VLDB 2026 Research / reviewers in the wild / expert
Zifu Li
dblp:131/9842
· DBLP profile ↗
26ranked-venue papers
5as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 4 first-author · 1 since 2021Computer networks · 5 · 3 since 2021Security and privacy · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Defense Response Time Window Optimization Against Coordinated Flooding Attacks in Space-Ground Integrated Networks
Dongbin Chen, Yunchuan Guo, Mengxiang Zhu, Zifu Li |
ICIC (11) | 5 |
| 2026 | HAS-B Tree: An Efficient Utility-Preserving Index for Anonymized Data Management
Haotian Yue, Fenghua Li 0001, Zifu Li, Yunchuan Guo, Shoukun Guo |
ICIC (2) | 3 |
| 2025 | BitInfer: An Automated Field Semantic Inference Method Based on Genetic AlgorithmabstractPrivate protocols are widely used on the network to improve efficiency and protect privacy. However, it lacks standard protocols to unify the communication process and improve security. Protocol Reverse Engineering (PRE) aims to infer the syntax, semantics, and timing of the unknown protocol. In detail, it always infers the field information and the state machine. Yet, the results of existing PRE methods focus byte-level, and the target setting is an empirical process. To overcome the shortage, we proposed BitInfer for binary protocols. BitInfer uses a set of field detectors, including Length Detector, Timestamp Detector, Entropy Detector, Sequence Detector and Reserve Detector to divide the protocols into bit-level field and get the confidence of them. Then we randomly choose the combination of detector tuples to get the init population by repeating the process for a specific times. Finally, we use NSGA2 as the intergrade algorithm to deal with the field conflict. Experiments show that the result of BitInfer precisely solve the conflict and extend to bit level. Liang Fang 0009, Junhai Yang, Zifu Li, Fenghua Li 0001 |
COMPSAC | 4 |
| 2025 | Automatic State Machine Inference for Binary Protocol Reverse EngineeringabstractProprietary protocols are widely used to ensure efficient data transmission, enhance privacy, and meet specific application requirements. However, the lack of public standards often leaves their security inadequately evaluated, posing significant challenges for network security. Protocol Reverse Engineering (PRE) is used to analyze protocols by inferring their structure and behavior. However, existing PRE methods primarily focus on protocol format analysis, neglecting Protocol State Machine (PSM) analysis, which can lead to insufficient detection of abnormal behaviors and potential vulnerabilities. To address this, we propose an automatic PSM inference framework for unknown protocols, incorporating a fuzzy membership-based auto-converging DBSCAN algorithm for protocol format clustering, followed by a session clustering algorithm based on Needleman-Wunsch and K-Medoids algorithm to classify sessions by protocol type. Finally, we refine a probabilistic PSM algorithm to infer protocol states and transitions. Experiments show that our method can infer PSMs while enabling precise protocol classification. Junhai Yang, Fenghua Li 0001, Liang Fang 0009, Yunchuan Guo, Zifu Li |
GLOBECOM | 6 |
| 2025 | SEHAP: Secure and Efficient Handover Authentication Protocol in LEO Satellite Non-Terrestrial NetworksabstractLEO satellite non-terrestrial networks (NTN) utilize satellites in Low Earth Orbit (LEO) to dynamically establish global communication service and own significant promise. The dynamic nature of LEO satellite NTN necessities efficient handover authentication protocols. However existing schemes cannot be directly applied in LEO satellite NTN because of their low efficiency and security. To address these problems, we propose a handover authentication protocol to quickly and securely authenticate the user’s identity during the handover process. In our scheme, we incorporate an implicit session-bound random challenge to facilitate mutual authentication and key agreement between the User Equipments (UEs) and satellites. To improve authentication efficiency, we propose a batch handover mechanism to transfer the necessary security contexts, largely reducing the handover authentication cost. We verify our protocol’s security using BAN logic and Tamarin prover. The performance evaluation shows that SEHAP outperforms other schemes in both communication and computational efficiency in LEO satellite NTN. Yunchuan Guo, Jing Wang 0174, Kui Geng, Zifu Li, Fenghua Li 0001, Liang Fang 0009 |
ICASSP | 4 |
| 2025 | Rule Generation for Anomalous Behaviors Detection in Enterprises: A Few-Shot Learning Approach via Chain-of-Thoughts
Xin Bao, Yunchuan Guo, Xinyi Shi, Kui Geng, Wenlong Kou, Zifu Li |
ICIC (7) | 6 |
| 2025 | Contrastive Learning with Knowledge-Enhanced Prompts for Insider Threat DetectionabstractInsider threat detection is essential for protecting organizations from malicious or negligent insiders. This paper proposes a knowledge-enhanced self-contrastive learning framework for insider threat detection in multi-source user behavior graph scenarios. In the user behavior graph representation phase, a multi-head attention mechanism with relational encoding is used to explore user adjacency relations, with node connectivity guiding subgraph sampling. In the knowledge enhancement phase, self-contrastive learning aligns subgraph embeddings with behavior descriptions generated by a prompt template, enriching user behavior features. Finally, the dual-stage detection scheme filters anomalous users using a variational autoencoder and categorizes them through multi-class classification. Experimental results on the CERT insider threat dataset show that our scheme achieves 97.2% accuracy and an F1 score of 0.72, significantly outperforming existing schemes. Yunchuan Guo, Mengxiang Zhu, Yongqiang Xu, Zifu Li |
IJCNN | 6 |
| 2025 | A Watermarking Framework for Secure Distribution of Meteorological ImagesabstractMeteorological images typically contain sensitive and critical information, demanding effective security mechanisms to prevent unauthorized copying and distribution. Digital watermarking, a widely adopted protection technique, imperceptibly embeds user identity information into images to enable subsequent traceability. However, existing methods fail to consider the impact of watermark embedding on critical meteorological features, as well as the limitations of high computational overhead and low embedding efficiency in multi-user distribution scenarios. To address these issues, we propose a watermarking framework tailored for the secure distribution of meteorological images. Specifically, we first design a content-adaptive region selection scheme that avoids embedding watermarks in critical meteorological regions such as cloud features. We then develop a two-stage decoupled embedding strategy to enhance distribution efficiency, where the preprocessing stage performs region selection and frequency transformation, while the distribution stage reuses these cached results to rapidly generate user-specific watermarked copies. Extensive experimental results demonstrate that our framework effectively avoids critical regions in meteorological images and maintains high visual quality (average PSNR of 38.10 dB and SSIM of 0.9815) while achieving better extraction accuracy under various attacks. Furthermore, the two-stage decoupled embedding strategy reduces server response latency by over 60.8% in concurrent distribution scenarios. Fenghua Li 0001, Zifu Li, Yanru He |
TrustCom | 4 |
| 2025 | HT-ASAF: Automatic Sample Augmentation Framework for Hardware TrojanabstractHardware Trojans pose a significant security risk in space-ground integrated network (SGIN) devices. It is widely accepted in academia and industry that detecting hardware Trojans at an early stage, typically in register transfer-level (RTL) hardware design, can effectively protect the SGIN device. However, the few hardware Trojan samples dedicated to SGIN (called sHT) make it difficult to detect them using deep learning. To obtain more sHT samples automatically and quickly, this article proposes a lightweight automatic sample augmentation framework for hardware Trojan (HT-ASAF). In our scheme, we first designed a lightweight neural network called variational autoencoder for hardware Trojan (HT-VAE) to achieve high-generation quality without a large amount of training data. Further, we develop the positional state tree (PST) and introduce a node tuple representation for interconversion between PST and sequence to capture the intricate semantic features of concurrent operations in hardware design to enhance the performance of HT-VAE. To automatically verify the effectiveness of the augmented samples, we established an experimental platform incorporating cluster mapping (CLM), which can reduce the verification complexity. In our experiments, to obtain a small number of the training hardware Trojan samples for SGIN, we added activation mechanisms, such as velocity or altitude, to the existing RTL hardware Trojans samples to simulate the hardware Trojan threats faced by orbit devices. The set of the obtained samples is called sHT dataset. Experimental results on the obtained sHT dataset demonstrate that HT-ASAF can automatically and efficiently augment hardware trojan sample compared to existing augmentation schemes, and it performs well in the downstream task of hardware Trojan detection on SGIN devices. Fenghua Li 0001, Yunchuan Guo, Ming Mao, Zifu Li |
IEEE Internet Things J. | 5 |
| 2024 | Orchestrating Security Protection Resource for Space-Ground Integrated NetworksabstractThe space-ground integrated networks (SGIN) is vulnerable to complex and evolving threats due to its open nature. However, the dynamic topology and limited resources of SGIN present significant challenges for security resource orchestration. Most existing studies focus on network function orchestration and resource allocation for service flows, overlooking the offensive and defensive characteristics of security resource orchestration. Moreover, they fail to adequately address the difficulties posed by the dynamic topology of SGIN. To address these gaps, we utilize a virtual node method and network structure characteristics to transform the dynamic network topology into a static scale-free network. The orchestration strategy generation problem is then modeled as a minimum spanning tree truncation game on the network. Given the NP-hard nature of the problem, we propose the OSG algorithm based on Benders decomposition to solve it. To further improve the OSG algorithm’s efficiency, we introduce an initial value algorithm and four cutting plane inequalities, culminating in the AOSG algorithm. Extensive experiments conducted on networks of varying scales demonstrate that the AOSG algorithm, incorporating the initial feasible solution and Hamming inequality, delivers superior performance and generates optimal orchestration strategies within a feasible time frame. Dongbin Chen, Yunchuan Guo, Fenghua Li 0001, Zifu Li |
TrustCom | 5 |
| 2024 | Efficiently Detecting DDoS in Heterogeneous Networks: A Parameter-Compressed Vertical Federated Learning approach
Cao Chen, Fenghua Li 0001, Yunchuan Guo, Zifu Li, Wenlong Kou |
TrustCom | 4 |
| 2023 | Dynamic threshold strategy optimization for security protection in Internet of Things: An adversarial deep learning-based game-theoretical approachabstractAbstract As mobile communications, the Internet, databases, distributed computing, and other technologies continue to develop, the Internet of Things (IoT) has emerged as prevalent technique. However, attacks on security and sensitive data in IoT occur frequently, and these attacks often evade intrusion detection systems strategically by mutating their traffic. To prevent security threats and sensitive data leakage, we propose a game approach based on adversarial deep learning to optimize a dynamic security threshold strategy. We introduce a mobile edge computing framework and utilize a game model to describe the adversarial interaction between the two participants. To solve the complexity of the game problem to gain dynamically randomized adversarial attacks, we present a column generation (CG) framework, which uses a feedforward neural network to quantify data flowing through IoT devices. Considering the limited resources of IoT devices, we calculate an optimal response to cyberattacks via a particle swarm optimization algorithm, aiming to reduce the false alarm rate. The adversarial dynamic threshold (ADT)‐based column generation (CG‐ADT) algorithm generates the set of detection threshold and the probability. Finally, we present the results of experiments conducted to demonstrate the effectiveness and robustness of the proposed dynamic threshold scheme for sensitive data security protection in IoT and its suitability for implementation in production systems. Zhen Wang 0013, Yunchuan Guo, Fenghua Li 0001, Zifu Li |
Concurr. Comput. Pract. Exp. | 6 |
| 2022 | Insider Threat Detection Using Generative Adversarial Graph Attention NetworksabstractInsiders cause serious security threats to organizations. Existing insider threat detection methods mainly mine the users' behaviors or psychological features by analyzing the users' operation logs, and they ignore the associations of behaviors among users and get unappealing performance on the imbalanced samples. In this paper, considering attention mechanism, we propose Generative Adversarial Graph Attention Networks (GAGAN) to detect insider threats. First, we design association rules to construct a graph to associate users' behaviors. Second, to address the imbalanced samples, we adopt graph generator to generate abnormal nodes; A discriminator with graph attention networks is designed to further mine the potential associations of behaviors among users and discriminate real nodes from the generated nodes, also adopted to discriminate anomaly nodes from normal nodes. Experimental results on CERT data set demonstrate that our method can accurately detect abnormal insiders and outperforms several state-of-the-art baseline methods. Chaoyang Li 0011, Fenghua Li 0001, Mingjie Yu, Yunchuan Guo, Yitong Wen, Zifu Li |
GLOBECOM | 6 |
| 2022 | Efficiently Constructing Topology of Dynamic NetworksabstractAccurately constructing dynamic network topology is one of the core tasks to provide on-demand security services to the ubiquitous network. Existing schemes cannot accurately construct dynamic network topologies in time. In this paper, we propose a novel scheme to construct the ubiquitous network topology. Firstly, ubiquitous network nodes are divided into three categories: terminal node, sink node, and control node. On this basis, we propose two operation primitives (i.e., addition and subtraction) and three atomic operations (i.e., intersection, union, and fusion), and design a series of algorithms to describe the network change and construct the network topology. We further use our scheme to depict the specific time-varying network topologies, including Satellite Internet and Internet of things. It demonstrates that their communication and security protection modes can be efficiently and accurately constructed on our scheme. The simulation and theoretical analysis also prove that the efficiency of our scheme, and effectively support the orchestration of protection capabilities. Fenghua Li 0001, Cao Chen, Yunchuan Guo, Liang Fang 0009, Chao Guo 0002, Zifu Li |
TrustCom | 6 |
| 2022 | A Terminal Security Authentication Protocol for Zero-Trust Satellite IoTabstractWith the help of satellites, Internet of Things (IoT) applications such as remote monitoring and ocean exploration can be realized. However, the network is vulnerable to malicious attacks due to the limited resources of satellite IoT (S-IoT) terminals and the openness of communication links. Ensuring that legitimate users can only access sensitive data remains a major concern. In this paper, a zero-trust access management model integrated with satellites, network and identity infrastructure, as well as the authentication protocol for S-IoT terminal security, was designed. The protocol adopts the Chinese cryptographic algorithms SM2, SM3, and SM4, combined with the Physical Unclonable Function (PUF) to achieve key agreement and bidirectional authentication. The security of this protocol is further analyzed, and its security, function, and performance are compared with other related protocols. Experimental results show that compared with existing similar schemes, the proposed protocol can more effectively consider the security requirements of S-IoT and reduce communication costs. Minqiu Tian, Zifu Li, Fenghua Li 0001, Jin Cao 0001, Chao Guo 0002 |
TrustCom | 2 |
| 2020 | Decision-Making for Intrusion Response: Which, Where, in What Order, and How Long?abstractGenerating fine-grained response policies is a fundamental problem for Intrusion Response Systems (IRSs). Although existing schemes determine countermeasures and defense points efficiently, they ignore the deployment orders and execution durations of the selected countermeasures, which may impact response performance. To address this problem, by considering four attributes (i.e., attack damage, deployment cost, negative impact on QoS, and security benefit), we propose a decisionmaking framework for IRSs to reach fine-grained decisions to balance attack damage and response cost. We formulate decisionmaking as a single-objective optimization problem. To efficiently solve this problem, a Genetic Algorithm with Three-dimensional Encoding (GATE) is proposed to not only select countermeasures and defense points, but also determine deployment orders and execution durations. Simulation results demonstrate the efficiency of our approach. Yunchuan Guo, Zifu Li, Fenghua Li 0001, Liang Fang 0009, Lihua Yin, Jin Cao 0001 |
ICC | 3 |
| 2020 | Securing instruction interaction for hierarchical management
Fenghua Li 0001, Zifu Li, Liang Fang 0009, Yaobing Xu, Yunchuan Guo |
J. Parallel Distributed Comput. | 2 |
| 2020 | Neural Network-Based Adaptive Control for Pure-Feedback Stochastic Nonlinear Systems With Time-Varying Delays and Dead-Zone InputabstractFor a class of stochastic nonlinear systems in pure-feedback form with dead-zone input and multiple time-varying delays, a novel neural network (NN)-based adaptive control approach is presented in this paper through the use of backstepping approach and dynamic surface technique. By choosing proper Lyapunov-Krasovskii functionals, utilizing the characteristic of hyperbolic tangent functions and adopting the function separation technique, difficulties of controller design that introduced by the time-varying delays can be dealt with properly. Moreover, all unknown nonlinear functions are lumped together and approximated by the NN. Additionally, any information over the boundedness of dead-zone parameters is not needed in the process of controller design. The control scheme proposed in this paper ensures the boundedness in probability of all signals in the closed-loop system, besides, excellent performance of arbitrarily small tracking error will be achieved by selecting control parameters appropriately. At last, two numerical simulation examples are provided to verify the validity of the designed algorithm. Zifu Li, Tieshan Li 0001, Gang Feng 0001, Qi-He Shan |
IEEE Trans. Syst. Man Cybern. Syst. | 1 |
| 2019 | Cyberspace-Oriented Access Control: A Cyberspace Characteristics-Based Model and its PoliciesabstractWith wide development of various information technologies, our daily activities are becoming deeply dependent on cyberspace. People often use handheld devices (e.g., mobile phones or laptops) to publish social messages, facilitate remote e-health diagnosis, or monitor a variety of surveillance. However, security insurance for these activities remains as a significant challenge. Representation of security purposes and their enforcement are two main issues in security of cyberspace. To address these challenging issues, we propose a cyberspace-oriented access control model (CoAC) for cyberspace whose typical usage scenario is as follows. Users leverage devices via network of networks to access sensitive objects with temporal and spatial limitations. We generalize subjects and objects in cyberspace and propose scene-based access control. To enforce security purposes, we argue that all operations on information in cyberspace are combinations of atomic operations. If every single atomic operation is secure, then the cyberspace is secure. Taking applications in the browser-server architecture as an example, we present seven atomic operations for these applications. A number of cases demonstrate that operations in these applications are combinations of introduced atomic operations. We also design a series of security policies for each atomic operation. Finally, we demonstrate both feasibility and flexibility of our CoAC model by examples. Fenghua Li 0001, Zifu Li, Weili Han, Ting Wu 0001, Yunchuan Guo, Jinjun Chen |
IEEE Internet Things J. | 2 |
| 2016 | Dynamic Surface Sliding Mode Algorithm Based on Approximation for Three-Dimensional Trajectory Tracking Control of an AUV
Tieshan Li 0001, Zifu Li |
ICONIP (1) | 4 |
| 2016 | Adaptive neural control of pure-feedback stochastic nonlinear systems with multiple unknown time-varying delaysabstractBy the combination of the adaptive backstepping design with the dynamic surface control technique, an novel adaptive neural control approach is investigated for a class of pure-feedback stochastic nonlinear systems with multiple unknown time-varying delays. To overcome the design difficulty arising from the non-affine structure of pure-feedback stochastic systems, the mean value theorem is exploited. The design difficulties due to multiple unknown time-varying delay functions are overcome by using the function separation technique, the appropriate Lyapunov-Krasovskii functionals and the desirable property of hyperbolic tangent functions. The radial-basis-function (RBF) neural networks are utilized to approximate the unknown nonlinear functions. It is shown that the proposed control approach can guarantee that all signals of the closed-loop system are bounded in probability, and the tracking errors can be made arbitrarily small in probability by choosing suitable design parameters. Finally, simulation example is provided to demonstrate the effectiveness of the proposed control scheme. Zifu Li, Tieshan Li 0001, Gang Feng 0001 |
IJCNN | 1 |
| 2015 | Adaptive Neural Network Control for a Class of Stochastic Nonlinear Strict-Feedback SystemsabstractAn adaptive neural network control approach is proposed for a class of stochastic nonlinear strict-feedback systems with unknown nonlinear function in this paper. Only one NN (neural network) approximator is used to tackle unknown nonlinear functions at the last step and only one actual control law and one adaptive law are contained in the designed controller. This approach simplifies the controller design and alleviates the computational burden. The Lyapunov Stability analysis given in this paper shows that the control law can guarantee the solution of the closed-loop system uniformly ultimate boundedness (UUB) in probability. The simulation example is given to illustrate the effectiveness of the proposed approach. Zifu Li, Tieshan Li 0001 |
ISNN | 1 |
| 2015 | Adaptive NN control for a class of stochastic nonlinear systems with unmodeled dynamics using DSC technique
Zifu Li, Tieshan Li 0001, Baobin Miao, C. L. Philip Chen |
Neurocomputing | 1 |
| 2015 | A novel single fuzzy approximation based adaptive control for a class of uncertain strict-feedback discrete-time nonlinear systems
Zhongming Xiao, Tieshan Li 0001, Zifu Li |
Neurocomputing | 3 |
| 2015 | Output-Feedback Adaptive Neural Control for Stochastic Nonlinear Time-Varying Delay Systems With Unknown Control DirectionsabstractThis paper presents an adaptive output-feedback neural network (NN) control scheme for a class of stochastic nonlinear time-varying delay systems with unknown control directions. To make the controller design feasible, the unknown control coefficients are grouped together and the original system is transformed into a new system using a linear state transformation technique. Then, the Nussbaum function technique is incorporated into the backstepping recursive design technique to solve the problem of unknown control directions. Furthermore, under the assumption that the time-varying delays exist in the system output, only one NN is employed to compensate for all unknown nonlinear terms depending on the delayed output. Moreover, by estimating the maximum of NN parameters instead of the parameters themselves, the NN parameters to be estimated are greatly decreased and the online learning time is also dramatically decreased. It is shown that all the signals of the closed-loop system are bounded in probability. The effectiveness of the proposed scheme is demonstrated by the simulation results. Tieshan Li 0001, Zifu Li, Dan Wang 0001, C. L. Philip Chen |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2013 | Adaptive NN Dynamic Surface Control for Stochastic Nonlinear Strict-Feedback Systems
Zifu Li, Tieshan Li 0001, Xiaori Gao |
ISNN (2) | 1 |