VLDB 2026 Research / reviewers in the wild / expert
Shuying Zhuang
dblp:07/10207
· DBLP profile ↗
9ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0002-2560-804XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 3 first-author · 5 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Link Prediction-Based Measurement Strategy for Efficient Topology Completeness ImprovementsabstractThe Autonomous System (AS) level topology observed from current measurement infrastructures is far from complete. Although Looking Glass (LG) vantage points (VPs) that support BGP route queries can provide valuable topology information, the query rate limitations of LG VPs imply that blindly using the VPs to conduct more measurements to improve the topology completeness is inefficient, if not infeasible. In this paper, we try to improve the efficiency by designing a link prediction based measurement strategy, whose basic idea is to first predict where unseen AS links are likely to be located and then use the prediction results to guide the measurements toward a more complete AS-level topology. We formulate the prediction of unseen AS links as a matrix completion problem and develop a side-information assisted learning-based matrix completion method. The method exploits a neural network and utilizes carefully chosen AS attributes based on our understanding on Internet peering practices, thereby learning more expressive latent vectors and achieving outstanding prediction performance in our scenario. We then develop a measurement strategy which takes the link prediction results as guidance to achieve efficient topology completeness improvements. The strategy leverages several heuristics to estimate the utilities of different measurements and takes a greedy algorithm to select the most valuable measurements. Experiments show that our link prediction method can achieve a high AUC (Area Under the Receiver Operating Characteristic Curve) of 0.834 and the link-guided measurement strategy can discover 1.82 times more unseen links than those discovered from non-guided measurement strategies with an equal number of measurements. Shuying Zhuang, Hui Wang 0011, Jilong Wang 0001, Changqing An, Yuedong Xu 0001, Tianhao Wu 0010 |
IEEE Trans. Netw. | 1 |
| 2025 | Poster: RMap: Uncovering Risky DNS Resolution Chains and MisconfigurationsabstractIn recent years, large-scale network outages caused by DNS misconfigurations have become increasingly common. The intricate inter-domain dependencies, along with emerging mechanisms (Such as DNSSEC, EDNS, and 0x20), have made DNS resolution increasingly complex and fault localization more challenging. We present RMap, a tool that rapidly probes all potential resolution chains of a domain, reveals its resolution dependency topology, and detects security risks. We experimentally demonstrate the effectiveness of RMap and its broad applicability. Our findings reveal that domain configurations in real-world environments remain concerning, with potential issues observed even in several well-known top-level domains. RMap is avaliable in https://github.com/ahlien/rmap. Fasheng Miao, Shuying Zhuang, Xiang Li 0108, Changqing An, Deliang Chang, Baojun Liu 0002, Jia Zhang 0004, Jilong Wang 0001 |
IMC | 2 |
| 2025 | Ares: Comprehensive Path Hijacking Detection via Routing Tree
Yinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang, Jilong Wang 0001, Congcong Miao |
USENIX Security Symposium | 4 |
| 2024 | Collecting Self-reported Semantics of BGP Communities and Investigating Their Consistency with Real-world UsageabstractPeople can extract various kinds of information about the Internet from BGP routes tagged with BGP community values with known semantics. In this paper, we conduct a study on the following three issues related to BGP community semantics. First, we design a method to automatically collect self-reported semantics from the Internet and assemble the collected semantics described in natural language into a structured dictionary. The comparison with prior dictionaries shows many community values are exclusively covered by ours and many of them had been used when prior dictionaries were constructed, which confirms the effectiveness of our method. Second, based on this large-size dictionary, we are able to re-evaluate two recent algorithms designed for categorizing community values with unknown semantics, which is a task that, while easier than inferring the detailed semantics, is also very valuable. Our evaluation uncovers some issues within the algorithms that can contribute to their performance improvement. Third, we investigate the fundamental issue in extracting information using community semantics: whether ISPs' behavior is consistent with the published semantics. Our preliminary best-effort investigation reveals the potential risks of using the semantics of some categories of community values. Yunhao Liu 0001, Tianhao Wu 0010, Hui Wang 0011, Jilong Wang 0001, Shuying Zhuang |
IMC | 5 |
| 2024 | Rumors Stop with the Wise: Unveiling Inbound SAV Deployment through Spoofed ICMP MessagesabstractIn the era of increasing network-based threats, particularly IP spoofing, Source Address Validation (SAV) is paramount for network security. The effective deployment of Inbound Source Address Validation (ISAV) is crucial yet often inadequate, posing significant risks to Internet infrastructure. This study presents ICMP_Sonar, a measurement system that deploys "rumors" -carefully crafted spoofed ICMP packets-to probe the network's defenses, revealing the "wise" networks with their robust ISAV implementations. ICMP_Sonar introduces two novel approaches that exploit the characteristics of ICMP unreachable messages and ICMP fragment needed messages, and exhibits the advantages of high coverage, fine granularity, low error rates, and the ability to measure in both IPv4 and IPv6. We also evaluate the applicability and security risks of ICMP error messages. Through large-scale measurements, ICMP_Sonar successfully covers 86M IPv4 hosts (0.8M IPv6 hosts), 3.5M IPv4 /24 subnets (24K IPv6 /40 subnets), and 59K IPv4 ASes (8.3K IPv6 ASes), surpassing the state-of-the-art dual-stack method's coverage by 16.2 (51.6), 2.9 (2.34), and 1.7 (1.7) times, respectively. The broad coverage across multiple granularities enables us to capture a more comprehensive and fine-grained view of ISAV deployment. Measurements show that while the percentage of ASes with no ISAV deployment is lower than previously identified, the percentage of ASes with partial ISAV deployment is much higher, indicating significant gaps in overall security. The analysis also reveals that ISAV deployment practices vary across different networks and between IPv4 and IPv6. Shuaicong Yu, Shuying Zhuang, Changqing An, Jilong Wang 0001 |
IMC | 2 |
| 2022 | Predicting Unseen Links Using Learning-based Matrix CompletionabstractResearchers have noticed the AS-level Internet topology that can be observed from the current measurement infrastructure is far from complete, which means researchers have to deploy more measurement vantage points (VPs) and conduct measurements for more source/destination pairs to fully understand the whole Internet. Unfortunately, it is known that blindly deploying more points and conducting more measurements to achieve the goal is inefficient, if not infeasible. In this paper, we try to improve the efficiency by predicting where unseen AS links might be located from the observed AS paths to guide the measurements towards a more complete AS-level topology. We formulate the prediction of unseen links as a matrix completion problem. However, the traditional matrix completion methods have limited learning capacities and cannot deal with the complex constraints on the underlying topology. We develop a learning-based matrix completion method specifically for the unseen AS link prediction problem. The method exploits a neural network and utilizes side-information which is carefully chosen from AS attributes based on our understanding on Internet peering practices, therefore our method is able to learn more expressive latent vectors and achieves outstanding prediction performance in our scenario. Experiments performed on a real-world dataset show the prediction results can achieve a high AUC (Area Under the Receiver Operating Characteristic Curve) of 0.834. Shuying Zhuang, Hui Wang 0011, Jilong Wang 0001, Changqing An, Yuedong Xu 0001, Tianhao Wu 0010 |
NOMS | 1 |
| 2022 | RouteInfer: Inferring Interdomain Paths by Capturing ISP Routing Behavior Diversity and Generality
Tianhao Wu 0010, Hui Wang 0011, Jilong Wang 0001, Shuying Zhuang |
PAM | 4 |
| 2021 | Discovering obscure looking glass sites on the web to facilitate internet measurement researchabstractDespite researchers have noticed that Looking Glass (LG) vantage points (VPs) are valuable for Internet measurement researches, they can only exploit VPs from well-known LG sites published on several LG portal pages. There should be a lot of LG sites that are not published in these portal pages, namely obscure LG sites, which are not easy to be found and exploited by researchers. In this paper, we design an efficient focused crawler to discover as many LG sites as possible which can avoid unnecessary resource consumption on analyzing irrelevant pages. Our designed focused crawler takes a similarity-guided search that exploits the well-developed search engines and comprehensively mines the common features shared by known LG sites to discover more LG pages. Moreover, the focused crawler takes a two-step PU learning classifier based on carefully selected LG features to efficiently discard irrelevant URLs, thus avoiding a lot of unnecessary resource consumption. As far as we know, we are the first to develop a method to discover obscure LG sites on the web. Experimental results show the effectiveness of our focused crawler. To facilitate practical applications, we further develop an automation tool, which can successfully retrieve 910 obscure automatable LG VPs from relevant pages obtained through our focused crawler. The 910 LG VPs significantly increase the geographic and network coverage of available VPs and we show their potential values in improving the completeness of AS-level Internet topology by a simple case study. Our method and the final VP list are beneficial to the measurement community. Shuying Zhuang, Hui Wang 0011, Jilong Wang 0001, Zujiang Pan, Tianhao Wu 0010 |
CoNEXT | 1 |
| 2020 | Understanding the latency to visit websites in China: An infrastructure perspective
Shuying Zhuang, Hui Wang 0011, Pei Zhang 0003, Jilong Wang 0001 |
Comput. Networks | 1 |