VLDB 2026 Research / reviewers in the wild / expert
Li Yang 0010
dblp:09/3925-10
· DBLP profile ↗
17ranked-venue papers
11as first author
15since 2021 · last 2026
0000-0001-9383-1097ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 8 first-author · 11 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SSH-Pulse: Detecting SSH communication in tunneled traffic
Jiangtao Zhai, Guangjie Liu 0001, Li Yang 0010, Yuewei Dai |
Comput. Networks | 4 |
| 2026 | A comprehensive review of traffic prediction: From traditional machine learning to AutoMLabstractIn the rapidly urbanizing world, efficient traffic prediction is essential for reducing congestion, optimizing travel times, and enhancing road safety. Traditional machine learning (ML) models have long been used for traffic forecasting but often struggle with unstructured data and capturing the complex temporal and spatio-temporal relationships inherent in traffic networks. Deep learning (DL) models, by contrast, can effectively handle large datasets and learn complex patterns, yet they still demand substantial human expertise for architecture design, hyperparameter tuning, and dataset-specific adaptation. This paper presents a comprehensive review of the evolution of traffic prediction models, highlighting the limitations of ML and DL approaches and introducing Automated Machine Learning (AutoML) as a promising solution. We discuss how AutoML can automate key stages of the ML pipeline—including data preprocessing, feature engineering, model learning, and model updating—reducing the need for human expertise, improving generalizability, and enabling model adaptation across datasets. While some studies have integrated AutoML components into traffic prediction tasks, a fully automated, end-to-end pipeline remains an open research challenge. This review identifies current gaps, explores AutoML’s potential to address these challenges, and outlines future directions for advancing traffic prediction through AutoML. Mahshid Khatiriolyaee, Li Yang 0010, Richard Werner Nelem Pazzi |
Neurocomputing | 2 |
| 2026 | Energy-Efficient Power Control and Jamming Selection Falsification for Age-Aware Covert Vehicular CommunicationsabstractThis study investigates energy-efficient resource allocation for covert vehicular communications with age constraints, where vehicle-to-vehicle (V2V) links leverage spectrum sharing to conceal covert transmissions. Vehicle-to-infrastructure (V2I) links serve as friendly jammers, simultaneously disrupting detection and maintaining connectivity with the base station. To maximize V2V links’ covert energy efficiency (CEE) and V2I links’ throughput under quality of service (QoS), communication covertness, and freshness constraints, a novel matching-based resource allocation framework is proposed. Specifically, we derive the minimum error detection rate and the optimal detection threshold at warden. The transmit probability and power are jointly optimized using the successive convex approximation method. Jamming selection is then modeled as a stable marriage problem, solved via the Gale-Shapley algorithm for stable matching between V2V and V2I links. Additionally, we explore a coalition falsification strategy to further enhance the CEE of certain V2V links without hurting the performance of the rest. Extensive simulations validate the proposed approach, showing significant improvements over existing baselines. Xin Sun 0035, Miao Du, Guangjie Liu 0001, Li Yang 0010, Chau Yuen, Mérouane Debbah |
IEEE Internet Things J. | 5 |
| 2025 | A Per-Bag Suspicion-Based Bagging Strategy for Fighting Poisoning Attacks in ClassificationabstractThe wide adoption of machine learning-powered systems in sensitive applications, such as banking for fraud detection, has attracted malicious actors who seek to break and subvert these systems. In this work, we focus on Data Poisoning attacks, which is a well-known type of adversarial attack carried out by an adversary whose goal is to reduce the effectiveness of the learning system. Bagging, a well-known ensemble learning technique that aims to improve performance and reduce the overall system variance, has demonstrated robustness against data poisoning attacks. Bagging has been further extended to include weighted schemes designed to detect outliers and assign lower resampling probabilities to anomalous instances, thereby enhancing the robustness of the standard bagging mechanism. Weighted bagging significantly improves system performance when the dataset is poisoned; however, it often suffers from instability due to the mechanism used to estimate the resampling probabilities. To address this challenge, we propose a novel weight estimation approach that leverages the reconstruction capabilities of autoencoders to identify and down-weight anomalous training samples. In particular, we investigate a specific type of data poisoning attack known as a label-flipping attack, using the widely studied MNIST dataset of handwritten images and conduct experiments using a Convolutional Neural Network (CNN). Our results show that the proposed weighted bagging mechanism consistently outperforms standard bagging under data poisoning levels of up to $50 \%$. To our knowledge, this is the first study to introduce a per-bag anomaly-based weighting mechanism, paving the way for future adaptive ensemble defenses in adversarial machine learning. Aghoghomena Akasukpe, Tomi Adeyemi, Pooria Madani, Li Yang 0010, Miguel Vargas Martin |
PST | 4 |
| 2025 | Toward Zero Touch Networks: Cross-Layer Automated Security Solutions for 6G Wireless NetworksabstractThe transition from fifth-generation (5G) to sixth-generation (6G) mobile networks necessitates network automation to meet the escalating demands for high data rates, ultra-low latency, and integrated technology. Recently, Zero-Touch Networks (ZTNs), driven by Artificial Intelligence (AI) and Machine Learning (ML), are designed to automate the entire lifecycle of network operations with minimal human intervention, presenting a promising solution for enhancing automation in 5G/6G networks. However, the implementation of ZTNs brings forth the need for autonomous and robust cybersecurity solutions, as ZTNs rely heavily on automation. AI/ML algorithms are widely used to develop cybersecurity mechanisms, but require substantial specialized expertise and encounter model drift issues, posing significant challenges in developing autonomous cybersecurity measures. Therefore, this paper proposes an automated security framework targeting Physical Layer Authentication (PLA) and Cross-Layer Intrusion Detection Systems (CLIDS) to address security concerns at multiple Internet protocol layers. The proposed framework employs drift-adaptive online learning techniques and a novel enhanced Successive Halving (SH)-based Automated ML (AutoML) method to automatically generate optimized ML models for dynamic networking environments. Experimental results illustrate that the proposed framework achieves high performance on the public Radio Frequency (RF) fingerprinting and the Canadian Institute for Cybersecurity Intrusion Detection System 2017 (CICIDS2017) datasets, showcasing its effectiveness in addressing PLA and CLIDS tasks within dynamic and complex networking environments. Furthermore, the paper explores open challenges and research directions in the 5G/6G cybersecurity domain. This framework represents a significant advancement towards fully autonomous and secure 6G networks, paving the way for future innovations in network automation and cybersecurity. Li Yang 0010, Shimaa Naser, Abdallah Shami, Sami Muhaidat, Lyndon Ong 0001, Mérouane Debbah |
IEEE Trans. Commun. | 1 |
| 2024 | Zero-touch networks: Towards next-generation network automation
Mirna El Rajab, Li Yang 0010, Abdallah Shami |
Comput. Networks | 2 |
| 2024 | Enabling AutoML for Zero-Touch Network Security: Use-Case Driven AnalysisabstractZero-Touch Networks (ZTNs) represent a state-of-the-art paradigm shift towards fully automated and intelligent network management, enabling the automation and intelligence required to manage the complexity, scale, and dynamic nature of next-generation (6G) networks. ZTNs leverage Artificial Intelligence (AI) and Machine Learning (ML) to enhance operational efficiency, support intelligent decision-making, and ensure effective resource allocation. However, the implementation of ZTNs is subject to security challenges that need to be resolved to achieve their full potential. In particular, two critical challenges arise: the need for human expertise in developing AI/ML-based security mechanisms, and the threat of adversarial attacks targeting AI/ML models. In this survey paper, we provide a comprehensive review of current security issues in ZTNs, emphasizing the need for advanced AI/ML-based security mechanisms that require minimal human intervention and protect AI/ML models themselves. Furthermore, we explore the potential of Automated ML (AutoML) technologies in developing robust security solutions for ZTNs. Through case studies, we illustrate practical approaches to securing ZTNs against both conventional and AI/ML-specific threats, including the development of autonomous intrusion detection systems and strategies to combat Adversarial ML (AML) attacks. The paper concludes with a discussion of the future research directions for the development of ZTN security approaches. Li Yang 0010, Mirna El Rajab, Abdallah Shami, Sami Muhaidat |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | A Multi-Stage Automated Online Network Data Stream Analytics Framework for IIoT SystemsabstractIndustry 5.0 aims at maximizing the collaboration between humans and machines. Machines are capable of automating repetitive jobs, while humans handle creative tasks. As a critical component of Industrial Internet of Things (IIoT) systems for service delivery, network data stream analytics often encounter concept drift issues due to dynamic IIoT environments, causing performance degradation and automation difficulties. In this article, we propose a novel multistage automated network analytics framework for concept drift adaptation in IIoT systems, consisting of dynamic data preprocessing, the proposed drift-based dynamic feature selection method, dynamic model learning and selection, and the proposed window-based weighted probability averaging ensemble model. It is a complete automated data stream analytics framework that enables automatic, effective, and efficient data analytics for IIoT systems in Industry 5.0. Experimental results on two public IoT datasets demonstrate that the proposed framework outperforms state-of-the-art methods for IIoT data stream analytics. Li Yang 0010, Abdallah Shami |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | LCCDE: A Decision-Based Ensemble Framework for Intrusion Detection in The Internet of VehiclesabstractModern vehicles, including autonomous vehicles and connected vehicles, have adopted an increasing variety of functionalities through connections and communications with other vehicles, smart devices, and infrastructures. However, the growing connectivity of the Internet of Vehicles (IoV) also increases the vulnerabilities to network attacks. To protect IoV systems against cyber threats, Intrusion Detection Systems (IDSs) that can identify malicious cyber-attacks have been developed using Machine Learning (ML) approaches. To accurately detect various types of attacks in IoV networks, we propose a novel ensemble IDS framework named Leader Class and Confidence Decision Ensemble (LCCDE). It is constructed by determining the best-performing ML model among three advanced ML algorithms (XGBoost, LightGBM, and CatBoost) for every class or type of attack. The class leader models with their prediction confidence values are then utilized to make accurate decisions regarding the detection of various types of cyber-attacks. Experiments on two public IoV security datasets (Car-Hacking and CICIDS2017 datasets) demonstrate the effectiveness of the proposed LCCDE for intrusion detection on both intra-vehicle and external networks. Li Yang 0010, Abdallah Shami, Gary Stevens, Stephen De Rusett |
GLOBECOM | 1 |
| 2022 | A Transfer Learning and Optimized CNN Based Intrusion Detection System for Internet of VehiclesabstractModern vehicles, including autonomous vehicles and connected vehicles, are increasingly connected to the external world, which enables various functionalities and services. However, the improving connectivity also increases the attack surfaces of the Internet of Vehicles (IoV), causing its vulnerabilities to cyber-threats. Due to the lack of authentication and encryption procedures in vehicular networks, Intrusion Detection Systems (IDSs) are essential approaches to protect modern vehicle systems from network attacks. In this paper, a transfer learning and ensemble learning-based IDS is proposed for IoV systems using convolutional neural networks (CNNs) and hyper-parameter optimization techniques. In the experiments, the proposed IDS has demonstrated over 99.25% detection rates and F1-scores on two well-known public benchmark IoV security datasets: the Car-Hacking dataset and the CICIDS2017 dataset. This shows the effectiveness of the proposed IDS for cyber-attack detection in both intra-vehicle and external vehicular networks. Li Yang 0010, Abdallah Shami |
ICC | 1 |
| 2022 | IoT data analytics in dynamic environments: From an automated machine learning perspective
Li Yang 0010, Abdallah Shami |
Eng. Appl. Artif. Intell. | 1 |
| 2022 | MTH-IDS: A Multitiered Hybrid Intrusion Detection System for Internet of VehiclesabstractModern vehicles, including connected vehicles and autonomous vehicles, nowadays involve many electronic control units connected through intravehicle networks (IVNs) to implement various functionalities and perform actions. Modern vehicles are also connected to external networks through vehicle-to-everything technologies, enabling their communications with other vehicles, infrastructures, and smart devices. However, the improving functionality and connectivity of modern vehicles also increase their vulnerabilities to cyber-attacks targeting both intravehicle and external networks due to the large attack surfaces. To secure vehicular networks, many researchers have focused on developing intrusion detection systems (IDSs) that capitalize on machine learning methods to detect malicious cyber-attacks. In this article, the vulnerabilities of intravehicle and external networks are discussed, and a multitiered hybrid IDS that incorporates a signature-based IDS and an anomaly-based IDS is proposed to detect both known and unknown attacks on vehicular networks. Experimental results illustrate that the proposed system can detect various types of known attacks with 99.99% accuracy on the CAN-intrusion-dataset representing the IVN data and 99.88% accuracy on the CICIDS2017 data set illustrating the external vehicular network data. For the zero-day attack detection, the proposed system achieves high F1-scores of 0.963 and 0.800 on the above two data sets, respectively. The average processing time of each data packet on a vehicle-level machine is less than 0.6 ms, which shows the feasibility of implementing the proposed system in real-time vehicle systems. This emphasizes the effectiveness and efficiency of the proposed IDS. Li Yang 0010, Abdallah Moubayed, Abdallah Shami |
IEEE Internet Things J. | 1 |
| 2022 | Multi-Perspective Content Delivery Networks Security Framework Using Optimized Unsupervised Anomaly DetectionabstractContent delivery networks (CDNs) provide efficient content distribution over the Internet. CDNs improve the connectivity and efficiency of global communications, but their caching mechanisms may be breached by cyber-attackers. Among the security mechanisms, effective anomaly detection forms an important part of CDN security enhancement. In this work, we propose a multi-perspective unsupervised learning framework for anomaly detection in CDNs. In the proposed framework, a multi-perspective feature engineering approach, an optimized unsupervised anomaly detection model that utilizes an isolation forest and a Gaussian mixture model, and a multi-perspective validation method, are developed to detect abnormal behaviors in CDNs mainly from the client Internet Protocol (IP) and node perspectives, therefore to identify the denial of service (DoS) and cache pollution attack (CPA) patterns. Experimental results are presented based on the analytics of eight days of real-world CDN log data provided by a major CDN operator. Through experiments, the abnormal contents, compromised nodes, malicious IPs, as well as their corresponding attack types, are identified effectively by the proposed framework and validated by multiple cybersecurity experts. This shows the effectiveness of the proposed method when applied to real-world CDN data. Li Yang 0010, Abdallah Moubayed, Abdallah Shami, Parisa Heidari, Amine Boukhtouta, Adel Larabi, Richard Brunner, Stere Preda, Daniel Migault |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | Concept Drift Detection in Federated Networked SystemsabstractAs next-generation networks materialize, increasing levels of intelligence are required. Federated Learning has been identified as a key enabling technology of intelligent and distributed networks; however, it is prone to concept drift as with any machine learning application. Concept drift directly affects the model's performance and can result in severe consequences considering the critical and emergency services provided by modern networks. To mitigate the adverse effects of drift, this paper proposes a concept drift detection system leveraging the federated learning updates provided at each iteration of the federated training process. Using dimensionality reduction and clustering techniques, a framework that isolates the system's drifted nodes is presented through experiments using an Intelligent Transportation System as a use case. The presented work demonstrates that the proposed framework is able to detect drifted nodes in a variety of non-iid scenarios at different stages of drift and different levels of system exposure. Dimitrios Michael Manias, Ibrahim Shaer, Li Yang 0010, Abdallah Shami |
GLOBECOM | 3 |
| 2021 | PWPAE: An Ensemble Framework for Concept Drift Adaptation in IoT Data StreamsabstractAs the number of Internet of Things (IoT) devices and systems have surged, IoT data analytics techniques have been developed to detect malicious cyber-attacks and secure IoT systems; however, concept drift issues often occur in IoT data analytics, as IoT data is often dynamic data streams that change over time, causing model degradation and attack detection failure. This is because traditional data analytics models are static models that cannot adapt to data distribution changes. In this paper, we propose a Performance Weighted Probability Averaging Ensemble (PWPAE) framework for drift adaptive IoT anomaly detection through IoT data stream analytics. Experiments on two public datasets show the effectiveness of our proposed PWPAE method compared against state-of-the-art methods. Li Yang 0010, Dimitrios Michael Manias, Abdallah Shami |
GLOBECOM | 1 |
| 2020 | On hyperparameter optimization of machine learning algorithms: Theory and practice
Li Yang 0010, Abdallah Shami |
Neurocomputing | 1 |
| 2019 | Tree-Based Intelligent Intrusion Detection System in Internet of VehiclesabstractThe use of autonomous vehicles (AVs) is a promising technology in Intelligent Transportation Systems (ITSs) to improve safety and driving efficiency. Vehicle-to-everything (V2X) technology enables communication among vehicles and other infrastructures. However, AVs and Internet of Vehicles (IoV) are vulnerable to different types of cyber-attacks such as denial of service, spoofing, and sniffing attacks. In this paper, an intelligent intrusion detection system (IDS) is proposed based on tree-structure machine learning models. The results from the implementation of the proposed intrusion detection system on standard data sets indicate that the system has the ability to identify various cyber-attacks in the AV networks. Furthermore, the proposed ensemble learning and feature selection approaches enable the proposed system to achieve high detection rate and low computational cost simultaneously. Li Yang 0010, Abdallah Moubayed, Ismail Hamieh, Abdallah Shami |
GLOBECOM | 1 |