Liangyi Gong

dblp:151/5896 · DBLP profile ↗
← Back
38ranked-venue papers
11as first author
24since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 24 · 7 first-author · 16 since 2021Systems, architecture and hardware · 6 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Optimizing multi-objective strategies for enhanced Tor De-anonymization
abstract
Abstract Tor employs multi-layer encryption and three-hop circuits to provide low-latency anonymity. While indispensable for privacy, these same properties can also be misused to conceal illicit activity. This dual-use nature makes effective de‑anonymization essential under appropriate, policy-bounded oversight, so that harmful behavior can be uncovered without undermining legitimate use. Yet de‑anonymization is not free: taking nodes offline and deploying honeypots consumes significant resources, increases exposure, and risks degrading network availability. Prior work faces two limitations: (i) it decouples the choice of which node to target from which method to apply, overlooking their strong coupling; and (ii) it often evaluates effectiveness with narrow, single-effect proxies, neglecting collateral network impact and operational cost. To support better de‑anonymization, we model joint node–technique selection as a tri-objective problem balancing attack gain ( AP ), attack impact ( AI ), and attack cost( AC ). For each feasible node–method pair we compute these three metrics, extract the Pareto set, prune with $$\epsilon$$ ϵ -constraints, and select a preference-aware compromise with VIKOR. In a Docker-orchestrated testbed, this Pareto-first pipeline achieves about $$+50\%$$ + 50 % higher attack gain and roughly $$-29\%$$ - 29 % lower attack Impact and attack cost compared with random selection.
Yali Yuan, Ruolin Ma, Liangyi Gong, Guang Cheng 0001
Cybersecur.4
2024 Robust Malicious Domain Detection Based on Spatio-Temporal Hypergraph Networks
abstract
Malicious domains serve as significant resources for adversaries to execute cyber attacks and are crucial indicators for detecting network intrusions. In practical scenarios, malicious domains associated with various attacks are intermingled within DNS traffic, leading to variability in the performance of machine learning-based detection methods. To address this challenge, we have collected extensive DNS traffic data spanning 12 months from a real-world large-scale network with 1 million users. From this dataset, we have extracted numerous requested domains, encompassing 267 attacks that exploit malicious domain names. Furthermore, we have observed that the distinct properties of malicious domains associated with different attacks contribute to the fluctuating performance of machine learning-based detection models. Consequently, we have introduced a spatiotemporal hypergraph network model, which establishes high-order relationships among domain properties to enhance the generalization capability and robustness of the detection model. The results of extensive testing experiments demonstrate that our model achieves remarkable performance, with an average precision of 97% and recall of 98%.
Liangyi Gong, Kunxian Lv, Chun Long, Huanran Wang
ISPA1
2024 A Measurement Study of DNS Query Protocols in Mobile Networks: Efficiency, Reliability and Choice
abstract
The Domain Name System (DNS) runs as a fundamental infrastructure of the mobile Internet. Various DNS protocols employed in the current network ecology can be predominantly classified as unencrypted DNS and encrypted DNS. However, existing research mainly focuses on assessing DNS performance within conventional internet structures, neglecting their evaluation in mobile contexts. In our pioneering study examining DNS within mobile networks, we developed an Android-based application to evaluate the efficiency and reliability of DNS protocols. The App issues nine domain name lookups to four cloud DNS providers supporting unencrypted and encrypted DNS protocols. Collaborating with volunteers from four countries, we collected about 52,000 test records. Our findings reveal substantial variability in the efficiency and reliability of all DNS protocols across different mobile scenarios. Overall, encrypted DNS protocols exhibit superior efficiency compared to plaintext DNS when oriented towards cloud DNS resolvers. In high-speed mobile scenarios, all DNS protocols demonstrate reduced efficiency, with encrypted DNS protocols showing relatively higher reliability. Our broad-scale measurement results indicate that the performance of DNS protocols varies across mobile contexts, but users are typically uninformed about these differences and do not realize how to break free. Intending to assist users in selecting an optimal DNS protocol, we propose a protocol choice model based on auto-encoding LSTM networks which leverages features of networking and protocols to predict the most suitable DNS protocol with reduced query time and enhanced reliability in the current scenario. Notably, we have achieved the prediction of the optimal DNS protocol for the future by foreseeing the network status ahead. Empirical results demonstrate an impressive 98.73% accuracy in prediction of DNS protocol selection.
Liangyi Gong, Lanqi Yang, Chun Long, Xiaochen Fan, Daibo Liu, Changhua Pei
MSN1
2024 A Large-Scale Study of Abnormal Recursive DNS
Anlei Hu, Liangyi Gong, Jieling Xie, Yufu Li, Gaogang Xie
NPC (2)2
2024 LTAChecker: Lightweight Android Malware Detection Based on Dalvik Opcode Sequences Using Attention Temporal Networks
abstract
Android applications have emerged as a prime target for hackers. Android malware detection stands as a pivotal technology, crucial for safeguarding network security and thwarting anomalies. However, traditional static analysis makes it difficult to analyze new malicious applications, while dynamic analysis requires higher system resources. We propose a novel lightweight Android malware deep-learning detection framework based on attention temporal networks. This study delves into the Dalvik opcode sequences of Android malware, employing the N-gram algorithm to partition sequences and extract contextual information features. Then, LSTM and TCN algorithms are employed to capture long-term dependencies and local features, enabling comprehensive comprehension of temporal information within Dalvik opcode sequences. Especially, TCN facilitates feature extraction across various time scales, thereby enabling the detection of anomaly patterns across diverse temporal scales within Dalvik opcode sequences. Moreover, we introduce multi-head attention mechanisms and reinforced learning to direct the model’s focus toward behavioral cues within malicious software sequences. Finally, extensive experiment results show that our proposed methodology and model exhibit higher detection accuracy and robustness, achieving an accuracy rate of 98.69% on average, surpassing traditional machine learning methods such as random forest, and Pseudo-Label deep neural networks.
Liangyi Gong, Xiuliang Mo, Guozhong Dong
IEEE Internet Things J.2
2024 Who Should We Blame for Android App Crashes? An In-Depth Study at Scale and Practical Resolutions
abstract
Android system has been widely deployed in energy-constrained IoT devices for many practical applications, such as smart phone, smart home, healthcare, fitness, and beacons. However, Android users oftentimes suffer from app crashes, which directly disrupt user experience and could lead to data loss. Till now, the community have limited understanding of their prevalence, characteristics, and root causes. In this article, we make an in-depth study of the crash events regarding ten very popular apps of different genres, based on fine-grained system-level traces crowd-sourced from 93 million Android devices. We find that app crashes occur prevalently on the various hardware models studied, and better hardware does not seem to essentially relieve the problem. Most importantly, we unravel multi-fold root causes of app crashes, and pinpoint that the most crashes stem from the subtle yet crucial inconsistency between app developers’ supposed memory/process management model and Android’s actual implementations. We design practical approaches to addressing the inconsistency; after large-scale deployment, they reduce 40.4% of the app crashes with negligible system overhead. In addition, we summarize important lessons learned from this study, and have released our measurement code/data to the community.
Liangyi Gong, Hao Lin 0005, Daibo Liu, Lanqi Yang, Hongyi Wang 0009, Jiaxing Qiu, Zhenhua Li 0001, Feng Qian 0001
ACM Trans. Sens. Networks1
2023 Quicksolver: A lightweight malicious domains detection system based on adaptive autoencoder
abstract
The Domain Name System (DNS) plays a critical role in the Internet, making it a popular target for cyber attackers. Malicious actors use DNS to locate their command and control servers, and spam often contains URLs linked to domains that host malicious servers. Detecting such malicious domain activities is essential. While many prior works have shown promising results in detecting malicious domains, the time and storage required during detection are relatively high.In this paper, we propose a lightweight and effective malicious domain detection system called Quicksolver, ideal for large-scale networks. Our system uses only domain features, eliminating the need for additional costs associated with DNS traffic and registration information. Additionally, we use an improved autoencoder as our classifier, combining it with neural networks to avoid the need for setting and adjusting thresholds manually.We evaluated Quicksolver using malicious data collected from a certain ISP over three months. The results show that Quicksolver has better detection ability and lower detection time compared to other state-of-the-art methods. Furthermore, it can automatically identify unknown malicious domains that are misused in seven types of cyber attacks.
Jinxia Wei, Liangyi Gong, Yuhao Fu
LCN4
2023 Virtual Device Farms for Mobile App Testing at Scale: A Pursuit for Fidelity, Efficiency, and Accessibility
abstract
Virtual devices based on device emulation have been widely used in lab research of mobile app testing for their efficiency and low cost. However, it remains controversial to use virtual devices for app testing in industry, given the inherent difficulties of high-fidelity emulation across diverse mobile systems and devices. Hence, mobile app companies still rely on physical device farms or services like AWS Device Farm.
Hao Lin 0005, Jiaxing Qiu, Hongyi Wang 0009, Zhenhua Li 0001, Liangyi Gong, Yunhao Liu 0001, Feng Qian 0001, Zhao Zhang 0001, Tianyin Xu
MobiCom5
2023 Robust Intrusion Detection for Industrial IoT
abstract
Due to the significant role of Industrial Internet of Things (IIoT) in industrial systems, it often faces numerous network attacks. Therefore, intrusion detection systems are crucial for real-world IIoT protection and network security solutions to propose. However, current rule-based and machine learning-based IIoT intrusion detection systems suffer from low robustness when facing complex and dynamic network attacks. To address these challenges, this paper proposes a novel intrusion detection model named RASNet (Residual Attention Self-learning Network), based on deep reinforcement learning. The model introduces residual networks to enhance its ability to represent complex attack features effectively as well as address problems such as gradient vanishing and exploding. Additionally, the model incorporates multiple layers of attention mechanisms into convolutional neural networks, in order to improve the feature extraction capability of convolutional blocks, finally key information can be captured further. By dynamically adjusting the weights of feature maps, the model highlights crucial information related to malicious attacks, promoting accurate classification. To handle the issues of imbalanced attack samples and adaptability to various attack types, the model introduces a self-learning mechanism. This mechanism dynamically adjusts to different data distributions and attack types, enhancing the model’s adaptability and generalization capability. Through the backpropagation algorithm, the model dynamically adjusts the weights of different attack types, thereby improving the accuracy and robustness of malicious attack detection. This self-learning mechanism enables the model to accurately detect malicious attacks in the Industrial Internet of Things and enhance its robustness and reliability in various attack scenarios. Experimental evaluations are conducted on the publicly available dataset Edge-IIoTset, which contains 14 types of attacks for comparison with control group models. The results demonstrate plain improvements in classification accuracy achieved by our proposed model, with an accuracy of $94.97 \%$ for 15 -class classification. These results also validate the effectiveness and robustness of our model compared to existing machine learning-based models in terms of classification performance and accuracy.
Huaishuo Ren, Liangyi Gong, Xiuliang Mo, Lanqi Yang, Zuwei Yin
MSN2
2022 A Comparative Approach to Resurrecting the Market of MOD Vehicular Crowdsensing
abstract
With the popularity of Mobility-on-Demand (MOD) vehicles, a new market called MOD-Vehicular-Crowdsensing (MOVE-CS) was introduced for drivers to earn more by collecting road data. Unfortunately, MOVE-CS failed after two years of operation. To identify the root cause, we survey 581 drivers and reveal its simple operation model based on blindly competitive rewards. This model brings most drivers few yields, resulting in their withdrawals. In contrast, a similar market termed MOD-Human-Crowdsensing (MOMAN-CS) remains successful thanks to a complex model based on exclusively customized rewards. Hence, we wonder whether MOVE-CS can be resurrected by learning from MOMAN-CS. Despite considerable similarity, we can hardly apply the operation model of MOMAN-CS to MOVE-CS, since drivers are also concerned with passenger missions that dominate their earnings. To this end, we analyze a large-scale dataset of 12,493 MOD vehicles, finding that drivers have explicit preference for short-term, immediate gains as well as implicit rationality in pursuit of long-term, stable profits. Therefore, we design a novel operation model for MOVE-CS, at the heart of which lies a spatial-temporal differentiation-aware task recommendation scheme empowered by submodular optimization. Applied to the dataset, our design would essentially benefit both the drivers and platform, thus possessing the potential to resurrect MOVE-CS.
Chaocan Xiang, Suining He, Yuben Qu, Zhenhua Li 0001, Liangyi Gong, Chao Chen 0004
INFOCOM7
2022 Trinity: High-Performance Mobile Emulation through Graphics Projection
Hao Lin 0005, Zhenhua Li 0001, Chengen Huang, Yunhao Liu 0001, Feng Qian 0001, Liangyi Gong, Tianyin Xu
OSDI7
2022 EdgeLoc: A Robust and Real-Time Localization System Toward Heterogeneous IoT Devices
abstract
Indoor localization has become an essential demand driven by indoor location-based services (ILBSs) for mobile users. With the rising of Internet of Things (IoT), heterogeneous smartphones and wearables have become ubiquitous. However, the ILBSs for heterogeneous IoT devices confront significant challenges, such as received signal strength (RSS) variances caused by hardware heterogeneity, multipath reflections from complex environments, and localization time restricted by computation resources. This article proposes EdgeLoc, a robust and real-time indoor localization system toward heterogeneous IoT devices to solve the above challenges. In particular, the RSS fingerprinting data of Wi-Fi is employed for localization and tackling the heterogeneity of IoT devices in twofold. First, feature-level and signal-level solutions are presented to address the random RSS variances. At the feature level, this work proposes a novel capsule neural network model to efficiently extract incremental features from RSS fingerprinting data. At the signal level, a multistep dataflow is further devised to process RSS fingerprints into image-like data, which utilizes the feature matrix to reduce absolute sensing errors introduced by hardware heterogeneity. Second, an edge-IoT framework is designed to utilize the edge server to train the deep learning model and further supports real-time localization for heterogeneous IoT devices. Extensive field experiments with over 33 600 data points are conducted to validate the effectiveness of EdgeLoc with a large-scale Wi-Fi fingerprint data set. The results show that EdgeLoc outperforms the state-of-the-art SAE-CNN method in localization accuracy by up to 14.4%, with an average error of 0.68 m and an average positioning time of 2.05 ms.
Qianwen Ye, Hongxia Bie, Kuanching Li, Xiaochen Fan, Liangyi Gong, Xiangjian He, Gengfa Fang
IEEE Internet Things J.5
2022 Wi-Gym: Gymnastics Activity Assessment Using Commodity Wi-Fi
abstract
Practicing gymnastics activities at home with online resources has become an increasingly popular choice due to its convenience and accessibility. However, without face-to-face guidance by a trainer, a major challenge is how to assess the quality of performed gymnastics activities, effectively and fairly. Existing intrusive assessing approaches usually require live cameras or wearable sensors, which usually generate privacy and feasibility concerns. There is a lacking of accurate approaches to assess the quality of the activities. To address these challenges, a gymnastics activity assessment approach is proposed in this article, and Wi-Gym, an effective first-of-its-kind gymnastics activity assessment system is developed utilizing commodity Wi-Fi. Wi-Gym is designed to compare the activity-induced channel state information (CSI) dynamics by an exerciser and that of a trainer utilizing dynamic time warping (DTW). The comparison results are provided by a fuzzy inference system (FIS). To make Wi-Gym robust to the changes in the environment, domain adaptation is leveraged to mitigate the data distribution imbalance caused by the environment changes. Extensive experimental studies have been conducted using Wi-Gym, acoustic, and video-based sensing systems. The experimental results validate the effectiveness and robustness of the proposed approach.
Lei Zhang 0024, Wenyuan Huang, Xiaoxia Jia, Xiaojie Fan, Xiaochen Fan, Liangyi Gong, Wenyuan Tao, Shiwen Mao
IEEE Internet Things J.6
2022 Toward robust and adaptive pedestrian monitoring using CSI: design, implementation, and evaluation
Jialai Liu, Kai Liu 0001, Feiyu Jin, Liangyi Gong
Neural Comput. Appl.4
2022 Device-free near-field human sensing using WiFi signals
Liangyi Gong, Chaocan Xiang, Xiaochen Fan, Tao Wu 0011, Chao Chen 0004, Miao Yu 0006, Wu Yang 0001
Pers. Ubiquitous Comput.1
2022 Overlay-Based Android Malware Detection at Market Scales: Systematically Adapting to the New Technological Landscape
abstract
Androidoverlayenables one app to draw over other apps by creating an extraViewlayer atop the hostView, which nevertheless can be exploited by malicious apps (malware) to attack users. To combat this threat, prior countermeasures concentrate on restricting the capabilities of overlays at the OS level while sacrificing overlays’ usability; recently, the overlay mechanism has been substantially updated to prevent a variety of attacks, which however can still be evaded by considerable adversaries. To address these shortcomings, a more pragmatic approach is to enableearly detectionof overlay-based malware during the app market review process, so that all the capabilities of overlays can stay unchanged. For this purpose, in this paper we first conduct a large-scale comparative study of overlay characteristics in benign and malicious apps, and then implement the OverlayChecker system to automatically detect overlay-based malware for one of the world’s largest Android app stores. In particular, we have made systematic efforts in feature engineering, UI exploration, emulation architecture, and run-time environment, thus maintaining high detection accuracy (97 percent precision and 97 percent recall) and short per-app scan time ($\sim$1.7 minutes) with only two commodity servers, under an intensive workload of$\sim$10K newly submitted apps per day.
Liangyi Gong, Zhenhua Li 0001, Hongyi Wang 0009, Hao Lin 0005, Xiaobo Ma 0001, Yunhao Liu 0001
IEEE Trans. Mob. Comput.1
2021 A nationwide census on wifi security threats: prevalence, riskiness, and the economics
abstract
Carrying over 75% of the last-mile mobile Internet traffic, WiFi has inevitably become an enticing target for various security threats. In this work, we characterize a wide variety of real-world WiFi threats at an unprecedented scale, involving 19 million WiFi access points (APs) mostly located in China, by deploying a crowdsourced security checking system on 14 million mobile devices in the wild. Leveraging the collected data, we reveal the landscape of nationwide WiFi threats for the first time. We find that the prevalence, riskiness, and breakdown of WiFi threats deviate significantly from common understandings and prior studies. In particular, we detect attacks at around 4% of all WiFi APs, uncover that most WiFi attacks are driven by an underground economy, and provide strong evidence of web analytics platforms being the bottleneck of its monetization chain. Further, we provide insightful guidance for defending against WiFi attacks at scale, and some of our efforts have already yielded real-world impact---effectively disrupted the WiFi attack ecosystem.
Hao Lin 0005, Zhenhua Li 0001, Feng Qian 0001, Qi Alfred Chen, Zhiyun Qian, Wei Liu 0148, Liangyi Gong, Yunhao Liu 0001
MobiCom8
2021 Fast and Light Bandwidth Testing for Internet Users
Xinlei Yang, Xianlong Wang 0003, Zhenhua Li 0001, Yunhao Liu 0001, Feng Qian 0001, Liangyi Gong, Tianyin Xu
NSDI6
2021 A nationwide study on cellular reliability: measurement, analysis, and enhancements
abstract
With recent advances on cellular technologies (such as 5G) that push the boundary of cellular performance, cellular reliability has become a key concern of cellular technology adoption and deployment. However, this fundamental concern has never been addressed due to the challenges of measuring cellular reliability on mobile devices and the cost of conducting large-scale measurements. This paper closes the knowledge gap by presenting the first large-scale, in-depth study on cellular reliability with more than 70 million Android phones across 34 different hardware models. Our study identifies the critical factors that affect cellular reliability and clears up misleading intuitions indicated by common wisdom. In particular, our study pinpoints that software reliability defects are among the main root causes of cellular data connection failures. Our work provides actionable insights for improving cellular reliability at scale. More importantly, we have built on our insights to develop enhancements that effectively address cellular reliability issues with remarkable real-world impact---our optimizations on Android's cellular implementations have effectively reduced 40% cellular connection failures for 5G phones and 36% failure duration across all phones.
Yang Li 0092, Hao Lin 0005, Zhenhua Li 0001, Yunhao Liu 0001, Feng Qian 0001, Liangyi Gong, Xianlong Xin, Tianyin Xu
SIGCOMM6
2021 Fine-grained Trust-based Routing Algorithm for Wireless Sensor Networks
Liangyi Gong, Chundong Wang 0002, Zhentang Zhao
Mob. Networks Appl.1
2021 Malware Detection Based on Multi-level and Dynamic Multi-feature Using Ensemble Learning at Hypervisor
Jian Zhang 0068, Liangyi Gong, Zhaojun Gu, Dapeng Man, Wu Yang 0001, Wenzhen Li
Mob. Networks Appl.3
2021 Fisher information-empowered sensing quality quantification for crowdsensing networks
Chaocan Xiang, Xiaochen Fan, Chao Chen 0004, Liangyi Gong, Songtao Guo
Neural Comput. Appl.4
2021 BuildSenSys: Reusing Building Sensing Data for Traffic Prediction With Cross-Domain Learning
abstract
With the rapid development of smart cities, smart buildings are generating a massive amount of building sensing data by the equipped sensors. Indeed, building sensing data provides a promising way to enrich a series of data-demanding and cost-expensive urban mobile applications. In this paper, as a preliminary exploration, we study how to reuse building sensing data to predict traffic volume on nearby roads. Compared with existing studies, reusing building sensing data has considerable merits of cost-efficiency and high-reliability. Nevertheless, it is non-trivial to achieve accurate prediction on such cross-domain data with two major challenges. First, relationships between building sensing data and traffic data are not unknown as prior, and the spatio-temporal complexities impose more difficulties to uncover the underlying reasons behind the above relationships. Second, it is even more daunting to accurately predict traffic volume with dynamic building-traffic correlations, which are cross-domain, non-linear, and time-varying. To address the above challenges, we design and implement BuildSenSys, a first-of-its-kind system for nearby traffic volume prediction by reusing building sensing data. Our work consists of two parts, i.e., Correlation Analysis and Cross-domain Learning. First, we conduct a comprehensive building-traffic analysis based on multi-source datasets, disclosing how and why building sensing data is correlated with nearby traffic volume. Second, we propose a novel recurrent neural network for traffic volume prediction based on cross-domain learning with two attention mechanisms. Specifically, a cross-domain attention mechanism captures the building-traffic correlations and adaptively extracts the most relevant building sensing data at each predicting step. Then, a temporal attention mechanism is employed to model the temporal dependencies of data across historical time intervals. The extensive experimental studies demonstrate that BuildSenSys outperforms all baseline methods with up to 65.3 percent accuracy improvement (e.g., 2.2 percent MAPE) in predicting nearby traffic volume. We believe that this work can open a new gate of reusing building sensing data for urban traffic sensing, thus establishing connections between smart buildings and intelligent transportation.
Xiaochen Fan, Chaocan Xiang, Chao Chen 0004, Panlong Yang, Liangyi Gong, Xudong Song, Priyadarsi Nanda, Xiangjian He
IEEE Trans. Mob. Comput.5
2021 Systematically Landing Machine Learning onto Market-Scale Mobile Malware Detection
abstract
Despite being crucial to today's mobile ecosystem, app markets have meanwhile become a natural, convenient malware delivery channel as they actually “lend credibility” to malicious apps. In the past few years, machine learning (ML) techniques have been widely explored for automated, robust malware detection, but till now we have not seen an ML-based malware detection solution applied at market scales. To systematically understand the real-world challenges, we conduct a collaborative study with T-Market, a popular Android app market that offers us large-scale ground-truth data. Our study illustrates that the key to successfully developing such systems is multifold, including feature selection and encoding, feature engineering and exposure, app analysis speed and efficacy, developer and user engagement, as well as ML model evolution. Failure in any of the above aspects could lead to the “wooden barrel effect” of the whole system. This article presents our judicious design choices and first-hand deployment experiences in building a practical ML-powered malware detection system. It has been operational at T-Market, using a single commodity server to check ~12K apps every day, and has achieved an overall precision of 98.9 percent and recall of 98.1 percent with an average per-app scan time of 0.9 minutes.
Liangyi Gong, Hao Lin 0005, Zhenhua Li 0001, Feng Qian 0001, Yang Li 0092, Xiaobo Ma 0001, Yunhao Liu 0001
IEEE Trans. Parallel Distributed Syst.1
2020 Experiences of landing machine learning onto market-scale mobile malware detection
abstract
App markets, being crucial and critical for today's mobile ecosystem, have also become a natural malware delivery channel since they actually "lend credibility" to malicious apps. In the past decade, machine learning (ML) techniques have been explored for automated, robust malware detection. Unfortunately, to date, we have yet to see an ML-based malware detection solution deployed at market scales. To better understand the real-world challenges, we conduct a collaborative study with a major Android app market (T-Market) offering us large-scale ground-truth data. Our study shows that the key to successfully developing such systems is manifold, including feature selection/engineering, app analysis speed, developer engagement, and model evolution. Failure in any of the above aspects would lead to the "wooden barrel effect" of the entire system. We discuss our careful design choices as well as our first-hand deployment experiences in building such an ML-powered malware detection system. We implement our design and examine its effectiveness in the T-Market for over one year, using a single commodity server to vet ~ 10K apps every day. The evaluation results show that this design achieves an overall precision of 98% and recall of 96% with an average per-app scan time of 1.3 minutes.
Liangyi Gong, Zhenhua Li 0001, Feng Qian 0001, Qi Alfred Chen, Zhiyun Qian, Hao Lin 0005, Yunhao Liu 0001
EuroSys1
2020 Deep learning for intelligent traffic sensing and prediction: recent advances and future challenges
Xiaochen Fan, Chaocan Xiang, Liangyi Gong, Yuben Qu, Saeed Amirgholipour Kasmani, Priyadarsi Nanda, Xiangjian He
CCF Trans. Pervasive Comput. Interact.3
2019 Demo: Robust Contactless Gesture Recognition Using Commodity WiFi
Shujie Ren, Huaibin Wang, Liangyi Gong, Chaocan Xiang
EWSN4
2019 Targeted Malicious Email Detection Using Hypervisor-Based Dynamic Analysis and Ensemble Learning
abstract
At present, email is still one of the most frequently used communication tools for organizations and individuals. With the leakage of personal privacy information, targeted malicious email (TME) is becoming a prominent targeted cyber attack vector in today's Internet. This type of attack often uses personal information, about an individual, group of individuals, or an organization, to make a TME more believable and personalized. TME is effective to penetrate email defense system because it is fundamentally difficult for traditional email security method to distinguish legitimate emails from malicious emails. And TMEs often contain malicious URLs or malicious attachments, which are extremely aggressive and destructive. In order to effectively deal with this new type of malicious email attack, this paper proposes a dynamic detection method for malicious email. We simulate the recipient opening the email in the virtual machine (VM), accessing the URL and activating the attachment. And we use the virtual machine introspection (VMI) and memory forensics analysis (MFA) technology to obtain the dynamic features of the email by the out-of-VM. Then we use AdaBoostM1 ensemble learning method and Voting combination strategy to combine three base classifiers such as BayesNet, SMO and J48 to build a powerful classification model for detecting TME attacks. The AdaBoostM1 classifier achieved the high detection rates, with an AUC of 0.997, true positive rate (TPR) of 0.997, and false positive rate (FPR) of 0.015. In addition, our proposed detection method is superior to the 56 anti-virus engines on VirusTotal and most of the existing research works.
Jian Zhang 0068, Wenzhen Li, Liangyi Gong, Zhaojun Gu
GLOBECOM3
2019 Wi-Run: Device-free step estimation system with commodity Wi-Fi
Meiguang Liu, Lei Zhang 0024, Panlong Yang, Liangyi Gong
J. Netw. Comput. Appl.5
2019 Robust Light-Weight Magnetic-Based Door Event Detection with Smartphones
abstract
Doors as densely-deployed natural landmarks play an important role in improving indoor positioning systems. However, the state-of-the-art door event detection works are based on either vision or infrastructure, thus incurring non-trivial device or management cost. To address these problems, we present a Light-weight Magnetic-based Door Event Detection method, called LMDD. It leverages built-in magnetic sensors of common smartphones to achieve infrastructure-free door event detection. After analyzing the special features of sensors' readings changes caused by the door, we design LMDD scheme with three main components, including data acquisition, events identification and events denoising. Moreover, an improved and robust door event detection framework based on a majority-voting model is proposed to fuse multiple-dimensional sensing data from non-magnetic built-in sensors. We have implemented a prototype of LMDD on Android-based platform. Experimental results show that LMDD with only magnetic sensor achieves door event detection accuracy of around 80 percent on average, ranging from 70 to 87 percent in various typical indoor environments. The enhanced LMDD based on the fusion of heterogeneous sensors can achieve a much higher door event detection accuracy of 90 percent on average.
Liangyi Gong, Chaocan Xiang, Zhenhua Li 0001, Chen Qian 0001, Panlong Yang
IEEE Trans. Mob. Comput.1
2018 Malware Detection Based on Dynamic Multi-Feature Using Ensemble Learning at Hypervisor
abstract
More data and applications are moving to the cloud, which presents many new security risks. Malware is one of the most significant threats to cloud computing. In this paper, we explore to employ virtual machine introspection(VMI) and memory forensics analysis(MFA) techniques to detect malware running in guest virtual machines. Our scheme differs from existing malware detection methods based on virtualization technology in three aspects. First, this paper combines VMI with MFA to extract multiple type features in the guest virtual machine at the same time. Our scheme can effectively minimize the data acquisition overhead. Second,compared with single dynamic feature or multiple static feature detection methods, our data acquisition method employs dynamic multiple type features, and effectively promotes the ability of sophisticated malware detection. Finally,we use AdaBoost ensemble learning method and combination strategy of voting to improve the accuracy and generalization ability of the overall classifier. The experimental results based on a lot of real-world malware show that our scheme can achieve a detection accuracy of 0.9975. Our approach can improve virtual machines security, and further effectively enhance the security of cloud computing environment.
Jian Zhang 0068, Liangyi Gong, Zhaojun Gu, Dapeng Man, Wu Yang 0001, Xiaojiang Du
GLOBECOM3
2018 Detecting Evil-Twin Attack with the Crowd Sensing of Landmark in Physical Layer
Chundong Wang 0002, Likun Zhu, Liangyi Gong, Zheli Liu, Xiuliang Mo, Min Li 0045
ICA3PP (4)3
2018 Wi-Run: Multi-Runner Step Estimation Using Commodity Wi-Fi
abstract
Step counting is a fundamental unit of human locomotion, and is a preferred metric for quantifying physical activity. However, the existing step counters are too inconvenient to wear and the treadmill can not count the steps. Recently, commercial Wi-Fi based device-free sensing shows a promising future for ubiquitous motion-based interactions and provides possibility for the device free step counting. Previous research of human activity sensing with commercial Wi- Fi mainly focuses on single person activity recognition. The primary challenge for the multi-person activity recognition is too difficult to derive each person's motion induced signal. All the independent running induced signals are mixed together with similar frequency and the common time-frequency analysis approaches do not work. The problem becomes even more difficult with only one pair of commodity Wi-Fi devices, which have limited number of antennas and bandwidth. In this paper, we propose Wi-Run, a multi-runner step estimation system with only one pair of commodity Wi-Fi devices. Wi-Run is composed of three innovative methods: (1) Canonical Polyadic (CP) decomposition can effectively separate running related signals. (2) The stable signal matching algorithm is applied to find the decomposed signal pairs for each runner. (3) The peak detection method is adopted to estimate steps for each runner. The multi-runner step estimation is achieved without introducing extra overhead. The experimental results illustrate the superior performance of Wi-Run, whose accuracy is about 88.25% on average.
Meiguang Liu, Liangyi Gong
SECON4
2018 LAMP: Lightweight and Accurate Malicious Access Points Localization via Channel Phase Information
Liangyi Gong, Chundong Wang 0002, Likun Zhu, Jian Zhang 0068, Wu Yang 0001, Chaocan Xiang
WASA1
2016 Robust WLAN-Based Indoor Fine-Grained Intrusion Detection
abstract
Intrusion detection plays a critical role in security of people's possessions. Approaches such as video-based, infrared-based, RFID, UWB, etc. can provide satisfying detection accuracy. However, they all require specialized hardware deployment and strict using conditions which hinder their wide deployment. Beyond communication, WLANs can also act as generalized sensor networks and there are several researches working on motion detection via WLAN due to its advantages in deployment flexibility, coverage, and cost efficiency. Nevertheless, they are unsuitable for intrusion detection as none of them can accurately detect human motion when the moving speed is very slow. This paper proposes SIED as an accurate method for Speed Independent device-free Entity Detection which is suitable for intrusion detection even when the entity's moving speed is very slow. The influence becomes much smaller when the entity is moving with a very slow speed. Previous methods have the limitations in that their performance downgrades sharply when the entity's moving speed is very slow. Recently, it has been shown that Channel State Information (CSI) at PHY layer of wireless network has the potential to detect moving entities more accurately. In this paper we leverage CSI of 802.11n wireless network and probability technique to detect entities of different moving speeds. SIED captures the variance of variances of amplitudes of each CSI subcarrier, and combines Hidden Markov Model (HMM) to make entity detection a probability problem. We implement SIED using commercial WiFi devices and evaluate our method using two typical testbeds and show that SIED can achieve an average detection accuracy of greater than 98% under different entity moving speed.
Jiguang Lv, Wu Yang 0001, Liangyi Gong, Dapeng Man, Xiaojiang Du
GLOBECOM3
2016 An adaptive wireless passive human detection via fine-grained physical layer information
Liangyi Gong, Wu Yang 0001, Zimu Zhou, Dapeng Man, Haibin Cai, Xiancun Zhou, Zheng Yang 0002
Ad Hoc Networks1
2015 LMDD: Light-Weight Magnetic-Based Door Detection with Your Smartphone
abstract
Doors are important landmarks for indoor positioning systems. Hence an accurate and light-weight door detection approach is highly desired. The state-of-the-art solutions are either vision based or infrastructure based, which incur nontrivial device or management cost. This paper presents a novel approach, Light-weight Magnetic-based Door Detection (LMDD), which only relies on the information from built-in sensors of a smartphone. LMDD detects a door by analyzing the change of magnetic signal and extracting special features caused by doors. It is light-weight in both computation and infrastructure cost. We have implemented a prototype of LMDD that has been installed on various Android phones. Experimental results show that LMDD achieves door detection accuracy of 74% in average, ranging from 66% to 85% in various typical environments such as offices, classrooms, residential houses, and a hospital.
Chen Qian 0001, Liangyi Gong, Zhenhua Li 0001, Yunhao Liu 0001
ICPP3
2015 Anomaly Detection in Microblogging via Co-Clustering
Wu Yang 0001, Guowei Shen, Wei Wang 0076, Liangyi Gong, Miao Yu 0006, Guozhong Dong
J. Comput. Sci. Technol.4