VLDB 2026 Research / reviewers in the wild / expert
Yuyu Zhao
dblp:118/4639
· DBLP profile ↗
16ranked-venue papers
4as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 3 first-author · 10 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LARSS: A Hardware-Software Co-designed Framework for Load-Aware Receive Side Scaling
Guang Cheng 0001, Hua Wu 0004, Deyu Zhao, Yuyu Zhao, Xiaoyan Hu 0007 |
IWQoS | 5 |
| 2026 | BitFL: Bitstream-based lightweight federated learning with differential privacy for radio frequency fingerprint identification of drones
Yuyu Zhao, Guang Cheng 0001 |
Comput. Networks | 2 |
| 2026 | INTDirector: Achieving lightweight in-band network telemetry with superior coverage
Deyu Zhao, Guang Cheng 0001, Yuyu Zhao |
Comput. Networks | 4 |
| 2026 | Ultimate Encrypted Traffic Feature Engineering: HTTPS Encrypted Traffic Classification Using Restored Application Data Unit LengthabstractOver-the-top (OTT) applications mainly communicate through HTTPS, the most famous encryption protocol family on the Internet. The classification of HTTPS encrypted traffic can effectively obtain fine-grained OTT application information for network management and cyber security. As the most expressive feature, the side-channel length sequence is widely used by current research, especially the packet length sequence. However, these attempts ignored interferences from protocol piecewise decoupling and encryption covering, leading to poor performance. Based on the application layer feature engineering theory, we proposed a new metric called Application Data Unit (ADU) length to eliminate the interferences. However, ADU length cannot be obtained directly from packets as the TLS encryption protocol covers the entire application layer, which contains an intrusive and variable HTTP header. Hence, we designed a Length-Correction Multiple Regression Neural Network (LCMRNN) algorithm to restore the real ADU length sequences accurately. Exhaustive experiments in two scenarios of the real CERNET network show that no matter the HTTP-1.1 or HTTP2.0 protocol, the LC-MRNN model can achieve significantly accurate ADU length restoration. In classification, with the assistance of the LS-LSTM classifier, our method outperforms the state-of-the-art methods with about 4.2% improvement in F1-score (93.52%). Zihan Chen 0003, Guang Cheng 0001, Dandan Niu, Yuyu Zhao, Shanqing Jiang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Round Sketch: A Generic and Efficient Network Measurement Framework over Sliding WindowabstractAs network line rates continue to escalate, sketch-based methods have become increasingly pivotal tools in network measurement. Traditional sketch-based measurements are performed in fixed windows, which leads to truncation of network traffic and results in issues of underreporting. Recently, some studies have introduced the sliding window model into sketch-based measurements, providing a promising solution to this problem. However, these methods require the deployment of multiple sketch instances on a network equipment, consuming substantial memory resources. In addition, they necessitate complex data collection operations to achieve high accuracy. In this paper, we propose a novel network measurement framework, namely Round Sketch, which minimizes memory usage by incorporating an indicator into each counter and simplifies the data collection process by providing an efficient collection-and-set operation. Furthermore, Round Sketch is generic and can be applied to a wide range of existing sketches. We have implemented Round Sketch on FPGA platform and conducted comprehensive evaluations based on various measurement tasks. The results indicate that Round Sketch achieves comparable accuracy to state-of-the-art solutions while occupying only half of the memory space. Hua Wu 0004, Deyu Zhao, XianLong Dai, Yuyu Zhao, Guang Cheng 0001 |
ICCCN | 6 |
| 2025 | Flowaccel: A Line-Rate Intelligent Traffic Analysis Framework in FPGA-Based SmartnicsabstractIntelligent traffic analysis, serving as a core enabler of QoS (Quality of Service) policies, plays a pivotal role in finegrained resource scheduling and mission-critical performance assurance. While SmartNIC-based data plane offloading effectively alleviates host processing burdens, existing solutions lack a unified traffic management capability, restricting them to packet-level classification or inference model acceleration. This paper proposes FlowAccel, an end-to-end hardware architecture for line-rate intelligent network traffic analysis in FPGA-based SmartNICs. FlowAccel constructs a hierarchical memory structure for real-time updates of flow state and per-flow packet length sequence. Its feature extraction pipeline enables parallel computation of traffic fingerprint features and incorporates a dedicated XGBoost acceleration engine for hardware-optimized model inference. Implemented on the Alveo U50, our prototype demonstrates a$1.08 \mu ~\mathrm{s}$median inference latency under 100 Gbps network traffic. Compared with a single-logical-core DPDK software implementation, FlowAccel achieves a$54 \times$latency reduction and$180 \times$throughput improvement. In terms of accuracy, FlowAccel attains Macro-F1 scores of$89.0 \%, 86.3 \%$, and 92.4 % across three public datasets, significantly outperforming existing single-port 100 Gbps hardware offloading approaches. Yadong Tang, Guang Cheng 0001, Yuyu Zhao, Deyu Zhao |
IWQoS | 3 |
| 2025 | Probe-Optimizer: Discovering important nodes for proactive in-band network telemetry to achieve better probe orchestration
Deyu Zhao, Guang Cheng 0001, Yuyu Zhao, Yuexia Fu |
Comput. Networks | 4 |
| 2025 | Some results on (1,2)-rainbow connection number
Yingbin Ma, Yuyu Zhao |
Discret. Appl. Math. | 2 |
| 2024 | Enabling Heavy Flow Detection on Resource-Constrained Data PlaneabstractIn an era of rapidly increasing network speeds and expanding infrastructures, the demand for real-time and accurate network measurement tasks by network management has progressively heightened. Among these tasks, heavy flow detection has received sustained attention due to its broad application in areas such as traffic scheduling and congestion control. Concurrently, as a growing number of network services are deployed to the data plane, the already scarce resources of the data plane face even stricter constraints in multi-task scenarios. Hence, this paper proposes a heavy flow detection method aimed at resource-constrained scenarios, implementing a lightweight and hardware-software integrated real-time heavy flow detection on a data plane based on FPGA programmable switches. By designing an accurate flow table utilizing FPGA resource characteristics and optimizing the implementation of the sketch algorithm in hardware, our method significantly reduces the resource overhead of the data plane while conducting real-time detection of large network flows. Tests conducted with different real network traffic and a 4×10Gbps programmable network card have demonstrated that, with minimal hardware resources and minimal interference with network forwarding services, the real-time heavy flow detection precision of our method can reach more than 97%. Deyu Zhao, Guang Cheng 0001, Ruixing Zhu, Yuyu Zhao |
HPCC | 4 |
| 2023 | Snapshot for Power Grids IoT: Adaptive Measurement for Resilience Intelligent Internet of ThingsabstractWith the wide application of Internet of Things (IoT) devices in the power grids, the sophisticated feedback on their operating status is of great significance for improving efficiency and reducing accidents. For exquisite management of the resilient intelligent IoT with flexible increase and decrease of devices and heterogeneous operating systems, this article proposes an adaptive measurement method “MRAM,” which can snapshot the multidimensional resource view (MRV) of all devices in the jurisdiction. Extensible gateway platform based on CPU, field-programmable gate array, and cloud computing is applied in MRAM, which liberates the local resources of monitored IoT devices. MRAM improves the long short-term memory algorithm called ELSTM. ELSTM can accommodate the current IoT devices’ state for detecting the mutation of MRV. The newly collected resources determined by ELSTM whether MRAM enters an abnormal state to drive the adaptive measurement state machine. According to the state machine which endeavors that the MRV is updated timely, MRAM adjusts the measurement granularity in real time. Simulations and experiments have tested the convergence time and occupied bandwidth of MRAM deployed in power grids. These evaluations confirmed MRAM’s practicality and robustness, as well as the MRV is genuine management data for the upper layer power grids applications. A real environment is built to test the performance of this method as well. MRAM has high measurement accuracy and the precision of mutation detection is 98.41%. It converges the update MRV of second level under the condition of IoT devices and the cloud’s low consumption of memory and CPU utilization. Yuyu Zhao, Guang Cheng 0001, Chunxiang Liu, Zihan Chen 0003, Donglai Xu |
IEEE Internet Things J. | 1 |
| 2023 | SINT: Toward a Blockchain-Based Secure In-Band Network Telemetry ArchitectureabstractThe foundation of network management is to timely, accurately, and flexibly monitor the status of a managed network. Recently, In-band Network Telemetry (INT) has presented its unique capabilities in acquiring the insights of a network and thus has been adopted in many production networks. However, less attention was put on the potential threats on INT (e.g., the man-in-the-middle attacks, Trojan horse injection) that may falsify network measurements resulting in catastrophic consequences. In this paper, we propose a secure INT architecture calledSINTthat can effectively mitigate INT vulnerabilities and can be implemented using ’chiplet’ based multi-modal network processors (MNP). SINT adopts blockchain technology into INT, in which a network status snapshot acquired via INT is viewed as a block and added into a network telemetry blockchain to prevent arbitrary access and malicious modification. To minimize the intrusiveness of the INT and blockchain operations, SINT is designed to be a lightweight protocol and uses improved RAFT consensus mechanisms to reduce its network and computing overhead. The design of the chiplet MNP system makes SINT highly flexible and adaptive to facilitate INT convergence and related blockchain updates. In the SINT architecture, INT tasks and blockchain operations are dispatched to different chips to achieve an optimal trade-off among measurement accuracy, security requirements, and computing resource on the data plane. Experiments and simulations show that SINT can alleviate most cyberattacks on INT and retain 97% of bandwidth utilization for other users’ normal traffic in a complex scenario with 500 nodes. Furthermore, SINT converges the INT results quickly and accurately with minor overhead compared to that of the state-of-art INT methods. Yuyu Zhao, Guang Cheng 0001, Yongning Tang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | NT-RP: A High-Versatility Approach for Network Telemetry Based on FPGA Dynamic Reconfigurable Pipeline
Deyu Zhao, Guang Cheng 0001, Yuyu Zhao, Ruixing Zhu |
WASA (3) | 3 |
| 2022 | Toward Proactive and Efficient DDoS Mitigation in IIoT Systems: A Moving Target Defense ApproachabstractNowadays, a large number of intelligent devices involved in the industrial Internet of Things (IIoT) environment lead to unprecedented challenges in security. Due to limited resources with weak security protection, the IIoT devices can be easily compromised to launch distributed denial-of-service (DDoS) attacks, resulting in catastrophic results. Although there are many DDoS mitigations of traditional static schemes, the proactive defense method to resist attacks has not been well studied. Furthermore, existing proactive schemes ignored the delay-sensitive characteristic of applications under the IIoT environments. To address these issues, we first adopt two kinds of moving target defense (MTD) techniques that dynamically control the admission of devices and migrate service replicas to isolate attackers on limited edge clouds and mitigate DDoS attacks early near its source. Then, we formulate a multistage optimization problem of MTD mechanisms deployment and model it as constrained Markov decision processes in order to maximize the available resources of the system under the limitations of the IIoT environments. Besides, we present an MTD optimal strategy algorithm to solve decision problems in a cost-effective manner. In this article, the proposed algorithm can achieve an optimal admission allocation by means of attackers gathering within the same service where the service migration decisions are assisted by means of value iteration. The experimental results verify that the proposed algorithm, compared with existing strategies, can effectively mitigate DDoS attacks with acceptable degradation of the quality of service. Guang Cheng 0001, Yuyu Zhao, Zihan Chen 0003, Shanqing Jiang |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Snapshot for IoT: Adaptive Measurement for Multidimensional QoS ResourcesabstractWith the increasing and extensive use of intelligent Internet of things (IoT) devices, its operational aspect in the network has become a significant dependent data for network QoS management and scheduling. For the resilient intelligent IoT cluster with flexible increase and decrease of devices and heterogeneous operating systems, this paper proposes an adaptive measurement method MRAM, which can snapshot the multidimensional QoS resources view (MRV) of the IoT devices in cluster. MRAM uses the measurement offloading architecture based on extensible gateway platform and cloud computing to liberate the local resources of monitored IoT devices. Based on the improved LSTM algorithm, the MRV’s mutations detection method ELSTM is designed. Newly collected QoS resource can be judged whether mutations have occurred and adaptive measurement state machine is enabled by ELSTM. According to the state machine which ensures that the MRV is updated timely and reflected the current status of the cluster, MRAM adjusts the measurement granularity in real time. This method provides a high time efficiency global profile for the upper QoS services and reduces the impact of measurement on the IoT devices. A real environment is built to test the performance of this method. MRAM has high measurement accuracy and the precision of mutations detection is 98.29%. It converges the update MRV of second level under the condition of IoT devices’ low consumption of storage and CPU utilization. Yuyu Zhao, Guang Cheng 0001, Chunxiang Liu, Zihan Chen 0003 |
IWQoS | 1 |
| 2021 | Secure IoT edge: Threat situation awareness based on network traffic
Yuyu Zhao, Guang Cheng 0001, Zhouchao Gu |
Comput. Networks | 1 |
| 2020 | Cost-effective moving target defense against DDoS attacks using trilateral game and multi-objective Markov decision processes
Guang Cheng 0001, Shanqing Jiang, Yuyu Zhao, Zihan Chen 0003 |
Comput. Secur. | 4 |