Chongrong Fang

dblp:166/5938 · DBLP profile ↗
← Back
14ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0003-2357-0228ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Practical Finite/Fixed-Time Tracking Control for Polynomial Systems With Unmeasurable States and Its Application to Circuits
abstract
The problem of finite/fixed-time tracking control has garnered considerable interest, owing to the stringent requirement on convergence performance in engineering applications. However, existing finite/fixed-time control methods are not directly applicable to polynomial systems, since the introduced fractional power term disrupts the inherent polynomial structure. To overcome this problem, we propose an observer-based tracking control strategy that achieves finite/fixed-time convergence for polynomial systems with unmeasurable states. First, a polynomial state observer is designed to estimate unmeasurable states. Based on the estimation results, finite-time and fixed-time tracking controllers are developed. Then, by utilizing Lyapunov stability theory and sum of squares optimization technique, sufficient conditions are constructed for the practical finite/fixed-time stability of the closed-loop system, enabling the co-design of observer and controller gains. Moreover, settling times are explicitly derived, and the fixed-time convergence is independent of initial system states. Finally, our theoretical methods are verified by simulation results.
Ying Li 0063, Jin Ke 0001, Chongrong Fang, Jianping He 0001
IEEE Trans Autom. Sci. Eng.3
2025 A Distributed Topology-Protecting Collaboration Algorithm: Design and Performance Analysis
abstract
The interaction topology of multiagent systems (MASs) is crucial for effective collaboration. Recent advances in topology inference provide a better understanding of the behaviors of the systems. Nevertheless, external attackers can exploit such techniques, posing a severe privacy breach, while the challenges to the topology protection problem remain unresolved. This article proposes a distributed collaboration algorithm for MASs to defend against topology inference attacks. The novelties include: 1) Compared with traditional noise-adding methods that inject decaying random inputs, the proposed algorithm constructs a novel noise term to increase the irregularity of the agents' states in a distributed manner while satisfying the convergence requirements. 2) A weight-selecting strategy is designed to choose the subtopologies to degrade the topology inference accuracy, further improving the topology-protecting performance. Theoretically, we derive the mean-square convergence factor and the nonasymptotic error bounds of our proposed algorithm. Extensive simulations demonstrate the effectiveness of the proposed algorithm in protecting the topology.
Zitong Wang 0001, Yushan Li 0001, Ying Li 0063, Chongrong Fang, Jianping He 0001
IEEE Trans. Cybern.4
2025 Enabling Stateful TCP Performance Profiling With Key Event Capturing
abstract
TCP ensures reliable transmission through its stateful implementation and remains crucial today. TCP performance profiling is essential for tasks like diagnosing network performance problems, optimizing transmission performance, and developing new TCP variants, etc. Existing profiling methods lack enough attention to TCP state transition to provide detailed insights on TCP performance. Thus, we build TcpSight, a tool focusing on TCP state transition throughout connection lifetimes. TcpSight conducts stateful analysis by capturing key events using an efficient per-connection lock-free data management mechanism. Besides, TcpSight enhances profiling by integrating application layer information collected from the TCP stack. With the profiling results, users can identify the culprit of TCP performance degradation, and evaluate the performance of TCP algorithms. We design optional modules and filtering mechanisms to reduce TcpSights overhead. Our evaluation presents that TcpSight incurs an additional CPU consumption of about 16.6% (without filtering) and 10.6% (with filtering) when the servers load is 55.7%, and generates storage consumption about 1.88 KB per connection on average. We also give application cases of TcpSight and the deployment experiences in Alibaba Cloud. TcpSight helps in revealing meaningful findings and insights into exploiting TCP in the production deployment.
Ruopeng Geng, Jianyuan Lu, Chongrong Fang, Shaokai Zhang, Jiangu Zhao, Zhigang Zong, Biao Lyu, Shunmin Zhu, Peng Cheng 0001, Jiming Chen 0001
IEEE Trans. Netw. Serv. Manag.3
2024 Towards resilient average consensus in multi-agent systems: a detection and compensation approach
abstract
Consensus is one of the fundamental distributed control technologies for collaboration in multi-agent systems such as collaborative handling in intelligent manufacturing. In this paper, we study the problem of resilient average consensus for multi-agent systems with misbehaving nodes. To protect consensus value from being influenced by misbehaving nodes, we address this problem by detecting misbehaviors, mitigating the corresponding adverse impact, and achieving the resilient average consensus. General types of misbehaviors are considered, including attacks, accidental faults, and link failures. We characterize the adverse impact of misbehaving nodes in a distributed manner via two-hop communication information and develop a deterministic detection compensation based consensus (D-DCC) algorithm with a decaying fault-tolerant error bound. Considering scenarios wherein information sets are intermittently available due to link failures, a stochastic extension named stochastic detection compensation based consensus (S-DCC) algorithm is proposed. We prove that D-DCC and S-DCC allow nodes to asymptotically achieve resilient accurate average consensus and unbiased resilient average consensus in a statistical sense, respectively. Then, the Wasserstein distance is introduced to analyze the accuracy of S-DCC. Finally, extensive simulations are conducted to verify the effectiveness of the proposed algorithms.
Chongrong Fang, Wenzhe Zheng, Zhiyu He 0002, Jianping He 0001, Chengcheng Zhao
Frontiers Inf. Technol. Electron. Eng.1
2023 Resilient Distributed Classification Learning Against Label Flipping Attack: An ADMM-Based Approach
abstract
Distributed classification learning (DCL) is a promising solution to establish Internet of Things-based smart applications, especially due to its strong ability in dealing with large-scale and high-concurrency data. However, the performance of DCL may be seriously affected by the label flipping attack (LFA). Regarding the LFA-resilient learning problem, most existing works are built in more centralized settings. The work addressing the secure DCL issue makes an assumption that the label flipping rates are symmetric and available for scheme design. In this article, we remove this assumption and propose an LFA-resilient DCL scheme, named FENDER, without knowing the asymmetric flipping rates. The challenge is to guarantee both attack resilience and algorithm convergence. We carefully integrate a resilient loss and the alternating direction method of the multiplier scheme, making FENDER resilient to LFA. Further, we systematically analyze the performance of FENDER according to a metric reflecting the models obtained by all the servers at different iterations. In addition, we discuss and compare FENDER with some existing methods from the aspects of algorithm establishment and performance guarantee. Finally, extensive experiments with multiple real-world data sets are performed to validate the developed theory and evaluate the performance of the trained models.
Xin Wang 0044, Chongrong Fang, Ming Yang 0023, Heng Zhang 0001, Peng Cheng 0001
IEEE Internet Things J.2
2023 FlowPinpoint: Localizing Anomalies in Cloud-Client Services for Cloud Providers
abstract
For public cloud providers, it is of great significance to maintain the availability of their cloud services, which requires efficient anomaly diagnosis and recovery. To achieve such properties, the first step is to localize the anomalies, i.e., determining where they happen in the network path of cloud-client services. We propose FlowPinpoint to perform anomaly localization for cloud providers. FlowPinpoint collects statistics of each network flow at the cloud network gateways (i.e., gateway flowlog), where the collected data can reflect the information from both the cloud side and the Internet side. Aggregation and association are conducted on the datacenter-scale gateway flowlogs by Alibaba's big data computing platform. In order to preclude the disturbance of anomaly-unrelated flowlogs, a two-layer filter is proposed which consists of an indicator-based filter and an isolation forest filter. Finally, the anomaly localization analyzer classifies the flowlogs and determines whether the anomaly is inside the cloud network or not according to the classification results. FlowPinpoint is implemented and tested in the production environment of Alibaba Cloud, and it correctly localizes 1 anomaly inside the cloud and 6 anomalies on the Internet over 4 months.
Ruopeng Geng, Chongrong Fang, Shiyang Guo, Daxiang Kang, Biao Lyu, Shunmin Zhu, Peng Cheng 0001
IEEE Trans. Cloud Comput.2
2023 Detection-Performance Tradeoff for Watermarking in Industrial Control Systems
abstract
The watermarking method, which adds unique watermarks to data, has been widely used for integrity attack detection in industrial control systems (ICSs). Existing literature generally designs watermarking mechanisms without considering the existence of noises, which cannot be trivially applied to realistic ICS scenarios in the presence of strong noise interference. On one hand, the low-intensity watermarking will be ineffective under the strong noise environment; while on the other hand, the oversized watermarking can possibly degrade the control performance or even destabilize the system. Therefore, the intensity of watermarks plays a fundamental role in balancing the tradeoff between detection effectiveness and control performance, which, to the best of our knowledge, has never been thoroughly analyzed yet. To this end, in this paper, we for the first time propose an optimal watermarking design method for ICSs considering the detection-performance tradeoff. To begin with, we shift the watermark container from data points to segments and update the detection metrics to reduce the noise impact. Then, we formulate an optimization problem to determine the strength of watermarks to balance the detection-performance tradeoff. Meanwhile, the detection effectiveness and control performance metrics are analytically modeled and theoretically analyzed considering the discrepancy between added watermarks and noises, signal quality, detection latency, as well as estimation of detection metrics. Finally, extensive numerical simulations and systematical experiments based on a practical Ethanol Distillation ICS are conducted to validate the theoretical analysis and demonstrate the outperformance of our proposed watermarking method in comparison with related works.
Hengye Zhu, Mengxiang Liu, Chongrong Fang, Ruilong Deng, Peng Cheng 0001
IEEE Trans. Inf. Forensics Secur.3
2022 Toward Global Sensing Quality Maximization: A Configuration Optimization Scheme for Camera Networks
abstract
The performance of a camera network monitoring a set of targets depends crucially on the configuration of the cameras. In this paper, we investigate the reconfiguration strategy for the parameterized camera network model, with which the sensing qualities of the multiple targets can be optimized globally and simultaneously. We first propose to use the number of pixels occupied by a unit-length object in image as a metric of the sensing quality of the object, which is determined by the parameters of the camera, such as intrinsic, extrinsic, and distortional coefficients. Then, we form a single quantity that measures the sensing quality of the targets by the camera network. This quantity further serves as the objective function of our optimization problem to obtain the optimal camera configuration. We verify the effectiveness of our approach through extensive simulations and experiments, and the results reveal its improved performance on the AprilTag detection tasks. Codes and related utilities for this work are open-sourced and available at https://github.com/sszxc/MultiCam-Simulation.
Xuechao Zhang, Xuda Ding, Yu Zheng 0001, Chongrong Fang, Jianping He 0001
IROS5
2022 Generating Adversarial Examples Against Machine Learning-Based Intrusion Detector in Industrial Control Systems
abstract
Deploying machine learning (ML)-based intrusion detection systems (IDS) is an effective way to improve the security of industrial control systems (ICS). However, ML models themselves are vulnerable to adversarial examples, generated by deliberately adding subtle perturbation to the input sample that some people are not aware of, causing the model to give a false output with high confidence. In this article, our goal is to investigate the possibility of stealthy cyber attacks towards IDS, including injection attack, function code attack and reconnaissance attack, and enhance its robustness to adversarial attack. However, adversarial algorithms are subject to communication protocol and legal range of data in ICS, unlike only limited by the distance between original samples and newly generated samples in image domain. We propose two strategies - optimal solution attack and GAN attack - oriented to flexibility and volume of data, formulating an optimization problem to find stealthy attacks, where the former is appropriate for not too large and more flexible samples while the latter provides a more efficient solution for larger and not too flexible samples. Finally, we conduct experiments on a semi-physical ICS testbed with a high detection performance ensemble ML-based detector to show the effectiveness of our attacks. The results indicate that new samples of reconnaissance and function code attack produced by both optimal solution and GAN algorithm possess 80 percent higher probability to evade the detector, still maintaining the same attack effect. In the meantime, we adopt adversarial training as a method to defend against adversarial attack. After training on the mixture of orginal dataset and newly generated samples, the detector becomes more robust to adversarial examples.
Jiming Chen 0001, Xiangshan Gao, Ruilong Deng, Chongrong Fang, Peng Cheng 0001
IEEE Trans. Dependable Secur. Comput.5
2022 Towards Automatic Root Cause Diagnosis of Persistent Packet Loss in Cloud Overlay Network
abstract
Persistent packet loss in the cloud-scale overlay network severely compromises tenant experiences. Cloud providers are keen to diagnose such problems efficiently. However, existing work is either designed for the physical network or insufficient to present the concrete reason of packet loss. We propose to record and analyze the on-site forwarding condition of packets during packet-level tracing. The cloud-scale overlay network presents great challenges to achieve this goal with its high network complexity, multi-tenant nature, and diversity of root causes. To address these challenges, we present VTrace, an automatic diagnostic system for persistent packet loss over the cloud-scale overlay network. Utilizing the “fast path-slow path” structure of virtual forwarding devices (VFDs), e.g., vSwitches, VTrace installs several “coloring-matching-logging” rules in VFDs to selectively track the target packets and inspect them in depth. The detailed forwarding situation at each hop is logged and then assembled to perform analysis with an efficient path reconstruction scheme. Experiments are conducted to demonstrate VTrace’s low overhead and quick response. Besides, based on the idea “coloring-matching-counting”, VTrace can be easily extended toVTrace-statsto identify the culprit device for transient packet loss. We share experiences of how VTrace andVTrace-statsefficiently work after deploying them in Alibaba Cloud for years.
Chongrong Fang, Haoyu Liu 0002, Mao Miao, Lei Wang 0005, Wansheng Zhang, Daxiang Kang, Biao Lyu, Shunmin Zhu, Peng Cheng 0001, Jiming Chen 0001
IEEE/ACM Trans. Netw.1
2021 A survey of cloud network fault diagnostic systems and tools
abstract
Recently, cloud computing has become a vital part that supports people’s normal lives and production. However, accompanied by the increasing complexity of the cloud network, failures constantly keep coming up and cause huge economic losses. Thus, to guarantee the cloud network performance and prevent execrable effects caused by failures, cloud network diagnostics has become of great interest for cloud service providers. Due to the characteristics of cloud network (e.g., virtualization and multi-tenancy), transplanting traditional network diagnostic tools to the cloud network face several difficulties. Additionally, many existing tools cannot solve problems in the cloud network. In this paper, we summarize and classify the state-of-the-art technologies of cloud diagnostics which can be used in the production cloud network according to their features. Moreover, we analyze the differences between cloud network diagnostics and traditional network diagnostics based on the characteristics of the cloud network. Considering the operation requirements of the cloud network, we propose the points that should be cared about when designing a cloud network diagnostic tool. Also, we discuss the challenges that cloud network diagnostics will face in future development.
Yining Qi, Chongrong Fang, Haoyu Liu 0002, Daxiang Kang, Biao Lyu, Peng Cheng 0001, Jiming Chen 0001
Frontiers Inf. Technol. Electron. Eng.2
2020 RAIN: Towards Real-Time Core Devices Anomaly Detection Through Session Data in Cloud Network
abstract
Core devices form the critical components of the cloud network and provide service to multiple tenants simultaneously. The anomalies that happened in core devices impact network availability of a large number of users, meanwhile, lead to the degradation of cloud providers’ profits. However, direct monitoring of core devices needs to deploy massive heartbeat checking tools on numerous related components, which will be extremely laborious. In this paper, we deploy RAIN to reduce the number of devices that need to be detailed investigated for anomalies. The session traffic data among core devices and served virtual machines are utilized to conduct the analyzing. To guarantee near real-time monitoring, RAIN is designed as a two-step structure and incorporating four feature-based detection methods. RAIN has been deployed in Alibaba’s production cloud network for over 6 months and is analyzing terabytes of traffic flow metrics per day.
Haoyu Liu 0002, Chongrong Fang, Yining Qi, Shaozhe Wang, Daxiang Kang, Biao Lyu, Peng Cheng 0001, Jiming Chen 0001
NOMS2
2020 VTrace: Automatic Diagnostic System for Persistent Packet Loss in Cloud-Scale Overlay Network
abstract
Persistent packet loss in the cloud-scale overlay network severely compromises tenant experiences. Cloud providers are keen to automatically and quickly determine the root cause of such problems. However, existing work is either designed for the physical network or insufficient to present the concrete reason of packet loss. In this paper, we propose to record and analyze the on-site forwarding condition of packets during packet-level tracing. The cloud-scale overlay network presents great challenges to achieve this goal with its high network complexity, multi-tenant nature, and diversity of root causes. To address these challenges, we present VTrace, an automatic diagnostic system for persistent packet loss over the cloud-scale overlay network. Utilizing the "fast path-slow path" structure of virtual forwarding devices (VFDs), e.g., vSwitches, VTrace installs several "coloring, matching and logging" rules in VFDs to selectively track the packets of interest and inspect them in depth. The detailed forwarding situation at each hop is logged and then assembled to perform analysis with an efficient path reconstruction scheme. Experiments are conducted to demonstrate VTrace's low overhead and quick responsiveness. We share experiences of how VTrace efficiently resolves persistent packet loss issues after deploying it in Alibaba Cloud for over 20 months.
Chongrong Fang, Haoyu Liu 0002, Mao Miao, Lei Wang 0005, Wansheng Zhang, Daxiang Kang, Biao Lyu, Peng Cheng 0001, Jiming Chen 0001
SIGCOMM1
2016 FindIt: Real-time Through-Wall Human Motion Detection Using Narrow Band SDR: Demo Abstract
abstract
We present a system utilizing narrow band software defined radio to detect the moving human through walls, and give some motion details, such as motion orientation which includes relative moving direction. To achieve high accuracy, FindIt applies Short Time Fourier Transform (STFT) and statistical methods to received signals. In order to adapt to different environments, FindIt uses clustering and classification methods to determine thresholds. Moreover, FindIt provides user-friendly real-time detection results, which can be used as a trigger of high-level functions.
Chongrong Fang, Yuanchao Shu, Zhiguo Shi 0001, Jiming Chen 0001
SenSys2