Yuli Deng

dblp:158/4719 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0001-7715-9966ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Ontology-Aware RAG for Improved Question-Answering in Cybersecurity Education
Chengshuai Zhao, Garima Agrawal, Tharindu Kumarage, Zhen Tan 0001, Yuli Deng, Ying-Chih Chen, Huan Liu 0001
IEEE Big Data6
2025 CyberBOT: Ontology-Grounded Retrieval Augmented Generation for Reliable Cybersecurity Education
abstract
Advancements in large language models (LLMs) have enabled the development of intelligent educational tools that support inquiry-based learning across technical domains. In cybersecurity education, where accuracy and safety are paramount, systems must go beyond surface-level relevance to provide information that is both trustworthy and domain-appropriate. To address this challenge, we introduce CyberBOT, a question-answering chatbot that leverages a retrieval-augmented generation (RAG) pipeline to incorporate contextual information from course-specific materials and validate responses using a domain-specific cybersecurity ontology. The ontology serves as a structured reasoning layer that constrains and verifies LLM-generated answers, reducing the risk of misleading or unsafe guidance. CyberBOT has been deployed in a large graduate-level course at Arizona State University (ASU), where more than one hundred students actively engage with the system through a dedicated web-based platform. Computational evaluations in lab environments highlight the potential capacity of CyberBOT, and a forthcoming field study will evaluate its pedagogical impact. By integrating structured domain reasoning with modern generative capabilities, CyberBOT illustrates a promising direction for developing reliable and curriculum-aligned AI applications in specialized educational contexts.
Chengshuai Zhao, Riccardo De Maria, Tharindu Kumarage, Kumar Satvik Chaudhary, Garima Agrawal, Ying-Chih Chen, Yuli Deng, Huan Liu 0001
CIKM9
2024 CyberQ: Generating Questions and Answers for Cybersecurity Education Using Knowledge Graph-Augmented LLMs
abstract
Building a skilled cybersecurity workforce is paramount to building a safer digital world. However, the diverse skill set, constantly emerging vulnerabilities, and deployment of new cyber threats make learning cybersecurity challenging. Traditional education methods struggle to cope with cybersecurity's rapidly evolving landscape and keep students engaged and motivated. Different studies on students' behaviors show that an interactive mode of education by engaging through a question-answering system or dialoguing is one of the most effective learning methodologies. There is a strong need to create advanced AI-enabled education tools to promote interactive learning in cybersecurity. Unfortunately, there are no publicly available standard question-answer datasets to build such systems for students and novice learners to learn cybersecurity concepts, tools, and techniques. The education course material and online question banks are unstructured and need to be validated and updated by domain experts, which is tedious when done manually. In this paper, we propose CyberGen, a novel unification of large language models (LLMs) and knowledge graphs (KG) to generate the questions and answers for cybersecurity automatically. Augmenting the structured knowledge from knowledge graphs in prompts improves factual reasoning and reduces hallucinations in LLMs. We used the knowledge triples from cybersecurity knowledge graphs (AISecKG) to design prompts for ChatGPT and generate questions and answers using different prompting techniques. Our question-answer dataset, CyberQ, contains around 4k pairs of questions and answers. The domain expert manually evaluated the random samples for consistency and correctness. We train the generative model using the CyberQ dataset for question answering task.
Garima Agrawal, Kuntal Pal, Yuli Deng, Huan Liu 0001, Ying-Chih Chen
AAAI3
2024 ILLATION: Improving Vulnerability Risk Prioritization by Learning From Network
abstract
Network administrators face the challenge of efficiently patching overwhelming volumes of vulnerabilities with limited time and resources. To address this issue, they must prioritize vulnerabilities based on the associated risk/severity measurements (i.e., CVSS). Existing solutions struggle to efficiently patch thousands of vulnerabilities on a network. This paper presents ILLATION, a proof-of-concept model that provides network-specific vulnerability risk prioritization to support efficient patching. ILLATION integrates AI techniques, such as neural networks and logical programming, to learn risk patterns from adversaries, vulnerability severity, and the network environment. It provides an integrated solution that learns and infers adversaries' motivation and ability in a network while also learning the constraints that restrict interactions between vulnerabilities and network elements. An evaluation of ILLATION against CVSS base and environmental metrics shows that it reflects changes in vulnerability scores and prioritization ranks as the same pattern as the CVSS model while identifying vulnerabilities with similar risk patterns to given adversaries better. On a simulated network with up to 10k vulnerable hosts and vulnerabilities, ILLATION can assess 1k vulnerabilities in about 4.5 minutes total, with an average running time of 0.19 seconds per vulnerability on a general-purpose computer.
Dijiang Huang, Guoliang Xue, Yuli Deng, Neha Vadnere, Liguang Xie
IEEE Trans. Dependable Secur. Comput.4
2023 Unraveled - A semi-synthetic dataset for Advanced Persistent Threats
abstract
Unraveled is a novel cybersecurity dataset capturing Advanced Persistent Threat (APT) attacks not available in the public domain. Existing cybersecurity datasets lack coherent information about sophisticated and persistent cyber-attack features, including attack planning and deployment, stealthiness of the attacker(s), longer dorm period between attack activities, etc. Our APT attack scenario in Unraveled is implemented on a real network system established on a cloud platform to emulate an organization’s network system. The new dataset provides a comprehensive network flow and host-level log information about the normal user(s) traffic and the cyber attacks traffic. To emulate realistic network traffic scenarios, Unraveled also includes attacks at different skills reflecting a typical organization’s threat posture, and by utilizing APT attack information from one of the well-known APT attack databases, i.e., MITRE’s APT-group database. Furthermore, we design and develop an Employee Behavior Generation (EBG) model to emulate multiple normal employees’ traffic and activities during a 6-week time period based on their pre-defined business functions. Using well-known machine learning models for anomaly detection, we show that the APT attack activities in Unraveled are hardly detected, indicating the need for more effective solutions that are based on datasets representing real world APT attacks.
Sowmya Myneni, Kritshekhar Jha, Abdulhakim Sabur, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Dijiang Huang
Comput. Networks5
2022 SCVS: On AI and Edge Clouds Enabled Privacy-preserved Smart-city Video Surveillance Services
abstract
Video surveillance systems are increasingly becoming common in many private and public campuses, city buildings, and facilities. They provide many useful smart campus/city monitoring and management services based on data captured from video sensors. However, the video surveillance services may also breach personally identifiable information, especially human face images being monitored; therefore, it may potentially violate the privacy of human subjects involved. To address this privacy issue, we introduced a large-scale distributed video surveillance service model, called Smart-city Video Surveillance (SCVS). SCVS is a video surveillance data collection and processing platform to identify important events, monitor, protect, and make decisions for smart campus/city applications. In this article, the specific research focus is on how to identify and anonymize human faces in a distributed edge cloud computing infrastructure. To preserve the privacy of data during video anonymization, SCVS utilizes a two-step approach: (i) parameter server-based distributed machine learning solution, which ensures that edge nodes can exchange parameters for machine learning-based training. Since the dataset is not located on a centralized location, the data privacy and ownership are protected and preserved. (ii) To improve the machine learning model’s accuracy, we presented an asynchronous training approach to protect data and model privacy for both data owners and data users, respectively. SCVS adopts an in-memory encryption approach, where edge computing nodes collect and process data in the memory of edge nodes in encrypted form. This approach can effectively prevent honest but curious attacks. The performance evaluation shows the presented privacy protection platform is efficient and effective compared to traditional centralized computing models as presented in Section 5 .
Sowmya Myneni, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Neha Vadnere, Dijiang Huang
ACM Trans. Internet Things3
2021 Global Feature Analysis and Comparative Evaluation of Freestyle In-Air-Handwriting Passcode for User Authentication
abstract
Freestyle in-air-handwriting passcode-based user authentication methods address the needs for Virtual Reality (VR) / Augmented Reality (AR) headsets, wearable devices, and game consoles where a physical keyboard cannot be provided for typing a password, but a gesture input interface is readily available. Such an authentication system can capture the hand movement of writing a passcode string in the air and verify the user identity using both the writing content (like a password) and the writing style (like a behavior biometric trait). However, distinguishing handwriting signals from different users is challenging in signal processing, feature extraction, and matching. In this paper, we provide a detailed analysis of the global features of in-air-handwriting signals and a comparative evaluation of such a user authentication framework. Also, we build a prototype system with two different types of hand motion capture devices, collect two datasets, and conduct an extensive evaluation.
Duo Lu, Yuli Deng, Dijiang Huang
ACSAC2
2021 NeoCyberKG: Enhancing Cybersecurity Laboratories with a Machine Learning-enabled Knowledge Graph
abstract
The hands-on lab is a critical component of cybersecurity education. There lacks of a coherent way to manage existing labs to provide a practical learning plan for learners in the cybersecurity area. Previous studies utilized the word embedding technologies to construct a knowledge graph and adopt it as a learning guide for students, but this approach has its limitations. In this paper, we present a new approach based on latent semantic analysis (LSA) method to replace word embedding in previous studies as it is more appropriate in a small-size corpus, and it is also able to create a mapping that connects both the topic of each lab and concepts contained in each lab. We use LSA to identify relevant semantic relations, extract relevant lab problems, and construct knowledge graphs from lab contents related to cybersecurity topics. We utilize the output of this study by establishing a web-based lab environment for students that: 1. providing lab index and searching, which contains concepts and knowledge extract from each lab. 2.building a recommendation/guidance system for cybersecurity labs and suggesting more relevant labs based on users learning preferences and past lab history to maximize learning outcomes. To measure the effectiveness of the proposed solution, we conducted a use case study and collected survey data from a graduate-level cybersecurity class at a public university. Our study shows that users tend to gain enhanced learning outcomes and express more interest in the cybersecurity area by leveraging the knowledge graph as a learning guide.
Yuli Deng, Dijiang Huang
ITiCSE (1)1
2020 Autonomous Security Analysis and Penetration Testing
abstract
Security Assessment of large networks is a challenging task. Penetration testing (pentesting) is a method of analyzing the attack surface of a network to find security vulnerabilities. Current network pentesting techniques involve a combination of automated scanning tools and manual exploitation of security issues to identify possible threats in a network. The solution scales poorly on a large network. We propose an autonomous security analysis and penetration testing framework (ASAP) that creates a map of security threats and possible attack paths in the network using attack graphs. Our framework utilizes: (i) state of the art reinforcement learning algorithm based on Deep-Q Network (DQN) to identify optimal policy for performing pentesting testing, and (ii) incorporates domain-specific transition matrix and reward modeling to capture the importance of security vulnerabilities and difficulty inherent in exploiting them. ASAP framework generates autonomous attack plans and validates them against real-world networks. The attack plans are generalizable to complex enterprise network, and the framework scales well on a large network. Our empirical evaluation shows that ASAP identifies non-intuitive attack plans on an enterprise network. The DQN planning algorithm employed scales well on a large network ~ 60 -70(s) for generating an attack plan for network with 300 hosts.
Ankur Chowdhary, Dijiang Huang, Jayasurya Sevalur Mahendran, Daniel Romo, Yuli Deng, Abdulhakim Sabur
MSN5
2018 Personalized Learning in a Virtual Hands-on Lab Platform for Computer Science Education
abstract
This Innovate Practice full paper presents a cloud-based personalized learning lab platform. Personalized learning is gaining popularity in online computer science education due to its characteristics of pacing the learning progress and adapting the instructional approach to each individual learner from a diverse background. Among various instructional methods in computer science education, hands-on labs have unique requirements of understanding learner's behavior and assessing learner's performance for personalization. However, it is rarely addressed in existing research. In this paper, we propose a personalized learning platform called ThoTh Lab specifically designed for computer science hands-on labs in a cloud environment. ThoTh Lab can identify the learning style from student activities and adapt learning material accordingly. With the awareness of student learning styles, instructors are able to use techniques more suitable for the specific student, and hence, improve the speed and quality of the learning process. With that in mind, ThoTh Lab also provides student performance prediction, which allows the instructors to change the learning progress and take other measurements to help the students timely. For example, instructors may provide more detailed instructions to help slow starters, while assigning more challenging labs to those quick learners in the same class. To evaluate ThoTh Lab, we conducted an experiment and collected data from an upper-division cybersecurity class for undergraduate students at Arizona State University in the US. The results show that ThoTh Lab can identify learning style with reasonable accuracy. By leveraging the personalized lab platform for a senior level cybersecurity course, our lab-use study also shows that the presented solution improves students engagement with better understanding of lab assignments, spending more effort on hands-on projects, and thus greatly enhancing learning outcomes.
Yuli Deng, Duo Lu, Chun-Jen Chung, Dijiang Huang
FIE1
2018 Improving student learning performance in a virtual hands-on lab system in cybersecurity education
abstract
This Research Work in Progress paper presents a study on improving student learning performance in a virtual hands-on lab system in cybersecurity education. As the demand for cybersecurity-trained professionals rapidly increasing, virtual hands-on lab systems have been introduced into cybersecurity education as a tool to enhance students' learning. To improve learning in a virtual hands-on lab system, instructors need to understand: what learning activities are associated with students' learning performance in this system? What relationship exists between different learning activities? What instructors can do to improve learning outcomes in this system? However, few of these questions has been studied for using virtual hands-on lab in cybersecurity education. In this research, we present our recent findings by identifying that two learning activities are positively associated with students' learning performance. Notably, the learning activity of reading lab materials (p <; 0:01) plays a more significant role in hands-on learning than the learning activity of working on lab tasks (p <; 0:05) in cybersecurity education.In addition, a student, who spends longer time on reading lab materials, may work longer time on lab tasks (p <; 0:01).
Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung
FIE2
2018 Conceptualizing Student Engagement in Virtual Hands-on Lab: Preliminary Findings from a Computer Network Security Course (Abstract Only)
abstract
Engaged students are more likely to spend longer time on study, and obtain a better academic performance. Previous studies investigated the role of student engagement in virtual learning environments (e.g., online course, online discussion forum, and intelligent tutoring systems). However, it is still challenging to engage students on a virtual hands-on lab system. Comparing to other virtual learning environment, students have a unique learning model -- learning by doing in virtual hands-on lab. To successfully engage students in a large hands-on lab in cybersecurity education, instructors need to understand how students engage in a lab session, and how their engagement affect lab learning outcome in this specific educational setting. In this paper, we developed a conceptual model, especially for virtual hands-on lab education, to describe student engagement during learning processes in working on virtual hands-on lab tasks. This model adopts two existing educational models on engagement behavior. Preliminary data was collected from 109 students' lab project in a computer network security course at Arizona State University in 2016 Fall semester. Pearson correlation coefficient analysis results reveal two statistically significant preliminary results: the longer time a student spends on reading lab instructional material, the more likely the student works longer time on lab tasks (p < 0.01); the longer time a student works on lab tasks, a better learning performance the student archives (p < 0.01).
Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung
SIGCSE2
2017 ThoTh Lab: A Personalized Learning Framework for CS Hands-on Projects (Abstract Only)
abstract
Personalized learning is often referred to a new learning approach by taking individual parameters such as learning preferences, abilities, skills and knowledge into account. In this poster, we present a personalized learning solution for computer networks, system, and cybersecurity focusing on hands-on projects. The personalized learning models are established in ThoTh Lab - a cloud-based hands-on virtual laboratory for Computer Science (CS) education. ThoTh Lab is a remote web-accessing virtual laboratory and it was originally designed to reduce lab management overhead for instructors and improve learning experience for CS students. By introducing new personalized learning capabilities, we can transfer ThoTh Lab from a traditional hands-on lab resource provisioning system to an active personalized e-learning platform for CS education. The system can track and assess students' hands-on projects' activities to monitor students' lab performance, and then provide intelligent suggestions or resources to improve students' learning experience and outcomes. Our personalized learning framework is distinguished from existing approaches by three salient features: (1) it is built into a hands-on and virtualized laboratory environment usually involving multiple virtual computers and their interconnections, (2) it has incorporated into a wide range of learners' characteristics such as individuals' learning style, prior knowledge and learning effectiveness, and it is designed to be able to include new and customizable features, (3) it uses machine learning approaches to model student characteristics during the learning process.
Yuli Deng, Dijiang Huang, Chun-Jen Chung
SIGCSE1
2014 QoS-constrained sensing task assignment for mobile crowd sensing
abstract
The ubiquitous sensing-capable mobile devices have been fuelling the new paradigm of Mobile Crowd Sensing (MCS) to collect data about their surrounding environment. To ensure the timeliness and quality of the data samples in MCS, it is critical to select qualified participants to maintain sensing coverage ratios over important spatial areas (i.e., hotspots) during time periods of interest and meet various Quality of Service (QoS) requirements of sensing applications. In this paper, we examine the problems of sensing task assignment to minimize the overall cost and maximize the total utility in MCS while adhering to the QoS constraints and prove that they are NP-hard problems. Consequently, we present heuristic greedy approaches as the baseline solutions and further propose new hybrid approaches with the greedy algorithm and bees algorithm combined to address them. We demonstrate that the hybrid approaches significantly outperform the greedy approaches through extensive simulation and the analysis is given in the end.
Zhijie Wang 0002, Dijiang Huang, Yuli Deng, Ailixier Aikebaier, Yuuichi Teranishi
GLOBECOM4
2014 Towards distributed privacy-preserving mobile access control
abstract
The mobile marketing is growing exponentially worldwide due to the emerging high speed wireless Internet and the proliferation of smartphones with powerful processors. Consequently, the management of the massive volume of mobile identities has sparked a lot of interest in both industry and academia, as they turn out to be a heavy burden for many mobile application startups. The conventional federated identity management technologies have been developed to delegate the users' identity tasks across different security domains to reduce the burden over the identity service consumers (i.e., Relying Party). However, they also raises serious security and privacy issues, such as the vulnerability to Single Point of Failure (SPOF) and the privacy leakage with respect to users' historical access information. To address these issues, we architect a novel Distributed Privacy-preserving Mobile Access Control (DP-MAC) framework. This framework also leverages a dual-root trust model to prevent identity theft in case of mobile device loss. In the end, we give performance evaluation and prove its applicability by implementing our system in the Cloud Computing platform and android smartphones based on jPBC in real-world settings.
Zhijie Wang 0002, Dijiang Huang, Bing Li 0019, Yuli Deng
GLOBECOM5