Zhida Li

dblp:166/3013 · DBLP profile ↗
← Back
16ranked-venue papers
6as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 6 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2025 GEE: Graphormer-Enhanced Encoder Model for Anomaly Detection in Weighted Signed Networks
abstract
Complex network structures with signed and weighted relationships are common in many real-world systems. We present Graphormer-Enhanced Encoder (GEE), a transformer-based model for anomaly detection in such graphs. GEE extends Graph-BERT’s subgraph batching with Graphormer-style attention, integrating a signed-edge Weisfeiler-Lehman (WL) absolute positional embedding to capture global structure and edge signs, and an edge-weight encoding within the attention mechanism to incorporate rating magnitudes. We also prove two properties of the signed WL formulation. Experiments on the Bitcoin Alpha and Bitcoin OTC networks demonstrate that GEE can effectively detect anomalies in complex weighted signed networks.
Hongbo Du, Zhida Li
SMC2
2025 CSFNet: A novel counting network based on context features and multi-scale information
Liyan Xiong, Zhida Li, Xiaohui Huang 0003
Multim. Syst.2
2023 Deep Echo State Networks for Detecting Internet Worm and Ransomware Attacks
abstract
With the advancement of technology over the last decade, there has been a rapid increase in the number and types of malware attacks such as worms whose primary function is to self-replicate and infect systems and ransomware that corrupts and encrypts data. Developing proactive cyber defense techniques is essential for effectively detecting network anomalies that are evolving and becoming more challenging to identify. In this paper, we consider intrusion detection techniques using fast machine learning algorithms. We investigate Echo and Deep Echo State Networks machine learning structures for detecting worm and ransomware anomalies. We demonstrate, analyze, and compare merits of this approach using Slammer worm, WannaCrypt ransomware, and WestRock ransomware attack datasets.
Khushi Patni, Zhida Li, Ljiljana Trajkovic
ISCAS3
2023 Enhancing Cyber Defense: Using Machine Learning Algorithms for Detection of Network Anomalies
abstract
Developing advanced cyber defense techniques is essential for effectively detecting network anomalies that are becoming more challenging to identify. In this paper, we generate machine learning models based on real-time Internet and historical data and evaluate their classification performance. We introduce a network anomaly detection tool CyberDefense that integrates various stages of the anomaly detection process. It facilitates performance evaluation of machine learning algorithms and generation of new machine learning models. Its modular and scalable design enables incorporating new datasets and machine learning algorithms. The tool has been utilized to generate models and evaluate their classification performance using datasets collected during reported power outage and ransomware attacks.
Zhida Li, Ljiljana Trajkovic
SMC1
2023 TFA-CNN: an efficient method for dealing with crowding and noise problems in crowd counting
Liyan Xiong, Zhida Li, Xiaohui Huang 0003, Yijuan Zeng
Multim. Syst.2
2021 Classifying Denial of Service Attacks Using Fast Machine Learning Algorithms
abstract
Denial of service attacks are harmful cyberattacks that diminish Internet resources and services. Hence, detecting these cyberattacks is a topic of great interest in cybersecurity. Using traditional machine learning approaches in intrusion detection systems requires long training time and has high computational complexity. Thus, we evaluate performance of fast machine learning algorithms for training and generating models to detect denial of service attacks in communication networks. We use synthetically generated datasets that captured Transmission Control Protocol and User Datagram Protocol network flows in a controlled testbed laboratory environment. Evaluated algorithms include broad learning system and its extensions as well as XGBoost, LightGBM, and CatBoost gra-dient boosting decision tree algorithms. Experiments indicate that boosting algorithms often require shorter training time and have better performance.
Zhida Li, Ana Laura Gonzalez Rios, Ljiljana Trajkovic
SMC1
2021 Machine Learning for Detecting Anomalies and Intrusions in Communication Networks
abstract
Cyber attacks are becoming more sophisticated and, hence, more difficult to detect. Using efficient and effective machine learning techniques to detect network anomalies and intrusions is an important aspect of cyber security. A variety of machine learning models have been employed to help detect malicious intentions of network users. In this paper, we evaluate performance of recurrent neural networks (Long Short-Term Memory and Gated Recurrent Unit) and Broad Learning System with its extensions to classify known network intrusions. We propose two BLS-based algorithms with and without incremental learning. The algorithms may be used to develop generalized models by using various subsets of input data and expanding the network structure. The models are trained and tested using Border Gateway Protocol routing records as well as network connection records from the NSL-KDD and Canadian Institute of Cybersecurity datasets. Performance of the models is evaluated based on selected features, accuracy, F-Score, and training time.
Zhida Li, Ana Laura Gonzalez Rios, Ljiljana Trajkovic
IEEE J. Sel. Areas Commun.1
2020 Detection of Denial of Service Attacks in Communication Networks
abstract
Detection of evolving cyber attacks is a challenging task for conventional network intrusion detection techniques. Various supervised machine learning algorithms have been implemented in network intrusion detection systems. However, traditional algorithms require long training time and have high computational complexity. Therefore, we propose detection of denial of service cyber attacks in communication networks by employing the broad learning system (BLS) that requires shorter training time while achieving comparable performance. Because designing effective detection systems relies on training and test datasets that contain anomalous network traffic data, in this paper we evaluate the performance of various BLS models by using recently generated network intrusion datasets. The best accuracy and F-Score were often achieved using BLS with cascades while BLS with incremental learning usually required shorter training time.
Ana Laura Gonzalez Rios, Zhida Li, Kamila Bekshentayeva, Ljiljana Trajkovic
ISCAS2
2020 Detecting Internet Worms, Ransomware, and Blackouts Using Recurrent Neural Networks
abstract
Analyzing and detecting Border Gateway Protocol (BGP) anomalies are topics of great interest in cybersecurity. Various anomaly detection approaches such as time series and historical-based analysis, statistical validation, reachability checks, and machine learning have been applied to BGP datasets. In this paper, we use BGP update messages collected from Réseaux IP Europeens and Route Views to detect BGP anomalies caused by Slammer worm, WannaCrypt ransomware, and Moscow blackout by employing recurrent neural network machine learning algorithms.
Zhida Li, Ana Laura Gonzalez Rios, Ljiljana Trajkovic
SMC1
2019 Machine Learning Techniques for Classifying Network Anomalies and Intrusions
abstract
Using machine learning techniques to detect network intrusions is an important topic in cybersecurity. A variety of machine learning models have been designed to help detect malicious intentions of network users. We employ two deep learning recurrent neural networks with a variable number of hidden layers: Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU). We also evaluate the recently proposed Broad Learning System (BLS) and its extensions. The models are trained and tested using Border Gateway Protocol (BGP) datasets that contain routing records collected from Réseaux IP Européens (RIPE) and BCNET as well as the NLS-KDD dataset containing network connection records. The algorithms are compared based on accuracy and F-Score.
Zhida Li, Ana Laura Gonzalez Rios, Ljiljana Trajkovic
ISCAS1
2018 Evaluation of Support Vector Machine Kernels for Detecting Network Anomalies
abstract
Border Gateway Protocol (BGP) is used to exchange routing information across the Internet. BGP anomalies severely affect network performance and, hence, algorithms for anomaly detection are important for improving BGP convergence. Efficient and effective anomaly detection mechanisms rely on employing machine learning techniques. Support Vector Machine (SVM) is a widely used machine learning algorithm. In this paper, we evaluate performance of SVM with linear, quadratic, and cubic kernels. The SVM kernels are compared based on accuracy and the F-Score when detecting BGP anomalies in Internet traffic traces. The performance heavily depends on the selected features and their combinations.
Prerna Batta, Maninder Singh 0001, Zhida Li, Qingye Ding, Ljiljana Trajkovic
ISCAS3
2018 Comparison of Machine Learning Algorithms for Detection of Network Intrusions
abstract
Detecting, analyzing, and defending against network intrusions is an important topic in cyber security. Various detection systems have been designed using machine learning techniques that help detect malicious intentions of network users. We apply Recurrent Neural Networks (RNNs) and Broad Learning System (BLS) machine learning algorithms to classify known network intrusions. The developed models are trained and tested using the NSL-KDD dataset containing information about both intrusion and regular network connections. The algorithms are used to classify various types of intrusion classes and regular data and are compared based on accuracy and F-Score. Comparison results indicate that the BLS algorithm shows comparable performance with shorter training time.
Zhida Li, Prerna Batta, Ljiljana Trajkovic
SMC1
2017 Comparison of Virtualization Algorithms and Topologies for Data Center Networks
abstract
Data centers are core infrastructure of cloud computing. Network virtualization in these centers is a promising solution that enables coexistence of multiple virtual networks on a shared infrastructure. It offers flexible management, lower implementation cost, higher network scalability, increased resource utilization, and improved energy efficiency. In this paper, we consider switch-centric data center network topologies and evaluate their use for network virtualization by comparing Deterministic (D-ViNE) and Randomized (R-ViNE) Virtual Network Embedding, Global Resource Capacity (GRC), and Global Resource Capacity-Multicommodity (GRC-M) Flow algorithms.
Hanene Ben Yedder, Qingye Ding, Umme Zakia, Zhida Li, Soroush Haeri, Ljiljana Trajkovic
ICCCN4
2016 Global resource capacity algorithm with path splitting for virtual network embedding
abstract
Network visualization enables support and deployment of new services and applications that the current Internet architecture is unable to support. Virtual Network Embedding (VNE) problem that addresses efficient mapping of virtual network elements onto a physical infrastructure (substrate network) is one of the main challenges in network virtualization. The Global Resource Capacity (GRC) is a VNE algorithm that utilizes for virtual link mapping a modified version of Dijkstra's shortest path algorithm. In this paper, we propose the GRC-M algorithm that utilizes the Multicommodity Flow (MCF) algorithm. MCF enables path splitting and yields to higher substrate resource utilizations. Simulation results show that MCF significantly enhances performance of the GRC algorithm.
Soroush Haeri, Qingye Ding, Zhida Li, Ljiljana Trajkovic
ISCAS3
2016 Detecting BGP anomalies using machine learning techniques
abstract
Border Gateway Protocol (BGP) anomalies affect network operations and, hence, their detection is of interest to researchers and practitioners. Various machine learning techniques have been applied for detection of such anomalies. In this paper, we first employ the minimum Redundancy Maximum Relevance (mRMR) feature selection algorithms to extract the most relevant features used for classifying BGP anomalies and then apply the Support Vector Machine (SVM) and Long Short-Term Memory (LSTM) algorithms for data classification. The SVM and LSTM algorithms are compared based on accuracy and F-score. Their performance was improved by choosing balanced data for model training.
Qingye Ding, Zhida Li, Prerna Batta, Ljiljana Trajkovic
SMC2
2015 The noise and spur delusion in fractional-N frequency synthesizer design
abstract
The standard design methodology for fractional-N frequency synthesizers assumes that the filtered shaped quantization noise from the requantizer is masked below the spectral envelope of the underlying integer-N synthesizer. Fractional-N frequency synthesizers are notorious for exhibiting an elevated noise floor and an unpredictable pattern of spurs. In this paper, we argue that designers should not be deluded by the overly conservative predictions of the simplified linear model but should instead consider nonlinearities as early as possible in the design process.
Michael Peter Kennedy, Hongjia Mo, Zhida Li, Guosheng Hu, Paolo Scognamiglio, Ettore Napoli
ISCAS3