date version because different versions have the same hash; and (ii) (lazy-redaction) miners have no motivations to update historical blocks, causing continuous spreading of data which should have been discarded. To solve the problems, we propose SEREDACT, a secure and efficient redactable blockchain protocol with verifiable modification. Specifically, we design a Merkle tree-based verification mechanism with efficient dynamic updating that supports quick version checks and forcible modification updates, and further integrate it with restricted redaction policies to guarantee security. Our security and performance analyses show that SEREDACT has adequate security as a redactable blockchain protocol and retains close efficiency compared with the immutable blockchain. Kaiping Xue, David S. L. Wei, Ruidong Li 0001 |
ICDCS | 5 |
| 2023 | RPBV: Reputation-Based Probabilistic Batch Verification Scheme for Named Data NetworkingabstractAs a promising implementation of Information Centric Networking, Named Data Networking (NDN) can facilitate content distribution with in-network caching and location-independent data access. However, the reliance on caches makes NDN vulnerable to content poisoning attacks, which waste network resources and decrease transmission efficiency. Most mitigating schemes follow the pattern that each content is repeatedly verified individually in each router and all producers have the same status, which wastes computation resources and degrades network performance. In this paper, we propose a Reputation-based Probabilistic Batch Verification (RPBV) scheme to address the issue, in which producers’ reputation is estimated according to verification results to distinguish different producers. We provide an adaptive probabilistic verification method based on reputation to avoid a lot of unnecessary verification operations. At the same time, we adopt an efficient batch verification algorithm to simultaneously verify multiple content, which reduces the overhead greatly. With the above mechanisms implemented only on the edge router to avoid repeated verification, we provide an optional probabilistic verification method on intermediate routers to strengthen the security. The extensive simulations show that RPBV achieves much lower computation overhead and shorter content retrieval time than the traditional schemes. Kunpeng Ding, Jiangping Han, Bobo Wang, Ruidong Li 0001, Kaiping Xue |
IWQoS | 5 |
| 2023 | MARS: An Adaptive Multi-Agent DRL-based Scheduler for Multipath QUIC in Dynamic NetworksabstractThe multipath extension of the Quick UDP Internet Connection (QUIC) protocol, also called MPQUIC, is currently attracting increasing attention from both industry and academia. The multipath scheduler of MPQUIC determines how to distribute the packets onto different paths. However, our experimental results show that they fail to adapt to various receive buffer sizes and Quality of Service (QoS) requirements while applying current multipath schedulers into MPQUIC due to the diversity of devices and applications. These problems are especially severe under heterogeneous and dynamic network environments. To tackle these problems, we propose MARS, a Multi-Agent deep Reinforcement learning (MADRL) based Multipath QUIC Scheduler, which is able to promptly adapt to dynamic network environments. It exploits the MADRL method to learn a neural network for each path and generate scheduling policy. Besides, it introduces a novel multi-objective reward function that takes out-of-order (OFO) queue size and different QoS metrics into consideration to realize adaptive scheduling optimization. We implement MARS in an MPQUIC prototype and compare it with the state-of-the-art multipath schedulers in both emulated and real-world networks. Experimental results show that MARS outperforms the other schedulers with better adaptive capability regarding the receive buffer sizes and QoS. Xueqiang Han, Biao Han 0003, Ruidong Li 0001, Xiaolan Ji |
IWQoS | 3 |
| 2023 | Fine-grained Ethereum behavior identification via encrypted traffic analysis with serialized backward inference
Xiaoyan Hu 0007, Zhuozhuo Shu, Zhongqi Tong, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Comput. Networks | 5 |
| 2023 | A Deep Subdomain Adaptation Network With Attention Mechanism for Malware Variant Traffic Identification at an IoT Edge GatewayabstractThe prevailing of malware variants in ubiquitous Internet of Things (IoT) devices causes enormous losses. Accurate and timely identification of malware variant traffic at an IoT edge gateway can effectively reduce the loss. TransNet, the state-of-the-art technology for malware variant traffic detection, considers only global domain adaptation and ignores the alignment of distributions between different subdomains, which fails to capture the fine-grained information of classification targets. Besides, TransNet converges very slowly, which may use up precious resources in IoT devices. This article proposes a deep subdomain adaptation network with attention mechanism (DSAN-AT) to accurately and efficiently identify malware variant traffic at an IoT edge gateway. DSAN-AT utilizes local maximum mean discrepancy (LMMD) to align the traffic feature distributions of subdomains in the source and target domains. It also exploits channel and spatial attention mechanisms to accelerate learning traffic features between different subdomains to save precious computing resources at the IoT edge gateway. Our experimental study demonstrates that DSAN-AT achieves an average accuracy of 97.15% (96.37% for TransNet) and converges fast without using a large target domain training data set. DSAN-AT has strong practicality for identifying malware variant traffic at an edge IoT gateway. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Internet Things J. | 4 |
| 2023 | MR-DRO: A Fast and Efficient Task Offloading Algorithm in Heterogeneous Edge/Cloud Computing EnvironmentsabstractWith the rapid development of Internet of Things (IoT) and next-generation communication technologies, resource-constrained mobile devices (MDs) fail to meet the demand of resource-hungry and compute-intensive applications. To cope with this challenge, with the assistance of mobile-edge computing (MEC), offloading complex tasks from MDs to edge cloud servers (CSs) or central CSs can reduce the computational burden of devices and improve the efficiency of task processing. However, it is difficult to obtain optimal offloading decisions by conventional heuristic optimization methods, because the decision-making problem is usually NP-hard. In addition, there are shortcomings in using intelligent decision-making methods, e.g., lack of training samples and poor ability of migration under different MEC environments. To this end, we propose a novel offloading algorithm named meta reinforcement-deep reinforcement learning-based offloading, consisting of a meta-reinforcement learning (meta-RL) model, which improves the migration ability of the whole model, and a deep reinforcement learning (DRL) model, which combines multiple parallel deep neural networks (DNNs) to learn from historical task offloading scenarios. Simulation results demonstrate that our approach can effectively and efficiently generate near-optimal offloading decisions in IoT environments with edge and cloud collaboration, which further improves the computational performance and has strong portability when making offloading decisions. Ziru Zhang, Nianfu Wang, Huaming Wu, Chaogang Tang, Ruidong Li 0001 |
IEEE Internet Things J. | 5 |
| 2023 | ReplaceDGA: BiLSTM-Based Adversarial DGA With High Anti-Detection AbilityabstractBotnets extensively leverage Domain Generation Algorithms (DGAs) to establish reliable communication channels between bots and Command and Control (C&C) servers. Numerous character-level DGA classifiers have been extensively studied to detect and classify domain names generated by DGAs. Meanwhile, a series of adversarial domain generation algorithms have been proposed to evade DGA classifiers. Although the existing domain name generation algorithms have progressed against DGA classifier, their anti-detection abilities are still weak. This paper proposes a Bidirectional Long Short-Term Memory (BiLSTM) network-based adversarial DGA with high anti-detection ability, referred to as ReplaceDGA. ReplaceDGA requires no knowledge of the targeted DGA classifiers. It first builds a prediction model for benign domain names using the BiLSTM network to model the semantic relationship hidden within benign domain names and then replaces two characters of each input benign domain name based on the prediction model to maximize the similarity between the benign and generated domain names. Our experimental results validate that ReplaceDGA successfully evades various character-level DGA classifiers even after they are retrained by domain names generated by ReplaceDGA and outperforms the state-of-the-art adversarial DGAs in anti-detection ability, repetition rate, and collision rate. Our study of ReplaceDGA promotes the urgent need for developing more comprehensive and robust DGA classifiers that consider other factors besides character-level information of domain names. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004, Yali Yuan |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Toward Early and Accurate Network Intrusion Detection Using Graph EmbeddingabstractEarly and accurate detection of network intrusions is crucial to ensure network security and stability. Existing network intrusion detection methods mainly use conventional machine learning or deep learning technology to classify intrusions based on the statistical features of network flows. The feature extraction relies on expert experience and cannot be performed until the end of network flows, which delays intrusion detection. The existing graph-based intrusion detection methods require global network traffic to construct communication graphs, which is complex and time-consuming. Besides, the existing deep learning-based and graph-based intrusion detection methods resort to massive training samples. This paper proposes Graph2vec+RF, an early and accurate network intrusion detection method based on graph embedding technology. We construct a flow graph from the initial several interactive packets for each bidirectional network flow instead, adopt graph embedding technology, graph2vec, to learn the vector representation of the flow graph and classify the graph vectors with Random Forest (RF). Graph2vec+RF automatically extracts flow graph features using subgraph structures and relies on only a small number of the initial interactive packets per bidirectional network flow without requiring massive training samples to achieve early and accurate network intrusion detection. Our experimental results on the CICIDS2017 and CICIDS2018 datasets show that our proposed Graph2vec+RF outperforms the state-of-the-art methods in terms of accuracy, recall, precision, and F1-score. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | SEAL: A Strategy-Proof and Privacy-Preserving UAV Computation Offloading FrameworkabstractDue to the limited battery and computing resource, offloading unmanned aerial vehicles (UAVs)’ computation tasks to ground infrastructure, e.g., vehicles, is a fundamental framework. Under such an open and untrusted environment, vehicles are reluctant to share their computing resource unless provisioning strong incentives, privacy protection, and fairness guarantee. Precisely, without strategy-proofness guarantee, the strategic vehicles can overclaim participation costs so as to conduct market manipulation. Without the fairness provision, vehicles can deliberately abort the assigned tasks without any punishments, and UAVs can refuse to pay by the end, causing an exchange dilemma. Lastly, the strategy-proofness and fairness provision typically require transparent payment/task results exchange under public audit, which may disclose sensitive information of vehicles and make the privacy preservation a foremost issue. To achieve the three design goals, we propose SEAL, an integrated framework to address Strategy-proof, fair, and privacy-prEserving UAV computation offLoading. SEAL deploys a strategy-proof reverse combinatorial auction mechanism to optimize UAVs’ task offloading under practical constraints while ensuring economic-robustness and polynomial-time efficiency. Based on smart contracts and hashchain micropayment, SEAL implements a fair on-chain exchange protocol to realize the atomic completion of batch payments and computing results in multi-round auctions. In addition, a privacy-preserving off-chain auction protocol is devised with the assistance of the trusted processor to efficiently protect vehicles’ bid privacy. Using rigorous theoretical analysis and extensive simulations, we validate that SEAL can effectively prevent vehicles from manipulating, ensure privacy protection and fairness, improve the offloading efficiency, and reduce UAV’s energy costs and expenses with low overheads. Yuntao Wang 0004, Zhou Su 0001, Tom H. Luan, Qichao Xu, Ruidong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Swapping-Based Entanglement Routing Design for Congestion Mitigation in Quantum NetworksabstractThe quantum network is designed to connect numerous quantum nodes and support various ground-breaking quantum applications. Most of these applications require communicating parties to share entangled pairs. Therefore, entanglement routing, a technology distributing entangled pairs between distant quantum nodes, plays a vital role in realizing quantum networks’ capability. However, due to the limitation of quantum memory size and quantum decoherence, the entangled pairs shared by adjacent quantum nodes can hardly satisfy concurrent entanglement routing requests, thus leading to severe network congestion. In this paper, we propose a novel congestion mitigation (CM) scheme to tackle such bottleneck problems. The basic idea of CM is to “recycle” idle link-level entanglement resources from well-resourced links to bottleneck links utilizing a unique enabling technology of quantum networks, called entanglement swapping. CM can increase the capacity of each bottleneck link, thus overcoming resource limitations to improve resource utilization and network throughput. To complete our work, we also propose a swapping-based entanglement routing design, including path selection and resource allocation algorithms. Extensive simulations show that our design can significantly alleviate network congestion and improve the request service rate of quantum networks compared to the traditional entanglement routing designs. Zhonghui Li, Jian Li 0031, Kaiping Xue, David S. L. Wei, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2023 | A Multivariate KPIs Anomaly Detection Framework With Dynamic Balancing Loss TrainingabstractAnomaly detection on multivariate KPIs (Key Performance Indicators, such as CPU utilization, sockets status, and HTTP requests per second) is of utmost importance to the systems’ reliability. Unsupervised methods have been of considerable interests and have significantly progressed due to their superior effectiveness. However, the state-of-art unsupervised anomaly detection methods still suffer from high false or missed alarm rates. To this end, in this paper, we propose MM, a practicalMultivariate KPIs anomaly detection framework following the principles ofMulti-task learning with the proposed dynamic balancing loss function. To capture KPIs’ characteristics to the most extent, we simultaneously train multiple sequential autoencoders with different connections based on a designed semi-Random Connection Recurrent Neural Network (sRC-RNN). These autoencoders can be treated as different reconstruction tasks while training. Furthermore, we propose a dynamic loss function to adaptively balance the tasks’ weights. Extensive experiments show that MM outperforms the state-of-art unsupervised multivariate KPIs anomaly detection algorithms and achieves an average F1-score of 0.95 on two public machine-level KPIs datasets and 0.96 on an internal container-level KPIs dataset. Biao Han 0003, Ruidong Li 0001, Jinshu Su |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Achieving Flexible and Lightweight Multipath Congestion Control Through Online LearningabstractThe upgrade of network devices to be equipped with multiple network interfaces makes it possible to improve network throughput performance through multipath transmission protocols, especially multipath TCP (MPTCP). However, so far the mostly used MPTCP protocols have a common limitation, namely the rigid and conservative method. They have been designed with little consideration of the fact that real networks are dynamic and the network status changes frequently, thus leading to the poor performance of current MPTCP in many realistic scenarios. In this paper, we propose a lightweight multipath congestion control algorithm based on online learning, named MP-OL. MP-OL models congestion control as a multi-armed bandit problem, and adjusts the sending rate of each subflow flexibly and adaptively through online learning. Therefore, MP-OL possesses the capability of suiting various network scenarios, and can achieve fairness and high performance in dynamic network environment. It can also flexibly switch between online learning and traditional method, which reduces the computational complexity while ensuring the learning efficiency, thus making MP-OL easy to deploy and use. As the experimental results demonstrated, compared with the leading MPTCP variants, MP-OL achieves significant improvements in fairness and link utilization, and shows better resilience to non-congestion loss and better adaptability to unstable network conditions. In real networks, MP-OL also obtains better throughput performance. Rui Zhuang, Jiangping Han, Kaiping Xue, Jian Li 0031, David S. L. Wei, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | A Secure and Intelligent Data Sharing Scheme for UAV-Assisted Disaster RescueabstractUnmanned aerial vehicles (UAVs) have the potential to establish flexible and reliable emergency networks in disaster sites when terrestrial communication infrastructures go down. Nevertheless, potential security threats may occur on UAVs during data transmissions due to the untrusted environment and open-access UAV networks. Moreover, UAVs typically have limited battery and computation capacity, making them unaffordable for heavy security provisioning operations when performing complicated rescue tasks. In this paper, we develop RescueChain, a secure and efficient information sharing scheme for UAV-assisted disaster rescue. Specifically, we first implement a lightweight blockchain-based framework to safeguard data sharing under disasters and immutably trace misbehaving entities. A reputation-based consensus protocol is devised to adapt the weakly connected environment with improved consensus efficiency and promoted UAVs’ honest behaviors. Furthermore, we introduce a novel vehicular fog computing (VFC)-based off-chain mechanism by leveraging ground vehicles as moving fog nodes to offload UAVs’ heavy data processing and storage tasks. To offload computational tasks from the UAVs to ground vehicles with idle computing resources, an optimal allocation strategy is developed by choosing payoffs that achieve equilibrium in a Stackelberg game formulation of the allocation problem. For lack of sufficient knowledge on network model parameters and users’ private cost parameters in practical environment, we also design a two-tier deep reinforcement learning-based algorithm to seek the optimal payment and resource strategies of UAVs and vehicles with improved learning efficiency. Simulation results show that RescueChain can effectively accelerate consensus process, improve offloading efficiency, reduce energy consumption, and enhance user payoffs. Yuntao Wang 0004, Zhou Su 0001, Qichao Xu, Ruidong Li 0001, Tom H. Luan, Pinghui Wang |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | EdAR: An Experience-Driven Multipath Scheduler for Seamless Handoff in Mobile NetworksabstractMultipath TCP (MPTCP) improves the bandwidth utilization in wireless network scenarios, since it can simultaneously utilize multiple interfaces for data transmission. However, with the fast growth of mobile devices and applications, link interruptions caused by handoffs still lead to drastic performance degradation in such scenarios. Typically, a series of packet losses on part of the links will block the transmission of the entire connection when handoff occurs. This paper proposes an Experience-driven Adaptive Redundant packet scheduler (EdAR) for MPTCP, aiming at achieving seamless handoffs in mobile networks. EdAR enables flexibly scheduling redundant packets with an experience-driven learning-based approach in the face of drastic network environment changes for multipath performance enhancement. To enable accurate learning and prediction, both the network environment and the best course of actions are jointly learned via a Deep Reinforcement Learning (DRL) agent, which we design with a hybrid structure to deal with the complexity of system states. Furthermore, both offline and online learning are utilized to allow the agent to adapt to different and changing network environments. Evaluation results show that EdAR outperforms the state-of-the-art MPTCP schedulers in most network scenarios. Specifically in mobile networks with frequent handoffs, EdAR brings$2\times $improvement in terms of the overall goodput. Jiangping Han, Kaiping Xue, Jian Li 0031, Rui Zhuang, Ruidong Li 0001, Ruozhou Yu, Guoliang Xue, Qibin Sun |
IEEE Trans. Wirel. Commun. | 5 |
| 2023 | A Stream-Aware MPQUIC Scheduler for HTTP Traffic in Mobile NetworksabstractA QUIC (Quick UDP Internet Connections) protocol is designed to improve Hypertext Transfer Protocol (HTTP) traffic and carries a non-negligible portion of the traffic in the current Internet. As its extension, Multipath QUIC (MPQUIC) provides higher bandwidth and smoother network handover by using multiple network interfaces simultaneously. However, to improve HTTP traffic, there are still some issues not yet carefully addressed in the existing MPQUIC, and packet scheduling is a vital one among the issues. Specifically, existing methods fail to respond to the stream prioritization of HTTP Version 2 (HTTP/2), leading to unsatisfying web page load performance. Besides, managing asymmetric and dynamic network paths is also a challenging issue, which may result in Head-of-Line (HoL) blocking and excessive buffer usage if not effectively handled. In this paper, we present a stream-aware per-packet scheduler, HoL Blocking Eliminating Scheduler (HBES), to improve the performance of MPQUIC in mobile networks. Firstly, HBES provides a fair allocation of aggregated bandwidth for different streams based on their priority. Then, it keeps stream data arriving at the receiver in order by estimating packet arrival time to mitigate HoL blocking and excessive buffer usage. We implement HBES and evaluate its performance in various network scenarios. Experimental results verify the superiority of HBES in reducing stream completion time and buffer occupation over those existing MPQUIC schedulers. Yitao Xing, Kaiping Xue, Jiangping Han, Jian Li 0031, David S. L. Wei, Ruidong Li 0001, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Wirel. Commun. | 7 |
| 2022 | A Learning-based Honeypot Game for Collaborative Defense in UAV NetworksabstractThe proliferation of unmanned aerial vehicles (UAVs) opens up new opportunities for on-demand service provisioning anywhere and anytime, but it also exposes UAVs to various cyber threats. Low/medium-interaction honeypot is regarded as a promising lightweight defense to actively protect mobile Internet of things, especially UAV networks. Existing works primarily focused on honeypot design and attack pattern recognition, the incentive issue for motivating UAVs' participation (e.g., sharing trapped attack data in honeypots) to collaboratively resist distributed and sophisticated attacks is still under-explored. This paper proposes a novel game-based collaborative defense approach to address optimal, fair, and feasible incentive mechanism design, in the pres-ence of network dynamics and UAVs' multi-dimensional private information (e.g., valid defense data (VDD) volume, communication delay, and UAV cost). Specifically, we first develop a honeypot game between UAVs under both partial and complete information asymmetry scenarios. We then devise a contract-theoretic method to solve the optimal VDD-reward contract design problem with partial information asymmetry, while ensuring truthfulness, fair-ness, and computational efficiency. Furthermore, under complete information asymmetry, we devise a reinforcement learning based distributed method to dynamically design optimal contracts for distinct types of UAVs in the fast-changing network. Experimental simulations show that the proposed scheme can motivate UAV's collaboration in VDD sharing and enhance defensive effectiveness, compared with existing solutions. Yuntao Wang 0004, Zhou Su 0001, Abderrahim Benslimane, Qichao Xu, Minghui Dai, Ruidong Li 0001 |
GLOBECOM | 6 |
| 2022 | An Adversarial Learning-based Tor Malware Traffic Detection ModelabstractAttackers often use Tor to launch cyberattacks and conduct illegal transactions, threatening cyberspace's security and people's daily lives. Existing methods for malware traffic detection on Tor can be classified as rule-based and network-based, both of which apply machine learning extensively. Tor malware traffic detection systems are often deployed in open network environments. Their machine learning systems are the first to be attacked by adversarial samples. To ensure that Tor is not abused, this paper proposes an Adversarial Learning-based Tor Malware Traffic Detection model, AL-TMTD. We generate realistic attack samples that can evade detection and use these samples to produce an augmented training set for producing hardened detectors. In such a way, we obtain a more resilient Tor malware traffic detection model that achieves adversarial robustness. We validate our proposal through an extensive experimental campaign that considers multiple machine learning algorithms and shadow models. We simulate the adversary to construct functionally approximate shadow models through black-box model extraction and generate adversarial samples to validate the adversarial robustness of our proposed AL-TMTD model. Our experimental results demonstrate that the average accuracy of AL-TMTD after the adversarial retraining is as high as 0.995 in detecting adversarial samples, which is 0.314 without the adversarial retraining, a significant improvement. Xiaoyan Hu 0007, Yishu Gao, Guang Cheng 0001, Hua Wu 0004, Ruidong Li 0001 |
GLOBECOM | 5 |
| 2022 | Towards Accurate DGA Detection based on Siamese Network with Insufficient Training SamplesabstractDomain Generation Algorithms (DGAs) are widely applied in diversified malicious attack patterns such as botnets. Attacks utilize DGAs to dynamically create pseudorandom domains to evade security detection and successfully connect bots with Command and Controls (C&C) servers. The detection of Algorithmically Generated Domains (AGDs) plays an essential role in network attack detection. Most of the existing DGA detectors are machine learning or deep learning-based methods. However, these DGA detectors perform relatively poorly with insufficient training samples, such as small-scale DGA families and emerging DGA variants. Besides, machine learning-based detectors require sophisticated and time-consuming artificial feature extraction, and attackers can circumvent the extracted features. This paper focuses on accurately detecting DGAs based on siamese network with insufficient training samples. Our proposed DGA detection method is referred to as DGAD-SN. DGAD-SN first introduces contrastive learning and adopts the siamese network framework to construct the feature extractor, which excavates the implicit relationship information between characters in the domain name strings using limited training samples. Then machine learning-based DGA classifiers are trained based on the extracted neural feature vectors of domain names to identify AGDs. Our experimental studies suggest that DGAD-SN can efficiently extract distinguishable neural feature vectors for domain names and outperforms state-of-the-art DGA detectors in identifying small-scale DGA families or emerging DGA variants. Its average accuracy is 10%−15% higher than conventional machine learning-based detection methods and about 1%−2% higher than deep learning-based detection methods using limited training samples. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
ICC | 4 |
| 2022 | UAVs Assisted Secure Blockchain Offline Transactions for V2V Charging Among Electric Vehicles in Disaster AreaabstractThe security of distributed communications in UAV rescue networks is promising to be provisioned by blockchain technology. However, due to high mobility, distributed UAVs cannot timely connect to the backbone to synchronize blocks, which can result in severe security issues (such as Forged deposit address and Double spend attack). These issues has been neglected in literature. This paper proposes a UAVs assisted and incentive based blockchain offline transaction scheme to address the above issues when UAVs and ground users are offline. Particularly, we consider vehicle-to-vehicle (V2V) charging transactions in disaster areas. First, we built an offline channel between charging and discharging electric vehicles (EVs), and then, we design an accountable assertions based UAVs aided penalty algorithm to prevent various attacks. Then, considering selfishness of users, we formulate an incentive model based on Stackelberg game to encourage EVs to participate to the offline V2V charging transactions. Our simulation results demonstrate that our proposed scheme obtain the optimal utilities for EVs, which outperforms the conventional schemes. Rui Xing 0001, Zhou Su 0001, Tom H. Luan, Qichao Xu, Yuntao Wang 0004, Ruidong Li 0001, Abderrahim Benslimane |
ICC | 6 |
| 2022 | User-centric In-network Caching Mechanism for Off-chain Storage with BlockchainabstractOff-chain storage is utilized to reduce on-chain storage costs, and further enhance the scalability of blockchain technology. For such mechanisms, transaction data of large size is stored in external centralized databases or distributed peer-to-peer storage, instead of blockchain nodes themselves. However, in emerging blockchain application areas, such as healthcare and the Internet of Things (IoT), off-chain data should be located close to the users with the right privileges, yet it is currently challenging to locate data close to such users and limit data transfers accordingly. To meet these challenges, we design a user-centric in-network caching mechanism for off-chain storage (UCINC) with information-centric networking (ICN) approach to regulate the data caching to the off-chain storage in the network where users are located. With UCINC, data is cached at off-chain storage based on location attributes, retrieved through the interest/data ICN paradigm, and users’ access privileges are determined based on their attributes including locations. We furthermore conduct simulation experiments to confirm that the proposed UCINC achieves higher download performance and traffic efficiency, compared with the existing off-chain storage mechanisms. Hiroaki Yamanaka, Yuuichi Teranishi, Yusaku Hayamizu, Atsushi Ooka, Kazuhisa Matsuzono, Ruidong Li 0001, Hitoshi Asaeda |
ICC | 6 |
| 2022 | ScalaCert: Scalability-Oriented PKI with Redactable Consortium Blockchain Enabled "On-Cert" Certificate RevocationabstractAs the voucher for identity, digital certificates and the public key infrastructure (PKI) system have always played a vital role to provide the authentication services. In recent years, with the increase in attacks on traditional centralized PKIs and the extensive deployment of blockchains, researchers have tried to establish blockchain-based secure decentralized PKIs and have made significant progress. Although blockchain enhances security, it brings new problems in scalability due to the inherent limitations of blockchain’s data structure and consensus mechanism, which become much severe for the massive access in the era of 5G and B5G. In this paper, we propose ScalaCert to mitigate the scalability problems of blockchain-based PKIs by utilizing redactable blockchain for "on-cert" revocation. Specifically, we utilize the redactable blockchain to record revocation information directly on the original certificate ("on-cert") and remove additional data structures such as CRL, significantly reducing storage overhead. Moreover, the combination of redactable and consortium blockchains brings a new kind of attack called deception of versions (DoV) attack. To defend against it, we design a random-block-node-check (RBNC) based freshness check mechanism. Security and performance analyses show that ScalaCert has sufficient security and effectively solves the scalability problem of the blockchain-based PKI system. Kaiping Xue, Qiantong Jiang, Ruidong Li 0001, David S. L. Wei |
ICDCS | 5 |
| 2022 | Collaborative Computation Offloading for UAVs and USV Fleets in Communication NetworksabstractUnmanned aerial vehicles (UAVs) empowered with artificial intelligence (AI) have become a new paradigm for marine monitoring and disaster rescue. In AI-enabled UAV applications, UAVs generate amounts of computation-intensive tasks (e.g., image recognition, video processing, and path planning, etc.) that cannot be locally executed by UAVs in time. How to offload the computation-intensive tasks of UAVs timely and effectively has become an urgent challenge. Multiple unmanned surface vehicles (USVs) integrated into a USV fleet is appealingly advocated to provide abundant computation resources for computation tasks. In this paper, we propose a collaborative computation offloading scheme with UAVs and USV fleets in maritime communication networks. Specifically, we first propose a collaborative computation offloading framework, where UAVs act as the requesters of computation offloading, and USV fleets are the assistants. Then, to minimize the overall execution time of computation tasks, UAVs determine the optimal ratio of compu-tation tasks offloaded to USV fleets in the worst case. Afterwards, the first sealed reverse auction with reserve price is utilized to incentivize USV fleets to assist in executing computation tasks of UAVs, where the reserve price guarantees the satisfied benefits of UAVs. Simulation results demonstrate that the proposed scheme reduces the overall execution time and improves the expected revenue of the USV fleet as compared to conventional schemes. Ruidong Li 0001, Zhou Su 0001, Qichao Xu, Yuntao Wang 0004, Minghui Dai, Tom H. Luan, Xin Sun 0011, Donglan Liu |
IWCMC | 2 |
| 2022 | ACCeSS: Adaptive QoS-aware Congestion Control for Multipath TCPabstractMultipath TCP (MPTCP) enables multi-home devices to establish multiple paths for simultaneous data transmission. However, due to diverse Quality of Service (QoS) requirements in real network, existing multipath congestion control algorithms (CCAs) fail to fast adapt to dynamic traffic, which leads to performance degradation, especially in heterogeneous network environments. To tackle these problems, in this paper, we first observe the performance limitations of current multipath CCAs by conducting extensive experiments. Then we propose ACCeSS, an adaptive QoS-aware multipath congestion control framework, which is able to promptly adapt to network changes and QoS requirements with a novel control policy optimization phase. In order to adjust and stimulate improvement of the preferred performance metric, ACCeSS exploits Random Forest Regressing (RFR) method to perform QoS-specific utility function optimization. ACCeSS is implemented and compared with other multipath CCAs in Linux kernel. Performances of ACCeSS are evaluated in both emulated and real-world networks, which reveal that ACCeSS outperforms classic multipath CCAs and the state-of-the-art learning based multipath CCA with better adaptive capability of QoS. Xiaolan Ji, Biao Han 0003, Ruidong Li 0001, Cao Xu, Jinshu Su |
IWQoS | 3 |
| 2022 | Identifying Ethereum traffic based on an active node library and DEVp2p features
Xiaoyan Hu 0007, Zhongqi Tong, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004 |
Future Gener. Comput. Syst. | 6 |
| 2022 | Guest Editorial Special Issue on Sustainable Solutions for the Internet of ThingsabstractAn Analysis of many IoT deployments showed that most of them can address the sustainable development goals (SDGs) and the UN’s 2030 agenda. Interestingly, most of these projects concentrate on five SDGs: 1) industry, innovation, infrastructure; 2) smart cities and communities; 3) affordable and clean energy; 4) good health and well-being; and 5) responsible production and consumption. Examples include a remote water-monitoring solution that ensures clean water in regions with an indigenous population and smart lighting initiatives in Chinese cities that halve total power output. Pietro Manzoni, Ruidong Li 0001, Marco Zennaro, Silvia M. Figueira |
IEEE Internet Things J. | 2 |
| 2022 | An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking
Xuanbo Huang, Kaiping Xue, Yitao Xing, Dingwen Hu, Ruidong Li 0001, Qibin Sun |
J. Comput. Sci. Technol. | 5 |
| 2022 | A Heuristic Remote Entanglement Distribution Algorithm on Memory-Limited Quantum PathsabstractRemote entanglement distribution plays a crucial role in large-scale quantum networks, and the key enabler for entanglement distribution is quantum routers (or repeaters) that can extend the entanglement transmission distance. However, the performance of quantum routers is far from perfect yet. Amongst the causes, the limited quantum memories in quantum routers largely affect the rate and efficiency of entanglement distribution. To overcome this challenge, this paper presents a new modeling for the maximization of entanglement distribution rate (EDR) on a memory-limited path, which is then transformed into entanglement generation and swapping sub-problems. We propose a greedy algorithm for short-distance entanglement generation so that the quantum memories can be efficiently used. As for the entanglement swapping sub-problem, we model it using an Entanglement Graph (EG), whose solution is yet found to be at least NP-complete. In light of it, we propose a heuristic algorithm by dividing the original EG into several sub-problems, each of which can be solved using dynamic programming (DP) in polynomial time. By conducting simulations, the results show that our proposed scheme can achieve a high EDR, and the developed algorithm has a polynomial-time upper bound and reasonable average runtime complexity. Lutong Chen, Kaiping Xue, Jian Li 0031, Nenghai Yu, Ruidong Li 0001, Jianqing Liu, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Commun. | 5 |
| 2022 | Fidelity-Guaranteed Entanglement Routing in Quantum NetworksabstractEntanglement routing establishes remote entanglement connection between two arbitrary nodes, which is one of the most important functions in quantum networks. The existing routing mechanisms mainly improve the robustness and throughput facing the failure of entanglement generations, which, however, rarely include the considerations on the most important metric to evaluate the quality of connection, entanglement fidelity. To solve this problem, we propose purification-enabled entanglement routing designs to provide fidelity guarantee for multiple Source-Destination (S-D) pairs in quantum networks. In our proposal, we first consider the single S-D pair scenario and design an iterative routing algorithm, Q-PATH, to find the optimal purification decisions along the routing path with minimum entangled pair cost. Further, a low-complexity routing algorithm using an extended Dijkstra algorithm, Q-LEAP, is designed to reduce the computational complexity by using a simple but effective purification decision method. Finally, we consider the common scenario with multiple S-D pairs and design a greedy-based algorithm considering resource allocation and re-routing process for multiple routing requests. Simulation results show that the proposed algorithms not only can provide fidelity-guaranteed routing solutions, but also has superior performance in terms of throughput, fidelity of end-to-end entanglement connection, and resource utilization ratio, compared with the existing routing scheme. Jian Li 0031, Kaiping Xue, Ruidong Li 0001, Nenghai Yu, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Commun. | 4 |
| 2022 | Green Parallel Online Offloading for DSCI-Type Tasks in IoT-Edge SystemsabstractIn order to meet people’s demands for intelligent and user-friendly Internet of Things (IoT) services, the amount of computation is increasing rapidly and the requirements of task delay are becoming increasingly more stringent. However, the constrained battery capacity of IoT devices greatly limits the user experience. Energy harvesting technologies enable green energy to provide continuous energy support for devices in the IoT environment. Together with the maturity of the mobile edge computing technology and the development of parallel computing, it provides a strong guarantee for the normal operation of resource-constrained IoT devices. In this article, we design a parallel offloading strategy based on Lyapunov optimization, which is conducive to efficiently finding the optimal decision for delay-sensitive and compute-intensive tasks. We establish a stochastic optimization problem on a discrete-time slot system and propose a green parallel online offloading algorithm (GPOOA). By decoupling the target problem three times, the joint optimization of green energy, task division factor, CPU frequency, and transmission power is realized. Experimental results demonstrate that under the constraints of strict task deadlines and limited server computing resources, GPOOA performs well in terms of system cost and task drop ratio, far superior to several existing offloading algorithms. Junqi Chen 0003, Huaming Wu, Ruidong Li 0001, Pengfei Jiao |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Security and Privacy-Enhanced Federated Learning for Anomaly Detection in IoT InfrastructuresabstractInternet of Things (IoT) anomaly detection is significant due to its fundamental roles of securing modern critical infrastructures, such as falsified data injection detection and transmission line faults diagnostic in smart grids. Researchers have proposed various detection methods fostered by machine learning (ML) techniques. Federated learning (FL), as a promising distributed ML paradigm, has been employed recently to improve detection performance due to its advantages of privacy-preserving and lower latency. However, existing FL-based methods still suffer from efficiency, robustness, and security challenges. To address these problems, in this article, we initially introduce a blockchain-empowered decentralized and asynchronous FL framework for anomaly detection in IoT systems, which ensures data integrity and prevents single-point failure while improving the efficiency. Further, we design an improved differentially private FL based on generative adversarial nets, aiming to optimize data utility throughout the training process. To the best of our knowledge, it is the first system to employ a decentralized FL approach with privacy-preserving for IoT anomaly detection. Simulation results on the real-world dataset demonstrate the superior performance from aspects of robustness, accuracy, and fast convergence while maintaining high level of privacy and security protection. Lei Cui 0006, Youyang Qu, Gang Xie 0001, Deze Zeng, Ruidong Li 0001, Shigen Shen, Shui Yu 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | ChainFL: A Simulation Platform for Joint Federated Learning and Blockchain in Edge/Cloud Computing EnvironmentsabstractAs a distributed computing paradigm, edge computing has become a key technology for providing timely services to mobile devices by connecting Internet of Things (IoT), cloud centers, and other facilities. By offloading compute-intensive tasks from IoT devices to edge/cloud servers, the communication and computation pressure caused by the massive data in Industrial IoT can be effectively reduced. In the process of computation offloading in edge computing, it is critical to dynamically make optimal offloading decisions to minimize the delay and energy consumption spent on the devices. Although there are a large number of task offloading-decision models, how to measure and evaluate the quality of different models and configurations is crucial. In this article, we propose a novel simulation platform named ChainFL, which can build an edge computing environment among IoT devices while being compatible with federated learning and blockchain technologies to better support the embedding of security-focused offloading algorithms. ChainFL is lightweight and compatible, and it can quickly build complex network environments by connecting devices of different architectures. Moreover, due to its distributed nature, ChainFL can also be deployed as a federated learning platform across multiple devices to enable federated learning with high security due to its embedded blockchain. Finally, we validate the versatility and effectiveness of ChainFL by embedding a complex offloading-decision model in the platform, and deploying it in an Industrial IoT environment with security risks. Guanjin Qu, Naichuan Cui, Huaming Wu, Ruidong Li 0001, Yuemin Ding |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Joint Channel Allocation and Data Delivery for UAV-Assisted Cooperative Transportation Communications in Post-Disaster NetworksabstractAs the natural disasters may destroy the ground communication infrastructures for the transportation systems, the communication relief in post-disaster networks is more crucial to reduce risk loss. The growing application of unmanned aerial vehicles (UAVs) holds great potential for disaster communication relief due to its flexibility and functionalities. In this paper, we investigate the channel allocation and data delivery problems for UAV-assisted cooperative transportation communications in post-disaster networks to provide communication and data delivery services for affected users. Specifically, we first introduce the UAV-assisted communication relief system, in which UAVs equipped with the communication and caching functionalities are deployed as the aerial base stations in post-disaster regions. Then, we propose the channel allocation scheme between UAVs and users by taking the interferences into consideration, and obtain the channel allocation strategy to improve the network throughput. Based on the optimal channel allocation strategy, users can deliver their data to UAVs for backup. Next, we propose the data delivery scheme to cope with the pricing problem for UAVs and the data delivery strategy for users to improve the efficiency of data delivery, with the objective of maximizing the utilities of both UAVs and users. The optimal strategy for both UAVs and users are derived according to the analysis of Stackelberg game. Finally, we conduct simulations to evaluate the performance of the proposed channel allocation and data delivery scheme, and the numerical results demonstrate that the proposed scheme can significantly improve the efficiency and effectiveness of channel allocation and data delivery in post-disaster networks, compared with benchmark schemes. Minghui Dai, Tom H. Luan, Zhou Su 0001, Ning Zhang 0007, Qichao Xu, Ruidong Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Joint Computation Offloading and Resource Allocation Under Task-Overflowed Situations in Mobile-Edge ComputingabstractWith the rapid development of Artificial Intelligence (AI) and Internet of Things (IoT), we have to perform increasingly more resource-hungry and compute-intensive applications on IoT devices, where the available computing resources are insufficient. With the assistance of Mobile Edge Computing (MEC), offloading partial complex tasks from mobile devices to edge servers can achieve faster response time and lower energy consumption. However, it still suffers from finding the optimal offloading decision when the total amount of computations overflows the available computing resources in MEC systems. In this paper, we establish a multi-user and multi-task MEC model and design an offloading indicator, through which we analyze what the current environment belongs to. In the cases where the computational resources of devices are sufficient or partially sufficient, we utilize the relationship between the offloading indicator and the cost incurred by the tasks that are executed in the current workflow to find the optimal offloading decision. In the cases where the computation on local and edge are both insufficient, we propose a novel Offloading Algorithm based on K-means clustering and Genetic algorithm for solving Multiple knapsack problem (OAKGM), aiming not only to jointly optimize the time and energy incurred by the tasks that are executed in the current workflow, but also to penalize the overflowed computations so that the task pressure in the next workflow can be greatly reduced. In addition, a simplified Offloading Algorithm based on Multiple Knapsack Problem (OAMKP) is proposed to further cope with the environments with a large number of users or tasks. Experimental results demonstrate the effectiveness and superiority of the proposed algorithms when compared with several benchmark offloading algorithms, which can better exploit the computing capacities of IoT devices and the edge server, greatly avoid resource occupation in edge nodes and make sustainable MEC possible. Huijun Tang, Huaming Wu, Yubin Zhao, Ruidong Li 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | Task Offloading for Post-Disaster Rescue in Unmanned Aerial Vehicles NetworksabstractNatural disasters often cause huge and unpredictable losses to human lives and properties. In such an emergency post-disaster rescue situation, unmanned aerial vehicles (UAVs) are effective tools to enter the damaged areas to perform immediate disaster recovery missions, owing to their flexible mobilities and fast deployment. However, UAVs typically have very limited battery and computational capacities, which makes them harder to perform heavy computation tasks during the complicated disaster recovery process. This paper addresses the issue of the battery and computation resource limitation with a fog computing based UAV system. Specifically, we first introduce the vehicular fog computing (VFC) system in which the unmanned ground vehicles (UGVs) perform the computation tasks offloaded from UAVs. To avoid the transmission competitions yet enable cooperations among UAVs and UGVs, a stable matching algorithm is developed to transform the computation task offloading problem into a two-sided matching problem. An iterative algorithm is then developed which matches each UAV with the most suitable UGV for offloading. Finally, extensive simulations are carried out to demonstrate that the proposed scheme can effectively improve utilities of UAVs and reduce average delay through comparison with conventional schemes. Yuntao Wang 0004, Weiwei Chen 0007, Tom H. Luan, Zhou Su 0001, Qichao Xu, Ruidong Li 0001, Nan Chen 0006 |
IEEE/ACM Trans. Netw. | 6 |
| 2022 | Resource Orchestration of Cloud-Edge-based Smart Grid Fault DetectionabstractReal-time smart grid monitoring is critical to enhancing resiliency and operational efficiency of power equipment. Cloud-based and edge-based fault detection systems integrating deep learning have been proposed recently to monitor the grid in real time. However, state-of-the-art cloud-based detection may require uploading a large amount of data and suffer from long network delay, while edge-based schemes do not adequately consider the detection requirement and thus cannot provide flexible and optimal performance. To solve these problems, we study a cloud-edge based hybrid smart grid fault detection system. Embedded devices are placed at the edge of the monitored equipment with several lightweight neural networks for fault detection. Considering limited communication resources, relatively low computation capabilities of edge devices, and different monitoring accuracies supported by these neural networks, we design an optimal communication and computational resource allocation method for this cloud-edge based smart grid fault detection system. Our method can maximize the processing throughput of the system and improve resource utilization while satisfying the data transmission and processing latency requirements. Extensive simulations are conducted and the results show the superiority of the proposed scheme over comparison schemes. We have also prototyped this system and verified its feasibility and performance in real-world scenarios. Jie Li 0015, Yuxing Deng, Wei Sun 0011, Ruidong Li 0001, Qiyue Li 0001, Zhi Liu 0002 |
ACM Trans. Sens. Networks | 5 |
| 2021 | A Deep Reinforcement Learning-based Routing Scheme with Two Modes for Dynamic NetworksabstractWith the development of communication and transmission technologies, more and more applications, like Internet of vehicles and tele-medicine, become more sensitive to network latency and accuracy, which requires routing schemes to be more efficient. In order to meet such urgent need, learning-based routing strategies emerges, with the advantages of high flexibility and accuracy. These strategies can be divided into two categories, centralized and distributed, enjoying the advantages of high precision and high efficiency, respectively. However, routing become more complex in dynamic network, where the link connections and access states are time-varying, so these learning-based routing mechanisms are required to be able to adapt to network changes in real time. In this paper, we designed and implemented both two of centralized and distributed reinforcement learning-based routing schemes (RLR-T). By conducting a series of experiments, we deeply analyzed the results and gave the conclusion that the centralized is better to cope with dynamic networks due to its faster reconvergence, while the distributed is better to handle with large-scale networks by its high scalability. Peizhuang Cong, Yuchao Zhang 0004, Wendong Wang 0003, Ke Xu 0002, Ruidong Li 0001, Fuliang Li |
ICC | 5 |
| 2021 | FSCC: Flexible Smart Contract Interaction with Access Control for BlockchainabstractSmart contract (SC) is a user-defined program code over blockchain, which holds the characteristics of immutability and auditability without requiring trust third party and is crucial to provide in-network computation for green applications. Herein we investigate the interactions among the SCs, where the functions defined in one SC are called by another one. The existing work, Ethereum name service (ENS), provides a method to map human-readable names to machine-readable addresses. However, it still suffers the problems induced from the ossification of SC, such as no mechanism to call functions in a non-existing SC, to update SC, to acquire the SC information (e.g. contract application binary interface and address), and to achieve access control. To solve these problems, we propose a flexible smart contract interaction framework with access control (FSCC), where SC name and information are separately stored at blockchain and the distributed off-chain storage to reduce on-chain storage overhead. With the FSCC, interactions with non-existing SC, update of SC, and access control of SC can be achieved. Furthermore, performance evaluations show that on-chain storage overhead can be greatly reduced with keeping the communication delay at a low level. Ruidong Li 0001, Hitoshi Asaeda |
ICC | 1 |
| 2021 | Game Theoretical Secure Bandwidth Allocation in UAV-assisted Heterogeneous NetworksabstractRecently, unmanned aerial vehicles (UAVs) have been employed to provide wireless communication services, which promotes the emergence of promising UAV-assisted heteroge-neous networks (UHetNets). However, due to the ever-increasing amount of data traffic and diverse wireless service demands of mobile users, it is challenging to efficiently allocate limited secure bandwidth for safe communication. To tackle this problem, in this paper, we propose a game theoretical secure bandwidth allocation scheme in UHetNets. Specifically, we first design a UAV-assisted bandwidth allocation framework, where each UAV as a flying base station reuses the secure spectrum to enhance the utilization rate of wireless resource. To allocate the restricted secure band-width, we further introduce the utility functions of both UAVs and mobile users, based on the real-time bandwidth capacity of each UAV and the demand of each mobile user. Stackelberg game is then utilized to model the dynamic interactions between UAVs and mobile users. Afterwards, we devise a gradient descent based optimal decision searching algorithm to achieve the Stackelberg equilibrium. The simulation results, at last, show the effectiveness of the proposed scheme to improve the utilities of both mobile users and UAVs. Qichao Xu, Zhou Su 0001, Ruidong Li 0001, Koichi Asatani, Dongfeng Fang |
ICC | 3 |
| 2021 | Lifesaving with RescueChain: Energy-Efficient and Partition-Tolerant Blockchain Based Secure Information Sharing for UAV-Aided Disaster RescueabstractUnmanned aerial vehicles (UAVs) have brought numerous potentials to establish flexible and reliable emergency networks in disaster areas when terrestrial communication infrastructures go down. Nevertheless, potential security threats may occur on UAVs during data transmissions due to the untrustful environment and open-access UAV networking. Moreover, UAVs typically have limited battery and computation capacity, making them unaffordable to execute heavy security provisioning operations when carrying out complicated rescue tasks. In this paper, we develop RescueChain, a secure and efficient information sharing scheme for UAV-aided disaster rescue. Specifically, we first implement a lightweight blockchain-based framework to safeguard data sharing under disasters and immutably trace misbehaving entities. A reputation-based consensus protocol is devised to adapt the weakly connected environment with improved consensus efficiency and promoted UAVs' honest behaviors. Furthermore, we introduce a novel vehicular fog computing based off-chain mechanism by leveraging ground vehicles as moving fog nodes to offload UAVs' heavy data processing and storage tasks. To optimally stimulate vehicles to share their idle computing resources, we also design a two-layer reinforcement learning based incentive algorithm for UAVs and ground vehicles in the highly dynamic networks. Simulation results show that RescueChain can effectively accelerate consensus process, enhance user payoffs, and reduce delivery latency, compared with representative existing approaches. Yuntao Wang 0004, Zhou Su 0001, Qichao Xu, Ruidong Li 0001, Tom H. Luan |
INFOCOM | 4 |
| 2021 | A deep reinforcement learning-based multi-optimality routing scheme for dynamic IoT networks
Peizhuang Cong, Yuchao Zhang 0004, Zheli Liu, Thar Baker, Hissam Tawfik, Wendong Wang 0003, Ke Xu 0002, Ruidong Li 0001, Fuliang Li |
Comput. Networks | 8 |
| 2021 | UAV Enabled Content Distribution for Internet of Connected Vehicles in 5G Heterogeneous NetworksabstractThe increasing development of Internet of Things (IoT) has led to the emergence of Internet of connected vehicles (IoCVs). These vehicles with various functionalities have the potential prospects for improving the quality of experience (QoE) of vehicle users. Moreover, the use of unmanned aerial vehicles (UAVs) in flying networks extends the connectivity and universality of IoT, and these UAVs with caching and communication capacities can support various services. However, due to the heterogeneity of vehicular networks and flying networks, the communication performance and content distribution between UAVs and IoCVs expose new challenges in heterogeneous networks (HetNets). Therefore, in this paper, a novel content distribution mechanism between UAVs and IoCVs is proposed to improve the QoE of vehicle users. Specifically, we first develop a novel content distribution architecture for UAVs and IoCVs in HetNets, where the content is distributed by UAV content providers to IoCVs. Next, we establish an optimization problem of content distribution between UAVs and IoCVs to minimize the transmission delay. In order to stimulate UAVs and IoCVs to join content distribution, the utilities of UAVs and IoCVs are formulated, respectively. Moreover, we design a coalition game between UAVs and IoCVs to determine the optimal strategy of content distribution. Finally, simulation results demonstrate that the proposed mechanism can significantly improve the performance of content distribution compared with the conventional mechanisms. Zhou Su 0001, Minghui Dai, Qichao Xu, Ruidong Li 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | DMRO: A Deep Meta Reinforcement Learning-Based Task Offloading Framework for Edge-Cloud ComputingabstractWith the explosive growth of mobile data and the unprecedented demand for computing power, resource-constrained edge devices cannot effectively meet the requirements of Internet of Things (IoT) applications and Deep Neural Network (DNN) computing. As a distributed computing paradigm, edge offloading that migrates complex tasks from IoT devices to edge-cloud servers can break through the resource limitation of IoT devices, reduce the computing burden and improve the efficiency of task processing. However, the problem of optimal offloading decision-making is NP-hard, traditional optimization methods are difficult to achieve results efficiently. Besides, there are still some shortcomings in existing deep learning methods, e.g., the slow learning speed and the weak adaptability to new environments. To tackle these challenges, we propose a Deep Meta Reinforcement Learning-based Offloading (DMRO) algorithm, which combines multiple parallel DNNs with Q-learning to make fine-grained offloading decisions. By aggregating the perceptive ability of deep learning, the decision-making ability of reinforcement learning, and the rapid environment learning ability of meta-learning, it is possible to quickly and flexibly obtain the optimal offloading strategy from a dynamic environment. We evaluate the effectiveness of DMRO through several simulation experiments, which demonstrate that when compared with traditional Deep Reinforcement Learning (DRL) algorithms, the offloading effect of DMRO can be improved by 17.6%. In addition, the model has strong portability when making real-time offloading decisions, and can fast adapt to a new MEC task environment. Guanjin Qu, Huaming Wu, Ruidong Li 0001, Pengfei Jiao |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | A Low-Latency MPTCP Scheduler for Live Video Streaming in Mobile NetworksabstractIt is a known issue that low-latency communication is hard to achieve when using multiple network interfaces with asymmetric capacity and delay (e.g., LTE and WLAN) simultaneously. A main underlying cause of this issue is that the packets with lower sequence number are stalled on a high-latency path, thus the early arriving packets with higher sequence number become “out-of-order (OFO)” packets. These OFO packets may excessively consume receiver’s buffer, causing long reordering delay and unnecessary packet retransmission. In this paper, we present a novel design of packet scheduling for Multipath TCP (MPTCP), called OverLapped Scheduler (OLS), able to tackle the OFO-packet problem more effectively. OLS can guarantee sufficient throughput on demand of upper layer applications, and utilizes the remaining bandwidth to reduce OFO-packets. To do so, OLS schedules packets according to their arrival time and sends a controlled number of redundant packets to avoid the impact of inaccurate arrival-time estimations due to network jitter. We implement OLS in a Linux kernel, and the experiments show that in asymmetric networks with or without jitter, OLS can effectively reduce OFO-packets and transmission latency while maintaining a sufficient throughput, which makes it fully capable to meet the requirements of applications such as live video streaming. Yitao Xing, Kaiping Xue, Jiangping Han, Jian Li 0031, Jianqing Liu, Ruidong Li 0001 |
IEEE Trans. Wirel. Commun. | 7 |
| 2020 | Security-Aware Resource Sharing in Software Defined Air-Ground Integrated Networks: A Game ApproachabstractTo accommodate the surge of data traffic in unmanned aerial vehicle (UAV) applications, software defined air-ground integrated networks (SD-AGNs) hold great potentials for efficient resource allocation and intelligent security countermeasures for UAVs. In SD-AGNs, virtualized bandwidth, computing and security resources owned by terrestrial mobile edge computing (MEC) nodes can be dynamically allocated to satisfy UAVs' diverse demands in data transmission and security protection. However, with complicated cooperative interactions among MEC nodes and competition among UAVs, it is of great challenge to allocate both the security and wireless resource in SD-AGNs. In this paper, we propose a security-aware resource sharing scheme for UAVs to jointly allocate bandwidth and security resource in SD-AGNs, using a game-theoretic approach. Specifically, we first investigate a software-defined collaborative mechanism to promote resource utilization for MEC nodes through coalition formation and resource sharing within each coalition. Then, a coalitional game model is presented to construct the Nash-stable coalition structure for MEC nodes. Furthermore, by modeling the interactions among UAVs as a non-cooperative game, their optimal demands of wireless and security resource, as well as the Nash equilibrium, are analyzed in the competitive environment. Simulation results show that the proposed scheme can effectively improve resource efficiency and reduce average delay. Yuntao Wang 0004, Zhou Su 0001, Ning Zhang 0007, Abderrahim Benslimane, Ruidong Li 0001, Ying Wang 0059 |
GLOBECOM | 5 |
| 2020 | Towards Network Coding and Request Pipelining Enabled NDN for Big Data TransmissionabstractTwo intrinsic features of Named Data Networking(NDN), in-network caching and multipath communication, offer the potential for fast and reliable big data transmissions via multisource content delivery. Network coding has recently been utilized to achieve efficient multisource content delivery in NDN. On the other hand, request pipelining is essential for efficient multisource content delivery in network coding enabled NDN. However, it is a challenge to simultaneously support network coding and request pipelining in NDN in a cost-effective way. To address this problem, we propose NCP-NDN, a network coding and request pipelining enabled named data networking architecture. NCP-NDN supports reasonably efficient Interest aggregation when enabling request pipelining without undermining the privacy of content retrieval by extending each Interest with a session and generation oriented requester identifier. Besides, NCP-NDN provides consumers with linearly independent blocks while request pipelining is enabled by combining rank-based matching, one forwarding of each block for per requester and face, and recoding the matching cached blocks before replying an Interest. Our experimental studies illustrate that NCP-NDN improves the performance of content delivery and reduces the overhead of big data transmissions as compared to the existing schemes. Xiaoyan Hu 0007, Xiaoyi Song, Shaoqi Zheng, Ruidong Li 0001, Guang Cheng 0001 |
GLOBECOM | 4 |
| 2020 | A Demand and Responsiveness-based Caching Strategy for Network Coding Enabled NDNabstractIn-network caching and multipath forwarding are prominent features of Named Data Networking (NDN). Network coding enabled NDN (NC-NDN) coordinates the in-network caching and multipath forwarding to improve content delivery performance. However, the existing NC-NDN lacks the considerations on the incorporation with caching schemes. It basically adopts the caching scheme of Caching Everything Everywhere (CEE) leading to cache redundancy and unnecessary and frequent cache replacement. On the other hand, the existing caching schemes for native NDN do not make use of the characteristic of network coded Data packets. To address these problems, this paper proposes a demand and responsiveness-based caching strategy specific to NC-NDN to enable cost-effective caching for network coded Data packets. In our proposed caching strategy, the caching decision at a caching node takes into account three factors, its present demand on the network coded Data packets of the requested generation of content, its distance to the original content provider, and its potential responsiveness to the future requests for the same generation based on the number of network coded Data packets locally cached and that would return for the requested generation. It commits to cache network coded Data packets of a generation of content at more valuable nodes along the transmission path. Our experimental studies show that the proposed caching strategy offers high-performance content delivery and reduces the caching overhead as compared to the existing strategies. Xiaoyan Hu 0007, Shaoqi Zheng, Ruidong Li 0001, Guang Cheng 0001 |
GLOBECOM | 4 |
| 2020 | VFC-Based Cooperative UAV Computation Task Offloading for Post-disaster RescueabstractNatural disasters often cause huge and unpredictable losses to human lives and properties. In such an emergency post-disaster rescue situation, unmanned aerial vehicles (UAVs) are effective tools to enter the damaged areas to perform immediate disaster recovery missions, due to their flexible mobilities and fast deployment. However, the UAVs typically have very limited batteries and computational capacities, which make them unable to perform heavy computation tasks during the complicated disaster recovery process. This paper addresses the issue with a fog computing based UAV system. In specific, we first introduce the vehicular fog computing (VFC) system in which the unmanned ground vehicles (UGVs) perform the computation tasks offloaded from UAVs. To resolve the transmission competitions yet enable cooperations among UAVs and UGVs, a stable matching algorithm is developed to transform the computation task offloading problem into a two-sided matching problem. An iterative algorithm is then developed which matches each UAV with the most suitable UGV for offloading. Finally, extensive simulations are carried out to demonstrate that the proposed scheme can effectively improve utilities of UAVs and reduce average delay through comparison with conventional schemes. Weiwei Chen 0007, Zhou Su 0001, Qichao Xu, Tom H. Luan, Ruidong Li 0001 |
INFOCOM | 5 |
| 2020 | FSDM: Fast Recovery Saturation Attack Detection and Mitigation Framework in SDNabstractThe whole Software-Defined Networking (SDN) system might be out of service when the control plane is overloaded by control plane saturation attacks. In this attack, a malicious host can manipulate massive table-miss packets to exhaust the control plane resources. Even though many studies have focused on this problem, systems still suffer from more influenced switches because of centralized mitigation policies, and long recovery delay because of the remaining attack flows. To solve these problems, we propose FSDM, a Fast recovery Saturation attack Detection and Mitigation framework. For detection, FSDM extracts the distribution of Control Channel Occupation Rate (CCOR) to detect the attack and locates the port that attackers come from. For mitigation, with the attacker's location and distributed Mitigation Agents, FSDM adopts different policies to migrate or block attack flows, which influences fewer switches and protects the control plane from resource exhaustion. Besides, to reduce the system recovery delay, FSDM equips a novel functional module called Force_Checking, which enables the whole system to quickly clean up the remaining attack flows and recovery faster. Finally, we conducted extensive experiments, which show that, with the increasing of attack PPS (Packets Per Second), FSDM only suffers a minor recovery delay increase. Compared with traditional methods without cleaning up remaining flows, FSDM saves more than 81% of ping RTT under attack rate ranged from 1000 to 4000 PPS, and successfully reduced the delay of 87% of HTTP requests time under large attack rate ranged from 5000 to 30000 PPS. Xuanbo Huang, Kaiping Xue, Yitao Xing, Dingwen Hu, Ruidong Li 0001, Qibin Sun |
MASS | 5 |
| 2020 | Generative adversarial networks enhanced location privacy in 5G networks
Youyang Qu, Ruidong Li 0001, Xuemeng Zhai, Shui Yu 0001 |
Sci. China Inf. Sci. | 3 |
| 2020 | An on-demand off-path cache exploration based multipath forwarding strategy
Xiaoyan Hu 0007, Shaoqi Zheng, Guoqiang Zhang 0004, Lixia Zhao, Guang Cheng 0001, Ruidong Li 0001 |
Comput. Networks | 7 |
| 2020 | MWBS: An Efficient Many-to-Many Wireless Big Data Delivery SchemeabstractWireless big data raises the demands on the networking schemes to support the efficient group data sharing over heterogeneous wireless technologies, which take many-to-many data delivery as the foundation. Information-centric networking (ICN) approach is a promising networking technology to support big data delivery, which has the potential to establish the harmony between networking and wireless big data sharing. However, the existing ICN schemes have not carefully addressed the many-to-many communications. To address this issue, we propose an efficient and secure many-to-many wireless big data delivery scheme (MWBS) to provide group-based data dissemination and retrieval with name-integrated forwarding. In MWBS, a bi-directional tree is securely constructed for each group through the procedures of group initiation, join, leave, publication, and multi-level inter-zone routing. Especially, Designated Forwarding and Cacheable Nodes (DFCNs) are introduced to act as the roots for the construction of such bi-directional trees. The implementation details of MWBS are provided for function verifications. To effectively deploy MWBS, we investigate the impacts to the MWBS performance from the number and locations of DFCNs, which show that the optimized number of DFCNs can reduce the total traffic cost and the DFCN close to users is preferred to be selected for a group. Finally, simulations are performed to evaluate the performance of MWBS, which show that MWBS can reduce the control packet overhead and the state storage overhead compared to the existing ICN schemes. Ruidong Li 0001, Hitoshi Asaeda |
IEEE Trans. Big Data | 1 |
| 2019 | DIBN: A Decentralized Information-Centric Blockchain NetworkabstractBlockchain is a distributed ledger, characterized by immutability, anonymity and auditability without requiring trust third party. To provide data exchanges to form such ledger, blockchain network enables the dissemination of transactions and blocks to reach the consensus, which mainly consists of attachment strategy and communication strategy. Currently, it is implemented with peer-to-peer overlay network, which, however, suffers from the intrinsic problem of mismatching between traffic flows and underlying network topology. To solve this problem, we employ information-centric networking (ICN) approach to design a decentralized information-centric blockchain network (DIBN), where categories are named to enable the traffic to be decentralized and an any-to-all category dissemination structure (CDS) is established among all the blockchain nodes (BNs) for each category. For the CDS, one BN can efficiently send data to all other BNs aligning the traffic with the underlying network, which overcomes the problem of mismatch. The performance analysis shows that the proposed DIBN can greatly reduce the average path length for data dissemination in blockchain. Ruidong Li 0001, Hitoshi Asaeda |
GLOBECOM | 1 |
| 2018 | Consecutive Caching and Adaptive Retrieval for In-Network Big Data SharingabstractInformation-centric networking (ICN) is a promising paradigm to support in-network big data sharing. However, it suffers from the problem of the segmented cached chunks resulting in low throughput and the large Interest packet overhead (IPO). The existing work cannot address these problems well, largely due to their insufficient considerations on the interplay between caching and data transport mechanisms. Through our experiments, we observe that ICN data chunks are cached in a distributed manner. Based on these observations, we propose consecutive data chunk caching (ConCaching) and adaptive data chunk retrieval (ACUR) to bridge the gap between caching and transport, where intermediate nodes on transmission path only cache the consecutive data chunks, while users can adjust the range of requested data chunks to maximize the throughput. Through the intensive simulations, we show that the proposed mechanisms can achieve better performance, in terms of higher throughput and substantial reduction in IPO compared with the existing pipeline mechanism in ICN. Ruidong Li 0001, Kazuhisa Matsuzono, Hitoshi Asaeda, Xiaoming Fu 0001 |
ICC | 1 |
| 2017 | A Verifiable and Flexible Data Sharing mechanism for Information-Centric IoTabstractIn an Information-Centric Internet of Things (ICIoT) environment for big data sharing, IoT data can be cached throughout the network. Such distributed data caching poses a challenge on flexible authorization and identity verification. For fine-grained data access authorization in a distributed manner, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been identified as a promising approach. However in the existing CP-ABE based scheme, each publisher would need to retrieve the attributes from the centralized server for encrypting data, resulting in high communication overhead. Moreover, valid authorization period and distributed authentication are still not addressed and seamlessly incorporated. In this paper, we propose a Verifiable and Flexible Data Sharing (VFDS) mechanism for ICIoT, which exploits CP-ABE for authorization and Identity-Based Signature (IBS) for the distributed verification of the identities. In VFDS, publishers retrieve the attributes from the nearby cache holders. In addition, the Attribute Manifest (AM) and the Automatic Attribute Update (AAU) realize efficient attribute updates within the distributed caches to achieve valid authorization period. Meanwhile, VFDS provides the public parameters of IBS in local domain, which enables the efficient identity verifications. Our system evaluations show that the VFDS can achieve lower bandwidth cost compared to the existing schemes for both authentication and flexible authorization. Ruidong Li 0001, Hitoshi Asaeda, Jie Li 0002, Xiaoming Fu 0001 |
ICC | 1 |
| 2017 | A Distributed Publisher-Driven Secure Data Sharing Scheme for Information-Centric IoTabstractIn Information-Centric Internet of Things (ICIoT), Internet of Things (IoT) data can be cached throughout a network for close data copy retrievals. Such a distributed data caching environment, however, poses a challenge to flexible authorization in the network. To address this challenge, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) has been identified as a promising approach. However, in the existing CP-ABE scheme, publishers need to retrieve attributes from a centralized server for encrypting data, which leads to high communication overhead. To solve this problem, we incorporate CP-ABE and propose a novel Distributed Publisher-Driven secure data sharing for ICIoT (DPD-ICIoT) to enable only authorized users to retrieve IoT data from distributed cache. In DPD-ICIoT, newly introduced attribute manifest is cached in the network, through which publishers can retrieve the attributes from nearby copy holders instead of a centralized attribute server. In addition, a key chain mechanism is utilized for efficient cryptographic operations, and an automatic attribute self-update mechanism is proposed to enable fast updates of attributes without querying centralized servers. According to the performance evaluation, DPD-ICIoT achieves lower bandwidth cost compared to the existing CP-ABE scheme. Ruidong Li 0001, Hitoshi Asaeda, Jie Li 0002 |
IEEE Internet Things J. | 1 |
| 2014 | A Game Theory Based Vertical Handoff Scheme for Wireless Heterogeneous NetworksabstractNext-generation wireless networks integrate multiple wireless access technologies to provide seamless wireless connectivity for mobile nodes (MNs). When MNs move in wireless heterogeneous networks, they may suffer from the great degradation of received signal strength (RSS) and further quality of services (QoS), if randomly selecting an access point (AP). We address vertical handoff with game theory to enable MNs to trigger the handoff and select an appropriate network from multiple wireless access technologies. On the other hand, the existing vertical handoff schemes lack of jointly considering the behaviors of MNs and APs for approaching the reality. To solve this problem, we propose a repeated game based scheme for vertical handoff. Each sub-game is formulated as a non-cooperative strategic game between a MN and an AP in which the Nash equilibrium is the solution of each strategic game. The proposed repeated game is to optimize the utility functions of the whole network by finding an equilibrium point. We perform the performance analysis, which shows that proposed scheme can achieve better bandwidth utilization and throughput of the network compared to the AP random selection scheme. Jie Li 0002, Ruidong Li 0001, Yusheng Ji |
MSN | 3 |
| 2014 | DataClouds: Enabling Community-Based Data-Centric Services Over the Internet of ThingsabstractThe Internet of Things (IoT) is emerging as one of the major trends for the next evolution of the Internet, where billions of physical objects or things (including but not limited to humans) will be connected over the Internet, and a vast amount of information data will be shared among them. However, the current Internet was built on a host-centric communication model, which was primarily designed for meeting the demand of pair-wise peer-to-peer communications and cannot well accommodate various advanced data-centric services boosted by the IoT in which users care about content and are oblivious to locations where the content is stored. In this paper, we propose a novel architecture for the future Internet based on information-centric networking (ICN), which is called DataClouds, to better accommodate data-centric services. Different from existing ICN-based architectures, we take the sharing nature of data-centric services under the IoT into consideration and introduce logically and physically formed communities as the basic building blocks to construct the network so that data could be more efficiently shared and disseminated among interested users. We also elaborate on several fundamental design challenges for the Internet under this new architecture and show that DataClouds could offer more efficient and flexible solutions than traditional ICN-based architectures. Hao Yue 0001, Linke Guo, Ruidong Li 0001, Hitoshi Asaeda, Yuguang Fang |
IEEE Internet Things J. | 3 |
| 2013 | Design and implementation of a proactive distributed authentication framework (PDAF)abstractWe are designing authentication framework for a regional network with concerns on fast authentication and disaster robustness. To achieve this goal, we previously proposed a proactive and distributed authentication framework (PDAF). In this paper, to enhance the robustness of PDAF, we add temporary registration and authentication procedures in a disaster scenario and the distributed regional network key server (RNKS) mechanism. Meanwhile, we optimize PDAF messaging through reducing redundancy to improve the performance. The proposed PDAF is a fully distributed design, which is intrinsically more robust than the existing authentication framework. In particular, we implement the PDAF over an existing regional network and measure the performance of PDAF. This shows that network scale and offered traffic load do not influence the PDAF's authentication time, which is usually around 31 ms under our experiment environment, because neighboring networking devices directly authenticate end devices. Ruidong Li 0001, Kazuyuki Morioka, Yasunori Owada, Masaaki Ohnishi, Hiroaki Harai |
ICNP | 1 |
| 2013 | A community-oriented route coordination using information centric networking approachabstractThe accommodation of growing tussles among different communities and the efficient and robust information dissemination in cyberspace have become crucial challenges for future network design, while the current Internet is ossified into the principle of end-to-end communications. To satisfy these challenges, in this paper we devise a community-oriented route coordination (CORIN) system using information-centric networking approach to naturally and efficiently provide community-based information dissemination and retrieval with name-integrated forwarding. The proposed CORIN modularizes users into communities, lets them express their interests and choices, and enables information objects to be searchable and retrievable in community units. We conduct performance analysis, which shows that CORIN can greatly reduce the control packet overhead compared with PURSUIT for community communication service provision. Ruidong Li 0001, Hitoshi Asaeda |
LCN | 1 |
| 2013 | Requirements and design for neutral trust management framework in unstructured networks
Ruidong Li 0001, Jie Li 0002 |
J. Supercomput. | 1 |
| 2012 | An integrated security scheme for ID/locator split architecture of future networkabstractFor the sake of better scalability and flexibility in the mobile and multihoming environments, future networks are expected to be based on the concept of ID/locator split. The ID/locator split architectures require storing, updating and retrieving of ID/locator mappings frequently, for which they need built-in security. To address this issue, this paper presents an integrated security scheme for securely storing, updating and retrieving hostnames to IDs and locators mapping records in two layers of name registries: domain name registries and host name registries. It then utilizes the mapping records retrieved from the registries for securing the network access, communication sessions, and mobility management functions. The scheme provides comprehensive protection of the ID/locator split architecture through an effective combination of asymmetric and symmetric cryptographic functions. Ved P. Kafle, Ruidong Li 0001, Hiroaki Harai |
ICC | 2 |
| 2012 | A proactive scheme for securing ID/locator split architectureabstractThe ID/locator split-based approach has been widely recognized as a promising approach for the design of future networks. However, the existing ID/locator split architectures are still vulnerable to various attacks, such as impersonation attacks and man-in-the-middle attacks. They cannot be simply protected by the existing security mechanisms, which have the limitations especially on scalability. To solve these problems, we propose a proactive scheme for securing ID/locator split architecture, which embeds built-in security features to enable proactive protections of the architecture. Through this scheme, hosts register their information to the network securely, obtain trustworthy information of destination hosts, authenticate each other, and securely update their locators without requiring an involvement of a trusted third party (TTP). Compared to other existing security mechanisms, the proposed scheme does not require additional authentication mechanism and it can provide the thorough protections of the whole architecture. Ruidong Li 0001, Ved P. Kafle, Hiroaki Harai |
ICNP | 1 |
| 2009 | Towards Neutral Trust Management Framework in Unstructured NetworksabstractFree-rider problem greatly influences the performance of unstructured networks (like ad-hoc or peer-to-peer networks). To solve such problem, we focus on trust management framework, which is intended to stimulate nodes to cooperate with each other. Currently, the existing trust management framework can be classified into trust establishment framework and reputation-based framework. However, none of them was explicitly designed with the considerations on neutrality, which is indispensable issue when devising a network system. In this paper, we investigate the relation between neutrality and trust definition, and then focus on trust management of one kind of typical unstructured networks, mobile ad hoc network (MANET). We propose a neutral trust management framework of MANET from the several aspects of neutrality characteristics, objectiveness, fairness and variegation. Then, we perform analysis on our proposed framework, which shows our proposal can achieve neutrality under the location-dependent attack of free-rider. Ruidong Li 0001, Jie Li 0002 |
MASS | 1 |
| 2009 | Capacity determination for deployment of managed mesh networksabstractWe start systematical analysis on the performance of managed mesh network (MMN), which provides communication function in the concept of community service platform in a local region. Towards the performance evaluation framework for MMN, we herein analyze the capacity provision of one base station (BS) under the constraints of physical transmission rate and available spectrum using queueing theory. In the related work of capacity analysis on mesh network, most of them have not put effort on the determination of exact capacity, or they investigated backhaul mesh network, which is different from MMN. Some other researchers investigated the architecture similar to MMN, but they have not investigated actual traffic processed in the transmission queue. Our modeling solves these problems and determines the exact capacity provided by each BS in an MMN. At the same time, we perform extensive simulations to verify the correctness of our modeling under a set of scenarios with different main parameters. After model verification, we apply our modeling results to a city and show how the capacity of one user at peak time changes with the deployment cost. Ruidong Li 0001, Masaaki Ohnishi, Ved P. Kafle, Masugi Inoue |
PIMRC | 1 |
| 2008 | Improving the Survivability of WSNs with Biological Characters Based on Rejuvenation TechnologyabstractBiological systems exhibit remarkable adaptation and robustness in the face of widely changing environments. Currently speaking, we often imitate the properties of biological systems. Based on this thought, it also exists the analogous situation in the WSNs (Wireless Sensor Networks). Survivability is the ability to provide essential services in the presence of attacks and failures, and recover full services in timely manner. The conventional security technologies for WSNs only focus on confidentiality, integrity and authentication and can not provide survival services. The WSNs survivability depends most critically on base station that attaches WSN to outside networks including Internet. Thus, to increase the survivability, one Survivable model for base station in WSNs is presented with rejuvenation technology, where it is designed to provide continued useful services in face of attacks, failure or accidents and to prevent the intruders’ attempts in their attack. This model is described and analyzed by semi-Markov Process for survivability. Finally, according to the experimental results, current model has the feasibility to enhance the survivability level for WSNs. Wei Wei 0006, Yong Qi 0001, Wei Wang 0015, Ruidong Li 0001 |
APSCC | 5 |
| 2008 | An Enhanced Fast Handover with Low Latency for Mobile IPv6abstractOne of the most important challenges in Mobile IPv6 is to provide the service for a mobile node to maintain its connectivity to the Internet when it moves from one domain to another, which is referred to as handover. Here we deal with the fast handover problem, which is to provide rapid handover service for the delay-sensitive and real-time applications. In this paper, we propose an enhanced fast handover scheme for Mobile IPv6. In our scheme, each AR (Access Router) maintains a CoA (Care of Address) table and generates the new CoA for the MN that will move to its domain. At the same time, the binding updates to home agent and correspondent node are to be performed from the time point when the new CoA for MN is known by PAR (Previous AR). Also the localized authentication procedure cooperated with the proposed scheme is provided. For the comparison with the existing fast handover scheme, detailed performance evaluation is performed. From the evaluation results, we can see that the proposed enhanced fast handover scheme can achieve low handover latency and low packet delay. Ruidong Li 0001, Jie Li 0002, Kui Wu 0001, Yang Xiao 0001, J. Xie |
IEEE Trans. Wirel. Commun. | 1 |
| 2007 | An Objective Trust Management Framework for Mobile Ad Hoc NetworksabstractIn mobile ad hoc networks (MANETs), each node should not only work for itself, but should be cooperative with other nodes. Under such environment, some nodes may misbehave for individual interests. Currently two categories of trust management frameworks, reputation-based framework and trust establishment framework, are used to guarantee nodes to perform normal behavior. However, in reputation-based framework, it is unreasonable that only one parameter, trust value, is considered. Meanwhile, the trust establishment framework is vulnerable under the selective misbehavior attack, by which the attacker performs different behaviors to different nodes. To solve these problems, we propose an objective trust management framework (OTMF) for MANETs, by which one node evaluates the trustworthiness of another node objectively based not only on direct observations, but on second-hand information. To compare the OTMF with the existing frameworks, we provide performance evaluation. The evaluation results show that the OTMF can obtain more reliable trust than the reputation-based framework and can prevent the selective misbehavior attack more effectively than the trust establishment framework. Ruidong Li 0001, Jie Li 0002, Peng Liu 0005, Hsiao-Hwa Chen |
VTC Spring | 1 |
| 2006 | An enhanced fast handover scheme for mobile IPv6abstractMobile IPv6 is the next generation wireless internet protocol to support IP mobility. One of the most important challenges in Mobile IPv6 is to provide the service for a mobile node to maintain its connectivity to the internet when it moves from one domain to another, which is referred to as handover. Because when performing the handover scheme, there is a period that the packets cannot reach the MN (Mobile Node) in time, the fast handover scheme is proposed to reduce the handover latency and packet delay. In this paper, we propose an enhanced fast handover scheme for Mobile IPv6. In our scheme, each AR (Access Router) maintains a CoA (Care of Address) table and generates the new CoA for the MN who will move to its domain. At the same time, the binding updates to home agent and correspondent node are proposed to be performed from the time point that the new CoA for MN is known by PAR (Previous AR). The performance analysis is provided in the paper. After the comparison with the existing fast handover scheme, we can see that the proposed enhanced fast handover scheme can achieve low handover latency and low packet delay. Ruidong Li 0001, Jie Li 0002 |
IWCMC | 1 |
| 2006 | On-demand public-key management for mobile ad hoc networksabstractAbstract A mobile ad hoc network (MANET) is the cooperative engagement of a collection of wireless mobile nodes without the aid of any established infrastructure or centralized administration. The conventional security solutions to provide key management through accessing trusted authorities or centralized servers are infeasible for this new environment since mobile ad hoc networks are characterized by the absence of any infrastructure, frequent mobility, and wireless links. In this paper, we propose an on‐demand, fully localized, and hop‐by‐hop public key management scheme for MANETs. It can be performed by generating public/private key pairs by nodes themselves, issuing certificates to neighboring nodes, holding these certificates in their certificate repositories, and providing authentication service adaptive quickly to the dynamic topology of the network without relying on any servers. Also, our scheme can be performed successfully as long as there is a physical communication line between two nodes, and it is accustomed well to the on‐demand routing for MANETs. Copyright © 2006 John Wiley & Sons, Ltd. Ruidong Li 0001, Jie Li 0002, Peng Liu 0005, Hsiao-Hwa Chen |
Wirel. Commun. Mob. Comput. | 1 |
| 2005 | Analysis and design of distributed hierarchical access control for multimedia networksabstractTo efficiently and effectively achieve the hierarchical access control for multimedia networks, in this paper we propose a distributed key management scheme whereby each SG (service group) maintains an SG server and give detailed analysis. In the proposed scheme, the server for a SG is utilized to manage the key tree and provide the related session keys for all the users in this SG. A detailed case study is provided, and we show that the communication overhead can be greatly reduced by O (n/sub O/ /spl middot/ log/sub d/n/sub O/), where n/sub O/ is the number of users in a SG, compared with employing an integrated key graph to the hierarchical access control problem. At the same time, the storage overhead for all users can be reduced by O(N), where N is the total number of users. Ruidong Li 0001, Jie Li 0002, Hsiao-Hwa Chen |
GLOBECOM | 1 |
| 2004 | Localized public-key management for mobile ad hoc networksabstractA mobile ad hoc network (MANET) is the cooperative engagement of a collection of wireless mobile nodes without aid of any established infrastructure or centralized administration. The conventional security solutions to provide key management through accessing trusted authorities or centralized servers are infeasible for this new environment since mobile ad hoc networks are characterized by the absence of any infrastructure, frequent mobility, and wireless links. In this paper, we propose an on-demand, fully localized, and hop-by-hop public key management scheme for MANETs. It can be performed by generating public/private key pairs by nodes themselves, issuing certificates to neighboring nodes, holding these certificates in their certificate repositories, and providing an authentication service quickly adaptive to the dynamic topology of the network without relying on any servers. Also, our scheme can be performed successfully as long as there is a physical communication line between two nodes, and it is accustomed well to the on-demand routing of MANETs. Ruidong Li 0001, Jie Li 0002, Hisao Kameda, Peng Liu 0005 |
GLOBECOM | 1 |